horstbernd | 16.08.2013 09:05 | Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.6 (08.15.2013:1)
OS: Windows 7 Professional x64
Ran by Stephan on 16.08.2013 at 9:59:14,44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322282250}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220322282250}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660366286650}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Stephan\AppData\Roaming\mozilla\firefox\profiles\c3kwxe5a.asdf\prefs.js
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.backgroundjs", "\n\n/****************************************************
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.js", "\n\n /************************************************************
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_14.name", "CrossriderUtils");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],regi
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){va
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.res
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_78.name", "CrossriderInfo");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_87.code", "var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jqu
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"unde
user_pref("extensions.crossrider.bic", "13fdea25003caa996f34941fa4e129f1");
Emptied folder: C:\Users\Stephan\AppData\Roaming\mozilla\firefox\profiles\c3kwxe5a.asdf\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.08.2013 at 10:03:04,74
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-08-2013 01
Ran by Stephan (administrator) on 16-08-2013 10:05:03
Running from C:\Users\Stephan\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SAsrv.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Authentec Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Lenovo Group Limited) C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPUIManager.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TpShocks] - C:\Windows\system32\TpShocks.exe [380776 2010-12-09] (Lenovo.)
HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.)
HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [40808 2011-05-31] (Lenovo Group Limited)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM\...\Run: [AcWin7Hlpr] - C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [63784 2013-03-18] (Lenovo)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
MountPoints2: {b3675e2f-ea0b-11e2-a049-806e6f6e6963} - Q:\LenovoQDrive.exe
MountPoints2: {f41dd8a6-ed1c-11e2-bb22-0021ccccd1a4} - V:\SETUP.EXE
HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] - C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL [1629544 2011-08-31] (Lenovo Group Limited)
HKLM-x32\...\Run: [Lenovo Registration] - C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.)
HKLM-x32\...\Run: [YTDownloader] - "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot [x]
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-05-17] (Lenovo)
HKU\Default\...\RunOnce: [] - [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] - C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe [159744 2009-03-24] ()
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-05-17] (Lenovo)
HKU\Default User\...\RunOnce: [] - [x]
HKU\Default User\...\RunOnce: [Lenovoautoqdrive] - C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe [159744 2009-03-24] ()
Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll ACGina
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Path=Profiles\c3kwxe5a.asdf
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [VIP@verisign.com] C:\Program Files (x86)\Symantec\VIP Access Client\
FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\
==================== Services (Whitelisted) =================
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
R2 CxAudMsg; C:\Windows\system32\CxAudMsg64.exe [198784 2010-12-17] (Conexant Systems Inc.)
S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2011-08-31] (Lenovo.)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] ()
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] ()
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-06-26] ()
R2 ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [1028096 2010-08-31] (Lenovo Group Limited)
S3 TVT Backup Service; C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe [1517928 2013-03-11] (Lenovo Group Limited)
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [82544 2011-07-12] (Symantec Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-07-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw00.sys [11518976 2013-02-05] (Intel Corporation)
R1 PHCORE; C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [32104 2011-07-08] (Lenovo Group Limited)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-30] (Lenovo Information Product(ShenZhen China) Inc.)
S2 smihlp2; \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-16 09:59 - 2013-08-16 09:59 - 00000000 ____D C:\Windows\ERUNT
2013-08-16 09:57 - 2013-08-16 09:57 - 01159319 _____ (Thisisu) C:\Users\Stephan\Desktop\JRT.exe
2013-08-16 09:52 - 2013-08-16 09:53 - 00003302 _____ C:\AdwCleaner[S1].txt
2013-08-16 09:46 - 2013-08-16 09:46 - 00666633 _____ C:\Users\Stephan\Desktop\adwcleaner.exe
2013-08-16 09:40 - 2013-08-16 09:40 - 00001120 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-16 09:40 - 2013-08-16 09:40 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Malwarebytes
2013-08-16 09:40 - 2013-08-16 09:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-16 09:40 - 2013-08-16 09:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-16 09:40 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-16 09:39 - 2013-08-16 09:40 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Stephan\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-16 09:06 - 2013-08-16 09:06 - 00002025 _____ C:\Users\Public\Desktop\Adobe Reader 9.lnk
2013-08-15 23:37 - 2013-08-15 23:37 - 00024300 _____ C:\Users\Stephan\Desktop\Addition.txt
2013-08-15 23:36 - 2013-08-15 23:36 - 00000000 ____D C:\FRST
2013-08-15 23:34 - 2013-08-15 23:36 - 01575570 _____ (Farbar) C:\Users\Stephan\Desktop\FRST64.exe
2013-08-15 16:59 - 2013-08-16 09:23 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-15 16:59 - 2013-08-15 16:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-15 15:44 - 2013-08-15 16:59 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-15 15:44 - 2013-08-15 16:59 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-15 15:43 - 2013-08-15 15:43 - 00001158 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-15 15:43 - 2013-08-15 15:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-15 15:40 - 2013-08-15 15:40 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-15 11:55 - 2013-08-15 11:55 - 00000000 ____D C:\Users\Stephan\Documents\Benutzerdefinierte Office-Vorlagen
2013-08-15 11:02 - 2013-08-15 11:02 - 00005739 _____ C:\QcOSD.txt
2013-08-14 23:48 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 23:48 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 23:48 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 23:48 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 23:48 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 23:48 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 23:48 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 23:48 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 23:48 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 23:48 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 23:48 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 23:48 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 23:48 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 23:48 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 23:11 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 23:11 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 23:11 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 23:11 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 23:11 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 23:11 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 23:11 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 23:11 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 23:11 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 23:11 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 23:11 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 23:11 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 23:11 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 23:11 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 23:11 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 23:11 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 23:11 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 23:11 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 23:11 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 23:11 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 23:11 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 23:11 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 23:11 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 23:11 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 23:11 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 23:11 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 23:11 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-13 08:34 - 2013-08-15 19:25 - 00000000 ____D C:\Users\Stephan\Documents\OpenTTD
2013-08-13 08:31 - 2013-08-13 08:32 - 00000000 ____D C:\Program Files\OpenTTD
2013-08-13 08:31 - 2013-08-13 08:31 - 07492071 _____ (OpenTTD Developers) C:\Users\Stephan\Downloads\openttd-1.3.2-windows-win64.exe
2013-08-13 08:31 - 2013-08-13 08:31 - 00000807 _____ C:\Users\Public\Desktop\OpenTTD.lnk
2013-08-13 08:19 - 2013-08-13 08:19 - 00000000 ____D C:\Users\Stephan\AppData\Local\Microsoft Games
2013-08-12 23:44 - 2013-08-15 15:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-12 22:49 - 2013-08-12 22:49 - 00001230 _____ C:\Users\Public\Desktop\MailStore Home.lnk
2013-08-12 22:49 - 2013-08-12 22:49 - 00000000 ____D C:\Program Files (x86)\deepinvent
2013-08-12 22:45 - 2013-08-12 22:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-08-12 22:29 - 2013-08-12 22:29 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-08-12 22:29 - 2013-08-12 22:29 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2013-08-12 21:31 - 2013-08-12 21:31 - 00000000 _RSHD C:\RRbackups
2013-07-20 01:51 - 2013-07-20 01:51 - 00311608 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00206648 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00071480 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
==================== One Month Modified Files and Folders =======
2013-08-16 10:03 - 2013-08-16 10:03 - 00004604 _____ C:\Users\Stephan\Desktop\JRT.txt
2013-08-16 10:02 - 2009-07-14 06:45 - 00031072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-16 10:02 - 2009-07-14 06:45 - 00031072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-16 09:59 - 2013-08-16 09:59 - 00000000 ____D C:\Windows\ERUNT
2013-08-16 09:59 - 2013-07-11 21:14 - 00654166 _____ C:\Windows\system32\perfh007.dat
2013-08-16 09:59 - 2013-07-11 21:14 - 00130006 _____ C:\Windows\system32\perfc007.dat
2013-08-16 09:59 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-16 09:57 - 2013-08-16 09:57 - 01159319 _____ (Thisisu) C:\Users\Stephan\Desktop\JRT.exe
2013-08-16 09:55 - 2013-07-14 21:13 - 00001220 _____ C:\Windows\Tasks\Object Browser-codedownloader.job
2013-08-16 09:55 - 2013-07-14 21:13 - 00001216 _____ C:\Windows\Tasks\Object Browser-updater.job
2013-08-16 09:55 - 2013-07-14 21:13 - 00001120 _____ C:\Windows\Tasks\Object Browser-enabler.job
2013-08-16 09:55 - 2013-07-14 21:12 - 00001858 _____ C:\Windows\Tasks\Object Browser-firefoxinstaller.job
2013-08-16 09:54 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-16 09:54 - 2009-07-14 06:51 - 00057526 _____ C:\Windows\setupact.log
2013-08-16 09:53 - 2013-08-16 09:52 - 00003302 _____ C:\AdwCleaner[S1].txt
2013-08-16 09:53 - 2013-07-11 11:35 - 01541790 _____ C:\Windows\WindowsUpdate.log
2013-08-16 09:49 - 2010-11-21 05:47 - 00562410 _____ C:\Windows\PFRO.log
2013-08-16 09:48 - 2013-07-15 11:11 - 00000000 ____D C:\Users\Stephan\Documents\Outlook-Dateien
2013-08-16 09:48 - 2013-07-14 21:12 - 00000000 ____D C:\Program Files (x86)\Object Browser
2013-08-16 09:46 - 2013-08-16 09:46 - 00666633 _____ C:\Users\Stephan\Desktop\adwcleaner.exe
2013-08-16 09:40 - 2013-08-16 09:40 - 00001120 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-16 09:40 - 2013-08-16 09:40 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Malwarebytes
2013-08-16 09:40 - 2013-08-16 09:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-16 09:40 - 2013-08-16 09:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-16 09:40 - 2013-08-16 09:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Stephan\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-16 09:23 - 2013-08-15 16:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-16 09:06 - 2013-08-16 09:06 - 00002025 _____ C:\Users\Public\Desktop\Adobe Reader 9.lnk
2013-08-16 09:06 - 2013-07-14 23:31 - 00000000 ____D C:\Users\Stephan\AppData\Local\Adobe
2013-08-16 09:06 - 2013-07-11 11:31 - 00000000 ____D C:\ProgramData\Adobe
2013-08-16 09:06 - 2013-07-11 11:31 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-16 09:05 - 2013-07-15 10:20 - 00000000 ____D C:\ProgramData\MFAData
2013-08-15 23:37 - 2013-08-15 23:37 - 00024300 _____ C:\Users\Stephan\Desktop\Addition.txt
2013-08-15 23:36 - 2013-08-15 23:36 - 00000000 ____D C:\FRST
2013-08-15 23:36 - 2013-08-15 23:34 - 01575570 _____ (Farbar) C:\Users\Stephan\Desktop\FRST64.exe
2013-08-15 19:25 - 2013-08-13 08:34 - 00000000 ____D C:\Users\Stephan\Documents\OpenTTD
2013-08-15 16:59 - 2013-08-15 16:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-15 16:59 - 2013-08-15 15:44 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-15 16:59 - 2013-08-15 15:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-15 15:43 - 2013-08-15 15:43 - 00001158 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-15 15:43 - 2013-08-15 15:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-15 15:43 - 2013-08-12 23:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-15 15:40 - 2013-08-15 15:40 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-15 11:55 - 2013-08-15 11:55 - 00000000 ____D C:\Users\Stephan\Documents\Benutzerdefinierte Office-Vorlagen
2013-08-15 11:03 - 2013-07-15 08:43 - 00000000 ____D C:\ldiag
2013-08-15 11:03 - 2013-07-14 20:57 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\LSC
2013-08-15 11:03 - 2013-07-11 11:31 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2013-08-15 11:03 - 2013-07-11 11:31 - 00000000 ____D C:\Windows\Downloaded Installations
2013-08-15 11:03 - 2013-07-11 11:27 - 00000000 ____D C:\Program Files\Lenovo
2013-08-15 11:02 - 2013-08-15 11:02 - 00005739 _____ C:\QcOSD.txt
2013-08-14 23:49 - 2013-07-15 09:38 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 23:49 - 2009-07-14 04:34 - 00000478 _____ C:\Windows\win.ini
2013-08-14 23:46 - 2013-07-14 22:28 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 23:45 - 2013-07-14 22:10 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-13 08:32 - 2013-08-13 08:31 - 00000000 ____D C:\Program Files\OpenTTD
2013-08-13 08:31 - 2013-08-13 08:31 - 07492071 _____ (OpenTTD Developers) C:\Users\Stephan\Downloads\openttd-1.3.2-windows-win64.exe
2013-08-13 08:31 - 2013-08-13 08:31 - 00000807 _____ C:\Users\Public\Desktop\OpenTTD.lnk
2013-08-13 08:19 - 2013-08-13 08:19 - 00000000 ____D C:\Users\Stephan\AppData\Local\Microsoft Games
2013-08-12 23:11 - 2013-07-15 14:52 - 00000000 ____D C:\ProgramData\firebird
2013-08-12 23:00 - 2013-07-15 14:52 - 00000000 ____D C:\Users\Stephan\Documents\MailStore Home
2013-08-12 22:49 - 2013-08-12 22:49 - 00001230 _____ C:\Users\Public\Desktop\MailStore Home.lnk
2013-08-12 22:49 - 2013-08-12 22:49 - 00000000 ____D C:\Program Files (x86)\deepinvent
2013-08-12 22:45 - 2013-08-12 22:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-08-12 22:45 - 2013-07-15 09:47 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Skype
2013-08-12 22:45 - 2013-07-15 09:39 - 00000000 ____D C:\ProgramData\Skype
2013-08-12 22:29 - 2013-08-12 22:29 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-08-12 22:29 - 2013-08-12 22:29 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2013-08-12 22:13 - 2013-07-11 21:14 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2013-08-12 22:13 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\winrm
2013-08-12 22:13 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\WCN
2013-08-12 22:13 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep
2013-08-12 22:13 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2013-08-12 22:13 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\SysWOW64\WindowsPowerShell
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Web
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Vss
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\TAPI
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\uk-UA
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\th-TH
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sr-Latn-CS
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sppui
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\spp
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Speech
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sl-SI
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\sk-SK
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\ro-RO
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Recovery
2013-08-12 22:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\ras
2013-08-12 22:12 - 2013-07-11 11:32 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-08-12 22:12 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\NetworkList
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Msdtc
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\manifeststore
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\lv-LV
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\lt-LT
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\InstallShield
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\IME
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\icsxml
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\hr-HR
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL
2013-08-12 22:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\et-EE
2013-08-12 22:11 - 2013-07-15 09:38 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2013-08-12 22:11 - 2013-07-14 23:37 - 00000000 ____D C:\Windows\System32\Tasks\TVT
2013-08-12 22:11 - 2013-07-14 22:44 - 00000000 ____D C:\Windows\system32\Macromed
2013-08-12 22:11 - 2013-07-11 21:14 - 00000000 ____D C:\Windows\SysWOW64\de
2013-08-12 22:11 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\winrm
2013-08-12 22:11 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\WCN
2013-08-12 22:11 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\slmgr
2013-08-12 22:11 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2013-08-12 22:11 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WindowsPowerShell
2013-08-12 22:11 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2013-08-12 22:11 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\bg-BG
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\winevt
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\uk-UA
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\th-TH
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sr-Latn-CS
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sppui
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\spp
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\spool
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Speech
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\SMI
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sk-SK
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ro-RO
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Recovery
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ras
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\oobe
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NetworkList
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\MUI
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Msdtc
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\migwiz
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\manifeststore
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lv-LV
2013-08-12 22:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lt-LT
2013-08-12 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\IME
2013-08-12 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\icsxml
2013-08-12 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ias
2013-08-12 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\hr-HR
2013-08-12 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\he-IL
2013-08-12 22:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\et-EE
2013-08-12 22:09 - 2013-07-11 21:14 - 00000000 ____D C:\Windows\system32\de
2013-08-12 22:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Dism
2013-08-12 22:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\com
2013-08-12 22:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\bg-BG
2013-08-12 22:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ar-SA
2013-08-12 22:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2013-08-12 22:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Speech
2013-08-12 22:08 - 2010-11-21 09:16 - 00000000 ____D C:\Windows\ShellNew
2013-08-12 22:08 - 2009-07-14 06:45 - 00000000 ____D C:\Windows\Setup
2013-08-12 22:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2013-08-12 22:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\security
2013-08-12 22:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\schemas
2013-08-12 22:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
2013-08-12 22:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-12 22:07 - 2013-07-11 11:37 - 00000000 ____D C:\Windows\PCHEALTH
2013-08-12 22:07 - 2011-02-15 11:42 - 00000000 ____D C:\Windows\Panther
2013-08-12 22:07 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Performance
2013-08-12 22:07 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Offline Web Pages
2013-08-12 22:07 - 2009-07-14 05:20 - 00000000 __RSD C:\Windows\Media
2013-08-12 22:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Registration
2013-08-12 22:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-08-12 22:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PLA
2013-08-12 22:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\L2Schemas
2013-08-12 22:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\IME
2013-08-12 22:03 - 2013-07-14 20:09 - 00000000 ____D C:\Windows\CSC
2013-08-12 22:03 - 2013-07-11 11:38 - 00000000 ____D C:\Windows\de
2013-08-12 22:03 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker
2013-08-12 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help
2013-08-12 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Globalization
2013-08-12 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Cursors
2013-08-12 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Branding
2013-08-12 22:02 - 2013-07-14 20:10 - 00000000 ____D C:\Users\Stephan
2013-08-12 22:02 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\addins
2013-08-12 22:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-08-12 22:01 - 2013-07-15 14:47 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Thunderbird
2013-08-12 22:01 - 2013-07-15 10:24 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\TuneUp Software
2013-08-12 22:01 - 2013-07-14 21:11 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Trillian
2013-08-12 22:01 - 2013-07-14 20:57 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\PwrMgr
2013-08-12 22:00 - 2013-07-15 14:47 - 00000000 ____D C:\Users\Stephan\AppData\Local\Thunderbird
2013-08-12 22:00 - 2013-07-15 10:24 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\AVG2013
2013-08-12 22:00 - 2013-07-15 10:20 - 00000000 ____D C:\Users\Stephan\AppData\Local\MFAData
2013-08-12 22:00 - 2013-07-15 10:20 - 00000000 ____D C:\Users\Stephan\AppData\Local\Avg2013
2013-08-12 22:00 - 2013-07-15 09:48 - 00000000 ____D C:\Users\Stephan\AppData\Local\Broadcom
2013-08-12 22:00 - 2013-07-14 23:49 - 00000000 ____D C:\Users\Public\Lenovo
2013-08-12 22:00 - 2013-07-14 23:32 - 00000000 ____D C:\Users\Stephan\AppData\Local\LSC
2013-08-12 22:00 - 2013-07-14 22:44 - 00000000 ____D C:\Users\Stephan\AppData\Local\Macromedia
2013-08-12 22:00 - 2013-07-14 21:04 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\FreeCommander
2013-08-12 22:00 - 2013-07-14 20:36 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Mozilla
2013-08-12 22:00 - 2013-07-14 20:36 - 00000000 ____D C:\Users\Stephan\AppData\Local\Mozilla
2013-08-12 22:00 - 2013-07-14 20:32 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Adobe
2013-08-12 22:00 - 2013-07-14 20:13 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Lenovo
2013-08-12 22:00 - 2013-07-14 20:13 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Leadertech
2013-08-12 22:00 - 2013-07-14 20:13 - 00000000 ____D C:\Users\Stephan\AppData\Local\Lenovo
2013-08-12 22:00 - 2013-07-14 20:12 - 00000000 ___RD C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-12 22:00 - 2013-07-14 20:12 - 00000000 ___RD C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-08-12 22:00 - 2013-07-14 20:10 - 00000000 ___RD C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-08-12 22:00 - 2013-07-14 20:10 - 00000000 ___RD C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-08-12 22:00 - 2013-07-14 20:10 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Macromedia
2013-08-12 22:00 - 2013-07-14 20:10 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Intel
2013-08-12 22:00 - 2013-07-11 11:39 - 00000000 ____D C:\Users\Public\Symantec
2013-08-12 22:00 - 2013-07-11 11:31 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-08-12 22:00 - 2013-07-11 11:31 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-08-12 22:00 - 2011-02-15 11:42 - 00000000 ____D C:\SWTOOLS
2013-08-12 22:00 - 2010-11-21 09:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-12 22:00 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-08-12 22:00 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-12 21:58 - 2013-07-14 23:45 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-12 21:58 - 2013-07-14 23:45 - 00000000 ____D C:\ProgramData\Intel.sav
2013-08-12 21:58 - 2013-07-14 20:36 - 00000000 ____D C:\ProgramData\Mozilla
2013-08-12 21:58 - 2013-07-14 20:33 - 00000000 ____D C:\ProgramData\Google
2013-08-12 21:58 - 2013-07-11 21:05 - 00000000 ____D C:\ProgramData\Lenovo
2013-08-12 21:58 - 2013-07-11 11:38 - 00000000 ____D C:\ProgramData\Norton
2013-08-12 21:58 - 2013-07-11 11:35 - 00000000 ____D C:\swshare
2013-08-12 21:58 - 2013-07-11 11:34 - 00000000 ____D C:\ProgramData\InterVideo
2013-08-12 21:58 - 2013-07-11 11:33 - 00000000 ____D C:\ProgramData\Ulead Systems
2013-08-12 21:58 - 2013-07-11 11:32 - 00000000 ____D C:\ProgramData\Corel
2013-08-12 21:58 - 2013-07-11 11:28 - 00000000 ____D C:\root
2013-08-12 21:58 - 2013-07-11 11:28 - 00000000 ____D C:\ProgramData\Intel
2013-08-12 21:57 - 2013-07-15 11:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-08-12 21:57 - 2013-07-15 10:24 - 00000000 ____D C:\ProgramData\AVG2013
2013-08-12 21:57 - 2013-07-15 09:40 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-08-12 21:57 - 2013-07-15 09:26 - 00000000 ____D C:\Program Files (x86)\WinCDEmu
2013-08-12 21:57 - 2013-07-14 21:11 - 00000000 ____D C:\Program Files (x86)\Trillian
2013-08-12 21:57 - 2013-07-11 11:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-08-12 21:57 - 2013-07-11 11:39 - 00000000 ____D C:\Program Files (x86)\SymSilent
2013-08-12 21:57 - 2013-07-11 11:39 - 00000000 ____D C:\Program Files (x86)\Symantec
2013-08-12 21:57 - 2013-07-11 11:38 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-08-12 21:57 - 2013-07-11 11:37 - 00000000 ____D C:\Program Files (x86)\Windows Live
2013-08-12 21:57 - 2013-07-11 11:29 - 00000000 ____D C:\Program Files (x86)\ThinkPad
2013-08-12 21:57 - 2013-07-11 11:28 - 00000000 ____D C:\Program Files (x86)\Ricoh
2013-08-12 21:57 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-08-12 21:57 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2013-08-12 21:57 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-08-12 21:57 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-12 21:57 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2013-08-12 21:57 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-08-12 21:57 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files (x86)\Windows NT
2013-08-12 21:56 - 2013-07-15 09:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-08-12 21:56 - 2013-07-14 21:04 - 00000000 ____D C:\Program Files (x86)\FreeCommander
2013-08-12 21:56 - 2013-07-11 11:38 - 00000000 ____D C:\Program Files (x86)\Lenovo Registration
2013-08-12 21:56 - 2013-07-11 11:36 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-12 21:56 - 2013-07-11 11:35 - 00000000 ____D C:\Program Files (x86)\Evernote
2013-08-12 21:56 - 2013-07-11 11:32 - 00000000 ____D C:\Program Files (x86)\Corel
2013-08-12 21:56 - 2013-07-11 11:29 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-08-12 21:56 - 2013-07-11 11:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-12 21:56 - 2013-07-11 11:28 - 00000000 ____D C:\Program Files (x86)\Intel
2013-08-12 21:51 - 2013-07-15 11:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-12 21:51 - 2013-07-15 10:24 - 00000000 ____D C:\Program Files (x86)\AVG
2013-08-12 21:51 - 2013-07-15 09:38 - 00000000 ____D C:\Program Files\Microsoft Office
2013-08-12 21:51 - 2013-07-14 23:45 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-08-12 21:51 - 2013-07-11 11:37 - 00000000 ____D C:\Program Files\Windows Live
2013-08-12 21:51 - 2013-07-11 11:35 - 00000000 ____D C:\Program Files\ThinkVantage Fingerprint Software
2013-08-12 21:51 - 2013-07-11 11:35 - 00000000 ____D C:\Program Files\Protector Suite
2013-08-12 21:51 - 2013-07-11 11:28 - 00000000 ____D C:\Program Files\Intel
2013-08-12 21:51 - 2013-07-11 11:27 - 00000000 ____D C:\Program Files\ThinkPad
2013-08-12 21:51 - 2013-07-11 11:26 - 00000000 ____D C:\Program Files\Synaptics
2013-08-12 21:51 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Reference Assemblies
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\MSBuild
2013-08-12 21:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2013-08-12 21:51 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT
2013-08-12 21:50 - 2013-07-15 10:24 - 00000000 ___HD C:\$AVG
2013-08-12 21:50 - 2013-07-15 09:37 - 00000000 __RHD C:\MSOCache
2013-08-12 21:50 - 2013-07-14 23:39 - 00000000 ____D C:\Program Files\Common Files\SPBA
2013-08-12 21:50 - 2013-07-14 22:26 - 00000000 ____D C:\Program Files\AuthenTec
2013-08-12 21:50 - 2013-07-11 11:29 - 00000000 ____D C:\Program Files\CONEXANT
2013-08-12 21:50 - 2013-07-11 11:29 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-08-12 21:50 - 2013-07-11 11:28 - 00000000 ____D C:\Program Files\Common Files\Intel
2013-08-12 21:50 - 2013-07-11 11:28 - 00000000 ____D C:\Intel
2013-08-12 21:50 - 2013-07-11 11:27 - 00000000 ____D C:\Program Files\Broadcom
2013-08-12 21:50 - 2013-07-11 11:26 - 00000000 ____D C:\Program Files\DIFX
2013-08-12 21:50 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-08-12 21:50 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-08-12 21:50 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2013-08-12 21:50 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Services
2013-08-12 21:50 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-08-12 21:31 - 2013-08-12 21:31 - 00000000 _RSHD C:\RRbackups
2013-07-26 07:13 - 2013-08-14 23:48 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 07:13 - 2013-08-14 23:48 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 07:13 - 2013-08-14 23:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 07:12 - 2013-08-14 23:48 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 07:12 - 2013-08-14 23:48 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 05:35 - 2013-08-14 23:48 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 05:13 - 2013-08-14 23:48 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-26 05:13 - 2013-08-14 23:48 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-26 05:12 - 2013-08-14 23:48 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-26 05:11 - 2013-08-14 23:48 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-26 05:11 - 2013-08-14 23:48 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-26 04:49 - 2013-08-14 23:48 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-26 04:39 - 2013-08-14 23:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-26 03:59 - 2013-08-14 23:48 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-25 11:25 - 2013-08-14 23:11 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-25 10:57 - 2013-08-14 23:11 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-20 01:51 - 2013-07-20 01:51 - 00311608 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00206648 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2013-07-20 01:50 - 2013-07-20 01:50 - 00071480 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2013-07-19 03:58 - 2013-08-14 23:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-07-19 03:41 - 2013-08-14 23:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2011-02-15 11:43
==================== End Of Log ============================ --- --- ---
--- --- --- |