Holistr Posted March 11, 2014 ID:801847 Share Posted March 11, 2014 Hello Guys, I came here through a search for a solution to random pop-ups in my brand new laptop with Win8, google chrome. Like yesterday first a random page opened and it seemed valid...today it happened again. Both of the pages are pretty well done. Unfortunatelly I have no screen, will make screen nextime if necessary. The pup-ups came out of nowhere and I am sure I did not even click anything. I started to use the new computer mainly cause my oldone with XP was infected. I use flashdisc to copy necessary data from one computer to another...maybe that caused the infection transfere - I used this flashdisc to install KasperskyAV on the new system. Ofcourse I run a scan right away but nothing was found. Now I looked at this thread: https://forums.malwarebytes.org/index.php?showtopic=124537 And am pretty scared what is in front of me. The system is brand new, so not many applications are intalled and used only for several days. PLEASE let me know how to procede in order to get rid of any possible infection. Thank you H. Link to post Share on other sites More sharing options...
Psychotic Posted March 11, 2014 ID:801876 Share Posted March 11, 2014 Hi there,my name is Marius and I will assist you with your malware related problems.Before we move on, please read the following points carefully.First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.Perform everything in the correct order. Sometimes one step requires the previous one.If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding. Scan with FRST in normal modePlease download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties) Run FRST.Don´t change one of the checkboxes and hit Scan.Logfiles are created on your desktop.Poste the FRST.txt and (after the first scan only!) the Addition.txt. Scan with Gmer rootkit scannerPlease download Gmer from here by clicking on the "Download EXE" Button.Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent. If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO. In the right panel, you will see several boxes that have been checked. Uncheck the following ...Sections IAT/EAT Show All ( should be unchecked by default )[*]Leave everything else as it is. [*]Close all other running programs as well as your Browser. [*]Click the Scan button & wait for it to finish. [*]Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post. [*]Save it where you can easily find it, such as your desktop. [*]Please post the content of the ark.txt here.**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries Link to post Share on other sites More sharing options...
Holistr Posted March 12, 2014 Author ID:802323 Share Posted March 12, 2014 Hello Psychotic, I did what you asked for, below you can see the 3 outputs. Note that I run gmer several times cause not all programs were shut down, though every time the scan stopped with error message: C_windows_system32_config_system and ntuser.dat files(can send screen of one of them if you ask for) were inaccessible because of used by another process. Logs too long to paste them. Sending as attachment.ark.txtAddition.txtFRST_13-03-2014_00-33-20.txt Link to post Share on other sites More sharing options...
Holistr Posted March 12, 2014 Author ID:802325 Share Posted March 12, 2014 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2014Ran by Martin (administrator) on HOLISTR on 13-03-2014 00:32:16Running from C:\Users\Martin\DownloadsWindows 8.1 (X64) OS Language: English(US)Internet Explorer Version 11Boot Mode: Normal The only official download link for FRST:Download link for 32-Bit version: Download link for 64-Bit Version: Download link from any site other than Bleeping Computer is unpermitted or outdated.See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe(Alipay Inc. ) C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe(Microsoft Corporation) C:\Windows\System32\skydrive.exe(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe(Microsoft Corporation) C:\WINDOWS\system32\wwahost.exe(Intel Corporation) C:\Windows\System32\igfxtray.exe(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe(Intel Corporation) C:\Windows\System32\hkcmd.exe(Intel Corporation) C:\Windows\System32\igfxpers.exe(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe(Microsoft Corporation) C:\WINDOWS\system32\AUDIODG.EXE(Microsoft Corporation) C:\WINDOWS\syswow64\wwahost.exe(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe(Microsoft Corporation) C:\Windows\System32\WWAHost.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [intelWirelessWiMAX] - C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [1626112 2012-07-26] (Intel® Corporation)HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)HKLM\...\Run: [smartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()HKLM\...\Run: [LenovoOptMouseUpdate] - C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)HKLM-x32\...\Run: [iMSS] - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [134616 2013-05-14] (Intel Corporation)Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnkShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)Tcpip\..\Interfaces\{71B995F2-8017-4977-9F48-9D894D207EBF}: [NameServer]8.8.8.8 8.8.4.4 Chrome: =======CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-03]CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-03]CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-03]CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-03]CHR Extension: (Kaspersky URL Advisor) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-03-03]CHR Extension: (Safe Money) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-03-03]CHR Extension: (Dangerous Websites Blocker) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-03-03]CHR Extension: (Virtuální klávesnice) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-03-03]CHR Extension: (Peněženka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-03]CHR Extension: (Evernote Web Clipper) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-03-11]CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-03]CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-11-26] ==================== Services (Whitelisted) ================= R2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [540032 2014-03-07] (Alipay Inc. )R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-11-26] (Kaspersky Lab ZAO)S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-11] (Intel® Corporation)R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-14] (Intel Corporation)R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-05-14] (Intel Corporation)S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-29] ()S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-03-12] (Microsoft Corporation)S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-12] (Microsoft Corporation)R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-29] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows ® Win 7 DDK provider)S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-31] (Intel Corporation)S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-26] (Intel Corporation)S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-03-12] (Microsoft Corporation)R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-26] (Kaspersky Lab ZAO)S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2013-11-26] (Kaspersky Lab)S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-03-03] (Kaspersky Lab ZAO)R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [624224 2014-03-03] (Kaspersky Lab ZAO)R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-11-26] (Kaspersky Lab ZAO)R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-03-03] (Kaspersky Lab ZAO)R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-11-26] (Kaspersky Lab ZAO)R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [64608 2013-11-26] (Kaspersky Lab ZAO)R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2014-03-03] (Kaspersky Lab ZAO)S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-09] (Intel Corporation)S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-03-12] (Microsoft Corporation)S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-03-12] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-13 00:32 - 2014-03-13 00:32 - 00014956 _____ () C:\Users\Martin\Downloads\FRST.txt2014-03-13 00:31 - 2014-03-13 00:32 - 00000000 ____D () C:\FRST2014-03-13 00:27 - 2014-03-13 00:28 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo2014-03-13 00:11 - 2012-08-09 16:31 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\WINDOWS\SysWOW64\CSVer.dll2014-03-13 00:07 - 2012-01-12 13:16 - 00002060 _____ () C:\WINDOWS\system32\Drivers\SamSfPa.dat2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v22014-03-13 00:06 - 2012-06-08 17:07 - 00201376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe2014-03-13 00:06 - 2011-01-07 12:28 - 00446592 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe2014-03-13 00:05 - 2012-08-31 19:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEP64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\EED64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEL64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEA64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEG64A.dll2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe2014-03-12 22:55 - 2014-03-12 22:57 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package2014-03-12 21:06 - 2014-03-13 00:16 - 00000000 __RDO () C:\Users\Martin\SkyDrive2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery2014-03-12 20:48 - 2014-03-12 15:00 - 00000000 ___DC () C:\WINDOWS\Panther2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff2014-03-12 16:22 - 2014-03-12 16:29 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini2014-03-12 05:02 - 2014-03-13 00:14 - 00205213 _____ () C:\WINDOWS\WindowsUpdate.log2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate2014-03-12 04:54 - 2014-03-12 21:06 - 00000000 ____D () C:\Users\Martin2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagwrn.xml2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagerr.xml2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance2014-03-12 04:51 - 2014-03-13 00:11 - 00000000 ____D () C:\Program Files (x86)\Intel2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics2014-03-12 04:51 - 2014-01-25 02:23 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL2014-03-12 04:51 - 2014-01-25 02:23 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL2014-03-12 04:50 - 2014-03-13 00:07 - 00000000 ____D () C:\Program Files\CONEXANT2014-03-12 04:50 - 2014-03-12 04:55 - 00000000 ____D () C:\Program Files\Intel2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay2014-03-12 04:11 - 2014-03-12 05:01 - 00006530 _____ () C:\WINDOWS\comsetup.log2014-03-12 01:05 - 2014-03-12 01:09 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe2014-03-12 01:01 - 2014-03-12 01:25 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity2014-03-12 00:52 - 2014-03-12 00:56 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe2014-03-11 22:31 - 2014-03-12 01:14 - 00000000 ____D () C:\Program Files (x86)\Audacity2014-03-11 22:22 - 2014-03-12 04:56 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit2014-03-11 22:22 - 2014-03-11 22:37 - 00000000 ____D () C:\Program Files (x86)\alipay2014-03-11 22:22 - 2014-03-11 22:25 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer2014-03-09 20:09 - 2014-03-09 20:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl2014-03-09 02:41 - 2014-03-12 23:56 - 00000000 ____D () C:\ProgramData\Conexant2014-03-09 02:40 - 2012-09-20 14:11 - 01609376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\Drivers\CHDRT64.sys2014-03-09 02:40 - 2012-09-12 11:35 - 02535520 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll2014-03-09 02:40 - 2012-08-08 13:12 - 01780896 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64AP74.dll2014-03-09 02:40 - 2012-06-29 13:04 - 00050848 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxPageMaster64.dll2014-03-09 02:40 - 2012-03-20 03:48 - 00568960 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\UCI64A89.dll2014-03-09 02:40 - 2012-01-16 10:42 - 00666240 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\C3DHPExt64.dll2014-03-09 02:40 - 2011-01-18 11:35 - 00030893 _____ () C:\WINDOWS\system32\Drivers\Mixer.ini2014-03-09 02:33 - 2014-03-09 02:39 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe2014-03-09 01:48 - 2014-03-12 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype2014-03-09 01:48 - 2014-03-09 14:35 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk2014-03-09 01:48 - 2014-03-09 14:35 - 00000000 ____D () C:\ProgramData\Skype2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype2014-03-09 01:45 - 2014-03-09 01:47 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote2014-03-06 21:10 - 2014-03-06 21:15 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent2014-03-03 23:13 - 2014-03-12 22:56 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent2014-03-03 23:13 - 2009-02-18 14:51 - 00018760 _____ () C:\WINDOWS\SysWOW64\QQVistaHelper.dll2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk2014-03-03 22:23 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll2014-03-03 22:22 - 2014-03-13 00:15 - 00000000 ____D () C:\ProgramData\Kaspersky Lab2014-03-03 22:22 - 2014-03-03 22:46 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys2014-03-03 22:22 - 2014-03-03 22:45 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe2014-03-03 22:05 - 2014-03-03 22:06 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip2014-03-03 21:56 - 2014-03-13 00:16 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job2014-03-03 21:56 - 2014-03-13 00:01 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk2014-03-03 21:51 - 2014-03-03 22:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe2014-03-03 21:45 - 2014-03-03 22:16 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe2014-03-03 21:28 - 2014-03-03 22:12 - 00000000 ____D () C:\Program Files (x86)\Google2014-03-03 21:28 - 2014-03-03 21:40 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google2014-03-03 21:07 - 2014-03-03 21:53 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP2014-03-03 20:06 - 2014-03-03 22:07 - 00000000 ____D () C:\totalcmd2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER2014-03-03 20:02 - 2014-03-03 20:03 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia2014-03-03 19:36 - 2014-03-13 00:20 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-10012014-03-03 19:30 - 2014-03-12 22:57 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore2014-03-03 19:30 - 2014-03-12 15:01 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe Link to post Share on other sites More sharing options...
Holistr Posted March 12, 2014 Author ID:802326 Share Posted March 12, 2014 ==================== One Month Modified Files and Folders ======= 2014-03-13 00:32 - 2014-03-13 00:32 - 00014956 _____ () C:\Users\Martin\Downloads\FRST.txt2014-03-13 00:32 - 2014-03-13 00:31 - 00000000 ____D () C:\FRST2014-03-13 00:28 - 2014-03-13 00:27 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe2014-03-13 00:21 - 2013-11-14 15:28 - 00818732 _____ () C:\WINDOWS\system32\PerfStringBackup.INI2014-03-13 00:20 - 2014-03-03 19:36 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-10012014-03-13 00:16 - 2014-03-12 21:06 - 00000000 __RDO () C:\Users\Martin\SkyDrive2014-03-13 00:16 - 2014-03-03 21:56 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job2014-03-13 00:15 - 2014-03-03 22:22 - 00000000 ____D () C:\ProgramData\Kaspersky Lab2014-03-13 00:14 - 2014-03-12 05:02 - 00205213 _____ () C:\WINDOWS\WindowsUpdate.log2014-03-13 00:14 - 2013-08-22 22:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT2014-03-13 00:14 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo2014-03-13 00:11 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files (x86)\Intel2014-03-13 00:07 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\CONEXANT2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v22014-03-13 00:05 - 2013-08-22 22:46 - 00285001 _____ () C:\WINDOWS\setupact.log2014-03-13 00:01 - 2014-03-03 21:56 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job2014-03-13 00:00 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\sru2014-03-12 23:57 - 2013-11-14 15:20 - 00004136 _____ () C:\WINDOWS\PFRO.log2014-03-12 23:56 - 2014-03-09 02:41 - 00000000 ____D () C:\ProgramData\Conexant2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe2014-03-12 23:30 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\tracing2014-03-12 22:57 - 2014-03-12 22:55 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files2014-03-12 22:57 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore2014-03-12 22:56 - 2014-03-03 23:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package2014-03-12 21:06 - 2014-03-12 04:54 - 00000000 ____D () C:\Users\Martin2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old2014-03-12 20:47 - 2013-08-22 23:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll2014-03-12 20:46 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\WinStore2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ___RD () C:\WINDOWS\ToastData2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\MediaViewer2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\FileManager2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Camera2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Windows Defender2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Dism2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff2014-03-12 16:29 - 2014-03-12 16:22 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip2014-03-12 15:09 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\AppReadiness2014-03-12 15:02 - 2013-11-14 16:08 - 00000000 ___HD () C:\$Windows.~BT2014-03-12 15:01 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages2014-03-12 15:00 - 2014-03-12 20:48 - 00000000 ___DC () C:\WINDOWS\Panther2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini2014-03-12 05:03 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\rescache2014-03-12 05:02 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Registration2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagwrn.xml2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagerr.xml2014-03-12 05:01 - 2014-03-12 04:11 - 00006530 _____ () C:\WINDOWS\comsetup.log2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RSD () C:\WINDOWS\Media2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RHD () C:\Users\Public\Libraries2014-03-12 04:57 - 2013-08-22 22:44 - 00335784 _____ () C:\WINDOWS\system32\FNTCACHE.DAT2014-03-12 04:56 - 2014-03-11 22:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\system32\WCN2014-03-12 04:56 - 2013-08-22 23:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\spool2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\NDF2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\MUI2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\IME2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep2014-03-12 04:56 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM2014-03-12 04:56 - 2012-07-26 13:37 - 00000000 ____D () C:\Users\Default.migrated2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility2014-03-12 04:55 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\Intel2014-03-12 04:55 - 2013-12-05 04:55 - 00000000 ____D () C:\ProgramData\PRICache2014-03-12 04:55 - 2013-08-22 23:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Help2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics2014-03-12 04:51 - 2013-08-22 22:46 - 00000084 _____ () C:\WINDOWS\setuperr.log2014-03-12 04:49 - 2013-08-22 21:36 - 00000000 __RHD () C:\Users\Default2014-03-12 04:31 - 2013-12-05 05:07 - 01679981 _____ () C:\WINDOWS\WindowsUpdate (1).log2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay2014-03-12 04:30 - 2012-07-26 16:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent2014-03-12 02:06 - 2013-12-05 05:00 - 00000000 ____D () C:\WINDOWS\SysWOW64\sda2014-03-12 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype2014-03-12 01:25 - 2014-03-12 01:01 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity2014-03-12 01:14 - 2014-03-11 22:31 - 00000000 ____D () C:\Program Files (x86)\Audacity2014-03-12 01:09 - 2014-03-12 01:05 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe2014-03-12 00:56 - 2014-03-12 00:52 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe2014-03-11 22:37 - 2014-03-11 22:22 - 00000000 ____D () C:\Program Files (x86)\alipay2014-03-11 22:25 - 2014-03-11 22:22 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer2014-03-09 20:13 - 2014-03-09 20:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf2014-03-09 14:35 - 2014-03-09 01:48 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk2014-03-09 14:35 - 2014-03-09 01:48 - 00000000 ____D () C:\ProgramData\Skype2014-03-09 13:59 - 2013-12-05 05:01 - 00000000 ____D () C:\Intel2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl2014-03-09 02:39 - 2014-03-09 02:33 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype2014-03-09 01:47 - 2014-03-09 01:45 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote2014-03-06 21:15 - 2014-03-06 21:10 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log2014-03-04 03:04 - 2014-01-07 03:35 - 00000000 ____D () C:\WINDOWS\system32\MRT2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent2014-03-03 22:46 - 2014-03-03 22:22 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys2014-03-03 22:46 - 2013-11-26 04:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys2014-03-03 22:46 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys2014-03-03 22:45 - 2014-03-03 22:22 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab2014-03-03 22:22 - 2012-07-26 16:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP2014-03-03 22:16 - 2014-03-03 21:45 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe2014-03-03 22:12 - 2014-03-03 21:28 - 00000000 ____D () C:\Program Files (x86)\Google2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER2014-03-03 22:08 - 2014-03-03 21:51 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe2014-03-03 22:07 - 2014-03-03 20:06 - 00000000 ____D () C:\totalcmd2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe2014-03-03 22:06 - 2014-03-03 22:05 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore2014-03-03 21:53 - 2014-03-03 21:07 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe2014-03-03 21:40 - 2014-03-03 21:28 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER2014-03-03 20:03 - 2014-03-03 20:02 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe Some content of TEMP:====================C:\Users\Martin\AppData\Local\Temp\KUIU.EXEC:\Users\Martin\AppData\Local\Temp\qqsafeud.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legitC:\Windows\System32\wininit.exe => MD5 is legitC:\Windows\explorer.exe => MD5 is legitC:\Windows\SysWOW64\explorer.exe => MD5 is legitC:\Windows\System32\svchost.exe => MD5 is legitC:\Windows\SysWOW64\svchost.exe => MD5 is legitC:\Windows\System32\services.exe => MD5 is legitC:\Windows\System32\User32.dll => MD5 is legitC:\Windows\SysWOW64\User32.dll => MD5 is legitC:\Windows\System32\userinit.exe => MD5 is legitC:\Windows\SysWOW64\userinit.exe => MD5 is legitC:\Windows\System32\rpcss.dll => MD5 is legitC:\Windows\System32\Drivers\volsnap.sys[2014-03-12 20:43] - [2014-03-12 20:43] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02 LastRegBack: 2014-03-12 04:49 ==================== End Of Log ============================ Addition Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2014Ran by Martin at 2014-03-13 00:32:52Running from C:\Users\Martin\DownloadsBoot Mode: Normal========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== Alipay security control 3.7.0.0 (x32 Version: 3.7.0.0 - Alipay.com Co., Ltd.) HiddenAlipayDHC 1.1.0.0 (x32 Version: 1.1.0.0 - Alipay.com Co., Ltd.) HiddenAudacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.48.0 - Conexant)Crystal Player Professional 1.99 (HKLM-x32\...\Crystal Player) (Version: Professional 1.99 - Crystal Reality LLC)Evernote v. 5.2 (HKLM-x32\...\{090931D6-A2F4-11E3-AD9C-00163E98E7D0}) (Version: 5.2.0.2946 - Evernote Corp.)Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.)Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) HiddenIntel PROSet Wireless (Version: - ) HiddenIntel® Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36702 - Intel Corporation)Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)Intel® PRO/Wireless Driver (Version: 16.01.5000.0577 - Intel Corporation) HiddenIntel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3412 - Intel Corporation)Intel® PROSet/Wireless for Bluetooth® + High Speed (Version: 15.6.1.0536 - Intel Corporation) HiddenIntel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)Intel® PROSet/Wireless Software (HKLM-x32\...\{fad118b4-798f-4755-9e67-a622eec95b62}) (Version: 15.6.1 - Intel Corporation)Intel® PROSet/Wireless WiFi Software (Version: 16.01.5000.0269 - Intel Corporation) HiddenIntel® PROSet/Wireless WiMAX Software (HKLM\...\{5F588B19-C575-4750-86FD-6ED2B76E61F1}) (Version: 7.50.0000 - Intel Corporation)Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) HiddenKaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) HiddenLenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.03.13 - )Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)Ö§¸¶±¦°²È«¿Ø¼þ 3.22.0.0 (HKLM-x32\...\alieditplus) (Version: 3.22.0.0 - Alipay.com Co., Ltd.)On Screen Display (HKLM\...\OnScreenDisplay) (Version: 7.09.00 - )QQ International (HKLM-x32\...\{3CA54984-A14B-42FE-9FF1-7EA90151D725}) (Version: 1.91.1213.0 - 腾讯科技(深圳)有限公司)Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29011 - Realtek Semiconductor Corp.)Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - )Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.50 - Ghisler Software GmbH) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2013-08-22 21:25 - 2013-08-22 21:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTaskTask: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTaskTask: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsListTask: {1F7AC4AB-170E-4FC4-8396-FAE75D46C284} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-15] (Intel Corporation)Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTaskTask: {2147C864-8D13-4AB9-9B87-CD4FBD731E84} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-04-24] (Synaptics Incorporated)Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulateTask: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalanceTask: {518B38DA-D07B-4E9E-A7AB-9FC0651CC346} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-03] (Google Inc.)Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play CleanupTask: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance TaskTask: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTaskTask: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryStateTask: {7A310B90-6F4B-4A9E-9745-2D7A89982220} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-15] (Intel Corporation)Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance TaskTask: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTaskTask: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance WorkTask: {B71EC85F-C04F-42B8-A2DA-C6CB4479EE97} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-03] (Google Inc.)Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTaskTask: {D62EB2BA-1E86-4981-969B-B7D2C525A1EF} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2013-08-22] (Microsoft Corporation)Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensingTask: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon SynchronizationTask: {E1D199D3-5710-4B4D-8655-6781E06824C8} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2012-08-31] (Dolby Laboratories Inc.)Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRETask: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-14 15:18 - 2013-11-14 15:18 - 00012728 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\Microsoft.PerfTrack.winmd2014-03-12 15:10 - 2014-03-12 15:10 - 00363520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\8d0f16d53c303f545bdc3bdeeb2a7fb3\Windows.Foundation.ni.dll2014-03-12 15:10 - 2014-03-12 15:10 - 00347136 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\ed3886aaf7efc3feec0169cf9014cb11\Windows.Globalization.ni.dll2014-03-12 15:10 - 2014-03-12 15:10 - 01782272 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\8848363a64856b740e9ebd321b6a98ca\Windows.ApplicationModel.ni.dll2014-03-12 15:10 - 2014-03-12 15:10 - 00207872 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.System\67df9eac656929e232d804428e224a7d\Windows.System.ni.dll2014-03-12 15:11 - 2014-03-12 15:11 - 01278464 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Storage\29e4b2d8f87a111865c3302f567b4a82\Windows.Storage.ni.dll2014-03-12 15:11 - 2014-03-12 15:11 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\3363e49b745a5ddf1aaf80b18c175191\Windows.UI.ni.dll2014-03-12 15:10 - 2014-03-12 15:10 - 01259520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Networking\5d30480aa910c28c2571439d412f3b53\Windows.Networking.ni.dll2013-11-14 15:18 - 2013-11-14 15:18 - 00016312 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\SqliteWrapper.winmd2013-11-14 15:18 - 2013-11-14 15:18 - 00485816 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\SqliteWrapper.dll2013-11-14 15:18 - 2013-11-14 15:18 - 00660920 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\Sqlite3.dll2014-03-12 15:10 - 2014-03-12 15:10 - 00467456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Graphics\fb496048d93b67e96961f34a0955f3d8\Windows.Graphics.ni.dll2013-08-22 15:19 - 2013-08-22 14:54 - 00093696 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Web.winmd2014-03-12 15:11 - 2014-03-12 15:11 - 00632320 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Security\b4178c95c7aafade0fcdb76b09bd2973\Windows.Security.ni.dll2013-08-22 15:19 - 2013-08-22 14:54 - 00050176 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Data.winmd2013-11-14 15:18 - 2013-11-14 15:18 - 00246168 _____ () C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.174_x64__8wekyb3d8bbwe\Microsoft.WindowsAzure.Messaging.Managed.DLL2014-03-12 15:11 - 2014-03-12 15:11 - 02019840 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Devices\690b3f44ab1db69bc7ba1e4ceee9b89f\Windows.Devices.ni.dll2014-01-25 02:22 - 2014-01-25 02:22 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll2014-03-13 00:07 - 2010-10-26 12:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll2014-02-24 16:56 - 2014-02-24 16:56 - 00433664 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll2014-02-24 16:56 - 2014-02-24 16:56 - 00315392 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll2013-12-05 05:01 - 2013-05-14 07:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll2014-03-09 01:31 - 2014-03-02 10:35 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll2014-03-09 01:31 - 2014-03-02 10:35 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libglesv2.dll2014-03-09 01:31 - 2014-03-02 10:35 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libegl.dll2014-03-09 01:31 - 2014-03-02 10:35 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll2014-03-09 01:31 - 2014-03-02 10:35 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll2014-03-09 01:31 - 2014-03-02 10:35 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Martin\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors:==================Error: (03/12/2014 11:55:52 PM) (Source: Application Error) (User: )Description: Faulting application name: CAudioFilterAgent64.exe, version: 1.7.40.0, time stamp: 0x4fd99b06Faulting module name: CAudioFilterAgent64.exe, version: 1.7.40.0, time stamp: 0x4fd99b06Exception code: 0xc0000005Fault offset: 0x000000000008bd28Faulting process id: 0x1294Faulting application start time: 0xCAudioFilterAgent64.exe0Faulting application path: CAudioFilterAgent64.exe1Faulting module path: CAudioFilterAgent64.exe2Report Id: CAudioFilterAgent64.exe3Faulting package full name: CAudioFilterAgent64.exe4Faulting package-relative application ID: CAudioFilterAgent64.exe5 Error: (03/12/2014 04:33:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: HOLISTR)Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147023174 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/12/2014 04:15:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: HOLISTR)Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147023174 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelQosEvent" whose target class "CIntelQosEvent" in //./ROOT/default namespace does not exist. The query will be ignored. Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelDot1xEvent" whose target class "CIntelDot1xEvent" in //./ROOT/default namespace does not exist. The query will be ignored. Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelWLANEvent" whose target class "CIntelWLANEvent" in //./ROOT/default namespace does not exist. The query will be ignored. Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)Description: Event provider attempted to register query "select * from CIntelQosEvent" whose target class "CIntelQosEvent" in //./ROOT/default namespace does not exist. The query will be ignored. Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)Description: Event provider attempted to register query "select * from CIntelDot1xEvent" whose target class "CIntelDot1xEvent" in //./ROOT/default namespace does not exist. The query will be ignored. Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI) (User: NT AUTHORITY)Description: Event provider attempted to register query "select * from CIntelWLANEvent" whose target class "CIntelWLANEvent" in //./ROOT/default namespace does not exist. The query will be ignored. Error: (03/11/2014 02:02:41 AM) (Source: Application Error) (User: )Description: Faulting application name: LiveComm.exe, version: 16.4.4206.722, time stamp: 0x500ca1a7Faulting module name: ntdll.dll, version: 6.2.9200.16579, time stamp: 0x51637f77Exception code: 0xc0000005Fault offset: 0x000000000005ab00Faulting process id: 0x46cFaulting application start time: 0xLiveComm.exe0Faulting application path: LiveComm.exe1Faulting module path: LiveComm.exe2Report Id: LiveComm.exe3Faulting package full name: LiveComm.exe4Faulting package-relative application ID: LiveComm.exe5 System errors:=============Error: (03/13/2014 00:14:50 AM) (Source: BTHUSB) (User: )Description: The local adapter does not support an important Low Energy controller state. The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff. Low Energy functionality will be disabled. Error: (03/13/2014 00:14:23 AM) (Source: Service Control Manager) (User: )Description: The Superfetch service terminated with the following error: %%1062 Error: (03/13/2014 00:07:51 AM) (Source: BTHUSB) (User: )Description: The local adapter does not support an important Low Energy controller state. The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff. Low Energy functionality will be disabled. Error: (03/12/2014 11:57:31 PM) (Source: BTHUSB) (User: )Description: The local adapter does not support an important Low Energy controller state. The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff. Low Energy functionality will be disabled. Error: (03/12/2014 09:04:15 PM) (Source: Service Control Manager) (User: )Description: The Print Spooler service terminated with the following error: %%2147944140 Error: (03/12/2014 09:04:05 PM) (Source: NetBT) (User: )Description: Initialization failed because the transport refused to open initial addresses. Error: (03/12/2014 09:03:41 PM) (Source: BTHUSB) (User: )Description: The local adapter does not support an important Low Energy controller state. The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff. Low Energy functionality will be disabled. Error: (03/12/2014 03:34:40 PM) (Source: DCOM) (User: NT AUTHORITY)Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (03/12/2014 05:02:02 AM) (Source: NETLOGON) (User: )Description: This computer is configured as a member of a workgroup, not asa member of a domain. The Netlogon service does not need to run in thisconfiguration. Error: (03/12/2014 04:59:04 AM) (Source: Service Control Manager) (User: )Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error: %%2147770990 Microsoft Office Sessions:=========================Error: (03/12/2014 11:55:52 PM) (Source: Application Error)(User: )Description: CAudioFilterAgent64.exe1.7.40.04fd99b06CAudioFilterAgent64.exe1.7.40.04fd99b06c0000005000000000008bd28129401cf3df3df66b6a4C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exeC:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exec93ff56d-a9fe-11e3-be76-6036dd6349a2 Error: (03/12/2014 04:33:28 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: HOLISTR)Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147023174 Error: (03/12/2014 04:15:10 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: HOLISTR)Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147023174 Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)Description: IntelWLANEventProviderselect * from CIntelQosEventCIntelQosEvent//./ROOT/default Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)Description: IntelWLANEventProviderselect * from CIntelDot1xEventCIntelDot1xEvent//./ROOT/default Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)Description: IntelWLANEventProviderselect * from CIntelWLANEventCIntelWLANEvent//./ROOT/default Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)Description: select * from CIntelQosEventCIntelQosEvent//./ROOT/default Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)Description: select * from CIntelDot1xEventCIntelDot1xEvent//./ROOT/default Error: (03/12/2014 05:01:40 AM) (Source: Microsoft-Windows-WMI)(User: NT AUTHORITY)Description: select * from CIntelWLANEventCIntelWLANEvent//./ROOT/default Error: (03/11/2014 02:02:41 AM) (Source: Application Error)(User: )Description: LiveComm.exe16.4.4206.722500ca1a7ntdll.dll6.2.9200.1657951637f77c0000005000000000005ab0046c01cf3c83cd376da0C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exeC:\Windows\SYSTEM32\ntdll.dll2bd3670b-a87e-11e3-be75-6036dd6349a2microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbweMicrosoft.WindowsLive.Mail Those are FIRST utility logs. Link to post Share on other sites More sharing options...
Holistr Posted March 12, 2014 Author ID:802329 Share Posted March 12, 2014 GMER 2.1.19357 - http://www.gmer.netRootkit scan 2014-03-13 00:40:13Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002e TOSHIBA_MK5061GSY rev.MC102E 465.76GBRunning: gvo4tdpt.exe; Driver: C:\Users\Martin\AppData\Local\Temp\kgddipod.sys ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [600:3492] fffff960008ba4d0---- Processes - GMER 2.1 ---- Library c:\programdata\kaspersky lab\avp14.0.0\data\wlengine.dll (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000071b50000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\uds.dll.7d02d20a9bb6867c09459f116feac15d (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000071af0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\avengine.dll.415c3b227a91a9693ad5a51f07dbba9c (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000071a60000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\kavbase.kdl.361acbb95e4cd361dbc67699794434a5 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 00000000719d0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\klavemu.kdl.593e72e97caef5dd742b394bd296e21a (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000071370000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\kjim.kdl.bccfc1c89017f4bdc90201e956eea7c5 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 00000000710c0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\mark.kdl.1c449ad92726ed14d895f09dcd861545 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000071050000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\vlns.kdl.317df7c0eff0939e6289f5c72f65ba51 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000038200000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\qscan.kdl.3d47406245e32365413c5b6ab2246586 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000070f30000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\pbs.kdl.41dc267440bc79cb8c2216bd28f1f254 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000070da0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\metascan.kdl.14a21353e2a9e2e50d0dfb513315a104 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000070af0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\kavsys.kdl.ec4d28bde98d9e3c76bf58ef5ba0728d (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000070810000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\arkmon.kdl.b3a9361231847f8f76294be7a6a1406a (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 00000000707f0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\swmon.kdl.f77eca979387a121bcc982e5ad84c0fb (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 000000006f9e0000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\swmon_drv.kdl.f6a00390b7c91892a6168d415f56d96c (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 000000006f950000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\bsshlp2.kdl.904c718bbe32f92d8d0c4c679ec8a7ac (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 000000006f800000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\heurap.dll.443a9903a4015ce41f2c859208d4e4b6 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000063400000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\Cache\pdm.kdl.3e8b21cf357ecefe6529658c1ae62636 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000063370000Library C:\ProgramData\Kaspersky Lab\AVP14.0.0\Bases\sys_critical_obj.dll (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [1480] (FILE NOT FOUND) 0000000063310000Library C:\Program Files\WindowsApps\Microsoft.SkypeApp_2.0.0.5011_x86__kzf8qxf38zg5c\LibWrap.dll (*** suspicious ***) @ C:\WINDOWS\syswow64\wwahost.exe [5176] (Microsoft Skype/Microsoft Corporation)(2013-11-14 07:19:09) 0000000064e50000Library C:\Program Files\WindowsApps\Microsoft.SkypeApp_2.0.0.5011_x86__kzf8qxf38zg5c\Microsoft.PerfTrack.dll (*** suspicious ***) @ C:\WINDOWS\syswow64\wwahost.exe [5176] (Microsoft.PerfTrack.dll/Microsoft Corporation)(2013-11-14 07:19:09) 000000006b620000Library C:\Program Files\WindowsApps\Microsoft.SkypeApp_2.0.0.5011_x86__kzf8qxf38zg5c\MicrosoftAdvertising.dll (*** suspicious ***) @ C:\WINDOWS\syswow64\wwahost.exe [5176] (Microsoft Advertising Native SDK for Windows 8/Microsoft Corporation)(2013-11-14 07:19:09) 0000000064250000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Note: Since today started to occur strange behavior of my browser...I am not sure if it is caused by the virus or simply by running programs, though the browser seems to hang for a 5-10 seconds from time to time. Link to post Share on other sites More sharing options...
Psychotic Posted March 13, 2014 ID:802612 Share Posted March 13, 2014 CombofixCombofix should only be run when adviced by a team member!LinkImportant - Save the file to your desktop! Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work. Run Combofix.exeWhen finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this. Link to post Share on other sites More sharing options...
Holistr Posted March 13, 2014 Author ID:802724 Share Posted March 13, 2014 Combofix is not compatible with my OS - Win 8.1. Any other suggestions? H. Link to post Share on other sites More sharing options...
Psychotic Posted March 14, 2014 ID:802964 Share Posted March 14, 2014 I´m sorry! Scan with FRST in normal modePlease download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)Run FRST. Don´t change one of the checkboxes and hit Scan. Logfiles are created on your desktop. Poste the FRST.txt and (after the first scan only!) the Addition.txt. Link to post Share on other sites More sharing options...
Holistr Posted March 14, 2014 Author ID:802974 Share Posted March 14, 2014 Hello Psychotic, It is the same program I have been using in the first step. Sent you the files in one of my posts before. But sure I will do another scan. Anything to help me get rid of that infection. Considering FRST was already run once the addition.txt was not created and I can only send you the previous one.Here you have the FRST.txt Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2014Ran by Martin (administrator) on HOLISTR on 14-03-2014 16:47:04Running from C:\Users\Martin\DownloadsWindows 8.1 (X64) OS Language: English(US)Internet Explorer Version 11Boot Mode: Normal The only official download link for FRST:Download link for 32-Bit version: Download link for 64-Bit Version: Download link from any site other than Bleeping Computer is unpermitted or outdated.See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe(Alipay Inc. ) C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe(Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SAsrv.exe(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe(Microsoft Corporation) C:\Windows\System32\skydrive.exe(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe(Intel Corporation) C:\Windows\System32\igfxtray.exe(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe(Intel Corporation) C:\Windows\System32\hkcmd.exe(Intel Corporation) C:\Windows\System32\igfxpers.exe(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE(Microsoft Corporation) C:\Windows\System32\WWAHost.exe(Google Inc.) C:\Program Files (x86)\Google\Picasa3\Picasa3.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\POWERPNT.EXE(Microsoft Corporation) C:\WINDOWS\splwow64.exe(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\MSTORDB.EXE(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Microsoft Corporation) C:\WINDOWS\system32\wwahost.exe(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\LiveComm.exe(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Microsoft Corporation) C:\WINDOWS\system32\AUDIODG.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [intelWirelessWiMAX] - C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [1626112 2012-07-26] (Intel® Corporation)HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)HKLM\...\Run: [smartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()HKLM\...\Run: [LenovoOptMouseUpdate] - C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-08-31] (Lenovo Group Limited)HKLM-x32\...\Run: [iMSS] - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [134616 2013-05-14] (Intel Corporation)HKLM-x32\...\Run: [RotateImage] - C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [64000 2012-08-10] (Ricoh co.,Ltd.)HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnkShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)Tcpip\Parameters: [DhcpNameServer] 61.128.128.68 61.128.192.68Tcpip\..\Interfaces\{71B995F2-8017-4977-9F48-9D894D207EBF}: [NameServer]8.8.8.8 8.8.4.4 Chrome: =======CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-03]CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-03]CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-03]CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-03]CHR Extension: (Kaspersky URL Advisor) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-03-03]CHR Extension: (Safe Money) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-03-03]CHR Extension: (Dangerous Websites Blocker) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-03-03]CHR Extension: (Virtuální klávesnice) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-03-03]CHR Extension: (Peněženka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-03]CHR Extension: (Evernote Web Clipper) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-03-11]CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-03]CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-11-26]CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-11-26] ==================== Services (Whitelisted) ================= R2 AlipaySecSvc; C:\Program Files (x86)\alipay\alieditplus\AlipaySecSvc.exe [540032 2014-03-07] (Alipay Inc. )R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-11-26] (Kaspersky Lab ZAO)S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-11] (Intel® Corporation)R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-14] (Intel Corporation)R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-05-14] (Intel Corporation)S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-29] ()S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-03-12] (Microsoft Corporation)S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-12] (Microsoft Corporation)R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-29] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows ® Win 7 DDK provider)S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-31] (Intel Corporation)S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-26] (Intel Corporation)S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-03-12] (Microsoft Corporation)R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-26] (Kaspersky Lab ZAO)S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2013-11-26] (Kaspersky Lab)S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-03-03] (Kaspersky Lab ZAO)R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [624224 2014-03-03] (Kaspersky Lab ZAO)R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-11-26] (Kaspersky Lab ZAO)R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-03-03] (Kaspersky Lab ZAO)R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-11-26] (Kaspersky Lab ZAO)R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [64608 2013-11-26] (Kaspersky Lab ZAO)R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2014-03-03] (Kaspersky Lab ZAO)S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-09] (Intel Corporation)R3 RCUVCAVS; C:\Windows\system32\DRIVERS\RCUVCAVS.sys [148352 2012-08-23] (Ricoh co.,Ltd.)S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-03-12] (Microsoft Corporation)S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-03-12] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-14 16:20 - 2014-03-14 16:20 - 00122480 _____ () C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT2014-03-14 15:24 - 2014-03-14 15:25 - 17529160 _____ (Google Inc.) C:\Users\Martin\Downloads\picasa39-setup.exe2014-03-14 01:04 - 2014-03-14 01:05 - 05190279 _____ (Swearware) C:\Users\Martin\Downloads\ComboFix.exe2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\MSBuild2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio2014-03-14 00:00 - 2014-03-14 00:00 - 00000000 ____D () C:\WINDOWS\PCHEALTH2014-03-13 23:59 - 2014-03-13 23:59 - 00000000 ____D () C:\Program Files\Microsoft Office2014-03-13 23:58 - 2014-03-14 00:02 - 00000000 ____D () C:\ProgramData\Microsoft Help2014-03-13 23:58 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 __RHD () C:\MSOCache2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft Help2014-03-13 02:48 - 2014-03-13 02:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft_Corporation2014-03-13 02:34 - 2014-03-13 02:34 - 00000000 ____D () C:\Program Files (x86)\ffdshow2014-03-13 02:34 - 2010-01-27 00:08 - 00085504 _____ () C:\WINDOWS\SysWOW64\ff_vfw.dll2014-03-13 02:33 - 2014-03-13 02:33 - 00000000 ____D () C:\ProgramData\APN2014-03-13 02:29 - 2014-03-13 02:29 - 02030080 _____ () C:\Users\Martin\Downloads\ffdshow-20041012.exe2014-03-13 02:28 - 2014-03-13 02:28 - 00389440 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_for_ffdshow.exe2014-03-13 01:15 - 2014-03-13 01:15 - 00000000 ____D () C:\Program Files (x86)\Integrated Camera Driver2014-03-13 01:14 - 2012-08-23 11:09 - 00148352 _____ (Ricoh co.,Ltd.) C:\WINDOWS\system32\Drivers\RCUVCAVS.sys2014-03-13 01:14 - 2012-08-23 08:56 - 00304640 _____ (Ricoh co.,Ltd.) C:\WINDOWS\system32\RCUVCAVS.ax2014-03-13 01:14 - 2012-08-23 08:56 - 00269824 _____ (Ricoh co.,Ltd.) C:\WINDOWS\SysWOW64\RCUVCAVS.ax2014-03-13 01:14 - 2012-08-23 08:55 - 00119808 _____ (Ricoh co.,Ltd.) C:\WINDOWS\system32\RCUVCAVS.dll2014-03-13 01:14 - 2012-08-23 08:55 - 00100864 _____ (Ricoh co.,Ltd.) C:\WINDOWS\SysWOW64\RCUVCAVS.dll2014-03-13 00:42 - 2014-03-13 00:42 - 00017920 ___SH () C:\Users\Martin\Desktop\Thumbs.db2014-03-13 00:40 - 2014-03-13 00:40 - 00007232 _____ () C:\Users\Martin\Desktop\ark.txt2014-03-13 00:32 - 2014-03-14 16:47 - 00016253 _____ () C:\Users\Martin\Downloads\FRST.txt2014-03-13 00:32 - 2014-03-13 00:33 - 00023288 _____ () C:\Users\Martin\Downloads\Addition.txt2014-03-13 00:31 - 2014-03-14 16:47 - 00000000 ____D () C:\FRST2014-03-13 00:27 - 2014-03-13 00:28 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe2014-03-13 00:13 - 2014-03-13 01:14 - 00000000 ____D () C:\Program Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo2014-03-13 00:11 - 2012-08-09 16:31 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\WINDOWS\SysWOW64\CSVer.dll2014-03-13 00:07 - 2012-01-12 13:16 - 00002060 _____ () C:\WINDOWS\system32\Drivers\SamSfPa.dat2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v22014-03-13 00:06 - 2012-06-08 17:07 - 00201376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe2014-03-13 00:06 - 2011-01-07 12:28 - 00446592 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe2014-03-13 00:05 - 2012-08-31 19:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEP64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\EED64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEL64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEA64A.dll2014-03-13 00:05 - 2012-08-31 19:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEG64A.dll2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe2014-03-12 22:55 - 2014-03-13 22:36 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package2014-03-12 21:06 - 2014-03-13 22:32 - 00000000 __RDO () C:\Users\Martin\SkyDrive2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery2014-03-12 20:48 - 2014-03-12 15:00 - 00000000 ___DC () C:\WINDOWS\Panther2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff2014-03-12 16:22 - 2014-03-12 16:29 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini2014-03-12 05:02 - 2014-03-14 15:59 - 01748233 _____ () C:\WINDOWS\WindowsUpdate.log2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate2014-03-12 04:54 - 2014-03-12 21:06 - 00000000 ____D () C:\Users\Martin2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagwrn.xml2014-03-12 04:54 - 2014-03-12 05:01 - 00020958 _____ () C:\WINDOWS\diagerr.xml2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 04:54 - 2014-03-12 04:55 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories2014-03-12 04:54 - 2013-08-22 23:36 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance2014-03-12 04:51 - 2014-03-13 00:11 - 00000000 ____D () C:\Program Files (x86)\Intel2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics2014-03-12 04:51 - 2014-01-25 02:23 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL2014-03-12 04:51 - 2014-01-25 02:23 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL2014-03-12 04:50 - 2014-03-13 00:07 - 00000000 ____D () C:\Program Files\CONEXANT2014-03-12 04:50 - 2014-03-12 04:55 - 00000000 ____D () C:\Program Files\Intel2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay2014-03-12 04:11 - 2014-03-12 05:01 - 00006530 _____ () C:\WINDOWS\comsetup.log2014-03-12 04:07 - 2014-03-12 04:07 - 04550656 _____ (Google Inc.) C:\WINDOWS\SysWOW64\GPhotos.scr2014-03-12 01:05 - 2014-03-12 01:09 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe2014-03-12 01:01 - 2014-03-12 01:25 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity2014-03-12 00:52 - 2014-03-12 00:56 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe2014-03-11 22:31 - 2014-03-12 01:14 - 00000000 ____D () C:\Program Files (x86)\Audacity2014-03-11 22:22 - 2014-03-12 04:56 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit2014-03-11 22:22 - 2014-03-11 22:37 - 00000000 ____D () C:\Program Files (x86)\alipay2014-03-11 22:22 - 2014-03-11 22:25 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer2014-03-09 20:09 - 2014-03-09 20:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl2014-03-09 02:41 - 2014-03-12 23:56 - 00000000 ____D () C:\ProgramData\Conexant2014-03-09 02:40 - 2012-09-20 14:11 - 01609376 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\Drivers\CHDRT64.sys2014-03-09 02:40 - 2012-09-12 11:35 - 02535520 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll2014-03-09 02:40 - 2012-08-08 13:12 - 01780896 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64AP74.dll2014-03-09 02:40 - 2012-06-29 13:04 - 00050848 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxPageMaster64.dll2014-03-09 02:40 - 2012-03-20 03:48 - 00568960 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\UCI64A89.dll2014-03-09 02:40 - 2012-01-16 10:42 - 00666240 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\C3DHPExt64.dll2014-03-09 02:40 - 2011-01-18 11:35 - 00030893 _____ () C:\WINDOWS\system32\Drivers\Mixer.ini2014-03-09 02:33 - 2014-03-09 02:39 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe2014-03-09 01:48 - 2014-03-14 16:45 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype2014-03-09 01:48 - 2014-03-09 14:35 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk2014-03-09 01:48 - 2014-03-09 14:35 - 00000000 ____D () C:\ProgramData\Skype2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype2014-03-09 01:45 - 2014-03-09 01:47 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote2014-03-06 21:10 - 2014-03-06 21:15 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent2014-03-03 23:13 - 2014-03-12 22:56 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent2014-03-03 23:13 - 2009-02-18 14:51 - 00018760 _____ () C:\WINDOWS\SysWOW64\QQVistaHelper.dll2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk2014-03-03 22:23 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll2014-03-03 22:22 - 2014-03-14 07:18 - 00000000 ____D () C:\ProgramData\Kaspersky Lab2014-03-03 22:22 - 2014-03-03 22:46 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys2014-03-03 22:22 - 2014-03-03 22:45 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe2014-03-03 22:05 - 2014-03-03 22:06 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip2014-03-03 21:56 - 2014-03-14 16:01 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job2014-03-03 21:56 - 2014-03-13 22:32 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk2014-03-03 21:51 - 2014-03-03 22:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe2014-03-03 21:45 - 2014-03-03 22:16 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe2014-03-03 21:28 - 2014-03-14 15:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google2014-03-03 21:28 - 2014-03-14 15:29 - 00000000 ____D () C:\Program Files (x86)\Google2014-03-03 21:07 - 2014-03-03 21:53 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP2014-03-03 20:06 - 2014-03-03 22:07 - 00000000 ____D () C:\totalcmd2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER2014-03-03 20:02 - 2014-03-03 20:03 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia2014-03-03 19:36 - 2014-03-14 15:34 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-10012014-03-03 19:30 - 2014-03-12 22:57 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore2014-03-03 19:30 - 2014-03-12 15:01 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup2014-03-03 19:30 - 2014-03-12 15:00 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe Continues in next post Link to post Share on other sites More sharing options...
Holistr Posted March 14, 2014 Author ID:802979 Share Posted March 14, 2014 ==================== One Month Modified Files and Folders ======= 2014-03-14 16:47 - 2014-03-13 00:32 - 00016253 _____ () C:\Users\Martin\Downloads\FRST.txt2014-03-14 16:47 - 2014-03-13 00:31 - 00000000 ____D () C:\FRST2014-03-14 16:45 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype2014-03-14 16:20 - 2014-03-14 16:20 - 00122480 _____ () C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT2014-03-14 16:16 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\tracing2014-03-14 16:01 - 2014-03-03 21:56 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job2014-03-14 16:00 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\sru2014-03-14 15:59 - 2014-03-12 05:02 - 01748233 _____ () C:\WINDOWS\WindowsUpdate.log2014-03-14 15:34 - 2014-03-03 19:36 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1901417010-66602696-720837262-10012014-03-14 15:30 - 2014-03-03 21:28 - 00000000 ____D () C:\Users\Martin\AppData\Local\Google2014-03-14 15:29 - 2014-03-03 21:28 - 00000000 ____D () C:\Program Files (x86)\Google2014-03-14 15:25 - 2014-03-14 15:24 - 17529160 _____ (Google Inc.) C:\Users\Martin\Downloads\picasa39-setup.exe2014-03-14 07:18 - 2014-03-03 22:22 - 00000000 ____D () C:\ProgramData\Kaspersky Lab2014-03-14 01:16 - 2013-11-14 15:28 - 00818732 _____ () C:\WINDOWS\system32\PerfStringBackup.INI2014-03-14 01:13 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\AppReadiness2014-03-14 01:05 - 2014-03-14 01:04 - 05190279 _____ (Swearware) C:\Users\Martin\Downloads\ComboFix.exe2014-03-14 00:02 - 2014-03-13 23:58 - 00000000 ____D () C:\ProgramData\Microsoft Help2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\MSBuild2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works2014-03-14 00:01 - 2014-03-14 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio2014-03-14 00:01 - 2014-03-13 23:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office2014-03-14 00:00 - 2014-03-14 00:00 - 00000000 ____D () C:\WINDOWS\PCHEALTH2014-03-14 00:00 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared2014-03-13 23:59 - 2014-03-13 23:59 - 00000000 ____D () C:\Program Files\Microsoft Office2014-03-13 23:59 - 2013-11-14 15:17 - 00000000 ____D () C:\WINDOWS\ShellNew2014-03-13 23:59 - 2013-08-22 21:25 - 00000167 _____ () C:\WINDOWS\win.ini2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 __RHD () C:\MSOCache2014-03-13 23:58 - 2014-03-13 23:58 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft Help2014-03-13 22:46 - 2013-08-22 22:46 - 00287534 _____ () C:\WINDOWS\setupact.log2014-03-13 22:36 - 2014-03-12 22:55 - 00000000 ____D () C:\Users\Martin\Documents\Tencent Files2014-03-13 22:32 - 2014-03-12 21:06 - 00000000 __RDO () C:\Users\Martin\SkyDrive2014-03-13 22:32 - 2014-03-03 21:56 - 00000964 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job2014-03-13 02:48 - 2014-03-13 02:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Microsoft_Corporation2014-03-13 02:34 - 2014-03-13 02:34 - 00000000 ____D () C:\Program Files (x86)\ffdshow2014-03-13 02:33 - 2014-03-13 02:33 - 00000000 ____D () C:\ProgramData\APN2014-03-13 02:29 - 2014-03-13 02:29 - 02030080 _____ () C:\Users\Martin\Downloads\ffdshow-20041012.exe2014-03-13 02:28 - 2014-03-13 02:28 - 00389440 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_for_ffdshow.exe2014-03-13 01:31 - 2013-08-22 22:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT2014-03-13 01:27 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI2014-03-13 01:20 - 2013-11-14 15:20 - 00004550 _____ () C:\WINDOWS\PFRO.log2014-03-13 01:15 - 2014-03-13 01:15 - 00000000 ____D () C:\Program Files (x86)\Integrated Camera Driver2014-03-13 01:14 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Lenovo2014-03-13 01:14 - 2013-12-05 04:59 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information2014-03-13 01:14 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\restore2014-03-13 00:42 - 2014-03-13 00:42 - 00017920 ___SH () C:\Users\Martin\Desktop\Thumbs.db2014-03-13 00:40 - 2014-03-13 00:40 - 00007232 _____ () C:\Users\Martin\Desktop\ark.txt2014-03-13 00:33 - 2014-03-13 00:32 - 00023288 _____ () C:\Users\Martin\Downloads\Addition.txt2014-03-13 00:28 - 2014-03-13 00:27 - 02157056 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files\Common Files\Lenovo2014-03-13 00:13 - 2014-03-13 00:13 - 00000000 ____D () C:\Program Files (x86)\Lenovo2014-03-13 00:11 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files (x86)\Intel2014-03-13 00:07 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\CONEXANT2014-03-13 00:06 - 2014-03-13 00:06 - 00002998 _____ () C:\WINDOWS\System32\Tasks\Dolby Selector2014-03-13 00:06 - 2014-03-13 00:06 - 00000000 ____D () C:\Program Files (x86)\Dolby Advanced Audio v22014-03-12 23:56 - 2014-03-09 02:41 - 00000000 ____D () C:\ProgramData\Conexant2014-03-12 23:30 - 2014-03-12 23:30 - 00380416 _____ () C:\Users\Martin\Downloads\gvo4tdpt.exe2014-03-12 22:57 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\VirtualStore2014-03-12 22:56 - 2014-03-03 23:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Tencent2014-03-12 21:10 - 2014-03-12 21:10 - 00000000 ____D () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package2014-03-12 21:06 - 2014-03-12 04:54 - 00000000 ____D () C:\Users\Martin2014-03-12 20:48 - 2014-03-12 20:48 - 00000000 __SHD () C:\Recovery2014-03-12 20:47 - 2014-03-12 20:47 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll2014-03-12 20:47 - 2014-03-12 20:47 - 00000000 ____D () C:\Windows.old2014-03-12 20:47 - 2013-08-22 23:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template2014-03-12 20:46 - 2014-03-12 20:46 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll2014-03-12 20:46 - 2014-03-12 20:46 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll2014-03-12 20:46 - 2014-03-12 20:46 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll2014-03-12 20:46 - 2014-03-12 20:46 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys2014-03-12 20:46 - 2014-03-12 20:46 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb2014-03-12 20:46 - 2014-03-12 20:46 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll2014-03-12 20:46 - 2014-03-12 20:46 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl2014-03-12 20:46 - 2014-03-12 20:46 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi2014-03-12 20:46 - 2014-03-12 20:46 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe2014-03-12 20:46 - 2014-03-12 20:46 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll2014-03-12 20:46 - 2014-03-12 20:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe2014-03-12 20:46 - 2014-03-12 20:46 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll2014-03-12 20:46 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\WinStore2014-03-12 20:45 - 2014-03-12 20:45 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll2014-03-12 20:45 - 2014-03-12 20:45 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll2014-03-12 20:45 - 2014-03-12 20:45 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll2014-03-12 20:45 - 2014-03-12 20:45 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe2014-03-12 20:45 - 2014-03-12 20:45 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms2014-03-12 20:45 - 2014-03-12 20:45 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ___RD () C:\WINDOWS\ToastData2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\MediaViewer2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\FileManager2014-03-12 20:45 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Camera2014-03-12 20:44 - 2014-03-12 20:44 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll2014-03-12 20:44 - 2014-03-12 20:44 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll2014-03-12 20:44 - 2014-03-12 20:44 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll2014-03-12 20:44 - 2014-03-12 20:44 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS2014-03-12 20:44 - 2014-03-12 20:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe2014-03-12 20:44 - 2014-03-12 20:44 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys2014-03-12 20:44 - 2014-03-12 20:44 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll2014-03-12 20:44 - 2014-03-12 20:44 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files\Windows Defender2014-03-12 20:44 - 2013-08-22 23:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism2014-03-12 20:44 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Dism2014-03-12 20:43 - 2014-03-12 20:43 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe2014-03-12 20:43 - 2014-03-12 20:43 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll2014-03-12 20:43 - 2014-03-12 20:43 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys2014-03-12 20:43 - 2014-03-12 20:43 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe2014-03-12 20:43 - 2014-03-12 20:43 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml2014-03-12 20:43 - 2014-03-12 20:43 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00311640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys2014-03-12 20:43 - 2014-03-12 20:43 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE2014-03-12 20:43 - 2014-03-12 20:43 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll2014-03-12 20:43 - 2014-03-12 20:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll2014-03-12 20:42 - 2014-03-12 20:42 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll2014-03-12 20:42 - 2014-03-12 20:42 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll2014-03-12 20:42 - 2014-03-12 20:42 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys2014-03-12 20:42 - 2014-03-12 20:42 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll2014-03-12 20:42 - 2014-03-12 20:42 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys2014-03-12 20:42 - 2014-03-12 20:42 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS2014-03-12 20:42 - 2014-03-12 20:42 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll2014-03-12 20:42 - 2014-03-12 20:42 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe2014-03-12 20:42 - 2014-03-12 20:42 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll2014-03-12 20:41 - 2014-03-12 20:41 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe2014-03-12 20:41 - 2014-03-12 20:41 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi2014-03-12 20:41 - 2014-03-12 20:41 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe2014-03-12 20:41 - 2014-03-12 20:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys2014-03-12 20:41 - 2014-03-12 20:41 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll2014-03-12 20:41 - 2014-03-12 20:41 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll2014-03-12 20:40 - 2014-03-12 20:40 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff2014-03-12 16:29 - 2014-03-12 16:22 - 34082966 _____ () C:\Users\Martin\Downloads\Novicorp WinToFlash 0.8.0009 beta Portable.zip2014-03-12 15:02 - 2013-11-14 16:08 - 00000000 ___HD () C:\$Windows.~BT2014-03-12 15:01 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Local\Packages2014-03-12 15:00 - 2014-03-12 20:48 - 00000000 ___DC () C:\WINDOWS\Panther2014-03-12 15:00 - 2014-03-12 15:00 - 00001438 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup2014-03-12 15:00 - 2014-03-03 19:30 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools2014-03-12 14:59 - 2014-03-12 14:59 - 00000020 ___SH () C:\Users\Martin\ntuser.ini2014-03-12 05:03 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\rescache2014-03-12 05:02 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Registration2014-03-12 05:01 - 2014-03-12 05:01 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagwrn.xml2014-03-12 05:01 - 2014-03-12 04:54 - 00020958 _____ () C:\WINDOWS\diagerr.xml2014-03-12 05:01 - 2014-03-12 04:11 - 00006530 _____ () C:\WINDOWS\comsetup.log2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RSD () C:\WINDOWS\Media2014-03-12 04:59 - 2013-08-22 23:36 - 00000000 __RHD () C:\Users\Public\Libraries2014-03-12 04:57 - 2013-08-22 22:44 - 00335784 _____ () C:\WINDOWS\system32\FNTCACHE.DAT2014-03-12 04:56 - 2014-03-11 22:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\aliedit2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep2014-03-12 04:56 - 2013-11-14 15:14 - 00000000 ____D () C:\WINDOWS\system32\WCN2014-03-12 04:56 - 2013-08-22 23:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\spool2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\NDF2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\MUI2014-03-12 04:56 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\IME2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI2014-03-12 04:56 - 2013-08-22 21:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep2014-03-12 04:56 - 2013-08-22 21:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM2014-03-12 04:56 - 2012-07-26 13:37 - 00000000 ____D () C:\Users\Default.migrated2014-03-12 04:55 - 2014-03-12 04:55 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools2014-03-12 04:55 - 2014-03-12 04:54 - 00000000 ___RD () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility2014-03-12 04:55 - 2014-03-12 04:50 - 00000000 ____D () C:\Program Files\Intel2014-03-12 04:55 - 2013-12-05 04:55 - 00000000 ____D () C:\ProgramData\PRICache2014-03-12 04:55 - 2013-08-22 23:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery2014-03-12 04:55 - 2013-08-22 23:36 - 00000000 ____D () C:\WINDOWS\Help2014-03-12 04:51 - 2014-03-12 04:51 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf2014-03-12 04:51 - 2014-03-12 04:51 - 00000000 ____D () C:\Program Files\Synaptics2014-03-12 04:51 - 2013-08-22 22:46 - 00000084 _____ () C:\WINDOWS\setuperr.log2014-03-12 04:49 - 2013-08-22 21:36 - 00000000 __RHD () C:\Users\Default2014-03-12 04:31 - 2013-12-05 05:07 - 01679981 _____ () C:\WINDOWS\WindowsUpdate (1).log2014-03-12 04:30 - 2014-03-12 04:30 - 00000000 ____D () C:\alipay2014-03-12 04:30 - 2012-07-26 16:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent2014-03-12 04:07 - 2014-03-12 04:07 - 04550656 _____ (Google Inc.) C:\WINDOWS\SysWOW64\GPhotos.scr2014-03-12 02:06 - 2013-12-05 05:00 - 00000000 ____D () C:\WINDOWS\SysWOW64\sda2014-03-12 01:25 - 2014-03-12 01:01 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Audacity2014-03-12 01:14 - 2014-03-11 22:31 - 00000000 ____D () C:\Program Files (x86)\Audacity2014-03-12 01:09 - 2014-03-12 01:05 - 22180353 _____ (Audacity Team ) C:\Users\Martin\Downloads\audacity-win-2.0.5.exe2014-03-12 00:56 - 2014-03-12 00:52 - 11236618 _____ () C:\Users\Martin\Downloads\lenovo_thinkpad_edge_e530_windows_8_x64_drivers_full_package.zip2014-03-12 00:45 - 2014-03-12 00:45 - 00000000 ____D () C:\Users\Martin\AppData\Local\alipay2014-03-11 22:39 - 2014-03-11 22:39 - 00987442 _____ () C:\Users\Martin\Downloads\SecurityCheck.exe2014-03-11 22:37 - 2014-03-11 22:22 - 00000000 ____D () C:\Program Files (x86)\alipay2014-03-11 22:25 - 2014-03-11 22:22 - 00001078 _____ () C:\Users\Martin\AppData\Roaming\base64.cer2014-03-09 20:13 - 2014-03-09 20:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Crystal Player2014-03-09 20:09 - 2014-03-09 20:09 - 00000000 ____D () C:\Program Files (x86)\Crystal Player2014-03-09 20:08 - 2014-03-09 20:08 - 04166950 _____ () C:\Users\Martin\Downloads\CrystalPro.exe2014-03-09 17:16 - 2014-03-09 17:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf2014-03-09 17:06 - 2014-03-09 17:06 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf2014-03-09 14:35 - 2014-03-09 01:48 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk2014-03-09 14:35 - 2014-03-09 01:48 - 00000000 ____D () C:\ProgramData\Skype2014-03-09 13:59 - 2013-12-05 05:01 - 00000000 ____D () C:\Intel2014-03-09 03:33 - 2014-03-09 03:33 - 00000000 ____D () C:\Users\Martin\AppData\Local\Conexant2014-03-09 02:42 - 2014-03-09 02:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl2014-03-09 02:39 - 2014-03-09 02:33 - 86614568 _____ (Lenovo Group Limited ) C:\Users\Martin\Downloads\h0ac09ww.exe2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ___RD () C:\Program Files (x86)\Skype2014-03-09 01:48 - 2014-03-09 01:48 - 00000000 ____D () C:\Users\Martin\AppData\Local\Skype2014-03-09 01:47 - 2014-03-09 01:45 - 34820256 _____ (Skype Technologies S.A.) C:\Users\Martin\Downloads\SkypeSetupFull.exe2014-03-06 21:19 - 2014-03-06 21:19 - 00000000 ____D () C:\Users\Martin\AppData\Local\Evernote2014-03-06 21:18 - 2014-03-06 21:18 - 00000000 ____D () C:\Program Files (x86)\Evernote2014-03-06 21:15 - 2014-03-06 21:10 - 83157856 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Martin\Downloads\Evernote_5.2.0.2946.exe2014-03-04 18:47 - 2014-03-04 18:47 - 00000000 _____ () C:\Users\Martin\agent.log2014-03-04 03:04 - 2014-01-07 03:35 - 00000000 ____D () C:\WINDOWS\system32\MRT2014-03-03 23:14 - 2014-03-03 23:14 - 00002049 _____ () C:\Users\Public\Desktop\Tencent QQ.lnk2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Users\Public\Documents\Tencent2014-03-03 23:14 - 2014-03-03 23:14 - 00000000 ____D () C:\Program Files (x86)\Tencent2014-03-03 22:46 - 2014-03-03 22:22 - 00624224 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys2014-03-03 22:46 - 2013-11-26 04:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys2014-03-03 22:46 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys2014-03-03 22:45 - 2014-03-03 22:22 - 00115296 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys2014-03-03 22:38 - 2014-03-03 22:38 - 00001321 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security.lnk2014-03-03 22:22 - 2014-03-03 22:22 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab2014-03-03 22:22 - 2012-07-26 16:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP2014-03-03 22:16 - 2014-03-03 21:45 - 232061760 _____ (Kaspersky Lab) C:\Users\Martin\Downloads\kis14.0.0.4651en_5449_trial.exe2014-03-03 22:09 - 2014-03-03 22:09 - 00000000 ____D () C:\Users\Martin\AppData\Local\GHISLER2014-03-03 22:08 - 2014-03-03 21:51 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-1-75-0-1300.exe2014-03-03 22:07 - 2014-03-03 20:06 - 00000000 ____D () C:\totalcmd2014-03-03 22:06 - 2014-03-03 22:06 - 00065232 _____ (Malwarebytes) C:\Users\Martin\Downloads\regassassin-setup-1.03.exe2014-03-03 22:06 - 2014-03-03 22:05 - 01440846 _____ () C:\Users\Martin\Downloads\mbam-chameleon-1.62.1.1000.zip2014-03-03 21:56 - 2014-03-03 21:56 - 00003940 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA2014-03-03 21:56 - 2014-03-03 21:56 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore2014-03-03 21:53 - 2014-03-03 21:07 - 414810493 _____ () C:\Users\Martin\Downloads\NORSKO.ZIP2014-03-03 21:52 - 2014-03-03 21:52 - 00000291 _____ () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer.lnk2014-03-03 21:47 - 2014-03-03 21:47 - 00733432 _____ () C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe2014-03-03 20:06 - 2014-03-03 20:06 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\GHISLER2014-03-03 20:03 - 2014-03-03 20:02 - 04605952 _____ (Ghisler Software GmbH) C:\Users\Martin\Downloads\tcm850x64.exe2014-03-03 19:40 - 2014-03-03 19:40 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Macromedia2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Intel2014-03-03 19:30 - 2014-03-03 19:30 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Adobe Some content of TEMP:====================C:\Users\Martin\AppData\Local\Temp\KUIU.EXEC:\Users\Martin\AppData\Local\Temp\ose00000.exeC:\Users\Martin\AppData\Local\Temp\qqsafeud.exeC:\Users\Martin\AppData\Local\Temp\SCC.dllC:\Users\Martin\AppData\Local\Temp\SymCCIS.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legitC:\Windows\System32\wininit.exe => MD5 is legitC:\Windows\explorer.exe => MD5 is legitC:\Windows\SysWOW64\explorer.exe => MD5 is legitC:\Windows\System32\svchost.exe => MD5 is legitC:\Windows\SysWOW64\svchost.exe => MD5 is legitC:\Windows\System32\services.exe => MD5 is legitC:\Windows\System32\User32.dll => MD5 is legitC:\Windows\SysWOW64\User32.dll => MD5 is legitC:\Windows\System32\userinit.exe => MD5 is legitC:\Windows\SysWOW64\userinit.exe => MD5 is legitC:\Windows\System32\rpcss.dll => MD5 is legitC:\Windows\System32\Drivers\volsnap.sys[2014-03-12 20:43] - [2014-03-12 20:43] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02 LastRegBack: 2014-03-12 04:49 ==================== End Of Log ============================ Link to post Share on other sites More sharing options...
Psychotic Posted March 15, 2014 ID:803422 Share Posted March 15, 2014 Delete junk with adwCleanerPlease download AdwCleaner to your desktop.Run adwcleaner.exe Hit Scan and wait for the scan to finish. Confirm the message but don´t uncheck anything. Hit Clean When the run is finished, it will open up a text file Please post its contents within your next reply You´ll find the log file at C:\AdwCleaner[s1].txt also Delete junk with JRT Please download Junkware Removal Tool to your desktop. Shut down your protection software now to avoid potential conflicts. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator". The tool will open and start scanning your system. Please be patient as this can take a while to complete depending on your system's specifications. On completion, a log (JRT.txt) is saved to your desktop and will automatically open. Post the contents of JRT.txt into your next message. Full System Scan with Malwarebytes AntimalwareIf not existing, please download Malwarebytes' Anti-Malware to your desktop. Double-click mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.If the program is already installed:Run Malwarebytes Antimalware If an update is found, it will download and install the latest version. Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan. When the scan is complete, click OK, then Show Results to view the results. Be sure that everything is checked, and click Remove Selected. When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here:C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt Post that log back here. Scan with ESET Online ScanPlease go to here to run the online scannner from ESET. Turn off the real time scanner of any existing antivirus program while performing the online scanTick the box next to YES, I accept the Terms of Use.Click StartWhen asked, allow the activex control to installClick StartMake sure that the option Remove found threats is unticked Click on Advanced Settings and ensure these options are ticked:Scan for potentially unwanted applicationsScan for potentially unsafe applicationsEnable Anti-Stealth Technology[*]Click Scan[*]Wait for the scan to finish[*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic. Link to post Share on other sites More sharing options...
Holistr Posted March 16, 2014 Author ID:803678 Share Posted March 16, 2014 Hey Psychotic, I run all the programs you asked for and sending the results. Since The time we started I did not experienced the pop-ups again. Just Chrome seems to acting really strange(hanging, not displaying pages, starts really slow) and I am forced to use IE for some of the utilities downloads. I plan to uninstall it and use FF instead...I wanted to give it a try since friends told me it is really good and fast...not for me it seems:-( ADW cleaner# AdwCleaner v3.022 - Report created 16/03/2014 at 01:14:01# Updated 13/03/2014 by Xplode# Operating System : Windows 8.1 (64 bits)# Username : Martin - HOLISTR# Running from : C:\Users\Martin\Downloads\adwcleaner.exe# Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\apnFolder Deleted : C:\Program Files (x86)\TencentFolder Deleted : C:\Program Files (x86)\Common Files\TencentFolder Deleted : C:\Users\Martin\AppData\Local\Temp\TencentFolder Deleted : C:\Users\Martin\AppData\Roaming\TencentFile Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\SoftonicKey Deleted : HKCU\Software\TENCENTKey Deleted : HKLM\Software\InstallIQKey Deleted : HKLM\Software\TENCENT ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Google Chrome v33.0.1750.146 [ File : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1293 octets] - [16/03/2014 01:10:41]AdwCleaner[s0].txt - [1161 octets] - [16/03/2014 01:14:01] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [1221 octets] ########## JRTlog~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by ThisisuVersion: 6.1.2 (02.20.2014:1)OS: Windows 8.1 x64Ran by Martin on ?? 2014/03/16 at 1:21:02.41~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Scan was completed on ?? 2014/03/16 at 1:25:17.93End of JRT log~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Link to post Share on other sites More sharing options...
Holistr Posted March 16, 2014 Author ID:803679 Share Posted March 16, 2014 MWBlog I run this test 3 times since forgot to delete the first 2 entries during first and second run. Hope that it is not a big deal. Eventually all were removed and MWB demanded restart. Malwarebytes Anti-Malware (Trial) 1.75.0.1300www.malwarebytes.org Database version: v2014.03.15.04 Windows 8 x64 NTFSInternet Explorer 11.0.9600.16518Martin :: HOLISTR [administrator] Protection: Enabled 2014/3/16 1:30:44mbam-log-2014-03-16 (01-30-44).txt Scan type: Full scan (C:\|D:\|E:\|H:\|)Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 345172Time elapsed: 40 minute(s), 17 second(s) Memory Processes Detected: 0(No malicious items detected) Memory Modules Detected: 0(No malicious items detected) Registry Keys Detected: 0(No malicious items detected) Registry Values Detected: 0(No malicious items detected) Registry Data Items Detected: 0(No malicious items detected) Folders Detected: 0(No malicious items detected) Files Detected: 3C:\$Recycle.Bin\S-1-5-21-1901417010-66602696-720837262-1001\$RJIR73L.exe (PUP.Optional.InstallIQ.A) -> No action taken.C:\Users\Martin\Downloads\SoftonicDownloader_for_ffdshow.exe (PUP.Optional.Softonic.A) -> No action taken.E:\System Volume Information\_restore{1524574E-B2D5-4DFD-BFBD-2A40EE3C71B2}\RP208\A0034729.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. (end) ESETonline log C:\Users\Martin\Downloads\chrome-lista-centrumcz-pro-internet-explorer.exe Win32/CentrumDownloader.A potentially unwanted application Link to post Share on other sites More sharing options...
Psychotic Posted March 17, 2014 ID:804121 Share Posted March 17, 2014 SecurityCheckPlease download SecurityCheck: LINK1 LINK2 Save it to your desktop, start it and follow the instructions in the window. After the scan finished the (checkup.txt) will open. Copy its content to your thread. Link to post Share on other sites More sharing options...
Holistr Posted March 17, 2014 Author ID:804172 Share Posted March 17, 2014 Results of screen317's Security Check version 0.99.80 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! Kaspersky Internet Security Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware version 1.75.0.1300 Google Chrome 33.0.1750.146 Google Chrome 33.0.1750.154 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` One More think Psychotic. I live in China and I use QQInternational as communication client. After all the steps we performed I am missing this application on my system. Maybe it was deleted as a potentially unwanted program by one of the utilities, though it is essential for me to communicate in here.Do you recommend to install it again now or should I wait till we finish the current steps? Thanks for help so far. H Link to post Share on other sites More sharing options...
Psychotic Posted March 17, 2014 ID:804183 Share Posted March 17, 2014 Feel free to reinstall the software from the original developer´s site. Your system is clean now! Uninstall our tools using delfixPlease follow these steps in order: In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed. In any case please download delfix to your desktop. Close all other programms and start delfix. Please check all the boxes and run the tool. delfix will now delete all found traces of our removal process [*] If there is still something left please delete it manualy. Recommendations: How to protect yourselfSystem UpdatesPlease ensure to have automatic updates activated in your control panel.For further information and a tutorial, see this Microsoft Support article. ProtectionWhat you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.To keep your browser free of advertising, you may install the Adblock Plus browser extension.It will filter unwanted advertising out of the website´s content. To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.In addition, before accessing a dangerous classified web site, a warning screen is displayed. [*]Up to date SoftwareKeep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:Secunia Personal Software Inspector - checks if your software has updates available. SecurityCheck (by screen317) - scans your computer for most vulnerable outdated software. Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins running in your Firefox browser. [*]BackupHardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system. [*]BehaviourThe commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help if you aren´t careful enough.While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware. Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything. When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system. Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Link to post Share on other sites More sharing options...
Holistr Posted March 18, 2014 Author ID:804551 Share Posted March 18, 2014 Hello Psychotic, thanks a lot for your help. Error 80 is usually caused cause of the user impatience and laziness. I was wondering if you could explain a bit what was wrong in my browser or where I could get that fast any infection. Or was it just minor slip and nothing really serious, really can not recall anything wrong I did. I always use one AV plus free version of one of the antimalware tools. Peace H. Link to post Share on other sites More sharing options...
Psychotic Posted March 18, 2014 ID:804568 Share Posted March 18, 2014 Some free software offers contain additional software that has nothing to do with the program itself but is installed as well.Most of these so called PUPs (Potentially Unwanted Program) are little toolbars or extensions that inject itselfs into your browsers, mining behaviour data or something like that. These additional functions are loaded when starting up the brwoser - what causes this procedure to take more time from now on. Some PUPs change your default search engine to offer different search results, directing you to more software products. These were just a few examples - some of these programs were installed on your computer. We´ve cleaned them out and now everything is like before. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted March 19, 2014 Root Admin ID:805220 Share Posted March 19, 2014 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts