Премини към съдържанието

Препоръчан отговор


Работи бавно както в интернет така и когато търса нещо в компютъра.Има доста процеси в таск менажера но не знам кои да махна.Компютъра е служебен и ми казаха че има мониторинг но не знаят точно какъв и да внимавам да не го изтрия.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2015
Ran by Administrator (administrator) on GLBG1543PC02 on 10-06-2015 09:01:43
Running from D:\Users\Administrator\Desktop
Loaded Profiles: Administrator &  (Available Profiles: Librarian & Visitor & Administrator)
Platform: Microsoft Windows 7 Enterprise  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Family Safety\fsssvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(OCS Inventory NG) C:\Program Files\OCS Inventory Agent\OcsService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [startCCC] => c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-07-13] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-05-31] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-21] (Avast Software s.r.o.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
Winlogon\Notify\avldr: avldr.dll [X]
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.)
HKU\S-1-5-19\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\Librarian\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-31] (Google Inc.)
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Facebook Update] => C:\Users\Librarian\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-24] (Facebook Inc.)
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Yahoo! Search] => C:\Users\Librarian\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe [533352 2014-10-31] (Pay By Ads LTD)
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\Visitor\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-08] (Google Inc.)
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Yahoo! Search] => C:\Users\Visitor\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrlte.exe [644352 2015-04-06] (Pay By Ads LTD)
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {e1cfbb30-26f5-11e1-8429-806e6f6e6963} - F:\setup.exe
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-299244719-1399796724-3294634451-500\...\MountPoints2: {4f5b41b8-3f6a-11e2-a03f-3cd92b637c04} - G:\Autoplay.exe -auto
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {4f5b41b8-3f6a-11e2-a03f-3cd92b637c04} - G:\Autoplay.exe -auto
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015-06-09] ()
Startup: C:\Users\Librarian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2012-04-17]
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Administrator\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-05-21] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-299244719-1399796724-3294634451-1006\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-299244719-1399796724-3294634451-1005\User: Group Policy Restriction detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/p/?LinkId=255141
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://rts.dsrlte.com?affID=na
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://rts.dsrlte.com?affID=na
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://rts.dsrlte.com?affID=na
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://rts.dsrlte.com?affID=na
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://rts.dsrlte.com?affID=na
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://rts.dsrlte.com?affID=na
URLSearchHook: HKLM - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871}
URLSearchHook: HKLM - (No Name) - {FE69C007-C452-4d3e-86D2-1730DF8BC871} -  No File
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
SearchScopes: HKLM -> {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=129&systemid=473&v=n13452-488&apn_uid=3353606502134112&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM -> {7182CC3C-E589-4389-7306-16715D3A4C42} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=944&systemid=2&apn_dtid=IME002&apn_ptnrs=AG2&o=APN10641&apn_uid=0222813120954441&q={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByCtAyB0CtDyE0D0BtC0CtN0D0Tzu0CtAtBtCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1760736312
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {DDFDC732-AAD1-47A8-8776-3550658B2875} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=738
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss_Btisdt7&mntrId=9C433CD92B637C04&affID=121565&tsp=5008
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=129&systemid=473&v=n13452-488&apn_uid=3353606502134112&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {7182CC3C-E589-4389-7306-16715D3A4C42} URL = http://search.babylon.com/?q={searchTerms}&AF=110393&babsrc=SP_ss&mntrId=9c43db1c0000000000003cd92b637c04
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=944&systemid=2&apn_dtid=IME002&apn_ptnrs=AG2&o=APN10641&apn_uid=0222813120954441&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {BA967819-B32C-4ED8-B04E-05D2A406477C} URL = http://www.mysearchresults.com/search?c=8004&t=11&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} URL = http://search.conduit.com/Results.aspx?ctid=CT3310393&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP6CFCCE7A-1268-4F59-949C-754A9EE916F8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {ECDD8EEE-1125-4213-A34F-F1E0BD72846F} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=980
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss_Btisdt7&mntrId=9C433CD92B637C04&affID=121565&tsp=5008
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=129&systemid=473&v=n13452-488&apn_uid=3353606502134112&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7182CC3C-E589-4389-7306-16715D3A4C42} URL = http://search.babylon.com/?q={searchTerms}&AF=110393&babsrc=SP_ss&mntrId=9c43db1c0000000000003cd92b637c04
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=944&systemid=2&apn_dtid=IME002&apn_ptnrs=AG2&o=APN10641&apn_uid=0222813120954441&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {BA967819-B32C-4ED8-B04E-05D2A406477C} URL = http://www.mysearchresults.com/search?c=8004&t=11&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} URL = http://search.conduit.com/Results.aspx?ctid=CT3310393&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP6CFCCE7A-1268-4F59-949C-754A9EE916F8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {ECDD8EEE-1125-4213-A34F-F1E0BD72846F} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=980
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-05-21] (Avast Software s.r.o.)
BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} ->  No File
Toolbar: HKLM - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM - No Name - {FE69C007-C452-4d3e-86D2-1730DF8BC871} -  No File
Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: AutorunsDisabled\skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default
FF NewTab: 
FF DefaultSearchEngine: Bing 
FF SearchEngineOrder.1: Ask.com
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Bing 
FF Keyword.URL: 
FF Homepage: hxxp://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=en-us|hxxp://rts.dsrlte.com?affID=na
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-21] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-09-12] (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-09-12] (globalUpdate)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\Librarian\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll [2014-10-31] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\Librarian\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll [2014-10-31] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: facebook.com/fbDesktopPlugin -> C:\Users\Librarian\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll [2013-03-07] (Facebook, Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\Visitor\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-06] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\Visitor\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-06] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500: @tools.google.com/Google Update;version=3 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500: @tools.google.com/Google Update;version=9 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF user.js: detected! => C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\user.js [2013-09-17]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Ask.xml [2014-10-02]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\bingp.xml [2015-04-03]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\browsemngr.xml [2012-11-13]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\conduit-search.xml [2013-09-26]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\dsrlte.xml [2015-01-22]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Funmoods.xml [2012-11-16]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\mixidj.xml [2013-09-17]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Search_Results.xml [2012-11-12]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml [2014-10-02]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml [2014-10-02]
FF Extension: Default Tab - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\addon@defaulttab.com [2013-09-17]
FF Extension: Funmoods.com - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\ffxtlbr@funmoods.com [2012-11-16]
FF Extension: new game - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\Sq3TM@gmail.com [2015-04-02]
FF Extension: Casual Games - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\ZAGeTQ8H@gmail.com [2015-05-28]
FF Extension: Ask New Tabs - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{9A7DF664-82DC-020F-C190-9A665AF83389} [2014-04-09]
FF Extension: SimilarSites - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{E71B541F-5E72-5555-A47C-E47863195841} [2013-04-11]
FF Extension: Flash Video Downloader - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\artur.dubovoy@gmail.com.xpi [2012-09-25]
FF Extension: SmileysWeLove: Smileys for use with Facebook, GMail, and more - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi [2014-02-26]
FF Extension: Feedback - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\testpilot@labs.mozilla.com.xpi [2012-12-04]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-09-25]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-01-10]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\addon@defaulttab.com.xpi [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\services-sync.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox-branding.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox-l10n.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox.js [2013-08-12]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\my-prefs.js [2015-03-25] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\mozilla.cfg [2007-04-03] <==== ATTENTION
 
Chrome: 
=======
CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-08]
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-08]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-25]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-25]
CHR Extension: (Google Search) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-25]
CHR Extension: (MSN Homepage & Bing Search Engine) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-06-08]
CHR Extension: (Google Sheets) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-08]
CHR Extension: (Bookmark Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-24]
CHR Extension: (Avast Online Security) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-06-08]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-25]
CHR HKLM\...\Chrome\Extension: [eiimolhnbbbdagljikeckdkldgemmmlj] - C:\Program Files\lucky leap\eiimolhnbbbdagljikeckdkldgemmmlj.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-21]
CHR HKLM\...\Chrome\Extension: [hidjnkeodmholilgafgdlgmgggbhnigl] - C:\Users\Administrator\AppData\Roaming\SimilarSites\similarsites.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [mpfapcdfbbledbojijcbcclmlieaoogk] - C:\Users\Administrator\AppData\Local\I Want This\Chrome\I Want This.crx [Not Found]
CHR HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
 
Opera: 
=======
OPR Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\lnpddjhhjmmcnjbjdbopmniafbpfppkb [2015-05-28]
OPR Extension: (lucky leap) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom [2015-04-20]
OPR Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\onbakjbemhciecaakohbeichgilnhhne [2015-04-21]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AgentService; C:\Program Files\LibraryClient\globalLibx32\service.exe [46592 2012-02-20] () [File not signed]
R2 AMD FUEL Service; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2011-07-13] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-21] (Avast Software s.r.o.)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [107448 2015-05-21] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3207800 2015-05-21] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 OCS Inventory Service; C:\Program Files\OCS Inventory Agent\OcsService.exe [38912 2013-04-08] (OCS Inventory NG) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 bProtector; C:\ProgramData\bProtector\bProtect.exe [X]
S4 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /svc [X] <==== ATTENTION
S4 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X] <==== ATTENTION
S2 Util lucky leap; "C:\Program Files\lucky leap\bin\utilluckyleap.exe" [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AODDriver4.01; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [39424 2011-06-24] (Advanced Micro Devices) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-05-21] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26096 2015-05-21] (Avast Software s.r.o.)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [74976 2015-05-21] (Avast Software s.r.o.)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [271248 2015-05-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-05-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-05-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787760 2015-05-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427992 2015-05-21] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-05-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209048 2015-05-21] ()
S3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [131064 2014-05-14] (HID Global Corporation)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [41984 2008-10-28] (Samsung Electronics Co., Ltd.) [File not signed]
S3 ebdrv; C:\Windows\system32\DRIVERS\evbdx.sys [3100160 2009-07-14] (Broadcom Corporation) [File not signed]
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-17] (Elaborate Bytes AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R1 MpKsl436a8c4f; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{81093FBA-0347-46D4-A016-D06A4B3C8376}\MpKsl436a8c4f.sys [39464 2015-06-09] (Microsoft Corporation)
R1 MpKsl9f5dc433; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{81093FBA-0347-46D4-A016-D06A4B3C8376}\MpKsl9f5dc433.sys [39464 2015-06-10] (Microsoft Corporation)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2008-10-27] (Samsung Electronics) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-05-21] (Avast Software)
R1 {3b232d24-d5de-4194-b4d7-d53b41a09748}w; C:\Windows\System32\drivers\{3b232d24-d5de-4194-b4d7-d53b41a09748}w.sys [52416 2014-09-10] (StdLib)
R1 {6ed88207-da38-4867-b856-ed5820836aa5}w; C:\Windows\System32\drivers\{6ed88207-da38-4867-b856-ed5820836aa5}w.sys [43152 2014-11-27] (StdLib)
R1 {d7e589a9-c9af-419b-8b29-f43cc9595584}w; C:\Windows\System32\drivers\{d7e589a9-c9af-419b-8b29-f43cc9595584}w.sys [43152 2014-11-30] (StdLib)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 yoqododh; \??\C:\Windows\system32\drivers\yoqododh.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-10 09:04 - 2015-06-10 09:04 - 00000000 ____D C:\Program Files\Microsoft Office
2015-06-10 08:56 - 2015-06-10 09:02 - 00000000 ____D C:\FRST
2015-06-09 09:04 - 2015-05-24 12:40 - 00593048 ____N (Sysinternals - www.sysinternals.com) C:\autorunsc.exe
2015-06-09 09:04 - 2015-05-24 12:39 - 00680600 ____N (Sysinternals - www.sysinternals.com) C:\Autoruns.exe
2015-06-09 09:04 - 2014-06-28 16:47 - 00002028 ____N C:\Eula.txt
2015-06-09 08:34 - 2015-06-09 08:34 - 00000000 ____D C:\Users\Administrator\AppData\Local\{9B08D2F6-41FE-40B1-8E2D-67A5F54D5468}
2015-06-08 11:46 - 2015-06-08 11:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\VSRevoGroup
2015-06-08 11:43 - 2015-06-08 11:43 - 00000000 ____D C:\Program Files\VS Revo Group
2015-06-08 10:09 - 2015-06-10 08:35 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-08 10:09 - 2015-06-08 10:09 - 00001026 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-08 10:09 - 2015-06-08 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-08 10:08 - 2015-06-08 10:09 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-08 10:08 - 2015-06-08 10:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-08 10:08 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-08 10:08 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-08 10:08 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-08 08:46 - 2015-06-08 08:47 - 00000000 ____D C:\Users\Administrator\AppData\Local\{55898BB4-84DB-4972-A6D3-1C422794C945}
2015-06-05 13:14 - 2015-05-22 21:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-05 13:14 - 2015-05-22 20:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-05 13:14 - 2015-05-21 16:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-05 13:01 - 2015-06-05 13:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\{B049210D-E73B-4D44-970C-05480D1A0D2B}
2015-06-02 10:06 - 2015-06-04 10:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\{2E0E6D98-968E-4C86-8268-82718DF5A82A}
2015-05-29 09:12 - 2015-05-29 09:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\{6CA558CC-73B4-4398-95F9-E50444B2C26F}
2015-05-28 13:26 - 2015-06-09 13:58 - 00000448 _____ C:\Windows\Tasks\casual_games_helper_service.job
2015-05-28 13:26 - 2015-05-28 13:26 - 00000000 ____D C:\Program Files\Casual Games
2015-05-28 10:46 - 2015-05-28 10:46 - 00000000 ____D C:\Users\Administrator\AppData\Local\{BD0DDE8F-FFF3-4EC5-83CF-F95D466E12EF}
2015-05-27 12:16 - 2015-05-27 12:16 - 00000000 ____D C:\Users\Administrator\AppData\Local\{C3E4B2B2-DF21-425B-A86D-13700E573D2E}
2015-05-26 12:50 - 2015-05-26 12:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\{A5570127-7FF7-45DB-88E2-DD178A14086B}
2015-05-25 12:51 - 2015-06-09 13:58 - 00001040 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-500UA.job
2015-05-25 12:51 - 2015-06-09 13:58 - 00000988 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-500Core.job
2015-05-25 11:49 - 2015-05-25 11:49 - 00000000 ____D C:\Users\Administrator\AppData\Local\{8B24C122-E5A7-4B6C-8C5E-8B75D03CF937}
2015-05-22 09:27 - 2015-05-22 09:27 - 00000000 ____D C:\Users\Administrator\AppData\Local\{E68D8378-FC2E-4AE7-8193-639A705BDA72}
2015-05-21 13:02 - 2015-05-21 13:03 - 00000000 ____D C:\Windows\system32\vbox
2015-05-21 12:53 - 2015-05-21 12:52 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-05-21 12:53 - 2015-05-21 12:52 - 00026096 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswKbd.sys
2015-05-21 12:52 - 2015-05-21 12:52 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-05-21 12:51 - 2015-05-21 12:51 - 00271248 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswNdisFlt.sys
2015-05-21 11:18 - 2015-05-21 11:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\{A159BB46-20C8-4923-BFD7-1B9B3B92EB9E}
2015-05-20 13:15 - 2015-05-20 13:16 - 00000000 ____D C:\Users\Administrator\AppData\Local\{D1FB0108-07FA-437F-9A97-A09534B49E55}
2015-05-19 09:43 - 2015-05-19 09:43 - 00000000 ____D C:\Users\Administrator\AppData\Local\{0F2D45D9-FF5C-46B5-B01F-4ABD68CD81C6}
2015-05-18 10:17 - 2015-05-18 10:17 - 00000000 ____D C:\Users\Administrator\AppData\Local\{6B81EFE9-D98C-4433-9719-07394B3803EE}
2015-05-15 10:45 - 2015-05-15 10:45 - 00000000 ____D C:\Users\Administrator\AppData\Local\{5E21014A-BBCB-4F87-A403-C2A4E99D190D}
2015-05-13 12:25 - 2015-05-01 16:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 10:29 - 2015-02-18 10:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-13 10:29 - 2015-01-29 06:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 10:28 - 2015-05-05 04:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 10:28 - 2015-04-27 22:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-05-13 10:28 - 2015-04-27 22:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-13 10:28 - 2015-04-27 22:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-13 10:28 - 2015-04-27 22:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-13 10:28 - 2015-04-27 22:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-13 10:28 - 2015-04-27 22:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-13 10:28 - 2015-04-27 22:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-13 10:28 - 2015-04-27 22:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-13 10:28 - 2015-04-27 22:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-13 10:28 - 2015-04-27 21:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-13 10:28 - 2015-04-27 21:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-13 10:28 - 2015-04-27 21:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 10:28 - 2015-04-20 05:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 10:28 - 2015-04-20 05:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 10:28 - 2015-04-20 05:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 10:28 - 2015-04-18 05:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 10:27 - 2015-04-22 04:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 10:27 - 2015-04-21 19:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 10:27 - 2015-04-21 19:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 10:27 - 2015-04-21 19:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 10:27 - 2015-04-21 19:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 10:27 - 2015-04-21 19:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-13 10:27 - 2015-04-21 19:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-13 10:27 - 2015-04-21 19:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 10:27 - 2015-04-21 19:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-13 10:27 - 2015-04-21 19:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 10:27 - 2015-04-21 19:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 10:27 - 2015-04-21 19:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-13 10:27 - 2015-04-21 19:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 10:27 - 2015-04-21 18:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 10:27 - 2015-04-21 18:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 10:27 - 2015-04-21 18:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-13 10:27 - 2015-04-21 18:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-13 10:27 - 2015-04-21 18:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 10:27 - 2015-04-21 18:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 10:27 - 2015-04-21 18:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 10:27 - 2015-04-21 18:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-13 10:27 - 2015-04-21 18:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 10:27 - 2015-04-21 18:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 10:27 - 2015-04-21 18:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 10:27 - 2015-04-21 18:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 10:27 - 2015-04-21 18:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 10:27 - 2015-04-21 18:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 10:27 - 2015-04-21 18:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-13 10:27 - 2015-04-21 18:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 10:27 - 2015-04-21 18:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 10:27 - 2015-04-21 17:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 10:27 - 2015-04-21 17:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 10:27 - 2015-04-13 06:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 10:24 - 2015-04-08 06:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-13 10:24 - 2015-04-08 06:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-13 10:24 - 2015-03-04 07:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-13 10:24 - 2015-03-04 07:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-13 10:24 - 2015-03-04 07:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-13 10:24 - 2015-03-04 07:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 09:39 - 2015-05-13 09:39 - 00000000 ____D C:\Users\Administrator\AppData\Local\{D8D53B24-10D1-46A4-A214-E7C7BD2096B8}
2015-05-11 08:49 - 2015-05-11 08:50 - 00000000 ____D C:\Users\Administrator\AppData\Local\{FD17A642-E643-4744-9064-EC6601204F7A}
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-10 09:05 - 2010-10-24 22:53 - 01257428 _____ C:\Windows\WindowsUpdate.log
2015-06-10 09:05 - 2010-10-24 20:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 08:48 - 2009-07-14 07:34 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-10 08:48 - 2009-07-14 07:34 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-10 08:34 - 2012-06-25 14:19 - 06455142 _____ C:\XrxUsd.log
2015-06-10 08:34 - 2010-10-25 14:50 - 00000000 ____D C:\Users\Administrator
2015-06-10 08:33 - 2014-09-12 13:21 - 00003464 _____ C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-7.job
2015-06-10 08:33 - 2014-09-12 13:21 - 00003464 _____ C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-6.job
2015-06-10 08:33 - 2014-09-12 13:20 - 00004490 _____ C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-11.job
2015-06-10 08:33 - 2013-07-02 08:32 - 00027062 _____ C:\Windows\setupact.log
2015-06-10 08:33 - 2009-07-14 07:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-09 16:43 - 2010-10-31 18:37 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype
2015-06-09 13:58 - 2015-04-02 13:48 - 00001304 _____ C:\Windows\Tasks\new_game_notification_service.job
2015-06-09 13:58 - 2015-04-02 13:48 - 00000666 _____ C:\Windows\Tasks\new_game_updating_service.job
2015-06-09 13:58 - 2014-09-12 13:21 - 00000900 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-06-09 13:58 - 2014-09-12 13:21 - 00000896 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-06-09 13:58 - 2013-03-04 10:31 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-09 13:58 - 2013-03-04 10:31 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-09 13:58 - 2012-04-17 12:11 - 00001098 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005UA.job
2015-06-09 13:58 - 2012-04-17 12:11 - 00001076 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005Core.job
2015-06-09 13:58 - 2011-04-04 16:21 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005UA.job
2015-06-09 13:58 - 2011-04-04 16:21 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005Core.job
2015-06-09 13:58 - 2010-10-31 14:28 - 00001016 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1006UA.job
2015-06-09 13:58 - 2010-10-31 14:28 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1006Core.job
2015-06-08 16:52 - 2012-07-04 12:57 - 00000000 ____D C:\Users\Administrator\AppData\Local\I Want This
2015-06-08 16:48 - 2015-04-02 13:48 - 00000000 ____D C:\Program Files\new game
2015-06-08 16:10 - 2015-04-03 08:28 - 00000004 _____ C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-06-08 16:10 - 2011-03-25 20:30 - 00109280 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-08 16:09 - 2013-03-04 10:31 - 00000000 ____D C:\Program Files\Google
2015-06-08 16:09 - 2010-10-24 19:25 - 00331874 _____ C:\Windows\PFRO.log
2015-06-08 16:08 - 2010-10-31 14:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2015-06-08 16:05 - 2013-09-05 11:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-06-08 16:05 - 2013-09-05 11:49 - 00000000 ____D C:\Program Files\Canon
2015-06-08 16:03 - 2013-01-03 11:43 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\calibre
2015-06-08 16:03 - 2013-01-03 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2015-06-08 15:57 - 2009-07-14 07:33 - 03763560 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-08 15:54 - 2012-09-11 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\BitComet
2015-06-08 15:54 - 2012-09-11 14:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit)
2015-06-08 15:35 - 2012-06-13 13:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Opera
2015-06-08 15:35 - 2012-06-13 13:36 - 00000000 ____D C:\Users\Administrator\AppData\Local\Opera
2015-06-08 15:34 - 2014-12-11 15:54 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\PhotoScape
2015-06-08 15:32 - 2013-09-17 15:03 - 00000000 ____D C:\ProgramData\SimilarSites
2015-06-08 15:32 - 2012-11-16 17:42 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\SimilarSites
2015-06-08 15:30 - 2013-06-21 10:16 - 00000000 ____D C:\Program Files\TeamViewer
2015-06-08 15:30 - 2012-11-22 12:50 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TeamViewer
2015-06-08 15:29 - 2012-11-12 15:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\BearShare
2015-06-08 15:27 - 2010-10-30 13:58 - 00000000 ____D C:\Program Files\Windows Live
2015-06-08 15:22 - 2013-09-13 09:50 - 00000000 ____D C:\Users\Administrator\AppData\Local\WebPlayer
2015-06-08 15:21 - 2012-04-26 10:02 - 140266064 _____ C:\xxbgtask.log
2015-06-08 15:12 - 2015-02-02 17:17 - 00000000 ____D C:\Users\Administrator\AppData\Local\Unity
2015-06-08 08:46 - 2009-07-14 05:04 - 00000710 _____ C:\Windows\win.ini
2015-06-08 08:42 - 2014-12-11 13:38 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-08 08:42 - 2014-05-10 08:49 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-05-29 13:42 - 2010-10-24 19:26 - 00980294 _____ C:\Windows\system32\perfh01F.dat
2015-05-29 13:42 - 2010-10-24 19:26 - 00455792 _____ C:\Windows\system32\perfc01F.dat
2015-05-29 13:42 - 2010-10-24 18:25 - 00006444 _____ C:\Windows\system32\PerfStringBackup.INI
2015-05-29 09:16 - 2010-10-24 18:32 - 00000000 ____D C:\ProgramData\Skype
2015-05-26 12:52 - 2013-09-25 13:32 - 00000000 ___RD C:\Program Files\Skype
2015-05-21 12:52 - 2014-09-24 13:10 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-05-21 12:52 - 2014-09-24 13:10 - 00024144 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-05-21 12:52 - 2013-03-04 09:35 - 00209048 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-05-21 12:52 - 2013-03-04 09:35 - 00049904 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00787760 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00427992 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00074976 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-05-15 16:55 - 2009-07-14 10:20 - 00000000 ____D C:\Program Files\Windows Journal
2015-05-15 12:10 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\rescache
2015-05-15 11:18 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-05-15 10:36 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\tr-TR
2015-05-15 10:36 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-15 10:34 - 2010-10-24 18:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-13 12:24 - 2010-10-24 20:22 - 00000039 _____ C:\Windows\vbaddin.ini
2015-05-13 12:23 - 2015-03-04 10:02 - 00002101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Center Endpoint Protection.lnk
2015-05-13 12:23 - 2011-03-25 23:13 - 00001945 _____ C:\Windows\epplauncher.mif
2015-05-13 12:22 - 2013-09-25 13:32 - 00000000 ____D C:\Program Files\Microsoft Security Client
2015-05-13 12:04 - 2013-08-14 18:06 - 00000000 ____D C:\Windows\system32\MRT
2015-05-13 12:04 - 2010-10-24 18:39 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 11:58 - 2010-10-24 18:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
 
==================== Files in the root of some directories =======
 
2014-09-12 13:18 - 2014-09-12 13:18 - 6010880 _____ () C:\Program Files\GUT7668.tmp
2013-01-19 10:44 - 2013-01-19 10:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files\Common Files\atimpenc.dll
2015-03-31 11:14 - 2015-03-31 11:14 - 0005655 _____ () C:\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX
2015-03-31 11:14 - 2015-03-31 11:14 - 0005655 _____ () C:\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX3
2015-03-31 11:14 - 2015-03-31 11:14 - 0004387 _____ () C:\Users\Administrator\AppData\Roaming\KfOwsG9x
2013-09-23 12:52 - 2015-02-17 13:54 - 0000135 _____ () C:\Users\Administrator\AppData\Roaming\WB.CFG
2010-10-29 19:41 - 2014-09-12 13:09 - 0008082 _____ () C:\Users\Administrator\AppData\Roaming\XeroxFaxOptions.xml
2015-03-31 11:14 - 2015-03-31 11:14 - 0004387 _____ () C:\Users\Administrator\AppData\Roaming\xwMEhk3tTuYDvHMsB1V2T
2012-11-16 17:43 - 2012-11-16 17:42 - 0290500 _____ () C:\Users\Administrator\AppData\Local\funmoods-speeddial_sf.crx
2012-11-16 17:43 - 2012-11-16 17:42 - 0031465 _____ () C:\Users\Administrator\AppData\Local\funmoods.crx
2010-10-26 17:33 - 2010-10-26 17:33 - 0000017 _____ () C:\Users\Administrator\AppData\Local\resmon.resmoncfg
2014-04-15 11:35 - 2014-04-15 11:35 - 0005113 _____ () C:\ProgramData\mtbjfghn.xbe
 
Some files in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\DeltaTB.exe
C:\Users\Administrator\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuuimyg.dll
C:\Users\Administrator\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Administrator\AppData\Local\Temp\WSSetup.exe
C:\Users\Visitor\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Visitor\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Visitor\AppData\Local\Temp\tmpCB3A.exe
C:\Users\Visitor\AppData\Local\Temp\_D6.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-06-09 12:15
 
==================== End of log ============================

Addition.txt

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Здравейте!

Важното е да се подчертае, че системата е сериозно инфектирана, а е служебен компютър, затова имайте предвид каква отговорност поемате. Аз мога да обещая, че ще внимавам максимално, за да не я повредим, а точно обратното. Освен това е нужно да работим само и единствено с администраторски права. Ако сте окей с тези неща, нека пристъпим към същинската работа:

Стъпка 1

Имате повече от една инсталирана и активна антивирусна програма. Това е проблем, защото работата на повече от една антивирусна програма едновременно води до конфликт с другата, което пък от своя страна води до незащитена и нестабилна система. Това е една от причините за инфектирането на системата.

Моля, деинсталирайте една от двете антивирусни програми: Avast Internet Security и Panda Antivirus Pro 2012 .

Освен това, деинсталирайте и следните програми: Funmoods, MaintenanceService-Funmoods, Moozy и Yahoo! Search .

След като приключите с всичко, моля рестартирайте компютъра.

Стъпка 2

Изтеглете fixlist.txt и го запазете в папката от която стартирахте FRST.exe.

Стартирайте FRST.exe и натиснете бутона Fix веднъж!

След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.

 

Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

Стъпка 3

Стартирайте Malwarebytes Anti-Malware, обновете я и направете сканиране тип Threat Scan. Накрая публикувайте лог файла си тук.

В следващия си коментар в тази тема, включете следните лог файлове:

  • Лог файл от FRST
  • Лог файл от Malwarebytes Anti-Malware

fixlist.txt

  • Харесва ми 1

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Сега изтрих само moozy предния ден трих доста програми сигурно изтрих и тях.FRST не ми изкара лог.

 

Malwarebytes Anti-Malware

www.malwarebytes.org
 
Дата на сканиране: 11.6.2015 г.
Час на сканиране: 09:25:38 ч.
Дневник: a.txt
Администратор: Да
 
Версия: 2.01.6.1022
База от данни за злонамерен софтуер: v2015.06.11.01
База от данни за рууткити: v2015.06.02.01
Лиценз: Пробен период
Защита от злонамерен софтуер: Разрешено
Защита от злонамерени страници: Разрешено
Самозащита: Забранено
 
ОС: Windows 7 Service Pack 1
Процесор: x86
Файлова система: NTFS
Потребител: Administrator
 
Тип сканиране: Сканиране за заплахи
Резултат: Завършено
Сканиране обекти: 461308
Изминало време: 43 мин. 4 сек.
 
Памет: Разрешено
Начално стартиране: Разрешено
Файлова система: Разрешено
Архиви: Разрешено
Рууткити: Забранено
Евристика: Разрешено
ПНП: Разрешено
ПНИ: Разрешено
 
Процеси: 0
(Не бяха открити злонамерени обекти)
 
Модули: 0
(Не бяха открити злонамерени обекти)
 
Ключове в системния регистър: 0
(Не бяха открити злонамерени обекти)
 
Стойности в системния регистър: 0
(Не бяха открити злонамерени обекти)
 
Данни в системния регистър: 0
(Не бяха открити злонамерени обекти)
 
Папки: 0
(Не бяха открити злонамерени обекти)
 
Файлове: 0
(Не бяха открити злонамерени обекти)
 
Физически сектори: 0
(Не бяха открити злонамерени обекти)
 
 
(end)

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

В такъв случай ми давате стари лог файлове. Освен това, ако сте изпълнили инструкциите ми правилно, няма как да не ви генерира лог файл. Проверете добре, ако го няма повторете процедурата.

И в случай, че вие правите каквито и да било промени по системата, докато работим тук, ще бъда принуден да прекратя работата ни тук.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

този път се появи лога.Извинявам се повече нищо няма да барам без ваше знание

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 08-06-2015
Ran by Administrator at 2015-06-11 11:17:59 Run:2
Running from D:\Users\Administrator\Desktop
Loaded Profiles: Administrator (Available Profiles: Librarian & Visitor & Administrator)
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
start
CloseProcesses:
Task: {0DF0C904-9ECD-4966-9C5F-55EC506EB63D} - System32\Tasks\new_game_updating_service => C:\Program Files\new game\new_game_updating_service.exe <==== ATTENTION
C:\Program Files\new game
C:\Users\ADMINI~1\AppData\Roaming\Funmoods
C:\Program Files\FLV Player Addon
C:\Program Files\globalUpdate
C:\Program Files\MyPC Backup
C:\ProgramData\bProtector
C:\Program Files\lucky leap
Task: {40082259-BF2A-4240-9355-3E4EB8013971} - System32\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-7 => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-7.exe <==== ATTENTION
Task: {41300F42-1703-46D8-BFDF-81490203FD2D} - System32\Tasks\new_game_notification_service => C:\Program Files\new game\new_game_notification_service.exe <==== ATTENTION
Task: {4877EBD6-649A-45D2-88C1-0C2A2D20D467} - System32\Tasks\Funmoods => C:\Users\ADMINI~1\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {5CD11495-3EE8-4B87-A7FC-4FA8E1843928} - System32\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-4 => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-4.exe <==== ATTENTION
Task: {67DC73B0-B07D-4342-91C0-C1B47F3C7239} - System32\Tasks\casual_games_helper_service => C:\Program Files\Casual Games\casual_games_helper_service.exe [2015-05-28] ()
Task: {A1DD53BD-9EEC-43E9-B87C-F922E60512B9} - System32\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-11 => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-11.exe <==== ATTENTION
Task: {B5EA0506-471C-49CC-84A9-0A702CE971F5} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: {C0FF6327-1261-414C-BA3C-9F27393847BB} - \f8aac747-34de-4f0b-948e-395f20e6f50d-6 No Task File <==== ATTENTION
Task: {DC9E7BB2-809F-412F-B0FE-10BE75DED338} - System32\Tasks\LaunchApp => C:\Program Files\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: C:\Windows\Tasks\casual_games_helper_service.job => C:\Program Files\Casual Games\casual_games_helper_service.exe
Task: C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-11.job => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-4.job => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-6.job => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-7.job => C:\Program Files\FLV Player Addon\f8aac747-34de-4f0b-948e-395f20e6f50d-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\new_game_notification_service.job => C:\Program Files\new game\new_game_notification_service.exeг/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='new game' /appid='73143' /srcid='2913' /bic='648227f55db0db856f1f5bd399587498' /verifier='fca1367fe909c2f6d773f88a1a813749' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
Task: C:\Windows\Tasks\new_game_updating_service.job => C:\Program Files\new game\new_game_updating_service.exeЁ/campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=new_game_updating_service /funurl=http:/stats.buildomserv.com <==== ATTENTION
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {e1cfbb30-26f5-11e1-8429-806e6f6e6963} - F:\setup.exe
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-299244719-1399796724-3294634451-1006\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-299244719-1399796724-3294634451-1005\User: Group Policy Restriction detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://dts.search.as...q={searchTerms}
SearchScopes: HKLM -> {7182CC3C-E589-4389-7306-16715D3A4C42} URL = http://dts.search-re...q={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://searchfunmood...E&cr=1760736312
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {DDFDC732-AAD1-47A8-8776-3550658B2875} URL = http://rts.dsrlte.co...rchTerms}&r=738
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol...121565&tsp=5008
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.as...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {7182CC3C-E589-4389-7306-16715D3A4C42} URL = http://search.babylo...0003cd92b637c04
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-re...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {BA967819-B32C-4ED8-B04E-05D2A406477C} URL = http://www.mysearchr...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} URL = http://search.condui...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> {ECDD8EEE-1125-4213-A34F-F1E0BD72846F} URL = http://rts.dsrlte.co...rchTerms}&r=980
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol...121565&tsp=5008
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.as...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7182CC3C-E589-4389-7306-16715D3A4C42} URL = http://search.babylo...0003cd92b637c04
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-re...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {BA967819-B32C-4ED8-B04E-05D2A406477C} URL = http://www.mysearchr...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} URL = http://search.condui...q={searchTerms}
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {ECDD8EEE-1125-4213-A34F-F1E0BD72846F} URL = http://rts.dsrlte.co...rchTerms}&r=980
BHO: No Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} ->  No File
Toolbar: HKLM - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM - No Name - {FE69C007-C452-4d3e-86D2-1730DF8BC871} -  No File
Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab
FF NewTab: 
FF SearchEngineOrder.1: Ask.com
FF Keyword.URL: 
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Ask.xml [2014-10-02]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\browsemngr.xml [2012-11-13]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\conduit-search.xml [2013-09-26]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\dsrlte.xml [2015-01-22]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Funmoods.xml [2012-11-16]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\mixidj.xml [2013-09-17]
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Search_Results.xml [2012-11-12]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml [2014-10-02]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml [2014-10-02]
FF Extension: Default Tab - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\addon@defaulttab.com [2013-09-17]
FF Extension: Funmoods.com - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\ffxtlbr@funmoods.com [2012-11-16]
FF Extension: new game - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\Sq3TM@gmail.com [2015-04-02]
FF Extension: Casual Games - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\ZAGeTQ8H@gmail.com [2015-05-28]
FF Extension: Ask New Tabs - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{9A7DF664-82DC-020F-C190-9A665AF83389} [2014-04-09]
FF Extension: SimilarSites - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{E71B541F-5E72-5555-A47C-E47863195841} [2013-04-11]
FF Extension: SmileysWeLove: Smileys for use with Facebook, GMail, and more - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi [2014-02-26]
FF Extension: Flash Video Downloader - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\artur.dubovoy@gmail.com.xpi [2012-09-25]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\addon@defaulttab.com.xpi [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\my-prefs.js [2015-03-25] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\mozilla.cfg [2007-04-03] <==== ATTENTION
CHR HKLM\...\Chrome\Extension: [eiimolhnbbbdagljikeckdkldgemmmlj] - C:\Program Files\lucky leap\eiimolhnbbbdagljikeckdkldgemmmlj.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [hidjnkeodmholilgafgdlgmgggbhnigl] - C:\Users\Administrator\AppData\Roaming\SimilarSites\similarsites.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [mpfapcdfbbledbojijcbcclmlieaoogk] - C:\Users\Administrator\AppData\Local\I Want This\Chrome\I Want This.crx [Not Found]
CHR HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.goo...ice/update2/crx
CHR HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.goo...ice/update2/crx
OPR Extension: (lucky leap) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom [2015-04-20]
OPR Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\onbakjbemhciecaakohbeichgilnhhne [2015-04-21]
S2 bProtector; C:\ProgramData\bProtector\bProtect.exe [X]
S4 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /svc [X] <==== ATTENTION
S4 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X] <==== ATTENTION
S2 Util lucky leap; "C:\Program Files\lucky leap\bin\utilluckyleap.exe" [X]
S1 yoqododh; \??\C:\Windows\system32\drivers\yoqododh.sys [X]
2015-06-08 08:46 - 2015-06-08 08:47 - 00000000 ____D C:\Users\Administrator\AppData\Local\{55898BB4-84DB-4972-A6D3-1C422794C945}
2015-05-28 13:26 - 2015-06-09 13:58 - 00000448 _____ C:\Windows\Tasks\casual_games_helper_service.job
2015-05-28 13:26 - 2015-05-28 13:26 - 00000000 ____D C:\Program Files\Casual Games
2015-06-09 13:58 - 2015-04-02 13:48 - 00001304 _____ C:\Windows\Tasks\new_game_notification_service.job
2015-06-09 13:58 - 2015-04-02 13:48 - 00000666 _____ C:\Windows\Tasks\new_game_updating_service.job
2015-06-09 13:58 - 2014-09-12 13:21 - 00000900 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-06-09 13:58 - 2014-09-12 13:21 - 00000896 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-06-08 16:52 - 2012-07-04 12:57 - 00000000 ____D C:\Users\Administrator\AppData\Local\I Want This
2015-06-08 15:32 - 2013-09-17 15:03 - 00000000 ____D C:\ProgramData\SimilarSites
2015-06-08 15:32 - 2012-11-16 17:42 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\SimilarSites
2015-06-08 15:29 - 2012-11-12 15:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\BearShare
2014-09-12 13:18 - 2014-09-12 13:18 - 6010880 _____ () C:\Program Files\GUT7668.tmp
2015-03-31 11:14 - 2015-03-31 11:14 - 0005655 _____ () C:\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX
2015-03-31 11:14 - 2015-03-31 11:14 - 0005655 _____ () C:\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX3
2015-03-31 11:14 - 2015-03-31 11:14 - 0004387 _____ () C:\Users\Administrator\AppData\Roaming\KfOwsG9x
2015-03-31 11:14 - 2015-03-31 11:14 - 0004387 _____ () C:\Users\Administrator\AppData\Roaming\xwMEhk3tTuYDvHMsB1V2T
2012-11-16 17:43 - 2012-11-16 17:42 - 0290500 _____ () C:\Users\Administrator\AppData\Local\funmoods-speeddial_sf.crx
2012-11-16 17:43 - 2012-11-16 17:42 - 0031465 _____ () C:\Users\Administrator\AppData\Local\funmoods.crx
2014-04-15 11:35 - 2014-04-15 11:35 - 0005113 _____ () C:\ProgramData\mtbjfghn.xbe
C:\Users\Administrator\AppData\Local\Temp\DeltaTB.exe
C:\Users\Administrator\AppData\Local\Temp\WSSetup.exe
C:\Users\Visitor\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Visitor\AppData\Local\Temp\tmpCB3A.exe
C:\Users\Visitor\AppData\Local\Temp\_D6.exe
EmptyTemp:
end
*****************
 
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DF0C904-9ECD-4966-9C5F-55EC506EB63D} => key not found. 
C:\Windows\System32\Tasks\new_game_updating_service not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\new_game_updating_service => key not found. 
"C:\Program Files\new game" => File/Folder not found.
"C:\Users\ADMINI~1\AppData\Roaming\Funmoods" => File/Folder not found.
"C:\Program Files\FLV Player Addon" => File/Folder not found.
"C:\Program Files\globalUpdate" => File/Folder not found.
"C:\Program Files\MyPC Backup" => File/Folder not found.
"C:\ProgramData\bProtector" => File/Folder not found.
"C:\Program Files\lucky leap" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40082259-BF2A-4240-9355-3E4EB8013971} => key not found. 
C:\Windows\System32\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-7 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\f8aac747-34de-4f0b-948e-395f20e6f50d-7 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41300F42-1703-46D8-BFDF-81490203FD2D} => key not found. 
C:\Windows\System32\Tasks\new_game_notification_service not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\new_game_notification_service => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4877EBD6-649A-45D2-88C1-0C2A2D20D467} => key not found. 
C:\Windows\System32\Tasks\Funmoods not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5CD11495-3EE8-4B87-A7FC-4FA8E1843928} => key not found. 
C:\Windows\System32\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-4 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\f8aac747-34de-4f0b-948e-395f20e6f50d-4 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{67DC73B0-B07D-4342-91C0-C1B47F3C7239} => key not found. 
C:\Windows\System32\Tasks\casual_games_helper_service not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\casual_games_helper_service => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1DD53BD-9EEC-43E9-B87C-F922E60512B9} => key not found. 
C:\Windows\System32\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-11 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\f8aac747-34de-4f0b-948e-395f20e6f50d-11 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5EA0506-471C-49CC-84A9-0A702CE971F5} => key not found. 
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0FF6327-1261-414C-BA3C-9F27393847BB} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\f8aac747-34de-4f0b-948e-395f20e6f50d-6 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC9E7BB2-809F-412F-B0FE-10BE75DED338} => key not found. 
C:\Windows\System32\Tasks\LaunchApp not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchApp => key not found. 
C:\Windows\Tasks\casual_games_helper_service.job not found.
C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-11.job not found.
C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-4.job not found.
C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-6.job not found.
C:\Windows\Tasks\f8aac747-34de-4f0b-948e-395f20e6f50d-7.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job not found.
C:\Windows\Tasks\new_game_notification_service.job not found.
C:\Windows\Tasks\new_game_updating_service.job not found.
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4} => key not found. 
HKCR\CLSID\{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4} => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe => key not found. 
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe => key not found. 
C:\Windows\system32\GroupPolicy\Machine => moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully.
"C:\Windows\system32\GroupPolicyUsers\S-1-5-21-299244719-1399796724-3294634451-1006\User" => File/Folder not found.
"C:\Windows\system32\GroupPolicyUsers\S-1-5-21-299244719-1399796724-3294634451-1005\User" => File/Folder not found.
HKLM\SOFTWARE\Policies\Google => key not found. 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value not found.
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value not found.
HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value not found.
HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{FE69C007-C452-4d3e-86D2-1730DF8BC871} => value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found. 
HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473} => key not found. 
HKCR\CLSID\{52db1893-8a90-4192-aede-08e00b8f8473} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7182CC3C-E589-4389-7306-16715D3A4C42} => key not found. 
HKCR\CLSID\{7182CC3C-E589-4389-7306-16715D3A4C42} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found. 
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found. 
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => value not found.
HKU\S-1-5-21-299244719-1399796724-3294634451-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => value not found.
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DDFDC732-AAD1-47A8-8776-3550658B2875} => key not found. 
HKCR\CLSID\{DDFDC732-AAD1-47A8-8776-3550658B2875} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473} => key not found. 
HKCR\CLSID\{52db1893-8a90-4192-aede-08e00b8f8473} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7182CC3C-E589-4389-7306-16715D3A4C42} => key not found. 
HKCR\CLSID\{7182CC3C-E589-4389-7306-16715D3A4C42} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found. 
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BA967819-B32C-4ED8-B04E-05D2A406477C} => key not found. 
HKCR\CLSID\{BA967819-B32C-4ED8-B04E-05D2A406477C} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} => key not found. 
HKCR\CLSID\{BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ECDD8EEE-1125-4213-A34F-F1E0BD72846F} => key not found. 
HKCR\CLSID\{ECDD8EEE-1125-4213-A34F-F1E0BD72846F} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473} => key not found. 
HKCR\CLSID\{52db1893-8a90-4192-aede-08e00b8f8473} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7182CC3C-E589-4389-7306-16715D3A4C42} => key not found. 
HKCR\CLSID\{7182CC3C-E589-4389-7306-16715D3A4C42} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found. 
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BA967819-B32C-4ED8-B04E-05D2A406477C} => key not found. 
HKCR\CLSID\{BA967819-B32C-4ED8-B04E-05D2A406477C} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} => key not found. 
HKCR\CLSID\{BBE9CA6B-DF88-4665-BCF3-DB5D8B6DF0D6} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ECDD8EEE-1125-4213-A34F-F1E0BD72846F} => key not found. 
HKCR\CLSID\{ECDD8EEE-1125-4213-A34F-F1E0BD72846F} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => key not found. 
HKCR\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} => value not found.
HKCR\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{FE69C007-C452-4d3e-86D2-1730DF8BC871} => value not found.
HKCR\CLSID\{FE69C007-C452-4d3e-86D2-1730DF8BC871} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value not found.
HKCR\CLSID\Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-1006-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value not found.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value not found.
HKCR\CLSID\Toolbar: HKU\S-1-5-21-299244719-1399796724-3294634451-500-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => key not found. 
HKCR\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => key not found. 
Firefox newtab removed successfully.
Firefox SearchEngineOrder.1 removed successfully.
Firefox Keyword.URL removed successfully.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Ask.xml" => not found.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\browsemngr.xml" => not found.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\conduit-search.xml" => not found.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\dsrlte.xml" => not found.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Funmoods.xml" => not found.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\mixidj.xml" => not found.
"C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\Search_Results.xml" => not found.
"C:\Program Files\mozilla firefox\searchplugins\Ask.xml" => not found.
"C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml" => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\addon@defaulttab.com => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\ffxtlbr@funmoods.com => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\Sq3TM@gmail.com => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\ZAGeTQ8H@gmail.com => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{9A7DF664-82DC-020F-C190-9A665AF83389} => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{E71B541F-5E72-5555-A47C-E47863195841} => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\artur.dubovoy@gmail.com.xpi => not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\addon@defaulttab.com.xpi => not found.
"C:\Program Files\mozilla firefox\browser\defaults\preferences\my-prefs.js" => not found.
"C:\Program Files\mozilla firefox\mozilla.cfg" => not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj => key not found. 
HKLM\SOFTWARE\Google\Chrome\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl => key not found. 
HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500\SOFTWARE\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd => key not found. 
HKU\S-1-5-21-299244719-1399796724-3294634451-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd => key not found. 
C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom folder not found.
C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\onbakjbemhciecaakohbeichgilnhhne folder not found.
bProtector => Service not found.
globalUpdate => Service not found.
globalUpdatem => Service not found.
Util lucky leap => Service not found.
yoqododh => Service not found.
"C:\Users\Administrator\AppData\Local\{55898BB4-84DB-4972-A6D3-1C422794C945}" => File/Folder not found.
"C:\Windows\Tasks\casual_games_helper_service.job" => File/Folder not found.
"C:\Program Files\Casual Games" => File/Folder not found.
"C:\Windows\Tasks\new_game_notification_service.job" => File/Folder not found.
"C:\Windows\Tasks\new_game_updating_service.job" => File/Folder not found.
"C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job" => File/Folder not found.
"C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job" => File/Folder not found.
"C:\Users\Administrator\AppData\Local\I Want This" => File/Folder not found.
"C:\ProgramData\SimilarSites" => File/Folder not found.
"C:\Users\Administrator\AppData\Roaming\SimilarSites" => File/Folder not found.
"C:\Users\Administrator\AppData\Local\BearShare" => File/Folder not found.
"C:\Program Files\GUT7668.tmp" => File/Folder not found.
"C:\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX" => File/Folder not found.
"C:\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX3" => File/Folder not found.
"C:\Users\Administrator\AppData\Roaming\KfOwsG9x" => File/Folder not found.
"C:\Users\Administrator\AppData\Roaming\xwMEhk3tTuYDvHMsB1V2T" => File/Folder not found.
"C:\Users\Administrator\AppData\Local\funmoods-speeddial_sf.crx" => File/Folder not found.
"C:\Users\Administrator\AppData\Local\funmoods.crx" => File/Folder not found.
"C:\ProgramData\mtbjfghn.xbe" => File/Folder not found.
"C:\Users\Administrator\AppData\Local\Temp\DeltaTB.exe" => File/Folder not found.
"C:\Users\Administrator\AppData\Local\Temp\WSSetup.exe" => File/Folder not found.
"C:\Users\Visitor\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe" => File/Folder not found.
"C:\Users\Visitor\AppData\Local\Temp\tmpCB3A.exe" => File/Folder not found.
"C:\Users\Visitor\AppData\Local\Temp\_D6.exe" => File/Folder not found.
EmptyTemp: => 39.5 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 11:18:11 ====

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Щом е липсващо това означава, че или защото сте променяли неща, съответно лог файла не е правилния, който сте ми дали, или пък сте го изпълнили вече и втория път дава този резултат, което е нормално.

Генерирайте нови лог файлове от FRST и ги публикувайте тук.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2015
Ran by Administrator (administrator) on GLBG1543PC02 on 11-06-2015 11:33:29
Running from D:\Users\Administrator\Desktop
Loaded Profiles: Administrator (Available Profiles: Librarian & Visitor & Administrator)
Platform: Microsoft Windows 7 Enterprise  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Family Safety\fsssvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(OCS Inventory NG) C:\Program Files\OCS Inventory Agent\OcsService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [startCCC] => c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-07-13] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-05-31] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-21] (Avast Software s.r.o.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation)
Winlogon\Notify\avldr: avldr.dll [X]
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-19\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-299244719-1399796724-3294634451-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2015-06-11]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015-06-09] ()
Startup: C:\Users\Librarian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2012-04-17]
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Administrator\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-05-21] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
SearchScopes: HKU\S-1-5-21-299244719-1399796724-3294634451-500 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
BHO: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2013-11-29] (BitComet)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-05-21] (Avast Software s.r.o.)
Handler: AutorunsDisabled\skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-12] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default
FF DefaultSearchEngine: Bing 
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Bing 
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-21] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll No File
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500: @tools.google.com/Google Update;version=3 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500: @tools.google.com/Google Update;version=9 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF user.js: detected! => C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\user.js [2015-06-11]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\bingp.xml [2015-04-03]
FF Extension: BitComet Video Downloader - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB} [2015-06-10]
FF Extension: Feedback - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\testpilot@labs.mozilla.com.xpi [2012-12-04]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-09-25]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-01-10]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\ffxtlbr@funmoods.com [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\{E71B541F-5E72-5555-A47C-E47863195841} [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\artur.dubovoy@gmail.com.xpi [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\addon@defaulttab.com.xpi [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\Sq3TM@gmail.com [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\ZAGeTQ8H@gmail.com [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\services-sync.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox-branding.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox-l10n.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox.js [2013-08-12]
FF ExtraCheck: C:\Program Files\mozilla firefox\my.cfg [2015-03-25] <==== ATTENTION
 
Chrome: 
=======
CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-08]
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-08]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-25]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-25]
CHR Extension: (Google Search) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-25]
CHR Extension: (Google Sheets) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-08]
CHR Extension: (Avast Online Security) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-06-08]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-25]
CHR HKLM\...\Chrome\Extension: [dhigneefebkcagnpnpbibganpmfgebnk] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-21]
 
Opera: 
=======
OPR Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\lnpddjhhjmmcnjbjdbopmniafbpfppkb [2015-05-28]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AgentService; C:\Program Files\LibraryClient\globalLibx32\service.exe [46592 2012-02-20] () [File not signed]
R2 AMD FUEL Service; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2011-07-13] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-21] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3207800 2015-05-21] (Avast Software)
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 OCS Inventory Service; C:\Program Files\OCS Inventory Agent\OcsService.exe [38912 2013-04-08] (OCS Inventory NG) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AODDriver4.01; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [39424 2011-06-24] (Advanced Micro Devices) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-05-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [74976 2015-05-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-05-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-05-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787760 2015-05-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427992 2015-05-21] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-05-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209048 2015-05-21] ()
S3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [131064 2014-05-14] (HID Global Corporation)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [41984 2008-10-28] (Samsung Electronics Co., Ltd.) [File not signed]
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-17] (Elaborate Bytes AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-11] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R1 MpKsl53abcca9; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{733B82C9-EE4F-4724-8D53-0A43FFAF3B20}\MpKsl53abcca9.sys [39464 2015-06-11] (Microsoft Corporation)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2008-10-27] (Samsung Electronics) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-05-21] (Avast Software)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-11 08:57 - 2015-06-11 08:57 - 00017231 _____ C:\Users\Administrator\Desktop\fixlist .txt
2015-06-11 08:28 - 2015-06-11 11:19 - 00155170 _____ C:\Windows\PFRO.log
2015-06-11 08:28 - 2015-06-11 11:19 - 00000224 _____ C:\Windows\setupact.log
2015-06-11 08:28 - 2015-06-11 08:28 - 00000000 _____ C:\Windows\setuperr.log
2015-06-10 15:01 - 2015-06-11 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-06-10 15:01 - 2008-11-10 11:41 - 00032656 _____ (Microsoft Corporation) C:\Windows\system32\msonpmon.dll
2015-06-10 14:59 - 2015-06-10 15:04 - 00000000 ____D C:\Program Files\Microsoft Works
2015-06-10 14:51 - 2015-06-10 14:52 - 00000000 ____D C:\Program Files\CCleaner
2015-06-10 14:51 - 2015-06-10 14:51 - 00000931 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-06-10 14:51 - 2015-06-10 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
2015-06-10 14:48 - 2015-06-10 14:58 - 00000000 ____D C:\Program Files\Microsoft Office
2015-06-10 14:28 - 2015-06-10 14:28 - 00001174 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2015-06-10 13:38 - 2015-06-10 13:38 - 00000931 _____ C:\Users\Public\Desktop\BitComet.lnk
2015-06-10 13:38 - 2015-06-10 13:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet
2015-06-10 13:37 - 2015-06-10 13:38 - 00000000 ____D C:\Program Files\BitComet
2015-06-10 13:04 - 2015-05-21 12:52 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-06-10 09:25 - 2015-05-09 06:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 09:25 - 2015-05-09 06:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 09:25 - 2015-05-09 06:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 09:25 - 2015-05-09 06:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 09:25 - 2015-05-09 06:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 09:25 - 2015-04-29 21:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 09:25 - 2015-04-29 21:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 09:25 - 2015-04-29 21:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 09:25 - 2015-04-29 21:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 09:25 - 2015-04-29 21:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 09:24 - 2015-04-24 20:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 08:56 - 2015-06-11 11:33 - 00000000 ____D C:\FRST
2015-06-09 09:04 - 2015-05-24 12:40 - 00593048 ____N (Sysinternals - www.sysinternals.com) C:\autorunsc.exe
2015-06-09 09:04 - 2015-05-24 12:39 - 00680600 ____N (Sysinternals - www.sysinternals.com) C:\Autoruns.exe
2015-06-09 09:04 - 2014-06-28 16:47 - 00002028 ____N C:\Eula.txt
2015-06-09 08:34 - 2015-06-09 08:34 - 00000000 ____D C:\Users\Administrator\AppData\Local\{9B08D2F6-41FE-40B1-8E2D-67A5F54D5468}
2015-06-08 11:46 - 2015-06-08 11:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\VSRevoGroup
2015-06-08 11:43 - 2015-06-08 11:43 - 00000000 ____D C:\Program Files\VS Revo Group
2015-06-08 10:09 - 2015-06-11 11:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-08 10:09 - 2015-06-08 10:09 - 00001026 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-08 10:09 - 2015-06-08 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-08 10:08 - 2015-06-08 10:09 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-08 10:08 - 2015-06-08 10:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-08 10:08 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-08 10:08 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-08 10:08 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-05 13:14 - 2015-05-22 21:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-05 13:14 - 2015-05-22 20:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-05 13:14 - 2015-05-21 16:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-05 13:01 - 2015-06-05 13:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\{B049210D-E73B-4D44-970C-05480D1A0D2B}
2015-06-02 10:06 - 2015-06-04 10:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\{2E0E6D98-968E-4C86-8268-82718DF5A82A}
2015-05-29 09:12 - 2015-05-29 09:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\{6CA558CC-73B4-4398-95F9-E50444B2C26F}
2015-05-28 10:46 - 2015-05-28 10:46 - 00000000 ____D C:\Users\Administrator\AppData\Local\{BD0DDE8F-FFF3-4EC5-83CF-F95D466E12EF}
2015-05-27 12:16 - 2015-05-27 12:16 - 00000000 ____D C:\Users\Administrator\AppData\Local\{C3E4B2B2-DF21-425B-A86D-13700E573D2E}
2015-05-26 12:50 - 2015-05-26 12:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\{A5570127-7FF7-45DB-88E2-DD178A14086B}
2015-05-25 12:51 - 2015-06-09 13:58 - 00001040 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-500UA.job
2015-05-25 12:51 - 2015-06-09 13:58 - 00000988 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-500Core.job
2015-05-25 11:49 - 2015-05-25 11:49 - 00000000 ____D C:\Users\Administrator\AppData\Local\{8B24C122-E5A7-4B6C-8C5E-8B75D03CF937}
2015-05-22 09:27 - 2015-05-22 09:27 - 00000000 ____D C:\Users\Administrator\AppData\Local\{E68D8378-FC2E-4AE7-8193-639A705BDA72}
2015-05-21 13:02 - 2015-05-21 13:03 - 00000000 ____D C:\Windows\system32\vbox
2015-05-21 12:52 - 2015-05-21 12:52 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-05-21 11:18 - 2015-05-21 11:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\{A159BB46-20C8-4923-BFD7-1B9B3B92EB9E}
2015-05-20 13:15 - 2015-05-20 13:16 - 00000000 ____D C:\Users\Administrator\AppData\Local\{D1FB0108-07FA-437F-9A97-A09534B49E55}
2015-05-19 09:43 - 2015-05-19 09:43 - 00000000 ____D C:\Users\Administrator\AppData\Local\{0F2D45D9-FF5C-46B5-B01F-4ABD68CD81C6}
2015-05-18 10:17 - 2015-05-18 10:17 - 00000000 ____D C:\Users\Administrator\AppData\Local\{6B81EFE9-D98C-4433-9719-07394B3803EE}
2015-05-15 10:45 - 2015-05-15 10:45 - 00000000 ____D C:\Users\Administrator\AppData\Local\{5E21014A-BBCB-4F87-A403-C2A4E99D190D}
2015-05-13 12:25 - 2015-05-01 16:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 10:29 - 2015-02-18 10:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-13 10:29 - 2015-01-29 06:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 10:28 - 2015-05-05 04:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 10:28 - 2015-04-27 22:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-05-13 10:28 - 2015-04-27 22:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-13 10:28 - 2015-04-27 22:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-13 10:28 - 2015-04-27 22:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-13 10:28 - 2015-04-27 22:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-13 10:28 - 2015-04-27 22:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-13 10:28 - 2015-04-27 22:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-13 10:28 - 2015-04-27 22:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-13 10:28 - 2015-04-27 22:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-13 10:28 - 2015-04-27 22:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-13 10:28 - 2015-04-27 22:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-13 10:28 - 2015-04-27 22:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-13 10:28 - 2015-04-27 21:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-13 10:28 - 2015-04-27 21:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-13 10:28 - 2015-04-27 21:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 10:28 - 2015-04-20 05:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 10:28 - 2015-04-20 05:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 10:28 - 2015-04-20 05:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 10:28 - 2015-04-18 05:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 10:27 - 2015-04-22 04:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 10:27 - 2015-04-21 19:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 10:27 - 2015-04-21 19:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 10:27 - 2015-04-21 19:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 10:27 - 2015-04-21 19:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 10:27 - 2015-04-21 19:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-13 10:27 - 2015-04-21 19:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-13 10:27 - 2015-04-21 19:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 10:27 - 2015-04-21 19:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-13 10:27 - 2015-04-21 19:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 10:27 - 2015-04-21 19:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 10:27 - 2015-04-21 19:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-13 10:27 - 2015-04-21 19:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 10:27 - 2015-04-21 18:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 10:27 - 2015-04-21 18:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 10:27 - 2015-04-21 18:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-13 10:27 - 2015-04-21 18:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-13 10:27 - 2015-04-21 18:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 10:27 - 2015-04-21 18:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 10:27 - 2015-04-21 18:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 10:27 - 2015-04-21 18:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-13 10:27 - 2015-04-21 18:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 10:27 - 2015-04-21 18:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 10:27 - 2015-04-21 18:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 10:27 - 2015-04-21 18:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 10:27 - 2015-04-21 18:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 10:27 - 2015-04-21 18:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 10:27 - 2015-04-21 18:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-13 10:27 - 2015-04-21 18:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 10:27 - 2015-04-21 18:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 10:27 - 2015-04-21 17:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 10:27 - 2015-04-21 17:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 10:27 - 2015-04-13 06:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 10:24 - 2015-04-08 06:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-13 10:24 - 2015-04-08 06:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-13 10:24 - 2015-03-04 07:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-13 10:24 - 2015-03-04 07:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-13 10:24 - 2015-03-04 07:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-13 10:24 - 2015-03-04 07:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 09:39 - 2015-05-13 09:39 - 00000000 ____D C:\Users\Administrator\AppData\Local\{D8D53B24-10D1-46A4-A214-E7C7BD2096B8}
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-11 11:32 - 2010-10-24 22:53 - 01775644 _____ C:\Windows\WindowsUpdate.log
2015-06-11 11:29 - 2009-07-14 07:34 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-11 11:29 - 2009-07-14 07:34 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-11 11:19 - 2012-06-25 14:19 - 06476514 _____ C:\XrxUsd.log
2015-06-11 11:19 - 2009-07-14 07:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-11 11:19 - 2009-07-14 05:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-06-11 10:30 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\Vss
2015-06-11 10:10 - 2014-10-02 12:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\FirefoxToolbar
2015-06-11 10:10 - 2014-04-15 11:33 - 00000000 ____D C:\ProgramData\APN
2015-06-11 10:10 - 2014-02-26 16:27 - 00000000 ____D C:\Users\Administrator\AppData\Local\Popajar
2015-06-11 10:10 - 2014-02-07 16:34 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\FunmoodsChat
2015-06-11 10:10 - 2012-07-09 10:24 - 00000000 ____D C:\Users\Librarian\AppData\Roaming\PerformerSoft
2015-06-11 10:10 - 2012-07-06 13:52 - 00000000 ____D C:\Users\Visitor\AppData\Roaming\PerformerSoft
2015-06-11 09:09 - 2010-10-29 17:32 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-06-11 09:09 - 2010-10-25 14:50 - 00000008 __RSH C:\Users\Administrator\ntuser.pol
2015-06-11 09:09 - 2010-10-25 14:50 - 00000000 ____D C:\Users\Administrator
2015-06-11 09:04 - 2013-04-11 15:18 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-11 09:03 - 2010-10-24 20:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-11 08:40 - 2010-10-30 10:53 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
2015-06-11 08:40 - 2010-10-24 19:51 - 00000000 ____D C:\ProgramData\Adobe
2015-06-11 08:31 - 2009-07-14 07:46 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-06-10 16:43 - 2012-09-11 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\BitComet
2015-06-10 15:06 - 2009-07-14 05:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-06-10 14:58 - 2009-07-14 07:52 - 00000000 ____D C:\Program Files\MSBuild
2015-06-10 14:57 - 2011-03-25 21:28 - 00000000 ____D C:\Windows\Panther
2015-06-10 14:56 - 2010-10-24 20:08 - 00000000 ____D C:\Program Files\Microsoft.NET
2015-06-10 14:51 - 2014-02-21 11:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-06-10 14:51 - 2010-10-24 20:06 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2015-06-10 14:06 - 2010-10-29 10:05 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2015-06-10 14:06 - 2010-10-24 19:51 - 00000000 ____D C:\Program Files\Adobe
2015-06-10 13:35 - 2009-07-14 05:04 - 00000710 _____ C:\Windows\win.ini
2015-06-09 16:43 - 2010-10-31 18:37 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype
2015-06-09 13:58 - 2013-03-04 10:31 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-09 13:58 - 2013-03-04 10:31 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-09 13:58 - 2012-04-17 12:11 - 00001098 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005UA.job
2015-06-09 13:58 - 2012-04-17 12:11 - 00001076 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005Core.job
2015-06-09 13:58 - 2011-04-04 16:21 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005UA.job
2015-06-09 13:58 - 2011-04-04 16:21 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005Core.job
2015-06-09 13:58 - 2010-10-31 14:28 - 00001016 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1006UA.job
2015-06-09 13:58 - 2010-10-31 14:28 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1006Core.job
2015-06-08 16:10 - 2015-04-03 08:28 - 00000004 _____ C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-06-08 16:10 - 2011-03-25 20:30 - 00109280 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-08 16:09 - 2013-03-04 10:31 - 00000000 ____D C:\Program Files\Google
2015-06-08 16:08 - 2010-10-31 14:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2015-06-08 16:05 - 2013-09-05 11:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-06-08 16:05 - 2013-09-05 11:49 - 00000000 ____D C:\Program Files\Canon
2015-06-08 16:03 - 2013-01-03 11:43 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\calibre
2015-06-08 16:03 - 2013-01-03 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2015-06-08 15:57 - 2009-07-14 07:33 - 03763560 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-08 15:54 - 2012-09-11 14:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit)
2015-06-08 15:35 - 2012-06-13 13:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Opera
2015-06-08 15:35 - 2012-06-13 13:36 - 00000000 ____D C:\Users\Administrator\AppData\Local\Opera
2015-06-08 15:34 - 2014-12-11 15:54 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\PhotoScape
2015-06-08 15:30 - 2013-06-21 10:16 - 00000000 ____D C:\Program Files\TeamViewer
2015-06-08 15:30 - 2012-11-22 12:50 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TeamViewer
2015-06-08 15:27 - 2010-10-30 13:58 - 00000000 ____D C:\Program Files\Windows Live
2015-06-08 15:22 - 2013-09-13 09:50 - 00000000 ____D C:\Users\Administrator\AppData\Local\WebPlayer
2015-06-08 15:21 - 2012-04-26 10:02 - 140266064 _____ C:\xxbgtask.log
2015-06-08 15:12 - 2015-02-02 17:17 - 00000000 ____D C:\Users\Administrator\AppData\Local\Unity
2015-06-08 08:42 - 2014-12-11 13:38 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-08 08:42 - 2014-05-10 08:49 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-05-29 13:42 - 2010-10-24 19:26 - 00980294 _____ C:\Windows\system32\perfh01F.dat
2015-05-29 13:42 - 2010-10-24 19:26 - 00455792 _____ C:\Windows\system32\perfc01F.dat
2015-05-29 13:42 - 2010-10-24 18:25 - 00006444 _____ C:\Windows\system32\PerfStringBackup.INI
2015-05-29 09:16 - 2010-10-24 18:32 - 00000000 ____D C:\ProgramData\Skype
2015-05-26 12:52 - 2013-09-25 13:32 - 00000000 ___RD C:\Program Files\Skype
2015-05-21 12:52 - 2014-09-24 13:10 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-05-21 12:52 - 2014-09-24 13:10 - 00024144 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-05-21 12:52 - 2013-03-04 09:35 - 00209048 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-05-21 12:52 - 2013-03-04 09:35 - 00049904 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00787760 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00427992 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00074976 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-05-15 16:55 - 2009-07-14 10:20 - 00000000 ____D C:\Program Files\Windows Journal
2015-05-15 12:10 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\rescache
2015-05-15 11:18 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-05-15 10:36 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\tr-TR
2015-05-15 10:36 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-15 10:34 - 2010-10-24 18:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-13 12:24 - 2010-10-24 20:22 - 00000039 _____ C:\Windows\vbaddin.ini
2015-05-13 12:23 - 2015-03-04 10:02 - 00002101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Center Endpoint Protection.lnk
2015-05-13 12:23 - 2011-03-25 23:13 - 00001945 _____ C:\Windows\epplauncher.mif
2015-05-13 12:22 - 2013-09-25 13:32 - 00000000 ____D C:\Program Files\Microsoft Security Client
2015-05-13 12:04 - 2013-08-14 18:06 - 00000000 ____D C:\Windows\system32\MRT
2015-05-13 12:04 - 2010-10-24 18:39 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 11:58 - 2010-10-24 18:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
 
==================== Files in the root of some directories =======
 
2013-01-19 10:44 - 2013-01-19 10:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files\Common Files\atimpenc.dll
2013-09-23 12:52 - 2015-02-17 13:54 - 0000135 _____ () C:\Users\Administrator\AppData\Roaming\WB.CFG
2010-10-29 19:41 - 2014-09-12 13:09 - 0008082 _____ () C:\Users\Administrator\AppData\Roaming\XeroxFaxOptions.xml
2010-10-26 17:33 - 2010-10-26 17:33 - 0000017 _____ () C:\Users\Administrator\AppData\Local\resmon.resmoncfg
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-06-09 12:15
 
==================== End of log ============================

Addition.txt

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

  • Моля изтеглете и стартирайте изпълнимия файл от линка отдолу:

    ESET OnlineScan

  • Сложете отметката предesetAcceptTerms.png
  • Натиснете бутона esetStart.png.
  • Сложете отметката пред Enable detection of potentially unwanted applications.
  • Сега кликнете на Advanced Settings и се уверете, че опцията Remove found threats не е маркирана, а следните са маркирани:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
    • Изберете сега бутона Change и изберете само Operating memory и дял C:\
fhSji42.png
  • Натиснете бутона Start.
  • ESET ще започне да сваля и инсталира актуализации за вирусните дефиниции и след това ще започне да сканира компютъра. Бъдете търпеливи, защото процеса е бавен и може да отнеме доста време.
  • След като проверката приключи натиснете бутонаesetListThreats.png
  • Сега натиснете бутона esetExport.png, и запазете файла на десктопа с име по избор като например (ESETScan.txt). Копирайте резултата в следващия си коментар.
  • Натиснете бутона esetBack.png и след това натиснете бутона esetFinish.png за да затворите приложението.
  • Харесва ми 2

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Извинявам се за закъснението

 

 

C:\FRST\Quarantine\C\Program Files\Casual Games\casual_games_helper_service.exe a variant of Win32/Toolbar.CrossRider.CR potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe Win32/AlteredSoftware.A potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe Win32/AlteredSoftware.C potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe a variant of Win32/AlteredSoftware.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe a variant of Win32/AlteredSoftware.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll a variant of Win32/AlteredSoftware.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll a variant of Win32/AlteredSoftware.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll a variant of Win32/AlteredSoftware.E potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll a variant of Win32/AlteredSoftware.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll a variant of Win32/AlteredSoftware.B potentially unwanted application
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\Download\{ADA00485-01A0-4995-B627-8C1068B634B7}\1.3.25.29\setup.exe a variant of Win32/Toolbar.CrossRider.CQ potentially unwanted application
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX.xBAD JS/Toolbar.Crossrider.C potentially unwanted application
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX3.xBAD JS/Toolbar.Crossrider.C potentially unwanted application
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\KfOwsG9x.xBAD JS/Toolbar.Crossrider.C potentially unwanted application
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\xwMEhk3tTuYDvHMsB1V2T.xBAD JS/Toolbar.Crossrider.C potentially unwanted application
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application
C:\Program Files\Cheat Engine 6.3\standalonephase1.dat a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application
C:\Users\Administrator\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.2.1.zip a variant of Win32/Mobogenie.A potentially unwanted application
C:\Users\Administrator\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk a variant of Android/Mobserv.A potentially unwanted application
C:\Users\Administrator\AppData\Roaming\BabSolution\Shared\BUSolution.dll Win32/Toolbar.Babylon.AE potentially unwanted application
C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application
C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application
C:\Users\Visitor\AppData\Roaming\Movies Toolbar\SafetyNut\components\SafetyNutHlpFF20.dll a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application
C:\Users\Visitor\Application Data\Movies Toolbar\SafetyNut\components\SafetyNutHlpFF20.dll a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application
C:\Users\Visitor\Local Settings\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application
C:\Users\Visitor\Local Settings\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application
C:\Windows\Installer\71a136.msi a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Не е проблем времето, не се притеснявайте.

Моля, направете ново сканиране с ESET Online Scanner като този път маркирате и Remove Selected, освен останалите неща по-горе посочени.

  • Харесва ми 2

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
C:\Users\Visitor\Application Data\Movies Toolbar\SafetyNut\components\SafetyNutHlpFF20.dll a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application
C:\Users\Visitor\Local Settings\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application
C:\Users\Visitor\Local Settings\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application
C:\FRST\Quarantine\C\Program Files\Casual Games\casual_games_helper_service.exe a variant of Win32/Toolbar.CrossRider.CR potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe Win32/AlteredSoftware.A potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe Win32/AlteredSoftware.C potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe a variant of Win32/AlteredSoftware.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe a variant of Win32/AlteredSoftware.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll a variant of Win32/AlteredSoftware.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll a variant of Win32/AlteredSoftware.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll a variant of Win32/AlteredSoftware.E potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll a variant of Win32/AlteredSoftware.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll a variant of Win32/AlteredSoftware.B potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Program Files\globalUpdate\Update\Download\{ADA00485-01A0-4995-B627-8C1068B634B7}\1.3.25.29\setup.exe a variant of Win32/Toolbar.CrossRider.CQ potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX.xBAD JS/Toolbar.Crossrider.C potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\0W9ojlSERHVQh9fP4uW0uqGX3.xBAD JS/Toolbar.Crossrider.C potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\KfOwsG9x.xBAD JS/Toolbar.Crossrider.C potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\xwMEhk3tTuYDvHMsB1V2T.xBAD JS/Toolbar.Crossrider.C potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application cleaned by deleting - quarantined
C:\Program Files\Cheat Engine 6.3\standalonephase1.dat a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application cleaned by deleting - quarantined
C:\Users\Administrator\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.2.1.zip a variant of Win32/Mobogenie.A potentially unwanted application deleted - quarantined
C:\Users\Administrator\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk a variant of Android/Mobserv.A potentially unwanted application deleted - quarantined
C:\Users\Administrator\AppData\Roaming\BabSolution\Shared\BUSolution.dll Win32/Toolbar.Babylon.AE potentially unwanted application cleaned by deleting - quarantined
C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application cleaned by deleting - quarantined
C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpfcgompgkeceodpodleppkhdjoeom\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application cleaned by deleting - quarantined
C:\Users\Visitor\AppData\Roaming\Movies Toolbar\SafetyNut\components\SafetyNutHlpFF20.dll a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application cleaned by deleting - quarantined
C:\Windows\Installer\71a136.msi a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application deleted - quarantined

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Супер!

Как е системата ви в момента?

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

не мисля че има разлика.Може ли да видите процесите виждат ми се доста

post-318579-0-46399800-1434116131_thumb.

post-318579-0-14680400-1434116143_thumb.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Броят на процесите няма никакво значение. Виждате множество процеси на Chrome, защото всеки таб създава нов процес. Виждате множество процеси svchost.exe , защото всеки един изпълнява различни услуги за операционната система.

Има ли подобрение в производителността? Все още ли има забавяне при търсене в Интернет, както сте посочили по-рано?

  • Харесва ми 3

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

1.Изтеглете Hitman Pro.

За 32-битова система - dEMD6.gif.

За 64-битова система - Download-button3.gif

2.Стартирайте програмата.

3.След като сте стартирали програмата като кликнете върху иконата 5vo5F.jpg и натиснете бутона „Напред“ като се съгласите с лицензионното споразумение (EULA).

4.Сложете отметка пред "Не, искам да завърша еднократно сканиране на компютъра".

5.Натиснете бутона „Напред“.

6.Програмата ще започне да сканира. Времето за сканиране е около 2 минути.

7.След завършване на сканирането от списъка с намерените неща (ако има такива) изберете Apply to all => Ignore.

8.Натиснете "Next" и след това натиснете "Изнеси резултата в XML file" и запазете лог файла на десктопа.

9.Архивирайте файла и го прикачете в следващия си коментар или копирайте съдържанието му в следващия си коментар.

 

Забележка: Ако няма падащо меню, където да изберете ignore както на снимката:

 

6-scanfin-choose.jpg

 

Тогава просто затворете програмата след края на проверката (без да премахвате нищо)...след това отворете C:Programdata\HitmanPro\Logs, отворете и публикувайте съдържанието на лог файла в следващия си коментар.

  • Харесва ми 1

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
HitmanPro 3.7.9.241
www.hitmanpro.com
 
   Computer name . . . . : GLBG1543PC02
   Windows . . . . . . . : 6.1.1.7601.X86/2
   User name . . . . . . : GLBG1543PC02\Administrator
   UAC . . . . . . . . . : Disabled
   License . . . . . . . : Free
 
   Scan date . . . . . . : 2015-06-15 09:04:46
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 14m 48s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No
 
   Threats . . . . . . . : 0
   Traces  . . . . . . . : 72
 
   Objects scanned . . . : 1 637 945
   Files scanned . . . . : 43 005
   Remnants scanned  . . : 299 289 files / 1 295 651 keys
 
Cookies _____________________________________________________________________
 
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.indexinfo.org
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.kaldata.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.mediade.sk
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pimdesign.org
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
   C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.kaldata.com
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.abv.bg
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
   C:\Users\Librarian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldpartners.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:adbrite.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.3bay.bg
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.ad4game.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.betweendigital.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.brandfit.net
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.domainbg.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.fashionsupreme.co.uk
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.gamesbannernet.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pik.bg
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.socialvi.be
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.yahoo.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.abv.bg
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertisegame.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstmedia.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:diff3.smartadserver.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:kontera.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:pool-eu-ie.creative-serving.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:server.cpmstar.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:statse.webtrendslive.com
   C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Cookies:zedo.com
   C:\Users\Visitor\AppData\Roaming\Mozilla\Firefox\Profiles\7m1w8icp.default\cookies.sqlite:casalemedia.com
   C:\Users\Visitor\AppData\Roaming\Mozilla\Firefox\Profiles\7m1w8icp.default\cookies.sqlite:doubleclick.net
   C:\Users\Visitor\AppData\Roaming\Mozilla\Firefox\Profiles\7m1w8icp.default\cookies.sqlite:smartadserver.com
   C:\Users\Visitor\AppData\Roaming\Mozilla\Firefox\Profiles\7m1w8icp.default\cookies.sqlite:www.etracker.de
 
 

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Изглежда чист.

Изтеглете Security Check от screen317 от този линк или и го запаметете на вашия десктоп.

Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.

Накрая, автоматично ще се отвори текстов документ, наречен checkup.txt, моля прикачете го в следващия ви коментар в тази тема.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
 Results of screen317's Security Check version 1.004  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
System Center Endpoint Protection   
avast! Antivirus                    
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 CCleaner     
 Adobe Reader XI  
 Mozilla Firefox (en-US). Firefox out of Date!  
 Google Chrome (43.0.2357.65) 
 Google Chrome (43.0.2357.81) 
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe 
 Microsoft Security Essentials msseces.exe 
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Malwarebytes Anti-Malware mbamscheduler.exe   
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast ng vbox\AvastVBoxSVC.exe 
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 1% 
````````````````````End of Log`````````````````````` 

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Моля, генерирайте нови лог файлове от FRST.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by Administrator (administrator) on GLBG1543PC02 on 16-06-2015 11:14:54
Running from D:\Users\Administrator\Desktop
Loaded Profiles: Administrator (Available Profiles: Librarian & Visitor & Administrator)
Platform: Microsoft Windows 7 Enterprise  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Family Safety\fsssvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(OCS Inventory NG) C:\Program Files\OCS Inventory Agent\OcsService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [startCCC] => c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-07-13] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-05-31] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-21] (Avast Software s.r.o.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
Winlogon\Notify\avldr: avldr.dll [X]
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-19\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-299244719-1399796724-3294634451-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-299244719-1399796724-3294634451-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [skype] => C:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2015-06-11]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015-06-09] ()
Startup: C:\Users\Librarian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2012-04-17]
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Administrator\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-05-21] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
BHO: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2013-11-29] (BitComet)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-05-21] (Avast Software s.r.o.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL No File
Handler: AutorunsDisabled\skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default
FF DefaultSearchEngine: Bing 
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Bing 
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-06-21] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll No File
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500: @tools.google.com/Google Update;version=3 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-299244719-1399796724-3294634451-500: @tools.google.com/Google Update;version=9 -> C:\Users\Administrator\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-25] (Google Inc.)
FF user.js: detected! => C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\user.js [2015-06-11]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\searchplugins\bingp.xml [2015-04-03]
FF Extension: BitComet Video Downloader - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB} [2015-06-10]
FF Extension: Feedback - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\testpilot@labs.mozilla.com.xpi [2012-12-04]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-09-25]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-01-10]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\ffxtlbr@funmoods.com [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\{E71B541F-5E72-5555-A47C-E47863195841} [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\artur.dubovoy@gmail.com.xpi [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\addon@defaulttab.com.xpi [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\Sq3TM@gmail.com [not found]
FF Extension: No Name - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\2bbrihkd.default\extensions\ZAGeTQ8H@gmail.com [not found]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\services-sync.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox-branding.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox-l10n.js [2010-01-01]
FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox.js [2013-08-12]
FF ExtraCheck: C:\Program Files\mozilla firefox\my.cfg [2015-03-25] <==== ATTENTION
 
Chrome: 
=======
CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-08]
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-08]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-25]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-25]
CHR Extension: (Google Search) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-25]
CHR Extension: (Google Sheets) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-08]
CHR Extension: (Avast Online Security) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-06-08]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-25]
CHR HKLM\...\Chrome\Extension: [dhigneefebkcagnpnpbibganpmfgebnk] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-21]
 
Opera: 
=======
OPR Extension: (No Name) - C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Extensions\lnpddjhhjmmcnjbjdbopmniafbpfppkb [2015-05-28]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AgentService; C:\Program Files\LibraryClient\globalLibx32\service.exe [46592 2012-02-20] () [File not signed]
R2 AMD FUEL Service; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2011-07-13] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-21] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3207800 2015-05-21] (Avast Software)
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 OCS Inventory Service; C:\Program Files\OCS Inventory Agent\OcsService.exe [38912 2013-04-08] (OCS Inventory NG) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AODDriver4.01; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [39424 2011-06-24] (Advanced Micro Devices) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-05-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [74976 2015-05-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-05-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-05-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787760 2015-05-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427992 2015-05-21] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-05-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209048 2015-05-21] ()
S3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [131064 2014-05-14] (HID Global Corporation)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [41984 2008-10-28] (Samsung Electronics Co., Ltd.) [File not signed]
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-17] (Elaborate Bytes AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-16] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2008-10-27] (Samsung Electronics) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-05-21] (Avast Software)
R1 MpKsle68b1499; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{69534278-A353-4E65-B7F9-FC02C1424233}\MpKsle68b1499.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-15 09:03 - 2015-06-15 10:03 - 00000000 ____D C:\ProgramData\HitmanPro
2015-06-11 12:35 - 2015-06-11 12:35 - 00000000 ____D C:\Program Files\ESET
2015-06-11 08:57 - 2015-06-11 08:57 - 00017231 _____ C:\Users\Administrator\Desktop\fixlist .txt
2015-06-11 08:28 - 2015-06-16 08:27 - 00001538 _____ C:\Windows\setupact.log
2015-06-11 08:28 - 2015-06-15 11:44 - 00155614 _____ C:\Windows\PFRO.log
2015-06-11 08:28 - 2015-06-11 08:28 - 00000000 _____ C:\Windows\setuperr.log
2015-06-10 15:01 - 2015-06-11 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-06-10 15:01 - 2009-02-27 03:42 - 00031640 _____ (Microsoft Corporation) C:\Windows\system32\msonpmon.dll
2015-06-10 14:59 - 2015-06-10 15:04 - 00000000 ____D C:\Program Files\Microsoft Works
2015-06-10 14:51 - 2015-06-10 14:52 - 00000000 ____D C:\Program Files\CCleaner
2015-06-10 14:51 - 2015-06-10 14:51 - 00000931 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-06-10 14:51 - 2015-06-10 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
2015-06-10 14:48 - 2015-06-15 08:54 - 00000000 ____D C:\Program Files\Microsoft Office
2015-06-10 14:28 - 2015-06-10 14:28 - 00001174 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2015-06-10 13:38 - 2015-06-10 13:38 - 00000931 _____ C:\Users\Public\Desktop\BitComet.lnk
2015-06-10 13:38 - 2015-06-10 13:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet
2015-06-10 13:37 - 2015-06-10 13:38 - 00000000 ____D C:\Program Files\BitComet
2015-06-10 13:04 - 2015-05-21 12:52 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-06-10 09:27 - 2015-06-02 22:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 09:27 - 2015-05-27 17:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 09:27 - 2015-05-23 06:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 09:27 - 2015-05-23 06:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 09:27 - 2015-05-23 06:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 09:27 - 2015-05-23 06:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 09:27 - 2015-05-23 06:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 09:27 - 2015-05-23 06:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 09:27 - 2015-05-23 06:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 09:27 - 2015-05-23 06:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 09:27 - 2015-05-23 06:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 09:27 - 2015-05-23 06:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 09:27 - 2015-05-23 06:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 09:27 - 2015-05-23 06:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 09:27 - 2015-05-23 06:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 09:27 - 2015-05-23 06:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 09:27 - 2015-05-23 06:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 09:27 - 2015-05-23 06:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 09:27 - 2015-05-23 05:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 09:27 - 2015-05-23 05:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 09:27 - 2015-05-23 05:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 09:27 - 2015-05-23 05:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 09:27 - 2015-05-23 05:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 09:27 - 2015-05-23 05:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 09:27 - 2015-05-23 05:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 09:27 - 2015-05-23 05:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 09:27 - 2015-05-23 05:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 09:27 - 2015-05-23 05:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 09:27 - 2015-05-23 05:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 09:27 - 2015-05-23 05:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 09:27 - 2015-05-23 05:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 09:27 - 2015-05-23 05:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 09:26 - 2015-05-25 21:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-10 09:26 - 2015-05-25 21:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 09:26 - 2015-05-25 21:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 09:26 - 2015-05-25 21:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 09:26 - 2015-05-25 21:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 09:26 - 2015-05-25 21:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 09:26 - 2015-05-25 21:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 09:26 - 2015-05-25 21:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 09:26 - 2015-05-25 20:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 09:26 - 2015-05-25 20:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 09:26 - 2015-05-25 20:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 09:26 - 2015-05-25 20:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 09:26 - 2015-05-25 20:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 09:26 - 2015-05-25 19:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 09:26 - 2015-04-11 06:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-10 09:25 - 2015-05-09 06:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 09:25 - 2015-05-09 06:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 09:25 - 2015-05-09 06:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 09:25 - 2015-05-09 06:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 09:25 - 2015-05-09 06:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 06:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 09:25 - 2015-05-09 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 09:25 - 2015-04-29 21:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 09:25 - 2015-04-29 21:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 09:25 - 2015-04-29 21:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 09:25 - 2015-04-29 21:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 09:25 - 2015-04-29 21:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 09:24 - 2015-04-24 20:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 08:56 - 2015-06-16 11:15 - 00000000 ____D C:\FRST
2015-06-09 09:04 - 2015-05-24 12:40 - 00593048 ____N (Sysinternals - www.sysinternals.com) C:\autorunsc.exe
2015-06-09 09:04 - 2015-05-24 12:39 - 00680600 ____N (Sysinternals - www.sysinternals.com) C:\Autoruns.exe
2015-06-09 09:04 - 2014-06-28 16:47 - 00002028 ____N C:\Eula.txt
2015-06-09 08:34 - 2015-06-09 08:34 - 00000000 ____D C:\Users\Administrator\AppData\Local\{9B08D2F6-41FE-40B1-8E2D-67A5F54D5468}
2015-06-08 11:46 - 2015-06-08 11:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\VSRevoGroup
2015-06-08 11:43 - 2015-06-08 11:43 - 00000000 ____D C:\Program Files\VS Revo Group
2015-06-08 10:09 - 2015-06-16 08:40 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-08 10:09 - 2015-06-08 10:09 - 00001026 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-08 10:09 - 2015-06-08 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-08 10:08 - 2015-06-08 10:09 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-08 10:08 - 2015-06-08 10:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-08 10:08 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-08 10:08 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-08 10:08 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-05 13:14 - 2015-05-22 21:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-05 13:14 - 2015-05-22 21:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-05 13:14 - 2015-05-22 20:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-05 13:14 - 2015-05-21 16:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-05 13:01 - 2015-06-05 13:02 - 00000000 ____D C:\Users\Administrator\AppData\Local\{B049210D-E73B-4D44-970C-05480D1A0D2B}
2015-06-02 10:06 - 2015-06-04 10:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\{2E0E6D98-968E-4C86-8268-82718DF5A82A}
2015-05-29 09:12 - 2015-05-29 09:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\{6CA558CC-73B4-4398-95F9-E50444B2C26F}
2015-05-28 10:46 - 2015-05-28 10:46 - 00000000 ____D C:\Users\Administrator\AppData\Local\{BD0DDE8F-FFF3-4EC5-83CF-F95D466E12EF}
2015-05-27 12:16 - 2015-05-27 12:16 - 00000000 ____D C:\Users\Administrator\AppData\Local\{C3E4B2B2-DF21-425B-A86D-13700E573D2E}
2015-05-26 12:50 - 2015-05-26 12:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\{A5570127-7FF7-45DB-88E2-DD178A14086B}
2015-05-25 12:51 - 2015-06-09 13:58 - 00001040 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-500UA.job
2015-05-25 12:51 - 2015-06-09 13:58 - 00000988 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-500Core.job
2015-05-25 11:49 - 2015-05-25 11:49 - 00000000 ____D C:\Users\Administrator\AppData\Local\{8B24C122-E5A7-4B6C-8C5E-8B75D03CF937}
2015-05-22 09:27 - 2015-05-22 09:27 - 00000000 ____D C:\Users\Administrator\AppData\Local\{E68D8378-FC2E-4AE7-8193-639A705BDA72}
2015-05-21 13:02 - 2015-05-21 13:03 - 00000000 ____D C:\Windows\system32\vbox
2015-05-21 12:52 - 2015-05-21 12:52 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-05-21 11:18 - 2015-05-21 11:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\{A159BB46-20C8-4923-BFD7-1B9B3B92EB9E}
2015-05-20 13:15 - 2015-05-20 13:16 - 00000000 ____D C:\Users\Administrator\AppData\Local\{D1FB0108-07FA-437F-9A97-A09534B49E55}
2015-05-19 09:43 - 2015-05-19 09:43 - 00000000 ____D C:\Users\Administrator\AppData\Local\{0F2D45D9-FF5C-46B5-B01F-4ABD68CD81C6}
2015-05-18 10:17 - 2015-05-18 10:17 - 00000000 ____D C:\Users\Administrator\AppData\Local\{6B81EFE9-D98C-4433-9719-07394B3803EE}
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-16 09:52 - 2010-10-24 22:53 - 01685495 _____ C:\Windows\WindowsUpdate.log
2015-06-16 09:29 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\rescache
2015-06-16 09:04 - 2009-07-14 07:34 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-16 09:04 - 2009-07-14 07:34 - 00020832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-16 09:01 - 2010-10-24 20:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-16 08:29 - 2012-06-25 14:19 - 06500750 _____ C:\XrxUsd.log
2015-06-16 08:27 - 2009-07-14 07:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-15 17:04 - 2013-08-14 18:06 - 00000000 ____D C:\Windows\system32\MRT
2015-06-15 17:04 - 2010-10-24 18:39 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-15 16:54 - 2010-10-31 18:37 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype
2015-06-15 11:54 - 2010-10-24 19:26 - 00993980 _____ C:\Windows\system32\perfh01F.dat
2015-06-15 11:54 - 2010-10-24 19:26 - 00468902 _____ C:\Windows\system32\perfc01F.dat
2015-06-15 11:54 - 2010-10-24 18:25 - 00006264 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-15 11:49 - 2009-07-14 07:33 - 03763560 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-15 11:44 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\tr-TR
2015-06-15 11:44 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\ro-RO
2015-06-15 11:44 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\bg-BG
2015-06-15 09:10 - 2010-10-24 20:22 - 00000039 _____ C:\Windows\vbaddin.ini
2015-06-12 15:40 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\system32\NDF
2015-06-12 14:51 - 2014-02-26 16:26 - 00000000 ____D C:\Program Files\Cheat Engine 6.3
2015-06-11 16:27 - 2010-10-29 10:05 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2015-06-11 11:19 - 2009-07-14 05:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-06-11 10:30 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\Vss
2015-06-11 10:10 - 2014-10-02 12:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\FirefoxToolbar
2015-06-11 10:10 - 2014-04-15 11:33 - 00000000 ____D C:\ProgramData\APN
2015-06-11 10:10 - 2014-02-26 16:27 - 00000000 ____D C:\Users\Administrator\AppData\Local\Popajar
2015-06-11 10:10 - 2014-02-07 16:34 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\FunmoodsChat
2015-06-11 10:10 - 2012-07-09 10:24 - 00000000 ____D C:\Users\Librarian\AppData\Roaming\PerformerSoft
2015-06-11 10:10 - 2012-07-06 13:52 - 00000000 ____D C:\Users\Visitor\AppData\Roaming\PerformerSoft
2015-06-11 09:09 - 2010-10-29 17:32 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-06-11 09:09 - 2010-10-25 14:50 - 00000008 __RSH C:\Users\Administrator\ntuser.pol
2015-06-11 09:09 - 2010-10-25 14:50 - 00000000 ____D C:\Users\Administrator
2015-06-11 09:04 - 2013-04-11 15:18 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-11 08:40 - 2010-10-30 10:53 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
2015-06-11 08:40 - 2010-10-24 19:51 - 00000000 ____D C:\ProgramData\Adobe
2015-06-11 08:31 - 2009-07-14 07:46 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-06-10 16:43 - 2012-09-11 14:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\BitComet
2015-06-10 15:06 - 2009-07-14 05:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-06-10 14:58 - 2009-07-14 07:52 - 00000000 ____D C:\Program Files\MSBuild
2015-06-10 14:57 - 2011-03-25 21:28 - 00000000 ____D C:\Windows\Panther
2015-06-10 14:56 - 2010-10-24 20:08 - 00000000 ____D C:\Program Files\Microsoft.NET
2015-06-10 14:51 - 2014-02-21 11:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-06-10 14:51 - 2010-10-24 20:06 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8
2015-06-10 14:06 - 2010-10-24 19:51 - 00000000 ____D C:\Program Files\Adobe
2015-06-10 13:35 - 2009-07-14 05:04 - 00000710 _____ C:\Windows\win.ini
2015-06-09 13:58 - 2013-03-04 10:31 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-09 13:58 - 2013-03-04 10:31 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-09 13:58 - 2012-04-17 12:11 - 00001098 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005UA.job
2015-06-09 13:58 - 2012-04-17 12:11 - 00001076 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005Core.job
2015-06-09 13:58 - 2011-04-04 16:21 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005UA.job
2015-06-09 13:58 - 2011-04-04 16:21 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1005Core.job
2015-06-09 13:58 - 2010-10-31 14:28 - 00001016 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1006UA.job
2015-06-09 13:58 - 2010-10-31 14:28 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299244719-1399796724-3294634451-1006Core.job
2015-06-08 16:10 - 2015-04-03 08:28 - 00000004 _____ C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-06-08 16:10 - 2011-03-25 20:30 - 00109280 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-08 16:09 - 2013-03-04 10:31 - 00000000 ____D C:\Program Files\Google
2015-06-08 16:08 - 2010-10-31 14:12 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2015-06-08 16:05 - 2013-09-05 11:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-06-08 16:05 - 2013-09-05 11:49 - 00000000 ____D C:\Program Files\Canon
2015-06-08 16:03 - 2013-01-03 11:43 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\calibre
2015-06-08 16:03 - 2013-01-03 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2015-06-08 15:54 - 2012-09-11 14:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit)
2015-06-08 15:35 - 2012-06-13 13:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Opera
2015-06-08 15:35 - 2012-06-13 13:36 - 00000000 ____D C:\Users\Administrator\AppData\Local\Opera
2015-06-08 15:34 - 2014-12-11 15:54 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\PhotoScape
2015-06-08 15:30 - 2013-06-21 10:16 - 00000000 ____D C:\Program Files\TeamViewer
2015-06-08 15:30 - 2012-11-22 12:50 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TeamViewer
2015-06-08 15:27 - 2010-10-30 13:58 - 00000000 ____D C:\Program Files\Windows Live
2015-06-08 15:22 - 2013-09-13 09:50 - 00000000 ____D C:\Users\Administrator\AppData\Local\WebPlayer
2015-06-08 15:21 - 2012-04-26 10:02 - 140266064 _____ C:\xxbgtask.log
2015-06-08 15:12 - 2015-02-02 17:17 - 00000000 ____D C:\Users\Administrator\AppData\Local\Unity
2015-06-08 08:42 - 2014-12-11 13:38 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-08 08:42 - 2014-05-10 08:49 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-05-29 09:16 - 2010-10-24 18:32 - 00000000 ____D C:\ProgramData\Skype
2015-05-26 12:52 - 2013-09-25 13:32 - 00000000 ___RD C:\Program Files\Skype
2015-05-21 12:52 - 2014-09-24 13:10 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-05-21 12:52 - 2014-09-24 13:10 - 00024144 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-05-21 12:52 - 2013-03-04 09:35 - 00209048 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-05-21 12:52 - 2013-03-04 09:35 - 00049904 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00787760 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00427992 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-05-21 12:52 - 2013-01-10 13:55 - 00074976 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
 
==================== Files in the root of some directories =======
 
2013-01-19 10:44 - 2013-01-19 10:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files\Common Files\atimpenc.dll
2013-09-23 12:52 - 2015-02-17 13:54 - 0000135 _____ () C:\Users\Administrator\AppData\Roaming\WB.CFG
2010-10-29 19:41 - 2014-09-12 13:09 - 0008082 _____ () C:\Users\Administrator\AppData\Roaming\XeroxFaxOptions.xml
2010-10-26 17:33 - 2010-10-26 17:33 - 0000017 _____ () C:\Users\Administrator\AppData\Local\resmon.resmoncfg
 
Some files in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\SkypeSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-06-15 12:25
 
==================== End of log ============================

Addition.txt

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Стъпка 1

Има остатъци от Microsoft Security Essentials, затова моля изпълнете инструкциите от секцията Решете моя проблем:

https://support.microsoft.com/bg-bg/kb/2483120

Накрая рестартирайте компютъра си.

Стъпка 2

Моля изтеглете icon1351185104.pngJunkware Removal Tool на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.
Стъпка 3
  • Изтеглете и стартирайте 6sv1DN9.jpgAdwCleaner.exe.
  • Натиснете бутона Scan.
  • AdwCleaner ще започне да проверява компютъра.
  • След като проверката приключи натиснете бутона Clean.
  • Програмата ще затвори всички излишни процеси и след почистването ще иска да рестартира машината. Съгласете се.
  • Ще се появи автоматично лог файл с името (AdwCleaner[s0].txt) в C:\Adwcleaner
  • Публикувайте съдържанието му в следващия си коментар.
В следващия си коментар в тази тема, включете следните лог файлове:
  • Лог файл от Junkware Removal Tool
  • Лог файл от AdwCleaner
  • Харесва ми 2

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Първата стъпка е невалиден уеб сайта

 

 
# AdwCleaner v4.206 - Logfile created 17/06/2015 at 12:55:06
# Updated 01/06/2015 by Xplode
# Database : 2015-06-17.1 [server]
# Operating system : Windows 7 Enterprise Service Pack 1 (x86)
# Username : Administrator - GLBG1543PC02
# Running from : D:\Users\Administrator\Downloads\adwcleaner_4.206.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\saave net
Folder Deleted : C:\Program Files\saave net
Folder Deleted : C:\Windows\system32\SearchProtect
Folder Deleted : C:\Users\Administrator\AppData\Local\Popajar
Folder Deleted : C:\Users\Administrator\AppData\LocalLow\mixidj
Folder Deleted : C:\Users\Administrator\AppData\Roaming\FirefoxToolbar
Folder Deleted : D:\Users\Administrator\Documents\Mobogenie
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Librarian\AppData\Local\torch
Folder Deleted : C:\Users\Librarian\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\Visitor\AppData\Local\torch
Folder Deleted : C:\Users\Visitor\AppData\Roaming\Movies Toolbar
Folder Deleted : C:\Users\Visitor\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dlabcihlajghaekmikmkncdhekcaaenl
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\dlabcihlajghaekmikmkncdhekcaaenl
File Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\eiimolhnbbbdagljikeckdkldgemmmlj
File Deleted : C:\Users\Administrator\daemonprocess.txt
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\services-sync.js
File Deleted : C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.blekko.com_0.localstorage
File Deleted : C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.blekko.com_0.localstorage-journal
File Deleted : C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.search.ask.com_0.localstorage
File Deleted : C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.search.ask.com_0.localstorage-journal
 
***** [ Scheduled tasks ] *****
 
Task Deleted : globalUpdateUpdateTaskMachineUA
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DiscoveryHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IMTrProgress.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IMWeb.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\DiscoveryHelper.iMesh6Discovery
Key Deleted : HKLM\SOFTWARE\Classes\DiscoveryHelper.iMesh6Discovery.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\imweb.imwebcontrol
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\WMHelperiMesh.WMHelper
Key Deleted : HKLM\SOFTWARE\Classes\WMHelperiMesh.WMHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zlib.Adler
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zlib.ZlibCodec
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zlib.ZlibException
Key Deleted : HKLM\SOFTWARE\Classes\MPCBContextMenu.ContextMenu
Key Deleted : HKLM\SOFTWARE\Classes\MPCBContextMenu.IconGenerator
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Logger
Key Deleted : HKLM\SOFTWARE\Classes\Record\{37AC0F3B-749F-3B22-811B-5A019EED2E85}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{3B96B73A-292C-31BF-A2D3-34DF54CBDB55}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{4392A6CC-7940-310E-8E16-799A8D93A438}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{66DF7821-ED6D-3534-893C-0E89E74B0F91}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{755CAFCC-F016-3B06-8F22-945EAA3AD10D}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{76552F88-640C-314D-82B6-0D8A740907F7}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{05660A04-00F1-3A04-AB3B-BC1074B84D67}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{07430FF5-B7A6-3D5A-9F9B-2D7C57183B3B}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{0B764022-3741-345E-AB39-0A2A8577C5E0}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{903F9872-E87F-3B74-83B0-DBE10073B29D}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{9558EEB4-CDA6-3778-B53B-98076F0A1E90}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{A865D884-9B93-377B-A24D-12BF02DFF6D3}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{B0EBAFE9-ED42-34D1-B7D7-CBBE39A467CF}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{B25AA9BA-FD52-3E5E-BFE3-9B106779DA6E}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{C852CF9F-37DC-35AC-926A-7E6CFFF7C501}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{C9777796-4378-3C90-B52D-7238FFFC2A5C}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{DB1BC8B2-FDBF-30E7-BE1C-AFF9160059E6}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{DE64992E-A184-3DA6-927A-DA3906A77D7B}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{F3D5729C-7DEB-3850-A026-D0E323ECFEF5}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{F489A9AA-4924-32DF-AB6C-6EEE3A3C0A99}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{F5C7BCD8-0F63-34D0-BA9C-906545CD4020}
Key Deleted : HKLM\SOFTWARE\Classes\Record\{FEC70973-CB8B-351C-8047-CAE1274CE249}
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Crc.CRC32
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.BadCrcException
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.BadPasswordException
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.BadReadException
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.BadStateException
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.ComHelper
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.ReadOptions
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.SelfExtractorSaveOptions
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.SfxGenerationException
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.ZipEntry
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.ZipException
Key Deleted : HKLM\SOFTWARE\Classes\Ionic.Zip.ZipFile
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.Cookie
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.CookieCollection
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.CookieException
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.hxxpListener
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.hxxpListenerException
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.hxxpVersion
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Net.WebHeaderCollection
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Server.hxxpServer
Key Deleted : HKLM\SOFTWARE\Classes\WebSocketSharp.Server.WebSocketServer
Key Deleted : HKCU\Software\5255dadae06eed12
Key Deleted : HKLM\SOFTWARE\5255dadae06eed12
Key Deleted : HKLM\SOFTWARE\fd381d96-c1fa-4ac8-bd39-1fca726d2d2b
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FC41815-FA4C-4F8B-B143-2C045C8EA2FC}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{756C097C-6BDB-45DE-A8F1-83E01AB86BA4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{270BE80F-7D12-3199-A5A6-C26956DC9B85}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{284BB344-E9D0-39E1-B44B-6D98A16E9B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3070CF0C-F396-3DCA-87D6-9DBF3D77B610}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{36906F02-A2B9-3047-9D5C-E05AF3E469E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{420E2C2E-80D9-3012-A43C-42241FB36D42}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4529EB14-6B38-3CC4-9504-6EAB6C9E1255}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{93ABB6F7-F27A-3431-88ED-6939B451FF0D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AFF295ED-76F5-3BAC-81AE-74CD223F2F5C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B59B2B9A-B0FD-32F2-AA3A-927ADA01CD81}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BEEA930F-CD8A-341E-B6B5-5BAF659685D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E89856E4-1085-3BDF-87AA-8A81E422767E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00004}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00005}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00006}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00007}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00008}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D00009}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBC25CF6-9120-4283-B972-0E5520D0000F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F03955F1-309E-34E9-A021-1399C3532273}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F8739A44-6C91-39E8-AA09-45DEF03E6C4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18A88C48-BC7B-35B3-BD38-74DED875FB28}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2097A1B6-E86A-4072-A32D-2249A3ECBC5A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{807DF5E0-4EF7-48A8-A405-239F3E29FFA9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE69C007-C452-4D3E-86D2-1730DF8BC871}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{807DF5E0-4EF7-48A8-A405-239F3E29FFA9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\DSNR Labs
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Delta
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKU\.DEFAULT\Software\bProtector
Key Deleted : HKU\.DEFAULT\Software\IBUpdaterService
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17840
 
 
-\\ Mozilla Firefox v23.0.0.0 (en-US)
 
[2bbrihkd.default\prefs.js] - Line Deleted : user_pref("extensions.funmoods.pnu_base", "{\"newVrsn\":\"237\",\"lastVrsn\":\"237\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":\"0\",\"lstMsgTs\":\"0\"}");
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0200 (FLE Standard Time)");
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.value", "1375438924");
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.adsOldValue", -1);
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.bic", "1403e8c683a828702119262ea5b5df0a");
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.firstrun", false);
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.installationdate", 1375438924);
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.lastcheck", 22929470);
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.lastcheckitem", 22929561);
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.misc.lastBgWorkerTimer", "1375773671239");
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258.misc.lastDomWorkerTimer", "1375773671238");
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.crossriderapp2258@crossrider.com.install-event-fired", true);
[7m1w8icp.default\prefs.js] - Line Deleted : user_pref("extensions.enabledAddons", "crossriderapp2258%40crossrider.com:0.81.50,testpilot%40labs.mozilla.com:1.2.2,wrc%40avast.com:8.0.1489,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0");
 
-\\ Google Chrome v43.0.2357.124
 
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=102&systemid=473&v=a13277-312&apn_uid=6962035003034258&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=102&systemid=473&v=a13277-312&apn_uid=6962035003034258&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [search Provider] : hxxp://rts.dsrlte.com/?affID=na&q={searchTerms}
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : hidjnkeodmholilgafgdlgmgggbhnigl
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : kdidombaedgpfiiedeimiebkmbilgmlc
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : mpfapcdfbbledbojijcbcclmlieaoogk
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : hxxp://rts.dsrlte.com?affID=na
[C:\Users\Visitor\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Default_Search_Provider_Data] : hxxp://rts.dsrlte.com/?affID=na&q={searchTerms}
 
-\\ Comodo Dragon v
 
 
-\\ Opera v0.0.0.0
 
 
-\\ Chrome Canary v
 
 
*************************
 
AdwCleaner[R0].txt - [17401 bytes] - [17/06/2015 12:47:32]
AdwCleaner[s0].txt - [17840 bytes] - [17/06/2015 12:55:06]
 
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [17900  bytes] ##########
 

 

JRT.txt

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Не е възможно да не работи, защото аз го отварям.

Този е на български:

https://support.microsoft.com/bg-bg/kb/2483120

Този е на английски:

https://support.microsoft.com/en-us/kb/2483120

Ако е необходимо, опитайте с различни браузъри.

  • Харесва ми 2

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

мисля че се оправи благодаря

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Регистрирайте се или влезете в профила си за да коментирате

Трябва да имате регистрация за да може да коментирате това

Регистрирайте се

Създайте нова регистрация в нашия форум. Лесно е!

Нова регистрация

Вход

Имате регистрация? Влезте от тук.

Вход

  • Разглеждащи това в момента   0 потребители

    Няма регистрирани потребители разглеждащи тази страница.

  • Горещи теми в момента

  • Подобни теми

    • от Йорданка Т. Иванова
      Здравейте, при опит за възстановяване на системата към предишна дата, Avast направи пълно сканиране на компютъра и ми премести в клетка заразените файлове.
      Има ли възможност да се почисти компютъра от въпросните заплахи и съответно да си възстановя файловете, най-вече тези /ако има такива/, които са необходими за правилното функциониране на системата.
      П.П.: Пълен лаик съм на тема антивирусни програми.
      Нов Microsoft Office PowerPoint Presentation.pptx


      Ето го резултата от файла FRST
       
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.10.2018
      Ran by Rosko (administrator) on ROSKO-PC (28-10-2018 14:36:09)
      Running from C:\Users\Rosko\Downloads
      Loaded Profiles: Rosko (Available Profiles: Rosko)
      Platform: Windows 7 Ultimate (X64) Language: Български (България)
      Internet Explorer Version 8 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
      (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
      (Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BAVSvc.exe
      (Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BHipsSvc.exe
      (Intel) C:\Program Files (x86)\Intel Driver Update Utility\DSAService.exe
      (Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
      (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
      (Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BavTray.exe
      (Intel) C:\Program Files (x86)\Intel Driver Update Utility\DSATray.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
      () C:\Program Files\Intel Driver Update Utility\SUR\SurSvc.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
      () C:\Program Files (x86)\CalendarTool\2.0.0.1000176\CalendarServ.exe
      () C:\Program Files (x86)\CalendarTool\2.0.0.1000176\calendar.exe
      (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
      (Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\bavhm.exe
      (Intel Corporation) C:\Windows\System32\igfxEM.exe
      (Intel Corporation) C:\Windows\System32\igfxHK.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      () C:\Program Files\Intel\SUR\QUEENCREEK\esrv.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
      () C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe
      () C:\Program Files\Intel\SUR\QUEENCREEK\esrv.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Baidu Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\bavadvtools2\8C8AEEC1-5166-4CE7-BBAD-7C37409D0C73\tool\bdMiniDownloaderGB_BAV-Mini_32_1002.exe
      (Baidu Inc.) C:\Users\Rosko\AppData\Local\MiniService\MiniService.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Viber Media S.à r.l.) C:\Users\Rosko\AppData\Local\Viber\Viber.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      ==================== Registry (Whitelisted) ===========================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2778352 2014-01-24] (Synaptics Incorporated)
      HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
      HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-10-18] (AVAST Software)
      HKLM-x32\...\Run: [Baidu Antivirus] => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BavTray.exe [2553328 2015-07-14] (Baidu, Inc.)
      HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver Update Utility\DsaTray.exe [132856 2017-05-18] (Intel)
      HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [133760 2013-12-24] (Qualcomm®Atheros®)
      HKU\S-1-5-21-749869763-3409154425-2811610640-1000\...\Run: [Viber] => C:\Users\Rosko\AppData\Local\Viber\Viber.exe [36762184 2018-10-22] (Viber Media S.à r.l.)
      HKU\S-1-5-21-749869763-3409154425-2811610640-1000\...\MountPoints2: {c4a92fbb-e173-11e7-9426-f8a963743fcb} - G:\LG_PC_Programs.exe
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      Tcpip\Parameters: [DhcpNameServer] 172.16.1.1
      Tcpip\..\Interfaces\{2FB69C23-4CBD-4252-994A-27D31EDC0D6D}: [DhcpNameServer] 172.16.1.1
      Internet Explorer:
      ==================
      HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
      HKU\S-1-5-21-749869763-3409154425-2811610640-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKU\S-1-5-21-749869763-3409154425-2811610640-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      HKU\S-1-5-21-749869763-3409154425-2811610640-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
      Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
      Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
      Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
      Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
      FireFox:
      ========
      FF DefaultProfile: 2csmqmsd.default
      FF ProfilePath: C:\Users\Rosko\AppData\Roaming\Mozilla\Firefox\Profiles\2csmqmsd.default [2018-07-05]
      FF Homepage: Mozilla\Firefox\Profiles\2csmqmsd.default -> about:blank
      FF Extension: (Avast SafePrice) - C:\Users\Rosko\AppData\Roaming\Mozilla\Firefox\Profiles\2csmqmsd.default\Extensions\sp@avast.com.xpi [2018-10-18]
      FF Extension: (Avast Online Security) - C:\Users\Rosko\AppData\Roaming\Mozilla\Firefox\Profiles\2csmqmsd.default\Extensions\wrc@avast.com.xpi [2018-10-18]
      FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_122.dll [2018-10-09] ()
      FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_122.dll [2018-10-09] ()
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
      FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2015-08-18] (Sun Microsystems, Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)
      FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\enpsysau.js [2017-09-10]
      Chrome: 
      =======
      CHR DefaultProfile: Default
      CHR Profile: C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default [2018-10-28]
      CHR Extension: (Презентации) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-02]
      CHR Extension: (Документи) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-02]
      CHR Extension: (Google Диск) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-02]
      CHR Extension: (YouTube) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-02]
      CHR Extension: (Adobe Acrobat) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-10-02]
      CHR Extension: (Avast SafePrice | Сравнение, сделки, купони) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2018-10-19]
      CHR Extension: (Таблици) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-02]
      CHR Extension: (Google Документи офлайн) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-08]
      CHR Extension: (АБВ Уведомител) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\glkfpmcniebkbeakjdpobddpjghbapec [2018-10-28]
      CHR Extension: (Avast Online Security) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-10-18]
      CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-02]
      CHR Extension: (Gmail) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-02]
      CHR Extension: (Chrome Media Router) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-28]
      CHR Profile: C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey [2018-10-28] <==== ATTENTION
      CHR Extension: (Презентации) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-23]
      CHR Extension: (Документи) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-23]
      CHR Extension: (Google Диск) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
      CHR Extension: (YouTube) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
      CHR Extension: (Google Търсене) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
      CHR Extension: (АБВ Уведомител) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\cpbekonjicgkldkmopnamgglbfaiojje [2015-11-25]
      CHR Extension: (Adobe Acrobat) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-08]
      CHR Extension: (Таблици) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-11]
      CHR Extension: (Farmville2 X-Press) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\gbgjpdhhnbgmnafojckjmjogcpoinlim [2018-10-24]
      CHR Extension: (Google Документи офлайн) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-21]
      CHR Extension: (Avast Online Security) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-10-18]
      CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-12]
      CHR Extension: (Gmail) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-23]
      CHR Extension: (Chrome Media Router) - C:\Users\Rosko\AppData\Local\Google\Chrome\User Data\lejutplovshprohey\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-01]
      CHR HKU\S-1-5-21-749869763-3409154425-2811610640-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
      ==================== Services (Whitelisted) ====================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [8188768 2018-10-18] (AVAST Software)
      R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [318592 2013-12-24] (Windows (R) Win 7 DDK provider) [File not signed]
      R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [325024 2018-10-18] (AVAST Software)
      R2 BavSvc; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BavSvc.exe [2805208 2015-07-14] (Baidu, Inc.)
      S3 BdSandboxSrv; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BdSandboxSrv64.exe [490480 2015-04-29] (Baidu, Inc.)
      R2 BHipsSvc; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BHipsSvc.exe [544032 2015-07-14] (Baidu, Inc.)
      S3 BsrSvc; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\BavAdvTools2\128B4BEC-5D89-43AD-BAA8-207084AA0E4F\tool\BsrSvc.exe [3503416 2015-07-08] (Baidu, Inc.)
      R2 DSAService; C:\Program Files (x86)\Intel Driver Update Utility\DSAService.exe [21240 2017-05-18] (Intel)
      R2 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe [824592 2017-03-07] ()
      R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation)
      R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
      S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
      R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
      R2 MiniService; C:\Users\Rosko\AppData\Local\MiniService\MiniService.exe [103616 2018-10-28] (Baidu Inc.) [File not signed] <==== ATTENTION
      R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel Driver Update Utility\SUR\SurSvc.exe [157456 2017-03-07] ()
      R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11644656 2018-09-10] (TeamViewer GmbH)
      R2 TheCalendarService; C:\Program Files (x86)\CalendarTool\2.0.0.1000176\CalendarServ.exe [152720 2017-08-09] ()
      S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe [824592 2017-03-07] ()
      R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
      ===================== Drivers (Whitelisted) ======================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      S3 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [201408 2018-10-18] (AVAST Software)
      S3 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [230512 2018-10-18] (AVAST Software)
      S3 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [201928 2018-10-18] (AVAST Software)
      S3 aswblog; C:\Windows\System32\drivers\aswbloga.sys [346760 2018-10-18] (AVAST Software)
      S3 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [59664 2018-10-18] (AVAST Software)
      R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [185240 2018-10-18] (AVAST Software)
      S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [47064 2018-10-18] (AVAST Software)
      R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42456 2018-10-18] (AVAST Software)
      R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [163376 2018-10-18] (AVAST Software)
      S3 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [111968 2018-10-18] (AVAST Software)
      R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [88112 2018-10-18] (AVAST Software)
      S3 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1028840 2018-10-18] (AVAST Software)
      R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [467904 2018-10-18] (AVAST Software)
      S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [208640 2018-10-18] (AVAST Software)
      S3 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [381144 2018-10-18] (AVAST Software)
      U3 BdApiUtil; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BdApiUtil64.sys [116936 2015-07-14] (Baidu, Inc.)
      R3 bdark64; C:\Windows\system32\drivers\bdark64.sys [78792 2015-04-20] ()
      U3 BdCameraProtect; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\BdCameraProtect64.sys [25000 2015-07-14] (Baidu, Inc.)
      S3 BdSandbox; C:\Windows\System32\drivers\BdSandbox.sys [235976 2015-04-29] (Baidu, Inc.)
      R1 Bfilter; C:\Windows\System32\drivers\Bfilter.sys [62920 2015-07-14] (Baidu, Inc.)
      R1 Bfmon; C:\Windows\System32\drivers\Bfmon.sys [38344 2015-07-14] (Baidu, Inc.)
      R1 Bnbase; C:\Windows\System32\drivers\bnbasex64.sys [62792 2015-07-14] (Baidu, Inc.)
      R1 Bndef; C:\Windows\System32\drivers\bndef64.sys [487144 2015-07-14] (Baidu, Inc.)
      R3 Bnmon; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.6.2.147365.0\Bnmon64.sys [82376 2015-07-14] (Baidu, Inc.)
      R1 Bprotect; C:\Windows\System32\drivers\Bprotect.sys [171464 2015-07-14] (Baidu, Inc.)
      S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-12-24] (Qualcomm Atheros)
      R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-08-08] (REALiX(tm))
      R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
      R3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation)
      R3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-10-18] ()
      U3 aswbdisk; no ImagePath
      U0 Partizan; system32\drivers\Partizan.sys [X]
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One Month Created files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-10-28 14:35 - 2018-10-28 14:36 - 000000000 ____D C:\FRST
      2018-10-28 14:35 - 2018-10-28 14:35 - 002414592 _____ (Farbar) C:\Users\Rosko\Downloads\FRST64.exe
      2018-10-28 14:28 - 2018-10-28 14:36 - 000021836 _____ C:\Users\Rosko\Downloads\FRST.txt
      2018-10-28 14:26 - 2018-10-28 14:27 - 000020080 _____ C:\Users\Rosko\Downloads\Addition.txt
      2018-10-28 13:34 - 2018-10-28 13:34 - 000000000 ____D C:\Users\Rosko\AppData\Local\MiniService
      2018-10-28 13:29 - 2018-10-28 13:32 - 000000000 ____D C:\ProgramData\BsrSvc_exe
      2018-10-28 13:19 - 2018-10-28 13:20 - 000617400 _____ C:\Users\Rosko\Desktop\Нов Microsoft Office PowerPoint Presentation.pptx
      2018-10-28 12:40 - 2018-10-28 13:16 - 000000000 ____D C:\ProgramData\BavSvc_exe
      2018-10-28 12:37 - 2018-10-28 12:37 - 000000000 ____D C:\Users\Rosko\AppData\Local\Viber
      2018-10-28 09:17 - 2018-10-28 11:16 - 000000000 ____D C:\Users\Rosko\Desktop\официялни споразумения 2018-2019г
      2018-10-26 17:03 - 2018-10-26 17:03 - 000102327 _____ C:\Users\Rosko\Downloads\П-03001718127835-177-001_archive (1).zip
      2018-10-24 10:41 - 2018-10-24 10:41 - 000000000 ____D C:\Users\Rosko\AppData\Roaming\AVAST Software
      2018-10-24 10:39 - 2018-10-24 10:39 - 000611358 _____ C:\Users\Rosko\Downloads\379984975 (1).pdf
      2018-10-24 10:32 - 2018-10-28 12:37 - 000000000 ____D C:\Users\Rosko\AppData\Local\AVAST Software
      2018-10-22 15:05 - 2018-10-22 15:06 - 000103383 _____ C:\Users\Rosko\Downloads\П-03001718185275-040-001_archive.zip
      2018-10-20 07:48 - 2018-10-20 07:48 - 000230931 _____ C:\Users\Rosko\Downloads\ЗП Ростислав Недков 19.10 (1).pdf
      2018-10-20 07:40 - 2018-10-20 07:40 - 000230931 _____ C:\Users\Rosko\Downloads\ЗП Ростислав Недков 19.10.pdf
      2018-10-19 08:51 - 2018-10-19 08:51 - 002437339 _____ C:\Users\Rosko\Downloads\dec92_2016_1010_баркод_с_ръководство_за_потребителя.rar
      2018-10-18 18:17 - 2018-10-18 18:17 - 000665976 _____ C:\Users\Rosko\Downloads\Re6enie_VAS_27.02.2018 (1).pdf
      2018-10-18 11:52 - 2018-10-18 11:52 - 000039854 _____ C:\Users\Rosko\Downloads\nlnazadyljenia[1] (1).pdf
      2018-10-18 10:16 - 2018-10-18 10:16 - 000001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
      2018-10-18 10:16 - 2018-10-18 10:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
      2018-10-18 10:15 - 2018-10-18 10:15 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
      2018-10-18 10:14 - 2018-10-26 00:45 - 000004168 _____ C:\Windows\System32\Tasks\Avast Emergency Update
      2018-10-18 10:13 - 2018-10-18 10:13 - 001142072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
      2018-10-18 10:13 - 2018-10-18 10:13 - 000467904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000381144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000378584 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
      2018-10-18 10:13 - 2018-10-18 10:13 - 000208640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000201408 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000163376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000111968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000088112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000047064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
      2018-10-18 10:13 - 2018-10-18 10:13 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
      2018-10-18 10:13 - 2018-10-18 10:12 - 001028840 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
      2018-10-18 10:13 - 2018-10-18 10:12 - 001001272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
      2018-10-18 10:13 - 2018-10-18 10:12 - 000346760 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
      2018-10-18 10:13 - 2018-10-18 10:12 - 000230512 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
      2018-10-18 10:13 - 2018-10-18 10:12 - 000201928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
      2018-10-18 10:13 - 2018-10-18 10:12 - 000185240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
      2018-10-18 10:13 - 2018-10-18 10:12 - 000059664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
      2018-10-18 10:13 - 2018-10-18 10:12 - 000042456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
      2018-10-18 10:11 - 2018-10-18 11:43 - 000000000 ____D C:\ProgramData\AVAST Software
      2018-10-18 10:11 - 2018-10-18 10:11 - 000000000 ____D C:\Program Files\AVAST Software
      2018-10-18 10:09 - 2018-10-18 16:40 - 000000000 ____D C:\Users\Rosko\Documents\ViberDownloads
      2018-10-18 10:09 - 2018-10-18 10:09 - 000000000 ____D C:\Users\Rosko\AppData\Local\Viber Media S.à r.l
      2018-10-18 10:08 - 2018-10-28 13:47 - 000000000 ____D C:\Users\Rosko\AppData\Roaming\ViberPC
      2018-10-18 10:08 - 2018-10-18 10:08 - 000000956 _____ C:\Users\Rosko\AppData\Roaming\Microsoft\Windows\Start Menu\Viber.lnk
      2018-10-18 10:08 - 2018-10-18 10:08 - 000000954 _____ C:\Users\Rosko\Desktop\Viber.lnk
      2018-10-18 10:08 - 2018-10-18 10:08 - 000000000 ____D C:\Users\Rosko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber
      2018-10-18 10:08 - 2018-10-18 10:08 - 000000000 ____D C:\Users\Rosko\AppData\Local\cache
      2018-10-18 10:07 - 2018-10-18 10:07 - 000000000 ____D C:\Users\Rosko\AppData\Local\Package Cache
      2018-10-18 10:06 - 2018-10-18 10:07 - 089186064 _____ (Viber Media Inc.) C:\Users\Rosko\Downloads\ViberSetup.exe
      2018-10-17 22:33 - 2018-10-17 22:33 - 000267977 _____ C:\Users\Rosko\Downloads\danuchno_oblagane_vnoski_na_zemedelski_proizvoditeli (4).pdf
      2018-10-17 22:08 - 2018-10-17 22:09 - 000749389 _____ C:\Users\Rosko\Downloads\Нов Презентация на Microsoft PowerPoint (2).pptx
      2018-10-17 21:41 - 2018-10-17 21:41 - 000749389 _____ C:\Users\Rosko\Downloads\Нов Презентация на Microsoft PowerPoint (1).pptx
      2018-10-17 21:14 - 2018-10-17 21:14 - 000267977 _____ C:\Users\Rosko\Downloads\danuchno_oblagane_vnoski_na_zemedelski_proizvoditeli (3).pdf
      2018-10-17 16:19 - 2018-10-17 16:19 - 000289368 _____ C:\Windows\Minidump\101718-14539-01.dmp
      2018-10-17 15:07 - 2018-10-17 15:07 - 003833305 _____ C:\Users\Rosko\Downloads\dec50_2017_19.03.2018.rar
      2018-10-17 14:45 - 2018-10-17 14:45 - 004074946 _____ C:\Users\Rosko\Downloads\dec50_2016_баркод_с_ръководство_за_потребителя.rar
      2018-10-17 12:55 - 2018-10-17 12:55 - 000648847 _____ C:\Users\Rosko\Downloads\DOM (2).pdf
      2018-10-17 07:52 - 2018-10-17 07:52 - 000012846 _____ C:\Users\Rosko\Downloads\Spravka vazstanovqvane (4).ods
      2018-10-17 07:52 - 2018-10-17 07:52 - 000000165 ____H C:\Users\Rosko\Downloads\~$Spravka vazstanovqvane (4).ods
      2018-10-16 13:59 - 2018-10-16 13:59 - 070935933 _____ C:\Users\Rosko\Downloads\wetransfer-a3a156.zip
      2018-10-16 12:10 - 2018-10-16 12:10 - 001266784 _____ C:\Users\Rosko\Downloads\statement (21).pdf
      2018-10-16 12:09 - 2018-10-16 12:09 - 001105420 _____ C:\Users\Rosko\Downloads\statement (20).pdf
      2018-10-16 10:58 - 2018-10-16 10:58 - 000648847 _____ C:\Users\Rosko\Downloads\DOM (1).pdf
      2018-10-16 08:14 - 2018-10-16 08:14 - 001939889 _____ C:\Users\Rosko\Downloads\95_09.pdf
      2018-10-15 16:01 - 2018-10-15 16:01 - 000749389 _____ C:\Users\Rosko\Downloads\Нов Презентация на Microsoft PowerPoint.pptx
      2018-10-15 15:57 - 2018-10-15 15:57 - 000102327 _____ C:\Users\Rosko\Downloads\П-03001718127835-177-001_archive.zip
      2018-10-15 13:54 - 2018-10-15 13:54 - 000648847 _____ C:\Users\Rosko\Downloads\Ползване на данъчни облекчения и наличие на задължения.pdf
      2018-10-15 13:47 - 2018-10-15 13:47 - 000648847 _____ C:\Users\Rosko\Downloads\DOM.pdf
      2018-10-12 13:49 - 2018-10-12 13:49 - 000009969 _____ C:\Users\Rosko\Downloads\РОСТИСЛАВ НЕДКОВ БОРИСОВ_2019_ЮПЕР.ZIP
      2018-10-12 13:49 - 2018-10-12 13:49 - 000001382 _____ C:\Users\Rosko\Downloads\НЕДКО БОРИСОВ КОЛЕВ_2019_ЮПЕР.ZIP
      2018-10-12 13:48 - 2018-10-12 13:48 - 000001499 _____ C:\Users\Rosko\Downloads\НЕДКО БОРИСОВ КОЛЕВ_2019_БОЖУРОВО.ZIP
      2018-10-12 09:23 - 2018-10-12 09:23 - 000075048 _____ C:\Users\Rosko\Downloads\Crystal Reports - sp_invoice_text_only_2007_5_l.rpt (1).pdf
      2018-10-10 12:50 - 2018-10-10 12:50 - 004808921 _____ C:\Users\Rosko\Downloads\П-03001718168660-004-001_archive.zip
      2018-10-06 15:09 - 2018-10-06 15:09 - 000611358 _____ C:\Users\Rosko\Downloads\379984975.pdf
      2018-10-04 13:28 - 2018-10-04 13:28 - 000156030 _____ C:\Users\Rosko\Downloads\П-03001718168660-040-001_archive.zip
      2018-10-01 18:27 - 2018-10-01 18:27 - 000143428 _____ C:\Users\Rosko\Downloads\Информационна брошура за бъдещите майки.pdf
      ==================== One Month Modified files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-10-28 14:23 - 2009-07-14 06:45 - 000016624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2018-10-28 14:23 - 2009-07-14 06:45 - 000016624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2018-10-28 14:19 - 2009-07-14 05:20 - 000000000 ____D C:\PerfLogs
      2018-10-28 14:11 - 2017-08-24 12:56 - 000000000 ____D C:\Users\Rosko\AppData\Roaming\CalendarTool
      2018-10-28 12:42 - 2009-07-14 07:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
      2018-10-28 12:42 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
      2018-10-28 12:36 - 2017-06-10 14:47 - 000000000 __SHD C:\Users\Rosko\IntelGraphicsProfiles
      2018-10-28 12:36 - 2015-04-23 13:38 - 000000000 ____D C:\Program Files (x86)\TeamViewer
      2018-10-28 12:35 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2018-10-28 11:44 - 2016-08-08 17:51 - 000000000 ___HD C:\Program Files (x86)\m3yE3E0
      2018-10-28 10:43 - 2015-04-23 12:58 - 000000000 ____D C:\Users\Rosko\AppData\Local\Microsoft Help
      2018-10-28 10:29 - 2017-01-10 10:04 - 000000000 ____D C:\Users\Rosko\AppData\Local\CrashDumps
      2018-10-27 19:48 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\tracing
      2018-10-24 07:25 - 2015-04-24 13:10 - 000000000 ____D C:\Users\Rosko\AppData\Roaming\Skype
      2018-10-23 08:18 - 2017-02-01 21:07 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
      2018-10-18 09:43 - 2018-07-09 15:03 - 000000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
      2018-10-18 09:43 - 2016-02-04 18:11 - 000002998 _____ C:\Windows\wininit.ini
      2018-10-17 16:19 - 2015-06-12 12:20 - 000000000 ____D C:\Windows\Minidump
      2018-10-17 16:18 - 2015-06-12 12:20 - 375178840 _____ C:\Windows\MEMORY.DMP
      2018-10-15 10:59 - 2009-07-14 07:08 - 000032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
      2018-10-09 21:41 - 2018-03-14 11:33 - 000004462 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
      2018-10-09 21:41 - 2017-02-01 18:37 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
      2018-10-09 21:41 - 2017-02-01 18:37 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
      2018-10-09 21:41 - 2017-02-01 18:37 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
      2018-10-09 21:41 - 2017-02-01 18:37 - 000000000 ____D C:\Windows\SysWOW64\Macromed
      2018-10-09 21:41 - 2017-02-01 18:37 - 000000000 ____D C:\Windows\system32\Macromed
      2018-10-04 13:28 - 2015-11-03 22:05 - 000000000 ____D C:\Users\Rosko\AppData\LocalLow\Adobe
      2018-10-01 21:10 - 2015-04-23 13:18 - 000000000 ____D C:\KMPlayer
      2018-10-01 08:27 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
      ==================== Files in the root of some directories =======
      2015-10-10 07:33 - 2015-10-10 07:33 - 000229019 _____ () C:\ProgramData\KTLVGTHRCQSO.dat
      2017-06-08 17:31 - 2017-06-08 17:31 - 000000017 _____ () C:\Users\Rosko\AppData\Local\resmon.resmoncfg
      ==================== Bamital & volsnap ======================
      (There is no automatic fix for files that do not pass verification.)
      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\SysWOW64\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
      LastRegBack: 2018-10-26 08:40
      ==================== End of FRST.txt ============================
      Addition.txt
    • от Magnolia D
      Здравейте, 
      От два - три дни интернет връзката ми се влоши драматично - почти невъзможно беше да се зареди каквато и да е страница (отнемаше минути, ако въобще успееше да го направи). Анти вирусната показа, че има Троянец(нещо си ) - може би е трябвало да запомня какво точно нещо си, но аз просто натиснах да го изтрие. Повторната проверка показа, че всичко е наред, но не мисля че е точно така. Сега зарежда малко по-бързо, но като цяло е изключително бавно и не мисля, че е от връзката. Предполагам, че се разбира, че знанието за компютрите не е една от най-силните ми страни, но за всеки случай ще го подчертая, за да се опитам да оправдая глупостите , които евентуално съм направила  и елементарния си "компютърен изказ". Относно стъпките за публикуване - нямам диск с операционната система, прикачвам другите два файла. П.С. Предварително благодаря за времето и съдействието!
      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11.11.2018
      Ran by Grigorovi (administrator) on DIDI (13-11-2018 15:39:12)
      Running from D:\Instal
      Loaded Profiles: Grigorovi (Available Profiles: Grigorovi)
      Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Language: Български (България)
      Internet Explorer Version 11 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
      (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
      (SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe
      (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
      (Google Inc.) C:\Program Files\Google\Update\1.3.33.17\GoogleCrashHandler.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
      (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      ==================== Registry (Whitelisted) ===========================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Run: [CL-22-D39888C9-D725-485F-B4A2-1AD9369147B7] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\CL-22-4DEB32A9-F15E-4B9A-A7FB-125105229440\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\CL-22-4DEB32A (the data entry has 44 more characters).
      HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [997920 2011-06-15] (Microsoft Corporation)
      HKU\S-1-5-21-2744073735-3007959217-1321240149-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> 
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
      Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1
      Tcpip\..\Interfaces\{3247EA78-9C23-40D4-AF6B-21088034F9BF}: [DhcpNameServer] 192.168.8.1 192.168.8.1
      Tcpip\..\Interfaces\{AE99D80D-ED5E-4FA1-8934-689D4319410D}: [DhcpNameServer] 192.168.8.1 192.168.8.1
      Internet Explorer:
      ==================
      HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
      FireFox:
      ========
      FF DefaultProfile: ixj5pejf.default-1538731853205
      FF ProfilePath: C:\Users\Grigorovi\AppData\Roaming\Mozilla\Firefox\Profiles\ixj5pejf.default-1538731853205 [2018-11-12]
      FF Extension: (Firefox Monitor) - C:\Users\Grigorovi\AppData\Roaming\Mozilla\Firefox\Profiles\ixj5pejf.default-1538731853205\features\{a452a5ff-64b4-44fa-910c-c6debf5ffb1d}\fxmonitor@mozilla.org.xpi [2018-10-05]
      FF Extension: (Telemetry coverage) - C:\Users\Grigorovi\AppData\Roaming\Mozilla\Firefox\Profiles\ixj5pejf.default-1538731853205\features\{a452a5ff-64b4-44fa-910c-c6debf5ffb1d}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-10-05] [Legacy]
      FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_29_0_0_140.dll [2018-04-14] ()
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
      FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-29] (Google Inc.)
      FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-29] (Google Inc.)
      FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
      FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
      FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
      FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
      FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
      FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-2744073735-3007959217-1321240149-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\Grigorovi\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-08-10] (Zoom Video Communications, Inc.)
      Chrome: 
      =======
      CHR Profile: C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default [2018-11-13]
      CHR Extension: (Презентации) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
      CHR Extension: (Документи) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
      CHR Extension: (Google Диск) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
      CHR Extension: (YouTube) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-26]
      CHR Extension: (Adblock Plus) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-10-31]
      CHR Extension: (Adobe Acrobat) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
      CHR Extension: (Facebook Pixel Helper) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2018-10-23]
      CHR Extension: (Таблици) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
      CHR Extension: (Google Документи офлайн) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
      CHR Extension: (Pinterest Save Button) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2018-10-19]
      CHR Extension: (Grammar.com) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hamhaljjdpcgkelbadepgmnocknejief [2018-10-02]
      CHR Extension: (Keywords Everywhere - Keyword Tool) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbapdpeemoojbophdfndmlgdhppljgmp [2018-09-19]
      CHR Extension: (Reasy) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhfiiflbfkgfmeinikcgikgiijegkhgf [2017-12-09]
      CHR Extension: (Grammar and Spelling checker by Ginger) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdfieneakcjfaiglcfcgkidlkmlijjnh [2018-11-07]
      CHR Extension: (Tag Assistant (by Google)) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2018-09-27]
      CHR Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2018-10-09]
      CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2018-07-23]
      CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
      CHR Extension: (Gmail) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-26]
      CHR Extension: (Chrome Media Router) - C:\Users\Grigorovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-19]
      CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
      ==================== Services (Whitelisted) ====================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      S4 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [26112 2009-12-03] (LSI Corporation)
      R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [114648 2018-11-12] (SurfRight B.V.)
      R2 hmpalertsvc; C:\Program Files\HitmanPro.Alert\hmpalert.exe [4406408 2018-11-12] (SurfRight B.V.)
      R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [5073376 2018-09-19] (Malwarebytes)
      R2 MsMpSvc; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-27] (Microsoft Corporation)
      R3 NisSrv; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [208944 2011-04-27] (Microsoft Corporation)
      S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
      ===================== Drivers (Whitelisted) ======================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [109456 2017-05-18] (Samsung Electronics Co., Ltd.)
      R1 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [263288 2018-11-12] (SurfRight B.V.)
      R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [229568 2018-11-13] (Malwarebytes)
      R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
      R1 MpKsl5e3716e3; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4EE32FF0-58AB-4EF4-90BC-B7873B344D95}\MpKsl5e3716e3.sys [49504 2018-11-13] (Microsoft Corporation)
      R3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [43392 2011-04-18] (Microsoft Corporation)
      S3 VGPU; System32\drivers\rdvgkmd.sys [X]
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One Month Created files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2099-10-22 18:57 - 30826-10-22 18:57 - 000186368 ____N (Microsoft Corporation) C:\Windows\foJiYOYp.exe
      2099-10-22 18:57 - 30826-10-22 18:57 - 000073216 ____N (Microsoft Corporation) C:\Windows\system32\rNZYYO.exe
      2099-10-22 18:57 - 30826-10-22 18:57 - 000073216 ____N (Microsoft Corporation) C:\Windows\system32\OmATowuMEtOu.exe
      2018-11-13 10:08 - 2018-11-13 10:08 - 000229568 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
      2018-11-12 18:25 - 2018-11-13 15:38 - 000000000 ____D C:\Windows\CryptoGuard
      2018-11-12 18:25 - 2018-11-13 10:06 - 000000000 ___DC C:\ProgramData\HitmanPro.Alert
      2018-11-12 18:25 - 2018-11-12 18:25 - 000875656 _____ (SurfRight B.V.) C:\Windows\system32\hmpalert.dll
      2018-11-12 18:25 - 2018-11-12 18:25 - 000263288 _____ (SurfRight B.V.) C:\Windows\system32\Drivers\hmpalert.sys
      2018-11-12 18:25 - 2018-11-12 18:25 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro.Alert
      2018-11-12 18:25 - 2018-11-12 18:25 - 000000000 ___DC C:\Program Files\HitmanPro.Alert
      2018-11-12 18:14 - 2018-11-12 18:14 - 000001847 _____ C:\Users\Public\Desktop\HitmanPro.lnk
      2018-11-12 18:14 - 2018-11-12 18:14 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
      2018-11-12 18:13 - 2018-11-12 18:14 - 000000000 ___DC C:\Program Files\HitmanPro
      2018-11-07 09:29 - 2018-11-07 09:29 - 001292716 _____ C:\Users\Grigorovi\Desktop\ros.zip
      2018-11-07 02:23 - 2018-11-05 16:55 - 009162423 _____ C:\Users\Grigorovi\Desktop\139_da_badesh_bog2.zip
      2018-11-07 02:14 - 2018-11-07 02:14 - 001062670 _____ C:\Users\Grigorovi\Desktop\Ерик Бърн -Психология на човешките взаимоотношения.pdf
      2018-11-07 02:13 - 2018-11-07 02:13 - 000798148 _____ C:\Users\Grigorovi\Desktop\Игрите, които хората играят.pdf
      2018-11-01 17:09 - 2018-11-04 22:36 - 000000000 ____D C:\Users\Grigorovi\Desktop\WP-UnEducatedMermad
      2018-10-29 18:44 - 2018-10-29 18:44 - 001092248 _____ C:\Users\Grigorovi\Desktop\Quick-Start-Affiliate-Marketing-Report.pdf
      2018-10-26 22:52 - 2018-10-26 22:52 - 002583150 _____ C:\Users\Grigorovi\Desktop\lipton_spontanna.zip
      2018-10-26 22:51 - 2018-10-26 22:51 - 001290479 _____ C:\Users\Grigorovi\Desktop\24_lipton_honemoon.zip
      2018-10-20 16:07 - 2018-10-20 16:07 - 002677746 _____ C:\Users\Grigorovi\Desktop\unblock_your_abundance_by_christiemarie_sheldon_workbook_nsp2.pdf
      2018-10-17 01:23 - 2018-10-17 01:24 - 000507221 _____ C:\Users\Grigorovi\Desktop\shum_v_ushite.zip
      2018-10-16 18:55 - 2018-10-16 18:55 - 006273583 _____ C:\Users\Grigorovi\Desktop\Шакти Гуаейн-Пътят към истинското блоагоденствие.rar
      ==================== One Month Modified files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-11-13 15:39 - 2018-04-07 19:16 - 000000000 ___DC C:\FRST
      2018-11-13 10:15 - 2009-07-14 06:34 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2018-11-13 10:15 - 2009-07-14 06:34 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2018-11-13 10:10 - 2018-04-10 19:56 - 000000386 _____ C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
      2018-11-13 10:06 - 2018-04-07 21:35 - 000065536 _____ C:\Windows\system32\Ikeext.etl
      2018-11-13 10:06 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2018-11-13 05:49 - 2017-04-26 17:00 - 000000000 ___DC C:\ProgramData\HitmanPro
      2018-11-12 19:59 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
      2018-11-12 18:48 - 2014-10-15 19:19 - 000000000 ____D C:\Windows\Minidump
      2018-11-12 18:34 - 2016-12-02 16:12 - 000000702 _____ C:\Users\Public\Desktop\System Ninja.lnk
      2018-11-12 18:34 - 2016-12-02 16:12 - 000000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Ninja
      2018-11-09 18:05 - 2018-07-24 14:22 - 000000000 ___DC C:\Users\Grigorovi\AppData\Local\gtk-2.0
      2018-10-30 09:45 - 2016-10-28 18:07 - 000660594 _____ C:\Windows\system32\perfh01D.dat
      2018-10-30 09:45 - 2016-10-28 18:07 - 000144252 _____ C:\Windows\system32\perfc01D.dat
      2018-10-30 09:45 - 2016-10-28 17:31 - 000425298 _____ C:\Windows\system32\perfh012.dat
      2018-10-30 09:45 - 2016-10-28 17:31 - 000122162 _____ C:\Windows\system32\perfc012.dat
      2018-10-30 09:45 - 2016-10-28 16:02 - 000378044 _____ C:\Windows\system32\prfh0804.dat
      2018-10-30 09:45 - 2016-10-28 16:02 - 000121370 _____ C:\Windows\system32\prfc0804.dat
      2018-10-30 09:45 - 2016-10-28 15:29 - 000413652 _____ C:\Windows\system32\perfh011.dat
      2018-10-30 09:45 - 2016-10-28 15:29 - 000123878 _____ C:\Windows\system32\perfc011.dat
      2018-10-30 09:45 - 2016-10-28 15:09 - 000680628 _____ C:\Windows\system32\perfh00E.dat
      2018-10-30 09:45 - 2016-10-28 15:09 - 000173052 _____ C:\Windows\system32\perfc00E.dat
      2018-10-30 09:45 - 2016-10-28 14:49 - 000478376 _____ C:\Windows\system32\perfh00B.dat
      2018-10-30 09:45 - 2016-10-28 14:49 - 000103298 _____ C:\Windows\system32\perfc00B.dat
      2018-10-30 09:45 - 2016-10-28 14:25 - 000389218 _____ C:\Windows\system32\perfh00D.dat
      2018-10-30 09:45 - 2016-10-28 14:25 - 000086536 _____ C:\Windows\system32\perfc00D.dat
      2018-10-30 09:45 - 2016-10-28 13:57 - 000740372 _____ C:\Windows\system32\perfh013.dat
      2018-10-30 09:45 - 2016-10-28 13:57 - 000154880 _____ C:\Windows\system32\perfc013.dat
      2018-10-30 09:45 - 2016-10-28 13:42 - 000491388 _____ C:\Windows\system32\perfh014.dat
      2018-10-30 09:45 - 2016-10-28 13:42 - 000097182 _____ C:\Windows\system32\perfc014.dat
      2018-10-30 09:45 - 2016-10-28 13:17 - 000603862 _____ C:\Windows\system32\perfh008.dat
      2018-10-30 09:45 - 2016-10-28 13:17 - 000112906 _____ C:\Windows\system32\perfc008.dat
      2018-10-30 09:45 - 2016-10-28 12:51 - 000736920 _____ C:\Windows\system32\perfh010.dat
      2018-10-30 09:45 - 2016-10-28 12:51 - 000148624 _____ C:\Windows\system32\perfc010.dat
      2018-10-30 09:45 - 2016-10-28 12:37 - 000665714 _____ C:\Windows\system32\perfh005.dat
      2018-10-30 09:45 - 2016-10-28 12:37 - 000143204 _____ C:\Windows\system32\perfc005.dat
      2018-10-30 09:45 - 2016-10-28 12:18 - 000475888 _____ C:\Windows\system32\perfh001.dat
      2018-10-30 09:45 - 2016-10-28 12:18 - 000096550 _____ C:\Windows\system32\perfc001.dat
      2018-10-30 09:45 - 2016-10-28 12:05 - 000742590 _____ C:\Windows\system32\perfh00C.dat
      2018-10-30 09:45 - 2016-10-28 12:05 - 000151358 _____ C:\Windows\system32\perfc00C.dat
      2018-10-30 09:45 - 2016-10-28 11:52 - 000725892 _____ C:\Windows\system32\prfh0816.dat
      2018-10-30 09:45 - 2016-10-28 11:52 - 000154684 _____ C:\Windows\system32\prfc0816.dat
      2018-10-30 09:45 - 2016-10-28 11:36 - 000506288 _____ C:\Windows\system32\perfh006.dat
      2018-10-30 09:45 - 2016-10-28 11:36 - 000100436 _____ C:\Windows\system32\perfc006.dat
      2018-10-30 09:45 - 2016-10-28 11:24 - 000742330 _____ C:\Windows\system32\perfh00A.dat
      2018-10-30 09:45 - 2016-10-28 11:24 - 000160252 _____ C:\Windows\system32\perfc00A.dat
      2018-10-30 09:45 - 2016-10-28 11:11 - 000395216 _____ C:\Windows\system32\prfh0404.dat
      2018-10-30 09:45 - 2016-10-28 11:11 - 000116868 _____ C:\Windows\system32\prfc0404.dat
      2018-10-30 09:45 - 2016-10-28 10:59 - 000737232 _____ C:\Windows\system32\perfh015.dat
      2018-10-30 09:45 - 2016-10-28 10:59 - 000157650 _____ C:\Windows\system32\perfc015.dat
      2018-10-30 09:45 - 2016-10-28 10:44 - 000721474 _____ C:\Windows\system32\perfh019.dat
      2018-10-30 09:45 - 2016-10-28 10:44 - 000152620 _____ C:\Windows\system32\perfc019.dat
      2018-10-30 09:45 - 2016-10-28 10:25 - 000710754 _____ C:\Windows\system32\prfh0416.dat
      2018-10-30 09:45 - 2016-10-28 10:25 - 000149434 _____ C:\Windows\system32\prfc0416.dat
      2018-10-30 09:45 - 2016-10-28 09:57 - 000694082 _____ C:\Windows\system32\perfh007.dat
      2018-10-30 09:45 - 2016-10-28 09:57 - 000150894 _____ C:\Windows\system32\perfc007.dat
      2018-10-30 09:45 - 2016-10-28 09:41 - 000653556 _____ C:\Windows\system32\perfh01F.dat
      2018-10-30 09:45 - 2016-10-28 09:41 - 000141778 _____ C:\Windows\system32\perfc01F.dat
      2018-10-30 09:45 - 2016-10-28 09:41 - 000126256 _____ C:\Windows\system32\perfh002.dat
      2018-10-30 09:45 - 2016-10-28 09:41 - 000028684 _____ C:\Windows\system32\perfc002.dat
      2018-10-30 09:45 - 2010-11-20 23:01 - 017739850 _____ C:\Windows\system32\PerfStringBackup.INI
      2018-10-26 11:12 - 2018-10-05 13:08 - 000129248 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
      2018-10-25 10:37 - 2018-04-10 18:45 - 000002093 _____ C:\Users\Public\Desktop\Google Chrome.lnk
      2018-10-25 10:37 - 2016-08-26 11:58 - 000002134 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
      2018-10-24 12:51 - 2018-04-15 10:33 - 000000000 ___DC C:\Users\Grigorovi\AppData\Local\ElevatedDiagnostics
      2018-10-23 08:50 - 2016-08-24 15:28 - 000002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
      2018-10-15 23:48 - 2014-10-15 19:37 - 000479504 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
      ==================== Files in the root of some directories =======
      2017-11-23 15:47 - 2017-11-23 15:47 - 001276776 _____ () C:\Users\Grigorovi\AppData\Roaming\screenshot11Thursday1547301350000.png
      2018-05-17 11:44 - 2018-05-17 11:44 - 001302316 _____ () C:\Users\Grigorovi\AppData\Roaming\screenshot5Thursday1244426890000.png
      2018-05-17 11:44 - 2018-05-17 11:44 - 001299942 _____ () C:\Users\Grigorovi\AppData\Roaming\screenshot5Thursday1244446010000.png
      2016-09-01 09:53 - 2016-09-01 09:53 - 000000000 ____C () C:\Users\Grigorovi\AppData\Local\AtStart.txt
      2016-09-01 09:53 - 2016-09-01 09:53 - 000000000 ____C () C:\Users\Grigorovi\AppData\Local\DSwitch.txt
      2016-09-01 09:53 - 2016-09-01 09:53 - 000000000 ____C () C:\Users\Grigorovi\AppData\Local\QSwitch.txt
      2018-07-31 22:52 - 2018-07-31 22:52 - 000003292 ____C () C:\Users\Grigorovi\AppData\Local\recently-used.xbel
      2017-08-26 20:16 - 2017-08-26 20:16 - 000007597 ____C () C:\Users\Grigorovi\AppData\Local\Resmon.ResmonCfg
      2018-04-07 13:19 - 2018-04-07 13:19 - 000000003 ____C () C:\Users\Grigorovi\AppData\Local\wbem.ini
      ==================== Bamital & volsnap ======================
      (There is no automatic fix for files that do not pass verification.)
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
      LastRegBack: 2018-11-04 00:42
      ==================== End of FRST.txt ============================
       
      Addition.txt
    • от D101149
      Здравейте! Съмнявам се, че система ми е заразена ако може да ми помогнете ще съм ви благодарен (за пореден път)  Първите 3-4 минути изобщо хрома не зарежда страниците..
       
      Addition.txt
      FRST.txt
    • от mordikai
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.09.2018
      Ran by Dellssd (administrator) on DELLSSD-PC (29-09-2018 16:54:29)
      Running from C:\Users\Dellssd\Downloads
      Loaded Profiles: Dellssd (Available Profiles: Dellssd)
      Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
      Internet Explorer Version 11 (Default browser: IE)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
      (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
      (Microsoft) C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
      () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
      (Intel Corporation) C:\Windows\System32\igfxtray.exe
      (Intel Corporation) C:\Windows\System32\hkcmd.exe
      (Intel Corporation) C:\Windows\System32\igfxpers.exe
      (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.805\SSScheduler.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
      (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
      (AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
      (AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
      (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
      (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Microsoft Corporation) C:\Windows\splwow64.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.10\Lightshot.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (BitTorrent Inc.) C:\Users\Dellssd\AppData\Roaming\uTorrent\uTorrent.exe
      (BitTorrent Inc.) C:\Users\Dellssd\AppData\Roaming\uTorrent\updates\3.4.6_42178\utorrentie.exe
      (BitTorrent Inc.) C:\Users\Dellssd\AppData\Roaming\uTorrent\updates\3.4.6_42178\utorrentie.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      ==================== Registry (Whitelisted) ===========================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-08-30] (AVAST Software)
      HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
      HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
      HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
      Winlogon\Notify\igfxcui: C:\Windows\SYSTEM32\igfxdev.dll (Intel Corporation)
      HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
      HKU\S-1-5-21-477188782-2465529923-3270759937-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_134_pepper.exe [1447936 2018-07-13] (Adobe Systems Incorporated)
      HKU\S-1-5-21-477188782-2465529923-3270759937-1000\...\MountPoints2: {6e61377d-2802-11e7-81ae-1c659d02e554} - G:\AutoRun.exe
      HKU\S-1-5-21-477188782-2465529923-3270759937-1000\...\MountPoints2: {76ec0a4f-0d2e-11e6-8287-1c659d02e554} - F:\SETUP.EXE
      HKU\S-1-5-21-477188782-2465529923-3270759937-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
      HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
      Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
      Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2018-09-26]
      ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.805\SSScheduler.exe (McAfee, Inc.)
      GroupPolicy: Restriction ? <==== ATTENTION
      GroupPolicy\User: Restriction ? <==== ATTENTION
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      ProxyEnable: [S-1-5-21-477188782-2465529923-3270759937-1000] => Proxy is enabled.
      Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
      Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{645E12D2-5740-463F-B063-09C024155032}: [DhcpNameServer] 192.168.8.1 192.168.8.1
      Tcpip\..\Interfaces\{B0D854A2-9D35-438A-98DE-EE2EB8CFFC94}: [DhcpNameServer] 192.168.0.1
      Internet Explorer:
      ==================
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
      HKU\S-1-5-21-477188782-2465529923-3270759937-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKLM-x32 -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKLM-x32 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKU\S-1-5-21-477188782-2465529923-3270759937-1000 -> 9845cd48-2779-11e7-bbbc-1c659d02e554 URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKU\S-1-5-21-477188782-2465529923-3270759937-1000 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://yandex.ru/search/?win=277&clid=2262092-3&text={searchTerms}
      SearchScopes: HKU\S-1-5-21-477188782-2465529923-3270759937-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10041_spdf_opdfs_all_b_doc2pdf_170414__yaie&p={searchTerms}
      BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
      BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2018-03-10] (Google Inc.)
      BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
      BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
      BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2018-03-10] (Google Inc.)
      BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
      Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2018-03-10] (Google Inc.)
      Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2018-03-10] (Google Inc.)
      Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Google\Google Desktop Search\Plugins\gdSkype\skype4com.dll No File
      StartMenuInternet: IEXPLORE.EXE - iexplore.exe
      FireFox:
      ========
      FF DefaultProfile: yk7fki5l.default
      FF ProfilePath: C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default [2018-09-26]
      FF Homepage: Mozilla\Firefox\Profiles\yk7fki5l.default -> hxxps://search.avast.com/AV772/
      FF NewTab: Mozilla\Firefox\Profiles\yk7fki5l.default -> about:newtab
      FF Extension: (Домашняя страница Mail.Ru) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\homepage@mail.ru.xpi [2018-08-10]
      FF Extension: (Поиск Mail.Ru) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\search@mail.ru.xpi [2018-04-12]
      FF Extension: (Советник Яндекс.Маркета) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\sovetnik@metabar.ru.xpi [2018-09-19]
      FF Extension: (Avast SafePrice) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\sp@avast.com.xpi [2018-08-10]
      FF Extension: (Визуальные закладки) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\vb@yandex.ru.xpi [2018-05-06]
      FF Extension: (Avast Online Security) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\wrc@avast.com.xpi [2018-05-30]
      FF Extension: (Пульт) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\Extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.xpi [2017-12-03]
      FF Extension: (Telemetry coverage) - C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\features\{02617030-72af-413d-a344-376f30098954}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-09-19] [Legacy]
      FF SearchPlugin: C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\searchplugins\avast-search.xml [2017-08-25]
      FF SearchPlugin: C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\searchplugins\yahoo-lavasoft.xml [2017-04-14]
      FF SearchPlugin: C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\searchplugins\Yahoo®-20173422.xml [2017-04-22]
      FF SearchPlugin: C:\Users\Dellssd\AppData\Roaming\Mozilla\Firefox\Profiles\yk7fki5l.default\searchplugins\yandex.ru-20173422.xml [2017-04-22]
      FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
      FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
      FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
      FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
      FF Plugin-x32: Soda PDF Desktop -> C:\Program Files (x86)\Soda PDF Desktop\np-previewer.dll [2017-03-23] (LULU Software)
      FF Plugin HKU\S-1-5-21-477188782-2465529923-3270759937-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\Dellssd\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-01-25] (Zoom Video Communications, Inc.)
      Chrome: 
      =======
      CHR HomePage: Default -> yandex.ru
      CHR NewTab: Default ->  Active:"chrome-extension://fehhbdbmfjboomkmkflbaekjkhkklbnh/newtabproduct.html", Active:"chrome-extension://ceopoaldcnmhechacafgagdkklcogkgd/newtabproduct.html", Not-active:"chrome-extension://hcckjhfbahlnihggjcbadkgfjcghcibl/newtab/newtab.html", Not-active:"chrome-extension://mebpengldpmmlnaeehejppajiakgpbek/redirect.html", Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/stubby.html", Not-active:"chrome-extension://agibagflppafhfonkefpklndlohkclcb/index.html", Not-active:"chrome-extension://ghfmhofojkkfdnlfefhkckbflohgiicn/index.html"
      CHR DefaultSearchURL: Default -> hxxp://musix.searchalgo.com/search/?category=web&s=wmds&q={searchTerms}
      CHR DefaultSearchKeyword: Default -> WowMusix
      CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
      CHR Profile: C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default [2018-09-29]
      CHR Extension: (Slides) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
      CHR Extension: (Docs) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
      CHR Extension: (Google Drive) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-19]
      CHR Extension: (Skype Calling) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2016-10-25]
      CHR Extension: (YouTube) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-19]
      CHR Extension: (OnlineMapFinder) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd [2018-04-26]
      CHR Extension: (Tampermonkey) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-08-24]
      CHR Extension: (Стартовая — Яндекс) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkekdlkmdpipihonapoleopfekmapadh [2017-06-14]
      CHR Extension: (Adobe Acrobat) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-14]
      CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2018-09-20]
      CHR Extension: (MyImageConverter) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\fehhbdbmfjboomkmkflbaekjkhkklbnh [2018-08-23]
      CHR Extension: (Sheets) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
      CHR Extension: (Search App - Music) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\flohajbbpjlbphjgeffnhlopdhoonghc [2017-09-13]
      CHR Extension: (Google Docs Offline) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-21]
      CHR Extension: (Avast Online Security) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-09-26]
      CHR Extension: (Яндекс) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfblcbjfojmgagikhldeppgmgdpjkpl [2017-06-20]
      CHR Extension: (Ask Web Search) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmengapaekgmapkcophhdmppmjinpogo [2018-09-21]
      CHR Extension: (Ask Web Search) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkmodlfcmmnhhlofndkhdcembjaefbb [2018-09-21]
      CHR Extension: (FromDocToPDF) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2018-08-24]
      CHR Extension: (Chrome Web Store Payments) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
      CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\odijcgafkhpobjlnfdgiacpdenpmbgme [2016-10-19]
      CHR Extension: (Parity to Affinity) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\peagbbjfdfkkfcehfbddelhhppflbgla [2017-03-13]
      CHR Extension: (Mail.Ru) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\phkdcinmmljblpnkohlipaiodlonpinf [2016-10-19]
      CHR Extension: (SearchApp - Entertainment) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlbjnedeghkgaeghaiocogfofoicbpg [2018-01-16]
      CHR Extension: (Gmail) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-19]
      CHR Extension: (Chrome Media Router) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-19]
      CHR Extension: (Pulse) - C:\Users\Dellssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmpoaahleccaibbhfjfimigepmfmmbbk [2018-06-06]
      CHR HKLM-x32\...\Chrome\Extension: [dkekdlkmdpipihonapoleopfekmapadh] - hxxp://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [jkfblcbjfojmgagikhldeppgmgdpjkpl] - hxxp://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [odijcgafkhpobjlnfdgiacpdenpmbgme] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [phkdcinmmljblpnkohlipaiodlonpinf] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [pmpoaahleccaibbhfjfimigepmfmmbbk] - hxxps://clients2.google.com/service/update2/crx
      Opera: 
      =======
      OPR StartupUrls: "hxxps://www.yandex.ru/?win=277&clid=2262091-3"
      ==================== Services (Whitelisted) ====================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-01-05] (Apple Inc.)
      R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7994520 2018-08-30] (AVAST Software)
      S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-23] (AVAST Software)
      R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-08-30] (AVAST Software)
      S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-23] (AVAST Software)
      S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo Uninstaller 2017\DfSdkS64.exe [544768 2009-08-24] (mst software GmbH, Germany) [File not signed]
      S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.805\McCHSvc.exe [405392 2018-09-24] (McAfee, Inc.)
      R2 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [51112 2017-02-22] (Microsoft)
      S2 Soda PDF Desktop Creator; C:\Program Files\Soda PDF Desktop\creator-ws.exe [755048 2017-03-23] (LULU Software)
      S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
      R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH)
      R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25192 2017-04-14] ()
      S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
      S3 wpscloudsvr; C:\Program Files (x86)\Kingsoft\Kingsoft Office\wpscloudsvr.exe [220288 2018-03-28] (Zhuhai Kingsoft Office Software Co.,Ltd)
      ===================== Drivers (Whitelisted) ======================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [199712 2018-08-30] (AVAST Software)
      R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [229384 2018-08-30] (AVAST Software)
      R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [201320 2018-08-30] (AVAST Software)
      R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [346664 2018-08-30] (AVAST Software)
      R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [59568 2018-08-30] (AVAST Software)
      R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [249016 2018-08-30] (AVAST Software)
      S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-08-30] (AVAST Software)
      R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [163392 2018-09-12] (AVAST Software)
      R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [111864 2018-08-30] (AVAST Software)
      R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [87904 2018-08-30] (AVAST Software)
      R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1027720 2018-08-30] (AVAST Software)
      R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [467320 2018-09-05] (AVAST Software)
      R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [215920 2018-09-12] (AVAST Software)
      R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [381560 2018-08-30] (AVAST Software)
      R3 ST_Accel; C:\Windows\System32\DRIVERS\ST_Accel.sys [103088 2015-02-26] (STMicroelectronics)
      R2 UI5IFS; C:\Program Files (x86)\Ashampoo\Ashampoo Uninstaller 2017\IFS64.sys [31320 2015-12-07] ()
      S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
      S3 btwaudio; system32\drivers\btwaudio.sys [X]
      S3 btwavdt; system32\drivers\btwavdt.sys [X]
      S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X]
      S3 btwrchid; system32\DRIVERS\btwrchid.sys [X]
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One Month Created files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-09-29 16:54 - 2018-09-29 16:54 - 000026700 _____ C:\Users\Dellssd\Downloads\FRST.txt
      2018-09-29 16:54 - 2018-09-29 16:54 - 000000000 ____D C:\FRST
      2018-09-29 16:53 - 2018-09-29 16:53 - 002414080 _____ (Farbar) C:\Users\Dellssd\Downloads\FRST64.exe
      2018-09-29 16:19 - 2018-09-29 16:19 - 004279416 _____ (ESET) C:\Users\Dellssd\Downloads\eset_internet_security_live_installer.exe
      2018-09-29 15:16 - 2018-09-29 15:16 - 000017773 _____ C:\Users\Dellssd\Downloads\American.Horror.Story.S08E03.720p.WEBRip.x264-TBS.torrent
      2018-09-29 11:31 - 2018-09-29 11:31 - 000001191 _____ C:\Users\Dellssd\AppData\Roaming\uni.txt
      2018-09-29 08:39 - 2018-09-29 08:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
      2018-09-29 08:30 - 2018-09-29 08:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
      2018-09-27 23:29 - 2018-09-27 23:29 - 005193216 _____ ( ) C:\Users\Dellssd\Downloads\wspsetup.exe
      2018-09-26 14:31 - 2018-09-26 14:31 - 000001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
      2018-09-26 14:31 - 2018-09-26 14:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
      2018-09-26 14:31 - 2018-09-26 14:31 - 000000000 ____D C:\ProgramData\McAfee Security Scan
      2018-09-25 11:26 - 2018-09-28 11:38 - 000109568 ____H C:\Users\Dellssd\Desktop\~WRL1409.tmp
      2018-09-25 11:26 - 2018-09-27 10:53 - 000094208 ____H C:\Users\Dellssd\Desktop\~WRL1082.tmp
      2018-09-25 11:26 - 2018-09-26 13:19 - 000084480 ____H C:\Users\Dellssd\Desktop\~WRL1831.tmp
      2018-09-24 22:25 - 2018-09-24 22:25 - 000014480 _____ C:\Users\Dellssd\Downloads\Preacher.S03E10.HDTV.x264-KILLERS.mkv (2).torrent
      2018-09-24 09:39 - 2018-09-24 09:39 - 000014480 _____ C:\Users\Dellssd\Downloads\Preacher.S03E10.HDTV.x264-KILLERS.mkv (1).torrent
      2018-09-23 22:48 - 2018-09-23 22:48 - 000014480 _____ C:\Users\Dellssd\Downloads\Preacher.S03E10.HDTV.x264-KILLERS.mkv.torrent
      2018-09-23 22:46 - 2018-09-23 22:46 - 000011432 _____ C:\Users\Dellssd\Downloads\Preacher.S03E09.HDTV.x264-SVA (2).torrent
      2018-09-23 08:18 - 2018-09-23 08:18 - 000011432 _____ C:\Users\Dellssd\Downloads\Preacher.S03E09.HDTV.x264-SVA (1).torrent
      2018-09-22 20:53 - 2018-09-22 20:53 - 000011432 _____ C:\Users\Dellssd\Downloads\Preacher.S03E09.HDTV.x264-SVA.torrent
      2018-09-22 19:56 - 2018-09-22 19:56 - 000018281 _____ C:\Users\Dellssd\Downloads\Preacher.S03E08.720p.HEVC.x265-MeGusta.torrent
      2018-09-22 19:03 - 2018-09-22 19:03 - 000017384 _____ C:\Users\Dellssd\Downloads\Preacher.S03E07.720p.HEVC.x265-MeGusta.torrent
      2018-09-22 10:02 - 2018-09-22 10:02 - 000010528 _____ C:\Users\Dellssd\Downloads\American.Horror.Story.S08E01.HDTV.x264-SVA (1).torrent
      2018-09-21 18:54 - 2018-09-21 18:54 - 000010528 _____ C:\Users\Dellssd\Downloads\American.Horror.Story.S08E01.HDTV.x264-SVA.torrent
      2018-09-21 18:52 - 2018-09-21 18:52 - 000017830 _____ C:\Users\Dellssd\Downloads\American.Horror.Story.S08E02.WEBRip.x264-TBS.torrent
      2018-09-19 10:10 - 2018-09-19 10:10 - 000262144 _____ C:\Windows\Minidump\091918-9126-01.dmp
      2018-09-16 10:43 - 2018-09-16 10:43 - 000218836 _____ C:\Users\Dellssd\Desktop\a.psd
      2018-09-16 10:20 - 2018-09-16 10:21 - 000024235 _____ C:\Users\Dellssd\Desktop\a.jpf
      2018-09-08 16:34 - 2018-09-08 16:34 - 000152887 _____ C:\Users\Dellssd\Desktop\5.jpeg
      2018-09-06 20:51 - 2018-09-06 20:51 - 000015001 _____ C:\Users\Dellssd\Downloads\[kinozal.tv]id1604058.torrent
      2018-08-30 23:30 - 2018-08-30 23:29 - 000379608 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
      ==================== One Month Modified files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-09-29 16:53 - 2016-04-28 15:06 - 000000000 ____D C:\Users\Dellssd\AppData\Roaming\uTorrent
      2018-09-29 16:43 - 2017-05-15 14:15 - 000000378 _____ C:\Windows\Tasks\WpsNotifyTask_Dellssd.job
      2018-09-29 16:39 - 2018-02-11 22:39 - 000000994 _____ C:\Windows\Tasks\Chromium nefil.job
      2018-09-29 16:12 - 2016-10-21 06:34 - 000000000 ____D C:\Users\Dellssd\AppData\Roaming\vlc
      2018-09-29 15:16 - 2017-09-30 23:37 - 000000000 ____D C:\Users\Dellssd\AppData\LocalLow\uTorrent
      2018-09-29 13:22 - 2016-04-28 19:38 - 000000392 _____ C:\Windows\Tasks\update-sys.job
      2018-09-29 12:57 - 2016-04-28 19:38 - 000000392 _____ C:\Windows\Tasks\update-S-1-5-21-477188782-2465529923-3270759937-1000.job
      2018-09-29 08:39 - 2016-04-28 19:38 - 000003270 _____ C:\Windows\System32\Tasks\update-S-1-5-21-477188782-2465529923-3270759937-1000
      2018-09-29 08:38 - 2009-07-14 07:45 - 000014448 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2018-09-29 08:38 - 2009-07-14 07:45 - 000014448 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2018-09-29 08:30 - 2017-08-13 12:16 - 000001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
      2018-09-29 08:30 - 2017-03-11 18:15 - 000001306 _____ C:\Users\Public\Desktop\Skype.lnk
      2018-09-29 08:30 - 2017-03-11 18:15 - 000000000 ___RD C:\Program Files (x86)\Skype
      2018-09-29 08:30 - 2016-04-28 15:22 - 000000000 ____D C:\ProgramData\Skype
      2018-09-29 08:28 - 2009-07-14 08:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI
      2018-09-29 08:28 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
      2018-09-29 08:21 - 2016-04-28 15:19 - 000000204 _____ C:\Windows\Tasks\AutoKMS.job
      2018-09-29 08:21 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2018-09-27 23:33 - 2018-03-23 00:37 - 000000000 ____D C:\Users\Dellssd\AppData\Local\AVAST Software
      2018-09-27 10:13 - 2016-12-02 22:36 - 000000000 ____D C:\Users\Dellssd\Desktop\преводи
      2018-09-26 14:31 - 2018-07-13 15:01 - 000000000 ____D C:\Program Files\McAfee Security Scan
      2018-09-24 09:29 - 2017-04-13 09:23 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
      2018-09-24 09:29 - 2016-08-18 13:17 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
      2018-09-23 23:46 - 2016-12-01 16:09 - 000000000 ____D C:\Users\Dellssd\AppData\LocalLow\Mozilla
      2018-09-23 08:33 - 2017-07-27 09:56 - 000003180 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-477188782-2465529923-3270759937-1000
      2018-09-23 08:33 - 2017-05-14 12:21 - 000002164 _____ C:\Users\Dellssd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
      2018-09-23 08:33 - 2017-05-14 12:21 - 000000000 ___RD C:\Users\Dellssd\OneDrive
      2018-09-22 17:35 - 2018-08-29 08:46 - 000501760 ____H C:\Users\Dellssd\Desktop\~WRL1243.tmp
      2018-09-21 18:56 - 2016-10-30 19:56 - 000000000 ____D C:\Users\Dellssd\Desktop\subtitri
      2018-09-21 14:57 - 2018-08-29 08:46 - 000493568 ____H C:\Users\Dellssd\Desktop\~WRL3209.tmp
      2018-09-20 12:11 - 2016-09-26 11:57 - 000119544 _____ C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
      2018-09-20 10:36 - 2017-04-14 13:23 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
      2018-09-20 10:36 - 2017-04-14 13:23 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
      2018-09-19 23:21 - 2018-03-23 00:38 - 000002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
      2018-09-19 10:10 - 2017-01-14 08:33 - 000000000 ____D C:\Windows\Minidump
      2018-09-18 23:46 - 2016-09-19 00:17 - 000002430 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
      2018-09-18 23:46 - 2016-09-19 00:17 - 000002389 _____ C:\Users\Public\Desktop\Google Chrome.lnk
      2018-09-18 12:47 - 2018-08-29 08:46 - 000419328 ____H C:\Users\Dellssd\Desktop\~WRL1414.tmp
      2018-09-17 12:36 - 2018-08-29 08:46 - 000396288 ____H C:\Users\Dellssd\Desktop\~WRL2232.tmp
      2018-09-17 09:55 - 2016-04-28 15:19 - 000000202 _____ C:\Windows\Tasks\AutoKMSDaily.job
      2018-09-16 22:22 - 2018-07-13 14:31 - 000004482 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
      2018-09-16 22:22 - 2018-06-17 11:13 - 000003138 _____ C:\Windows\System32\Tasks\{810AB3C2-34D4-499B-B4BB-9D38D546FA12}
      2018-09-16 22:22 - 2018-05-05 14:25 - 000003944 _____ C:\Windows\System32\Tasks\WpsUpdateTask_Dellssd
      2018-09-16 22:22 - 2017-08-07 09:24 - 000004192 _____ C:\Windows\System32\Tasks\WpsExternal_Dellssd_20170807092444
      2018-09-16 22:22 - 2017-05-15 14:15 - 000004196 _____ C:\Windows\System32\Tasks\WpsKtpcntrQingTask_Dellssd
      2018-09-16 22:22 - 2017-05-15 14:15 - 000003362 _____ C:\Windows\System32\Tasks\WpsNotifyTask_Dellssd
      2018-09-16 22:22 - 2017-04-16 19:21 - 000004308 _____ C:\Windows\System32\Tasks\Opera scheduled suite Autoupdate 1492359678
      2018-09-16 22:22 - 2017-04-16 19:21 - 000004086 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1492359677
      2018-09-16 22:22 - 2017-04-14 13:19 - 000003572 _____ C:\Windows\System32\Tasks\doPDF Update
      2018-09-16 22:22 - 2017-03-11 18:01 - 000003154 _____ C:\Windows\System32\Tasks\{F75FB1AB-3FC6-4CCB-8E59-EFFFE1750F20}
      2018-09-16 22:22 - 2017-03-11 17:59 - 000003154 _____ C:\Windows\System32\Tasks\{CEDD031E-67BD-4005-BC8D-F936A030F0BA}
      2018-09-16 22:22 - 2017-03-10 11:47 - 000003154 _____ C:\Windows\System32\Tasks\{54495718-5171-4E02-8AE9-0C0BA73E7D7F}
      2018-09-16 22:22 - 2017-03-10 11:46 - 000003154 _____ C:\Windows\System32\Tasks\{E1C2E6E7-851E-4C71-BE27-06A41080DD86}
      2018-09-16 22:22 - 2017-03-08 15:35 - 000003154 _____ C:\Windows\System32\Tasks\{380FC156-4700-48BE-8B5A-FBA1286DCE61}
      2018-09-16 22:22 - 2017-03-07 19:54 - 000003154 _____ C:\Windows\System32\Tasks\{B59123EA-C895-4329-A7B1-CB325A18760F}
      2018-09-16 22:22 - 2017-03-07 19:53 - 000003154 _____ C:\Windows\System32\Tasks\{1B3678E0-0EBD-4B19-8557-0E961136459F}
      2018-09-16 22:22 - 2017-03-07 19:23 - 000003152 _____ C:\Windows\System32\Tasks\{C3112054-5422-446C-8C6A-CBF71C0F1362}
      2018-09-16 22:22 - 2017-03-07 19:18 - 000003154 _____ C:\Windows\System32\Tasks\{2A7E9ED5-EA5D-44CE-A690-23D3D3057CA2}
      2018-09-16 22:22 - 2017-03-07 19:14 - 000003154 _____ C:\Windows\System32\Tasks\{E3C65BC8-A75A-427C-B27F-42C9BBE41C62}
      2018-09-16 22:22 - 2016-10-20 13:50 - 000003112 _____ C:\Windows\System32\Tasks\{35511907-B4BB-42B6-B5D5-1DEA4D518FE5}
      2018-09-16 22:22 - 2016-10-20 13:36 - 000003164 _____ C:\Windows\System32\Tasks\{CF456C35-60A1-4F96-848F-0062539D31D4}
      2018-09-16 22:22 - 2016-10-20 13:08 - 000003164 _____ C:\Windows\System32\Tasks\{286D155D-B077-4884-A3BD-71EBE307BEF5}
      2018-09-16 22:22 - 2016-10-20 13:07 - 000003164 _____ C:\Windows\System32\Tasks\{295B979B-F0EA-40DA-9832-C45D45FC859B}
      2018-09-16 22:22 - 2016-10-19 13:20 - 000003164 _____ C:\Windows\System32\Tasks\{B72E12E4-120A-46A7-B0FC-AED00851297F}
      2018-09-16 22:22 - 2016-10-19 12:55 - 000003164 _____ C:\Windows\System32\Tasks\{A7EABB03-E8E6-444E-9C70-01DEA803DBEC}
      2018-09-16 22:22 - 2016-10-19 12:53 - 000003164 _____ C:\Windows\System32\Tasks\{D6E5F4DF-91E3-4ECA-B09F-9DCF123E1030}
      2018-09-16 22:22 - 2016-09-19 00:16 - 000003432 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
      2018-09-16 22:22 - 2016-09-19 00:16 - 000003304 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
      2018-09-16 22:22 - 2016-04-28 19:38 - 000003400 _____ C:\Windows\System32\Tasks\update-sys
      2018-09-16 22:22 - 2016-04-28 15:19 - 000002740 _____ C:\Windows\System32\Tasks\AutoKMSDaily
      2018-09-16 22:22 - 2016-04-28 15:19 - 000002436 _____ C:\Windows\System32\Tasks\AutoKMS
      2018-09-16 22:22 - 2016-04-28 15:14 - 000003148 _____ C:\Windows\System32\Tasks\{5A5A1497-EAC4-4683-9946-09144759EE3B}
      2018-09-16 22:22 - 2016-04-28 13:36 - 000003254 _____ C:\Windows\System32\Tasks\{CD225CD4-3990-439E-8F36-78EB3BDEE4E1}
      2018-09-16 20:22 - 2018-08-29 08:46 - 000370688 ____H C:\Users\Dellssd\Desktop\~WRL3793.tmp
      2018-09-15 19:37 - 2018-08-29 08:46 - 000344576 ____H C:\Users\Dellssd\Desktop\~WRL1766.tmp
      2018-09-14 18:54 - 2018-08-29 08:46 - 000297984 ____H C:\Users\Dellssd\Desktop\~WRL2266.tmp
      2018-09-13 15:27 - 2018-08-29 08:46 - 000268288 ____H C:\Users\Dellssd\Desktop\~WRL2379.tmp
      2018-09-12 23:30 - 2016-04-28 15:24 - 000215920 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
      2018-09-12 12:59 - 2018-08-29 08:46 - 000251904 ____H C:\Users\Dellssd\Desktop\~WRL1812.tmp
      2018-09-12 12:19 - 2016-04-28 15:24 - 000163392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
      2018-09-09 09:00 - 2018-08-29 08:46 - 000212992 ____H C:\Users\Dellssd\Desktop\~WRL1160.tmp
      2018-09-08 11:36 - 2018-08-29 08:46 - 000209920 ____H C:\Users\Dellssd\Desktop\~WRL3129.tmp
      2018-09-07 13:25 - 2018-08-29 08:46 - 000199168 ____H C:\Users\Dellssd\Desktop\~WRL0459.tmp
      2018-09-05 11:53 - 2016-04-28 15:24 - 000467320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
      2018-09-04 13:41 - 2018-08-29 08:46 - 000154624 ____H C:\Users\Dellssd\Desktop\~WRL0358.tmp
      2018-09-03 23:58 - 2017-03-11 17:50 - 000000000 _____ C:\Windows\SysWOW64\last.dump
      2018-09-03 10:30 - 2018-08-29 08:46 - 000122368 ____H C:\Users\Dellssd\Desktop\~WRL1632.tmp
      2018-09-01 12:16 - 2018-08-29 08:46 - 000114688 ____H C:\Users\Dellssd\Desktop\~WRL0845.tmp
      2018-08-31 12:46 - 2018-08-29 08:46 - 000098304 ____H C:\Users\Dellssd\Desktop\~WRL3568.tmp
      2018-08-30 23:30 - 2017-04-04 12:54 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
      2018-08-30 23:30 - 2016-04-28 15:24 - 000087904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
      2018-08-30 23:29 - 2017-12-23 19:29 - 000249016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
      2018-08-30 23:29 - 2017-11-13 11:28 - 000199712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
      2018-08-30 23:29 - 2017-04-04 12:54 - 000346664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
      2018-08-30 23:29 - 2017-04-04 12:54 - 000229384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
      2018-08-30 23:29 - 2017-04-04 12:54 - 000201320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
      2018-08-30 23:29 - 2017-04-04 12:54 - 000059568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
      2018-08-30 23:29 - 2016-04-28 15:24 - 001027720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
      2018-08-30 23:29 - 2016-04-28 15:24 - 000381560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
      2018-08-30 23:29 - 2016-04-28 15:24 - 000111864 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
      2018-08-30 23:29 - 2016-04-28 15:24 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
      2018-08-30 13:39 - 2018-08-29 08:46 - 000077824 ____H C:\Users\Dellssd\Desktop\~WRL3210.tmp
      ==================== Files in the root of some directories =======
      2015-10-21 18:11 - 2015-10-21 18:11 - 130502551 _____ () C:\Program Files\openoffice1.cab
      2015-10-21 18:10 - 2015-10-21 18:10 - 002310144 _____ () C:\Program Files\openoffice412.msi
      2015-10-21 18:10 - 2015-10-21 18:10 - 000478720 _____ () C:\Program Files\setup.exe
      2015-10-21 18:10 - 2015-10-21 18:10 - 000000279 _____ () C:\Program Files\setup.ini
      2016-12-08 14:00 - 2017-03-04 10:53 - 000000132 _____ () C:\Users\Dellssd\AppData\Roaming\Adobe AIFF Format CS6 Prefs
      2016-12-07 08:29 - 2016-12-07 08:29 - 000000146 _____ () C:\Users\Dellssd\AppData\Roaming\gamma_ramp.reg
      2018-09-29 11:31 - 2018-09-29 11:31 - 000001191 _____ () C:\Users\Dellssd\AppData\Roaming\uni.txt
      2017-04-08 21:19 - 2016-03-31 21:40 - 000145792 _____ () C:\Users\Dellssd\AppData\Local\downloader.exe
      2016-04-28 19:38 - 2016-04-28 19:38 - 000000003 ____H () C:\Users\Dellssd\AppData\Local\updater.log
      2016-04-28 19:38 - 2016-04-28 19:38 - 000000424 ____H () C:\Users\Dellssd\AppData\Local\UserProducts.xml
      2016-10-29 12:23 - 2016-10-29 12:23 - 000017408 _____ () C:\Users\Dellssd\AppData\Local\WebpageIcons.db
      2017-02-10 09:00 - 2017-02-10 09:00 - 000000000 _____ () C:\Users\Dellssd\AppData\Local\{DC54C818-2F39-4DF4-A54B-09F3D3BE3CC3}
      Some files in TEMP:
      ====================
      2018-04-09 11:51 - 2018-08-20 12:55 - 062983128 _____ (Softland) C:\Users\Dellssd\AppData\Local\Temp\dopdf-full.exe
      2017-05-15 14:12 - 2017-05-15 14:12 - 003463288 _____ (Gadomotus                                                   ) C:\Users\Dellssd\AppData\Local\Temp\ICReinstall_microsoft_office (1).exe
      2016-10-29 19:52 - 2016-10-30 14:18 - 037642072 _____ (PandoraTV) C:\Users\Dellssd\AppData\Local\Temp\KMP_4.1.3.3.exe
      2017-12-16 10:25 - 2017-12-16 10:25 - 039544976 _____ (PandoraTV) C:\Users\Dellssd\AppData\Local\Temp\KMP_4.2.2.5.exe
      2016-12-06 13:30 - 2016-12-07 08:28 - 048947193 _____ () C:\Users\Dellssd\AppData\Local\Temp\new_version.exe
      2017-10-10 23:42 - 2017-10-10 23:42 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201710104236545.dll
      2017-10-12 10:00 - 2017-10-12 10:00 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017101208259.dll
      2017-10-13 10:42 - 2017-10-13 10:42 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201710134229437.dll
      2017-10-13 10:47 - 2017-10-13 10:47 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171013479979.dll
      2017-10-16 10:13 - 2017-10-16 10:13 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201710161342290.dll
      2017-10-19 23:59 - 2017-10-19 23:59 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201710195926616.dll
      2017-10-24 10:14 - 2017-10-24 10:14 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201710241457563.dll
      2017-10-24 10:09 - 2017-10-24 10:09 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171024911435.dll
      2017-10-02 08:58 - 2017-10-02 08:58 - 002163200 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171025819305.dll
      2017-10-28 08:06 - 2017-10-28 08:06 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171028622139.dll
      2017-10-04 09:31 - 2017-10-04 09:31 - 002163200 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171043113370.dll
      2017-10-05 09:53 - 2017-10-05 09:53 - 002163200 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017105532580.dll
      2017-10-06 09:16 - 2017-10-06 09:16 - 002163200 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171061623730.dll
      2017-10-06 23:52 - 2017-10-06 23:52 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171065224505.dll
      2017-10-07 09:54 - 2017-10-07 09:54 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171075447890.dll
      2017-10-09 10:23 - 2017-10-09 10:23 - 002163712 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171092328422.dll
      2017-11-10 11:43 - 2017-11-10 11:43 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201711104321386.dll
      2017-11-01 10:23 - 2017-11-01 10:23 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171112339856.dll
      2017-11-02 00:52 - 2017-11-02 00:52 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171115225368.dll
      2017-11-17 12:11 - 2017-11-17 12:11 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171117111267.dll
      2017-11-18 19:17 - 2017-11-18 19:17 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201711181734927.dll
      2017-11-21 00:46 - 2017-11-21 00:46 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017112046238.dll
      2017-11-23 00:46 - 2017-11-23 00:46 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201711224618694.dll
      2017-11-25 09:12 - 2017-11-25 09:12 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201711251244928.dll
      2017-11-27 10:16 - 2017-11-27 10:16 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201711271659784.dll
      2017-11-06 09:42 - 2017-11-06 09:42 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171164236192.dll
      2017-11-08 10:10 - 2017-11-08 10:10 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017118103184.dll
      2017-11-09 00:50 - 2017-11-09 00:50 - 002172416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171185049290.dll
      2017-12-11 11:10 - 2017-12-11 11:10 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171211109386.dll
      2017-12-16 10:08 - 2017-12-16 10:08 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171216841406.dll
      2017-12-20 10:30 - 2017-12-20 10:30 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171220300768.dll
      2017-12-21 09:59 - 2017-12-21 09:59 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171221599557.dll
      2017-12-25 11:52 - 2017-12-25 11:52 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201712255220697.dll
      2017-12-27 10:46 - 2017-12-27 10:46 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201712274620418.dll
      2017-12-28 10:30 - 2017-12-28 10:30 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20171228304823.dll
      2017-12-30 09:54 - 2017-12-30 09:54 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201712305435151.dll
      2017-12-06 11:04 - 2017-12-06 11:04 - 002230784 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017126459962.dll
      2017-05-16 23:45 - 2017-05-16 23:45 - 001980416 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20175164533688.dll
      2017-05-19 08:44 - 2017-05-19 08:44 - 002008064 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20175194420141.dll
      2017-05-20 06:44 - 2017-05-20 06:44 - 002008064 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20175204459667.dll
      2017-05-24 09:17 - 2017-05-24 09:17 - 002008064 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017524175694.dll
      2017-05-29 08:07 - 2017-05-29 08:07 - 002008064 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20175297735.dll
      2017-06-13 07:40 - 2017-06-13 07:40 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20176134013374.dll
      2017-06-13 23:42 - 2017-06-13 23:42 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017613428192.dll
      2017-06-16 08:07 - 2017-06-16 08:07 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017616745230.dll
      2017-06-17 20:54 - 2017-06-17 20:54 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20176175444375.dll
      2017-06-20 12:39 - 2017-06-20 12:39 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017620392713.dll
      2017-06-22 07:31 - 2017-06-22 07:31 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20176223128826.dll
      2017-06-30 08:43 - 2017-06-30 08:43 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017630439814.dll
      2017-06-05 13:34 - 2017-06-05 13:34 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017653419350.dll
      2017-06-06 23:39 - 2017-06-06 23:39 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017663958437.dll
      2017-06-08 18:49 - 2017-06-08 18:49 - 002011648 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017684938352.dll
      2017-07-10 18:05 - 2017-07-10 18:05 - 001972736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017710548407.dll
      2017-07-14 18:41 - 2017-07-14 18:41 - 001973248 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017714411279.dll
      2017-07-18 23:54 - 2017-07-18 23:54 - 001973248 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20177185419573.dll
      2017-07-21 05:15 - 2017-07-21 05:15 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20177211525566.dll
      2017-07-27 09:55 - 2017-07-27 09:55 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20177275517760.dll
      2017-07-28 04:57 - 2017-07-28 04:57 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20177285736189.dll
      2017-07-03 08:19 - 2017-07-03 08:19 - 001972736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017731946996.dll
      2017-07-04 09:07 - 2017-07-04 09:07 - 001972736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201774732193.dll
      2017-08-01 08:38 - 2017-08-01 08:38 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201781381180.dll
      2017-08-16 05:06 - 2017-08-16 05:06 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017816647150.dll
      2017-08-18 04:56 - 2017-08-18 04:56 - 001999360 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20178185624580.dll
      2017-08-20 07:53 - 2017-08-20 07:53 - 001999360 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20178205358978.dll
      2017-08-23 09:46 - 2017-08-23 09:46 - 001999360 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20178234653479.dll
      2017-08-26 09:05 - 2017-08-26 09:05 - 001999360 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017826549919.dll
      2017-08-31 08:56 - 2017-08-31 08:56 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017831561686.dll
      2017-08-05 07:40 - 2017-08-05 07:40 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017854013409.dll
      2017-08-06 22:28 - 2017-08-06 22:28 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017862837477.dll
      2017-08-09 09:31 - 2017-08-09 09:31 - 001973760 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017893159204.dll
      2017-09-14 08:52 - 2017-09-14 08:52 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20179145250727.dll
      2017-09-20 08:56 - 2017-09-20 08:56 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20179205616444.dll
      2017-09-02 09:04 - 2017-09-02 09:04 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201792421331.dll
      2017-09-26 11:48 - 2017-09-26 11:48 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20179264854497.dll
      2017-09-28 00:05 - 2017-09-28 00:05 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017927529360.dll
      2017-09-07 04:56 - 2017-09-07 04:56 - 001999872 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2017975639972.dll
      2018-01-16 10:06 - 2018-01-16 10:06 - 002329600 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_201811662581.dll
      2018-01-18 00:32 - 2018-01-18 00:32 - 002329600 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20181173214934.dll
      2018-01-19 00:31 - 2018-01-19 00:31 - 002329600 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20181183124471.dll
      2018-01-21 11:17 - 2018-01-21 11:17 - 002329600 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_20181211757955.dll
      2018-01-04 11:38 - 2018-01-04 11:38 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2018143847667.dll
      2018-01-07 08:59 - 2018-01-07 08:59 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2018175955849.dll
      2018-01-09 10:29 - 2018-01-09 10:29 - 002228736 _____ (Opera Software) C:\Users\Dellssd\AppData\Local\Temp\Opera_installer_2018192959337.dll
      2010-06-17 17:09 - 2010-06-17 17:09 - 000149352 ____R (Microsoft Corporation) C:\Users\Dellssd\AppData\Local\Temp\ose00000.exe
      2012-11-10 21:20 - 2012-11-10 21:20 - 000150600 ____R (Microsoft Corporation) C:\Users\Dellssd\AppData\Local\Temp\ose00001.exe
      2008-11-16 13:38 - 2008-11-16 13:38 - 000145184 ____R (Microsoft Corporation) C:\Users\Dellssd\AppData\Local\Temp\ose00002.exe
      2010-06-17 17:09 - 2010-06-17 17:09 - 000149352 ____R (Microsoft Corporation) C:\Users\Dellssd\AppData\Local\Temp\ose00003.exe
      2016-08-16 10:48 - 2016-08-16 10:48 - 000488960 _____ () C:\Users\Dellssd\AppData\Local\Temp\sqlite3.exe
      2017-04-22 19:34 - 2017-04-22 19:34 - 000181544 _____ () C:\Users\Dellssd\AppData\Local\Temp\ubar-yadownloader.exe
      2017-03-15 22:10 - 2017-03-15 22:10 - 014456872 _____ (Microsoft Corporation) C:\Users\Dellssd\AppData\Local\Temp\vc_redist.x86.exe
      2017-08-13 12:15 - 2017-08-13 12:15 - 030950664 _____ () C:\Users\Dellssd\AppData\Local\Temp\vlc-2.2.6-win32.exe
      2017-04-14 13:05 - 2017-04-14 13:05 - 000349280 _____ (Lavasoft) C:\Users\Dellssd\AppData\Local\Temp\WcInstaller.exe
      2017-04-22 21:17 - 2017-03-27 12:10 - 000237920 _____ () C:\Users\Dellssd\AppData\Local\Temp\YandexWorking.exe
      2017-03-30 21:07 - 2017-03-30 21:07 - 061980664 _____ (YANDEX LLC) C:\Users\Dellssd\AppData\Local\Temp\{13BD144E-5CAE-445E-ACAC-B02F6DDCF43E}.exe
      2016-10-20 12:07 - 2016-10-20 12:07 - 044295032 _____ (Google Inc.) C:\Users\Dellssd\AppData\Local\Temp\{486E4B52-BB14-452C-9A04-353419ACD5E8}-54.0.2840.71_chrome_installer.exe
      ==================== Bamital & volsnap ======================
      (There is no automatic fix for files that do not pass verification.)
      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\SysWOW64\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
      LastRegBack: 2018-09-25 14:59
      ==================== End of FRST.txt ============================
      Addition.txt
    • от ivan_dimitrov26
      Добър ден. От няколко дни след зареждане на Windows-а се зарежда Chromuim (подобен на Google Chrome). Предполагам, че е влязъл с инсталиране на друга програма. Сканирах с Аваст, но не намери нищо. Компютърът е с по-стара операционна система, но се използва рядко.
      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06.10.2018
      Ran by Administrator (administrator) on V002-16032D283A (09-10-2018 12:51:00)
      Running from C:\Documents and Settings\Administrator\Desktop
      Loaded Profiles: Administrator (Available Profiles: Administrator)
      Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
      Internet Explorer Version 8 (Default browser: IE)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
      (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
      (Samsung Electronics.) C:\WINDOWS\Samsung\ComSMMgr\SSMMgr.exe
      (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
      (Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
      (NewSoft Technology Corporation) C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe
      (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
      (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
      () C:\WINDOWS\Datecs\FType2K.exe
      (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
      (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
      (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
      (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
      (Google Inc.) C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      (Google Inc.) C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
      (Google Inc.) C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      (Google Inc.) C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      (Google Inc.) C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      ==================== Registry (Whitelisted) ===========================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      HKLM\...\Run: [nwiz] => nwiz.exe /install
      HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)
      HKLM\...\Run: [Samsung Common SM] => C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe [372736 2005-07-03] (Samsung Electronics.)
      HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2005-01-12] (Cyberlink Corp.)
      HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [925696 2005-05-20] (Analog Devices, Inc.)
      HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [716800 2005-09-07] (Analog Devices, Inc.)
      HKLM\...\Run: [Smart Start UP] => C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe [104528 2007-04-27] (NewSoft Technology Corporation)
      HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
      HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-10-09] (AVAST Software)
      HKU\S-1-5-21-2025429265-842925246-1177238915-500\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [27716568 2017-05-05] (Skype Technologies S.A.)
      HKU\S-1-5-21-2025429265-842925246-1177238915-500\...\Run: [MSMSGS] => C:\Program Files\Messenger\MSMSGS.EXE [1507600 2002-10-17] (Microsoft Corporation)
      HKU\S-1-5-21-2025429265-842925246-1177238915-500\...\Run: [Chromium] => c:\documents and settings\administrator\local settings\application data\chromium\application\chrome.exe [666624 2015-07-30] (The Chromium Authors)
      SecurityProviders: msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll
      Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2018-10-06]
      ShortcutTarget: FlexType 2K.lnk -> C:\WINDOWS\Datecs\FType2K.exe ()
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{15E2290D-8571-410D-8D3C-128B92D7A9B4}: [DhcpNameServer] 192.168.0.1
      Internet Explorer:
      ==================
      HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
      HKU\S-1-5-19\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
      HKU\S-1-5-20\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
      HKU\S-1-5-21-2025429265-842925246-1177238915-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
      HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avast.com/AV772/
      HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
      HKU\S-1-5-21-2025429265-842925246-1177238915-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      HKU\S-1-5-21-2025429265-842925246-1177238915-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avast.com/AV772/
      HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <==== ATTENTION
      SearchScopes: HKLM -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKLM -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKU\S-1-5-21-2025429265-842925246-1177238915-500 -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      SearchScopes: HKU\S-1-5-21-2025429265-842925246-1177238915-500 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms}
      BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
      Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
      StartMenuInternet: IEXPLORE.EXE - iexplore.exe
      FireFox:
      ========
      FF DefaultProfile: wykzwtrk.default
      FF ProfilePath: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wykzwtrk.default [2018-10-09]
      FF Homepage: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wykzwtrk.default -> hxxps://www.gbg.bg/
      FF Extension: (Avast Online Security) - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wykzwtrk.default\Extensions\wrc@avast.com.xpi [2018-10-09]
      FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
      FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2018-10-05] [Legacy] [not signed]
      FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
      StartMenuInternet: FIREFOX.EXE - firefox.exe
      Chrome: 
      =======
      CHR Profile: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default [2018-10-09]
      CHR Extension: (Docs) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-04]
      CHR Extension: (Google Drive) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-04]
      CHR Extension: (YouTube) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-04]
      CHR Extension: (Google Docs Offline) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-04]
      CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-04]
      CHR Extension: (Gmail) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-04]
      StartMenuInternet: chrome.exe - C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      StartMenuInternet: Google Chrome - C:\Program Files\Chrome\chrome32_49.0.2623.75\chrome.exe
      ==================== Services (Whitelisted) ====================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6488376 2018-10-09] (AVAST Software)
      R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-10-09] (AVAST Software)
      S2 SkypeUpdate; C:\Program Files\Skype\Updater\Updater.exe [317400 2017-04-05] (Skype Technologies) [File not signed]
      ===================== Drivers (Whitelisted) ======================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R3 AEAudioService; C:\WINDOWS\System32\drivers\AEAudio.sys [127872 2005-03-04] (Andrea Electronics Corporation)
      R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [167552 2018-10-09] (AVAST Software)
      R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriverx.sys [188336 2018-10-09] (AVAST Software)
      R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidshx.sys [164944 2018-10-09] (AVAST Software)
      R0 aswblog; C:\WINDOWS\System32\drivers\aswblogx.sys [284320 2018-10-09] (AVAST Software)
      R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbunivx.sys [57968 2018-10-09] (AVAST Software)
      R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [196008 2018-10-09] (AVAST Software)
      S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [42808 2018-10-09] (AVAST Software)
      R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [135376 2018-10-09] (AVAST Software)
      R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr.sys [70840 2018-10-09] (AVAST Software)
      R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [73264 2018-10-09] (AVAST Software)
      R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [784112 2018-10-09] (AVAST Software)
      R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [396536 2018-10-09] (AVAST Software)
      R3 aswStmXP; C:\WINDOWS\System32\drivers\aswStmXP.sys [206976 2018-10-09] (AVAST Software)
      R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [311328 2018-10-09] (AVAST Software)
      R2 DgiVecp; C:\WINDOWS\System32\Drivers\DgiVecp.sys [41984 2005-03-14] (DeviceGuys, Inc.) [File not signed]
      R0 giveio; C:\WINDOWS\System32\giveio.sys [5248 1996-04-03] () [File not signed]
      R3 HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [907456 2001-08-17] (Conexant)
      R0 mv61xxmm; C:\WINDOWS\system32\Drivers\mv61xxmm.sys [14184 2014-02-12] (Marvell Semiconductor Inc.)
      R0 mv64xxmm; C:\WINDOWS\system32\Drivers\mv64xxmm.sys [5632 2014-02-12] (Marvell Semiconductor Inc.) [File not signed]
      R0 mvxxmm; C:\WINDOWS\system32\Drivers\mvxxmm.sys [14184 2014-02-12] (Marvell Semiconductor Inc.)
      R0 PxHelp20; C:\WINDOWS\System32\DRIVERS\PxHelp20.sys [20016 2003-10-28] (Sonic Solutions) [File not signed]
      R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [393088 2005-08-11] (Sensaura)
      R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [299424 2012-03-27] (Marvell)
      S4 IntelIde; no ImagePath
      U1 WS2IFSL; no ImagePath
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One Month Created files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-10-09 12:51 - 2018-10-09 12:51 - 000012972 _____ C:\Documents and Settings\Administrator\Desktop\FRST.txt
      2018-10-09 12:50 - 2018-10-09 12:51 - 000000000 ____D C:\FRST
      2018-10-09 12:47 - 2018-10-09 12:49 - 001774592 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\FRST.exe
      2018-10-09 08:45 - 2018-10-09 08:45 - 000000000 ____D C:\WINDOWS\CSC
      2018-10-09 08:42 - 2018-10-09 08:42 - 000323288 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
      2018-10-09 08:33 - 2018-10-09 08:33 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\AVAST Software
      2018-10-09 08:32 - 2018-10-09 08:32 - 000001689 _____ C:\Documents and Settings\All Users\Desktop\Avast Free Antivirus.lnk
      2018-10-09 08:32 - 2018-10-09 08:32 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\AVAST Software
      2018-10-09 08:31 - 2018-10-09 12:43 - 000000310 ____H C:\WINDOWS\Tasks\Avast Emergency Update.job
      2018-10-09 08:30 - 2018-10-09 08:43 - 000396536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
      2018-10-09 08:30 - 2018-10-09 08:43 - 000206976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
      2018-10-09 08:30 - 2018-10-09 08:43 - 000135376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
      2018-10-09 08:30 - 2018-10-09 08:43 - 000073264 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
      2018-10-09 08:30 - 2018-10-09 08:42 - 000784112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
      2018-10-09 08:30 - 2018-10-09 08:42 - 000311328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
      2018-10-09 08:30 - 2018-10-09 08:42 - 000196008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
      2018-10-09 08:30 - 2018-10-09 08:42 - 000167552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
      2018-10-09 08:30 - 2018-10-09 08:42 - 000070840 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
      2018-10-09 08:30 - 2018-10-09 08:42 - 000042808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
      2018-10-09 08:30 - 2018-10-09 08:41 - 000284320 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswblogx.sys
      2018-10-09 08:30 - 2018-10-09 08:41 - 000188336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriverx.sys
      2018-10-09 08:30 - 2018-10-09 08:41 - 000164944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidshx.sys
      2018-10-09 08:30 - 2018-10-09 08:41 - 000057968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbunivx.sys
      2018-10-09 08:29 - 2018-10-09 08:29 - 000000000 ____D C:\Program Files\AVAST Software
      2018-10-08 13:13 - 2018-10-08 13:14 - 000000099 _____ C:\WINDOWS\Reimage.ini
      2018-10-08 13:13 - 2018-10-08 13:13 - 000000000 ____D C:\rei
      2018-10-07 09:40 - 2018-10-07 09:40 - 000000043 _____ C:\Documents and Settings\NetworkService\Application Data\WB.CFG
      2018-10-06 14:51 - 2018-10-06 14:51 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\CEF
      2018-10-06 14:48 - 2018-10-09 09:02 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\AVAST Software
      2018-10-06 14:46 - 2018-10-06 14:46 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp
      2018-10-06 14:45 - 2018-10-06 14:45 - 000000000 __HDC C:\WINDOWS\$NtUninstallWdf01009$
      2018-10-06 14:45 - 2008-11-07 18:55 - 000016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsgXP_2k3.dll
      2018-10-06 14:44 - 2018-10-06 14:43 - 001142072 _____ (Microsoft Corporation) C:\WINDOWS\ucrtbase.dll
      2018-10-06 14:42 - 2018-10-06 14:42 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Media Player Classic
      2018-10-06 14:41 - 2018-10-06 14:42 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\chromium
      2018-10-06 14:40 - 2018-10-08 13:58 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Namek
      2018-10-06 14:39 - 2018-10-09 12:32 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\AVAST Software
      2018-10-06 14:39 - 2018-10-06 14:39 - 000000717 _____ C:\Documents and Settings\All Users\Desktop\Crystal Player.lnk
      2018-10-06 14:39 - 2018-10-06 14:39 - 000000000 ____D C:\Program Files\Crystal Player
      2018-10-06 14:39 - 2018-10-06 14:39 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Crystal Player
      2018-10-06 14:39 - 2018-10-06 14:39 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Crystal Player
      2018-10-06 14:37 - 2018-10-06 14:37 - 000000940 _____ C:\Documents and Settings\All Users\Desktop\Media Player Classic.lnk
      2018-10-06 14:37 - 2018-10-06 14:37 - 000000000 ____D C:\Program Files\K-Lite Codec Pack
      2018-10-06 14:37 - 2018-10-06 14:37 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
      2018-10-06 14:37 - 2006-09-13 23:14 - 000593938 _____ C:\WINDOWS\system32\x264vfw.dll
      2018-10-06 14:37 - 2006-07-05 20:02 - 000005120 _____ C:\WINDOWS\system32\ff_vfw.dll
      2018-10-06 14:37 - 2006-07-03 23:40 - 000620180 _____ (DivX, Inc.) C:\WINDOWS\system32\divx.dll
      2018-10-06 14:37 - 2006-06-21 12:42 - 001044480 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\libdivx.dll
      2018-10-06 14:37 - 2006-06-21 12:42 - 000200704 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\WINDOWS\system32\ssldivx.dll
      2018-10-06 14:37 - 2006-05-25 00:47 - 003596288 _____ C:\WINDOWS\system32\qt-dx331.dll
      2018-10-06 14:37 - 2006-05-25 00:46 - 000200704 _____ (DivXNetworks) C:\WINDOWS\system32\dtu100.dll
      2018-10-06 14:37 - 2006-05-13 23:16 - 000118784 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
      2018-10-06 14:37 - 2006-04-20 16:00 - 000856064 _____ C:\WINDOWS\system32\xvidcore.dll
      2018-10-06 14:37 - 2006-04-08 03:13 - 000090112 _____ (DivXNetworks) C:\WINDOWS\system32\dpl100.dll
      2018-10-06 14:37 - 2006-02-27 15:30 - 000217088 _____ C:\WINDOWS\system32\xvidvfw.dll
      2018-10-06 14:37 - 2005-02-24 18:56 - 000000547 _____ C:\WINDOWS\system32\ff_vfw.dll.manifest
      2018-10-06 14:37 - 2003-06-23 02:44 - 001415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMV9VCM.dll
      2018-10-06 14:26 - 2018-10-06 14:26 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Datecs Applications
      2018-10-06 14:20 - 2018-10-06 14:20 - 000000763 _____ C:\Documents and Settings\Administrator\Desktop\BSPlayer.lnk
      2018-10-06 14:20 - 2018-10-06 14:20 - 000000000 ____D C:\Program Files\Webteh
      2018-10-06 14:20 - 2018-10-06 14:20 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\Webteh
      2018-10-06 09:28 - 2018-10-06 14:57 - 000000654 _____ C:\Documents and Settings\Administrator\Desktop\Winamp.lnk
      2018-10-06 09:28 - 2018-10-06 14:57 - 000000000 ____D C:\Program Files\Winamp
      2018-10-06 09:28 - 2018-10-06 09:28 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\Winamp
      2018-10-05 12:45 - 2018-10-05 12:45 - 000053248 _____ C:\WINDOWS\system32\zlib.dll
      2018-10-05 09:04 - 2018-10-05 09:04 - 000001106 _____ C:\Documents and Settings\Administrator\Desktop\Nero Burning ROM.lnk
      2018-10-05 09:02 - 2018-10-05 09:03 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Nero
      2018-10-05 09:02 - 2018-10-05 09:02 - 000000000 ____D C:\Program Files\Common Files\Ahead
      2018-10-05 09:02 - 2004-03-03 20:30 - 000125184 _____ (Ahead Software AG) C:\WINDOWS\system32\Drivers\imagesrv.sys
      2018-10-05 09:02 - 2004-03-03 20:30 - 000005504 _____ (Ahead Software AG) C:\WINDOWS\system32\Drivers\imagedrv.sys
      2018-10-05 09:02 - 2001-07-09 10:50 - 000155648 _____ (Ahead Software Gmbh) C:\WINDOWS\system32\NeroCheck.exe
      2018-10-05 09:02 - 2001-07-06 17:24 - 000283920 _____ (Pegasus Software, LLC) C:\WINDOWS\system32\ImagXpr5.dll
      2018-10-05 09:02 - 2001-07-06 13:41 - 000569344 _____ (Pegasus Software,LLC) C:\WINDOWS\system32\imagr5.dll
      2018-10-05 09:02 - 2001-07-06 11:44 - 000544768 _____ (Pegasus Software, LLC) C:\WINDOWS\system32\imagx5.dll
      2018-10-05 09:02 - 2001-06-26 07:15 - 000038912 _____ (Pegasus Imaging Corp.) C:\WINDOWS\system32\picn20.dll
      2018-10-05 09:02 - 2000-06-26 10:45 - 000106496 _____ (Pegasus Software) C:\WINDOWS\system32\TwnLib20.dll
      2018-10-05 08:52 - 2018-10-05 08:52 - 000000000 ____D C:\Program Files\MSECache
      2018-10-05 08:45 - 2018-10-05 08:45 - 000000000 ____D C:\Documents and Settings\Administrator\My Documents\My Skype Received Files
      2018-10-05 08:45 - 2018-10-05 08:45 - 000000000 ____D C:\Documents and Settings\Administrator\My Documents\My Skype Pictures
      2018-10-05 08:45 - 2018-10-05 08:45 - 000000000 ____D C:\Documents and Settings\Administrator\My Documents\My Skype Content
      2018-10-05 08:36 - 2018-10-05 08:36 - 000154568 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
      2018-10-05 08:35 - 2018-10-05 08:35 - 000000000 ____D C:\WINDOWS\system32\XPSViewer
      2018-10-05 08:34 - 2018-10-05 08:34 - 000000000 ____D C:\Program Files\Reference Assemblies
      2018-10-05 08:34 - 2018-10-05 08:34 - 000000000 ____D C:\Program Files\MSBuild
      2018-10-05 08:34 - 2008-11-07 18:55 - 000026144 _____ (Microsoft Corporation) C:\WINDOWS\system32\spupdsvc.exe
      2018-10-05 08:34 - 2008-07-06 15:06 - 001676288 ____N (Microsoft Corporation) C:\WINDOWS\system32\xpssvcs.dll
      2018-10-05 08:34 - 2008-07-06 15:06 - 001676288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpssvcs.dll
      2018-10-05 08:34 - 2008-07-06 15:06 - 000575488 ____N (Microsoft Corporation) C:\WINDOWS\system32\xpsshhdr.dll
      2018-10-05 08:34 - 2008-07-06 15:06 - 000575488 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpsshhdr.dll
      2018-10-05 08:34 - 2008-07-06 15:06 - 000117760 ____N (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
      2018-10-05 08:34 - 2008-07-06 15:06 - 000089088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll
      2018-10-05 08:34 - 2008-07-06 13:50 - 000597504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
      2018-10-05 08:34 - 2007-11-30 15:39 - 000017272 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll
      2018-10-05 08:33 - 2018-10-05 08:33 - 000000829 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
      2018-10-05 08:33 - 2018-10-05 08:33 - 000000000 ____D C:\Program Files\Messenger
      2018-10-05 08:31 - 2018-10-05 08:31 - 000000000 ____D C:\Program Files\Microsoft .NET Micro Framework
      2018-10-05 08:28 - 2018-10-05 08:28 - 000000853 _____ C:\Documents and Settings\All Users\Desktop\PDFArchitect.lnk
      2018-10-05 08:28 - 2018-10-05 08:28 - 000000706 _____ C:\Documents and Settings\All Users\Desktop\PDFCreator.lnk
      2018-10-05 08:28 - 2018-10-05 08:28 - 000000000 ____D C:\Program Files\PDFCreator
      2018-10-05 08:28 - 2018-10-05 08:28 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\PDFCreator
      2018-10-05 08:28 - 2018-10-05 08:28 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\pdfforge
      2018-10-05 08:28 - 2012-03-05 21:04 - 000054272 _____ (pdfforge GbR) C:\WINDOWS\system32\pdfcmon.dll
      2018-10-05 08:27 - 2018-10-05 08:27 - 000000000 ____D C:\WINDOWS\system32\appmgmt
      2018-10-04 14:04 - 2018-10-04 14:04 - 000000738 _____ C:\Documents and Settings\Administrator\Desktop\Outlook Express.lnk
      2018-10-04 14:03 - 2018-10-04 14:03 - 000002016 _____ C:\Documents and Settings\Administrator\Desktop\Microsoft Office PowerPoint 2003 (2).lnk
      2018-10-04 12:43 - 2018-10-04 12:43 - 000001527 _____ C:\Documents and Settings\Administrator\Desktop\Tour Windows XP.lnk
      2018-10-04 12:37 - 2018-10-04 12:37 - 000000702 _____ C:\Documents and Settings\All Users\Desktop\MozBackup.lnk
      2018-10-04 12:37 - 2018-10-04 12:37 - 000000000 ____D C:\Program Files\MozBackup
      2018-10-04 12:37 - 2018-10-04 12:37 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\MozBackup
      2018-10-04 12:37 - 2018-09-29 12:42 - 000000775 _____ C:\Documents and Settings\Administrator\My Documents\indexfile.txt
      2018-10-04 12:34 - 2018-10-08 08:43 - 000000000 ____D C:\Documents and Settings\Administrator\My Documents\Изтегляния
      2018-10-04 12:30 - 2018-10-04 12:30 - 000000754 _____ C:\Documents and Settings\All Users\Desktop\YoWindow.lnk
      2018-10-04 12:30 - 2018-10-04 12:30 - 000000000 ____D C:\Program Files\YoWindow
      2018-10-04 12:30 - 2018-10-04 12:30 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\YoWindow
      2018-10-04 12:30 - 2018-10-04 12:30 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\YoWindow
      2018-10-04 12:28 - 2018-10-04 12:28 - 000001487 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Explorer (2).lnk
      2018-10-04 12:25 - 2018-10-04 12:25 - 000000784 _____ C:\Documents and Settings\Administrator\Desktop\ESET Online Scanner.lnk
      2018-10-04 12:20 - 2018-10-04 12:20 - 000000000 ____D C:\Program Files\Marvell
      2018-10-04 12:20 - 2012-03-27 17:48 - 000299424 _____ (Marvell) C:\WINDOWS\system32\Drivers\yk51x86.sys
      2018-10-04 08:51 - 2018-10-09 09:05 - 000000000 ____D C:\Documents and Settings\Administrator\My Documents\My Photo
      2018-10-04 08:48 - 2018-10-06 14:25 - 000002497 _____ C:\Documents and Settings\Administrator\Desktop\Microsoft Office Word 2003 (2).lnk
      2018-10-04 08:48 - 2018-10-04 08:48 - 000002044 _____ C:\Documents and Settings\Administrator\Desktop\Microsoft Office Excel 2003 (2).lnk
      2018-10-04 08:46 - 2018-10-09 09:22 - 000000192 _____ C:\WINDOWS\winamp.ini
      2018-10-04 08:46 - 2018-10-04 08:46 - 000001826 _____ C:\Documents and Settings\All Users\Desktop\Presto! Mr. Photo 4.lnk
      2018-10-04 08:46 - 2003-10-29 03:34 - 000462848 ____N (Sonic Solutions) C:\WINDOWS\system32\px.dll
      2018-10-04 08:46 - 2003-10-29 03:33 - 000286720 ____N (Sonic Solutions) C:\WINDOWS\system32\pxwave.dll
      2018-10-04 08:46 - 2003-10-29 03:33 - 000143360 ____N (Sonic Solutions) C:\WINDOWS\system32\pxmas.dll
      2018-10-04 08:46 - 2003-10-28 13:02 - 000053248 ____N C:\WINDOWS\system32\pxhpinst.exe
      2018-10-04 08:46 - 2003-10-28 13:02 - 000020016 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\pxhelp20.sys
      2018-10-04 08:46 - 2003-10-27 12:00 - 000319488 ____N (Sonic Solutions) C:\WINDOWS\system32\pxdrv.dll
      2018-10-04 08:46 - 2003-10-14 12:00 - 000028672 ____N (Sonic Solutions) C:\WINDOWS\system32\vxblock.dll
      2018-10-04 08:45 - 2018-10-04 08:45 - 000000000 ____D C:\Program Files\NewSoft
      2018-10-04 08:45 - 2018-10-04 08:45 - 000000000 ____D C:\Program Files\Common Files\NewSoft
      2018-10-04 08:45 - 2018-10-04 08:45 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\NewSoft
      2018-10-04 08:45 - 2018-10-04 08:45 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\Newsoft
      2018-10-04 08:45 - 2018-10-04 08:45 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\NewSoft
      2018-10-04 08:45 - 1998-06-17 00:00 - 000385100 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVCRTD.DLL
      2018-10-04 08:43 - 2018-10-04 08:43 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Canon
      2018-10-04 08:42 - 2018-10-04 08:42 - 000000000 ___HD C:\CanoScan
      2018-10-04 08:42 - 2018-10-04 08:42 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Canon
      2018-10-04 08:42 - 2013-07-03 01:59 - 000014976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbscan.sys
      2018-10-04 08:42 - 2013-07-03 01:59 - 000014976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbscan.sys
      2018-10-04 08:42 - 2005-06-23 22:17 - 000352256 _____ (CANON INC.) C:\WINDOWS\system32\CNQL1213.DLL
      2018-10-04 08:42 - 2005-02-28 13:20 - 000057344 _____ (CANON INC.) C:\WINDOWS\system32\CNQU110.DLL
      2018-10-04 08:38 - 2018-10-09 12:42 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Skype
      2018-10-04 08:38 - 2018-10-05 13:45 - 000002265 _____ C:\Documents and Settings\All Users\Desktop\Skype.lnk
      2018-10-04 08:38 - 2018-10-04 08:38 - 000000000 ___RD C:\Program Files\Skype
      2018-10-04 08:38 - 2018-10-04 08:38 - 000000000 ____D C:\Program Files\Common Files\Skype
      2018-10-04 08:38 - 2018-10-04 08:38 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
      2018-10-04 08:38 - 2018-10-04 08:38 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
      2018-10-04 08:38 - 2018-10-04 08:38 - 000000000 ____D C:\Documents and Settings\Administrator\Tracing
      2018-10-04 08:37 - 2018-10-08 12:43 - 000170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
      2018-10-04 08:37 - 2018-10-05 13:43 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache
      2018-10-04 08:37 - 2018-10-04 08:37 - 000000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
      2018-10-04 08:37 - 2018-10-04 08:37 - 000000000 ____D C:\Program Files\Malwarebytes Anti-Malware
      2018-10-04 08:37 - 2018-10-04 08:37 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
      2018-10-04 08:37 - 2018-10-04 08:37 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2018-10-04 08:37 - 2016-03-10 14:09 - 000123264 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
      2018-10-04 08:37 - 2016-03-10 14:08 - 000024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
      2018-10-04 08:36 - 2018-10-06 14:51 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\vlc
      2018-10-04 08:36 - 2018-10-04 08:36 - 000000000 ____D C:\Program Files\VideoLAN
      2018-10-04 08:31 - 2018-10-04 08:31 - 000000000 ____D C:\Program Files\FinalWire
      2018-10-04 08:31 - 2018-10-04 08:31 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\FinalWire
      2018-10-03 18:55 - 2018-10-03 18:55 - 000000301 _____ C:\Documents and Settings\Administrator\Desktop\Shortcut to Sounds and Audio Devices.lnk
      2018-10-03 18:47 - 2018-10-05 12:33 - 000000000 ___RD C:\Documents and Settings\Administrator\Desktop\New Briefcase
      2018-10-03 18:35 - 2008-04-13 22:47 - 000083072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wdmaud.sys
      2018-10-03 18:35 - 2008-04-13 22:47 - 000083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wdmaud.sys
      2018-10-03 18:35 - 2008-04-13 22:15 - 000006272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\splitter.sys
      2018-10-03 18:35 - 2008-04-13 22:15 - 000006272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\splitter.sys
      2018-10-03 18:34 - 2018-10-03 18:34 - 000000000 ____D C:\Program Files\Analog Devices
      2018-10-03 18:34 - 2018-10-03 18:34 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\SoundMAX
      2018-10-03 18:34 - 2008-04-14 03:42 - 000129536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ksproxy.ax
      2018-10-03 18:34 - 2008-04-14 03:42 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
      2018-10-03 18:34 - 2008-04-14 03:41 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ksuser.dll
      2018-10-03 18:34 - 2008-04-14 03:41 - 000004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksuser.dll
      2018-10-03 18:34 - 2008-04-13 22:45 - 000060800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sysaudio.sys
      2018-10-03 18:34 - 2008-04-13 22:45 - 000060800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sysaudio.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000172416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kmixer.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kmixer.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000060160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\drmk.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000060160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\drmk.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000056576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\swmidi.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000056576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\swmidi.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000052864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dmusic.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000052864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\DMusic.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000002944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\drmkaud.sys
      2018-10-03 18:34 - 2008-04-13 22:15 - 000002944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\drmkaud.sys
      2018-10-03 18:34 - 2008-04-13 22:09 - 000007552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mskssrv.sys
      2018-10-03 18:34 - 2008-04-13 22:09 - 000007552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MSKSSRV.sys
      2018-10-03 18:34 - 2008-04-13 22:09 - 000005376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mspclock.sys
      2018-10-03 18:34 - 2008-04-13 22:09 - 000005376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MSPCLOCK.sys
      2018-10-03 18:34 - 2008-04-13 22:09 - 000004992 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mspqm.sys
      2018-10-03 18:34 - 2008-04-13 22:09 - 000004992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MSPQM.sys
      2018-10-03 18:34 - 2008-04-13 20:09 - 000142592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\aec.sys
      2018-10-03 18:34 - 2008-04-13 20:09 - 000142592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\aec.sys
      2018-10-03 18:34 - 2008-03-21 11:35 - 000146048 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\portcls.sys
      2018-10-03 18:34 - 2008-03-21 11:35 - 000146048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
      2018-10-03 18:34 - 2005-09-26 16:20 - 000049152 _____ (Analog Devices Inc.) C:\WINDOWS\system32\DSndUp.exe
      2018-10-03 18:34 - 2005-05-04 09:20 - 000053248 ____N (Analog Devices Inc.) C:\WINDOWS\system32\wdmioctl.dll
      2018-10-03 18:34 - 2002-04-17 15:05 - 000045056 ____N (adi) C:\WINDOWS\system32\CleanUp.exe
      2018-10-03 18:34 - 2001-09-11 15:20 - 001285632 ____N (Analog Devices) C:\WINDOWS\system32\SMMedia.dll
      2018-10-03 18:31 - 2018-10-03 18:31 - 000000000 ____D C:\Program Files\Realtek
      2018-10-03 18:31 - 2018-10-03 18:31 - 000000000 ____D C:\Program Files\Intel Desktop Board
      2018-10-03 18:30 - 2018-10-07 09:22 - 000069800 _____ C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2018-10-03 18:30 - 2018-10-03 18:30 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\DriverDR.com
      2018-10-03 14:32 - 2018-10-03 14:22 - 000000804 _____ C:\Documents and Settings\Administrator\Desktop\Windows Media Player.lnk
      2018-10-03 14:29 - 2018-10-03 14:29 - 000001487 _____ C:\Documents and Settings\All Users\Desktop\ICQ6.5.lnk
      2018-10-03 14:29 - 2018-10-03 14:29 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\ICQ6.5
      2018-10-03 14:28 - 2018-10-08 09:25 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\ICQ
      2018-10-03 14:28 - 2018-10-03 14:49 - 000000000 ____D C:\Program Files\ICQ6.5
      2018-10-03 14:28 - 2018-10-03 14:28 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\ICQ
      2018-10-03 14:27 - 2018-10-03 14:27 - 000000000 ____D C:\Program Files\SpeedFan
      2018-10-03 14:27 - 2018-10-03 14:27 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\SpeedFan
      2018-10-03 14:21 - 2018-10-03 14:22 - 000000000 ____D C:\WINDOWS\RegisteredPackages
      2018-10-03 14:19 - 2018-10-06 14:49 - 000000116 _____ C:\WINDOWS\NeroDigital.ini
      2018-10-03 14:19 - 2018-10-03 14:19 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\CyberLink
      2018-10-03 14:19 - 2018-10-03 14:19 - 000000000 ____D C:\Documents and Settings\Administrator\My Documents\CyberLink
      2018-10-03 14:19 - 2018-10-03 14:19 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\CyberLink
      2018-10-03 14:17 - 2018-10-05 09:02 - 000000000 ____D C:\Program Files\Ahead
      2018-10-03 14:16 - 2018-10-03 14:16 - 000001684 _____ C:\Documents and Settings\All Users\Desktop\CyberLink PowerDVD.lnk
      2018-10-03 14:16 - 2018-10-03 14:16 - 000000000 ____D C:\Program Files\CyberLink
      2018-10-03 14:16 - 2018-10-03 14:16 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CyberLink PowerDVD
      2018-10-03 14:14 - 2018-10-03 14:14 - 000000857 _____ C:\Documents and Settings\All Users\Desktop\Wise Disk Cleaner.lnk
      2018-10-03 14:14 - 2018-10-03 14:14 - 000000000 ____D C:\Program Files\Wise
      2018-10-03 14:14 - 2018-10-03 14:14 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Wise Disk Cleaner
      2018-10-03 14:13 - 2018-10-04 12:30 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\YoWindow
      2018-10-03 14:12 - 2018-10-03 14:12 - 000000755 _____ C:\Documents and Settings\All Users\Desktop\Billiards.lnk
      2018-10-03 14:12 - 2018-10-03 14:12 - 000000000 ____D C:\Program Files\IrfanView
      2018-10-03 14:12 - 2018-10-03 14:12 - 000000000 ____D C:\Program Files\ePlaybus.com
      2018-10-03 14:12 - 2018-10-03 14:12 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\ePlaybus.com
      2018-10-03 14:12 - 2018-10-03 14:12 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\IrfanView
      2018-10-03 14:11 - 2018-10-03 14:11 - 000000000 ____D C:\Program Files\ESET
      2018-10-03 14:10 - 2018-10-06 14:26 - 000000000 ____D C:\WINDOWS\Datecs
      2018-10-03 14:10 - 2018-10-03 14:10 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\Datecs Applications
      2018-10-03 14:10 - 2000-06-08 17:00 - 000000398 _____ C:\WINDOWS\system32\kbdus.kbd
      2018-10-03 14:10 - 1997-01-06 11:35 - 000005120 _____ (Datecs Ltd. ) C:\WINDOWS\system32\vga856.fon
      2018-10-03 14:09 - 2018-10-03 14:09 - 000001487 _____ C:\Documents and Settings\Administrator\Desktop\Windows Explorer (2).lnk
      2018-10-03 14:07 - 2018-10-03 13:19 - 000000856 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Copy of Shortcut to chrome.lnk
      2018-10-03 13:19 - 2018-10-03 13:19 - 000000856 _____ C:\Documents and Settings\Administrator\Desktop\Google chrome.lnk
      2018-10-03 11:52 - 2013-08-09 00:55 - 000032384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbccgp.sys
      2018-10-03 11:52 - 2013-08-09 00:55 - 000032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
      2018-10-03 11:52 - 2008-04-14 03:41 - 000021504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidserv.dll
      2018-10-03 11:52 - 2008-04-14 03:41 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidserv.dll
      2018-10-03 11:52 - 2008-04-13 22:15 - 000010368 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidusb.sys
      2018-10-03 11:52 - 2008-04-13 22:15 - 000010368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
      2018-10-03 11:52 - 2008-04-13 22:09 - 000014592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhid.sys
      2018-10-03 11:52 - 2008-04-13 22:09 - 000014592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
      2018-10-03 11:52 - 2001-08-17 11:48 - 000012160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mouhid.sys
      2018-10-03 11:52 - 2001-08-17 11:48 - 000012160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
      2018-10-02 08:49 - 2018-10-02 08:49 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe
      2018-10-02 08:45 - 2018-10-02 08:45 - 000000376 _____ C:\WINDOWS\ODBC.INI
      2018-10-02 08:45 - 2003-06-18 17:31 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdimon.dll
      2018-10-02 08:44 - 2018-10-04 14:03 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
      2018-10-02 08:44 - 2018-10-02 08:44 - 000002002 _____ C:\Documents and Settings\All Users\Start Menu\Open Office Document.lnk
      2018-10-02 08:44 - 2018-10-02 08:44 - 000001992 _____ C:\Documents and Settings\All Users\Start Menu\New Office Document.lnk
      2018-10-02 08:44 - 2018-10-02 08:44 - 000000000 ____D C:\Program Files\Microsoft Works
      2018-10-02 08:44 - 2018-10-02 08:44 - 000000000 ____D C:\Program Files\Microsoft Visual Studio
      2018-10-02 08:44 - 2018-10-02 08:44 - 000000000 ____D C:\Program Files\Microsoft ActiveSync
      2018-10-02 08:44 - 2018-10-02 08:44 - 000000000 ____D C:\Program Files\Common Files\L&H
      2018-10-02 08:44 - 2018-10-02 08:44 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
      2018-10-02 08:43 - 2018-10-05 08:52 - 000000000 ____D C:\Program Files\Microsoft Office
      2018-10-02 08:43 - 2018-10-02 08:44 - 000000000 ____D C:\WINDOWS\SHELLNEW
      2018-10-02 08:42 - 2018-10-02 08:42 - 000000000 __RHD C:\MSOCache
      2018-10-02 08:40 - 2018-10-04 08:45 - 000000000 ___HD C:\Program Files\InstallShield Installation Information
      2018-10-02 08:40 - 2018-10-02 08:40 - 000000129 _____ C:\Documents and Settings\All Users\Desktop\SAMSUNG Dr.Printer.url
      2018-10-02 08:40 - 2018-10-02 08:40 - 000000000 ____D C:\Program Files\Samsung ML-2010 Series
      2018-10-02 08:40 - 2018-10-02 08:40 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Samsung ML-2010 Series
      2018-10-02 08:40 - 2005-04-08 05:29 - 000020622 _____ (Samsung Electronics.) C:\WINDOWS\system32\SUGS2LMK.DLL
      2018-10-02 08:40 - 2005-03-03 14:23 - 000000604 _____ C:\WINDOWS\system32\SUGS2LMK.SMT
      2018-10-02 08:40 - 2005-03-03 13:09 - 000057344 _____ (SEC) C:\WINDOWS\system32\SSCoInst.dll
      2018-10-02 08:40 - 2005-03-03 07:32 - 000151552 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\SSCoInst.exe
      2018-10-02 08:39 - 2018-10-02 08:40 - 000000000 ____D C:\WINDOWS\Samsung
      2018-10-02 08:39 - 2005-03-14 08:01 - 000208896 ____N (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\SSRemove.exe
      2018-10-02 08:39 - 2005-03-14 08:01 - 000041984 ____N (DeviceGuys, Inc.) C:\WINDOWS\system32\Drivers\DGIVECP.SYS
      2018-10-02 08:37 - 2018-10-02 08:37 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Help
      2018-10-02 08:37 - 2018-10-02 08:37 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Help
      2018-10-01 15:58 - 2018-10-01 15:58 - 000000000 _____ C:\WINDOWS\system32\h323log.txt
      2018-10-01 15:56 - 2001-08-17 14:59 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\audstub.sys
      2018-10-01 15:55 - 2008-04-14 06:42 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbui.dll
      2018-10-01 15:55 - 2008-04-14 01:10 - 000057600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\redbook.sys
      2018-10-01 15:55 - 2001-08-17 14:28 - 000907456 _____ (Conexant) C:\WINDOWS\system32\Drivers\HCF_MSFT.sys
      2018-10-01 15:53 - 2018-10-05 08:52 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
      2018-10-01 15:53 - 2018-10-05 08:36 - 000506702 _____ C:\WINDOWS\system32\PerfStringBackup.INI
      2018-10-01 15:53 - 2018-10-01 15:53 - 000004444 _____ C:\WINDOWS\system32\pid.PNF
      2018-10-01 15:53 - 2018-10-01 15:53 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
      2018-10-01 15:53 - 2018-10-01 15:53 - 000000000 ____D C:\Program Files\Common Files\ODBC
      2018-10-01 15:53 - 2018-10-01 13:10 - 000004512 _____ C:\WINDOWS\imsins.BAK
      2018-10-01 15:53 - 2018-10-01 13:06 - 000004161 _____ C:\WINDOWS\ODBCINST.INI
      2018-10-01 15:53 - 2014-02-12 16:56 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\NOTEPAD.EXE
      2018-10-01 15:53 - 2008-04-14 14:00 - 001685606 ____C C:\WINDOWS\system32\dllcache\sam.spd
      2018-10-01 15:53 - 2008-04-14 14:00 - 000774144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\spttseng.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000741376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sapi.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000643717 ____C C:\WINDOWS\system32\dllcache\ltts1033.lxa
      2018-10-01 15:53 - 2008-04-14 14:00 - 000605050 ____C C:\WINDOWS\system32\dllcache\r1033tts.lxa
      2018-10-01 15:53 - 2008-04-14 14:00 - 000176157 ____C (Digi International, Inc.) C:\WINDOWS\system32\dllcache\dgrpsetu.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000176157 _____ (Digi International, Inc.) C:\WINDOWS\system32\dgrpsetu.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000155648 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sapi.cpl
      2018-10-01 15:53 - 2008-04-14 14:00 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system\WINSPOOL.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000126912 _____ (Microsoft Corporation) C:\WINDOWS\system\MSVIDEO.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000109456 _____ (Microsoft Corporation) C:\WINDOWS\system\AVIFILE.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000103424 ____C (Equinox Systems Inc.) C:\WINDOWS\system32\dllcache\eqnclass.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000103424 _____ (Equinox Systems Inc.) C:\WINDOWS\system32\EqnClass.Dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000085020 ____C (Digi International) C:\WINDOWS\system32\dllcache\dgsetup.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000085020 _____ (Digi International) C:\WINDOWS\system32\dgsetup.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system\OLECLI.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\spcommon.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000073376 _____ (Microsoft Corporation) C:\WINDOWS\system\MCIAVI.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000069584 _____ (Microsoft Corporation) C:\WINDOWS\system\AVICAP.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000068768 _____ (Microsoft Corporation) C:\WINDOWS\system\MMSYSTEM.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_869.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_866.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_857.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_855.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_852.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_737.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 _____ C:\WINDOWS\system32\c_869.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 _____ C:\WINDOWS\system32\c_866.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 _____ C:\WINDOWS\system32\c_857.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 _____ C:\WINDOWS\system32\c_855.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 _____ C:\WINDOWS\system32\c_852.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066594 _____ C:\WINDOWS\system32\c_737.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_875.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_28603.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_28599.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_28597.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_28595.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_28594.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20127.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10082.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10081.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10029.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10017.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10010.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10007.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10006.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_875.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_28603.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_28599.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\C_28597.NLS
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\C_28595.NLS
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\C_28594.NLS
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_20127.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10082.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10081.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10029.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10017.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10010.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10007.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000066082 _____ C:\WINDOWS\system32\c_10006.nls
      2018-10-01 15:53 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\spcplui.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000036864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sapisvr.exe
      2018-10-01 15:53 - 2008-04-14 14:00 - 000036656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dosapp.fon
      2018-10-01 15:53 - 2008-04-14 14:00 - 000032816 _____ (Microsoft Corporation) C:\WINDOWS\system\COMMDLG.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system\MCIWAVE.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000025264 _____ (Microsoft Corporation) C:\WINDOWS\system\MCISEQ.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000024661 ____C (Perle Systems Ltd.) C:\WINDOWS\system32\dllcache\spxcoins.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000024661 _____ (Perle Systems Ltd.) C:\WINDOWS\system32\spxcoins.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system\OLESVR.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000022016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0408.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000019968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt040e.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt041f.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0419.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0415.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0405.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000019200 _____ (Microsoft Corporation) C:\WINDOWS\system\TAPI.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000015360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\taskman.exe
      2018-10-01 15:53 - 2008-04-14 14:00 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\TASKMAN.EXE
      2018-10-01 15:53 - 2008-04-14 14:00 - 000013600 _____ (Microsoft Corporation) C:\WINDOWS\system\WFWNET.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\irclass.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\irclass.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000011264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\irenum.sys
      2018-10-01 15:53 - 2008-04-14 14:00 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\irenum.sys
      2018-10-01 15:53 - 2008-04-14 14:00 - 000009936 _____ (Microsoft Corporation) C:\WINDOWS\system\LZEXPAND.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000009008 _____ (Microsoft Corporation) C:\WINDOWS\system\VER.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\batt.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\batt.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000008192 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhept.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000008192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhept.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000007168 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdcz.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdcz.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdycl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdsl1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdsl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdpl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhu.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhela3.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdcz2.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdcz1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdcr.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\KBDAL.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdycl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdsl1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdsl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdpl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhu.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhela3.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdcz2.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdcz1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdcr.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdal.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdtuq.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdtuf.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdlv1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdlv.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhela2.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdgkl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdest.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdtuq.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdtuf.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlv1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlv.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhela2.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdgkl.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdest.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____R (Microsoft Corporation) C:\WINDOWS\system32\kbdmon.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____R (Microsoft Corporation) C:\WINDOWS\system32\kbdkyr.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdycc.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbduzb.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdur.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdtat.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdru1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdru.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdro.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdpl1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdlt1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdlt.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdkaz.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhu1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhe319.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhe220.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdhe.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdbu.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdblr.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdazel.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdaze.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdycc.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbduzb.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdur.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdtat.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdru1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdru.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdro.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdpl1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdmon.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlt1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlt.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdkyr.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdkaz.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhu1.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhe319.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhe220.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdhe.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdbu.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdblr.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdazel.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdaze.dll
      2018-10-01 15:53 - 2008-04-14 14:00 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\system\SHELL.DLL
      2018-10-01 15:53 - 2008-04-14 14:00 - 000004048 _____ (Microsoft Corporation) C:\WINDOWS\system\TIMER.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000003360 _____ (Microsoft Corporation) C:\WINDOWS\system\SYSTEM.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000002577 ____N C:\WINDOWS\system32\CONFIG.TMP
      2018-10-01 15:53 - 2008-04-14 14:00 - 000002176 _____ (Microsoft Corporation) C:\WINDOWS\system\VGA.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000002032 _____ (Microsoft Corporation) C:\WINDOWS\system\MOUSE.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000002000 _____ (Microsoft Corporation) C:\WINDOWS\system\KEYBOARD.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000001744 _____ (Microsoft Corporation) C:\WINDOWS\system\SOUND.DRV
      2018-10-01 15:53 - 2008-04-14 14:00 - 000001688 _____ C:\WINDOWS\system32\AUTOEXEC.NT
      2018-10-01 15:53 - 2008-04-14 14:00 - 000001152 _____ (Microsoft Corporation) C:\WINDOWS\system\MMTASK.TSK
      2018-10-01 15:53 - 2008-04-14 14:00 - 000000888 ____C C:\WINDOWS\system32\dllcache\sam.sdf
      2018-10-01 15:53 - 2008-04-14 06:42 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\storprop.dll
      2018-10-01 15:52 - 2018-10-01 15:52 - 000000000 ____D C:\Documents and Settings\Default User\Local Settings\Temp
      2018-10-01 15:52 - 2018-10-01 13:11 - 000733603 _____ C:\WINDOWS\setuplog.txt
      2018-10-01 15:52 - 2009-01-09 21:19 - 001089593 ____C C:\WINDOWS\system32\dllcache\NTPRINT.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 002144487 ____C C:\WINDOWS\system32\dllcache\NT5.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 001296669 ____C C:\WINDOWS\system32\dllcache\SP3.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000797189 ____C C:\WINDOWS\system32\dllcache\NT5IIS.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000522220 ____C C:\WINDOWS\system32\dllcache\NT5INF.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000399645 ____C C:\WINDOWS\system32\dllcache\MAPIMIG.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000144484 ____C C:\WINDOWS\system32\dllcache\netfx.cat
      2018-10-01 15:52 - 2008-04-14 14:00 - 000112918 ____C C:\WINDOWS\system32\dllcache\tabletpc.cat
      2018-10-01 15:52 - 2008-04-14 14:00 - 000037484 ____C C:\WINDOWS\system32\dllcache\MW770.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000034747 ____C C:\WINDOWS\system32\dllcache\mediactr.cat
      2018-10-01 15:52 - 2008-04-14 14:00 - 000034063 ____C C:\WINDOWS\system32\dllcache\FP4.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000016535 ____C C:\WINDOWS\system32\dllcache\IMS.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000013472 ____C C:\WINDOWS\system32\dllcache\HPCRDP.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000010027 ____C C:\WINDOWS\system32\dllcache\MSTSWEB.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000008574 ____C C:\WINDOWS\system32\dllcache\IASNT4.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000007382 ____C C:\WINDOWS\system32\dllcache\OEMBIOS.CAT
      2018-10-01 15:52 - 2008-04-14 14:00 - 000007334 ____C C:\WINDOWS\system32\dllcache\wmerrenu.cat
      2018-10-01 15:51 - 2018-10-09 08:47 - 000000211 ___SH C:\boot.ini
      2018-10-01 15:51 - 2018-10-06 14:27 - 000272576 _____ C:\WINDOWS\system32\FNTCACHE.DAT
      2018-10-01 15:51 - 2018-10-03 14:17 - 000000000 ___HD C:\Documents and Settings\Default User
      2018-10-01 15:51 - 2018-10-01 15:51 - 001138688 _____ C:\WINDOWS\system32\config\software.sav
      2018-10-01 15:51 - 2018-10-01 15:51 - 000913408 _____ C:\WINDOWS\system32\config\system.sav
      2018-10-01 15:51 - 2018-10-01 15:51 - 000094208 _____ C:\WINDOWS\system32\config\default.sav
      2018-10-01 15:51 - 2018-10-01 13:12 - 000000000 ____D C:\Documents and Settings
      2018-10-01 15:51 - 2018-10-01 13:05 - 000000000 ____D C:\Documents and Settings\All Users
      2018-10-01 15:50 - 2018-10-01 15:51 - 000262144 _____ C:\WINDOWS\system32\config\userdiff
      2018-10-01 15:43 - 2018-10-09 08:43 - 000000000 ___HD C:\WINDOWS\inf
      2018-10-01 15:43 - 2018-10-08 09:27 - 000000000 ____D C:\WINDOWS\Driver Cache
      2018-10-01 15:43 - 2018-10-06 14:26 - 000000000 RSHDC C:\WINDOWS\system32\dllcache
      2018-10-01 15:43 - 2018-10-05 08:55 - 000000000 ____D C:\WINDOWS\system32\Macromed
      2018-10-01 15:43 - 2018-10-05 08:34 - 000000000 ____D C:\WINDOWS\system32\spool
      2018-10-01 15:43 - 2018-10-04 08:42 - 000000000 ____D C:\WINDOWS\Media
      2018-10-01 15:43 - 2018-10-03 18:34 - 000000000 ____D C:\WINDOWS\system
      2018-10-01 15:43 - 2018-10-03 14:21 - 000000000 ____D C:\WINDOWS\security
      2018-10-01 15:43 - 2018-10-03 14:21 - 000000000 ____D C:\WINDOWS\Help
      2018-10-01 15:43 - 2018-10-02 08:43 - 000000000 ____D C:\WINDOWS\pchealth
      2018-10-01 15:43 - 2018-10-01 15:51 - 000000000 ____D C:\WINDOWS\system32\usmt
      2018-10-01 15:43 - 2018-10-01 15:51 - 000000000 ____D C:\WINDOWS\system32\scripting
      2018-10-01 15:43 - 2018-10-01 15:51 - 000000000 ____D C:\WINDOWS\Network Diagnostic
      2018-10-01 15:43 - 2018-10-01 15:51 - 000000000 ____D C:\WINDOWS\L2Schemas
      2018-10-01 15:43 - 2018-10-01 15:50 - 000000000 ___SD C:\WINDOWS\Offline Web Pages
      2018-10-01 15:43 - 2018-10-01 15:50 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
      2018-10-01 15:43 - 2018-10-01 15:49 - 000000000 ____D C:\WINDOWS\system32\Setup
      2018-10-01 15:43 - 2018-10-01 15:49 - 000000000 ____D C:\WINDOWS\system32\npp
      2018-10-01 15:43 - 2018-10-01 15:49 - 000000000 ____D C:\WINDOWS\PeerNet
      2018-10-01 15:43 - 2018-10-01 15:49 - 000000000 ____D C:\WINDOWS\mui
      2018-10-01 15:43 - 2018-10-01 15:49 - 000000000 ____D C:\WINDOWS\msagent
      2018-10-01 15:43 - 2018-10-01 15:46 - 000000000 ____D C:\WINDOWS\system32\ras
      2018-10-01 15:43 - 2018-10-01 15:45 - 000000000 ____D C:\WINDOWS\system32\icsxml
      2018-10-01 15:43 - 2018-10-01 15:44 - 000000000 ____D C:\WINDOWS\system32\1033
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\wins
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\ShellExt
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\PreInstall
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\mui
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\inetsrv
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\IME
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\export
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\Drivers\disdn
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\dhcp
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\3com_dmi
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\3076
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\2052
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1054
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1042
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1041
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1037
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1031
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1028
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\system32\1025
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\Resources
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\Provisioning
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\msapps
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\java
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\Connection Wizard
      2018-10-01 15:43 - 2018-10-01 15:43 - 000000000 ____D C:\WINDOWS\addins
      2018-10-01 15:43 - 2018-10-01 13:06 - 000000000 ____D C:\WINDOWS\repair
      2018-10-01 15:43 - 2018-10-01 13:06 - 000000000 ____D C:\WINDOWS\ime
      2018-10-01 15:43 - 2018-10-01 13:05 - 000000000 ___RD C:\WINDOWS\Web
      2018-10-01 15:43 - 2018-10-01 13:05 - 000000000 ____D C:\WINDOWS\system32\ias
      2018-10-01 15:43 - 2018-10-01 13:03 - 000000000 ____D C:\WINDOWS\system32\oobe
      2018-10-01 15:43 - 2018-10-01 13:00 - 000000000 ____D C:\WINDOWS\Cursors
      2018-10-01 13:56 - 2018-10-02 08:49 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Adobe
      2018-10-01 13:56 - 2018-10-01 13:56 - 000001804 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
      2018-10-01 13:56 - 2018-10-01 13:56 - 000001729 _____ C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
      2018-10-01 13:56 - 2018-10-01 13:56 - 000000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
      2018-10-01 13:56 - 2018-10-01 13:56 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Macromedia
      2018-10-01 13:55 - 2018-10-01 13:56 - 000000000 ____D C:\Program Files\Common Files\Adobe
      2018-10-01 13:55 - 2018-10-01 13:55 - 000000694 _____ C:\Documents and Settings\Administrator\Desktop\BitComet.lnk
      2018-10-01 13:55 - 2018-10-01 13:55 - 000000000 ____D C:\Program Files\BitComet
      2018-10-01 13:55 - 2018-10-01 13:55 - 000000000 ____D C:\Program Files\Adobe
      2018-10-01 13:55 - 2018-10-01 13:55 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\BitComet
      2018-10-01 13:55 - 2018-10-01 13:55 - 000000000 _____ C:\WINDOWS\PROTOCOL.INI
      2018-10-01 13:54 - 2018-10-01 13:54 - 000000776 _____ C:\Documents and Settings\All Users\Start Menu\Programs\SA Dictionary.lnk
      2018-10-01 13:54 - 2018-10-01 13:54 - 000000770 _____ C:\Documents and Settings\All Users\Desktop\SA Dictionary.lnk
      2018-10-01 13:54 - 2018-10-01 13:54 - 000000000 ____D C:\Program Files\SA Dictionary 2004 Datacenter
      2018-10-01 13:54 - 1999-03-23 09:12 - 000299520 _____ (InstallShield Corporation, Inc.) C:\WINDOWS\uninst.exe
      2018-10-01 13:53 - 2018-10-03 14:11 - 000000000 ____D C:\Program Files\CPUID
      2018-10-01 13:53 - 2018-10-03 14:11 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CPUID
      2018-10-01 13:53 - 2018-10-01 13:53 - 000000000 ____D C:\Documents and Settings\Administrator\WINDOWS
      2018-10-01 13:52 - 2018-10-01 13:52 - 000000000 ____D C:\Program Files\WinRAR
      2018-10-01 13:52 - 2018-10-01 13:52 - 000000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
      2018-10-01 13:52 - 2018-10-01 13:52 - 000000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\WinRAR
      2018-10-01 13:50 - 2018-10-01 13:50 - 000000000 ____D C:\Program Files\Datecs
      2018-10-01 13:50 - 2002-04-23 00:17 - 000045056 _____ C:\WINDOWS\system32\newdll.dll
      2018-10-01 13:50 - 2000-11-17 08:47 - 000008992 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdbphz.dLL
      2018-10-01 13:50 - 2000-11-15 01:52 - 000006416 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdbds.Dll
      2018-10-01 13:50 - 1999-12-07 09:00 - 000006416 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdbp.Dll
      2018-10-01 13:50 - 1999-11-18 05:04 - 000007440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Kbddll.dll
      2018-10-01 13:50 - 1999-11-11 13:47 - 000006928 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdhebx.Dll
      2018-10-01 13:50 - 1999-11-11 13:47 - 000006416 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdinori.Dll
      2018-10-01 13:50 - 1999-11-11 13:47 - 000006416 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdinasa.Dll
      2018-10-01 13:50 - 1997-04-03 21:00 - 000066594 _____ C:\WINDOWS\system32\C_856.nls
      2018-10-01 13:50 - 1997-04-03 21:00 - 000008992 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDBPH.dLL
      2018-10-01 13:41 - 2018-10-09 12:42 - 000088566 _____ C:\WINDOWS\system32\nvapps.xml
      2018-10-01 13:41 - 2018-10-01 13:43 - 000000000 ____D C:\WINDOWS\nview
      2018-10-01 13:41 - 2006-10-22 15:06 - 000208896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NVUNINST.EXE
      2018-10-01 13:41 - 2006-10-22 12:22 - 000208896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvudisp.exe
      2018-10-01 13:41 - 2006-10-22 12:22 - 000017056 _____ C:\WINDOWS\system32\nvdisp.nvu
      2018-10-01 13:40 - 2018-10-01 13:40 - 000000000 ____D C:\NVIDIA
      2018-10-01 13:39 - 2018-10-01 13:39 - 000000000 ____D C:\WINDOWS\pss
      2018-10-01 13:38 - 2015-08-16 17:29 - 042567136 _____ (NVIDIA Corporation ) C:\Documents and Settings\Administrator\Desktop\93.71_forceware_winxp2k_english_whql.exe
      2018-10-01 13:37 - 2018-10-04 13:35 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
      2018-10-01 13:37 - 2018-10-04 12:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
      2018-10-01 13:37 - 2018-10-01 13:37 - 000000730 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
      2018-10-01 13:37 - 2018-10-01 13:37 - 000000724 _____ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
      2018-10-01 13:37 - 2018-10-01 13:37 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
      2018-10-01 13:37 - 2018-10-01 13:37 - 000000000 ____D C:\Documents and Settings\Administrator\Application Data\Mozilla
      2018-10-01 13:35 - 2018-10-01 13:35 - 000000000 ____D C:\Program Files\Chrome
      2018-10-01 13:35 - 2018-10-01 13:35 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
      2018-10-01 13:34 - 2008-04-13 22:15 - 000026368 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbstor.sys
      2018-10-01 13:34 - 2008-04-13 22:15 - 000026368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
      2018-10-01 13:33 - 2018-10-07 09:14 - 000006144 _____ C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      2018-10-01 13:19 - 2018-10-01 13:19 - 000000000 __SHD C:\Documents and Settings\Administrator\PrivacIE
      2018-10-01 13:14 - 2018-10-03 14:33 - 000000803 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk
      2018-10-01 13:14 - 2008-04-14 14:00 - 000026991 ____C C:\WINDOWS\system32\dllcache\msn7.cat
      2018-10-01 13:14 - 2008-04-14 14:00 - 000014433 ____C C:\WINDOWS\system32\dllcache\msn9.cat
      2018-10-01 13:14 - 2008-04-14 14:00 - 000012363 ____C C:\WINDOWS\system32\dllcache\MSMSGS.CAT
      2018-10-01 13:13 - 2018-10-01 13:19 - 000000738 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Outlook Express.lnk
      2018-10-01 13:12 - 2018-10-09 12:53 - 000000000 ____D C:\Documents and Settings\Administrator\Local Settings\Temp
      2018-10-01 13:12 - 2018-10-09 12:41 - 000000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
      2018-10-01 13:12 - 2018-10-09 12:41 - 000000000 ____D C:\Documents and Settings\Administrator
      2018-10-01 13:12 - 2018-10-03 14:22 - 000000792 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
      2018-10-01 13:12 - 2018-10-01 13:06 - 000001599 _____ C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
      2018-10-01 13:12 - 2018-10-01 13:06 - 000000000 __SHD C:\Documents and Settings\Administrator\IETldCache
      2018-10-01 13:11 - 2018-10-09 12:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
      2018-10-01 13:11 - 2018-10-09 12:41 - 000017208 _____ C:\WINDOWS\SchedLgU.Txt
      2018-10-01 13:11 - 2018-10-01 13:11 - 000000020 ___SH C:\Documents and Settings\LocalService\ntuser.ini
      2018-10-01 13:11 - 2018-10-01 13:11 - 000000000 __SHD C:\Documents and Settings\LocalService
      2018-10-01 13:11 - 2018-10-01 13:11 - 000000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
      2018-10-01 13:11 - 2018-10-01 13:06 - 000000000 __SHD C:\Documents and Settings\LocalService\IETldCache
      2018-10-01 13:10 - 2018-10-01 13:10 - 000008192 _____ C:\WINDOWS\REGLOCS.OLD
      2018-10-01 13:10 - 2018-10-01 13:10 - 000000020 ___SH C:\Documents and Settings\NetworkService\ntuser.ini
      2018-10-01 13:10 - 2018-10-01 13:10 - 000000000 __SHD C:\Documents and Settings\NetworkService
      2018-10-01 13:10 - 2018-10-01 13:10 - 000000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
      2018-10-01 13:10 - 2018-10-01 13:06 - 000000000 __SHD C:\Documents and Settings\NetworkService\IETldCache
      2018-10-01 13:09 - 2014-02-12 16:56 - 000456704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpsvc.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000571392 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlgnt.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000455168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintsetp.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000426041 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\voicepad.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000364032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w3svc.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000358400 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpincl.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000259072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpcl.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000236544 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smi2smir.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000221696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\seo.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000188416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpsmir.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000185344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\thawbrkr.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winzm.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winsp.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winpy.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000143422 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\softkey.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000103424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\uihelper.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000101376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srusbusd.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000086073 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\voicesub.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000079872 ____C (Ricoh Co., Ltd.) C:\WINDOWS\system32\dllcache\rwia330.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000079872 ____C (Ricoh Co., Ltd.) C:\WINDOWS\system32\dllcache\rwia001.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000079360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winar30.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000076800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wam51.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000076288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\uniime.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000073728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w3ext.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000072704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wingb.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000065536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winime.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000065024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\unicdime.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000053248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wamreg51.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000048256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w32.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000046592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\svcext51.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000046592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sspifilt.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000045056 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ssinc51.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000044032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlphr.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000041600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\weitekp9.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000039936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpthrd.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000038912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm9aw.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tools.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000033280 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmp.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smb6w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sma3w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000031232 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\weitekp9.sys
      2018-10-01 13:09 - 2008-04-14 14:00 - 000030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm87w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm81w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000029184 ____C (Ricoh Co., Ltd.) C:\WINDOWS\system32\dllcache\rw330ext.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000029184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm8cw.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000028288 ____C C:\WINDOWS\system32\dllcache\xjis.nls
      2018-10-01 13:09 - 2008-04-14 14:00 - 000027648 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rw001ext.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm93w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm92w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm90w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm8dw.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm8aw.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm89w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\romanime.ime
      2018-10-01 13:09 - 2008-04-14 14:00 - 000025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm59w.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000021896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdipx.sys
      2018-10-01 13:09 - 2008-04-14 14:00 - 000019464 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdspx.sys
      2018-10-01 13:09 - 2008-04-14 14:00 - 000018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\simptcp.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000016896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\status.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smierrsm.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000014848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\register.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tsprof.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000013192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdasync.sys
      2018-10-01 13:09 - 2008-04-14 14:00 - 000010752 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpapi.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tmigrate.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpstup.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000009728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rwnh.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wamps51.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmptrap.exe
      2018-10-01 13:09 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpmib.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w3svapi.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smimsgif.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smierrsy.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000004608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w3ctrs51.dll
      2018-10-01 13:09 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rpcref.dll
      2018-10-01 13:09 - 2001-08-17 22:36 - 000057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
      2018-10-01 13:09 - 2001-08-17 22:36 - 000026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_seos.dll
      2018-10-01 13:09 - 2001-08-17 22:36 - 000023040 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_regtrace.exe
      2018-10-01 13:09 - 2001-08-17 22:36 - 000012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_smtpctrs.dll
      2018-10-01 13:09 - 2001-08-17 22:36 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
      2018-10-01 13:08 - 2014-02-12 16:55 - 000257024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\infocomm.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 010129408 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hwxkor.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 001875968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msir3jp.lex
      2018-10-01 13:08 - 2008-04-14 14:00 - 001158818 ____C C:\WINDOWS\system32\dllcache\korwbrkr.lex
      2018-10-01 13:08 - 2008-04-14 14:00 - 000811064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjp81k.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000716856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpcus.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000482304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlgnt.ime
      2018-10-01 13:08 - 2008-04-14 14:00 - 000471102 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imskdic.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000368696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpcic.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000340023 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjp81.ime
      2018-10-01 13:08 - 2008-04-14 14:00 - 000315455 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imskf.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000311359 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsv.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000307257 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000274489 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputyc.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000262200 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputy.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000233527 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjprw.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000229439 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\multibox.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000208952 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpmig.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000196665 ____C C:\WINDOWS\system32\dllcache\imjpinst.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000175104 ____C C:\WINDOWS\system32\dllcache\pintlcsa.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000155705 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdsvr.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000145408 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iische51.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000134339 ____C C:\WINDOWS\system32\dllcache\imekr.lex
      2018-10-01 13:08 - 2008-04-14 14:00 - 000131584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmxviceo.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000119808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtstocom.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000106496 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrcic.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000102463 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsm.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000102456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imlang.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000098304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msir3jp.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000094720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekr61.ime
      2018-10-01 13:08 - 2008-04-14 14:00 - 000092416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mga.sys
      2018-10-01 13:08 - 2008-04-14 14:00 - 000092032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mga.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000086016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmbx.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000085504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\metada51.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000083748 ____C C:\WINDOWS\system32\dllcache\prcp.nls
      2018-10-01 13:08 - 2008-04-14 14:00 - 000083748 ____C C:\WINDOWS\system32\dllcache\prc.nls
      2018-10-01 13:08 - 2008-04-14 14:00 - 000081976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000079872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iislog51.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000079360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\phon.ime
      2018-10-01 13:08 - 2008-04-14 14:00 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\quick.ime
      2018-10-01 13:08 - 2008-04-14 14:00 - 000070656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\korwbrkr.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000070144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlphr.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000067584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmigrate.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000060928 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisclex4.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000059904 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imkrinst.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000059392 ____C C:\WINDOWS\system32\dllcache\imscinst.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000057398 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdadm.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000053760 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlcsd.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000053248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nextlink.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000047066 ____C C:\WINDOWS\system32\dllcache\ksc.nls
      2018-10-01 13:08 - 2008-04-14 14:00 - 000045109 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpuex.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000044544 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nsepm.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000044032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmig.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000040960 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msiregmv.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000037888 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\md5filt.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000036927 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs411.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000035328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iprip.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lmmib2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pagecnt.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mdsync.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iscomlog.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisadmin.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000022528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lpdsvc.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000022016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\logscrpt.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\permchk.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000020736 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ramdisk.sys
      2018-10-01 13:08 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iiscrmap.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lprmon.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000018432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jupiw.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\quser.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs404.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000015360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs804.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000015360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetin51.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs412.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lonsint.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000011264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmxmcro.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000009728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\query.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000009216 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdnecat.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnecat.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iwrps.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\infoctrs.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007680 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdnecnt.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pwsdata.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\migregdb.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnecnt.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007168 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdnec95.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007168 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdibm02.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnec95.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdibm02.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isapips.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisfecnv.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006656 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdlk41a.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlk41a.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iissync.exe
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdth3.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdth2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdlk41j.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdinpun.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdax2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbd106n.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbd101a.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbd101.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmxgl.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth3.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlk41j.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinpun.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdax2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd106n.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101a.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdvntc.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdusa.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdth1.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdth0.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdintel.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdintam.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdinmar.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdinkan.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdinhin.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdinguj.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdindev.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdheb.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdfa.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbda3.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbda2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbda1.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdvntc.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdusa.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdurdu.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth1.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth0.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdsyr2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdsyr1.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdintel.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdintam.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinmar.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinkan.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinhin.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinguj.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdindev.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdheb.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdfa.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbddiv2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbddiv1.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbda3.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbda2.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbda1.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005120 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdgeo.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005120 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdarmw.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005120 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdarme.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdgeo.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdarmw.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000005120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdarme.dll
      2018-10-01 13:08 - 2008-04-14 14:00 - 000003584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iismui.dll
      2018-10-01 13:08 - 2001-08-17 22:36 - 000065536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_mailmsg.dll
      2018-10-01 13:08 - 2001-08-17 22:36 - 000038912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
      2018-10-01 13:07 - 2014-02-12 16:55 - 000369664 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\asp51.dll
      2018-10-01 13:07 - 2014-02-12 16:55 - 000268288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\httpext.dll
      2018-10-01 13:07 - 2014-02-12 16:55 - 000229888 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscover.exe
      2018-10-01 13:07 - 2014-02-12 16:55 - 000126464 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftpsv251.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 013463552 ____C C:\WINDOWS\system32\dllcache\hwxjpn.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 010096640 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hwxcht.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 002134528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpsnap.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 001677824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chsbrkr.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000838144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtbrkr.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000562176 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsst.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000514587 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\edb500.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000480256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintsetp.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000451584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsapi.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000400384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsxp32.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000397312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxstiff.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000331264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\aqueue.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000285184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscomex.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000267776 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxssvc.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000246272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxst30.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000218112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_g18030.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000198656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintime.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000195618 ____C C:\WINDOWS\system32\dllcache\c_10002.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000192512 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxswzrd.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000189986 ____C C:\WINDOWS\system32\dllcache\c_1361.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000189440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpadm.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000187938 ____C C:\WINDOWS\system32\dllcache\c_20005.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000186402 ____C C:\WINDOWS\system32\dllcache\c_20001.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000185378 ____C C:\WINDOWS\system32\dllcache\c_20003.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000180770 ____C C:\WINDOWS\system32\dllcache\c_20932.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000180258 ____C C:\WINDOWS\system32\dllcache\c_20004.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000180258 ____C C:\WINDOWS\system32\dllcache\c_20000.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000177698 ____C C:\WINDOWS\system32\dllcache\c_20949.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000177698 ____C C:\WINDOWS\system32\dllcache\c_10003.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000173602 ____C C:\WINDOWS\system32\dllcache\c_20936.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000173602 ____C C:\WINDOWS\system32\dllcache\c_20002.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000173602 ____C C:\WINDOWS\system32\dllcache\c_10008.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000173568 ____C C:\WINDOWS\system32\dllcache\chtskf.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000162850 ____C C:\WINDOWS\system32\dllcache\c_10001.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000154112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsui.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000142848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsclnt.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000132608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsclntr.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000111104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscfgwz.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000108827 ____C C:\WINDOWS\system32\dllcache\hanja.lex
      2018-10-01 13:07 - 2008-04-14 14:00 - 000108544 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\appconf.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000101888 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\evntagnt.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000097792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtmbx.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000092160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\evntwin.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000082172 ____C C:\WINDOWS\system32\dllcache\bopomofo.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000078848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dayi.ime
      2018-10-01 13:07 - 2008-04-14 14:00 - 000078336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chajei.ime
      2018-10-01 13:07 - 2008-04-14 14:00 - 000072192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscom.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066728 ____C C:\WINDOWS\system32\dllcache\big5.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_864.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_862.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_858.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066594 ____C C:\WINDOWS\system32\dllcache\c_720.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_870.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_708.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_28596.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_21027.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_21025.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20924.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20880.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20871.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20838.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20833.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20424.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20423.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20420.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20297.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20290.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20285.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20284.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20280.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20278.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20277.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20273.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20269.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20108.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20107.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20106.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_20105.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1149.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1148.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1147.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1146.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1145.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1144.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1143.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1142.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1141.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1140.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_1047.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10021.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10005.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000066082 ____C C:\WINDOWS\system32\dllcache\c_10004.nls
      2018-10-01 13:07 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\httpod51.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000057856 ____C (SEIKO EPSON CORP.) C:\WINDOWS\system32\dllcache\esuimgd.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000057399 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cplexe.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000056320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\convlog.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000056320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtskdic.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsevent.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000054528 ____C (Philips Semiconductors GmbH) C:\WINDOWS\system32\dllcache\cap7146.sys
      2018-10-01 13:07 - 2008-04-14 14:00 - 000049664 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\adrot.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000045568 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\browscap.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000045056 ____C (SEIKO EPSON CORP.) C:\WINDOWS\system32\dllcache\esunid.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000042496 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\davcdata.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000039936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hostmib.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000036864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hanjadic.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\controt.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000032256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\gzip.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000031744 ____C (SEIKO EPSON CORP.) C:\WINDOWS\system32\dllcache\esucmd.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsroute.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000029696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admexs.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000029184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\asptxn.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsdrv.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000025856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\et4000.sys
      2018-10-01 13:07 - 2008-04-14 14:00 - 000024064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\evntcmd.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000024064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\compfilt.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000023552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsmon.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000023552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsext32.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000021504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintlgnt.ime
      2018-10-01 13:07 - 2008-04-14 14:00 - 000020480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\counters.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0804.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0412.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0411.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt040d.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0404.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0401.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cprofile.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chgport.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000014848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\flattemp.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\exstrace.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chgusr.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chglogon.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000011264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxssend.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000010752 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_iscii.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\aspperf.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000009728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\change.exe
      2018-10-01 13:07 - 2008-04-14 14:00 - 000009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\authfilt.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsperf.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000008192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\staxmem.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000008192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\httpmb51.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftpctrs2.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wamregps.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\f3ahvoas.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsres.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_is2022.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftpmib.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftlx041e.dll
      2018-10-01 13:07 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admxprox.dll
      2018-10-01 13:07 - 2003-03-24 16:52 - 000618605 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4autl.dll
      2018-10-01 13:07 - 2003-03-24 16:52 - 000094208 ____C C:\WINDOWS\system32\dllcache\fpencode.dll
      2018-10-01 13:07 - 2003-03-24 16:52 - 000032827 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tcptest.exe
      2018-10-01 13:07 - 2003-03-24 16:52 - 000024632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpadmcgi.exe
      2018-10-01 13:07 - 2003-03-24 16:52 - 000020541 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpadmdll.dll
      2018-10-01 13:07 - 2003-03-24 16:52 - 000020536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shtml.dll
      2018-10-01 13:07 - 2003-03-24 16:52 - 000016437 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shtml.exe
      2018-10-01 13:07 - 2003-03-24 16:52 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tcptsat.dll
      2018-10-01 13:07 - 2001-08-17 22:36 - 000045056 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_aqadmin.dll
      2018-10-01 13:07 - 2001-08-17 22:36 - 000043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_fcachdll.dll
      2018-10-01 13:07 - 2001-08-17 22:36 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
      2018-10-01 13:06 - 2018-10-03 14:31 - 000001607 _____ C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
      2018-10-01 13:06 - 2018-10-03 14:22 - 000023392 _____ C:\WINDOWS\system32\nscompat.tlb
      2018-10-01 13:06 - 2018-10-03 14:22 - 000016832 _____ C:\WINDOWS\system32\amcompat.tlb
      2018-10-01 13:06 - 2018-10-03 14:21 - 000316640 _____ C:\WINDOWS\WMSysPr9.prx
      2018-10-01 13:06 - 2018-10-01 13:19 - 000001006 _____ C:\WINDOWS\OEWABLog.txt
      2018-10-01 13:06 - 2018-10-01 13:06 - 000002577 _____ C:\WINDOWS\system32\CONFIG.NT
      2018-10-01 13:06 - 2018-10-01 13:06 - 000001599 _____ C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000792 _____ C:\Documents and Settings\Default User\Start Menu\Programs\Windows Media Player.lnk
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000398 _____ C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 __SHD C:\Documents and Settings\Default User\IETldCache
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 __RSH C:\MSDOS.SYS
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 __RSH C:\IO.SYS
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 ____D C:\WINDOWS\system32\xircom
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 ____D C:\Program Files\xerox
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 ____D C:\Program Files\microsoft frontpage
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 _____ C:\WINDOWS\control.ini
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 _____ C:\CONFIG.SYS
      2018-10-01 13:06 - 2018-10-01 13:06 - 000000000 _____ C:\AUTOEXEC.BAT
      2018-10-01 13:06 - 2008-04-14 14:00 - 000829440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetmgr.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000290816 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\adsiis51.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000275968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\certwiz.ocx
      2018-10-01 13:06 - 2008-04-14 14:00 - 000169984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisui.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000133632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisrtl.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000094720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\certmap.ocx
      2018-10-01 13:06 - 2008-04-14 14:00 - 000076800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\logui.ocx
      2018-10-01 13:06 - 2008-04-14 14:00 - 000076288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cnfgprts.ocx
      2018-10-01 13:06 - 2008-04-14 14:00 - 000068608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isatq.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000068608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisext51.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000064512 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iismap.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000046592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\coadmin.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admwprox.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000030720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisrstas.exe
      2018-10-01 13:06 - 2008-04-14 14:00 - 000019968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetsloc.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisreset.exe
      2018-10-01 13:06 - 2008-04-14 14:00 - 000013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\infoadmn.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetmgr.exe
      2018-10-01 13:06 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftpsapi2.dll
      2018-10-01 13:06 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisrstap.dll
      2018-10-01 13:06 - 2004-05-13 00:39 - 000876653 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4awel.dll
      2018-10-01 13:06 - 2004-05-13 00:39 - 000598071 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpmmc.dll
      2018-10-01 13:06 - 2004-05-13 00:39 - 000184435 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4amsft.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000208896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpmmcsat.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000188494 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpcount.exe
      2018-10-01 13:06 - 2003-03-24 16:52 - 000188480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cfgwiz.exe
      2018-10-01 13:06 - 2003-03-24 16:52 - 000147513 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4apws.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000109328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp98swin.exe
      2018-10-01 13:06 - 2003-03-24 16:52 - 000102509 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4atxt.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000082035 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4anscp.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000049212 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4awebs.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000049210 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4areg.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000041020 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4avnb.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000032826 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4avss.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000020541 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpexedll.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000020540 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\author.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000020540 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admin.dll
      2018-10-01 13:06 - 2003-03-24 16:52 - 000020538 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpremadm.exe
      2018-10-01 13:06 - 2003-03-24 16:52 - 000016439 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\author.exe
      2018-10-01 13:06 - 2003-03-24 16:52 - 000016439 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admin.exe
      2018-10-01 13:06 - 2003-03-24 16:52 - 000014608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp98sadm.exe
      2018-10-01 13:05 - 2018-10-03 14:21 - 000000000 __SHD C:\Documents and Settings\All Users\DRM
      2018-10-01 13:05 - 2018-10-01 13:05 - 000000000 ____D C:\Program Files\Microsoft CAPICOM 2.1.0.2
      2018-10-01 13:04 - 2018-10-01 13:04 - 000065536 _____ C:\WINDOWS\system32\config\Internet.evt
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000786 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000749 ___RH C:\WINDOWS\WindowsShell.Manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000749 ___RH C:\WINDOWS\system32\wuaucpl.cpl.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000749 ___RH C:\WINDOWS\system32\sapi.cpl.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000749 ___RH C:\WINDOWS\system32\nwc.cpl.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000749 ___RH C:\WINDOWS\system32\ncpa.cpl.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000749 ___RH C:\WINDOWS\system32\cdplayer.exe.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000488 ___RH C:\WINDOWS\system32\WindowsLogon.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000488 ___RH C:\WINDOWS\system32\logonui.exe.manifest
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000000 ___HD C:\Program Files\WindowsUpdate
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000000 ____D C:\WINDOWS\system32\DirectX
      2018-10-01 13:04 - 2018-10-01 13:04 - 000000000 ____D C:\Program Files\Online Services
      2018-10-01 13:04 - 2008-04-14 14:00 - 004399505 ____C C:\WINDOWS\system32\dllcache\nls302en.lex
      2018-10-01 13:04 - 2008-04-14 14:00 - 000099840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\helphost.exe
      2018-10-01 13:04 - 2008-04-14 14:00 - 000048680 ___SH C:\WINDOWS\winnt256.bmp
      2018-10-01 13:04 - 2008-04-14 14:00 - 000048680 ___SH C:\WINDOWS\winnt.bmp
      2018-10-01 13:04 - 2008-04-14 14:00 - 000035328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\notiflag.exe
      2018-10-01 13:04 - 2008-04-14 14:00 - 000021504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\brpinfo.dll
      2018-10-01 13:04 - 2008-04-14 14:00 - 000011264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\atrace.dll
      2018-10-01 13:04 - 2008-04-14 14:00 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\atrace.dll
      2018-10-01 13:04 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hcappres.dll
      2018-10-01 13:03 - 2018-10-01 13:04 - 000000000 ____D C:\WINDOWS\srchasst
      2018-10-01 13:03 - 2018-10-01 13:03 - 000000000 ____D C:\Program Files\Movie Maker
      2018-10-01 13:03 - 2018-10-01 13:03 - 000000000 ____D C:\Program Files\Common Files\Services
      2018-10-01 13:03 - 2018-10-01 13:03 - 000000000 ____D C:\Program Files\Common Files\MSSoap
      2018-10-01 13:03 - 2014-02-12 16:57 - 000759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 001933848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuaueng.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 001933848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000577048 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuapi.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000577048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000329240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wucltui.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000329240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltui.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000219160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuaucpl.cpl
      2018-10-01 13:03 - 2014-02-12 16:56 - 000219160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaucpl.cpl
      2018-10-01 13:03 - 2014-02-12 16:56 - 000210968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuweb.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000210968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuweb.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000194520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuaueng1.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000194520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng1.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000172504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuauclt1.exe
      2018-10-01 13:03 - 2014-02-12 16:56 - 000172504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt1.exe
      2018-10-01 13:03 - 2014-02-12 16:56 - 000053784 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuauclt.exe
      2018-10-01 13:03 - 2014-02-12 16:56 - 000053784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
      2018-10-01 13:03 - 2014-02-12 16:56 - 000035864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wups.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000035864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000023064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuauserv.dll
      2018-10-01 13:03 - 2014-02-12 16:56 - 000023064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauserv.dll
      2018-10-01 13:03 - 2014-02-12 16:55 - 003558912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\moviemk.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 004256768 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2res.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 003166208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msgr3en.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000726078 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srchui.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000502272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2fxa.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000409088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\qmgr.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000402432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2filt.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000364544 ____C (Microsoft Corporation (written by Digital Renaissance Inc.)) C:\WINDOWS\system32\dllcache\npdsplay.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000325632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2fxb.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000235520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mssoap1.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000226816 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\npdrmv2.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000221184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmpns.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000167936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2ae.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msg723.acm
      2018-10-01 13:03 - 2008-04-14 14:00 - 000093184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieinfo5.ocx
      2018-10-01 13:03 - 2008-04-14 14:00 - 000073728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwtutor.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000064512 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\acctres.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\acctres.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwres.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000058434 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srchctls.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000047104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srdiag.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000040960 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\trialoc.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000039936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msinfo32.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wisc10.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000023552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mssoapr.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\qmgrprxy.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgrprxy.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isignup.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icfgnt5.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfgnt5.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wb32.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmevtmsg.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cb32.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\nmevtmsg.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\npwmsdrm.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000008192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\bitsprx2.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx2.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2ext.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\bitsprx4.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\bitsprx3.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx4.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx3.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2res2.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000004639 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mplayer2.exe
      2018-10-01 13:03 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmm2eres.dll
      2018-10-01 13:03 - 2008-04-14 14:00 - 000000984 ____C C:\WINDOWS\system32\dllcache\srframe.mmf
      2018-10-01 13:03 - 2005-01-28 13:44 - 000991232 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\migrate.exe
      2018-10-01 13:03 - 2005-01-28 13:44 - 000819200 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\setup_wm.exe
      2018-10-01 13:03 - 2005-01-28 13:44 - 000352256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mpvis.dll
      2018-10-01 13:03 - 2005-01-28 13:44 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmpband.dll
      2018-10-01 13:03 - 2005-01-28 13:44 - 000073728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmplayer.exe
      2018-10-01 13:03 - 2005-01-28 13:44 - 000028672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\custsat.dll
      2018-10-01 13:02 - 2018-10-02 08:44 - 000000000 ____D C:\Program Files\Common Files\System
      2018-10-01 13:02 - 2018-10-01 13:03 - 000000000 ____D C:\Program Files\Outlook Express
      2018-10-01 13:02 - 2018-10-01 13:03 - 000000000 ____D C:\Program Files\NetMeeting
      2018-10-01 13:02 - 2014-02-12 16:57 - 000638816 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iexplore.exe
      2018-10-01 13:02 - 2014-02-12 16:57 - 000068608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hmmapi.dll
      2018-10-01 13:02 - 2014-02-12 16:56 - 001315328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msoe.dll
      2018-10-01 13:02 - 2014-02-12 16:56 - 000153088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\triedit.dll
      2018-10-01 13:02 - 2014-02-12 16:56 - 000102400 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msjro.dll
      2018-10-01 13:02 - 2014-02-12 16:56 - 000045568 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wab.exe
      2018-10-01 13:02 - 2014-02-12 16:55 - 000744448 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\helpsvc.exe
      2018-10-01 13:02 - 2014-02-12 16:55 - 000692736 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcomm.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000565248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msado15.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000331776 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadce.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000200704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadox.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000180224 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadomd.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000143360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadco.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000128512 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dhtmled.ocx
      2018-10-01 13:02 - 2014-02-12 16:55 - 000081920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msado27.tlb
      2018-10-01 13:02 - 2014-02-12 16:55 - 000081920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isign32.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\isign32.dll
      2018-10-01 13:02 - 2014-02-12 16:55 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msado26.tlb
      2018-10-01 13:02 - 2014-02-12 16:55 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msado25.tlb
      2018-10-01 13:02 - 2014-02-12 16:55 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msado21.tlb
      2018-10-01 13:02 - 2014-02-12 16:55 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msado20.tlb
      2018-10-01 13:02 - 2014-02-12 16:55 - 000057344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msador15.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 002479616 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msoeres.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 001032192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\conf.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000769024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\helpctr.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000565248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msobmain.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000554008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dao360.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000510976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wab32.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000487424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\oledb32.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000385024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\callcont.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000380416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rstrui.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000376832 ____C () C:\WINDOWS\system32\dllcache\msinfo.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000315392 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdasql.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000274944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstask.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstask.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000274432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mst120.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000274432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcfg.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcfg.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000252928 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msoeacct.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoeacct.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000249856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wab32res.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000239104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srrstr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\srrstr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000233472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaora.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000229376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmas.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000221184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nac.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000217088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sqlxmlx.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000214528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwconn1.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000204800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaps.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000200704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaprst.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000192512 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\schedsvc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000188416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmwb.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msh261.drv
      2018-10-01 13:02 - 2008-04-14 14:00 - 000172032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmoldwb.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000172032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwhelp.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000171008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srsvc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\srsvc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000169984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msconfig.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000155648 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadds.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000151552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmft.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000150528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\uploadm.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000129792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fltmgr.sys
      2018-10-01 13:02 - 2008-04-14 14:00 - 000129792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
      2018-10-01 13:02 - 2008-04-14 14:00 - 000122368 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msobcomm.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000118784 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdarem.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msoert2.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000104448 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\oeimport.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000102912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pchshell.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000094208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdatl3.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000086528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\directdb.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000086016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwconn2.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000085504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wabimp.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000081920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmchat.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000081920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ils.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ils.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmcom.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaosp.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000073728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwdial.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\icwdial.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000073472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sr.sys
      2018-10-01 13:02 - 2008-04-14 14:00 - 000073472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sr.sys
      2018-10-01 13:02 - 2008-04-14 14:00 - 000073216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\setup50.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000069632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msconf.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msconf.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000067584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\srclient.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000065536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\oledb32r.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000065536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwphbk.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\icwphbk.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rrcm.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadcf.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwconn.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000060416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\oemig50.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000060416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msimn.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000057344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mst123.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000057344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadrh15.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000057344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\h323cc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000053248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadcs.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000051200 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\oobebaln.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000049152 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwutil.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000048128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetres.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetres.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000045568 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\safrslv.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\safrslv.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000045056 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\confmrsl.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\safrcdlg.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\racpldlg.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\safrcdlg.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000040960 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dcap32.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000038400 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pchsvc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000036864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdfmap.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000035328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\oemiglib.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000034560 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mnmdd.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000034560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mnmdd.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000032768 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wabfind.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000032768 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mnmsrvc.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000032768 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwdl.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000032768 ____C (Intel Corporation) C:\WINDOWS\system32\dllcache\isrdbg32.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mnmsrvc.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000032768 _____ (Intel Corporation) C:\WINDOWS\system32\isrdbg32.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000030720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msobshel.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wabmig.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000029696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\safrdm.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\safrdm.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000029184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msoobe.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000028672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmmkcert.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000028672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nmasnt.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\nmmkcert.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000024576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msxactps.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000024576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msader15.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000024576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msaddsr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000024576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icwrmind.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000023040 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fltmc.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltMc.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000020480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdatt.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000020480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadcer.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000020480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetwiz.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msobweb.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000018432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedw.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000018432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hscupd.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fltlib.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltlib.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msobdl.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdasqlr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaremr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaprsr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaorar.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadcor.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msadcfr.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstinit.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstinit.exe
      2018-10-01 13:02 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaurl.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdasc.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaer.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdaenum.dll
      2018-10-01 13:02 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdadc.dll
      2018-10-01 13:01 - 2018-10-09 12:37 - 000000599 _____ C:\Documents and Settings\All Users\Start Menu\Microsoft Update Catalog.lnk
      2018-10-01 13:01 - 2018-10-01 13:05 - 000000000 ____D C:\WINDOWS\Registration
      2018-10-01 13:01 - 2018-10-01 13:01 - 000021640 _____ C:\WINDOWS\system32\emptyregdb.dat
      2018-10-01 13:01 - 2018-10-01 13:01 - 000001570 _____ C:\Documents and Settings\All Users\Start Menu\Microsoft Update.lnk
      2018-10-01 13:01 - 2018-10-01 13:01 - 000000037 _____ C:\WINDOWS\vbaddin.ini
      2018-10-01 13:01 - 2018-10-01 13:01 - 000000036 _____ C:\WINDOWS\vb.ini
      2018-10-01 13:01 - 2018-10-01 13:01 - 000000000 ___RD C:\Documents and Settings\All Users\Start Menu\Programs\Games
      2018-10-01 13:01 - 2018-10-01 13:01 - 000000000 ____D C:\Program Files\MSN Gaming Zone
      2018-10-01 13:01 - 2018-10-01 13:01 - 000000000 ____D C:\Program Files\ComPlus Applications
      2018-10-01 13:01 - 2008-04-14 14:00 - 002178131 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shvlres.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 001817687 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\bckgres.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 001175635 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hrtzres.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 001039955 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cmnresm.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000780885 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chkrres.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000753236 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rvseres.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000217160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cmnclim.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000113222 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\zoneclim.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000082501 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\bckg.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000066113 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shvl.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000057409 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hrtz.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000048706 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rvse.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000042577 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\bckgzm.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000042575 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chkrzm.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000042574 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rvsezm.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000042573 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shvlzm.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000042573 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hrtzzm.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000041029 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\zcorem.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000040515 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chkr.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000036937 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\zclientm.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000032339 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\uniansi.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000029760 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\znetm.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000013894 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\zonelibm.dll
      2018-10-01 13:01 - 2008-04-14 14:00 - 000005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\write.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\write.exe
      2018-10-01 13:01 - 2008-04-14 14:00 - 000004677 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\zeeverm.dll
      2018-10-01 13:00 - 2018-10-01 13:01 - 000000000 ____D C:\WINDOWS\system32\MsDtc
      2018-10-01 13:00 - 2018-10-01 13:01 - 000000000 ____D C:\WINDOWS\system32\Com
      2018-10-01 13:00 - 2018-10-01 13:00 - 000000000 ____D C:\Program Files\Windows NT
      2018-10-01 13:00 - 2014-02-12 16:56 - 000453120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiprvsd.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000343040 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mspaint.exe
      2018-10-01 13:00 - 2014-02-12 16:56 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
      2018-10-01 13:00 - 2014-02-12 16:56 - 000299008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msiprov.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000296960 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\termsrv.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000227840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiprvse.exe
      2018-10-01 13:00 - 2014-02-12 16:56 - 000218112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wordpad.exe
      2018-10-01 13:00 - 2014-02-12 16:56 - 000139784 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdpwd.sys
      2018-10-01 13:00 - 2014-02-12 16:56 - 000139784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpwd.sys
      2018-10-01 13:00 - 2014-02-12 16:56 - 000092672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\policman.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000091648 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtxoci.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000036864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tsgqec.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
      2018-10-01 13:00 - 2014-02-12 16:56 - 000022024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdtcp.sys
      2018-10-01 13:00 - 2014-02-12 16:56 - 000022024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdtcp.sys
      2018-10-01 13:00 - 2014-02-12 16:55 - 002691072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lhmstscx.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 002691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 001358336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cimwin32.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 001034240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lhmstsc.exe
      2018-10-01 13:00 - 2014-02-12 16:55 - 001034240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
      2018-10-01 13:00 - 2014-02-12 16:55 - 000956928 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdtctm.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000473600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fastprox.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000428032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdtcprx.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000161792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdtcuiu.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000131072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\aaclient.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\aaclient.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000058880 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdtclog.dll
      2018-10-01 13:00 - 2014-02-12 16:55 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtclog.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 001267200 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comsvcs.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 001267200 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000625664 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\catsrvut.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000625664 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000605696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\getuname.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000605696 _____ (Microsoft Corporation) C:\WINDOWS\system32\getuname.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000539648 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comuid.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\comuid.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000539136 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dialer.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000538624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\spider.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\spider.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000531456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemcore.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000498688 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\clbcatq.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\clbcatq.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000358912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmic.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000347136 _____ (Hilgraeve, Inc.) C:\WINDOWS\system32\hypertrm.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000290304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rhttpaa.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\system32\rhttpaa.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000281088 ____C (Cinematronics) C:\WINDOWS\system32\dllcache\pinball.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000273920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemess.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\esscli.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000237056 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\provthrd.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000227840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\avtapi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\avtapi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000226304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\catsrv.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrv.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000214528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemcomn.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000212992 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ntevt.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000197120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemupgd.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000196608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiadap.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000196608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemcntl.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000195072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comadmin.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000185344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\framedyn.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000185344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cmprops.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmprops.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\accwiz.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\accwiz.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000178176 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemdisp.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000178176 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\repdrvfs.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000167424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comsnap.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsnap.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmipcima.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000147968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdchost.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdchost.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000144896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmisvc.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000144896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000141312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sessmgr.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sessmgr.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000140800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmidcprv.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000138752 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sndvol32.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\sndvol32.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000132096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmipdskq.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000131584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\viewprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000131584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sndrec32.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sndrec32.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000126976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshearts.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshearts.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000126464 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiapsrv.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000123904 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mofd.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000123392 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mplay32.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mplay32.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000120320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dsprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000119808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winmine.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmine.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000116224 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemtest.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000116224 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\updprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000114688 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\calc.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000110592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\clbcatex.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\clbcatex.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000102912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\clipbrd.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\clipbrd.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000097792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comrepl.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\comrepl.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000095232 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiutils.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000093702 _____ C:\WINDOWS\system32\subrange.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000093696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tscfgwmi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000088576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiaprpl.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000087176 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdpwsx.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000087176 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpwsx.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000086528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\stdprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000085504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\catsrvps.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000080384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\charmap.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\charmap.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000075264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmipicmp.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000073216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\avwav.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\avwav.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000071680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemcons.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000068608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\access.cpl
      2018-10-01 13:00 - 2008-04-14 14:00 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\access.cpl
      2018-10-01 13:00 - 2008-04-14 14:00 - 000067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdshost.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdshost.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000065978 _____ C:\WINDOWS\Soap Bubbles.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000065954 _____ C:\WINDOWS\Prairie Wind.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000065832 _____ C:\WINDOWS\Santa Fe Stucco.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000063488 _____ C:\WINDOWS\system32\wmimgmt.msc
      2018-10-01 13:00 - 2008-04-14 14:00 - 000062976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdpclip.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000062464 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmipjobj.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000061952 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmipiprt.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000061952 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tmplprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000061440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmimsg.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000060928 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmicookr.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000060458 _____ C:\WINDOWS\system32\ideograf.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000060416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\remotepg.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000060416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\colbact.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remotepg.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\colbact.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000059904 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemdisp.tlb
      2018-10-01 13:00 - 2008-04-14 14:00 - 000059904 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\trnsprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000059392 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\stclient.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\stclient.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000058880 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licwmi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\licwmi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000056832 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sol.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\sol.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000056320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\servdeps.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\servdeps.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\freecell.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\freecell.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000053248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fwdprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000052224 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmitimep.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000047104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ncprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000045568 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmi2xml.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000044544 _____ (Hilgraeve, Inc.) C:\WINDOWS\system32\hticons.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemsvc.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000041472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmipsess.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000040960 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpcons.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000038912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cfgbkend.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000036352 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\scrcons.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000035328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winchat.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winchat.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000034304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtxlegih.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxlegih.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\regini.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\regini.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000031232 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemads.tlb
      2018-10-01 13:00 - 2008-04-14 14:00 - 000030720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtxdm.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxdm.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000028160 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comaddin.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comaddin.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000026680 _____ C:\WINDOWS\River Sumida.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000026582 _____ C:\WINDOWS\Greenstone.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000024576 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\krnlprov.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000024006 _____ C:\WINDOWS\system32\gb2312.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000022984 _____ C:\WINDOWS\system32\bopomofo.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000022016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\qwinsta.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\qwinsta.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msg.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msg.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000019968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdpsnd.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000019968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\qprocess.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsnd.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\qprocess.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtsadmin.tlb
      2018-10-01 13:00 - 2008-04-14 14:00 - 000018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemprox.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000017408 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mmfutil.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmfutil.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000017362 _____ C:\WINDOWS\Rhododendron.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000017336 _____ C:\WINDOWS\Gone Fishing.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000017062 _____ C:\WINDOWS\Coffee Bean.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\unsecapp.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tsshutdn.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\qappsrv.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsshutdn.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\qappsrv.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016740 _____ C:\WINDOWS\system32\shiftjis.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016730 _____ C:\WINDOWS\FeatherTexture.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winmgmtr.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tskill.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mofcomp.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\avmeter.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\tskill.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\avmeter.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rwinsta.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cdmodem.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rwinsta.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdmodem.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000015360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\logoff.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoff.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000014848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tsdiscon.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000014848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tscon.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000014848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shadow.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsdiscon.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscon.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\shadow.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000013824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdsaddin.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsaddin.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winmgmt.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000013312 ____C (Hilgraeve, Inc.) C:\WINDOWS\system32\dllcache\htrn_jis.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000013223 _____ C:\WINDOWS\system32\tslabels.ini
      2018-10-01 13:00 - 2008-04-14 14:00 - 000012876 _____ C:\WINDOWS\system32\korean.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000012288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wbemads.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000012040 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdpipe.sys
      2018-10-01 13:00 - 2008-04-14 14:00 - 000012040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdpipe.sys
      2018-10-01 13:00 - 2008-04-14 14:00 - 000011776 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xolehlp.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\xolehlp.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000011264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\icaapi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\icaapi.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000009728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\reset.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000009728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comrepl.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\reset.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000009522 _____ C:\WINDOWS\Zapotec.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000008484 _____ C:\WINDOWS\system32\kanji_2.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006948 _____ C:\WINDOWS\system32\kanji_1.uce
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiapres.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msdtc.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dcomcnfg.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\comrereg.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtc.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomcnfg.exe
      2018-10-01 13:00 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rdpcfgex.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtxex.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcfgex.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxex.dll
      2018-10-01 13:00 - 2008-04-14 14:00 - 000003286 _____ C:\WINDOWS\system32\tslabels.h
      2018-10-01 13:00 - 2008-04-14 14:00 - 000001931 _____ C:\WINDOWS\system32\msdtcprf.ini
      2018-10-01 13:00 - 2008-04-14 14:00 - 000001272 _____ C:\WINDOWS\Blue Lace 16.bmp
      2018-10-01 13:00 - 2008-04-14 14:00 - 000001161 _____ C:\WINDOWS\system32\usrlogon.cmd
      2018-10-01 13:00 - 2008-04-14 14:00 - 000000768 _____ C:\WINDOWS\system32\msdtcprf.h
      2018-10-01 12:59 - 2009-09-04 16:43 - 000195712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
      2018-10-01 12:59 - 2008-04-14 03:43 - 000040840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\termdd.sys
      ==================== One Month Modified files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-10-09 08:47 - 2008-04-14 14:00 - 000000573 _____ C:\WINDOWS\win.ini
      2018-10-09 08:47 - 2008-04-14 14:00 - 000000227 _____ C:\WINDOWS\system.ini
      2018-10-05 08:55 - 2008-04-14 14:00 - 000842240 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
      2018-10-05 08:55 - 2008-04-14 14:00 - 000175104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
      2018-10-03 10:08 - 2008-04-14 14:00 - 000002206 _____ C:\WINDOWS\system32\wpa.dbl
      ==================== Files in the root of some directories =======
      2018-10-01 13:33 - 2018-10-07 09:14 - 000006144 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      Some files in TEMP:
      ====================
      2018-10-08 13:13 - 2018-10-08 13:14 - 013604352 _____ (Reimage) C:\Documents and Settings\Administrator\Local Settings\Temp\ReimagePackage.exe
      2002-07-15 21:43 - 2002-07-15 21:43 - 000052736 _____ () C:\Documents and Settings\Administrator\Local Settings\Temp\sfextra.dll
      ==================== Bamital & volsnap ======================
      (There is no automatic fix for files that do not pass verification.)
      C:\WINDOWS\explorer.exe => File is digitally signed
      C:\WINDOWS\system32\winlogon.exe => File is digitally signed
      C:\WINDOWS\system32\svchost.exe => File is digitally signed
      C:\WINDOWS\system32\services.exe => File is digitally signed
      C:\WINDOWS\system32\User32.dll => File is digitally signed
      C:\WINDOWS\system32\userinit.exe => File is digitally signed
      C:\WINDOWS\system32\rpcss.dll => File is digitally signed
      C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
      C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
      ==================== End of FRST.txt ============================
      Addition.txt
  • Дарение