Tento log by podle topicu měl být správný
Logfile of random's system information tool 1.09 (written by random/random)
Run by XDANCUMP at 2014-01-12 11:32:23
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 117 GB (50%) free of 234 GB
Total RAM: 8055 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:32:26, on 12.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon2.exe
C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\RealTimeProtector.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\XDANCUMP.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Bluetooth Monitor.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\Windows\SysWOW64\guard32.dll
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Session Launcher Service (FUSServices) - Unknown owner - C:\Windows\SysWOW64\FUSServices.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - (no file)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Samsung AllShare PC (SamsungAllShareV2.0) - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 10544 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 21610528
\??\C:\Windows\system32\conhost.exe "-1828113422-1196841228-307285812-1583608731968674873-80543703320718247531847388907
C:\Windows\System32\spoolsv.exe
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\FUSServices.exe
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\SysWOW64\nlssrv32.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-7e184acd-193e-4622-a742-0b26e83d30e5 -SystemEventPortName:HostProcess-a9c2c701-4fae-4c63-aad2-6f9ba96e2cdb -IoCancelEventPortName:HostProcess-d515a0d6-56a4-4d23-8008-5920e870bb90 -NonStateChangingEventPortName:HostProcess-f16f6787-f441-4863-a166-4c9d9a2418e6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:eb604370-1d4d-4c87-9b4e-017631b22ab4 -DeviceGroupId:WpdFsGroup
"LFOGRPOW.exe"
"taskhost.exe"
taskeng.exe {40917ED0-57F4-49B9-8744-18385E175D7E}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe"
"C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon2.exe"
"C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe"
BtMon64.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\RealTimeProtector.exe" /RunCurUs
"C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2536.0.415672626\1908685513" --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,13,23 --gpu-vendor-id=0x1002 --gpu-device-id=0x9553 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.723.2.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.1.84784011\1248888892" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --instant-process --disable-html-notifications --enable-software-compositing --channel="2536.2.1068599432\1462594617" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.3.2014160149\1341934698" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.4.237964087\2121612344" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.6.469141315\1560273319" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.7.1444683701\838311874" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.8.326504809\1862262841" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.9.949372145\1142519951" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.10.1600408402\1010160901" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.11.2103285482\1402187649" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2536.12.1546969557\1455057278" --ppapi-flash-args --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/DeferBackgroundExtensionCreation/RateLimited/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_44/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --disable-html-notifications --enable-software-compositing --channel="2536.13.1832130584\1745359431" /prefetch:673131151
"C:\Users\XDANCUMP\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\Driver Booster Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2013-11-18 2486592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-10-17 669504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-19 529784]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartFaceVWatcher"=C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2010-07-09 38304]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-22 521272]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-05-10 915320]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-09-25 472984]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AllShareAgent]
C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [2012-03-01 285072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-14 2779024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [2011-08-04 1612920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScannerSelectorEX]
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2011-01-15 452016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPreload]
C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-09-04 1564528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2013-09-04 311152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MFFSum_Pro_LL2]
c:\program files (x86)\companion suite pro ll2\mffsum.exe [2010-01-08 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MFPrintServer_Pro_LL2]
c:\program files (x86)\companion suite pro ll2\mfprintserver.exe [2010-01-08 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
C:\Program Files (x86)\PDF24\pdf24.exe [2012-12-12 163000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder]
c:\program files (x86)\scansoft\paperport\ereg\ereg.exe [2007-02-01 255528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchProtection]
c:\users\xdancump\appdata\roaming\search protection\searchprotection.exe /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
c:\program files (x86)\common files\scansoft shared\ssbkgdupdate\ssbkgdupdate.exe [2006-10-25 210472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO]
C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2010-10-26 1050072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosNC]
C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2010-04-23 595816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
C:\Program Files\toshiba\power saver\tpwrmain.exe [2010-09-28 566184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
c:\program files\zoner\photo studio 15\program32\zpstray.exe [2013-06-07 774680]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^XDANCUMP^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\XDANCUMP\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-12-18 30714312]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PaperPort PTD"=C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [2007-11-13 29984]
"IndexSearch"=C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [2007-11-13 46368]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2013-11-05 2237328]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-04-26 102400]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
Bluetooth Monitor.lnk - C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon2.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\System32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\29927148.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\29927148.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.CFHD"=CFHD.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-01-12 11:32:23 ----D---- C:\rsit
2014-01-12 11:32:23 ----D---- C:\Program Files\trend micro
2014-01-12 03:05:02 ----A---- C:\Windows\wininit.ini
2014-01-12 01:47:28 ----A---- C:\TDSSKiller.3.0.0.19_12.01.2014_01.47.28_log.txt
2014-01-12 01:44:18 ----A---- C:\TDSSKiller.2.8.16.0_12.01.2014_01.44.18_log.txt
2014-01-12 01:36:39 ----A---- C:\TDSSKiller.2.8.16.0_12.01.2014_01.36.39_log.txt
2014-01-11 12:17:41 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-01-11 12:17:41 ----A---- C:\Windows\system32\DWrite.dll
2014-01-07 18:55:12 ----HD---- C:\ProgramData\CanonIJEPPEX
2014-01-05 23:54:24 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2013-12-30 19:22:21 ----A---- C:\Windows\system32\spoolsv.exe
2013-12-30 19:22:21 ----A---- C:\Windows\splwow64.exe
2013-12-28 21:19:58 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-28 21:19:57 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-28 21:19:57 ----A---- C:\Windows\system32\ieui.dll
2013-12-28 21:19:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-28 21:19:56 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-28 21:19:56 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-28 21:19:56 ----A---- C:\Windows\system32\iesetup.dll
2013-12-28 21:19:56 ----A---- C:\Windows\system32\iernonce.dll
2013-12-28 21:19:56 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-28 21:19:56 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-28 21:19:55 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-28 21:19:55 ----A---- C:\Windows\system32\mshtml.dll
2013-12-28 21:19:55 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-28 21:19:55 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-28 21:19:54 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-28 21:19:54 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-28 21:19:53 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-28 21:19:53 ----A---- C:\Windows\system32\iertutil.dll
2013-12-28 21:19:52 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-28 21:19:52 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-28 21:19:52 ----A---- C:\Windows\system32\wininet.dll
2013-12-28 21:19:52 ----A---- C:\Windows\system32\urlmon.dll
2013-12-28 21:19:51 ----A---- C:\Windows\system32\ieframe.dll
2013-12-28 21:19:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-28 21:19:48 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-28 21:19:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-28 21:19:48 ----A---- C:\Windows\system32\jscript9.dll
2013-12-25 04:05:53 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-25 04:05:53 ----A---- C:\Windows\system32\msieftp.dll
2013-12-25 04:05:34 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-25 04:05:34 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-25 04:05:34 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-25 04:05:34 ----A---- C:\Windows\system32\wmp.dll
2013-12-25 04:05:06 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-25 04:05:06 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-25 04:04:45 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-12-25 04:04:45 ----A---- C:\Windows\system32\authui.dll
2013-12-25 04:04:44 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-12-25 04:04:44 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-12-25 04:04:44 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-12-25 04:04:44 ----A---- C:\Windows\system32\credui.dll
2013-12-25 04:03:57 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2013-12-25 04:03:57 ----A---- C:\Windows\system32\cryptdlg.dll
2013-12-25 04:03:16 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2013-12-25 04:03:16 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2013-12-25 04:03:16 ----A---- C:\Windows\system32\WebClnt.dll
2013-12-25 04:03:16 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2013-12-25 04:03:16 ----A---- C:\Windows\system32\davclnt.dll
2013-12-25 04:03:00 ----A---- C:\Windows\system32\scavengeui.dll
2013-12-25 04:02:31 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-12-25 04:02:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-12-25 04:02:31 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2013-12-25 04:02:31 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-12-25 04:02:31 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-12-25 04:02:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\wksprt.exe
2013-12-25 04:02:31 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-12-25 04:02:31 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-25 04:02:31 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\tsgqec.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\rdpudd.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\rdpendp_winip.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\rdpcorets.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\mstscax.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\mstsc.exe
2013-12-25 04:02:31 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-12-25 04:02:31 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-12-25 04:02:31 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2013-12-25 04:02:31 ----A---- C:\Windows\system32\aaclient.dll
2013-12-25 04:02:30 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-12-25 04:02:30 ----A---- C:\Windows\system32\wksprtPS.dll
2013-12-25 03:59:57 ----A---- C:\Windows\system32\drivers\ataport.sys
2013-12-25 03:59:46 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2013-12-25 03:59:46 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-12-25 03:59:36 ----A---- C:\Windows\system32\wwansvc.dll
2013-12-25 03:59:36 ----A---- C:\Windows\system32\wwanprotdim.dll
2013-12-25 03:58:19 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2013-12-25 03:58:19 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2013-12-25 03:58:19 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-12-25 03:58:19 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-12-25 03:57:23 ----A---- C:\Windows\SYSWOW64\netevent.dll
2013-12-25 03:57:23 ----A---- C:\Windows\system32\nlasvc.dll
2013-12-25 03:57:23 ----A---- C:\Windows\system32\nlaapi.dll
2013-12-25 03:57:23 ----A---- C:\Windows\system32\netevent.dll
2013-12-25 03:57:23 ----A---- C:\Windows\system32\ncsi.dll
2013-12-25 03:57:23 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-12-25 03:57:23 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-12-25 03:57:22 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2013-12-25 03:57:22 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2013-12-25 03:57:22 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2013-12-25 03:57:22 ----A---- C:\Windows\system32\netcorehc.dll
2013-12-25 03:56:37 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-12-25 03:56:11 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-12-25 03:56:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-12-25 03:55:55 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2013-12-25 03:55:55 ----A---- C:\Windows\system32\qdvd.dll
2013-12-23 00:30:37 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-12-23 00:25:04 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-12-23 00:25:04 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-23 00:24:57 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-23 00:24:57 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-12-23 00:24:57 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-12-23 00:24:57 ----A---- C:\Windows\system32\elshyph.dll
2013-12-23 00:24:56 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-12-23 00:24:55 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-12-23 00:24:55 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\url.dll
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-12-23 00:24:54 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-12-23 00:24:53 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-12-23 00:24:53 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-12-23 00:24:53 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-12-23 00:24:53 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-12-23 00:24:53 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-12-23 00:24:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-23 00:24:52 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-12-23 00:24:52 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-12-23 00:24:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-12-23 00:24:52 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-12-23 00:24:51 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-12-23 00:24:50 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-12-23 00:24:50 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-12-23 00:24:50 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-12-23 00:24:50 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-12-23 00:24:50 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-12-23 00:24:49 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-12-23 00:24:49 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-23 00:24:46 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-23 00:24:46 ----A---- C:\Windows\system32\msrating.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\msls31.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\mshtmler.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\msfeedssync.exe
2013-12-23 00:24:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\jsIntl.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-23 00:24:46 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\wextract.exe
2013-12-23 00:24:45 ----A---- C:\Windows\system32\webcheck.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\vbscript.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\url.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\pngfilt.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\occache.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\mshtmled.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\mshta.exe
2013-12-23 00:24:45 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\licmgr10.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\jscript.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\inseng.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\imgutil.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\iexpress.exe
2013-12-23 00:24:45 ----A---- C:\Windows\system32\iepeers.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\iedkcs32.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\ieapfltr.dat
2013-12-23 00:24:45 ----A---- C:\Windows\system32\icardie.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\dxtrans.dll
2013-12-23 00:24:45 ----A---- C:\Windows\system32\dxtmsft.dll
2013-12-23 00:23:09 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-12-23 00:23:09 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-12-23 00:23:09 ----A---- C:\Windows\system32\wow64.dll
2013-12-23 00:23:09 ----A---- C:\Windows\system32\tdh.dll
2013-12-23 00:23:09 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-12-23 00:23:09 ----A---- C:\Windows\system32\ntdll.dll
2013-12-23 00:23:09 ----A---- C:\Windows\system32\advapi32.dll
2013-12-23 00:23:08 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-12-23 00:23:08 ----A---- C:\Windows\SYSWOW64\user.exe
2013-12-23 00:23:08 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-12-23 00:23:08 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-12-23 00:23:08 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-12-23 00:23:07 ----A---- C:\Windows\SYSWOW64\tdh.dll
2013-12-23 00:23:07 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-12-23 00:23:07 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2013-12-23 00:22:32 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2013-12-23 00:22:32 ----A---- C:\Windows\system32\mswsock.dll
2013-12-23 00:22:32 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-12-23 00:19:58 ----D---- C:\Program Files (x86)\MSXML 4.0
2013-12-21 22:33:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-12-21 22:33:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-12-21 22:33:00 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-12-21 22:33:00 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2013-12-21 22:33:00 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2013-12-21 22:33:00 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2013-12-21 22:33:00 ----A---- C:\Windows\system32\XpsPrint.dll
2013-12-21 22:33:00 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-12-21 22:33:00 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-12-21 22:33:00 ----A---- C:\Windows\system32\d3d10warp.dll
2013-12-21 22:33:00 ----A---- C:\Windows\system32\d2d1.dll
2013-12-21 22:32:59 ----A---- C:\Windows\system32\dxgi.dll
2013-12-21 22:32:57 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2013-12-21 22:32:57 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2013-12-21 22:32:57 ----A---- C:\Windows\system32\FntCache.dll
2013-12-21 22:32:55 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2013-12-21 22:32:55 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2013-12-21 22:32:55 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2013-12-21 22:32:55 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2013-12-21 22:32:55 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2013-12-21 22:32:55 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2013-12-21 22:32:55 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-12-21 22:32:55 ----A---- C:\Windows\system32\d3d10level9.dll
2013-12-21 22:32:55 ----A---- C:\Windows\system32\d3d10core.dll
2013-12-21 22:32:55 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-12-21 22:32:55 ----A---- C:\Windows\system32\d3d10_1.dll
2013-12-21 22:32:55 ----A---- C:\Windows\system32\d3d10.dll
2013-12-21 22:32:54 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2013-12-21 22:32:54 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2013-12-21 22:32:54 ----A---- C:\Windows\system32\UIAnimation.dll
2013-12-21 22:30:24 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2013-12-21 22:30:24 ----A---- C:\Windows\system32\d3d11.dll
2013-12-21 22:03:09 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-21 22:03:09 ----A---- C:\Windows\system32\tzres.dll
2013-12-21 22:02:56 ----A---- C:\Windows\SYSWOW64\certutil.exe
2013-12-21 22:02:56 ----A---- C:\Windows\system32\certutil.exe
2013-12-21 22:02:53 ----A---- C:\Windows\SYSWOW64\certenc.dll
2013-12-21 22:02:53 ----A---- C:\Windows\system32\certenc.dll
2013-12-21 22:01:51 ----A---- C:\Windows\system32\KernelBase.dll
2013-12-21 22:01:50 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-12-21 22:01:50 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-12-21 22:01:50 ----A---- C:\Windows\system32\smss.exe
2013-12-21 22:01:50 ----A---- C:\Windows\system32\kernel32.dll
2013-12-21 22:01:49 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-12-21 22:01:49 ----A---- C:\Windows\system32\winsrv.dll
2013-12-21 22:01:49 ----A---- C:\Windows\system32\csrsrv.dll
2013-12-21 22:01:49 ----A---- C:\Windows\system32\conhost.exe
2013-12-21 22:01:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-12-21 22:01:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-12-21 22:01:48 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-12-21 22:01:48 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-12-21 22:01:48 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-12-21 22:01:47 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-12-21 22:01:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-12-21 22:01:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-12-21 22:01:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-12-21 22:01:46 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-12-21 22:01:46 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-12-21 22:01:46 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-12-21 22:01:45 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-12-21 22:01:45 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-12-21 22:01:45 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-12-21 22:01:45 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-12-21 22:01:45 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-12-21 22:01:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-12-21 22:01:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-12-21 22:01:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-12-21 22:01:44 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-12-21 22:01:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-12-21 22:01:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-12-21 22:01:43 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-12-21 22:01:43 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-12-21 22:01:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-12-21 22:01:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-12-21 22:01:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-12-21 22:01:42 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-12-21 22:01:42 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-12-21 22:01:42 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-12-21 22:01:41 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-12-21 22:01:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-12-21 22:01:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-12-21 22:01:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-12-21 22:01:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-12-21 22:01:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-12-21 22:01:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-12-21 22:01:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-12-21 22:01:38 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-12-21 22:01:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-12-21 22:01:37 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-12-21 22:01:36 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-12-21 22:01:36 ----A---- C:\Windows\system32\apisetschema.dll
2013-12-21 22:01:18 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-12-21 22:01:18 ----A---- C:\Windows\system32\cryptsvc.dll
2013-12-21 22:01:18 ----A---- C:\Windows\system32\cryptnet.dll
2013-12-21 22:01:18 ----A---- C:\Windows\system32\crypt32.dll
2013-12-21 22:01:17 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-12-21 22:01:17 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-12-21 22:00:54 ----A---- C:\Windows\system32\consent.exe
2013-12-21 22:00:54 ----A---- C:\Windows\system32\appinfo.dll
2013-12-21 22:00:42 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-12-21 22:00:42 ----A---- C:\Windows\system32\schannel.dll
2013-12-21 22:00:42 ----A---- C:\Windows\system32\lsasrv.dll
2013-12-21 22:00:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-12-21 22:00:42 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-12-21 22:00:42 ----A---- C:\Windows\system32\drivers\cng.sys
2013-12-21 22:00:41 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-12-21 22:00:41 ----A---- C:\Windows\system32\sspicli.dll
2013-12-21 22:00:40 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-12-21 22:00:40 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-12-21 22:00:40 ----A---- C:\Windows\system32\sspisrv.dll
2013-12-21 22:00:40 ----A---- C:\Windows\system32\secur32.dll
2013-12-21 22:00:40 ----A---- C:\Windows\system32\ncrypt.dll
2013-12-21 22:00:40 ----A---- C:\Windows\system32\lsass.exe
2013-12-21 22:00:36 ----A---- C:\Windows\system32\wintrust.dll
2013-12-21 22:00:35 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-12-21 22:00:22 ----A---- C:\Windows\system32\shell32.dll
2013-12-21 22:00:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2013-12-21 22:00:20 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2013-12-21 22:00:20 ----A---- C:\Windows\system32\shdocvw.dll
2013-12-21 22:00:16 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-21 22:00:16 ----A---- C:\Windows\system32\wscript.exe
2013-12-21 22:00:16 ----A---- C:\Windows\system32\scrrun.dll
2013-12-21 22:00:16 ----A---- C:\Windows\system32\cscript.exe
2013-12-21 22:00:15 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-21 22:00:15 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-21 22:00:01 ----A---- C:\Windows\system32\drivers\usbscan.sys
2013-12-21 22:00:01 ----A---- C:\Windows\system32\drivers\hidparse.sys
2013-12-21 22:00:01 ----A---- C:\Windows\system32\drivers\hidclass.sys
2013-12-21 22:00:00 ----A---- C:\Windows\system32\win32k.sys
2013-12-21 21:59:57 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-21 21:59:57 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-21 21:59:51 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2013-12-21 21:59:51 ----A---- C:\Windows\system32\drivers\usbcir.sys
2013-12-21 21:59:50 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-12-21 21:59:49 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2013-12-21 21:59:48 ----A---- C:\Windows\system32\rpcrt4.dll
2013-12-21 21:59:47 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2013-12-21 21:59:46 ----A---- C:\Windows\system32\win32spl.dll
2013-12-21 21:59:45 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-12-21 21:59:43 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-12-21 21:59:37 ----A---- C:\Windows\system32\comctl32.dll
2013-12-21 21:59:36 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2013-12-21 21:59:35 ----A---- C:\Windows\system32\drivers\afd.sys
2013-12-21 21:59:34 ----A---- C:\Windows\system32\qedit.dll
2013-12-21 21:59:33 ----A---- C:\Windows\SYSWOW64\qedit.dll
2013-12-21 21:59:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-12-21 21:59:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-12-21 21:59:29 ----A---- C:\Windows\system32\cdd.dll
2013-12-21 21:59:28 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-12-21 21:59:28 ----A---- C:\Windows\system32\lpk.dll
2013-12-21 21:59:28 ----A---- C:\Windows\system32\dciman32.dll
2013-12-21 21:59:28 ----A---- C:\Windows\system32\atmfd.dll
2013-12-21 21:59:27 ----A---- C:\Windows\SYSWOW64\lpk.dll
2013-12-21 21:59:27 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2013-12-21 21:59:27 ----A---- C:\Windows\system32\fontsub.dll
2013-12-21 21:59:26 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2013-12-21 21:59:26 ----A---- C:\Windows\system32\atmlib.dll
2013-12-21 21:59:25 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-12-21 21:59:18 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-12-21 21:59:18 ----A---- C:\Windows\system32\gdi32.dll
2013-12-21 21:59:15 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-21 21:59:15 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-21 21:59:09 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-12-21 21:59:09 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-12-21 21:59:08 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-12-21 21:59:05 ----A---- C:\Windows\system32\taskhost.exe
2013-12-21 21:44:50 ----A---- C:\Windows\system32\nshwfp.dll
2013-12-21 21:44:50 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-12-21 21:44:50 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-12-21 21:44:49 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-12-21 21:44:49 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-12-21 17:58:58 ----A---- C:\Windows\system32\Wdfres.dll
2013-12-21 17:58:58 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2013-12-21 17:55:16 ----A---- C:\Windows\system32\CNMLMAT.DLL
2013-12-21 17:45:38 ----D---- C:\Windows\system32\SPReview
2013-12-21 17:45:03 ----D---- C:\Windows\system32\EventProviders
2013-12-21 17:42:41 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2013-12-21 17:42:41 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2013-12-21 17:42:34 ----A---- C:\Windows\system32\WUDFSvc.dll
2013-12-21 17:42:34 ----A---- C:\Windows\system32\WUDFPlatform.dll
2013-12-21 17:42:22 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2013-12-21 17:42:21 ----A---- C:\Windows\system32\WUDFx.dll
2013-12-21 17:42:21 ----A---- C:\Windows\system32\WUDFHost.exe
2013-12-21 17:37:18 ----D---- C:\Windows\system32\MRT
2013-12-21 17:37:16 ----A---- C:\Windows\system32\MRT.exe
2013-12-21 17:19:48 ----A---- C:\Windows\system32\netfxperf.dll
2013-12-21 17:19:48 ----A---- C:\Windows\system32\dfshim.dll
2013-12-21 17:19:41 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2013-12-21 17:19:29 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2013-12-21 17:19:29 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2013-12-21 17:19:29 ----A---- C:\Windows\system32\sysmain.dll
2013-12-21 17:19:28 ----A---- C:\Windows\system32\tssrvlic.dll
2013-12-21 17:19:28 ----A---- C:\Windows\system32\RDVGHelper.exe
2013-12-21 17:19:27 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2013-12-21 17:19:26 ----A---- C:\Windows\system32\MSVidCtl.dll
2013-12-21 17:19:25 ----A---- C:\Windows\system32\tquery.dll
2013-12-21 17:19:23 ----A---- C:\Windows\system32\mssrch.dll
2013-12-21 17:19:22 ----A---- C:\Windows\system32\mscoree.dll
2013-12-21 17:19:22 ----A---- C:\Windows\system32\mmcndmgr.dll
2013-12-21 17:19:21 ----A---- C:\Windows\system32\secproc_isv.dll
2013-12-21 17:19:21 ----A---- C:\Windows\system32\mf.dll
2013-12-21 17:19:20 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2013-12-21 17:19:20 ----A---- C:\Windows\system32\xpsservices.dll
2013-12-21 17:19:20 ----A---- C:\Windows\system32\secproc.dll
2013-12-21 17:19:20 ----A---- C:\Windows\system32\RMActivate_isv.exe
2013-12-21 17:19:20 ----A---- C:\Windows\system32\RMActivate.exe
2013-12-21 17:19:18 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2013-12-21 17:19:17 ----A---- C:\Windows\SYSWOW64\secproc.dll
2013-12-21 17:19:16 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2013-12-21 17:19:15 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2013-12-21 17:19:15 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2013-12-21 17:19:15 ----A---- C:\Windows\system32\schedsvc.dll
2013-12-21 17:19:15 ----A---- C:\Windows\system32\ole32.dll
2013-12-21 17:19:12 ----A---- C:\Windows\system32\spwizui.dll
2013-12-21 17:19:11 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2013-12-21 17:19:11 ----A---- C:\Windows\system32\taskschd.dll
2013-12-21 17:19:11 ----A---- C:\Windows\system32\RacEngn.dll
2013-12-21 17:19:10 ----A---- C:\Windows\SYSWOW64\mf.dll
2013-12-21 17:19:10 ----A---- C:\Windows\system32\wevtsvc.dll
2013-12-21 17:19:10 ----A---- C:\Windows\system32\ExplorerFrame.dll
2013-12-21 17:19:10 ----A---- C:\Windows\system32\diagperf.dll
2013-12-21 17:19:09 ----A---- C:\Windows\system32\vssapi.dll
2013-12-21 17:19:08 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2013-12-21 17:19:08 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2013-12-21 17:19:08 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2013-12-21 17:19:07 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2013-12-21 17:19:07 ----A---- C:\Windows\system32\UIRibbon.dll
2013-12-21 17:19:07 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2013-12-21 17:19:06 ----A---- C:\Windows\explorer.exe
2013-12-21 17:19:05 ----A---- C:\Windows\system32\WsmSvc.dll
2013-12-21 17:19:04 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2013-12-21 17:19:04 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2013-12-21 17:19:04 ----A---- C:\Windows\system32\WMVCORE.DLL
2013-12-21 17:19:04 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2013-12-21 17:19:04 ----A---- C:\Windows\system32\PresentationHost.exe
2013-12-21 17:19:03 ----A---- C:\Windows\system32\rdpdd.dll
2013-12-21 17:19:02 ----A---- C:\Windows\system32\WinSAT.exe
2013-12-21 17:19:02 ----A---- C:\Windows\system32\spreview.exe
2013-12-21 17:19:02 ----A---- C:\Windows\system32\spinstall.exe
2013-12-21 17:19:02 ----A---- C:\Windows\system32\MPSSVC.dll
2013-12-21 17:19:02 ----A---- C:\Windows\system32\CertEnroll.dll
2013-12-21 17:19:01 ----A---- C:\Windows\SYSWOW64\tquery.dll
2013-12-21 17:19:00 ----A---- C:\Windows\system32\d3d9.dll
2013-12-21 17:18:59 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2013-12-21 17:18:59 ----A---- C:\Windows\system32\SearchFolder.dll
2013-12-21 17:18:58 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2013-12-21 17:18:57 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2013-12-21 17:18:57 ----A---- C:\Windows\system32\VSSVC.exe
2013-12-21 17:18:57 ----A---- C:\Windows\system32\gpsvc.dll
2013-12-21 17:18:57 ----A---- C:\Windows\system32\dwmcore.dll
2013-12-21 17:18:57 ----A---- C:\Windows\system32\dbgeng.dll
2013-12-21 17:18:56 ----A---- C:\Windows\system32\drivers\http.sys
2013-12-21 17:18:54 ----A---- C:\Windows\SYSWOW64\rdvgumd32.dll
2013-12-21 17:18:52 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2013-12-21 17:18:51 ----A---- C:\Windows\SYSWOW64\ole32.dll
2013-12-21 17:18:51 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-12-21 17:18:51 ----A---- C:\Windows\system32\qmgr.dll
2013-12-21 17:18:51 ----A---- C:\Windows\system32\audiosrv.dll
2013-12-21 17:18:51 ----A---- C:\Windows\system32\actxprxy.dll
2013-12-21 17:18:50 ----A---- C:\Windows\system32\termsrv.dll
2013-12-21 17:18:50 ----A---- C:\Windows\system32\gpprefcl.dll
2013-12-21 17:18:49 ----A---- C:\Windows\system32\netlogon.dll
2013-12-21 17:18:49 ----A---- C:\Windows\system32\imapi2fs.dll
2013-12-21 17:18:48 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2013-12-21 17:18:48 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2013-12-21 17:18:48 ----A---- C:\Windows\system32\winhttp.dll
2013-12-21 17:18:47 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2013-12-21 17:18:47 ----A---- C:\Windows\SYSWOW64\explorer.exe
2013-12-21 17:18:47 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2013-12-21 17:18:47 ----A---- C:\Windows\system32\wbengine.exe
2013-12-21 17:18:47 ----A---- C:\Windows\system32\setupapi.dll
2013-12-21 17:18:47 ----A---- C:\Windows\system32\rpcss.dll
2013-12-21 17:18:47 ----A---- C:\Windows\system32\QAGENTRT.DLL
2013-12-21 17:18:47 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2013-12-21 17:18:47 ----A---- C:\Windows\system32\propsys.dll
2013-12-21 17:18:47 ----A---- C:\Windows\system32\msv1_0.dll
2013-12-21 17:18:46 ----A---- C:\Windows\system32\werconcpl.dll
2013-12-21 17:18:46 ----A---- C:\Windows\system32\taskeng.exe
2013-12-21 17:18:46 ----A---- C:\Windows\system32\odbc32.dll
2013-12-21 17:18:45 ----A---- C:\Windows\system32\user32.dll
2013-12-21 17:18:44 ----A---- C:\Windows\system32\WSDApi.dll
2013-12-21 17:18:44 ----A---- C:\Windows\system32\umrdp.dll
2013-12-21 17:18:44 ----A---- C:\Windows\system32\LSCSHostPolicy.dll
2013-12-21 17:18:44 ----A---- C:\Windows\system32\drivers\tdx.sys
2013-12-21 17:18:44 ----A---- C:\Windows\system32\dhcpcore.dll
2013-12-21 17:18:44 ----A---- C:\Windows\system32\certmgr.dll
2013-12-21 17:18:42 ----A---- C:\Windows\SYSWOW64\wer.dll
2013-12-21 17:18:42 ----A---- C:\Windows\system32\drivers\netbt.sys
2013-12-21 17:18:41 ----A---- C:\Windows\SYSWOW64\certcli.dll
2013-12-21 17:18:41 ----A---- C:\Windows\system32\tsmf.dll
2013-12-21 17:18:41 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2013-12-21 17:18:40 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2013-12-21 17:18:40 ----A---- C:\Windows\system32\shlwapi.dll
2013-12-21 17:18:40 ----A---- C:\Windows\system32\netshell.dll
2013-12-21 17:18:40 ----A---- C:\Windows\system32\msdtctm.dll
2013-12-21 17:18:40 ----A---- C:\Windows\system32\msdrm.dll
2013-12-21 17:18:40 ----A---- C:\Windows\system32\framedynos.dll
2013-12-21 17:18:39 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2013-12-21 17:18:39 ----A---- C:\Windows\system32\rdpshell.exe
2013-12-21 17:18:38 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2013-12-21 17:18:38 ----A---- C:\Windows\system32\wmicmiplugin.dll
2013-12-21 17:18:37 ----A---- C:\Windows\system32\ws2_32.dll
2013-12-21 17:18:37 ----A---- C:\Windows\system32\winlogon.exe
2013-12-21 17:18:37 ----A---- C:\Windows\system32\netcfgx.dll
2013-12-21 17:18:37 ----A---- C:\Windows\system32\appmgr.dll
2013-12-21 17:18:36 ----A---- C:\Windows\system32\wmpps.dll
2013-12-21 17:18:36 ----A---- C:\Windows\system32\lsm.exe
2013-12-21 17:18:36 ----A---- C:\Windows\system32\drivers\csc.sys
2013-12-21 17:18:36 ----A---- C:\Windows\system32\comdlg32.dll
2013-12-21 17:18:36 ----A---- C:\Windows\system32\apphelp.dll
2013-12-21 17:18:35 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-12-21 17:18:35 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2013-12-21 17:18:35 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2013-12-21 17:18:35 ----A---- C:\Windows\system32\Query.dll
2013-12-21 17:18:35 ----A---- C:\Windows\system32\drvstore.dll
2013-12-21 17:18:34 ----A---- C:\Windows\system32\wpdshext.dll
2013-12-21 17:18:34 ----A---- C:\Windows\system32\azroles.dll
2013-12-21 17:18:33 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2013-12-21 17:18:33 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2013-12-21 17:18:33 ----A---- C:\Windows\SYSWOW64\printmanagement.msc
2013-12-21 17:18:33 ----A---- C:\Windows\system32\QAGENT.DLL
2013-12-21 17:18:33 ----A---- C:\Windows\system32\BFE.DLL
2013-12-21 17:18:32 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2013-12-21 17:18:32 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2013-12-21 17:18:32 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2013-12-21 17:18:32 ----A---- C:\Windows\system32\Vault.dll
2013-12-21 17:18:32 ----A---- C:\Windows\system32\samsrv.dll
2013-12-21 17:18:32 ----A---- C:\Windows\system32\lpksetup.exe
2013-12-21 17:18:32 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2013-12-21 17:18:32 ----A---- C:\Windows\system32\cmd.exe
2013-12-21 17:18:31 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2013-12-21 17:18:31 ----A---- C:\Windows\system32\mssvp.dll
2013-12-21 17:18:31 ----A---- C:\Windows\system32\cscsvc.dll
2013-12-21 17:18:30 ----A---- C:\Windows\system32\rdpclip.exe
2013-12-21 17:18:29 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2013-12-21 17:18:28 ----A---- C:\Windows\system32\sxs.dll
2013-12-21 17:18:28 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2013-12-21 17:18:27 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2013-12-21 17:18:27 ----A---- C:\Windows\SYSWOW64\Query.dll
2013-12-21 17:18:27 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2013-12-21 17:18:27 ----A---- C:\Windows\system32\Wldap32.dll
2013-12-21 17:18:27 ----A---- C:\Windows\system32\taskcomp.dll
2013-12-21 17:18:27 ----A---- C:\Windows\system32\mfds.dll
2013-12-21 17:18:27 ----A---- C:\Windows\system32\mcbuilder.exe
2013-12-21 17:18:27 ----A---- C:\Windows\system32\cscobj.dll
2013-12-21 17:18:26 ----A---- C:\Windows\SYSWOW64\upnp.dll
2013-12-21 17:18:26 ----A---- C:\Windows\system32\pnidui.dll
2013-12-21 17:18:26 ----A---- C:\Windows\system32\ipsmsnap.dll
2013-12-21 17:18:25 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2013-12-21 17:18:25 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2013-12-21 17:18:25 ----A---- C:\Windows\system32\webservices.dll
2013-12-21 17:18:25 ----A---- C:\Windows\system32\rdpendp.dll
2013-12-21 17:18:25 ----A---- C:\Windows\system32\hgprint.dll
2013-12-21 17:18:24 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2013-12-21 17:18:24 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2013-12-21 17:18:24 ----A---- C:\Windows\system32\SessEnv.dll
2013-12-21 17:18:23 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2013-12-21 17:18:23 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2013-12-21 17:18:22 ----A---- C:\Windows\system32\winsta.dll
2013-12-21 17:18:21 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2013-12-21 17:18:21 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2013-12-21 17:18:21 ----A---- C:\Windows\system32\sqlsrv32.dll
2013-12-21 17:18:21 ----A---- C:\Windows\system32\fveapi.dll
2013-12-21 17:18:21 ----A---- C:\Windows\system32\dot3api.dll
2013-12-21 17:18:20 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2013-12-21 17:18:20 ----A---- C:\Windows\system32\drivers\volsnap.sys
2013-12-21 17:18:20 ----A---- C:\Windows\system32\drivers\msrpc.sys
2013-12-21 17:18:19 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2013-12-21 17:18:19 ----A---- C:\Windows\system32\prncache.dll
2013-12-21 17:18:19 ----A---- C:\Windows\system32\mcmde.dll
2013-12-21 17:18:18 ----A---- C:\Windows\SYSWOW64\userenv.dll
2013-12-21 17:18:18 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2013-12-21 17:18:18 ----A---- C:\Windows\system32\WMNetMgr.dll
2013-12-21 17:18:18 ----A---- C:\Windows\system32\wlanpref.dll
2013-12-21 17:18:18 ----A---- C:\Windows\system32\schtasks.exe
2013-12-21 17:18:17 ----A---- C:\Windows\system32\vpnike.dll
2013-12-21 17:18:17 ----A---- C:\Windows\system32\userenv.dll
2013-12-21 17:18:17 ----A---- C:\Windows\system32\drivers\rdbss.sys
2013-12-21 17:18:16 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2013-12-21 17:18:16 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2013-12-21 17:18:15 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2013-12-21 17:18:15 ----A---- C:\Windows\system32\tspubwmi.dll
2013-12-21 17:18:15 ----A---- C:\Windows\system32\photowiz.dll
2013-12-21 17:18:15 ----A---- C:\Windows\system32\evr.dll
2013-12-21 17:18:15 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2013-12-21 17:18:14 ----A---- C:\Windows\system32\wmpmde.dll
2013-12-21 17:18:14 ----A---- C:\Windows\system32\IPSECSVC.DLL
2013-12-21 17:18:14 ----A---- C:\Windows\system32\FXSSVC.exe
2013-12-21 17:18:14 ----A---- C:\Windows\system32\framedyn.dll
2013-12-21 17:18:14 ----A---- C:\Windows\system32\AudioSes.dll
2013-12-21 17:18:14 ----A---- C:\Windows\system32\aepdu.dll
2013-12-21 17:18:13 ----A---- C:\Windows\SYSWOW64\cmd.exe
2013-12-21 17:18:13 ----A---- C:\Windows\system32\WMPEncEn.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\wmpeffects.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\tscfgwmi.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\SyncCenter.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\srvsvc.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\sppobjs.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\shsvcs.dll
2013-12-21 17:18:13 ----A---- C:\Windows\system32\rdpinit.exe
2013-12-21 17:18:13 ----A---- C:\Windows\system32\mfreadwrite.dll
2013-12-21 17:18:12 ----A---- C:\Windows\system32\vmicsvc.exe
2013-12-21 17:18:12 ----A---- C:\Windows\system32\fde.dll
2013-12-21 17:18:12 ----A---- C:\Windows\system32\aeinv.dll
2013-12-21 17:18:11 ----A---- C:\Windows\SYSWOW64\propsys.dll
2013-12-21 17:18:11 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2013-12-21 17:18:11 ----A---- C:\Windows\system32\WinSATAPI.dll
2013-12-21 17:18:10 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2013-12-21 17:18:10 ----A---- C:\Windows\SYSWOW64\mfds.dll
2013-12-21 17:18:10 ----A---- C:\Windows\system32\stobject.dll
2013-12-21 17:18:10 ----A---- C:\Windows\system32\netdiagfx.dll
2013-12-21 17:18:10 ----A---- C:\Windows\system32\localsec.dll
2013-12-21 17:18:10 ----A---- C:\Windows\system32\imapi2.dll
2013-12-21 17:18:10 ----A---- C:\Windows\system32\bcryptprimitives.dll
2013-12-21 17:18:09 ----A---- C:\Windows\SYSWOW64\user32.dll
2013-12-21 17:18:09 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2013-12-21 17:18:09 ----A---- C:\Windows\system32\netid.dll
2013-12-21 17:18:09 ----A---- C:\Windows\system32\inetpp.dll
2013-12-21 17:18:09 ----A---- C:\Windows\system32\drivers\vmbus.sys
2013-12-21 17:18:09 ----A---- C:\Windows\system32\drivers\udfs.sys
2013-12-21 17:18:09 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2013-12-21 17:18:08 ----A---- C:\Windows\system32\tcpipcfg.dll
2013-12-21 17:18:08 ----A---- C:\Windows\system32\spp.dll
2013-12-21 17:18:08 ----A---- C:\Windows\system32\QSHVHOST.DLL
2013-12-21 17:18:07 ----A---- C:\Windows\SYSWOW64\azroles.dll
2013-12-21 17:18:07 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2013-12-21 17:18:07 ----A---- C:\Windows\system32\cscui.dll
2013-12-21 17:18:07 ----A---- C:\Windows\system32\biocpl.dll
2013-12-21 17:18:06 ----A---- C:\Windows\system32\scansetting.dll
2013-12-21 17:18:06 ----A---- C:\Windows\system32\printui.dll
2013-12-21 17:18:06 ----A---- C:\Windows\system32\mspbda.dll
2013-12-21 17:18:06 ----A---- C:\Windows\system32\msinfo32.exe
2013-12-21 17:18:05 ----A---- C:\Windows\SYSWOW64\themeui.dll
2013-12-21 17:18:05 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2013-12-21 17:18:05 ----A---- C:\Windows\system32\pla.dll
2013-12-21 17:18:05 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2013-12-21 17:18:04 ----A---- C:\Windows\SYSWOW64\spp.dll
2013-12-21 17:18:04 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2013-12-21 17:18:03 ----A---- C:\Windows\system32\wusa.exe
2013-12-21 17:18:03 ----A---- C:\Windows\system32\msdri.dll
2013-12-21 17:18:03 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2013-12-21 17:18:03 ----A---- C:\Windows\system32\aitagent.exe
2013-12-21 17:18:02 ----A---- C:\Windows\system32\wiaservc.dll
2013-12-21 17:18:02 ----A---- C:\Windows\system32\vds.exe
2013-12-21 17:18:02 ----A---- C:\Windows\system32\drivers\pci.sys
2013-12-21 17:18:02 ----A---- C:\Windows\system32\AdmTmpl.dll
2013-12-21 17:18:01 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2013-12-21 17:18:01 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2013-12-21 17:18:01 ----A---- C:\Windows\system32\rpchttp.dll
2013-12-21 17:18:01 ----A---- C:\Windows\system32\mscms.dll
2013-12-21 17:18:00 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2013-12-21 17:18:00 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2013-12-21 17:18:00 ----A---- C:\Windows\system32\PkgMgr.exe
2013-12-21 17:18:00 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2013-12-21 17:18:00 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2013-12-21 17:17:59 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2013-12-21 17:17:59 ----A---- C:\Windows\SYSWOW64\evr.dll
2013-12-21 17:17:59 ----A---- C:\Windows\system32\XpsRasterService.dll
2013-12-21 17:17:59 ----A---- C:\Windows\system32\wisptis.exe
2013-12-21 17:17:59 ----A---- C:\Windows\system32\ocsetup.exe
2013-12-21 17:17:58 ----A---- C:\Windows\system32\sppwinob.dll
2013-12-21 17:17:57 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2013-12-21 17:17:57 ----A---- C:\Windows\SYSWOW64\calc.exe
2013-12-21 17:17:57 ----A---- C:\Windows\system32\ocsetapi.dll
2013-12-21 17:17:57 ----A---- C:\Windows\system32\DXP.dll
2013-12-21 17:17:57 ----A---- C:\Windows\system32\drivers\volmgr.sys
2013-12-21 17:17:56 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2013-12-21 17:17:56 ----A---- C:\Windows\system32\wpdbusenum.dll
2013-12-21 17:17:56 ----A---- C:\Windows\system32\eapp3hst.dll
2013-12-21 17:17:56 ----A---- C:\Windows\system32\drivers\msdsm.sys
2013-12-21 17:17:56 ----A---- C:\Windows\system32\ci.dll