Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola po MBAM

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Gilina
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 27 pro 2014 03:11

kontrola po MBAM

#1 Příspěvek od Gilina »

Ahoj,

Potřebovala bych zkontrolovat log z MBAM či to mohu dát do karantény nebo ne.

Předem děkuji Gita :)

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 27.12.2014
Čas skenování: 2:53:42
Protokol: 000.txt
Správce: Ano

Verze: 2.00.4.1028
Databáze malwaru: v2014.12.27.01
Databáze rootkitů: v2014.12.23.02
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Sebeobrany: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: LENOVO

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 298062
Uplynulý čas: 9 min, 40 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 1
Trojan.Downloader, C:\ProgramData\Trusted Publisher\NetEnhance\ContradeTree.exe, 1876, , [2f9e194ee8946bcbde7410bfb84a05fb]

Moduly: 1
PUP.Optional.DeltaFix.A, C:\Program Files\DeltaFix\DeltaFix.dll, , [7d50580ff8840b2b1a9cb3aa48bb38c8],

Klíče registru: 33
Trojan.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\S-2464380207, , [2f9e194ee8946bcbde7410bfb84a05fb],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{3d6bdb04-566c-4bae-8227-9f8b6cb1ef7b}, , [ae1fef78225a0234917c4d8834ce669a],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3D6BDB04-566C-4BAE-8227-9F8B6CB1EF7B}, , [ae1fef78225a0234917c4d8834ce669a],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3D6BDB04-566C-4BAE-8227-9F8B6CB1EF7B}, , [ae1fef78225a0234917c4d8834ce669a],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{3D6BDB04-566C-4BAE-8227-9F8B6CB1EF7B}\INPROCSERVER32, , [ae1fef78225a0234917c4d8834ce669a],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{660b4b1a-9f0f-43e4-a5a0-73d3d94c73a4}, , [745980e71369ae881bb5685c42bf8779],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{660B4B1A-9F0F-43E4-A5A0-73D3D94C73A4}, , [745980e71369ae881bb5685c42bf8779],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{660B4B1A-9F0F-43E4-A5A0-73D3D94C73A4}, , [745980e71369ae881bb5685c42bf8779],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{660B4B1A-9F0F-43E4-A5A0-73D3D94C73A4}\INPROCSERVER32, , [745980e71369ae881bb5685c42bf8779],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{86069dac-31c3-44e7-aa78-f572e65df38f}, , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{86069DAC-31C3-44E7-AA78-F572E65DF38F}, , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\., , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\..10, , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{86069DAC-31C3-44E7-AA78-F572E65DF38F}, , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{86069DAC-31C3-44E7-AA78-F572E65DF38F}\INPROCSERVER32, , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{ae688172-50c1-4c5d-9e74-4927b76c2ee0}, , [9e2f5a0d502c171fb31d784c2bd69c64],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{AE688172-50C1-4C5D-9E74-4927B76C2EE0}, , [9e2f5a0d502c171fb31d784c2bd69c64],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{AE688172-50C1-4C5D-9E74-4927B76C2EE0}, , [9e2f5a0d502c171fb31d784c2bd69c64],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{AE688172-50C1-4C5D-9E74-4927B76C2EE0}\INPROCSERVER32, , [9e2f5a0d502c171fb31d784c2bd69c64],
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}, , [d0fdd493017b45f1e7f05f9e19e8c838],
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C8AAF59A-6BAA-F68B-9470-A856460A8093}, , [d6f7da8d94e87fb76c6bc934ce33be42],
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{6824985F-31D5-9CBE-1EB7-3D7ECDC6356E}, , [7657ec7b146841f5686fcb32ff02a45c],
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{D238A788-39B6-B97D-A5BA-13FE8E34E03C}, , [01ccbaad5c201620b72048b5dc25da26],
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{842C4394-47F7-60DE-480B-C09116B63559}, , [359896d199e31d195d7a66970ef3b64a],
PUP.Optional.Booster.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\S-2464380207, , [daf30463bac22c0a8418e69552b1857b],
PUP.Optional.Booster.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{24c54e38}, , [3598a6c1fc808bab79242c4f4bb89070],
PUP.Optional.DeltaFix.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\24c54e38, , [75586afd0973fc3a90b174eee320df21],
PUP.Optional.DeleteAd.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{37476589-E48E-439E-A706-56189E2ED4C4}_is1, , [2aa3ca9d017b3ef86b3f2a263dc624dc],
PUP.Optional.BuyNSave.A, HKLM\SOFTWARE\CLASSES\CLSID\{8b2cee43-afbc-4d77-a58d-b6628800a1fd}, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, HKLM\SOFTWARE\CLASSES\BuyNsave.BuyNsave, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, HKLM\SOFTWARE\CLASSES\BuyNsave.BuyNsave.9, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{8B2CEE43-AFBC-4D77-A58D-B6628800A1FD}, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{842C4394-47F7-60DE-480B-C09116B63559}, , [65688ed9c1bb9b9b1b225ef829da916f],

Hodnoty registru: 0
(Žádné zákerné zjištěny položek)

Data registru: 2
PUP.Optional.GboxApp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://search.gboxapp.com/, Dobré: (www.google.com), Špatné: (http://search.gboxapp.com/),,[be0f184f2f4d989eda009dd55ea7b24e]
PUP.Optional.GboxApp.A, HKU\S-1-5-21-3704115430-2805409799-3134472837-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://search.gboxapp.com/, Dobré: (www.google.com), Špatné: (http://search.gboxapp.com/),,[dfeea2c5e696f83ec11aec860afb8779]

Složky: 7
PUP.Optional.DeltaFix.A, C:\Program Files\DeltaFix, , [7d50580ff8840b2b1a9cb3aa48bb38c8],
PUP.Optional.MultiPlug.A, C:\ProgramData\50Coupons, , [21ac1453601cd4628d2d8db238cb43bd],
PUP.Optional.MultiPlug.A, C:\ProgramData\RegularDeals, , [3c910d5a730950e60eb0d867f211ce32],
PUP.Optional.DeleteAd.A, C:\ProgramData\DeleteAd, , [2aa3ca9d017b3ef86b3f2a263dc624dc],
PUP.Optional.AllCheapPrice.A, C:\ProgramData\AllCheapPrice, , [d0fd3d2a6b110e282c3f48096f9433cd],
PUP.Optional.BuyNSave.A, C:\Program Files\BuyNsave, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.TakeTheCoupon.A, C:\ProgramData\TakeTheCoupon, , [af1e8bdcef8d2313a0b74a0c0003c23e],

Soubory: 28
Trojan.Downloader, C:\ProgramData\Trusted Publisher\NetEnhance\ContradeTree.exe, , [2f9e194ee8946bcbde7410bfb84a05fb],
PUP.Optional.Multiplug, C:\ProgramData\copunk\i6AvO6kbMvQUqi.dll, , [ae1fef78225a0234917c4d8834ce669a],
PUP.Optional.MultiPlug, C:\ProgramData\coinsave\kIyUsX1PFbGc4E.dll, , [745980e71369ae881bb5685c42bf8779],
PUP.Optional.Multiplug, C:\ProgramData\takesave\bc4Oa43Qlmna0y.dll, , [8c4186e1f78555e1ff0e2ca9ed150df3],
PUP.Optional.MultiPlug, C:\ProgramData\clickit\p9LC9USDb13XoP.dll, , [9e2f5a0d502c171fb31d784c2bd69c64],
Trojan.Agent, C:\ProgramData\clickit\p9LC9USDb13XoP.exe, , [d0fdd493017b45f1e7f05f9e19e8c838],
Trojan.Agent, C:\ProgramData\coinsave\kIyUsX1PFbGc4E.exe, , [d6f7da8d94e87fb76c6bc934ce33be42],
Trojan.Agent, C:\ProgramData\copunk\i6AvO6kbMvQUqi.exe, , [7657ec7b146841f5686fcb32ff02a45c],
Trojan.Agent, C:\ProgramData\takesave\bc4Oa43Qlmna0y.exe, , [01ccbaad5c201620b72048b5dc25da26],
Trojan.Agent, C:\Program Files\BuyNsave\kfgx2Y723UiyL4.exe, , [359896d199e31d195d7a66970ef3b64a],
Trojan.Downloader, C:\Users\LENOVO\AppData\Local\Temp\d8A3D\temp\usetup.exe, , [00cd6afd2e4e4ee8cf839b34cd3517e9],
PUP.Optional.OpenCandy, C:\Users\LENOVO\Downloads\DTLite4491-0356.exe, , [3d902245176505315926931164a1ee12],
PUP.Optional.DeltaFix.A, C:\Program Files\DeltaFix\DeltaFix.dll, , [7d50580ff8840b2b1a9cb3aa48bb38c8],
PUP.Optional.MultiPlug.A, C:\ProgramData\50Coupons\oJQdRo1cHVnsQ3.dat, , [21ac1453601cd4628d2d8db238cb43bd],
PUP.Optional.MultiPlug.A, C:\ProgramData\RegularDeals\45vZllCxKRUihO.dat, , [3c910d5a730950e60eb0d867f211ce32],
PUP.Optional.MultiPlug.A, C:\ProgramData\RegularDeals\45vZllCxKRUihO.tlb, , [3c910d5a730950e60eb0d867f211ce32],
PUP.Optional.MultiPlug.A, C:\ProgramData\RegularDeals\JJa9yDBP0kO3y3.dat, , [3c910d5a730950e60eb0d867f211ce32],
PUP.Optional.DeleteAd.A, C:\ProgramData\DeleteAd\DeleteAd.exe, , [2aa3ca9d017b3ef86b3f2a263dc624dc],
PUP.Optional.AllCheapPrice.A, C:\ProgramData\AllCheapPrice\aHGZwySegfPMo3.dat, , [d0fd3d2a6b110e282c3f48096f9433cd],
PUP.Optional.AllCheapPrice.A, C:\ProgramData\AllCheapPrice\aHGZwySegfPMo3.tlb, , [d0fd3d2a6b110e282c3f48096f9433cd],
PUP.Optional.BuyNSave.A, C:\Program Files\BuyNsave\kfgx2Y723UiyL4.dat, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, C:\Program Files\BuyNsave\kfgx2Y723UiyL4.dll, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, C:\Program Files\BuyNsave\kfgx2Y723UiyL4.exe, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.BuyNSave.A, C:\Program Files\BuyNsave\kfgx2Y723UiyL4.tlb, , [65688ed9c1bb9b9b1b225ef829da916f],
PUP.Optional.TakeTheCoupon.A, C:\ProgramData\TakeTheCoupon\d6Rbd2QM4G23fB.dat, , [af1e8bdcef8d2313a0b74a0c0003c23e],
PUP.Optional.GboxApp.A, C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\Preferences, Dobré: (), Špatné: ( "startup_urls": [ "http://search.gboxapp.com/" ],), ,[27a62d3a89f3f244d1f607ae94711ae6]
PUP.Optional.GboxApp.A, C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\Preferences, Dobré: (), Špatné: ( "homepage": "http://search.gboxapp.com/",), ,[a02df1762c50f046daeec6effb0ae818]
PUP.Optional.GboxApp.A, C:\Users\LENOVO\AppData\Roaming\Mozilla\Firefox\Profiles\d9e719hf.default\prefs.js, Dobré: (), Špatné: (user_pref("browser.startup.homepage", "http://search.gboxapp.com/");), ,[9d300b5c344849ed982c882d1ee7fd03]

Fyzické sektory: 0
(Žádné zákerné zjištěny položek)


(end)

altrok
Moderátor
Moderátor
Příspěvky: 7321
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: kontrola po MBAM

#2 Příspěvek od altrok »

Ahoj,

vsechny nalezy muzes smazat/presunout do karanteny. Mam dost velke podezreni, ze Ti tam jeste havet preziva, takze pokud bude zajem i z Tve strany, dej log z RSIT a kouknem na to poradne ;)

http://forum.viry.cz/viewtopic.php?f=13&t=130786
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Gilina
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 27 pro 2014 03:11

Re: kontrola po MBAM

#3 Příspěvek od Gilina »

Logfile of random's system information tool 1.10 (written by random/random)
Run by LENOVO at 2014-12-27 09:56:12
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 148 GB (59%) free of 250 GB
Total RAM: 3018 MB (45% free)


======Scheduled tasks folder======

C:\Windows\tasks\ContradeTree-S-2464380207.job - c:\programdata\trusted publisher\netenhance\ContradeTree.exe /schedule /profile "c:\programdata\trusted publisher\netenhance\2464380207.ini"
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\LENOVO\AppData\Roaming\Mozilla\Firefox\Profiles\d9e719hf.default

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll


C:\Users\LENOVO\AppData\Roaming\Mozilla\Firefox\Profiles\d9e719hf.default\extensions\
beR@P0h9FE.com
bJ@kkLqk8.org
dhG1UE@B.com
LKY5FoR@4DuN.net

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-03-30 143384]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-03-30 176664]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-03-30 178200]
"IntelWireless"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-01-05 1210640]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-04-08 2229544]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"332BigDog"=C:\Program Files\USB Camera2\VM332_STI.EXE [2010-01-19 536576]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-30 288768]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-12-27 09:51:28 ----D---- C:\Program Files\trend micro
2014-12-27 09:51:26 ----D---- C:\rsit
2014-12-27 02:52:38 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-12-27 02:52:15 ----D---- C:\ProgramData\Malwarebytes
2014-12-27 02:52:15 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2014-12-27 02:52:15 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-12-27 02:52:15 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-12-27 02:52:15 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-12-27 02:11:25 ----D---- C:\Program Files\TeamViewer
2014-12-24 08:25:24 ----D---- C:\ProgramData\takesave
2014-12-24 08:24:43 ----D---- C:\ProgramData\mnfdchpaigacgaomlekgifgeaaiohiml
2014-12-24 08:24:31 ----D---- C:\ProgramData\copunk
2014-12-19 18:55:33 ----D---- C:\Program Files\Mozilla Firefox
2014-12-18 23:07:21 ----D---- C:\Program Files\GameforgeLive
2014-12-18 11:52:36 ----A---- C:\Windows\system32\ieUnatt.exe
2014-12-17 20:26:05 ----D---- C:\ProgramData\LogMeIn
2014-12-17 20:14:36 ----AH---- C:\Windows\system32\hamachi.sys
2014-12-17 19:49:29 ----D---- C:\Users\LENOVO\AppData\Roaming\.technic
2014-12-17 17:55:37 ----D---- C:\Users\LENOVO\AppData\Roaming\java
2014-12-17 17:55:36 ----D---- C:\ProgramData\Sun
2014-12-17 17:55:35 ----D---- C:\Program Files\Common Files\Java
2014-12-17 17:55:28 ----D---- C:\Users\LENOVO\AppData\Roaming\.minecraft
2014-12-17 17:55:27 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2014-12-17 17:55:01 ----D---- C:\ProgramData\Oracle
2014-12-17 17:54:59 ----D---- C:\Program Files\Java
2014-12-15 11:56:42 ----D---- C:\ProgramData\SaveNewaAppz
2014-12-13 21:19:24 ----D---- C:\ProgramData\coinsave
2014-12-13 21:18:18 ----D---- C:\ProgramData\caildhlbbpfbfdempkffgbmjmmkkjdkg
2014-12-13 21:18:06 ----D---- C:\ProgramData\clickit
2014-12-13 03:17:31 ----D---- C:\Windows\system32\appraiser
2014-12-13 03:02:42 ----A---- C:\Windows\system32\mfpmp.exe
2014-12-13 03:02:42 ----A---- C:\Windows\system32\mferror.dll
2014-12-13 03:02:41 ----A---- C:\Windows\system32\rrinstaller.exe
2014-12-13 03:02:41 ----A---- C:\Windows\system32\mfps.dll
2014-12-13 03:02:41 ----A---- C:\Windows\system32\mf.dll
2014-12-13 03:01:13 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-12-12 22:47:50 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-12-12 22:47:49 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-12-12 22:45:29 ----A---- C:\Windows\system32\fsutil.exe
2014-12-12 22:45:29 ----A---- C:\Windows\system32\esent.dll
2014-12-12 22:45:29 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-12-12 22:45:29 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-12-12 22:45:29 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-12-12 22:45:29 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-12-12 22:45:29 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-12-12 22:45:29 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-12-12 22:45:13 ----A---- C:\Windows\system32\appraiser.dll
2014-12-12 22:45:13 ----A---- C:\Windows\system32\aitstatic.exe
2014-12-12 22:45:13 ----A---- C:\Windows\system32\aepic.dll
2014-12-12 22:45:13 ----A---- C:\Windows\system32\aeinv.dll
2014-12-12 22:45:12 ----A---- C:\Windows\system32\invagent.dll
2014-12-12 22:45:12 ----A---- C:\Windows\system32\generaltel.dll
2014-12-12 22:45:12 ----A---- C:\Windows\system32\devinv.dll
2014-12-12 22:45:11 ----A---- C:\Windows\system32\aepdu.dll
2014-12-12 22:44:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-12 22:44:57 ----A---- C:\Windows\system32\jsproxy.dll
2014-12-12 22:44:57 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-12 22:44:57 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-12-12 22:44:57 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-12-12 22:44:56 ----A---- C:\Windows\system32\wininet.dll
2014-12-12 22:44:56 ----A---- C:\Windows\system32\vbscript.dll
2014-12-12 22:44:56 ----A---- C:\Windows\system32\jscript9diag.dll
2014-12-12 22:44:56 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-12-12 22:44:56 ----A---- C:\Windows\system32\dxtmsft.dll
2014-12-12 22:44:54 ----A---- C:\Windows\system32\dxtrans.dll
2014-12-12 22:44:53 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-12-12 22:44:53 ----A---- C:\Windows\system32\mshtmled.dll
2014-12-12 22:44:53 ----A---- C:\Windows\system32\ieui.dll
2014-12-12 22:44:52 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-12-12 22:44:52 ----A---- C:\Windows\system32\iertutil.dll
2014-12-12 22:44:51 ----A---- C:\Windows\system32\jscript9.dll
2014-12-12 22:44:50 ----A---- C:\Windows\system32\mshtml.dll
2014-12-12 22:44:48 ----A---- C:\Windows\system32\urlmon.dll
2014-12-12 22:44:48 ----A---- C:\Windows\system32\iernonce.dll
2014-12-12 22:44:48 ----A---- C:\Windows\system32\iedkcs32.dll
2014-12-12 22:44:48 ----A---- C:\Windows\system32\ieapfltr.dll
2014-12-12 22:44:48 ----A---- C:\Windows\system32\ie4uinit.exe
2014-12-12 22:44:47 ----A---- C:\Windows\system32\msfeeds.dll
2014-12-12 22:44:45 ----A---- C:\Windows\system32\msrating.dll
2014-12-12 22:44:45 ----A---- C:\Windows\system32\iesetup.dll
2014-12-12 22:44:45 ----A---- C:\Windows\system32\ieframe.dll
2014-12-12 22:42:36 ----A---- C:\Windows\system32\tzres.dll
2014-12-12 22:42:06 ----A---- C:\Windows\system32\charmap.exe
2014-12-12 22:42:04 ----A---- C:\Windows\system32\WsmWmiPl.dll
2014-12-12 22:42:04 ----A---- C:\Windows\system32\WsmSvc.dll
2014-12-12 22:42:04 ----A---- C:\Windows\system32\WsmAuto.dll
2014-12-12 22:42:04 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-12 22:42:04 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 18:08:03 ----D---- C:\ProgramData\bpkejbpgaghelchhhcgmhdlkillocmbm
2014-12-10 18:07:50 ----D---- C:\ProgramData\takeorleave
2014-12-09 21:55:13 ----D---- C:\ProgramData\485afbbff108764f
2014-12-09 01:24:13 ----D---- C:\ProgramData\shoppi
2014-12-09 01:23:34 ----D---- C:\ProgramData\dimolfhajnogdghdilipgkdmcfgffpim
2014-12-09 01:23:24 ----D---- C:\ProgramData\takeshop
2014-12-08 16:44:15 ----D---- C:\ProgramData\DigiSaver
2014-12-04 12:31:23 ----A---- C:\Windows\system32\WMPhoto.dll
2014-12-04 12:31:22 ----A---- C:\Windows\system32\d3d10warp.dll
2014-12-04 12:31:07 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-12-04 12:31:07 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-12-04 12:31:07 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-12-04 12:31:07 ----A---- C:\Windows\system32\KBDRU.DLL
2014-12-04 12:31:07 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-12-04 12:31:04 ----A---- C:\Windows\system32\d2d1.dll
2014-12-04 11:51:46 ----A---- C:\Windows\system32\DWrite.dll
2014-12-04 11:06:20 ----D---- C:\Windows\Migration
2014-12-04 10:22:22 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-12-04 10:22:22 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-12-04 10:22:20 ----A---- C:\Windows\system32\WUDFx.dll
2014-12-04 10:22:20 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-12-04 10:22:20 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-12-04 10:22:20 ----A---- C:\Windows\system32\WUDFHost.exe
2014-12-04 10:22:20 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-12-04 10:20:21 ----A---- C:\Windows\system32\infocardapi.dll
2014-12-04 10:20:19 ----A---- C:\Windows\system32\icardres.dll
2014-12-04 10:20:09 ----A---- C:\Windows\system32\icardagt.exe
2014-12-04 10:20:06 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-12-04 10:00:10 ----A---- C:\Windows\system32\wmp.dll
2014-12-04 10:00:09 ----A---- C:\Windows\system32\wmploc.DLL
2014-12-04 09:49:54 ----A---- C:\Windows\system32\wextract.exe
2014-12-04 09:49:54 ----A---- C:\Windows\system32\webcheck.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\url.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-12-04 09:49:54 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-12-04 09:49:54 ----A---- C:\Windows\system32\pngfilt.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\occache.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\msls31.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\mshtmler.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\mshta.exe
2014-12-04 09:49:54 ----A---- C:\Windows\system32\msfeedssync.exe
2014-12-04 09:49:54 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\licmgr10.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\jsIntl.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\jscript.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\inseng.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\imgutil.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\iexpress.exe
2014-12-04 09:49:54 ----A---- C:\Windows\system32\iesysprep.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\iepeers.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\ieapfltr.dat
2014-12-04 09:49:54 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\icardie.dll
2014-12-04 09:49:54 ----A---- C:\Windows\system32\elshyph.dll
2014-12-04 09:48:38 ----A---- C:\Windows\system32\mswsock.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-04 09:45:33 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-04 09:45:33 ----A---- C:\Windows\system32\XpsPrint.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\UIAnimation.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\FntCache.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\dxgi.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\d3d10level9.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\d3d10core.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\d3d10_1.dll
2014-12-04 09:45:32 ----A---- C:\Windows\system32\d3d10.dll
2014-12-03 14:27:36 ----A---- C:\Windows\system32\spoolsv.exe
2014-12-03 14:27:33 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2014-12-03 14:27:33 ----A---- C:\Windows\system32\drivers\bthport.sys
2014-12-03 14:27:33 ----A---- C:\Windows\explorer.exe
2014-12-02 21:11:37 ----A---- C:\Windows\system32\comctl32.dll
2014-12-02 21:11:35 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-12-02 21:11:35 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-12-02 21:11:32 ----A---- C:\Windows\system32\oleaut32.dll
2014-12-02 21:11:20 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-12-02 21:11:19 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2014-12-02 21:11:17 ----A---- C:\Windows\system32\wintrust.dll
2014-12-02 21:11:01 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-12-02 21:11:01 ----A---- C:\Windows\system32\credui.dll
2014-12-02 21:10:14 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-12-02 21:10:14 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-12-02 21:10:14 ----A---- C:\Windows\system32\drivers\srv.sys
2014-12-02 21:10:06 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-12-02 21:09:20 ----A---- C:\Windows\system32\prevhost.exe
2014-12-02 21:09:18 ----A---- C:\Windows\system32\dpnet.dll
2014-12-02 21:09:16 ----A---- C:\Windows\system32\xmllite.dll
2014-12-02 21:09:12 ----A---- C:\Windows\system32\msieftp.dll
2014-12-02 21:08:42 ----A---- C:\Windows\system32\rpcrt4.dll
2014-12-02 21:07:54 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-12-02 21:07:45 ----A---- C:\Windows\system32\pku2u.dll
2014-12-02 21:07:45 ----A---- C:\Windows\system32\kerberos.dll
2014-12-02 21:07:40 ----A---- C:\Windows\system32\dnsapi.dll
2014-12-02 21:07:39 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-12-02 21:07:39 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-12-02 21:07:34 ----A---- C:\Windows\system32\wmi.dll
2014-12-02 21:07:34 ----A---- C:\Windows\system32\imagehlp.dll
2014-12-02 21:07:34 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-12-02 21:07:32 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-12-02 21:07:32 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-12-02 21:07:32 ----A---- C:\Windows\system32\cdd.dll
2014-12-02 21:07:25 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-12-02 21:07:25 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-12-02 21:07:24 ----A---- C:\Windows\system32\objsel.dll
2014-12-02 21:07:24 ----A---- C:\Windows\system32\KernelBase.dll
2014-12-02 21:07:23 ----A---- C:\Windows\system32\wincredprovider.dll
2014-12-02 21:07:23 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-12-02 21:07:23 ----A---- C:\Windows\system32\dimsroam.dll
2014-12-02 21:07:23 ----A---- C:\Windows\system32\cngprovider.dll
2014-12-02 21:07:23 ----A---- C:\Windows\system32\capiprovider.dll
2014-12-02 21:07:23 ----A---- C:\Windows\system32\adprovider.dll
2014-12-02 21:07:13 ----A---- C:\Windows\system32\IMJP10K.DLL
2014-12-02 21:07:12 ----A---- C:\Windows\system32\wscript.exe
2014-12-02 21:07:12 ----A---- C:\Windows\system32\scrrun.dll
2014-12-02 21:07:12 ----A---- C:\Windows\system32\cscript.exe
2014-12-02 21:07:11 ----A---- C:\Windows\system32\msxml6.dll
2014-12-02 21:07:10 ----A---- C:\Windows\system32\msxml6r.dll
2014-12-02 21:07:04 ----A---- C:\Windows\system32\msi.dll
2014-12-02 21:06:54 ----A---- C:\Windows\system32\gdi32.dll
2014-12-02 21:06:52 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-12-02 21:06:48 ----A---- C:\Windows\system32\psisdecd.dll
2014-12-02 21:06:41 ----A---- C:\Windows\system32\msxml3r.dll
2014-12-02 21:06:41 ----A---- C:\Windows\system32\msxml3.dll
2014-12-02 21:06:25 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-12-02 21:06:23 ----A---- C:\Windows\system32\oleacc.dll
2014-12-02 21:06:22 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-12-02 21:06:22 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-12-02 21:06:22 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-12-02 21:06:20 ----A---- C:\Windows\system32\cryptdlg.dll
2014-12-02 21:06:10 ----A---- C:\Windows\system32\rastls.dll
2014-12-02 21:05:49 ----A---- C:\Windows\system32\tdh.dll
2014-12-02 21:05:49 ----A---- C:\Windows\system32\smss.exe
2014-12-02 21:05:49 ----A---- C:\Windows\system32\ntdll.dll
2014-12-02 21:05:49 ----A---- C:\Windows\system32\csrsrv.dll
2014-12-02 21:05:49 ----A---- C:\Windows\system32\advapi32.dll
2014-12-02 21:05:47 ----A---- C:\Windows\system32\EncDump.dll
2014-12-02 21:05:47 ----A---- C:\Windows\system32\audiosrv.dll
2014-12-02 21:05:47 ----A---- C:\Windows\system32\AudioSes.dll
2014-12-02 21:05:47 ----A---- C:\Windows\system32\AUDIOKSE.dll
2014-12-02 21:05:47 ----A---- C:\Windows\system32\AudioEng.dll
2014-12-02 21:05:45 ----A---- C:\Windows\system32\win32k.sys
2014-12-02 21:05:33 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-12-02 21:05:32 ----A---- C:\Windows\system32\wwansvc.dll
2014-12-02 21:05:32 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-12-02 21:05:31 ----A---- C:\Windows\system32\win32spl.dll
2014-12-02 21:05:29 ----A---- C:\Windows\system32\inetcomm.dll
2014-12-02 21:05:28 ----A---- C:\Windows\system32\lpk.dll
2014-12-02 21:05:28 ----A---- C:\Windows\system32\fontsub.dll
2014-12-02 21:05:28 ----A---- C:\Windows\system32\dciman32.dll
2014-12-02 21:05:28 ----A---- C:\Windows\system32\atmlib.dll
2014-12-02 21:05:28 ----A---- C:\Windows\system32\atmfd.dll
2014-12-02 21:05:26 ----A---- C:\Windows\system32\scavengeui.dll
2014-12-02 21:05:21 ----A---- C:\Windows\system32\certutil.exe
2014-12-02 21:05:21 ----A---- C:\Windows\system32\certenc.dll
2014-12-02 21:05:11 ----A---- C:\Windows\system32\schannel.dll
2014-12-02 21:05:10 ----A---- C:\Windows\system32\wdigest.dll
2014-12-02 21:05:10 ----A---- C:\Windows\system32\TSpkg.dll
2014-12-02 21:05:10 ----A---- C:\Windows\system32\ncrypt.dll
2014-12-02 21:05:10 ----A---- C:\Windows\system32\msv1_0.dll
2014-12-02 21:05:09 ----A---- C:\Windows\system32\credssp.dll
2014-12-02 21:04:56 ----A---- C:\Windows\system32\iologmsg.dll
2014-12-02 21:04:56 ----A---- C:\Windows\system32\drivers\storport.sys
2014-12-02 21:04:56 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-12-02 21:04:56 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-12-02 21:04:50 ----A---- C:\Windows\system32\ncsi.dll
2014-12-02 21:04:49 ----A---- C:\Windows\system32\nlasvc.dll
2014-12-02 21:04:49 ----A---- C:\Windows\system32\nlaapi.dll
2014-12-02 21:04:49 ----A---- C:\Windows\system32\netcorehc.dll
2014-12-02 21:04:49 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-12-02 21:04:49 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-12-02 21:04:48 ----A---- C:\Windows\system32\netevent.dll
2014-12-02 21:04:14 ----A---- C:\Windows\system32\mssrch.dll
2014-12-02 21:04:13 ----A---- C:\Windows\system32\tquery.dll
2014-12-02 21:04:13 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2014-12-02 21:04:13 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-12-02 21:04:13 ----A---- C:\Windows\system32\mssph.dll
2014-12-02 21:04:11 ----A---- C:\Windows\system32\SearchFilterHost.exe
2014-12-02 21:04:11 ----A---- C:\Windows\system32\mssvp.dll
2014-12-02 21:04:11 ----A---- C:\Windows\system32\mssphtb.dll
2014-12-02 21:04:11 ----A---- C:\Windows\system32\msscntrs.dll
2014-12-02 21:04:00 ----A---- C:\Windows\system32\cdosys.dll
2014-12-02 21:03:57 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-12-02 21:03:55 ----A---- C:\Windows\system32\qdvd.dll
2014-12-02 21:03:54 ----A---- C:\Windows\system32\srcore.dll
2014-12-02 21:03:43 ----A---- C:\Windows\system32\EncDec.dll
2014-12-02 21:03:41 ----A---- C:\Windows\system32\osk.exe
2014-12-02 21:03:36 ----A---- C:\Windows\system32\netapi32.dll
2014-12-02 21:03:36 ----A---- C:\Windows\system32\browser.dll
2014-12-02 21:03:36 ----A---- C:\Windows\system32\browcli.dll
2014-12-02 21:03:33 ----A---- C:\Windows\system32\d3d11.dll
2014-12-02 21:03:31 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-12-02 21:03:30 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-12-02 21:03:28 ----A---- C:\Windows\system32\sbe.dll
2014-12-02 21:03:28 ----A---- C:\Windows\system32\CPFilters.dll
2014-12-02 21:03:22 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-12-02 21:03:22 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-12-02 21:03:21 ----A---- C:\Windows\system32\quartz.dll
2014-12-02 21:03:07 ----A---- C:\Windows\system32\msihnd.dll
2014-12-02 21:03:07 ----A---- C:\Windows\system32\consent.exe
2014-12-02 21:03:07 ----A---- C:\Windows\system32\authui.dll
2014-12-02 21:02:54 ----A---- C:\Windows\system32\Wpc.dll
2014-12-02 21:02:54 ----A---- C:\Windows\system32\gameux.dll
2014-12-02 21:02:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-12-02 21:02:40 ----A---- C:\Windows\system32\qedit.dll
2014-12-02 21:02:39 ----A---- C:\Windows\system32\drivers\afd.sys
2014-12-02 21:02:37 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-12-02 21:02:37 ----A---- C:\Windows\system32\drivers\netio.sys
2014-12-02 21:02:37 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-12-02 21:02:33 ----A---- C:\Windows\system32\mscories.dll
2014-12-02 21:02:33 ----A---- C:\Windows\system32\mscorier.dll
2014-12-02 21:02:33 ----A---- C:\Windows\system32\dfshim.dll
2014-12-02 21:02:03 ----A---- C:\Windows\system32\packager.dll
2014-12-02 21:02:02 ----A---- C:\Windows\system32\webio.dll
2014-12-02 21:01:57 ----A---- C:\Windows\system32\odbctrac.dll
2014-12-02 21:01:57 ----A---- C:\Windows\system32\odbcjt32.dll
2014-12-02 21:01:57 ----A---- C:\Windows\system32\odbccu32.dll
2014-12-02 21:01:57 ----A---- C:\Windows\system32\odbccr32.dll
2014-12-02 21:01:57 ----A---- C:\Windows\system32\odbccp32.dll
2014-12-02 21:01:56 ----A---- C:\Windows\system32\WebClnt.dll
2014-12-02 21:01:56 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-12-02 21:01:56 ----A---- C:\Windows\system32\davclnt.dll
2014-12-02 21:01:53 ----A---- C:\Windows\system32\msvcrt.dll
2014-12-02 21:01:39 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-12-02 21:01:38 ----A---- C:\Windows\system32\profsvc.dll
2014-12-02 21:01:37 ----A---- C:\Windows\system32\synceng.dll
2014-12-02 21:01:36 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-12-02 21:01:36 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-12-02 21:01:35 ----A---- C:\Windows\system32\nshwfp.dll
2014-12-02 21:01:35 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-12-02 21:01:31 ----A---- C:\Windows\system32\shdocvw.dll
2014-12-02 21:01:24 ----A---- C:\Windows\system32\localspl.dll
2014-12-02 21:01:20 ----A---- C:\Windows\system32\ntshrui.dll
2014-12-02 21:01:11 ----A---- C:\Windows\system32\mstscax.dll
2014-12-02 21:01:10 ----A---- C:\Windows\system32\winsta.dll
2014-12-02 21:01:10 ----A---- C:\Windows\system32\winlogon.exe
2014-12-02 21:01:10 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-12-02 21:01:10 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-12-02 21:01:10 ----A---- C:\Windows\system32\mstsc.exe
2014-12-02 21:01:09 ----A---- C:\Windows\system32\tsgqec.dll
2014-12-02 21:01:09 ----A---- C:\Windows\system32\rdpwsx.dll
2014-12-02 21:01:09 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-12-02 21:01:09 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-12-02 21:01:09 ----A---- C:\Windows\system32\aaclient.dll
2014-12-02 21:00:55 ----A---- C:\Windows\system32\taskhost.exe
2014-12-02 21:00:50 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2014-12-02 21:00:50 ----A---- C:\Windows\system32\dhcpcore6.dll
2014-12-02 21:00:43 ----A---- C:\Windows\system32\cryptsvc.dll
2014-12-02 21:00:43 ----A---- C:\Windows\system32\cryptnet.dll
2014-12-02 21:00:43 ----A---- C:\Windows\system32\crypt32.dll
2014-12-02 21:00:35 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-12-02 21:00:35 ----A---- C:\Windows\system32\drivers\usbcir.sys
2014-12-02 21:00:31 ----A---- C:\Windows\system32\kernel32.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-12-02 21:00:30 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-12-02 21:00:30 ----A---- C:\Windows\system32\winsrv.dll
2014-12-02 21:00:30 ----A---- C:\Windows\system32\conhost.exe
2014-12-02 21:00:28 ----A---- C:\Windows\system32\wer.dll
2014-12-02 21:00:27 ----A---- C:\Windows\system32\mfc42u.dll
2014-12-02 21:00:27 ----A---- C:\Windows\system32\mfc42.dll
2014-12-02 21:00:21 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-12-02 21:00:18 ----A---- C:\Windows\system32\usp10.dll
2014-12-02 21:00:13 ----A---- C:\Windows\system32\Wdfres.dll
2014-12-02 21:00:13 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-12-02 21:00:13 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-12-02 21:00:10 ----A---- C:\Windows\system32\shell32.dll
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-12-02 21:00:08 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-12-02 20:59:54 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-12-02 20:59:53 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-12-02 20:59:53 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-12-02 20:59:53 ----A---- C:\Windows\system32\secproc_isv.dll
2014-12-02 20:59:53 ----A---- C:\Windows\system32\secproc.dll
2014-12-02 20:59:53 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-12-02 20:59:53 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-12-02 20:59:53 ----A---- C:\Windows\system32\RMActivate.exe
2014-12-02 20:59:53 ----A---- C:\Windows\system32\msdrm.dll
2014-12-02 20:59:30 ----A---- C:\Windows\system32\lsasrv.dll
2014-12-02 20:59:30 ----A---- C:\Windows\system32\drivers\cng.sys
2014-12-02 20:59:29 ----A---- C:\Windows\system32\termsrv.dll
2014-12-02 20:59:29 ----A---- C:\Windows\system32\sspisrv.dll
2014-12-02 20:59:29 ----A---- C:\Windows\system32\sspicli.dll
2014-12-02 20:59:29 ----A---- C:\Windows\system32\secur32.dll
2014-12-02 20:59:29 ----A---- C:\Windows\system32\msaudite.dll
2014-12-02 20:59:29 ----A---- C:\Windows\system32\lsass.exe
2014-12-02 20:59:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-12-02 20:59:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-12-02 20:59:29 ----A---- C:\Windows\system32\adtschema.dll
2014-12-02 20:40:50 ----A---- C:\Windows\system32\appinfo.dll
2014-12-02 20:20:59 ----A---- C:\Windows\system32\rdpcore.dll
2014-12-02 20:20:58 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-12-02 20:10:47 ----A---- C:\Windows\system32\wups2.dll
2014-12-02 20:10:47 ----A---- C:\Windows\system32\wucltux.dll
2014-12-02 20:10:47 ----A---- C:\Windows\system32\wuaueng.dll
2014-12-02 20:10:47 ----A---- C:\Windows\system32\wuauclt.exe
2014-12-02 20:10:26 ----A---- C:\Windows\system32\wups.dll
2014-12-02 20:10:26 ----A---- C:\Windows\system32\wudriver.dll
2014-12-02 20:10:26 ----A---- C:\Windows\system32\wuapi.dll
2014-12-02 20:10:12 ----A---- C:\Windows\system32\wuwebv.dll
2014-12-02 20:10:12 ----A---- C:\Windows\system32\wuapp.exe
2014-12-01 21:55:23 ----D---- C:\ProgramData\Ubisoft
2014-12-01 21:40:55 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-12-01 21:40:55 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-12-01 21:40:55 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-12-01 21:40:55 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\xactengine3_6.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-12-01 21:40:54 ----A---- C:\Windows\system32\d3dcsx_43.dll
2014-12-01 20:59:32 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-12-01 20:59:32 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-12-01 20:59:32 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-12-01 20:59:32 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-12-01 20:59:32 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-12-01 20:59:32 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-12-01 20:59:27 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-12-01 20:59:18 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-12-01 20:59:18 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-12-01 20:57:47 ----D---- C:\direct
2014-12-01 20:54:43 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-12-01 20:54:43 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-12-01 20:54:42 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-12-01 20:54:42 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-12-01 20:54:42 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-12-01 20:54:41 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-12-01 20:54:41 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-12-01 20:54:41 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-12-01 20:54:41 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-12-01 20:54:40 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-12-01 20:54:40 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-12-01 20:54:40 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-12-01 20:54:40 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-12-01 20:54:40 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-12-01 20:54:40 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-12-01 20:54:38 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-12-01 20:54:38 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-12-01 20:54:37 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-12-01 20:54:37 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-12-01 20:54:37 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-12-01 20:54:37 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-12-01 20:54:36 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-12-01 20:54:34 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-12-01 20:54:32 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\xinput1_3.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-12-01 20:54:29 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xinput1_2.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xinput1_1.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\d3dx10.dll
2014-12-01 20:54:28 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-12-01 20:54:16 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-12-01 20:54:16 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-12-01 20:54:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-12-01 20:54:16 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-12-01 20:54:15 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-12-01 20:54:15 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-12-01 20:54:15 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-12-01 20:54:15 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-12-01 20:54:15 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-12-01 18:21:08 ----D---- C:\Program Files\Ubisoft
2014-12-01 17:00:08 ----D---- C:\Users\LENOVO\AppData\Roaming\Origin
2014-12-01 16:57:34 ----D---- C:\Program Files\Origin
2014-12-01 16:39:16 ----D---- C:\ProgramData\Origin
2014-12-01 14:37:55 ----D---- C:\ProgramData\Electronic Arts
2014-12-01 12:49:05 ----D---- C:\ProgramData\Trusted Publisher
2014-12-01 12:47:51 ----D---- C:\ProgramData\5213756320435959375
2014-12-01 12:47:16 ----D---- C:\ProgramData\lfgnjpeocjmddeipbpnjnbnkgnigbajg
2014-12-01 09:27:39 ----D---- C:\Windows\system32\SPReview
2014-11-30 18:15:44 ----D---- C:\Users\LENOVO\AppData\Roaming\WinRAR
2014-11-30 18:15:32 ----D---- C:\Program Files\WinRAR
2014-11-30 14:59:46 ----D---- C:\Users\LENOVO\AppData\Roaming\Skype
2014-11-30 14:59:20 ----RD---- C:\Program Files\Skype
2014-11-30 14:59:20 ----D---- C:\Program Files\Common Files\Skype
2014-11-30 14:58:57 ----D---- C:\ProgramData\Skype
2014-11-29 22:43:32 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2014-11-29 22:43:29 ----D---- C:\Users\LENOVO\AppData\Roaming\DAEMON Tools Lite
2014-11-29 22:43:27 ----D---- C:\Program Files\DAEMON Tools Lite
2014-11-29 22:42:20 ----D---- C:\ProgramData\DAEMON Tools Lite
2014-11-29 19:46:50 ----D---- C:\Users\LENOVO\AppData\Roaming\Theta
2014-11-29 19:36:19 ----D---- C:\Games
2014-11-29 17:34:07 ----D---- C:\Users\LENOVO\AppData\Roaming\uTorrent
2014-11-29 13:15:47 ----D---- C:\Users\LENOVO\AppData\Roaming\LolClient
2014-11-29 13:15:45 ----D---- C:\Users\LENOVO\AppData\Roaming\Macromedia
2014-11-29 13:15:43 ----D---- C:\Users\LENOVO\AppData\Roaming\Adobe
2014-11-29 12:41:09 ----D---- C:\Windows\Minidump
2014-11-29 11:27:55 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-11-29 11:27:55 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-11-29 11:27:52 ----A---- C:\Windows\system32\mfc40u.dll
2014-11-29 11:27:52 ----A---- C:\Windows\system32\mfc40.dll
2014-11-29 11:27:50 ----A---- C:\Windows\system32\sysmain.dll
2014-11-29 11:27:46 ----A---- C:\Windows\system32\spwizui.dll
2014-11-29 11:27:46 ----A---- C:\Windows\system32\mscoree.dll
2014-11-29 11:27:44 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-11-29 11:27:44 ----A---- C:\Windows\system32\CertEnroll.dll
2014-11-29 11:27:42 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2014-11-29 11:27:42 ----A---- C:\Windows\system32\PresentationHost.exe
2014-11-29 11:27:42 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2014-11-29 11:27:41 ----A---- C:\Windows\system32\schedsvc.dll
2014-11-29 11:27:41 ----A---- C:\Windows\system32\RacEngn.dll
2014-11-29 11:27:40 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2014-11-29 11:27:38 ----A---- C:\Windows\system32\rdpdd.dll
2014-11-29 11:27:38 ----A---- C:\Windows\system32\qmgr.dll
2014-11-29 11:27:37 ----A---- C:\Windows\system32\ExplorerFrame.dll
2014-11-29 11:27:36 ----A---- C:\Windows\system32\wevtsvc.dll
2014-11-29 11:27:36 ----A---- C:\Windows\system32\vssapi.dll
2014-11-29 11:27:36 ----A---- C:\Windows\system32\ole32.dll
2014-11-29 11:27:35 ----A---- C:\Windows\system32\SearchFolder.dll
2014-11-29 11:27:35 ----A---- C:\Windows\system32\d3d9.dll
2014-11-29 11:27:34 ----A---- C:\Windows\system32\taskschd.dll
2014-11-29 11:27:33 ----A---- C:\Windows\system32\spreview.exe
2014-11-29 11:27:32 ----A---- C:\Windows\system32\spinstall.exe
2014-11-29 11:27:32 ----A---- C:\Windows\system32\certcli.dll
2014-11-29 11:27:31 ----A---- C:\Windows\system32\gpsvc.dll
2014-11-29 11:27:31 ----A---- C:\Windows\system32\dwmcore.dll
2014-11-29 11:27:30 ----A---- C:\Windows\system32\odbc32.dll
2014-11-29 11:27:29 ----A---- C:\Windows\system32\wbengine.exe
2014-11-29 11:27:29 ----A---- C:\Windows\system32\MPSSVC.dll
2014-11-29 11:27:29 ----A---- C:\Windows\system32\diagperf.dll
2014-11-29 11:27:28 ----A---- C:\Windows\system32\WinSAT.exe
2014-11-29 11:27:28 ----A---- C:\Windows\system32\tsmf.dll
2014-11-29 11:27:28 ----A---- C:\Windows\system32\dot3api.dll
2014-11-29 11:27:27 ----A---- C:\Windows\system32\winhttp.dll
2014-11-29 11:27:27 ----A---- C:\Windows\system32\setupapi.dll
2014-11-29 11:27:27 ----A---- C:\Windows\system32\MSVidCtl.dll
2014-11-29 11:27:27 ----A---- C:\Windows\system32\apphelp.dll
2014-11-29 11:27:26 ----A---- C:\Windows\system32\VSSVC.exe
2014-11-29 11:27:26 ----A---- C:\Windows\system32\netlogon.dll
2014-11-29 11:27:26 ----A---- C:\Windows\system32\dbgeng.dll
2014-11-29 11:27:24 ----A---- C:\Windows\system32\user32.dll
2014-11-29 11:27:24 ----A---- C:\Windows\system32\Query.dll
2014-11-29 11:27:24 ----A---- C:\Windows\system32\netcfgx.dll
2014-11-29 11:27:22 ----D---- C:\ProgramData\Riot Games
2014-11-29 11:27:22 ----A---- C:\Windows\system32\upnp.dll
2014-11-29 11:27:22 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2014-11-29 11:27:21 ----A---- C:\Windows\system32\mmcndmgr.dll
2014-11-29 11:27:20 ----A---- C:\Windows\system32\netfxperf.dll
2014-11-29 11:27:20 ----A---- C:\Windows\system32\lsm.exe
2014-11-29 11:27:19 ----A---- C:\Windows\system32\imapi2fs.dll
2014-11-29 11:27:17 ----A---- C:\Windows\system32\sppobjs.dll
2014-11-29 11:27:16 ----A---- C:\Windows\system32\shlwapi.dll
2014-11-29 11:27:16 ----A---- C:\Windows\system32\SessEnv.dll
2014-11-29 11:27:16 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2014-11-29 11:27:15 ----A---- C:\Windows\system32\xpsservices.dll
2014-11-29 11:27:15 ----A---- C:\Windows\system32\winload.exe
2014-11-29 11:27:15 ----A---- C:\Windows\system32\userenv.dll
2014-11-29 11:27:15 ----A---- C:\Windows\system32\mcbuilder.exe
2014-11-29 11:27:15 ----A---- C:\Windows\system32\drvstore.dll
2014-11-29 11:27:15 ----A---- C:\Windows\system32\certmgr.dll
2014-11-29 11:27:14 ----A---- C:\Windows\system32\sppwinob.dll
2014-11-29 11:27:14 ----A---- C:\Windows\system32\rpcss.dll
2014-11-29 11:27:14 ----A---- C:\Windows\system32\comdlg32.dll
2014-11-29 11:27:14 ----A---- C:\Windows\system32\cmd.exe
2014-11-29 11:27:13 ----A---- C:\Windows\system32\wmicmiplugin.dll
2014-11-29 11:27:13 ----A---- C:\Windows\system32\Wldap32.dll
2014-11-29 11:27:13 ----A---- C:\Windows\system32\samsrv.dll
2014-11-29 11:27:13 ----A---- C:\Windows\system32\propsys.dll
2014-11-29 11:27:13 ----A---- C:\Windows\system32\mfds.dll
2014-11-29 11:27:13 ----A---- C:\Windows\system32\framedynos.dll
2014-11-29 11:27:13 ----A---- C:\Windows\system32\drivers\volsnap.sys
2014-11-29 11:27:13 ----A---- C:\Windows\system32\BFE.DLL
2014-11-29 11:27:12 ----A---- C:\Windows\system32\winresume.exe
2014-11-29 11:27:12 ----A---- C:\Windows\system32\werconcpl.dll
2014-11-29 11:27:12 ----A---- C:\Windows\system32\azroles.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\themeui.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\taskeng.exe
2014-11-29 11:27:11 ----A---- C:\Windows\system32\taskcomp.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\spp.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\evr.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\drivers\http.sys
2014-11-29 11:27:11 ----A---- C:\Windows\system32\dhcpcore.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\dbghelp.dll
2014-11-29 11:27:11 ----A---- C:\Windows\system32\basecsp.dll
2014-11-29 11:27:10 ----A---- C:\Windows\system32\WinSATAPI.dll
2014-11-29 11:27:10 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2014-11-29 11:27:10 ----A---- C:\Windows\system32\calc.exe
2014-11-29 11:27:09 ----A---- C:\Windows\system32\vpnike.dll
2014-11-29 11:27:09 ----A---- C:\Windows\system32\UIRibbon.dll
2014-11-29 11:27:09 ----A---- C:\Windows\system32\srvsvc.dll
2014-11-29 11:27:09 ----A---- C:\Windows\system32\sqlsrv32.dll
2014-11-29 11:27:09 ----A---- C:\Windows\system32\QAGENTRT.DLL
2014-11-29 11:27:09 ----A---- C:\Windows\system32\lpksetup.exe
2014-11-29 11:27:09 ----A---- C:\Windows\system32\fveapi.dll
2014-11-29 11:27:08 ----A---- C:\Windows\system32\ws2_32.dll
2014-11-29 11:27:08 ----A---- C:\Windows\system32\sxs.dll
2014-11-29 11:27:08 ----A---- C:\Windows\system32\netshell.dll
2014-11-29 11:27:07 ----A---- C:\Windows\system32\stobject.dll
2014-11-29 11:27:07 ----A---- C:\Windows\system32\hgprint.dll
2014-11-29 11:27:07 ----A---- C:\Windows\system32\drivers\rdbss.sys
2014-11-29 11:27:07 ----A---- C:\Windows\system32\drivers\msdsm.sys
2014-11-29 11:27:06 ----A---- C:\Windows\system32\prncache.dll
2014-11-29 11:27:06 ----A---- C:\Windows\system32\printui.dll
2014-11-29 11:27:06 ----A---- C:\Windows\system32\inetpp.dll
2014-11-29 11:27:06 ----A---- C:\Windows\system32\dps.dll
2014-11-29 11:27:05 ----A---- C:\Windows\system32\WSDApi.dll
2014-11-29 11:27:05 ----A---- C:\Windows\system32\wmpeffects.dll
2014-11-29 11:27:05 ----A---- C:\Windows\system32\rpchttp.dll
2014-11-29 11:27:05 ----A---- C:\Windows\system32\net1.exe
2014-11-29 11:27:05 ----A---- C:\Windows\system32\ci.dll
2014-11-29 11:27:05 ----A---- C:\Windows\system32\aitagent.exe
2014-11-29 11:27:04 ----A---- C:\Windows\system32\FXSSVC.exe
2014-11-29 11:27:04 ----A---- C:\Windows\system32\drivers\pci.sys
2014-11-29 11:27:03 ----A---- C:\Windows\system32\wpdshext.dll
2014-11-29 11:27:03 ----A---- C:\Windows\system32\WMVCORE.DLL
2014-11-29 11:27:03 ----A---- C:\Windows\system32\wlangpui.dll
2014-11-29 11:27:03 ----A---- C:\Windows\system32\vds.exe
2014-11-29 11:27:03 ----A---- C:\Windows\system32\t2embed.dll
2014-11-29 11:27:03 ----A---- C:\Windows\system32\scansetting.dll
2014-11-29 11:27:03 ----A---- C:\Windows\system32\QSHVHOST.DLL
2014-11-29 11:27:03 ----A---- C:\Windows\system32\pnidui.dll
2014-11-29 11:27:03 ----A---- C:\Windows\system32\MMDevAPI.dll
2014-11-29 11:27:03 ----A---- C:\Windows\system32\IPSECSVC.DLL
2014-11-29 11:27:02 ----A---- C:\Windows\system32\wscapi.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\webservices.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\SyncCenter.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\sdengin2.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\netdiagfx.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\fde.dll
2014-11-29 11:27:02 ----A---- C:\Windows\system32\drivers\termdd.sys
2014-11-29 11:27:02 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2014-11-29 11:27:01 ----A---- C:\Windows\system32\wisptis.exe
2014-11-29 11:27:01 ----A---- C:\Windows\system32\WinSCard.dll
2014-11-29 11:27:01 ----A---- C:\Windows\system32\WFS.exe
2014-11-29 11:27:01 ----A---- C:\Windows\system32\pla.dll
2014-11-29 11:27:01 ----A---- C:\Windows\system32\msasn1.dll
2014-11-29 11:27:01 ----A---- C:\Windows\system32\mcmde.dll
2014-11-29 11:27:00 ----A---- C:\Windows\system32\wiaservc.dll
2014-11-29 11:27:00 ----A---- C:\Windows\system32\setupcl.exe
2014-11-29 11:27:00 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2014-11-29 11:27:00 ----A---- C:\Windows\system32\imapi2.dll
2014-11-29 11:27:00 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2014-11-29 11:27:00 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2014-11-29 11:27:00 ----A---- C:\Windows\system32\drivers\msahci.sys
2014-11-29 11:26:59 ----A---- C:\Windows\system32\WMPEncEn.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\winmm.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\TabSvc.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\shsvcs.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\rasmans.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\onex.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\dwmredir.dll
2014-11-29 11:26:59 ----A---- C:\Windows\system32\drivers\udfs.sys
2014-11-29 11:26:59 ----A---- C:\Windows\system32\drivers\acpi.sys
2014-11-29 11:26:58 ----A---- C:\Windows\system32\vaultsvc.dll
2014-11-29 11:26:58 ----A---- C:\Windows\system32\samcli.dll
2014-11-29 11:26:58 ----A---- C:\Windows\system32\netiohlp.dll
2014-11-29 11:26:58 ----A---- C:\Windows\system32\Narrator.exe
2014-11-29 11:26:58 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2014-11-29 11:26:58 ----A---- C:\Windows\system32\hbaapi.dll
2014-11-29 11:26:58 ----A---- C:\Windows\system32\bootres.dll
2014-11-29 11:26:58 ----A---- C:\Windows\system32\autochk.exe
2014-11-29 11:26:58 ----A---- C:\Windows\system32\autofmt.exe
2014-11-29 11:26:58 ----A---- C:\Windows\system32\audiodg.exe
2014-11-29 11:26:57 ----A---- C:\Windows\system32\wcncsvc.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\thumbcache.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\tcpipcfg.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\srchadmin.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\schtasks.exe
2014-11-29 11:26:57 ----A---- C:\Windows\system32\regapi.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\proquota.exe
2014-11-29 11:26:57 ----A---- C:\Windows\system32\powercpl.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\msutb.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\msinfo32.exe
2014-11-29 11:26:57 ----A---- C:\Windows\system32\mimefilt.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\ipsmsnap.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\halmacpi.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\hal.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\framedyn.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\eapphost.dll
2014-11-29 11:26:57 ----A---- C:\Windows\system32\drivers\volmgr.sys
2014-11-29 11:26:57 ----A---- C:\Windows\system32\autoconv.exe
2014-11-29 11:26:56 ----A---- C:\Windows\system32\umpo.dll
2014-11-29 11:26:56 ----A---- C:\Windows\system32\QAGENT.DLL
2014-11-29 11:26:56 ----A---- C:\Windows\system32\netid.dll
2014-11-29 11:26:56 ----A---- C:\Windows\system32\DXP.dll
2014-11-29 11:26:56 ----A---- C:\Windows\system32\drivers\netbt.sys
2014-11-29 11:26:56 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2014-11-29 11:26:55 ----A---- C:\Windows\system32\wdc.dll
2014-11-29 11:26:55 ----A---- C:\Windows\system32\StructuredQuery.dll
2014-11-29 11:26:55 ----A---- C:\Windows\system32\scesrv.dll
2014-11-29 11:26:55 ----A---- C:\Windows\system32\actxprxy.dll
2014-11-29 11:26:54 ----A---- C:\Windows\system32\Vault.dll
2014-11-29 11:26:54 ----A---- C:\Windows\system32\untfs.dll
2014-11-29 11:26:54 ----A---- C:\Windows\system32\sdclt.exe
2014-11-29 11:26:54 ----A---- C:\Windows\system32\nci.dll
2014-11-29 11:26:53 ----A---- C:\Windows\system32\WMNetMgr.dll
2014-11-29 11:26:53 ----A---- C:\Windows\system32\wlanpref.dll
2014-11-29 11:26:53 ----A---- C:\Windows\system32\sppsvc.exe
2014-11-29 11:26:53 ----A---- C:\Windows\system32\RpcRtRemote.dll
2014-11-29 11:26:53 ----A---- C:\Windows\system32\Robocopy.exe
2014-11-29 11:26:53 ----A---- C:\Windows\system32\ListSvc.dll
2014-11-29 11:26:53 ----A---- C:\Windows\system32\DxpTaskSync.dll
2014-11-29 11:26:52 ----A---- C:\Windows\system32\XpsRasterService.dll
2014-11-29 11:26:52 ----A---- C:\Windows\system32\userinit.exe
2014-11-29 11:26:52 ----A---- C:\Windows\system32\taskmgr.exe
2014-11-29 11:26:52 ----A---- C:\Windows\system32\sharemediacpl.dll
2014-11-29 11:26:52 ----A---- C:\Windows\system32\puiobj.dll
2014-11-29 11:26:52 ----A---- C:\Windows\system32\mtxclu.dll
2014-11-29 11:26:52 ----A---- C:\Windows\system32\msdri.dll
2014-11-29 11:26:52 ----A---- C:\Windows\system32\drivers\mpio.sys
2014-11-29 11:26:52 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2014-11-29 11:26:52 ----A---- C:\Windows\system32\Display.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\wiadefui.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\termmgr.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\shsetup.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\rasppp.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\msdtctm.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\logoncli.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\eudcedit.exe
2014-11-29 11:26:51 ----A---- C:\Windows\system32\drivers\scsiport.sys
2014-11-29 11:26:51 ----A---- C:\Windows\system32\DiagCpl.dll
2014-11-29 11:26:51 ----A---- C:\Windows\system32\biocpl.dll
2014-11-29 11:26:50 ----A---- C:\Windows\system32\themecpl.dll
2014-11-29 11:26:50 ----A---- C:\Windows\system32\sppcomapi.dll
2014-11-29 11:26:50 ----A---- C:\Windows\system32\SensorsCpl.dll
2014-11-29 11:26:50 ----A---- C:\Windows\system32\msconfig.exe
2014-11-29 11:26:50 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2014-11-29 11:26:50 ----A---- C:\Windows\system32\cabview.dll
2014-11-29 11:26:49 ----A---- C:\Windows\system32\wpccpl.dll
2014-11-29 11:26:49 ----A---- C:\Windows\system32\tapisrv.dll
2014-11-29 11:26:49 ----A---- C:\Windows\system32\scecli.dll
2014-11-29 11:26:49 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2014-11-29 11:26:49 ----A---- C:\Windows\system32\hgcpl.dll
2014-11-29 11:26:49 ----A---- C:\Windows\system32\fontext.dll
2014-11-29 11:26:49 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2014-11-29 11:26:49 ----A---- C:\Windows\system32\dnscmmc.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\wlanui.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\wkssvc.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\VAN.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\usercpl.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\SndVolSSO.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\mscms.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\mprddm.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\localsec.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\KMSVC.DLL
2014-11-29 11:26:48 ----A---- C:\Windows\system32\iasacct.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\bcdsrv.dll
2014-11-29 11:26:48 ----A---- C:\Windows\system32\batmeter.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\zipfldr.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\wpdbusenum.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\wksprt.exe
2014-11-29 11:26:47 ----A---- C:\Windows\system32\w32tm.exe
2014-11-29 11:26:47 ----A---- C:\Windows\system32\spwizeng.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\SndVol.exe
2014-11-29 11:26:47 ----A---- C:\Windows\system32\prntvpt.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\netcenter.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\mblctr.exe
2014-11-29 11:26:47 ----A---- C:\Windows\system32\fdeploy.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\drivers\ks.sys
2014-11-29 11:26:47 ----A---- C:\Windows\system32\azroleui.dll
2014-11-29 11:26:47 ----A---- C:\Windows\system32\accessibilitycpl.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\wusa.exe
2014-11-29 11:26:46 ----A---- C:\Windows\system32\sud.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\prnfldr.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\photowiz.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\networkmap.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\netjoin.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\mspbda.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2014-11-29 11:26:46 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\Faultrep.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\cryptui.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\cfgmgr32.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\adsldp.dll
2014-11-29 11:26:46 ----A---- C:\Windows\system32\ActionCenter.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\wpd_ci.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\taskbarcpl.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\slui.exe
2014-11-29 11:26:45 ----A---- C:\Windows\system32\sisbkup.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\shwebsvc.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\iprtrmgr.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\ifsutil.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\iasrad.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\halacpi.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\ftp.exe
2014-11-29 11:26:45 ----A---- C:\Windows\system32\efscore.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\dot3cfg.dll
2014-11-29 11:26:45 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\syncui.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\sppnp.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\sdcpl.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\recovery.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\fsquirt.exe
2014-11-29 11:26:44 ----A---- C:\Windows\system32\DeviceCenter.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\bcdedit.exe
2014-11-29 11:26:44 ----A---- C:\Windows\system32\autoplay.dll
2014-11-29 11:26:44 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2014-11-29 11:26:43 ----A---- C:\Windows\system32\wmpmde.dll
2014-11-29 11:26:43 ----A---- C:\Windows\system32\ntlanman.dll
2014-11-29 11:26:43 ----A---- C:\Windows\system32\dskquoui.dll
2014-11-29 11:26:41 ----A---- C:\Windows\system32\rtutils.dll
2014-11-29 11:26:41 ----A---- C:\Windows\system32\OobeFldr.dll
2014-11-29 11:26:40 ----A---- C:\Windows\system32\vdsutil.dll
2014-11-29 11:26:40 ----A---- C:\Windows\system32\systemcpl.dll
2014-11-29 11:26:40 ----A---- C:\Windows\system32\recdisc.exe
2014-11-29 11:26:40 ----A---- C:\Windows\system32\ntprint.dll
2014-11-29 11:26:39 ----A---- C:\Windows\system32\sethc.exe
2014-11-29 11:26:39 ----A---- C:\Windows\system32\riched20.dll
2014-11-29 11:26:39 ----A---- C:\Windows\system32\bcdboot.exe
2014-11-29 11:26:38 ----A---- C:\Windows\system32\rstrui.exe
2014-11-29 11:26:37 ----A---- C:\Windows\system32\blackbox.dll
2014-11-29 11:26:37 ----A---- C:\Windows\system32\AxInstSv.dll
2014-11-29 11:26:36 ----A---- C:\Windows\system32\wmpsrcwp.dll
2014-11-29 11:26:36 ----A---- C:\Windows\system32\netplwiz.dll
2014-11-29 11:26:36 ----A---- C:\Windows\system32\NAPHLPR.DLL
2014-11-29 11:26:36 ----A---- C:\Windows\system32\migisol.dll
2014-11-29 11:26:36 ----A---- C:\Windows\system32\fms.dll
2014-11-29 11:26:36 ----A---- C:\Windows\system32\activeds.dll
2014-11-29 11:26:35 ----A---- C:\Windows\system32\httpapi.dll
2014-11-29 11:26:35 ----A---- C:\Windows\system32\dpx.dll
2014-11-29 11:26:35 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2014-11-29 11:26:34 ----A---- C:\Windows\system32\wsqmcons.exe
2014-11-29 11:26:34 ----A---- C:\Windows\system32\nshipsec.dll
2014-11-29 11:26:34 ----A---- C:\Windows\system32\msftedit.dll
2014-11-29 11:26:34 ----A---- C:\Windows\system32\isoburn.exe
2014-11-29 11:26:34 ----A---- C:\Windows\system32\dot3svc.dll
2014-11-29 11:26:34 ----A---- C:\Windows\system32\asycfilt.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\wvc.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\wtsapi32.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\wlanmsm.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\wimgapi.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\wavemsp.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\tzutil.exe
2014-11-29 11:26:33 ----A---- C:\Windows\system32\sysclass.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\ReAgent.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\provsvc.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\PkgMgr.exe
2014-11-29 11:26:33 ----A---- C:\Windows\system32\ocsetup.exe
2014-11-29 11:26:33 ----A---- C:\Windows\system32\mstask.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\dsuiext.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2014-11-29 11:26:33 ----A---- C:\Windows\system32\dot3ui.dll
2014-11-29 11:26:33 ----A---- C:\Windows\system32\dfrgui.exe
2014-11-29 11:26:33 ----A---- C:\Windows\system32\certprop.dll
2014-11-29 11:26:32 ----A---- C:\Windows\twain_32.dll
2014-11-29 11:26:32 ----A---- C:\Windows\system32\twext.dll
2014-11-29 11:26:32 ----A---- C:\Windows\system32\SmiEngine.dll
2014-11-29 11:26:32 ----A---- C:\Windows\system32\setupugc.exe
2014-11-29 11:26:32 ----A---- C:\Windows\system32\qcap.dll
2014-11-29 11:26:32 ----A---- C:\Windows\system32\qasf.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\wwanconn.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\wmdrmsdk.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\uxlib.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\ssText3d.scr
2014-11-29 11:26:31 ----A---- C:\Windows\system32\srrstr.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\slwga.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\nslookup.exe
2014-11-29 11:26:31 ----A---- C:\Windows\system32\msvfw32.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\mciavi32.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\imm32.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\clusapi.dll
2014-11-29 11:26:31 ----A---- C:\Windows\system32\audiodev.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\wimserv.exe
2014-11-29 11:26:30 ----A---- C:\Windows\system32\remotepg.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\rdpencom.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\raschap.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\QUTIL.DLL
2014-11-29 11:26:30 ----A---- C:\Windows\system32\perfmon.exe
2014-11-29 11:26:30 ----A---- C:\Windows\system32\msscp.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\input.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\drmmgrtn.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\diskraid.exe
2014-11-29 11:26:30 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2014-11-29 11:26:30 ----A---- C:\Windows\system32\acppage.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\wpdwcn.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\wmpdxm.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-11-29 11:26:29 ----A---- C:\Windows\system32\vpnikeapi.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\vdsbas.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\sdrsvc.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\runonce.exe
2014-11-29 11:26:29 ----A---- C:\Windows\system32\onexui.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\olepro32.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\ocsetapi.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\nltest.exe
2014-11-29 11:26:29 ----A---- C:\Windows\system32\networkexplorer.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2014-11-29 11:26:29 ----A---- C:\Windows\system32\iTVData.dll
2014-11-29 11:26:29 ----A---- C:\Windows\system32\dxdiagn.dll
2014-11-29 11:26:29 ----A---- C:\Windows\bfsvc.exe
2014-11-29 11:26:28 ----A---- C:\Windows\system32\msvidc32.dll
2014-11-29 11:26:28 ----A---- C:\Windows\system32\MFPlay.dll
2014-11-29 11:26:28 ----A---- C:\Windows\system32\Mcx2Svc.dll
2014-11-29 11:26:28 ----A---- C:\Windows\system32\logagent.exe
2014-11-29 11:26:28 ----A---- C:\Windows\system32\eapp3hst.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\wmpshell.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\wmdrmdev.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\unimdmat.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\tabcal.exe
2014-11-29 11:26:27 ----A---- C:\Windows\system32\sqlcese30.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\shacct.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\rdpd3d.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\PnPUnattend.exe
2014-11-29 11:26:27 ----A---- C:\Windows\system32\pdh.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\OpcServices.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\msiexec.exe
2014-11-29 11:26:27 ----A---- C:\Windows\system32\mprapi.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\lsmproxy.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\iscsium.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\drivers\rmcast.sys
2014-11-29 11:26:27 ----A---- C:\Windows\system32\cscapi.dll
2014-11-29 11:26:27 ----A---- C:\Windows\system32\Bubbles.scr
2014-11-29 11:26:27 ----A---- C:\Windows\system32\bitsadmin.exe
2014-11-29 11:26:26 ----A---- C:\Windows\system32\WPDSp.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\srvcli.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\Ribbons.scr
2014-11-29 11:26:26 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2014-11-29 11:26:26 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\olethk32.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\ncryptui.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\Mystify.scr
2014-11-29 11:26:26 ----A---- C:\Windows\system32\MdSched.exe
2014-11-29 11:26:26 ----A---- C:\Windows\system32\mapistub.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\mapi32.dll
2014-11-29 11:26:26 ----A---- C:\Windows\system32\lpremove.exe
2014-11-29 11:26:26 ----A---- C:\Windows\system32\logman.exe
2014-11-29 11:26:26 ----A---- C:\Windows\system32\djoin.exe
2014-11-29 11:26:26 ----A---- C:\Windows\system32\ActionQueue.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\WMVSDECD.DLL
2014-11-29 11:26:25 ----A---- C:\Windows\system32\wmdrmnet.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\WMADMOD.DLL
2014-11-29 11:26:25 ----A---- C:\Windows\system32\WindowsAnytimeUpgrade.exe
2014-11-29 11:26:25 ----A---- C:\Windows\system32\wiavideo.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\utildll.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-11-29 11:26:25 ----A---- C:\Windows\system32\takeown.exe
2014-11-29 11:26:25 ----A---- C:\Windows\system32\sqmapi.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\sppinst.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\qdv.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\QCLIPROV.DLL
2014-11-29 11:26:25 ----A---- C:\Windows\system32\msyuv.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\msrle32.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\msnetobj.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\iyuv_32.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\fphc.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\EhStorAPI.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\dot3msm.dll
2014-11-29 11:26:25 ----A---- C:\Windows\system32\avifil32.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\wsnmp32.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2014-11-29 11:26:24 ----A---- C:\Windows\system32\vfwwdm32.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\unattend.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\setupcln.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\RelPost.exe
2014-11-29 11:26:24 ----A---- C:\Windows\system32\pdhui.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\MuiUnattend.exe
2014-11-29 11:26:24 ----A---- C:\Windows\system32\cmstp.exe
2014-11-29 11:26:24 ----A---- C:\Windows\system32\cca.dll
2014-11-29 11:26:24 ----A---- C:\Windows\system32\basesrv.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\wkscli.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\WavDest.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\umb.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\tsbyuv.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\sppuinotify.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\spbcd.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\relog.exe
2014-11-29 11:26:23 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\netiougc.exe
2014-11-29 11:26:23 ----A---- C:\Windows\system32\mydocs.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\msorcl32.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\iscsicli.exe
2014-11-29 11:26:23 ----A---- C:\Windows\system32\iasrecst.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2014-11-29 11:26:23 ----A---- C:\Windows\system32\diskpart.exe
2014-11-29 11:26:23 ----A---- C:\Windows\system32\AzSqlExt.dll
2014-11-29 11:26:23 ----A---- C:\Windows\system32\amstream.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\syssetup.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\setbcdlocale.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\resutils.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\rastapi.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\nrpsrv.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\netbtugc.exe
2014-11-29 11:26:22 ----A---- C:\Windows\system32\MultiDigiMon.exe
2014-11-29 11:26:22 ----A---- C:\Windows\system32\itircl.dll
2014-11-29 11:26:22 ----A---- C:\Windows\system32\CertPolEng.dll
2014-11-29 11:26:21 ----A---- C:\Windows\system32\wmpps.dll
2014-11-29 11:26:21 ----A---- C:\Windows\system32\FXSTIFF.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\wiarpc.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\WerFaultSecure.exe
2014-11-29 11:26:20 ----A---- C:\Windows\system32\tlscsp.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\sppc.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\ReAgentc.exe
2014-11-29 11:26:20 ----A---- C:\Windows\system32\netutils.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\muifontsetup.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\mobsync.exe
2014-11-29 11:26:20 ----A---- C:\Windows\system32\mciqtz32.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\iccvid.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\findstr.exe
2014-11-29 11:26:20 ----A---- C:\Windows\system32\eappgnui.dll
2014-11-29 11:26:20 ----A---- C:\Windows\system32\cabinet.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\unlodctr.exe
2014-11-29 11:26:19 ----A---- C:\Windows\system32\spopk.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\shimgvw.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\repair-bde.exe
2014-11-29 11:26:19 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\profprov.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\odbcconf.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\netcfg.exe
2014-11-29 11:26:19 ----A---- C:\Windows\system32\msdmo.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\manage-bde.exe
2014-11-29 11:26:19 ----A---- C:\Windows\system32\luainstall.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\inetmib1.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2014-11-29 11:26:19 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2014-11-29 11:26:19 ----A---- C:\Windows\system32\drivers\tdi.sys
2014-11-29 11:26:19 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2014-11-29 11:26:19 ----A---- C:\Windows\system32\drivers\cdrom.sys
2014-11-29 11:26:19 ----A---- C:\Windows\system32\dosx.exe
2014-11-29 11:26:18 ----A---- C:\Windows\system32\UIRibbonRes.dll
2014-11-29 11:26:18 ----A---- C:\Windows\system32\perfts.dll
2014-11-29 11:26:17 ----A---- C:\Windows\system32\icaapi.dll
2014-11-29 11:26:17 ----A---- C:\Windows\system32\FXSMON.dll
2014-11-29 11:26:17 ----A---- C:\Windows\system32\drivers\dfsc.sys
2014-11-29 11:26:16 ----A---- C:\Windows\system32\elsTrans.dll
2014-11-29 11:26:16 ----A---- C:\Windows\system32\drivers\tunnel.sys
2014-11-29 11:26:15 ----A---- C:\Windows\system32\wshbth.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\TRAPI.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\sscore.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\schedcli.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\RDPENCDD.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\napdsnap.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\LogonUI.exe
2014-11-29 11:26:15 ----A---- C:\Windows\system32\dsauth.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2014-11-29 11:26:15 ----A---- C:\Windows\system32\cscdll.dll
2014-11-29 11:26:15 ----A---- C:\Windows\system32\bitsperf.dll
2014-11-29 11:26:14 ----A---- C:\Windows\system32\wsdchngr.dll
2014-11-29 11:26:14 ----A---- C:\Windows\system32\shgina.dll
2014-11-29 11:26:14 ----A---- C:\Windows\system32\riched32.dll
2014-11-29 11:26:14 ----A---- C:\Windows\system32\rdpcfgex.dll
2014-11-29 11:26:14 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2014-11-29 11:26:14 ----A---- C:\Windows\system32\drivers\hidusb.sys
2014-11-29 11:26:14 ----A---- C:\Windows\system32\drivers\appid.sys
2014-11-29 11:26:13 ----A---- C:\Windows\system32\wshirda.dll
2014-11-29 11:26:13 ----A---- C:\Windows\system32\spwmp.dll
2014-11-29 11:26:13 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2014-11-29 11:26:13 ----A---- C:\Windows\system32\drivers\USBCAMD.sys
2014-11-29 11:26:13 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2014-11-29 11:26:13 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2014-11-29 11:26:13 ----A---- C:\Windows\system32\browseui.dll
2014-11-29 11:26:12 ----A---- C:\Windows\system32\shunimpl.dll
2014-11-29 11:26:12 ----A---- C:\Windows\system32\RDPREFDD.dll
2014-11-29 11:26:12 ----A---- C:\Windows\system32\dxmasf.dll
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\wanarp.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\umbus.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\tdpipe.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\scfilter.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\RDPCDD.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2014-11-29 11:26:12 ----A---- C:\Windows\system32\C_ISCII.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\spwizres.dll
2014-11-29 11:26:11 ----A---- C:\Windows\system32\pifmgr.dll
2014-11-29 11:26:11 ----A---- C:\Windows\system32\nlsbres.dll
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDUS.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDTURME.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDTUQ.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDTUF.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDSG.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDSF.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDPO.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDNEPR.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDMON.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDMAORI.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDLT1.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\kbdlk41a.dll
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINTEL.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINTAM.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINORI.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINMAR.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINKAN.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINHIN.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDINBEN.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDGR1.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDGKL.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDGEO.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDCZ1.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDBULG.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\KBDBLR.DLL
2014-11-29 11:26:11 ----A---- C:\Windows\system32\dpnaddr.dll
2014-11-29 11:26:11 ----A---- C:\Windows\system32\BlbEvents.dll
2014-11-29 11:25:55 ----A---- C:\Windows\system32\wdscore.dll
2014-11-29 11:25:37 ----A---- C:\Windows\system32\wbemcomn.dll
2014-11-29 11:20:49 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-11-29 11:20:49 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-11-29 11:20:49 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-11-29 11:20:49 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-11-29 11:20:49 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-11-29 11:19:32 ----D---- C:\Riot Games
2014-11-29 11:13:08 ----D---- C:\Users\LENOVO\AppData\Roaming\Riot Games

======List of files/folders modified in the last 1 month======

2014-12-27 09:56:00 ----D---- C:\Windows\Temp
2014-12-27 09:51:28 ----RD---- C:\Program Files
2014-12-27 09:41:36 ----D---- C:\Windows\system32\config
2014-12-27 09:34:55 ----D---- C:\Windows\System32
2014-12-27 09:34:55 ----D---- C:\Windows\inf
2014-12-27 09:34:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-27 06:21:25 ----D---- C:\Windows\system32\drivers
2014-12-27 06:19:58 ----D---- C:\Windows\addins
2014-12-27 06:19:57 ----HD---- C:\ProgramData
2014-12-27 02:24:41 ----SHD---- C:\Windows\Installer
2014-12-27 02:24:23 ----SHD---- C:\System Volume Information
2014-12-27 02:21:14 ----HD---- C:\Program Files\InstallShield Installation Information
2014-12-27 02:21:14 ----D---- C:\Windows\Options
2014-12-27 02:11:56 ----D---- C:\Windows\system32\Tasks
2014-12-27 02:11:31 ----RSD---- C:\Windows\Fonts
2014-12-27 00:53:16 ----D---- C:\Windows\LiveKernelReports
2014-12-26 12:31:05 ----D---- C:\Windows\Prefetch
2014-12-25 17:19:13 ----SD---- C:\Users\LENOVO\AppData\Roaming\Microsoft
2014-12-21 15:44:39 ----D---- C:\Windows\system32\NDF
2014-12-20 21:36:36 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-12-19 01:58:37 ----D---- C:\Windows\winsxs
2014-12-18 23:10:36 ----RSD---- C:\Windows\assembly
2014-12-18 15:45:47 ----D---- C:\Windows\rescache
2014-12-18 11:51:38 ----D---- C:\Windows\system32\catroot
2014-12-17 17:55:35 ----D---- C:\Program Files\Common Files
2014-12-17 08:37:04 ----D---- C:\Windows\system32\catroot2
2014-12-13 03:17:31 ----SD---- C:\Windows\system32\CompatTel
2014-12-13 03:17:31 ----D---- C:\Windows\system32\cs-CZ
2014-12-13 03:17:30 ----D---- C:\Windows\system32\en-US
2014-12-13 03:17:30 ----D---- C:\Windows\PolicyDefinitions
2014-12-13 03:17:30 ----D---- C:\Windows
2014-12-13 03:17:30 ----D---- C:\Program Files\Internet Explorer
2014-12-13 03:17:29 ----D---- C:\Windows\system32\DriverStore
2014-12-12 18:08:30 ----D---- C:\Windows\Tasks
2014-12-12 17:28:10 ----D---- C:\Windows\system32\wfp
2014-12-12 17:27:44 ----D---- C:\Windows\system32\wbem
2014-12-12 17:27:43 ----D---- C:\Windows\system32\CodeIntegrity
2014-12-12 17:27:19 ----D---- C:\Program Files\Common Files\microsoft shared
2014-12-12 17:26:16 ----D---- C:\Windows\registration
2014-12-12 17:21:57 ----D---- C:\Windows\AppCompat
2014-12-12 17:19:34 ----SD---- C:\ProgramData\Microsoft
2014-12-09 20:54:24 ----RSD---- C:\Windows\Media
2014-12-05 19:48:31 ----D---- C:\Windows\Microsoft.NET
2014-12-04 17:10:09 ----D---- C:\Windows\ehome
2014-12-04 17:10:08 ----D---- C:\Program Files\Common Files\System
2014-12-04 17:10:06 ----D---- C:\Program Files\Windows Journal
2014-12-04 11:41:33 ----D---- C:\Windows\system32\migration
2014-12-04 11:41:33 ----D---- C:\Windows\AppPatch
2014-12-04 11:41:29 ----D---- C:\Windows\system32\Dism
2014-12-04 11:41:27 ----D---- C:\Windows\system32\drivers\cs-CZ
2014-12-04 11:41:15 ----D---- C:\Program Files\Windows Media Player
2014-12-04 11:41:03 ----D---- C:\Program Files\Windows Defender
2014-12-04 11:40:49 ----D---- C:\Windows\system32\zh-TW
2014-12-04 11:40:49 ----D---- C:\Windows\system32\zh-HK
2014-12-04 11:40:49 ----D---- C:\Windows\system32\tr-TR
2014-12-04 11:40:49 ----D---- C:\Windows\system32\sv-SE
2014-12-04 11:40:49 ----D---- C:\Windows\system32\pt-PT
2014-12-04 11:40:49 ----D---- C:\Windows\system32\pt-BR
2014-12-04 11:40:49 ----D---- C:\Windows\system32\pl-PL
2014-12-04 11:40:49 ----D---- C:\Windows\system32\nl-NL
2014-12-04 11:40:49 ----D---- C:\Windows\system32\ko-KR
2014-12-04 11:40:49 ----D---- C:\Windows\system32\it-IT
2014-12-04 11:40:49 ----D---- C:\Windows\system32\hu-HU
2014-12-04 11:40:49 ----D---- C:\Windows\system32\fr-FR
2014-12-04 11:40:49 ----D---- C:\Windows\system32\fi-FI
2014-12-04 11:40:49 ----D---- C:\Windows\system32\es-ES
2014-12-04 11:40:49 ----D---- C:\Windows\system32\el-GR
2014-12-04 11:40:48 ----D---- C:\Windows\system32\zh-CN
2014-12-04 11:40:48 ----D---- C:\Windows\system32\ru-RU
2014-12-04 11:40:48 ----D---- C:\Windows\system32\nb-NO
2014-12-04 11:40:48 ----D---- C:\Windows\system32\ja-JP
2014-12-04 11:40:48 ----D---- C:\Windows\system32\de-DE
2014-12-04 11:40:48 ----D---- C:\Windows\system32\da-DK
2014-12-04 09:54:02 ----D---- C:\Windows\Logs
2014-12-01 20:32:01 ----SHD---- C:\Boot
2014-12-01 20:28:42 ----D---- C:\Windows\system32\wdi
2014-12-01 20:27:41 ----D---- C:\Program Files\Windows Sidebar
2014-12-01 20:27:41 ----D---- C:\Program Files\Windows Portable Devices
2014-12-01 20:27:41 ----D---- C:\Program Files\Windows Photo Viewer
2014-12-01 20:27:41 ----D---- C:\Program Files\Windows Mail
2014-12-01 20:27:41 ----D---- C:\Program Files\DVD Maker
2014-12-01 20:27:39 ----D---- C:\Windows\servicing
2014-12-01 20:27:31 ----D---- C:\Windows\system32\sysprep
2014-12-01 20:27:31 ----D---- C:\Windows\system32\oobe
2014-12-01 20:27:31 ----D---- C:\Windows\system32\AdvancedInstallers
2014-12-01 20:27:30 ----D---- C:\Windows\system32\Setup
2014-12-01 20:27:30 ----D---- C:\Windows\system32\cs
2014-12-01 20:27:28 ----D---- C:\Windows\system32\sppui
2014-12-01 20:27:28 ----D---- C:\Windows\system32\manifeststore
2014-12-01 20:27:26 ----D---- C:\Windows\system32\migwiz
2014-12-01 20:26:56 ----D---- C:\Windows\system32\Boot
2014-12-01 09:33:05 ----A---- C:\Windows\system32\msclmd.dll
2014-11-29 11:06:29 ----D---- C:\Windows\system32\XPSViewer
2014-11-29 11:06:28 ----D---- C:\Windows\system32\spp
2014-11-29 11:06:28 ----D---- C:\Windows\system32\Speech
2014-11-29 11:06:26 ----D---- C:\Windows\system32\MUI
2014-11-29 11:02:09 ----D---- C:\Windows\system32\LogFiles

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-11-29 243128]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2010-10-28 4245568]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2010-12-15 301608]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-12-15 93224]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2010-12-15 114728]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-12-15 33320]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-12-15 18728]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2011-03-10 1282688]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-03-30 10542080]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-03-30 269824]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x86.sys [2011-01-25 68720]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 23256]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-12-27 114904]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 51928]
R3 MEI;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECI.sys [2010-10-19 41088]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-04-08 1338160]
R3 vm2uvcflt;Vimicro USB Camera Filter 2; C:\Windows\System32\Drivers\vm2uvcflt.sys [2010-09-21 12624]
R3 vm332avs;Lenovo Camera2; C:\Windows\System32\Drivers\vm332avs.sys [2010-12-10 203088]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2010-09-30 218624]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2010-12-14 656672]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-01-05 936208]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-01-05 477456]
R2 TeamViewer;TeamViewer 10; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2014-12-15 5426448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-16 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-16 107912]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-12-19 114800]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-01-05 227600]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Gilina
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 27 pro 2014 03:11

Re: kontrola po MBAM

#4 Příspěvek od Gilina »

info.txt logfile of random's system information tool 1.10 2014-12-27 09:56:21

======MBR======

0x33C08ED0BC007C8EC08ED8BE007CBF0006B90002FCF3A450681C06CBFBB90400BDBE07807E00007C0B0F850E0183C510E2F1CD1888560055C6461105C6461000B441BBAA55CD135D720F81FB55AA7509F7C101007403FE46106660807E1000742666680000000066FF760868000068007C680100681000B4428A56008BF4CD139F83C4109EEB14B80102BB007C8A56008A76018A4E028A6E03CD136661731CFE4E11750C807E00800F848A00B280EB845532E48A5600CD135DEB9E813EFE7D55AA756EFF7600E88D007517FAB0D1E664E88300B0DFE660E87C00B0FFE664E87500FBB800BBCD1A6623C0753B6681FB54435041753281F90201722C666807BB00006668000200006668080000006653665366556668000000006668007C0000666168000007CD1A5A32F6EA007C0000CD18A0B707EB08A0B607EB03A0B50732E40500078BF0AC3C007409BB0700B40ECD10EBF2F4EBFD2BC9E464EB002402E0F82402C3496E76616C696420706172746974696F6E207461626C65004572726F72206C6F6164696E67206F7065726174696E672073797374656D004D697373696E67206F7065726174696E672073797374656D000000637B9A6706DCDB000080FEFFFF07FEFFFF000871020078841E00FEFFFF07FEFFFF0088F52041C44219000000000000000000000000000000000000000000000000000000000000000055AA

======Uninstall list======

-->C:\Program Files\Conexant\SAII\SETUP.EXE -U -ISAII -SM=SmartAudio.EXE,1801
AION Free-to-Play-->"C:\Program Files\GameforgeLive\Games\GBR_eng\AION\unins000.exe"
AllCheapPrice-->"C:\ProgramData\AllCheapPrice\aHGZwySegfPMo3.exe" /s /n /i:"ExecuteCommands;UninstallCommands" ""
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver-->"C:\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -removeonly
ATI Catalyst Install Manager-->msiexec /q/x{084A0863-6C27-9180-87E6-D34C4DAD78DE} REBOOT=ReallySuppress
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -G -IPIWCC2xa.inf
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
DigiSaver-->"C:\ProgramData\DigiSaver\ypqlDMtzQmDDuS.exe" /s /n /i:"ExecuteCommands;UninstallCommands" ""
Gameforge Live 2.0.5-->"C:\Program Files\GameforgeLive\unins000.exe"
Google Chrome-->"C:\Program Files\Google\Chrome\Application\39.0.2171.71\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Intel PROSet Wireless-->Intel PROSet Wireless
Intel(R) Processor Graphics-->C:\Program Files\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Java 8 Update 25-->MsiExec.exe /I{26A24AE4-039D-4CA4-87B4-2F83218025F0}
League of Legends-->msiexec.exe /x {6B84E528-9705-4D36-9C97-97B8E23DAB75}
League of Legends-->MsiExec.exe /X{6B84E528-9705-4D36-9C97-97B8E23DAB75}
Lenovo Bluetooth with Enhanced Data Rate Software-->MsiExec.exe /X{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}
Lenovo EasyCamera-->C:\Program Files\InstallShield Installation Information\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}\setup.exe -runfromtemp -l0x0009 -removeonly
Lenovo_Wireless_Driver-->C:\Program Files\InstallShield Installation Information\{28ABE740-47F3-441B-9437-852F6A64EFF8}\setup.exe -runfromtemp -l0x0009 -removeonly
Malwarebytes Anti-Malware verze 2.0.4.1028-->"C:\Program Files\Malwarebytes Anti-Malware\unins000.exe"
Microsoft .NET Framework 4.5.1 (CSY)-->MsiExec.exe /X{123F4E9B-80E6-3A84-BDD4-3CB3AC59ABF0}
Microsoft .NET Framework 4.5.1 (čeština)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\CSY\\Setup.exe /repair /x86 /lcid 1029
Microsoft .NET Framework 4.5.1-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\\Setup.exe /repair /x86
Microsoft .NET Framework 4.5.1-->MsiExec.exe /X{4903D172-DCCB-392F-93A3-34CA9D47FE3D}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Mozilla Firefox 34.0.5 (x86 cs)-->"C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
Mozilla Maintenance Service-->"C:\Program Files\Mozilla Maintenance Service\uninstall.exe"
Realtek USB 2.0 Reader Driver-->"C:\Program Files\InstallShield Installation Information\{62BBB2F0-E220-4821-A564-730807D2C34D}\setup.exe" -runfromtemp -removeonly
RegularDeals-->"C:\ProgramData\RegularDeals\45vZllCxKRUihO.exe" /s /n /i:"ExecuteCommands;UninstallCommands" ""
SaveNewaAppz-->"C:\ProgramData\SaveNewaAppz\Y6RBA6Vnt0cFhw.exe" /s /n /i:"ExecuteCommands;UninstallCommands" ""
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\setup.exe /uninstallpatch {8086EDC0-3409-3560-B108-44FC46882443}
Skype™ 6.22-->MsiExec.exe /X{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
Software Intel(R) PROSet/Wireless WiFi-->MsiExec.exe /I{1927E640-A2C6-4BA7-8F43-FFD2AE3DFCF3}
Synaptics Pointing Device Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
TeamViewer 10-->C:\Program Files\TeamViewer\uninstall.exe
Ubisoft Game Launcher-->"C:\Program Files\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409 -removeonly
WinRAR 5.11 (32-bit)-->C:\Program Files\WinRAR\uninstall.exe

======System event log======

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247D28-05
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPDriverNotFound
Reakce: Není k dispozici
ID souboru CAB: 0

Podpis problému:
P1: x86
P2: PCI\VEN_8086&DEV_1C3A&SUBSYS_397517AA&REV_04
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

Připojené soubory:
C:\Windows\Temp\DMIBE7D.tmp.log.xml

Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_17bc19cbcf3d3ce75f2f020944546f0c9b0d4de_cab_01b2becb

Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: fa4701cd-6d27-11e4-b6b5-c45e4bd94ef5
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20141116003200.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20141116003032.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20141116003029.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141116003027.612151-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20141116003027.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: 37L4247D28-05
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141116002953.182890-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x1bc
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141116002953.182890-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x2201a
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141116002946.942879-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141116002945.757277-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141116002945.726077-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\Lenovo\Bluetooth Software\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 42 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=2a07

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7321
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: kontrola po MBAM

#5 Příspěvek od altrok »

:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Clean
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Gilina
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 27 pro 2014 03:11

Re: kontrola po MBAM

#6 Příspěvek od Gilina »

# AdwCleaner v4.106 - Report created 27/12/2014 at 14:14:52
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : LENOVO - LENOVO-PC
# Running from : C:\Users\LENOVO\Downloads\adwcleaner_4.106.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\ClickIT
Folder Deleted : C:\ProgramData\DigiSaver
Folder Deleted : C:\ProgramData\Trusted Publisher
Folder Deleted : C:\ProgramData\SaveNewaAppz
Folder Deleted : C:\ProgramData\485afbbff108764f
Folder Deleted : C:\ProgramData\5213756320435959375
File Deleted : C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
File Deleted : C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\..9
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{260a11ee-ed95-43bc-9814-d8acd8c23ece}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3625f6df-8ad3-489a-96ce-01cb20e73fe8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5d4b7c5e-2d26-4030-8f46-dc935216447b}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86f485cb-5a10-4335-b9de-4d898a20f67f}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{d88e3a19-bc9e-44d6-943b-72276a2211ba}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{260a11ee-ed95-43bc-9814-d8acd8c23ece}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3625f6df-8ad3-489a-96ce-01cb20e73fe8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5d4b7c5e-2d26-4030-8f46-dc935216447b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{86f485cb-5a10-4335-b9de-4d898a20f67f}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d88e3a19-bc9e-44d6-943b-72276a2211ba}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7223EDAC-E091-B3C1-BD91-B66CE557800F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A1D3F9E-73B5-95EC-1233-6646E1358965}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7304C9D1-98AD-55F0-636E-22D8DD57F176}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{76DEE3DC-2B8B-E212-2126-D31D9E73DFE4}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v34.0.5 (x86 cs)

[d9e719hf.default\prefs.js] - Line Deleted : user_pref("extensions.Nby2ZIydFP6erWtA.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[d9e719hf.default\prefs.js] - Line Deleted : user_pref("extensions.QTv4q1yHjXCXe2ME.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[d9e719hf.default\prefs.js] - Line Deleted : user_pref("extensions.ajONB1mwhbYiU8fN.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[d9e719hf.default\prefs.js] - Line Deleted : user_pref("extensions.muex2SRxzcry7sdo.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]

-\\ Google Chrome v39.0.2171.71

[C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Homepage] : hxxp://search.gboxapp.com/
[C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://search.gboxapp.com/

*************************

AdwCleaner[R0].txt - [4670 octets] - [27/12/2014 14:03:18]
AdwCleaner[R1].txt - [4730 octets] - [27/12/2014 14:08:41]
AdwCleaner[S0].txt - [4320 octets] - [27/12/2014 14:14:52]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4380 octets] ##########

altrok
Moderátor
Moderátor
Příspěvky: 7321
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: kontrola po MBAM

#7 Příspěvek od altrok »

:arrow: Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm
  • spustte jako spravce
  • do velkeho okna zkopirujte script uvedeny nize
  • kliknete na Run script
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi

    Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět