Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-12-2013 Ran by User (administrator) on USER-TOSH on 24-12-2013 15:06:27 Running from C:\Users\User\Downloads Microsoft Windows 7 Starter (X86) OS Language: Polish Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe [761024 2013-12-13] () HKLM\...\Run: [AVP] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-12-23] (Kaspersky Lab ZAO) HKCU\...\Run: [AVG-Secure-Search-Update_1213b] - C:\Users\User\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=51ee35d7521d47d3a491cd3c4e649496-abe65da737d9ea232d85c0e25071aaac39ffc351 /CMPID=1213b HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\User\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\Default\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [ 2010-03-03] (TOSHIBA) HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [ 2010-03-03] (TOSHIBA) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://toshiba.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {7CC7958E-AC05-4B62-90C3-76E94E1EB1B7} URL = SearchScopes: HKCU - {0FA4B384-E90A-4074-9336-5CA1325AFF6B} URL = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2 SearchScopes: HKCU - {7CC7958E-AC05-4B62-90C3-76E94E1EB1B7} URL = SearchScopes: HKCU - {8352BF87-4199-4DE2-BEB3-0255939E311F} URL = http://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\mauzbtet.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wolnelektury-pl.xml FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-12-23] (Kaspersky Lab ZAO) S4 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2010-01-28] (TOSHIBA CORPORATION) S4 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION) S4 IconMan_R; C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) S4 NAUpdate; c:\Program Files\Nero\Update\NASvc.exe [503080 2010-05-04] (Nero AG) S4 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH) S4 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51576 2010-07-01] (TOSHIBA Corporation) S4 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [189880 2010-07-28] (TOSHIBA Corporation) S4 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2010-02-05] (TOSHIBA Corporation) ==================== Drivers (Whitelisted) ==================== R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [63616 2010-08-14] (Advanced Micro Devices) R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [32384 2010-08-14] (Advanced Micro Devices) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [102416 2010-09-24] (ATI Technologies, Inc.) S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [33640 2010-10-18] (Atheros) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-12-24] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [595552 2013-12-24] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-12-24] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25696 2013-12-24] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-12-24] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2013-12-24] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145040 2013-12-24] (Kaspersky Lab ZAO) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [36208 2009-07-30] (COMPAL ELECTRONIC INC.) R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation) U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2013-12-24] (Kaspersky Lab ZAO) S3 Tosrfcom; No ImagePath ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-24 15:06 - 2013-12-24 15:07 - 00011350 _____ C:\Users\User\Downloads\FRST.txt 2013-12-24 15:05 - 2013-12-24 15:05 - 00000000 ____D C:\FRST 2013-12-24 15:02 - 2013-12-24 15:02 - 01061581 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2013-12-24 15:01 - 2013-12-24 15:01 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe 2013-12-22 15:43 - 2013-12-22 15:43 - 00002297 _____ C:\Users\User\Desktop\Bezpieczne pieniądze.lnk 2013-12-22 13:47 - 2013-12-22 13:44 - 00001123 _____ C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk 2013-12-22 13:40 - 2013-12-22 13:40 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-22 13:39 - 2013-12-24 14:42 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-12-22 13:39 - 2013-12-22 13:39 - 00000000 ____D C:\Program Files\Kaspersky Lab 2013-12-22 13:38 - 2013-12-24 04:59 - 00595552 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-12-22 13:38 - 2013-12-24 04:59 - 00074848 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-12-22 13:29 - 2013-12-22 13:30 - 00000000 ____D C:\Users\User\.android 2013-12-22 13:29 - 2013-12-22 13:29 - 00000000 ____D C:\Users\User\AppData\Local\cache 2013-12-22 13:28 - 2013-12-24 14:40 - 00000000 ____D C:\Users\User\AppData\Roaming\newnext.me 2013-12-22 13:28 - 2013-12-22 19:13 - 00000000 ____D C:\Users\User\AppData\Local\Mobogenie 2013-12-22 13:28 - 2013-12-22 19:10 - 00000350 _____ C:\Users\User\daemonprocess.txt 2013-12-22 13:28 - 2013-12-22 13:28 - 00000000 ____D C:\Users\User\AppData\Local\genienext 2013-12-22 13:27 - 2013-12-22 19:13 - 00000000 ____D C:\Program Files\Mobogenie 2013-12-22 13:27 - 2013-12-22 13:27 - 00000000 ____D C:\Users\User\AppData\Roaming\WinRAR 2013-12-22 13:27 - 2013-12-22 13:27 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-22 13:27 - 2013-12-22 13:27 - 00000000 ____D C:\Program Files\WinRAR 2013-12-22 13:26 - 2013-12-22 13:25 - 01934344 _____ C:\Users\User\Downloads\wrar501pl(dobreprogramy.pl).exe 2013-12-22 13:25 - 2013-12-22 13:25 - 00664472 _____ C:\Users\User\Downloads\WinRAR(12398).exe 2013-12-22 11:28 - 2013-12-22 11:33 - 00000000 ____D C:\Windows\system32\MRT 2013-12-22 11:27 - 2013-12-01 14:42 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-22 11:20 - 2013-12-22 11:20 - 00000000 ____D C:\Users\User\AppData\Roaming\TP 2013-12-22 07:49 - 2013-12-22 07:49 - 00000000 ____D C:\Windows\system32\SPReview 2013-12-22 04:58 - 2013-12-22 04:59 - 00000000 ____D C:\Windows\system32\EventProviders 2013-12-20 16:23 - 2013-01-04 05:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-12-20 16:22 - 2013-01-04 05:46 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-12-20 16:22 - 2013-01-04 05:46 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 03:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 03:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 03:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-12-20 16:22 - 2013-01-04 03:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-12-20 16:21 - 2013-01-04 03:59 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-12-20 16:20 - 2012-02-15 06:44 - 00826368 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-12-20 16:20 - 2012-02-15 05:22 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-12-20 11:43 - 2012-12-16 15:25 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-12-20 11:43 - 2012-12-16 15:25 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-12-20 11:30 - 2013-12-20 11:30 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software 2013-12-20 11:30 - 2013-12-20 11:30 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software 2013-12-20 11:18 - 2009-11-25 12:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2013-12-20 11:18 - 2009-11-25 12:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2013-12-20 11:18 - 2009-11-25 12:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2013-12-20 11:18 - 2009-11-25 12:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2013-12-20 11:18 - 2009-11-25 12:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2013-12-20 03:37 - 2012-03-01 06:53 - 00019312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2013-12-20 03:37 - 2012-03-01 06:45 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-20 03:37 - 2012-03-01 06:40 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-20 03:32 - 2013-12-20 03:32 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-20 03:32 - 2013-12-20 03:32 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-20 03:32 - 2013-12-20 03:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00434176 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-20 03:32 - 2013-12-20 03:32 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00353584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-20 03:32 - 2013-12-20 03:32 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-20 03:28 - 2013-12-20 03:28 - 01495040 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00728448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-12-20 03:28 - 2013-12-20 03:28 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00283648 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00219008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-12-20 03:28 - 2013-12-20 03:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-12-20 03:26 - 2013-12-20 03:37 - 00004610 _____ C:\Windows\IE9_main.log 2013-12-20 03:25 - 2010-02-11 08:10 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2013-12-20 03:16 - 2013-12-20 03:17 - 00278104 _____ C:\Windows\msxml4-KB954430-enu.LOG 2013-12-20 03:16 - 2013-12-20 03:16 - 00285846 _____ C:\Windows\msxml4-KB973688-enu.LOG 2013-12-20 03:16 - 2013-12-20 03:16 - 00000000 ____D C:\Program Files\MSXML 4.0 2013-12-19 19:23 - 2013-12-19 19:33 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Games 2013-12-19 19:06 - 2013-04-12 14:58 - 01210728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-12-19 19:06 - 2011-04-29 03:57 - 00311296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2013-12-19 19:06 - 2011-04-29 03:57 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-12-19 19:06 - 2011-04-29 03:57 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-12-19 19:05 - 2013-02-12 14:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-12-19 19:05 - 2011-11-17 06:41 - 01288984 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-19 19:05 - 2011-04-25 03:35 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-12-19 19:05 - 2011-02-23 06:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2013-12-19 17:47 - 2013-03-01 04:11 - 02345984 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-19 17:47 - 2012-11-02 05:48 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2013-12-19 17:47 - 2012-08-24 18:10 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-12-19 17:46 - 2013-03-19 06:06 - 03958120 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-12-19 17:46 - 2013-03-19 06:06 - 03902312 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-19 17:46 - 2013-03-19 05:54 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-12-19 17:46 - 2013-03-19 03:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-12-19 17:46 - 2012-11-09 05:49 - 00492032 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-12-19 17:46 - 2011-03-03 06:29 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2013-12-19 17:46 - 2011-03-03 06:29 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2013-12-19 17:46 - 2011-03-03 06:27 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2013-12-19 17:44 - 2012-06-02 05:45 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-12-19 17:44 - 2012-06-02 05:45 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-12-19 17:44 - 2012-06-02 05:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-12-19 17:44 - 2011-08-17 05:26 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2013-12-19 17:44 - 2011-08-17 05:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax 2013-12-19 17:44 - 2011-08-17 05:22 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2013-12-19 17:44 - 2011-08-17 05:22 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax 2013-12-19 17:44 - 2011-08-17 05:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax 2013-12-19 17:43 - 2012-06-06 06:09 - 01236992 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2013-12-19 17:43 - 2012-06-02 05:51 - 00134000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-12-19 17:43 - 2012-06-02 05:51 - 00067440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-12-19 17:43 - 2012-06-02 05:50 - 00369336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-12-19 17:43 - 2012-06-02 05:48 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-12-19 17:43 - 2012-04-28 04:19 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-12-19 17:43 - 2011-08-27 05:43 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-12-19 17:43 - 2011-08-27 05:43 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2013-12-19 17:43 - 2011-07-09 03:26 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2013-12-19 17:43 - 2011-05-24 11:35 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2013-12-19 17:43 - 2011-05-04 03:43 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-12-19 17:43 - 2011-05-04 03:43 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-12-19 17:43 - 2010-11-02 05:41 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll 2013-12-19 17:43 - 2010-11-02 05:40 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll 2013-12-19 17:43 - 2010-11-02 05:40 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll 2013-12-19 17:43 - 2010-11-02 05:39 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2013-12-19 17:43 - 2010-11-02 05:34 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe 2013-12-19 17:43 - 2010-11-02 05:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe 2013-12-19 17:42 - 2013-02-12 16:13 - 02691072 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-12-19 17:42 - 2013-02-12 16:07 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-12-19 17:42 - 2013-02-12 14:59 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-12-19 17:42 - 2011-04-27 03:33 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2013-12-19 17:42 - 2010-10-16 05:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll 2013-12-19 17:41 - 2013-01-04 05:55 - 01287528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-19 17:41 - 2013-01-04 05:55 - 00187240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-12-19 17:41 - 2012-11-02 05:50 - 01388544 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2013-12-19 17:41 - 2011-11-19 15:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2013-12-19 17:41 - 2011-05-03 05:50 - 00740864 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2013-12-19 17:40 - 2011-10-15 06:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2013-12-19 17:40 - 2011-02-12 06:30 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2013-12-19 17:35 - 2012-07-04 22:26 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2013-12-19 17:35 - 2012-07-04 22:23 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2013-12-19 17:35 - 2012-07-04 22:23 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2013-12-19 17:34 - 2010-12-23 06:28 - 00850432 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2013-12-19 17:34 - 2010-12-23 06:28 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2013-12-19 17:34 - 2010-12-23 06:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2013-12-19 17:33 - 2012-08-11 00:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2013-12-19 17:33 - 2011-10-26 05:33 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-12-19 17:33 - 2011-10-26 05:28 - 01328640 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2013-12-19 17:33 - 2010-12-18 06:26 - 01034240 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-12-19 17:29 - 2012-11-20 06:10 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-12-19 17:29 - 2012-04-26 05:43 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2013-12-19 17:29 - 2011-11-17 06:39 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2013-12-19 17:29 - 2011-11-17 06:39 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-12-19 17:29 - 2011-11-17 06:39 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-12-19 17:29 - 2011-11-17 06:39 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-12-19 17:29 - 2011-11-17 06:38 - 01037312 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-12-19 17:29 - 2011-11-17 06:36 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-12-19 17:29 - 2011-06-15 10:04 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll 2013-12-19 17:29 - 2011-06-15 10:04 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll 2013-12-19 17:29 - 2011-06-15 10:04 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2013-12-19 17:29 - 2011-06-15 10:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll 2013-12-19 17:29 - 2011-06-15 10:04 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll 2013-12-19 17:28 - 2012-09-25 22:55 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2013-12-19 17:28 - 2012-05-14 05:37 - 00768512 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-12-19 17:28 - 2012-04-26 05:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2013-12-19 17:28 - 2012-04-26 05:48 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2013-12-19 17:28 - 2012-03-17 08:20 - 00056688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-12-19 17:28 - 2012-03-03 06:40 - 01170944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-12-19 17:28 - 2012-03-03 06:40 - 01074176 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-12-19 17:28 - 2012-03-03 06:40 - 00739840 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-12-19 17:28 - 2012-03-03 06:40 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-12-19 17:28 - 2012-03-03 06:40 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-12-19 17:28 - 2011-12-16 08:59 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2013-12-19 17:28 - 2010-10-16 05:41 - 00101760 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-12-19 17:27 - 2012-09-06 17:48 - 00245616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-12-19 17:27 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2013-12-19 17:27 - 2011-03-11 06:40 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2013-12-19 17:27 - 2011-03-11 06:40 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2013-12-19 17:26 - 2012-06-09 05:46 - 12868608 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-12-19 17:04 - 2012-11-09 05:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-10 14:15 - 2013-12-10 14:15 - 00000000 ____D C:\Users\User\AppData\Local\Macromedia 2013-12-10 10:30 - 2012-06-02 23:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-10 10:30 - 2012-06-02 23:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-10 10:30 - 2012-06-02 23:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-10 10:30 - 2012-06-02 23:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-12-10 10:30 - 2012-06-02 23:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-12-10 10:30 - 2012-06-02 23:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-10 10:30 - 2012-06-02 23:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-10 10:29 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-10 10:29 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-08 12:16 - 2013-12-08 12:16 - 00000000 ____D C:\Users\User\AppData\Roaming\Media Player Classic 2013-12-07 14:59 - 2013-12-07 14:59 - 00000000 ____D C:\Users\User\AppData\Roaming\WinBatch 2013-12-03 12:48 - 2013-12-18 20:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype 2013-12-03 12:47 - 2013-12-03 12:47 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-12-03 12:46 - 2013-12-03 12:45 - 00866720 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-12-03 12:46 - 2013-12-03 12:45 - 00263584 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-12-03 12:46 - 2013-12-03 12:45 - 00174496 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-12-03 12:46 - 2013-12-03 12:45 - 00094112 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-12-03 12:42 - 2013-12-03 12:42 - 00000000 ____D C:\Program Files\K-Lite Codec Pack 2013-12-03 12:42 - 2012-06-09 19:21 - 00178688 _____ C:\Windows\system32\unrar.dll 2013-12-03 12:36 - 2013-12-03 12:36 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-03 12:36 - 2013-12-03 12:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-03 12:21 - 2013-12-03 12:27 - 00000000 ____D C:\Users\User\AppData\Local\Mozilla 2013-12-03 12:21 - 2013-12-03 12:22 - 00000000 ____D C:\Users\User\AppData\Roaming\Mozilla 2013-12-03 12:20 - 2013-12-21 09:32 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-03 12:20 - 2013-12-03 12:20 - 00001116 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-12-03 12:20 - 2013-12-03 12:20 - 00000000 ____D C:\ProgramData\Mozilla 2013-12-03 12:19 - 2013-12-21 06:13 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-03 12:16 - 2013-12-03 12:16 - 00001996 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-12-03 12:16 - 2013-12-03 12:16 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-12-03 12:15 - 2013-12-03 12:37 - 00000000 ____D C:\Users\User\AppData\Local\Adobe 2013-12-03 11:51 - 2013-12-03 11:51 - 00000000 ____D C:\Users\User\AppData\Roaming\AVG2014 2013-12-03 11:47 - 2013-12-03 11:47 - 00000000 ____D C:\Users\User\AppData\Roaming\TuneUp Software 2013-12-03 11:43 - 2013-12-22 11:21 - 00000000 ___HD C:\$AVG 2013-12-03 11:42 - 2013-12-22 11:21 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-03 11:38 - 2013-12-22 13:21 - 00000000 ____D C:\ProgramData\MFAData 2013-12-03 11:38 - 2013-12-22 11:24 - 00000000 ____D C:\Users\User\AppData\Local\Avg2014 2013-12-03 11:38 - 2013-12-03 11:38 - 00000000 ____D C:\Users\User\AppData\Local\MFAData 2013-12-03 11:31 - 2013-12-22 13:21 - 00003732 _____ C:\Windows\PFRO.log 2013-12-03 11:15 - 2013-12-03 11:15 - 00000000 ____D C:\Users\User\AppData\Roaming\Adobe ==================== One Month Modified Files and Folders ======= 2013-12-24 15:07 - 2013-12-24 15:06 - 00011350 _____ C:\Users\User\Downloads\FRST.txt 2013-12-24 15:06 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public 2013-12-24 15:05 - 2013-12-24 15:05 - 00000000 ____D C:\FRST 2013-12-24 15:04 - 2009-07-14 05:34 - 00014304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-24 15:04 - 2009-07-14 05:34 - 00014304 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-24 15:02 - 2013-12-24 15:02 - 01061581 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2013-12-24 15:01 - 2013-12-24 15:01 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe 2013-12-24 15:01 - 2013-11-20 16:25 - 01717627 _____ C:\Windows\WindowsUpdate.log 2013-12-24 14:42 - 2013-12-22 13:39 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-12-24 14:40 - 2013-12-22 13:28 - 00000000 ____D C:\Users\User\AppData\Roaming\newnext.me 2013-12-24 14:39 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-24 14:39 - 2009-07-14 05:39 - 00032129 _____ C:\Windows\setupact.log 2013-12-24 11:28 - 2010-12-09 07:48 - 01523412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-24 11:28 - 2009-07-14 09:07 - 00687828 _____ C:\Windows\system32\perfh015.dat 2013-12-24 11:28 - 2009-07-14 09:07 - 00131382 _____ C:\Windows\system32\perfc015.dat 2013-12-24 05:21 - 2010-12-09 09:34 - 00002505 _____ C:\Users\Public\Desktop\Skype.lnk 2013-12-24 05:21 - 2010-12-09 09:34 - 00000000 ____D C:\ProgramData\Skype 2013-12-24 04:59 - 2013-12-22 13:38 - 00595552 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-12-24 04:59 - 2013-12-22 13:38 - 00074848 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-12-24 04:59 - 2012-08-13 16:49 - 00145040 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2013-12-24 04:59 - 2012-08-02 15:09 - 00025696 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-24 04:59 - 2012-07-25 14:53 - 00025696 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys 2013-12-24 04:59 - 2012-06-08 11:38 - 00044000 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys 2013-12-24 04:59 - 2012-05-25 19:38 - 00025696 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2013-12-24 04:58 - 2012-06-19 17:28 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-22 19:13 - 2013-12-22 13:28 - 00000000 ____D C:\Users\User\AppData\Local\Mobogenie 2013-12-22 19:13 - 2013-12-22 13:27 - 00000000 ____D C:\Program Files\Mobogenie 2013-12-22 19:10 - 2013-12-22 13:28 - 00000350 _____ C:\Users\User\daemonprocess.txt 2013-12-22 15:43 - 2013-12-22 15:43 - 00002297 _____ C:\Users\User\Desktop\Bezpieczne pieniądze.lnk 2013-12-22 13:44 - 2013-12-22 13:47 - 00001123 _____ C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk 2013-12-22 13:40 - 2013-12-22 13:40 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-22 13:39 - 2013-12-22 13:39 - 00000000 ____D C:\Program Files\Kaspersky Lab 2013-12-22 13:30 - 2013-12-22 13:29 - 00000000 ____D C:\Users\User\.android 2013-12-22 13:29 - 2013-12-22 13:29 - 00000000 ____D C:\Users\User\AppData\Local\cache 2013-12-22 13:28 - 2013-12-22 13:28 - 00000000 ____D C:\Users\User\AppData\Local\genienext 2013-12-22 13:27 - 2013-12-22 13:27 - 00000000 ____D C:\Users\User\AppData\Roaming\WinRAR 2013-12-22 13:27 - 2013-12-22 13:27 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-22 13:27 - 2013-12-22 13:27 - 00000000 ____D C:\Program Files\WinRAR 2013-12-22 13:25 - 2013-12-22 13:26 - 01934344 _____ C:\Users\User\Downloads\wrar501pl(dobreprogramy.pl).exe 2013-12-22 13:25 - 2013-12-22 13:25 - 00664472 _____ C:\Users\User\Downloads\WinRAR(12398).exe 2013-12-22 13:21 - 2013-12-03 11:38 - 00000000 ____D C:\ProgramData\MFAData 2013-12-22 13:21 - 2013-12-03 11:31 - 00003732 _____ C:\Windows\PFRO.log 2013-12-22 11:33 - 2013-12-22 11:28 - 00000000 ____D C:\Windows\system32\MRT 2013-12-22 11:24 - 2013-12-03 11:38 - 00000000 ____D C:\Users\User\AppData\Local\Avg2014 2013-12-22 11:21 - 2013-12-03 11:43 - 00000000 ___HD C:\$AVG 2013-12-22 11:21 - 2013-12-03 11:42 - 00000000 ____D C:\ProgramData\AVG2014 2013-12-22 11:20 - 2013-12-22 11:20 - 00000000 ____D C:\Users\User\AppData\Roaming\TP 2013-12-22 07:49 - 2013-12-22 07:49 - 00000000 ____D C:\Windows\system32\SPReview 2013-12-22 05:42 - 2009-07-14 05:33 - 00266376 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-22 05:39 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-12-22 04:59 - 2013-12-22 04:58 - 00000000 ____D C:\Windows\system32\EventProviders 2013-12-21 09:32 - 2013-12-03 12:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-21 06:13 - 2013-12-03 12:19 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-20 20:46 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-12-20 20:16 - 2013-11-20 17:29 - 00000000 ____D C:\Users\User\AppData\Roaming\Toshiba 2013-12-20 11:57 - 2013-11-20 17:27 - 00001432 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-20 11:50 - 2010-12-09 09:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-12-20 11:46 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\System 2013-12-20 11:30 - 2013-12-20 11:30 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software 2013-12-20 11:30 - 2013-12-20 11:30 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software 2013-12-20 03:37 - 2013-12-20 03:26 - 00004610 _____ C:\Windows\IE9_main.log 2013-12-20 03:32 - 2013-12-20 03:32 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-20 03:32 - 2013-12-20 03:32 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-20 03:32 - 2013-12-20 03:32 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-20 03:32 - 2013-12-20 03:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00434176 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-20 03:32 - 2013-12-20 03:32 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00353584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-20 03:32 - 2013-12-20 03:32 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-20 03:32 - 2013-12-20 03:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-20 03:32 - 2013-12-20 03:32 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-20 03:28 - 2013-12-20 03:28 - 01495040 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00728448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-12-20 03:28 - 2013-12-20 03:28 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00283648 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00219008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-12-20 03:28 - 2013-12-20 03:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll 2013-12-20 03:28 - 2013-12-20 03:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-12-20 03:17 - 2013-12-20 03:16 - 00278104 _____ C:\Windows\msxml4-KB954430-enu.LOG 2013-12-20 03:16 - 2013-12-20 03:16 - 00285846 _____ C:\Windows\msxml4-KB973688-enu.LOG 2013-12-20 03:16 - 2013-12-20 03:16 - 00000000 ____D C:\Program Files\MSXML 4.0 2013-12-19 19:33 - 2013-12-19 19:23 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Games 2013-12-18 20:57 - 2013-12-03 12:48 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype 2013-12-18 17:42 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\LogFiles 2013-12-10 14:15 - 2013-12-10 14:15 - 00000000 ____D C:\Users\User\AppData\Local\Macromedia 2013-12-10 13:55 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF 2013-12-08 12:16 - 2013-12-08 12:16 - 00000000 ____D C:\Users\User\AppData\Roaming\Media Player Classic 2013-12-07 14:59 - 2013-12-07 14:59 - 00000000 ____D C:\Users\User\AppData\Roaming\WinBatch 2013-12-03 12:47 - 2013-12-03 12:47 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-12-03 12:47 - 2010-12-09 09:34 - 00000000 ___RD C:\Program Files\Skype 2013-12-03 12:45 - 2013-12-03 12:46 - 00866720 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-12-03 12:45 - 2013-12-03 12:46 - 00263584 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-12-03 12:45 - 2013-12-03 12:46 - 00174496 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-12-03 12:45 - 2013-12-03 12:46 - 00094112 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-12-03 12:45 - 2010-12-09 09:08 - 00788896 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-12-03 12:45 - 2010-12-09 09:08 - 00000000 ____D C:\Program Files\Java 2013-12-03 12:42 - 2013-12-03 12:42 - 00000000 ____D C:\Program Files\K-Lite Codec Pack 2013-12-03 12:37 - 2013-12-03 12:15 - 00000000 ____D C:\Users\User\AppData\Local\Adobe 2013-12-03 12:36 - 2013-12-03 12:36 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-03 12:36 - 2013-12-03 12:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-03 12:27 - 2013-12-03 12:21 - 00000000 ____D C:\Users\User\AppData\Local\Mozilla 2013-12-03 12:22 - 2013-12-03 12:21 - 00000000 ____D C:\Users\User\AppData\Roaming\Mozilla 2013-12-03 12:20 - 2013-12-03 12:20 - 00001116 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-12-03 12:20 - 2013-12-03 12:20 - 00000000 ____D C:\ProgramData\Mozilla 2013-12-03 12:16 - 2013-12-03 12:16 - 00001996 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-12-03 12:16 - 2013-12-03 12:16 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-12-03 12:16 - 2010-12-09 09:18 - 00000000 ____D C:\ProgramData\Adobe 2013-12-03 12:16 - 2010-12-09 09:18 - 00000000 ____D C:\Program Files\Adobe 2013-12-03 11:51 - 2013-12-03 11:51 - 00000000 ____D C:\Users\User\AppData\Roaming\AVG2014 2013-12-03 11:47 - 2013-12-03 11:47 - 00000000 ____D C:\Users\User\AppData\Roaming\TuneUp Software 2013-12-03 11:40 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\system32\restore 2013-12-03 11:38 - 2013-12-03 11:38 - 00000000 ____D C:\Users\User\AppData\Local\MFAData 2013-12-03 11:32 - 2010-12-09 09:19 - 00000000 ____D C:\ProgramData\McAfee 2013-12-03 11:15 - 2013-12-03 11:15 - 00000000 ____D C:\Users\User\AppData\Roaming\Adobe 2013-12-01 14:42 - 2013-12-22 11:27 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-26 12:25 - 2010-12-09 07:58 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\User\AppData\Local\Temp\install_flashplayer11x32_mssd_aaa_aih.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2010-12-09 07:30 ==================== End Of Log ============================