I recently (27th Dec) bought a new laptop (Lenovo IdeaPad 310 i7 64-bit). All I have downloaded on it are the following programmes:
Malwarebytes, Spywareblaster, Superantipspyware, WinPatrol, Filehippo, uTorrent, Advanced uninstaller PRO, Daemon tools, 7zip, iTunes, Java, Skype, VLC media player, and Microsoft office from my university's free subscription service. I have windows defender set to periodic scanning, with real time protection from the McAfee antivirus the laptop came with. I was planning on getting Kaspersky antivirus before disabling McAfee but I started having this problem before I could.
WinPatrol monitors changes programes want to make on my computer, and I get a pop-up asking for permission to let programes start at startup. After I downloaded microsoft office I got a pop asking for permission for Windows Command Processor, which sounded important and I was going to accept the change but I decided to research it a little bit first and found that it is actually type of malware. I rejected the change, but the same pop-up kept coming back and I found during my research that the malware is tricky to uninstall. On top of that several other start-up permission pop ups (Lync browser helper, itunes helper) and add-on permission pop-ups (Onedrive for business and lync click-to-call) keep coming up repeated within minutes of me rejecting them. On top of that, my new laptop is very slow on start-up despite my having disabled the programes I know I don't need running at start-up, and barely having anything in it. It cannot be because the processor is weak (its an i7) or because it doesn't have enough memory (8gb ram with 2tb storage). I checked task manager and found that the CPU usage was at 97% at one point and then dropped to 58% so I wasn't able to check what was eating up so much power. I am not sure exactly what is wrong, and how I got infected in the first place. The laptop is also running slower than expected when operating normally, and a lot of the setting that I have changed haven't actually taken effect even after restarting. If i check my settings they are set to what I changed them to, but in actual use I don't see those changes.
My old laptop is 6 years old and while I am a relatively safe user now, that wasn't really the case when I first got my old laptop. It could be that some form of infection I got in the early days never got cleaned out properly and stayed on. The only thing that I have connected from my old laptop to my new one is the USB mouse that I use instead of the touchpad. However, I am aware that it is possible for infections to go from one device to another if they're connected to the same router. I have 3 laptops, 1 desktop and 5 mobile phones all using the same wifi connection within my household, and I cannot say that all users are safe users within us. I have read the posting guidelines, and gather all the necessary logs from both my new laptop and the old one as I am suspecting there is a high chance that is how my new laptop got infected and I am copying them below. The first set is from my new laptop, and the second set is from my old one (Sony VAIO i3)
New laptop:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-12-2016
Ran by rubai (administrator) on LAPTOP-H11LMCGD (28-12-2016 22:08:04)
Running from C:\Users\rubai\Downloads
Loaded Profiles: rubai (Available Profiles: defaultuser0 & rubai)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
() C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\mcsvchost\McSvHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Innovative Solutions GRUP SRL) C:\Program Files (x86)\Innovative Solutions\Advanced Uninstaller PRO\uninstaller.exe
(Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD12\PDVD12Serv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files\Lenovo\LenovoUtility\utility.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
() C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe
(Ruiware) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
(SweetLabs, Inc) C:\Users\rubai\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.9.829.0\McCSPServiceHost.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(Lenovo) C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Intel Security) C:\Program Files\Common Files\McAfee\ClientAnalytics\McClientAnalytics.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.350_none_43278ee965418581\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791848 2016-08-27] ()
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [809472 2016-05-16] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830232 2016-03-08] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [602968 2015-12-08] (Conexant Systems, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES/MALWAREBYTES/ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110008 2015-07-21] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492472 2015-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-249857850-3300716479-2824224529-1001\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe [10566352 2015-09-02] ()
HKU\S-1-5-21-249857850-3300716479-2824224529-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe [1231240 2016-11-14] (Ruiware)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3c534fd4-232a-4f81-a4ae-106587f717f2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{524bc8a0-db43-47fd-b825-64eaecd18972}: [DhcpNameServer] 150.207.1.2
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-249857850-3300716479-2824224529-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-249857850-3300716479-2824224529-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-249857850-3300716479-2824224529-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
SearchScopes: HKU\S-1-5-21-249857850-3300716479-2824224529-1001 -> DefaultScope {2EFAACDB-4865-45C6-849A-0F556923BA18} URL =
SearchScopes: HKU\S-1-5-21-249857850-3300716479-2824224529-1001 -> {2EFAACDB-4865-45C6-849A-0F556923BA18} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-12-27] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-27] (Oracle Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-27] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-27] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-27] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-27] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2016-10-19] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2016-10-19] (McAfee, Inc.)
FireFox:
========
FF DefaultProfile: s2hjnj8d.default
FF ProfilePath: C:\Users\rubai\AppData\Roaming\Mozilla\Firefox\Profiles\s2hjnj8d.default [2016-12-28]
FF Extension: (Awesome Screenshot - Capture, Annotate & More) - C:\Users\rubai\AppData\Roaming\Mozilla\Firefox\Profiles\s2hjnj8d.default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2016-12-27]
FF Extension: (uBlock Origin) - C:\Users\rubai\AppData\Roaming\Mozilla\Firefox\Profiles\s2hjnj8d.default\Extensions\uBlock0@raymondhill.net.xpi [2016-12-27]
FF Extension: (Session Manager) - C:\Users\rubai\AppData\Roaming\Mozilla\Firefox\Profiles\s2hjnj8d.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2016-12-27]
FF Extension: (YouTube High Definition) - C:\Users\rubai\AppData\Roaming\Mozilla\Firefox\Profiles\s2hjnj8d.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2016-12-27]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2016-12-27] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-10-19] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-27] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-10-19] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-27] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default [2016-12-28]
CHR Extension: (Google Slides) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-27]
CHR Extension: (Google Docs) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-27]
CHR Extension: (Google Drive) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-27]
CHR Extension: (YouTube) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-27]
CHR Extension: (Session Buddy) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2016-12-27]
CHR Extension: (Google Sheets) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-27]
CHR Extension: (Whatsapp Web) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahehbojcacaklcdefjblcpcpammjlj [2016-12-27]
CHR Extension: (Google Docs Offline) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-27]
CHR Extension: (Awesome Screenshot: Screen capture, Annotate) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2016-12-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-27]
CHR Extension: (Speedtest by Ookla) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjjikdiikihdfpoppgaidccahalehjh [2016-12-27]
CHR Extension: (Gmail) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-27]
CHR Extension: (Chrome Media Router) - C:\Users\rubai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-27]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
S2 0143641482962494mcinstcleanup; C:\Windows\TEMP\014364~1.EXE [961888 2016-05-16] (McAfee, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [338312 2016-06-29] (Windows ® Win 7 DDK provider)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [666608 2016-03-22] (Lenovo)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3019968 2016-12-04] (Microsoft Corporation)
S3 cplspcon; C:\Windows\system32\IntelCpHDCPSvc.exe [457184 2016-09-03] (Intel Corporation)
R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [146944 2016-05-16] () [File not signed]
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [134888 2016-07-20] (ELAN Microelectronics Corp.)
R2 GDCAgent; C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe [1210352 2016-03-23] (Lenovo)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [382440 2016-09-03] (Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [62792 2016-12-01] (Lenovo Group Limited)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [993824 2016-10-19] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [419096 2016-04-01] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.9.829.0\\McCSPServiceHost.exe [1910000 2016-05-31] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [816128 2016-06-21] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232688 2016-04-27] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [382456 2016-07-01] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [277744 2016-04-27] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1454216 2016-09-13] (McAfee, Inc.)
S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1045336 2016-05-25] (Intel Security, Inc.)
R2 SAService; C:\Windows\system32\SAsrv.exe [431960 2015-09-15] (Conexant Systems, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [78632 2016-04-27] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [216704 2016-08-02] (McAfee, Inc.)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [250816 2016-12-28] (Malwarebytes)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [419616 2016-04-27] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [349480 2016-04-27] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [83608 2016-04-27] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [493352 2016-04-27] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [843048 2016-04-27] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [519456 2016-08-01] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [100136 2016-08-01] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [243488 2016-04-27] (McAfee, Inc.)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3343872 2016-07-16] (Intel Corporation)
R3 Qcamain10x64; C:\Windows\System32\drivers\Qcamain10x64.sys [2400184 2016-06-29] (Qualcomm Atheros, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-01-22] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [416472 2016-05-17] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3118848 2016-05-12] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-28 22:08 - 2016-12-28 22:08 - 00023551 _____ C:\Users\rubai\Downloads\FRST.txt
2016-12-28 22:07 - 2016-12-28 22:08 - 00000000 ____D C:\FRST
2016-12-28 21:55 - 2016-12-28 22:07 - 02420736 _____ (Farbar) C:\Users\rubai\Downloads\FRST64.exe
2016-12-28 21:54 - 2016-12-28 22:07 - 00899072 _____ C:\Users\rubai\Downloads\RGSA.exe
2016-12-28 21:40 - 2016-12-28 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2016-12-28 07:48 - 2016-12-28 07:48 - 00000020 ___SH C:\Users\defaultuser0\ntuser.ini
2016-12-28 07:48 - 2016-12-28 07:48 - 00000000 _SHDL C:\Users\defaultuser0\My Documents
2016-12-28 07:48 - 2016-12-28 07:48 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Videos
2016-12-28 07:48 - 2016-12-28 07:48 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Pictures
2016-12-28 07:48 - 2016-12-28 07:48 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Music
2016-12-28 07:48 - 2016-12-27 16:53 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\Host App Service
2016-12-28 07:48 - 2016-12-27 16:48 - 00000000 ____D C:\Users\defaultuser0
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Public\Documents\My Music
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default\My Documents
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-12-28 07:46 - 2016-12-28 07:46 - 00000000 _SHDL C:\Documents and Settings
2016-12-28 00:47 - 2016-12-28 00:47 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-12-28 00:27 - 2016-12-28 00:27 - 02365296 _____ (Microsoft Corporation) C:\Windows\system32\WudfUpdate_01011.dll
2016-12-27 23:52 - 2016-12-27 23:52 - 00002248 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-12-27 23:52 - 2016-12-27 23:52 - 00002214 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-12-27 23:48 - 2016-12-27 23:48 - 03907376 _____ (Microsoft Corporation) C:\Users\rubai\Downloads\Setup.X86.en-us_O365ProPlusRetail_009121f5-1790-439a-bb30-497507999e9b_TX_PR_b_32_.exe
2016-12-27 23:38 - 2016-12-27 23:38 - 01512368 _____ (Ruiware) C:\Users\rubai\Downloads\wpsetup (1).exe
2016-12-27 23:36 - 2016-12-28 22:01 - 00004208 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
2016-12-27 23:36 - 2016-12-28 22:01 - 00004020 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
2016-12-27 22:37 - 2016-12-27 22:37 - 00000000 ____D C:\Users\rubai\Downloads\Install JDownloader
2016-12-27 22:36 - 2016-12-27 22:36 - 01381582 _____ (Igor Pavlov) C:\Users\rubai\Downloads\7z1604-x64.exe
2016-12-27 22:36 - 2016-12-27 22:36 - 00248946 _____ C:\Users\rubai\Downloads\Install JDownloader.rar
2016-12-27 22:36 - 2016-12-27 22:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-12-27 22:36 - 2016-12-27 22:36 - 00000000 ____D C:\Program Files\7-Zip
2016-12-27 22:29 - 2016-12-27 22:29 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-12-27 22:09 - 2016-12-27 22:32 - 00000000 ____D C:\Users\rubai\AppData\Roaming\WinPatrol
2016-12-27 22:08 - 2016-12-27 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-12-27 22:08 - 2016-12-27 22:08 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2016-12-27 22:05 - 2016-12-27 22:05 - 00001821 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-12-27 22:05 - 2016-12-27 22:05 - 00000000 ____D C:\Users\rubai\AppData\Roaming\DAEMON Tools Lite
2016-12-27 22:05 - 2016-12-27 22:05 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-12-27 22:05 - 2016-12-27 22:05 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2016-12-27 22:03 - 2016-12-27 22:03 - 00692488 _____ (Disc Soft Ltd.) C:\Users\rubai\Downloads\DTLiteInstaller.exe
2016-12-27 21:58 - 2016-12-27 22:07 - 30533688 _____ C:\Users\rubai\Downloads\vlc-2.2.4-win32.exe
2016-12-27 21:57 - 2016-12-27 23:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2016-12-27 21:57 - 2016-12-27 23:38 - 00000000 ____D C:\ProgramData\InstallMate
2016-12-27 21:57 - 2016-12-27 21:57 - 00000000 ____D C:\Program Files (x86)\Ruiware
2016-12-27 21:56 - 2016-12-27 21:57 - 01512368 _____ (Ruiware) C:\Users\rubai\Downloads\wpsetup.exe
2016-12-27 21:44 - 2016-12-27 21:46 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Apple Computer
2016-12-27 21:44 - 2016-12-27 21:44 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\Users\rubai\AppData\Local\Apple Computer
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\Users\rubai\AppData\Local\Apple
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\ProgramData\Apple Computer
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\Program Files\iTunes
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\Program Files\iPod
2016-12-27 21:44 - 2016-12-27 21:44 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-12-27 21:43 - 2016-12-27 21:44 - 00000000 ____D C:\ProgramData\Apple
2016-12-27 21:43 - 2016-12-27 21:44 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-12-27 21:43 - 2016-12-27 21:43 - 00000000 ____D C:\Program Files\Bonjour
2016-12-27 21:43 - 2016-12-27 21:43 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-12-27 21:42 - 2016-12-27 21:42 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-12-27 21:33 - 2016-12-27 21:42 - 177044296 _____ (Apple Inc.) C:\Users\rubai\Downloads\iTunes6464Setup.exe
2016-12-27 21:31 - 2016-12-27 21:31 - 00000000 ____D C:\Users\rubai\Documents\My Filehippo Downloads
2016-12-27 21:30 - 2016-12-27 21:30 - 00000000 ___HD C:\OneDriveTemp
2016-12-27 21:23 - 2016-12-27 21:23 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Innovative Solutions
2016-12-27 21:22 - 2016-12-27 21:22 - 00002870 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-12-27 21:22 - 2016-12-27 21:22 - 00000870 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-12-27 21:22 - 2016-12-27 21:22 - 00000000 ____D C:\Users\rubai\AppData\LocalLow\uTorrent
2016-12-27 21:22 - 2016-12-27 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-12-27 21:22 - 2016-12-27 21:22 - 00000000 ____D C:\Program Files\CCleaner
2016-12-27 21:21 - 2016-12-27 21:21 - 00002691 _____ C:\Users\rubai\Desktop\µTorrent.lnk
2016-12-27 21:19 - 2016-12-27 21:25 - 00000000 ____D C:\Users\rubai\AppData\Roaming\uTorrent
2016-12-27 21:19 - 2016-12-27 21:22 - 08803648 _____ (Piriform Ltd) C:\Users\rubai\Downloads\ccsetup525.exe
2016-12-27 21:19 - 2016-12-27 21:19 - 02237120 _____ (BitTorrent Inc.) C:\Users\rubai\Downloads\uTorrent.exe
2016-12-27 21:13 - 2016-12-06 15:17 - 00035488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2016-12-27 21:13 - 2016-12-06 15:16 - 00153392 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2016-12-27 21:13 - 2016-12-06 15:16 - 00151352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2016-12-27 21:13 - 2016-09-07 08:51 - 00040664 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tap0901.sys
2016-12-27 21:10 - 2016-12-27 21:26 - 00000376 _____ C:\Windows\Tasks\Health-Check-deep.job
2016-12-27 21:10 - 2016-12-27 21:26 - 00000368 _____ C:\Windows\Tasks\Health-Check.job
2016-12-27 21:10 - 2016-12-27 21:24 - 00004114 _____ C:\Windows\System32\Tasks\AupAvUpdate
2016-12-27 21:10 - 2016-12-27 21:24 - 00003828 _____ C:\Windows\System32\Tasks\UninstallMonitor
2016-12-27 21:10 - 2016-12-27 21:24 - 00000000 ____D C:\Program Files (x86)\Innovative Solutions
2016-12-27 21:10 - 2016-12-27 21:13 - 00000000 ____D C:\Users\rubai\AppData\Local\Innovative Solutions
2016-12-27 21:10 - 2016-12-27 21:13 - 00000000 ____D C:\ProgramData\Innovative Solutions
2016-12-27 21:10 - 2016-12-27 21:10 - 00003002 _____ C:\Windows\System32\Tasks\Health-Check-deep
2016-12-27 21:10 - 2016-12-27 21:10 - 00002984 _____ C:\Windows\System32\Tasks\Health-Check
2016-12-27 21:10 - 2016-12-27 21:10 - 00001721 _____ C:\Users\rubai\Desktop\Advanced Uninstaller PRO 12.lnk
2016-12-27 21:10 - 2016-12-27 21:10 - 00001605 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO 12.lnk
2016-12-27 21:10 - 2016-12-27 21:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO
2016-12-27 21:06 - 2016-12-27 21:06 - 10388528 _____ (Innovative Solutions ) C:\Users\rubai\Downloads\Advanced_Uninstaller12.exe
2016-12-27 21:04 - 2016-12-27 21:04 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Oracle
2016-12-27 21:00 - 2016-12-27 21:00 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-12-27 21:00 - 2016-12-27 21:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-12-27 21:00 - 2016-12-27 21:00 - 00000000 ____D C:\Program Files (x86)\Java
2016-12-27 20:28 - 2016-12-27 20:59 - 00737344 _____ (Oracle Corporation) C:\Users\rubai\Downloads\JavaSetup8u111.exe
2016-12-27 20:16 - 2016-12-28 00:26 - 00000000 ____D C:\Users\rubai\AppData\LocalLow\Mozilla
2016-12-27 20:16 - 2016-12-27 20:22 - 00000000 ____D C:\Users\rubai\AppData\Local\Mozilla
2016-12-27 20:16 - 2016-12-27 20:16 - 00001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-12-27 20:16 - 2016-12-27 20:16 - 00001223 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-12-27 20:16 - 2016-12-27 20:16 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Mozilla
2016-12-27 20:16 - 2016-12-27 20:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-27 20:16 - 2016-12-27 20:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-27 20:14 - 2016-12-27 21:01 - 00000000 ____D C:\ProgramData\Oracle
2016-12-27 20:14 - 2016-12-27 20:15 - 00243552 _____ C:\Users\rubai\Downloads\Firefox Setup Stub 50.1.0.exe
2016-12-27 20:14 - 2016-12-27 20:14 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Sun
2016-12-27 20:14 - 2016-12-27 20:14 - 00000000 ____D C:\Users\rubai\AppData\LocalLow\Sun
2016-12-27 20:11 - 2016-12-27 20:13 - 63235648 _____ (Oracle Corporation) C:\Users\rubai\Downloads\jre-8u111-windows-x64.exe
2016-12-27 20:06 - 2016-12-28 00:26 - 00000000 ____D C:\Users\rubai\AppData\Roaming\Skype
2016-12-27 20:06 - 2016-12-27 20:06 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2016-12-27 20:06 - 2016-12-27 20:06 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-12-27 20:06 - 2016-12-27 20:06 - 00000000 ____D C:\Users\rubai\Tracing
2016-12-27 20:06 - 2016-12-27 20:06 - 00000000 ____D C:\ProgramData\Skype
2016-12-27 20:06 - 2016-12-27 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-12-27 20:05 - 2016-12-27 20:05 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2016-12-27 20:04 - 2016-12-27 20:06 - 43878872 _____ (Skype Technologies S.A.) C:\Users\rubai\Downloads\SkypeSetupFull.exe
2016-12-27 20:03 - 2016-12-27 20:04 - 02190552 _____ C:\Users\rubai\Downloads\appmanagersetup_2.0_b4_292.exe
2016-12-27 20:03 - 2016-12-27 20:03 - 00001856 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-12-27 20:03 - 2016-12-27 20:03 - 00000000 ____D C:\Users\rubai\AppData\Roaming\SUPERAntiSpyware.com
2016-12-27 20:03 - 2016-12-27 20:03 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2016-12-27 20:03 - 2016-12-27 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2016-12-27 20:03 - 2016-12-27 20:03 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-12-27 20:01 - 2016-12-27 20:02 - 28761688 _____ (SUPERAntiSpyware) C:\Users\rubai\Downloads\SUPERAntiSpyware.exe
2016-12-27 20:00 - 2016-12-27 22:29 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2016-12-27 20:00 - 2016-12-27 20:00 - 00001155 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2016-12-27 20:00 - 2016-12-27 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2016-12-27 20:00 - 2012-05-02 12:17 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX
2016-12-27 20:00 - 2009-03-24 13:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL
2016-12-27 19:59 - 2016-12-27 20:00 - 04291320 _____ (BrightFort LLC ) C:\Users\rubai\Downloads\spywareblastersetup55.exe
2016-12-27 19:58 - 2016-12-28 00:48 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-12-27 19:58 - 2016-12-27 21:28 - 00102856 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2016-12-27 19:58 - 2016-12-27 21:28 - 00091584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2016-12-27 19:58 - 2016-12-27 21:28 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-12-27 19:58 - 2016-12-27 19:58 - 00176064 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2016-12-27 19:58 - 2016-12-27 19:58 - 00001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2016-12-27 19:58 - 2016-12-27 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2016-12-27 19:58 - 2016-12-27 19:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-12-27 19:58 - 2016-12-27 19:58 - 00000000 ____D C:\Program Files\Malwarebytes
2016-12-27 19:58 - 2016-12-14 12:55 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys
2016-12-27 19:56 - 2016-12-27 19:57 - 54199488 _____ (Malwarebytes ) C:\Users\rubai\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2016-12-27 19:22 - 2016-07-15 19:29 - 07702016 _____ (Microsoft Corporation) C:\Windows\system32\NL7Models0011.dll
2016-12-27 19:22 - 2016-07-15 19:29 - 02454528 _____ (Microsoft Corporation) C:\Windows\system32\NL7Lexicons0011.dll
2016-12-27 19:22 - 2016-07-15 19:25 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\MSWB70011.dll
2016-12-27 19:22 - 2016-07-15 19:24 - 07417344 _____ (Microsoft Corporation) C:\Windows\system32\NL7Data0011.dll
2016-12-27 19:22 - 2016-07-15 18:40 - 07253504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NL7Data0011.dll
2016-12-27 19:22 - 2016-07-15 18:40 - 00526848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWB70011.dll
2016-12-27 19:22 - 2016-05-25 14:39 - 00002060 _____ C:\Windows\system32\noise.jpn
2016-12-27 19:22 - 2016-05-25 11:10 - 00002060 _____ C:\Windows\SysWOW64\noise.jpn
2016-12-27 19:20 - 2016-07-15 19:29 - 01794048 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0045.dll
2016-12-27 19:20 - 2016-07-15 19:26 - 03054080 _____ (Microsoft Corporation) C:\Windows\system32\MLS1.dll
2016-12-27 19:20 - 2016-07-15 19:26 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0045.dll
2016-12-27 19:20 - 2016-07-15 18:45 - 01794048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsLexicons0045.dll
2016-12-27 19:20 - 2016-07-15 18:43 - 00132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsData0045.dll
2016-12-27 19:20 - 2016-07-15 18:39 - 03004416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MLS1.dll
2016-12-27 19:05 - 2016-12-27 17:14 - 00485032 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-12-27 18:42 - 2016-12-27 18:42 - 00002351 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-27 18:42 - 2016-12-27 18:42 - 00002339 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-27 18:31 - 2016-12-27 18:34 - 00000000 ____D C:\Windows\system32\MRT
2016-12-27 18:31 - 2016-12-27 18:31 - 135632432 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-12-27 18:26 - 2016-12-09 10:32 - 07816032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-12-27 18:26 - 2016-12-09 10:29 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
2016-12-27 18:26 - 2016-12-09 10:19 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-12-27 18:26 - 2016-12-09 10:18 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2016-12-27 18:26 - 2016-12-09 10:18 - 00989024 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2016-12-27 18:26 - 2016-12-09 10:18 - 00947552 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2016-12-27 18:26 - 2016-12-09 10:18 - 00811872 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2016-12-27 18:26 - 2016-12-09 10:15 - 08168000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-12-27 18:26 - 2016-12-09 10:15 - 01988560 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-12-27 18:26 - 2016-12-09 10:14 - 01274712 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-12-27 18:26 - 2016-12-09 10:01 - 02323728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-12-27 18:26 - 2016-12-09 10:01 - 01503544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2016-12-27 18:26 - 2016-12-09 09:57 - 01852720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2016-12-27 18:26 - 2016-12-09 09:52 - 01435896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2016-12-27 18:26 - 2016-12-09 09:51 - 00117240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-12-27 18:26 - 2016-12-09 09:41 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll
2016-12-27 18:26 - 2016-12-09 09:38 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2016-12-27 18:26 - 2016-12-09 09:37 - 00411136 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2016-12-27 18:26 - 2016-12-09 09:36 - 06285312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-12-27 18:26 - 2016-12-09 09:36 - 03059200 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-12-27 18:26 - 2016-12-09 09:36 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2016-12-27 18:26 - 2016-12-09 09:36 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-12-27 18:26 - 2016-12-09 09:33 - 03777536 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-12-27 18:26 - 2016-12-09 09:33 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2016-12-27 18:26 - 2016-12-09 09:31 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2016-12-27 18:26 - 2016-12-09 09:30 - 04612608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-12-27 18:26 - 2016-12-09 09:28 - 03306496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-12-27 18:26 - 2016-12-09 09:27 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2016-12-27 18:26 - 2016-12-09 09:26 - 01692672 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2016-12-27 18:26 - 2016-12-09 09:24 - 02275840 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-12-27 18:26 - 2016-12-09 09:22 - 02820096 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2016-12-27 18:26 - 2016-12-09 09:22 - 02688512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-12-27 18:26 - 2016-12-09 09:19 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2016-12-27 18:26 - 2016-12-09 09:19 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2016-12-27 18:26 - 2016-12-09 09:18 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2016-12-27 18:26 - 2016-12-09 09:16 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2016-12-27 18:26 - 2016-12-09 09:15 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-12-27 18:26 - 2016-12-09 09:15 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputLocaleManager.dll
2016-12-27 18:26 - 2016-12-09 09:15 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EditBufferTestHook.dll
2016-12-27 18:26 - 2016-11-11 10:15 - 00101216 _____ (Microsoft Corporation) C:\Windows\system32\DeviceReactivation.dll
2016-12-27 18:26 - 2016-11-11 10:14 - 00603488 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2016-12-27 18:26 - 2016-11-11 10:13 - 00352096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2016-12-27 18:26 - 2016-11-11 10:03 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2016-12-27 18:26 - 2016-11-11 10:02 - 00360040 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2016-12-27 18:26 - 2016-11-11 10:01 - 01859264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2016-12-27 18:26 - 2016-11-11 10:00 - 00219488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2016-12-27 18:26 - 2016-11-11 09:57 - 04130432 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-12-27 18:26 - 2016-11-11 09:57 - 01473048 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-12-27 18:26 - 2016-11-11 09:56 - 01062480 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-12-27 18:26 - 2016-11-11 09:56 - 00187520 _____ (Microsoft Corporation) C:\Windows\system32\CloudStorageWizard.exe
2016-12-27 18:26 - 2016-11-11 09:56 - 00126568 _____ (Microsoft Corporation) C:\Windows\system32\mfaudiocnv.dll
2016-12-27 18:26 - 2016-11-11 09:55 - 01600624 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-12-27 18:26 - 2016-11-11 09:55 - 00882680 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeManagerObj.dll
2016-12-27 18:26 - 2016-11-11 09:55 - 00743224 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-12-27 18:26 - 2016-11-11 09:51 - 00454592 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2016-12-27 18:26 - 2016-11-11 09:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\CbtBackgroundManagerPolicy.dll
2016-12-27 18:26 - 2016-11-11 09:27 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe
2016-12-27 18:26 - 2016-11-11 09:25 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2016-12-27 18:26 - 2016-11-11 09:25 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-12-27 18:26 - 2016-11-11 09:24 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll
2016-12-27 18:26 - 2016-11-11 09:24 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-12-27 18:26 - 2016-11-11 09:24 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll
2016-12-27 18:26 - 2016-11-11 09:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2016-12-27 18:26 - 2016-11-11 09:22 - 00211968 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2016-12-27 18:26 - 2016-11-11 09:21 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2016-12-27 18:26 - 2016-11-11 09:20 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2016-12-27 18:26 - 2016-11-11 09:20 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2016-12-27 18:26 - 2016-11-11 09:19 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2016-12-27 18:26 - 2016-11-11 09:16 - 01477632 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2016-12-27 18:26 - 2016-11-11 09:16 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2016-12-27 18:26 - 2016-11-11 09:14 - 02104320 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2016-12-27 18:26 - 2016-11-11 09:14 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-12-27 18:26 - 2016-11-11 09:13 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2016-12-27 18:26 - 2016-11-11 09:12 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll
2016-12-27 18:26 - 2016-11-11 09:11 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2016-12-27 18:26 - 2016-11-11 09:08 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2016-12-27 18:26 - 2016-11-11 09:07 - 00991232 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2016-12-27 18:26 - 2016-11-11 09:05 - 04136448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2016-12-27 18:26 - 2016-11-11 09:05 - 02852864 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-12-27 18:26 - 2016-11-11 09:05 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-12-27 18:26 - 2016-11-11 09:04 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2016-12-27 18:26 - 2016-11-11 09:03 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-12-27 18:26 - 2016-11-11 09:03 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-12-27 18:26 - 2016-11-11 09:02 - 03542016 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2016-12-27 18:26 - 2016-11-11 09:02 - 01726976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2016-12-27 18:26 - 2016-11-11 08:01 - 00167848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2016-12-27 18:26 - 2016-11-11 07:54 - 00122208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll
2016-12-27 18:26 - 2016-11-11 07:49 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2016-12-27 18:26 - 2016-11-11 07:48 - 02277248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2016-12-27 18:26 - 2016-11-11 07:47 - 05722832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-12-27 18:26 - 2016-11-11 07:47 - 00527880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2016-12-27 18:26 - 2016-11-11 07:42 - 03892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-12-27 18:26 - 2016-11-11 07:42 - 01123912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-12-27 18:26 - 2016-11-11 07:42 - 00952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-12-27 18:26 - 2016-11-11 07:42 - 00091936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfaudiocnv.dll
2016-12-27 18:26 - 2016-11-11 07:41 - 04311736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-12-27 18:26 - 2016-11-11 07:41 - 00157536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudStorageWizard.exe
2016-12-27 18:26 - 2016-11-11 07:38 - 01263856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-12-27 18:26 - 2016-11-11 07:25 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapsBtSvc.dll
2016-12-27 18:26 - 2016-11-11 07:25 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosStorage.dll
2016-12-27 18:26 - 2016-11-11 07:23 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2016-12-27 18:26 - 2016-11-11 07:22 - 00505856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2016-12-27 18:26 - 2016-11-11 07:21 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2016-12-27 18:26 - 2016-11-11 07:19 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2016-12-27 18:26 - 2016-11-11 07:18 - 02333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2016-12-27 18:26 - 2016-11-11 07:17 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2016-12-27 18:26 - 2016-11-11 07:15 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-12-27 18:26 - 2016-11-11 07:15 - 01357824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2016-12-27 18:26 - 2016-11-11 07:15 - 00838144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll
2016-12-27 18:26 - 2016-11-11 07:15 - 00348672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2016-12-27 18:26 - 2016-11-11 07:10 - 06109184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2016-12-27 18:26 - 2016-11-11 07:10 - 00746496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcprx.dll
2016-12-27 18:26 - 2016-11-11 07:09 - 05380608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2016-12-27 18:26 - 2016-11-11 07:09 - 00545280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2016-12-27 18:26 - 2016-11-11 07:08 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xolehlp.dll
2016-12-27 18:26 - 2016-11-11 07:06 - 02362880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll
2016-12-27 18:26 - 2016-11-11 07:06 - 02109952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapGeocoder.dll
2016-12-27 18:26 - 2016-11-11 07:06 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll
2016-12-27 18:26 - 2016-11-11 07:05 - 04423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-12-27 18:26 - 2016-11-11 07:05 - 03370496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2016-12-27 18:26 - 2016-11-11 07:04 - 01992704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2016-12-27 18:26 - 2016-11-11 07:04 - 00912896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2016-12-27 18:26 - 2016-11-11 07:04 - 00715264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll
2016-12-27 18:26 - 2016-11-11 07:03 - 02484736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2016-12-27 18:26 - 2016-11-11 07:03 - 01556480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2016-12-27 18:26 - 2016-11-11 07:03 - 00760832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NMAA.dll
2016-12-27 18:26 - 2016-11-11 07:02 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2016-12-27 18:26 - 2016-11-02 12:01 - 00315744 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-12-27 18:26 - 2016-11-02 11:22 - 00601712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2016-12-27 18:26 - 2016-11-02 11:09 - 02257104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-12-27 18:26 - 2016-11-02 11:05 - 00405856 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-12-27 18:26 - 2016-11-02 11:03 - 00714592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2016-12-27 18:26 - 2016-11-02 11:01 - 00545936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2016-12-27 18:26 - 2016-11-02 10:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsensorgroup.dll
2016-12-27 18:26 - 2016-11-02 10:43 - 00198144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FSClient.dll
2016-12-27 18:26 - 2016-11-02 10:42 - 00632832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sud.dll
2016-12-27 18:26 - 20