So, hier die gewünschten Logs:
AdwCleaner Logfile: Code:
# AdwCleaner v3.210 - Bericht erstellt am 24/05/2014 um 17:24:14
# Aktualisiert 19/05/2014 von Xplode
# Betriebssystem : Windows 8.1 Pro with Media Center (64 bits)
# Benutzername : Hanling - HANLING-PC
# Gestartet von : C:\Users\hanla_000\Desktop\adwcleaner_3.210.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\hanla_000\AppData\Roaming\software4u
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKCU\Software\InstallCore
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
*************************
AdwCleaner[R0].txt - [941 octets] - [24/05/2014 17:23:56]
AdwCleaner[S0].txt - [809 octets] - [24/05/2014 17:24:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [868 octets] ########## --- --- --- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 Pro with Media Center x64
Ran by Hanling on 24.05.2014 at 17:28:55,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
~~~ Files
Successfully deleted: [File] "C:\Users\hanla_000\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.05.2014 at 17:31:01,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 24.05.2014
Suchlauf-Zeit: 17:32:38
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.05.24.04
Rootkit Datenbank: v2014.05.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Hanling
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 308572
Verstrichene Zeit: 3 Min, 50 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 1
Riskware.BitcoinMiner, C:\Users\hanla_000\AppData\Local\Temp\msupdate71\msupdate.7z, In Quarantäne, [112376df7dfe5adc3208f74ba75a58a8],
Physische Sektoren: 0
(No malicious items detected)
(end)
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-05-2014 1
Ran by Hanling (administrator) on HANLING-PC on 24-05-2014 17:39:23
Running from C:\Users\hanla_000\Desktop
Platform: Windows 8.1 Pro with Media Center (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
() C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
() C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP ENVY 110 series\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP ENVY 110 series\Bin\HPNetworkCommunicator.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2419512 2012-11-04] (Logitech, Inc.)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1742064 2014-03-31] (Bitdefender)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [ACPW07DE] => C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [1739080 2013-09-25] (ACD Systems)
HKLM\...\Run: [ACPW07EN] => C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [1739080 2013-09-25] (ACD Systems)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] => C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2012-08-20] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253672 2011-01-07] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [MagicRotation] => C:\Program Files\MagicRotation Auto\MagicRotation Auto.exe [954880 2012-09-20] (Samsung Electronics, Inc.)
HKLM-x32\...\Run: [MagicRotation Auto] => C:\Program Files\MagicRotation Auto\MagicRotation Auto.exe [954880 2012-09-20] (Samsung Electronics, Inc.)
HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 9.2.2\bin\EpmNews.exe [2081792 2013-03-29] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [RoccatKone+] => C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.EXE [557056 2013-09-13] (ROCCAT GmbH)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5562736 2014-05-09] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-15] (Apple Inc.)
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [567888 2014-03-31] (Bitdefender)
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1001536 2014-03-31] (Bitdefender)
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614232 2014-03-31] (Bitdefender)
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [567888 2014-03-31] (Bitdefender)
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614232 2014-03-31] (Bitdefender)
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\Run: [HP ENVY 110 series (NET)] => C:\Program Files\HP\HP ENVY 110 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-719912548-1546492267-3311168217-1001\...\MountPoints2: {4d8ed5b2-b7e0-11e2-bf55-000c55ff7c4a} - "R:\LaunchU3.exe" -a
Startup: C:\Users\hanla_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autostart\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe (Samsung Electronics.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gmx.net/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Bitdefender-Geldbörse - {09F58E74-42B4-4D70-BA26-35FC954E7A17} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: HKLM-x32 {271A3CF5-5A54-447B-A08F-BE805F0DA60B} https://finanzcenter.sparkasse-bremen.de/_plugin/AXFOAM.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.10.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2013-08-14]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-01-02]
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ []
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2013-08-14]
==================== Services (Whitelisted) =================
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe [324608 2012-05-18] (ASUSTeK Computer Inc.)
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2013-11-27] (Bitdefender)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S4 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1617352 2014-04-02] (NVIDIA Corporation)
S4 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20542408 2014-04-02] (NVIDIA Corporation)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2013-12-21] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [143288 2014-04-04] (Stardock Software, Inc)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-22] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1523728 2014-03-31] (Bitdefender)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-05-09] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [295800 2014-05-09] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2012-04-19] (ASUSTek Computer Inc.)
R0 asahci64; C:\Windows\System32\drivers\asahci64.sys [49760 2012-01-06] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [893440 2014-02-03] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [635392 2014-02-03] (BitDefender)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23456 2012-07-11] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-10-02] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-10-02] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-10-02] (Bitdefender SRL)
S3 BDSandBox; C:\WINDOWS\system32\drivers\bdsandbox.sys [82824 2013-11-27] (BitDefender SRL)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-12-23] (Disc Soft Ltd)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [17480 2013-03-07] ()
S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [13896 2013-03-07] ()
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [9800 2013-03-07] ()
S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] ()
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-02] (BitDefender LLC)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R1 MagicRotation; C:\Windows\system32\drivers\MTiCtwl.sys [23096 2008-11-04] (Samsung Electronics, Inc. )
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] ()
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-12-02] (Microsoft Corporation)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-02] (BitDefender S.R.L.)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
R3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-24 17:39 - 2014-05-24 17:39 - 00023067 _____ () C:\Users\hanla_000\Desktop\FRST.txt
2014-05-24 17:39 - 2014-05-24 17:39 - 00001254 _____ () C:\Users\hanla_000\Desktop\mbam.txt
2014-05-24 17:31 - 2014-05-24 17:38 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-24 17:31 - 2014-05-24 17:31 - 00001120 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-24 17:31 - 2014-05-24 17:31 - 00000976 _____ () C:\Users\hanla_000\Desktop\JRT.txt
2014-05-24 17:31 - 2014-05-24 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-24 17:31 - 2014-05-24 17:31 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-24 17:31 - 2014-05-24 17:31 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-24 17:31 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-24 17:31 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-24 17:31 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-24 17:28 - 2014-05-24 17:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-24 17:24 - 2014-05-24 17:24 - 00000947 _____ () C:\Users\hanla_000\Desktop\AdwCleaner[S0].txt
2014-05-24 17:23 - 2014-05-24 17:28 - 00000000 ____D () C:\AdwCleaner
2014-05-24 17:22 - 2014-05-24 17:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\hanla_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-05-24 17:22 - 2014-05-24 17:22 - 01016261 _____ (Thisisu) C:\Users\hanla_000\Desktop\JRT.exe
2014-05-24 17:20 - 2014-05-24 17:20 - 01326389 _____ () C:\Users\hanla_000\Desktop\adwcleaner_3.210.exe
2014-05-24 16:30 - 2014-05-24 16:30 - 00000000 ____D () C:\Users\hanla_000\Desktop\FRST-OlderVersion
2014-05-24 16:29 - 2014-05-24 16:30 - 02066432 _____ (Farbar) C:\Users\hanla_000\Desktop\FRST64.exe
2014-05-23 20:19 - 2014-05-24 17:39 - 00000000 ____D () C:\FRST
2014-05-23 17:40 - 2014-05-23 17:40 - 00012288 _____ () C:\WINDOWS\system32\umstartup.etl
2014-05-23 14:54 - 2014-05-23 15:00 - 00003337 _____ () C:\ProgramData\RUNDLL32.EXE-5756-F.txt
2014-05-18 12:46 - 2014-05-19 18:04 - 00119296 ___SH () C:\Users\hanla_000\Desktop\Thumbs.db
2014-05-18 12:13 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-05-18 12:13 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-05-18 12:13 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-05-18 12:13 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2014-05-18 12:13 - 2014-04-18 11:32 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-05-18 12:13 - 2014-04-18 10:58 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-05-18 12:13 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-05-18 12:13 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-05-18 12:13 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-05-18 12:13 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-05-18 12:13 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-05-18 12:13 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2014-05-18 12:13 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2014-05-18 12:13 - 2014-04-11 08:13 - 01200128 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2014-05-18 12:13 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-05-18 12:13 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2014-05-18 12:13 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-05-18 12:13 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-05-18 12:13 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2014-05-18 12:13 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2014-05-18 12:13 - 2014-04-09 06:35 - 01411584 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-05-18 12:13 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2014-05-18 12:13 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2014-05-18 12:13 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2014-05-18 12:13 - 2014-04-06 18:34 - 00275800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2014-05-18 12:13 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-05-18 12:13 - 2014-04-06 18:31 - 21268952 ____N (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-05-18 12:13 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2014-05-18 12:13 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2014-05-18 12:13 - 2014-04-06 18:20 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 01401224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcmde.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-05-18 12:13 - 2014-04-06 18:20 - 00233912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2014-05-18 12:13 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2014-05-18 12:13 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2014-05-18 12:13 - 2014-04-06 17:22 - 18755672 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-05-18 12:13 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-05-18 12:13 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-05-18 12:13 - 2014-04-06 16:10 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-05-18 12:13 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
2014-05-18 12:13 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2014-05-18 12:13 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2014-05-18 12:13 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2014-05-18 12:13 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srclient.dll
2014-05-18 12:13 - 2014-04-06 13:55 - 16872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-05-18 12:13 - 2014-04-06 13:54 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-05-18 12:13 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2014-05-18 12:13 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-05-18 12:13 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-05-18 12:13 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-05-18 12:13 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2014-05-18 12:13 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-05-18 12:13 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2014-05-18 12:13 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2014-05-18 12:13 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2014-05-18 12:13 - 2014-04-03 10:12 - 02124840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-05-18 12:13 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2014-05-18 12:13 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2014-05-18 12:13 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2014-05-18 12:13 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
2014-05-18 12:13 - 2014-04-03 05:53 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2014-05-18 12:13 - 2014-04-03 04:53 - 04269056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-05-18 12:13 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-05-18 12:13 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2014-05-18 12:13 - 2014-04-03 04:23 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-05-18 12:13 - 2014-04-03 04:23 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-05-18 12:13 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tlscsp.dll
2014-05-18 12:13 - 2014-04-03 04:22 - 03359744 ____N (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-05-18 12:13 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll
2014-05-18 12:13 - 2014-04-01 08:23 - 00384856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-05-18 12:13 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-05-18 12:13 - 2014-03-31 07:35 - 02518360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-05-18 12:13 - 2014-03-31 07:35 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-05-18 12:13 - 2014-03-31 02:41 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2014-05-18 12:13 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2014-05-18 12:13 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2014-05-18 12:13 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2014-05-18 12:13 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-05-18 12:13 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-05-18 12:13 - 2014-03-31 00:11 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-05-18 12:13 - 2014-03-30 23:47 - 00872448 ____N (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-05-18 12:13 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2014-05-18 12:13 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-05-18 12:13 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2014-05-18 12:13 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2014-05-18 12:13 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2014-05-18 12:13 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2014-05-18 12:13 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-05-18 12:13 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-05-18 12:13 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2014-05-18 12:13 - 2014-03-25 00:58 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-05-18 12:13 - 2014-03-21 06:14 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
2014-05-18 12:13 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-05-18 12:13 - 2014-03-20 02:51 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2014-05-18 12:13 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-05-18 12:13 - 2014-03-20 01:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2014-05-18 12:13 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-05-18 12:13 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2014-05-18 12:13 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2014-05-18 12:13 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-05-18 12:13 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2014-05-18 12:13 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-05-18 12:13 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2014-05-18 12:13 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2014-05-18 12:13 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2014-05-18 12:13 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2014-05-18 12:13 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-05-18 12:13 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2014-05-18 12:13 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2014-05-18 12:13 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-05-18 12:13 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-05-18 12:13 - 2014-03-18 10:19 - 00077312 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-05-18 12:13 - 2014-03-18 10:18 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xusb22.sys
2014-05-18 12:13 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2014-05-18 12:13 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2014-05-18 12:13 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-05-18 12:13 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-05-18 12:13 - 2014-03-17 05:01 - 00486912 ____N (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2014-05-18 12:13 - 2014-03-17 04:47 - 01025024 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-05-18 12:13 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2014-05-18 12:13 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2014-05-18 12:13 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2014-05-18 12:13 - 2014-03-06 14:42 - 00310616 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-05-18 12:12 - 2014-05-18 12:12 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2014-05-17 18:31 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files (x86)\Crewlog
2014-05-17 18:31 - 2014-05-17 18:31 - 00001027 ____N () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crewlog.lnk
2014-05-17 18:31 - 2008-10-20 09:34 - 00521552 ____N (ComponentOne LLC) C:\WINDOWS\SysWOW64\VSRpt8.ocx
2014-05-17 18:31 - 2008-10-20 09:34 - 00451880 ____N (ComponentOne) C:\WINDOWS\SysWOW64\VSPrint8.ocx
2014-05-17 18:31 - 2008-10-20 09:34 - 00222504 ____N (ComponentOne) C:\WINDOWS\SysWOW64\VSVPort8.ocx
2014-05-17 18:31 - 2008-10-20 09:07 - 00623920 ____N (ComponentOne) C:\WINDOWS\SysWOW64\VSFlex8.ocx
2014-05-17 18:31 - 2008-01-16 13:55 - 00349504 _____ (ComponentOne LLC) C:\WINDOWS\SysWOW64\titime8.ocx
2014-05-17 18:31 - 2006-10-20 13:35 - 00064512 _____ () C:\WINDOWS\SysWOW64\shdocvw.oca
2014-05-17 18:31 - 2004-07-27 16:22 - 00856064 _____ (AppForge, Inc.) C:\WINDOWS\SysWOW64\afCore.dll
2014-05-17 18:31 - 2004-07-27 16:20 - 00081920 _____ (AppForge, Inc.) C:\WINDOWS\SysWOW64\pCOM.dll
2014-05-17 18:31 - 2003-09-12 20:19 - 00548864 _____ (ComponentOne LLC) C:\WINDOWS\SysWOW64\tibase8.dll
2014-05-17 18:31 - 2003-09-12 19:00 - 00131072 ____N (ComponentOne LLC) C:\WINDOWS\SysWOW64\tishare8.dll
2014-05-17 18:31 - 2002-07-31 17:36 - 00094208 ____N (ST-software) C:\WINDOWS\SysWOW64\STrainbowbar.ocx
2014-05-17 18:31 - 2001-04-07 16:24 - 00044544 ____N () C:\WINDOWS\SysWOW64\Gif89.dll
2014-05-17 18:31 - 2000-12-06 06:00 - 00262328 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSDATGRD.OCX
2014-05-17 18:31 - 2000-12-06 06:00 - 00109248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswinsck.ocx
2014-05-17 18:31 - 2000-10-02 06:00 - 00125712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VB6DE.DLL
2014-05-17 18:31 - 2000-05-22 06:00 - 00647872 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCT2.OCX
2014-05-17 18:31 - 2000-05-22 06:00 - 00232640 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSDATLST.OCX
2014-05-17 18:31 - 2000-05-22 06:00 - 00140488 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\COMDLG32.OCX
2014-05-17 18:31 - 2000-05-22 06:00 - 00118976 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSADODC.OCX
2014-05-17 18:31 - 2000-05-22 06:00 - 00115920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSINET.ocx
2014-05-17 18:31 - 2000-05-11 06:00 - 00397312 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSRDO20.DLL
2014-05-17 18:31 - 2000-05-11 06:00 - 00077824 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSBIND.DLL
2014-05-17 18:31 - 2000-03-14 06:00 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RDOCURS.DLL
2014-05-17 18:31 - 2000-03-14 06:00 - 00118784 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSSTDFMT.DLL
2014-05-17 18:31 - 1998-11-25 22:25 - 00018944 _____ ( ) C:\WINDOWS\SysWOW64\implode.dll
2014-05-17 18:31 - 1998-10-30 06:02 - 00901120 _____ (Three |D| Graphics, Inc.) C:\WINDOWS\SysWOW64\sscsdk32.dll
2014-05-17 18:31 - 1998-07-06 06:00 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCMCDE.DLL
2014-05-17 18:31 - 1998-07-06 06:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RDO20DE.DLL
2014-05-17 18:31 - 1998-07-06 06:00 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCC2DE.DLL
2014-05-17 18:31 - 1998-07-06 06:00 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CMDLGDE.DLL
2014-05-17 18:31 - 1998-07-06 06:00 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DATLSDE.DLL
2014-05-17 18:31 - 1998-07-06 06:00 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DATGDDE.DLL
2014-05-17 18:31 - 1998-07-06 06:00 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ADODCDE.DLL
2014-05-17 18:31 - 1998-06-18 06:00 - 00089360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VB5DB.DLL
2014-05-17 18:31 - 1998-05-29 02:49 - 00026624 ____N (Seagate Software, Inc.) C:\WINDOWS\SysWOW64\CDO32.dll
2014-05-17 18:29 - 2014-05-24 17:38 - 00008180 _____ () C:\WINDOWS\AutoKMS.log
2014-05-17 18:28 - 2014-05-24 17:26 - 00000660 _____ () C:\WINDOWS\PFRO.log
2014-05-17 18:28 - 2014-05-17 18:28 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-05-17 18:28 - 2014-05-17 18:28 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-05-17 13:56 - 2014-05-24 15:31 - 00000000 ____D () C:\Users\hanla_000\AppData\Local\77B7FFD3-307F-4D31-B5D7-373B34EAF54F.aplzod
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Apple
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files\iTunes
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files\Bonjour
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-05-17 13:46 - 2014-05-18 12:20 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-05-17 13:46 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files\iPod
2014-05-17 13:46 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2014-05-16 18:00 - 2014-05-16 18:42 - 126399323 _____ () C:\Users\hanla_000\Desktop\Squirting_Over_The_Bedsheets.avi
2014-05-15 20:04 - 2014-05-15 20:04 - 00000000 ____D () C:\Program Files\Western Digital
2014-05-14 16:44 - 2014-03-24 04:30 - 00257880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-05-14 16:44 - 2014-03-24 04:30 - 00123224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-05-14 16:44 - 2014-03-24 04:27 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-05-14 16:44 - 2014-03-13 09:42 - 00308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2014-05-14 16:44 - 2014-03-13 08:51 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wusa.exe
2014-05-14 16:43 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-05-14 16:43 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-05-14 16:43 - 2014-05-06 05:00 - 00084992 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-05-14 16:43 - 2014-05-06 04:10 - 00069632 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-05-14 16:43 - 2014-04-11 12:03 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-05-14 16:43 - 2014-04-11 12:03 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-05-14 16:43 - 2014-04-11 10:25 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2014-05-14 16:43 - 2014-04-11 08:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-05-14 16:43 - 2014-04-11 07:53 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-05-14 16:43 - 2014-04-11 07:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-05-14 16:43 - 2014-04-11 05:54 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-05-14 16:43 - 2014-04-11 05:06 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-05-14 16:43 - 2014-04-11 05:05 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-14 16:43 - 2014-04-11 05:05 - 00123904 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-05-14 16:43 - 2014-04-11 05:02 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-14 16:43 - 2014-04-11 05:02 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-05-14 16:43 - 2014-04-11 05:01 - 00137728 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-05-14 16:43 - 2014-04-11 05:00 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-05-14 16:43 - 2014-04-11 04:59 - 00666624 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-05-14 16:43 - 2014-04-11 04:57 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-05-14 16:43 - 2014-04-11 04:56 - 00381440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-05-14 16:43 - 2014-04-11 04:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-05-14 16:43 - 2014-04-11 04:53 - 00827392 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-05-14 16:43 - 2014-04-11 04:52 - 03464192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-05-14 16:43 - 2014-04-11 04:46 - 01705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-05-14 16:43 - 2014-04-11 04:36 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-05-14 16:43 - 2014-04-11 04:34 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-05-14 16:43 - 2014-04-11 04:29 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-05-14 16:43 - 2014-04-11 04:25 - 00921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-05-14 16:43 - 2014-04-09 00:46 - 00086688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll
2014-05-14 16:43 - 2014-04-09 00:46 - 00028320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll
2014-05-14 16:43 - 2014-04-08 20:54 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt_map.dll
2014-05-14 16:43 - 2014-04-08 20:54 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt100.dll
2014-05-09 18:00 - 2014-05-18 12:21 - 00000000 ____D () C:\Program Files (x86)\MKVToolNix
2014-05-07 17:12 - 2014-05-07 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Just Flight
2014-05-07 16:47 - 2014-05-07 16:47 - 00000000 ____D () C:\Users\hanla_000\AppData\Local\Microsoft Game Studios
2014-05-07 16:39 - 2014-05-07 16:39 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-02 11:23 - 2014-05-02 11:23 - 02724864 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-05-02 11:23 - 2014-05-02 11:23 - 02724864 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-04-26 22:31 - 2014-04-26 22:32 - 00000000 ____D () C:\Users\hanla_000\Desktop\bun
2014-04-25 17:40 - 2014-04-25 17:40 - 00000000 _____ () C:\WINDOWS\SysWOW64\Drivers\1043_ASUSTeK_P8Z77-V.alu
2014-04-25 17:13 - 2014-04-25 17:13 - 00003826 ____N () C:\WINDOWS\System32\Tasks\Security Center Update - 4185919329
2014-04-25 17:13 - 2014-04-25 17:13 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\Kuqybobi
2014-04-25 15:36 - 2014-03-26 23:40 - 00601432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2014-04-25 15:34 - 2014-03-27 14:45 - 31270856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 25257416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 23785416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 17561544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 17467048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 15964736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 13158232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2014-04-25 15:34 - 2014-03-27 14:45 - 11644392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 11598560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 09734744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 09697128 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 03139928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 02949976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 02785056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 02413344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 01890080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433750.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 01539416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433750.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00894752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00891168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00864600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00859592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00836544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00354016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00305600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00166568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2014-04-25 15:34 - 2014-03-27 14:45 - 00146480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2014-04-25 15:34 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2014-04-25 15:34 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2014-04-25 15:29 - 2014-04-25 15:29 - 00000000 ____D () C:\Program Files (x86)\ASM104xUSB3
2014-04-25 14:49 - 2014-04-25 14:49 - 00016896 _____ (ASUS) C:\WINDOWS\AsTaskSched.dll
2014-04-25 14:45 - 2014-04-25 14:45 - 00000000 ____D () C:\Users\hanla_000\Intel
==================== One Month Modified Files and Folders =======
2014-05-24 17:39 - 2014-05-24 17:39 - 00023067 _____ () C:\Users\hanla_000\Desktop\FRST.txt
2014-05-24 17:39 - 2014-05-24 17:39 - 00001254 _____ () C:\Users\hanla_000\Desktop\mbam.txt
2014-05-24 17:39 - 2014-05-23 20:19 - 00000000 ____D () C:\FRST
2014-05-24 17:38 - 2014-05-24 17:31 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-24 17:38 - 2014-05-17 18:29 - 00008180 _____ () C:\WINDOWS\AutoKMS.log
2014-05-24 17:38 - 2013-12-02 20:01 - 02079341 _____ () C:\WINDOWS\WindowsUpdate.log
2014-05-24 17:38 - 2013-07-31 18:45 - 00008192 _____ () C:\WINDOWS\SysWOW64\WDPABKP.dat
2014-05-24 17:38 - 2013-01-02 00:03 - 00003494 _____ () C:\WINDOWS\System32\Tasks\AutoKMS
2014-05-24 17:38 - 2012-12-28 22:16 - 01048576 _____ () C:\WINDOWS\PE_Rom.dll
2014-05-24 17:37 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-24 17:37 - 2012-12-28 21:08 - 00003030 _____ () C:\WINDOWS\System32\Tasks\MSIAfterburner
2014-05-24 17:33 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-24 17:33 - 2013-09-30 05:58 - 00765378 _____ () C:\WINDOWS\system32\perfh007.dat
2014-05-24 17:33 - 2013-09-30 05:58 - 00159696 _____ () C:\WINDOWS\system32\perfc007.dat
2014-05-24 17:32 - 2012-12-28 22:21 - 00000000 _____ () C:\WINDOWS\Path.idx
2014-05-24 17:31 - 2014-05-24 17:31 - 00001120 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-24 17:31 - 2014-05-24 17:31 - 00000976 _____ () C:\Users\hanla_000\Desktop\JRT.txt
2014-05-24 17:31 - 2014-05-24 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-24 17:31 - 2014-05-24 17:31 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-24 17:31 - 2014-05-24 17:31 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-24 17:28 - 2014-05-24 17:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-24 17:28 - 2014-05-24 17:23 - 00000000 ____D () C:\AdwCleaner
2014-05-24 17:28 - 2013-08-14 12:21 - 00003576 _____ () C:\WINDOWS\System32\Tasks\Bitdefender Auto-Scan
2014-05-24 17:26 - 2014-05-17 18:28 - 00000660 _____ () C:\WINDOWS\PFRO.log
2014-05-24 17:24 - 2014-05-24 17:24 - 00000947 _____ () C:\Users\hanla_000\Desktop\AdwCleaner[S0].txt
2014-05-24 17:23 - 2012-12-28 21:38 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\vlc
2014-05-24 17:22 - 2014-05-24 17:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\hanla_000\Desktop\mbam-setup-2.0.2.1012.exe
2014-05-24 17:22 - 2014-05-24 17:22 - 01016261 _____ (Thisisu) C:\Users\hanla_000\Desktop\JRT.exe
2014-05-24 17:20 - 2014-05-24 17:20 - 01326389 _____ () C:\Users\hanla_000\Desktop\adwcleaner_3.210.exe
2014-05-24 17:12 - 2013-04-27 11:02 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-24 17:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-05-24 16:30 - 2014-05-24 16:30 - 00000000 ____D () C:\Users\hanla_000\Desktop\FRST-OlderVersion
2014-05-24 16:30 - 2014-05-24 16:29 - 02066432 _____ (Farbar) C:\Users\hanla_000\Desktop\FRST64.exe
2014-05-24 15:31 - 2014-05-17 13:56 - 00000000 ____D () C:\Users\hanla_000\AppData\Local\77B7FFD3-307F-4D31-B5D7-373B34EAF54F.aplzod
2014-05-24 12:26 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-05-23 22:56 - 2013-12-02 20:23 - 00000000 ____D () C:\Users\hanla_000
2014-05-23 22:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-05-23 17:40 - 2014-05-23 17:40 - 00012288 _____ () C:\WINDOWS\system32\umstartup.etl
2014-05-23 16:06 - 2013-11-24 20:13 - 00000000 ____D () C:\WINDOWS\pss
2014-05-23 15:56 - 2012-12-28 17:56 - 00000000 ___RD () C:\Users\hanla_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autostart
2014-05-23 15:47 - 2013-09-30 06:00 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-05-23 15:47 - 2012-12-29 20:17 - 00000000 ____D () C:\ProgramData\pdf995
2014-05-23 15:47 - 2012-12-28 21:24 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\Winamp
2014-05-23 15:46 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\registration
2014-05-23 15:00 - 2014-05-23 14:54 - 00003337 _____ () C:\ProgramData\RUNDLL32.EXE-5756-F.txt
2014-05-23 14:52 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-05-23 14:18 - 2012-12-28 18:04 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-719912548-1546492267-3311168217-1001
2014-05-21 23:11 - 2014-01-09 23:57 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0
2014-05-21 19:26 - 2012-12-28 22:21 - 00003039 _____ () C:\WINDOWS\MB.idx
2014-05-21 16:28 - 2012-12-30 15:13 - 00000000 ____D () C:\ProgramData\Origin
2014-05-21 16:27 - 2013-09-26 18:19 - 00000000 ____D () C:\Users\hanla_000\Desktop\ebay
2014-05-19 18:04 - 2014-05-18 12:46 - 00119296 ___SH () C:\Users\hanla_000\Desktop\Thumbs.db
2014-05-18 20:35 - 2012-12-30 02:27 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\Apple Computer
2014-05-18 16:27 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-05-18 13:24 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-18 13:23 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-18 12:21 - 2014-05-09 18:00 - 00000000 ____D () C:\Program Files (x86)\MKVToolNix
2014-05-18 12:21 - 2014-03-01 12:33 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-18 12:21 - 2013-12-23 19:05 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-05-18 12:21 - 2013-08-21 20:23 - 00000000 ____D () C:\Program Files (x86)\Samsung SSD Magician
2014-05-18 12:21 - 2013-05-24 12:57 - 00000000 ____D () C:\Program Files (x86)\CrystalDiskInfo
2014-05-18 12:21 - 2013-04-05 17:30 - 00000000 ____D () C:\Program Files (x86)\PDF24
2014-05-18 12:21 - 2012-12-30 01:41 - 00000000 ____D () C:\Program Files (x86)\PS3 Media Server
2014-05-18 12:21 - 2012-12-29 20:36 - 00000000 ____D () C:\Program Files (x86)\Movies2iPhone
2014-05-18 12:21 - 2012-12-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-18 12:20 - 2014-05-17 18:31 - 00000000 ____D () C:\Program Files (x86)\Crewlog
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Apple
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files\iTunes
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files\Bonjour
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-05-18 12:20 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-05-18 12:20 - 2013-12-02 20:01 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-18 12:20 - 2013-09-30 06:00 - 00000000 ____D () C:\Program Files\Windows Journal
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\WinMetadata
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Com
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\Com
2014-05-18 12:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-05-18 12:20 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2014-05-18 12:20 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-05-18 12:20 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers
2014-05-18 12:20 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\servicing
2014-05-18 12:20 - 2013-04-20 22:23 - 00000000 ____D () C:\Program Files\Recuva
2014-05-18 12:20 - 2013-01-02 00:00 - 00000000 ____D () C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-05-18 12:20 - 2012-12-30 20:30 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-05-18 12:20 - 2012-12-30 02:15 - 00000000 ____D () C:\Program Files\Common Files\ACD Systems
2014-05-18 12:20 - 2012-12-29 20:31 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\Wise Registry Cleaner
2014-05-18 12:20 - 2012-12-29 19:45 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-18 12:20 - 2012-12-28 22:13 - 00000000 ____D () C:\WINDOWS\System32\Tasks\ASUS
2014-05-18 12:20 - 2012-12-28 21:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multimedia
2014-05-18 12:20 - 2012-12-28 21:04 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-05-18 12:20 - 2012-12-28 18:24 - 00000000 ____D () C:\Program Files\WinRAR
2014-05-18 12:14 - 2013-08-22 16:44 - 00496880 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-05-18 12:12 - 2014-05-18 12:12 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2014-05-17 18:31 - 2014-05-17 18:31 - 00001027 ____N () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crewlog.lnk
2014-05-17 18:28 - 2014-05-17 18:28 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-05-17 18:28 - 2014-05-17 18:28 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-05-17 18:21 - 2012-12-28 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anwendungen
2014-05-17 13:56 - 2012-12-30 02:27 - 00000000 ____D () C:\Users\hanla_000\AppData\Local\Apple Computer
2014-05-17 13:46 - 2014-05-17 13:46 - 00000000 ____D () C:\Program Files\iPod
2014-05-17 13:46 - 2012-12-30 02:27 - 00000000 ____D () C:\ProgramData\Apple
2014-05-16 22:36 - 2012-12-28 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hardware
2014-05-16 18:42 - 2014-05-16 18:00 - 126399323 _____ () C:\Users\hanla_000\Desktop\Squirting_Over_The_Bedsheets.avi
2014-05-15 20:04 - 2014-05-15 20:04 - 00000000 ____D () C:\Program Files\Western Digital
2014-05-15 20:04 - 2014-01-09 19:45 - 00000000 ____D () C:\Program Files\Common Files\Western Digital
2014-05-15 20:04 - 2014-01-09 19:45 - 00000000 ____D () C:\Program Files (x86)\Western Digital
2014-05-15 20:04 - 2013-07-31 18:48 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-15 20:04 - 2013-07-31 18:43 - 00000000 ____D () C:\ProgramData\Western Digital
2014-05-15 19:59 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-15 19:59 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-15 19:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-05-15 19:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates
2014-05-15 19:59 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-15 19:59 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 17:03 - 2013-01-01 19:14 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-14 17:02 - 2013-07-19 14:52 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-05-14 17:01 - 2012-12-28 18:13 - 93223848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-05-13 23:41 - 2014-01-16 17:19 - 00002457 ____N () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-13 20:13 - 2013-04-27 11:02 - 00003772 ____N () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-05-12 07:26 - 2014-05-24 17:31 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-24 17:31 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-24 17:31 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-09 18:01 - 2014-03-03 21:46 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\mkvtoolnix
2014-05-07 17:12 - 2014-05-07 17:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Just Flight
2014-05-07 17:12 - 2012-12-28 20:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-07 16:47 - 2014-05-07 16:47 - 00000000 ____D () C:\Users\hanla_000\AppData\Local\Microsoft Game Studios
2014-05-07 16:39 - 2014-05-07 16:39 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-06 06:40 - 2014-05-14 16:43 - 23544320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-05-06 05:25 - 2014-05-14 16:43 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-05-06 05:00 - 2014-05-14 16:43 - 00084992 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-14 16:43 - 00069632 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-05-02 17:19 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Help
2014-05-02 11:23 - 2014-05-02 11:23 - 02724864 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-05-02 11:23 - 2014-05-02 11:23 - 02724864 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-05-01 22:30 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-05-01 22:30 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-30 16:26 - 2012-12-28 19:26 - 00000145 _____ () C:\Users\hanla_000\Desktop\Passes.txt
2014-04-26 22:32 - 2014-04-26 22:31 - 00000000 ____D () C:\Users\hanla_000\Desktop\bun
2014-04-25 17:40 - 2014-04-25 17:40 - 00000000 _____ () C:\WINDOWS\SysWOW64\Drivers\1043_ASUSTeK_P8Z77-V.alu
2014-04-25 17:13 - 2014-04-25 17:13 - 00003826 ____N () C:\WINDOWS\System32\Tasks\Security Center Update - 4185919329
2014-04-25 17:13 - 2014-04-25 17:13 - 00000000 ____D () C:\Users\hanla_000\AppData\Roaming\Kuqybobi
2014-04-25 15:36 - 2013-12-02 20:01 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-04-25 15:36 - 2013-12-02 20:01 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-04-25 15:29 - 2014-04-25 15:29 - 00000000 ____D () C:\Program Files (x86)\ASM104xUSB3
2014-04-25 15:09 - 2013-01-16 12:45 - 04700560 _____ () C:\WINDOWS\PE_File.dll
2014-04-25 14:50 - 2012-12-28 21:44 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-04-25 14:49 - 2014-04-25 14:49 - 00016896 _____ (ASUS) C:\WINDOWS\AsTaskSched.dll
2014-04-25 14:46 - 2012-12-28 21:46 - 00000000 ____D () C:\ProgramData\Intel
2014-04-25 14:46 - 2012-12-28 21:46 - 00000000 ____D () C:\Program Files\Intel
2014-04-25 14:45 - 2014-04-25 14:45 - 00000000 ____D () C:\Users\hanla_000\Intel
2014-04-24 14:47 - 2014-02-26 17:48 - 00000000 ____D () C:\Users\hanla_000\AppData\Local\Ajdvworks
Some content of TEMP:
====================
C:\Users\hanla_000\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2014-05-18 12:13] - [2014-03-28 17:58] - 0407016 ____A (Microsoft Corporation) 067CB90C277DB4A737D5DEABA3055972
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2014-05-18 12:13] - [2014-03-06 14:42] - 0310616 ___AC (Microsoft Corporation) 4BB9BC49DEE1A319EC58274A7BBED663
LastRegBack: 2014-05-24 12:31
==================== End Of Log ============================ --- --- ---
--- --- --- |