Jump to content

Random pop-ups in Chrome Win8


Recommended Posts

Hello Guys, 

 

I came here through a search for a solution to random pop-ups in my brand new laptop with Win8, google chrome.

 

Like yesterday first a random page opened and it seemed valid...today it happened again. Both of the pages are pretty well done. Unfortunatelly I have no screen, will make screen nextime if necessary.

 

The pup-ups came out of nowhere and I am sure I did not even click anything.

 

I started to use the new computer mainly cause my oldone with XP was infected. I use flashdisc to copy necessary data from one computer to another...maybe that caused the infection transfere - I used this flashdisc to install KasperskyAV on the new system. 

Ofcourse I run a scan right away but nothing was found.

 

Now I looked at this thread:

 

https://forums.malwarebytes.org/index.php?showtopic=124537

 

And am pretty scared what is in front of me.

 

The system is brand new, so not many applications are intalled and used only for several days.

 

PLEASE let me know how to procede in order to get rid of any possible infection.

 

Thank you

 

H. 

Link to post
Share on other sites

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 

 

 

 

 

Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)
 

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 

 

 

Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.

  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )

    [*]Leave everything else as it is. [*]Close all other running programs as well as your Browser. [*]Click the Scan button & wait for it to finish. [*]Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post. [*]Save it where you can easily find it, such as your desktop. [*]Please post the content of the ark.txt here.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Link to post
Share on other sites

Hello Psychotic,

 

I did what you asked for, below you can see the 3 outputs.

 

Note that I run gmer several times cause not all programs were shut down, though every time the scan stopped with error message: C_windows_system32_config_system and ntuser.dat files(can send screen of one of them if you ask for)  were inaccessible because of used by another process.

 

Logs too long to paste them. Sending as attachment.

ark.txtAddition.txtFRST_13-03-2014_00-33-20.txt

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2014

Ran by Martin (administrator) on HOLISTR on 13-03-2014 00:32:16

Running from C:\Users\Martin\Downloads

Windows 8.1 (X64) OS Language: English(US)

Internet Explorer Version 11

Boot Mode: Normal

 

The only official download link for FRST:

Download link for 32-Bit version:

Download link for 64-Bit Version:

Download link from any site other than Bleeping Computer is unpermitted or outdated.


 

==================== Processes (Whitelisted) =================

 

(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe

(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe

(Alipay Inc. ) C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe

(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe

(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe

(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe

(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe

(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe

(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe

(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe

(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe

(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe

(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe

(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe

(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe

(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe

(Microsoft Corporation) C:\Windows\System32\skydrive.exe

(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe

(Microsoft Corporation) C:\WINDOWS\system32\wwahost.exe

(Intel Corporation) C:\Windows\System32\igfxtray.exe

(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe

(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe

() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe

(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe

(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe

(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe

(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe

(Microsoft Corporation) C:\WINDOWS\system32\AUDIODG.EXE

(Microsoft Corporation) C:\WINDOWS\syswow64\wwahost.exe

(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe

(Microsoft Corporation) C:\Windows\System32\WWAHost.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE

 

 

==================== Registry (Whitelisted) ==================

 

HKLM\...\Run: [intelWirelessWiMAX] - C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [1626112 2012-07-26] (Intel® Corporation)

HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)

HKLM\...\Run: [smartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)

HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)

HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()

HKLM\...\Run: [LenovoOptMouseUpdate] - C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)

HKLM-x32\...\Run: [iMSS] - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [134616 2013-05-14] (Intel Corporation)

Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)

Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk

ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)

 

==================== Internet (Whitelisted) ====================

 

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/

BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)

BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)

BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)

BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)

BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)

BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)

BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)

Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

Tcpip\..\Interfaces\{71B995F2-8017-4977-9F48-9D894D207EBF}: [NameServer]8.8.8.8 8.8.4.4

 

Chrome: 

=======

CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-03]

CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-03]

CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-03]

CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-03]

CHR Extension: (Kaspersky URL Advisor) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-03-03]

CHR Extension: (Safe Money) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-03-03]

CHR Extension: (Dangerous Websites Blocker) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-03-03]

CHR Extension: (Virtuální klávesnice) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-03-03]

CHR Extension: (Peněženka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-03]

CHR Extension: (Evernote Web Clipper) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-03-11]

CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-03]

CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-11-26]

CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-11-26]

CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-11-26]

CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-11-26]

CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-11-26]

 

==================== Services (Whitelisted) =================

 

R2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [540032 2014-03-07] (Alipay Inc. )

R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-11-26] (Kaspersky Lab ZAO)

S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-11] (Intel® Corporation)

R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-14] (Intel Corporation)

R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-05-14] (Intel Corporation)

S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-29] ()

S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-03-12] (Microsoft Corporation)

S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-12] (Microsoft Corporation)

R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-29] (Intel® Corporation)

 

==================== Drivers (Whitelisted) ====================

 

S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)

S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows ® Win 7 DDK provider)

S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-31] (Intel Corporation)

S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-26] (Intel Corporation)

S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)

R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-03-12] (Microsoft Corporation)

R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-26] (Kaspersky Lab ZAO)

S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2013-11-26] (Kaspersky Lab)

S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-03-03] (Kaspersky Lab ZAO)

R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [624224 2014-03-03] (Kaspersky Lab ZAO)

R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-11-26] (Kaspersky Lab ZAO)

R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-03-03] (Kaspersky Lab ZAO)

R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-11-26] (Kaspersky Lab ZAO)

R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)

R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [64608 2013-11-26] (Kaspersky Lab ZAO)

R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2014-03-03] (Kaspersky Lab ZAO)

S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)

R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)

S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)

R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-09] (Intel Corporation)

S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)

S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-03-12] (Microsoft Corporation)

S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)

S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)

S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-03-12] (Microsoft Corporation)

 

==================== NetSvcs (Whitelisted) ===================

 

 

==================== One Month Created Files and Folders ========

 

2014-03-13 00:32 - 2014-03-13 00:32 - 00014956 _____ () C:\Users\Martin\Downloads\FRST.txt

2014-03-13 00:31 - 2014-03-13 00:32 - 00000000 ____D () C:\FRST

2014-03-13 00:27 - 2014-03-13 00:28 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Lenovo

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo

2014-03-13 00:11 - 2012-08-09 16:31 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\WINDOWS\SysWOW64\CSVer.dll

2014-03-13 00:07 - 2012-01-12 13:16 - 00002060 _____ () C:\WINDOWS\system32\Drivers\SamSfPa.dat

2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector

2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v2

2014-03-13 00:06 - 2012-06-08 17:07 - 00201376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe

2014-03-13 00:06 - 2011-01-07 12:28 - 00446592 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe

2014-03-13 00:05 - 2012-08-31 19:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEP64A.dll

2014-03-13 00:05 - 2012-08-31 19:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\EED64A.dll

2014-03-13 00:05 - 2012-08-31 19:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEL64A.dll

2014-03-13 00:05 - 2012-08-31 19:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEA64A.dll

2014-03-13 00:05 - 2012-08-31 19:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEG64A.dll

2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe

2014-03-12 22:55 - 2014-03-12 22:57 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files

2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package

2014-03-12 21:06 - 2014-03-13 00:16 - 00000000 __RDO () C:\Users\Martin\SkyDrive

2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery

2014-03-12 20:48 - 2014-03-12 15:00 - 00000000 ___DC () C:\WINDOWS\Panther

2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old

2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys

2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb

2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb

2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl

2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl

2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi

2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe

2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms

2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms

2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS

2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe

2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe

2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml

2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE

2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE

2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS

2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi

2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff

2014-03-12 16:22 - 2014-03-12 16:29 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip

2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini

2014-03-12 05:02 - 2014-03-13 00:14 - 00205213 _____ () C:\WINDOWS\WindowsUpdate.log

2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat

2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate

2014-03-12 04:54 - 2014-03-12 21:06 - 00000000 ____D () C:\Users\Martin

2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagwrn.xml

2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagerr.xml

2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility

2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

2014-03-12 04:51 - 2014-03-13 00:11 - 00000000 ____D () C:\Program Files (x86)\Intel

2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics

2014-03-12 04:51 - 2014-01-25 02:23 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL

2014-03-12 04:51 - 2014-01-25 02:23 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL

2014-03-12 04:50 - 2014-03-13 00:07 - 00000000 ____D () C:\Program Files\CONEXANT

2014-03-12 04:50 - 2014-03-12 04:55 - 00000000 ____D () C:\Program Files\Intel

2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay

2014-03-12 04:11 - 2014-03-12 05:01 - 00006530 _____ () C:\WINDOWS\comsetup.log

2014-03-12 01:05 - 2014-03-12 01:09 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe

2014-03-12 01:01 - 2014-03-12 01:25 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity

2014-03-12 00:52 - 2014-03-12 00:56 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip

2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay

2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe

2014-03-11 22:31 - 2014-03-12 01:14 - 00000000 ____D () C:\Program Files (x86)\Audacity

2014-03-11 22:22 - 2014-03-12 04:56 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit

2014-03-11 22:22 - 2014-03-11 22:37 - 00000000 ____D () C:\Program Files (x86)\alipay

2014-03-11 22:22 - 2014-03-11 22:25 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer

2014-03-09 20:09 - 2014-03-09 20:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player

2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player

2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe

2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf

2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf

2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant

2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl

2014-03-09 02:41 - 2014-03-12 23:56 - 00000000 ____D () C:\ProgramData\Conexant

2014-03-09 02:40 - 2012-09-20 14:11 - 01609376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\Drivers\CHDRT64.sys

2014-03-09 02:40 - 2012-09-12 11:35 - 02535520 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll

2014-03-09 02:40 - 2012-08-08 13:12 - 01780896 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64AP74.dll

2014-03-09 02:40 - 2012-06-29 13:04 - 00050848 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxPageMaster64.dll

2014-03-09 02:40 - 2012-03-20 03:48 - 00568960 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\UCI64A89.dll

2014-03-09 02:40 - 2012-01-16 10:42 - 00666240 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\C3DHPExt64.dll

2014-03-09 02:40 - 2011-01-18 11:35 - 00030893 _____ () C:\WINDOWS\system32\Drivers\Mixer.ini

2014-03-09 02:33 - 2014-03-09 02:39 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe

2014-03-09 01:48 - 2014-03-12 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype

2014-03-09 01:48 - 2014-03-09 14:35 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk

2014-03-09 01:48 - 2014-03-09 14:35 - 00000000 ____D () C:\ProgramData\Skype

2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype

2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype

2014-03-09 01:45 - 2014-03-09 01:47 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe

2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote

2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote

2014-03-06 21:10 - 2014-03-06 21:15 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe

2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log

2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk

2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent

2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent

2014-03-03 23:13 - 2014-03-12 22:56 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent

2014-03-03 23:13 - 2009-02-18 14:51 - 00018760 _____ () C:\WINDOWS\SysWOW64\QQVistaHelper.dll

2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk

2014-03-03 22:23 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll

2014-03-03 22:22 - 2014-03-13 00:15 - 00000000 ____D () C:\ProgramData\Kaspersky Lab

2014-03-03 22:22 - 2014-03-03 22:46 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys

2014-03-03 22:22 - 2014-03-03 22:45 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys

2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab

2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER

2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe

2014-03-03 22:05 - 2014-03-03 22:06 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip

2014-03-03 21:56 - 2014-03-13 00:16 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2014-03-03 21:56 - 2014-03-13 00:01 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk

2014-03-03 21:51 - 2014-03-03 22:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe

2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe

2014-03-03 21:45 - 2014-03-03 22:16 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe

2014-03-03 21:28 - 2014-03-03 22:12 - 00000000 ____D () C:\Program Files (x86)\Google

2014-03-03 21:28 - 2014-03-03 21:40 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google

2014-03-03 21:07 - 2014-03-03 21:53 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP

2014-03-03 20:06 - 2014-03-03 22:07 - 00000000 ____D () C:\totalcmd

2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER

2014-03-03 20:02 - 2014-03-03 20:03 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe

2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia

2014-03-03 19:36 - 2014-03-13 00:20 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-1001

2014-03-03 19:30 - 2014-03-12 22:57 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore

2014-03-03 19:30 - 2014-03-12 15:01 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages

2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel

2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe
Link to post
Share on other sites

 


==================== One Month Modified Files and Folders =======

 

2014-03-13 00:32 - 2014-03-13 00:32 - 00014956 _____ () C:\Users\Martin\Downloads\FRST.txt

2014-03-13 00:32 - 2014-03-13 00:31 - 00000000 ____D () C:\FRST

2014-03-13 00:28 - 2014-03-13 00:27 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe

2014-03-13 00:21 - 2013-11-14 15:28 - 00818732 _____ () C:\WINDOWS\system32\PerfStringBackup.INI

2014-03-13 00:20 - 2014-03-03 19:36 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-1001

2014-03-13 00:16 - 2014-03-12 21:06 - 00000000 __RDO () C:\Users\Martin\SkyDrive

2014-03-13 00:16 - 2014-03-03 21:56 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2014-03-13 00:15 - 2014-03-03 22:22 - 00000000 ____D () C:\ProgramData\Kaspersky Lab

2014-03-13 00:14 - 2014-03-12 05:02 - 00205213 _____ () C:\WINDOWS\WindowsUpdate.log

2014-03-13 00:14 - 2013-08-22 22:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT

2014-03-13 00:14 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Lenovo

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo

2014-03-13 00:11 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files (x86)\Intel

2014-03-13 00:07 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\CONEXANT

2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector

2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v2

2014-03-13 00:05 - 2013-08-22 22:46 - 00285001 _____ () C:\WINDOWS\setupact.log

2014-03-13 00:01 - 2014-03-03 21:56 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2014-03-13 00:00 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\sru

2014-03-12 23:57 - 2013-11-14 15:20 - 00004136 _____ () C:\WINDOWS\PFRO.log

2014-03-12 23:56 - 2014-03-09 02:41 - 00000000 ____D () C:\ProgramData\Conexant

2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe

2014-03-12 23:30 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\tracing

2014-03-12 22:57 - 2014-03-12 22:55 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files

2014-03-12 22:57 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore

2014-03-12 22:56 - 2014-03-03 23:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent

2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package

2014-03-12 21:06 - 2014-03-12 04:54 - 00000000 ____D () C:\Users\Martin

2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery

2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old

2014-03-12 20:47 - 2013-08-22 23:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template

2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys

2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb

2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb

2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl

2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl

2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi

2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll

2014-03-12 20:46 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\WinStore

2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe

2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms

2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ___RD () C:\WINDOWS\ToastData

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\MediaViewer

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\FileManager

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Camera

2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS

2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe

2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe

2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Windows Defender

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender

2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism

2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Dism

2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml

2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE

2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE

2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS

2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi

2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff

2014-03-12 16:29 - 2014-03-12 16:22 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip

2014-03-12 15:09 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\AppReadiness

2014-03-12 15:02 - 2013-11-14 16:08 - 00000000 ___HD () C:\$Windows.~BT

2014-03-12 15:01 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages

2014-03-12 15:00 - 2014-03-12 20:48 - 00000000 ___DC () C:\WINDOWS\Panther

2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini

2014-03-12 05:03 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\rescache

2014-03-12 05:02 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Registration

2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat

2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagwrn.xml

2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagerr.xml

2014-03-12 05:01 - 2014-03-12 04:11 - 00006530 _____ () C:\WINDOWS\comsetup.log

2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RSD () C:\WINDOWS\Media

2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RHD () C:\Users\Public\Libraries

2014-03-12 04:57 - 2013-08-22 22:44 - 00335784 _____ () C:\WINDOWS\system32\FNTCACHE.DAT

2014-03-12 04:56 - 2014-03-11 22:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit

2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN

2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep

2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\system32\WCN

2014-03-12 04:56 - 2013-08-22 23:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\spool

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\NDF

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\MUI

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\IME

2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI

2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep

2014-03-12 04:56 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM

2014-03-12 04:56 - 2012-07-26 13:37 - 00000000 ____D () C:\Users\Default.migrated

2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate

2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility

2014-03-12 04:55 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\Intel

2014-03-12 04:55 - 2013-12-05 04:55 - 00000000 ____D () C:\ProgramData\PRICache

2014-03-12 04:55 - 2013-08-22 23:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Help

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared

2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics

2014-03-12 04:51 - 2013-08-22 22:46 - 00000084 _____ () C:\WINDOWS\setuperr.log

2014-03-12 04:49 - 2013-08-22 21:36 - 00000000 __RHD () C:\Users\Default

2014-03-12 04:31 - 2013-12-05 05:07 - 01679981 _____ () C:\WINDOWS\WindowsUpdate (1).log

2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay

2014-03-12 04:30 - 2012-07-26 16:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent

2014-03-12 02:06 - 2013-12-05 05:00 - 00000000 ____D () C:\WINDOWS\SysWOW64\sda

2014-03-12 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype

2014-03-12 01:25 - 2014-03-12 01:01 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity

2014-03-12 01:14 - 2014-03-11 22:31 - 00000000 ____D () C:\Program Files (x86)\Audacity

2014-03-12 01:09 - 2014-03-12 01:05 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe

2014-03-12 00:56 - 2014-03-12 00:52 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip

2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay

2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe

2014-03-11 22:37 - 2014-03-11 22:22 - 00000000 ____D () C:\Program Files (x86)\alipay

2014-03-11 22:25 - 2014-03-11 22:22 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer

2014-03-09 20:13 - 2014-03-09 20:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player

2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player

2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe

2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf

2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf

2014-03-09 14:35 - 2014-03-09 01:48 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk

2014-03-09 14:35 - 2014-03-09 01:48 - 00000000 ____D () C:\ProgramData\Skype

2014-03-09 13:59 - 2013-12-05 05:01 - 00000000 ____D () C:\Intel

2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant

2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl

2014-03-09 02:39 - 2014-03-09 02:33 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe

2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype

2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype

2014-03-09 01:47 - 2014-03-09 01:45 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe

2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote

2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote

2014-03-06 21:15 - 2014-03-06 21:10 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe

2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log

2014-03-04 03:04 - 2014-01-07 03:35 - 00000000 ____D () C:\WINDOWS\system32\MRT

2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk

2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent

2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent

2014-03-03 22:46 - 2014-03-03 22:22 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys

2014-03-03 22:46 - 2013-11-26 04:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys

2014-03-03 22:46 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys

2014-03-03 22:45 - 2014-03-03 22:22 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys

2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk

2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab

2014-03-03 22:22 - 2012-07-26 16:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP

2014-03-03 22:16 - 2014-03-03 21:45 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe

2014-03-03 22:12 - 2014-03-03 21:28 - 00000000 ____D () C:\Program Files (x86)\Google

2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER

2014-03-03 22:08 - 2014-03-03 21:51 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe

2014-03-03 22:07 - 2014-03-03 20:06 - 00000000 ____D () C:\totalcmd

2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe

2014-03-03 22:06 - 2014-03-03 22:05 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip

2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2014-03-03 21:53 - 2014-03-03 21:07 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP

2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk

2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe

2014-03-03 21:40 - 2014-03-03 21:28 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google

2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER

2014-03-03 20:03 - 2014-03-03 20:02 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe

2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia

2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel

2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe

 

Some content of TEMP:

====================

C:\Users\Martin\AppData\Local\Temp\KUIU.EXE

C:\Users\Martin\AppData\Local\Temp\qqsafeud.exe

 

 

==================== Bamital & volsnap Check =================

 

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\rpcss.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys

[2014-03-12 20:43] - [2014-03-12 20:43] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02

 

 

 

LastRegBack: 2014-03-12 04:49

 

==================== End Of Log ============================

 

Addition

 

 


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2014

Ran by Martin at 2014-03-13 00:32:52

Running from C:\Users\Martin\Downloads

Boot Mode: Normal

==========================================================

 

 

==================== Security Center ========================

 

AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

 

==================== Installed Programs ======================

 

Alipay security control 3.7.0.0 (x32 Version: 3.7.0.0 - Alipay.com Co., Ltd.) Hidden

AlipayDHC 1.1.0.0 (x32 Version: 1.1.0.0 - Alipay.com Co., Ltd.) Hidden

Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)

Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.48.0 - Conexant)

Crystal Player Professional 1.99 (HKLM-x32\...\Crystal Player) (Version: Professional 1.99 - Crystal Reality LLC)

Evernote v. 5.2 (HKLM-x32\...\{090931D6-A2F4-11E3-AD9C-00163E98E7D0}) (Version: 5.2.0.2946 - Evernote Corp.)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.)

Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden

Intel PROSet Wireless (Version:  - ) Hidden

Intel® Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36702 - Intel Corporation)

Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)

Intel® PRO/Wireless Driver (Version: 16.01.5000.0577 - Intel Corporation) Hidden

Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3412 - Intel Corporation)

Intel® PROSet/Wireless for Bluetooth® + High Speed (Version: 15.6.1.0536 - Intel Corporation) Hidden

Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)

Intel® PROSet/Wireless Software (HKLM-x32\...\{fad118b4-798f-4755-9e67-a622eec95b62}) (Version: 15.6.1 - Intel Corporation)

Intel® PROSet/Wireless WiFi Software (Version: 16.01.5000.0269 - Intel Corporation) Hidden

Intel® PROSet/Wireless WiMAX Software (HKLM\...\{5F588B19-C575-4750-86FD-6ED2B76E61F1}) (Version: 7.50.0000 - Intel Corporation)

Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) Hidden

Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)

Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden

Lenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)

Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)

Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.03.13 - )

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Ö§¸¶±¦°²È«¿Ø¼þ 3.22.0.0 (HKLM-x32\...\alieditplus) (Version: 3.22.0.0 - Alipay.com Co., Ltd.)

On Screen Display (HKLM\...\OnScreenDisplay) (Version: 7.09.00 - )

QQ International (HKLM-x32\...\{3CA54984-A14B-42FE-9FF1-7EA90151D725}) (Version: 1.91.1213.0 - 腾讯科技(深圳)有限公司)

Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29011 - Realtek Semiconductor Corp.)

Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)

ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - )

Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.50 - Ghisler Software GmbH)

 

==================== Restore Points  =========================

 

 

==================== Hosts content: ==========================

 

2013-08-22 21:25 - 2013-08-22 21:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

 

==================== Scheduled Tasks (whitelisted) =============

 

Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask

Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask

Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList

Task: {1F7AC4AB-170E-4FC4-8396-FAE75D46C284} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-15] (Intel Corporation)

Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask

Task: {2147C864-8D13-4AB9-9B87-CD4FBD731E84} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-04-24] (Synaptics Incorporated)

Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate

Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)

Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)

Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance

Task: {518B38DA-D07B-4E9E-A7AB-9FC0651CC346} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-03] (Google Inc.)

Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup

Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task

Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask

Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState

Task: {7A310B90-6F4B-4A9E-9745-2D7A89982220} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-15] (Intel Corporation)

Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task

Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask

Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work

Task: {B71EC85F-C04F-42B8-A2DA-C6CB4479EE97} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-03] (Google Inc.)

Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask

Task: {D62EB2BA-1E86-4981-969B-B7D2C525A1EF} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2013-08-22] (Microsoft Corporation)

Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing

Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization

Task: {E1D199D3-5710-4B4D-8655-6781E06824C8} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2012-08-31] (Dolby Laboratories Inc.)

Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

 

==================== Loaded Modules (whitelisted) =============

 

2013-11-14 15:18 - 2013-11-14 15:18 - 00012728 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\Microsoft.PerfTrack.winmd

2014-03-12 15:10 - 2014-03-12 15:10 - 00363520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\8d0f16d53c303f545bdc3bdeeb2a7fb3\Windows.Foundation.ni.dll

2014-03-12 15:10 - 2014-03-12 15:10 - 00347136 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\ed3886aaf7efc3feec0169cf9014cb11\Windows.Globalization.ni.dll

2014-03-12 15:10 - 2014-03-12 15:10 - 01782272 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\8848363a64856b740e9ebd321b6a98ca\Windows.ApplicationModel.ni.dll

2014-03-12 15:10 - 2014-03-12 15:10 - 00207872 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.System\67df9eac656929e232d804428e224a7d\Windows.System.ni.dll

2014-03-12 15:11 - 2014-03-12 15:11 - 01278464 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Storage\29e4b2d8f87a111865c3302f567b4a82\Windows.Storage.ni.dll

2014-03-12 15:11 - 2014-03-12 15:11 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\3363e49b745a5ddf1aaf80b18c175191\Windows.UI.ni.dll

2014-03-12 15:10 - 2014-03-12 15:10 - 01259520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Networking\5d30480aa910c28c2571439d412f3b53\Windows.Networking.ni.dll

2013-11-14 15:18 - 2013-11-14 15:18 - 00016312 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\SqliteWrapper.winmd

2013-11-14 15:18 - 2013-11-14 15:18 - 00485816 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\SqliteWrapper.dll

2013-11-14 15:18 - 2013-11-14 15:18 - 00660920 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\Sqlite3.dll

2014-03-12 15:10 - 2014-03-12 15:10 - 00467456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Graphics\fb496048d93b67e96961f34a0955f3d8\Windows.Graphics.ni.dll

2013-08-22 15:19 - 2013-08-22 14:54 - 00093696 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Web.winmd

2014-03-12 15:11 - 2014-03-12 15:11 - 00632320 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Security\b4178c95c7aafade0fcdb76b09bd2973\Windows.Security.ni.dll

2013-08-22 15:19 - 2013-08-22 14:54 - 00050176 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Data.winmd

2013-11-14 15:18 - 2013-11-14 15:18 - 00246168 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\Microsoft.WindowsAzure.Messaging.Managed.DLL

2014-03-12 15:11 - 2014-03-12 15:11 - 02019840 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Devices\690b3f44ab1db69bc7ba1e4ceee9b89f\Windows.Devices.ni.dll

2014-01-25 02:22 - 2014-01-25 02:22 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll

2014-03-13 00:07 - 2010-10-26 12:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe

2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll

2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll

2014-02-24 16:56 - 2014-02-24 16:56 - 00433664 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll

2014-02-24 16:56 - 2014-02-24 16:56 - 00315392 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll

2013-12-05 05:01 - 2013-05-14 07:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll

2014-03-09 01:31 - 2014-03-02 10:35 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll

2014-03-09 01:31 - 2014-03-02 10:35 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libglesv2.dll

2014-03-09 01:31 - 2014-03-02 10:35 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libegl.dll

2014-03-09 01:31 - 2014-03-02 10:35 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll

2014-03-09 01:31 - 2014-03-02 10:35 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll

2014-03-09 01:31 - 2014-03-02 10:35 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll

 

==================== Alternate Data Streams (whitelisted) =========

 

AlternateDataStreams: C:\Users\Martin\SkyDrive:ms-properties

 

==================== Safe Mode (whitelisted) ===================

 

 

==================== Disabled items from MSCONFIG ==============

 

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (03/12/2014 11:55:52 PM) (Source: Application Error) (User: )

Description: Faulting application name: CAudioFilterAgent64.exe, version: 1.7.40.0, time stamp: 0x4fd99b06

Faulting module name: CAudioFilterAgent64.exe, version: 1.7.40.0, time stamp: 0x4fd99b06

Exception code: 0xc0000005

Fault offset: 0x000000000008bd28

Faulting process id: 0x1294

Faulting application start time: 0xCAudioFilterAgent64.exe0

Faulting application path: CAudioFilterAgent64.exe1

Faulting module path: CAudioFilterAgent64.exe2

Report Id: CAudioFilterAgent64.exe3

Faulting package full name: CAudioFilterAgent64.exe4

Faulting package-relative application ID: CAudioFilterAgent64.exe5

 

Error: (03/12/2014 04:33:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: HOLISTR)

Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147023174 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (03/12/2014 04:15:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: HOLISTR)

Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147023174 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)

Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelQosEvent" whose target class "CIntelQosEvent" in //./ROOT/default namespace does not exist. The query will be ignored.

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)

Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelDot1xEvent" whose target class "CIntelDot1xEvent" in //./ROOT/default namespace does not exist. The query will be ignored.

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)

Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelWLANEvent" whose target class "CIntelWLANEvent" in //./ROOT/default namespace does not exist. The query will be ignored.

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)

Description: Event provider  attempted to register query "select * from CIntelQosEvent" whose target class "CIntelQosEvent" in //./ROOT/default namespace does not exist. The query will be ignored.

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)

Description: Event provider  attempted to register query "select * from CIntelDot1xEvent" whose target class "CIntelDot1xEvent" in //./ROOT/default namespace does not exist. The query will be ignored.

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)

Description: Event provider  attempted to register query "select * from CIntelWLANEvent" whose target class "CIntelWLANEvent" in //./ROOT/default namespace does not exist. The query will be ignored.

 

Error: (03/11/2014 02:02:41 AM) (Source: Application Error) (User: )

Description: Faulting application name: LiveComm.exe, version: 16.4.4206.722, time stamp: 0x500ca1a7

Faulting module name: ntdll.dll, version: 6.2.9200.16579, time stamp: 0x51637f77

Exception code: 0xc0000005

Fault offset: 0x000000000005ab00

Faulting process id: 0x46c

Faulting application start time: 0xLiveComm.exe0

Faulting application path: LiveComm.exe1

Faulting module path: LiveComm.exe2

Report Id: LiveComm.exe3

Faulting package full name: LiveComm.exe4

Faulting package-relative application ID: LiveComm.exe5

 

 

System errors:

=============

Error: (03/13/2014 00:14:50 AM) (Source: BTHUSB) (User: )

Description: The local adapter does not support an important Low Energy controller state.  The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff.  Low Energy functionality will be disabled.

 

Error: (03/13/2014 00:14:23 AM) (Source: Service Control Manager) (User: )

Description: The Superfetch service terminated with the following error: 

%%1062

 

Error: (03/13/2014 00:07:51 AM) (Source: BTHUSB) (User: )

Description: The local adapter does not support an important Low Energy controller state.  The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff.  Low Energy functionality will be disabled.

 

Error: (03/12/2014 11:57:31 PM) (Source: BTHUSB) (User: )

Description: The local adapter does not support an important Low Energy controller state.  The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff.  Low Energy functionality will be disabled.

 

Error: (03/12/2014 09:04:15 PM) (Source: Service Control Manager) (User: )

Description: The Print Spooler service terminated with the following error: 

%%2147944140

 

Error: (03/12/2014 09:04:05 PM) (Source: NetBT) (User: )

Description: Initialization failed because the transport refused to open initial addresses.

 

Error: (03/12/2014 09:03:41 PM) (Source: BTHUSB) (User: )

Description: The local adapter does not support an important Low Energy controller state.  The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff.  Low Energy functionality will be disabled.

 

Error: (03/12/2014 03:34:40 PM) (Source: DCOM) (User: NT AUTHORITY)

Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

 

Error: (03/12/2014 05:02:02 AM) (Source: NETLOGON) (User: )

Description: This computer is configured as a member of a workgroup, not as

a member of a domain. The Netlogon service does not need to run in this

configuration.

 

Error: (03/12/2014 04:59:04 AM) (Source: Service Control Manager) (User: )

Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error: 

%%2147770990

 

 

Microsoft Office Sessions:

=========================

Error: (03/12/2014 11:55:52 PM) (Source: Application Error)(User: )

Description: CAudioFilterAgent64.exe1.7.40.04fd99b06CAudioFilterAgent64.exe1.7.40.04fd99b06c0000005000000000008bd28129401cf3df3df66b6a4C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exeC:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exec93ff56d-a9fe-11e3-be76-6036dd6349a2

 

Error: (03/12/2014 04:33:28 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: HOLISTR)

Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147023174

 

Error: (03/12/2014 04:15:10 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: HOLISTR)

Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147023174

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)

Description: IntelWLANEventProviderselect * from CIntelQosEventCIntelQosEvent//./ROOT/default

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)

Description: IntelWLANEventProviderselect * from CIntelDot1xEventCIntelDot1xEvent//./ROOT/default

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)

Description: IntelWLANEventProviderselect * from CIntelWLANEventCIntelWLANEvent//./ROOT/default

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)

Description: select * from CIntelQosEventCIntelQosEvent//./ROOT/default

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)

Description: select * from CIntelDot1xEventCIntelDot1xEvent//./ROOT/default

 

Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)

Description: select * from CIntelWLANEventCIntelWLANEvent//./ROOT/default

 

Error: (03/11/2014 02:02:41 AM) (Source: Application Error)(User: )

Description: LiveComm.exe16.4.4206.722500ca1a7ntdll.dll6.2.9200.1657951637f77c0000005000000000005ab0046c01cf3c83cd376da0C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exeC:\Windows\SYSTEM32\ntdll.dll2bd3670b-a87e-11e3-be75-6036dd6349a2microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbweMicrosoft.WindowsLive.Mail

 

 

 


Those are FIRST utility logs.

 

Link to post
Share on other sites

GMER 2.1.19357 - http://www.gmer.net

Rootkit scan 2014-03-13 00:40:13

Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\0000002e TOSHIBA_MK5061GSY rev.MC102E 465.76GB

Running: gvo4tdpt.exe; Driver: C:\Users\Martin\AppData\Local\Temp\kgddipod.sys

 

 

---- Threads - GMER 2.1 ----

 

Thread   C:\WINDOWS\system32\csrss.exe [600:3492]                                                                                                                                                                                                                          fffff960008ba4d0

---- Processes - GMER 2.1 ----

 

Library  c:\programdata\kaspersky lab\avp14.0.0\data\wlengine.dll (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                                                           0000000071b50000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\uds.dll.7d02d20a9bb6867c09459f116feac15d (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                        0000000071af0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\avengine.dll.415c3b227a91a9693ad5a51f07dbba9c (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                   0000000071a60000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\kavbase.kdl.361acbb95e4cd361dbc67699794434a5 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                    00000000719d0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\klavemu.kdl.593e72e97caef5dd742b394bd296e21a (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                    0000000071370000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\kjim.kdl.bccfc1c89017f4bdc90201e956eea7c5 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                       00000000710c0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\mark.kdl.1c449ad92726ed14d895f09dcd861545 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                       0000000071050000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\vlns.kdl.317df7c0eff0939e6289f5c72f65ba51 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                       0000000038200000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\qscan.kdl.3d47406245e32365413c5b6ab2246586 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                      0000000070f30000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\pbs.kdl.41dc267440bc79cb8c2216bd28f1f254 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                        0000000070da0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\metascan.kdl.14a21353e2a9e2e50d0dfb513315a104 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                   0000000070af0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\kavsys.kdl.ec4d28bde98d9e3c76bf58ef5ba0728d (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                     0000000070810000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\arkmon.kdl.b3a9361231847f8f76294be7a6a1406a (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                     00000000707f0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\swmon.kdl.f77eca979387a121bcc982e5ad84c0fb (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                      000000006f9e0000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\swmon_drv.kdl.f6a00390b7c91892a6168d415f56d96c (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                  000000006f950000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\bsshlp2.kdl.904c718bbe32f92d8d0c4c679ec8a7ac (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                    000000006f800000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\heurap.dll.443a9903a4015ce41f2c859208d4e4b6 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                     0000000063400000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\pdm.kdl.3e8b21cf357ecefe6529658c1ae62636 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                        0000000063370000

Library  C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\sys_critical_obj.dll (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND)                                                                  0000000063310000

Library  C:\Program Files\WindowsApps\Microsoft.SkypeApp_2.0.0.5011_x86__kzf8qxf38zg5c\LibWrap.dll (*** suspicious ***) @ C:\WINDOWS\syswow64\wwahost.exe [5176] (Microsoft Skype/Microsoft Corporation)(2013-11-14 07:19:09)                                              0000000064e50000

Library  C:\Program Files\WindowsApps\Microsoft.SkypeApp_2.0.0.5011_x86__kzf8qxf38zg5c\Microsoft.PerfTrack.dll (*** suspicious ***) @ C:\WINDOWS\syswow64\wwahost.exe [5176] (Microsoft.PerfTrack.dll/Microsoft Corporation)(2013-11-14 07:19:09)                          000000006b620000

Library  C:\Program Files\WindowsApps\Microsoft.SkypeApp_2.0.0.5011_x86__kzf8qxf38zg5c\MicrosoftAdvertising.dll (*** suspicious ***) @ C:\WINDOWS\syswow64\wwahost.exe [5176] (Microsoft Advertising Native SDK for Windows 8/Microsoft Corporation)(2013-11-14 07:19:09)  0000000064250000

 

---- Disk sectors - GMER 2.1 ----

 

Disk     \Device\Harddisk0\DR0                                                                                                                                                                                                                                             unknown MBR code

 

---- EOF - GMER 2.1 ----

 

 

Note: Since today started to occur strange behavior of my browser...I am not sure if it is caused by the virus or simply by running programs, though the browser seems to hang for a 5-10 seconds from time to time.
Link to post
Share on other sites

Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe



When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.

Link to post
Share on other sites

I´m sorry!

 

Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

Link to post
Share on other sites

Hello Psychotic,

 

It is the same program I have been using in the first step. Sent you the files in one of my posts before. But sure I will do another scan. Anything to help me get rid of that infection.

 

Considering FRST was already run once the addition.txt was not created and I can only send you the previous one.

Here you have the FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2014
Ran by Martin (administrator) on HOLISTR on 14-03-2014 16:47:04
Running from C:\Users\Martin\Downloads
Windows 8.1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link for 32-Bit version:
Download link for 64-Bit Version:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Alipay Inc. ) C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Picasa3\Picasa3.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\POWERPNT.EXE
(Microsoft Corporation) C:\WINDOWS\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\MSTORDB.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\wwahost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\LiveComm.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\AUDIODG.EXE
 
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [intelWirelessWiMAX] - C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [1626112 2012-07-26] (Intel® Corporation)
HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM\...\Run: [smartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [LenovoOptMouseUpdate] - C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)
HKLM-x32\...\Run: [iMSS] - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [134616 2013-05-14] (Intel Corporation)
HKLM-x32\...\Run: [RotateImage] - C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [64000 2012-08-10] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 61.128.128.68 61.128.192.68
Tcpip\..\Interfaces\{71B995F2-8017-4977-9F48-9D894D207EBF}: [NameServer]8.8.8.8 8.8.4.4
 
Chrome: 
=======
CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-03]
CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-03]
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-03]
CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-03]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-03-03]
CHR Extension: (Safe Money) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-03-03]
CHR Extension: (Dangerous Websites Blocker) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-03-03]
CHR Extension: (Virtuální klávesnice) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-03-03]
CHR Extension: (Peněženka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-03]
CHR Extension: (Evernote Web Clipper) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-03-11]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-03]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-11-26]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-11-26]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-11-26]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-11-26]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-11-26]
 
==================== Services (Whitelisted) =================
 
R2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [540032 2014-03-07] (Alipay Inc. )
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-11-26] (Kaspersky Lab ZAO)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-11] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-14] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-05-14] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-29] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-03-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-12] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-29] (Intel® Corporation)
 
==================== Drivers (Whitelisted) ====================
 
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows ® Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-31] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-26] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-03-12] (Microsoft Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-26] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2013-11-26] (Kaspersky Lab)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-03-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [624224 2014-03-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-11-26] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-03-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-11-26] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [64608 2013-11-26] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2014-03-03] (Kaspersky Lab ZAO)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-09] (Intel Corporation)
R3 RCUVCAVS; C:\Windows\system32\DRIVERS\RCUVCAVS.sys [148352 2012-08-23] (Ricoh co.,Ltd.)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-03-12] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-03-12] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2014-03-14 16:20 - 2014-03-14 16:20 - 00122480 _____ () C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-14 15:24 - 2014-03-14 15:25 - 17529160 _____ (Google Inc.) C:\Users\Martin\Downloads\picasa39-setup.exe
2014-03-14 01:04 - 2014-03-14 01:05 - 05190279 _____ (Swearware) C:\Users\Martin\Downloads\ComboFix.exe
2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2014-03-14 00:00 - 2014-03-14 00:00 - 00000000 ____D () C:\WINDOWS\PCHEALTH
2014-03-13 23:59 - 2014-03-13 23:59 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-13 23:58 - 2014-03-14 00:02 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-13 23:58 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 __RHD () C:\MSOCache
2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft Help
2014-03-13 02:48 - 2014-03-13 02:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft_Corporation
2014-03-13 02:34 - 2014-03-13 02:34 - 00000000 ____D () C:\Program Files (x86)\ffdshow
2014-03-13 02:34 - 2010-01-27 00:08 - 00085504 _____ () C:\WINDOWS\SysWOW64\ff_vfw.dll
2014-03-13 02:33 - 2014-03-13 02:33 - 00000000 ____D () C:\ProgramData\APN
2014-03-13 02:29 - 2014-03-13 02:29 - 02030080 _____ () C:\Users\Martin\Downloads\ffdshow-20041012.exe
2014-03-13 02:28 - 2014-03-13 02:28 - 00389440 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_for_ffdshow.exe
2014-03-13 01:15 - 2014-03-13 01:15 - 00000000 ____D () C:\Program Files (x86)\Integrated Camera Driver
2014-03-13 01:14 - 2012-08-23 11:09 - 00148352 _____ (Ricoh co.,Ltd.) C:\WINDOWS\system32\Drivers\RCUVCAVS.sys
2014-03-13 01:14 - 2012-08-23 08:56 - 00304640 _____ (Ricoh co.,Ltd.) C:\WINDOWS\system32\RCUVCAVS.ax
2014-03-13 01:14 - 2012-08-23 08:56 - 00269824 _____ (Ricoh co.,Ltd.) C:\WINDOWS\SysWOW64\RCUVCAVS.ax
2014-03-13 01:14 - 2012-08-23 08:55 - 00119808 _____ (Ricoh co.,Ltd.) C:\WINDOWS\system32\RCUVCAVS.dll
2014-03-13 01:14 - 2012-08-23 08:55 - 00100864 _____ (Ricoh co.,Ltd.) C:\WINDOWS\SysWOW64\RCUVCAVS.dll
2014-03-13 00:42 - 2014-03-13 00:42 - 00017920 ___SH () C:\Users\Martin\Desktop\Thumbs.db
2014-03-13 00:40 - 2014-03-13 00:40 - 00007232 _____ () C:\Users\Martin\Desktop\ark.txt
2014-03-13 00:32 - 2014-03-14 16:47 - 00016253 _____ () C:\Users\Martin\Downloads\FRST.txt
2014-03-13 00:32 - 2014-03-13 00:33 - 00023288 _____ () C:\Users\Martin\Downloads\Addition.txt
2014-03-13 00:31 - 2014-03-14 16:47 - 00000000 ____D () C:\FRST
2014-03-13 00:27 - 2014-03-13 00:28 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe
2014-03-13 00:13 - 2014-03-13 01:14 - 00000000 ____D () C:\Program Files\Lenovo
2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo
2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2014-03-13 00:11 - 2012-08-09 16:31 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\WINDOWS\SysWOW64\CSVer.dll
2014-03-13 00:07 - 2012-01-12 13:16 - 00002060 _____ () C:\WINDOWS\system32\Drivers\SamSfPa.dat
2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector
2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v2
2014-03-13 00:06 - 2012-06-08 17:07 - 00201376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
2014-03-13 00:06 - 2011-01-07 12:28 - 00446592 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe
2014-03-13 00:05 - 2012-08-31 19:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEP64A.dll
2014-03-13 00:05 - 2012-08-31 19:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\EED64A.dll
2014-03-13 00:05 - 2012-08-31 19:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEL64A.dll
2014-03-13 00:05 - 2012-08-31 19:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEA64A.dll
2014-03-13 00:05 - 2012-08-31 19:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEG64A.dll
2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe
2014-03-12 22:55 - 2014-03-13 22:36 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files
2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package
2014-03-12 21:06 - 2014-03-13 22:32 - 00000000 __RDO () C:\Users\Martin\SkyDrive
2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery
2014-03-12 20:48 - 2014-03-12 15:00 - 00000000 ___DC () C:\WINDOWS\Panther
2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old
2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms
2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms
2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys
2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll
2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys
2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll
2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-03-12 16:22 - 2014-03-12 16:29 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip
2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini
2014-03-12 05:02 - 2014-03-14 15:59 - 01748233 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat
2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
2014-03-12 04:54 - 2014-03-12 21:06 - 00000000 ____D () C:\Users\Martin
2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagwrn.xml
2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagerr.xml
2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-12 04:51 - 2014-03-13 00:11 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job
2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics
2014-03-12 04:51 - 2014-01-25 02:23 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2014-03-12 04:51 - 2014-01-25 02:23 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2014-03-12 04:50 - 2014-03-13 00:07 - 00000000 ____D () C:\Program Files\CONEXANT
2014-03-12 04:50 - 2014-03-12 04:55 - 00000000 ____D () C:\Program Files\Intel
2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay
2014-03-12 04:11 - 2014-03-12 05:01 - 00006530 _____ () C:\WINDOWS\comsetup.log
2014-03-12 04:07 - 2014-03-12 04:07 - 04550656 _____ (Google Inc.) C:\WINDOWS\SysWOW64\GPhotos.scr
2014-03-12 01:05 - 2014-03-12 01:09 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe
2014-03-12 01:01 - 2014-03-12 01:25 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity
2014-03-12 00:52 - 2014-03-12 00:56 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip
2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay
2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe
2014-03-11 22:31 - 2014-03-12 01:14 - 00000000 ____D () C:\Program Files (x86)\Audacity
2014-03-11 22:22 - 2014-03-12 04:56 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit
2014-03-11 22:22 - 2014-03-11 22:37 - 00000000 ____D () C:\Program Files (x86)\alipay
2014-03-11 22:22 - 2014-03-11 22:25 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer
2014-03-09 20:09 - 2014-03-09 20:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player
2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player
2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe
2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant
2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-03-09 02:41 - 2014-03-12 23:56 - 00000000 ____D () C:\ProgramData\Conexant
2014-03-09 02:40 - 2012-09-20 14:11 - 01609376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\Drivers\CHDRT64.sys
2014-03-09 02:40 - 2012-09-12 11:35 - 02535520 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
2014-03-09 02:40 - 2012-08-08 13:12 - 01780896 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64AP74.dll
2014-03-09 02:40 - 2012-06-29 13:04 - 00050848 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxPageMaster64.dll
2014-03-09 02:40 - 2012-03-20 03:48 - 00568960 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\UCI64A89.dll
2014-03-09 02:40 - 2012-01-16 10:42 - 00666240 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\C3DHPExt64.dll
2014-03-09 02:40 - 2011-01-18 11:35 - 00030893 _____ () C:\WINDOWS\system32\Drivers\Mixer.ini
2014-03-09 02:33 - 2014-03-09 02:39 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe
2014-03-09 01:48 - 2014-03-14 16:45 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype
2014-03-09 01:48 - 2014-03-09 14:35 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-09 01:48 - 2014-03-09 14:35 - 00000000 ____D () C:\ProgramData\Skype
2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype
2014-03-09 01:45 - 2014-03-09 01:47 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe
2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote
2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-03-06 21:10 - 2014-03-06 21:15 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe
2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log
2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk
2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent
2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent
2014-03-03 23:13 - 2014-03-12 22:56 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent
2014-03-03 23:13 - 2009-02-18 14:51 - 00018760 _____ () C:\WINDOWS\SysWOW64\QQVistaHelper.dll
2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk
2014-03-03 22:23 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2014-03-03 22:22 - 2014-03-14 07:18 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-03 22:22 - 2014-03-03 22:46 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2014-03-03 22:22 - 2014-03-03 22:45 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys
2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER
2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe
2014-03-03 22:05 - 2014-03-03 22:06 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip
2014-03-03 21:56 - 2014-03-14 16:01 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-03 21:56 - 2014-03-13 22:32 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk
2014-03-03 21:51 - 2014-03-03 22:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe
2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe
2014-03-03 21:45 - 2014-03-03 22:16 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe
2014-03-03 21:28 - 2014-03-14 15:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google
2014-03-03 21:28 - 2014-03-14 15:29 - 00000000 ____D () C:\Program Files (x86)\Google
2014-03-03 21:07 - 2014-03-03 21:53 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP
2014-03-03 20:06 - 2014-03-03 22:07 - 00000000 ____D () C:\totalcmd
2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER
2014-03-03 20:02 - 2014-03-03 20:03 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe
2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia
2014-03-03 19:36 - 2014-03-14 15:34 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-1001
2014-03-03 19:30 - 2014-03-12 22:57 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore
2014-03-03 19:30 - 2014-03-12 15:01 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages
2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel
2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe
 
Continues in next post
Link to post
Share on other sites

==================== One Month Modified Files and Folders =======

 

2014-03-14 16:47 - 2014-03-13 00:32 - 00016253 _____ () C:\Users\Martin\Downloads\FRST.txt

2014-03-14 16:47 - 2014-03-13 00:31 - 00000000 ____D () C:\FRST

2014-03-14 16:45 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype

2014-03-14 16:20 - 2014-03-14 16:20 - 00122480 _____ () C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT

2014-03-14 16:16 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\tracing

2014-03-14 16:01 - 2014-03-03 21:56 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2014-03-14 16:00 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\sru

2014-03-14 15:59 - 2014-03-12 05:02 - 01748233 _____ () C:\WINDOWS\WindowsUpdate.log

2014-03-14 15:34 - 2014-03-03 19:36 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-1001

2014-03-14 15:30 - 2014-03-03 21:28 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google

2014-03-14 15:29 - 2014-03-03 21:28 - 00000000 ____D () C:\Program Files (x86)\Google

2014-03-14 15:25 - 2014-03-14 15:24 - 17529160 _____ (Google Inc.) C:\Users\Martin\Downloads\picasa39-setup.exe

2014-03-14 07:18 - 2014-03-03 22:22 - 00000000 ____D () C:\ProgramData\Kaspersky Lab

2014-03-14 01:16 - 2013-11-14 15:28 - 00818732 _____ () C:\WINDOWS\system32\PerfStringBackup.INI

2014-03-14 01:13 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\AppReadiness

2014-03-14 01:05 - 2014-03-14 01:04 - 05190279 _____ (Swearware) C:\Users\Martin\Downloads\ComboFix.exe

2014-03-14 00:02 - 2014-03-13 23:58 - 00000000 ____D () C:\ProgramData\Microsoft Help

2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\MSBuild

2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works

2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio

2014-03-14 00:01 - 2014-03-13 23:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office

2014-03-14 00:00 - 2014-03-14 00:00 - 00000000 ____D () C:\WINDOWS\PCHEALTH

2014-03-14 00:00 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared

2014-03-13 23:59 - 2014-03-13 23:59 - 00000000 ____D () C:\Program Files\Microsoft Office

2014-03-13 23:59 - 2013-11-14 15:17 - 00000000 ____D () C:\WINDOWS\ShellNew

2014-03-13 23:59 - 2013-08-22 21:25 - 00000167 _____ () C:\WINDOWS\win.ini

2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 __RHD () C:\MSOCache

2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft Help

2014-03-13 22:46 - 2013-08-22 22:46 - 00287534 _____ () C:\WINDOWS\setupact.log

2014-03-13 22:36 - 2014-03-12 22:55 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files

2014-03-13 22:32 - 2014-03-12 21:06 - 00000000 __RDO () C:\Users\Martin\SkyDrive

2014-03-13 22:32 - 2014-03-03 21:56 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2014-03-13 02:48 - 2014-03-13 02:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft_Corporation

2014-03-13 02:34 - 2014-03-13 02:34 - 00000000 ____D () C:\Program Files (x86)\ffdshow

2014-03-13 02:33 - 2014-03-13 02:33 - 00000000 ____D () C:\ProgramData\APN

2014-03-13 02:29 - 2014-03-13 02:29 - 02030080 _____ () C:\Users\Martin\Downloads\ffdshow-20041012.exe

2014-03-13 02:28 - 2014-03-13 02:28 - 00389440 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_for_ffdshow.exe

2014-03-13 01:31 - 2013-08-22 22:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT

2014-03-13 01:27 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI

2014-03-13 01:20 - 2013-11-14 15:20 - 00004550 _____ () C:\WINDOWS\PFRO.log

2014-03-13 01:15 - 2014-03-13 01:15 - 00000000 ____D () C:\Program Files (x86)\Integrated Camera Driver

2014-03-13 01:14 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Lenovo

2014-03-13 01:14 - 2013-12-05 04:59 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information

2014-03-13 01:14 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\restore

2014-03-13 00:42 - 2014-03-13 00:42 - 00017920 ___SH () C:\Users\Martin\Desktop\Thumbs.db

2014-03-13 00:40 - 2014-03-13 00:40 - 00007232 _____ () C:\Users\Martin\Desktop\ark.txt

2014-03-13 00:33 - 2014-03-13 00:32 - 00023288 _____ () C:\Users\Martin\Downloads\Addition.txt

2014-03-13 00:28 - 2014-03-13 00:27 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo

2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo

2014-03-13 00:11 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files (x86)\Intel

2014-03-13 00:07 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\CONEXANT

2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector

2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v2

2014-03-12 23:56 - 2014-03-09 02:41 - 00000000 ____D () C:\ProgramData\Conexant

2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe

2014-03-12 22:57 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore

2014-03-12 22:56 - 2014-03-03 23:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent

2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package

2014-03-12 21:06 - 2014-03-12 04:54 - 00000000 ____D () C:\Users\Martin

2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery

2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll

2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old

2014-03-12 20:47 - 2013-08-22 23:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template

2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys

2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb

2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb

2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl

2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl

2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi

2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll

2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe

2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll

2014-03-12 20:46 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\WinStore

2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe

2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll

2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms

2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ___RD () C:\WINDOWS\ToastData

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\MediaViewer

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\FileManager

2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Camera

2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS

2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe

2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe

2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys

2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll

2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Windows Defender

2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender

2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism

2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Dism

2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe

2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml

2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys

2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE

2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE

2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll

2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys

2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS

2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll

2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe

2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi

2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe

2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys

2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll

2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll

2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff

2014-03-12 16:29 - 2014-03-12 16:22 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip

2014-03-12 15:02 - 2013-11-14 16:08 - 00000000 ___HD () C:\$Windows.~BT

2014-03-12 15:01 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages

2014-03-12 15:00 - 2014-03-12 20:48 - 00000000 ___DC () C:\WINDOWS\Panther

2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini

2014-03-12 05:03 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\rescache

2014-03-12 05:02 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Registration

2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat

2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagwrn.xml

2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagerr.xml

2014-03-12 05:01 - 2014-03-12 04:11 - 00006530 _____ () C:\WINDOWS\comsetup.log

2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RSD () C:\WINDOWS\Media

2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RHD () C:\Users\Public\Libraries

2014-03-12 04:57 - 2013-08-22 22:44 - 00335784 _____ () C:\WINDOWS\system32\FNTCACHE.DAT

2014-03-12 04:56 - 2014-03-11 22:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit

2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN

2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep

2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\system32\WCN

2014-03-12 04:56 - 2013-08-22 23:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\spool

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\NDF

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\MUI

2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\IME

2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI

2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep

2014-03-12 04:56 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM

2014-03-12 04:56 - 2012-07-26 13:37 - 00000000 ____D () C:\Users\Default.migrated

2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate

2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility

2014-03-12 04:55 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\Intel

2014-03-12 04:55 - 2013-12-05 04:55 - 00000000 ____D () C:\ProgramData\PRICache

2014-03-12 04:55 - 2013-08-22 23:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery

2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Help

2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf

2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics

2014-03-12 04:51 - 2013-08-22 22:46 - 00000084 _____ () C:\WINDOWS\setuperr.log

2014-03-12 04:49 - 2013-08-22 21:36 - 00000000 __RHD () C:\Users\Default

2014-03-12 04:31 - 2013-12-05 05:07 - 01679981 _____ () C:\WINDOWS\WindowsUpdate (1).log

2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay

2014-03-12 04:30 - 2012-07-26 16:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent

2014-03-12 04:07 - 2014-03-12 04:07 - 04550656 _____ (Google Inc.) C:\WINDOWS\SysWOW64\GPhotos.scr

2014-03-12 02:06 - 2013-12-05 05:00 - 00000000 ____D () C:\WINDOWS\SysWOW64\sda

2014-03-12 01:25 - 2014-03-12 01:01 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity

2014-03-12 01:14 - 2014-03-11 22:31 - 00000000 ____D () C:\Program Files (x86)\Audacity

2014-03-12 01:09 - 2014-03-12 01:05 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe

2014-03-12 00:56 - 2014-03-12 00:52 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip

2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay

2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe

2014-03-11 22:37 - 2014-03-11 22:22 - 00000000 ____D () C:\Program Files (x86)\alipay

2014-03-11 22:25 - 2014-03-11 22:22 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer

2014-03-09 20:13 - 2014-03-09 20:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player

2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player

2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe

2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf

2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf

2014-03-09 14:35 - 2014-03-09 01:48 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk

2014-03-09 14:35 - 2014-03-09 01:48 - 00000000 ____D () C:\ProgramData\Skype

2014-03-09 13:59 - 2013-12-05 05:01 - 00000000 ____D () C:\Intel

2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant

2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl

2014-03-09 02:39 - 2014-03-09 02:33 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe

2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype

2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype

2014-03-09 01:47 - 2014-03-09 01:45 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe

2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote

2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote

2014-03-06 21:15 - 2014-03-06 21:10 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe

2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log

2014-03-04 03:04 - 2014-01-07 03:35 - 00000000 ____D () C:\WINDOWS\system32\MRT

2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk

2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent

2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent

2014-03-03 22:46 - 2014-03-03 22:22 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys

2014-03-03 22:46 - 2013-11-26 04:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys

2014-03-03 22:46 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys

2014-03-03 22:45 - 2014-03-03 22:22 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys

2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk

2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab

2014-03-03 22:22 - 2012-07-26 16:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP

2014-03-03 22:16 - 2014-03-03 21:45 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe

2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER

2014-03-03 22:08 - 2014-03-03 21:51 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe

2014-03-03 22:07 - 2014-03-03 20:06 - 00000000 ____D () C:\totalcmd

2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe

2014-03-03 22:06 - 2014-03-03 22:05 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip

2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2014-03-03 21:53 - 2014-03-03 21:07 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP

2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk

2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe

2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER

2014-03-03 20:03 - 2014-03-03 20:02 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe

2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia

2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel

2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe

 

Some content of TEMP:

====================

C:\Users\Martin\AppData\Local\Temp\KUIU.EXE

C:\Users\Martin\AppData\Local\Temp\ose00000.exe

C:\Users\Martin\AppData\Local\Temp\qqsafeud.exe

C:\Users\Martin\AppData\Local\Temp\SCC.dll

C:\Users\Martin\AppData\Local\Temp\SymCCIS.dll

 

 

==================== Bamital & volsnap Check =================

 

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\rpcss.dll => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys

[2014-03-12 20:43] - [2014-03-12 20:43] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02

 

 

 

LastRegBack: 2014-03-12 04:49

 

==================== End Of Log ============================

Link to post
Share on other sites

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe
  • Hit Scan and wait for the scan to finish.
  • Confirm the message but don´t uncheck anything.
  • Hit Clean
  • When the run is finished, it will open up a text file
  • Please post its contents within your next reply
  • You´ll find the log file at C:\AdwCleaner[s1].txt also

 
 
 
Delete junk with JRT

thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

 

 

Full System Scan with Malwarebytes Antimalware


  • If not existing, please download
Malwarebytes' Anti-Malware to your desktop. Double-click mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.



If the program is already installed:

  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

 

 

 

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology

[*]Click Scan[*]Wait for the scan to finish[*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic.

Link to post
Share on other sites

Hey Psychotic,

 

I run all the programs you asked for and sending the results. Since The time we started I did not experienced the pop-ups again. Just Chrome seems to acting really strange(hanging, not displaying pages, starts really slow) and I am forced to use IE for some of the utilities downloads. I plan to uninstall it and use FF instead...I wanted to give it a try since friends told me it is really good and fast...not for me it seems:-(

 

ADW cleaner

# AdwCleaner v3.022 - Report created 16/03/2014 at 01:14:01

# Updated 13/03/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : Martin - HOLISTR
# Running from : C:\Users\Martin\Downloads\adwcleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\Program Files (x86)\Tencent
Folder Deleted : C:\Program Files (x86)\Common Files\Tencent
Folder Deleted : C:\Users\Martin\AppData\Local\Temp\Tencent
Folder Deleted : C:\Users\Martin\AppData\Roaming\Tencent
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\TENCENT
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\Software\TENCENT
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.16518
 
 
-\\ Google Chrome v33.0.1750.146
 
[ File : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [1293 octets] - [16/03/2014 01:10:41]
AdwCleaner[s0].txt - [1161 octets] - [16/03/2014 01:14:01]
 
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [1221 octets] ##########
 
 
JRTlog
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 8.1 x64
Ran by Martin on ?? 2014/03/16 at  1:21:02.41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ?? 2014/03/16 at  1:25:17.93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Link to post
Share on other sites

MWBlog

 

I run this test 3 times since forgot to delete the first 2 entries during first and second run. Hope that it is not a big deal. Eventually all were removed and MWB demanded restart.

 

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
 
Database version: v2014.03.15.04
 
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16518
Martin :: HOLISTR [administrator]
 
Protection: Enabled
 
2014/3/16 1:30:44
mbam-log-2014-03-16 (01-30-44).txt
 
Scan type: Full scan (C:\|D:\|E:\|H:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 345172
Time elapsed: 40 minute(s), 17 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 3
C:\$Recycle.Bin\S-1-5-21-1901417010-66602696-720837262-1001\$RJIR73L.exe (PUP.Optional.InstallIQ.A) -> No action taken.
C:\Users\Martin\Downloads\SoftonicDownloader_for_ffdshow.exe (PUP.Optional.Softonic.A) -> No action taken.
E:\System Volume Information\_restore{1524574E-B2D5-4DFD-BFBD-2A40EE3C71B2}\RP208\A0034729.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
 
(end)
 
 
ESETonline log
 
C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe Win32/CentrumDownloader.A potentially unwanted application
Link to post
Share on other sites

 Results of screen317's Security Check version 0.99.80  

   x64 (UAC is enabled)  

 Internet Explorer 11  

``````````````Antivirus/Firewall Check:`````````````` 

 Windows Firewall Enabled!  

Kaspersky Internet Security   

Windows Defender              

 Antivirus up to date!   

`````````Anti-malware/Other Utilities Check:````````` 

 Malwarebytes Anti-Malware version 1.75.0.1300  

 Google Chrome 33.0.1750.146  

 Google Chrome 33.0.1750.154  

````````Process Check: objlist.exe by Laurent````````  

 Malwarebytes Anti-Malware mbamservice.exe  

 Malwarebytes Anti-Malware mbamgui.exe  

 Malwarebytes' Anti-Malware mbamscheduler.exe   

 Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe  

 Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe  

`````````````````System Health check````````````````` 

 Total Fragmentation on Drive C:  % 

````````````````````End of Log`````````````````````` 

 

One More think Psychotic. I live in China and I use QQInternational as communication client. After all the steps we performed I am missing this application on my system. Maybe it was deleted as a potentially unwanted program by one of the utilities, though it is essential for me to communicate in here.

Do you recommend to install it again now or should I wait till we finish the current steps?

 

Thanks for help so far. H
Link to post
Share on other sites

Feel free to reinstall the software from the original developer´s site. :)

 

Your system is clean now! :)

 

 

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

[*] If there is still something left please delete it manualy.

 

 

 

Recommendations: How to protect yourself

  • System Updates
    Please ensure to have automatic updates activated in your control panel.
    For further information and a tutorial, see this Microsoft Support article.
  • Protection
    What you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.
    Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.
    • To keep your browser free of advertising, you may install the Adblock Plus browser extension.
      It will filter unwanted advertising out of the website´s content.
    • To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.
      It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.
      In addition, before accessing a dangerous classified web site, a warning screen is displayed.


    [*]Up to date Software
    Keep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:

    [*]Backup
    Hardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system. [*]Behaviour
    The commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help if you aren´t careful enough.

    • While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware.
    • Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything.
    • When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system.
    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
      They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.



Link to post
Share on other sites

Hello Psychotic,

 

thanks a lot for your help. Error 80 is usually caused cause of the user impatience and laziness.

 

I was wondering if you could explain a bit what was wrong in my browser or where I could get that fast any infection. Or was it just minor slip and nothing really serious, really can not recall anything wrong I did. I always use one AV plus free version of one of the antimalware tools.

 

Peace

 

H.

Link to post
Share on other sites

Some free software offers contain additional software that has nothing to do with the program itself but is installed as well.

Most of these so called PUPs (Potentially Unwanted Program) are little toolbars or extensions that inject itselfs into your browsers, mining behaviour data or something like that.

 

These additional functions are loaded when starting up the brwoser - what causes this procedure to take more time from now on.

 

Some PUPs change your default search engine to offer different search results, directing you to more software products.

 

These were just a few examples - some of these programs were installed on your computer. We´ve cleaned them out and now everything is like before.

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.