Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-11-2014
- Ran by Erich (administrator) on ERICH-PC on 04-11-2014 22:25:11
- Running from C:\Users\Erich\Desktop
- Loaded Profile: Erich (Available profiles: Erich & Katarinna)
- Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
- Internet Explorer Version 11
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
- (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
- (Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
- (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
- (LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (Microsoft Corporation) C:\Windows\System32\msiexec.exe
- (Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
- () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
- () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
- (Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
- (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
- (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
- (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler64.exe
- (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
- (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe
- (Intel Corporation) C:\Windows\System32\igfxtray.exe
- (Intel Corporation) C:\Windows\System32\hkcmd.exe
- (Intel Corporation) C:\Windows\System32\igfxpers.exe
- (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
- (Safer Networking Limited) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
- (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
- (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
- (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
- (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
- (Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
- (RealNetworks, Inc.) C:\Program Files (x86)\real\realplayer\Update\realsched.exe
- (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
- (Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
- (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
- (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
- (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
- (Microsoft Corporation) C:\Windows\System32\taskmgr.exe
- (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
- (Microsoft Corporation) C:\Windows\System32\dllhost.exe
- (Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
- (Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
- ==================== Registry (Whitelisted) ==================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2046760 2010-02-05] (Synaptics Incorporated)
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6160928 2010-01-29] (Realtek Semiconductor)
- HKLM\...\Run: [RtkOSD] => C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe [995840 2010-01-12] (Realtek Semiconductor Corp.)
- HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1571144 2012-11-12] (Bitdefender)
- HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-28] (Nullsoft, Inc.)
- HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [268640 2011-11-12] (LeapFrog Enterprises, Inc.)
- HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [Intuit SyncManager] => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [2771832 2012-12-07] (Intuit Inc. All rights reserved.)
- HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
- HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-10-18] (RealNetworks, Inc.)
- HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
- HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
- HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1056976 2014-06-27] (Carbonite, Inc.)
- Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2144088 2009-01-26] (Safer Networking Limited)
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1326408 2013-11-15] (Apple Inc.)
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...\Policies\system: [LogonHoursAction] 2
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
- HKU\S-1-5-18\...\Policies\system: [LogonHoursAction] 2
- HKU\S-1-5-18\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
- Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
- ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
- ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
- ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
- ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
- ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
- ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
- ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
- GroupPolicyUsers\S-1-5-21-103344571-3548091809-1978653994-1001\User: Group Policy restriction detected <======= ATTENTION
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
- HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
- HKU\S-1-5-21-103344571-3548091809-1978653994-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
- StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
- SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKLM - {D977D65C-56D1-4FAA-B238-AB00DD61CC0F} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
- SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKLM-x32 - {09971cee-01b8-42bc-9d91-456b1faad6be} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=CDxdm150YYus&ptnrS=CDxdm150YYus&si=i44&ptb=59C594D3-82FF-451D-AA15-42FE1B130574&ind=2011092923&n=77ded7bb&psa=&st=sb&searchfor={searchTerms}
- SearchScopes: HKLM-x32 - {44f44034-6036-4f06-9336-74ec4620edab} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=RGxdm002YYus&ptb=F4DC894F-9AC3-4DC8-9902-55A460C7ECFA&ind=2011052316&ptnrS=RGxdm002YYus&si=&n=77de391c&psa=&st=sb&searchfor={searchTerms}
- SearchScopes: HKLM-x32 - {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=RGxdm112YYUS&ptnrS=RGxdm112YYUS&ptb=t5qnqmdHIpMVQCKlcVPuKQ&ind=2011010520&n=77dd95d8&psa=&st=sb&searchfor={searchTerms}
- SearchScopes: HKLM-x32 - {D977D65C-56D1-4FAA-B238-AB00DD61CC0F} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
- SearchScopes: HKCU - DefaultScope {BD4E9F9C-4BAF-49A3-B71F-ED63F47BFE69} URL = https://www.google.com/search?q={searchTerms}
- SearchScopes: HKCU - {BD4E9F9C-4BAF-49A3-B71F-ED63F47BFE69} URL = https://www.google.com/search?q={searchTerms}
- SearchScopes: HKCU - {D977D65C-56D1-4FAA-B238-AB00DD61CC0F} URL =
- BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
- BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
- BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
- BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
- BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
- BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
- BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
- BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
- BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
- Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
- DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
- DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
- DPF: HKLM-x32 {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} http://archives.gametap.com/static/cab_headless/GameTapWebPlayer.cab
- DPF: HKLM-x32 {B5B8593C-89BC-44A7-BCE3-32FE4FED7C5C} http://na.secureserver.net/starfieldinstall.exe
- DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
- DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
- Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - No File
- Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
- Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File
- Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
- Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
- Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
- Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
- Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
- Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
- Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75 192.168.1.1
- FireFox:
- ========
- FF ProfilePath: C:\Users\Erich\AppData\Roaming\Mozilla\Firefox\Profiles\289w0zz8.default
- FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
- FF Plugin: @microsoft.com/GENUINE -> disabled No File
- FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
- FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
- FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
- FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
- FF Plugin-x32: @arcanum.hu/AAGISView Link;version=1 -> C:\Program Files (x86)\Arcanum Adatbázis\AAGISView\NPAAGVL.DLL ( )
- FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
- FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
- FF Plugin-x32: @java.com/DTPlugin -> C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll (Sun Microsystems, Inc.)
- FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
- FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
- FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
- FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
- FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
- FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
- FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
- FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Erich\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Erich\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Erich\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
- FF user.js: detected! => C:\Users\Erich\AppData\Roaming\Mozilla\Firefox\Profiles\289w0zz8.default\user.js
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
- FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
- FF SearchPlugin: C:\Users\Erich\AppData\Roaming\Mozilla\Firefox\Profiles\289w0zz8.default\searchplugins\askcom.xml
- FF SearchPlugin: C:\Users\Erich\AppData\Roaming\Mozilla\Firefox\Profiles\289w0zz8.default\searchplugins\safeguard-secure-search.xml
- FF Extension: TSAF.TokenPwdReset - C:\Users\Erich\AppData\Roaming\Mozilla\Firefox\Profiles\289w0zz8.default\Extensions\{CC867A61-A2D8-B4F7-B485-7376BD23B2C7} [2014-03-31]
- FF Extension: GameTap - C:\Program Files (x86)\Mozilla Firefox\extensions\GameTapPlayer@gametap.com [2011-01-12]
- FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-02-13]
- FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} [2011-06-05]
- FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
- FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-18]
- Chrome:
- =======
- CHR HomePage: Default -> hxxp://www.delta-search.com/?babsrc=HP_ss&mntrId=B0AE70F1A1EE333F&affID=120684&tsp=5025
- CHR StartupUrls: Default -> ""
- CHR DefaultSearchKeyword: Default -> delta-search.com_
- CHR DefaultSearchURL: Default -> http://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B0AE70F1A1EE333F&affID=120684&tsp=5025
- CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
- CHR Profile: C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default
- CHR Extension: (Google Docs) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-08]
- CHR Extension: (Google Drive) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-08]
- CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-08]
- CHR Extension: (YouTube) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-08]
- CHR Extension: (Google Search) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-08]
- CHR Extension: (RealDownloader) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-10-18]
- CHR Extension: (Google Wallet) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-03]
- CHR Extension: (Gmail) - C:\Users\Erich\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-08]
- CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
- CHR StartMenuInternet: Google Chrome - C:\Users\Erich\AppData\Local\Google\Chrome\Application\chrome.exe
- ==================== Services (Whitelisted) =================
- (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
- R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
- R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
- R2 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2013-02-01] (Intuit) [File not signed]
- S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2009-07-23] (Intuit Inc.) [File not signed]
- R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
- R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] ()
- S2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-08-07] (Bitdefender)
- S4 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-11-11] (Bitdefender)
- ==================== Drivers (Whitelisted) ====================
- (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
- U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
- R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [705552 2012-10-24] (BitDefender)
- R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [258736 2011-11-25] (BitDefender)
- S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [587024 2012-10-24] (BitDefender)
- R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
- U5 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
- S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [24576 2011-11-12] (LeapFrog)
- R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [138232 2012-04-11] (BitDefender LLC)
- S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.)
- R1 SbFw; C:\Windows\System32\drivers\SbFw.sys [253528 2011-04-05] (Sunbelt Software, Inc.)
- S3 SBFWIMCL; C:\Windows\System32\DRIVERS\sbfwim.sys [84568 2011-02-08] (Sunbelt Software, Inc.)
- R3 SBFWIMCLMP; C:\Windows\System32\DRIVERS\SBFWIM.sys [84568 2011-02-08] (Sunbelt Software, Inc.)
- S3 sbhips; C:\Windows\System32\drivers\sbhips.sys [60504 2011-04-05] (Sunbelt Software, Inc.)
- R1 SbTis; C:\Windows\System32\drivers\sbtis.sys [94296 2011-04-05] (Sunbelt Software, Inc.)
- R2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [329800 2012-04-24] (BitDefender S.R.L.)
- S3 catchme; \??\C:\ComboFix\catchme.sys [X]
- S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]
- ==================== NetSvcs (Whitelisted) ===================
- (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
- ==================== One Month Created Files and Folders ========
- (If an entry is included in the fixlist, the file\folder will be moved.)
- 2014-11-04 22:25 - 2014-11-04 22:26 - 00027143 _____ () C:\Users\Erich\Desktop\FRST.txt
- 2014-11-04 22:25 - 2014-11-04 22:25 - 00000000 ____D () C:\FRST
- 2014-11-04 22:23 - 2014-11-04 22:17 - 02114560 _____ (Farbar) C:\Users\Erich\Desktop\FRST64.exe
- 2014-11-04 22:22 - 2014-11-04 22:22 - 00003340 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-103344571-3548091809-1978653994-1000
- 2014-11-04 22:22 - 2014-11-04 22:22 - 00003206 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-103344571-3548091809-1978653994-1000
- 2014-11-04 21:50 - 2014-11-04 21:50 - 00077412 _____ () C:\ProgramData\1415155797.bdinstall.bin
- 2014-11-04 20:33 - 2014-11-04 20:33 - 00000081 _____ () C:\Users\Erich\AppData\Local\svcxdcl32.dat
- 2014-11-04 20:31 - 2014-11-04 20:33 - 00225792 _____ (Emurasoft, Inc.) C:\Users\Erich\AppData\Local\svcxdcl32.exe
- 2014-11-04 20:31 - 2014-11-04 20:31 - 00023552 _____ () C:\Users\Erich\AppData\Local\ivijios.dll
- 2014-11-04 20:31 - 2014-11-04 20:31 - 00000000 ____D () C:\ProgramData\CaxsEtemd
- 2014-11-04 20:30 - 2014-11-04 20:31 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
- 2014-11-04 20:30 - 2014-11-04 20:30 - 00000000 ____D () C:\ProgramData\NumeqImcuc
- 2014-11-04 18:10 - 2014-11-04 18:10 - 00000000 _____ () C:\Windows\SysWOW64\sho12E4.tmp
- 2014-11-04 17:45 - 2014-11-04 17:46 - 00907144 _____ () C:\Windows\Minidump\110414-26067-01.dmp
- 2014-10-30 05:07 - 2014-10-30 05:07 - 00894960 _____ () C:\Windows\Minidump\103014-42463-01.dmp
- 2014-10-29 17:03 - 2014-10-29 17:03 - 00362198 _____ () C:\ProgramData\1414619810.bdinstall.bin
- 2014-10-29 16:59 - 2014-10-29 16:59 - 00000684 ____H () C:\bdr-cf01
- 2014-10-29 16:59 - 2014-10-29 16:59 - 00000000 ____D () C:\Users\Erich\AppData\Roaming\Bitdefender
- 2014-10-29 16:59 - 2014-10-29 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2013
- 2014-10-29 16:59 - 2013-11-04 14:47 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin.dll
- 2014-10-29 16:59 - 2013-11-04 14:47 - 00074512 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
- 2014-10-29 16:59 - 2013-11-04 14:46 - 00034384 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuh.dll
- 2014-10-29 16:58 - 2014-10-29 16:59 - 00009216 ____H () C:\bdr-ld01.mbr
- 2014-10-29 16:58 - 2013-08-13 11:38 - 03271472 ____H () C:\bdr-bz01
- 2014-10-29 16:57 - 2014-10-29 16:59 - 00253404 ____H () C:\bdr-ld01
- 2014-10-29 16:57 - 2013-09-24 14:38 - 46879860 ____H () C:\bdr-im01.gz
- 2014-10-29 16:57 - 2012-04-24 14:28 - 00329800 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
- 2014-10-29 16:57 - 2012-04-11 16:03 - 00138232 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
- 2014-10-29 16:49 - 2014-10-29 16:49 - 00000000 _____ () C:\Windows\SysWOW64\sho78CD.tmp
- 2014-10-29 11:34 - 2014-10-29 11:34 - 00262144 _____ () C:\Windows\Minidump\102914-30451-01.dmp
- 2014-10-28 20:45 - 2014-10-28 20:45 - 00025821 _____ () C:\ComboFix.txt
- 2014-10-28 20:07 - 2011-06-26 01:45 - 00256000 _____ () C:\Windows\PEV.exe
- 2014-10-28 20:07 - 2010-11-07 12:20 - 00208896 _____ () C:\Windows\MBR.exe
- 2014-10-28 20:07 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
- 2014-10-28 20:07 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
- 2014-10-28 20:07 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
- 2014-10-28 20:07 - 2000-08-30 19:00 - 00098816 _____ () C:\Windows\sed.exe
- 2014-10-28 20:07 - 2000-08-30 19:00 - 00080412 _____ () C:\Windows\grep.exe
- 2014-10-28 20:07 - 2000-08-30 19:00 - 00068096 _____ () C:\Windows\zip.exe
- 2014-10-28 20:06 - 2014-10-28 20:45 - 00000000 ____D () C:\Qoobox
- 2014-10-28 20:06 - 2014-10-28 20:36 - 00000000 ____D () C:\Windows\erdnt
- 2014-10-28 13:31 - 2014-10-28 13:31 - 00912624 _____ () C:\Windows\Minidump\102814-23166-01.dmp
- 2014-10-28 12:17 - 2014-10-28 12:17 - 00000000 _____ () C:\autoexec.bat
- 2014-10-28 06:58 - 2014-10-28 15:57 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
- 2014-10-28 06:58 - 2014-10-28 06:58 - 00000000 ____D () C:\Program Files\Enigma Software Group
- 2014-10-28 06:38 - 2011-06-05 20:51 - 00157472 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
- 2014-10-28 06:38 - 2011-06-05 20:51 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
- 2014-10-28 06:38 - 2011-06-05 20:51 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
- 2014-10-26 06:28 - 2014-10-26 21:00 - 00000000 ____D () C:\Photos Hold
- 2014-10-23 20:30 - 2014-10-23 20:30 - 00262144 _____ () C:\Windows\Minidump\102314-53399-01.dmp
- 2014-10-19 12:44 - 2014-10-19 12:44 - 00869264 _____ () C:\Windows\Minidump\101914-99357-01.dmp
- 2014-10-17 12:11 - 2014-10-17 12:11 - 00262144 _____ () C:\Windows\Minidump\101714-25022-01.dmp
- 2014-10-17 12:07 - 2014-10-17 12:07 - 00262144 _____ () C:\Windows\Minidump\101714-26395-01.dmp
- 2014-10-16 19:53 - 2014-10-16 19:55 - 00000000 ____D () C:\0fae4ee31701a5a2895fd1a393c800a7
- 2014-10-15 07:23 - 2014-09-28 19:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
- 2014-10-15 07:23 - 2014-07-06 21:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
- 2014-10-15 07:23 - 2014-07-06 21:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
- 2014-10-15 07:23 - 2014-07-06 21:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
- 2014-10-15 07:23 - 2014-07-06 21:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
- 2014-10-15 07:23 - 2014-07-06 21:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
- 2014-10-15 07:23 - 2014-07-06 21:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
- 2014-10-15 07:23 - 2014-07-06 20:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
- 2014-10-15 07:23 - 2014-07-06 20:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
- 2014-10-15 07:23 - 2014-07-06 20:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
- 2014-10-15 07:23 - 2014-07-06 20:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
- 2014-10-15 07:23 - 2014-06-18 17:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
- 2014-10-15 07:23 - 2014-06-18 17:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
- 2014-10-15 07:23 - 2014-06-18 17:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
- 2014-10-15 07:23 - 2014-06-18 17:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
- 2014-10-15 07:23 - 2014-06-18 17:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
- 2014-10-15 07:23 - 2014-06-18 17:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
- 2014-10-15 07:22 - 2014-10-09 21:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
- 2014-10-15 07:22 - 2014-10-09 21:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
- 2014-10-15 07:22 - 2014-10-09 21:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
- 2014-10-15 07:22 - 2014-10-06 21:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
- 2014-10-15 07:22 - 2014-10-06 21:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
- 2014-10-15 07:22 - 2014-09-25 17:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
- 2014-10-15 07:22 - 2014-09-25 17:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
- 2014-10-15 07:22 - 2014-09-25 17:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
- 2014-10-15 07:22 - 2014-09-25 17:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
- 2014-10-15 07:22 - 2014-09-25 17:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
- 2014-10-15 07:22 - 2014-09-25 17:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
- 2014-10-15 07:22 - 2014-09-25 17:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
- 2014-10-15 07:22 - 2014-09-18 21:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
- 2014-10-15 07:22 - 2014-09-18 20:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
- 2014-10-15 07:22 - 2014-09-18 20:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
- 2014-10-15 07:22 - 2014-09-18 20:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
- 2014-10-15 07:22 - 2014-09-18 20:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
- 2014-10-15 07:22 - 2014-09-18 20:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
- 2014-10-15 07:22 - 2014-09-18 20:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
- 2014-10-15 07:22 - 2014-09-18 20:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
- 2014-10-15 07:22 - 2014-09-18 20:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
- 2014-10-15 07:22 - 2014-09-18 20:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
- 2014-10-15 07:22 - 2014-09-18 20:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
- 2014-10-15 07:22 - 2014-09-18 20:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
- 2014-10-15 07:22 - 2014-09-18 20:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
- 2014-10-15 07:22 - 2014-09-18 20:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
- 2014-10-15 07:22 - 2014-09-18 20:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
- 2014-10-15 07:22 - 2014-09-18 20:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
- 2014-10-15 07:22 - 2014-09-18 20:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
- 2014-10-15 07:22 - 2014-09-18 20:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
- 2014-10-15 07:22 - 2014-09-18 20:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
- 2014-10-15 07:22 - 2014-09-18 20:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
- 2014-10-15 07:22 - 2014-09-18 20:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
- 2014-10-15 07:22 - 2014-09-18 20:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
- 2014-10-15 07:22 - 2014-09-18 20:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
- 2014-10-15 07:22 - 2014-09-18 20:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
- 2014-10-15 07:22 - 2014-09-18 20:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
- 2014-10-15 07:22 - 2014-09-18 20:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
- 2014-10-15 07:22 - 2014-09-18 19:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
- 2014-10-15 07:22 - 2014-09-18 19:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
- 2014-10-15 07:22 - 2014-09-18 19:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
- 2014-10-15 07:22 - 2014-09-18 19:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
- 2014-10-15 07:22 - 2014-09-18 19:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
- 2014-10-15 07:22 - 2014-09-18 19:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
- 2014-10-15 07:22 - 2014-09-18 19:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
- 2014-10-15 07:22 - 2014-09-18 19:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
- 2014-10-15 07:22 - 2014-09-18 19:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
- 2014-10-15 07:22 - 2014-09-18 19:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
- 2014-10-15 07:22 - 2014-09-18 19:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
- 2014-10-15 07:22 - 2014-09-18 19:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
- 2014-10-15 07:22 - 2014-09-18 19:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
- 2014-10-15 07:22 - 2014-09-18 19:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
- 2014-10-15 07:22 - 2014-09-18 19:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
- 2014-10-15 07:22 - 2014-09-18 19:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
- 2014-10-15 07:22 - 2014-09-18 19:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
- 2014-10-15 07:22 - 2014-09-18 18:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
- 2014-10-15 07:22 - 2014-09-18 18:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
- 2014-10-15 07:22 - 2014-09-18 18:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
- 2014-10-15 07:22 - 2014-09-18 18:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
- 2014-10-15 07:22 - 2014-09-17 21:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
- 2014-10-15 07:22 - 2014-09-17 20:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
- 2014-10-15 07:22 - 2014-08-18 22:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
- 2014-10-15 07:22 - 2014-08-18 22:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
- 2014-10-15 07:22 - 2014-08-18 22:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
- 2014-10-15 07:22 - 2014-08-18 22:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
- 2014-10-15 07:22 - 2014-08-18 22:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
- 2014-10-15 07:22 - 2014-08-18 22:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
- 2014-10-15 07:22 - 2014-08-18 22:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
- 2014-10-15 07:22 - 2014-08-18 22:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
- 2014-10-15 07:22 - 2014-08-18 22:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
- 2014-10-15 07:22 - 2014-08-18 22:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
- 2014-10-15 07:22 - 2014-08-18 21:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
- 2014-10-15 07:22 - 2014-08-18 21:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
- 2014-10-15 07:22 - 2014-08-18 21:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
- 2014-10-15 07:22 - 2014-07-06 21:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
- 2014-10-15 07:22 - 2014-07-06 21:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
- 2014-10-15 07:22 - 2014-07-06 21:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
- 2014-10-15 07:22 - 2014-07-06 21:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
- 2014-10-15 07:22 - 2014-07-06 21:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
- 2014-10-15 07:22 - 2014-07-06 21:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
- 2014-10-15 07:22 - 2014-07-06 20:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
- 2014-10-15 07:22 - 2014-07-06 20:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
- 2014-10-15 07:22 - 2014-07-06 20:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
- 2014-10-15 07:22 - 2014-07-06 20:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
- 2014-10-15 07:22 - 2014-07-06 20:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
- 2014-10-15 07:22 - 2014-07-06 20:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
- 2014-10-15 07:22 - 2014-07-06 20:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
- 2014-10-15 07:22 - 2014-07-06 20:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
- 2014-10-15 07:22 - 2014-07-06 20:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
- 2014-10-15 07:22 - 2014-06-27 19:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
- 2014-10-15 07:22 - 2014-06-27 19:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
- 2014-10-15 07:22 - 2014-06-27 19:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
- 2014-10-15 07:21 - 2014-09-12 20:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
- 2014-10-15 07:21 - 2014-09-12 20:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
- 2014-10-15 07:21 - 2014-09-04 00:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
- 2014-10-15 07:21 - 2014-09-04 00:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
- 2014-10-15 07:21 - 2014-07-16 21:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
- 2014-10-15 07:21 - 2014-07-16 21:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
- 2014-10-15 07:21 - 2014-07-16 21:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
- 2014-10-15 07:21 - 2014-07-16 21:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
- 2014-10-15 07:21 - 2014-07-16 21:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
- 2014-10-15 07:21 - 2014-07-16 21:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
- 2014-10-15 07:21 - 2014-07-16 21:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
- 2014-10-15 07:21 - 2014-07-16 21:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
- 2014-10-15 07:21 - 2014-07-16 20:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
- 2014-10-15 07:21 - 2014-07-16 20:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
- 2014-10-15 07:21 - 2014-07-16 20:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
- 2014-10-15 07:21 - 2014-07-16 20:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
- 2014-10-15 07:21 - 2014-07-16 20:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
- 2014-10-15 07:21 - 2014-07-16 20:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
- 2014-10-15 07:21 - 2014-07-16 20:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
- 2014-10-15 07:21 - 2014-07-16 20:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
- 2014-10-15 07:01 - 2014-10-15 07:01 - 00010672 _____ () C:\Users\Erich\Downloads\meeting (12).jnlp
- 2014-10-12 19:18 - 2014-10-12 19:18 - 00000000 ____D () C:\Users\Erich\AppData\Local\{59056512-07C5-42D2-8451-87DC1D2B4D21}
- 2014-10-07 11:55 - 2014-10-07 11:55 - 00010657 _____ () C:\Users\Erich\Downloads\meeting (11).jnlp
- 2014-10-07 10:54 - 2014-10-07 10:54 - 00010656 _____ () C:\Users\Erich\Downloads\meeting (10).jnlp
- 2014-10-07 09:51 - 2014-10-07 09:51 - 00010658 _____ () C:\Users\Erich\Downloads\meeting (9).jnlp
- 2014-10-07 08:45 - 2014-10-07 08:45 - 00010674 _____ () C:\Users\Erich\Downloads\meeting (8).jnlp
- 2014-10-07 06:39 - 2014-10-07 06:39 - 00010672 _____ () C:\Users\Erich\Downloads\meeting (7).jnlp
- 2014-10-06 11:52 - 2014-10-06 11:52 - 00010657 _____ () C:\Users\Erich\Downloads\meeting (6).jnlp
- 2014-10-06 10:48 - 2014-10-06 10:48 - 00010656 _____ () C:\Users\Erich\Downloads\meeting (5).jnlp
- 2014-10-06 09:53 - 2014-10-06 09:53 - 00010658 _____ () C:\Users\Erich\Downloads\meeting (4).jnlp
- 2014-10-06 08:51 - 2014-10-06 08:51 - 00010674 _____ () C:\Users\Erich\Downloads\meeting (3).jnlp
- 2014-10-06 08:28 - 2014-10-06 08:28 - 00561350 _____ () C:\Users\Erich\Downloads\The City of Cuttbus.pptx
- 2014-10-06 07:54 - 2014-10-06 07:55 - 00010664 _____ () C:\Users\Erich\Downloads\meeting (2).jnlp
- 2014-10-06 07:22 - 2014-10-06 07:22 - 00010672 _____ () C:\Users\Erich\Downloads\meeting (1).jnlp
- 2014-10-06 06:51 - 2014-10-15 07:02 - 00000000 ____D () C:\Users\Erich\Documents\Kat School
- 2014-10-06 06:50 - 2014-10-06 07:52 - 00000000 ____D () C:\Users\Erich\AppData\Roaming\Blackboard
- 2014-10-06 06:48 - 2014-10-06 06:48 - 00010672 _____ () C:\Users\Erich\Downloads\meeting.jnlp
- 2014-10-06 06:47 - 2014-10-15 07:26 - 00425984 _____ () C:\Users\Erich\AppData\Local\ChromeHitoryDB
- 2014-10-05 13:57 - 2014-10-05 13:57 - 00000000 _____ () C:\Windows\SysWOW64\sho2128.tmp
- ==================== One Month Modified Files and Folders =======
- (If an entry is included in the fixlist, the file\folder will be moved.)
- 2014-11-04 22:21 - 2013-03-26 22:10 - 00000480 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
- 2014-11-04 22:21 - 2013-03-26 22:10 - 00000472 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
- 2014-11-04 22:21 - 2012-11-17 16:33 - 00018863 _____ () C:\Windows\setupact.log
- 2014-11-04 22:21 - 2012-02-26 22:43 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- 2014-11-04 22:21 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
- 2014-11-04 21:57 - 2009-07-14 00:13 - 00783400 _____ () C:\Windows\system32\PerfStringBackup.INI
- 2014-11-04 21:50 - 2012-11-17 17:34 - 01214698 _____ () C:\Windows\WindowsUpdate.log
- 2014-11-04 21:48 - 2009-07-13 23:45 - 00026192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2014-11-04 21:48 - 2009-07-13 23:45 - 00026192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2014-11-04 21:12 - 2012-04-08 18:26 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
- 2014-11-04 21:01 - 2012-09-19 06:05 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-103344571-3548091809-1978653994-1000UA1cd9656a9dd1feb.job
- 2014-11-04 20:56 - 2012-02-26 22:43 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- 2014-11-04 20:55 - 2011-03-01 22:59 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-103344571-3548091809-1978653994-1000UA.job
- 2014-11-04 20:34 - 2010-12-08 06:49 - 00000000 ____D () C:\Users\Erich\AppData\Local\CrashDumps
- 2014-11-04 17:45 - 2013-02-08 21:41 - 541388934 _____ () C:\Windows\MEMORY.DMP
- 2014-11-04 17:45 - 2011-06-25 20:55 - 00000000 ____D () C:\Windows\Minidump
- 2014-11-04 07:05 - 2011-03-01 22:59 - 00000856 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-103344571-3548091809-1978653994-1000Core.job
- 2014-11-03 13:57 - 2012-09-19 06:05 - 00000856 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-103344571-3548091809-1978653994-1000Core1cd9656a5776789.job
- 2014-10-30 05:08 - 2014-08-26 05:55 - 00003228 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-103344571-3548091809-1978653994-1000
- 2014-10-30 05:08 - 2014-04-18 13:06 - 00003362 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-103344571-3548091809-1978653994-1000
- 2014-10-29 17:03 - 2012-11-17 18:02 - 00176622 _____ () C:\Windows\PFRO.log
- 2014-10-29 16:57 - 2012-08-12 12:49 - 00000000 ____D () C:\ProgramData\Bitdefender
- 2014-10-29 16:57 - 2012-08-12 12:02 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
- 2014-10-29 16:46 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
- 2014-10-28 20:45 - 2009-07-13 22:20 - 00000000 __RHD () C:\Users\Default
- 2014-10-28 20:30 - 2009-07-13 21:34 - 00000215 _____ () C:\Windows\system.ini
- 2014-10-28 20:27 - 2014-09-27 11:00 - 00000000 ____D () C:\Program Files (x86)\Browser Features
- 2014-10-28 17:47 - 2013-08-10 16:59 - 00000000 ____D () C:\Hold
- 2014-10-28 07:24 - 2010-05-16 07:41 - 00000000 ____D () C:\Program Files (x86)\Java
- 2014-10-27 19:57 - 2011-03-01 22:59 - 00002364 _____ () C:\Users\Erich\Desktop\Google Chrome.lnk
- 2014-10-23 20:32 - 2010-08-11 16:31 - 00111368 _____ () C:\Users\Erich\AppData\Local\GDIPFONTCACHEV1.DAT
- 2014-10-22 19:58 - 2010-09-14 19:38 - 00000000 ____D () C:\Users\Erich\AppData\Roaming\SoftGrid Client
- 2014-10-21 05:51 - 2012-02-26 22:43 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
- 2014-10-21 05:51 - 2012-02-26 22:43 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
- 2014-10-19 12:46 - 2009-07-14 00:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
- 2014-10-18 11:56 - 2012-09-19 06:05 - 00003878 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-103344571-3548091809-1978653994-1000UA1cd9656a9dd1feb
- 2014-10-18 11:56 - 2012-09-19 06:05 - 00003482 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-103344571-3548091809-1978653994-1000Core1cd9656a5776789
- 2014-10-17 13:32 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
- 2014-10-16 22:22 - 2009-07-13 23:45 - 00397136 _____ () C:\Windows\system32\FNTCACHE.DAT
- 2014-10-16 22:19 - 2014-05-06 06:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
- 2014-10-16 22:19 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
- 2014-10-16 22:19 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\Dism
- 2014-10-16 19:46 - 2010-08-20 16:17 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
- 2014-10-05 13:24 - 2014-10-03 10:02 - 00000196 _____ () C:\Users\Erich\Desktop\German Deli.txt
- 2014-10-05 12:46 - 2010-12-22 22:55 - 00000000 ____D () C:\Users\Erich\Documents\Annie
- ZeroAccess:
- C:\Windows\Installer\{f2c68d70-a2fd-fe55-5ab1-2db3e1926075}
- C:\Windows\Installer\{f2c68d70-a2fd-fe55-5ab1-2db3e1926075}\@
- C:\Windows\Installer\{f2c68d70-a2fd-fe55-5ab1-2db3e1926075}\L\00000004.@
- C:\Windows\Installer\{f2c68d70-a2fd-fe55-5ab1-2db3e1926075}\L\201d3dde
- ZeroAccess:
- C:\Users\Erich\AppData\Local\{f2c68d70-a2fd-fe55-5ab1-2db3e1926075}
- C:\Users\Erich\AppData\Local\{f2c68d70-a2fd-fe55-5ab1-2db3e1926075}\@
- Files to move or delete:
- ====================
- C:\ProgramData\SMRResults311.dat
- Some content of TEMP:
- ====================
- C:\Users\Erich\AppData\Local\Temp\ApphRESM.exe
- C:\Users\Erich\AppData\Local\Temp\UpdateFlashPlayer_245316cd.exe
- C:\Users\Erich\AppData\Local\Temp\UpdateFlashPlayer_7de9cf46.exe
- ==================== Bamital & volsnap Check =================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\System32\winlogon.exe => File is digitally signed
- C:\Windows\System32\wininit.exe => File is digitally signed
- C:\Windows\SysWOW64\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\System32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\System32\services.exe => File is digitally signed
- C:\Windows\System32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\System32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\System32\rpcss.dll => File is digitally signed
- C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2014-10-26 07:14
- ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement