Jump to content

Build Theme!
  •  
  • Infected?

big grin WE'RE SURE THAT YOU'LL LOVE US!

We invite you to ask questions, share experiences, and learn. It's 100% free. Did we mention that it's free. It is. It's free. Join 91521 other members! Anybody can ask, anybody can answer. Consistently helpful members with best answers are invited to staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Rootkit Infection [Solved]


  • This topic is locked This topic is locked
16 replies to this topic

#1 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 13 November 2013 - 10:12 PM

Hello Everyone,

 

Today November 13, 2013 I was working on my computer and everything was fin until I uninstalled Microsoft Office 2013 Professional Plus and rebooted. Once reboot Avast popup stating it has detected a rootkit. Somewhere in C:\ProgramFles if my memory serves me right. I deleted the rootkit Avast detected and did a boot scan. The scan turned up empty. Yet, I am still woried. That is why I am here. Here are the OTL.txt and Extras.txt

 

OTL logfile created on: 11/13/2013 10:20:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Anna\Desktop
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16438)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.47 Gb Total Physical Memory | 1.99 Gb Available Physical Memory | 57.29% Memory free
4.10 Gb Paging File | 1.82 Gb Available in Paging File | 44.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.00 Gb Total Space | 401.63 Gb Free Space | 90.46% Space Free | Partition Type: NTFS
Drive D: | 19.95 Gb Total Space | 2.46 Gb Free Space | 12.32% Space Free | Partition Type: NTFS
Drive G: | 232.83 Gb Total Space | 232.31 Gb Free Space | 99.78% Space Free | Partition Type: FAT32
 
Computer Name: ANNAPERSONALPC | User Name: Anna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Anna\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXE (Oracle Corporation)
PRC - c:\oraclexe\app\oracle\product\11.2.0\server\bin\oracle.exe (Oracle Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files\AVAST Software\Avast\libcef.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:64bit: - (IEEtwCollectorService) -- C:\WINDOWS\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (EpsonCustomerParticipation) -- C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV:64bit: - (EpsonScanSvc) -- C:\Windows\SysNative\escsvc64.exe (Seiko Epson Corporation)
SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
SRV - (PrintNotify) -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (TinyWall) -- C:\Program Files (x86)\TinyWall\TinyWall.exe (Károly Pados)
SRV - (HPConnectedRemote) -- c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe (Hewlett-Packard)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPRegistrationSvc) -- c:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HPRegistrationService.exe (Hewlett-Packard)
SRV - (OracleXEClrAgent) -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe (Oracle Corporation)
SRV - (OracleXETNSListener) -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXE (Oracle Corporation)
SRV - (OracleMTSRecoveryService) -- C:\oraclexe\app\oracle\product\11.2.0\server\BIN\omtsreco.exe (Oracle Corporation)
SRV - (OracleJobSchedulerXE) -- c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe ()
SRV - (OracleServiceXE) -- c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE (Oracle Corporation)
SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswsp.sys (AVAST Software)
DRV:64bit: - (aswVmm) -- C:\WINDOWS\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswRvrt) -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:64bit: - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
DRV:64bit: - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:64bit: - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (ReFS) -- C:\WINDOWS\SysNative\drivers\refs.sys (Microsoft Corporation)
DRV:64bit: - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:64bit: - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
DRV:64bit: - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:64bit: - (RTL8168) -- C:\Windows\SysNative\drivers\Rt630x64.sys (Realtek                                            )
DRV:64bit: - (AODDriver4.2) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...0TR&pc=HPDTDFJS
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{34DC9E98-373F-4B8E-9386-6AF33F502E3C}: "URL" = http://www.amazon.co...s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...54371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...0TR&pc=HPDTDFJS
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
IE - HKLM\..\SearchScopes\{34DC9E98-373F-4B8E-9386-6AF33F502E3C}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...54371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {1F1249A4-1DD1-4AA8-852A-B05F1216A713}
IE - HKCU\..\SearchScopes\{1F1249A4-1DD1-4AA8-852A-B05F1216A713}: "URL" = http://www.google.co...utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
 
 
 
O1 HOSTS File: ([2013/07/08 07:35:00 | 000,567,880 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1  localhost
O1 - Hosts: ::1  localhost #[IPv6]
O1 - Hosts: 127.0.0.1  fr.a2dfp.net
O1 - Hosts: 127.0.0.1  m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1  ad.a8.net
O1 - Hosts: 127.0.0.1  asy.a8ww.net
O1 - Hosts: 127.0.0.1  abcstats.com
O1 - Hosts: 127.0.0.1  a.abv.bg
O1 - Hosts: 127.0.0.1  adserver.abv.bg
O1 - Hosts: 127.0.0.1  adv.abv.bg
O1 - Hosts: 127.0.0.1  bimg.abv.bg
O1 - Hosts: 127.0.0.1  ca.abv.bg
O1 - Hosts: 127.0.0.1  www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1  track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1  accuserveadsystem.com
O1 - Hosts: 127.0.0.1  www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1  achmedia.com
O1 - Hosts: 127.0.0.1  csh.actiondesk.com
O1 - Hosts: 127.0.0.1  www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1  ads.activepower.net
O1 - Hosts: 127.0.0.1  stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1  cms.ad2click.nl
O1 - Hosts: 127.0.0.1  ad2games.com
O1 - Hosts: 127.0.0.1  ads.ad2games.com
O1 - Hosts: 127.0.0.1  content.ad20.net
O1 - Hosts: 15455 more lines...
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\WINDOWS\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [TinyWall Controller] C:\Program Files (x86)\TinyWall\TinyWall.exe (Károly Pados)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" File not found
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIIBE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-400 Series" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105 File not found
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: devry.edu ([lab] https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{365D606D-DF18-4FF0-A21C-F2A90B8C80DD}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/08 09:59:46 | 000,000,000 | ---D | M] - G:\autorun -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs:64bit: lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
 
 CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/11/13 22:16:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Anna\Desktop\OTL.exe
[2013/11/13 20:50:08 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/11/13 14:35:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Belarc
[2013/11/13 10:59:04 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\LibreOffice
[2013/11/12 16:04:01 | 003,395,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSService.dll
[2013/11/12 16:03:58 | 006,639,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2013/11/12 16:03:56 | 007,399,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2013/11/12 16:03:56 | 005,769,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2013/11/12 16:03:55 | 002,570,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2013/11/12 16:03:54 | 004,104,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2013/11/12 16:03:53 | 002,617,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2013/11/12 16:03:53 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2013/11/12 16:03:52 | 002,295,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2013/11/12 16:03:52 | 001,231,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2013/11/12 16:03:52 | 001,147,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2013/11/12 16:03:51 | 002,328,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2013/11/12 16:03:51 | 002,065,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2013/11/12 16:03:51 | 001,584,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2013/11/12 16:03:50 | 001,765,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2013/11/12 16:03:50 | 001,067,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfasfsrcsnk.dll
[2013/11/12 16:03:50 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAutomationCore.dll
[2013/11/12 16:03:50 | 000,888,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2013/11/12 16:03:49 | 000,883,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfasfsrcsnk.dll
[2013/11/12 16:03:49 | 000,839,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2013/11/12 16:03:49 | 000,700,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2013/11/12 16:03:49 | 000,481,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2013/11/12 16:03:48 | 004,599,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d2d1.dll
[2013/11/12 16:03:48 | 002,134,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2013/11/12 16:03:48 | 001,287,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kernel32.dll
[2013/11/12 16:03:48 | 001,160,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Web.Http.dll
[2013/11/12 16:03:48 | 000,699,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10level9.dll
[2013/11/12 16:03:48 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.BackgroundTransfer.dll
[2013/11/12 16:03:48 | 000,380,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2013/11/12 16:03:47 | 001,399,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2013/11/12 16:03:47 | 001,373,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2013/11/12 16:03:47 | 001,011,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TSWorkspace.dll
[2013/11/12 16:03:47 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Web.Http.dll
[2013/11/12 16:03:47 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.BackgroundTransfer.dll
[2013/11/12 16:03:46 | 001,204,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2013/11/12 16:03:46 | 000,761,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2013/11/12 16:03:46 | 000,708,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iuilp.dll
[2013/11/12 16:03:46 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2013/11/12 16:03:46 | 000,631,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe
[2013/11/12 16:03:46 | 000,533,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppReadiness.dll
[2013/11/12 16:03:46 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eapphost.dll
[2013/11/12 16:03:45 | 000,795,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TSWorkspace.dll
[2013/11/12 16:03:45 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2013/11/12 16:03:45 | 000,558,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\apphelp.dll
[2013/11/12 16:03:45 | 000,518,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe
[2013/11/12 16:03:45 | 000,465,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2013/11/12 16:03:45 | 000,391,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tsmf.dll
[2013/11/12 16:03:45 | 000,345,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tsmf.dll
[2013/11/12 16:03:45 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eapp3hst.dll
[2013/11/12 16:03:45 | 000,317,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2013/11/12 16:03:45 | 000,171,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kd_02_8086.dll
[2013/11/12 16:03:45 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2013/11/12 16:03:45 | 000,031,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ploptin.dll
[2013/11/12 16:03:44 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\samsrv.dll
[2013/11/12 16:03:44 | 000,371,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2013/11/12 16:03:44 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll
[2013/11/12 16:03:44 | 000,262,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eapphost.dll
[2013/11/12 16:03:44 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msched.dll
[2013/11/12 16:03:44 | 000,104,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2013/11/12 16:03:44 | 000,088,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2013/11/12 16:03:44 | 000,044,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wldp.dll
[2013/11/12 16:03:43 | 001,843,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Display.dll
[2013/11/12 16:03:43 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2013/11/12 16:03:43 | 000,325,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2013/11/12 16:03:43 | 000,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWfdProvider.dll
[2013/11/12 16:03:43 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shsetup.dll
[2013/11/12 16:03:43 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafBth.dll
[2013/11/12 16:03:43 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TSWbPrxy.exe
[2013/11/12 16:03:43 | 000,057,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2013/11/12 16:03:43 | 000,054,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2013/11/12 16:03:43 | 000,039,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\intelpep.sys
[2013/11/12 16:03:42 | 001,816,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Display.dll
[2013/11/12 16:03:42 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eappcfg.dll
[2013/11/12 16:03:42 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2013/11/12 16:03:42 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\shsetup.dll
[2013/11/12 16:03:41 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2013/11/12 16:03:41 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2013/11/12 16:03:41 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eappcfg.dll
[2013/11/12 16:03:41 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eapp3hst.dll
[2013/11/12 16:03:41 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WiFiDisplay.dll
[2013/11/12 16:03:41 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eappgnui.dll
[2013/11/12 16:03:41 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eappgnui.dll
[2013/11/12 16:03:40 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2013/11/12 16:03:40 | 001,704,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2013/11/12 16:03:40 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2013/11/12 16:03:40 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersShell.dll
[2013/11/12 16:03:40 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ftp.exe
[2013/11/12 16:03:38 | 000,338,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2013/11/12 16:03:38 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2013/11/12 16:03:38 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2013/11/12 16:03:37 | 000,909,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2013/11/12 16:03:37 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2013/11/12 16:03:37 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\miutils.dll
[2013/11/12 16:03:37 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\miutils.dll
[2013/11/12 16:03:37 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ftp.exe
[2013/11/12 16:03:13 | 002,801,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2013/11/12 16:03:13 | 001,085,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2013/11/12 16:03:13 | 000,869,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2013/11/12 16:03:10 | 018,577,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2013/11/12 16:03:08 | 013,925,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2013/11/12 16:03:07 | 013,176,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2013/11/12 16:03:06 | 011,674,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2013/11/12 16:03:05 | 001,341,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2013/11/12 16:03:04 | 001,302,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2013/11/12 16:03:04 | 000,922,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2013/11/12 16:03:04 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2013/11/12 16:03:04 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2013/11/12 16:03:04 | 000,136,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wfplwfs.sys
[2013/11/12 16:02:52 | 001,943,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\crypt32.dll
[2013/11/12 15:24:46 | 000,312,744 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysNative\javaws.exe
[2013/11/12 15:24:43 | 000,189,352 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysNative\javaw.exe
[2013/11/12 15:24:43 | 000,189,352 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysNative\java.exe
[2013/11/12 15:24:43 | 000,108,968 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysNative\WindowsAccessBridge-64.dll
[2013/11/12 15:24:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
[2013/11/12 15:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013/11/12 09:18:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013/11/12 09:18:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/11/12 09:18:32 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2013/11/12 09:18:29 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2013/11/12 09:18:29 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2013/11/12 09:18:29 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2013/11/12 09:18:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/11/12 09:18:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013/11/07 08:57:26 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\NetBeans
[2013/11/07 08:57:25 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\NetBeans
[2013/11/02 15:38:47 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\Citrix
[2013/11/02 10:27:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013/11/02 10:26:47 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2013/11/02 07:21:07 | 000,000,000 | ---D | C] -- C:\Users\Anna\Oracle
[2013/11/02 07:20:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle Database 11g Express Edition
[2013/11/02 07:19:58 | 000,000,000 | ---D | C] -- C:\oraclexe
[2013/11/02 04:36:09 | 000,000,000 | ---D | C] -- C:\Users\Anna\Documents\Eclipse Project
[2013/11/02 04:34:29 | 000,000,000 | ---D | C] -- C:\Program Files\eclipse
[2013/10/31 06:51:30 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\Media Player Classic
[2013/10/31 06:48:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
[2013/10/31 06:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\MPC-HC
[2013/10/30 10:51:01 | 000,000,000 | ---D | C] -- C:\Users\Anna\.eclipse
[2013/10/30 10:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBeans
[2013/10/30 10:30:03 | 000,000,000 | ---D | C] -- C:\Program Files\NetBeans 7.4
[2013/10/30 10:29:32 | 000,000,000 | ---D | C] -- C:\Users\Anna\.nbi
[2013/10/29 08:05:46 | 000,872,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2013/10/29 08:05:45 | 000,698,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2013/10/26 06:58:28 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\TinyWall
[2013/10/26 06:57:26 | 000,000,000 | ---D | C] -- C:\ProgramData\TinyWall
[2013/10/26 06:57:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TinyWall
[2013/10/26 06:57:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TinyWall
[2013/10/24 18:47:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2013/10/24 10:29:55 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013/10/24 10:29:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2013/10/24 10:28:35 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.dll
[2013/10/24 10:28:35 | 000,977,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Streaming.dll
[2013/10/24 10:28:34 | 002,140,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2013/10/24 10:28:34 | 001,765,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2013/10/24 10:28:34 | 001,286,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctf.dll
[2013/10/24 10:28:34 | 000,516,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2013/10/24 10:28:34 | 000,382,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2013/10/24 10:28:34 | 000,294,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2013/10/24 10:28:34 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2013/10/24 10:26:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2013/10/24 10:26:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2013/10/24 10:26:13 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2013/10/24 10:26:13 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2013/10/24 10:25:23 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2013/10/24 10:25:23 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2013/10/24 10:25:22 | 000,778,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
[2013/10/24 10:25:21 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2013/10/24 10:25:20 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2013/10/24 10:25:19 | 001,166,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationNative_v0300.dll
[2013/10/24 08:08:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/10/24 08:08:44 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2013/10/24 08:08:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/10/24 07:20:37 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\assembly
[2013/10/24 07:10:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2013/10/24 07:10:27 | 001,032,416 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSnx.sys
[2013/10/24 07:10:27 | 000,409,832 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsp.sys
[2013/10/24 07:10:27 | 000,092,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2013/10/24 07:10:27 | 000,084,328 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswMonFlt.sys
[2013/10/24 07:10:27 | 000,038,984 | ---- | C] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswFsBlk.sys
[2013/10/24 07:10:24 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013/10/24 07:10:08 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013/10/24 06:56:58 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\ElevatedDiagnostics
[2013/10/24 06:53:08 | 000,000,000 | R--D | C] -- C:\Users\Anna\SkyDrive
[2013/10/24 06:51:34 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\Identities
[2013/10/24 06:36:13 | 000,000,000 | --SD | C] -- C:\Users\Anna\AppData\Roaming\Microsoft
[2013/10/24 06:36:13 | 000,000,000 | R--D | C] -- C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2013/10/24 06:36:13 | 000,000,000 | R--D | C] -- C:\Users\Anna\Favorites
[2013/10/24 06:36:13 | 000,000,000 | R--D | C] -- C:\Users\Anna\Documents
[2013/10/24 06:36:13 | 000,000,000 | R--D | C] -- C:\Users\Anna\Desktop
[2013/10/24 06:36:13 | 000,000,000 | R--D | C] -- C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/10/24 06:36:13 | 000,000,000 | R--D | C] -- C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\AppData\Local\Temporary Internet Files
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Templates
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Start Menu
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\SendTo
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Recent
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\PrintHood
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\NetHood
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Documents\My Videos
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Documents\My Pictures
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Documents\My Music
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\My Documents
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Local Settings
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\AppData\Local\History
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Cookies
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\Application Data
[2013/10/24 06:36:13 | 000,000,000 | -HSD | C] -- C:\Users\Anna\AppData\Local\Application Data
[2013/10/24 06:36:13 | 000,000,000 | -H-D | C] -- C:\Users\Anna\AppData
[2013/10/24 06:36:13 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\Temp
[2013/10/24 06:36:13 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\Microsoft
[2013/10/24 06:36:13 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/10/24 06:32:09 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2013/10/24 06:32:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2013/10/24 06:31:57 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2013/10/24 06:31:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2013/10/24 05:28:51 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Local\AMD
[2013/10/24 05:28:45 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013/10/24 05:28:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2013/10/24 05:28:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2013/10/24 05:28:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2013/10/24 05:27:37 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2013/10/24 05:25:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2013/10/24 05:24:39 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2013/10/24 05:23:40 | 000,000,000 | ---D | C] -- C:\AMD
[2013/10/15 14:40:19 | 000,000,000 | ---D | C] -- C:\Users\Anna\AppData\Roaming\AVAST Software
 
========== Files - Modified Within 30 Days ==========
 
[2013/11/13 22:16:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Anna\Desktop\OTL.exe
[2013/11/13 21:40:16 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/11/13 21:38:14 | 000,517,144 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2013/11/13 21:38:06 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/11/13 21:01:08 | 2983,743,488 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/13 11:08:39 | 000,002,959 | ---- | M] () -- C:\Users\Anna\Documents\New Database.odb
[2013/11/13 10:37:48 | 000,007,687 | ---- | M] () -- C:\Users\Anna\Documents\Untitled 1.odt
[2013/11/12 17:13:39 | 000,995,700 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2013/11/12 17:13:39 | 000,825,210 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2013/11/12 17:13:39 | 000,169,514 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2013/11/12 15:24:37 | 000,108,968 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysNative\WindowsAccessBridge-64.dll
[2013/11/12 15:24:35 | 000,312,744 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysNative\javaws.exe
[2013/11/12 15:24:35 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysNative\javaw.exe
[2013/11/12 15:24:34 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysNative\java.exe
[2013/11/12 09:18:22 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2013/11/12 09:18:21 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2013/11/12 09:18:21 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2013/11/12 09:18:21 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2013/11/11 13:13:28 | 001,032,416 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswSnx.sys
[2013/11/11 13:13:28 | 000,334,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2013/11/11 13:13:28 | 000,084,328 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswMonFlt.sys
[2013/11/11 13:13:28 | 000,038,984 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswFsBlk.sys
[2013/11/11 13:13:27 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013/11/06 11:55:32 | 000,409,832 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsp.sys
[2013/11/05 18:31:26 | 000,693,240 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2013/11/05 18:31:26 | 000,105,464 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2013/11/05 11:20:05 | 013,925,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2013/11/05 11:11:46 | 018,577,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2013/11/05 09:30:00 | 011,674,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2013/11/05 09:29:00 | 013,176,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2013/11/02 07:21:39 | 001,009,226 | ---- | M] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2013/11/01 07:38:12 | 000,000,145 | ---- | M] () -- C:\Users\Anna\.appletviewer
[2013/10/26 06:58:28 | 000,013,116 | ---- | M] () -- C:\WINDOWS\SysNative\InstallUtil.InstallLog
[2013/10/25 19:11:28 | 000,000,028 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2013/10/24 10:28:35 | 001,217,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.dll
[2013/10/24 10:28:35 | 000,977,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Streaming.dll
[2013/10/24 10:28:34 | 002,140,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2013/10/24 10:28:34 | 001,765,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2013/10/24 10:28:34 | 001,286,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctf.dll
[2013/10/24 10:28:34 | 000,516,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2013/10/24 10:28:34 | 000,382,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2013/10/24 10:28:34 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2013/10/24 10:28:34 | 000,225,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2013/10/24 07:10:25 | 000,205,320 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2013/10/24 07:10:25 | 000,092,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2013/10/24 07:10:25 | 000,065,776 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2013/10/24 06:57:28 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2013/10/24 06:48:37 | 000,032,388 | ---- | M] () -- C:\WINDOWS\diagwrn.xml
[2013/10/24 06:48:37 | 000,032,388 | ---- | M] () -- C:\WINDOWS\diagerr.xml
[2013/10/24 06:48:21 | 000,022,744 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2013/10/24 06:32:02 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2013/10/23 06:29:02 | 000,044,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wldp.dll
[2013/10/23 06:13:34 | 000,171,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kd_02_8086.dll
[2013/10/23 06:01:19 | 000,872,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2013/10/23 03:59:16 | 000,698,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2013/10/23 00:27:30 | 000,249,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2013/10/23 00:09:21 | 004,104,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2013/10/23 00:04:06 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2013/10/22 23:55:03 | 000,839,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2013/10/22 23:46:07 | 000,700,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2013/10/22 03:18:52 | 001,287,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kernel32.dll
[2013/10/22 02:55:27 | 002,328,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2013/10/22 01:03:47 | 002,065,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2013/10/22 00:15:38 | 000,558,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\apphelp.dll
[2013/10/21 22:56:17 | 000,186,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkFoldersShell.dll
[2013/10/21 22:44:06 | 000,761,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2013/10/21 21:22:39 | 000,381,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2013/10/21 21:13:33 | 001,704,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2013/10/21 21:07:57 | 002,617,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2013/10/21 20:53:47 | 001,584,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2013/10/21 20:47:12 | 002,295,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2013/10/19 03:51:07 | 000,481,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2013/10/19 02:12:06 | 000,380,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2013/10/19 00:37:49 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2013/10/19 00:19:05 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2013/10/19 00:10:24 | 005,765,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2013/10/18 23:48:38 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2013/10/18 23:31:56 | 001,993,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2013/10/18 22:57:16 | 002,143,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2013/10/18 22:55:02 | 001,926,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2013/10/18 22:28:22 | 001,765,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2013/10/18 22:26:57 | 001,231,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2013/10/18 22:14:29 | 000,888,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2013/10/17 10:42:33 | 001,373,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2013/10/17 10:42:31 | 001,399,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2013/10/17 09:04:13 | 001,204,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2013/10/16 10:58:02 | 001,943,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\crypt32.dll
[2013/10/16 04:34:26 | 000,518,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe
[2013/10/16 04:33:06 | 000,631,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe
[2013/10/15 14:21:25 | 000,000,000 | ---- | M] () -- C:\WINDOWS\SysWow64\config.nt
 
========== Files Created - No Company Name ==========
 
[2013/11/13 10:39:32 | 000,002,959 | ---- | C] () -- C:\Users\Anna\Documents\New Database.odb
[2013/11/13 10:37:46 | 000,007,687 | ---- | C] () -- C:\Users\Anna\Documents\Untitled 1.odt
[2013/11/12 16:03:43 | 000,385,528 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2013/11/02 04:35:14 | 000,001,115 | ---- | C] () -- C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk
[2013/11/01 07:38:12 | 000,000,145 | ---- | C] () -- C:\Users\Anna\.appletviewer
[2013/10/25 16:33:26 | 000,000,028 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2013/10/24 07:10:27 | 000,205,320 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2013/10/24 07:10:27 | 000,065,776 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2013/10/24 06:57:28 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2013/10/24 06:51:37 | 000,001,444 | ---- | C] () -- C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/10/24 06:48:21 | 000,022,744 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2013/10/24 06:40:40 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2013/10/24 06:36:13 | 000,000,352 | ---- | C] () -- C:\Users\Anna\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/10/24 06:36:13 | 000,000,334 | ---- | C] () -- C:\Users\Anna\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/10/24 06:36:03 | 000,032,388 | ---- | C] () -- C:\WINDOWS\diagwrn.xml
[2013/10/24 06:36:03 | 000,032,388 | ---- | C] () -- C:\WINDOWS\diagerr.xml
[2013/10/24 06:33:53 | 001,009,226 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2013/10/24 06:32:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013/10/08 08:45:08 | 000,038,912 | ---- | C] () -- C:\WINDOWS\SysWow64\kdbsdk32.dll
[2013/09/26 18:02:38 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013/09/26 18:02:38 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013/09/26 18:02:36 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013/09/26 18:02:18 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013/09/26 18:02:18 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013/09/26 18:02:12 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013/09/16 18:56:24 | 000,000,079 | ---- | C] () -- C:\WINDOWS\XP400.ini
[2013/08/22 10:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 10:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 09:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 02:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/21 22:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/21 22:17:46 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013/08/21 18:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/21 18:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2013/02/05 16:52:50 | 000,974,848 | ---- | C] () -- C:\WINDOWS\SysWow64\cis-2.4.dll
[2013/02/05 16:52:50 | 000,081,920 | ---- | C] () -- C:\WINDOWS\SysWow64\issacapi_bs-2.3.dll
[2013/02/05 16:52:50 | 000,065,536 | ---- | C] () -- C:\WINDOWS\SysWow64\issacapi_pe-2.3.dll
[2013/02/05 16:52:50 | 000,057,344 | ---- | C] () -- C:\WINDOWS\SysWow64\issacapi_se-2.3.dll
[2013/01/29 09:44:13 | 000,000,141 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2012/07/25 15:22:54 | 000,982,240 | ---- | C] () -- C:\WINDOWS\SysWow64\igkrng500.bin
[2012/07/25 15:22:54 | 000,439,308 | ---- | C] () -- C:\WINDOWS\SysWow64\igcompkrng500.bin
[2012/07/25 15:22:54 | 000,092,356 | ---- | C] () -- C:\WINDOWS\SysWow64\igfcg500m.bin
 
========== ZeroAccess Check ==========
 
[2013/11/02 07:21:24 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/11/05 15:21:27 | 021,196,664 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/11/05 13:51:37 | 018,642,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/10/15 14:40:19 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\AVAST Software
[2013/04/09 15:55:58 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\e-academy Inc
[2013/09/16 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Epson
[2013/04/09 21:00:27 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\ICAClient
[2013/09/16 19:00:55 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Leadertech
[2013/11/13 10:59:04 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\LibreOffice
[2013/11/07 08:57:47 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\NetBeans
[2013/10/20 17:55:18 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\Samsung
[2013/10/26 06:58:45 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\TinyWall
[2013/05/13 17:29:44 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\WebApp
[2013/04/10 08:52:26 | 000,000,000 | ---D | M] -- C:\Users\Anna\AppData\Roaming\WildTangent
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %USERPROFILE%\..|smtmp;true;true;true /FP >
 
<  %temp%\smtmp\*.* /s > >
 
< MD5 for: EXPLORER.ADML  >
[2013/09/29 22:48:10 | 000,003,671 | ---- | M] () MD5=007B16AEF3E958080573CDB80648167D -- C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.3.9600.16384_en-us_13bedf9d3e4c78d1\Explorer.adml
 
< MD5 for: EXPLORER.ADMX  >
[2013/06/18 09:57:40 | 000,003,836 | ---- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 -- C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.3.9600.16384_none_067909bec4cce684\Explorer.admx
 
< MD5 for: EXPLORER.EXE  >
[2013/10/22 01:03:47 | 002,065,448 | ---- | M] (Microsoft Corporation) MD5=1A0BC9598E4A58FC84570FFF5A108E58 -- C:\Windows\SysWOW64\explorer.exe
[2013/10/22 01:03:47 | 002,065,448 | ---- | M] (Microsoft Corporation) MD5=1A0BC9598E4A58FC84570FFF5A108E58 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2013/11/13 09:49:23 | 000,133,444 | ---- | M] () MD5=3DDF61E1B538A1205612192A61CC2376 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_42cd898b4d6ef82e\explorer.exe
[2013/10/22 02:55:27 | 002,328,872 | ---- | M] (Microsoft Corporation) MD5=63DC38C3E4564B2405D562855643ABA2 -- C:\Windows\explorer.exe
[2013/10/22 02:55:27 | 002,328,872 | ---- | M] (Microsoft Corporation) MD5=63DC38C3E4564B2405D562855643ABA2 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe
[2013/11/13 16:57:15 | 000,127,825 | ---- | M] () MD5=983D8A3EB94B05A199D3744C0F0C475F -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_4d2233dd81cfba29\explorer.exe
 
< MD5 for: EXPLORER.EXE.MUI  >
[2013/09/29 22:47:55 | 000,016,896 | ---- | M] (Microsoft Corporation) MD5=6B943F9892499269B3C4886C1F0BD843 -- C:\Windows\en-US\explorer.exe.mui
[2013/09/29 22:47:55 | 000,016,896 | ---- | M] (Microsoft Corporation) MD5=6B943F9892499269B3C4886C1F0BD843 -- C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2013/09/29 22:47:55 | 000,016,896 | ---- | M] (Microsoft Corporation) MD5=6B943F9892499269B3C4886C1F0BD843 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.3.9600.16384_en-us_f6b0e7284798d168\explorer.exe.mui
[2013/09/29 22:47:55 | 000,016,896 | ---- | M] (Microsoft Corporation) MD5=6B943F9892499269B3C4886C1F0BD843 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.3.9600.16384_en-us_0105917a7bf99363\explorer.exe.mui
 
< MD5 for: EXPLORER.EXE-03C49D11.PF  >
[2013/11/13 22:01:31 | 000,275,326 | ---- | M] () MD5=9B3F40AA0C2211E6134FAD97EF3368A0 -- C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
 
< MD5 for: EXPLORER.PROPERTIES  >
[2013/11/07 09:06:58 | 000,000,039 | ---- | M] () MD5=2BB97C1EFB43BE88E1BBDB121CAA9327 -- C:\Users\Anna\AppData\Roaming\NetBeans\7.4\config\Preferences\org\openide\explorer.properties
 
< MD5 for: EXPLORER.WSMODE  >
[2013/11/08 21:43:46 | 000,000,529 | ---- | M] () MD5=D6F21F6A9F8622776A062DB76714709C -- C:\Users\Anna\AppData\Roaming\NetBeans\7.4\config\Windows2Local\Modes\explorer.wsmode
 
< MD5 for: IEXPLORE.EXE  >
[2013/08/22 07:34:04 | 000,804,464 | ---- | M] (Microsoft Corporation) MD5=1C39C41D50FF7113748D825F4327D406 -- C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/22 07:34:04 | 000,804,464 | ---- | M] (Microsoft Corporation) MD5=1C39C41D50FF7113748D825F4327D406 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.0.9600.16384_none_9c7bbe6690ba5bc1\iexplore.exe
[2013/04/04 13:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2013/08/22 00:20:05 | 000,805,992 | ---- | M] (Microsoft Corporation) MD5=EE889775E0F9755C90FAEBFB93FBD781 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/08/22 00:20:05 | 000,805,992 | ---- | M] (Microsoft Corporation) MD5=EE889775E0F9755C90FAEBFB93FBD781 -- C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.0.9600.16384_none_a6d068b8c51b1dbc\iexplore.exe
 
< MD5 for: IEXPLORE.EXE.MUI  >
[2013/09/29 22:48:12 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=25B70D28D1CE87B67EEC2BA899126244 -- C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/09/29 22:48:12 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=25B70D28D1CE87B67EEC2BA899126244 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/09/29 22:48:12 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=25B70D28D1CE87B67EEC2BA899126244 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.0.9600.16384_en-us_962853ddc8679ca8\iexplore.exe.mui
[2013/09/29 22:48:12 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=25B70D28D1CE87B67EEC2BA899126244 -- C:\Windows\WinSxS\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.0.9600.16384_en-us_a07cfe2ffcc85ea3\iexplore.exe.mui
 
< MD5 for: IEXPLORE.EXE-6C28DB75.PF  >
[2013/11/10 22:39:56 | 000,155,202 | ---- | M] () MD5=62F1D836F2B9D75FFE62A9F66EA8BC30 -- C:\Windows\Prefetch\IEXPLORE.EXE-6C28DB75.pf
 
< MD5 for: IEXPLORE.EXE-6C28DB76.PF  >
[2013/11/10 22:39:57 | 000,297,692 | ---- | M] () MD5=FA28644D3C3E3C7C3E9C74525AC2027B -- C:\Windows\Prefetch\IEXPLORE.EXE-6C28DB76.pf
 
< MD5 for: IEXPLORE.EXE-7A9337F2.PF  >
[2013/11/13 22:19:00 | 000,096,008 | ---- | M] () MD5=F98FFB735020DFA2153BDAA1E8F4C87D -- C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
 
< MD5 for: IEXPLORE.EXE-7A9337F4.PF  >
[2013/11/13 05:58:26 | 000,170,726 | ---- | M] () MD5=BC621D49AE0F41DFF6E6DFA400D27650 -- C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F4.pf
 
< MD5 for: IEXPLORE.EXE-F4FB5D2F.PF  >
[2013/11/13 22:16:07 | 000,354,292 | ---- | M] () MD5=18805D41FC904AE90A59B43CE44C6D14 -- C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
 
< MD5 for: IEXPLORE.VISUALELEMENTSMANIFEST.XML  >
[2013/06/18 09:48:46 | 000,000,340 | ---- | M] () MD5=2C776DCD91132FCC6A8C066DD529B307 -- C:\Program Files\Internet Explorer\iexplore.VisualElementsManifest.xml
[2013/06/18 09:48:46 | 000,000,340 | ---- | M] () MD5=2C776DCD91132FCC6A8C066DD529B307 -- C:\Windows\WinSxS\amd64_microsoft-windows-immersivebrowser_31bf3856ad364e35_11.0.9600.16384_none_c673d0d2f4ca87f4\iexplore.VisualElementsManifest.xml
 
< MD5 for: SERVICES  >
[2013/08/22 10:04:54 | 000,003,777 | ---- | M] () MD5=5EE2D65841D1985E8C1BC68B2EB4357B -- C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.3.9600.16384_none_25fdfd813908f8a6\services
[2013/10/24 05:37:43 | 000,092,875 | ---- | M] () MD5=9CEA05C6911F6F2DA50ED6C470313CF2 -- C:\Users\Anna\AppData\Roaming\Microsoft\MMC\services
 
< MD5 for: SERVICES.EXE  >
[2013/08/22 08:25:40 | 000,405,488 | ---- | M] (Microsoft Corporation) MD5=B4B610BBCB002EC478C6FD80CF915697 -- C:\WINDOWS\SysNative\services.exe
[2013/08/22 08:25:40 | 000,405,488 | ---- | M] (Microsoft Corporation) MD5=B4B610BBCB002EC478C6FD80CF915697 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.16384_none_2fd72579d09a45e9\services.exe
 
< MD5 for: SERVICES.EXE.MUI  >
[2013/09/29 22:47:46 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=0626E9CF9F010A5E5D5A8E200A59DDDC -- C:\WINDOWS\SysNative\en-US\services.exe.mui
[2013/09/29 22:47:46 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=0626E9CF9F010A5E5D5A8E200A59DDDC -- C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.3.9600.16384_en-us_5abba721f9ec3435\services.exe.mui
 
< MD5 for: SERVICES.JS  >
[2013/09/29 22:53:03 | 000,089,002 | ---- | M] () MD5=BCF4AD208163A961EEAF9F67C7DDA943 -- C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.1.177_x64__8wekyb3d8bbwe\common\js\services.js
[2013/09/29 22:53:12 | 000,089,002 | ---- | M] () MD5=BCF4AD208163A961EEAF9F67C7DDA943 -- C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.1.176_x64__8wekyb3d8bbwe\common\js\services.js
[2013/10/24 07:10:26 | 000,095,331 | ---- | M] () MD5=FAA0FC80FCDDF0B163707F352BEA3C36 -- C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.1.203_x64__8wekyb3d8bbwe\common\js\services.js
[2013/10/24 07:10:26 | 000,095,331 | ---- | M] () MD5=FAA0FC80FCDDF0B163707F352BEA3C36 -- C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.1.205_x64__8wekyb3d8bbwe\common\js\services.js
[2013/10/24 07:10:26 | 000,095,331 | ---- | M] () MD5=FAA0FC80FCDDF0B163707F352BEA3C36 -- C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.1.203_x64__8wekyb3d8bbwe\common\js\services.js
[2013/10/24 07:10:27 | 000,095,331 | ---- | M] () MD5=FAA0FC80FCDDF0B163707F352BEA3C36 -- C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.1.202_x64__8wekyb3d8bbwe\common\js\services.js
[2013/10/24 07:10:26 | 000,095,331 | ---- | M] () MD5=FAA0FC80FCDDF0B163707F352BEA3C36 -- C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.1.203_x64__8wekyb3d8bbwe\common\js\services.js
 
< MD5 for: SERVICES.LNK  >
[2013/08/22 01:54:57 | 000,001,158 | ---- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2013/08/22 01:54:57 | 000,001,158 | ---- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2013/08/22 01:54:57 | 000,001,158 | ---- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 -- C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.3.9600.16384_none_c02242af19b1eb57\services.lnk
 
< MD5 for: SERVICES.MOF  >
[2013/06/18 09:51:33 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\WINDOWS\SysNative\wbem\services.mof
[2013/06/18 09:51:33 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.3.9600.16384_none_c01e2072a140077e\services.mof
 
< MD5 for: SERVICES.MSC  >
[2013/09/29 22:47:49 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\WINDOWS\SysNative\en-US\services.msc
[2013/06/18 09:47:53 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\WINDOWS\SysNative\services.msc
[2013/09/29 22:47:49 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\SysWOW64\en-US\services.msc
[2013/06/18 07:23:54 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\SysWOW64\services.msc
[2013/09/29 22:47:49 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.3.9600.16384_en-us_94fd770dd055ce28\services.msc
[2013/06/18 09:47:53 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.3.9600.16384_none_c02242af19b1eb57\services.msc
[2013/06/18 07:23:54 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.3.9600.16384_none_ca76ed014e12ad52\services.msc
[2013/09/29 22:47:49 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.3.9600.16384_en-us_38dedb8a17f85cf2\services.msc
 
< MD5 for: SERVICES.PTXML  >
[2013/08/22 01:45:36 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\WINDOWS\SysNative\wdi\perftrack\Services.ptxml
[2013/08/22 01:45:36 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.3.9600.16384_none_c01e2072a140077e\Services.ptxml
 
< MD5 for: SERVICES.SETTINGS  >
[2013/11/08 21:43:46 | 000,001,622 | ---- | M] () MD5=9D486393976FDCB5F1706828D147FE43 -- C:\Users\Anna\AppData\Roaming\NetBeans\7.4\config\Windows2Local\Components\services.settings
 
< MD5 for: SERVICES.WSTCGRP  >
[2013/11/08 21:43:46 | 000,000,225 | ---- | M] () MD5=E4AD31A486D75BC449F02775904D2430 -- C:\Users\Anna\AppData\Roaming\NetBeans\7.4\config\Windows2Local\Groups\InitialLayout\services.wstcgrp
[2013/11/08 21:43:46 | 000,000,225 | ---- | M] () MD5=E4AD31A486D75BC449F02775904D2430 -- C:\Users\Anna\AppData\Roaming\NetBeans\7.4\config\Windows2Local\Groups\OpenedProjects\services.wstcgrp
 
< MD5 for: SERVICES.WSTCREF  >
[2013/11/08 21:43:46 | 000,000,129 | ---- | M] () MD5=73E5717A2B2C3FF0F7ED6EFDD0A658B3 -- C:\Users\Anna\AppData\Roaming\NetBeans\7.4\config\Windows2Local\Modes\explorer\services.wstcref
 
< MD5 for: WINLOGON.ADML  >
[2013/09/29 23:18:27 | 000,002,631 | ---- | M] () MD5=3FC16D999444A213C04297050F42DA07 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.3.9600.16384_en-us_85c27192b0d9003d\WinLogon.adml
 
< MD5 for: WINLOGON.ADMX  >
[2013/08/22 09:57:15 | 000,001,101 | ---- | M] () MD5=513B8C31BC439F0A37EA44D540F98916 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.3.9600.16384_none_6bcbbccd4d39421a\WinLogon.admx
 
< MD5 for: WINLOGON.EXE  >
[2013/08/22 04:55:08 | 000,564,736 | ---- | M] (Microsoft Corporation) MD5=7C94FDA3809015B8F2208D2E1C221F17 -- C:\WINDOWS\SysNative\winlogon.exe
[2013/08/22 04:55:08 | 000,564,736 | ---- | M] (Microsoft Corporation) MD5=7C94FDA3809015B8F2208D2E1C221F17 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2013/04/04 13:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< MD5 for: WINLOGON.EXE.MUI  >
[2013/09/29 22:48:02 | 000,024,064 | ---- | M] (Microsoft Corporation) MD5=E1EA8FA8EDA1C8E5BFF41FCECE119841 -- C:\WINDOWS\SysNative\en-US\winlogon.exe.mui
[2013/09/29 22:48:02 | 000,024,064 | ---- | M] (Microsoft Corporation) MD5=E1EA8FA8EDA1C8E5BFF41FCECE119841 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.3.9600.16384_en-us_bbb6f195d80d78ae\winlogon.exe.mui
 
< MD5 for: WINLOGON.EXE-0D9AB72B.PF  >
[2013/11/13 17:03:24 | 000,030,862 | ---- | M] () MD5=B4C85DFFF5B13CC50EF557DECC32437B -- C:\Windows\Prefetch\WINLOGON.EXE-0D9AB72B.pf
 
< MD5 for: WINLOGON.MFL  >
[2013/09/29 22:48:02 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\WINDOWS\SysNative\wbem\en-US\winlogon.mfl
[2013/09/29 22:48:02 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.3.9600.16384_en-us_19794360f345d243\winlogon.mfl
 
< MD5 for: WINLOGON.MOF  >
[2013/08/22 01:45:12 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\WINDOWS\SysNative\wbem\winlogon.mof
[2013/08/22 01:45:12 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.3.9600.16384_none_70f729db49dee3dc\winlogon.mof
 
<  %SYSTEMDRIVE%\*.* >
[2012/07/25 22:44:30 | 000,398,156 | RHS- | M] () -- C:\bootmgr
[2013/06/18 07:18:29 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT
[2013/11/13 21:01:08 | 2983,743,488 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/29 09:43:24 | 000,000,000 | RHS- | M] () -- C:\OS
[2013/11/13 21:38:05 | 671,088,640 | -HS- | M] () -- C:\pagefile.sys
[2013/11/13 21:38:06 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
 
<  %systemroot%\Fonts\*.com >
[2013/10/24 10:26:11 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2013/10/24 10:26:11 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2013/10/24 10:26:11 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2013/10/24 10:26:11 | 000,043,318 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
 
<  %systemroot%\Fonts\*.dll >
 
<  %systemroot%\Fonts\*.ini >
[2013/08/22 10:35:03 | 000,000,065 | ---- | M] () -- C:\WINDOWS\Fonts\desktop.ini
 
<  %systemroot%\Fonts\*.ini2 >
 
<  %systemroot%\Fonts\*.exe >
 
<  %systemroot%\system32\spool\prtprocs\w32x86\*.* >
 
<  %systemroot%\REPAIR\*.bak1 >
 
<  %systemroot%\REPAIR\*.ini >
 
<  %systemroot%\system32\*.jpg >
 
<  %systemroot%\*.jpg >
 
<  %systemroot%\*.png >
 
<  %systemroot%\*.scr >
[2013/11/11 13:13:27 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/07/28 05:54:00 | 000,321,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
 
<  %systemroot%\*._sy >
 
<  %APPDATA%\Adobe\Update\*.* >
 
<  %ALLUSERSPROFILE%\Favorites\*.* >
 
<  %APPDATA%\Microsoft\*.* >
 
<  %PROGRAMFILES%\*.* >
[2013/08/22 10:34:52 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
 
<  %APPDATA%\Update\*.* >
 
<  %systemroot%\*. /mp /s >
 
<  dir "%systemdrive%\*" /S /A:L /C >
 Volume in drive C is OS
 Volume Serial Number is 06E2-8684
 Directory of C:\
08/22/2013  09:45 AM    <JUNCTION>     Documents and Settings [C:\Users]
               0 File(s)              0 bytes
 Directory of C:\ProgramData
08/22/2013  09:45 AM    <JUNCTION>     Application Data [C:\ProgramData]
08/22/2013  09:45 AM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
08/22/2013  09:45 AM    <JUNCTION>     Documents [C:\Users\Public\Documents]
08/22/2013  09:45 AM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
08/22/2013  09:45 AM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\SYSTEM.SAV\LOGS\SymLogs
01/29/2013  09:37 AM    <SYMLINKD>     cclog [C:\Users\Public\Symantec\SymSilent\cclog]
               0 File(s)              0 bytes
 Directory of C:\Users
08/22/2013  09:45 AM    <SYMLINKD>     All Users [C:\ProgramData]
08/22/2013  09:45 AM    <JUNCTION>     Default User [C:\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users
08/22/2013  09:45 AM    <JUNCTION>     Application Data [C:\ProgramData]
08/22/2013  09:45 AM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
08/22/2013  09:45 AM    <JUNCTION>     Documents [C:\Users\Public\Documents]
08/22/2013  09:45 AM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
08/22/2013  09:45 AM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Anna
10/24/2013  06:36 AM    <JUNCTION>     Application Data [C:\Users\Anna\AppData\Roaming]
10/24/2013  06:36 AM    <JUNCTION>     Cookies [C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCookies]
10/24/2013  06:36 AM    <JUNCTION>     Local Settings [C:\Users\Anna\AppData\Local]
10/24/2013  06:36 AM    <JUNCTION>     My Documents [C:\Users\Anna\Documents]
10/24/2013  06:36 AM    <JUNCTION>     NetHood [C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
10/24/2013  06:36 AM    <JUNCTION>     PrintHood [C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
10/24/2013  06:36 AM    <JUNCTION>     Recent [C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Recent]
10/24/2013  06:36 AM    <JUNCTION>     SendTo [C:\Users\Anna\AppData\Roaming\Microsoft\Windows\SendTo]
10/24/2013  06:36 AM    <JUNCTION>     Start Menu [C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu]
10/24/2013  06:36 AM    <JUNCTION>     Templates [C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Anna\AppData\Local
10/24/2013  06:36 AM    <JUNCTION>     Application Data [C:\Users\Anna\AppData\Local]
10/24/2013  06:36 AM    <JUNCTION>     History [C:\Users\Anna\AppData\Local\Microsoft\Windows\History]
10/24/2013  06:36 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCache]
               0 File(s)              0 bytes
 Directory of C:\Users\Anna\AppData\Local\Microsoft\Windows
10/24/2013  06:36 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCache]
               0 File(s)              0 bytes
 Directory of C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCache
10/24/2013  06:51 AM    <JUNCTION>     Content.IE5 [C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCache\IE\]
               0 File(s)              0 bytes
 Directory of C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCache\Low
10/24/2013  08:03 AM    <JUNCTION>     Content.IE5 [C:\Users\Anna\AppData\Local\Microsoft\Windows\INetCache\Low\IE\]
               0 File(s)              0 bytes
 Directory of C:\Users\Anna\Documents
10/24/2013  06:36 AM    <JUNCTION>     My Music [C:\Users\Anna\Music]
10/24/2013  06:36 AM    <JUNCTION>     My Pictures [C:\Users\Anna\Pictures]
10/24/2013  06:36 AM    <JUNCTION>     My Videos [C:\Users\Anna\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default
08/22/2013  09:45 AM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
08/22/2013  09:45 AM    <JUNCTION>     Cookies [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCookies]
08/22/2013  09:45 AM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
08/22/2013  09:45 AM    <JUNCTION>     My Documents [C:\Users\Default\Documents]
08/22/2013  09:45 AM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/22/2013  09:45 AM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/22/2013  09:45 AM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
08/22/2013  09:45 AM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
08/22/2013  09:45 AM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
08/22/2013  09:45 AM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local
08/22/2013  09:45 AM    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
08/22/2013  09:45 AM    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
08/22/2013  09:45 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local\Microsoft\Windows
08/22/2013  09:45 AM    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Documents
08/22/2013  09:45 AM    <JUNCTION>     My Music [C:\Users\Default\Music]
08/22/2013  09:45 AM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
08/22/2013  09:45 AM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default.migrated\Documents
07/26/2012  02:22 AM    <JUNCTION>     My Music [C:\Users\Default\Music]
07/26/2012  02:22 AM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/26/2012  02:22 AM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool
10/24/2013  06:36 AM    <JUNCTION>     Application Data [C:\Users\DefaultAppPool\AppData\Roaming]
10/24/2013  06:36 AM    <JUNCTION>     Cookies [C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\INetCookies]
10/24/2013  06:36 AM    <JUNCTION>     Local Settings [C:\Users\DefaultAppPool\AppData\Local]
10/24/2013  06:36 AM    <JUNCTION>     My Documents [C:\Users\DefaultAppPool\Documents]
10/24/2013  06:36 AM    <JUNCTION>     NetHood [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
10/24/2013  06:36 AM    <JUNCTION>     PrintHood [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
10/24/2013  06:36 AM    <JUNCTION>     Recent [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Recent]
10/24/2013  06:36 AM    <JUNCTION>     SendTo [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo]
10/24/2013  06:36 AM    <JUNCTION>     Start Menu [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu]
10/24/2013  06:36 AM    <JUNCTION>     Templates [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool\AppData\Local
10/24/2013  06:36 AM    <JUNCTION>     Application Data [C:\Users\DefaultAppPool\AppData\Local]
10/24/2013  06:36 AM    <JUNCTION>     History [C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\History]
10/24/2013  06:36 AM    <JUNCTION>     Temporary Internet Files [C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\INetCache]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows
10/24/2013  06:36 AM    <JUNCTION>     Temporary Internet Files [C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\INetCache]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool\Documents
10/24/2013  06:36 AM    <JUNCTION>     My Music [C:\Users\DefaultAppPool\Music]
10/24/2013  06:36 AM    <JUNCTION>     My Pictures [C:\Users\DefaultAppPool\Pictures]
10/24/2013  06:36 AM    <JUNCTION>     My Videos [C:\Users\DefaultAppPool\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Public\Documents
08/22/2013  09:45 AM    <JUNCTION>     My Music [C:\Users\Public\Music]
08/22/2013  09:45 AM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
08/22/2013  09:45 AM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache
10/24/2013  07:19 AM    <JUNCTION>     Content.IE5 [C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\]
               0 File(s)              0 bytes
 Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache
10/24/2013  07:19 AM    <JUNCTION>     Content.IE5 [C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\]
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
              75 Dir(s)  431,249,899,520 bytes free
 
<  %systemroot%\System32\config\*.sav >
 
<  %PROGRAMFILES%\bak. /s >
 
<  %systemroot%\system32\bak. /s >
 
<  %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
 
<  %systemroot%\system32\config\systemprofile\*.dat /x >
 
<  %systemroot%\*.config >
 
<  %systemroot%\system32\*.db >
 
<  %PROGRAMFILES%\Internet Explorer\*.dat >
 
<  %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/04/09 12:45:14 | 000,000,223 | -HS- | M] () -- C:\Users\Anna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2013/08/22 10:35:52 | 000,000,148 | -HS- | M] () -- C:\Users\Anna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
 
<  %USERPROFILE%\Desktop\*.exe >
[2013/11/13 22:16:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Anna\Desktop\OTL.exe
 
<  %PROGRAMFILES%\Common Files\*.* >
 
<  %systemroot%\*.src >
 
<  %systemroot%\install\*.* >
 
<  %systemroot%\system32\DLL\*.* >
 
<  %systemroot%\system32\HelpFiles\*.* >
 
<  %systemroot%\system32\rundll\*.* >
 
<  %systemroot%\winn32\*.* >
 
<  %systemroot%\Java\*.* >
 
<  %systemroot%\system32\test\*.* >
 
<  %systemroot%\system32\Rundll32\*.* >
 
<  %systemroot%\AppPatch\Custom\*.* >
 
<  HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
<  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 199 bytes -> C:\Users\Anna\SkyDrive:ms-properties

< End of report >
 

 

OTL Extras logfile created on: 11/13/2013 10:20:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Anna\Desktop
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16438)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.47 Gb Total Physical Memory | 1.99 Gb Available Physical Memory | 57.29% Memory free
4.10 Gb Paging File | 1.82 Gb Available in Paging File | 44.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.00 Gb Total Space | 401.63 Gb Free Space | 90.46% Space Free | Partition Type: NTFS
Drive D: | 19.95 Gb Total Space | 2.46 Gb Free Space | 12.32% Space Free | Partition Type: NTFS
Drive G: | 232.83 Gb Total Space | 232.31 Gb Free Space | 99.78% Space Free | Partition Type: FAT32
 
Computer Name: ANNAPERSONALPC | User Name: Anna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" =  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DefaultInboundAction" = 1
"DefaultOutboundAction" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A5C5FB8-EF52-48DC-9BB7-989631B04986}" = lport=5357 | protocol=6 | dir=in | app=system |
"{13A7CE7D-4E11-419B-A064-43FD8AE3929C}" = rport=53 | protocol=6 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{13EF2457-F140-41DE-AB1C-7F3B6E269B2E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{156FB420-81C0-4736-A799-68368787E66C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{19F58E2A-4AB1-4662-BAF9-2C733809BD08}" = rport=53 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{26F3DF8D-8B13-4A91-ACD9-C61C18205795}" = lport=2869 | protocol=6 | dir=in | app=system |
"{37CC76B7-12FC-4149-BAC8-3726207FAFA4}" = rport=2 | protocol=6 | dir=in | name=[tw5yrosa0dqr7t][tcp][in] malware port block |
"{39A04B12-4352-4105-BCB9-345142037AD5}" = rport=547 | protocol=17 | dir=out | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{3F7B60E2-AD2B-4B8B-9112-A85CA2C3BC8D}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{46EF4CA2-CE0D-48A1-AC13-5D8F098C56DF}" = rport=2 | protocol=17 | dir=in | name=[tw5yrosa0dqr7t][udp][in] malware port block |
"{4F5AE2F9-1AB9-4364-B981-1AE8F7ABD045}" = lport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{558965ED-D48A-4B58-864D-3E4F4A00BEE5}" = rport=5357 | protocol=6 | dir=out | app=system |
"{66096A95-4D1C-4451-93B7-0EC33EA41268}" = rport=547 | protocol=17 | dir=in | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{6D31E3B2-D679-475A-8E3F-9946762471AD}" = rport=67 | protocol=17 | dir=out | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{6E039F13-7681-4A14-BAA7-73BD2E7C208C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7B9C33F5-0614-4727-B9EF-8CEFF176D223}" = rport=123 | protocol=17 | dir=out | svc=w32time | app=c:\windows\system32\svchost.exe |
"{7CE1B31E-2E4E-46F7-9E29-C20A585F5AF3}" = rport=2 | protocol=17 | dir=out | name=[tw5yrosa0dqr7t][udp][out] malware port block |
"{8FF253C5-0B72-4720-BC13-21300D2C8BD6}" = rport=2 | protocol=6 | dir=out | name=[tw5yrosa0dqr7t][tcp][out] malware port block |
"{97D23637-6792-4BFA-B2EC-73B32A44DD33}" = rport=53 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{9DB3A9DC-25AF-4EC6-B14E-8B16724C2B62}" = rport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{9E4B10EF-C95D-48FF-AFEA-4F576D437C4B}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{AB7596E4-7E50-4CC1-95BE-CD2D2054D80B}" = rport=67 | protocol=17 | dir=in | svc=dhcp | app=c:\windows\system32\svchost.exe |
"{B1071333-BA8A-4BB3-879E-1400DFF2DCFE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{CBDF1546-56B5-45C7-AED6-098E6FAEF566}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{CC966182-7E35-45F2-8803-EA85C721B7C3}" = rport=2869 | protocol=6 | dir=out | app=system |
"{DD61F81E-55E0-439C-BE09-B5A375B1C5C0}" = rport=67 | protocol=17 | dir=out | svc=lmhosts | app=c:\windows\system32\svchost.exe |
"{EAB80BF9-9663-4FC0-B40C-5E6167A7151A}" = lport=2869 | protocol=6 | dir=in | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{FC2FE091-3A2E-47E8-B789-ECF4AA149A4E}" = rport=123 | protocol=17 | dir=in | svc=w32time | app=c:\windows\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05EE99C5-5E7D-4CBE-8BBF-D8EBFCABAD9E}" = protocol=6 | dir=in | app=c:\windows\system32\svchost.exe |
"{0F644321-461C-4AA2-BD7F-AE51134DFC94}" = protocol=17 | dir=in | app=c:\windows\system32\svchost.exe |
"{1B8F2B01-C445-48A7-B5B1-889DC1524B08}" = protocol=58 | dir=out | name=[twuwvaxiayjmt8] icmpv6 (echo-req) out |
"{2466D0B8-AACE-49EE-8D33-AFE67BEFDA30}" = protocol=17 | dir=out | app=c:\program files (x86)\internet explorer\iexplore.exe |
"{405684C3-96EB-455B-9B92-FBC65227322C}" = protocol=6 | dir=out | app=c:\program files\avast software\avast\avastsvc.exe |
"{4E7AEA3E-724A-4D75-9F87-46BAFE389F0D}" = protocol=6 | dir=out | svc=wuauserv | app=c:\windows\system32\svchost.exe |
"{4FE65608-9526-4856-869D-31FDEEF5AEC5}" = protocol=17 | dir=out | app=c:\windows\system32\svchost.exe |
"{73A785EC-032D-4AD0-99F2-FB0A5BAF9A94}" = protocol=6 | dir=out | app=c:\windows\system32\svchost.exe |
"{7883537C-7191-4E2E-BF28-3873D3FD12B9}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\avastsvc.exe |
"{9E6B12B1-FE0A-4115-BAE3-9C6B9F2D2109}" = protocol=17 | dir=out | app=c:\program files\avast software\avast\avastsvc.exe |
"{BAC5F128-8A35-4605-BBF4-D3D98698CCDC}" = protocol=58 | dir=in | name=[twuwvaxiayjmt8] icmpv6 (safe) |
"{C244A919-EB26-4424-B67F-BE651DFB086D}" = protocol=1 | dir=in | name=[twuwvaxiayjmt8] icmpv4 (safe) |
"{C56D1611-1DF5-4C1C-B5D5-2B752394893D}" = protocol=6 | dir=out | app=c:\program files (x86)\tinywall\tinywall.exe |
"{E5C207F7-70B0-4814-B700-EBDA4DF8E58A}" = protocol=1 | dir=out | name=[twuwvaxiayjmt8] icmpv4 (echo-req) out |
"{E7927273-55C7-47E0-9064-4EB52F6BD0EE}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\avastsvc.exe |
"{FD513131-0390-4041-8FED-073AF36C41D7}" = protocol=6 | dir=out | app=c:\program files (x86)\internet explorer\iexplore.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86417045FF}" = Java 7 Update 45 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.7.0 (64-bit)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5AE0838D-19B1-5D12-5FE8-E6503B2C8716}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64A3A4F4-B792-11D6-A78A-00B0D0170450}" = Java SE Development Kit 7 Update 45 (64-bit)
"{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{814FA673-A085-403C-9545-747FC1495069}" = Epson Customer Participation
"{8AB933A1-603C-5B22-3D56-19593698C41A}" = AMD Fuel
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service
"{E57289A3-B314-F00A-F0D0-7CB63E588CFF}" = AMD Accelerated Video Transcoding
"{F842F8B0-6942-4930-821F-543E976B2C66}" = MSVCRT110_amd64
"{FEB22B7A-7B05-4A49-3BA3-D24815D37FAE}" = ccc-utility64
"EPSON XP-400 Series" = EPSON XP-400 Series Printer Uninstall
"nbi-nb-base-7.4.0.0.201310111528" = NetBeans IDE 7.4
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05A7B662-80A3-4EB9-AE1D-89A62449431C}" = Oracle Database 11g Express Edition
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{1057511B-F8FE-4230-9ED3-AB949A57EE4A}" = Windows Live PIMT Platform
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{170236F2-1F88-A116-DA64-3FEED17B9387}" = CCC Help Italian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2178EDD8-A3A6-50E3-407B-6629EA8E6ECE}" = AMD Catalyst Control Center
"{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45
"{29315CEC-E6CE-4394-84DC-6F862E8D9A52}" = Windows Live UX Platform
"{2D416A80-0BB1-4D8B-B770-7BE8F53D5937}" = Windows Live UX Platform Language Pack
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{32957F2B-A371-151F-9DA1-7BCA54BA2C71}" = CCC Help Danish
"{398004A7-6198-B8AB-443A-D250FFA57446}" = CCC Help Greek
"{3A29665B-2304-A9F7-601D-86340BD29D57}" = CCC Help Korean
"{40F55150-F43D-4C9F-9A00-1A0A6F1EB7F0}" = Movie Maker
"{4310E447-8AF3-020C-06D0-CB317D1BC92B}" = CCC Help Spanish
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{46316411-80D8-4F68-8118-696E05FCE199}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DF0CAAC-F479-1673-EE92-03FFB9A05C1A}" = CCC Help English
"{4F9A382F-4478-4036-905C-F77DF2EA0370}" = Windows Live SOXE
"{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}" = Windows Live SOXE Definitions
"{5CC4C963-F772-4766-BFF2-DE551E205EE9}" = Photo Common
"{60A1253C-2D51-4166-95C2-52E9CF4F8D64}" = Photo Gallery
"{64BA551C-9AF6-495C-93F3-D1270E0045FC}" = Epson Connect
"{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}" = Windows Live Photo Common
"{6670AE0A-83FD-C514-C4EC-51618BEDCF04}" = Catalyst Control Center InstallProxy
"{6DD76706-759A-1D77-9D1B-39FFFEC203BE}" = CCC Help Hungarian
"{6DF3C5B5-AEA5-198E-289C-CAADC4A17C04}" = CCC Help Dutch
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.0.0
"{6F9B3984-08EB-19EE-5E93-E79FD0854596}" = CCC Help Czech
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}" = Windows Live Installer
"{82DA3D5E-0041-D8F7-6ACD-53A06C863FD4}" = CCC Help Swedish
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{88B2ABCF-9C00-47C1-8FC4-369B98845DD7}" = Catalyst Control Center - Branding
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8E63AD00-6BEB-9E98-739E-C8EE42CF0419}" = CCC Help Norwegian
"{9584BE1B-2FBE-4F45-13EA-6567F3E2D9A2}" = CCC Help Chinese Traditional
"{993609E5-B0A7-0270-BA78-385016D5A4FA}" = CCC Help Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B2E55F8-5BA8-4A45-9682-ACB6F2CC0DA5}" = Photo Gallery
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom
"{9C50B767-48BA-A567-0CFE-31620AE8FC97}" = CCC Help German
"{9E94C6F8-2B4E-D900-E73C-E7BCC7653188}" = CCC Help Japanese
"{B2B7B1C8-7C8B-476C-BE2C-049731C55992}" = HP Support Information
"{BA73469B-D8C7-4FE3-B33C-1340D09F0709}" = Windows Live Communications Platform
"{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}" = Epson Event Manager
"{BEFD4139-C684-DBF8-33F2-7963161E2F10}" = CCC Help Russian
"{CFBC3C9F-C781-4A0A-4AC9-BEBDE9850C16}" = CCC Help Turkish
"{D17BE572-CBFB-2AA4-759B-E21F04093001}" = CCC Help Thai
"{D3C44AE6-7A77-6CB3-0708-C970C53E8136}" = Catalyst Control Center Localization All
"{D71BC54E-A4E6-4E06-866C-FD6EE16EA187}" = Movie Maker
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E728441A-7820-4B1C-87C9-DE7BE37B2953}" = Download Navigator
"{E87F67CD-B72A-4B47-A01D-28CD16AC0711}" = TinyWall
"{E9E87CFE-894C-8FFB-31C2-61C6B640F2B2}" = CCC Help Finnish
"{E9F63F5F-00EF-516C-C7F6-ABD3DC174B5E}" = CCC Help Polish
"{EA3960CB-883C-5B18-FA85-7C36C320E4BC}" = Catalyst Control Center Graphics Previews Common
"{ED62231A-B71D-C39A-7CE0-B2C8388A67C2}" = CCC Help French
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F243A34B-AB7F-4065-B770-B85B767C247C}" = HP Connected Remote
"{FBC9A8BD-C74D-86B3-7818-D584C9174F48}" = CCC Help Portuguese
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{FF27F674-821E-4BA2-985B-DDF539C2CD03}" = HP Support Assistant
"Avast" = avast! Free Antivirus
"EPSON Scanner" = EPSON Scan
"InstallShield_{05A7B662-80A3-4EB9-AE1D-89A62449431C}" = Oracle Database 11g Express Edition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"StartHPConnectedMusic" = HP Connected Music (Meridian - installer)
"WildTangent hp Master Uninstall" = HP Games
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WTA-09159dff-d00f-4249-92a9-d21bd2c23087" = Final Drive Fury
"WTA-0d2bf4b2-f3c1-42d8-9f95-f7020595d4cb" = Polar Golfer
"WTA-0f0375fa-8d74-4b22-b473-c63035d20911" = Governor of Poker 2 Premium Edition
"WTA-181dd5df-03b6-41c5-ae6f-d012b549a3b0" = Cradle of Rome 2
"WTA-2804a01c-98a5-4ad8-8497-d1adee2eff1e" = Mortimer Beckett and the Crimson Thief Premium Edition
"WTA-31ae23af-5326-489e-bf3c-71e96da21e00" = John Deere Drive Green
"WTA-452d24a6-2630-41f5-8cdc-de303a21881c" = Luxor Evolved
"WTA-4a1d1efa-3285-47d8-8275-8a83c8c55b76" = Bejeweled 3
"WTA-4f1c660e-f86b-4041-9227-11ec091bfd45" = Roads of Rome 3
"WTA-5ae6d930-a0f2-4389-a7f6-fb54482b2395" = Peggle Nights
"WTA-5d1a4dbf-f606-4e54-b4ff-e5faa6915274" = Polar Bowler
"WTA-66cc5333-1ab7-4389-98ae-7cdb8f39d844" = Vacation Quest™ - Australia
"WTA-6b654f1e-3e9b-48de-9abf-0b2d4cd33975" = Build-a-lot 4 - Power Source
"WTA-6bb4aa06-bca4-486a-90aa-8d5bdb52b613" = Mahjongg Dimensions Deluxe: Tiles in Time
"WTA-6f2cf829-048b-4d88-b4b5-ec1b45d4ccc8" = Tales of Lagoona
"WTA-8dda22ea-ef5e-46a0-ad77-1070ec24d7e9" = FATE: The Cursed King
"WTA-a9c17bdd-c791-4cb9-916a-c87a71b1f6ce" = Jewel Match 3
"WTA-aec06a9a-8d3b-408f-bc24-88dc0850c924" = Zuma's Revenge
"WTA-b4af75bb-a1a7-4650-859a-68eccc00cefe" = Chuzzle Deluxe
"WTA-ba5a9411-aea3-41ab-a930-0b28e9ace639" = Penguins!
"WTA-c3bb4900-dd8f-4ea7-8c60-93780d379ee2" = Cradle Of Egypt Collector's Edition
"WTA-d364e5e4-411c-48bf-a277-0b7d036617e0" = Mystery P.I. - Curious Case of Counterfeit Cove
"WTA-db59cb34-a79a-46fa-86d1-bc7c955aeb47" = FlatOut 2
"WTA-e073819f-a49a-4f9c-a964-413c642aada2" = 4 Elements II
"WTA-e9258e1f-d5bb-4b3e-920e-e5f2d90c8b52" = Farm Frenzy
"WTA-f8201723-e249-4292-8aff-a40e96796301" = Hoyle Card Games
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 11/13/2013 9:37:40 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 8200
Description = License acquisition failure details.   hr=0xC004C020
 
Error - 11/13/2013 9:37:40 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 1014
Description = Acquisition of End User License failed. hr=0xC004C020  Sku Id=2b88c4f2-ea8f-43cd-805e-4d41346e18a7
 
Error - 11/13/2013 9:41:16 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 8200
Description = License acquisition failure details.   hr=0xC004C020
 
Error - 11/13/2013 9:41:16 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 1014
Description = Acquisition of End User License failed. hr=0xC004C020  Sku Id=2b88c4f2-ea8f-43cd-805e-4d41346e18a7
 
Error - 11/13/2013 9:42:04 PM | Computer Name = AnnaPersonalPC | Source = Microsoft Office 15 | ID = 2011
Description =
 
Error - 11/13/2013 9:42:04 PM | Computer Name = AnnaPersonalPC | Source = Microsoft Office 15 | ID = 2011
Description =
 
Error - 11/13/2013 9:49:01 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 8200
Description = License acquisition failure details.   hr=0x80072EFD
 
Error - 11/13/2013 9:49:01 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 1014
Description = Acquisition of End User License failed. hr=0x80072EFD  Sku Id=2b88c4f2-ea8f-43cd-805e-4d41346e18a7
 
Error - 11/13/2013 9:49:13 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 8200
Description = License acquisition failure details.   hr=0xC004C020
 
Error - 11/13/2013 9:49:13 PM | Computer Name = AnnaPersonalPC | Source = Software Protection Platform Service | ID = 1014
Description = Acquisition of End User License failed. hr=0xC004C020  Sku Id=2b88c4f2-ea8f-43cd-805e-4d41346e18a7
 
[ System Events ]
Error - 11/11/2013 6:05:38 PM | Computer Name = AnnaPersonalPC | Source = Schannel | ID = 36887
Description = A fatal alert was received from the remote endpoint. The TLS protocol
 defined fatal alert code is 40.
 
Error - 11/11/2013 6:05:38 PM | Computer Name = AnnaPersonalPC | Source = Schannel | ID = 36887
Description = A fatal alert was received from the remote endpoint. The TLS protocol
 defined fatal alert code is 40.
 
Error - 11/11/2013 7:17:59 PM | Computer Name = AnnaPersonalPC | Source = Schannel | ID = 36870
Description = A fatal error occurred when attempting to access the SSL server credential
 private key. The error code returned from the cryptographic module is 0x8009030d.
 The internal error state is 10001.
 
Error - 11/11/2013 7:17:59 PM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10010
Description =
 
Error - 11/11/2013 7:17:59 PM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10010
Description =
 
Error - 11/12/2013 11:31:40 AM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10016
Description =
 
Error - 11/12/2013 12:30:17 PM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10010
Description =
 
Error - 11/12/2013 12:30:17 PM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10010
Description =
 
Error - 11/12/2013 12:30:20 PM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10010
Description =
 
Error - 11/12/2013 12:30:20 PM | Computer Name = AnnaPersonalPC | Source = DCOM | ID = 10010
Description =
 
 
< End of report >
 

Any help would be much appreciated.

 

Thank you,

Angel of the Moon


    Advertisements

Register to Remove


#2 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 14 November 2013 - 06:41 PM

Hi and Welcome!!   
 
My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.

 
Having said that....   YBCQLm4.gif   Let's get going!!  
----------
 

Please download DDS from either of these links
 
LINK 1
LINK 2
 
and save it to your desktop.

  • Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.

---------------------------------------------------
Please include the contents of the following in your next reply:
 
DDS.txt
 
Attach.txt
----------

 

weVCzW0.jpg Please download TDSSKiller

  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

----------


Posted Image
 
 

#3 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 14 November 2013 - 09:49 PM

Hello Jeff,
I ran into problems running DDS as an error occurred stating: DDS is not meant to run in Compatibility Mode. The program shall now exit. Everytime I click it, download it from the other link it's the same thing. However, I was able to run TDSSKiller from Kaspersky. Here is the log.

 

22:46:14.0504 4568  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:46:14.0504 4568  UEFI system
22:46:15.0926 4568  ============================================================
22:46:15.0926 4568  Current date / time: 2013/11/14 22:46:15.0926
22:46:15.0926 4568  SystemInfo:
22:46:15.0926 4568  
22:46:15.0926 4568  OS Version: 6.2.9200 ServicePack: 0.0
22:46:15.0926 4568  Product type: Workstation
22:46:15.0926 4568  ComputerName: ANNAPC
22:46:15.0926 4568  UserName: Anna
22:46:15.0926 4568  Windows directory: C:\WINDOWS
22:46:15.0926 4568  System windows directory: C:\WINDOWS
22:46:15.0926 4568  Running under WOW64
22:46:15.0926 4568  Processor architecture: Intel x64
22:46:15.0926 4568  Number of processors: 2
22:46:15.0926 4568  Page size: 0x1000
22:46:15.0926 4568  Boot type: Normal boot
22:46:15.0926 4568  ============================================================
22:46:16.0191 4568  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:46:16.0207 4568  ============================================================
22:46:16.0207 4568  \Device\Harddisk0\DR0:
22:46:16.0207 4568  GPT partitions:
22:46:16.0207 4568  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {9B87CEAA-D114-4139-9784-9DC26ADEBD5A}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1FF800
22:46:16.0207 4568  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {CDC46449-435B-437B-8856-F2843D7CF0C9}, Name: EFI system partition, StartLBA 0x200000, BlocksNum 0xB4000
22:46:16.0207 4568  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {C0108D69-9894-4066-A433-79F55F262F6B}, Name: Microsoft reserved partition, StartLBA 0x2B4000, BlocksNum 0x40000
22:46:16.0207 4568  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {5965C0D2-8857-45E8-A68A-30795830076C}, Name: Basic data partition, StartLBA 0x2F4000, BlocksNum 0x377FE000
22:46:16.0207 4568  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {93E04A30-E510-49CD-9E7D-4A8E774222E7}, Name: , StartLBA 0x37AF2000, BlocksNum 0xAF000
22:46:16.0207 4568  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {7E539EFF-FB07-404B-947D-37D1432F2C2C}, Name: Basic data partition, StartLBA 0x37BA1000, BlocksNum 0x27E5000
22:46:16.0207 4568  MBR partitions:
22:46:16.0207 4568  ============================================================
22:46:16.0238 4568  C: <-> \Device\Harddisk0\DR0\Partition4
22:46:16.0285 4568  D: <-> \Device\Harddisk0\DR0\Partition6
22:46:16.0285 4568  ============================================================
22:46:16.0285 4568  Initialize success
22:46:16.0285 4568  ============================================================
22:46:17.0256 3844  ============================================================
22:46:17.0256 3844  Scan started
22:46:17.0256 3844  Mode: Manual;
22:46:17.0256 3844  ============================================================
22:46:17.0600 3844  ================ Scan system memory ========================
22:46:17.0600 3844  System memory - ok
22:46:17.0600 3844  ================ Scan services =============================
22:46:17.0818 3844  [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1 ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
22:46:17.0818 3844  1394ohci - ok
22:46:17.0834 3844  [ AD508A1A46EC21B740AB31C28EFDFDB1 ] 3ware           C:\WINDOWS\system32\drivers\3ware.sys
22:46:17.0834 3844  3ware - ok
22:46:17.0865 3844  [ 3D30878A269D934100FA5F972E53AF39 ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
22:46:17.0865 3844  ACPI - ok
22:46:17.0881 3844  [ AC8279D229398BCF05C3154ADCA86813 ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
22:46:17.0881 3844  acpiex - ok
22:46:17.0881 3844  [ A8970D9BF23CD309E0403978A1B58F3F ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
22:46:17.0881 3844  acpipagr - ok
22:46:17.0912 3844  [ 111A89C99C5B4F1A7BCE5F643DD86F65 ] AcpiPmi         C:\WINDOWS\System32\drivers\acpipmi.sys
22:46:17.0912 3844  AcpiPmi - ok
22:46:17.0912 3844  [ 5758387D68A20AE7D3245011B07E36E7 ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
22:46:17.0912 3844  acpitime - ok
22:46:17.0943 3844  [ 7C1FDF1B48298CBA7CE4BDD4978951AD ] ADP80XX         C:\WINDOWS\system32\drivers\ADP80XX.SYS
22:46:17.0943 3844  ADP80XX - ok
22:46:17.0990 3844  [ B19CA8E441D35AA2B1EE51C10B27DA1B ] AeLookupSvc     C:\WINDOWS\System32\aelupsvc.dll
22:46:17.0990 3844  AeLookupSvc - ok
22:46:17.0990 3844  [ 239268BAB58EAE9A3FF4E08334C00451 ] AFD             C:\WINDOWS\system32\drivers\afd.sys
22:46:18.0006 3844  AFD - ok
22:46:18.0006 3844  [ 7DFAEBA9AD62D20102B576D5CAC45EC8 ] agp440          C:\WINDOWS\system32\drivers\agp440.sys
22:46:18.0006 3844  agp440 - ok
22:46:18.0037 3844  [ 8E8E34B7BA059050EED827410D0697A2 ] ahcache         C:\WINDOWS\system32\DRIVERS\ahcache.sys
22:46:18.0037 3844  ahcache - ok
22:46:18.0068 3844  [ A91D8E1E433EFB32551BCE69037E1CE7 ] ALG             C:\WINDOWS\System32\alg.exe
22:46:18.0068 3844  ALG - ok
22:46:18.0084 3844  [ FED8F396537A5E4FA58E6C8BA8070081 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
22:46:18.0099 3844  AMD External Events Utility - ok
22:46:18.0131 3844  AMD FUEL Service - ok
22:46:18.0146 3844  [ 7589DE749DB6F71A68489DCE04158729 ] AmdK8           C:\WINDOWS\System32\drivers\amdk8.sys
22:46:18.0146 3844  AmdK8 - ok
22:46:18.0365 3844  [ EB3F3FDC7D0EC927A4AB31F9F6235A7C ] amdkmdag        C:\WINDOWS\system32\DRIVERS\atikmdag.sys
22:46:18.0443 3844  amdkmdag - ok
22:46:18.0459 3844  [ 160159231941801A458FEF8A73D494AC ] amdkmdap        C:\WINDOWS\system32\DRIVERS\atikmpag.sys
22:46:18.0459 3844  amdkmdap - ok
22:46:18.0506 3844  [ B46D2D89AFF8A9490FA8C98C7A5616E3 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
22:46:18.0506 3844  AmdPPM - ok
22:46:18.0506 3844  [ D2BF2F94A47D332814910FD47C6BBCD2 ] amdsata         C:\WINDOWS\system32\drivers\amdsata.sys
22:46:18.0506 3844  amdsata - ok
22:46:18.0521 3844  [ A8E04943C7BBA7219AA50400272C3C6E ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
22:46:18.0521 3844  amdsbs - ok
22:46:18.0537 3844  [ CEA5F4F27CFC08E3A44D576811B35F50 ] amdxata         C:\WINDOWS\system32\drivers\amdxata.sys
22:46:18.0537 3844  amdxata - ok
22:46:18.0568 3844  [ F2154A205F4B784B61A72AEBC72BDC5F ] AODDriver4.2    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
22:46:18.0568 3844  AODDriver4.2 - ok
22:46:18.0615 3844  [ 9DCB42905F1EBF9CEC57EE5DF0BDA965 ] AppHostSvc      C:\WINDOWS\system32\inetsrv\apphostsvc.dll
22:46:18.0615 3844  AppHostSvc - ok
22:46:18.0646 3844  [ 04951A9A937CBE28A2D3FEEA360B6D1F ] AppID           C:\WINDOWS\system32\drivers\appid.sys
22:46:18.0646 3844  AppID - ok
22:46:18.0678 3844  [ C0DC3F58214A227980AEB091CFD2F973 ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
22:46:18.0678 3844  AppIDSvc - ok
22:46:18.0693 3844  [ 7E790DE2487CEDB349D1750B9E47F090 ] Appinfo         C:\WINDOWS\System32\appinfo.dll
22:46:18.0693 3844  Appinfo - ok
22:46:18.0740 3844  [ 4B964AE0DF433A3BFA7BD24713BC2E9B ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
22:46:18.0740 3844  AppReadiness - ok
22:46:18.0787 3844  [ 27334B4E29DC8E26FF86E0F075A6CED5 ] AppXSvc         C:\WINDOWS\system32\appxdeploymentserver.dll
22:46:18.0803 3844  AppXSvc - ok
22:46:18.0818 3844  [ 65045784366F7EC5FB4E71BCF923187B ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
22:46:18.0818 3844  arcsas - ok
22:46:18.0896 3844  [ AA2E8C6B8D7EA7BAF04C988801927F48 ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:46:18.0896 3844  aspnet_state - ok
22:46:18.0912 3844  [ 9F34AA1124EEA112E49E48258B1D6394 ] aswFsBlk        C:\WINDOWS\system32\drivers\aswFsBlk.sys
22:46:18.0912 3844  aswFsBlk - ok
22:46:18.0928 3844  [ 5C49AB607897C94E123EC8364FF4BF61 ] aswMonFlt       C:\WINDOWS\system32\drivers\aswMonFlt.sys
22:46:18.0928 3844  aswMonFlt - ok
22:46:18.0959 3844  [ 679712B7A353EE665B9301592164A172 ] aswRdr          C:\WINDOWS\system32\drivers\aswRdr2.sys
22:46:18.0959 3844  aswRdr - ok
22:46:18.0975 3844  [ C04F7B373881009D7994D9BF55D24AB4 ] aswRvrt         C:\WINDOWS\system32\drivers\aswRvrt.sys
22:46:18.0975 3844  aswRvrt - ok
22:46:19.0006 3844  [ 1BA60C77EB3CDB6129DAD25BAF675F43 ] aswSnx          C:\WINDOWS\system32\drivers\aswSnx.sys
22:46:19.0006 3844  aswSnx - ok
22:46:19.0021 3844  [ 79ADA401A6E2054F110E7FBDFAC71942 ] aswSP           C:\WINDOWS\system32\drivers\aswSP.sys
22:46:19.0021 3844  aswSP - ok
22:46:19.0053 3844  [ 59787B95DD9CA44CB139D96863438587 ] aswVmm          C:\WINDOWS\system32\drivers\aswVmm.sys
22:46:19.0053 3844  aswVmm - ok
22:46:19.0053 3844  [ 74B14192CF79A72F7536B27CB8814FBD ] atapi           C:\WINDOWS\system32\drivers\atapi.sys
22:46:19.0053 3844  atapi - ok
22:46:19.0084 3844  [ 4903CBC14742B5AB4DCF7A92F7DEC483 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
22:46:19.0084 3844  AudioEndpointBuilder - ok
22:46:19.0115 3844  [ 86DD7884124D363A63CCE7A11FDEBBED ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
22:46:19.0115 3844  Audiosrv - ok
22:46:19.0178 3844  [ 4D41D30E2FAB3307967C7A0B045DC874 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
22:46:19.0178 3844  avast! Antivirus - ok
22:46:19.0209 3844  [ 96E8CAF20FC4B6C31CAD7816A801EB78 ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
22:46:19.0209 3844  AxInstSV - ok
22:46:19.0256 3844  [ A4A73F631FE2AA2826FBE4A399B04DEF ] b06bdrv         C:\WINDOWS\system32\drivers\bxvbda.sys
22:46:19.0256 3844  b06bdrv - ok
22:46:19.0287 3844  [ 8CC7F7E4AFCBA605921B137ED7992C68 ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
22:46:19.0287 3844  BasicDisplay - ok
22:46:19.0303 3844  [ 2748E116F8621A4DB0D39FCDD7318C01 ] BasicRender     C:\WINDOWS\System32\drivers\BasicRender.sys
22:46:19.0303 3844  BasicRender - ok
22:46:19.0318 3844  [ C1ABB0F7E3BEA48A0417BDF6FF14AB21 ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
22:46:19.0318 3844  bcmfn2 - ok
22:46:19.0334 3844  [ BBE61A40665B83488901E41082A6097D ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
22:46:19.0350 3844  BDESVC - ok
22:46:19.0365 3844  [ EC19013E4CF87609534165DF897274D6 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
22:46:19.0365 3844  Beep - ok
22:46:19.0396 3844  [ 6468B696C65775D51A06615830E0E79D ] BFE             C:\WINDOWS\System32\bfe.dll
22:46:19.0412 3844  BFE - ok
22:46:19.0443 3844  [ 15225081966C785A9192782401643FD4 ] BITS            C:\WINDOWS\System32\qmgr.dll
22:46:19.0459 3844  BITS - ok
22:46:19.0490 3844  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:46:19.0506 3844  Bonjour Service - ok
22:46:19.0506 3844  [ 6B4FFFDDC618FCF64473CAA86E305697 ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
22:46:19.0506 3844  bowser - ok
22:46:19.0521 3844  [ 748141CC03DF40C38F17D3F96BB15C80 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
22:46:19.0537 3844  BrokerInfrastructure - ok
22:46:19.0537 3844  [ D528D6A92D187777691993DD757AF19A ] Browser         C:\WINDOWS\System32\browser.dll
22:46:19.0537 3844  Browser - ok
22:46:19.0553 3844  [ A8F23D453A424FF4DE04989C4727ECC7 ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
22:46:19.0553 3844  BthAvrcpTg - ok
22:46:19.0568 3844  [ 746B9F94214915AECDE4B7FEA5FF9664 ] BthHFEnum       C:\WINDOWS\System32\drivers\bthhfenum.sys
22:46:19.0568 3844  BthHFEnum - ok
22:46:19.0568 3844  [ 71FE2A48E4C93DDB9798C024880B6C07 ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
22:46:19.0568 3844  bthhfhid - ok
22:46:19.0584 3844  [ 07E33226AD218A2A162662A05CAFB52F ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
22:46:19.0584 3844  BTHMODEM - ok
22:46:19.0615 3844  [ E5E48FEED73D463175EAB1542495191C ] bthserv         C:\WINDOWS\system32\bthserv.dll
22:46:19.0615 3844  bthserv - ok
22:46:19.0631 3844  [ 2FA6510E33F7DEFEC03658B74101A9B9 ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
22:46:19.0631 3844  cdfs - ok
22:46:19.0631 3844  [ C6796EA22B513E3457514D92DCDB1A3D ] cdrom           C:\WINDOWS\System32\drivers\cdrom.sys
22:46:19.0646 3844  cdrom - ok
22:46:19.0646 3844  [ AB285CE3431FF3D2ACE669245874C1C7 ] CertPropSvc     C:\WINDOWS\System32\certprop.dll
22:46:19.0646 3844  CertPropSvc - ok
22:46:19.0662 3844  [ BE9936EDD3267FAAFF94A7835867F00B ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
22:46:19.0662 3844  circlass - ok
22:46:19.0693 3844  [ 7F006813C2AFE622C13D7AF94F56CD07 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
22:46:19.0693 3844  CLFS - ok
22:46:19.0709 3844  [ EF6EF85DADC3184A10D8F2F7159973CB ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
22:46:19.0709 3844  CmBatt - ok
22:46:19.0740 3844  [ 825BE21E6395E00698D8A23955A87972 ] CNG             C:\WINDOWS\system32\Drivers\cng.sys
22:46:19.0740 3844  CNG - ok
22:46:19.0756 3844  [ 03AAED827C36F35D70900558B8274905 ] CompositeBus    C:\WINDOWS\System32\drivers\CompositeBus.sys
22:46:19.0771 3844  CompositeBus - ok
22:46:19.0771 3844  COMSysApp - ok
22:46:19.0771 3844  [ A1FF7DFBFBE164CF92603C651D304DD2 ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
22:46:19.0771 3844  condrv - ok
22:46:19.0818 3844  [ 0EFE4B5884A8032617826A4D76F80969 ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
22:46:19.0818 3844  CryptSvc - ok
22:46:19.0818 3844  [ 315BA4BC19316D72B2E037534E048B93 ] dam             C:\WINDOWS\system32\drivers\dam.sys
22:46:19.0818 3844  dam - ok
22:46:19.0850 3844  [ 3FD5AE42EC87C6F532A931F96BE731DD ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
22:46:19.0865 3844  DcomLaunch - ok
22:46:19.0896 3844  [ F4CCAADC2C78F57E4F16B24C9201CE22 ] defragsvc       C:\WINDOWS\System32\defragsvc.dll
22:46:19.0896 3844  defragsvc - ok
22:46:19.0928 3844  [ 0BC71D4D3B5883903C37BF4E13B0F0C5 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
22:46:19.0928 3844  DeviceAssociationService - ok
22:46:19.0943 3844  [ 752A457320A946E03C3AA86C3ACD735E ] DeviceInstall   C:\WINDOWS\system32\umpnpmgr.dll
22:46:19.0943 3844  DeviceInstall - ok
22:46:19.0959 3844  [ 5DB26D7E0216D0BF364A81D3829AD7B9 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
22:46:19.0959 3844  Dfsc - ok
22:46:19.0975 3844  [ 8B107F55FD61654A6C9F1B819AEC5FC4 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
22:46:19.0975 3844  Dhcp - ok
22:46:19.0975 3844  [ 4D40C9B33F738797CF50E77CB7C53E85 ] disk            C:\WINDOWS\system32\drivers\disk.sys
22:46:19.0975 3844  disk - ok
22:46:20.0006 3844  [ EB70A894708D1BC176AFD690FF06085F ] dmvsc           C:\WINDOWS\System32\drivers\dmvsc.sys
22:46:20.0006 3844  dmvsc - ok
22:46:20.0037 3844  [ 5BAF7714E68F93515A937A3FA8587EF9 ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
22:46:20.0037 3844  Dnscache - ok
22:46:20.0068 3844  [ 50288EA079BB520C2B8C8A154202D518 ] dot3svc         C:\WINDOWS\System32\dot3svc.dll
22:46:20.0068 3844  dot3svc - ok
22:46:20.0084 3844  [ 281BEE07BA97E3E98D12A822D923D0D8 ] DPS             C:\WINDOWS\system32\dps.dll
22:46:20.0100 3844  DPS - ok
22:46:20.0100 3844  [ DDC11A202207C0400CBE07315B8FDE5E ] drmkaud         C:\WINDOWS\system32\drivers\drmkaud.sys
22:46:20.0100 3844  drmkaud - ok
22:46:20.0115 3844  [ 5B074F14F5DD6418F46EE4CA2DEB7EA8 ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
22:46:20.0115 3844  DsmSvc - ok
22:46:20.0146 3844  [ DA8E85F1BE0C9B7D2EE2949248A389D8 ] DXGKrnl         C:\WINDOWS\System32\drivers\dxgkrnl.sys
22:46:20.0162 3844  DXGKrnl - ok
22:46:20.0209 3844  [ 6073537F250B45E1CB2A02E97F0FE1B2 ] Eaphost         C:\WINDOWS\System32\eapsvc.dll
22:46:20.0209 3844  Eaphost - ok
22:46:20.0271 3844  [ 114BCFDF367FF37C3F1B0A96AF542E4D ] ebdrv           C:\WINDOWS\system32\drivers\evbda.sys
22:46:20.0318 3844  ebdrv - ok
22:46:20.0350 3844  [ F6F209DDB94959BA104FC8FC87C53759 ] EFS             C:\WINDOWS\System32\lsass.exe
22:46:20.0350 3844  EFS - ok
22:46:20.0381 3844  [ 43531A5993380CC5113242C29D265FD9 ] EhStorClass     C:\WINDOWS\system32\drivers\EhStorClass.sys
22:46:20.0381 3844  EhStorClass - ok
22:46:20.0396 3844  [ 6F8E738A9505A388B1157FDDE7B3101B ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
22:46:20.0396 3844  EhStorTcgDrv - ok
22:46:20.0412 3844  [ DFFFAE1442BA4076E18EED5E406FA0D3 ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
22:46:20.0412 3844  ErrDev - ok
22:46:20.0443 3844  [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3 ] EventSystem     C:\WINDOWS\system32\es.dll
22:46:20.0443 3844  EventSystem - ok
22:46:20.0459 3844  [ 7729D294A555C7AEB281ED8E4D0E01E4 ] exfat           C:\WINDOWS\system32\drivers\exfat.sys
22:46:20.0459 3844  exfat - ok
22:46:20.0459 3844  [ 7C4E0D5900B2A1D11EDD626D6DDB937B ] fastfat         C:\WINDOWS\system32\drivers\fastfat.sys
22:46:20.0475 3844  fastfat - ok
22:46:20.0506 3844  [ 2BC8532ABF2B3756B78FA1DA54147DDE ] Fax             C:\WINDOWS\system32\fxssvc.exe
22:46:20.0506 3844  Fax - ok
22:46:20.0506 3844  [ 5D8402613E778B3BD45E687A8372710B ] fdc             C:\WINDOWS\System32\drivers\fdc.sys
22:46:20.0521 3844  fdc - ok
22:46:20.0537 3844  [ DC1A78BCCCB7EE53D6FD3BD615A8E222 ] fdPHost         C:\WINDOWS\system32\fdPHost.dll
22:46:20.0537 3844  fdPHost - ok
22:46:20.0553 3844  [ E5AD448F2DC84B1CF387FA7F2A3D1936 ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
22:46:20.0553 3844  FDResPub - ok
22:46:20.0568 3844  [ 0046E0BD031213D37123876B0D0FA61C ] fhsvc           C:\WINDOWS\system32\fhsvc.dll
22:46:20.0568 3844  fhsvc - ok
22:46:20.0584 3844  [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5 ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
22:46:20.0584 3844  FileInfo - ok
22:46:20.0584 3844  [ A1A66C4FDAFD6B0289523232AFB7D8AF ] Filetrace       C:\WINDOWS\system32\drivers\filetrace.sys
22:46:20.0584 3844  Filetrace - ok
22:46:20.0600 3844  [ BE743083CF7063C486A4398E3AEFE59A ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
22:46:20.0600 3844  flpydisk - ok
22:46:20.0600 3844  [ 60D5067FCE6D9433D35E04C01D8538B3 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
22:46:20.0615 3844  FltMgr - ok
22:46:20.0646 3844  [ 183CA7699474FDE235853967D1DA4D9B ] FontCache       C:\WINDOWS\system32\FntCache.dll
22:46:20.0646 3844  FontCache - ok
22:46:20.0693 3844  [ 1C52387BF5A127F5F3BFB31288F30D93 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:46:20.0709 3844  FontCache3.0.0.0 - ok
22:46:20.0740 3844  [ 35005534E600E993A90B036E4E599F2B ] FsDepends       C:\WINDOWS\system32\drivers\FsDepends.sys
22:46:20.0740 3844  FsDepends - ok
22:46:20.0756 3844  [ 09F460AFEDCA03F3BF6E07D1CCC9AC42 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:46:20.0756 3844  Fs_Rec - ok
22:46:20.0803 3844  [ 83E1F0983B02A6F8EC764D18E24ECF10 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
22:46:20.0818 3844  fvevol - ok
22:46:20.0834 3844  [ 9591D0B9351ED489EAFD9D1CE52A8015 ] FxPPM           C:\WINDOWS\System32\drivers\fxppm.sys
22:46:20.0834 3844  FxPPM - ok
22:46:20.0834 3844  [ FC3EF65EE20D39F8749C2218DBA681CA ] gagp30kx        C:\WINDOWS\system32\drivers\gagp30kx.sys
22:46:20.0834 3844  gagp30kx - ok
22:46:20.0912 3844  [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
22:46:20.0928 3844  GamesAppService - ok
22:46:20.0943 3844  [ 0BF5CAD281E25F1418E5B8875DC5ADD1 ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
22:46:20.0943 3844  gencounter - ok
22:46:20.0975 3844  [ FDA72810CA2F8409D9B31E833C448E34 ] GPIOClx0101     C:\WINDOWS\system32\Drivers\msgpioclx.sys
22:46:20.0975 3844  GPIOClx0101 - ok
22:46:21.0021 3844  [ 0BDE0FCF597E9B65600121EF54FF8340 ] gpsvc           C:\WINDOWS\System32\gpsvc.dll
22:46:21.0037 3844  gpsvc - ok
22:46:21.0053 3844  [ 03909BDBFF0DCACCABF2B2D4ADEE44DC ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
22:46:21.0068 3844  HDAudBus - ok
22:46:21.0068 3844  [ 10A70BC1871CD955D85CD88372724906 ] HidBatt         C:\WINDOWS\System32\drivers\HidBatt.sys
22:46:21.0068 3844  HidBatt - ok
22:46:21.0084 3844  [ 1EA1B4FABB8CC348E73CA90DBA22E104 ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
22:46:21.0084 3844  HidBth - ok
22:46:21.0100 3844  [ C241A8BAFBBFC90176EA0F5240EACC17 ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
22:46:21.0100 3844  hidi2c - ok
22:46:21.0100 3844  [ 9BDDEE26255421017E161CCB9D5EDA95 ] HidIr           C:\WINDOWS\System32\drivers\hidir.sys
22:46:21.0100 3844  HidIr - ok
22:46:21.0115 3844  [ 449A20A674AA3FAA7F0DD4E33EE2DC20 ] hidserv         C:\WINDOWS\system32\hidserv.dll
22:46:21.0115 3844  hidserv - ok
22:46:21.0115 3844  [ F31397220D9687E11EB448649AA6E038 ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
22:46:21.0115 3844  HidUsb - ok
22:46:21.0146 3844  [ 7BF3ADCBD021D4F4A84CF40EB49C71B5 ] hkmsvc          C:\WINDOWS\system32\kmsvc.dll
22:46:21.0146 3844  hkmsvc - ok
22:46:21.0162 3844  [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
22:46:21.0162 3844  HomeGroupListener - ok
22:46:21.0193 3844  [ BE5F89BAFBD4272D5A0C0A37B97865ED ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
22:46:21.0209 3844  HomeGroupProvider - ok
22:46:21.0271 3844  [ E1C037A7E05FD39E6C1AF93CEEFDC53A ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
22:46:21.0271 3844  HP Support Assistant Service - ok
22:46:21.0318 3844  [ E2550FBBBA31E2D4F9757E0A533689F0 ] HPConnectedRemote c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
22:46:21.0318 3844  HPConnectedRemote - ok
22:46:21.0396 3844  [ 9B7EDD3FE7C211C36E921D34D18A3A0A ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
22:46:21.0412 3844  hpqwmiex - ok
22:46:21.0443 3844  [ C230B671A7646C9B8FAC0B4D0DB65B71 ] HPRegistrationSvc c:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HPRegistrationService.exe
22:46:21.0443 3844  HPRegistrationSvc - ok
22:46:21.0475 3844  [ A6AACEA4C785789BDA5912AD1FEDA80D ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
22:46:21.0475 3844  HpSAMD - ok
22:46:21.0506 3844  [ 3502776E366C913D49C0DA928AE3E6CB ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
22:46:21.0521 3844  HTTP - ok
22:46:21.0537 3844  [ 90656C0B3864804B090434EFC582404F ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
22:46:21.0537 3844  hwpolicy - ok
22:46:21.0553 3844  [ 6D6F9E3BF0484967E52F7E846BFF1CA1 ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
22:46:21.0553 3844  hyperkbd - ok
22:46:21.0568 3844  [ 907C870F8C31F8DDD6F090857B46AB25 ] HyperVideo      C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
22:46:21.0568 3844  HyperVideo - ok
22:46:21.0568 3844  [ 84CFC5EFA97D0C965EDE1D56F116A541 ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
22:46:21.0568 3844  i8042prt - ok
22:46:21.0584 3844  [ 5D90E32E36CE5D4C535D17CE08AEAF05 ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
22:46:21.0584 3844  iaLPSSi_GPIO - ok
22:46:21.0584 3844  [ DD05E7E80F52ADE9AEB292819920F32C ] iaLPSSi_I2C     C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
22:46:21.0584 3844  iaLPSSi_I2C - ok
22:46:21.0615 3844  [ 08BFE413B0B4AA8DFA4B5684CE06D3DC ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
22:46:21.0615 3844  iaStorAV - ok
22:46:21.0631 3844  [ A2200C3033FA4EF249FC096A7A7D02A2 ] iaStorV         C:\WINDOWS\system32\drivers\iaStorV.sys
22:46:21.0631 3844  iaStorV - ok
22:46:21.0631 3844  IEEtwCollectorService - ok
22:46:21.0678 3844  [ B82255670D270B75D2D2F0F8747D1443 ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
22:46:21.0693 3844  IKEEXT - ok
22:46:21.0787 3844  [ C2F868881D48A568B525255F084EF063 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
22:46:21.0818 3844  IntcAzAudAddService - ok
22:46:21.0834 3844  [ 4E448FCFFD00E8D657CD9E48D3E47157 ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
22:46:21.0834 3844  intelide - ok
22:46:21.0865 3844  [ C1A9592EE57C6FF0A0904B9DFD55942D ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
22:46:21.0865 3844  intelpep - ok
22:46:21.0865 3844  [ 47E74A8E53C7C24DCE38311E1451C1D9 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
22:46:21.0865 3844  intelppm - ok
22:46:21.0896 3844  [ 9DB76D7F9E4E53EFE5DD8C53DE837514 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:46:21.0896 3844  IpFilterDriver - ok
22:46:21.0928 3844  [ DFC4050D58565ADBEE793A8D4AEBDAE6 ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
22:46:21.0943 3844  iphlpsvc - ok
22:46:21.0943 3844  [ 9949A3C7590B8C536C05312205079A82 ] IPMIDRV         C:\WINDOWS\System32\drivers\IPMIDrv.sys
22:46:21.0943 3844  IPMIDRV - ok
22:46:21.0943 3844  [ E23D32BAF152FBE35F18C6A2AB8EF271 ] IPNAT           C:\WINDOWS\system32\drivers\ipnat.sys
22:46:21.0959 3844  IPNAT - ok
22:46:21.0975 3844  [ AE44C526AB5F8A487D941CEB57B10C97 ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
22:46:21.0975 3844  IRENUM - ok
22:46:21.0975 3844  [ 8AFEEA3955AA43616A60F133B1D25F21 ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
22:46:21.0975 3844  isapnp - ok
22:46:21.0990 3844  [ 034D4BD9DC67C64F3A4C8A049B5173BF ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
22:46:21.0990 3844  iScsiPrt - ok
22:46:22.0021 3844  [ 8BE92376799B6B44D543E8D07CDCF885 ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
22:46:22.0021 3844  kbdclass - ok
22:46:22.0021 3844  [ FB6E47E569D4872ABEB506BE03A45FBA ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
22:46:22.0021 3844  kbdhid - ok
22:46:22.0037 3844  [ 813871C7D402A05F2E3A7075F9584A05 ] kdnic           C:\WINDOWS\system32\DRIVERS\kdnic.sys
22:46:22.0037 3844  kdnic - ok
22:46:22.0053 3844  [ F6F209DDB94959BA104FC8FC87C53759 ] KeyIso          C:\WINDOWS\system32\lsass.exe
22:46:22.0053 3844  KeyIso - ok
22:46:22.0068 3844  [ ADDECBCC777665BD113BED437E602AB0 ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
22:46:22.0068 3844  KSecDD - ok
22:46:22.0084 3844  [ 7296EA420134EAC390798B3232D066A4 ] KSecPkg         C:\WINDOWS\system32\Drivers\ksecpkg.sys
22:46:22.0084 3844  KSecPkg - ok
22:46:22.0084 3844  [ 11AFB527AA370B1DAFD5C36F35F6D45F ] ksthunk         C:\WINDOWS\system32\drivers\ksthunk.sys
22:46:22.0084 3844  ksthunk - ok
22:46:22.0115 3844  [ 32B1A8351160F307A8C66BCB0F94A9C2 ] KtmRm           C:\WINDOWS\system32\msdtckrm.dll
22:46:22.0115 3844  KtmRm - ok
22:46:22.0162 3844  [ 27B58E16CF895AC1F1A97C04814C2239 ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
22:46:22.0162 3844  LanmanServer - ok
22:46:22.0178 3844  [ D0D9C2ECA4D03A8F06DCD91236B90C98 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
22:46:22.0178 3844  LanmanWorkstation - ok
22:46:22.0225 3844  [ EE289BD147FDFF95EF1B9BD65D3B974A ] lfsvc           C:\WINDOWS\System32\GeofenceMonitorService.dll
22:46:22.0225 3844  lfsvc - ok
22:46:22.0225 3844  [ C09010B3680860131631F53E8FE7BAD8 ] lltdio          C:\WINDOWS\system32\DRIVERS\lltdio.sys
22:46:22.0225 3844  lltdio - ok
22:46:22.0256 3844  [ 00E070FC0C673311AFD4B068D1242780 ] lltdsvc         C:\WINDOWS\System32\lltdsvc.dll
22:46:22.0256 3844  lltdsvc - ok
22:46:22.0287 3844  [ D113FAD71A5E67AA94B32A0F8828D265 ] lmhosts         C:\WINDOWS\System32\lmhsvc.dll
22:46:22.0287 3844  lmhosts - ok
22:46:22.0334 3844  [ C755AE4635457AA2A11F79C0DF857ABC ] LSI_SAS         C:\WINDOWS\system32\drivers\lsi_sas.sys
22:46:22.0334 3844  LSI_SAS - ok
22:46:22.0334 3844  [ ADAC09CBE7A2040B7F68B5E5C9A75141 ] LSI_SAS2        C:\WINDOWS\system32\drivers\lsi_sas2.sys
22:46:22.0334 3844  LSI_SAS2 - ok
22:46:22.0350 3844  [ 04D1274BB9BBCCF12BD12374002AA191 ] LSI_SAS3        C:\WINDOWS\system32\drivers\lsi_sas3.sys
22:46:22.0350 3844  LSI_SAS3 - ok
22:46:22.0350 3844  [ 327469EEF3833D0C584B7E88A76AEC0C ] LSI_SSS         C:\WINDOWS\system32\drivers\lsi_sss.sys
22:46:22.0350 3844  LSI_SSS - ok
22:46:22.0365 3844  [ B6B69FF200F68888A7FAFDF204D00C91 ] LSM             C:\WINDOWS\System32\lsm.dll
22:46:22.0365 3844  LSM - ok
22:46:22.0381 3844  [ 5EF604B0698F4FA962778285E8C5F1F2 ] luafv           C:\WINDOWS\system32\drivers\luafv.sys
22:46:22.0381 3844  luafv - ok
22:46:22.0396 3844  [ EB5C03A070F30D64A6DF80E53B22F53F ] megasas         C:\WINDOWS\system32\drivers\megasas.sys
22:46:22.0396 3844  megasas - ok
22:46:22.0412 3844  [ F6F13533196DE7A582D422B0241E4363 ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
22:46:22.0412 3844  megasr - ok
22:46:22.0443 3844  [ FD788C2D96EA91469A3C1D13E80D7473 ] MMCSS           C:\WINDOWS\system32\mmcss.dll
22:46:22.0443 3844  MMCSS - ok
22:46:22.0459 3844  [ 8B38C44F69259987C95135C9627E2378 ] Modem           C:\WINDOWS\system32\drivers\modem.sys
22:46:22.0459 3844  Modem - ok
22:46:22.0459 3844  [ 601589000CC90F0DF8DA2CC254A3CCC9 ] monitor         C:\WINDOWS\System32\drivers\monitor.sys
22:46:22.0459 3844  monitor - ok
22:46:22.0475 3844  [ CEAC6D40FE887CE8406C2393CF97DE06 ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
22:46:22.0475 3844  mouclass - ok
22:46:22.0490 3844  [ 02D98BF804084E9A0D69D1C69B02CCA9 ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
22:46:22.0490 3844  mouhid - ok
22:46:22.0490 3844  [ 515549560D481138E6E21AF7C6998E56 ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
22:46:22.0490 3844  mountmgr - ok
22:46:22.0506 3844  [ F170510BE94CF45E3C6274578F6204B2 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
22:46:22.0506 3844  mpsdrv - ok
22:46:22.0521 3844  [ D186C5844393252147BE934F3871DB7A ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
22:46:22.0537 3844  MpsSvc - ok
22:46:22.0537 3844  [ 59DCEC7499095DE5AED741358037AE2D ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
22:46:22.0537 3844  MRxDAV - ok
22:46:22.0553 3844  [ 6129EDB793A4255B1E2FB41773AC9D9A ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:46:22.0553 3844  mrxsmb - ok
22:46:22.0568 3844  [ 295771B092D4F7FCF2B62F80CCD14320 ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
22:46:22.0568 3844  mrxsmb10 - ok
22:46:22.0584 3844  [ AAF56E4E84D35411B4E446C445732DFE ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
22:46:22.0584 3844  mrxsmb20 - ok
22:46:22.0600 3844  [ 4E888019078AC363076A5433E89AA4F8 ] MsBridge        C:\WINDOWS\system32\DRIVERS\bridge.sys
22:46:22.0600 3844  MsBridge - ok
22:46:22.0631 3844  [ A082C17D14D0790E27D064EA4B138AE1 ] MSDTC           C:\WINDOWS\System32\msdtc.exe
22:46:22.0631 3844  MSDTC - ok
22:46:22.0646 3844  [ D13329FBF8345B28AB30F44CC247DC08 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
22:46:22.0646 3844  Msfs - ok
22:46:22.0662 3844  [ C6B474E46F9E543B875981ED3FFE6ADD ] msgpiowin32     C:\WINDOWS\System32\drivers\msgpiowin32.sys
22:46:22.0662 3844  msgpiowin32 - ok
22:46:22.0678 3844  [ 65C92EB9D08DB5C69F28C7FFD4E84E31 ] mshidkmdf       C:\WINDOWS\System32\drivers\mshidkmdf.sys
22:46:22.0678 3844  mshidkmdf - ok
22:46:22.0678 3844  [ 52299F086AC2DAFD100DD5DC4A8614BA ] mshidumdf       C:\WINDOWS\System32\drivers\mshidumdf.sys
22:46:22.0678 3844  mshidumdf - ok
22:46:22.0693 3844  [ 36D92AF3343C3A3E57FEF11C449AEA4C ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
22:46:22.0693 3844  msisadrv - ok
22:46:22.0725 3844  [ 810F8A0A0680662BB0CE44D0E2CEF90C ] MSiSCSI         C:\WINDOWS\system32\iscsiexe.dll
22:46:22.0725 3844  MSiSCSI - ok
22:46:22.0725 3844  msiserver - ok
22:46:22.0740 3844  [ A9BBBD2BAE6142253B9195E949AC2E8D ] MSKSSRV         C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:46:22.0740 3844  MSKSSRV - ok
22:46:22.0740 3844  [ 375E44168F2DFB91A68B8A3F619C5A7C ] MsLldp          C:\WINDOWS\system32\DRIVERS\mslldp.sys
22:46:22.0740 3844  MsLldp - ok
22:46:22.0756 3844  [ 7B2128EB875DCBC006E6A913211006D6 ] MSPCLOCK        C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:46:22.0756 3844  MSPCLOCK - ok
22:46:22.0756 3844  [ 1E88171579B218115C7A772F8DE04BD8 ] MSPQM           C:\WINDOWS\system32\drivers\MSPQM.sys
22:46:22.0756 3844  MSPQM - ok
22:46:22.0771 3844  [ BBE2A455053E63BECBF42C2F9B21FAE0 ] MsRPC           C:\WINDOWS\system32\drivers\MsRPC.sys
22:46:22.0771 3844  MsRPC - ok
22:46:22.0787 3844  [ 8D6B7D515C5CBCDB75B928A0B73C3C5E ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
22:46:22.0787 3844  mssmbios - ok
22:46:22.0787 3844  [ 115019AE01E0EB9C048530D2928AB4A2 ] MSTEE           C:\WINDOWS\system32\drivers\MSTEE.sys
22:46:22.0803 3844  MSTEE - ok
22:46:22.0803 3844  [ 96D604A35070360F0DD4A7A8AF410B5E ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
22:46:22.0803 3844  MTConfig - ok
22:46:22.0803 3844  [ 619CA29326B82372621DB2C0964D8365 ] Mup             C:\WINDOWS\system32\Drivers\mup.sys
22:46:22.0818 3844  Mup - ok
22:46:22.0818 3844  [ B8C35C94DCB2DFEAF03BB42131F2F77F ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
22:46:22.0818 3844  mvumis - ok
22:46:22.0850 3844  [ 41A45D2A75494EABF2806EA051E00376 ] napagent        C:\WINDOWS\system32\qagentRT.dll
22:46:22.0850 3844  napagent - ok
22:46:22.0865 3844  [ CF8B989D89D6807B887690F2CF24EFD9 ] NativeWifiP     C:\WINDOWS\system32\DRIVERS\nwifi.sys
22:46:22.0865 3844  NativeWifiP - ok
22:46:22.0896 3844  [ 71E3C0100AA19D11373CCEB2F51A6008 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
22:46:22.0912 3844  NcaSvc - ok
22:46:22.0928 3844  [ 51DF09CAB2CAC64FEE3E371D9028ED01 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
22:46:22.0928 3844  NcbService - ok
22:46:22.0943 3844  [ 2586C4C167499210DCBF3ECFD8CCE210 ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
22:46:22.0943 3844  NcdAutoSetup - ok
22:46:22.0990 3844  [ AD9086052A5E5153AF43FE74138A4B27 ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
22:46:22.0990 3844  NDIS - ok
22:46:23.0006 3844  [ C6BB12BC35D1637CA17AE16D3A4725EB ] NdisCap         C:\WINDOWS\system32\DRIVERS\ndiscap.sys
22:46:23.0006 3844  NdisCap - ok
22:46:23.0006 3844  [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37 ] NdisImPlatform  C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
22:46:23.0021 3844  NdisImPlatform - ok
22:46:23.0037 3844  [ 9423421E735BD5394351E0C47C76BB92 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:46:23.0037 3844  NdisTapi - ok
22:46:23.0037 3844  [ B832B35055BA2B7B4181861FF94D8E59 ] Ndisuio         C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:46:23.0037 3844  Ndisuio - ok
22:46:23.0068 3844  [ 1F58E48EF75F34C35D8E93A0DC535CFE ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
22:46:23.0068 3844  NdisVirtualBus - ok
22:46:23.0068 3844  [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWan         C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:46:23.0068 3844  NdisWan - ok
22:46:23.0084 3844  [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWanLegacy   C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:46:23.0084 3844  NdisWanLegacy - ok
22:46:23.0084 3844  [ A5BD69A8812FA79D1A487691DD3FB244 ] NDProxy         C:\WINDOWS\system32\drivers\NDProxy.sys
22:46:23.0084 3844  NDProxy - ok
22:46:23.0100 3844  [ 5A072F0B90C29C5233D78BE33EF5ED78 ] Ndu             C:\WINDOWS\system32\drivers\Ndu.sys
22:46:23.0100 3844  Ndu - ok
22:46:23.0100 3844  [ A83D67D347A684F10B7D3019C8A6380C ] NetBIOS         C:\WINDOWS\system32\DRIVERS\netbios.sys
22:46:23.0100 3844  NetBIOS - ok
22:46:23.0115 3844  [ 0217532E19A748F0E5D569307363D5FD ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
22:46:23.0115 3844  NetBT - ok
22:46:23.0131 3844  [ F6F209DDB94959BA104FC8FC87C53759 ] Netlogon        C:\WINDOWS\system32\lsass.exe
22:46:23.0131 3844  Netlogon - ok
22:46:23.0162 3844  [ B7AD851A21FEBA3BA214972627614207 ] Netman          C:\WINDOWS\System32\netman.dll
22:46:23.0178 3844  Netman - ok
22:46:23.0209 3844  [ F0F0A372C2EF6358399C4936F91B6131 ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
22:46:23.0209 3844  netprofm - ok
22:46:23.0240 3844  [ 1092B3190E69E0C5ECBCE90F171DE047 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:46:23.0240 3844  NetTcpPortSharing - ok
22:46:23.0271 3844  [ 70414DB660BFBB7BD58FCE8EA4364E1B ] netvsc          C:\WINDOWS\system32\DRIVERS\netvsc63.sys
22:46:23.0271 3844  netvsc - ok
22:46:23.0287 3844  [ 3A280F3B3C7A46E29C404ACD46ECBF5E ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
22:46:23.0287 3844  NlaSvc - ok
22:46:23.0303 3844  [ 8F44A2F57C9F1A19AC9C6288C10FB351 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
22:46:23.0303 3844  Npfs - ok
22:46:23.0318 3844  [ CBDB4F0871C88DF930FC0E8588CA67FC ] npsvctrig       C:\WINDOWS\System32\drivers\npsvctrig.sys
22:46:23.0318 3844  npsvctrig - ok
22:46:23.0318 3844  [ 6E2271ED0C3E95B8E29F3752B91B9E84 ] nsi             C:\WINDOWS\system32\nsisvc.dll
22:46:23.0318 3844  nsi - ok
22:46:23.0334 3844  [ E490B459978CB87779E84C761D22B827 ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
22:46:23.0334 3844  nsiproxy - ok
22:46:23.0381 3844  [ 4412D565C0278C401575E11072C7DCE3 ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
22:46:23.0381 3844  Ntfs - ok
22:46:23.0396 3844  [ EF1B290FC9F0E47CC0B537292BEE5904 ] Null            C:\WINDOWS\system32\drivers\Null.sys
22:46:23.0396 3844  Null - ok
22:46:23.0412 3844  [ BC6B5942AFF25EBAF62DE43C3807EDF8 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
22:46:23.0412 3844  nvraid - ok
22:46:23.0428 3844  [ 1F43ABFFAC3D6CA356851D517392966E ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
22:46:23.0428 3844  nvstor - ok
22:46:23.0443 3844  [ 6934A936A7369DFE37B7DBA93F5E5E49 ] nv_agp          C:\WINDOWS\system32\drivers\nv_agp.sys
22:46:23.0443 3844  nv_agp - ok
22:46:23.0475 3844  [ 3B510F20806B94E389784ED09DBD2111 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
22:46:23.0475 3844  p2pimsvc - ok
22:46:23.0537 3844  [ 2A57A937BC5B1B2D6AFE6A8C5925F50B ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
22:46:23.0553 3844  p2psvc - ok
22:46:23.0584 3844  [ 764B1121867B2D9B31C491668AC72B2B ] Parport         C:\WINDOWS\System32\drivers\parport.sys
22:46:23.0584 3844  Parport - ok
22:46:23.0600 3844  [ EF0C1749C9A8CEE9A457473D433CC00F ] partmgr         C:\WINDOWS\system32\drivers\partmgr.sys
22:46:23.0600 3844  partmgr - ok
22:46:23.0615 3844  [ 9A5309EF92F39346CFD5A4C2C3D1BFAD ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
22:46:23.0615 3844  PcaSvc - ok
22:46:23.0631 3844  [ C0D3F3BC1C84B4BA746D9847314C1164 ] pci             C:\WINDOWS\system32\drivers\pci.sys
22:46:23.0631 3844  pci - ok
22:46:23.0646 3844  [ 346E38FCC6859A727DD28AFAD1F0AFF4 ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
22:46:23.0646 3844  pciide - ok
22:46:23.0646 3844  [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
22:46:23.0646 3844  pcmcia - ok
22:46:23.0662 3844  [ BF28771D1436C88BE1D297D3098B0F7D ] pcw             C:\WINDOWS\system32\drivers\pcw.sys
22:46:23.0662 3844  pcw - ok
22:46:23.0678 3844  [ E170103E68329E9154A5EC383CD253ED ] pdc             C:\WINDOWS\system32\drivers\pdc.sys
22:46:23.0678 3844  pdc - ok
22:46:23.0693 3844  [ BA50CC0BD19004AAB88BE37338B6FA0D ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
22:46:23.0693 3844  PEAUTH - ok
22:46:23.0771 3844  [ 8E3C640FFF5A963F570233AE99C0FFF3 ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
22:46:23.0771 3844  PerfHost - ok
22:46:23.0818 3844  [ 928061178CD9856CA6B67FFFCE6BA766 ] pla             C:\WINDOWS\system32\pla.dll
22:46:23.0818 3844  pla - ok
22:46:23.0865 3844  [ 752A457320A946E03C3AA86C3ACD735E ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
22:46:23.0865 3844  PlugPlay - ok
22:46:23.0881 3844  [ 045EB4F260606A03BE340D09DEAF3BA4 ] PNRPAutoReg     C:\WINDOWS\system32\pnrpauto.dll
22:46:23.0881 3844  PNRPAutoReg - ok
22:46:23.0896 3844  [ 3B510F20806B94E389784ED09DBD2111 ] PNRPsvc         C:\WINDOWS\system32\pnrpsvc.dll
22:46:23.0912 3844  PNRPsvc - ok
22:46:23.0943 3844  [ C16097D77A232A288D65F299E2E01105 ] PolicyAgent     C:\WINDOWS\System32\ipsecsvc.dll
22:46:23.0943 3844  PolicyAgent - ok
22:46:23.0959 3844  [ 00E08B30E7F7C13ECE2CDF4F46A77311 ] Power           C:\WINDOWS\system32\umpo.dll
22:46:23.0959 3844  Power - ok
22:46:24.0068 3844  [ B7DB57A000D46D4DE75BC0C563E58072 ] PrintNotify     C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
22:46:24.0084 3844  PrintNotify - ok
22:46:24.0115 3844  [ ECD373F9571C745894367CC2635EA44F ] Processor       C:\WINDOWS\System32\drivers\processr.sys
22:46:24.0115 3844  Processor - ok
22:46:24.0146 3844  [ 8513A1E7AE4B9DC82C4B4F432C648A58 ] ProfSvc         C:\WINDOWS\system32\profsvc.dll
22:46:24.0146 3844  ProfSvc - ok
22:46:24.0162 3844  [ 8528BB05E4D4E25945F78B00B2555FB7 ] Psched          C:\WINDOWS\system32\DRIVERS\pacer.sys
22:46:24.0162 3844  Psched - ok
22:46:24.0193 3844  [ AF90BB44C99D6820BE52C9BBAA523283 ] QWAVE           C:\WINDOWS\system32\qwave.dll
22:46:24.0193 3844  QWAVE - ok
22:46:24.0225 3844  [ 3FB466684609A4329858CF2EBD62E0FD ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
22:46:24.0225 3844  QWAVEdrv - ok
22:46:24.0240 3844  [ 2C56F0EE27E4EF70CA4B4983D3638905 ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:46:24.0240 3844  RasAcd - ok
22:46:24.0276 3844  [ 5F061AC45266841A2860C1858ED863B8 ] RasAuto         C:\WINDOWS\System32\rasauto.dll
22:46:24.0276 3844  RasAuto - ok
22:46:24.0291 3844  [ BF3B17016764F20F9D28CF1A8DC210C0 ] RasMan          C:\WINDOWS\System32\rasmans.dll
22:46:24.0307 3844  RasMan - ok
22:46:24.0307 3844  [ 5247F308C4103CDC4FE12AE1D235800A ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:46:24.0307 3844  RasPppoe - ok
22:46:24.0338 3844  [ B939A2A0F9D6C6C186721E268EB6FA93 ] rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:46:24.0338 3844  rdbss - ok
22:46:24.0354 3844  [ 6B21EBF892CD8CACB71669B35AB5DE32 ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
22:46:24.0354 3844  rdpbus - ok
22:46:24.0354 3844  [ 680C1DAE268B6FB67FA21B389A8B79EF ] RDPDR           C:\WINDOWS\system32\drivers\rdpdr.sys
22:46:24.0354 3844  RDPDR - ok
22:46:24.0370 3844  [ 858776908AF838E3790F3261B799CDA6 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
22:46:24.0370 3844  RdpVideoMiniport - ok
22:46:24.0401 3844  [ 847C6A08912C3515807049C93E526D65 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
22:46:24.0401 3844  rdyboost - ok
22:46:24.0432 3844  [ 036746D54347FD2D0385668E2A4064E4 ] ReFS            C:\WINDOWS\system32\drivers\ReFS.sys
22:46:24.0448 3844  ReFS - ok
22:46:24.0479 3844  [ BFFB40FBE6D2C3469F8D06EE5E4934AB ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
22:46:24.0495 3844  RemoteAccess - ok
22:46:24.0526 3844  [ 4DCCABE03D06955ED61BABBD8EF9F30F ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
22:46:24.0526 3844  RemoteRegistry - ok
22:46:24.0557 3844  [ D894CBD7DA753C881EE8D5E33B583225 ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
22:46:24.0557 3844  RpcEptMapper - ok
22:46:24.0588 3844  [ 5CAE8F47B31D5CFC322B5B898C19E0FE ] RpcLocator      C:\WINDOWS\system32\locator.exe
22:46:24.0588 3844  RpcLocator - ok
22:46:24.0620 3844  [ 3FD5AE42EC87C6F532A931F96BE731DD ] RpcSs           C:\WINDOWS\system32\rpcss.dll
22:46:24.0635 3844  RpcSs - ok
22:46:24.0651 3844  [ 2D05A5508F4685412F2B89E8C2189ABC ] rspndr          C:\WINDOWS\system32\DRIVERS\rspndr.sys
22:46:24.0651 3844  rspndr - ok
22:46:24.0682 3844  [ 19764658C1468C2C0CEF133D28414A6B ] RTL8168         C:\WINDOWS\system32\DRIVERS\Rt630x64.sys
22:46:24.0682 3844  RTL8168 - ok
22:46:24.0698 3844  [ 1A063730F221B2746FF00457AE17E4F0 ] s3cap           C:\WINDOWS\System32\drivers\vms3cap.sys
22:46:24.0698 3844  s3cap - ok
22:46:24.0729 3844  [ F6F209DDB94959BA104FC8FC87C53759 ] SamSs           C:\WINDOWS\system32\lsass.exe
22:46:24.0729 3844  SamSs - ok
22:46:24.0760 3844  [ C624A1B32211C3166EDB3F4AB02A30B7 ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
22:46:24.0760 3844  sbp2port - ok
22:46:24.0791 3844  [ 47C497FA4DDEA908633CAA60CEBE6805 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
22:46:24.0791 3844  SCardSvr - ok
22:46:24.0807 3844  [ E76C4E98302AE39CC6FA5D20FC8B5438 ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
22:46:24.0807 3844  ScDeviceEnum - ok
22:46:24.0807 3844  [ ABD0237B15DBD2B4695F4B7D734A58F7 ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
22:46:24.0823 3844  scfilter - ok
22:46:24.0854 3844  [ 888A30EAB651502352C18745367FD179 ] Schedule        C:\WINDOWS\system32\schedsvc.dll
22:46:24.0854 3844  Schedule - ok
22:46:24.0885 3844  [ AB285CE3431FF3D2ACE669245874C1C7 ] SCPolicySvc     C:\WINDOWS\System32\certprop.dll
22:46:24.0885 3844  SCPolicySvc - ok
22:46:24.0901 3844  [ 2F9A3380B8C0380E5608E29C7AA66899 ] sdbus           C:\WINDOWS\System32\drivers\sdbus.sys
22:46:24.0901 3844  sdbus - ok
22:46:24.0916 3844  [ 4EAF4DCF9DBD9A56952A58F56D61C005 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
22:46:24.0916 3844  sdstor - ok
22:46:24.0916 3844  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\WINDOWS\system32\drivers\secdrv.sys
22:46:24.0916 3844  secdrv - ok
22:46:24.0932 3844  [ C49009F897BA4F2F4F31043663AA1485 ] seclogon        C:\WINDOWS\system32\seclogon.dll
22:46:24.0948 3844  seclogon - ok
22:46:24.0963 3844  [ A88882E64BDC1D8E8D6E727B71CCCC53 ] SENS            C:\WINDOWS\System32\sens.dll
22:46:24.0963 3844  SENS - ok
22:46:24.0979 3844  [ E66A7C8CE7ED22DED6DF1CA479FB4790 ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
22:46:24.0995 3844  SensrSvc - ok
22:46:25.0010 3844  [ DB2FF24CE0BDD15FE75870AFE312BA89 ] SerCx           C:\WINDOWS\system32\drivers\SerCx.sys
22:46:25.0010 3844  SerCx - ok
22:46:25.0010 3844  [ 53BDBF04ECAF943CBF6359E3BCB2445E ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
22:46:25.0010 3844  SerCx2 - ok
22:46:25.0026 3844  [ 3CD600C089C1251BEEB4CD4CD5164F9E ] Serenum         C:\WINDOWS\System32\drivers\serenum.sys
22:46:25.0026 3844  Serenum - ok
22:46:25.0026 3844  [ D864381BC9C725FAB01D94C060660166 ] Serial          C:\WINDOWS\System32\drivers\serial.sys
22:46:25.0026 3844  Serial - ok
22:46:25.0041 3844  [ 0BD2B65DCE756FDE95A2E5CCCBF7705D ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
22:46:25.0041 3844  sermouse - ok
22:46:25.0057 3844  [ 441E6FF1F34D7A942946DB42A15FB519 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
22:46:25.0057 3844  SessionEnv - ok
22:46:25.0073 3844  [ 472B7A5AC181C050888DB454663DD764 ] sfloppy         C:\WINDOWS\System32\drivers\sfloppy.sys
22:46:25.0073 3844  sfloppy - ok
22:46:25.0104 3844  [ F4414F57DF2CECB8FC969AA43A6B0D50 ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
22:46:25.0104 3844  SharedAccess - ok
22:46:25.0135 3844  [ 0D190D8B4B20446BE6299AC734DFADF1 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:46:25.0135 3844  ShellHWDetection - ok
22:46:25.0151 3844  [ 2F518D13DD6F3053837FE606F1A2EA1F ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
22:46:25.0151 3844  SiSRaid2 - ok
22:46:25.0151 3844  [ 1AC9A200A9C49C4508F04AAFFCA34A3F ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
22:46:25.0151 3844  SiSRaid4 - ok
22:46:25.0182 3844  [ 587ACA15210D1B01FBF272E07A08F91A ] smphost         C:\WINDOWS\System32\smphost.dll
22:46:25.0182 3844  smphost - ok
22:46:25.0213 3844  [ 49EEB92DE930B8566EF615D600781DB4 ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
22:46:25.0213 3844  SNMPTRAP - ok
22:46:25.0245 3844  [ 8A2F723010B77C79898836784032BFF7 ] spaceport       C:\WINDOWS\system32\drivers\spaceport.sys
22:46:25.0260 3844  spaceport - ok
22:46:25.0276 3844  [ F337BE11071818FC3F5DC2940B6BDE34 ] SpbCx           C:\WINDOWS\system32\drivers\SpbCx.sys
22:46:25.0276 3844  SpbCx - ok
22:46:25.0307 3844  [ FE0CB40F36D3FCDD3A1B312EF72C38D5 ] Spooler         C:\WINDOWS\System32\spoolsv.exe
22:46:25.0307 3844  Spooler - ok
22:46:25.0432 3844  [ E6DEC72A2A23FAA53EB9FEC3C7E29D66 ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
22:46:25.0463 3844  sppsvc - ok
22:46:25.0495 3844  [ 2B78788A1485F9B99A578A299DF42C02 ] srv             C:\WINDOWS\system32\DRIVERS\srv.sys
22:46:25.0510 3844  srv - ok
22:46:25.0541 3844  [ C1AE59C0B0817236EC083A91C396005A ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
22:46:25.0541 3844  srv2 - ok
22:46:25.0557 3844  [ 77195C32175FC63D6054EBA5A066D727 ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
22:46:25.0557 3844  srvnet - ok
22:46:25.0573 3844  [ BB9ED3EDD8E85008215A7250D325A72E ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
22:46:25.0588 3844  SSDPSRV - ok
22:46:25.0604 3844  [ 3911418AFDE10EA6823B7799E4815524 ] SstpSvc         C:\WINDOWS\system32\sstpsvc.dll
22:46:25.0604 3844  SstpSvc - ok
22:46:25.0651 3844  [ 366DEA74BBA65B362BCCFC6FC2ADFD8B ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
22:46:25.0651 3844  stexstor - ok
22:46:25.0682 3844  [ D638904FE86A5FE542A1BA13A9D68E5C ] stisvc          C:\WINDOWS\System32\wiaservc.dll
22:46:25.0682 3844  stisvc - ok
22:46:25.0713 3844  [ 0ED2E318ABB68C1A35A8B8038BDB4C90 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
22:46:25.0713 3844  storahci - ok
22:46:25.0729 3844  [ 7A08CEE1535F5A448215634C5EA74E50 ] storflt         C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
22:46:25.0729 3844  storflt - ok
22:46:25.0745 3844  [ 6B06E2D11E604BE2B1A406C4CB3B90DE ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
22:46:25.0745 3844  stornvme - ok
22:46:25.0760 3844  [ 3118058E3D07021A55324A943C6D722B ] StorSvc         C:\WINDOWS\system32\storsvc.dll
22:46:25.0776 3844  StorSvc - ok
22:46:25.0776 3844  [ 548759755BC73DAD663250239D7E0B9F ] storvsc         C:\WINDOWS\system32\drivers\storvsc.sys
22:46:25.0776 3844  storvsc - ok
22:46:25.0807 3844  [ D8E1AE075AB3E8AD56F69C44AA978596 ] svsvc           C:\WINDOWS\system32\svsvc.dll
22:46:25.0807 3844  svsvc - ok
22:46:25.0823 3844  [ 84E0F5D41C138C5CC975137A2A98F6D3 ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
22:46:25.0823 3844  swenum - ok
22:46:25.0854 3844  [ A5DC2E63F5E5D3C0B843307374998479 ] swprv           C:\WINDOWS\System32\swprv.dll
22:46:25.0854 3844  swprv - ok
22:46:25.0901 3844  [ E45DA7CBBA34510C8B9473AD7D4FFD0B ] SysMain         C:\WINDOWS\system32\sysmain.dll
22:46:25.0932 3844  SysMain - ok
22:46:25.0948 3844  [ 373382005ACB27CB16ED16722FBE946A ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
22:46:25.0948 3844  SystemEventsBroker - ok
22:46:25.0979 3844  [ BA6DD39266A5E15515C8C14DA2DA3E5C ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
22:46:25.0979 3844  TabletInputService - ok
22:46:26.0010 3844  [ B517410F157693043DACA21B19B258A6 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
22:46:26.0010 3844  TapiSrv - ok
22:46:26.0073 3844  [ 6617F44D2432C529B2249A0498B6B40A ] Tcpip           C:\WINDOWS\system32\drivers\tcpip.sys
22:46:26.0088 3844  Tcpip - ok
22:46:26.0120 3844  [ 6617F44D2432C529B2249A0498B6B40A ] TCPIP6          C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:46:26.0135 3844  TCPIP6 - ok
22:46:26.0166 3844  [ 33A7D83EEB15431773A6E186CFAABA21 ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
22:46:26.0166 3844  tcpipreg - ok
22:46:26.0198 3844  [ FFF28F9F6823EB1756C60F1649560BBF ] tdx             C:\WINDOWS\system32\DRIVERS\tdx.sys
22:46:26.0198 3844  tdx - ok
22:46:26.0213 3844  [ 232D185D2337F141311D0CF1983E1431 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
22:46:26.0213 3844  terminpt - ok
22:46:26.0245 3844  [ 2C77831737491F4D684D315B95C62883 ] TermService     C:\WINDOWS\System32\termsrv.dll
22:46:26.0245 3844  TermService - ok
22:46:26.0276 3844  [ 05FBE1F7C13E87AF7A414CDF288B1F62 ] Themes          C:\WINDOWS\system32\themeservice.dll
22:46:26.0276 3844  Themes - ok
22:46:26.0307 3844  [ FD788C2D96EA91469A3C1D13E80D7473 ] THREADORDER     C:\WINDOWS\system32\mmcss.dll
22:46:26.0307 3844  THREADORDER - ok
22:46:26.0327 3844  [ 347A3E49CE18402305B8119A6EC7CFEB ] TimeBroker      C:\WINDOWS\System32\TimeBrokerServer.dll
22:46:26.0327 3844  TimeBroker - ok
22:46:26.0355 3844  [ 82F909359600D3603FE852DB7F135626 ] TPM             C:\WINDOWS\system32\drivers\tpm.sys
22:46:26.0355 3844  TPM - ok
22:46:26.0370 3844  [ C97E14BB6A196B0554D6EB67D8818175 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
22:46:26.0370 3844  TrkWks - ok
22:46:26.0433 3844  [ DA56FFA46030E6FEB215E3D5DAA65B11 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
22:46:26.0433 3844  TrustedInstaller - ok
22:46:26.0464 3844  [ BF8F54CA37E9C9D6582C31C5761F8C93 ] TsUsbFlt        C:\WINDOWS\system32\drivers\tsusbflt.sys
22:46:26.0464 3844  TsUsbFlt - ok
22:46:26.0480 3844  [ E0088068DCE2EE82897027DDB8E05254 ] TsUsbGD         C:\WINDOWS\System32\drivers\TsUsbGD.sys
22:46:26.0480 3844  TsUsbGD - ok
22:46:26.0511 3844  [ C8E0E78B5D284C2FF59BDFFDAF997242 ] tunnel          C:\WINDOWS\system32\DRIVERS\tunnel.sys
22:46:26.0511 3844  tunnel - ok
22:46:26.0526 3844  [ F6EEAD052943B5A3104C1405BB856C54 ] uagp35          C:\WINDOWS\system32\drivers\uagp35.sys
22:46:26.0526 3844  uagp35 - ok
22:46:26.0542 3844  [ FE6067B1FD4E63650C667B33D080565B ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
22:46:26.0542 3844  UASPStor - ok
22:46:26.0542 3844  [ 5D1B430EA11064C56E7C8F84B90DEB6A ] UCX01000        C:\WINDOWS\System32\drivers\ucx01000.sys
22:46:26.0542 3844  UCX01000 - ok
22:46:26.0558 3844  [ 1EC649F112896FAE33250F0B97AC5D0B ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
22:46:26.0558 3844  udfs - ok
22:46:26.0573 3844  [ 9578691F297E1B1F519970FE6D47CB21 ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
22:46:26.0573 3844  UEFI - ok
22:46:26.0605 3844  [ 320878AFECDBBD61BBE98624A6CAAC08 ] UI0Detect       C:\WINDOWS\system32\UI0Detect.exe
22:46:26.0605 3844  UI0Detect - ok
22:46:26.0605 3844  [ 5EAB5117DDB24FC4D39E6FFFCF1837B9 ] uliagpkx        C:\WINDOWS\system32\drivers\uliagpkx.sys
22:46:26.0605 3844  uliagpkx - ok
22:46:26.0636 3844  [ DA34C39A18E60E7C3FA0630566408034 ] umbus           C:\WINDOWS\System32\drivers\umbus.sys
22:46:26.0636 3844  umbus - ok
22:46:26.0636 3844  [ AE8294875E5446E359B1E8035D40C05E ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
22:46:26.0636 3844  UmPass - ok
22:46:26.0667 3844  [ E3DDF7D43E05784FAA5E042605EEE528 ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
22:46:26.0683 3844  UmRdpService - ok
22:46:26.0698 3844  [ 4A2FFDAC45F317E17DF642C7160EB633 ] upnphost        C:\WINDOWS\System32\upnphost.dll
22:46:26.0698 3844  upnphost - ok
22:46:26.0730 3844  [ 433ECDE01A52691FA7ACA51C10C09B70 ] usbccgp         C:\WINDOWS\System32\drivers\usbccgp.sys
22:46:26.0730 3844  usbccgp - ok
22:46:26.0761 3844  [ B3D6457D841A0CAEF4C52D88621715F2 ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
22:46:26.0761 3844  usbcir - ok
22:46:26.0776 3844  [ 5477D6E27C7D266EF8C152B9A25ADE5E ] usbehci         C:\WINDOWS\System32\drivers\usbehci.sys
22:46:26.0776 3844  usbehci - ok
22:46:26.0808 3844  [ 4875DC63E548812C75D4FDEF84970C89 ] usbfilter       C:\WINDOWS\System32\drivers\usbfilter.sys
22:46:26.0808 3844  usbfilter - ok
22:46:26.0823 3844  [ DF56C2C04EFA328D7A66B69007130266 ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
22:46:26.0823 3844  usbhub - ok
22:46:26.0839 3844  [ C0E33820326199CE3CFD3B9F27F81D99 ] USBHUB3         C:\WINDOWS\System32\drivers\UsbHub3.sys
22:46:26.0839 3844  USBHUB3 - ok
22:46:26.0855 3844  [ 3019097FB6C985EF24C058090FF3BDBD ] usbohci         C:\WINDOWS\System32\drivers\usbohci.sys
22:46:26.0855 3844  usbohci - ok
22:46:26.0855 3844  [ 4D655E3B684BE9B0F7FFD8A2935C348C ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
22:46:26.0855 3844  usbprint - ok
22:46:26.0870 3844  [ B1230E9813B5C7E762DF27756AA23917 ] USBSTOR         C:\WINDOWS\System32\drivers\USBSTOR.SYS
22:46:26.0870 3844  USBSTOR - ok
22:46:26.0886 3844  [ BA4FA655E0FC577DB7436FC963932CE4 ] usbuhci         C:\WINDOWS\System32\drivers\usbuhci.sys
22:46:26.0886 3844  usbuhci - ok
22:46:26.0917 3844  [ 53AA1CD1740BDE110EB22CD8C05F615F ] USBXHCI         C:\WINDOWS\System32\drivers\USBXHCI.SYS
22:46:26.0917 3844  USBXHCI - ok
22:46:26.0933 3844  [ F6F209DDB94959BA104FC8FC87C53759 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
22:46:26.0933 3844  VaultSvc - ok
22:46:26.0948 3844  [ FEB26E3B8345A7E8D62F945C4AE86562 ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
22:46:26.0948 3844  vdrvroot - ok
22:46:26.0995 3844  [ CFBAD6B48EDFAA0828A52646B7C4C08D ] vds             C:\WINDOWS\System32\vds.exe
22:46:26.0995 3844  vds - ok
22:46:27.0011 3844  [ A026EDEAA5EECAE0B08E2748B616D4BD ] VerifierExt     C:\WINDOWS\system32\drivers\VerifierExt.sys
22:46:27.0011 3844  VerifierExt - ok
22:46:27.0042 3844  [ 041D3EF364E624DBB2703A64A5AADF89 ] vhdmp           C:\WINDOWS\System32\drivers\vhdmp.sys
22:46:27.0042 3844  vhdmp - ok
22:46:27.0058 3844  [ 06D38968028E9AB19DE9B618C7B6D199 ] viaide          C:\WINDOWS\system32\drivers\viaide.sys
22:46:27.0058 3844  viaide - ok
22:46:27.0058 3844  [ C6305BDFC4F7CE51F72BB072C03D4ACE ] vmbus           C:\WINDOWS\system32\drivers\vmbus.sys
22:46:27.0058 3844  vmbus - ok
22:46:27.0073 3844  [ DA40BEA0A863CE768C940CA9723BF81F ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
22:46:27.0073 3844  VMBusHID - ok
22:46:27.0120 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
22:46:27.0136 3844  vmicguestinterface - ok
22:46:27.0183 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicheartbeat   C:\WINDOWS\System32\ICSvc.dll
22:46:27.0183 3844  vmicheartbeat - ok
22:46:27.0214 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
22:46:27.0214 3844  vmickvpexchange - ok
22:46:27.0230 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicrdv         C:\WINDOWS\System32\ICSvc.dll
22:46:27.0230 3844  vmicrdv - ok
22:46:27.0245 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicshutdown    C:\WINDOWS\System32\ICSvc.dll
22:46:27.0245 3844  vmicshutdown - ok
22:46:27.0261 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmictimesync    C:\WINDOWS\System32\ICSvc.dll
22:46:27.0261 3844  vmictimesync - ok
22:46:27.0276 3844  [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicvss         C:\WINDOWS\System32\ICSvc.dll
22:46:27.0276 3844  vmicvss - ok
22:46:27.0292 3844  [ 55D7D963DE85162F1C49721E502F9744 ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
22:46:27.0292 3844  volmgr - ok
22:46:27.0308 3844  [ CCB9E901F7254BF96D28EB1B0E5329B7 ] volmgrx         C:\WINDOWS\system32\drivers\volmgrx.sys
22:46:27.0308 3844  volmgrx - ok
22:46:27.0308 3844  [ 9F9CE33B50611A1C61A46B8911E0B30B ] volsnap         C:\WINDOWS\system32\drivers\volsnap.sys
22:46:27.0323 3844  volsnap - ok
22:46:27.0339 3844  [ 01355C98B5C3ED1EC446743CDA848FCE ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
22:46:27.0339 3844  vpci - ok
22:46:27.0355 3844  [ 4539F45F9F4C9757A86A56C949421E07 ] vsmraid         C:\WINDOWS\system32\drivers\vsmraid.sys
22:46:27.0355 3844  vsmraid - ok
22:46:27.0401 3844  [ D51D7EF1EA5ED2BB01E9D07E6E0533BC ] VSS             C:\WINDOWS\system32\vssvc.exe
22:46:27.0401 3844  VSS - ok
22:46:27.0417 3844  [ 0849B7260F26FE05EA56DED0672E2F4B ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
22:46:27.0417 3844  VSTXRAID - ok
22:46:27.0433 3844  [ BE970C369E43B509C1EDA2B8FA7CECB0 ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
22:46:27.0433 3844  vwifibus - ok
22:46:27.0480 3844  [ 7599E582CA3A6AAA95A18FFE1172D339 ] W32Time         C:\WINDOWS\system32\w32time.dll
22:46:27.0480 3844  W32Time - ok
22:46:27.0526 3844  [ 8E553C859C83784DEC08B10AFC3EAC92 ] w3logsvc        C:\WINDOWS\system32\inetsrv\w3logsvc.dll
22:46:27.0526 3844  w3logsvc - ok
22:46:27.0526 3844  [ 0910AB9ED404C1434E2D0376C2AD5D8B ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
22:46:27.0542 3844  WacomPen - ok
22:46:27.0573 3844  [ 9BAE40BD31E3EE0B0C70BEF167E0A2BC ] WAS             C:\WINDOWS\system32\inetsrv\iisw3adm.dll
22:46:27.0573 3844  WAS - ok
22:46:27.0589 3844  [ 92BF4B3EBD6F163B94B7A20C65E7B698 ] wbengine        C:\WINDOWS\system32\wbengine.exe
22:46:27.0605 3844  wbengine - ok
22:46:27.0620 3844  [ 58F28103889817C93E5B5AFABC87E709 ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
22:46:27.0636 3844  WbioSrvc - ok
22:46:27.0636 3844  [ 772365894F14652D376B2E5030179DC9 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
22:46:27.0651 3844  Wcmsvc - ok
22:46:27.0667 3844  [ D2726823DF7E19F213F4805A9D6D145F ] wcncsvc         C:\WINDOWS\System32\wcncsvc.dll
22:46:27.0683 3844  wcncsvc - ok
22:46:27.0698 3844  [ 846C02A8B48CBD921A3D6AB521AA0DC4 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
22:46:27.0698 3844  WcsPlugInService - ok
22:46:27.0730 3844  [ 694B28DE12AD47031FFB4B052662131A ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
22:46:27.0730 3844  WdBoot - ok
22:46:27.0776 3844  [ CB6C63FF8342B467E2EF76E98D5B934D ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
22:46:27.0776 3844  Wdf01000 - ok
22:46:27.0792 3844  [ 0B99529A3BECC3528D865DDECB62503B ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
22:46:27.0792 3844  WdFilter - ok
22:46:27.0792 3844  [ 40C67D1A4891120874767F6E6604D6C5 ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
22:46:27.0792 3844  WdiServiceHost - ok
22:46:27.0808 3844  [ 40C67D1A4891120874767F6E6604D6C5 ] WdiSystemHost   C:\WINDOWS\system32\wdi.dll
22:46:27.0808 3844  WdiSystemHost - ok
22:46:27.0839 3844  [ 282E7D46310338FF4A6B7680440EB0DA ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
22:46:27.0839 3844  WdNisDrv - ok
22:46:27.0870 3844  WdNisSvc - ok
22:46:27.0901 3844  [ 6588A957873326361AB1CAC4E76F8394 ] WebClient       C:\WINDOWS\System32\webclnt.dll
22:46:27.0901 3844  WebClient - ok
22:46:27.0917 3844  [ 3274312F263882B51B964329FAF49734 ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
22:46:27.0917 3844  Wecsvc - ok
22:46:27.0917 3844  [ 7CDD84E0023A0C5C230B06A7965EC65E ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
22:46:27.0933 3844  WEPHOSTSVC - ok
22:46:27.0948 3844  [ AA1315B87D9B2E39584165318A59F15D ] wercplsupport   C:\WINDOWS\System32\wercplsupport.dll
22:46:27.0948 3844  wercplsupport - ok
22:46:27.0948 3844  [ 22B4C24AB921BFF7827FFBCA1F4E1BB3 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
22:46:27.0964 3844  WerSvc - ok
22:46:27.0980 3844  [ 2E3E82D7B1076B90F4E228A8EF17B261 ] WFPLWFS         C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
22:46:27.0980 3844  WFPLWFS - ok
22:46:28.0011 3844  [ E06AFE2F94BA7CFA2FE4FD2A449E60E2 ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
22:46:28.0011 3844  WiaRpc - ok
22:46:28.0042 3844  [ 867BCC69ED9C31C501465EB0E8BA9DFA ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
22:46:28.0042 3844  WIMMount - ok
22:46:28.0042 3844  WinDefend - ok
22:46:28.0089 3844  [ DD079EC8F44DCA3A176B345C6ADEFB66 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
22:46:28.0089 3844  WinHttpAutoProxySvc - ok
22:46:28.0120 3844  [ 9DB490F3E823C5C3C070644B96CB9D59 ] Winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
22:46:28.0120 3844  Winmgmt - ok
22:46:28.0183 3844  [ 690C3FC5C9DBD6B9AEDF8341EC720E41 ] WinRM           C:\WINDOWS\system32\WsmSvc.dll
22:46:28.0214 3844  WinRM - ok
22:46:28.0276 3844  [ 9378B4E7E4E3EAE2F05823CFFF2C6EF4 ] WlanSvc         C:\WINDOWS\System32\wlansvc.dll
22:46:28.0292 3844  WlanSvc - ok
22:46:28.0370 3844  [ C2838466CCC44FAEF2C3D4C1E5971ECB ] wlidsvc         C:\WINDOWS\system32\wlidsvc.dll
22:46:28.0386 3844  wlidsvc - ok
22:46:28.0401 3844  [ 2834D9D3B4F554A39C72F00EA3F0E128 ] WmiAcpi         C:\WINDOWS\System32\drivers\wmiacpi.sys
22:46:28.0401 3844  WmiAcpi - ok
22:46:28.0417 3844  [ 7AFAC828F52D62F304A911EC32F42EEE ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
22:46:28.0433 3844  wmiApSrv - ok
22:46:28.0448 3844  WMPNetworkSvc - ok
22:46:28.0495 3844  [ E178371E493BF17EB90FE71ABA8BE643 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
22:46:28.0511 3844  workfolderssvc - ok
22:46:28.0542 3844  [ E746BCDBA2E02CF6B8D6B26FB167FBE0 ] wpcfltr         C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
22:46:28.0542 3844  wpcfltr - ok
22:46:28.0558 3844  [ 4E6A0F60DA7EF050D3D26417CD4D24E9 ] WPCSvc          C:\WINDOWS\System32\wpcsvc.dll
22:46:28.0558 3844  WPCSvc - ok
22:46:28.0573 3844  [ D27491CFCE452C154CECFA155AD0EBC8 ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
22:46:28.0589 3844  WPDBusEnum - ok
22:46:28.0589 3844  [ 9F2904B55F6CECCD1A8D986B5CE2609A ] WpdUpFltr       C:\WINDOWS\system32\drivers\WpdUpFltr.sys
22:46:28.0589 3844  WpdUpFltr - ok
22:46:28.0589 3844  [ AE072B0339D0A18E455DC21666CAD572 ] ws2ifsl         C:\WINDOWS\system32\drivers\ws2ifsl.sys
22:46:28.0605 3844  ws2ifsl - ok
22:46:28.0620 3844  [ 5CFA46C4ACB2FD70572017052378DAE5 ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
22:46:28.0620 3844  wscsvc - ok
22:46:28.0620 3844  WSearch - ok
22:46:28.0698 3844  [ 3671C668670626DAB0D47B44F65F0489 ] WSService       C:\WINDOWS\System32\WSService.dll
22:46:28.0714 3844  WSService - ok
22:46:28.0808 3844  [ 86D0BF4F792053A50D6EE43DFA5837A5 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
22:46:28.0839 3844  wuauserv - ok
22:46:28.0855 3844  [ 2FEAE33E9B2B56104596E1BA444405A9 ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
22:46:28.0855 3844  WudfPf - ok
22:46:28.0870 3844  [ 19240C13F526125554B5370566F21A0A ] WUDFRd          C:\WINDOWS\System32\drivers\WUDFRd.sys
22:46:28.0870 3844  WUDFRd - ok
22:46:28.0886 3844  [ 19240C13F526125554B5370566F21A0A ] WUDFSensorLP    C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
22:46:28.0886 3844  WUDFSensorLP - ok
22:46:28.0901 3844  [ BB73CBC65AABC4EA0A5C6A1474A0A743 ] wudfsvc         C:\WINDOWS\System32\WUDFSvc.dll
22:46:28.0901 3844  wudfsvc - ok
22:46:28.0917 3844  [ 19240C13F526125554B5370566F21A0A ] WUDFWpdFs       C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
22:46:28.0917 3844  WUDFWpdFs - ok
22:46:28.0948 3844  [ 2FA9794CA36147756F3FDFD6CA29B46F ] WwanSvc         C:\WINDOWS\System32\wwansvc.dll
22:46:28.0948 3844  WwanSvc - ok
22:46:28.0964 3844  ================ Scan global ===============================
22:46:28.0980 3844  [ C89780A6F58D113C28A96D85D1261DC5 ] C:\WINDOWS\system32\basesrv.dll
22:46:29.0011 3844  [ 599F1244C60E3D6C28A8DA7FBA7A2C13 ] C:\WINDOWS\system32\winsrv.dll
22:46:29.0042 3844  [ 9C1833ABD62876856836C5AE55C7CE86 ] C:\WINDOWS\system32\sxssrv.dll
22:46:29.0058 3844  [ B4B610BBCB002EC478C6FD80CF915697 ] C:\WINDOWS\system32\services.exe
22:46:29.0058 3844  [Global] - ok
22:46:29.0058 3844  ================ Scan MBR ==================================
22:46:29.0073 3844  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
22:46:29.0089 3844  \Device\Harddisk0\DR0 - ok
22:46:29.0089 3844  ================ Scan VBR ==================================
22:46:29.0089 3844  [ C918EC9BEDD1F9D2CB9C0A10E34EE3E5 ] \Device\Harddisk0\DR0\Partition1
22:46:29.0089 3844  \Device\Harddisk0\DR0\Partition1 - ok
22:46:29.0105 3844  [ 2EE8DEFD07952CA1D8D24402ECA9773C ] \Device\Harddisk0\DR0\Partition2
22:46:29.0105 3844  \Device\Harddisk0\DR0\Partition2 - ok
22:46:29.0122 3844  [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
22:46:29.0123 3844  \Device\Harddisk0\DR0\Partition3 - ok
22:46:29.0123 3844  [ 363B7336ACEDCBC3E04272589EFE1B8F ] \Device\Harddisk0\DR0\Partition4
22:46:29.0123 3844  \Device\Harddisk0\DR0\Partition4 - ok
22:46:29.0154 3844  [ AFAB5D57FBBC76B3F4F51FFB7AA77736 ] \Device\Harddisk0\DR0\Partition5
22:46:29.0154 3844  \Device\Harddisk0\DR0\Partition5 - ok
22:46:29.0169 3844  [ C1E4FBB8A0D1F00160E487EF520A562F ] \Device\Harddisk0\DR0\Partition6
22:46:29.0169 3844  \Device\Harddisk0\DR0\Partition6 - ok
22:46:29.0169 3844  ============================================================
22:46:29.0169 3844  Scan finished
22:46:29.0169 3844  ============================================================
22:46:29.0185 4748  Detected object count: 0
22:46:29.0185 4748  Actual detected object count: 0
22:46:31.0433 1264  Deinitialize success
 



#4 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 15 November 2013 - 06:37 AM

Thanks for letting me know about DDS.   :)  Let's try something different.  

 
N4qAiMQ.jpgFRST
 
Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.


Posted Image
 
 

#5 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 15 November 2013 - 06:51 AM

Hello Jeff,

 

Your Welcome. Here is the FRST log and attached is the Addition log

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013
Ran by Anna (administrator) on ANNAPC on 15-11-2013 07:42:16
Running from C:\Users\Anna\Desktop
Windows 8.1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\WINDOWS\system32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20279_x64__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\WINDOWS\WinStore\WSHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_fa1dc1539b4180d8\TiWorker.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Runonce: [ASYNCMAC] - rundll32.exe streamci,StreamingDeviceSetup {eeab7790-c514-11d1-b42b-00805fc1270e},asyncmac,{ad498944-762f-11d0-8dcb-00c04fc3358c},C:\WINDOWS\INF\netrasa.inf,Ndis-Mp-AsyncMac
HKLM\...\RunOnce: [NCPluginUpdater] - "c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe" Update [21720 2013-11-07] (Hewlett-Packard)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-10-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-14] (AVAST Software)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKLM - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL = http://www.amazon.co...s={searchTerms}
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...54371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKLM-x32 - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL = http://www.amazon.co...s={searchTerms}
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...54371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL =
SearchScopes: HKCU - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL =
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\r7h6unwt.default
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()

==================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-10-08] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-14] (AVAST Software)
R2 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-08-29] (Hewlett-Packard)
S2 HPRegistrationSvc; c:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HPRegistrationService.exe [205216 2012-07-18] (Hewlett-Packard)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-14] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57512 2012-11-20] (Advanced Micro Devices)
R2 aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [38984 2013-11-14] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [84328 2013-11-14] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [92544 2013-11-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-14] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1032416 2013-11-14] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [409832 2013-11-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-11-14] ()
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows ® Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-14] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-15 07:42 - 2013-11-15 07:42 - 00010174 _____ C:\Users\Anna\Desktop\FRST.txt
2013-11-15 07:42 - 2013-11-15 07:42 - 00000000 ____D C:\FRST
2013-11-15 07:40 - 2013-11-15 07:40 - 01957794 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2013-11-15 07:40 - 2013-11-15 07:40 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2013-11-15 07:40 - 2013-11-15 07:40 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-14 22:39 - 2013-11-14 22:51 - 00000000 ____D C:\Users\Anna\AppData\Local\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 22:25 - 2013-11-14 22:25 - 00688992 _____ (Swearware) C:\Users\Anna\Desktop\dds.com
2013-11-14 22:20 - 2013-11-14 22:20 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Anna\Desktop\tdsskiller.exe
2013-11-14 13:11 - 2013-11-14 13:11 - 00000145 _____ C:\Users\Anna\.appletviewer
2013-11-14 13:08 - 2013-11-14 13:08 - 00000000 ____D C:\Users\Anna\workspace
2013-11-14 13:07 - 2013-11-14 13:07 - 00000000 ____D C:\Users\Anna\.eclipse
2013-11-14 12:10 - 2013-11-14 12:13 - 00000000 ____D C:\Program Files\NetBeans 7.4
2013-11-14 12:10 - 2013-11-14 12:10 - 00001155 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk
2013-11-14 12:09 - 2013-11-14 12:14 - 00000000 ____D C:\Users\Anna\.nbi
2013-11-14 12:08 - 2013-11-14 12:09 - 00000000 ____D C:\Program Files\eclipse
2013-11-14 12:08 - 2013-11-14 12:08 - 00312744 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00108968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2013-11-14 12:07 - 2013-11-14 12:08 - 00000000 ____D C:\Program Files\Java
2013-11-14 11:57 - 2013-11-14 11:57 - 00000000 ____D C:\Users\Anna\AppData\Local\Hewlett-Packard
2013-11-14 11:56 - 2013-11-14 11:56 - 00000000 ____D C:\Users\Anna\AppData\Roaming\LibreOffice
2013-11-14 11:50 - 2013-11-14 11:50 - 00000773 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Web of Trust (WOT) – Crowdsourced web safety  WOT (Web of Trust).website
2013-11-14 11:35 - 2013-11-14 11:35 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-14 11:30 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-11-14 11:27 - 2013-11-14 22:17 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2013-11-14 11:27 - 2013-11-14 11:27 - 01032416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00409832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00334648 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2013-11-14 11:27 - 2013-11-14 11:27 - 00205320 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00092544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00084328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00065776 _____ C:\WINDOWS\system32\Drivers\aswRvrt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2013-11-14 11:27 - 2013-11-14 11:27 - 00038984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswFsBlk.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Users\Anna\AppData\Roaming\AVAST Software
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-14 11:26 - 2013-11-14 11:26 - 00000000 ____D C:\ProgramData\AVAST Software
2013-11-14 11:08 - 2013-11-14 11:08 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-11-14 10:51 - 2013-11-15 07:35 - 00000000 __RDO C:\Users\Anna\SkyDrive
2013-11-14 10:50 - 2013-11-14 10:50 - 00001448 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-14 10:50 - 2013-11-14 10:50 - 00000020 ___SH C:\Users\Anna\ntuser.ini
2013-11-14 10:46 - 2013-11-15 07:42 - 01889016 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-14 10:45 - 2013-11-14 10:45 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default\Documents\hp.system.package.metadata
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default User\Documents\hp.system.package.metadata
2013-11-14 10:38 - 2013-11-14 10:38 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-14 10:37 - 2013-11-14 13:11 - 00000000 ____D C:\Users\Anna
2013-11-14 10:37 - 2013-11-14 10:46 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2013-11-14 10:37 - 2013-11-14 10:46 - 00020958 _____ C:\WINDOWS\diagerr.xml
2013-11-14 10:37 - 2013-11-14 10:38 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-14 10:37 - 2013-08-22 07:36 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-14 10:37 - 2013-08-22 07:36 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-14 10:37 - 2013-08-22 07:36 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-14 10:35 - 2013-11-14 10:38 - 00012096 _____ C:\WINDOWS\iis.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00930400 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\Realtek
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\AMD
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2013-11-14 10:32 - 2013-11-14 12:09 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 __SHD C:\Recovery
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 ____D C:\Windows.old
2013-11-14 10:31 - 2013-11-14 10:31 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-14 10:31 - 2013-11-14 10:31 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00523096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-11-14 10:28 - 2013-11-14 10:28 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00371032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-11-14 10:28 - 2013-11-14 10:28 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00057176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-14 10:26 - 2013-11-14 10:26 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-14 10:25 - 2013-11-14 10:25 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\MSBuild
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-14 10:25 - 2013-08-02 20:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2013-11-14 10:25 - 2013-08-02 20:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-11-14 10:25 - 2013-08-02 20:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2013-11-14 10:24 - 2013-11-14 10:24 - 00155480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2013-11-14 10:24 - 2013-08-02 20:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2013-11-14 10:24 - 2013-08-02 20:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-14 10:24 - 2013-08-02 20:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2013-11-14 10:15 - 2013-11-14 10:46 - 00006702 _____ C:\WINDOWS\comsetup.log
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\Users\Anna\AppData\Local\AMD
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\ProgramData\ATI
2013-11-14 09:51 - 2013-11-14 09:51 - 00060777 _____ C:\WINDOWS\SysWOW64\CCCInstall_201311140951425666.log
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\ProgramData\AMD
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-11-14 09:50 - 2013-11-14 09:50 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-14 09:49 - 2013-11-14 09:51 - 00000000 ____D C:\Program Files\ATI Technologies
2013-11-14 09:48 - 2013-11-14 09:48 - 00000000 ____D C:\AMD
2013-11-14 08:23 - 2013-11-14 08:24 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 08:22 - 2013-11-07 16:00 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-14 08:19 - 2013-11-14 08:19 - 00000000 ____D C:\Users\Anna\Documents\DVR
2013-11-14 08:01 - 2013-11-14 08:01 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-14 07:35 - 2013-05-03 20:51 - 00014848 _____ (Microsoft) C:\WINDOWS\system32\rars.rs
2013-11-14 07:35 - 2013-05-03 20:10 - 00014848 _____ (Microsoft) C:\WINDOWS\SysWOW64\rars.rs
2013-11-14 07:26 - 2013-11-15 07:40 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1143663921-3194390258-2856191937-1001
2013-11-14 07:26 - 2013-11-14 07:26 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Macromedia
2013-11-14 07:20 - 2013-11-14 10:59 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Hewlett-Packard
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Roaming\ATI
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Local\ATI
2013-11-14 07:19 - 2013-11-15 07:38 - 00003914 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{211EF257-B9B6-4D8E-85C3-DE86094A10D9}
2013-11-14 07:19 - 2013-11-14 10:50 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-14 07:19 - 2013-11-14 10:50 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Adobe
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Local\Power2Go8
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\SysWOW64\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\system32\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-01-29 06:34 - 00002213 _____ C:\Users\Public\Desktop\Snapfish.lnk
2013-11-14 07:18 - 2013-01-29 06:25 - 00002103 _____ C:\Users\Public\Desktop\HP Games.lnk
2013-11-14 07:17 - 2013-11-14 13:16 - 00000000 ____D C:\Users\Anna\AppData\Local\Packages
2013-11-14 07:17 - 2013-11-14 10:19 - 01801805 _____ C:\WINDOWS\WindowsUpdate (1).log
2013-11-14 07:17 - 2013-11-14 07:17 - 00000000 ____D C:\Users\Anna\AppData\Local\VirtualStore
2013-11-14 07:17 - 2013-01-29 06:06 - 00000000 ___HD C:\Users\Anna\Documents\hp.system.package.metadata
2013-11-14 07:12 - 2013-11-14 07:12 - 00000000 _____ C:\Recovery.txt

==================== One Month Modified Files and Folders =======

2013-11-15 07:42 - 2013-11-15 07:42 - 00010174 _____ C:\Users\Anna\Desktop\FRST.txt
2013-11-15 07:42 - 2013-11-15 07:42 - 00000000 ____D C:\FRST
2013-11-15 07:42 - 2013-11-14 10:46 - 01889016 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-15 07:40 - 2013-11-15 07:40 - 01957794 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2013-11-15 07:40 - 2013-11-15 07:40 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2013-11-15 07:40 - 2013-11-15 07:40 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-15 07:40 - 2013-11-14 07:26 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1143663921-3194390258-2856191937-1001
2013-11-15 07:40 - 2013-01-29 06:06 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-11-15 07:38 - 2013-11-14 07:19 - 00003914 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{211EF257-B9B6-4D8E-85C3-DE86094A10D9}
2013-11-15 07:35 - 2013-11-14 10:51 - 00000000 __RDO C:\Users\Anna\SkyDrive
2013-11-15 07:34 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-11-14 22:59 - 2013-09-29 20:04 - 00956412 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-14 22:51 - 2013-11-14 22:39 - 00000000 ____D C:\Users\Anna\AppData\Local\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 22:25 - 2013-11-14 22:25 - 00688992 _____ (Swearware) C:\Users\Anna\Desktop\dds.com
2013-11-14 22:20 - 2013-11-14 22:20 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Anna\Desktop\tdsskiller.exe
2013-11-14 22:17 - 2013-11-14 11:27 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2013-11-14 22:16 - 2013-08-22 06:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-14 13:17 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-11-14 13:16 - 2013-11-14 07:17 - 00000000 ____D C:\Users\Anna\AppData\Local\Packages
2013-11-14 13:11 - 2013-11-14 13:11 - 00000145 _____ C:\Users\Anna\.appletviewer
2013-11-14 13:11 - 2013-11-14 10:37 - 00000000 ____D C:\Users\Anna
2013-11-14 13:08 - 2013-11-14 13:08 - 00000000 ____D C:\Users\Anna\workspace
2013-11-14 13:07 - 2013-11-14 13:07 - 00000000 ____D C:\Users\Anna\.eclipse
2013-11-14 12:14 - 2013-11-14 12:09 - 00000000 ____D C:\Users\Anna\.nbi
2013-11-14 12:13 - 2013-11-14 12:10 - 00000000 ____D C:\Program Files\NetBeans 7.4
2013-11-14 12:10 - 2013-11-14 12:10 - 00001155 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk
2013-11-14 12:09 - 2013-11-14 12:08 - 00000000 ____D C:\Program Files\eclipse
2013-11-14 12:09 - 2013-11-14 10:32 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-14 12:08 - 2013-11-14 12:08 - 00312744 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00108968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2013-11-14 12:08 - 2013-11-14 12:07 - 00000000 ____D C:\Program Files\Java
2013-11-14 11:57 - 2013-11-14 11:57 - 00000000 ____D C:\Users\Anna\AppData\Local\Hewlett-Packard
2013-11-14 11:56 - 2013-11-14 11:56 - 00000000 ____D C:\Users\Anna\AppData\Roaming\LibreOffice
2013-11-14 11:53 - 2013-09-29 19:55 - 00001142 _____ C:\WINDOWS\PFRO.log
2013-11-14 11:53 - 2013-08-22 06:44 - 00399256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-14 11:53 - 2013-08-22 05:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-11-14 11:50 - 2013-11-14 11:50 - 00000773 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Web of Trust (WOT) – Crowdsourced web safety  WOT (Web of Trust).website
2013-11-14 11:35 - 2013-11-14 11:35 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-14 11:35 - 2013-08-22 06:46 - 00291785 _____ C:\WINDOWS\setupact.log
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-14 11:27 - 2013-11-14 11:27 - 01032416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00409832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00334648 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2013-11-14 11:27 - 2013-11-14 11:27 - 00205320 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00092544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00084328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00065776 _____ C:\WINDOWS\system32\Drivers\aswRvrt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2013-11-14 11:27 - 2013-11-14 11:27 - 00038984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswFsBlk.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Users\Anna\AppData\Roaming\AVAST Software
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-14 11:26 - 2013-11-14 11:26 - 00000000 ____D C:\ProgramData\AVAST Software
2013-11-14 11:25 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\restore
2013-11-14 11:08 - 2013-11-14 11:08 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-11-14 10:59 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Hewlett-Packard
2013-11-14 10:50 - 2013-11-14 10:50 - 00001448 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-14 10:50 - 2013-11-14 10:50 - 00000020 ___SH C:\Users\Anna\ntuser.ini
2013-11-14 10:50 - 2013-11-14 07:19 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-14 10:50 - 2013-11-14 07:19 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-14 10:47 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\rescache
2013-11-14 10:46 - 2013-11-14 10:37 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2013-11-14 10:46 - 2013-11-14 10:37 - 00020958 _____ C:\WINDOWS\diagerr.xml
2013-11-14 10:46 - 2013-11-14 10:15 - 00006702 _____ C:\WINDOWS\comsetup.log
2013-11-14 10:46 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\Registration
2013-11-14 10:45 - 2013-11-14 10:45 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-14 10:44 - 2013-08-22 07:36 - 00000000 __RSD C:\WINDOWS\Media
2013-11-14 10:43 - 2013-08-22 07:36 - 00000000 __RHD C:\Users\Public\Libraries
2013-11-14 10:41 - 2013-08-22 05:25 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM
2013-11-14 10:41 - 2013-01-29 06:35 - 00000000 ____D C:\WINDOWS\en
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default\Documents\hp.system.package.metadata
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default User\Documents\hp.system.package.metadata
2013-11-14 10:40 - 2013-09-29 19:48 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2013-11-14 10:40 - 2013-09-29 19:48 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2013-11-14 10:40 - 2013-09-29 19:48 - 00000000 ____D C:\WINDOWS\system32\WCN
2013-11-14 10:40 - 2013-08-22 07:37 - 00004893 _____ C:\WINDOWS\DtcInstall.log
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\spool
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\MUI
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\IME
2013-11-14 10:40 - 2013-08-22 05:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2013-11-14 10:40 - 2013-08-22 05:36 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-11-14 10:40 - 2012-07-25 21:37 - 00000000 ____D C:\Users\Default.migrated
2013-11-14 10:39 - 2013-08-22 07:43 - 00000000 ____D C:\WINDOWS\DigitalLocker
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\Help
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-14 10:39 - 2012-08-01 18:05 - 00000000 ____D C:\ProgramData\PRICache
2013-11-14 10:38 - 2013-11-14 10:38 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-14 10:38 - 2013-11-14 10:37 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-14 10:38 - 2013-11-14 10:35 - 00012096 _____ C:\WINDOWS\iis.log
2013-11-14 10:38 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\Recovery
2013-11-14 10:35 - 2013-11-14 10:35 - 00930400 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2013-11-14 10:35 - 2013-08-22 05:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\Realtek
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\AMD
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2013-11-14 10:33 - 2013-08-22 05:36 - 00000000 __RHD C:\Users\Default
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 __SHD C:\Recovery
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 ____D C:\Windows.old
2013-11-14 10:32 - 2013-08-22 07:36 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2013-11-14 10:31 - 2013-11-14 10:31 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-14 10:31 - 2013-11-14 10:31 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-14 10:30 - 2013-08-22 07:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-11-14 10:30 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\Camera
2013-11-14 10:29 - 2013-11-14 10:29 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2013-11-14 10:29 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-14 10:29 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\migwiz
2013-11-14 10:29 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-14 10:28 - 2013-11-14 10:28 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00523096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-11-14 10:28 - 2013-11-14 10:28 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00371032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-11-14 10:28 - 2013-11-14 10:28 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00057176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-14 10:26 - 2013-11-14 10:26 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-14 10:25 - 2013-11-14 10:25 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\MSBuild
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-14 10:25 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2013-11-14 10:25 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2013-11-14 10:24 - 2013-11-14 10:24 - 00155480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2013-11-14 10:19 - 2013-11-14 07:17 - 01801805 _____ C:\WINDOWS\WindowsUpdate (1).log
2013-11-14 10:14 - 2013-09-29 20:51 - 00000000 ___HD C:\$Windows.~BT
2013-11-14 10:07 - 2012-07-26 00:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\Users\Anna\AppData\Local\AMD
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\ProgramData\ATI
2013-11-14 09:51 - 2013-11-14 09:51 - 00060777 _____ C:\WINDOWS\SysWOW64\CCCInstall_201311140951425666.log
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\ProgramData\AMD
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-11-14 09:51 - 2013-11-14 09:49 - 00000000 ____D C:\Program Files\ATI Technologies
2013-11-14 09:51 - 2013-01-29 06:09 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2013-11-14 09:50 - 2013-11-14 09:50 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-14 09:48 - 2013-11-14 09:48 - 00000000 ____D C:\AMD
2013-11-14 09:21 - 2013-01-29 06:36 - 00000000 ____D C:\ProgramData\Norton
2013-11-14 09:18 - 2012-07-26 00:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2013-11-14 08:24 - 2013-11-14 08:23 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 08:19 - 2013-11-14 08:19 - 00000000 ____D C:\Users\Anna\Documents\DVR
2013-11-14 08:01 - 2013-11-14 08:01 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-14 07:56 - 2013-01-29 06:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-14 07:26 - 2013-11-14 07:26 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Macromedia
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Roaming\ATI
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Local\ATI
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Adobe
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Local\Power2Go8
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\SysWOW64\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\system32\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-01-29 06:34 - 00000000 ___RD C:\Program Files\Online Services
2013-11-14 07:18 - 2013-01-29 06:15 - 00000000 ___RD C:\Program Files (x86)\Online Services
2013-11-14 07:18 - 2013-01-07 03:46 - 00000000 _RSHD C:\hp
2013-11-14 07:18 - 2012-08-01 19:15 - 00000000 ____D C:\SWSETUP
2013-11-14 07:18 - 2012-08-01 01:57 - 00000000 _RSHD C:\system.sav
2013-11-14 07:17 - 2013-11-14 07:17 - 00000000 ____D C:\Users\Anna\AppData\Local\VirtualStore
2013-11-14 07:12 - 2013-11-14 07:12 - 00000000 _____ C:\Recovery.txt
2013-11-07 16:00 - 2013-11-14 08:22 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-05 15:31 - 2013-08-22 07:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-11-05 15:31 - 2013-08-22 07:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2013-11-14 10:28] - [2013-11-14 10:28] - 2328872 ____A (Microsoft Corporation) 63DC38C3E4564B2405D562855643ABA2

C:\Windows\SysWOW64\explorer.exe
[2013-11-14 10:28] - [2013-11-14 10:28] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll
[2013-11-14 10:28] - [2013-11-14 10:28] - 1362944 ____A (Microsoft Corporation) C72456BFFE941714CF05B0AA0BEE5B45

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-14 10:33

==================== End Of Log ============================

Attached Files


Edited by Angel of the Moon, 15 November 2013 - 06:52 AM.


#6 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 15 November 2013 - 10:47 AM

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt 
 

SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL =
SearchScopes: HKCU - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL =
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =

 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
----------
 
Post the new FRST log and let me know how your system is running.   :)


Posted Image
 
 

#7 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 15 November 2013 - 01:21 PM

Hello Jeff,

 

My system seems to be running fine; however, there's a few things that are not normal. For instance: recovering something from the recycle bin. If I delete an application file and restore it back to its original location (Desktop), it would do so without error/notification; however, if a delete a shortcut and restore it, I get an error message saying I need administrative permission as I am not allowed to move the file. Secondly, I can't paste anything in the What the Tech reply box using Internet Explorer. When I right-click the text-box area I am given the option to paste the text I copped; but, it doesn’t paste. Everywhere else though is fine. So I don't know if this is What the Tech problem or not. The only way I am pasting the logs is by using Firefox. Other than that everything fine. Here are the logs you requested.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-11-2013
Ran by Anna at 2013-11-15 13:31:35 Run:1
Running from C:\Users\Anna\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPDTDF
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL =
SearchScopes: HKCU - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL =
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
*****************

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully.
HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully.
HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{34DC9E98-373F-4B8E-9386-6AF33F502E3C} => Key deleted successfully.
HKCR\CLSID\{34DC9E98-373F-4B8E-9386-6AF33F502E3C} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key deleted successfully.
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key not found.

==== End of Fixlog ====

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013
Ran by Anna (administrator) on ANNAPC on 15-11-2013 13:44:04
Running from C:\Users\Anna\Desktop
Windows 8.1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\WINDOWS\system32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\WINDOWS\WinStore\WSHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2013-11-07] (Hewlett-Packard)
MountPoints2: {701fbc9f-4dbd-11e3-be73-7054d296e1a2} - "H:\LaunchU3.exe" -a
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-10-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-14] (AVAST Software)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL = http://www.amazon.co...s={searchTerms}
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...54371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM-x32 - {34DC9E98-373F-4B8E-9386-6AF33F502E3C} URL = http://www.amazon.co...s={searchTerms}
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...54371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPDTDF
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\r7h6unwt.default
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()

==================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-10-08] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-14] (AVAST Software)
R2 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-08-29] (Hewlett-Packard)
S2 HPRegistrationSvc; c:\Program Files (x86)\Hewlett-Packard\HP Registration Service\HPRegistrationService.exe [205216 2012-07-18] (Hewlett-Packard)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-14] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57512 2012-11-20] (Advanced Micro Devices)
R2 aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [38984 2013-11-14] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [84328 2013-11-14] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [92544 2013-11-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-14] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1032416 2013-11-14] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [409832 2013-11-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-11-14] ()
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows ® Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-14] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-15 11:15 - 2013-11-15 11:30 - 00000028 _____ C:\WINDOWS\ODBC.INI
2013-11-15 11:13 - 2013-11-15 11:14 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2013-11-15 07:43 - 2013-11-15 07:43 - 00018678 _____ C:\Users\Anna\Desktop\Addition.txt
2013-11-15 07:42 - 2013-11-15 13:44 - 00009118 _____ C:\Users\Anna\Desktop\FRST.txt
2013-11-15 07:42 - 2013-11-15 07:42 - 00000000 ____D C:\FRST
2013-11-15 07:40 - 2013-11-15 07:40 - 01957794 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2013-11-15 07:40 - 2013-11-15 07:40 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2013-11-15 07:40 - 2013-11-15 07:40 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-14 22:39 - 2013-11-14 22:51 - 00000000 ____D C:\Users\Anna\AppData\Local\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 22:25 - 2013-11-14 22:25 - 00688992 _____ (Swearware) C:\Users\Anna\Desktop\dds.com
2013-11-14 22:20 - 2013-11-14 22:20 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Anna\Desktop\tdsskiller.exe
2013-11-14 13:11 - 2013-11-14 13:11 - 00000145 _____ C:\Users\Anna\.appletviewer
2013-11-14 13:08 - 2013-11-14 13:08 - 00000000 ____D C:\Users\Anna\workspace
2013-11-14 13:07 - 2013-11-14 13:07 - 00000000 ____D C:\Users\Anna\.eclipse
2013-11-14 12:10 - 2013-11-14 12:13 - 00000000 ____D C:\Program Files\NetBeans 7.4
2013-11-14 12:10 - 2013-11-14 12:10 - 00001155 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk
2013-11-14 12:09 - 2013-11-14 12:14 - 00000000 ____D C:\Users\Anna\.nbi
2013-11-14 12:08 - 2013-11-14 12:09 - 00000000 ____D C:\Program Files\eclipse
2013-11-14 12:08 - 2013-11-14 12:08 - 00312744 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00108968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2013-11-14 12:07 - 2013-11-14 12:08 - 00000000 ____D C:\Program Files\Java
2013-11-14 11:57 - 2013-11-14 11:57 - 00000000 ____D C:\Users\Anna\AppData\Local\Hewlett-Packard
2013-11-14 11:56 - 2013-11-14 11:56 - 00000000 ____D C:\Users\Anna\AppData\Roaming\LibreOffice
2013-11-14 11:50 - 2013-11-14 11:50 - 00000773 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Web of Trust (WOT) – Crowdsourced web safety  WOT (Web of Trust).website
2013-11-14 11:35 - 2013-11-14 11:35 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-14 11:30 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-11-14 11:27 - 2013-11-14 22:17 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2013-11-14 11:27 - 2013-11-14 11:27 - 01032416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00409832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00334648 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2013-11-14 11:27 - 2013-11-14 11:27 - 00205320 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00092544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00084328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00065776 _____ C:\WINDOWS\system32\Drivers\aswRvrt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2013-11-14 11:27 - 2013-11-14 11:27 - 00038984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswFsBlk.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Users\Anna\AppData\Roaming\AVAST Software
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-14 11:26 - 2013-11-14 11:26 - 00000000 ____D C:\ProgramData\AVAST Software
2013-11-14 11:08 - 2013-11-14 11:08 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-11-14 10:51 - 2013-11-15 13:27 - 00000000 __RDO C:\Users\Anna\SkyDrive
2013-11-14 10:50 - 2013-11-14 10:50 - 00001448 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-14 10:50 - 2013-11-14 10:50 - 00000020 ___SH C:\Users\Anna\ntuser.ini
2013-11-14 10:46 - 2013-11-15 13:38 - 01915577 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-14 10:45 - 2013-11-14 10:45 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default\Documents\hp.system.package.metadata
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default User\Documents\hp.system.package.metadata
2013-11-14 10:38 - 2013-11-14 10:38 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-14 10:37 - 2013-11-14 13:11 - 00000000 ____D C:\Users\Anna
2013-11-14 10:37 - 2013-11-14 10:46 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2013-11-14 10:37 - 2013-11-14 10:46 - 00020958 _____ C:\WINDOWS\diagerr.xml
2013-11-14 10:37 - 2013-11-14 10:38 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-14 10:37 - 2013-08-22 07:36 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-14 10:37 - 2013-08-22 07:36 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-14 10:37 - 2013-08-22 07:36 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-14 10:35 - 2013-11-14 10:38 - 00012096 _____ C:\WINDOWS\iis.log
2013-11-14 10:35 - 2013-11-14 10:35 - 00930400 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\Realtek
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\AMD
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2013-11-14 10:32 - 2013-11-14 12:09 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 __SHD C:\Recovery
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 ____D C:\Windows.old
2013-11-14 10:31 - 2013-11-14 10:31 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-14 10:31 - 2013-11-14 10:31 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00523096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-11-14 10:28 - 2013-11-14 10:28 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00371032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-11-14 10:28 - 2013-11-14 10:28 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00057176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-14 10:26 - 2013-11-14 10:26 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-14 10:25 - 2013-11-14 10:25 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\MSBuild
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-14 10:25 - 2013-08-02 20:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2013-11-14 10:25 - 2013-08-02 20:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-11-14 10:25 - 2013-08-02 20:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2013-11-14 10:24 - 2013-11-14 10:24 - 00155480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2013-11-14 10:24 - 2013-08-02 20:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2013-11-14 10:24 - 2013-08-02 20:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-14 10:24 - 2013-08-02 20:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2013-11-14 10:15 - 2013-11-14 10:46 - 00006702 _____ C:\WINDOWS\comsetup.log
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\Users\Anna\AppData\Local\AMD
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\ProgramData\ATI
2013-11-14 09:51 - 2013-11-14 09:51 - 00060777 _____ C:\WINDOWS\SysWOW64\CCCInstall_201311140951425666.log
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\ProgramData\AMD
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-11-14 09:50 - 2013-11-14 09:50 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-14 09:49 - 2013-11-14 09:51 - 00000000 ____D C:\Program Files\ATI Technologies
2013-11-14 09:48 - 2013-11-14 09:48 - 00000000 ____D C:\AMD
2013-11-14 08:23 - 2013-11-14 08:24 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 08:22 - 2013-11-07 16:00 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-14 08:19 - 2013-11-14 08:19 - 00000000 ____D C:\Users\Anna\Documents\DVR
2013-11-14 08:01 - 2013-11-14 08:01 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-14 07:35 - 2013-05-03 20:51 - 00014848 _____ (Microsoft) C:\WINDOWS\system32\rars.rs
2013-11-14 07:35 - 2013-05-03 20:10 - 00014848 _____ (Microsoft) C:\WINDOWS\SysWOW64\rars.rs
2013-11-14 07:26 - 2013-11-15 13:32 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1143663921-3194390258-2856191937-1001
2013-11-14 07:26 - 2013-11-14 07:26 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Macromedia
2013-11-14 07:20 - 2013-11-14 10:59 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Hewlett-Packard
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Roaming\ATI
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Local\ATI
2013-11-14 07:19 - 2013-11-15 07:38 - 00003914 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{211EF257-B9B6-4D8E-85C3-DE86094A10D9}
2013-11-14 07:19 - 2013-11-14 10:50 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-14 07:19 - 2013-11-14 10:50 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Adobe
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Local\Power2Go8
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\SysWOW64\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\system32\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-01-29 06:34 - 00002213 _____ C:\Users\Public\Desktop\Snapfish.lnk
2013-11-14 07:18 - 2013-01-29 06:25 - 00002103 _____ C:\Users\Public\Desktop\HP Games.lnk
2013-11-14 07:17 - 2013-11-14 13:16 - 00000000 ____D C:\Users\Anna\AppData\Local\Packages
2013-11-14 07:17 - 2013-11-14 10:19 - 01801805 _____ C:\WINDOWS\WindowsUpdate (1).log
2013-11-14 07:17 - 2013-11-14 07:17 - 00000000 ____D C:\Users\Anna\AppData\Local\VirtualStore
2013-11-14 07:17 - 2013-01-29 06:06 - 00000000 ___HD C:\Users\Anna\Documents\hp.system.package.metadata
2013-11-14 07:12 - 2013-11-14 07:12 - 00000000 _____ C:\Recovery.txt

==================== One Month Modified Files and Folders =======

2013-11-15 13:44 - 2013-11-15 07:42 - 00009118 _____ C:\Users\Anna\Desktop\FRST.txt
2013-11-15 13:39 - 2013-09-29 20:04 - 00956412 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-15 13:38 - 2013-11-14 10:46 - 01915577 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-15 13:32 - 2013-11-14 07:26 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1143663921-3194390258-2856191937-1001
2013-11-15 13:29 - 2013-08-22 06:46 - 00293373 _____ C:\WINDOWS\setupact.log
2013-11-15 13:27 - 2013-11-14 10:51 - 00000000 __RDO C:\Users\Anna\SkyDrive
2013-11-15 13:26 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-11-15 11:30 - 2013-11-15 11:15 - 00000028 _____ C:\WINDOWS\ODBC.INI
2013-11-15 11:14 - 2013-11-15 11:13 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2013-11-15 07:43 - 2013-11-15 07:43 - 00018678 _____ C:\Users\Anna\Desktop\Addition.txt
2013-11-15 07:42 - 2013-11-15 07:42 - 00000000 ____D C:\FRST
2013-11-15 07:40 - 2013-11-15 07:40 - 01957794 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2013-11-15 07:40 - 2013-11-15 07:40 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2013-11-15 07:40 - 2013-11-15 07:40 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-15 07:40 - 2013-01-29 06:06 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-11-15 07:38 - 2013-11-14 07:19 - 00003914 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{211EF257-B9B6-4D8E-85C3-DE86094A10D9}
2013-11-14 22:51 - 2013-11-14 22:39 - 00000000 ____D C:\Users\Anna\AppData\Local\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Mozilla
2013-11-14 22:39 - 2013-11-14 22:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 22:25 - 2013-11-14 22:25 - 00688992 _____ (Swearware) C:\Users\Anna\Desktop\dds.com
2013-11-14 22:20 - 2013-11-14 22:20 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Anna\Desktop\tdsskiller.exe
2013-11-14 22:17 - 2013-11-14 11:27 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2013-11-14 22:16 - 2013-08-22 06:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-14 13:17 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-11-14 13:16 - 2013-11-14 07:17 - 00000000 ____D C:\Users\Anna\AppData\Local\Packages
2013-11-14 13:11 - 2013-11-14 13:11 - 00000145 _____ C:\Users\Anna\.appletviewer
2013-11-14 13:11 - 2013-11-14 10:37 - 00000000 ____D C:\Users\Anna
2013-11-14 13:08 - 2013-11-14 13:08 - 00000000 ____D C:\Users\Anna\workspace
2013-11-14 13:07 - 2013-11-14 13:07 - 00000000 ____D C:\Users\Anna\.eclipse
2013-11-14 12:14 - 2013-11-14 12:09 - 00000000 ____D C:\Users\Anna\.nbi
2013-11-14 12:13 - 2013-11-14 12:10 - 00000000 ____D C:\Program Files\NetBeans 7.4
2013-11-14 12:10 - 2013-11-14 12:10 - 00001155 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eclipse.lnk
2013-11-14 12:09 - 2013-11-14 12:08 - 00000000 ____D C:\Program Files\eclipse
2013-11-14 12:09 - 2013-11-14 10:32 - 00000000 ___DC C:\WINDOWS\Panther
2013-11-14 12:08 - 2013-11-14 12:08 - 00312744 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-11-14 12:08 - 2013-11-14 12:08 - 00108968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2013-11-14 12:08 - 2013-11-14 12:07 - 00000000 ____D C:\Program Files\Java
2013-11-14 11:57 - 2013-11-14 11:57 - 00000000 ____D C:\Users\Anna\AppData\Local\Hewlett-Packard
2013-11-14 11:56 - 2013-11-14 11:56 - 00000000 ____D C:\Users\Anna\AppData\Roaming\LibreOffice
2013-11-14 11:53 - 2013-09-29 19:55 - 00001142 _____ C:\WINDOWS\PFRO.log
2013-11-14 11:53 - 2013-08-22 06:44 - 00399256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-14 11:53 - 2013-08-22 05:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-11-14 11:50 - 2013-11-14 11:50 - 00000773 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Web of Trust (WOT) – Crowdsourced web safety  WOT (Web of Trust).website
2013-11-14 11:35 - 2013-11-14 11:35 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-14 11:30 - 2013-11-14 11:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-14 11:27 - 2013-11-14 11:27 - 01032416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00409832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00334648 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2013-11-14 11:27 - 2013-11-14 11:27 - 00205320 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00092544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00084328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00065776 _____ C:\WINDOWS\system32\Drivers\aswRvrt.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2013-11-14 11:27 - 2013-11-14 11:27 - 00038984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswFsBlk.sys
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Users\Anna\AppData\Roaming\AVAST Software
2013-11-14 11:27 - 2013-11-14 11:27 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-14 11:26 - 2013-11-14 11:26 - 00000000 ____D C:\ProgramData\AVAST Software
2013-11-14 11:25 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\restore
2013-11-14 11:08 - 2013-11-14 11:08 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-11-14 10:59 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Hewlett-Packard
2013-11-14 10:50 - 2013-11-14 10:50 - 00001448 _____ C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-14 10:50 - 2013-11-14 10:50 - 00000020 ___SH C:\Users\Anna\ntuser.ini
2013-11-14 10:50 - 2013-11-14 07:19 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-14 10:50 - 2013-11-14 07:19 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-14 10:47 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\rescache
2013-11-14 10:46 - 2013-11-14 10:37 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2013-11-14 10:46 - 2013-11-14 10:37 - 00020958 _____ C:\WINDOWS\diagerr.xml
2013-11-14 10:46 - 2013-11-14 10:15 - 00006702 _____ C:\WINDOWS\comsetup.log
2013-11-14 10:46 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\Registration
2013-11-14 10:45 - 2013-11-14 10:45 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2013-11-14 10:44 - 2013-08-22 07:36 - 00000000 __RSD C:\WINDOWS\Media
2013-11-14 10:43 - 2013-08-22 07:36 - 00000000 __RHD C:\Users\Public\Libraries
2013-11-14 10:41 - 2013-08-22 05:25 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM
2013-11-14 10:41 - 2013-01-29 06:35 - 00000000 ____D C:\WINDOWS\en
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default\Documents\hp.system.package.metadata
2013-11-14 10:40 - 2013-11-14 10:40 - 00000000 ____D C:\Users\Default User\Documents\hp.system.package.metadata
2013-11-14 10:40 - 2013-09-29 19:48 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2013-11-14 10:40 - 2013-09-29 19:48 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2013-11-14 10:40 - 2013-09-29 19:48 - 00000000 ____D C:\WINDOWS\system32\WCN
2013-11-14 10:40 - 2013-08-22 07:37 - 00004893 _____ C:\WINDOWS\DtcInstall.log
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\spool
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\MUI
2013-11-14 10:40 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\IME
2013-11-14 10:40 - 2013-08-22 05:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2013-11-14 10:40 - 2013-08-22 05:36 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-11-14 10:40 - 2012-07-25 21:37 - 00000000 ____D C:\Users\Default.migrated
2013-11-14 10:39 - 2013-08-22 07:43 - 00000000 ____D C:\WINDOWS\DigitalLocker
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\Help
2013-11-14 10:39 - 2013-08-22 07:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-14 10:39 - 2012-08-01 18:05 - 00000000 ____D C:\ProgramData\PRICache
2013-11-14 10:38 - 2013-11-14 10:38 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2013-11-14 10:38 - 2013-11-14 10:37 - 00000000 ___RD C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-14 10:38 - 2013-11-14 10:35 - 00012096 _____ C:\WINDOWS\iis.log
2013-11-14 10:38 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\Recovery
2013-11-14 10:35 - 2013-11-14 10:35 - 00930400 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2013-11-14 10:35 - 2013-08-22 05:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\Realtek
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 ____D C:\Program Files\AMD
2013-11-14 10:34 - 2013-11-14 10:34 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2013-11-14 10:33 - 2013-08-22 05:36 - 00000000 __RHD C:\Users\Default
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 __SHD C:\Recovery
2013-11-14 10:32 - 2013-11-14 10:32 - 00000000 ____D C:\Windows.old
2013-11-14 10:32 - 2013-08-22 07:36 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2013-11-14 10:31 - 2013-11-14 10:31 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-14 10:31 - 2013-11-14 10:31 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01286552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 01018960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00977408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2013-11-14 10:30 - 2013-11-14 10:30 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2013-11-14 10:30 - 2013-08-22 07:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-11-14 10:30 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\Camera
2013-11-14 10:29 - 2013-11-14 10:29 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2013-11-14 10:29 - 2013-11-14 10:29 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2013-11-14 10:29 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-14 10:29 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\migwiz
2013-11-14 10:29 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-14 10:28 - 2013-11-14 10:28 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-14 10:28 - 2013-11-14 10:28 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00523096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-11-14 10:28 - 2013-11-14 10:28 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00371032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-11-14 10:28 - 2013-11-14 10:28 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00057176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2013-11-14 10:28 - 2013-11-14 10:28 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2013-11-14 10:28 - 2013-11-14 10:28 - 00039768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-11-14 10:28 - 2013-11-14 10:28 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-14 10:27 - 2013-11-14 10:27 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-14 10:27 - 2013-11-14 10:27 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-14 10:26 - 2013-11-14 10:26 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-11-14 10:25 - 2013-11-14 10:25 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2013-11-14 10:25 - 2013-11-14 10:25 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files\MSBuild
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-11-14 10:25 - 2013-11-14 10:25 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-14 10:25 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2013-11-14 10:25 - 2013-08-22 07:36 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2013-11-14 10:24 - 2013-11-14 10:24 - 00155480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2013-11-14 10:19 - 2013-11-14 07:17 - 01801805 _____ C:\WINDOWS\WindowsUpdate (1).log
2013-11-14 10:14 - 2013-09-29 20:51 - 00000000 ___HD C:\$Windows.~BT
2013-11-14 10:07 - 2012-07-26 00:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\Users\Anna\AppData\Local\AMD
2013-11-14 09:52 - 2013-11-14 09:52 - 00000000 ____D C:\ProgramData\ATI
2013-11-14 09:51 - 2013-11-14 09:51 - 00060777 _____ C:\WINDOWS\SysWOW64\CCCInstall_201311140951425666.log
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\ProgramData\AMD
2013-11-14 09:51 - 2013-11-14 09:51 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-11-14 09:51 - 2013-11-14 09:49 - 00000000 ____D C:\Program Files\ATI Technologies
2013-11-14 09:51 - 2013-01-29 06:09 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2013-11-14 09:50 - 2013-11-14 09:50 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-14 09:48 - 2013-11-14 09:48 - 00000000 ____D C:\AMD
2013-11-14 09:21 - 2013-01-29 06:36 - 00000000 ____D C:\ProgramData\Norton
2013-11-14 09:18 - 2012-07-26 00:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2013-11-14 08:24 - 2013-11-14 08:23 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-14 08:19 - 2013-11-14 08:19 - 00000000 ____D C:\Users\Anna\Documents\DVR
2013-11-14 08:01 - 2013-11-14 08:01 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-14 07:56 - 2013-01-29 06:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-14 07:26 - 2013-11-14 07:26 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Macromedia
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Roaming\ATI
2013-11-14 07:20 - 2013-11-14 07:20 - 00000000 ____D C:\Users\Anna\AppData\Local\ATI
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Adobe
2013-11-14 07:19 - 2013-11-14 07:19 - 00000000 ____D C:\Users\Anna\AppData\Local\Power2Go8
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\SysWOW64\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-11-14 07:18 - 00000000 __RSH C:\WINDOWS\system32\Drivers\103C_HP_cPC_p6-2316s_Y53316J_0U_QMXU30802WT_E12NA3RR8607_4A_I2ACF_SPEGATRON CORPORATION_V1.03_B8.12_T121218_W8101-0_L409_M3557_J500_7AMD_8F10_92.80_#130129_N10EC8168_Z_G10029644_Ohp DVD A DH16ACSHR_DSAM08E9.MRK
2013-11-14 07:18 - 2013-01-29 06:34 - 00000000 ___RD C:\Program Files\Online Services
2013-11-14 07:18 - 2013-01-29 06:15 - 00000000 ___RD C:\Program Files (x86)\Online Services
2013-11-14 07:18 - 2013-01-07 03:46 - 00000000 _RSHD C:\hp
2013-11-14 07:18 - 2012-08-01 19:15 - 00000000 ____D C:\SWSETUP
2013-11-14 07:18 - 2012-08-01 01:57 - 00000000 _RSHD C:\system.sav
2013-11-14 07:17 - 2013-11-14 07:17 - 00000000 ____D C:\Users\Anna\AppData\Local\VirtualStore
2013-11-14 07:12 - 2013-11-14 07:12 - 00000000 _____ C:\Recovery.txt
2013-11-07 16:00 - 2013-11-14 08:22 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-05 15:31 - 2013-08-22 07:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-11-05 15:31 - 2013-08-22 07:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2013-11-14 10:28] - [2013-11-14 10:28] - 2328872 ____A (Microsoft Corporation) 63DC38C3E4564B2405D562855643ABA2

C:\Windows\SysWOW64\explorer.exe
[2013-11-14 10:28] - [2013-11-14 10:28] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll
[2013-11-14 10:28] - [2013-11-14 10:28] - 1362944 ____A (Microsoft Corporation) C72456BFFE941714CF05B0AA0BEE5B45

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-14 10:33

==================== End Of Log ============================



#8 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 15 November 2013 - 01:25 PM

The problem that you are having with posting replies here is probably the forum.  We are going through some changes here.   :)  The other we will address in a bit.
 
GUZVCQN.jpgMalwarebytes
 
Please open Malwarebytes, update it and then run a Quick Scan.  Save the log that is created for your next reply.
----------
 

ESET Online Scanner
 
Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.

----------


Posted Image
 
 

#9 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 15 November 2013 - 06:59 PM

Hello Jeff,

 

Ran ESET and no threats were found. Since no threats were found, it didn't give me an option of exporting the scan log. However, I was able to get the log from Malwarebytes (pasted below). Everything is fine except for the one thing I've already mentioned. When I try to recover a simple shortcut from the recycle bin to desktop, it denies me access. Everything else is fine. Finally here is the Malwarebytes log.

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.11.15.10

Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16438
Anna :: ANNAPC [administrator]

11/15/2013 4:23:05 PM
mbam-log-2013-11-15 (16-23-05).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204240
Time elapsed: 3 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



#10 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 16 November 2013 - 08:46 AM

Good....let's see if we can get that remaining problem fixed up.
 
n1eMMmT.jpg  Download  Windows Repair (all in one)  from this site 
 
Install and then run the program.
 
On the Start Repairs tab click Start
DwysfIW.jpg
 
 
When the Repair Options screen populates, be sure to select all items and also check Restart System When Finished.
 
Now press Start
----------


Posted Image
 
 

    Advertisements

Register to Remove


#11 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 16 November 2013 - 10:22 AM

Hello Jeff,

 

Just did the scan with Windows Repair (all in one) and the problem that I've mentioned/experienced is now gone. Thank you. Now, where do we go from here?



#12 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 16 November 2013 - 02:48 PM

Sounds great!!  Any other malware related problems??


Posted Image
 
 

#13 Angel of the Moon

Angel of the Moon

    Authentic Member

  • Authentic Member
  • PipPip
  • 53 posts

Posted 16 November 2013 - 08:14 PM

Jeff,

 

There is no other problems that I could see. I think we're good.



#14 jeffce

jeffce

    Malware Guy

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,693 posts

Posted 17 November 2013 - 10:23 AM

Providing there are no other malware related problems...
 
IT APPEARS THAT THE LOGS WE HAVE NOW ARE NOW CLEAN!  GREAT JOB!!  
 
This infection appears to have been cleared, but I can not give you any absolute guarantees.  As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
----------
 

ttLR1ki.jpg  Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • ----------
     
    Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop. If you did not have Malwarebytes Antimalware before, I would keep it and run it weekly.
    ----------
     
    Here are some tips to reduce the potential for spyware infection in the future:
     
    1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • 2. FireFox  If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
     
    3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.
     
    4. Firewall
    Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly.   **There are firewalls that could be downloaded and used but I would personally only recommend using one of the following below:
     
    5. Make sure you keep your Windows OS current.  Windows XP users can visit Windows update  regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.  Without these you are leaving the back door open.
     
    6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites.  WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.
     
    7. Finally, I strongly recommend that you read Miekiemoes' great advice How to prevent malware.
     
    Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
    ----------

    Posted Image
     
     

    #15 Angel of the Moon

    Angel of the Moon

      Authentic Member

    • Authentic Member
    • PipPip
    • 53 posts

    Posted 18 November 2013 - 06:29 AM

    Jeff,

     

     I am satisfied and we can mark this problem as resolved. Thank you for your help.

     

    Angel of the Moon


    Related Topics



    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users