FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by aysenur (administrator) on AYSENUR-PC on 05-10-2013 20:19:02
Running from C:\Users\aysenur\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\Omiga Plus\omigaplusSvc.exe
(Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\WinZipper\winzipersvc.exe
(Wsys Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Yontoo LLC) C:\Users\aysenur\AppData\Roaming\Yontoo\YontooDesktop.exe
(Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\Omiga Plus\omigaplus.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Windows\System32\snmp.exe
(Microsoft) C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsd.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6486120 2010-09-08] (Realtek Semiconductor)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Yontoo Desktop] - C:\Users\aysenur\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-03-23] (Yontoo LLC)
HKCU\...\Run: [Google Update] - "C:\Users\aysenur\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
HKCU\...\Run: [SDP] - C:\Users\aysenur\AppData\Local\FilesFrog Update Checker\update_checker.exe /auto
HKCU\...\Run: [AppsHat] - C:\Users\aysenur\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
HKCU\...\Run: [FLV Player] - C:\Users\aysenur\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
HKCU\...\Run: [fTalk] - "C:\Users\aysenur\AppData\Local\fTalk\fTalk.exe" -autorun
HKCU\...\Run: [Omiga Plus] - C:\Program Files (x86)\Omiga Plus\omigaplus.exe [1361576 2013-10-05] (Taiwan Shui Mu Chih Ching Technology Limited.)
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard)
HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard)
AppInit_DLLs: [97280 2009-07-14] ()
AppInit_DLLs-x32: [ ] ()
Startup: C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=294d87e3-a4f0-4813-bbb1-3814519d23bc&searchtype=ds&q={searchTerms}&installDate=28/04/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google/de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x15DF96FFF228CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www1.delta-search.com/?affID=120518&babsrc=HP_ss&mntrId=AAF6002682D12299
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=1372934719
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=294d87e3-a4f0-4813-bbb1-3814519d23bc&searchtype=ds&q={searchTerms}&installDate=28/04/2013
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=1372934719
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=1372934719
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=1372934719
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=1372934719
URLSearchHook: (No Name) - {539F76FD-084E-4858-86D5-62F02F54AE86} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=1372934719
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=3604531
SearchScopes: HKLM - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=3604531
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=544&systemid=406&apn_uid=2484038090034522&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2431} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=431&v=a9397-122&apn_uid=2484038090034522&apn_dtid=BND431&o=APN10656&apn_ptnrs=AGH&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=3604531
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=294d87e3-a4f0-4813-bbb1-3814519d23bc&searchtype=ds&q={searchTerms}&installDate=28/04/2013
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=3604531
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=544&systemid=406&apn_uid=2484038090034522&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2431} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=431&v=a9397-122&apn_uid=2484038090034522&apn_dtid=BND431&o=APN10656&apn_ptnrs=AGH&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=3604531
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=294d87e3-a4f0-4813-bbb1-3814519d23bc&searchtype=ds&q={searchTerms}&installDate=28/04/2013
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3312375&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPBC83A137-C396-492A-9150-6BCB88D0D443&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=120518&babsrc=SP_ss_bad2g&mntrId=AAF6002682D12299
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD3200BEKT-60V5T1_WD-WXL1A60P6267P6267&ts=3604531
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=544&systemid=406&apn_uid=2484038090034522&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2431} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=135&systemid=431&v=r8462-99&apn_uid=2484038090034522&apn_dtid=BND431&o=APN10656&apn_ptnrs=AGH&q={searchTerms}
SearchScopes: HKCU - ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± v˰!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO-x32: PricePeep - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - C:\Program Files (x86)\PricePeep\pricepeep.dll (PricePeep)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {85938687-8069-4eb7-bfba-48745cac96e8} - No File
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect125.cab
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.179.1
FireFox:
========
FF ProfilePath: C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default
FF user.js: detected! => C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\user.js
FF NewTab: hxxp://www2.delta-search.com/?babsrc=NT_ss&mntrId=AAF6002682D12299&affID=119357&tsp=5001
FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Ask.com
FF Homepage: www.google.de
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF SearchPlugin: C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\delta-homes.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\USearch.xml
FF Extension: No Name - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\staged
FF Extension: New tab - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\{4DFC09CE-7796-7271-8DED-69D828FC3264}
FF Extension: Wajam - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
FF Extension: HP Detect - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
FF Extension: pricepeep - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\pricepeep@getpricepeep.com.xpi
FF Extension: webbooster - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\webbooster@iminent.com.xpi
FF Extension: No Name - C:\Users\aysenur\AppData\Roaming\Mozilla\Firefox\Profiles\y93l4bzt.default\Extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi
FF HKLM\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] - C:\Program Files\Video downloader\Firefox
FF Extension: V-bates - C:\Program Files\Video downloader\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] - C:\Program Files\Video downloader\Firefox
FF Extension: V-bates - C:\Program Files\Video downloader\Firefox
FF HKCU\...\Firefox\Extensions: [{0F827075-B026-42F3-885D-98981EE7B1AE}] - C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
Chrome:
=======
CHR HomePage: hxxp://www.searchnu.com/406?appid=544
CHR RestoreOnStartup: "hxxp://www.searchnu.com/406?appid=544"]},"sync":{"keep_everything_synced":false,"preferences":false,"search_engines":false,"suppress_start":true},"sync_promo":{"startup_count":10},"translate_accepted_count":{"en":0,"tr":0},"translate_denied_count":{"en":2,"tr":5},"variations_seed":"CigyNDhjZGFhYjk0ZTFkZjg0YmUzYzBjYjY2ZjU4ZWFmZmZiMGQ1NWZkEmgKCEFzeW5jRG5zGMTJ5o8FOABCClN5c3RlbURuc0FKDgoKU3lzdGVtRG5zQRAZSg4KClN5c3RlbURuc0IQGUoOCglBc3luY0Ruc0EQ2wNKDgoJQXN5bmNEbnNCENsDUggSBDI2LiooAxJuCghBc3luY0RucxjEyeaPBTgAQgpTeXN0ZW1EbnNBSg4KClN5c3RlbURuc0EQGUoOCgpTeXN0ZW1EbnNCEBlKDQoJQXN5bmNEbnNBEBlKDQoJQXN5bmNEbnNCEBlSEBIEMjkuKiAAIAEoACgBKAISagoIQXN5bmNEbnMYxIzDjgU4AEIKU3lzdGVtRG5zQUoOCgpTeXN0ZW1EbnNBEDJKDgoKU3lzdGVtRG5zQhAySg0KCUFzeW5jRG5zQRAySg0KCUFzeW5jRG5zQhAyUgwSBDI4LiogAigBKAISPAoIQXN5bmNEbnMYxMnmjwU4AEIKU3lzdGVtRG5zQUoOCgpTeXN0ZW1EbnNBEAFSDBIEMjYuKiADKAEoAhKPAQoaQXV0b2NvbXBsZXRlRHluYW1pY1RyaWFsXzAYgMPQjAU4AUITTGl2ZVNwZWxsaW5nQ29udHJvbEogChZMaXZlU3BlbGxpbmdFeHBlcmltZW50ELYHGIaEygFKHAoTTGl2ZVNwZWxsaW5nQ29udHJvbBAyGIeEygFSFBIEMjYuKiAAIAEgAiADKAAoASgCEosBChpBdXRvY29tcGxldGVEeW5hbWljVHJpYWxfMRiAhNyPBTgBQg5EZWZhdWx0Q29udHJvbEodChREaXNhYmxlZFByb3ZpZGVyc18xNhAKGJeEygFKGAoORGVmYXVsdENvbnRyb2wQ9gcYmITKAVIWEgwyNi4wLjE0MTAuMTkgAygAKAEoAliN0I+PAhKAAQoaQXV0b2NvbXBsZXRlRHluYW1pY1RyaWFsXzIYgKfhjwU4AUIORGVmYXVsdENvbnRyb2xKHgoURW5hYmxlQ3Vyc29yUG9zaXRpb24QzAEYlYTKAUoYCg5EZWZhdWx0Q29udHJvbBC0BhiWhMoBUhASBDI4LiogASACKAAoASgCEsgBChpBdXRvY29tcGxldGVEeW5hbWljVHJpYWxfMxiAhNyPBTgBQg5EZWZhdWx0Q29udHJvbEohChhFbmFibGVaZXJvU3VnZ2VzdFF1ZXJpZXMQABiRhMoBSh4KFUVuYWJsZVplcm9TdWdnZXN0VXJscxAAGJKEygFKJQocRW5hYmxlWmVyb1N1Z2dlc3RRdWVyaWVzVXJscxAAGJOEygFKGAoORGVmYXVsdENvbnRyb2wQ6AcYlITKAVIOEgQyOS4qIAEoACgBKAISkgEKGENhY2hlU2Vuc2l0aXZpdHlBbmFseXNpcxjEx/KOBTgAQgJOb0oMCghDb250cm9sQRAFSgwKCENvbnRyb2xCEAVKCAoEMTAwQRAFSggKBDEwMEIQBUoICgQyMDBBEAVKCAoEMjAwQhAFSggKBDQwMEEQBUoICgQ0MDBCEAVKBgoCTm8QPFIKEgQyOC4qIAIoBBKaAQoYQ2FjaGVTZW5zaXRpdml0eUFuYWx5c2lzGMTK/YoFOABCAk5vSgYKAk5vECRKDAoIQ29udHJvbEEQCEoMCghDb250cm9sQhAISggKBDEwMEEQCEoICgQxMDBCEAhKCAoEMjAwQRAISggKBDIwMEIQCEoICgQ0MDBBEAhKCAoENDAwQhAIUhISBDI1LiogACABIAIoACgBKAISnQEKGENhY2hlU2Vuc2l0aXZpdHlBbmFseXNpcxjEstOKBTgAQgJOb0oHCgJObxDgB0oMCghDb250cm9sQRABSgwKCENvbnRyb2xCEAFKCAoEMTAwQRABSggKBDEwMEIQAUoICgQyMDBBEAFKCAoEMjAwQhABSggKBDQwMEEQAUoICgQ0MDBCEAFSFAiAp76KBRIEMjUuKiADKAAoASgCElYKG0RhdGFDb21wcmVzc2lvblByb3h5Um9sbG91dBjEgpe0BTgBQgdFbmFibGVkSgwKCERpc2FibGVkEABKDAoHRW5hYmxlZBDoB1IKIAAgASACKAQoBRJTChtEYXRhQ29tcHJlc3Npb25Qcm94eVJvbGxvdXQYxIKXtAU4AUIIRGlzYWJsZWRKDQoIRGlzYWJsZWQQ3gdKCwoHRW5hYmxlZBAKUgYgAygEKAUSRAoRRG5zUHJvYmUtQXR0ZW1wdHMYgLWNlgU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EFpKBQoBMRAKUgoSBDI1LiogACABEkcKD0Ruc1Byb2JlLUVuYWJsZRiAtY2WBTgBQgdkaXNhYmxlSgsKB2Rpc2FibGUQAEoKCgZlbmFibGUQZFIKEgQyNS4qIAAgARJjCiNVTUEtRHluYW1pYy1CaW5hcnktVW5pZm9ybWl0eS1UcmlhbBiAnJKlBTgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQMhiptskBShEKCGdyb3VwXzAxEDIYqrbJAVIGIAAgASACEl8KI1VNQS1EeW5hbWljLUJpbmFyeS1Vbmlmb3JtaXR5LVRyaWFsGICckqUFOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBBjGKm2yQFKEQoIZ3JvdXBfMDEQARiqtskBUgIgAxJXChRGb3JjZUNvbXBvc2l0aW5nTW9kZRiAkoiWBTgBQgdkaXNhYmxlSgsKB2Rpc2FibGUQZEoLCgdlbmFibGVkEABKCgoGdGhyZWFkEABSCBIEMjQuKigCElcKFEZvcmNlQ29tcG9zaXRpbmdNb2RlGICSiJYFOAFCB2Rpc2FibGVKCwoHZGlzYWJsZRAASgsKB2VuYWJsZWQQAEoKCgZ0aHJlYWQQZFIIEgQyOC4qKAESWQoURm9yY2VDb21wb3NpdGluZ01vZGUYgJKIlgU4AUIHZGlzYWJsZUoLCgdkaXNhYmxlEGRKCwoHZW5hYmxlZBAASgoKBnRocmVhZBAAUgoaBDI3LiogAygBElcKFEZvcmNlQ29tcG9zaXRpbmdNb2RlGICSiJYFOAFCB2Rpc2FibGVKCwoHZGlzYWJsZRAASgsKB2VuYWJsZWQQAEoKCgZ0aHJlYWQQZFIIEgQyNC4qKAASWQoURm9yY2VDb21wb3NpdGluZ01vZGUYgJKIlgU4AUIHZGlzYWJsZUoLCgdkaXNhYmxlEABKCwoHZW5hYmxlZBAySgoKBnRocmVhZBAyUgoSBDI0LiogAygAEosBCg1Ib3N0Q2FjaGVTaXplGMTNiIcFOABCB0RlZmF1bHRKCwoHRGVmYXVsdBAASggKBDEwMEEQCkoICgQxMDBCEApKCAoEMzAwQRAKSggKBDMwMEIQCkoJCgUxMDAwQRAKSgkKBTEwMDBCEApKCQoFMzAwMEEQCkoJCgUzMDAwQhAKUggSBDI1LiooAxKTAQoNSG9zdENhY2hlU2l6ZRjErPeHBTgAQgdEZWZhdWx0SgsKB0RlZmF1bHQQAEoICgQxMDBBEApKCAoEMTAwQhAKSggKBDMwMEEQCkoICgQzMDBCEApKCQoFMTAwMEEQCkoJCgUxMDAwQhAKSgkKBTMwMDBBEApKCQoFMzAwMEIQClIQEgQyNS4qIAAgASgAKAEoAhJECg1JbmZpbml0ZUNhY2hlGMS0jZYFOAFCAk5vSgcKAk5vENQHSgcKA1llcxAKSgsKB0NvbnRyb2wQClIIIAIoACgBKAISRgoNSW5maW5pdGVDYWNoZRjEtI2WBTgBQgJOb0oHCgJObxCEB0oHCgNZZXMQMkoLCgdDb250cm9sEDJSCiAAIAEoACgBKAISRAoNSW5maW5pdGVDYWNoZRjEtI2WBTgBQgJOb0oHCgJObxDmB0oHCgNZZXMQAUoLCgdDb250cm9sEAFSCCADKAAoASgCEt8ECgxJbnN0YW50RHVtbXkYgITcjwU4AUIMRGVmYXVsdEdyb3VwSi8KIUR1bW15R3JvdXAxIGNoYW5uZWw6c3RhYmxlIG1vZHM6MRABGMeFygEgx4XKAUovCiFEdW1teUdyb3VwMiBjaGFubmVsOnN0YWJsZSBtb2RzOjEQARjIhcoBIMiFygFKLwohRHVtbXlHcm91cDMgY2hhbm5lbDpzdGFibGUgbW9kczoxEAEYyYXKASDJhcoBSi8KIUR1bW15R3JvdXA0IGNoYW5uZWw6c3RhYmxlIG1vZHM6MRABGMqFygEgyoXKAUovCiFEdW1teUdyb3VwNSBjaGFubmVsOnN0YWJsZSBtb2RzOjkQCRjLhcoBIMuFygFKLwohRHVtbXlHcm91cDYgY2hhbm5lbDpzdGFibGUgbW9kczo5EAkYzIXKASDMhcoBSi8KIUR1bW15R3JvdXA3IGNoYW5uZWw6c3RhYmxlIG1vZHM6ORAJGM2FygEgzYXKAUovCiFEdW1teUdyb3VwOCBjaGFubmVsOnN0YWJsZSBtb2RzOjkQCRjOhcoBIM6FygFKMQojRHVtbXlHcm91cDkgY2hhbm5lbDpzdGFibGUgbW9kczoxMDAQZBjPhcoBIM+FygFKMgokRHVtbXlHcm91cDEwIGNoYW5uZWw6c3RhYmxlIG1vZHM6MTAwEGQY0IXKASDQhcoBSioKG0R1bW15UGFkZGluZyBjaGFubmVsOnN0YWJsZRD4BRjRhcoBINGFygFKEAoMRGVmYXVsdEdyb3VwEABSDBIEMjcuKiADKAAoARKpAgoPSW5zdGFudEV4dGVuZGVkGIDqvY4FOAFCDERlZmF1bHRHcm91cEo+Ci9Hcm91cDEgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6YmV0YRD6ARi9hcoBIL2FygFKRwo4R3JvdXAyIGVzcHY6MjA1IHVzZV9yZW1vdGVfbnRwX29uX3N0YXJ0dXA6MSBjaGFubmVsOmJldGEQ+gEYvoXKASC+hcoBSiQKFUNvbnRyb2wxIGNoYW5uZWw6YmV0YRD6ARi/hcoBIL+FygFKJAoVQ29udHJvbDIgY2hhbm5lbDpiZXRhEPoBGMCFygEgwIXKAUoQCgxEZWZhdWx0R3JvdXAQAFIOEgQyOC4qIAIoACgBKANY2o+ih/n/////ARKmAgoPSW5zdGFudEV4dGVuZGVkGIDqvY4FOAFCDERlZmF1bHRHcm91cEpACjFHcm91cDEgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6Y2FuYXJ5EPoBGOeDygEg54PKAUpJCjpHcm91cDIgZXNwdjoyMDUgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6Y2FuYXJ5EPoBGISEygEghITKAUomChdDb250cm9sMSBjaGFubmVsOmNhbmFyeRD6ARjog8oBIOiDygFKJgoXQ29udHJvbDIgY2hhbm5lbDpjYW5hcnkQ+gEYgoTKASCChMoBShAKDERlZmF1bHRHcm91cBAAUg4SBDI4LiogACgAKAEoAxKgAgoPSW5zdGFudEV4dGVuZGVkGIDqvY4FOAFCDERlZmF1bHRHcm91cEo9Ci5Hcm91cDEgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6ZGV2EPoBGLmFygEguYXKAUpGCjdHcm91cDIgZXNwdjoyMDUgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6ZGV2EPoBGLqFygEguoXKAUojChRDb250cm9sMSBjaGFubmVsOmRldhD6ARi7hcoBILuFygFKIwoUQ29udHJvbDIgY2hhbm5lbDpkZXYQ+gEYvIXKASC8hcoBShAKDERlZmF1bHRHcm91cBAAUg4SBDI4LiogASgAKAEoA1jkr7jAARKLAwoPSW5zdGFudEV4dGVuZGVkGICE3I8FOAFCDERlZmF1bHRHcm91cEpRCkNHcm91cDEgZXNwdjoyMDUgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6c3RhYmxlIERJU0FCTEVEEAEYwYXKASDBhcoBSlEKQ0dyb3VwMiBlc3B2OjIwNSB1c2VfcmVtb3RlX250cF9vbl9zdGFydHVwOjEgY2hhbm5lbDpzdGFibGUgRElTQUJMRUQQCRjFhcoBIMWFygFKJgoXUGFkZGluZzEgY2hhbm5lbDpzdGFibGUQ6gMYwoXKASDChcoBSiUKF0NvbnRyb2wxIGNoYW5uZWw6c3RhYmxlEAEYw4XKASDDhcoBSiUKF0NvbnRyb2wyIGNoYW5uZWw6c3RhYmxlEAkYxoXKASDGhcoBSiYKF1BhZGRpbmcyIGNoYW5uZWw6c3RhYmxlEOoDGMSFygEgxIXKAUoQCgxEZWZhdWx0R3JvdXAQAFIMEgQyNy4qIAMoACgBEogCChZJbnRlcnN0aXRpYWxNYWx3YXJlMzEwGMDpw5MFOAFCB0RlZmF1bHRKDAoHRGVmYXVsdBCzAUoXChNjb25kMU1hbHdhcmVDb250cm9sEANKFwoTY29uZDJNYWx3YXJlTm9CcmFuZBADShcKE2NvbmQ1TWFsd2FyZU9uZVN0ZXAQA0oXChNjb25kN01hbHdhcmVGZWFyTXNnEANKGQoVY29uZDlNYWx3YXJlQ29sbGFiTXNnEANKGQoVY29uZDExTWFsd2FyZVF1ZXN0aW9uEANKFwoTY29uZDEzTWFsd2FyZUdvQmFjaxADUhwIwNmjjAUoACgBKAIoAzIFZW4tVVMyBWVuLUdCEpECChdJbnRlcnN0aXRpYWxQaGlzaGluZzU2NBjA6cOTBTgBQgdEZWZhdWx0SgwKB0RlZmF1bHQQswFKGAoUY29uZDNQaGlzaGluZ0NvbnRyb2wQA0oYChRjb25kNFBoaXNoaW5nTm9CcmFuZBADShgKFGNvbmQ2UGhpc2hpbmdPbmVTdGVwEANKGAoUY29uZDhQaGlzaGluZ0ZlYXJNc2cQA0obChdjb25kMTBQaGlzaGluZ0NvbGxhYk1zZxADShoKFmNvbmQxMlBoaXNoaW5nUXVlc3Rpb24QA0oYChRjb25kMTRQaGlzaGluZ0dvQmFjaxADUhwIwNmjjAUoACgBKAIoAzIFZW4tVVMyBWVuLUdCEsMBChJJbnRlcnN0aXRpYWxTU0w1MTcYwOnDkwU4AUIHRGVmYXVsdEoMCgdEZWZhdWx0ELMBShkKFUNvbmRpdGlvbjE1U1NMQ29udHJvbBADShkKFUNvbmRpdGlvbjE2U1NMRmlyZWZveBADSh4KGkNvbmRpdGlvbjE3U1NMRmFuY3lGaXJlZm94EANKGgoWQ29uZGl0aW9uMThTU0xOb0ltYWdlcxADUhwIwNmjjAUoACgBKAIoAzIFZW4tVVMyBWVuLUdCElEKEU1hbmFnZWRNb2RlTGF1bmNoGIDzx5IFOAFCCEluYWN0aXZlSgoKBkFjdGl2ZRBkSgwKCEluYWN0aXZlEABSEBIEMjkuKiAAIAEoACgBKAISsAIKGE1vc3RWaXNpdGVkVGlsZVBsYWNlbWVudBiArZqNBTgBQgdEZWZhdWx0ShYKEk9uZUVpZ2h0X0FfRmxpcHBlZBADShYKEk9uZUVpZ2h0X0JfRmxpcHBlZBADShYKEk9uZUVpZ2h0X0NfRmxpcHBlZBADShYKEk9uZUVpZ2h0X0RfRmxpcHBlZBADShUKEU9uZUZvdXJfQV9GbGlwcGVkEANKFQoRT25lRm91cl9CX0ZsaXBwZWQQA0oVChFPbmVGb3VyX0NfRmxpcHBlZBADShUKEU9uZUZvdXJfRF9GbGlwcGVkEANKCwoHQ29udHJvbBADShQKEERvbnRTaG93T3BlblRhYnMQA0oLCgdEZWZhdWx0EEZSFxILMjguMC4xNDk2LjAgASgAKAEoAigDElcKDE5ld01lbnVTdHlsZRiA0J+NBTgBQgdEZWZhdWx0SgsKB0RlZmF1bHQQAEoNCghOZXdTdHlsZRDmB0oMCghPbGRTdHlsZRACUgwSBDI2LiogAygAKAMSfgoMTmV3TWVudVN0eWxlGICn4Y8FOAFCB0RlZmF1bHRKCwoHRGVmYXVsdBA8SgwKCENvbXBhY3QxEApKDAoIQ29tcGFjdDIQCkoSCg5IaWdoZXJDb250cmFzdBAKShAKDENvbnRyb2xHcm91cBAKUg4SBDI4LiogASAAKAAoAxJXCgxOZXdUYWJCdXR0b24YgLWNlgU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EGJKCwoHQ29udHJvbBABSggKBFBsdXMQAVISEgwyMS4wLjExODAuMTUgAygAEs0BCh5PbW5pYm94UmVwbGFjZUhVUEFuZE5ld1Njb3JpbmcYwIWzkAU4AUIIU3RhbmRhcmRKDAoIU3RhbmRhcmQQPEoNCglTdGFuZGFyZDIQCkodChlIUVAtcG9zdHBlcmlvZC1SZXBsYWNlSFVQEApKDgoKTmV3U2NvcmluZxAKSjQKMEhRUC1wb3N0cGVyaW9kLVJlcGxhY2VIVVBfTmV3LXBvc3RwZXJpb2QtU2NvcmluZxAKUhcIwJ+LhwUSCzI4LjAuMTQ5OS4qIAEgAhJlChBPbW5pYm94U3RvcFRpbWVyGMDRmZMFOAFCCFN0YW5kYXJkShIKCFN0YW5kYXJkEPQDGLeFygFKFgoMVXNlU3RvcFRpbWVyEPQDGLiFygFSEwjAzNSLBRILMjguMC4xNDg4LjASZgoXUHJlcmVuZGVyTG9jYWxQcmVkaWN0b3IYxIehjAU4AEIIRGlzYWJsZWRKDQoIRGlzYWJsZWQQ1AdKCwoHRW5hYmxlZBAKSgsKB0NvbnRyb2wQClIQEgQyNS4qIAMgAigAKAEoAhJmChdQcmVyZW5kZXJMb2NhbFByZWRpY3RvchjEtI2WBTgAQghEaXNhYmxlZEoMCghEaXNhYmxlZBBkSgwKB0VuYWJsZWQQoAZKCwoHQ29udHJvbBBkUhASBDI1LiogACABKAAoASgCEocBCgRRVUlDGMTjhJEFOABCCERpc2FibGVkSgsKB0VuYWJsZWQQCkoMCghEaXNhYmxlZBBaSh4KDUVuYWJsZWRCeUZsYWcQACoLZW5hYmxlLXF1aWNKIAoORGlzYWJsZWRCeUZsYWcQACoMZGlzYWJsZS1xdWljUhASBDI5LiogACABKAAoASgCEjYKDlNCSW50ZXJzdGl0aWFsGMDSjYkFOAFCAlYxSgYKAlYxEAFKBgoCVjIQY1IIKAAoASgCKAMSqgEKGFNlbmRGZWVkYmFja0xpbmtMb2NhdGlvbjgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQKBiphcoBShAKB2NvbnRyb2wQDxj4hMoBShEKCGFsdC10ZXh0EA8Y/ITKAUoVCgxhbHQtbG9jYXRpb24QDxiChcoBSh4KFWFsdC10ZXh0LWFuZC1sb2NhdGlvbhAPGIiFygFSFRILMjcuMC4xNDUzLiogAigAKAIoARKmAQoYU2VuZEZlZWRiYWNrTGlua0xvY2F0aW9uOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBAoGKmFygFKEAoHY29udHJvbBAPGPmEygFKEQoIYWx0LXRleHQQDxj/hMoBShUKDGFsdC1sb2NhdGlvbhAPGIWFygFKHgoVYWx0LXRleHQtYW5kLWxvY2F0aW9uEA8Yi4XKAVIREgsyNy4wLjE0NTMuKiACKAMSqgEKGFNlbmRGZWVkYmFja0xpbmtMb2NhdGlvbjgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQKBiphcoBShAKB2NvbnRyb2wQDxj4hMoBShEKCGFsdC10ZXh0EA8Y+oTKAUoVCgxhbHQtbG9jYXRpb24QDxiAhcoBSh4KFWFsdC10ZXh0LWFuZC1sb2NhdGlvbhAPGIaFygFSFRILMjcuMC4xNDUzLiogASgAKAIoARKmAQoYU2VuZEZlZWRiYWNrTGlua0xvY2F0aW9uOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBAoGKmFygFKEAoHY29udHJvbBAPGPmEygFKEQoIYWx0LXRleHQQDxj9hMoBShUKDGFsdC1sb2NhdGlvbhAPGIOFygFKHgoVYWx0LXRleHQtYW5kLWxvY2F0aW9uEA8YiYXKAVIREgsyNy4wLjE0NTMuKiABKAMSqgEKGFNlbmRGZWVkYmFja0xpbmtMb2NhdGlvbjgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQPBiphcoBShAKB2NvbnRyb2wQChj4hMoBShEKCGFsdC10ZXh0EAoY+4TKAUoVCgxhbHQtbG9jYXRpb24QChiBhcoBSh4KFWFsdC10ZXh0LWFuZC1sb2NhdGlvbhAKGIeFygFSFRILMjcuMC4xNDUzLiogAygAKAIoARKmAQoYU2VuZEZlZWRiYWNrTGlua0xvY2F0aW9uOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBA8GKmFygFKEAoHY29udHJvbBAKGPmEygFKEQoIYWx0LXRleHQQChj+hMoBShUKDGFsdC1sb2NhdGlvbhAKGISFygFKHgoVYWx0LXRleHQtYW5kLWxvY2F0aW9uEAoYioXKAVIREgsyNy4wLjE0NTMuKiADKAMSYgoTU2hvd1Byb2ZpbGVTd2l0Y2hlchjAyuCKBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQUEoLCgdjb250cm9sEApKDgoKQWx3YXlzU2hvdxAKUhASBDI2LiogACABKAAoASgCElcKD1NpZGVsb2FkV2lwZW91dBjEnJ2LBTgBQghEaXNhYmxlZEoMCghEaXNhYmxlZBAASgsKB0VuYWJsZWQQZFIXEgsyNS4wLjEzNjAuKiAAIAEgAiADKAASdwoaU2lnbkluVG9DaHJvbWVDb25maXJtYXRpb24YwMrgigU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EFBKFAoQY29udHJvbF9ESVNBQkxFRBAKShMKD0J1YmJsZV9ESVNBQkxFRBAKUhASBDI2LiogACABKAAoASgCEoQBChBTaW1wbGVDYWNoZVRyaWFsGMS0jZYFOAFCDEV4cGVyaW1lbnROb0oQCgxFeHBlcmltZW50Tm8QZEoRCg1FeHBlcmltZW50WWVzEABKEgoORXhwZXJpbWVudFllczIQAEoVChFFeHBlcmltZW50Q29udHJvbBAAUgoSBDI4LiogAigEEoYBChBTaW1wbGVDYWNoZVRyaWFsGMS0jZYFOAFCDEV4cGVyaW1lbnROb0oQCgxFeHBlcmltZW50Tm8QAEoRCg1FeHBlcmltZW50WWVzEFBKEgoORXhwZXJpbWVudFllczIQCkoVChFFeHBlcmltZW50Q29udHJvbBAKUgwSBDI4LiogACABKAQSlQMKHlNwZWN1bGF0aXZlUmVzb3VyY2VQcmVmZXRjaGluZxiAnOOKBTgBQghEaXNhYmxlZEoMCghEaXNhYmxlZBAoShAKDExlYXJuaW5nSG9zdBAKSg8KC0xlYXJuaW5nVVJMEApKDAoITGVhcm5pbmcQCkoTCg9QcmVmZXRjaGluZ0hvc3QQCkoSCg5QcmVmZXRjaGluZ1VSTBAKSg8KC1ByZWZldGNoaW5nEApKHAoYUHJlZmV0Y2hpbmdMb3dDb25maWRlbmNlEABKHQoZUHJlZmV0Y2hpbmdIaWdoQ29uZmlkZW5jZRAAShwKGFByZWZldGNoaW5nTW9yZVJlc291cmNlcxAAShMKD0xlYXJuaW5nU21hbGxEQhAAShYKElByZWZldGNoaW5nU21hbGxEQhAASiMKH1ByZWZldGNoaW5nU21hbGxEQkxvd0NvbmZpZGVuY2UQAEokCiBQcmVmZXRjaGluZ1NtYWxsREJIaWdoQ29uZmlkZW5jZRAAUhUSCzI1LjAuMTM2NC4qIAIoACgBKAISlwMKHlNwZWN1bGF0aXZlUmVzb3VyY2VQcmVmZXRjaGluZxiAnOOKBTgBQghEaXNhYmxlZEoMCghEaXNhYmxlZBAoShAKDExlYXJuaW5nSG9zdBAKSg8KC0xlYXJuaW5nVVJMEApKDAoITGVhcm5pbmcQCkoTCg9QcmVmZXRjaGluZ0hvc3QQCkoSCg5QcmVmZXRjaGluZ1VSTBAKSg8KC1ByZWZldGNoaW5nEApKHAoYUHJlZmV0Y2hpbmdMb3dDb25maWRlbmNlEABKHQoZUHJlZmV0Y2hpbmdIaWdoQ29uZmlkZW5jZRAAShwKGFByZWZldGNoaW5nTW9yZVJlc291cmNlcxAAShMKD0xlYXJuaW5nU21hbGxEQhAAShYKElByZWZldGNoaW5nU21hbGxEQhAASiMKH1ByZWZldGNoaW5nU21hbGxEQkxvd0NvbmZpZGVuY2UQAEokCiBQcmVmZXRjaGluZ1NtYWxsREJIaWdoQ29uZmlkZW5jZRAAUhcSCzI1LjAuMTM2NC4qIAAgASgAKAEoAhJSCgpTcGVsbGNoZWNrGMTbtI0FOAFCB0RlZmF1bHRKCwoHRGVmYXVsdBBkSg8KC1N1Z2dlc3Rpb25zEABSFRILMjYuMC4xNDAzLjAgAiABIAAoABJUCgpTcGVsbGNoZWNrGMTbtI0FOAFCB0RlZmF1bHRKCwoHRGVmYXVsdBBkSg8KC1N1Z2dlc3Rpb25zEABSFxILMjYuMC4xNDAzLjAgAyACIAEoAigDEk4KClNwZWxsY2hlY2sYxNu0jQU4AUIHRGVmYXVsdEoLCgdEZWZhdWx0EGRKDwoLU3VnZ2VzdGlvbnMQAFIREgsyNi4wLjE0MDMuMCADKAASTwoNRW5hYmxlU3RhZ2UzRBiAiP6GBTgBQgdlbmFibGVkSgwKB2VuYWJsZWQQtgdKDwoLYmxhY2tsaXN0ZWQQMlIOEgQyMi4qIAAgASACKAASUQoNRW5hYmxlU3RhZ2UzRBiAiP6GBTgBQgdlbmFibGVkSgwKB2VuYWJsZWQQ6AdKDwoLYmxhY2tsaXN0ZWQQAFIQEgQyMi4qGgQyMi4qIAMoABJoCg1FbmFibGVTdGFnZTNEGIDfv4kFOAFCD2VuYWJsZWRfZGVmYXVsdEoTCg9lbmFibGVkX2RlZmF1bHQQAEoMCgdlbmFibGVkEOgHSg8KC2JsYWNrbGlzdGVkEABSChIEMjMuKiADKAASTgoTVGVzdDBQZXJjZW50RGVmYXVsdBiAnJKlBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQAEoMCghncm91cF8wMRBkSgsKB2RvZ2Zvb2QQABLaAQocVU1BLUR5bmFtaWMtVW5pZm9ybWl0eS1UcmlhbBiAnJKlBTgBQgdEZWZhdWx0ShQKBkdyb3VwMRABGL+2yQEgv7bJAUoUCgZHcm91cDIQCRjAtskBIMC2yQFKFQoGR3JvdXAzEOoDGMG2yQEgwbbJAUoUCgZHcm91cDQQARjCtskBIMK2yQFKFAoGR3JvdXA1EAkYw7bJASDDtskBShUKBkdyb3VwNhDqAxjEtskBIMS2yQFKFQoHRGVmYXVsdBAAGMW2yQEgxbbJAVIMEgQyNy4qIAMoACgBEr0BCh9VTUEtVW5pZm9ybWl0eS1UcmlhbC0xMC1QZXJjZW50GICckqUFOAFCB2RlZmF1bHRKCwoHZGVmYXVsdBABSgwKCGdyb3VwXzAxEAFKDAoIZ3JvdXBfMDIQAUoMCghncm91cF8wMxABSgwKCGdyb3VwXzA0EAFKDAoIZ3JvdXBfMDUQAUoMCghncm91cF8wNhABSgwKCGdyb3VwXzA3EAFKDAoIZ3JvdXBfMDgQAUoMCghncm91cF8wORABEqYPCh5VTUEtVW5pZm9ybWl0eS1UcmlhbC0xLVBlcmNlbnQYgJySpQU4AUIHZGVmYXVsdEoQCgdkZWZhdWx0EAEYoLXJAUoRCghncm91cF8wMRABGKG1yQFKEQoIZ3JvdXBfMDIQARiitckBShEKCGdyb3VwXzAzEAEYo7XJAUoRCghncm91cF8wNBABGKS1yQFKEQoIZ3JvdXBfMDUQARiltckBShEKCGdyb3VwXzA2EAEYprXJAUoRCghncm91cF8wNxABGKe1yQFKEQoIZ3JvdXBfMDgQARiotckBShEKCGdyb3VwXzA5EAEYqbXJAUoRCghncm91cF8xMBABGKq1yQFKEQoIZ3JvdXBfMTEQARirtckBShEKCGdyb3VwXzEyEAEYrLXJAUoRCghncm91cF8xMxABGK21yQFKEQoIZ3JvdXBfMTQQARiutckBShEKCGdyb3VwXzE1EAEYr7XJAUoRCghncm91cF8xNhABGLC1yQFKEQoIZ3JvdXBfMTcQARixtckBShEKCGdyb3VwXzE4EAEYsrXJAUoRCghncm91cF8xORABGLO1yQFKEQoIZ3JvdXBfMjAQARi0tckBShEKCGdyb3VwXzIxEAEYtbXJAUoRCghncm91cF8yMhABGLa1yQFKEQoIZ3JvdXBfMjMQARi3tckBShEKCGdyb3VwXzI0EAEYuLXJAUoRCghncm91cF8yNRABGLm1yQFKEQoIZ3JvdXBfMjYQARi6tckBShEKCGdyb3VwXzI3EAEYu7XJAUoRCghncm91cF8yOBABGLy1yQFKEQoIZ3JvdXBfMjkQARi9tckBShEKCGdyb3VwXzMwEAEYvrXJAUoRCghncm91cF8zMRABGL+1yQFKEQoIZ3JvdXBfMzIQARjAtckBShEKCGdyb3VwXzMzEAEYwbXJAUoRCghncm91cF8zNBABGMK1yQFKEQoIZ3JvdXBfMzUQARjDtckBShEKCGdyb3VwXzM2EAEYxLXJAUoRCghncm91cF8zNxABGMW1yQFKEQoIZ3JvdXBfMzgQARjGtckBShEKCGdyb3VwXzM5EAEYx7XJAUoRCghncm91cF80MBABGMi1yQFKEQoIZ3JvdXBfNDEQARjJtckBShEKCGdyb3VwXzQyEAEYyrXJAUoRCghncm91cF80MxABGMu1yQFKEQoIZ3JvdXBfNDQQARjMtckBShEKCGdyb3VwXzQ1EAEYzbXJAUoRCghncm91cF80NhABGM61yQFKEQoIZ3JvdXBfNDcQARjPtckBShEKCGdyb3VwXzQ4EAEY0LXJAUoRCghncm91cF80ORABGNG1yQFKEQoIZ3JvdXBfNTAQARjStckBShEKCGdyb3VwXzUxEAEY07XJAUoRCghncm91cF81MhABGNS1yQFKEQoIZ3JvdXBfNTMQARjVtckBShEKCGdyb3VwXzU0EAEY1rXJAUoRCghncm91cF81NRABGNe1yQFKEQoIZ3JvdXBfNTYQARjYtckBShEKCGdyb3VwXzU3EAEY2bXJAUoRCghncm91cF81OBABGNq1yQFKEQoIZ3JvdXBfNTkQARjbtckBShEKCGdyb3VwXzYwEAEY3LXJAUoRCghncm91cF82MRABGN21yQFKEQoIZ3JvdXBfNjIQARjetckBShEKCGdyb3VwXzYzEAEY37XJAUoRCghncm91cF82NBABGOC1yQFKEQoIZ3JvdXBfNjUQARjhtckBShEKCGdyb3VwXzY2EAEY4rXJAUoRCghncm91cF82NxABGOO1yQFKEQoIZ3JvdXBfNjgQARjktckBShEKCGdyb3VwXzY5EAEY5bXJAUoRCghncm91cF83MBABGOa1yQFKEQoIZ3JvdXBfNzEQARjntckBShEKCGdyb3VwXzcyEAEY6LXJAUoRCghncm91cF83MxABGOm1yQFKEQoIZ3JvdXBfNzQQARjqtckBShEKCGdyb3VwXzc1EAEY67XJAUoRCghncm91cF83NhABGOy1yQFKEQoIZ3JvdXBfNzcQARjttckBShEKCGdyb3VwXzc4EAEY7rXJAUoRCghncm91cF83ORABGO+1yQFKEQoIZ3JvdXBfODAQARjwtckBShEKCGdyb3VwXzgxEAEY8bXJAUoRCghncm91cF84MhABGPK1yQFKEQoIZ3JvdXBfODMQARjztckBShEKCGdyb3VwXzg0EAEY9LXJAUoRCghncm91cF84NRABGPW1yQFKEQoIZ3JvdXBfODYQARj2tckBShEKCGdyb3VwXzg3EAEY97XJAUoRCghncm91cF84OBABGPi1yQFKEQoIZ3JvdXBfODkQARj5tckBShEKCGdyb3VwXzkwEAEY+rXJAUoRCghncm91cF85MRABGPu1yQFKEQoIZ3JvdXBfOTIQARj8tckBShEKCGdyb3VwXzkzEAEY/bXJAUoRCghncm91cF85NBABGP61yQFKEQoIZ3JvdXBfOTUQARj/tckBShEKCGdyb3VwXzk2EAEYgLbJAUoRCghncm91cF85NxABGIG2yQFKEQoIZ3JvdXBfOTgQARiCtskBShEKCGdyb3VwXzk5EAEYg7bJAVIIKAAoASgCKAMSrgsKHlVNQS1Vbmlmb3JtaXR5LVRyaWFsLTEtUGVyY2VudBiAnJKlBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQAUoMCghncm91cF8wMRABSgwKCGdyb3VwXzAyEAFKDAoIZ3JvdXBfMDMQAUoMCghncm91cF8wNBABSgwKCGdyb3VwXzA1EAFKDAoIZ3JvdXBfMDYQAUoMCghncm91cF8wNxABSgwKCGdyb3VwXzA4EAFKDAoIZ3JvdXBfMDkQAUoMCghncm91cF8xMBABSgwKCGdyb3VwXzExEAFKDAoIZ3JvdXBfMTIQAUoMCghncm91cF8xMxABSgwKCGdyb3VwXzE0EAFKDAoIZ3JvdXBfMTUQAUoMCghncm91cF8xNhABSgwKCGdyb3VwXzE3EAFKDAoIZ3JvdXBfMTgQAUoMCghncm91cF8xORABSgwKCGdyb3VwXzIwEAFKDAoIZ3JvdXBfMjEQAUoMCghncm91cF8yMhABSgwKCGdyb3VwXzIzEAFKDAoIZ3JvdXBfMjQQAUoMCghncm91cF8yNRABSgwKCGdyb3VwXzI2EAFKDAoIZ3JvdXBfMjcQAUoMCghncm91cF8yOBABSgwKCGdyb3VwXzI5EAFKDAoIZ3JvdXBfMzAQAUoMCghncm91cF8zMRABSgwKCGdyb3VwXzMyEAFKDAoIZ3JvdXBfMzMQAUoMCghncm91cF8zNBABSgwKCGdyb3VwXzM1EAFKDAoIZ3JvdXBfMzYQAUoMCghncm91cF8zNxABSgwKCGdyb3VwXzM4EAFKDAoIZ3JvdXBfMzkQAUoMCghncm91cF80MBABSgwKCGdyb3VwXzQxEAFKDAoIZ3JvdXBfNDIQAUoMCghncm91cF80MxABSgwKCGdyb3VwXzQ0EAFKDAoIZ3JvdXBfNDUQAUoMCghncm91cF80NhABSgwKCGdyb3VwXzQ3EAFKDAoIZ3JvdXBfNDgQAUoMCghncm91cF80ORABSgwKCGdyb3VwXzUwEAFKDAoIZ3JvdXBfNTEQAUoMCghncm91cF81MhABSgwKCGdyb3VwXzUzEAFKDAoIZ3JvdXBfNTQQAUoMCghncm91cF81NRABSgwKCGdyb3VwXzU2EAFKDAoIZ3JvdXBfNTcQAUoMCghncm91cF81OBABSgwKCGdyb3VwXzU5EAFKDAoIZ3JvdXBfNjAQAUoMCghncm91cF82MRABSgwKCGdyb3VwXzYyEAFKDAoIZ3JvdXBfNjMQAUoMCghncm91cF82NBABSgwKCGdyb3VwXzY1EAFKDAoIZ3JvdXBfNjYQAUoMCghncm91cF82NxABSgwKCGdyb3VwXzY4EAFKDAoIZ3JvdXBfNjkQAUoMCghncm91cF83MBABSgwKCGdyb3VwXzcxEAFKDAoIZ3JvdXBfNzIQAUoMCghncm91cF83MxABSgwKCGdyb3VwXzc0EAFKDAoIZ3JvdXBfNzUQAUoMCghncm91cF83NhABSgwKCGdyb3VwXzc3EAFKDAoIZ3JvdXBfNzgQAUoMCghncm91cF83ORABSgwKCGdyb3VwXzgwEAFKDAoIZ3JvdXBfODEQAUoMCghncm91cF84MhABSgwKCGdyb3VwXzgzEAFKDAoIZ3JvdXBfODQQAUoMCghncm91cF84NRABSgwKCGdyb3VwXzg2EAFKDAoIZ3JvdXBfODcQAUoMCghncm91cF84OBABSgwKCGdyb3VwXzg5EAFKDAoIZ3JvdXBfOTAQAUoMCghncm91cF85MRABSgwKCGdyb3VwXzkyEAFKDAoIZ3JvdXBfOTMQAUoMCghncm91cF85NBABSgwKCGdyb3VwXzk1EAFKDAoIZ3JvdXBfOTYQAUoMCghncm91cF85NxABSgwKCGdyb3VwXzk4EAFKDAoIZ3JvdXBfOTkQAVIEKAQoBRJ3Ch9VTUEtVW5pZm9ybWl0eS1UcmlhbC0yMC1QZXJjZW50GICckqUFOAFCB2RlZmF1bHRKCwoHZGVmYXVsdBABSgwKCGdyb3VwXzAxEAFKDAoIZ3JvdXBfMDIQAUoMCghncm91cF8wMxABSgwKCGdyb3VwXzA0EAESTQofVU1BLVVuaWZvcm1pdHktVHJpYWwtNTAtUGVyY2VudBiAnJKlBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQAUoMCghncm91cF8wMRABErYDCh5VTUEtVW5pZm9ybWl0eS1UcmlhbC01LVBlcmNlbnQYgJySpQU4AUIHZGVmYXVsdEoQCgdkZWZhdWx0EAEYhLbJAUoRCghncm91cF8wMRABGIW2yQFKEQoIZ3JvdXBfMDIQARiGtskBShEKCGdyb3VwXzAzEAEYh7bJAUoRCghncm91cF8wNBABGIi2yQFKEQoIZ3JvdXBfMDUQARiJtskBShEKCGdyb3VwXzA2EAEYirbJAUoRCghncm91cF8wNxABGIu2yQFKEQoIZ3JvdXBfMDgQARiMtskBShEKCGdyb3VwXzA5EAEYjbbJAUoRCghncm91cF8xMBABGI62yQFKEQoIZ3JvdXBfMTEQARiPtskBShEKCGdyb3VwXzEyEAEYkLbJAUoRCghncm91cF8xMxABGJG2yQFKEQoIZ3JvdXBfMTQQARiStskBShEKCGdyb3VwXzE1EAEYk7bJAUoRCghncm91cF8xNhABGJS2yQFKEQoIZ3JvdXBfMTcQARiVtskBShEKCGdyb3VwXzE4EAEYlrbJAUoRCghncm91cF8xORABGJe2yQFSCCgAKAEoAigDEs4CCh5VTUEtVW5pZm9ybWl0eS1UcmlhbC01LVBlcmNlbnQYgJySpQU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EAFKDAoIZ3JvdXBfMDEQAUoMCghncm91cF8wMhABSgwKCGdyb3VwXzAzEAFKDAoIZ3JvdXBfMDQQAUoMCghncm91cF8wNRABSgwKCGdyb3VwXzA2EAFKDAoIZ3JvdXBfMDcQAUoMCghncm91cF8wOBABSgwKCGdyb3VwXzA5EAFKDAoIZ3JvdXBfMTAQAUoMCghncm91cF8xMRABSgwKCGdyb3VwXzEyEAFKDAoIZ3JvdXBfMTMQAUoMCghncm91cF8xNBABSgwKCGdyb3VwXzE1EAFKDAoIZ3JvdXBfMTYQAUoMCghncm91cF8xNxABSgwKCGdyb3VwXzE4EAFKDAoIZ3JvdXBfMTkQAVIEKAQoBQ=="
CHR Extension: ({"name":"Avira SearchFree Toolbar plus Web Protection","version":"22.57772","manifest_version":2,"description":"Convenient tools and links to make your browsing more enjoyable","icons":{"128":"config/skin/images/logo/logo_128x.png","32":"config/skin/images/logo/logo_32x.png","24":"config/skin/images/logo/logo_24x.png"},"browser_action":{"default_icon":"config/skin/images/logo/logo_19x.png","default_title":"Control the Avira SearchFree Toolbar","default_popup":"config/skin/chrome-options.html"},"background":{"page":"background/background.html"},"chrome_url_overrides":{"newtab":"config/skin/new-tab-page.html"},"content_scripts":[{"matches":["*://*/*"],"js":["lib/constant.js","lib/default-config.js","config/tb-config.js","lib/protocol.js","lib/tb-message.js","lib/widget-messaging.js","content_script/inline-html.js"],"all_frames":true,"run_at":"document_end"},{"matches":["*://*/*"],"js":["lib/jquery.js","lib/constant.js","lib/default-config.js","config/tb-config.js","config/widget-config.js","lib/protocol.js","lib/tb-message.js","lib/state-machine.js","lib/window-position.js","content_script/positioning.js","content_script/toolbar.js","content_script/widget.js","content_script/injector.js"],"run_at":"document_start"},{"matches":["*://*.facebook.com/*"],"css":["content_script/hack/facebook.css"]},{"matches":["*://*.google.com/*","*://*.ask.com/","*://*.bagsbuy.com/*","*://*.csaa.com/*","*://*.childrenschorus.org/*","*://*.wikipedia.org/*","*://*.mercurynews.com/*","*://*.usnews.com/*"],"css":["content_script/hack/relative.css"],"run_at":"document_start"},{"matches":["*://*.google.com/imgres*","*://images.google.com/*","*://codesearch.google.com/*"],"css":["content_script/hack/static.css"],"run_at":"document_start"}],"permissions":["bookmarks","contextMenus","contentSettings","cookies","geolocation","history","idle","management","notifications","tabs","unlimitedStorage","webRequest","webRequestBlocking","hxxp://*/*","https://*/*","chrome://favicon/*","bookmarks","contextMenus","contentSettings","cookies","geolocation","history","idle","management","notifications","tabs","unlimitedStorage","hxxp://*/*","https://*/*","chrome://favicon/*","webRequest","webRequestBlocking"],"plugins":[{"path":"background/ChromeUtilPlugin.dll","public":false}],"update_url":"hxxp://apnmedia.ask.com/media/toolbar/everest/partners/AVIRA-V7/ZF/update.xml","web_accessible_resources":["config/skin/css/containers.css","config/skin/toolbar.html","widgets/search-suggestion/search-suggestion.html","widgets/options/options.html","widgets/templates/feed.html","widgets/templates/menu.html","config/skin/widgets/com.avira.dnt/widget/background.html","config/skin/widgets/com.avira.dnt/widget/button.html","config/skin/widgets/com.avira.dnt/widget/window.html","config/skin/widgets/com.avira.dnt/widget/blank.html","config/skin/widgets/com.avira.dnt/widget/blank.gif","config/skin/widgets/toolbar-options/options.html"]}) - C:\Users\aysenur\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\22.57772
CHR Extension: (PriceGong) - C:\Users\aysenur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.11_1
CHR Extension: (Torch Share) - C:\Users\aysenur\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.4232_1
CHR Extension: (PricePeep) - C:\Users\aysenur\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb\2.2.0.3_0
CHR Extension: (Yontoo) - C:\Users\aysenur\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_1
CHR Extension: (Chrome In-App Payments service) - C:\Users\aysenur\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR HKLM-x32\...\Chrome\Extension: [bkomkajifikmkfnjgphkjcfeepbnojok] - C:\Program Files (x86)\PriceGong\2.6.11\pricegong.crx
CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Administrator\AppData\Local\Wajam\Chrome\wajam.crx
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\aysenur\AppData\Local\Torch\Plugins\TorchPlugin.crx
CHR HKLM-x32\...\Chrome\Extension: [leocdeigfnkaojcapikdjcdbedcjmffc] - C:\Users\Administrator\AppData\Local\CRE\leocdeigfnkaojcapikdjcdbedcjmffc.crx
CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files (x86)\Yontoo\YontooLayers.crx
==================== Services (Whitelisted) =================
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-20] (Just Develop It)
R2 omigaplussvc; C:\Program Files (x86)\Omiga Plus\omigaplusSvc.exe [424104 2013-10-05] (Taiwan Shui Mu Chih Ching Technology Limited.)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-20] (Microsoft Corporation)
S4 SProtection; C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe [2864448 2013-08-21] (Iminent)
S4 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-09-12] ()
S4 TorchCrashHandler; C:\Users\aysenur\AppData\Local\Torch\Update\TorchCrashHandler.exe [1207648 2013-07-30] (TorchMedia Inc.)
S4 Video downloader Updater; C:\Program Files\Video downloader\ExtensionUpdaterService.exe [188760 2013-09-24] ()
R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [424104 2013-10-05] (Taiwan Shui Mu Chih Ching Technology Limited.)
R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [825920 2013-10-05] (Wsys Co., Ltd.)
R2 Yontoo Desktop Updater; C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [23552 2013-03-23] (Microsoft)
==================== Drivers (Whitelisted) ====================
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2013-10-05] ()
S3 clwvd; system32\DRIVERS\clwvd.sys [x]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-05 20:18 - 2013-10-05 20:18 - 01954124 _____ (Farbar) C:\Users\aysenur\Downloads\FRST64.exe
2013-10-05 20:18 - 2013-10-05 20:18 - 00000000 ____D C:\FRST
2013-10-05 15:42 - 2013-10-05 15:54 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\337 Wallpaper
2013-10-05 15:39 - 2013-10-05 20:16 - 00000000 ____D C:\Program Files (x86)\WinZipper
2013-10-05 15:39 - 2013-10-05 20:16 - 00000000 ____D C:\Program Files (x86)\Omiga Plus
2013-10-05 15:39 - 2013-10-05 15:57 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Omiga Plus
2013-10-05 15:39 - 2013-10-05 15:39 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\WinZipper
2013-10-05 15:39 - 2013-10-05 15:39 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\337
2013-10-05 15:34 - 2013-10-05 15:34 - 00001087 _____ C:\Users\aysenur\Desktop\MyPC Backup.lnk
2013-10-05 15:34 - 2013-10-05 15:34 - 00001033 _____ C:\Users\Public\Desktop\VideoPlayer.lnk
2013-10-05 15:34 - 2013-10-05 15:34 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-05 15:34 - 2013-10-05 15:34 - 00000000 ____D C:\Users\aysenur\AppData\Local\DriverTuner
2013-10-05 15:34 - 2013-10-05 15:34 - 00000000 ____D C:\Program Files (x86)\VideoPlayer
2013-10-05 15:33 - 2013-10-05 15:36 - 02756664 _____ C:\Users\aysenur\Downloads\hpdj1000wx64psge (1).exe
2013-10-05 15:31 - 2013-10-05 15:31 - 00000000 ____D C:\Program Files (x86)\PricePeep
2013-10-05 15:29 - 2013-10-05 15:29 - 02756664 _____ C:\Users\aysenur\Downloads\hpdj1000wx64psge.exe
2013-10-05 14:17 - 2013-10-05 15:33 - 02816072 _____ (LionSea SoftWare ) C:\Users\aysenur\Downloads\setup (1).exe
2013-10-05 03:51 - 2013-10-05 20:13 - 00000224 _____ C:\Windows\setupact.log
2013-10-05 03:51 - 2013-10-05 03:51 - 00000000 _____ C:\Windows\setuperr.log
2013-10-05 03:50 - 2013-10-05 20:13 - 00003976 _____ C:\Windows\PFRO.log
2013-10-05 03:43 - 2013-10-05 03:44 - 00000353 _____ C:\Windows\SynInst.log
2013-10-03 23:51 - 2010-09-08 11:27 - 01146984 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2013-10-03 23:51 - 2010-09-01 08:28 - 01251944 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2013-10-03 23:38 - 2013-10-03 23:50 - 105267376 _____ (Hewlett-Packard ) C:\Users\Administrator\Downloads\sp50701.exe
2013-10-03 23:20 - 2013-10-03 23:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\MFAData
2013-10-03 23:16 - 2013-10-03 23:17 - 03294168 _____ (Piriform Ltd) C:\Users\Administrator\Downloads\ccsetup406_slim.exe
2013-10-03 13:06 - 2013-10-03 13:06 - 00003416 ____N C:\bootsqm.dat
2013-10-03 13:03 - 2013-10-03 13:03 - 00000000 __SHD C:\found.001
2013-10-03 12:58 - 2013-10-03 23:52 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2013-10-03 12:58 - 2010-09-08 11:27 - 02620008 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2013-10-03 12:58 - 2010-09-08 11:27 - 02484072 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2013-10-03 12:58 - 2010-09-08 11:27 - 02045032 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2013-10-03 12:58 - 2010-09-08 11:27 - 01215592 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2013-10-03 12:58 - 2010-09-08 11:27 - 00540264 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2013-10-03 12:58 - 2010-09-08 11:27 - 00332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2013-10-03 12:58 - 2010-09-08 11:27 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2013-10-03 12:58 - 2010-09-08 11:27 - 00081000 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll
2013-10-03 12:58 - 2010-07-23 08:37 - 00200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2013-10-03 12:58 - 2010-01-12 03:36 - 00000176 _____ C:\Windows\system32\Drivers\RTHDAEQ0.dat
2013-10-03 12:58 - 2010-01-08 06:37 - 00000712 _____ C:\Windows\system32\Drivers\RTEQEX0.dat
2013-10-03 12:58 - 2009-12-16 10:26 - 00372936 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2013-10-03 12:58 - 2009-12-16 10:26 - 00201928 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2013-10-03 12:58 - 2009-12-16 10:26 - 00099016 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2013-10-03 12:58 - 2009-12-16 10:26 - 00076488 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2013-10-03 12:58 - 2009-12-12 01:55 - 00307920 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2013-10-03 12:58 - 2009-12-12 01:55 - 00307920 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2013-10-03 12:58 - 2009-11-25 01:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2013-10-03 12:58 - 2009-11-25 01:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2013-10-03 12:58 - 2009-11-18 10:12 - 00108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2013-10-03 12:48 - 2013-10-03 12:56 - 105267376 _____ (Hewlett-Packard ) C:\Users\aysenur\Downloads\sp50701.exe
2013-10-03 12:44 - 2013-10-03 12:44 - 03891200 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2013-10-03 12:44 - 2013-10-03 12:44 - 03555840 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2013-10-03 12:44 - 2013-10-03 12:44 - 03063360 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL664.SYS
2013-10-03 12:44 - 2013-10-03 12:44 - 00006656 _____ C:\Windows\system32\bcmwlrc.dll
2013-10-03 12:44 - 2013-10-03 12:44 - 00000000 ____D C:\Program Files\Broadcom
2013-10-03 12:40 - 2013-10-03 12:42 - 21683544 _____ (Hewlett-Packard Company ) C:\Users\aysenur\Downloads\sp49541.exe
2013-10-03 12:37 - 2013-10-03 12:38 - 11293952 _____ (Hewlett-Packard Company ) C:\Users\aysenur\Downloads\sp56036.exe
2013-10-03 12:30 - 2013-10-03 12:30 - 03618776 _____ C:\Users\Administrator\Downloads\Broadcom_Wireless_LAN_drivers.ZIP
2013-10-01 18:32 - 2013-10-01 18:33 - 00000000 ____D C:\ProgramData\Datamngr
2013-10-01 16:47 - 2013-10-01 16:47 - 00501248 _____ (Facebook Inc.) C:\Users\Administrator\Downloads\FacebookVideoCallSetup_v1.2.205.0 (2).exe
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Public\CyberLink
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Administrator\Documents\Youcam
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\CyberLink
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Administrator\AppData\Local\CyberLink
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\ProgramData\CyberLink
2013-10-01 16:39 - 2013-10-02 17:57 - 01608544 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-01 16:32 - 2013-10-01 16:32 - 00001878 _____ C:\Users\Administrator\Desktop\Search.lnk
2013-10-01 16:30 - 2013-10-01 16:30 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-10-01 16:30 - 2013-10-01 16:30 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\DealPly
2013-10-01 16:30 - 2013-10-01 16:30 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-10-01 16:29 - 2013-10-01 16:30 - 00501248 _____ (Facebook Inc.) C:\Users\Administrator\Downloads\FacebookVideoCallSetup_v1.2.205.0 (1).exe
2013-10-01 16:25 - 2013-10-01 16:25 - 00501248 _____ (Facebook Inc.) C:\Users\Administrator\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2013-09-30 20:55 - 2013-09-30 20:55 - 00208464 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (6).exe
2013-09-30 20:54 - 2013-09-30 20:54 - 00208576 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (5).exe
2013-09-30 19:12 - 2013-09-30 19:12 - 98512375 _____ C:\Windows\SysWOW64\蒜ª
2013-09-30 18:58 - 2013-09-30 18:58 - 00208584 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (4).exe
2013-09-30 18:58 - 2013-09-30 18:58 - 00208512 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (3).exe
2013-09-30 17:21 - 2013-09-30 17:21 - 00359059 _____ C:\Users\Administrator\Downloads\photo.php
2013-09-29 19:18 - 2013-09-30 13:13 - 98499637 _____ C:\Windows\SysWOW64\ꝼⒻ
2013-09-29 17:19 - 2013-09-29 17:19 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\OpenOffice.org
2013-09-29 15:07 - 2013-09-29 15:07 - 00236280 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (2).exe
2013-09-29 15:06 - 2013-09-29 15:06 - 00236360 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (1).exe
2013-09-27 21:35 - 2013-10-03 11:57 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
2013-09-27 21:25 - 2013-09-27 21:28 - 28795304 _____ (DVDVideoSoft Ltd. ) C:\Users\Administrator\Downloads\Free31213YouTubeToMP3Converter.exe
2013-09-27 19:13 - 2013-09-28 08:41 - 98372650 _____ C:\Windows\SysWOW64\₼、¢
2013-09-27 06:49 - 2013-09-27 06:49 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2013-09-26 16:44 - 2013-09-26 16:44 - 00000000 _____ C:\end
2013-09-26 13:39 - 2013-09-26 13:39 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-09-26 13:39 - 2013-09-26 13:39 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2013-09-24 13:34 - 2013-09-24 13:34 - 00657472 _____ C:\Users\Administrator\Downloads\Setup.exe
2013-09-23 20:32 - 2013-09-23 20:32 - 98685961 _____ C:\Windows\SysWOW64\짦ੳ§
2013-09-22 19:34 - 2013-09-22 19:34 - 98597466 _____ C:\Windows\SysWOW64\ਵῪi
2013-09-22 13:44 - 2013-09-22 13:44 - 00646056 _____ C:\Users\aysenur\Downloads\Setup(1).exe
2013-09-22 13:42 - 2013-09-22 13:42 - 00646056 _____ C:\Users\aysenur\Downloads\Setup.exe
2013-09-21 08:35 - 2013-09-21 08:35 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG
2013-09-21 08:32 - 2013-09-21 08:32 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG2014
2013-09-21 08:31 - 2013-10-03 23:25 - 00000000 ____D C:\Users\Administrator\AppData\Local\Avg2014
2013-09-21 01:58 - 2013-09-21 01:58 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\AVG
2013-09-21 01:57 - 2013-09-21 02:03 - 00000000 ____D C:\ProgramData\AVG
2013-09-21 01:55 - 2013-09-21 01:55 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-09-21 01:50 - 2013-09-21 01:54 - 78407592 _____ (AVG) C:\Users\aysenur\Downloads\avg_tuh_stf_all_2014_146_24c4.exe
2013-09-21 01:40 - 2013-09-21 01:40 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\AVG2014
2013-09-21 01:39 - 2013-09-21 01:39 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-09-21 01:37 - 2013-10-03 23:53 - 00000000 ____D C:\ProgramData\AVG2014
2013-09-21 01:37 - 2013-10-03 23:25 - 00000000 ___HD C:\$AVG
2013-09-21 01:33 - 2013-09-21 01:33 - 00000000 ____D C:\ProgramData\APN
2013-09-21 01:32 - 2013-10-03 23:25 - 00000000 ____D C:\ProgramData\Avira
2013-09-21 01:28 - 2013-10-03 23:53 - 00000000 ____D C:\ProgramData\MFAData
2013-09-21 01:28 - 2013-09-21 01:46 - 00000000 ____D C:\Users\aysenur\AppData\Local\Avg2014
2013-09-21 01:28 - 2013-09-21 01:28 - 00000000 ____D C:\Users\aysenur\AppData\Local\MFAData
2013-09-21 01:27 - 2013-09-21 01:28 - 04425448 _____ (AVG Technologies) C:\Users\aysenur\Downloads\avg_free_stb_all_2014_4116.exe
2013-09-21 01:21 - 2013-09-21 01:21 - 02092792 _____ C:\Users\aysenur\Downloads\avira_free_4052_antivirus.exe
2013-09-21 01:20 - 2013-09-21 01:20 - 00000000 ____D C:\Program Files\Microsoft Games
2013-09-20 22:33 - 2013-09-20 22:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_androidusb_01009.Wdf
2013-09-20 22:28 - 2013-09-20 22:28 - 00000000 ____D C:\Users\Administrator\Documents\Optimizer Pro
2013-09-15 18:52 - 2013-10-01 16:50 - 00000000 ____D C:\Users\Administrator\AppData\Local\Facebook
2013-09-15 14:31 - 2013-09-15 14:31 - 00000000 ____D C:\Users\Administrator\SyncFolder
2013-09-15 14:01 - 2013-09-15 14:01 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\File Scout
2013-09-15 12:44 - 2013-09-15 12:44 - 00000000 ____D C:\Users\Administrator\AppData\Local\CRE
2013-09-15 12:44 - 2013-09-15 12:44 - 00000000 ____D C:\Program Files (x86)\Conduit
2013-09-15 12:42 - 2013-10-03 12:00 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\uTorrent
2013-09-13 03:02 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-13 03:02 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-13 03:02 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-13 03:02 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-13 03:02 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-13 03:02 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-13 03:02 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-13 03:02 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-13 03:02 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-13 03:02 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-13 03:02 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-13 03:02 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-13 03:02 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-13 03:02 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-13 02:49 - 2013-10-03 23:28 - 00000000 ____D C:\Windows\pss
2013-09-13 02:46 - 2013-09-13 02:46 - 00003008 _____ C:\Windows\System32\Tasks\{8ADB8A36-9271-4A0C-8C34-DBE93931F42D}
2013-09-13 02:46 - 2013-09-13 02:46 - 00003008 _____ C:\Windows\System32\Tasks\{8ABBA6B6-E932-4FEC-88EB-092EB111B241}
2013-09-12 17:14 - 2013-09-12 17:14 - 00000000 ____D C:\Program Files (x86)\Tor
2013-09-12 07:13 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 07:13 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-12 07:13 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-12 07:13 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-12 07:13 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-12 07:13 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-12 07:13 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-12 07:13 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-12 07:13 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-12 07:13 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-12 07:13 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-12 07:13 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-12 07:13 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-12 07:13 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-12 07:13 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-12 07:13 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-12 07:13 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-12 07:13 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-12 07:13 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-12 07:13 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-12 07:13 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 07:13 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-12 07:13 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-12 07:13 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-12 07:13 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-12 07:13 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-11 02:31 - 2013-09-11 02:31 - 00000000 __SHD C:\found.000
2013-09-10 10:29 - 2013-10-05 15:34 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-09-10 10:29 - 2013-09-10 10:29 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-09-10 10:28 - 2013-09-10 10:28 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
2013-09-10 10:28 - 2013-09-10 10:28 - 00000000 ____D C:\Users\Administrator\AppData\Local\Wajam
2013-09-10 10:28 - 2013-09-10 10:28 - 00000000 ____D C:\Users\Administrator\AppData\Local\avgchrome
2013-09-10 10:27 - 2013-10-03 12:07 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Systweak
2013-09-10 10:27 - 2013-10-01 16:32 - 00000000 ____D C:\ProgramData\DSearchLink
2013-09-10 10:27 - 2013-09-21 01:48 - 00000000 ____D C:\Program Files (x86)\FLVPlayer
2013-09-10 10:27 - 2013-09-10 10:27 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Babylon
2013-09-10 09:04 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2013-09-10 09:04 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-09-10 09:04 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2013-09-10 09:04 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-09-10 09:04 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-09-10 09:04 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-09-10 09:04 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-09-10 09:04 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2013-09-10 09:04 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-09-10 09:04 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2013-09-10 09:04 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2013-09-10 09:04 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-09-10 09:04 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-09-10 09:04 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-09-10 09:04 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2013-09-10 09:04 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-09-10 09:04 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2013-09-10 09:04 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2013-09-10 09:04 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-09-10 09:04 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-09-10 09:04 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2013-09-10 09:04 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-09-10 09:04 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2013-09-10 09:04 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-09-10 09:04 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2013-09-10 09:04 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-09-10 09:04 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-09-10 09:04 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2013-09-10 09:04 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-09-10 09:04 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-09-10 09:04 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-09-10 09:04 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2013-09-10 09:04 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-09-10 09:04 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2013-09-10 09:04 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2013-09-10 09:04 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-09-10 09:04 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-09-10 09:04 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2013-09-10 09:04 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-09-10 09:04 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2013-09-10 09:04 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2013-09-10 09:04 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-09-10 09:04 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2013-09-10 09:04 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-09-10 09:04 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2013-09-10 09:04 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-09-10 09:04 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-09-10 09:04 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2013-09-10 09:04 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2013-09-10 09:04 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-09-10 09:04 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-09-10 09:04 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2013-09-10 09:04 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2013-09-10 09:04 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-09-10 09:04 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-09-10 09:04 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2013-09-10 09:04 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-09-10 09:04 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2013-09-10 09:04 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-09-10 09:04 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2013-09-10 09:04 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-09-10 09:04 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2013-09-10 09:04 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2013-09-10 09:04 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-09-10 09:04 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-09-10 09:04 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2013-09-10 09:04 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-09-10 09:04 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2013-09-10 09:04 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-09-10 09:04 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2013-09-10 09:04 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-09-10 09:04 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2013-09-10 09:04 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-09-10 09:04 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2013-09-10 09:04 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-09-10 09:04 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2013-09-10 09:04 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-09-10 09:04 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2013-09-10 09:04 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-09-10 09:04 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2013-09-10 09:04 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-09-10 09:04 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2013-09-10 09:04 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-09-10 09:04 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2013-09-10 09:04 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-09-10 09:04 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-09-10 09:04 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-09-10 09:04 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2013-09-10 09:04 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-09-10 09:04 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2013-09-10 09:04 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-09-10 09:04 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2013-09-10 09:04 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-09-10 09:04 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-09-10 09:04 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-09-10 09:04 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2013-09-10 09:04 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-09-10 09:04 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2013-09-10 09:04 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-09-10 09:04 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2013-09-10 09:04 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-09-10 09:04 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2013-09-10 09:04 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-09-10 09:04 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2013-09-10 09:04 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-09-10 09:04 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2013-09-10 09:04 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-09-10 09:04 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2013-09-10 09:04 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-09-10 09:04 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2013-09-10 09:04 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-09-10 09:04 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2013-09-10 09:04 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2013-09-10 09:04 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-09-10 09:04 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-09-10 09:04 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2013-09-10 09:04 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-09-10 09:04 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2013-09-10 09:04 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-09-10 09:04 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2013-09-10 09:04 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2013-09-10 09:04 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-09-10 09:04 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-09-10 09:04 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-09-10 09:04 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2013-09-10 09:04 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2013-09-10 09:04 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2013-09-10 09:04 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-09-10 09:04 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-09-10 09:04 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-09-10 09:04 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-09-10 09:04 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2013-09-10 09:04 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-09-10 09:04 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2013-09-10 09:04 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-09-10 09:04 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2013-09-10 09:04 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-09-10 09:04 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2013-09-10 09:04 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-09-10 09:04 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2013-09-10 09:04 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-09-10 09:04 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2013-09-10 09:04 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-09-10 09:04 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2013-09-10 09:04 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-09-10 09:04 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2013-09-10 09:04 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-09-10 09:04 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2013-09-10 09:04 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-09-10 09:04 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2013-09-10 08:50 - 2013-09-10 09:11 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-09-10 08:50 - 2013-09-10 09:11 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-09 21:02 - 2013-09-11 19:46 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\.minecraft
2013-09-09 21:01 - 2013-09-09 21:01 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-09 21:01 - 2013-09-09 21:01 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-09-09 16:56 - 2013-09-09 17:00 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2013-09-09 11:14 - 2013-09-09 11:14 - 00000000 _____ C:\Windows\System32\Tasks\BrowserProtect
2013-09-09 09:57 - 2013-09-09 09:57 - 00000000 ____D C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2013-09-09 09:56 - 2013-09-09 09:56 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-09 09:54 - 2013-09-09 09:54 - 00000000 ____D C:\Users\Administrator\AppData\Local\Gameforge4d
2013-09-08 15:22 - 2013-10-03 23:06 - 00000000 ____D C:\ProgramData\TorchCrashHandler
2013-09-08 15:22 - 2013-09-08 15:23 - 00001348 _____ C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2013-09-08 15:22 - 2013-09-08 15:22 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\TFP
2013-09-08 15:22 - 2012-05-11 15:47 - 01081616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2013-09-08 15:22 - 2012-05-11 15:47 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX
2013-09-08 15:22 - 2012-05-11 15:47 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCFR.DLL
2013-09-08 15:22 - 2012-05-11 15:47 - 00119568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6FR.DLL
2013-09-08 15:22 - 2012-05-11 15:47 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL
2013-09-08 15:22 - 2012-05-11 15:47 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMDLGFR.DLL
2013-09-08 15:21 - 2013-10-04 00:31 - 00000000 ____D C:\Users\aysenur\AppData\Local\Torch
2013-09-08 15:17 - 2013-10-01 18:34 - 00000000 ____D C:\ProgramData\Wincert
2013-09-08 15:17 - 2013-09-08 15:17 - 00000000 ____D C:\Program Files (x86)\Music Toolbar
2013-09-08 09:44 - 2012-06-01 07:39 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wamregps.dll
2013-09-08 09:44 - 2012-06-01 07:36 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\iisRtl.dll
2013-09-08 09:44 - 2012-06-01 07:36 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\iisrstap.dll
2013-09-08 09:44 - 2012-06-01 07:35 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ahadmin.dll
2013-09-08 09:44 - 2012-06-01 07:34 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\admwprox.dll
2013-09-08 09:44 - 2012-06-01 07:33 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\iisreset.exe
2013-09-08 09:44 - 2012-06-01 06:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wamregps.dll
2013-09-08 09:44 - 2012-06-01 06:37 - 00154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisRtl.dll
2013-09-08 09:44 - 2012-06-01 06:37 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisrstap.dll
2013-09-08 09:44 - 2012-06-01 06:35 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admwprox.dll
2013-09-08 09:44 - 2012-06-01 06:35 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ahadmin.dll
2013-09-08 09:44 - 2012-06-01 06:34 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisreset.exe
2013-09-08 09:38 - 2013-09-08 09:38 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel Corporation
2013-09-07 21:41 - 2013-09-07 21:41 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Hewlett-Packard
2013-09-07 21:25 - 2013-09-07 21:25 - 00003138 _____ C:\Windows\System32\Tasks\{FE99B07C-6D66-4659-8337-0E8D5A45A00C}
2013-09-07 21:25 - 2013-09-07 21:25 - 00000000 ____D C:\system.sav
2013-09-07 21:23 - 2013-09-07 21:43 - 00000000 ____D C:\HP
2013-09-07 21:23 - 2013-09-07 21:23 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\hpqLog
2013-09-07 20:46 - 2013-09-07 20:46 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Intel Corporation
2013-09-07 20:39 - 2013-09-07 20:39 - 00003138 _____ C:\Windows\System32\Tasks\{E7DD76E8-435B-4BDB-A5FC-1709B95F161C}
2013-09-07 20:38 - 2013-09-07 20:38 - 00003138 _____ C:\Windows\System32\Tasks\{7592FD78-271F-4CE7-B56B-45232067F8E3}
2013-09-07 20:37 - 2013-09-07 20:37 - 00003144 _____ C:\Windows\System32\Tasks\{0FFE5498-6F26-4744-8DA6-B8202EF6CA0C}
2013-09-07 20:37 - 2013-09-07 20:37 - 00003138 _____ C:\Windows\System32\Tasks\{CD0A8580-CE1B-471B-972A-00F3E22DE585}
2013-09-07 20:36 - 2013-09-07 20:36 - 00000000 ____D C:\ProgramData\Atheros
2013-09-07 20:34 - 2013-09-07 20:34 - 00003138 _____ C:\Windows\System32\Tasks\{2D1B2C10-07FD-4C39-8434-6E98DA71D54F}
2013-09-07 20:25 - 2013-09-07 20:25 - 00003138 _____ C:\Windows\System32\Tasks\{3A997E32-6505-4803-868B-C295073A5527}
2013-09-07 20:18 - 2013-09-07 20:18 - 00003138 _____ C:\Windows\System32\Tasks\{9BA9FD80-3705-46DF-9302-3E187BC164F8}
2013-09-07 20:17 - 2013-09-07 20:17 - 00003144 _____ C:\Windows\System32\Tasks\{AD4EEE0D-680C-4D50-8BE5-4E7CAF396DF8}
2013-09-07 19:59 - 2010-04-13 09:44 - 00540696 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys
2013-09-07 19:59 - 2009-02-03 03:27 - 07360512 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSUSTORicon.dll
2013-09-07 19:58 - 2009-09-23 02:39 - 00225280 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\Drivers\RtsUStor.sys
2013-09-07 19:57 - 2013-09-07 19:57 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-09-07 19:35 - 2013-09-07 19:35 - 00003138 _____ C:\Windows\System32\Tasks\{DA011454-E305-4BDD-B688-49E934CEE1DD}
2013-09-07 19:25 - 2013-09-07 19:25 - 00003138 _____ C:\Windows\System32\Tasks\{2A35A8F6-06F9-44D8-9A6E-91241A183107}
2013-09-07 18:55 - 2013-09-07 21:25 - 00000000 ____D C:\swsetup
2013-09-07 18:55 - 2010-08-25 13:19 - 00349800 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-09-07 18:55 - 2010-01-06 16:39 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-09-07 18:55 - 2009-12-04 09:27 - 00074272 _____ C:\Windows\system32\RtNicProp64.dll
2013-09-07 18:52 - 2013-10-05 15:06 - 00000067 _____ C:\Windows\system32err.xml
2013-09-07 18:52 - 2013-10-05 15:06 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-09-07 18:25 - 2013-09-07 18:25 - 00000000 ____D C:\ProgramData\Samsung
2013-09-07 18:25 - 2013-09-07 18:25 - 00000000 ____D C:\Program Files\SAMSUNG
2013-09-07 18:17 - 2013-09-07 18:17 - 00000000 ____D C:\Intel
2013-09-07 12:10 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-09-07 12:10 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-09-07 12:10 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-09-07 12:10 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-09-07 12:10 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-09-07 12:10 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-09-07 12:10 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-09-07 12:10 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-09-05 07:28 - 2013-09-13 03:02 - 00000000 ____D C:\Windows\system32\MRT
==================== One Month Modified Files and Folders =======
2013-10-05 20:18 - 2013-10-05 20:18 - 01954124 _____ (Farbar) C:\Users\aysenur\Downloads\FRST64.exe
2013-10-05 20:18 - 2013-10-05 20:18 - 00000000 ____D C:\FRST
2013-10-05 20:18 - 2013-03-24 17:36 - 01475215 _____ C:\Windows\WindowsUpdate.log
2013-10-05 20:16 - 2013-10-05 15:39 - 00000000 ____D C:\Program Files (x86)\WinZipper
2013-10-05 20:16 - 2013-10-05 15:39 - 00000000 ____D C:\Program Files (x86)\Omiga Plus
2013-10-05 20:16 - 2013-04-20 21:53 - 00000000 ____D C:\ProgramData\eSafe
2013-10-05 20:15 - 2013-03-24 18:13 - 00016152 _____ C:\Windows\system32\Drivers\SWDUMon.sys
2013-10-05 20:15 - 2013-03-24 18:13 - 00002844 _____ C:\Windows\System32\Tasks\SlimDrivers Startup
2013-10-05 20:15 - 2013-03-24 18:13 - 00000414 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2013-10-05 20:15 - 2009-07-14 06:45 - 00019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-05 20:15 - 2009-07-14 06:45 - 00019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-05 20:14 - 2013-04-14 21:25 - 00000364 _____ C:\Windows\Tasks\AmiUpdXp.job
2013-10-05 20:13 - 2013-10-05 03:51 - 00000224 _____ C:\Windows\setupact.log
2013-10-05 20:13 - 2013-10-05 03:50 - 00003976 _____ C:\Windows\PFRO.log
2013-10-05 20:13 - 2013-03-31 18:08 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Yontoo
2013-10-05 20:13 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-05 15:57 - 2013-10-05 15:39 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Omiga Plus
2013-10-05 15:54 - 2013-10-05 15:42 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\337 Wallpaper
2013-10-05 15:39 - 2013-10-05 15:39 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\WinZipper
2013-10-05 15:39 - 2013-10-05 15:39 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\337
2013-10-05 15:39 - 2013-04-20 21:53 - 00000000 ____D C:\Program Files (x86)\Desk 365
2013-10-05 15:39 - 2011-02-19 23:03 - 00421032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2013-10-05 15:39 - 2011-02-19 00:40 - 00773800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2013-10-05 15:36 - 2013-10-05 15:33 - 02756664 _____ C:\Users\aysenur\Downloads\hpdj1000wx64psge (1).exe
2013-10-05 15:34 - 2013-10-05 15:34 - 00001087 _____ C:\Users\aysenur\Desktop\MyPC Backup.lnk
2013-10-05 15:34 - 2013-10-05 15:34 - 00001033 _____ C:\Users\Public\Desktop\VideoPlayer.lnk
2013-10-05 15:34 - 2013-10-05 15:34 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-05 15:34 - 2013-10-05 15:34 - 00000000 ____D C:\Users\aysenur\AppData\Local\DriverTuner
2013-10-05 15:34 - 2013-10-05 15:34 - 00000000 ____D C:\Program Files (x86)\VideoPlayer
2013-10-05 15:34 - 2013-09-10 10:29 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-05 15:34 - 2013-03-24 17:38 - 00000000 ___RD C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-05 15:34 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-05 15:33 - 2013-10-05 14:17 - 02816072 _____ (LionSea SoftWare ) C:\Users\aysenur\Downloads\setup (1).exe
2013-10-05 15:33 - 2013-04-20 21:53 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Desk 365
2013-10-05 15:31 - 2013-10-05 15:31 - 00000000 ____D C:\Program Files (x86)\PricePeep
2013-10-05 15:29 - 2013-10-05 15:29 - 02756664 _____ C:\Users\aysenur\Downloads\hpdj1000wx64psge.exe
2013-10-05 15:14 - 2009-07-14 19:58 - 00704754 _____ C:\Windows\system32\perfh007.dat
2013-10-05 15:14 - 2009-07-14 19:58 - 00150640 _____ C:\Windows\system32\perfc007.dat
2013-10-05 15:14 - 2009-07-14 07:13 - 01630650 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-05 15:06 - 2013-09-07 18:52 - 00000067 _____ C:\Windows\system32err.xml
2013-10-05 15:06 - 2013-09-07 18:52 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-10-05 14:16 - 2013-03-26 20:59 - 00000000 ____D C:\Users\aysenur\AppData\Local\Facebook
2013-10-05 04:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-05 03:51 - 2013-10-05 03:51 - 00000000 _____ C:\Windows\setuperr.log
2013-10-05 03:44 - 2013-10-05 03:43 - 00000353 _____ C:\Windows\SynInst.log
2013-10-05 03:37 - 2013-04-14 21:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-04 00:31 - 2013-09-08 15:21 - 00000000 ____D C:\Users\aysenur\AppData\Local\Torch
2013-10-04 00:06 - 2013-03-29 02:32 - 00000000 ____D C:\Program Files (x86)\AVG
2013-10-03 23:53 - 2013-09-21 01:37 - 00000000 ____D C:\ProgramData\AVG2014
2013-10-03 23:53 - 2013-09-21 01:28 - 00000000 ____D C:\ProgramData\MFAData
2013-10-03 23:52 - 2013-10-03 12:58 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2013-10-03 23:52 - 2013-03-25 03:09 - 00000000 ____D C:\Program Files\Realtek
2013-10-03 23:51 - 2013-03-25 03:09 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-03 23:51 - 2013-03-25 03:09 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-10-03 23:50 - 2013-10-03 23:38 - 105267376 _____ (Hewlett-Packard ) C:\Users\Administrator\Downloads\sp50701.exe
2013-10-03 23:28 - 2013-09-13 02:49 - 00000000 ____D C:\Windows\pss
2013-10-03 23:25 - 2013-09-21 08:31 - 00000000 ____D C:\Users\Administrator\AppData\Local\Avg2014
2013-10-03 23:25 - 2013-09-21 01:37 - 00000000 ___HD C:\$AVG
2013-10-03 23:25 - 2013-09-21 01:32 - 00000000 ____D C:\ProgramData\Avira
2013-10-03 23:20 - 2013-10-03 23:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\MFAData
2013-10-03 23:18 - 2013-04-11 15:08 - 00000000 ____D C:\Windows\Minidump
2013-10-03 23:18 - 2010-02-10 00:18 - 00000000 ____D C:\Windows\Panther
2013-10-03 23:17 - 2013-10-03 23:16 - 03294168 _____ (Piriform Ltd) C:\Users\Administrator\Downloads\ccsetup406_slim.exe
2013-10-03 23:11 - 2013-08-16 09:51 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-03 23:06 - 2013-09-08 15:22 - 00000000 ____D C:\ProgramData\TorchCrashHandler
2013-10-03 13:06 - 2013-10-03 13:06 - 00003416 ____N C:\bootsqm.dat
2013-10-03 13:03 - 2013-10-03 13:03 - 00000000 __SHD C:\found.001
2013-10-03 12:56 - 2013-10-03 12:48 - 105267376 _____ (Hewlett-Packard ) C:\Users\aysenur\Downloads\sp50701.exe
2013-10-03 12:44 - 2013-10-03 12:44 - 03891200 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2013-10-03 12:44 - 2013-10-03 12:44 - 03555840 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2013-10-03 12:44 - 2013-10-03 12:44 - 03063360 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL664.SYS
2013-10-03 12:44 - 2013-10-03 12:44 - 00006656 _____ C:\Windows\system32\bcmwlrc.dll
2013-10-03 12:44 - 2013-10-03 12:44 - 00000000 ____D C:\Program Files\Broadcom
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\th-TH
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sk-SK
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ro-RO
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lv-LV
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lt-LT
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\hr-HR
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\he-IL
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\et-EE
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\bg-BG
2013-10-03 12:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ar-SA
2013-10-03 12:42 - 2013-10-03 12:40 - 21683544 _____ (Hewlett-Packard Company ) C:\Users\aysenur\Downloads\sp49541.exe
2013-10-03 12:40 - 2013-03-24 17:38 - 00000000 ____D C:\Users\aysenur
2013-10-03 12:38 - 2013-10-03 12:37 - 11293952 _____ (Hewlett-Packard Company ) C:\Users\aysenur\Downloads\sp56036.exe
2013-10-03 12:30 - 2013-10-03 12:30 - 03618776 _____ C:\Users\Administrator\Downloads\Broadcom_Wireless_LAN_drivers.ZIP
2013-10-03 12:07 - 2013-09-10 10:27 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Systweak
2013-10-03 12:00 - 2013-09-15 12:42 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\uTorrent
2013-10-03 11:57 - 2013-09-27 21:35 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
2013-10-03 11:55 - 2013-03-25 03:54 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-02 17:57 - 2013-10-01 16:39 - 01608544 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-01 18:34 - 2013-09-08 15:17 - 00000000 ____D C:\ProgramData\Wincert
2013-10-01 18:33 - 2013-10-01 18:32 - 00000000 ____D C:\ProgramData\Datamngr
2013-10-01 16:50 - 2013-09-15 18:52 - 00000000 ____D C:\Users\Administrator\AppData\Local\Facebook
2013-10-01 16:47 - 2013-10-01 16:47 - 00501248 _____ (Facebook Inc.) C:\Users\Administrator\Downloads\FacebookVideoCallSetup_v1.2.205.0 (2).exe
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Public\CyberLink
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Administrator\Documents\Youcam
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\CyberLink
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\Users\Administrator\AppData\Local\CyberLink
2013-10-01 16:45 - 2013-10-01 16:45 - 00000000 ____D C:\ProgramData\CyberLink
2013-10-01 16:32 - 2013-10-01 16:32 - 00001878 _____ C:\Users\Administrator\Desktop\Search.lnk
2013-10-01 16:32 - 2013-09-10 10:27 - 00000000 ____D C:\ProgramData\DSearchLink
2013-10-01 16:30 - 2013-10-01 16:30 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-10-01 16:30 - 2013-10-01 16:30 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\DealPly
2013-10-01 16:30 - 2013-10-01 16:30 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-10-01 16:30 - 2013-10-01 16:29 - 00501248 _____ (Facebook Inc.) C:\Users\Administrator\Downloads\FacebookVideoCallSetup_v1.2.205.0 (1).exe
2013-10-01 16:25 - 2013-10-01 16:25 - 00501248 _____ (Facebook Inc.) C:\Users\Administrator\Downloads\FacebookVideoCallSetup_v1.2.205.0.exe
2013-09-30 20:55 - 2013-09-30 20:55 - 00208464 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (6).exe
2013-09-30 20:54 - 2013-09-30 20:54 - 00208576 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (5).exe
2013-09-30 19:12 - 2013-09-30 19:12 - 98512375 _____ C:\Windows\SysWOW64\蒜ª
2013-09-30 18:58 - 2013-09-30 18:58 - 00208584 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (4).exe
2013-09-30 18:58 - 2013-09-30 18:58 - 00208512 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (3).exe
2013-09-30 17:21 - 2013-09-30 17:21 - 00359059 _____ C:\Users\Administrator\Downloads\photo.php
2013-09-30 13:13 - 2013-09-29 19:18 - 98499637 _____ C:\Windows\SysWOW64\ꝼⒻ
2013-09-29 17:19 - 2013-09-29 17:19 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\OpenOffice.org
2013-09-29 15:07 - 2013-09-29 15:07 - 00236280 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (2).exe
2013-09-29 15:06 - 2013-09-29 15:06 - 00236360 _____ (Tuguu S.L.U) C:\Users\Administrator\Downloads\Setup (1).exe
2013-09-28 08:41 - 2013-09-27 19:13 - 98372650 _____ C:\Windows\SysWOW64\₼、¢
2013-09-27 21:28 - 2013-09-27 21:25 - 28795304 _____ (DVDVideoSoft Ltd. ) C:\Users\Administrator\Downloads\Free31213YouTubeToMP3Converter.exe
2013-09-27 06:49 - 2013-09-27 06:49 - 00000000 ____D C:\Windows\SysWOW64\SearchProtect
2013-09-27 06:42 - 2013-04-14 21:25 - 00000000 ____D C:\Program Files\Video downloader
2013-09-26 16:44 - 2013-09-26 16:44 - 00000000 _____ C:\end
2013-09-26 13:39 - 2013-09-26 13:39 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-09-26 13:39 - 2013-09-26 13:39 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2013-09-24 13:34 - 2013-09-24 13:34 - 00657472 _____ C:\Users\Administrator\Downloads\Setup.exe
2013-09-23 20:32 - 2013-09-23 20:32 - 98685961 _____ C:\Windows\SysWOW64\짦ੳ§
2013-09-22 19:34 - 2013-09-22 19:34 - 98597466 _____ C:\Windows\SysWOW64\ਵῪi
2013-09-22 14:25 - 2013-03-24 17:38 - 00001659 _____ C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-22 14:06 - 2013-05-04 12:11 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-22 13:44 - 2013-09-22 13:44 - 00646056 _____ C:\Users\aysenur\Downloads\Setup(1).exe
2013-09-22 13:42 - 2013-09-22 13:42 - 00646056 _____ C:\Users\aysenur\Downloads\Setup.exe
2013-09-21 09:07 - 2013-08-21 21:41 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mozilla
2013-09-21 08:35 - 2013-09-21 08:35 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG
2013-09-21 08:32 - 2013-09-21 08:32 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG2014
2013-09-21 02:03 - 2013-09-21 01:57 - 00000000 ____D C:\ProgramData\AVG
2013-09-21 01:58 - 2013-09-21 01:58 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\AVG
2013-09-21 01:57 - 2013-04-11 14:02 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2013
2013-09-21 01:55 - 2013-09-21 01:55 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-09-21 01:54 - 2013-09-21 01:50 - 78407592 _____ (AVG) C:\Users\aysenur\Downloads\avg_tuh_stf_all_2014_146_24c4.exe
2013-09-21 01:49 - 2013-03-31 18:08 - 00000000 ____D C:\Program Files (x86)\Yontoo
2013-09-21 01:48 - 2013-09-10 10:27 - 00000000 ____D C:\Program Files (x86)\FLVPlayer
2013-09-21 01:46 - 2013-09-21 01:28 - 00000000 ____D C:\Users\aysenur\AppData\Local\Avg2014
2013-09-21 01:40 - 2013-09-21 01:40 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\AVG2014
2013-09-21 01:39 - 2013-09-21 01:39 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-09-21 01:39 - 2013-04-11 14:03 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\TuneUp Software
2013-09-21 01:33 - 2013-09-21 01:33 - 00000000 ____D C:\ProgramData\APN
2013-09-21 01:28 - 2013-09-21 01:28 - 00000000 ____D C:\Users\aysenur\AppData\Local\MFAData
2013-09-21 01:28 - 2013-09-21 01:27 - 04425448 _____ (AVG Technologies) C:\Users\aysenur\Downloads\avg_free_stb_all_2014_4116.exe
2013-09-21 01:21 - 2013-09-21 01:21 - 02092792 _____ C:\Users\aysenur\Downloads\avira_free_4052_antivirus.exe
2013-09-21 01:20 - 2013-09-21 01:20 - 00000000 ____D C:\Program Files\Microsoft Games
2013-09-21 01:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-20 23:48 - 2013-05-04 13:54 - 00000000 ____D C:\Users\aysenur\AppData\Local\Mozilla
2013-09-20 23:42 - 2013-03-24 18:44 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-20 23:42 - 2013-03-24 18:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-20 22:33 - 2013-09-20 22:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_androidusb_01009.Wdf
2013-09-20 22:28 - 2013-09-20 22:28 - 00000000 ____D C:\Users\Administrator\Documents\Optimizer Pro
2013-09-20 22:23 - 2013-08-16 09:51 - 00000000 ____D C:\Users\Administrator
2013-09-19 17:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-15 14:31 - 2013-09-15 14:31 - 00000000 ____D C:\Users\Administrator\SyncFolder
2013-09-15 14:01 - 2013-09-15 14:01 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\File Scout
2013-09-15 12:44 - 2013-09-15 12:44 - 00000000 ____D C:\Users\Administrator\AppData\Local\CRE
2013-09-15 12:44 - 2013-09-15 12:44 - 00000000 ____D C:\Program Files (x86)\Conduit
2013-09-15 11:14 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-09-13 13:09 - 2013-08-16 09:51 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 03:33 - 2013-03-24 17:38 - 00000000 ___RD C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 03:30 - 2009-07-14 06:45 - 00293504 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-13 03:02 - 2013-09-05 07:28 - 00000000 ____D C:\Windows\system32\MRT
2013-09-13 03:01 - 2010-02-10 00:33 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-13 02:46 - 2013-09-13 02:46 - 00003008 _____ C:\Windows\System32\Tasks\{8ADB8A36-9271-4A0C-8C34-DBE93931F42D}
2013-09-13 02:46 - 2013-09-13 02:46 - 00003008 _____ C:\Windows\System32\Tasks\{8ABBA6B6-E932-4FEC-88EB-092EB111B241}
2013-09-13 02:34 - 2013-04-14 22:06 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Systweak
2013-09-12 17:14 - 2013-09-12 17:14 - 00000000 ____D C:\Program Files (x86)\Tor
2013-09-12 14:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2013-09-12 14:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\inetsrv
2013-09-11 19:46 - 2013-09-09 21:02 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\.minecraft
2013-09-11 02:39 - 2013-03-25 03:54 - 00000000 ____D C:\Users\aysenur\AppData\Local\Google
2013-09-11 02:31 - 2013-09-11 02:31 - 00000000 __SHD C:\found.000
2013-09-10 13:48 - 2013-04-14 21:25 - 00000000 ____D C:\ProgramData\BrowserProtect
2013-09-10 10:29 - 2013-09-10 10:29 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-09-10 10:28 - 2013-09-10 10:28 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
2013-09-10 10:28 - 2013-09-10 10:28 - 00000000 ____D C:\Users\Administrator\AppData\Local\Wajam
2013-09-10 10:28 - 2013-09-10 10:28 - 00000000 ____D C:\Users\Administrator\AppData\Local\avgchrome
2013-09-10 10:27 - 2013-09-10 10:27 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Babylon
2013-09-10 09:11 - 2013-09-10 08:50 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-09-10 09:11 - 2013-09-10 08:50 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-09 21:44 - 2013-08-16 09:51 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-09-09 21:01 - 2013-09-09 21:01 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-09 21:01 - 2013-09-09 21:01 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-09-09 17:00 - 2013-09-09 16:56 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2013-09-09 11:14 - 2013-09-09 11:14 - 00000000 _____ C:\Windows\System32\Tasks\BrowserProtect
2013-09-09 09:57 - 2013-09-09 09:57 - 00000000 ____D C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2013-09-09 09:56 - 2013-09-09 09:56 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-09 09:54 - 2013-09-09 09:54 - 00000000 ____D C:\Users\Administrator\AppData\Local\Gameforge4d
2013-09-08 15:23 - 2013-09-08 15:22 - 00001348 _____ C:\Users\aysenur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2013-09-08 15:22 - 2013-09-08 15:22 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\TFP
2013-09-08 15:17 - 2013-09-08 15:17 - 00000000 ____D C:\Program Files (x86)\Music Toolbar
2013-09-08 09:38 - 2013-09-08 09:38 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel Corporation
2013-09-07 21:43 - 2013-09-07 21:23 - 00000000 ____D C:\HP
2013-09-07 21:41 - 2013-09-07 21:41 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Hewlett-Packard
2013-09-07 21:41 - 2013-03-25 04:13 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-09-07 21:30 - 2013-06-10 19:53 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2013-09-07 21:25 - 2013-09-07 21:25 - 00003138 _____ C:\Windows\System32\Tasks\{FE99B07C-6D66-4659-8337-0E8D5A45A00C}
2013-09-07 21:25 - 2013-09-07 21:25 - 00000000 ____D C:\system.sav
2013-09-07 21:25 - 2013-09-07 18:55 - 00000000 ____D C:\swsetup
2013-09-07 21:23 - 2013-09-07 21:23 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\hpqLog
2013-09-07 20:46 - 2013-09-07 20:46 - 00000000 ____D C:\Users\aysenur\AppData\Roaming\Intel Corporation
2013-09-07 20:39 - 2013-09-07 20:39 - 00003138 _____ C:\Windows\System32\Tasks\{E7DD76E8-435B-4BDB-A5FC-1709B95F161C}
2013-09-07 20:38 - 2013-09-07 20:38 - 00003138 _____ C:\Windows\System32\Tasks\{7592FD78-271F-4CE7-B56B-45232067F8E3}
2013-09-07 20:37 - 2013-09-07 20:37 - 00003144 _____ C:\Windows\System32\Tasks\{0FFE5498-6F26-4744-8DA6-B8202EF6CA0C}
2013-09-07 20:37 - 2013-09-07 20:37 - 00003138 _____ C:\Windows\System32\Tasks\{CD0A8580-CE1B-471B-972A-00F3E22DE585}
2013-09-07 20:36 - 2013-09-07 20:36 - 00000000 ____D C:\ProgramData\Atheros
2013-09-07 20:34 - 2013-09-07 20:34 - 00003138 _____ C:\Windows\System32\Tasks\{2D1B2C10-07FD-4C39-8434-6E98DA71D54F}
2013-09-07 20:32 - 2013-03-25 03:01 - 00095544 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll
2013-09-07 20:25 - 2013-09-07 20:25 - 00003138 _____ C:\Windows\System32\Tasks\{3A997E32-6505-4803-868B-C295073A5527}
2013-09-07 20:18 - 2013-09-07 20:18 - 00003138 _____ C:\Windows\System32\Tasks\{9BA9FD80-3705-46DF-9302-3E187BC164F8}
2013-09-07 20:17 - 2013-09-07 20:17 - 00003144 _____ C:\Windows\System32\Tasks\{AD4EEE0D-680C-4D50-8BE5-4E7CAF396DF8}
2013-09-07 19:59 - 2013-03-24 19:47 - 00000000 ____D C:\Program Files (x86)\Intel
2013-09-07 19:57 - 2013-09-07 19:57 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-09-07 19:35 - 2013-09-07 19:35 - 00003138 _____ C:\Windows\System32\Tasks\{DA011454-E305-4BDD-B688-49E934CEE1DD}
2013-09-07 19:25 - 2013-09-07 19:25 - 00003138 _____ C:\Windows\System32\Tasks\{2A35A8F6-06F9-44D8-9A6E-91241A183107}
2013-09-07 18:25 - 2013-09-07 18:25 - 00000000 ____D C:\ProgramData\Samsung
2013-09-07 18:25 - 2013-09-07 18:25 - 00000000 ____D C:\Program Files\SAMSUNG
2013-09-07 18:17 - 2013-09-07 18:17 - 00000000 ____D C:\Intel
2013-09-07 18:14 - 2013-03-24 18:13 - 00002467 _____ C:\Users\Public\Desktop\SlimDrivers.lnk
2013-09-07 18:14 - 2013-03-24 18:13 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
Files to move or delete:
====================
C:\Users\aysenur\ISSetup.dll
C:\Users\aysenur\setup.exe
C:\Users\aysenur\_setup.dll
C:\Users\Public\AlexaNSISPlugin.1328.dll
Some content of TEMP:
====================
C:\Users\aysenur\AppData\Local\Temp\BackupSetup.exe
C:\Users\aysenur\AppData\Local\Temp\nsm738E.exe
C:\Users\aysenur\AppData\Local\Temp\pricepeep_1.exe
C:\Users\aysenur\AppData\Local\Temp\Setup.exe
C:\Users\aysenur\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-04 00:26
==================== End Of Log ============================ --- --- --- |