Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

How do I remove "Optimize Your PC" or "PC Fix Speed"?


  • This topic is locked This topic is locked
16 replies to this topic

#1 gigi8967

gigi8967

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 20 April 2014 - 10:46 PM

I somehow got PCFixSpeed/Optimize Your PC on my desktop and can't remove it despite attempts to uninstall the program through the control panel.  I've looked at the self-help forums, but couldn't find a fix without a BleepingComputer intervention to review log files.  I've installed MalwareBytes as well as Webroot which removed some threat, but not the PCFixSpeed problem which makes me wonder what else didn't these anti-virus software not pick up?  Can someone please advise me on process of removal?  Your help is much appreciated.  Thanks.



BC AdBot (Login to Remove)

 


#2 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 20 April 2014 - 11:46 PM

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17041
Run by ghiagriarte at 21:43:19 on 2014-04-20
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.2046.836 [GMT -7:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {66A6FE14-08CB-F415-3742-517201416109}
SP: Webroot SecureAnywhere *Enabled/Updated* {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Webroot\WRSA.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Webroot\WRSA.exe
C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Program Files\PFU\ScanSnap\SSFolder\SSFolderTray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - c:\program files\mcafee security scan\3.8.141\McAfeeMSS_IE.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Webroot Vault: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - c:\programdata\wrdata\pkg\LPBar.dll
BHO: Webroot Filtering Extension: {C9C42510-9B41-42c1-9DCD-7282A2D07C61} - c:\program files\webroot\wrdata\pkg\vistax86\wrflt.dll
TB: Webroot Toolbar: {97ab88ef-346b-4179-a0b1-7445896547a5} - c:\programdata\wrdata\pkg\LPBar.dll
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_12_0_0_77_Plugin.exe -update plugin
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ScanSnap WIA Service Checker] c:\windows\ssdriver\fi5110\SsWiaChecker.exe
mRun: [WRSVC] "c:\program files\webroot\WRSA.exe" -ul
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: c:\users\ghiagr~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\fujits~1.lnk - c:\program files\fujitsu\leadertech\fujitsuWebview-Release.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cardmi~1.lnk - c:\program files\pfu\scansnap\cardminder\CardLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\conver~1.lnk - c:\program files\pfu\scansnap\organizer\PfuSsOrgOcrChk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\instal~2.lnk - c:\program files\common files\wruninstall.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\instal~1.lnk - c:\program files\common files\wruninstall.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.8.141\SSScheduler.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe
uPolicies-Explorer: NoViewOnDrive = dword:0
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: DisableLocalMachineRun = dword:0
uPolicies-Explorer: DisableLocalMachineRunOnce = dword:0
uPolicies-Explorer: DisableCurrentUserRun = dword:0
uPolicies-Explorer: DisableCurrentUserRunOnce = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:0
uPolicies-Explorer: NoFile = dword:0
uPolicies-Explorer: HideClock = dword:0
uPolicies-Explorer: NoDevMgrUpdate = dword:0
uPolicies-Explorer: NoDFSTab = dword:0
uPolicies-Explorer: NoWindowsUpdate = dword:0
uPolicies-Explorer: NoEncryptOnMove = dword:0
uPolicies-Explorer: NoRunasInstallPrompt = dword:0
uPolicies-Explorer: NoResolveTrack = dword:0
uPolicies-Explorer: NoStartMenuSubFolders = dword:0
uPolicies-System: NoDispAppearancePage = dword:0
uPolicies-System: NoDispSettingsPage = dword:0
mPolicies-Explorer: NoViewOnDrive = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: DisableLocalMachineRun = dword:0
mPolicies-Explorer: DisableLocalMachineRunOnce = dword:0
mPolicies-Explorer: DisableCurrentUserRun = dword:0
mPolicies-Explorer: DisableCurrentUserRunOnce = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:0
mPolicies-Explorer: NoFile = dword:0
mPolicies-Explorer: HideClock = dword:0
mPolicies-Explorer: NoDevMgrUpdate = dword:0
mPolicies-Explorer: NoDFSTab = dword:0
mPolicies-Explorer: NoWindowsUpdate = dword:0
mPolicies-Explorer: NoEncryptOnMove = dword:0
mPolicies-Explorer: NoRunasInstallPrompt = dword:0
mPolicies-Explorer: NoResolveTrack = dword:0
mPolicies-Explorer: NoStartMenuSubFolders = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: NoDispAppearancePage = dword:0
mPolicies-System: NoDispSettingsPage = dword:0
mPolicies-Explorer: NoViewOnDrive = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: DisableLocalMachineRun = dword:0
mPolicies-Explorer: DisableLocalMachineRunOnce = dword:0
mPolicies-Explorer: DisableCurrentUserRun = dword:0
mPolicies-Explorer: DisableCurrentUserRunOnce = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:0
mPolicies-Explorer: NoFile = dword:0
mPolicies-Explorer: HideClock = dword:0
mPolicies-Explorer: NoDevMgrUpdate = dword:0
mPolicies-Explorer: NoDFSTab = dword:0
mPolicies-Explorer: NoWindowsUpdate = dword:0
mPolicies-Explorer: NoEncryptOnMove = dword:0
mPolicies-Explorer: NoRunasInstallPrompt = dword:0
mPolicies-Explorer: NoResolveTrack = dword:0
mPolicies-Explorer: NoStartMenuSubFolders = dword:0
mPolicies-System: NoDispAppearancePage = dword:0
mPolicies-System: NoDispSettingsPage = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - c:\programdata\wrdata\pkg\LPBar.dll
TCP: NameServer = 75.75.75.75 75.75.76.76 192.168.1.1
TCP: Interfaces\{73B7FEE8-DFD7-4D24-BED5-F7B6F44CDD1E} : DHCPNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\34.0.1847.116\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ghiagriarte\appdata\roaming\mozilla\firefox\profiles\zgd2dou1.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.23.9\npGoogleUpdate3.dll
FF - plugin: c:\program files\mcafee security scan\3.8.141\npMcAfeeMSS.dll
FF - plugin: c:\program files\skypewebplugin\npSkypeWebPlugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_12_0_0_77.dll
FF - plugin: c:\windows\system32\wat\npWatWeb.dll
.
============= SERVICES / DRIVERS ===============
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2014-4-10 116736]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-4-10 1809720]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-4-10 857912]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2014-4-10 763512]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-4-10 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-4-10 107736]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-4-10 51416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-4-17 108032]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.8.141\McCHSvc.exe [2014-1-15 235696]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-4-12 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2014-4-8 1343400]
.
=============== Created Last 30 ================
.
2014-04-20 19:23:35    --------    d-----w-    c:\program files\FileASSASSIN
2014-04-18 11:11:19    62576    ----a-w-    c:\programdata\microsoft\windows defender\definition updates\{6d11563c-4017-4b23-b523-39d0ebd7e22c}\offreg.dll
2014-04-18 06:56:35    8050496    ----a-w-    c:\programdata\microsoft\windows defender\definition updates\{6d11563c-4017-4b23-b523-39d0ebd7e22c}\mpengine.dll
2014-04-17 10:04:02    --------    d-----w-    c:\windows\Migration
2014-04-15 10:02:29    71680    ----a-w-    c:\windows\system32\RegisterIEPKEYs.exe
2014-04-14 22:12:22    317440    ----a-w-    c:\windows\system32\spoolsv.exe
2014-04-14 22:12:21    417792    ----a-w-    c:\windows\system32\WMPhoto.dll
2014-04-14 22:12:21    1230336    ----a-w-    c:\windows\system32\WindowsCodecs.dll
2014-04-14 22:12:19    2616320    ----a-w-    c:\windows\explorer.exe
2014-04-14 22:12:18    3419136    ----a-w-    c:\windows\system32\d2d1.dll
2014-04-14 22:12:18    1987584    ----a-w-    c:\windows\system32\d3d10warp.dll
2014-04-14 10:22:44    66560    ----a-w-    c:\windows\system32\drivers\WUDFPf.sys
2014-04-14 10:22:44    155136    ----a-w-    c:\windows\system32\drivers\WUDFRd.sys
2014-04-14 10:22:43    73216    ----a-w-    c:\windows\system32\WUDFSvc.dll
2014-04-14 10:22:43    172032    ----a-w-    c:\windows\system32\WUDFPlatform.dll
2014-04-14 10:22:42    613888    ----a-w-    c:\windows\system32\WUDFx.dll
2014-04-14 10:22:42    38912    ----a-w-    c:\windows\system32\WUDFCoinstaller.dll
2014-04-14 10:22:42    196608    ----a-w-    c:\windows\system32\WUDFHost.exe
2014-04-14 10:14:53    12625408    ----a-w-    c:\windows\system32\wmploc.DLL
2014-04-14 10:14:52    164864    ----a-w-    c:\program files\windows media player\wmplayer.exe
2014-04-14 10:05:10    49152    ----a-w-    c:\windows\system32\taskhost.exe
2014-04-14 10:03:01    1505280    ----a-w-    c:\windows\system32\d3d11.dll
2014-04-14 04:01:58    729024    ----a-w-    c:\windows\system32\drivers\dxgkrnl.sys
2014-04-14 04:00:58    81920    ----a-w-    c:\windows\system32\davclnt.dll
2014-04-14 03:48:05    47104    ----a-w-    c:\windows\system32\appinfo.dll
2014-04-14 03:48:05    101720    ----a-w-    c:\windows\system32\consent.exe
2014-04-13 10:48:59    55296    ----a-w-    c:\windows\system32\cero.rs
2014-04-13 10:48:59    51712    ----a-w-    c:\windows\system32\esrb.rs
2014-04-13 10:48:59    23552    ----a-w-    c:\windows\system32\oflc.rs
2014-04-13 10:48:59    20480    ----a-w-    c:\windows\system32\pegi-fi.rs
2014-04-13 10:48:52    164352    ----a-w-    c:\windows\system32\profsvc.dll
2014-04-13 10:48:50    442880    ----a-w-    c:\windows\system32\ntshrui.dll
2014-04-13 10:08:35    --------    d-----w-    c:\windows\system32\SPReview
2014-04-13 10:07:35    --------    d-----w-    c:\windows\system32\EventProviders
2014-04-12 11:43:14    1130824    ----a-w-    c:\windows\system32\dfshim.dll
2014-04-12 11:43:10    52224    ----a-w-    c:\windows\system32\drivers\TsUsbFlt.sys
2014-04-12 11:43:10    11776    ----a-w-    c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-04-12 11:43:06    954752    ----a-w-    c:\windows\system32\mfc40.dll
2014-04-12 11:43:06    954288    ----a-w-    c:\windows\system32\mfc40u.dll
2014-04-12 11:43:04    1159168    ----a-w-    c:\windows\system32\sysmain.dll
2014-04-12 11:41:59    98304    ----a-w-    c:\windows\system32\nslookup.exe
2014-04-11 00:31:03    107736    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-11 00:30:47    73432    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2014-04-11 00:30:47    51416    ----a-w-    c:\windows\system32\drivers\mwac.sys
2014-04-11 00:30:47    23256    ----a-w-    c:\windows\system32\drivers\mbam.sys
2014-04-11 00:30:47    --------    d-----w-    c:\programdata\Malwarebytes
2014-04-11 00:30:47    --------    d-----w-    c:\program files\Malwarebytes Anti-Malware
2014-04-10 20:41:18    19824    ----a-w-    c:\windows\system32\drivers\fs_rec.sys
2014-04-10 20:41:17    5120    ----a-w-    c:\windows\system32\wmi.dll
2014-04-10 20:33:35    --------    d-----w-    c:\program files\MSXML 4.0
2014-04-10 20:28:27    --------    d-----w-    c:\users\ghiagriarte\appdata\local\lptmp532480255
2014-04-10 20:28:05    152744    ----a-w-    c:\windows\system32\WRusr.dll
2014-04-10 20:28:04    116736    ----a-w-    c:\windows\system32\drivers\WRkrn.sys
2014-04-10 20:28:03    --------    d-----w-    c:\program files\Webroot
2014-04-10 20:27:57    --------    d-----w-    c:\programdata\WRData
2014-04-09 11:34:34    311808    ----a-w-    c:\windows\system32\drivers\srv.sys
2014-04-09 11:34:34    310272    ----a-w-    c:\windows\system32\drivers\srv2.sys
2014-04-09 11:34:34    114688    ----a-w-    c:\windows\system32\drivers\srvnet.sys
2014-04-09 11:34:32    15872    ----a-w-    c:\windows\system32\drivers\usb8023.sys
2014-04-09 11:34:15    376832    ----a-w-    c:\windows\system32\dpnet.dll
2014-04-09 11:34:15    2560    ----a-w-    c:\windows\system32\dpnaddr.dll
2014-04-09 11:34:06    28672    ----a-w-    c:\windows\system32\dnscacheugc.exe
2014-04-09 11:34:06    132608    ----a-w-    c:\windows\system32\dnsrslvr.dll
2014-04-09 11:34:05    708608    ----a-w-    c:\program files\common files\system\wab32.dll
2014-04-09 11:34:01    69632    ----a-w-    c:\windows\system32\smss.exe
2014-04-09 11:34:01    38912    ----a-w-    c:\windows\system32\csrsrv.dll
2014-04-09 11:32:58    741376    ----a-w-    c:\windows\system32\inetcomm.dll
2014-04-09 11:31:57    69632    ----a-w-    c:\windows\system32\drivers\bowser.sys
2014-04-09 11:31:53    123904    ----a-w-    c:\windows\system32\poqexec.exe
2014-04-09 11:21:14    826880    ----a-w-    c:\windows\system32\rdpcore.dll
2014-04-09 11:21:14    24576    ----a-w-    c:\windows\system32\drivers\tdtcp.sys
2014-04-09 11:21:14    18432    ----a-w-    c:\windows\system32\drivers\tdpipe.sys
2014-04-09 06:41:04    --------    d-----w-    c:\users\ghiagriarte\appdata\local\Microsoft Corporation
2014-04-09 00:52:51    --------    d-----w-    c:\users\ghiagriarte\appdata\local\Google
2014-04-09 00:48:47    --------    d-----w-    c:\programdata\AVAST Software
2014-04-09 00:46:56    --------    d-----w-    c:\windows\system32\Wat
2014-04-09 00:46:18    --------    d-----w-    c:\program files\Optimizer Pro
2014-04-09 00:46:13    --------    d-----w-    c:\users\ghiagriarte\appdata\local\Programs
2014-03-25 20:02:25    --------    d-----w-    c:\program files\McAfee Security Scan
2014-03-24 13:43:33    7969936    ----a-w-    c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
.
==================== Find3M  ====================
.
2014-04-14 10:04:39    9728    ---ha-w-    c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-13 10:15:45    152576    ----a-w-    c:\windows\system32\msclmd.dll
2014-03-31 16:35:10    231584    ------w-    c:\windows\system32\MpSigStub.exe
2014-03-12 04:19:04    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-12 04:19:04    692616    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2014-03-06 08:32:07    2724864    ----a-w-    c:\windows\system32\mshtml.tlb
2014-03-06 08:31:27    4096    ----a-w-    c:\windows\system32\ieetwcollectorres.dll
2014-03-06 08:02:34    61952    ----a-w-    c:\windows\system32\iesetup.dll
2014-03-06 08:02:33    455168    ----a-w-    c:\windows\system32\vbscript.dll
2014-03-06 08:01:01    51200    ----a-w-    c:\windows\system32\ieetwproxystub.dll
2014-03-06 07:46:36    4254720    ----a-w-    c:\windows\system32\jscript9.dll
2014-03-06 07:38:13    112128    ----a-w-    c:\windows\system32\ieUnatt.exe
2014-03-06 07:38:10    108032    ----a-w-    c:\windows\system32\ieetwcollector.exe
2014-03-06 07:36:40    592896    ----a-w-    c:\windows\system32\jscript9diag.dll
2014-03-06 07:28:01    646144    ----a-w-    c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-06 07:13:43    32256    ----a-w-    c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-06 06:40:39    1967104    ----a-w-    c:\windows\system32\inetcpl.cpl
2014-03-06 05:41:49    1789440    ----a-w-    c:\windows\system32\wininet.dll
2014-02-07 01:07:56    2349056    ----a-w-    c:\windows\system32\win32k.sys
2014-02-04 02:07:53    149440    ----a-w-    c:\windows\system32\drivers\storport.sys
2014-02-04 02:07:50    234432    ----a-w-    c:\windows\system32\drivers\msiscsi.sys
2014-02-04 02:07:41    27072    ----a-w-    c:\windows\system32\drivers\Diskdump.sys
2014-02-04 02:04:11    509440    ----a-w-    c:\windows\system32\qedit.dll
2014-02-04 02:00:39    2048    ----a-w-    c:\windows\system32\iologmsg.dll
2014-01-29 02:06:47    381440    ----a-w-    c:\windows\system32\wer.dll
2014-01-28 02:07:07    185344    ----a-w-    c:\windows\system32\wwansvc.dll
2014-01-24 02:18:22    1212352    ----a-w-    c:\windows\system32\drivers\ntfs.sys
.
============= FINISH: 21:43:43.61 ===============



#3 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 20 April 2014 - 11:58 PM

Here's the Attach.txt file created by DDS.

Attached Files



#4 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 21 April 2014 - 01:53 AM

I've also been getting "This copy of Windows is not genuine." when we've physically purchased the software and have the packaging with the key.  So I may have multiple issues on going.



#5 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:07:52 AM

Posted 23 April 2014 - 02:30 PM

Hello gigi8967,
  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Follow This Topic.I suggest you click it and select Immediate E-Mail notification and click on Follow This Topic. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

  • Finally, please reply using the Post button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.
  • 1.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool .
    • Click on the Scan button.
    • AdwCleaner will begin to scan your computer.
    • After the scan has finished...
    • Click on the Clean button.
    • Press OK when asked to close all programs and follow the onscreen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    2.
    Please download Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#6 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 23 April 2014 - 10:04 PM

Hi Fireman4IT,

Many thanks in advance.  Adcleaner logfile:

 

# AdwCleaner v3.202 - Report created 23/04/2014 at 19:55:08
# Updated 23/04/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : ghiagriarte - GHIAGRIARTE-PC
# Running from : C:\Users\ghiagriarte\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\Optimizer Pro
Folder Deleted : C:\Users\ghiagriarte\Documents\Optimizer Pro

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Mozilla Firefox v28.0 (en-US)

[ File : C:\Users\ghiagriarte\AppData\Roaming\Mozilla\Firefox\Profiles\zgd2dou1.default\prefs.js ]


-\\ Google Chrome v34.0.1847.116

[ File : C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh

*************************

AdwCleaner[R0].txt - [2039 octets] - [23/04/2014 19:45:55]
AdwCleaner[S0].txt - [2000 octets] - [23/04/2014 19:55:08]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2060 octets] ##########
 



#7 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 23 April 2014 - 10:10 PM

Farbar Recovery Scan Tool.  Results of FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-04-2014
Ran by ghiagriarte (administrator) on GHIAGRIARTE-PC on 23-04-2014 20:05:54
Running from C:\Users\ghiagriarte\Desktop
Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Webroot) C:\Program Files\Webroot\WRSA.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(PFU LIMITED) C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(PFU LIMITED) C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(PFU LIMITED) C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
(PFU LIMITED) C:\Program Files\PFU\ScanSnap\SSFolder\SSFolderTray.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-20] (Adobe Systems Incorporated)
HKLM\...\Run: [ScanSnap WIA Service Checker] => C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
HKLM\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [763512 2014-04-13] (Webroot)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2014-04-13] (Microsoft Corporation)
HKU\.DEFAULT\...\Policies\system: [DisableCMD] 0
HKU\.DEFAULT\...\Policies\system: [NoDispAppearancePage] 0
HKU\.DEFAULT\...\Policies\system: [NoDispBackgroundPage] 0
HKU\.DEFAULT\...\Policies\system: [NoDispSettingsPage] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFind] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFile] 0
HKU\.DEFAULT\...\Policies\Explorer: [HideClock] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoSetFolders] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoDFSTab] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoLogoff] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoSaveSettings] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoHardwareTab] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-2936780568-2621215044-1807614538-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardMinder Viewer.lnk
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot FF RunOnce.lnk
ShortcutTarget: Install Webroot FF RunOnce.lnk -> C:\Program Files\Common Files\wruninstall.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot IE RunOnce.lnk
ShortcutTarget: Install Webroot IE RunOnce.lnk -> C:\Program Files\Common Files\wruninstall.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
Startup: C:\Users\ghiagriarte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fujitsu S1100 Registration.lnk
ShortcutTarget: Fujitsu S1100 Registration.lnk -> C:\Program Files\Fujitsu\LeaderTech\fujitsuWebview-Release.exe (Leader Technologies/Fujitsu)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA71B7E50A14ECF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
SearchScopes: HKLM - DefaultScope value is missing.
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Webroot Vault - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
BHO: Webroot Filtering Extension - {C9C42510-9B41-42c1-9DCD-7282A2D07C61} - C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll (Webroot)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\ghiagriarte\AppData\Roaming\Mozilla\Firefox\Profiles\zgd2dou1.default
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @Skype Technologies S.A..com/Skype Web Plugin - C:\Program Files\SkypeWebPlugin\npSkypeWebPlugin.dll (Skype)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Webroot Password Manager - C:\Users\ghiagriarte\AppData\Roaming\Mozilla\Firefox\Profiles\zgd2dou1.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda} [2014-04-10]
FF HKLM\...\Firefox\Extensions: [webrootsecure@webroot.com] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: Webroot Filtering Extension - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2014-04-10]

Chrome:
=======
CHR HomePage:
CHR StartupUrls: "hxxp://www.google.com/"]},"sync_promo":{"show_on_first_run_allowed":false},"translate_blocked_languages":["en"],"translate_whitelists":{},"homepage":""
CHR Extension: (Google Docs) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-08]
CHR Extension: (Google Drive) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-08]
CHR Extension: (YouTube) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-08]
CHR Extension: (Google Search) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-08]
CHR Extension: (avast! Online Security) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-04-08]
CHR Extension: (Google Wallet) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-08]
CHR Extension: (Gmail) - C:\Users\ghiagriarte\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-08]
CHR HKLM\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - C:\ProgramData\WRData\PKG\CHROME\CHROME_1.0.0.32.crx [2014-04-10]
CHR HKLM\...\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2014-04-10]

========================== Services (Whitelisted) =================

R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [235696 2014-01-15] (McAfee, Inc.)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [763512 2014-04-13] (Webroot)

==================== Drivers (Whitelisted) ====================

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-04-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-04-03] (Malwarebytes Corporation)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116736 2014-04-13] (Webroot)
U0 SR;
U2 srservice;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-23 20:05 - 2014-04-23 20:06 - 00019233 _____ () C:\Users\ghiagriarte\Desktop\FRST.txt
2014-04-23 20:05 - 2014-04-23 20:05 - 01048576 _____ (Farbar) C:\Users\ghiagriarte\Desktop\FRST.exe
2014-04-23 20:05 - 2014-04-23 20:05 - 00000000 ____D () C:\FRST
2014-04-23 19:46 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-04-23 19:45 - 2014-04-23 19:55 - 00000000 ____D () C:\AdwCleaner
2014-04-23 19:45 - 2014-04-23 19:45 - 01365865 _____ () C:\Users\ghiagriarte\Desktop\AdwCleaner.exe
2014-04-20 21:43 - 2014-04-20 21:43 - 00018332 _____ () C:\Users\ghiagriarte\Desktop\dds.txt
2014-04-20 21:43 - 2014-04-20 21:43 - 00004914 _____ () C:\Users\ghiagriarte\Desktop\attach.txt
2014-04-20 20:37 - 2014-04-20 20:37 - 00688992 ____R (Swearware) C:\Users\ghiagriarte\Desktop\dds.com
2014-04-20 12:23 - 2014-04-20 12:23 - 00001017 _____ () C:\Users\Public\Desktop\FileASSASSIN.lnk
2014-04-20 12:23 - 2014-04-20 12:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
2014-04-20 12:23 - 2014-04-20 12:23 - 00000000 ____D () C:\Program Files\FileASSASSIN
2014-04-20 12:22 - 2014-04-20 12:22 - 00167034 _____ () C:\Users\ghiagriarte\Desktop\fileassassin-setup-1.06.exe
2014-04-17 03:01 - 2014-03-06 02:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-17 03:01 - 2014-03-06 01:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-17 03:01 - 2014-03-06 01:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-17 03:01 - 2014-03-06 01:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-17 03:01 - 2014-03-06 01:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-17 03:01 - 2014-03-06 01:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-17 03:01 - 2014-03-06 00:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-17 03:01 - 2014-03-06 00:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-17 03:01 - 2014-03-06 00:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-17 03:01 - 2014-03-06 00:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-17 03:01 - 2014-03-06 00:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-17 03:01 - 2014-03-06 00:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-17 03:01 - 2014-03-06 00:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-17 03:01 - 2014-03-06 00:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-17 03:01 - 2014-03-06 00:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-17 03:01 - 2014-03-06 00:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-17 03:01 - 2014-03-06 00:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-17 03:01 - 2014-03-06 00:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-17 03:01 - 2014-03-06 00:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-17 03:01 - 2014-03-06 00:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-17 03:01 - 2014-03-05 23:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-17 03:01 - 2014-03-05 23:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-17 03:01 - 2014-03-05 23:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-17 03:01 - 2014-03-05 22:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-17 03:01 - 2014-03-05 22:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-17 03:01 - 2014-03-05 22:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-04-15 03:02 - 2014-04-15 03:02 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-04-15 03:02 - 2014-04-15 03:02 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-04-15 03:02 - 2014-04-15 03:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-04-14 15:12 - 2014-02-03 19:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-04-14 15:12 - 2013-12-24 16:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-04-14 15:12 - 2013-11-26 01:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-04-14 15:12 - 2013-11-23 11:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-04-14 15:12 - 2012-02-10 22:37 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-04-14 15:12 - 2011-02-24 22:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-04-14 03:22 - 2012-07-25 20:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-04-14 03:22 - 2012-07-25 20:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-04-14 03:22 - 2012-07-25 20:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-04-14 03:22 - 2012-07-25 20:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-04-14 03:22 - 2012-07-25 20:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-04-14 03:22 - 2012-07-25 19:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-04-14 03:22 - 2012-07-25 19:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-04-14 03:22 - 2012-06-02 07:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-04-14 03:14 - 2013-05-09 21:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-04-14 03:14 - 2013-05-09 21:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-04-14 03:10 - 2014-04-15 03:03 - 00013207 _____ () C:\Windows\IE11_main.log
2014-04-14 03:05 - 2014-04-14 03:05 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-04-14 03:04 - 2014-04-14 03:04 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-04-14 03:03 - 2014-04-14 03:03 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-04-14 03:02 - 2014-04-14 03:07 - 00009669 _____ () C:\Windows\IE10_main.log
2014-04-13 21:02 - 2014-02-03 19:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-13 21:02 - 2013-12-31 16:05 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-04-13 21:02 - 2013-12-05 19:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-13 21:02 - 2013-12-05 19:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-04-13 21:02 - 2013-10-29 19:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-04-13 21:02 - 2013-10-18 18:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-04-13 21:02 - 2013-10-11 19:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-04-13 21:02 - 2013-10-11 19:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-13 21:02 - 2013-10-11 18:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-04-13 21:02 - 2013-10-11 18:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-04-13 21:02 - 2013-10-03 18:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-04-13 21:02 - 2013-10-03 18:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-04-13 21:02 - 2013-10-03 18:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-04-13 21:02 - 2013-09-24 19:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-04-13 21:02 - 2013-09-24 19:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-04-13 21:02 - 2013-09-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-04-13 21:02 - 2013-09-24 18:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-04-13 21:02 - 2013-09-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-04-13 21:02 - 2013-09-24 18:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-04-13 21:02 - 2013-09-24 18:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-04-13 21:02 - 2013-09-24 17:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-04-13 21:02 - 2013-09-24 17:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-04-13 21:02 - 2013-09-13 17:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-04-13 21:02 - 2013-09-07 19:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-04-13 21:02 - 2013-07-08 21:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-04-13 21:02 - 2013-07-08 21:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-04-13 21:02 - 2013-07-04 05:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-04-13 21:02 - 2013-07-04 04:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-04-13 21:02 - 2013-07-02 21:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2014-04-13 21:02 - 2013-07-02 20:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-04-13 21:02 - 2013-07-02 20:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-04-13 21:02 - 2012-08-22 10:16 - 00712048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-04-13 21:02 - 2012-08-21 13:12 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-04-13 21:02 - 2012-07-04 12:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-04-13 21:01 - 2014-02-06 18:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-13 21:01 - 2014-02-03 19:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-13 21:01 - 2014-02-03 19:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-13 21:01 - 2014-02-03 19:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-13 21:01 - 2014-02-03 19:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-13 21:01 - 2014-01-27 19:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-04-13 21:01 - 2014-01-23 19:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-13 21:01 - 2013-11-11 19:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-04-13 21:01 - 2013-10-03 18:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-04-13 21:01 - 2013-10-03 18:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-04-13 21:01 - 2013-08-28 18:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-04-13 21:01 - 2013-08-28 18:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-04-13 21:01 - 2013-08-28 18:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-04-13 21:01 - 2013-08-28 18:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-04-13 21:01 - 2013-08-28 18:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-04-13 21:01 - 2013-08-27 17:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-04-13 21:01 - 2013-08-01 04:03 - 00729024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-04-13 21:01 - 2013-07-25 01:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-04-13 21:01 - 2013-07-20 03:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-04-13 21:01 - 2013-06-05 21:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-04-13 21:01 - 2013-06-05 21:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-04-13 21:01 - 2013-06-05 21:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-04-13 21:01 - 2013-06-05 20:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-04-13 21:01 - 2013-06-05 20:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-04-13 21:01 - 2013-05-12 20:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-04-13 21:01 - 2013-05-12 20:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-04-13 21:01 - 2013-05-09 20:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-04-13 21:01 - 2013-04-25 21:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-04-13 21:01 - 2013-04-09 22:18 - 00218984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-04-13 21:01 - 2013-03-18 20:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-04-13 21:01 - 2012-10-03 09:42 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-04-13 21:01 - 2012-10-03 09:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-04-13 21:01 - 2012-10-03 09:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-04-13 21:01 - 2012-10-03 09:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-04-13 21:01 - 2012-10-03 09:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-04-13 21:01 - 2012-10-03 09:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-04-13 21:01 - 2012-10-03 08:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-04-13 21:00 - 2014-03-04 02:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-13 21:00 - 2014-01-28 19:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-13 21:00 - 2013-12-03 19:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-04-13 21:00 - 2013-12-03 19:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-04-13 21:00 - 2013-12-03 19:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-04-13 21:00 - 2013-12-03 19:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-04-13 21:00 - 2013-12-03 19:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-04-13 21:00 - 2013-12-03 18:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-04-13 21:00 - 2013-12-03 18:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-04-13 21:00 - 2013-12-03 18:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-04-13 21:00 - 2013-12-03 18:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-04-13 21:00 - 2013-11-26 18:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-04-13 21:00 - 2013-11-26 18:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-04-13 21:00 - 2013-11-26 18:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-04-13 21:00 - 2013-11-26 18:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-04-13 21:00 - 2013-11-26 18:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-04-13 21:00 - 2013-11-26 18:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-04-13 21:00 - 2013-11-26 18:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-04-13 21:00 - 2013-11-26 04:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-04-13 21:00 - 2013-10-11 19:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-04-13 21:00 - 2013-10-11 19:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-04-13 21:00 - 2013-10-11 19:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-04-13 21:00 - 2013-10-05 12:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-04-13 21:00 - 2013-10-02 18:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-04-13 21:00 - 2013-09-07 19:07 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-04-13 21:00 - 2013-08-04 18:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-04-13 21:00 - 2013-08-01 18:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-04-13 21:00 - 2013-08-01 18:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 17:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-04-13 21:00 - 2013-08-01 17:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 17:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 17:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-04-13 21:00 - 2013-08-01 17:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-04-13 21:00 - 2013-07-25 18:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-04-13 21:00 - 2013-07-25 18:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-04-13 21:00 - 2013-07-12 03:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-04-13 21:00 - 2013-07-12 03:07 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2014-04-13 21:00 - 2013-07-08 21:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-04-13 21:00 - 2013-07-08 21:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-04-13 21:00 - 2013-07-04 04:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-04-13 21:00 - 2013-07-04 04:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-04-13 21:00 - 2013-07-04 02:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-04-13 21:00 - 2013-06-25 15:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-04-13 21:00 - 2013-06-14 20:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-04-13 21:00 - 2012-11-28 15:57 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-04-13 21:00 - 2012-11-28 15:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-04-13 21:00 - 2012-11-28 15:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-04-13 21:00 - 2012-10-09 10:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-04-13 21:00 - 2012-10-09 10:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-04-13 20:48 - 2013-02-26 22:05 - 00101720 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-04-13 20:48 - 2013-02-26 21:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-04-13 03:49 - 2013-01-23 21:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-04-13 03:49 - 2012-12-07 05:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-04-13 03:49 - 2012-12-07 05:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-04-13 03:49 - 2012-12-07 03:46 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-04-13 03:49 - 2012-12-07 03:46 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-04-13 03:49 - 2012-11-21 21:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-04-13 03:49 - 2012-05-05 00:46 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-04-13 03:49 - 2012-04-07 04:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-04-13 03:49 - 2011-12-29 22:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-04-13 03:49 - 2011-06-15 21:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-04-13 03:49 - 2011-05-03 21:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-04-13 03:49 - 2011-05-03 21:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-04-13 03:49 - 2011-05-03 21:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-04-13 03:49 - 2011-05-03 21:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-04-13 03:49 - 2011-05-03 21:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-04-13 03:49 - 2011-05-03 21:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-04-13 03:49 - 2011-05-03 21:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-04-13 03:49 - 2011-05-03 21:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-04-13 03:49 - 2011-05-03 21:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-04-13 03:49 - 2011-03-10 22:39 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-04-13 03:49 - 2011-03-10 22:39 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-04-13 03:49 - 2011-03-10 22:38 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-04-13 03:49 - 2011-03-10 22:38 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-04-13 03:49 - 2011-03-10 22:38 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-04-13 03:49 - 2011-03-10 22:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-04-13 03:49 - 2011-03-10 22:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-04-13 03:49 - 2011-03-10 21:01 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-04-13 03:49 - 2011-02-17 22:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-04-13 03:48 - 2012-12-07 03:46 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-04-13 03:48 - 2012-12-07 03:46 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-04-13 03:48 - 2012-12-07 03:46 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-04-13 03:48 - 2012-12-07 03:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-04-13 03:48 - 2012-04-30 21:44 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-04-13 03:48 - 2012-01-04 01:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-04-13 03:08 - 2014-04-13 03:08 - 00000000 ____D () C:\Windows\system32\SPReview
2014-04-13 03:07 - 2014-04-13 03:07 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-04-13 03:05 - 2014-04-13 03:05 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-04-13 03:05 - 2014-04-13 03:05 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-04-12 04:43 - 2010-11-20 05:21 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-04-12 04:43 - 2010-11-20 05:21 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-04-12 04:43 - 2010-11-20 05:19 - 00954752 _____ (Microsoft Corporation) C:\Windows\system32\mfc40.dll
2014-04-12 04:43 - 2010-11-20 05:19 - 00954288 _____ (Microsoft Corporation) C:\Windows\system32\mfc40u.dll
2014-04-12 04:43 - 2010-11-20 03:24 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-04-12 04:43 - 2010-11-04 18:58 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-04-12 04:42 - 2010-11-20 05:36 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2014-04-12 04:42 - 2010-11-20 05:36 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\NAPHLPR.DLL
2014-04-12 04:42 - 2010-11-20 05:32 - 05066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2014-04-12 04:42 - 2010-11-20 05:30 - 00245632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00173440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00160128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00153984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00140160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scsiport.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00130432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpio.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00116096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00085376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sbp2port.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00078208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2014-04-12 04:42 - 2010-11-20 05:30 - 00028032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2014-04-12 04:42 - 2010-11-20 05:29 - 02217856 _____ (Microsoft Corporation) C:\Windows\system32\bootres.dll
2014-04-12 04:42 - 2010-11-20 05:29 - 00520064 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-04-12 04:42 - 2010-11-20 05:29 - 00274304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-04-12 04:42 - 2010-11-20 05:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2014-04-12 04:42 - 2010-11-20 05:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-04-12 04:42 - 2010-11-20 05:29 - 00137088 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2014-04-12 04:42 - 2010-11-20 05:29 - 00014208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys
2014-04-12 04:42 - 2010-11-20 05:24 - 00690680 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-04-12 04:42 - 2010-11-20 05:24 - 00508904 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-04-12 04:42 - 2010-11-20 05:24 - 00442720 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-04-12 04:42 - 2010-11-20 05:24 - 00271664 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-04-12 04:42 - 2010-11-20 05:23 - 00144768 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 02983424 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 02755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 02202624 _____ (Microsoft Corporation) C:\Windows\system32\SensorsCpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 02157568 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01712640 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01667584 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01624064 _____ (Microsoft Corporation) C:\Windows\system32\WMPEncEn.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01363456 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01326592 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01227776 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01175040 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01128448 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01115136 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01086976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01063936 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 01003008 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00974336 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\Vault.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00907776 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00782336 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00755200 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00750592 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00750080 _____ (Microsoft Corporation) C:\Windows\system32\sdcpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00738816 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00697344 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\VAN.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00577024 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00521216 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00463360 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00428544 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\wiadefui.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00410624 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00380416 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00372224 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\termmgr.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00352256 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00307712 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\taskbarcpl.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\wavemsp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\upnp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\wmpsrcwp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\twext.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\recovery.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\uxlib.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00111104 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00051200 _____ (Twain Working Group) C:\Windows\twain_32.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\samcli.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\RpcRtRemote.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wtsapi32.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\sisbkup.dll
2014-04-12 04:42 - 2010-11-20 05:21 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 02504192 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2014-04-12 04:42 - 2010-11-20 05:20 - 02494464 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 02130944 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 01750528 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 01644032 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 01414144 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00932352 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00563712 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00395264 _____ (Microsoft Corporation) C:\Windows\system32\prnfldr.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\nshipsec.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL
2014-04-12 04:42 - 2010-11-20 05:20 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\netdiagfx.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\OnLineIDCpl.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\qcap.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\QAGENT.DLL
2014-04-12 04:42 - 2010-11-20 05:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\QSHVHOST.DLL
2014-04-12 04:42 - 2010-11-20 05:20 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\provsvc.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\netjoin.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\prncache.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\nci.dll
2014-04-12 04:42 - 2010-11-20 05:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\ntlanman.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 03207680 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 02151936 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 01493504 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 01066496 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\FirewallControlPanel.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2014-04-12 04:42 - 2010-11-20 05:19 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00732160 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00592384 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00429056 _____ (Microsoft Corporation) C:\Windows\system32\localsec.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\msdri.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\mspbda.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2014-04-12 04:42 - 2010-11-20 05:19 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2014-04-12 04:42 - 2010-11-20 05:19 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\mstask.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\hgprint.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\fde.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
2014-04-12 04:42 - 2010-11-20 05:19 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00093696 _____ (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\fms.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\KMSVC.DLL
2014-04-12 04:42 - 2010-11-20 05:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll
2014-04-12 04:42 - 2010-11-20 05:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 03727872 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 02522624 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01828352 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01555456 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01400320 _____ (Microsoft Corporation) C:\Windows\system32\DxpTaskSync.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01371136 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01334272 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\DiagCpl.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01040384 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 01003520 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00863744 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00854016 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00762880 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00740864 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00685056 _____ (Microsoft Corporation) C:\Windows\system32\dsuiext.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00665600 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00537600 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenterCPL.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-04-12 04:42 - 2010-11-20 05:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCenter.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\biocpl.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\dot3ui.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\azroleui.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\dpx.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00252928 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\defaultlocationcpl.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\activeds.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\dskquoui.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\adsldp.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\dps.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\bcdsrv.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\dot3api.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-04-12 04:42 - 2010-11-20 05:18 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-04-12 04:42 - 2010-11-20 05:17 - 03367424 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 01131008 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 01049600 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00941568 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\FXSSVC.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\slui.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00280576 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\lsm.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\msconfig.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\recdisc.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\net1.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\setupcl.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00098816 _____ (Microsoft) C:\Windows\system32\Robocopy.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\isoburn.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tzutil.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\proquota.exe
2014-04-12 04:42 - 2010-11-20 05:17 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\userinit.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00905216 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00776192 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00668160 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00658944 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\main.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2014-04-12 04:42 - 2010-11-20 05:16 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2014-04-12 04:42 - 2010-11-20 05:16 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00326656 _____ (Microsoft Corporation) C:\Windows\system32\sysdm.cpl
2014-04-12 04:42 - 2010-11-20 05:16 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-04-12 04:42 - 2010-11-20 05:16 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\ssText3d.scr
2014-04-12 04:42 - 2010-11-20 05:16 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2014-04-12 04:42 - 2010-11-20 05:16 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2014-04-12 04:42 - 2010-11-20 05:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv
2014-04-12 04:42 - 2010-11-20 05:16 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-04-12 04:42 - 2010-11-20 05:16 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\WSTPager.ax
2014-04-12 04:42 - 2010-11-20 04:56 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-04-12 04:42 - 2010-11-20 04:54 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-12 04:42 - 2010-11-20 03:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-04-12 04:42 - 2010-11-20 03:22 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2014-04-12 04:42 - 2010-11-20 03:07 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2014-04-12 04:42 - 2010-11-20 03:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\1394ohci.sys
2014-04-12 04:42 - 2010-11-20 02:59 - 00035968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winusb.sys
2014-04-12 04:42 - 2010-11-20 02:50 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-04-12 04:42 - 2010-11-20 01:44 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-04-12 04:42 - 2010-11-20 01:42 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2014-04-12 04:42 - 2010-11-20 01:40 - 00513536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2014-04-12 04:42 - 2010-11-20 01:39 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2014-04-12 04:42 - 2010-11-20 01:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-04-12 04:42 - 2010-11-04 19:20 - 00146852 _____ () C:\Windows\system32\systemsf.ebd
2014-04-12 04:42 - 2010-11-04 19:11 - 00312168 _____ (Microsoft Corporation) C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2014-04-12 04:42 - 2010-11-04 18:58 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2014-04-12 04:42 - 2010-11-04 18:58 - 00155472 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-04-12 04:42 - 2010-11-04 18:58 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-04-12 04:42 - 2010-11-04 18:58 - 00049488 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2014-04-12 04:42 - 2010-11-04 18:53 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2014-04-12 04:42 - 2010-11-04 18:53 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2014-04-12 04:41 - 2010-11-20 05:36 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\NAPCRYPT.DLL
2014-04-12 04:41 - 2010-11-20 05:21 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2014-04-12 04:41 - 2010-11-20 05:21 - 00739328 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2014-04-12 04:41 - 2010-11-20 05:21 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2014-04-12 04:41 - 2010-11-20 05:21 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmnet.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00350720 _____ (Microsoft Corporation) C:\Windows\system32\WPDSp.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00318976 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\sqlcese30.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\unattend.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\wpdwcn.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\remotepg.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\sdrsvc.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\wiavideo.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WPDShServiceObj.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\wmpshell.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\sppinst.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\srvcli.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\QUTIL.DLL
2014-04-12 04:41 - 2010-11-20 05:21 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountControlSettings.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\unimdmat.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\vfwwdm32.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\sppuinotify.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rdpd3d.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\umb.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wkscli.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\WavDest.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\shimgvw.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wiarpc.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\wdiasqmmodule.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\utildll.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\vpnikeapi.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\TRAPI.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\rdprefdrvapi.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\shgina.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\spopk.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\schedcli.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\syssetup.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wshirda.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\shunimpl.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\riched32.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\rdpcfgex.dll
2014-04-12 04:41 - 2010-11-20 05:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-04-12 04:41 - 2010-11-20 05:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 01661440 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\onexui.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceStatus.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00283136 _____ (Microsoft Corporation) C:\Windows\system32\qdv.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceSyncProvider.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\mydocs.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\QSVRMGMT.DLL
2014-04-12 04:41 - 2010-11-20 05:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\olethk32.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\QCLIPROV.DLL
2014-04-12 04:41 - 2010-11-20 05:20 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\napdsnap.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\PrintIsolationProxy.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\profprov.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\netutils.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\perfts.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\nrpsrv.dll
2014-04-12 04:41 - 2010-11-20 05:20 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\iTVData.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\msvfw32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\fphc.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\mciavi32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00082944 _____ (Radius Inc.) C:\Windows\system32\iccvid.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\Mcx2Svc.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\inetmib1.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\luainstall.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\FXSMON.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\mciqtz32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\msdmo.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\iscsium.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\HotStartUserAgent.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\lsmproxy.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2014-04-12 04:41 - 2010-11-20 05:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00402944 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\audiodev.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingFolder.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\dxdiagn.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\avifil32.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\cabinet.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\amstream.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\cca.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\CertPolEng.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dsauth.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\AzSqlExt.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\elsTrans.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\bitsperf.dll
2014-04-12 04:41 - 2010-11-20 05:18 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\C_ISCII.DLL
2014-04-12 04:41 - 2010-11-20 05:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll
2014-04-12 04:41 - 2010-11-20 05:17 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00257536 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgrade.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\iscsicli.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\MdSched.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\mobsync.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\cmstp.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\MuiUnattend.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\djoin.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\repair-bde.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\MultiDigiMon.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\takeown.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\runonce.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\unlodctr.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netcfg.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\LogonUI.exe
2014-04-12 04:41 - 2010-11-20 05:17 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-04-12 04:41 - 2010-11-20 05:16 - 00878592 _____ (Microsoft Corporation) C:\Windows\system32\Bubbles.scr
2014-04-12 04:41 - 2010-11-20 05:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\Mystify.scr
2014-04-12 04:41 - 2010-11-20 05:16 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\Ribbons.scr
2014-04-12 04:41 - 2010-11-20 05:16 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\bitsadmin.exe
2014-04-12 04:41 - 2010-11-20 05:16 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2014-04-12 04:41 - 2010-11-20 05:16 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2014-04-12 04:41 - 2010-11-20 05:16 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\desk.cpl
2014-04-12 04:41 - 2010-11-20 05:16 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax
2014-04-12 04:41 - 2010-11-20 05:16 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\kstvtune.ax
2014-04-12 04:41 - 2010-11-20 05:16 - 00065024 _____ (Microsoft Corporation) C:\Windows\bfsvc.exe
2014-04-12 04:41 - 2010-11-20 05:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ksxbar.ax
2014-04-12 04:41 - 2010-11-20 05:16 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\g711codc.ax
2014-04-12 04:41 - 2010-11-20 05:16 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\vbisurf.ax
2014-04-12 04:41 - 2010-11-20 05:07 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2014-04-12 04:41 - 2010-11-20 05:07 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwizres.dll
2014-04-12 04:41 - 2010-11-20 05:06 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2014-04-12 04:41 - 2010-11-20 05:05 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\RDPENCDD.dll
2014-04-12 04:41 - 2010-11-20 05:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\pifmgr.dll
2014-04-12 04:41 - 2010-11-20 05:00 - 01027584 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2014-04-12 04:41 - 2010-11-20 05:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2014-04-12 04:41 - 2010-11-20 05:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDSG.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdlk41a.dll
2014-04-12 04:41 - 2010-11-20 05:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDCZ1.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUQ.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUF.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDSF.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDPO.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDNEPR.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGR1.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGKL.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUS.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUGHR1.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTURME.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAJIK.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMON.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMAORI.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDLT1.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBULG.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBLR.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-04-12 04:41 - 2010-11-20 05:00 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDGEO.DLL
2014-04-12 04:41 - 2010-11-20 04:56 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\BlbEvents.dll
2014-04-12 04:41 - 2010-11-20 03:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2014-04-12 04:41 - 2010-11-20 03:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RDPCDD.sys
2014-04-12 04:41 - 2010-11-20 03:21 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\RDPREFDD.dll
2014-04-12 04:41 - 2010-11-20 03:07 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2014-04-12 04:41 - 2010-11-20 03:07 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2014-04-12 04:41 - 2010-11-20 03:06 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2014-04-12 04:41 - 2010-11-20 03:06 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2014-04-12 04:41 - 2010-11-20 03:06 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndisuio.sys
2014-04-12 04:41 - 2010-11-20 03:00 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2014-04-12 04:41 - 2010-11-20 03:00 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\umbus.sys
2014-04-12 04:41 - 2010-11-20 03:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys
2014-04-12 04:41 - 2010-11-20 03:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys
2014-04-12 04:41 - 2010-11-20 02:59 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-04-12 04:41 - 2010-11-20 02:59 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2014-04-12 04:41 - 2010-11-20 02:50 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\CompositeBus.sys
2014-04-12 04:41 - 2010-11-20 02:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2014-04-12 04:41 - 2010-11-20 02:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_sd.sys
2014-04-12 04:41 - 2010-11-20 02:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-04-12 04:41 - 2010-11-20 02:24 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2014-04-12 04:41 - 2010-11-20 02:19 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-04-12 04:41 - 2010-11-20 01:47 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpipmi.sys
2014-04-12 04:41 - 2010-11-20 01:42 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-04-12 04:41 - 2010-11-20 01:39 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdi.sys
2014-04-12 04:41 - 2010-11-20 01:38 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2014-04-12 04:41 - 2010-11-19 22:23 - 00053600 _____ () C:\Windows\system32\dosx.exe
2014-04-12 04:41 - 2010-11-09 18:45 - 00010429 _____ () C:\Windows\system32\ScavengeSpace.xml
2014-04-12 04:41 - 2010-11-04 19:20 - 00105559 _____ () C:\Windows\system32\RacRules.xml
2014-04-10 17:31 - 2014-04-23 20:00 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-10 17:30 - 2014-04-10 17:33 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-10 17:30 - 2014-04-10 17:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-10 17:30 - 2014-04-10 17:33 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-10 17:30 - 2014-04-10 17:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-10 17:30 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-10 17:30 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-10 17:30 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-10 13:41 - 2012-02-29 22:46 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-04-10 13:41 - 2012-02-29 22:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-04-10 13:39 - 2014-04-10 13:41 - 00003801 _____ () C:\Windows\IE9_main.log
2014-04-10 13:34 - 2014-04-10 13:34 - 00285768 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2014-04-10 13:33 - 2014-04-10 13:34 - 00288420 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2014-04-10 13:33 - 2014-04-10 13:33 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-04-10 13:28 - 2014-04-23 19:58 - 00000828 _____ () C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2014-04-10 13:28 - 2014-04-13 04:40 - 00152744 _____ (Webroot) C:\Windows\system32\WRusr.dll
2014-04-10 13:28 - 2014-04-13 04:40 - 00116736 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2014-04-10 13:28 - 2014-04-10 14:02 - 00000000 ____D () C:\Program Files\Webroot
2014-04-10 13:28 - 2014-04-10 13:30 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\lptmp532480255
2014-04-10 13:28 - 2014-04-10 13:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2014-04-10 13:27 - 2014-04-23 20:06 - 00000000 ____D () C:\ProgramData\WRData
2014-04-09 04:34 - 2013-03-18 21:48 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-04-09 04:34 - 2013-03-18 19:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-04-09 04:34 - 2013-02-11 20:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-04-09 04:34 - 2012-11-01 22:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-04-09 04:34 - 2011-04-28 19:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-04-09 04:34 - 2011-04-28 19:46 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-04-09 04:34 - 2011-04-28 19:46 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-04-09 04:34 - 2011-03-02 22:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-04-09 04:34 - 2011-03-02 22:38 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-04-09 04:34 - 2011-03-02 22:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-04-09 04:34 - 2010-11-20 04:57 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2014-04-09 04:33 - 2013-02-14 21:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-04-09 04:33 - 2013-02-14 21:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-04-09 04:33 - 2013-02-14 20:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-04-09 04:33 - 2013-01-02 22:04 - 00187752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-04-09 04:33 - 2012-10-31 21:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-04-09 04:33 - 2012-06-05 22:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-04-09 04:33 - 2012-04-27 20:17 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-04-09 04:33 - 2011-08-26 21:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-04-09 04:33 - 2011-08-26 21:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-04-09 04:33 - 2011-08-16 21:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-04-09 04:33 - 2011-08-16 21:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-04-09 04:33 - 2011-07-08 19:30 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-04-09 04:33 - 2011-05-24 03:44 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-04-09 04:33 - 2011-04-26 19:17 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-04-09 04:33 - 2011-04-26 19:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-04-09 04:33 - 2010-11-20 05:18 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cfgmgr32.dll
2014-04-09 04:33 - 2010-11-20 05:16 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-04-09 04:33 - 2010-11-20 05:16 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-04-09 04:33 - 2010-11-20 05:16 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-04-09 04:32 - 2012-09-25 15:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-04-09 04:32 - 2012-08-10 16:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-04-09 04:32 - 2012-07-04 14:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-04-09 04:32 - 2012-07-04 14:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-04-09 04:32 - 2012-07-04 14:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-04-09 04:32 - 2012-05-13 21:33 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-04-09 04:32 - 2012-04-25 21:45 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-04-09 04:32 - 2012-04-25 21:45 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-04-09 04:32 - 2012-04-25 21:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-04-09 04:32 - 2012-03-17 00:27 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-04-09 04:32 - 2011-12-16 00:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-04-09 04:32 - 2011-11-19 07:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-04-09 04:32 - 2011-11-16 22:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-04-09 04:32 - 2011-10-25 21:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-04-09 04:32 - 2011-10-25 21:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-04-09 04:32 - 2011-10-14 22:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-04-09 04:32 - 2011-06-15 01:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll
2014-04-09 04:32 - 2011-06-15 01:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-04-09 04:32 - 2011-06-15 01:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-04-09 04:32 - 2011-06-15 01:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-04-09 04:32 - 2011-06-15 01:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-04-09 04:32 - 2011-05-02 21:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-04-09 04:32 - 2011-03-10 22:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-04-09 04:32 - 2011-03-10 22:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-04-09 04:32 - 2011-02-11 22:35 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-04-09 04:32 - 2010-12-22 22:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-04-09 04:32 - 2010-12-22 22:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-04-09 04:32 - 2010-12-22 22:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-04-09 04:32 - 2010-11-20 05:17 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2014-04-09 04:31 - 2011-04-08 22:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-04-09 04:31 - 2011-02-22 21:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-04-09 04:21 - 2012-02-16 22:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-04-09 04:21 - 2012-02-16 21:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-04-09 04:21 - 2010-11-20 03:21 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdpipe.sys
2014-04-08 23:41 - 2014-04-08 23:41 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\Microsoft Corporation
2014-04-08 22:47 - 2014-04-08 22:47 - 00002701 _____ () C:\Users\ghiagriarte\Downloads\legitcheck.hta
2014-04-08 20:53 - 2014-04-23 19:58 - 00000896 _____ () C:\Windows\setupact.log
2014-04-08 20:53 - 2014-04-14 04:19 - 00417238 _____ () C:\Windows\PFRO.log
2014-04-08 20:53 - 2014-04-08 20:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-08 17:54 - 2014-04-08 17:54 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-08 17:54 - 2014-04-08 17:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-08 17:53 - 2014-04-23 19:59 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-08 17:53 - 2014-04-23 19:10 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-08 17:52 - 2014-04-08 20:36 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\Google
2014-04-08 17:52 - 2014-04-08 17:53 - 00000000 ____D () C:\Program Files\Google
2014-04-08 17:48 - 2014-04-08 23:56 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-08 17:46 - 2014-04-08 17:46 - 00000937 _____ () C:\Users\Public\Desktop\Optimize Your PC.lnk
2014-04-08 17:45 - 2014-04-08 17:45 - 00000000 ____D () C:\Users\ghiagriarte\Downloads\Avast_Free_Antivirus_TSV37PWKR
2014-04-08 17:44 - 2014-04-08 17:44 - 00159144 _____ (Microsoft Corporation) C:\Users\ghiagriarte\Downloads\WindowsActivationUpdate.exe
2014-04-08 17:44 - 2014-04-08 17:44 - 00159144 _____ (Microsoft Corporation) C:\Users\ghiagriarte\Downloads\WindowsActivationUpdate(1).exe
2014-04-08 16:29 - 2014-04-08 16:29 - 00533746 _____ () C:\Users\ghiagriarte\Downloads\A few requests of new KAC members.zip
2014-03-25 13:02 - 2014-03-25 13:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-03-25 13:02 - 2014-03-25 13:02 - 00000000 ____D () C:\Program Files\McAfee Security Scan

==================== One Month Modified Files and Folders =======

2014-04-23 20:06 - 2014-04-23 20:05 - 00019233 _____ () C:\Users\ghiagriarte\Desktop\FRST.txt
2014-04-23 20:06 - 2014-04-10 13:27 - 00000000 ____D () C:\ProgramData\WRData
2014-04-23 20:05 - 2014-04-23 20:05 - 01048576 _____ (Farbar) C:\Users\ghiagriarte\Desktop\FRST.exe
2014-04-23 20:05 - 2014-04-23 20:05 - 00000000 ____D () C:\FRST
2014-04-23 20:05 - 2013-10-28 16:09 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-23 20:02 - 2013-10-28 15:40 - 01496883 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 20:00 - 2014-04-10 17:31 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 19:59 - 2014-04-08 17:53 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-23 19:58 - 2014-04-10 13:28 - 00000828 _____ () C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2014-04-23 19:58 - 2014-04-08 20:53 - 00000896 _____ () C:\Windows\setupact.log
2014-04-23 19:58 - 2009-07-13 21:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-23 19:56 - 2009-07-13 21:34 - 00012688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 19:56 - 2009-07-13 21:34 - 00012688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 19:55 - 2014-04-23 19:45 - 00000000 ____D () C:\AdwCleaner
2014-04-23 19:45 - 2014-04-23 19:45 - 01365865 _____ () C:\Users\ghiagriarte\Desktop\AdwCleaner.exe
2014-04-23 19:19 - 2013-11-01 16:46 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-23 19:10 - 2014-04-08 17:53 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-20 21:43 - 2014-04-20 21:43 - 00018332 _____ () C:\Users\ghiagriarte\Desktop\dds.txt
2014-04-20 21:43 - 2014-04-20 21:43 - 00004914 _____ () C:\Users\ghiagriarte\Desktop\attach.txt
2014-04-20 20:37 - 2014-04-20 20:37 - 00688992 ____R (Swearware) C:\Users\ghiagriarte\Desktop\dds.com
2014-04-20 12:23 - 2014-04-20 12:23 - 00001017 _____ () C:\Users\Public\Desktop\FileASSASSIN.lnk
2014-04-20 12:23 - 2014-04-20 12:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
2014-04-20 12:23 - 2014-04-20 12:23 - 00000000 ____D () C:\Program Files\FileASSASSIN
2014-04-20 12:22 - 2014-04-20 12:22 - 00167034 _____ () C:\Users\ghiagriarte\Desktop\fileassassin-setup-1.06.exe
2014-04-18 03:08 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-04-17 03:48 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\rescache
2014-04-17 03:04 - 2013-10-28 16:17 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-04-15 03:03 - 2014-04-14 03:10 - 00013207 _____ () C:\Windows\IE11_main.log
2014-04-15 03:02 - 2014-04-15 03:02 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-04-15 03:02 - 2014-04-15 03:02 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-04-15 03:02 - 2014-04-15 03:02 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-04-15 03:02 - 2014-04-15 03:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-04-15 03:02 - 2014-04-15 03:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-04-15 03:02 - 2014-04-15 03:02 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-04-14 04:20 - 2009-07-13 21:33 - 00339720 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-14 04:19 - 2014-04-08 20:53 - 00417238 _____ () C:\Windows\PFRO.log
2014-04-14 04:16 - 2009-07-14 00:49 - 00000000 ____D () C:\Program Files\Windows Journal
2014-04-14 04:16 - 2009-07-13 21:52 - 00000000 ____D () C:\Program Files\Windows Defender
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\zh-TW
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\zh-CN
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\sv-SE
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\pt-PT
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\pt-BR
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\nl-NL
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\nb-NO
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\it-IT
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\hu-HU
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\fr-FR
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\fi-FI
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\el-GR
2014-04-14 04:15 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-04-14 03:54 - 2013-10-28 16:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-14 03:21 - 2009-07-13 19:04 - 00000478 _____ () C:\Windows\win.ini
2014-04-14 03:07 - 2014-04-14 03:02 - 00009669 _____ () C:\Windows\IE10_main.log
2014-04-14 03:05 - 2014-04-14 03:05 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-04-14 03:04 - 2014-04-14 03:04 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-04-14 03:04 - 2014-04-14 03:04 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-04-14 03:03 - 2014-04-14 03:03 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-04-13 04:40 - 2014-04-10 13:28 - 00152744 _____ (Webroot) C:\Windows\system32\WRusr.dll
2014-04-13 04:40 - 2014-04-10 13:28 - 00116736 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2014-04-13 03:34 - 2009-07-13 21:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-04-13 03:34 - 2009-07-13 21:52 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-04-13 03:34 - 2009-07-13 21:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-04-13 03:34 - 2009-07-13 21:52 - 00000000 ____D () C:\Program Files\DVD Maker
2014-04-13 03:34 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2014-04-13 03:34 - 2009-07-13 19:37 - 00000000 ____D () C:\Program Files\Common Files\System
2014-04-13 03:15 - 2009-07-13 19:05 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2014-04-13 03:08 - 2014-04-13 03:08 - 00000000 ____D () C:\Windows\system32\SPReview
2014-04-13 03:07 - 2014-04-13 03:07 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-04-13 03:05 - 2014-04-13 03:05 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-04-13 03:05 - 2014-04-13 03:05 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-04-10 17:55 - 2013-10-28 16:35 - 00000000 ____D () C:\Windows\Panther
2014-04-10 17:33 - 2014-04-10 17:30 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-10 17:33 - 2014-04-10 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-10 17:33 - 2014-04-10 17:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-10 17:30 - 2014-04-10 17:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-10 14:57 - 2013-10-28 15:59 - 00001417 _____ () C:\Users\ghiagriarte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-10 14:02 - 2014-04-10 13:28 - 00000000 ____D () C:\Program Files\Webroot
2014-04-10 13:41 - 2014-04-10 13:39 - 00003801 _____ () C:\Windows\IE9_main.log
2014-04-10 13:36 - 2009-07-13 19:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-04-10 13:34 - 2014-04-10 13:34 - 00285768 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2014-04-10 13:34 - 2014-04-10 13:33 - 00288420 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2014-04-10 13:33 - 2014-04-10 13:33 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-04-10 13:30 - 2014-04-10 13:28 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\lptmp532480255
2014-04-10 13:28 - 2014-04-10 13:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2014-04-08 23:56 - 2014-04-08 17:48 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-08 23:41 - 2014-04-08 23:41 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\Microsoft Corporation
2014-04-08 23:21 - 2009-07-13 19:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-04-08 22:47 - 2014-04-08 22:47 - 00002701 _____ () C:\Users\ghiagriarte\Downloads\legitcheck.hta
2014-04-08 20:53 - 2014-04-08 20:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-08 20:53 - 2013-10-28 16:22 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-08 20:36 - 2014-04-08 17:52 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\Google
2014-04-08 17:54 - 2014-04-08 17:54 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-08 17:54 - 2014-04-08 17:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-08 17:53 - 2014-04-08 17:52 - 00000000 ____D () C:\Program Files\Google
2014-04-08 17:46 - 2014-04-08 17:46 - 00000937 _____ () C:\Users\Public\Desktop\Optimize Your PC.lnk
2014-04-08 17:45 - 2014-04-08 17:45 - 00000000 ____D () C:\Users\ghiagriarte\Downloads\Avast_Free_Antivirus_TSV37PWKR
2014-04-08 17:44 - 2014-04-08 17:44 - 00159144 _____ (Microsoft Corporation) C:\Users\ghiagriarte\Downloads\WindowsActivationUpdate.exe
2014-04-08 17:44 - 2014-04-08 17:44 - 00159144 _____ (Microsoft Corporation) C:\Users\ghiagriarte\Downloads\WindowsActivationUpdate(1).exe
2014-04-08 16:29 - 2014-04-08 16:29 - 00533746 _____ () C:\Users\ghiagriarte\Downloads\A few requests of new KAC members.zip
2014-04-03 09:51 - 2014-04-10 17:30 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-10 17:30 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-10 17:30 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2013-10-28 16:23 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-25 13:32 - 2013-10-28 16:12 - 00000000 ____D () C:\Users\ghiagriarte\AppData\Local\Microsoft Help
2014-03-25 13:02 - 2014-03-25 13:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-03-25 13:02 - 2014-03-25 13:02 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-03-25 13:02 - 2013-11-01 16:46 - 00002012 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk

Some content of TEMP:
====================
C:\Users\ghiagriarte\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-19 00:18

==================== End Of Log ============================



#8 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 23 April 2014 - 10:12 PM

Addition.txt log:

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-04-2014
Ran by ghiagriarte at 2014-04-23 20:06:59
Running from C:\Users\ghiagriarte\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

32 Bit HP CIO Components Installer (Version: 15.1.1 - Hewlett-Packard) Hidden
ABBYY FineReader for ScanSnap ™ 4.1 (HKLM\...\{FB410000-0002-0000-0000-074957833700}) (Version: 8.02.650.72520 - ABBYY)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
CardMinder (HKLM\...\{D4F2AFD3-0167-4464-B92F-78AB6DA8A0AA}) (Version: V4.1L50 - PFU)
CardMinder V4.1 (Version: 4.1.50.1 - PFU) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version:  - Microsoft)
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - )
FileASSASSIN (HKLM\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Google Chrome (HKLM\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.)
Google Update Helper (Version: 1.3.23.9 - Google Inc.) Hidden
Malwarebytes Anti-Malware version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.141.11 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Mozilla Firefox 28.0 (x86 en-US) (HKLM\...\Mozilla Firefox 28.0 (x86 en-US)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
ScanSnap (Version: 5.1.60.2 - PFU Limited) Hidden
ScanSnap Manager (HKLM\...\{DBCDB997-EEEB-4BE9-BAFF-26B4094DBDE6}) (Version: V5.1L60 - PFU)
ScanSnap Organizer (HKLM\...\{E58F3B88-3B3E-4F85-9323-04789D979C15}) (Version: V4.1L60 - PFU)
ScanSnap Organizer (Version: 4.1.60.2 - PFU LIMITED) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version:  - Microsoft) Hidden
Skype Web Plugin (HKLM\...\{B51DD93B-3CB5-4D9D-BFF2-FD19DBBBFD9A}) (Version: 2.9.13008.18866 - Skype Technologies S.A.)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{460FF681-BC66-4C38-99DF-7012E03F1EBA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{DCE104A1-1875-4469-A83D-A5BFA6C4640F}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{334AA0A1-2BB1-4D74-B66A-2B2C4D9C2C87}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version:  - Microsoft)
Webroot SecureAnywhere (HKLM\...\WRUNINST) (Version: 8.0.4.70 - Webroot)

==================== Restore Points  =========================


==================== Hosts content: ==========================

2009-07-13 19:04 - 2009-06-10 14:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {48236D1E-9272-4AAF-9E40-3AA85B87586B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated)
Task: {7C6903FB-DA66-4628-8CD6-B796A77553AA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-08] (Google Inc.)
Task: {E9DC00A2-7C03-4D42-93D7-263E13D59E46} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-08] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-03-19 18:10 - 2008-11-12 15:32 - 00014848 _____ () C:\Program Files\PFU\ScanSnap\CardMinder\CardPath.dll
2014-03-19 18:05 - 2012-01-18 16:35 - 00385024 _____ () C:\Program Files\PFU\ScanSnap\Driver\PfuSsConfig.dll
2014-03-19 18:06 - 2011-12-14 21:49 - 00233472 _____ () C:\Program Files\PFU\ScanSnap\Driver\PfuSsExtention.dll
2014-03-19 18:06 - 2003-03-26 18:46 - 00135168 _____ () C:\Program Files\PFU\ScanSnap\Driver\PfuSsImgIO.dll
2014-03-19 18:06 - 2010-08-24 16:56 - 00167936 _____ () C:\Program Files\PFU\ScanSnap\Driver\SSsltsa.dll
2014-03-19 13:31 - 2014-03-19 13:31 - 03642480 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2014-04-10 13:30 - 2014-04-10 13:30 - 01013248 _____ () C:\Users\ghiagriarte\AppData\Roaming\Mozilla\Firefox\Profiles\zgd2dou1.default\extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda}\platform\WINNT_x86-msvc\components\wrxpcom.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"

==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/23/2014 05:26:13 PM) (Source: Software Protection Platform Service) (User: )
Description: Acquisition of End User License failed. hr=0xC004C008
Sku Id=2e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 05:26:13 PM) (Source: Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0xC004C008

Error: (04/23/2014 01:26:13 PM) (Source: Software Protection Platform Service) (User: )
Description: Acquisition of End User License failed. hr=0xC004C008
Sku Id=2e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 01:26:13 PM) (Source: Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0xC004C008

Error: (04/23/2014 09:26:13 AM) (Source: Software Protection Platform Service) (User: )
Description: Acquisition of End User License failed. hr=0xC004C008
Sku Id=2e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 09:26:13 AM) (Source: Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0xC004C008

Error: (04/23/2014 05:26:16 AM) (Source: Software Protection Platform Service) (User: )
Description: Acquisition of End User License failed. hr=0xC004C008
Sku Id=2e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 05:26:16 AM) (Source: Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0xC004C008

Error: (04/23/2014 01:26:13 AM) (Source: Software Protection Platform Service) (User: )
Description: Acquisition of End User License failed. hr=0xC004C008
Sku Id=2e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 01:26:13 AM) (Source: Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0xC004C008


System errors:
=============
Error: (04/23/2014 07:58:00 PM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

Error: (04/17/2014 03:10:01 AM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

Error: (04/16/2014 03:04:39 AM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

Error: (04/15/2014 03:11:55 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 10 for Windows 7 (KB2909210).

Error: (04/15/2014 03:08:21 AM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

Error: (04/14/2014 04:19:53 AM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

Error: (04/14/2014 03:26:52 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Update for Windows 7 (KB2834140).

Error: (04/14/2014 03:11:29 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7.

Error: (04/13/2014 03:37:18 AM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.

Error: (04/12/2014 03:17:00 AM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.


Microsoft Office Sessions:
=========================
Error: (04/23/2014 05:26:13 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C0082e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 05:26:13 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C00800010001(0x00000000, 17:26:13:782 - http://go.microsoft.com/fwlink/?LinkID=88341)
00020001(0x00000000, 17:26:13:783)
00030001(0x00000000, 17:26:13:783 - http://go.microsoft.com)
00030002(0x00000000, 17:26:13:783 - 1)
00020005(0x00000000, 17:26:13:783 - 0)
0002000C(0x00000000, 17:26:13:830 - 302)
0002000E(0x00000000, 17:26:13:830 - https://activation.sls.microsoft.com/sllicensing/SLLicense.asmx)
00020001(0x00000000, 17:26:13:830)
00030001(0x00000000, 17:26:13:831 - https://activation.sls.microsoft.com)
00030002(0x00000000, 17:26:13:831 - 1)
00020005(0x00000000, 17:26:13:831 - 0)
0002000C(0x00000000, 17:26:13:982 - 500)
00010002(0x8004FC01, 17:26:13:983 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C008</HRESULT><Messages><Message>113 (Activation) - [PA Maximum unlock exceeded.  ---&gt; Maximum unlock exceeded]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 17:26:13:983)

Error: (04/23/2014 01:26:13 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C0082e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 01:26:13 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C00800010001(0x00000000, 13:26:13:584 - http://go.microsoft.com/fwlink/?LinkID=88341)
00020001(0x00000000, 13:26:13:585)
00030001(0x00000000, 13:26:13:585 - http://go.microsoft.com)
00030002(0x00000000, 13:26:13:585 - 1)
00020005(0x00000000, 13:26:13:585 - 0)
0002000C(0x00000000, 13:26:13:623 - 302)
0002000E(0x00000000, 13:26:13:623 - https://activation.sls.microsoft.com/sllicensing/SLLicense.asmx)
00020001(0x00000000, 13:26:13:623)
00030001(0x00000000, 13:26:13:623 - https://activation.sls.microsoft.com)
00030002(0x00000000, 13:26:13:623 - 1)
00020005(0x00000000, 13:26:13:623 - 0)
0002000C(0x00000000, 13:26:13:775 - 500)
00010002(0x8004FC01, 13:26:13:776 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C008</HRESULT><Messages><Message>113 (Activation) - [PA Maximum unlock exceeded.  ---&gt; Maximum unlock exceeded]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 13:26:13:776)

Error: (04/23/2014 09:26:13 AM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C0082e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 09:26:13 AM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C00800010001(0x00000000, 09:26:13:455 - http://go.microsoft.com/fwlink/?LinkID=88341)
00020001(0x00000000, 09:26:13:457)
00030001(0x00000000, 09:26:13:457 - http://go.microsoft.com)
00030002(0x00000000, 09:26:13:457 - 1)
00020005(0x00000000, 09:26:13:457 - 0)
0002000C(0x00000000, 09:26:13:508 - 302)
0002000E(0x00000000, 09:26:13:508 - https://activation.sls.microsoft.com/sllicensing/SLLicense.asmx)
00020001(0x00000000, 09:26:13:508)
00030001(0x00000000, 09:26:13:509 - https://activation.sls.microsoft.com)
00030002(0x00000000, 09:26:13:509 - 1)
00020005(0x00000000, 09:26:13:509 - 0)
0002000C(0x00000000, 09:26:13:644 - 500)
00010002(0x8004FC01, 09:26:13:645 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C008</HRESULT><Messages><Message>113 (Activation) - [PA Maximum unlock exceeded.  ---&gt; Maximum unlock exceeded]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 09:26:13:645)

Error: (04/23/2014 05:26:16 AM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C0082e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 05:26:16 AM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C00800010001(0x00000000, 05:26:16:269 - http://go.microsoft.com/fwlink/?LinkID=88341)
00020001(0x00000000, 05:26:16:293)
00030001(0x00000000, 05:26:16:293 - http://go.microsoft.com)
00030002(0x00000000, 05:26:16:293 - 1)
00020005(0x00000000, 05:26:16:293 - 0)
0002000C(0x00000000, 05:26:16:334 - 302)
0002000E(0x00000000, 05:26:16:334 - https://activation.sls.microsoft.com/sllicensing/SLLicense.asmx)
00020001(0x00000000, 05:26:16:334)
00030001(0x00000000, 05:26:16:334 - https://activation.sls.microsoft.com)
00030002(0x00000000, 05:26:16:334 - 1)
00020005(0x00000000, 05:26:16:334 - 0)
0002000C(0x00000000, 05:26:16:462 - 500)
00010002(0x8004FC01, 05:26:16:463 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C008</HRESULT><Messages><Message>113 (Activation) - [PA Maximum unlock exceeded.  ---&gt; Maximum unlock exceeded]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 05:26:16:463)

Error: (04/23/2014 01:26:13 AM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C0082e7d060d-4714-40f2-9896-1e4f15b612ad

Error: (04/23/2014 01:26:13 AM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C00800010001(0x00000000, 01:26:13:087 - http://go.microsoft.com/fwlink/?LinkID=88341)
00020001(0x00000000, 01:26:13:088)
00030001(0x00000000, 01:26:13:088 - http://go.microsoft.com)
00030002(0x00000000, 01:26:13:088 - 1)
00020005(0x00000000, 01:26:13:088 - 0)
0002000C(0x00000000, 01:26:13:141 - 302)
0002000E(0x00000000, 01:26:13:141 - https://activation.sls.microsoft.com/sllicensing/SLLicense.asmx)
00020001(0x00000000, 01:26:13:141)
00030001(0x00000000, 01:26:13:141 - https://activation.sls.microsoft.com)
00030002(0x00000000, 01:26:13:141 - 1)
00020005(0x00000000, 01:26:13:141 - 0)
0002000C(0x00000000, 01:26:13:268 - 500)
00010002(0x8004FC01, 01:26:13:268 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C008</HRESULT><Messages><Message>113 (Activation) - [PA Maximum unlock exceeded.  ---&gt; Maximum unlock exceeded]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 01:26:13:268)


==================== Memory info ===========================

Percentage of memory in use: 49%
Total physical RAM: 2045.61 MB
Available physical RAM: 1042.86 MB
Total Pagefile: 4091.23 MB
Available Pagefile: 2951.19 MB
Total Virtual: 2047.88 MB
Available Virtual: 1902.97 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:74.44 GB) (Free:16.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: 41AB2316)
Partition 1: (Not Active) - (Size=63 MB) - (Type=DE)
Partition 2: (Active) - (Size=74 GB) - (Type=07 NTFS)

==================== End Of Log ============================



#9 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 24 April 2014 - 10:05 AM

I forgot to turn off the Malwarebytes which ran a scan early this morning.  Didn't detect anything.



#10 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:07:52 AM

Posted 24 April 2014 - 06:49 PM

1.

Download attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

Attached File  fixlist.txt   156bytes   1 downloads

 

 

2.

 ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go >>HERE<< then click on: ESET1st.jpg

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on the ESETexe.jpg icon to install.

    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: ESETsave.jpg
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats IS checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: EOLS4.gif
    (Selecting Uninstall application on close if you so wish)

 

 

 

Things to include in your next reply::

Fixlog.txt

Eset log

How is the machine running now?


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#11 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 24 April 2014 - 08:17 PM

Log below after running FRST, then Fixlist.txt

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 24-04-2014
Ran by ghiagriarte at 2014-04-24 18:16:23 Run:1
Running from C:\Users\ghiagriarte\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
2014-04-08 17:46 - 2014-04-08 17:46 - 00000937 _____ () C:\Users\Public\Desktop\Optimize Your PC.lnk
C:\Users\ghiagriarte\AppData\Local\Temp\Quarantine.exe
*****************

C:\Users\Public\Desktop\Optimize Your PC.lnk => Moved successfully.
C:\Users\ghiagriarte\AppData\Local\Temp\Quarantine.exe => Moved successfully.

==== End of Fixlog ====



#12 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:07:52 AM

Posted 24 April 2014 - 08:31 PM

Ok, now we need the Eset log. :thumbup2:


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#13 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 24 April 2014 - 09:11 PM

Eset log below.  It found 1 threat.

 

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=ab9ddd5a6dda1648b85d3a1ea9207635
# engine=18024
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-04-25 02:08:16
# local_time=2014-04-24 07:08:16 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 0 149936487 0 0
# scanned=53351
# found=1
# cleaned=0
# scan_time=1700
sh=8B3287E8852150D8BE757FA7400AC43FB7EA9D84 ft=1 fh=da79998d3678275e vn="multiple threats" ac=I fn="C:\Users\ghiagriarte\AppData\Local\Temp\{EEAA55E1-01D0-49C6-8DB3-F10655B88F69}\setup.exe"



#14 gigi8967

gigi8967
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 24 April 2014 - 09:15 PM

Fireman4it,

I don't see a 'PC Optimizer' shortcut on my desktop anymore!  Let me know if I'm all clean.  I'm assuming I can enable the anti-virus, anti-malware software after you've given me the all clean signal.



#15 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:07:52 AM

Posted 24 April 2014 - 09:27 PM

Hello, gigi8967

.
Congratulations! You now appear clean! :cool:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

We Need to Clean Up Our Mess

 

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.

 

 

  • Download OTC by OldTimer and save it to your desktop.
  • Double click OTC_Icon.jpg icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big CleanUp.jpg button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.


Now you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Start > Run and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links: Create a New Restore Point in Vista or Windows 7 and Disk Cleanup in Vista.

 

 

 

One of the most common questions found when cleaning malware is "how did my machine get infected?"

There are a variety of reasons, but the most common ones are that you are not practicing Safe Internet, you are not running the proper security software or that your computer's security settings are set too low.

Below I have outlined a series of categories that outline how you can increase the security of your computer to help reduce the chance of being infected again in the future.

Do not use P2P programs
Peer-to-peer or file-sharing programs (such as uTorrent, Limewire and Bitorrent) are probably the primary route of infection nowadays. These programs allow file sharing between users as the name(s) suggest.  It is almost impossible to know whether the file you’re downloading through P2P programs is safe.

It is therefore possible to be infected by downloading infected files via peer-to-peer programs and so I recommend that you do not use these programs. Should you wish to use them, they must be used with extreme care. Some further reading on this subject, along with included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."

In addition, P2P programs facilitate cyber crime and help distribute pirated software, movies and other illegal material.

Practice Safe Internet
Another one of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on.  Whether these things are files or sites it doesn't really matter.  If something is out to get you, and you click on it, it most likely will. 

Below are a list of simple precautions to take to keep your computer clean and running securely:

  • If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that.  Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.
  • If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean.  For the casual computer user, you will almost never receive a valid attachment of this type.
  • If you receive an attachment from someone you know, and it looks suspicious, then it probably is.  The email could be from someone you know who is themselves infected with malware which is trying to infect everyone in their address book. A key thing to look out for here is: does the email sound as though it’s from the person you know? Often, the email may simply have a web link or a “Run this file to make your PC run fast” message in it.
  • If you are browsing the Internet and a popup appears saying that you are infected, ignore it!.  These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software.  For an example of these types of pop-ups, or Foistware, you should read this article: Foistware, And how to avoid it.
    There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. Removal instructions for a lot of these "rogues" can be found here.
  • Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message  or alert.  When you click on them, though, they instead bring you to another site that is trying to push a product on you, or will download a file to your PC without your knowledge.  You can check to see if it's a real alert by right-clicking on the window.  If there is a menu that comes up saying Add to Favorites... you know it's a fake. DO NOT click on these windows, instead close them by finding the open window on your http://en.wikipedia.org/wiki/Taskbar#Screenshots '>Taskbar, right click and chose close.
  • Do not visit pornographic websites.  I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites.  I am not saying all adult sites do this, but a lot do, as this can often form part of their funding.
  • When using an Instant Messaging program be cautious about clicking on links people send to you.  It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection.  Instead when you receive a message that contains a link you should message back to the person asking if it is legit.
  • Stay away from Warez and Crack sites! As with Peer-2-Peer programs, in addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.
  • Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download files from a site, and are not sure if they are legitimate, you can use tools such as BitDefender Traffic Light, Norton Safe Web, or McAfee SiteAdvisor to look up info on the site and stay protected against malicious sites. Please be sure to only choose and install one of those tool bars.
  • DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money.  By reading the agreement there is a good chance you can spot this and not install the software.
    Sometimes even legitimate programs will try to bundle extra, unwanted, software with the program you want - this is done to raise money for the program. Be sure to untick any boxes which may indicate that other programs will be downloaded.


Keep Windows up-to-date
Microsoft continually releases security and stability updates for its supported operating systems and you should always apply these to help keep your PC secure.

  • Windows XP users
    You should visit Windows Update to check for the latest updates to your system. The latest service pack (SP3) can be obtained directly from Microsoft here.
  • Windows Vista users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP2) can be obtained directly from Microsoft here.
  • Windows 7 users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP1) can be obtained directly from Microsoft here



Keep your browser secure
Most modern browsers have come on in leaps and bounds with their inbuilt, default security. The best way to keep your browser secure nowadays is simply to keep it up-to-date.

The latest versions of the three common browsers can be found below:


Use an AntiVirus Software
It is very important that your computer has an up-to-date anti-virus software on it which has a real-time agent running.  This alone can save you a lot of trouble with malware in the future. 
See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources, a couple of free Anti-Virus programs you may be interested in are Microsoft Security Essentials and Avast.

It is imperative that you update your Antivirus software at least once a week (even more if you wish).  If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.  If you use a commercial antivirus program you must make sure you keep renewing your subscription.  Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer.  Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.

All versions of Windows starting from XP have an in-built firewall. With Windows XP this firewall will protect you from incoming traffic (i.e. hackers). Starting with Windows Vista, the firewall was beefed up to also protect you against outgoing traffic (i.e. malicious programs installed on your machine should be blocked from sending data, such as your bank details and passwords, out).

In addition, if you connect to the internet via a router, this will normally have a firewall in-built.

Some people will recommend installing a different firewall (instead of the Windows’ built one), this is personal choice, but the message is to definitely have one! For a tutorial on Firewalls and a listing of some available ones see this link: Understanding and Using Firewalls

Install an Anti-Malware program
Recommended, and free, Anti-Malware programs are Malwarebytes Anti-Malware and SuperAntiSpyware.

You should regularly (perhaps once a week) scan your computer with an Anti-Malware program just as you would with an antivirus software.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you.  Therefore, it is very important to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities (such as Adobe Reader and Java).  You can check these by visiting Secunia Software Inspector.

Follow this list and your potential for being infected again will reduce dramatically.


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users