Nejake hrozby v avaste
Napsal: 19 zář 2014 00:43
Logfile of random's system information tool 1.10 (written by random/random)
Run by Feri at 2014-09-19 01:38:50
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 272 GB (60%) free of 455 GB
Total RAM: 3894 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:38:58, on 19. 9. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\Users\Feri\Downloads\CoreTemp32\Core Temp.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\Feri\AppData\Local\Temp\Install_18638\delay.exe
C:\Program Files\trend micro\Feri.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: 2657e500f3e90131a4e91fb939dcadf40061913 - {11111111-1111-1111-1111-110611191113} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: HP SimplePass Identity Protection Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\dpotspluginie8.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: WinToFlash Suggestor - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - (no file)
O9 - Extra 'Tools' menuitem: WinToFlash Suggestor options - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - (no file)
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Documention Flash Card Detection Service (hpdoccardsvc) - Hewlett-Packard Developement Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\doccardsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10854 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\vcsFPService.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"C:\Program Files\DigitalPersona\Bin\DpHostW.exe"
"taskhost.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
taskeng.exe {78539D4B-C035-41CC-8BFA-618FCF96985B}
"C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" /background
"C:\Users\Feri\Downloads\CoreTemp32\Core Temp.exe"
"C:\Program Files\Hewlett-Packard\HPToneControl\HPToneCtl.exe"
"C:\Program Files\Java\jre6\bin\jusched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files\DigitalPersona\Bin\DPAgent.exe"
"C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
HydraDM64.exe -h:65992 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe" KMPProcess
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Bluetooth®: Disabled
WLAN: Disabled</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_off.ico</IconPath><ID>1552689904</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
C:\Users\Feri\AppData\Local\Temp\Install_18638\delay.exe /S /MAG=smtycdelay /PIXGUID=3029b78f-ab04-42c9-809e-225120539caa
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"taskhost.exe"
/QuitInfo:000000000000075C;00000000000005BC;
"C:\Users\Feri\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\6563fb0e-3562-4199-a0a7-ee44667f7754-11.job - C:\Program Files (x86)\Senses\6563fb0e-3562-4199-a0a7-ee44667f7754-11.exe /rawdata=cPxZ4xyXv3AZZtOLhG1WgwfbkjTNnTdzAl+R4/JNnKz7AXSKaR8Z4KvJHdCEV8wVN3m0pZwHM19adBdeMG6l4LkpTe85+F9IKExrMROi6nlNDYXuTNIveBm5OpiinEvjKoFkOn0cvr2coCvEYI4swexBdisE1STgr0Gy0oxEnxhPEFyTQ8lW232CqeG0nBj5TVj1c4+j1TIT+/UGAACRBjNdBMOOLn3GGtdyo7D2JbOGciar22utFz4xFCrcPp25KJJAmjVi0xBA5tecQJdWYzS/F2szCS9+jgaHgnBOsIEtuq1bMvOt/CPtj6Xf61ZWgBx1aqt8x5MZOEhnOHSjQiI8DzhCwA4AtR0vSOqNqVUTHTamlyoXW/Zi13W8jZiPsROHqdyfZ7o13c761edd5SjMXywH1it3c//+RiMbKVjwZ+9fHw5w/aKTN4M+rLbzH0EoYdYpkg9OUOSfuAlHg/LxGw3W/UJDbF8iaY4uBCRAUUfPSoZfUKCSP7b3fGlQxaqRyL8IX0KzAWRRyTfoyaSQYcQebUyqWJnnqHNjhDnECNSoOLl52+lvvKMlMlH99k3iBGn0Uq/C/XfnFJ0rUwTObtRjaz4eJjha3d0rSoHlkY0Xi5bZAb01pOGKLQ88E3YIMn1JKG2pqSIxgdyOFo3XVxjk8mubJl8DUDqpdwuku2KUtTj0DFVYYfugaJRpBfLdP0kFMLcPrwKQXBid59Zj0jK0V2BVDjKdJ+LqwjDPChcv8z+yIPZRlnedQD2UwFY9VMGyajgl2ny9CKUnV9iScACjK0TSW1CHoKHdigu0L3U2/wkNslJ+rTINFEKf650zIovVsVVz4PG48IQt8mFpxnArtKnNOfL/Fi6afiuAcnv1gisGPh/A2UzOB1u41o5aKXU4GN+qr7We6efkaL5pxJXONhVPYW17oJmq87mYcFZavrH+ElXKLubWi9vHjWqP9yRRzuw8v8qWvU3QZxF/SpNFNXgegD/9RkoeSCnear0MwzkQ47W+AbpQ6CqvvfU4q8GLNdWgF82LrstLM1XhaV3XNxHMOWuMKgHCF4xm80FVnewqDdDBF250iz0gDEcpwJ4Ss01BQsLM1M7Iu+oFC3Lw7vKlDmDzt75WtmHUiGfeLwuilsoYLjUtg79+BQNim5+N137WxeHXrm+mRfgIyMocdVeCVAxu+HHL4I2A8YBqiHheGiT6aQw8+l2+ea8RuqniPD3N6PwB6+PLCP+wGMk0+X706rwzT9snR+3yFDjhuSATxK84yXFxsilWnpazC7kBd/JtF2eVXjzqI4oC9FOQkP5jzlzxZ9Ja+2NoXnDNNFq6uqyNM8CSR07GrD6yqR4cty3UZ8QaIoGeo4BcDKX2+TOyg+ffktUT5RuHdTtwhrJo5Xjn5vXF7AYoiwygbqVg3to5hOprTUUI1a1VIbx6xVPHp2IJRcyHjEELOWZ9NJ036IjLp27AmG8pxd9gCJPsjNXvfB7TG9Y7MB6C4CP2ZyU4If1wypQIicIomKV/QSvitSdxLL5hgGg3oJzuDSMtzEqHyFl04ZnnKrHtsY/7m4LVIJ1z8YZznNskdgbgP/hp757hHs2rHDln1VZC/kQwH7CIboAl2AOklph8KI849ZhDPtlN+rXKA5x+7iJsHwVhQ4TREwJe4YV0RhflR7G6ANqmag+jQfe15KQbvfOBlb3r13EsYtqTTSxepaHXjnlRV6wl5p/kdpMXP2aHQwHWHHtJ1jiQnzgQ/FxyM0vy6+Ip6qySHGgoBrr87GGj1oziaT1SJZBrZyJUSYqQ5hDcwtfyWZpExQ/hOR9nvbypSSXxcX9H/a00xuCcIDmm6PicORFK+9Sg864N5XRZvWvGNqB5Kxv5Mo3ITYLcCzQvJyMgqlUloQXA7gEyqd6lStgrpJPU7Pv5nn7+n8cODAo+LuVwq6OQvG2Qe3KRLgjPZUp5NctKa6XRtItwvA4w+rbAqtK64rcw2GSRkdrY2FrNBy/4k89RWHlKGfyKeHt4nkomz1aU7pVhqJBxWgI2poc/C7yG+AoBtZP7OSsucMVjCaQBBInpivUjqm7xsBQZlKfPvci3uWVSZSoE9SrZHKJMVg/Kck2I5t6UTDIUY4zJdK1LkFwJQeP83utzc+yr8sjGTs/ynC9vcr+/kdOt3LBsVMGGJUUY+LhMjVE1YSBAfxr9P69Z7PoMMdxl89kQAt/eQe+vvHWfttc=
C:\Windows\tasks\6563fb0e-3562-4199-a0a7-ee44667f7754-3.job - C:\Program Files (x86)\Senses\6563fb0e-3562-4199-a0a7-ee44667f7754-3.exe /rawdata=KobGJht2gTYWhzOxKEtHXc1Jrh83/ltFmpXHEBdiyFFmT55kK95U1XfEuBUutNw5JYqgMJDZ5zKGBmvkI5c9d68S8H1sv7AfdQ1/4XLYJLnRZoOFPdBsG0j7yHNuvksyqmBnDB4dKtf10exmNY/i+tgoT5sNCj7nT+bsJVQZ6OsW4a1SZzN/uRFgVgM9EG5i4F+aQbX3H2XGuo6bKeEQYLnBNIB3kVFc3DbiLKRwcIsQHmF1NeyUMX6s1u76S9JRIK0g48m9N5b9N1oWe9lx55gLiQDiX77gxZwN4HaWEMbQmSCPrvybge9bxZIk5KesiWpW1+MHDNUAmp598LBEZKPkFj6wm5WN8pauhE3zVFChTMH4kOJVmqOgbAYLsu2x27ZfGbiU0HDoZ5B4AVQvvJAGtN98kTTxFa4dBk9hQ1Fol4mCv5Eie5ghcXYkvdRugX5cSz8dnz2Jd5eFxyKu9Lv3Vl+Jmkcupaag7vFaK2KUQ15BmfuKMGrv+jyjaLiifqVMw66/YcDNJOO+3QLrntZH89vuVKXVx/7c1gdGuoa28QDNNXte/z0e/UiJ585oPmEDPEsGp2XVkFsHBMc4/NJpDIALv00wJgZ0r1+5VEE/VQTIUliHDiArDdmYY0acRG4y/qWs7yMJEKzWAgnlahE4sDfib+vORUPsjkuEHfO2MyZfADUdey3kEaJUACZNxhjXGanR/c/788xoxriA7k7Xmz+Jjb2DgbWamkC+nTGLyR6KiQ/pdrg/vZT8KkTKqnmvJxbteUr4XGDTWgji91DCdq8/3ZwHvSwLMC6gpSThE7YSRNmoHbt8hvjjxaU2KhAHFSlAzChR1lO/NjEGRIcqbfXfokHtApORGC2adjF2jVnxO7Ovwm+PBprutdJyHCgNxkMVWXxso8ohKXG/K/Dee4hMAijhs6CxjB2ryDOyyvo9qjN4A8bNZjKDPhkLOFYw5UBIYesuBMptfMyyEEghREhVLICE+wryx5lXPU1qsOG70sNFY7FVyoQj6MQMWdJ2O1BDSihjTskm8z/IySu8WVVCLZ5VxxTo8/s3FzaP2/tSRBHYy3k2fR4blXtll8Q5OLbwwyiwHFIR8phJ/EsvTIS00EG0AFfNNIXhOjYGjDqDRP6u0LLspj/WPZ1Tf5i8K/+4YvbsR0HWc0wkx8Rb6CExcmlHR/gao3yRCTSG6W1RMEvQcp7PLtO99pa/zQeRnahM4KVGwkK5uCu4GAbXIaKtvDAw/8Ig5yHovMZoUiUAJDoGtL1I3AaT5ePHMKqpuwVld20PnxuZefYl1rL4NRhlJWk+ycdHhygJHK0VVctH5BBsOpbbIEBlyXp82uqadZy7wYO1XtEV2K4THA==
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /rawdata=hb2JFSOlZimKckdaPFosDzlwxkLwGPKkF5nob7XzDDHC0XXA/12a5pLU0P9KCJAgxbSOtGglRqIfkWMcHXtbAc2VRXU7sl35U5/ixQXuiDyRJZOvlgZ6xPPoeD2JTQNbyu6VroVXPLPAGg17Iolr/6InyV0Wx1vQDmfQFrgxVE7ExE2NN4xiksmXJ0CONt6K44FFOk1RXlmh25A+HBknM5ZYXmxEDW0MUnNUbPZ9HTSpfJKQ0bEhgezBuARRxduuLixmjNG66Z4xmH1kiga26d2tetqCqLI+2sZ72Lr6hoJO/1MeRhamn0NHaI9cbWXa8m8sOWtVXLZ3bxAVnGJ4JyXG3nbMdyG+LHOy413PMLM+axUihQ++dgZe+tQhowrt3RTx/6KyfcH8LHh4dhIMDvdcnWE6m5cZRnQBnBu6WVYRRHTO4av5Lzeu10urLnDYFphMDa6LZxfaE73pWlQB+xlajlIO09IPrl/TFCDNY0YzgLw4wEVi6d5FBLoTASSTsGDjPRc/ECqImEoz4MXuVOq9er0VlzmWfu1Vgbe50HR5Hzi6sShby/wZ0yMy4Kf0dfkfdY//9xsz+Mf/X2qySnLA7iJ2XsiyC92khE4W73gR4WPdqJs8v5LPopu8nk2FKYKn7yhlfc2S4icq/hqQcvdtxcDhEf8JwEhUzQwjUBJfH+H6N+N9kt5kCNFAdjCJjhpoQ2MDHYnHmS+OvmQqV7jbxQS9uUIJltU0ZwcxV49YAmXMbGT0m3zZPJULCANt6tMMwOHGAKyYQwcwLQPkf3lz5/JcQEXo73bcw76s0/JyqIuYsM5j+loFePX7Bw99QmycZBzTd2NmvH+ZRSWzIy5gdO0EDsVzLvREORcvYgDmJn/Hr9E7E+Tw0hCyNW462c33VLXnIJv5PH0HySXEBiWAb7N/au3h3Ec02gbfY+eYpKki9eUwkkgTXEldBomFv3WZLzRiHD8mlGks2aOO7QNIN61IE9M3GJrNc2aaN6uicgl3UIJRHi3TSBemIghdL5s/UtLPdxbtwe5tPSULKhaQ/HTr3h3qJBM3Z6QZqtM5HlLroGP3jOjb96IRYNXWqmk90cCU0noP/l6FZcQREaW/FEi+qwhn+HOoySSyP8s5EBp7kmKCgXYJxFEZVpq3PkaTA6FvfhhUDodek+UTE6e3IScQioAUmOCAuagv++lRkEa6I3agSuIp5Hts5v+IVrHycnkXZuc0oGBCLVQ5VZJXPvJloD8Lt1qQyr2AvLKOqjCOZnG4BU5R7xmQd4GJJ78UQUCGPxWpCLIZuc7YkNRpn+bRlAShE/UyS493UFR9g83ZPnru790pxtB3iNrLRzdtbpFnQDBC9p9/CpXPpQ==
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-11.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-11.exe /rawdata=tkSD2/0/fVBqDiiPqs5gMcGc5taRaFZW32RCLSae+mWHPSlfT7oPBpA1JlF6no/OtoCPEwTgayWtBilWvBgmu+jrHPFOAJOzYcPuuu7Q8z9gVkV7UbLbVJVjyUktWCeNuAnykr7NGLp3SCColGWLX4VUP2e/Zh/dUCt2XyfEK2+a7NORBqdSkUZ10fZKQzY5fJbYctuU4Smm/nBEKXOOpY86AhjLYF4WtgW2DZ/4NRpBL6yk4HIKxgjAr4rFVflgY6rzS83kO4HXdzHCoMxoPUc5PGzVfjGdh+8gbidD+gP596Q34XAs3o8J+yyoBKcyBeCkvYC6E45hh18XGUd3sXWPdxpyjX/v6ewhtMc+gl9s/OuVuQa0KVNkqv8s+R5k2sVAN3lF1snMMCZddMrGaRiKlBBJCX2bNmX1eEfdxN0LcSQUDLOlE2kilbJR/VFmIrzQKcCd6lfrouVKg1DXAjy5bDhIV61cPwSsJSUfQFJGCTom4LFIP+YLBgQFKn6BR9tqnMyPGD8bMH/kN3pL8Q+a1cKT+RwtlL8QOUiJKKIC+nKfEPCVY76jAgcHRUCb8kyC+2dtG2ql7lNKssdJ//GJayFvk1ZNGwE3qb5AuHQaeM9txsliSWuGmYLX1djQe+WIZQYt0H9hMTQaE8jyG323s9BJWelyx3ZSRUo3R1aigvshGMfdT0rWlyrYYJ946aNNf2OsdKI0w+ejXXHCqvnMFMYCJuZ3hs9F0+JAJdEwY3dtf6VXGLQ3dXRZTG9dR07PA56UwJxYjdVNKsEU/BPs3TOvap0AKpNJTI6ZYAV0HvLUim/kWGhpBntpc/JgtOdVz4MyDSpRDvBR0vU2USOhT0WvkDhYfto0uLJTZLmrXnbjzfLMN6GhpfPgDKPLeNTv/FXpnQPEiA4q2m9ua7TCJVPVT2VYfO9i/8DUVxt/IWNZtCJHYawnRmqwk5doS2AA/9Wm3ssTkKvMFUuj0NtYXZhDcVnN47S5KMp5iDwiIQ+yoVKxQCQXu/5zaRLSA2ZPd9xe1lL5GVBSvErtn+JiqdSzzYQ/brvplnqHLN8fdKLN3zgAbtmGckkAVq87G0/93EE5fzjgVyy9mCn8F2P5Ito6r1k/jemDYwDujh0waoYnkUkVUO/wOlCee1RNFZqd5CjaJDU4wpu1I65Yb96iMBXtLp2iBnglD0HVRuWVks3HwiYL4GiH/Y4b5DeO12aI7/8KZU119l6vHFtz9F+I/v6dLMWXRoC6BGNogUm7dk8InQ14V81rZY4Ku4OSTyJGQ2vcdJempRjx6PLHYO6DfY6jY4hBNQ/Du6b+fCRxf2gMsm6o/Q3Ftwe8IjmdL320XzVtxQgCQc4pKgsUkjPW7roLbWEzIP8EaFt7UM4NMyVwIyrTNWrryOJBv1LunXDgc4sNEGBrvJnc2yLtCcIJSpYHX5xQRrZHWLHLZZDXXOBW3ViC0RzCfEj04TULxmxOZ8CsrrYt7lUJAdOVH5SCGnwyryGhk4Q6iN4ivLWcPUOUitFCT6VVVN24+qcoiU1pqOkdMU40r6uRPCc1mH2LYU1NbFGxMU5oBXZ6APsB5uc1i9/L/3tuGbfZpLecr2tT/FsJxOw+YD5qrUj4DuK78QpU4aDTVGeefoVglYxxRa731lprLYBdKR2VayG0TQYvWbQ2Z9zLBjz/dGO0sMyHAn5Msgpj2BjiwBfSh8AP0FgFOjqOmcIm2yZqrmGV0p0tvNLF0UQ8akfNgkRErZ8x9CDc315xrM77Cz6KLXvH7ujLImm94oY1Ey6OYuvtLuPaYwi8cFeBuB0nPHpOxWFWkA9ybQMdXjo5MXY1tJmZuO+ctK3o1qrfGIui0jwoOSxkREO/9b1uuk55llZ4UKYM9UaVyCBXe0+3roaMpePcfUf62GB+akF42wCgphk6fOFK+vtBQQDPntzqmRHTd1Ntu7lNp4PWJ1PY6zujV5SKTWFDXFwKGaGSV8C5e8tRjuen3G5Xrs36ZGBF/DIGV48naN7rOeqD9LdO0Cf0RMp5eE4voPTQdxfgBUZPpFtPnUO2UAVe4YphaT0okS/tpLeRIDNXklQPv9+y4VaQk3jXRsSguEVFLE/9Q7zOElfzHP5IscujjIFxvhx6s+rB/3AAqUw7BAhFgvu5VLzkQ9Hww2e31zOPp7vpW3Tu4xofMqkeCgvAdxIOBc1deVRORx7HJa3OVBKLHzWzwOXK2Xo=
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-2.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-2.exe /rawdata=ZpEpDeFKA0in4DJjIfC8Y7k4037MecGan2d++XTmPMPTcGcypvibf3QQkKm0vBYs8vjkjmu1Io9hFaOV3x8L5VdTCKsdT1FIq8ebPoOtEhLPZAL5Hnz+Fe51tx6Ev9aivesUz4ROtSHIUUdYh3wYRwvNR/pnDLDM7apq+5YBJ9RZkAFqgpklpCAluHalwkOvzu2qj/5n47lRS6jPyXxJcERG77oJd/YRltGVrBI9IuChX0+Y/Sq86IgoSuA8Ye5DIRJrzxKUDzTr9gentmOULIJuaYQ+7SSsX+s1BWZIs19XedGxAgo4KagdxsnQ/t4236me4B3xGU91+nXWWtNcJKytSIwnjPOwawfF+nerQuVpGqZB4RorHTOPoBDeOysA+tLSqn5eVcoaLlsOq1btOOcKhVWZzQlqPtBP++tMxN+JTUQzkxuKcMHjDL3cOATt29133nJexPwlLBP0oLaxaMdtL3bfYOc+idRu1VFGIssGqK0QCYaGTMJlAhN139sOO8791ovBTmo7rhh8lBZR6iUGclXR1bSHiZEtp6/hFzxDkP191mlvai3TtM/AuuTOi0IZxzGpNhFXNadoS/iDXW2F5GwDPNFiFhU6knQ3kQQMsyuk09e8TizfWOQl4dbwCXk2Xh1yl+Pd8f/UJXXLt54A/3B5u1WrtVNQU9wDh0QQCiA43zlCuz/jDnptyOPkd7yTuKr/DX01QTbnCQiNJsUkgl5W6lTeNOUftHwGsXj97E8DJEIxIGktN4XlYyWwqQB6YiP8aMLCivrOjBCP+Jgv+JXtb/GcJk4loCaTV8jqjq8kqoP2xHh+xuPGdwgge+Tnv0diEn96l5h9Vm2yV4Ri9HRCXUQV7Ul+F7BL7YSOPNNhXTd5BYXBT+aRY1eDx6GJ0O6aJR0xO5NkwXDdOr05EuDqXfIf4xx7Ii+zViKWfuLK/ExPay2x4gSpBN7403w0yFU6DLUjh0K3Pqt2AFfqR8JwXOEKuTyKKf/hR3MukVG8FFka8wKf6yoK8EZr
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-4.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-4.exe /rawdata=kAJwYS1BvM8Ta/FAIYwC7sOqf0wBUtAjJZahcox/MGykY3rIf/YyfU6vXFLKvDyiOMKI9nMAM6ivxyhHRq+n/CXQ2EhGju6wEuaXbn4Fm6VWzZq99Ke3fmgRpqJde5XGFyX2uKKJ68OZcbq5hKWVs9jsCSZITuCTQzofTTI/011am5bNDp9z26/FLvI+a9oms0rX7EzbdS+aqMcD6bLpOQaj8xYxgpokCaSe5crulwaLL4cnQajLJkR4lYxLVURGaieo3jDg5FbyPp5rHUFnW4P/sAJbBC/RzU7hDaMkL+P0I9cHSJa3HceMCjIVfwuLw8oTVCbIO32DUHJluuxM6WaIdJFB0XEJ/l1UcJA3VWJsCn6WaCZ7EOHo754DyJJGvyT012WjU2Sk1o/oELAeK/LSBdcTHVW5W2mI3vcNMax1m+LLKUJsIiM2H7BlT5/75tgX7VT6L/8TZBMVoClto2p7Kg74ui1pX/6AUAcYMToO3HeOqthFwh2WIMuzOOgkvZP/BW0iDCwU976tYavvVA1CMv3SmSCnwPGxgjkkLXyf2LdTAl5nDfZSJXoyMmrG1e09fx7UVE+yyfdsPW+swky0dKcTE4hIrm8+ZyheWexhk78j64Rf1T6HKcUxKrQLZhG/YAymiX6UJ0D5a7J2rQgfKDxYRcoqNO7Xbm3T+ZgCMWE5tIeeX5Qwnab5+CD4GsfAhFv6GIrNaYz/RiKQ3uSuXwWITbyaFdr4EId7voIBIl7p+N4xx7OZI6v/CjkQhksTVbErvNOgyX6vEKrkOWmjkyS7fFzn2NL+g69ACTL/GGvTn4YmTAGZC1Cf1wk9SmIaoAnbmA3vt4CakuaIWE+EHaF4lSlUhp8bvmg1feRYJdieI90YNq14ZJQfUpK6ukzxAT8tEfA1gcRw3mpGN7bn9uhMuuYVuQoHx4YknhQGR0dK9UfPClO31u3+/Yb5fM5qeG6JB+RXmWt2AJvNfMthHn9v0dpFrzPxcRQSdxFATQnJ1T5hShOR+r+zC5cwe0CPyviQ4sj8ESZn4zoj8NC4zb0IljqCJOb/HYe+P6n+4uQYzSyor93Ux3h0DeciDAiDMVGnopM4mq2aM4lHIsz9gKcin6Mx+jFHCLtMxaYQ7mIgXt/qd5A55u/Qk2ze7QqFesnmFS+tkqIuhbj5alk+FpV+YlEmbpKr9uhw33VHPgFR77MNsAq05oiP2YYpZGLJ7+CNPF/dy5gVYmhNY9msR9xut2OT+RabK/R2aOlhHwGW0b4JyBeyc8/jKw28JsjD/t22Kds3RZXIlPpgrPY/9FyWDwVK3DAtsii2OYNpHoKCFQj8Vq9PV1MTpPWs8QIIcasrVdrp+RU75tD+0XR+PRdHtrCOK+sZSfCWFuNdKTH1u/K0k1ApAczt6JeT3OujAjosJuu57fQ0WxT/GIUPZyICJ3kePcs63MR9ZvM/CnaZIC31WdIQNBJn5jZ+1ZzWbYe79sG8AZLtu2eCpbe6BkMMPQtcpnFPgKECw6Ppxu75V2QZYNYY8mCCuJtOi7ijgoKoCpAzTX3u7QX3FQ6HX4y8+jJEl8hLJ0+ZwfGpHVdhQ6bfV44P3F8DkscuiB3QqchZE77KfSDzNUiO4JGBJ3XulIYfagA9oFkMtCOUTtnm3yWb413WTdeC1G+QqfVVrwe5K5skA1LPCTYjbrav60s1cd5FkW2yghKjIciIiHoIc/B0UDbQ5+8GfOmaIfmPtgo6e+K17xU+PdgAgSwhU6NudL2fJBksbG9f4aqK6H2HXq/lB9i3nSq6SwrtCCT4YMzEK0F20Fq7qUGRKzHxzwZ4r63CnHLDlQCNVBSWy3XN6JVl1vTh0S6pMlDhvLULmJ6Bbq6lWwBsLUoH7w==
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-6.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-6.exe /rawdata=OMGC5d6znlN6zMyfLI6Pn4G2DkDDOKypvh7RZgY/zCuRfGqljLxaZOnnISp9tuPBFsYTUYCmJ3SDffbz/YcRwV7f8FcKaL/DEUCh6mtC2D9jzTFbLT0TgTQAusyA9JhHRvlKuRxLgXUxfCpVGYMlnT9g6hO13y56jhf+ySiFpo5H+phXlceLacbiAVospmpQsnw1y5N/hL15C/tvyY/kuHZx2zxrk5gxqLZzUcysBCbbfzzhQRSNYZJKMqkdTOZ8HXmN2iM5nVzoAHbGC1zXtuKPk2sERD1aFUSrSMwWZvvAGyUIPS3yfmbMskYrPNo9wr3Jat7kK1uHsSxpUm+xyJHeQwQxk/bjVTNiqBgpf6w+TVPwR4LFIOq1iTC5sKreYdCbk3pMN7KCdl8SihJqZ0dLDDEkruv8Fi4Fu8C8xmZoAC+LJ45QX08XZjmVNiSVvY4byfhaomJREFEGWc1D8x161GWPabMj9f2uE5cq4/4iDdHymri9HMSMoDOdsLpumyJtOjO2ngoW/tSO21xNVF/IFnNnKmCxvVSbvMskj4r9d4oT9ZCvBGShSiRfGzDQr3xIYS9JYtzc538qo2mm6dHjGZE9wWTEt1ULY1C53E/WXBykN+kJVPhoRXq+fWKgRaxeMjhEKHWhSF+xQKZ2QLVzDY7yRcgaeDqVRvbzjyiEFch2TeZa0jGMwOUdeIld5hANc80eFuTE+VSQN4+4bdt1KJgtrTlybV2v+Mboo9wcO6YxucymM8PO/oqjacK0uECTpSDNcYmHoHNk5r40UAvH1S0ai9HLOgbBBNDnTjPed+iMq1G+8yAHiiVEYwyaAelZjP+JwWWOzXon2Z649Ke4/dWv79W7biWXQyExJvE6or9oQoAs2q1lPo38bNx7TQ3vTMK85hrezrpqqSjTawwZyDtl1wQ6MgGCCCT7qC0QRkJUDKrA9SFdLUdDnmy67d7+LFXWYO3O2ckXstg9uWFzpOpSr2418ESPxDqa3mnJoF/Fbv0vULCnTBmCUF6dc7o8q+nM90Y3RxXLIJEO349UQBKEEixcs0JgMfY4EJsviht9mgMFRplIEJhUGpLjF0nmHTLqzbBZhCFES7iDjbFcpsvTx9kokISCBzQf02DwrL4w4XDLTjzek3LaIkXZbeB5sUBYVWgIi2FgdQCtV7akARtaFx1bdFRlXWotZ8+PUDn5t3o4f3OylRG8hjREkjauhoEhj4Wxj3+0TtioXtcRvxqlQPXjqJEfwFD1aHUBGElndHhwmy4M/L6oEOUsTiRS3hS1Acz1kfeQ+ufO/LfJAkiRkDFHkg1j3LuXcoXwbjLkwuzqT+3e0sMzk3I+oW8cDciLZiB1mjc0o2Sp11/BuuTWHA/NekGsI/8bj/XNx1ICFT7LcDENzLFFHcV3Ca3io07lIIWjODhY6BDbXa4MubskgjtxvwWE4umkZ4Mtb6AQE+7XDVLeLRuAcIahWWZreAhPgZXAiTEE8hSBv9DNGyXKqyOuU3wglwy1tJFJfWc++FWflj15LkLfSsJbgo9nOYJZ15aJAf8ZTSzHDcYwamA0fDRxstfffXrZ+9Kct9hsxps/4B0ea1QCTut1MZoUyLQmFxjhjWqyBV0eP1Ko7AjkH4WJ7qxMDOi7YKDwsqFvFsecPcF0UaojnCDG8E0quzaxtlcMRBWpVEM+sGbkPgo4CpPv0UjUSRJbp4c=
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-7.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-7.exe /rawdata=GkyhJQZuR7pAaAIwAZQSkqhmGcyulkdCBqnTb0wjp1S/Yo6tAZIgqLIpDmkMgNq1ZCqexkX30VUxkCmEnizLTKnD+2bqJTpy2c9l6Rtrl5njf6SjtcgahRRG9JwcoWATeuwLNHLfkj/dWrsrqhZM7r9p67miel6C0VwItI3NeVWd91Tqsf6ZDzPJWMFx22qJb7JGpqA4HJDgUJ556ZYdjEow5rOeVrw0VF/sbgbdH0RU7uMWNoJw6kHUDTQIw7WJRvBGRtUYzgTD0WHIIC6dio8gv4bEirSzkNLqXAMAuRKa6rWqQ43KLgmYtFK43q/KwLeszs0Uh/Ach5D3xoy1GluMD5t+xOzO6TNd8iGvWGwandTnzettryBeUCVZBoKmNu2RaGriwCTFmrXRWAguEeer+hhsyTL2cbqUxSoe4HDowQC83dmRDNqGRphLXUl0ET0lZQZXSb6cajHVOxT+/PM6ymfZmjxYwysMqUkTL3nuh+b5FYEXGsEn5Z6JZe6hL8/yO9ThiDy6jlodtu9SVOj9M7fkW7kfD6Vl7mUHAJ1y1ZA6Ev02fAa2C3Yddo2E8SqLIayW3sZTEIDe4HsWjq2Lb69T2cZ957jcfgM59+adD5XMmu0Iu1ILbuseIHMtQnPEsAvzvNnyJ+uXIexC2Zam3h2a30U/jUqQV+mDttSh+mYoxxrwlUoKExUeRxo/6lr+1dr3pJo/pEOYWMtAy9UvHpTCbVPX+oRKnuCgv9B6DPwiwj4RrGQp7MS3QdyYkC68z5aQRkOkX+SfIORhapvGOeFvbji80Iktsfmv6h/31fMa3f7zgAFugnesdST9DcE7vv2SKvVqTLJ4lQn+FIWdAiJ+bGXb7EY0ecmdxHawVZB35lLyTQP3I9Gwe+m218ggKlHGbUqBU88pAqM4uJh6Pw4iktpm+DXoxYaX+L6DokgtS87dSldlViEyx/iLuZ7ecpA78Oi5aXbjzllrj7i8FTiWP3xLODPWbqM5a96bM5Uuju2Rrp4CbyPsOXqQuJCqonGJMQFQJPxhG5KUTbrURZOgKv0GztMZBNPVgVpufE7C2jTSo28Ga0Kf37Naz2Yuri/N1r8vFDNe65fRqi7HMw4+kMgXmg3nRc51WrSu0/9I34POZokeWji9GKc0KbckGjkqp0eiGvDhXljv4aVtRtM3pg+jO2kCKZZYqO4RmqQ+Sq+L99/r2/XE5DrZ2oU8Yf/pNzfF3q07PoFTYF9iEyo2quwabMYLh6k1CJZvfTR0nlM/kArKXnLBSlsP5QW4+i5fEUSGuOKhTchxeDbdp3NwcXEU1tMQvtC5/0EBqNkzLIekvBd/qJ9XRsEaNPpJ/sqfOVbtEpkRfUhbgXje4WJEqqxBXRTFZTqOg53R6/Bp6t9YfgZh5dMNrRgGgB9lg5T28pCIfpsO6op0kcbPYPzL+iDlDmqxvq2Mrtkb2DmxhtQOM8VRpo2Rk4QY8Imf5IVz+snJ+bGUAZAEVGHeSVXJ0ux8GZyVmY7qXs0Rx/m/QAXnLNDl6hXjRtb0FW7oKxg/L6nNLIBxnobJVBjRe285XyCWl6HvWAzlWEzjTG1cskwsmOuR+BV/g3bcAdqAuzexkWJAPd7dQRdy8dOfk0O6BQ2w0bhR9qP/Ua7Hjm88nTkja3zitGMaa0QlD7ApS7TayZdnuq5opho5L/wSTD6yWLaxXB3Yi9m7C+8=
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\temp_c94697dc-6b6d-478f-bddd-348b413d6a2a-2.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-2.exe /rawdata=ZpEpDeFKA0in4DJjIfC8Y7k4037MecGan2d++XTmPMPTcGcypvibf3QQkKm0vBYs8vjkjmu1Io9hFaOV3x8L5VdTCKsdT1FIq8ebPoOtEhLPZAL5Hnz+Fe51tx6Ev9aivesUz4ROtSHIUUdYh3wYRwvNR/pnDLDM7apq+5YBJ9RZkAFqgpklpCAluHalwkOvzu2qj/5n47lRS6jPyXxJcERG77oJd/YRltGVrBI9IuChX0+Y/Sq86IgoSuA8Ye5DIRJrzxKUDzTr9gentmOULIJuaYQ+7SSsX+s1BWZIs19XedGxAgo4KagdxsnQ/t4236me4B3xGU91+nXWWtNcJKytSIwnjPOwawfF+nerQuVpGqZB4RorHTOPoBDeOysA+tLSqn5eVcoaLlsOq1btOOcKhVWZzQlqPtBP++tMxN+JTUQzkxuKcMHjDL3cOATt29133nJexPwlLBP0oLaxaMdtL3bfYOc+idRu1VFGIssGqK0QCYaGTMJlAhN139sOO8791ovBTmo7rhh8lBZR6iUGclXR1bSHiZEtp6/hFzxDkP191mlvai3TtM/AuuTOi0IZxzGpNhFXNadoS/iDXW2F5GwDPNFiFhU6knQ3kQQMsyuk09e8TizfWOQl4dbwCXk2Xh1yl+Pd8f/UJXXLt54A/3B5u1WrtVNQU9wDh0QQCiA43zlCuz/jDnptyOPkd7yTuKr/DX01QTbnCQiNJsUkgl5W6lTeNOUftHwGsXj97E8DJEIxIGktN4XlYyWwqQB6YiP8aMLCivrOjBCP+Jgv+JXtb/GcJk4loCaTV8jqjq8kqoP2xHh+xuPGdwgge+Tnv0diEn96l5h9Vm2yV7MyOb2pRe0+969CBqmvRqq9mUMseSvmrlRph9jJY2YSMEkB6d3o8DASvEv2LQljqG53PcXGRln2NkUP5MUCQMgwBJfCa47TdzuqpZeRPOKDewIamBaE+cB3z4Vo9qIn7PelbvMoQEFXtBR9z8F/xMp0nd1xwOs41ZnZZtFR2MlFr5pGkDGNXuLWHxDCn8B8c/bT5gWztcQpoIX2Mjv999sMLMupTOIhbj5Iph3L+x+nHzsKJv7wt0pzW6DdG+LtBxjN8jwcKIwoAeyAQOATroHLoXZZiuRGINXiyVnEELiFvHvsrx0uCRQVOFY6T3mGV4JanG3rg3apd0s2cmtlMlk=
=========Mozilla firefox=========
ProfilePath - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\v63wnowc.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
firefox@firefox.sk
urlbox@firefox.sk
C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\v63wnowc.default\extensions\
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191113}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho64.dll [2014-09-19 883048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP SimplePass Identity Protection Extension - C:\Program Files\DigitalPersona\Bin\dpotspluginie8.dll [2009-12-30 2213128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-09-11 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-30 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191113}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho.dll [2014-09-19 652648]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP SimplePass Identity Protection Extension - C:\Program Files (x86)\DigitalPersona\Bin\dpotspluginie8.dll [2009-12-30 1262856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-09-11 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-05-30 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-01-22 166424]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-01-22 390680]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-01-22 410136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-04-10 2104104]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-01-14 487424]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2010-01-20 611896]
"HPToneControl"=C:\Program Files\Hewlett-Packard\HPToneControl\HPTonectl.exe [2009-08-19 107832]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-05-30 172032]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-16 8192]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2014-04-17 1967616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easybits Recovery]
C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Envy Guides AutoPlay]
C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\hpdocstart.exe [2010-03-24 76584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-01-22 2363392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintoflashvddc]
[]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2010-05-30 149280]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-09-11 4085896]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-04-17 767200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-01-22 268800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-19 01:38:50 ----D---- C:\rsit
2014-09-19 01:38:50 ----D---- C:\Program Files\trend micro
2014-09-19 01:14:59 ----D---- C:\Program Files (x86)\iWebar
2014-09-19 01:14:10 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-19 01:14:08 ----D---- C:\Program Files (x86)\Senses
2014-09-19 01:03:59 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-09-19 01:02:46 ----D---- C:\AdwCleaner
2014-09-18 14:29:21 ----D---- C:\Windows\Migration
2014-09-18 14:26:31 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-18 14:22:15 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-18 14:22:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-18 12:36:55 ----A---- C:\Windows\explorer.exe
2014-09-18 12:36:54 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-09-18 12:36:53 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-09-18 12:36:53 ----A---- C:\Windows\system32\WMPhoto.dll
2014-09-18 12:36:52 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-18 12:36:52 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-18 12:36:42 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-09-18 12:36:42 ----A---- C:\Windows\system32\d2d1.dll
2014-09-18 12:36:24 ----A---- C:\Windows\system32\drivers\bthport.sys
2014-09-18 12:36:23 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2014-09-18 12:36:19 ----A---- C:\Windows\system32\fsutil.exe
2014-09-18 12:36:19 ----A---- C:\Windows\system32\esent.dll
2014-09-18 12:36:18 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-09-18 12:36:18 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-09-18 12:36:18 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-09-18 12:36:18 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-09-18 12:36:17 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2014-09-18 12:36:17 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-09-18 12:36:17 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-09-18 12:36:17 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-09-18 12:32:16 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-09-18 12:32:16 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-09-18 12:32:15 ----A---- C:\Windows\system32\spoolsv.exe
2014-09-18 12:32:15 ----A---- C:\Windows\splwow64.exe
2014-09-18 12:14:07 ----D---- C:\Windows\system32\MRT
2014-09-18 12:14:00 ----A---- C:\Windows\system32\MRT.exe
2014-09-18 12:05:29 ----D---- C:\Windows\SYSWOW64\Wat
2014-09-18 12:05:29 ----D---- C:\Windows\system32\Wat
2014-09-18 03:06:05 ----A---- C:\Windows\system32\wmploc.DLL
2014-09-18 03:06:04 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-09-18 03:06:04 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-09-18 03:06:02 ----A---- C:\Windows\system32\wmp.dll
2014-09-18 01:54:11 ----D---- C:\7dfe590c07e7d46d901171a242b9
2014-09-18 01:50:22 ----A---- C:\Windows\system32\IEUDINIT.EXE
2014-09-18 01:44:46 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\wextract.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\url.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\occache.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msls31.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\inseng.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\icardie.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\wininet.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\wextract.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\webcheck.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\urlmon.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\url.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msrating.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msls31.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\mshtmler.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msfeedssync.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\licmgr10.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jsIntl.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jscript9.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\inseng.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iexpress.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieui.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iesysprep.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iesetup.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iertutil.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iernonce.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieframe.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieapfltr.dat
2014-09-18 01:44:40 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\icardie.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\elshyph.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\vbscript.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\pngfilt.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\occache.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\mshtml.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\mshta.exe
2014-09-18 01:44:39 ----A---- C:\Windows\system32\jscript.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\imgutil.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-18 01:44:39 ----A---- C:\Windows\system32\iepeers.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\XpsPrint.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\UIAnimation.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\FntCache.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\dxgi.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\DWrite.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10level9.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10_1.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10.dll
2014-09-18 01:00:50 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-09-18 01:00:49 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-09-18 01:00:49 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-09-18 01:00:49 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-09-18 01:00:47 ----A---- C:\Windows\system32\WUDFx.dll
2014-09-18 01:00:47 ----A---- C:\Windows\system32\WUDFHost.exe
2014-09-18 01:00:47 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-09-17 23:58:53 ----D---- C:\d5a25a2c76fd5f6abe6105ffd152
2014-09-17 23:56:04 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-09-17 23:56:04 ----A---- C:\Windows\system32\wmi.dll
2014-09-17 23:56:04 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-09-17 20:41:55 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-09-17 20:41:55 ----A---- C:\Windows\system32\infocardapi.dll
2014-09-17 20:41:54 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-09-17 20:41:54 ----A---- C:\Windows\system32\icardagt.exe
2014-09-17 20:41:53 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-09-17 20:41:53 ----A---- C:\Windows\system32\icardres.dll
2014-09-17 20:41:30 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-09-17 20:41:30 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-09-17 18:58:02 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2014-09-17 18:58:02 ----A---- C:\Windows\system32\xmllite.dll
2014-09-17 18:57:55 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-09-17 18:57:55 ----A---- C:\Windows\system32\msieftp.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbctrac.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbccu32.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbccr32.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbccp32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2014-09-17 18:57:52 ----A---- C:\Windows\system32\wwansvc.dll
2014-09-17 18:57:52 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-09-17 18:57:49 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-09-17 18:57:49 ----A---- C:\Windows\system32\comctl32.dll
2014-09-17 18:57:41 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2014-09-17 18:57:41 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2014-09-17 18:57:41 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2014-09-17 18:57:41 ----A---- C:\Windows\system32\dhcpcore6.dll
2014-09-17 18:57:36 ----A---- C:\Windows\system32\mstscax.dll
2014-09-17 18:57:35 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-09-17 18:57:35 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2014-09-17 18:57:34 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-09-17 18:57:34 ----A---- C:\Windows\system32\tsgqec.dll
2014-09-17 18:57:34 ----A---- C:\Windows\system32\aaclient.dll
2014-09-17 18:57:18 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-09-17 18:57:18 ----A---- C:\Windows\system32\wintrust.dll
2014-09-17 18:57:07 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2014-09-17 18:57:07 ----A---- C:\Windows\system32\CPFilters.dll
2014-09-17 18:57:06 ----A---- C:\Windows\system32\sbe.dll
2014-09-17 18:57:05 ----A---- C:\Windows\SYSWOW64\sbe.dll
2014-09-17 18:56:59 ----A---- C:\Windows\SYSWOW64\quartz.dll
2014-09-17 18:56:59 ----A---- C:\Windows\system32\quartz.dll
2014-09-17 18:56:57 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-09-17 18:56:57 ----A---- C:\Windows\system32\qdvd.dll
2014-09-17 18:56:49 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2014-09-17 18:56:49 ----A---- C:\Windows\system32\ntshrui.dll
2014-09-17 18:56:39 ----A---- C:\Windows\system32\tquery.dll
2014-09-17 18:56:38 ----A---- C:\Windows\SYSWOW64\tquery.dll
2014-09-17 18:56:38 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2014-09-17 18:56:38 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2014-09-17 18:56:38 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-09-17 18:56:38 ----A---- C:\Windows\system32\mssrch.dll
2014-09-17 18:56:37 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2014-09-17 18:56:37 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2014-09-17 18:56:37 ----A---- C:\Windows\SYSWOW64\mssph.dll
2014-09-17 18:56:37 ----A---- C:\Windows\system32\SearchFilterHost.exe
2014-09-17 18:56:37 ----A---- C:\Windows\system32\mssvp.dll
2014-09-17 18:56:37 ----A---- C:\Windows\system32\mssphtb.dll
2014-09-17 18:56:37 ----A---- C:\Windows\system32\mssph.dll
2014-09-17 18:56:36 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2014-09-17 18:56:36 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2014-09-17 18:56:36 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2014-09-17 18:56:36 ----A---- C:\Windows\system32\msscntrs.dll
2014-09-17 18:56:35 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2014-09-17 18:56:07 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-09-17 18:56:07 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-09-17 18:56:06 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-09-17 18:56:05 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-09-17 18:56:05 ----A---- C:\Windows\system32\usp10.dll
2014-09-17 18:56:03 ----A---- C:\Windows\SYSWOW64\webio.dll
2014-09-17 18:56:03 ----A---- C:\Windows\system32\webio.dll
2014-09-17 18:56:01 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-17 18:56:01 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-17 18:51:01 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-09-17 18:51:01 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-09-17 18:51:01 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-09-17 18:51:01 ----A---- C:\Windows\system32\cryptsvc.dll
2014-09-17 18:51:01 ----A---- C:\Windows\system32\cryptnet.dll
2014-09-17 18:51:01 ----A---- C:\Windows\system32\crypt32.dll
2014-09-17 18:50:52 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-09-17 18:50:52 ----A---- C:\Windows\system32\wer.dll
2014-09-17 18:50:51 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-09-17 18:50:51 ----A---- C:\Windows\system32\imagehlp.dll
2014-09-17 18:50:50 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-09-17 18:50:50 ----A---- C:\Windows\system32\drivers\netio.sys
2014-09-17 18:50:50 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-09-17 18:49:49 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-09-17 18:49:49 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-09-17 18:49:49 ----A---- C:\Windows\system32\msxml6.dll
2014-09-17 18:49:49 ----A---- C:\Windows\system32\msxml3.dll
2014-09-17 18:49:48 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-09-17 18:49:48 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-09-17 18:49:48 ----A---- C:\Windows\system32\msxml6r.dll
2014-09-17 18:49:48 ----A---- C:\Windows\system32\msxml3r.dll
2014-09-17 18:48:47 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-09-17 18:48:47 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-09-17 18:48:42 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-09-17 18:48:42 ----A---- C:\Windows\system32\osk.exe
2014-09-17 18:48:33 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-09-17 18:48:28 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-09-17 18:48:28 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-09-17 18:48:28 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-09-17 18:48:28 ----A---- C:\Windows\system32\credui.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\lpk.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\lpk.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\fontsub.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\dciman32.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\atmlib.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\atmfd.dll
2014-09-17 18:48:17 ----A---- C:\Windows\system32\mfc42u.dll
2014-09-17 18:48:17 ----A---- C:\Windows\system32\mfc42.dll
2014-09-17 18:48:16 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2014-09-17 18:48:16 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\secproc_isv.dll
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate.exe
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\secproc.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\msdrm.dll
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-09-17 18:47:42 ----A---- C:\Windows\system32\d3d11.dll
2014-09-17 18:47:41 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2014-09-17 18:47:39 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2014-09-17 18:47:39 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-09-17 18:47:34 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-09-17 18:47:34 ----A---- C:\Windows\system32\qedit.dll
2014-09-17 18:47:26 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-09-17 18:47:26 ----A---- C:\Windows\system32\rdpwsx.dll
2014-09-17 18:47:26 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-09-17 18:47:24 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-09-17 18:47:22 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-09-17 18:47:22 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-09-17 18:47:18 ----A---- C:\Windows\system32\drivers\afd.sys
2014-09-17 18:47:17 ----A---- C:\Windows\system32\Wdfres.dll
2014-09-17 18:47:17 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-09-17 18:47:17 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-09-17 18:44:42 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-09-17 18:44:40 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2014-09-17 18:44:40 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2014-09-17 18:44:40 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\nlasvc.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\netcorehc.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\ncsi.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-09-17 18:44:39 ----A---- C:\Windows\SYSWOW64\netevent.dll
2014-09-17 18:44:39 ----A---- C:\Windows\system32\nlaapi.dll
2014-09-17 18:44:39 ----A---- C:\Windows\system32\netevent.dll
2014-09-17 18:44:39 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-09-17 18:44:28 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-09-17 18:44:28 ----A---- C:\Windows\system32\tzres.dll
2014-09-17 18:44:24 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-09-17 18:44:24 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-09-17 18:44:23 ----A---- C:\Windows\system32\profsvc.dll
2014-09-17 18:44:22 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2014-09-17 18:44:22 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2014-09-17 18:44:22 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-09-17 18:44:22 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-09-17 18:44:22 ----A---- C:\Windows\system32\dnsapi.dll
2014-09-17 18:43:40 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-09-17 18:43:40 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-09-17 18:43:40 ----A---- C:\Windows\system32\WebClnt.dll
2014-09-17 18:43:40 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-09-17 18:43:40 ----A---- C:\Windows\system32\davclnt.dll
2014-09-17 18:43:39 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-09-17 18:43:39 ----A---- C:\Windows\system32\dpnet.dll
2014-09-17 18:43:36 ----A---- C:\Windows\system32\msi.dll
2014-09-17 18:43:35 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-09-17 18:43:35 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-09-17 18:43:35 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-09-17 18:43:35 ----A---- C:\Windows\system32\msihnd.dll
2014-09-17 18:43:35 ----A---- C:\Windows\system32\consent.exe
2014-09-17 18:43:35 ----A---- C:\Windows\system32\authui.dll
2014-09-17 18:43:35 ----A---- C:\Windows\system32\appinfo.dll
2014-09-17 18:43:17 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-09-17 18:43:16 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-09-17 18:43:16 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-09-17 18:43:15 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-09-17 18:43:15 ----A---- C:\Windows\system32\winlogon.exe
2014-09-17 18:43:15 ----A---- C:\Windows\system32\objsel.dll
2014-09-17 18:43:15 ----A---- C:\Windows\system32\KernelBase.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-09-17 18:43:14 ----A---- C:\Windows\system32\smss.exe
2014-09-17 18:43:14 ----A---- C:\Windows\system32\dimsroam.dll
2014-09-17 18:43:14 ----A---- C:\Windows\system32\cngprovider.dll
2014-09-17 18:43:14 ----A---- C:\Windows\system32\adprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\wincredprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\csrsrv.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\capiprovider.dll
2014-09-17 18:43:11 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-09-17 18:43:11 ----A---- C:\Windows\system32\apisetschema.dll
2014-09-17 18:43:02 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-09-17 18:41:58 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-09-17 18:41:58 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-09-17 18:41:58 ----A---- C:\Windows\system32\drivers\srv.sys
2014-09-17 18:41:57 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-09-17 18:41:57 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-09-17 18:41:56 ----A---- C:\Windows\system32\cdd.dll
2014-09-17 18:41:53 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-09-17 18:41:52 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2014-09-17 18:41:52 ----A---- C:\Windows\system32\mswsock.dll
2014-09-17 18:41:44 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-09-17 18:41:44 ----A---- C:\Windows\SYSWOW64\gameux.dll
2014-09-17 18:41:44 ----A---- C:\Windows\system32\Wpc.dll
2014-09-17 18:41:44 ----A---- C:\Windows\system32\gameux.dll
2014-09-17 18:41:26 ----A---- C:\Windows\system32\psisdecd.dll
2014-09-17 18:41:25 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-09-17 18:41:23 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-09-17 18:40:37 ----A---- C:\Windows\SYSWOW64\tdh.dll
2014-09-17 18:40:37 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-09-17 18:40:37 ----A---- C:\Windows\system32\tdh.dll
2014-09-17 18:40:37 ----A---- C:\Windows\system32\ntdll.dll
2014-09-17 18:40:37 ----A---- C:\Windows\system32\advapi32.dll
2014-09-17 18:40:36 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-09-17 18:40:32 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-09-17 18:39:49 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-09-17 18:39:49 ----A---- C:\Windows\system32\iologmsg.dll
2014-09-17 18:39:49 ----A---- C:\Windows\system32\drivers\storport.sys
2014-09-17 18:39:49 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-09-17 18:39:49 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-09-17 18:39:42 ----A---- C:\Windows\system32\schannel.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\wdigest.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\TSpkg.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\ncrypt.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\msv1_0.dll
2014-09-17 18:39:40 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-09-17 18:39:40 ----A---- C:\Windows\system32\credssp.dll
2014-09-17 18:39:33 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-09-17 18:39:33 ----A---- C:\Windows\system32\synceng.dll
2014-09-17 18:39:27 ----A---- C:\Windows\system32\winresume.exe
2014-09-17 18:39:27 ----A---- C:\Windows\system32\winload.exe
2014-09-17 18:39:27 ----A---- C:\Windows\system32\kdusb.dll
2014-09-17 18:39:27 ----A---- C:\Windows\system32\kd1394.dll
2014-09-17 18:39:26 ----A---- C:\Windows\system32\kdcom.dll
2014-09-17 18:39:21 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-09-17 18:39:21 ----A---- C:\Windows\system32\shdocvw.dll
2014-09-17 18:39:12 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-09-17 18:39:12 ----A---- C:\Windows\system32\win32spl.dll
2014-09-17 18:39:11 ----A---- C:\Windows\system32\taskhost.exe
2014-09-17 18:38:22 ----A---- C:\Windows\system32\shell32.dll
2014-09-17 18:38:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-09-17 18:38:18 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-09-17 18:38:18 ----A---- C:\Windows\system32\cryptdlg.dll
2014-09-17 18:38:10 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\devobj.dll
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2014-09-17 18:37:48 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-09-17 18:37:48 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-09-17 18:37:47 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-09-17 18:37:47 ----A---- C:\Windows\system32\netapi32.dll
2014-09-17 18:37:47 ----A---- C:\Windows\system32\browser.dll
2014-09-17 18:37:47 ----A---- C:\Windows\system32\browcli.dll
2014-09-17 18:37:46 ----A---- C:\Windows\SYSWOW64\browcli.dll
2014-09-17 18:37:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-09-17 18:37:45 ----A---- C:\Windows\system32\wow64win.dll
2014-09-17 18:37:45 ----A---- C:\Windows\system32\wow64.dll
2014-09-17 18:37:45 ----A---- C:\Windows\system32\kernel32.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-09-17 18:37:44 ----A---- C:\Windows\system32\wow64cpu.dll
2014-09-17 18:37:44 ----A---- C:\Windows\system32\winsrv.dll
2014-09-17 18:37:44 ----A---- C:\Windows\system32\ntvdm64.dll
2014-09-17 18:37:44 ----A---- C:\Windows\system32\conhost.exe
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-09-17 18:37:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2014-09-17 18:37:41 ----A---- C:\Windows\SYSWOW64\user.exe
2014-09-17 18:37:39 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2014-09-17 18:37:39 ----A---- C:\Windows\system32\prevhost.exe
2014-09-17 18:37:39 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-09-17 18:37:38 ----A---- C:\Windows\system32\srcore.dll
2014-09-17 18:37:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2014-09-17 18:37:36 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-09-17 18:37:34 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2014-09-17 18:37:34 ----A---- C:\Windows\system32\inetcomm.dll
2014-09-17 18:37:31 ----A---- C:\Windows\system32\msvcrt.dll
2014-09-17 18:37:30 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-09-17 18:37:29 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-09-17 18:37:26 ----A---- C:\Windows\system32\certutil.exe
2014-09-17 18:37:25 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-09-17 18:37:24 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-09-17 18:37:24 ----A---- C:\Windows\system32\certenc.dll
2014-09-17 18:37:08 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-17 18:37:08 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-17 18:37:08 ----A---- C:\Windows\system32\kerberos.dll
2014-09-17 18:37:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-17 18:37:07 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-17 18:36:54 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-09-17 18:36:54 ----A---- C:\Windows\system32\scrrun.dll
2014-09-17 18:36:54 ----A---- C:\Windows\system32\cscript.exe
2014-09-17 18:36:53 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-09-17 18:36:53 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-09-17 18:36:53 ----A---- C:\Windows\system32\wscript.exe
2014-09-17 18:36:48 ----A---- C:\Windows\system32\lsass.exe
2014-09-17 18:36:48 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-09-17 18:36:48 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-09-17 18:36:48 ----A---- C:\Windows\system32\drivers\cng.sys
2014-09-17 18:36:47 ----A---- C:\Windows\system32\sspisrv.dll
2014-09-17 18:36:47 ----A---- C:\Windows\system32\sspicli.dll
2014-09-17 18:36:47 ----A---- C:\Windows\system32\secur32.dll
2014-09-17 18:36:26 ----A---- C:\Windows\system32\localspl.dll
2014-09-17 18:36:25 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-09-17 18:36:25 ----A---- C:\Windows\system32\win32k.sys
2014-09-17 18:36:25 ----A---- C:\Windows\system32\gdi32.dll
2014-09-17 18:36:24 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-09-17 18:36:22 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-09-17 18:36:22 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-09-17 18:36:22 ----A---- C:\Windows\system32\oleaut32.dll
2014-09-17 18:36:22 ----A---- C:\Windows\system32\oleacc.dll
2014-09-17 18:36:20 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-09-17 18:36:20 ----A---- C:\Windows\system32\EncDec.dll
2014-09-17 18:35:52 ----A---- C:\Windows\system32\aepdu.dll
2014-09-17 18:35:52 ----A---- C:\Windows\system32\aeinv.dll
2014-09-17 18:35:49 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2014-09-17 18:35:48 ----A---- C:\Windows\system32\cdosys.dll
2014-09-17 18:34:00 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-09-17 18:34:00 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-09-17 18:34:00 ----A---- C:\Windows\system32\nshwfp.dll
2014-09-17 18:34:00 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-09-17 18:34:00 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-09-17 18:33:58 ----A---- C:\Windows\system32\scavengeui.dll
2014-09-17 18:33:55 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-09-17 18:33:55 ----A---- C:\Windows\system32\rpcrt4.dll
2014-09-17 18:32:58 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-09-17 18:32:58 ----A---- C:\Windows\system32\packager.dll
2014-09-17 16:56:08 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2014-09-17 16:56:08 ----A---- C:\Windows\system32\rdpcore.dll
2014-09-17 16:56:08 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wups2.dll
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wucltux.dll
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wuaueng.dll
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wuauclt.exe
2014-09-17 16:46:01 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-09-17 16:46:01 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-09-17 16:46:01 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-09-17 16:46:01 ----A---- C:\Windows\system32\wups.dll
2014-09-17 16:46:01 ----A---- C:\Windows\system32\wudriver.dll
2014-09-17 16:46:01 ----A---- C:\Windows\system32\wuapi.dll
2014-09-17 16:45:52 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-09-17 16:45:52 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-09-17 16:45:52 ----A---- C:\Windows\system32\wuwebv.dll
2014-09-17 16:45:52 ----A---- C:\Windows\system32\wuapp.exe
2014-09-16 17:46:56 ----D---- C:\Windows\system32\SPReview
2014-09-16 17:46:16 ----D---- C:\Windows\system32\EventProviders
2014-09-16 16:23:15 ----A---- C:\Windows\system32\netfxperf.dll
2014-09-16 16:23:15 ----A---- C:\Windows\system32\dfshim.dll
2014-09-16 16:23:08 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-09-16 16:23:03 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-09-16 16:23:03 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-09-16 16:22:58 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2014-09-16 16:22:58 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2014-09-16 16:22:58 ----A---- C:\Windows\system32\sysmain.dll
2014-09-16 16:22:56 ----A---- C:\Windows\system32\MSVidCtl.dll
2014-09-16 16:22:54 ----A---- C:\Windows\system32\mscoree.dll
2014-09-16 16:22:53 ----A---- C:\Windows\system32\mmcndmgr.dll
2014-09-16 16:22:52 ----A---- C:\Windows\system32\xpsservices.dll
2014-09-16 16:22:52 ----A---- C:\Windows\system32\mf.dll
2014-09-16 16:22:49 ----A---- C:\Windows\system32\schedsvc.dll
2014-09-16 16:22:49 ----A---- C:\Windows\system32\ole32.dll
2014-09-16 16:22:48 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2014-09-16 16:22:48 ----A---- C:\Windows\system32\spwizui.dll
2014-09-16 16:22:47 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\wevtsvc.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\taskschd.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\RacEngn.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\diagperf.dll
2014-09-16 16:22:46 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2014-09-16 16:22:46 ----A---- C:\Windows\system32\vssapi.dll
2014-09-16 16:22:46 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2014-09-16 16:22:46 ----A---- C:\Windows\system32\ExplorerFrame.dll
2014-09-16 16:22:45 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-09-16 16:22:44 ----A---- C:\Windows\system32\UIRibbon.dll
2014-09-16 16:22:42 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2014-09-16 16:22:42 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2014-09-16 16:22:42 ----A---- C:\Windows\system32\WsmSvc.dll
2014-09-16 16:22:42 ----A---- C:\Windows\system32\WMVCORE.DLL
2014-09-16 16:22:42 ----A---- C:\Windows\system32\rdpdd.dll
2014-09-16 16:22:42 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2014-09-16 16:22:42 ----A---- C:\Windows\system32\PresentationHost.exe
2014-09-16 16:22:41 ----A---- C:\Windows\system32\spreview.exe
2014-09-16 16:22:41 ----A---- C:\Windows\system32\spinstall.exe
2014-09-16 16:22:41 ----A---- C:\Windows\system32\MPSSVC.dll
2014-09-16 16:22:41 ----A---- C:\Windows\system32\CertEnroll.dll
2014-09-16 16:22:40 ----A---- C:\Windows\system32\WinSAT.exe
2014-09-16 16:22:40 ----A---- C:\Windows\system32\d3d9.dll
2014-09-16 16:22:39 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2014-09-16 16:22:39 ----A---- C:\Windows\system32\SearchFolder.dll
2014-09-16 16:22:38 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2014-09-16 16:22:38 ----A---- C:\Windows\system32\VSSVC.exe
2014-09-16 16:22:38 ----A---- C:\Windows\system32\gpsvc.dll
2014-09-16 16:22:38 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2014-09-16 16:22:37 ----A---- C:\Windows\system32\dwmcore.dll
2014-09-16 16:22:37 ----A---- C:\Windows\system32\dbgeng.dll
2014-09-16 16:22:36 ----A---- C:\Windows\system32\drivers\http.sys
2014-09-16 16:22:35 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2014-09-16 16:22:35 ----A---- C:\Windows\system32\actxprxy.dll
2014-09-16 16:22:34 ----A---- C:\Windows\SYSWOW64\ole32.dll
2014-09-16 16:22:34 ----A---- C:\Windows\system32\termsrv.dll
2014-09-16 16:22:34 ----A---- C:\Windows\system32\qmgr.dll
2014-09-16 16:22:34 ----A---- C:\Windows\system32\audiosrv.dll
2014-09-16 16:22:33 ----A---- C:\Windows\system32\sqmapi.dll
2014-09-16 16:22:33 ----A---- C:\Windows\system32\mstsc.exe
2014-09-16 16:22:32 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2014-09-16 16:22:32 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2014-09-16 16:22:32 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2014-09-16 16:22:32 ----A---- C:\Windows\system32\winhttp.dll
2014-09-16 16:22:32 ----A---- C:\Windows\system32\netlogon.dll
2014-09-16 16:22:32 ----A---- C:\Windows\system32\imapi2fs.dll
2014-09-16 16:22:31 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2014-09-16 16:22:31 ----A---- C:\Windows\system32\wbengine.exe
2014-09-16 16:22:31 ----A---- C:\Windows\system32\setupapi.dll
2014-09-16 16:22:31 ----A---- C:\Windows\system32\rpcss.dll
2014-09-16 16:22:31 ----A---- C:\Windows\system32\QAGENTRT.DLL
2014-09-16 16:22:31 ----A---- C:\Windows\system32\propsys.dll
2014-09-16 16:22:30 ----A---- C:\Windows\system32\werconcpl.dll
2014-09-16 16:22:30 ----A---- C:\Windows\system32\taskeng.exe
2014-09-16 16:22:30 ----A---- C:\Windows\system32\odbc32.dll
2014-09-16 16:22:29 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-09-16 16:22:29 ----A---- C:\Windows\system32\user32.dll
2014-09-16 16:22:28 ----A---- C:\Windows\system32\WSDApi.dll
2014-09-16 16:22:28 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-09-16 16:22:28 ----A---- C:\Windows\system32\drivers\netbt.sys
2014-09-16 16:22:28 ----A---- C:\Windows\system32\dhcpcore.dll
2014-09-16 16:22:28 ----A---- C:\Windows\system32\certmgr.dll
2014-09-16 16:22:27 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-09-16 16:22:27 ----A---- C:\Windows\system32\tsmf.dll
2014-09-16 16:22:27 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2014-09-16 16:22:26 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2014-09-16 16:22:26 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\shlwapi.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\netshell.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\msdtctm.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\framedynos.dll
2014-09-16 16:22:25 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2014-09-16 16:22:25 ----A---- C:\Windows\system32\ws2_32.dll
2014-09-16 16:22:25 ----A---- C:\Windows\system32\wmicmiplugin.dll
2014-09-16 16:22:25 ----A---- C:\Windows\system32\netcfgx.dll
2014-09-16 16:22:24 ----A---- C:\Windows\system32\lsm.exe
2014-09-16 16:22:24 ----A---- C:\Windows\system32\comdlg32.dll
2014-09-16 16:22:23 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\wmpps.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\Query.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\drvstore.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\apphelp.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2014-09-16 16:22:22 ----A---- C:\Windows\system32\wpdshext.dll
2014-09-16 16:22:22 ----A---- C:\Windows\system32\Vault.dll
2014-09-16 16:22:22 ----A---- C:\Windows\system32\QAGENT.DLL
2014-09-16 16:22:22 ----A---- C:\Windows\system32\cmd.exe
2014-09-16 16:22:22 ----A---- C:\Windows\system32\BFE.DLL
2014-09-16 16:22:22 ----A---- C:\Windows\system32\azroles.dll
2014-09-16 16:22:21 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2014-09-16 16:22:21 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2014-09-16 16:22:21 ----A---- C:\Windows\system32\samsrv.dll
2014-09-16 16:22:21 ----A---- C:\Windows\system32\lpksetup.exe
2014-09-16 16:22:21 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2014-09-16 16:22:20 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2014-09-16 16:22:20 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2014-09-16 16:22:19 ----A---- C:\Windows\SYSWOW64\Query.dll
2014-09-16 16:22:19 ----A---- C:\Windows\system32\sxs.dll
2014-09-16 16:22:19 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\upnp.dll
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\Wldap32.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\taskcomp.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\pnidui.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\mfds.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\mcbuilder.exe
2014-09-16 16:22:18 ----A---- C:\Windows\system32\ipsmsnap.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\hgprint.dll
2014-09-16 16:22:17 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2014-09-16 16:22:17 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2014-09-16 16:22:17 ----A---- C:\Windows\system32\webservices.dll
2014-09-16 16:22:17 ----A---- C:\Windows\system32\SessEnv.dll
2014-09-16 16:22:16 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\winsta.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\sqlsrv32.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\fveapi.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\dot3api.dll
2014-09-16 16:22:12 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2014-09-16 16:22:12 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2014-09-16 16:22:12 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2014-09-16 16:22:12 ----A---- C:\Windows\system32\prncache.dll
2014-09-16 16:22:12 ----A---- C:\Windows\system32\mcmde.dll
2014-09-16 16:22:12 ----A---- C:\Windows\system32\drivers\volsnap.sys
2014-09-16 16:22:12 ----A---- C:\Windows\system32\drivers\msrpc.sys
2014-09-16 16:22:11 ----A---- C:\Windows\SYSWOW64\userenv.dll
2014-09-16 16:22:11 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\WMNetMgr.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\wlanpref.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\vpnike.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\schtasks.exe
2014-09-16 16:22:10 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2014-09-16 16:22:10 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2014-09-16 16:22:10 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\userenv.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\photowiz.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\evr.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\drivers\rdbss.sys
2014-09-16 16:22:10 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2014-09-16 16:22:09 ----A---- C:\Windows\SYSWOW64\cmd.exe
2014-09-16 16:22:09 ----A---- C:\Windows\system32\wmpmde.dll
2014-09-16 16:22:09 ----A---- C:\Windows\system32\sppobjs.dll
2014-09-16 16:22:09 ----A---- C:\Windows\system32\IPSECSVC.DLL
2014-09-16 16:22:09 ----A---- C:\Windows\system32\FXSSVC.exe
2014-09-16 16:22:09 ----A---- C:\Windows\system32\framedyn.dll
2014-09-16 16:22:09 ----A---- C:\Windows\system32\AudioSes.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\WMPEncEn.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\wmpeffects.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\SyncCenter.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\srvsvc.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-09-16 16:22:07 ----A---- C:\Windows\system32\shsvcs.dll
2014-09-16 16:22:07 ----A---- C:\Windows\system32\fde.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\propsys.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\mfds.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2014-09-16 16:22:06 ----A---- C:\Windows\system32\WinSATAPI.dll
2014-09-16 16:22:06 ----A---- C:\Windows\system32\stobject.dll
2014-09-16 16:22:06 ----A---- C:\Windows\system32\netdiagfx.dll
Run by Feri at 2014-09-19 01:38:50
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 272 GB (60%) free of 455 GB
Total RAM: 3894 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:38:58, on 19. 9. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\Users\Feri\Downloads\CoreTemp32\Core Temp.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\Feri\AppData\Local\Temp\Install_18638\delay.exe
C:\Program Files\trend micro\Feri.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: 2657e500f3e90131a4e91fb939dcadf40061913 - {11111111-1111-1111-1111-110611191113} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: HP SimplePass Identity Protection Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\dpotspluginie8.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: WinToFlash Suggestor - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - (no file)
O9 - Extra 'Tools' menuitem: WinToFlash Suggestor options - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - (no file)
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Documention Flash Card Detection Service (hpdoccardsvc) - Hewlett-Packard Developement Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\doccardsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10854 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\vcsFPService.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"C:\Program Files\DigitalPersona\Bin\DpHostW.exe"
"taskhost.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
taskeng.exe {78539D4B-C035-41CC-8BFA-618FCF96985B}
"C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" /background
"C:\Users\Feri\Downloads\CoreTemp32\Core Temp.exe"
"C:\Program Files\Hewlett-Packard\HPToneControl\HPToneCtl.exe"
"C:\Program Files\Java\jre6\bin\jusched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files\DigitalPersona\Bin\DPAgent.exe"
"C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
HydraDM64.exe -h:65992 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe" KMPProcess
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Bluetooth®: Disabled
WLAN: Disabled</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_off.ico</IconPath><ID>1552689904</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
C:\Users\Feri\AppData\Local\Temp\Install_18638\delay.exe /S /MAG=smtycdelay /PIXGUID=3029b78f-ab04-42c9-809e-225120539caa
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"taskhost.exe"
/QuitInfo:000000000000075C;00000000000005BC;
"C:\Users\Feri\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\6563fb0e-3562-4199-a0a7-ee44667f7754-11.job - C:\Program Files (x86)\Senses\6563fb0e-3562-4199-a0a7-ee44667f7754-11.exe /rawdata=cPxZ4xyXv3AZZtOLhG1WgwfbkjTNnTdzAl+R4/JNnKz7AXSKaR8Z4KvJHdCEV8wVN3m0pZwHM19adBdeMG6l4LkpTe85+F9IKExrMROi6nlNDYXuTNIveBm5OpiinEvjKoFkOn0cvr2coCvEYI4swexBdisE1STgr0Gy0oxEnxhPEFyTQ8lW232CqeG0nBj5TVj1c4+j1TIT+/UGAACRBjNdBMOOLn3GGtdyo7D2JbOGciar22utFz4xFCrcPp25KJJAmjVi0xBA5tecQJdWYzS/F2szCS9+jgaHgnBOsIEtuq1bMvOt/CPtj6Xf61ZWgBx1aqt8x5MZOEhnOHSjQiI8DzhCwA4AtR0vSOqNqVUTHTamlyoXW/Zi13W8jZiPsROHqdyfZ7o13c761edd5SjMXywH1it3c//+RiMbKVjwZ+9fHw5w/aKTN4M+rLbzH0EoYdYpkg9OUOSfuAlHg/LxGw3W/UJDbF8iaY4uBCRAUUfPSoZfUKCSP7b3fGlQxaqRyL8IX0KzAWRRyTfoyaSQYcQebUyqWJnnqHNjhDnECNSoOLl52+lvvKMlMlH99k3iBGn0Uq/C/XfnFJ0rUwTObtRjaz4eJjha3d0rSoHlkY0Xi5bZAb01pOGKLQ88E3YIMn1JKG2pqSIxgdyOFo3XVxjk8mubJl8DUDqpdwuku2KUtTj0DFVYYfugaJRpBfLdP0kFMLcPrwKQXBid59Zj0jK0V2BVDjKdJ+LqwjDPChcv8z+yIPZRlnedQD2UwFY9VMGyajgl2ny9CKUnV9iScACjK0TSW1CHoKHdigu0L3U2/wkNslJ+rTINFEKf650zIovVsVVz4PG48IQt8mFpxnArtKnNOfL/Fi6afiuAcnv1gisGPh/A2UzOB1u41o5aKXU4GN+qr7We6efkaL5pxJXONhVPYW17oJmq87mYcFZavrH+ElXKLubWi9vHjWqP9yRRzuw8v8qWvU3QZxF/SpNFNXgegD/9RkoeSCnear0MwzkQ47W+AbpQ6CqvvfU4q8GLNdWgF82LrstLM1XhaV3XNxHMOWuMKgHCF4xm80FVnewqDdDBF250iz0gDEcpwJ4Ss01BQsLM1M7Iu+oFC3Lw7vKlDmDzt75WtmHUiGfeLwuilsoYLjUtg79+BQNim5+N137WxeHXrm+mRfgIyMocdVeCVAxu+HHL4I2A8YBqiHheGiT6aQw8+l2+ea8RuqniPD3N6PwB6+PLCP+wGMk0+X706rwzT9snR+3yFDjhuSATxK84yXFxsilWnpazC7kBd/JtF2eVXjzqI4oC9FOQkP5jzlzxZ9Ja+2NoXnDNNFq6uqyNM8CSR07GrD6yqR4cty3UZ8QaIoGeo4BcDKX2+TOyg+ffktUT5RuHdTtwhrJo5Xjn5vXF7AYoiwygbqVg3to5hOprTUUI1a1VIbx6xVPHp2IJRcyHjEELOWZ9NJ036IjLp27AmG8pxd9gCJPsjNXvfB7TG9Y7MB6C4CP2ZyU4If1wypQIicIomKV/QSvitSdxLL5hgGg3oJzuDSMtzEqHyFl04ZnnKrHtsY/7m4LVIJ1z8YZznNskdgbgP/hp757hHs2rHDln1VZC/kQwH7CIboAl2AOklph8KI849ZhDPtlN+rXKA5x+7iJsHwVhQ4TREwJe4YV0RhflR7G6ANqmag+jQfe15KQbvfOBlb3r13EsYtqTTSxepaHXjnlRV6wl5p/kdpMXP2aHQwHWHHtJ1jiQnzgQ/FxyM0vy6+Ip6qySHGgoBrr87GGj1oziaT1SJZBrZyJUSYqQ5hDcwtfyWZpExQ/hOR9nvbypSSXxcX9H/a00xuCcIDmm6PicORFK+9Sg864N5XRZvWvGNqB5Kxv5Mo3ITYLcCzQvJyMgqlUloQXA7gEyqd6lStgrpJPU7Pv5nn7+n8cODAo+LuVwq6OQvG2Qe3KRLgjPZUp5NctKa6XRtItwvA4w+rbAqtK64rcw2GSRkdrY2FrNBy/4k89RWHlKGfyKeHt4nkomz1aU7pVhqJBxWgI2poc/C7yG+AoBtZP7OSsucMVjCaQBBInpivUjqm7xsBQZlKfPvci3uWVSZSoE9SrZHKJMVg/Kck2I5t6UTDIUY4zJdK1LkFwJQeP83utzc+yr8sjGTs/ynC9vcr+/kdOt3LBsVMGGJUUY+LhMjVE1YSBAfxr9P69Z7PoMMdxl89kQAt/eQe+vvHWfttc=
C:\Windows\tasks\6563fb0e-3562-4199-a0a7-ee44667f7754-3.job - C:\Program Files (x86)\Senses\6563fb0e-3562-4199-a0a7-ee44667f7754-3.exe /rawdata=KobGJht2gTYWhzOxKEtHXc1Jrh83/ltFmpXHEBdiyFFmT55kK95U1XfEuBUutNw5JYqgMJDZ5zKGBmvkI5c9d68S8H1sv7AfdQ1/4XLYJLnRZoOFPdBsG0j7yHNuvksyqmBnDB4dKtf10exmNY/i+tgoT5sNCj7nT+bsJVQZ6OsW4a1SZzN/uRFgVgM9EG5i4F+aQbX3H2XGuo6bKeEQYLnBNIB3kVFc3DbiLKRwcIsQHmF1NeyUMX6s1u76S9JRIK0g48m9N5b9N1oWe9lx55gLiQDiX77gxZwN4HaWEMbQmSCPrvybge9bxZIk5KesiWpW1+MHDNUAmp598LBEZKPkFj6wm5WN8pauhE3zVFChTMH4kOJVmqOgbAYLsu2x27ZfGbiU0HDoZ5B4AVQvvJAGtN98kTTxFa4dBk9hQ1Fol4mCv5Eie5ghcXYkvdRugX5cSz8dnz2Jd5eFxyKu9Lv3Vl+Jmkcupaag7vFaK2KUQ15BmfuKMGrv+jyjaLiifqVMw66/YcDNJOO+3QLrntZH89vuVKXVx/7c1gdGuoa28QDNNXte/z0e/UiJ585oPmEDPEsGp2XVkFsHBMc4/NJpDIALv00wJgZ0r1+5VEE/VQTIUliHDiArDdmYY0acRG4y/qWs7yMJEKzWAgnlahE4sDfib+vORUPsjkuEHfO2MyZfADUdey3kEaJUACZNxhjXGanR/c/788xoxriA7k7Xmz+Jjb2DgbWamkC+nTGLyR6KiQ/pdrg/vZT8KkTKqnmvJxbteUr4XGDTWgji91DCdq8/3ZwHvSwLMC6gpSThE7YSRNmoHbt8hvjjxaU2KhAHFSlAzChR1lO/NjEGRIcqbfXfokHtApORGC2adjF2jVnxO7Ovwm+PBprutdJyHCgNxkMVWXxso8ohKXG/K/Dee4hMAijhs6CxjB2ryDOyyvo9qjN4A8bNZjKDPhkLOFYw5UBIYesuBMptfMyyEEghREhVLICE+wryx5lXPU1qsOG70sNFY7FVyoQj6MQMWdJ2O1BDSihjTskm8z/IySu8WVVCLZ5VxxTo8/s3FzaP2/tSRBHYy3k2fR4blXtll8Q5OLbwwyiwHFIR8phJ/EsvTIS00EG0AFfNNIXhOjYGjDqDRP6u0LLspj/WPZ1Tf5i8K/+4YvbsR0HWc0wkx8Rb6CExcmlHR/gao3yRCTSG6W1RMEvQcp7PLtO99pa/zQeRnahM4KVGwkK5uCu4GAbXIaKtvDAw/8Ig5yHovMZoUiUAJDoGtL1I3AaT5ePHMKqpuwVld20PnxuZefYl1rL4NRhlJWk+ycdHhygJHK0VVctH5BBsOpbbIEBlyXp82uqadZy7wYO1XtEV2K4THA==
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /rawdata=hb2JFSOlZimKckdaPFosDzlwxkLwGPKkF5nob7XzDDHC0XXA/12a5pLU0P9KCJAgxbSOtGglRqIfkWMcHXtbAc2VRXU7sl35U5/ixQXuiDyRJZOvlgZ6xPPoeD2JTQNbyu6VroVXPLPAGg17Iolr/6InyV0Wx1vQDmfQFrgxVE7ExE2NN4xiksmXJ0CONt6K44FFOk1RXlmh25A+HBknM5ZYXmxEDW0MUnNUbPZ9HTSpfJKQ0bEhgezBuARRxduuLixmjNG66Z4xmH1kiga26d2tetqCqLI+2sZ72Lr6hoJO/1MeRhamn0NHaI9cbWXa8m8sOWtVXLZ3bxAVnGJ4JyXG3nbMdyG+LHOy413PMLM+axUihQ++dgZe+tQhowrt3RTx/6KyfcH8LHh4dhIMDvdcnWE6m5cZRnQBnBu6WVYRRHTO4av5Lzeu10urLnDYFphMDa6LZxfaE73pWlQB+xlajlIO09IPrl/TFCDNY0YzgLw4wEVi6d5FBLoTASSTsGDjPRc/ECqImEoz4MXuVOq9er0VlzmWfu1Vgbe50HR5Hzi6sShby/wZ0yMy4Kf0dfkfdY//9xsz+Mf/X2qySnLA7iJ2XsiyC92khE4W73gR4WPdqJs8v5LPopu8nk2FKYKn7yhlfc2S4icq/hqQcvdtxcDhEf8JwEhUzQwjUBJfH+H6N+N9kt5kCNFAdjCJjhpoQ2MDHYnHmS+OvmQqV7jbxQS9uUIJltU0ZwcxV49YAmXMbGT0m3zZPJULCANt6tMMwOHGAKyYQwcwLQPkf3lz5/JcQEXo73bcw76s0/JyqIuYsM5j+loFePX7Bw99QmycZBzTd2NmvH+ZRSWzIy5gdO0EDsVzLvREORcvYgDmJn/Hr9E7E+Tw0hCyNW462c33VLXnIJv5PH0HySXEBiWAb7N/au3h3Ec02gbfY+eYpKki9eUwkkgTXEldBomFv3WZLzRiHD8mlGks2aOO7QNIN61IE9M3GJrNc2aaN6uicgl3UIJRHi3TSBemIghdL5s/UtLPdxbtwe5tPSULKhaQ/HTr3h3qJBM3Z6QZqtM5HlLroGP3jOjb96IRYNXWqmk90cCU0noP/l6FZcQREaW/FEi+qwhn+HOoySSyP8s5EBp7kmKCgXYJxFEZVpq3PkaTA6FvfhhUDodek+UTE6e3IScQioAUmOCAuagv++lRkEa6I3agSuIp5Hts5v+IVrHycnkXZuc0oGBCLVQ5VZJXPvJloD8Lt1qQyr2AvLKOqjCOZnG4BU5R7xmQd4GJJ78UQUCGPxWpCLIZuc7YkNRpn+bRlAShE/UyS493UFR9g83ZPnru790pxtB3iNrLRzdtbpFnQDBC9p9/CpXPpQ==
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-11.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-11.exe /rawdata=tkSD2/0/fVBqDiiPqs5gMcGc5taRaFZW32RCLSae+mWHPSlfT7oPBpA1JlF6no/OtoCPEwTgayWtBilWvBgmu+jrHPFOAJOzYcPuuu7Q8z9gVkV7UbLbVJVjyUktWCeNuAnykr7NGLp3SCColGWLX4VUP2e/Zh/dUCt2XyfEK2+a7NORBqdSkUZ10fZKQzY5fJbYctuU4Smm/nBEKXOOpY86AhjLYF4WtgW2DZ/4NRpBL6yk4HIKxgjAr4rFVflgY6rzS83kO4HXdzHCoMxoPUc5PGzVfjGdh+8gbidD+gP596Q34XAs3o8J+yyoBKcyBeCkvYC6E45hh18XGUd3sXWPdxpyjX/v6ewhtMc+gl9s/OuVuQa0KVNkqv8s+R5k2sVAN3lF1snMMCZddMrGaRiKlBBJCX2bNmX1eEfdxN0LcSQUDLOlE2kilbJR/VFmIrzQKcCd6lfrouVKg1DXAjy5bDhIV61cPwSsJSUfQFJGCTom4LFIP+YLBgQFKn6BR9tqnMyPGD8bMH/kN3pL8Q+a1cKT+RwtlL8QOUiJKKIC+nKfEPCVY76jAgcHRUCb8kyC+2dtG2ql7lNKssdJ//GJayFvk1ZNGwE3qb5AuHQaeM9txsliSWuGmYLX1djQe+WIZQYt0H9hMTQaE8jyG323s9BJWelyx3ZSRUo3R1aigvshGMfdT0rWlyrYYJ946aNNf2OsdKI0w+ejXXHCqvnMFMYCJuZ3hs9F0+JAJdEwY3dtf6VXGLQ3dXRZTG9dR07PA56UwJxYjdVNKsEU/BPs3TOvap0AKpNJTI6ZYAV0HvLUim/kWGhpBntpc/JgtOdVz4MyDSpRDvBR0vU2USOhT0WvkDhYfto0uLJTZLmrXnbjzfLMN6GhpfPgDKPLeNTv/FXpnQPEiA4q2m9ua7TCJVPVT2VYfO9i/8DUVxt/IWNZtCJHYawnRmqwk5doS2AA/9Wm3ssTkKvMFUuj0NtYXZhDcVnN47S5KMp5iDwiIQ+yoVKxQCQXu/5zaRLSA2ZPd9xe1lL5GVBSvErtn+JiqdSzzYQ/brvplnqHLN8fdKLN3zgAbtmGckkAVq87G0/93EE5fzjgVyy9mCn8F2P5Ito6r1k/jemDYwDujh0waoYnkUkVUO/wOlCee1RNFZqd5CjaJDU4wpu1I65Yb96iMBXtLp2iBnglD0HVRuWVks3HwiYL4GiH/Y4b5DeO12aI7/8KZU119l6vHFtz9F+I/v6dLMWXRoC6BGNogUm7dk8InQ14V81rZY4Ku4OSTyJGQ2vcdJempRjx6PLHYO6DfY6jY4hBNQ/Du6b+fCRxf2gMsm6o/Q3Ftwe8IjmdL320XzVtxQgCQc4pKgsUkjPW7roLbWEzIP8EaFt7UM4NMyVwIyrTNWrryOJBv1LunXDgc4sNEGBrvJnc2yLtCcIJSpYHX5xQRrZHWLHLZZDXXOBW3ViC0RzCfEj04TULxmxOZ8CsrrYt7lUJAdOVH5SCGnwyryGhk4Q6iN4ivLWcPUOUitFCT6VVVN24+qcoiU1pqOkdMU40r6uRPCc1mH2LYU1NbFGxMU5oBXZ6APsB5uc1i9/L/3tuGbfZpLecr2tT/FsJxOw+YD5qrUj4DuK78QpU4aDTVGeefoVglYxxRa731lprLYBdKR2VayG0TQYvWbQ2Z9zLBjz/dGO0sMyHAn5Msgpj2BjiwBfSh8AP0FgFOjqOmcIm2yZqrmGV0p0tvNLF0UQ8akfNgkRErZ8x9CDc315xrM77Cz6KLXvH7ujLImm94oY1Ey6OYuvtLuPaYwi8cFeBuB0nPHpOxWFWkA9ybQMdXjo5MXY1tJmZuO+ctK3o1qrfGIui0jwoOSxkREO/9b1uuk55llZ4UKYM9UaVyCBXe0+3roaMpePcfUf62GB+akF42wCgphk6fOFK+vtBQQDPntzqmRHTd1Ntu7lNp4PWJ1PY6zujV5SKTWFDXFwKGaGSV8C5e8tRjuen3G5Xrs36ZGBF/DIGV48naN7rOeqD9LdO0Cf0RMp5eE4voPTQdxfgBUZPpFtPnUO2UAVe4YphaT0okS/tpLeRIDNXklQPv9+y4VaQk3jXRsSguEVFLE/9Q7zOElfzHP5IscujjIFxvhx6s+rB/3AAqUw7BAhFgvu5VLzkQ9Hww2e31zOPp7vpW3Tu4xofMqkeCgvAdxIOBc1deVRORx7HJa3OVBKLHzWzwOXK2Xo=
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-2.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-2.exe /rawdata=ZpEpDeFKA0in4DJjIfC8Y7k4037MecGan2d++XTmPMPTcGcypvibf3QQkKm0vBYs8vjkjmu1Io9hFaOV3x8L5VdTCKsdT1FIq8ebPoOtEhLPZAL5Hnz+Fe51tx6Ev9aivesUz4ROtSHIUUdYh3wYRwvNR/pnDLDM7apq+5YBJ9RZkAFqgpklpCAluHalwkOvzu2qj/5n47lRS6jPyXxJcERG77oJd/YRltGVrBI9IuChX0+Y/Sq86IgoSuA8Ye5DIRJrzxKUDzTr9gentmOULIJuaYQ+7SSsX+s1BWZIs19XedGxAgo4KagdxsnQ/t4236me4B3xGU91+nXWWtNcJKytSIwnjPOwawfF+nerQuVpGqZB4RorHTOPoBDeOysA+tLSqn5eVcoaLlsOq1btOOcKhVWZzQlqPtBP++tMxN+JTUQzkxuKcMHjDL3cOATt29133nJexPwlLBP0oLaxaMdtL3bfYOc+idRu1VFGIssGqK0QCYaGTMJlAhN139sOO8791ovBTmo7rhh8lBZR6iUGclXR1bSHiZEtp6/hFzxDkP191mlvai3TtM/AuuTOi0IZxzGpNhFXNadoS/iDXW2F5GwDPNFiFhU6knQ3kQQMsyuk09e8TizfWOQl4dbwCXk2Xh1yl+Pd8f/UJXXLt54A/3B5u1WrtVNQU9wDh0QQCiA43zlCuz/jDnptyOPkd7yTuKr/DX01QTbnCQiNJsUkgl5W6lTeNOUftHwGsXj97E8DJEIxIGktN4XlYyWwqQB6YiP8aMLCivrOjBCP+Jgv+JXtb/GcJk4loCaTV8jqjq8kqoP2xHh+xuPGdwgge+Tnv0diEn96l5h9Vm2yV4Ri9HRCXUQV7Ul+F7BL7YSOPNNhXTd5BYXBT+aRY1eDx6GJ0O6aJR0xO5NkwXDdOr05EuDqXfIf4xx7Ii+zViKWfuLK/ExPay2x4gSpBN7403w0yFU6DLUjh0K3Pqt2AFfqR8JwXOEKuTyKKf/hR3MukVG8FFka8wKf6yoK8EZr
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-4.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-4.exe /rawdata=kAJwYS1BvM8Ta/FAIYwC7sOqf0wBUtAjJZahcox/MGykY3rIf/YyfU6vXFLKvDyiOMKI9nMAM6ivxyhHRq+n/CXQ2EhGju6wEuaXbn4Fm6VWzZq99Ke3fmgRpqJde5XGFyX2uKKJ68OZcbq5hKWVs9jsCSZITuCTQzofTTI/011am5bNDp9z26/FLvI+a9oms0rX7EzbdS+aqMcD6bLpOQaj8xYxgpokCaSe5crulwaLL4cnQajLJkR4lYxLVURGaieo3jDg5FbyPp5rHUFnW4P/sAJbBC/RzU7hDaMkL+P0I9cHSJa3HceMCjIVfwuLw8oTVCbIO32DUHJluuxM6WaIdJFB0XEJ/l1UcJA3VWJsCn6WaCZ7EOHo754DyJJGvyT012WjU2Sk1o/oELAeK/LSBdcTHVW5W2mI3vcNMax1m+LLKUJsIiM2H7BlT5/75tgX7VT6L/8TZBMVoClto2p7Kg74ui1pX/6AUAcYMToO3HeOqthFwh2WIMuzOOgkvZP/BW0iDCwU976tYavvVA1CMv3SmSCnwPGxgjkkLXyf2LdTAl5nDfZSJXoyMmrG1e09fx7UVE+yyfdsPW+swky0dKcTE4hIrm8+ZyheWexhk78j64Rf1T6HKcUxKrQLZhG/YAymiX6UJ0D5a7J2rQgfKDxYRcoqNO7Xbm3T+ZgCMWE5tIeeX5Qwnab5+CD4GsfAhFv6GIrNaYz/RiKQ3uSuXwWITbyaFdr4EId7voIBIl7p+N4xx7OZI6v/CjkQhksTVbErvNOgyX6vEKrkOWmjkyS7fFzn2NL+g69ACTL/GGvTn4YmTAGZC1Cf1wk9SmIaoAnbmA3vt4CakuaIWE+EHaF4lSlUhp8bvmg1feRYJdieI90YNq14ZJQfUpK6ukzxAT8tEfA1gcRw3mpGN7bn9uhMuuYVuQoHx4YknhQGR0dK9UfPClO31u3+/Yb5fM5qeG6JB+RXmWt2AJvNfMthHn9v0dpFrzPxcRQSdxFATQnJ1T5hShOR+r+zC5cwe0CPyviQ4sj8ESZn4zoj8NC4zb0IljqCJOb/HYe+P6n+4uQYzSyor93Ux3h0DeciDAiDMVGnopM4mq2aM4lHIsz9gKcin6Mx+jFHCLtMxaYQ7mIgXt/qd5A55u/Qk2ze7QqFesnmFS+tkqIuhbj5alk+FpV+YlEmbpKr9uhw33VHPgFR77MNsAq05oiP2YYpZGLJ7+CNPF/dy5gVYmhNY9msR9xut2OT+RabK/R2aOlhHwGW0b4JyBeyc8/jKw28JsjD/t22Kds3RZXIlPpgrPY/9FyWDwVK3DAtsii2OYNpHoKCFQj8Vq9PV1MTpPWs8QIIcasrVdrp+RU75tD+0XR+PRdHtrCOK+sZSfCWFuNdKTH1u/K0k1ApAczt6JeT3OujAjosJuu57fQ0WxT/GIUPZyICJ3kePcs63MR9ZvM/CnaZIC31WdIQNBJn5jZ+1ZzWbYe79sG8AZLtu2eCpbe6BkMMPQtcpnFPgKECw6Ppxu75V2QZYNYY8mCCuJtOi7ijgoKoCpAzTX3u7QX3FQ6HX4y8+jJEl8hLJ0+ZwfGpHVdhQ6bfV44P3F8DkscuiB3QqchZE77KfSDzNUiO4JGBJ3XulIYfagA9oFkMtCOUTtnm3yWb413WTdeC1G+QqfVVrwe5K5skA1LPCTYjbrav60s1cd5FkW2yghKjIciIiHoIc/B0UDbQ5+8GfOmaIfmPtgo6e+K17xU+PdgAgSwhU6NudL2fJBksbG9f4aqK6H2HXq/lB9i3nSq6SwrtCCT4YMzEK0F20Fq7qUGRKzHxzwZ4r63CnHLDlQCNVBSWy3XN6JVl1vTh0S6pMlDhvLULmJ6Bbq6lWwBsLUoH7w==
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-6.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-6.exe /rawdata=OMGC5d6znlN6zMyfLI6Pn4G2DkDDOKypvh7RZgY/zCuRfGqljLxaZOnnISp9tuPBFsYTUYCmJ3SDffbz/YcRwV7f8FcKaL/DEUCh6mtC2D9jzTFbLT0TgTQAusyA9JhHRvlKuRxLgXUxfCpVGYMlnT9g6hO13y56jhf+ySiFpo5H+phXlceLacbiAVospmpQsnw1y5N/hL15C/tvyY/kuHZx2zxrk5gxqLZzUcysBCbbfzzhQRSNYZJKMqkdTOZ8HXmN2iM5nVzoAHbGC1zXtuKPk2sERD1aFUSrSMwWZvvAGyUIPS3yfmbMskYrPNo9wr3Jat7kK1uHsSxpUm+xyJHeQwQxk/bjVTNiqBgpf6w+TVPwR4LFIOq1iTC5sKreYdCbk3pMN7KCdl8SihJqZ0dLDDEkruv8Fi4Fu8C8xmZoAC+LJ45QX08XZjmVNiSVvY4byfhaomJREFEGWc1D8x161GWPabMj9f2uE5cq4/4iDdHymri9HMSMoDOdsLpumyJtOjO2ngoW/tSO21xNVF/IFnNnKmCxvVSbvMskj4r9d4oT9ZCvBGShSiRfGzDQr3xIYS9JYtzc538qo2mm6dHjGZE9wWTEt1ULY1C53E/WXBykN+kJVPhoRXq+fWKgRaxeMjhEKHWhSF+xQKZ2QLVzDY7yRcgaeDqVRvbzjyiEFch2TeZa0jGMwOUdeIld5hANc80eFuTE+VSQN4+4bdt1KJgtrTlybV2v+Mboo9wcO6YxucymM8PO/oqjacK0uECTpSDNcYmHoHNk5r40UAvH1S0ai9HLOgbBBNDnTjPed+iMq1G+8yAHiiVEYwyaAelZjP+JwWWOzXon2Z649Ke4/dWv79W7biWXQyExJvE6or9oQoAs2q1lPo38bNx7TQ3vTMK85hrezrpqqSjTawwZyDtl1wQ6MgGCCCT7qC0QRkJUDKrA9SFdLUdDnmy67d7+LFXWYO3O2ckXstg9uWFzpOpSr2418ESPxDqa3mnJoF/Fbv0vULCnTBmCUF6dc7o8q+nM90Y3RxXLIJEO349UQBKEEixcs0JgMfY4EJsviht9mgMFRplIEJhUGpLjF0nmHTLqzbBZhCFES7iDjbFcpsvTx9kokISCBzQf02DwrL4w4XDLTjzek3LaIkXZbeB5sUBYVWgIi2FgdQCtV7akARtaFx1bdFRlXWotZ8+PUDn5t3o4f3OylRG8hjREkjauhoEhj4Wxj3+0TtioXtcRvxqlQPXjqJEfwFD1aHUBGElndHhwmy4M/L6oEOUsTiRS3hS1Acz1kfeQ+ufO/LfJAkiRkDFHkg1j3LuXcoXwbjLkwuzqT+3e0sMzk3I+oW8cDciLZiB1mjc0o2Sp11/BuuTWHA/NekGsI/8bj/XNx1ICFT7LcDENzLFFHcV3Ca3io07lIIWjODhY6BDbXa4MubskgjtxvwWE4umkZ4Mtb6AQE+7XDVLeLRuAcIahWWZreAhPgZXAiTEE8hSBv9DNGyXKqyOuU3wglwy1tJFJfWc++FWflj15LkLfSsJbgo9nOYJZ15aJAf8ZTSzHDcYwamA0fDRxstfffXrZ+9Kct9hsxps/4B0ea1QCTut1MZoUyLQmFxjhjWqyBV0eP1Ko7AjkH4WJ7qxMDOi7YKDwsqFvFsecPcF0UaojnCDG8E0quzaxtlcMRBWpVEM+sGbkPgo4CpPv0UjUSRJbp4c=
C:\Windows\tasks\c94697dc-6b6d-478f-bddd-348b413d6a2a-7.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-7.exe /rawdata=GkyhJQZuR7pAaAIwAZQSkqhmGcyulkdCBqnTb0wjp1S/Yo6tAZIgqLIpDmkMgNq1ZCqexkX30VUxkCmEnizLTKnD+2bqJTpy2c9l6Rtrl5njf6SjtcgahRRG9JwcoWATeuwLNHLfkj/dWrsrqhZM7r9p67miel6C0VwItI3NeVWd91Tqsf6ZDzPJWMFx22qJb7JGpqA4HJDgUJ556ZYdjEow5rOeVrw0VF/sbgbdH0RU7uMWNoJw6kHUDTQIw7WJRvBGRtUYzgTD0WHIIC6dio8gv4bEirSzkNLqXAMAuRKa6rWqQ43KLgmYtFK43q/KwLeszs0Uh/Ach5D3xoy1GluMD5t+xOzO6TNd8iGvWGwandTnzettryBeUCVZBoKmNu2RaGriwCTFmrXRWAguEeer+hhsyTL2cbqUxSoe4HDowQC83dmRDNqGRphLXUl0ET0lZQZXSb6cajHVOxT+/PM6ymfZmjxYwysMqUkTL3nuh+b5FYEXGsEn5Z6JZe6hL8/yO9ThiDy6jlodtu9SVOj9M7fkW7kfD6Vl7mUHAJ1y1ZA6Ev02fAa2C3Yddo2E8SqLIayW3sZTEIDe4HsWjq2Lb69T2cZ957jcfgM59+adD5XMmu0Iu1ILbuseIHMtQnPEsAvzvNnyJ+uXIexC2Zam3h2a30U/jUqQV+mDttSh+mYoxxrwlUoKExUeRxo/6lr+1dr3pJo/pEOYWMtAy9UvHpTCbVPX+oRKnuCgv9B6DPwiwj4RrGQp7MS3QdyYkC68z5aQRkOkX+SfIORhapvGOeFvbji80Iktsfmv6h/31fMa3f7zgAFugnesdST9DcE7vv2SKvVqTLJ4lQn+FIWdAiJ+bGXb7EY0ecmdxHawVZB35lLyTQP3I9Gwe+m218ggKlHGbUqBU88pAqM4uJh6Pw4iktpm+DXoxYaX+L6DokgtS87dSldlViEyx/iLuZ7ecpA78Oi5aXbjzllrj7i8FTiWP3xLODPWbqM5a96bM5Uuju2Rrp4CbyPsOXqQuJCqonGJMQFQJPxhG5KUTbrURZOgKv0GztMZBNPVgVpufE7C2jTSo28Ga0Kf37Naz2Yuri/N1r8vFDNe65fRqi7HMw4+kMgXmg3nRc51WrSu0/9I34POZokeWji9GKc0KbckGjkqp0eiGvDhXljv4aVtRtM3pg+jO2kCKZZYqO4RmqQ+Sq+L99/r2/XE5DrZ2oU8Yf/pNzfF3q07PoFTYF9iEyo2quwabMYLh6k1CJZvfTR0nlM/kArKXnLBSlsP5QW4+i5fEUSGuOKhTchxeDbdp3NwcXEU1tMQvtC5/0EBqNkzLIekvBd/qJ9XRsEaNPpJ/sqfOVbtEpkRfUhbgXje4WJEqqxBXRTFZTqOg53R6/Bp6t9YfgZh5dMNrRgGgB9lg5T28pCIfpsO6op0kcbPYPzL+iDlDmqxvq2Mrtkb2DmxhtQOM8VRpo2Rk4QY8Imf5IVz+snJ+bGUAZAEVGHeSVXJ0ux8GZyVmY7qXs0Rx/m/QAXnLNDl6hXjRtb0FW7oKxg/L6nNLIBxnobJVBjRe285XyCWl6HvWAzlWEzjTG1cskwsmOuR+BV/g3bcAdqAuzexkWJAPd7dQRdy8dOfk0O6BQ2w0bhR9qP/Ua7Hjm88nTkja3zitGMaa0QlD7ApS7TayZdnuq5opho5L/wSTD6yWLaxXB3Yi9m7C+8=
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\temp_c94697dc-6b6d-478f-bddd-348b413d6a2a-2.job - C:\Program Files (x86)\iWebar\c94697dc-6b6d-478f-bddd-348b413d6a2a-2.exe /rawdata=ZpEpDeFKA0in4DJjIfC8Y7k4037MecGan2d++XTmPMPTcGcypvibf3QQkKm0vBYs8vjkjmu1Io9hFaOV3x8L5VdTCKsdT1FIq8ebPoOtEhLPZAL5Hnz+Fe51tx6Ev9aivesUz4ROtSHIUUdYh3wYRwvNR/pnDLDM7apq+5YBJ9RZkAFqgpklpCAluHalwkOvzu2qj/5n47lRS6jPyXxJcERG77oJd/YRltGVrBI9IuChX0+Y/Sq86IgoSuA8Ye5DIRJrzxKUDzTr9gentmOULIJuaYQ+7SSsX+s1BWZIs19XedGxAgo4KagdxsnQ/t4236me4B3xGU91+nXWWtNcJKytSIwnjPOwawfF+nerQuVpGqZB4RorHTOPoBDeOysA+tLSqn5eVcoaLlsOq1btOOcKhVWZzQlqPtBP++tMxN+JTUQzkxuKcMHjDL3cOATt29133nJexPwlLBP0oLaxaMdtL3bfYOc+idRu1VFGIssGqK0QCYaGTMJlAhN139sOO8791ovBTmo7rhh8lBZR6iUGclXR1bSHiZEtp6/hFzxDkP191mlvai3TtM/AuuTOi0IZxzGpNhFXNadoS/iDXW2F5GwDPNFiFhU6knQ3kQQMsyuk09e8TizfWOQl4dbwCXk2Xh1yl+Pd8f/UJXXLt54A/3B5u1WrtVNQU9wDh0QQCiA43zlCuz/jDnptyOPkd7yTuKr/DX01QTbnCQiNJsUkgl5W6lTeNOUftHwGsXj97E8DJEIxIGktN4XlYyWwqQB6YiP8aMLCivrOjBCP+Jgv+JXtb/GcJk4loCaTV8jqjq8kqoP2xHh+xuPGdwgge+Tnv0diEn96l5h9Vm2yV7MyOb2pRe0+969CBqmvRqq9mUMseSvmrlRph9jJY2YSMEkB6d3o8DASvEv2LQljqG53PcXGRln2NkUP5MUCQMgwBJfCa47TdzuqpZeRPOKDewIamBaE+cB3z4Vo9qIn7PelbvMoQEFXtBR9z8F/xMp0nd1xwOs41ZnZZtFR2MlFr5pGkDGNXuLWHxDCn8B8c/bT5gWztcQpoIX2Mjv999sMLMupTOIhbj5Iph3L+x+nHzsKJv7wt0pzW6DdG+LtBxjN8jwcKIwoAeyAQOATroHLoXZZiuRGINXiyVnEELiFvHvsrx0uCRQVOFY6T3mGV4JanG3rg3apd0s2cmtlMlk=
=========Mozilla firefox=========
ProfilePath - C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\v63wnowc.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
firefox@firefox.sk
urlbox@firefox.sk
C:\Users\Feri\AppData\Roaming\Mozilla\Firefox\Profiles\v63wnowc.default\extensions\
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191113}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho64.dll [2014-09-19 883048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP SimplePass Identity Protection Extension - C:\Program Files\DigitalPersona\Bin\dpotspluginie8.dll [2009-12-30 2213128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-09-11 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-30 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191113}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho.dll [2014-09-19 652648]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP SimplePass Identity Protection Extension - C:\Program Files (x86)\DigitalPersona\Bin\dpotspluginie8.dll [2009-12-30 1262856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-09-11 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-05-30 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-01-22 166424]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-01-22 390680]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-01-22 410136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-04-10 2104104]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-01-14 487424]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2010-01-20 611896]
"HPToneControl"=C:\Program Files\Hewlett-Packard\HPToneControl\HPTonectl.exe [2009-08-19 107832]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-05-30 172032]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-16 8192]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2014-04-17 1967616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easybits Recovery]
C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Envy Guides AutoPlay]
C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\hpdocstart.exe [2010-03-24 76584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-01-22 2363392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintoflashvddc]
[]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2010-05-30 149280]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-09-11 4085896]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-04-17 767200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-01-22 268800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-19 01:38:50 ----D---- C:\rsit
2014-09-19 01:38:50 ----D---- C:\Program Files\trend micro
2014-09-19 01:14:59 ----D---- C:\Program Files (x86)\iWebar
2014-09-19 01:14:10 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-19 01:14:08 ----D---- C:\Program Files (x86)\Senses
2014-09-19 01:03:59 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-09-19 01:02:46 ----D---- C:\AdwCleaner
2014-09-18 14:29:21 ----D---- C:\Windows\Migration
2014-09-18 14:26:31 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-18 14:22:15 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-18 14:22:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-18 12:36:55 ----A---- C:\Windows\explorer.exe
2014-09-18 12:36:54 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-09-18 12:36:53 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-09-18 12:36:53 ----A---- C:\Windows\system32\WMPhoto.dll
2014-09-18 12:36:52 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-18 12:36:52 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-18 12:36:42 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-09-18 12:36:42 ----A---- C:\Windows\system32\d2d1.dll
2014-09-18 12:36:24 ----A---- C:\Windows\system32\drivers\bthport.sys
2014-09-18 12:36:23 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2014-09-18 12:36:19 ----A---- C:\Windows\system32\fsutil.exe
2014-09-18 12:36:19 ----A---- C:\Windows\system32\esent.dll
2014-09-18 12:36:18 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-09-18 12:36:18 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-09-18 12:36:18 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-09-18 12:36:18 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-09-18 12:36:17 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2014-09-18 12:36:17 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-09-18 12:36:17 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-09-18 12:36:17 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-09-18 12:32:16 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-09-18 12:32:16 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-09-18 12:32:15 ----A---- C:\Windows\system32\spoolsv.exe
2014-09-18 12:32:15 ----A---- C:\Windows\splwow64.exe
2014-09-18 12:14:07 ----D---- C:\Windows\system32\MRT
2014-09-18 12:14:00 ----A---- C:\Windows\system32\MRT.exe
2014-09-18 12:05:29 ----D---- C:\Windows\SYSWOW64\Wat
2014-09-18 12:05:29 ----D---- C:\Windows\system32\Wat
2014-09-18 03:06:05 ----A---- C:\Windows\system32\wmploc.DLL
2014-09-18 03:06:04 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-09-18 03:06:04 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-09-18 03:06:02 ----A---- C:\Windows\system32\wmp.dll
2014-09-18 01:54:11 ----D---- C:\7dfe590c07e7d46d901171a242b9
2014-09-18 01:50:22 ----A---- C:\Windows\system32\IEUDINIT.EXE
2014-09-18 01:44:46 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\wextract.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\url.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\occache.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msls31.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\inseng.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\icardie.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-18 01:44:40 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\wininet.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\wextract.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\webcheck.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\urlmon.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\url.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msrating.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msls31.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\mshtmler.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msfeedssync.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\licmgr10.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jsIntl.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\jscript9.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\inseng.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iexpress.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieui.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iesysprep.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iesetup.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iertutil.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iernonce.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieframe.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ieapfltr.dat
2014-09-18 01:44:40 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-18 01:44:40 ----A---- C:\Windows\system32\icardie.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\elshyph.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-18 01:44:40 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\vbscript.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\pngfilt.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\occache.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\mshtml.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\mshta.exe
2014-09-18 01:44:39 ----A---- C:\Windows\system32\jscript.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\imgutil.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-18 01:44:39 ----A---- C:\Windows\system32\iepeers.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-18 01:44:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-09-18 01:41:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2014-09-18 01:41:53 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\XpsPrint.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\UIAnimation.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\FntCache.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\dxgi.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\DWrite.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10level9.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10_1.dll
2014-09-18 01:41:53 ----A---- C:\Windows\system32\d3d10.dll
2014-09-18 01:00:50 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-09-18 01:00:49 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-09-18 01:00:49 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-09-18 01:00:49 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-09-18 01:00:47 ----A---- C:\Windows\system32\WUDFx.dll
2014-09-18 01:00:47 ----A---- C:\Windows\system32\WUDFHost.exe
2014-09-18 01:00:47 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-09-17 23:58:53 ----D---- C:\d5a25a2c76fd5f6abe6105ffd152
2014-09-17 23:56:04 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-09-17 23:56:04 ----A---- C:\Windows\system32\wmi.dll
2014-09-17 23:56:04 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-09-17 20:41:55 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-09-17 20:41:55 ----A---- C:\Windows\system32\infocardapi.dll
2014-09-17 20:41:54 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-09-17 20:41:54 ----A---- C:\Windows\system32\icardagt.exe
2014-09-17 20:41:53 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-09-17 20:41:53 ----A---- C:\Windows\system32\icardres.dll
2014-09-17 20:41:30 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-09-17 20:41:30 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-09-17 18:58:02 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2014-09-17 18:58:02 ----A---- C:\Windows\system32\xmllite.dll
2014-09-17 18:57:55 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-09-17 18:57:55 ----A---- C:\Windows\system32\msieftp.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbctrac.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbccu32.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbccr32.dll
2014-09-17 18:57:54 ----A---- C:\Windows\system32\odbccp32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2014-09-17 18:57:53 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2014-09-17 18:57:52 ----A---- C:\Windows\system32\wwansvc.dll
2014-09-17 18:57:52 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-09-17 18:57:49 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-09-17 18:57:49 ----A---- C:\Windows\system32\comctl32.dll
2014-09-17 18:57:41 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2014-09-17 18:57:41 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2014-09-17 18:57:41 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2014-09-17 18:57:41 ----A---- C:\Windows\system32\dhcpcore6.dll
2014-09-17 18:57:36 ----A---- C:\Windows\system32\mstscax.dll
2014-09-17 18:57:35 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-09-17 18:57:35 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2014-09-17 18:57:34 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-09-17 18:57:34 ----A---- C:\Windows\system32\tsgqec.dll
2014-09-17 18:57:34 ----A---- C:\Windows\system32\aaclient.dll
2014-09-17 18:57:18 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-09-17 18:57:18 ----A---- C:\Windows\system32\wintrust.dll
2014-09-17 18:57:07 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2014-09-17 18:57:07 ----A---- C:\Windows\system32\CPFilters.dll
2014-09-17 18:57:06 ----A---- C:\Windows\system32\sbe.dll
2014-09-17 18:57:05 ----A---- C:\Windows\SYSWOW64\sbe.dll
2014-09-17 18:56:59 ----A---- C:\Windows\SYSWOW64\quartz.dll
2014-09-17 18:56:59 ----A---- C:\Windows\system32\quartz.dll
2014-09-17 18:56:57 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-09-17 18:56:57 ----A---- C:\Windows\system32\qdvd.dll
2014-09-17 18:56:49 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2014-09-17 18:56:49 ----A---- C:\Windows\system32\ntshrui.dll
2014-09-17 18:56:39 ----A---- C:\Windows\system32\tquery.dll
2014-09-17 18:56:38 ----A---- C:\Windows\SYSWOW64\tquery.dll
2014-09-17 18:56:38 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2014-09-17 18:56:38 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2014-09-17 18:56:38 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-09-17 18:56:38 ----A---- C:\Windows\system32\mssrch.dll
2014-09-17 18:56:37 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2014-09-17 18:56:37 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2014-09-17 18:56:37 ----A---- C:\Windows\SYSWOW64\mssph.dll
2014-09-17 18:56:37 ----A---- C:\Windows\system32\SearchFilterHost.exe
2014-09-17 18:56:37 ----A---- C:\Windows\system32\mssvp.dll
2014-09-17 18:56:37 ----A---- C:\Windows\system32\mssphtb.dll
2014-09-17 18:56:37 ----A---- C:\Windows\system32\mssph.dll
2014-09-17 18:56:36 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2014-09-17 18:56:36 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2014-09-17 18:56:36 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2014-09-17 18:56:36 ----A---- C:\Windows\system32\msscntrs.dll
2014-09-17 18:56:35 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2014-09-17 18:56:07 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-09-17 18:56:07 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-09-17 18:56:06 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-09-17 18:56:05 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-09-17 18:56:05 ----A---- C:\Windows\system32\usp10.dll
2014-09-17 18:56:03 ----A---- C:\Windows\SYSWOW64\webio.dll
2014-09-17 18:56:03 ----A---- C:\Windows\system32\webio.dll
2014-09-17 18:56:01 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-17 18:56:01 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-17 18:51:01 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-09-17 18:51:01 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-09-17 18:51:01 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-09-17 18:51:01 ----A---- C:\Windows\system32\cryptsvc.dll
2014-09-17 18:51:01 ----A---- C:\Windows\system32\cryptnet.dll
2014-09-17 18:51:01 ----A---- C:\Windows\system32\crypt32.dll
2014-09-17 18:50:52 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-09-17 18:50:52 ----A---- C:\Windows\system32\wer.dll
2014-09-17 18:50:51 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-09-17 18:50:51 ----A---- C:\Windows\system32\imagehlp.dll
2014-09-17 18:50:50 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-09-17 18:50:50 ----A---- C:\Windows\system32\drivers\netio.sys
2014-09-17 18:50:50 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-09-17 18:49:49 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-09-17 18:49:49 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-09-17 18:49:49 ----A---- C:\Windows\system32\msxml6.dll
2014-09-17 18:49:49 ----A---- C:\Windows\system32\msxml3.dll
2014-09-17 18:49:48 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-09-17 18:49:48 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-09-17 18:49:48 ----A---- C:\Windows\system32\msxml6r.dll
2014-09-17 18:49:48 ----A---- C:\Windows\system32\msxml3r.dll
2014-09-17 18:48:47 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-09-17 18:48:47 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-09-17 18:48:42 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-09-17 18:48:42 ----A---- C:\Windows\system32\osk.exe
2014-09-17 18:48:33 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-09-17 18:48:28 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-09-17 18:48:28 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-09-17 18:48:28 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-09-17 18:48:28 ----A---- C:\Windows\system32\credui.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\lpk.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-09-17 18:48:18 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\lpk.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\fontsub.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\dciman32.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\atmlib.dll
2014-09-17 18:48:18 ----A---- C:\Windows\system32\atmfd.dll
2014-09-17 18:48:17 ----A---- C:\Windows\system32\mfc42u.dll
2014-09-17 18:48:17 ----A---- C:\Windows\system32\mfc42.dll
2014-09-17 18:48:16 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2014-09-17 18:48:16 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\secproc_isv.dll
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-09-17 18:48:12 ----A---- C:\Windows\system32\RMActivate.exe
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-09-17 18:48:11 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\secproc.dll
2014-09-17 18:48:11 ----A---- C:\Windows\system32\msdrm.dll
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-09-17 18:47:43 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-09-17 18:47:42 ----A---- C:\Windows\system32\d3d11.dll
2014-09-17 18:47:41 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2014-09-17 18:47:39 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2014-09-17 18:47:39 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-09-17 18:47:34 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-09-17 18:47:34 ----A---- C:\Windows\system32\qedit.dll
2014-09-17 18:47:26 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-09-17 18:47:26 ----A---- C:\Windows\system32\rdpwsx.dll
2014-09-17 18:47:26 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-09-17 18:47:24 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-09-17 18:47:22 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-09-17 18:47:22 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-09-17 18:47:18 ----A---- C:\Windows\system32\drivers\afd.sys
2014-09-17 18:47:17 ----A---- C:\Windows\system32\Wdfres.dll
2014-09-17 18:47:17 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-09-17 18:47:17 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-09-17 18:44:42 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-09-17 18:44:40 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2014-09-17 18:44:40 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2014-09-17 18:44:40 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\nlasvc.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\netcorehc.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\ncsi.dll
2014-09-17 18:44:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-09-17 18:44:39 ----A---- C:\Windows\SYSWOW64\netevent.dll
2014-09-17 18:44:39 ----A---- C:\Windows\system32\nlaapi.dll
2014-09-17 18:44:39 ----A---- C:\Windows\system32\netevent.dll
2014-09-17 18:44:39 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-09-17 18:44:28 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-09-17 18:44:28 ----A---- C:\Windows\system32\tzres.dll
2014-09-17 18:44:24 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-09-17 18:44:24 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-09-17 18:44:23 ----A---- C:\Windows\system32\profsvc.dll
2014-09-17 18:44:22 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2014-09-17 18:44:22 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2014-09-17 18:44:22 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-09-17 18:44:22 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-09-17 18:44:22 ----A---- C:\Windows\system32\dnsapi.dll
2014-09-17 18:43:40 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-09-17 18:43:40 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-09-17 18:43:40 ----A---- C:\Windows\system32\WebClnt.dll
2014-09-17 18:43:40 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-09-17 18:43:40 ----A---- C:\Windows\system32\davclnt.dll
2014-09-17 18:43:39 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-09-17 18:43:39 ----A---- C:\Windows\system32\dpnet.dll
2014-09-17 18:43:36 ----A---- C:\Windows\system32\msi.dll
2014-09-17 18:43:35 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-09-17 18:43:35 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-09-17 18:43:35 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-09-17 18:43:35 ----A---- C:\Windows\system32\msihnd.dll
2014-09-17 18:43:35 ----A---- C:\Windows\system32\consent.exe
2014-09-17 18:43:35 ----A---- C:\Windows\system32\authui.dll
2014-09-17 18:43:35 ----A---- C:\Windows\system32\appinfo.dll
2014-09-17 18:43:17 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-09-17 18:43:16 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-09-17 18:43:16 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-09-17 18:43:15 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-09-17 18:43:15 ----A---- C:\Windows\system32\winlogon.exe
2014-09-17 18:43:15 ----A---- C:\Windows\system32\objsel.dll
2014-09-17 18:43:15 ----A---- C:\Windows\system32\KernelBase.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-09-17 18:43:14 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-09-17 18:43:14 ----A---- C:\Windows\system32\smss.exe
2014-09-17 18:43:14 ----A---- C:\Windows\system32\dimsroam.dll
2014-09-17 18:43:14 ----A---- C:\Windows\system32\cngprovider.dll
2014-09-17 18:43:14 ----A---- C:\Windows\system32\adprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\wincredprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\csrsrv.dll
2014-09-17 18:43:13 ----A---- C:\Windows\system32\capiprovider.dll
2014-09-17 18:43:11 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-09-17 18:43:11 ----A---- C:\Windows\system32\apisetschema.dll
2014-09-17 18:43:02 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-09-17 18:41:58 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-09-17 18:41:58 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-09-17 18:41:58 ----A---- C:\Windows\system32\drivers\srv.sys
2014-09-17 18:41:57 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-09-17 18:41:57 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-09-17 18:41:56 ----A---- C:\Windows\system32\cdd.dll
2014-09-17 18:41:53 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-09-17 18:41:52 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2014-09-17 18:41:52 ----A---- C:\Windows\system32\mswsock.dll
2014-09-17 18:41:44 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-09-17 18:41:44 ----A---- C:\Windows\SYSWOW64\gameux.dll
2014-09-17 18:41:44 ----A---- C:\Windows\system32\Wpc.dll
2014-09-17 18:41:44 ----A---- C:\Windows\system32\gameux.dll
2014-09-17 18:41:26 ----A---- C:\Windows\system32\psisdecd.dll
2014-09-17 18:41:25 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-09-17 18:41:23 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-09-17 18:40:37 ----A---- C:\Windows\SYSWOW64\tdh.dll
2014-09-17 18:40:37 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-09-17 18:40:37 ----A---- C:\Windows\system32\tdh.dll
2014-09-17 18:40:37 ----A---- C:\Windows\system32\ntdll.dll
2014-09-17 18:40:37 ----A---- C:\Windows\system32\advapi32.dll
2014-09-17 18:40:36 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-09-17 18:40:32 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-09-17 18:39:49 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-09-17 18:39:49 ----A---- C:\Windows\system32\iologmsg.dll
2014-09-17 18:39:49 ----A---- C:\Windows\system32\drivers\storport.sys
2014-09-17 18:39:49 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-09-17 18:39:49 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-09-17 18:39:42 ----A---- C:\Windows\system32\schannel.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-09-17 18:39:41 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\wdigest.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\TSpkg.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\ncrypt.dll
2014-09-17 18:39:41 ----A---- C:\Windows\system32\msv1_0.dll
2014-09-17 18:39:40 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-09-17 18:39:40 ----A---- C:\Windows\system32\credssp.dll
2014-09-17 18:39:33 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-09-17 18:39:33 ----A---- C:\Windows\system32\synceng.dll
2014-09-17 18:39:27 ----A---- C:\Windows\system32\winresume.exe
2014-09-17 18:39:27 ----A---- C:\Windows\system32\winload.exe
2014-09-17 18:39:27 ----A---- C:\Windows\system32\kdusb.dll
2014-09-17 18:39:27 ----A---- C:\Windows\system32\kd1394.dll
2014-09-17 18:39:26 ----A---- C:\Windows\system32\kdcom.dll
2014-09-17 18:39:21 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-09-17 18:39:21 ----A---- C:\Windows\system32\shdocvw.dll
2014-09-17 18:39:12 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-09-17 18:39:12 ----A---- C:\Windows\system32\win32spl.dll
2014-09-17 18:39:11 ----A---- C:\Windows\system32\taskhost.exe
2014-09-17 18:38:22 ----A---- C:\Windows\system32\shell32.dll
2014-09-17 18:38:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-09-17 18:38:18 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-09-17 18:38:18 ----A---- C:\Windows\system32\cryptdlg.dll
2014-09-17 18:38:10 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\devobj.dll
2014-09-17 18:38:09 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2014-09-17 18:37:48 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-09-17 18:37:48 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-09-17 18:37:47 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-09-17 18:37:47 ----A---- C:\Windows\system32\netapi32.dll
2014-09-17 18:37:47 ----A---- C:\Windows\system32\browser.dll
2014-09-17 18:37:47 ----A---- C:\Windows\system32\browcli.dll
2014-09-17 18:37:46 ----A---- C:\Windows\SYSWOW64\browcli.dll
2014-09-17 18:37:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-09-17 18:37:45 ----A---- C:\Windows\system32\wow64win.dll
2014-09-17 18:37:45 ----A---- C:\Windows\system32\wow64.dll
2014-09-17 18:37:45 ----A---- C:\Windows\system32\kernel32.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-09-17 18:37:44 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-09-17 18:37:44 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-09-17 18:37:44 ----A---- C:\Windows\system32\wow64cpu.dll
2014-09-17 18:37:44 ----A---- C:\Windows\system32\winsrv.dll
2014-09-17 18:37:44 ----A---- C:\Windows\system32\ntvdm64.dll
2014-09-17 18:37:44 ----A---- C:\Windows\system32\conhost.exe
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-09-17 18:37:43 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-09-17 18:37:42 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-09-17 18:37:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2014-09-17 18:37:41 ----A---- C:\Windows\SYSWOW64\user.exe
2014-09-17 18:37:39 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2014-09-17 18:37:39 ----A---- C:\Windows\system32\prevhost.exe
2014-09-17 18:37:39 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-09-17 18:37:38 ----A---- C:\Windows\system32\srcore.dll
2014-09-17 18:37:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2014-09-17 18:37:36 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-09-17 18:37:34 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2014-09-17 18:37:34 ----A---- C:\Windows\system32\inetcomm.dll
2014-09-17 18:37:31 ----A---- C:\Windows\system32\msvcrt.dll
2014-09-17 18:37:30 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-09-17 18:37:29 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-09-17 18:37:26 ----A---- C:\Windows\system32\certutil.exe
2014-09-17 18:37:25 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-09-17 18:37:24 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-09-17 18:37:24 ----A---- C:\Windows\system32\certenc.dll
2014-09-17 18:37:08 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-17 18:37:08 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-17 18:37:08 ----A---- C:\Windows\system32\kerberos.dll
2014-09-17 18:37:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-17 18:37:07 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-17 18:36:54 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-09-17 18:36:54 ----A---- C:\Windows\system32\scrrun.dll
2014-09-17 18:36:54 ----A---- C:\Windows\system32\cscript.exe
2014-09-17 18:36:53 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-09-17 18:36:53 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-09-17 18:36:53 ----A---- C:\Windows\system32\wscript.exe
2014-09-17 18:36:48 ----A---- C:\Windows\system32\lsass.exe
2014-09-17 18:36:48 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-09-17 18:36:48 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-09-17 18:36:48 ----A---- C:\Windows\system32\drivers\cng.sys
2014-09-17 18:36:47 ----A---- C:\Windows\system32\sspisrv.dll
2014-09-17 18:36:47 ----A---- C:\Windows\system32\sspicli.dll
2014-09-17 18:36:47 ----A---- C:\Windows\system32\secur32.dll
2014-09-17 18:36:26 ----A---- C:\Windows\system32\localspl.dll
2014-09-17 18:36:25 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-09-17 18:36:25 ----A---- C:\Windows\system32\win32k.sys
2014-09-17 18:36:25 ----A---- C:\Windows\system32\gdi32.dll
2014-09-17 18:36:24 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-09-17 18:36:22 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-09-17 18:36:22 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-09-17 18:36:22 ----A---- C:\Windows\system32\oleaut32.dll
2014-09-17 18:36:22 ----A---- C:\Windows\system32\oleacc.dll
2014-09-17 18:36:20 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-09-17 18:36:20 ----A---- C:\Windows\system32\EncDec.dll
2014-09-17 18:35:52 ----A---- C:\Windows\system32\aepdu.dll
2014-09-17 18:35:52 ----A---- C:\Windows\system32\aeinv.dll
2014-09-17 18:35:49 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2014-09-17 18:35:48 ----A---- C:\Windows\system32\cdosys.dll
2014-09-17 18:34:00 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-09-17 18:34:00 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-09-17 18:34:00 ----A---- C:\Windows\system32\nshwfp.dll
2014-09-17 18:34:00 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-09-17 18:34:00 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-09-17 18:33:58 ----A---- C:\Windows\system32\scavengeui.dll
2014-09-17 18:33:55 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-09-17 18:33:55 ----A---- C:\Windows\system32\rpcrt4.dll
2014-09-17 18:32:58 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-09-17 18:32:58 ----A---- C:\Windows\system32\packager.dll
2014-09-17 16:56:08 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2014-09-17 16:56:08 ----A---- C:\Windows\system32\rdpcore.dll
2014-09-17 16:56:08 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wups2.dll
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wucltux.dll
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wuaueng.dll
2014-09-17 16:46:13 ----A---- C:\Windows\system32\wuauclt.exe
2014-09-17 16:46:01 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-09-17 16:46:01 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-09-17 16:46:01 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-09-17 16:46:01 ----A---- C:\Windows\system32\wups.dll
2014-09-17 16:46:01 ----A---- C:\Windows\system32\wudriver.dll
2014-09-17 16:46:01 ----A---- C:\Windows\system32\wuapi.dll
2014-09-17 16:45:52 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-09-17 16:45:52 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-09-17 16:45:52 ----A---- C:\Windows\system32\wuwebv.dll
2014-09-17 16:45:52 ----A---- C:\Windows\system32\wuapp.exe
2014-09-16 17:46:56 ----D---- C:\Windows\system32\SPReview
2014-09-16 17:46:16 ----D---- C:\Windows\system32\EventProviders
2014-09-16 16:23:15 ----A---- C:\Windows\system32\netfxperf.dll
2014-09-16 16:23:15 ----A---- C:\Windows\system32\dfshim.dll
2014-09-16 16:23:08 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-09-16 16:23:03 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-09-16 16:23:03 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-09-16 16:22:58 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2014-09-16 16:22:58 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2014-09-16 16:22:58 ----A---- C:\Windows\system32\sysmain.dll
2014-09-16 16:22:56 ----A---- C:\Windows\system32\MSVidCtl.dll
2014-09-16 16:22:54 ----A---- C:\Windows\system32\mscoree.dll
2014-09-16 16:22:53 ----A---- C:\Windows\system32\mmcndmgr.dll
2014-09-16 16:22:52 ----A---- C:\Windows\system32\xpsservices.dll
2014-09-16 16:22:52 ----A---- C:\Windows\system32\mf.dll
2014-09-16 16:22:49 ----A---- C:\Windows\system32\schedsvc.dll
2014-09-16 16:22:49 ----A---- C:\Windows\system32\ole32.dll
2014-09-16 16:22:48 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2014-09-16 16:22:48 ----A---- C:\Windows\system32\spwizui.dll
2014-09-16 16:22:47 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\wevtsvc.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\taskschd.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\RacEngn.dll
2014-09-16 16:22:47 ----A---- C:\Windows\system32\diagperf.dll
2014-09-16 16:22:46 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2014-09-16 16:22:46 ----A---- C:\Windows\system32\vssapi.dll
2014-09-16 16:22:46 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2014-09-16 16:22:46 ----A---- C:\Windows\system32\ExplorerFrame.dll
2014-09-16 16:22:45 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-09-16 16:22:44 ----A---- C:\Windows\system32\UIRibbon.dll
2014-09-16 16:22:42 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2014-09-16 16:22:42 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2014-09-16 16:22:42 ----A---- C:\Windows\system32\WsmSvc.dll
2014-09-16 16:22:42 ----A---- C:\Windows\system32\WMVCORE.DLL
2014-09-16 16:22:42 ----A---- C:\Windows\system32\rdpdd.dll
2014-09-16 16:22:42 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2014-09-16 16:22:42 ----A---- C:\Windows\system32\PresentationHost.exe
2014-09-16 16:22:41 ----A---- C:\Windows\system32\spreview.exe
2014-09-16 16:22:41 ----A---- C:\Windows\system32\spinstall.exe
2014-09-16 16:22:41 ----A---- C:\Windows\system32\MPSSVC.dll
2014-09-16 16:22:41 ----A---- C:\Windows\system32\CertEnroll.dll
2014-09-16 16:22:40 ----A---- C:\Windows\system32\WinSAT.exe
2014-09-16 16:22:40 ----A---- C:\Windows\system32\d3d9.dll
2014-09-16 16:22:39 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2014-09-16 16:22:39 ----A---- C:\Windows\system32\SearchFolder.dll
2014-09-16 16:22:38 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2014-09-16 16:22:38 ----A---- C:\Windows\system32\VSSVC.exe
2014-09-16 16:22:38 ----A---- C:\Windows\system32\gpsvc.dll
2014-09-16 16:22:38 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2014-09-16 16:22:37 ----A---- C:\Windows\system32\dwmcore.dll
2014-09-16 16:22:37 ----A---- C:\Windows\system32\dbgeng.dll
2014-09-16 16:22:36 ----A---- C:\Windows\system32\drivers\http.sys
2014-09-16 16:22:35 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2014-09-16 16:22:35 ----A---- C:\Windows\system32\actxprxy.dll
2014-09-16 16:22:34 ----A---- C:\Windows\SYSWOW64\ole32.dll
2014-09-16 16:22:34 ----A---- C:\Windows\system32\termsrv.dll
2014-09-16 16:22:34 ----A---- C:\Windows\system32\qmgr.dll
2014-09-16 16:22:34 ----A---- C:\Windows\system32\audiosrv.dll
2014-09-16 16:22:33 ----A---- C:\Windows\system32\sqmapi.dll
2014-09-16 16:22:33 ----A---- C:\Windows\system32\mstsc.exe
2014-09-16 16:22:32 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2014-09-16 16:22:32 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2014-09-16 16:22:32 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2014-09-16 16:22:32 ----A---- C:\Windows\system32\winhttp.dll
2014-09-16 16:22:32 ----A---- C:\Windows\system32\netlogon.dll
2014-09-16 16:22:32 ----A---- C:\Windows\system32\imapi2fs.dll
2014-09-16 16:22:31 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2014-09-16 16:22:31 ----A---- C:\Windows\system32\wbengine.exe
2014-09-16 16:22:31 ----A---- C:\Windows\system32\setupapi.dll
2014-09-16 16:22:31 ----A---- C:\Windows\system32\rpcss.dll
2014-09-16 16:22:31 ----A---- C:\Windows\system32\QAGENTRT.DLL
2014-09-16 16:22:31 ----A---- C:\Windows\system32\propsys.dll
2014-09-16 16:22:30 ----A---- C:\Windows\system32\werconcpl.dll
2014-09-16 16:22:30 ----A---- C:\Windows\system32\taskeng.exe
2014-09-16 16:22:30 ----A---- C:\Windows\system32\odbc32.dll
2014-09-16 16:22:29 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-09-16 16:22:29 ----A---- C:\Windows\system32\user32.dll
2014-09-16 16:22:28 ----A---- C:\Windows\system32\WSDApi.dll
2014-09-16 16:22:28 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-09-16 16:22:28 ----A---- C:\Windows\system32\drivers\netbt.sys
2014-09-16 16:22:28 ----A---- C:\Windows\system32\dhcpcore.dll
2014-09-16 16:22:28 ----A---- C:\Windows\system32\certmgr.dll
2014-09-16 16:22:27 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-09-16 16:22:27 ----A---- C:\Windows\system32\tsmf.dll
2014-09-16 16:22:27 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2014-09-16 16:22:26 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2014-09-16 16:22:26 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\shlwapi.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\netshell.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\msdtctm.dll
2014-09-16 16:22:26 ----A---- C:\Windows\system32\framedynos.dll
2014-09-16 16:22:25 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2014-09-16 16:22:25 ----A---- C:\Windows\system32\ws2_32.dll
2014-09-16 16:22:25 ----A---- C:\Windows\system32\wmicmiplugin.dll
2014-09-16 16:22:25 ----A---- C:\Windows\system32\netcfgx.dll
2014-09-16 16:22:24 ----A---- C:\Windows\system32\lsm.exe
2014-09-16 16:22:24 ----A---- C:\Windows\system32\comdlg32.dll
2014-09-16 16:22:23 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\wmpps.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\Query.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\drvstore.dll
2014-09-16 16:22:23 ----A---- C:\Windows\system32\apphelp.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2014-09-16 16:22:22 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2014-09-16 16:22:22 ----A---- C:\Windows\system32\wpdshext.dll
2014-09-16 16:22:22 ----A---- C:\Windows\system32\Vault.dll
2014-09-16 16:22:22 ----A---- C:\Windows\system32\QAGENT.DLL
2014-09-16 16:22:22 ----A---- C:\Windows\system32\cmd.exe
2014-09-16 16:22:22 ----A---- C:\Windows\system32\BFE.DLL
2014-09-16 16:22:22 ----A---- C:\Windows\system32\azroles.dll
2014-09-16 16:22:21 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2014-09-16 16:22:21 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2014-09-16 16:22:21 ----A---- C:\Windows\system32\samsrv.dll
2014-09-16 16:22:21 ----A---- C:\Windows\system32\lpksetup.exe
2014-09-16 16:22:21 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2014-09-16 16:22:20 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2014-09-16 16:22:20 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2014-09-16 16:22:19 ----A---- C:\Windows\SYSWOW64\Query.dll
2014-09-16 16:22:19 ----A---- C:\Windows\system32\sxs.dll
2014-09-16 16:22:19 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\upnp.dll
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2014-09-16 16:22:18 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\Wldap32.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\taskcomp.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\pnidui.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\mfds.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\mcbuilder.exe
2014-09-16 16:22:18 ----A---- C:\Windows\system32\ipsmsnap.dll
2014-09-16 16:22:18 ----A---- C:\Windows\system32\hgprint.dll
2014-09-16 16:22:17 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2014-09-16 16:22:17 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2014-09-16 16:22:17 ----A---- C:\Windows\system32\webservices.dll
2014-09-16 16:22:17 ----A---- C:\Windows\system32\SessEnv.dll
2014-09-16 16:22:16 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\winsta.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\sqlsrv32.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\fveapi.dll
2014-09-16 16:22:16 ----A---- C:\Windows\system32\dot3api.dll
2014-09-16 16:22:12 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2014-09-16 16:22:12 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2014-09-16 16:22:12 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2014-09-16 16:22:12 ----A---- C:\Windows\system32\prncache.dll
2014-09-16 16:22:12 ----A---- C:\Windows\system32\mcmde.dll
2014-09-16 16:22:12 ----A---- C:\Windows\system32\drivers\volsnap.sys
2014-09-16 16:22:12 ----A---- C:\Windows\system32\drivers\msrpc.sys
2014-09-16 16:22:11 ----A---- C:\Windows\SYSWOW64\userenv.dll
2014-09-16 16:22:11 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\WMNetMgr.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\wlanpref.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\vpnike.dll
2014-09-16 16:22:11 ----A---- C:\Windows\system32\schtasks.exe
2014-09-16 16:22:10 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2014-09-16 16:22:10 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2014-09-16 16:22:10 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\userenv.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\photowiz.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\evr.dll
2014-09-16 16:22:10 ----A---- C:\Windows\system32\drivers\rdbss.sys
2014-09-16 16:22:10 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2014-09-16 16:22:09 ----A---- C:\Windows\SYSWOW64\cmd.exe
2014-09-16 16:22:09 ----A---- C:\Windows\system32\wmpmde.dll
2014-09-16 16:22:09 ----A---- C:\Windows\system32\sppobjs.dll
2014-09-16 16:22:09 ----A---- C:\Windows\system32\IPSECSVC.DLL
2014-09-16 16:22:09 ----A---- C:\Windows\system32\FXSSVC.exe
2014-09-16 16:22:09 ----A---- C:\Windows\system32\framedyn.dll
2014-09-16 16:22:09 ----A---- C:\Windows\system32\AudioSes.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\WMPEncEn.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\wmpeffects.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\SyncCenter.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\srvsvc.dll
2014-09-16 16:22:08 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-09-16 16:22:07 ----A---- C:\Windows\system32\shsvcs.dll
2014-09-16 16:22:07 ----A---- C:\Windows\system32\fde.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\propsys.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\mfds.dll
2014-09-16 16:22:06 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2014-09-16 16:22:06 ----A---- C:\Windows\system32\WinSATAPI.dll
2014-09-16 16:22:06 ----A---- C:\Windows\system32\stobject.dll
2014-09-16 16:22:06 ----A---- C:\Windows\system32\netdiagfx.dll