2013-11-11 20:26:40 CF249ED2936A58C624526923217EBD8B 940 —-a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-11 20:26:40 448F2CB19A5462197ED1CFFCD131855D 3792 —-a-w- C:\Windows\system32\Tasks\Adobe Flash Player Updater
2013-11-11 07:46:55 ——– d—–w- C:\Windows\system32\Tasks\WPD
2013-11-11 07:46:33 73947CACB238544D7E89AA849B0C4732 3718 —-a-w- C:\Windows\system32\Tasks\User_Feed_Synchronization-{54650A72-F786-4C2D-963B-DEA61A3CF1CD}
2013-11-07 08:29:59 8CF9C767452F72E8FAF9B6F7E2634011 3328 —-a-w- C:\Windows\system32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2394964391-1668799144-2153826031-1000
2013-11-07 06:11:40 36A2CFC699E0C75F08BE57ABEE8115B9 3080 —-a-w- C:\Windows\system32\Tasks\{C57CF2B4-B10A-4859-BD79-A5EC162F5763}
2013-11-06 20:43:24 1B2D7BBE0DE084B26C055B40962687A7 3838 —-a-w- C:\Windows\system32\Tasks\avast! Emergency Update
====== C:\Windows\Temp ======
======= C:\Program Files =====
2013-11-12 07:55:37 ——– d—–w- C:\Program Files\trend micro
2013-11-11 07:39:58 ——– d—–w- C:\Program Files\Windows Portable Devices
2013-11-08 06:20:13 ——– d—–w- C:\Program Files\Common Files\Java
2013-11-08 06:19:11 ——– d—–w- C:\Program Files\Java
2013-11-06 21:16:46 ——– d—–w- C:\Program Files\Xvid
2013-11-06 21:16:14 ——– d—–w- C:\Program Files\Haali
2013-11-06 21:16:12 ——– d—–w- C:\Program Files\DSP-worx
2013-11-06 21:16:05 ——– d—–w- C:\Program Files\OpenSource Flash Video Splitter
2013-11-06 21:16:05 ——– d—–w- C:\Program Files\ffdshow
======= C: =====
====== C:\Users\ans\AppData\Roaming ======
2013-11-08 06:15:13 ——– d—–w- C:\Users\ans\AppData\Locallow\Sun
2013-11-06 21:35:19 A9067562D82CECCA77EB2490B2BB9D98 10498 —-a-w- C:\Users\ans\AppData\Locallow\lpm.dat
2013-11-06 21:16:52 ——– d—–w- C:\Users\ans\AppData\Roaming\0D0S1L2Z1P1B
2013-11-06 21:16:34 ——– d—–w- C:\Users\ans\AppData\Roaming\LavFilters
2013-11-06 21:16:34 ——– d—–w- C:\Users\ans\AppData\Roaming\CDXReader
2013-11-06 21:16:14 ——– d—–w- C:\Users\ans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2013-11-06 21:15:37 ——– d—–w- C:\Users\ans\AppData\Roaming\Real
2013-11-06 21:08:12 ——– d—–w- C:\Users\Default\AppData\Local\Microsoft Help
2013-11-06 21:08:12 ——– d—–w- C:\Users\Default User\AppData\Local\Microsoft Help
2013-11-06 20:43:05 7D5B50479D03FB9A2F14E068D8AF9BF8 91 —-a-w- C:\Users\ans\AppData\Roaming\WB.CFG
2013-11-06 20:43:05 4E6B97D11A53A281E346032ACE785757 6 —-a-w- C:\Users\ans\AppData\Roaming\WBPU-TTL.DAT
2013-10-23 06:41:51 ——– d—–w- C:\Users\ans\AppData\Local\HP
====== C:\Users\ans ======
2013-11-13 20:06:17 683FDD3D773C58B262DC07CD0C6CE938 10285040 —-a-w- C:\Users\ans\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-08 06:20:14 ——– d—–w- C:\ProgramData\Sun
2013-11-08 06:19:34 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2013-11-06 21:16:57 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
2013-11-06 21:16:39 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2013-11-06 21:16:13 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
2013-11-06 21:16:10 ——– d—–w- C:\ProgramData\DivX
2013-11-06 21:14:27 ——– d—–w- C:\ProgramData\Real
2013-11-06 20:43:32 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
====== C: exe-files ==
2013-11-13 20:06:17 683FDD3D773C58B262DC07CD0C6CE938 10285040 —-a-w- C:\Users\ans\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-13 07:46:42 E2E9F49C84C49C2DB5ADAF85D8CD8F1C 142848 —-a-w- C:\Windows\System32\ieUnatt.exe
2013-11-13 07:46:40 06085B62BC7E0C8E2605CEA38774D956 757488 —-a-w- C:\Program Files\Internet Explorer\iexplore.exe
2013-11-12 07:55:38 9A2347903D6EDB84C10F288BC0578C1C 388608 —-a-w- C:\Program Files\trend micro\ans.exe
2013-11-12 06:29:27 E8D3E34FFDAF21DF7C09CBBBA5763237 2347384 —-a-w- C:\Users\ans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CMQNBUMZ\esetsmartinstaller_enu.exe
2013-11-11 20:26:38 75984F7E3F7B231552775808C6D3CC6C 692616 —-a-w- C:\Windows\System32\FlashPlayerApp.exe
2013-11-11 20:20:25 EE1948B8957C38A9CBB92CA2B84E7A85 1071584 —-a-w- C:\Users\ans\AppData\Local\Temp\install_flashplayer11x32ax_chra_awa_aih.exe
2013-11-11 07:25:00 D1D523242056B2ADC5424832CCAC384A 304128 —-a-w- C:\Program Files\Internet Explorer\ieuser.exe
2013-11-11 07:10:21 1D7D7E32A80109D5C3167309265EAC83 30208 —-a-w- C:\Windows\System32\WPDShextAutoplay.exe
2013-11-11 06:46:26 825E01EEC25E744FBCFB92F07FF411EE 307200 —-a-w- C:\Program Files\Internet Explorer\iediagcmd.exe
2013-11-11 06:46:26 73C8D00A87332F2DF0A7CFF87CEE1A82 107008 —-a-w- C:\Program Files\Internet Explorer\iecleanup.exe
2013-11-11 06:46:26 736D1B28224F9DF8008BE8B0DEDFC9EF 76800 —-a-w- C:\Windows\System32\SetIEInstalledDate.exe
2013-11-11 06:46:26 6B036492120E65C0C367DC31D01088A1 74752 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-11-11 06:46:25 C0B8B96D018849FD8CCF15FED84E8782 74240 —-a-w- C:\Windows\System32\ie4uinit.exe
2013-11-11 06:46:25 A04CEF82046BCF539B33EEF62F0A3825 466432 —-a-w- C:\Program Files\Internet Explorer\ieinstal.exe
2013-11-11 06:46:25 8911702CC546B76FE8F9C61987C68C43 222720 —-a-w- C:\Program Files\Internet Explorer\ielowutil.exe
2013-11-11 06:46:24 67BC2BA6F94D2D0C51213691FBFEEBB1 152064 —-a-w- C:\Windows\System32\wextract.exe
2013-11-11 06:46:24 51AF0A12CD86E22E1A027C38CC021AC6 150528 —-a-w- C:\Windows\System32\iexpress.exe
2013-11-11 06:46:24 061CBB1058A10C0875D18CAFF835AE97 11776 —-a-w- C:\Windows\System32\mshta.exe
2013-11-11 06:46:23 512C7881C3F7836455ADC9EBF0A0B167 22016 —-a-w- C:\Program Files\Internet Explorer\ExtExport.exe
2013-11-11 06:46:23 1D3EE28BA231CBB9600F5D102EAF4EA7 10752 —-a-w- C:\Windows\System32\msfeedssync.exe
2013-11-11 06:45:32 DFD714F1A410B32DA258423CF592A96E 667648 —-a-w- C:\Windows\System32\printfilterpipelinesvc.exe
2013-11-11 06:45:01 60BBAF3F5A38D0274B0C46710A218051 252928 —-a-w- C:\Windows\System32\dxdiag.exe
2013-11-11 06:27:54 980B6A5F92B8DB235C4A26728C2BE732 196608 —-a-w- C:\Windows\System32\WUDFHost.exe
2013-11-10 09:49:53 A41D107A42B7CFC4FD6C566CC6F37F23 19456 —-a-w- C:\Windows\servicing\GC32\tzupd.exe
2013-11-10 09:49:42 F189F4921D3C24AC96861AA27D329B9B 23040 —-a-w- C:\Windows\System32\dpnsvr.exe
2013-11-10 09:48:25 84BDC77A844493FCD76858B52690F31B 812544 —-a-w- C:\Windows\System32\certutil.exe
2013-11-10 09:48:14 FC1CDF0AC20808719891DD6D965B8F99 299160 —-a-w- C:\Windows\System32\XPSViewer\XPSViewer.exe
2013-11-10 09:47:51 61E5B6E75A5E53D1052A6D18BF67B59A 3603904 —-a-w- C:\Windows\System32\ntkrnlpa.exe
2013-11-10 09:47:49 CB284FC56D12BF5D2503CB75B03FD40A 3551680 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-11-10 09:47:48 BE7480C91E89EB82FC080F772C220AE4 64000 —-a-w- C:\Windows\System32\smss.exe
2013-11-10 09:46:42 A3E186B4B935905B829219502557314E 9728 —-a-w- C:\Windows\System32\lsass.exe
2013-11-09 12:00:15 2E0B0A051FFAA86E358465BB0880D453 53784 —-a-w- C:\Windows\System32\wuauclt.exe
2013-11-09 11:59:52 069385484EA57B663D688894C88975C5 33792 —-a-w- C:\Windows\System32\wuapp.exe
2013-11-08 07:07:17 862BB4CBC05D80C5B45BE430E5EF872F 3408896 —-a-w- C:\Windows\System32\SLsvc.exe
2013-11-08 07:07:15 5AAE542EBB0F3CA7C1E5E6D5457BA2CE 65536 —-a-w- C:\Windows\System32\DevicePairingWizard.exe
2013-11-08 07:07:05 4304D04DFDAAE621171A2F955981016E 2820608 —-a-w- C:\Program Files\Microsoft Games\Chess\Chess.exe
2013-11-08 07:07:04 EBAE6CE901EDB7F0F794589BF5FDF695 619864 —-a-w- C:\Windows\System32\icardagt.exe
2013-11-08 07:07:04 3F903BDD206EB3C688651048B5E304E1 1081856 —-a-w- C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe
2013-11-08 07:07:02 E953D69576A1BF077E709A0231E4714C 289792 —-a-w- C:\Windows\System32\spinstall.exe
2013-11-08 07:07:02 73157FFB9EF9E9C61740A5F9CA5C7B17 112640 —-a-w- C:\Windows\System32\spreview.exe
2013-11-08 07:07:01 C8C383E6AA546780B2AD3034D6F6ACEF 958464 —-a-w- C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe
2013-11-08 07:07:01 7A88900F2F11882FFCE3BF3D4EAEFB4B 687104 —-a-w- C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe
2013-11-08 07:07:01 6ED28075D6D9E0C0464048A30432A142 721408 —-a-w- C:\Program Files\Microsoft Games\Hearts\Hearts.exe
2013-11-08 07:07:01 401A203AB058DEC44BD44AA81BF2CB64 735232 —-a-w- C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
2013-11-08 07:07:01 21AD332BE723EFE40D9F32AD97BA8376 724480 —-a-w- C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe
2013-11-08 07:07:01 07302F014858D038CB93CC349505D0E6 732160 —-a-w- C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
2013-11-08 07:06:59 AED0DFF80C6B3914769407E78D7AB21A 441344 —-a-w- C:\Windows\System32\SearchIndexer.exe
2013-11-08 07:06:53 52BC119E49F88F2A5D1466230B1275C7 403968 —-a-w- C:\Program Files\Windows Collaboration\WinCollab.exe
2013-11-08 07:06:50 520FCEF4D87E37C17BB6D554B2A332E8 463872 —-a-w- C:\Windows\System32\IasMigReader.exe
2013-11-08 07:06:49 BB96D0590B491CDEA2EBF6D697BE8976 1792512 —-a-w- C:\Windows\System32\mmc.exe
2013-11-08 07:06:49 338104E0E18307CD65604FE317B5FB8D 950272 —-a-w- C:\Windows\System32\mblctr.exe
2013-11-08 07:06:49 074DF633D8C15656560F0388AA7F6237 986600 —-a-w- C:\Windows\System32\winload.exe
2013-11-08 07:06:49 074DF633D8C15656560F0388AA7F6237 986600 —-a-w- C:\Windows\System32\Boot\winload.exe
2013-11-08 07:06:48 2CC3DCFB533A1035B13DCAB6160AB38B 2092544 —-a-w- C:\Windows\System32\dfsr.exe
2013-11-08 07:06:47 A547F2E6EE21B65A9EC308F9AD9715C5 310784 —-a-w- C:\Windows\System32\IME\IMEJP10\IMJPDCT.EXE
2013-11-08 07:06:47 7122B0AA2212B07BBFC49BD22215BF3B 304128 —-a-w- C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
2013-11-08 07:06:46 C9EE7FF225EAC1CB9C78C413667CDB80 87552 —-a-w- C:\Windows\System32\SearchFilterHost.exe
2013-11-08 07:06:46 B5EF1DA337DB9859709A387638AC5E07 185344 —-a-w- C:\Windows\System32\SearchProtocolHost.exe
2013-11-08 07:06:44 A59DCD3DB4E966582F6FA83F2977C137 196608 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_426d1460\fsquirt.exe
2013-11-08 07:06:44 A59DCD3DB4E966582F6FA83F2977C137 196608 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_00899617\fsquirt.exe
2013-11-08 07:06:44 192316B389D98D836FFA27F1D939A8AC 9540608 —-a-w- C:\Windows\ehome\CreateDisc\SBEServer.exe
2013-11-08 07:06:43 C6FD3425B1ADD739B95DC4D661FF4DD3 167424 —-a-w- C:\Windows\System32\PresentationSettings.exe
2013-11-08 07:06:43 858F65A141F97D3DC404FD32A6F394AD 3217408 —-a-w- C:\Windows\System32\WinSAT.exe
2013-11-08 07:06:42 E47C854A28A81F2939F42CBE9FEA994C 710144 —-a-w- C:\Windows\System32\Magnify.exe
2013-11-08 07:06:38 A2EE76B0AC8D3D170FA05CB36419EC0D 253952 —-a-w- C:\Windows\ehome\ehvid.exe
2013-11-08 07:06:37 D07D4C3038F3578FFCE1C0237F2A1253 2926592 —-a-w- C:\Windows\explorer.exe
2013-11-08 07:06:37 8C40C45EBA2DBFB487415A66E43906D6 44544 —-a-w- C:\Windows\System32\IME\IMEJP10\IMJPUEX.EXE
2013-11-08 07:06:37 7095D31979FFB0B917987B388779BD01 205824 —-a-w- C:\Windows\System32\eudcedit.exe
2013-11-08 07:06:36 EB851C302B2A75908FE5AF34472A08BC 361472 —-a-w- C:\Windows\System32\IME\IMETC10\IMTCPROP.exe
2013-11-08 07:06:31 85C04F75503F73C21AEC0AEB815065B9 57856 —-a-w- C:\Windows\System32\compcln.exe
2013-11-08 07:06:29 DB3D19F850C6EB32BDCB9BC0836ACDDB 1055232 —-a-w- C:\Windows\System32\VSSVC.exe
2013-11-08 07:06:29 9495FCC01D7AB7B60E5B8BA7AEFE9E3D 247296 —-a-w- C:\Windows\System32\wbem\WmiPrvSE.exe
2013-11-08 07:06:28 E82FE16FD3F4569EF5D5381901D02EC0 361984 —-a-w- C:\Windows\System32\SLUI.exe
2013-11-08 07:06:26 2EEC42B4831B9CECB5AE14D63DAA6704 926184 —-a-w- C:\Windows\System32\winresume.exe
2013-11-08 07:06:26 2EEC42B4831B9CECB5AE14D63DAA6704 926184 —-a-w- C:\Windows\System32\Boot\winresume.exe
2013-11-08 07:06:24 C794EC11280250A3A60DC65CB3CC10D0 173056 —-a-w- C:\Windows\ehome\McrMgr.exe
2013-11-08 07:06:24 2C2DE9CD93DD4F11F8715B7334EB40A7 163840 —-a-w- C:\Windows\System32\wevtutil.exe
2013-11-08 07:06:22 CD88D1B7776DC17A119049742EC07EB4 385536 —-a-w- C:\Windows\System32\vds.exe
2013-11-08 07:06:22 488F6147CBBF38ADFA29710537E02E61 194048 —-a-w- C:\Windows\System32\drvinst.exe
2013-11-08 07:06:22 22F3DFB7C939D601C4F9672035908C41 405992 —-a-w- C:\Windows\Boot\PCAT\memtest.exe
2013-11-08 07:06:19 D4E6D91C1349B7BFB3599A6ADA56851B 279552 —-a-w- C:\Windows\System32\services.exe
2013-11-08 07:06:19 BF899F57858B8C6F162D9EEB2370641C 1143296 —-a-w- C:\Windows\System32\wercon.exe
2013-11-08 07:06:17 DE4E8E68DE8CFBEB1B5C6B6E6022D98C 61952 —-a-w- C:\Windows\System32\reg.exe
2013-11-08 07:06:14 C20436B4F0596ACD5569749206F99265 1850880 —-a-w- C:\Program Files\Windows Journal\Journal.exe
2013-11-08 07:06:14 7EE55302291DD7AA5C2237B0CC7D49E1 35680 —-a-w- C:\Windows\System32\TsWpfWrp.exe
2013-11-08 07:06:13 790222D6CCFC576F0D07D418E6115D85 967680 —-a-w- C:\Program Files\Windows Calendar\WinCal.exe
2013-11-08 07:06:13 574F7EB2D1A291C99324D9EFC2ACC2B9 1315840 —-a-w- C:\Windows\System32\oobe\msoobe.exe
2013-11-08 07:06:12 C9B9E01C077CEA69CD51F4C9FB3510C2 285184 —-a-w- C:\Windows\System32\IME\shared\IMCCPHR.exe
2013-11-08 07:06:12 055C9B5A3E4D2100F5607087B2B006F9 2944512 —-a-w- C:\Program Files\Movie Maker\CaptureWizard.exe
2013-11-08 07:06:11 C559672F31ABE6BA7277DD73C4502238 73216 —-a-w- C:\Windows\System32\msiexec.exe
2013-11-08 07:06:10 38B2955792561C5A1E1E712551BD7ACC 141312 —-a-w- C:\Windows\ehome\mcupdate.exe
2013-11-08 07:06:10 34DA5AE04CA114B23D93CD9D4D05FCB7 636416 —-a-w- C:\Windows\System32\autofmt.exe
2013-11-08 07:06:05 56A1CFFFFC8D646A0388DFBF3EC362CF 244224 —-a-w- C:\Windows\System32\wisptis.exe
2013-11-08 07:06:05 291B27D159AE56A049C1526AF4B3957E 627200 —-a-w- C:\Windows\System32\sethc.exe
2013-11-08 07:06:04 10761177A6EBE45843F443E99509F5E7 643072 —-a-w- C:\Windows\System32\autochk.exe
2013-11-08 07:06:04 01DD1004181FD46ECDC3628228EB269D 81920 —-a-w- C:\Windows\System32\dwm.exe
2013-11-08 07:06:03 15B7BDA10B91FE62466F2A18682C16E8 656896 —-a-w- C:\Windows\System32\autoconv.exe
2013-11-08 07:06:02 63F2534E7E063B4F2054433597D7A1B9 135168 —-a-w- C:\Windows\System32\cscript.exe
2013-11-08 07:06:02 3437B9E218A2E4586BEF4F7A3BD00777 88576 —-a-w- C:\Windows\System32\audiodg.exe
2013-11-08 07:06:01 9E35FF7F943AE0FB89192BFE058B7FD4 1233920 —-a-w- C:\Program Files\Windows Sidebar\sidebar.exe
2013-11-08 07:06:01 877F2939794EBA4F3D1BB967007E99E8 182272 —-a-w- C:\Windows\System32\osk.exe
2013-11-08 07:06:00 DA06BE393317EA5756B218633A537B47 860160 —-a-w- C:\Windows\System32\WerFaultSecure.exe
2013-11-08 07:05:58 7BEDD051B53821B040EAD42DB0724848 217088 —-a-w- C:\Windows\System32\WerFault.exe
2013-11-08 07:05:58 206B492CC40E0E0C01F6EA73F724AB9A 230912 —-a-w- C:\Windows\System32\diskraid.exe
2013-11-08 07:05:58 10FB8976B556A75098868CFFAD6DC576 638976 —-a-w- C:\Windows\System32\Utilman.exe
2013-11-08 07:05:57 96DD35AB1C1420E0CD70EF9ECD32B825 197632 —-a-w- C:\Windows\System32\SndVol.exe
2013-11-08 07:05:56 1259E03DCD5F265B23DB738FB075DF8C 155648 —-a-w- C:\Windows\System32\wscript.exe
2013-11-08 07:05:54 A9F36F9BEC6F23F5B6EDF1EB4D1AA452 119808 —-a-w- C:\Windows\System32\diskpart.exe
2013-11-08 07:05:53 10BE37532F4AD750958AB53A786F74BD 140800 —-a-w- C:\Windows\System32\wusa.exe
2013-11-08 07:05:52 186954438DE3DDBF0B46F895B7936DE3 60928 —-a-w- C:\Windows\System32\findstr.exe
2013-11-08 07:05:51 F8D8BB3F6173FFF00128612F33D3197A 117248 —-a-w- C:\Windows\System32\wbem\WMIADAP.exe
2013-11-08 07:05:50 C667C3CC62B3E0FBC2011265EFABED0C 783872 —-a-w- C:\Program Files\Common Files\microsoft shared\ink\InkWatson.exe
2013-11-08 07:05:50 949B048F7D17E0BDAFCDA613458DE06A 941056 —-a-w- C:\Program Files\Common Files\microsoft shared\ink\ShapeCollector.exe
2013-11-08 07:05:47 DD251E13AAAA5F5AF09934759A4E1FC5 74752 —-a-w- C:\Windows\System32\newdev.exe
2013-11-08 07:05:47 DC289E2856F08B26A474BC8826B1B5BA 105472 —-a-w- C:\Windows\System32\IME\IMEJP10\imjpuexc.exe
2013-11-08 07:05:47 395335431AD55C167CFDBBAB8420DA73 1963008 —-a-w- C:\Program Files\Movie Maker\DVDMaker.exe
2013-11-08 07:05:44 D3D1CE8FF30786D50272DA3085149904 408064 —-a-w- C:\Windows\System32\msinfo32.exe
2013-11-08 07:05:44 D3D1CE8FF30786D50272DA3085149904 408064 —-a-w- C:\Program Files\Common Files\microsoft shared\MSInfo\msinfo32.exe
2013-11-08 07:05:43 79DB32BA1FED01EC05A5D5158CF1A279 43520 —-a-w- C:\Windows\System32\rekeywiz.exe
2013-11-08 07:05:42 493083D1BF3D62A2C2C6BE1D2194289E 26112 —-a-w- C:\Windows\System32\DeviceEject.exe
2013-11-08 07:05:42 29B84718CDCBCA66A47B64AA2B02318F 407040 —-a-w- C:\Windows\System32\dpapimig.exe
2013-11-08 07:05:41 56C182F55BF68556C974E9AD32BF56BF 215552 —-a-w- C:\Windows\System32\certreq.exe
2013-11-08 07:05:41 1BAF5FE4C31D20CF805B2FA7A7C2B886 80384 —-a-w- C:\Windows\System32\hdwwiz.exe
2013-11-08 07:05:40 DE4DAA15B2405AB4D5B2476F1B7C8F1E 58368 —-a-w- C:\Windows\System32\PnPUnattend.exe
2013-11-08 07:05:40 86497C6A9825B6252804D5C4E189AA67 49152 —-a-w- C:\Windows\System32\cmmon32.exe
2013-11-08 07:05:40 1904DBA08C2D63CE2025CAD78F5DF2BB 38400 —-a-w- C:\Windows\System32\TSTheme.exe
2013-11-08 07:05:39 D3D0B9D1491F62B489DA0CE2CF091129 252416 —-a-w- C:\Windows\System32\IME\shared\IMEPADSV.EXE
2013-11-08 07:05:39 63AB8E496AF20989A875CEACEA0CB7A2 131072 —-a-w- C:\Windows\ehome\ehexthost.exe
2013-11-08 07:05:39 6080A176D09435FC8E6E800996656E18 69120 —-a-w- C:\Windows\System32\conime.exe
2013-11-08 07:05:38 F13604BABB4C2AF86E0D2858A2EEC4CF 87552 —-a-w- C:\Windows\System32\IME\IMESC5\IMSCPROP.exe
2013-11-08 07:05:38 E80DB295132C5EF0C623935422BD0FC7 275968 —-a-w- C:\Windows\System32\SnippingTool.exe
2013-11-08 07:05:38 13E4FB6985AC5744609E4289319BF220 33280 —-a-w- C:\Windows\System32\PnPutil.exe
2013-11-08 07:05:35 44308D95668E4A98EE4B4560F2E8E2CD 82944 —-a-w- C:\Windows\ehome\Mcx2Prov.exe
2013-11-08 07:05:33 F01C34454A2DBA34439C2FB2B6CDDB9A 128000 —-a-w- C:\Windows\System32\gpresult.exe
2013-11-08 07:05:33 9E447B628CBF81F006218E7B6127B7E2 58368 —-a-w- C:\Windows\System32\cipher.exe
2013-11-08 07:05:32 43BE3875207DCB62A85C8C49970B66CC 137728 —-a-w- C:\Windows\System32\wbem\WmiApSrv.exe
2013-11-08 07:05:31 319A08B6652EB7F2CDA681DF4F1DA7C6 24064 —-a-w- C:\Windows\System32\IME\IMEJP10\imjppdmg.exe
2013-11-08 07:05:30 C839042193F589E667FAF1D4474DD468 60416 —-a-w- C:\Windows\System32\IME\IMEJP10\IMJPMGR.EXE
2013-11-08 07:05:30 967D0C026913D6A628C4BE8F4EFF2AC6 185856 —-a-w- C:\Windows\System32\SLLUA.exe
2013-11-08 07:05:30 3105CFE0ADAAED21148597001478E89F 19968 —-a-w- C:\Windows\System32\fc.exe
2013-11-08 07:05:29 9F43A02154881DCB6AF350D0C361F339 59392 —-a-w- C:\Windows\System32\IME\IMEJP10\IMJPDSVR.EXE
2013-11-08 07:05:29 8274C87726D4561EE8750D883764ACC1 37888 —-a-w- C:\Windows\System32\wbem\unsecapp.exe
2013-11-08 07:05:28 7F79769473C0DDEDC7CC3D9D0139DA44 58368 —-a-w- C:\Program Files\Movie Maker\VideoCameraAutoPlayManager.exe
2013-11-08 07:05:28 1E2940E465AA5B2C4840E8D220BF1F32 41984 —-a-w- C:\Windows\System32\ftp.exe
2013-11-08 07:05:27 CE89D942BECC4E4350FC76D4A0443997 16896 —-a-w- C:\Windows\System32\rasdial.exe
2013-11-08 07:05:27 A5CBBED853E6183D4E067B42B73A20DA 26624 —-a-w- C:\Windows\System32\ipconfig.exe
2013-11-08 07:05:27 7F5936A3FF5E83272EA1DC8985B2A228 34304 —-a-w- C:\Windows\System32\bthudtask.exe
2013-11-08 07:05:26 BCAA8437FC3CC898C76BA120F88CFBCD 82944 —-a-w- C:\Windows\System32\nslookup.exe
2013-11-08 07:05:26 BC89C1733F25EEADD9C765D2C9C0E8B8 35840 —-a-w- C:\Windows\System32\ocsetup.exe
2013-11-08 07:05:25 97D9D6A04E3AD9B6C626B9931DB78DBA 39424 —-a-w- C:\Windows\servicing\TrustedInstaller.exe
2013-11-08 07:05:24 BADB6B77C2C9F729528543D79418429F 16896 —-a-w- C:\Windows\System32\gpupdate.exe
2013-11-08 07:05:23 701E62EE60DAFD5B6951B6999CB01F95 44032 —-a-w- C:\Windows\System32\cbsra.exe
2013-11-08 07:05:23 5A736A107416E9B55D5B5F77B06921B4 46080 —-a-w- C:\Windows\System32\csrstub.exe
2013-11-08 07:04:33 6C235B6FF358E8CA7D6CD2954C1F933E 130560 —-a-w- C:\Windows\System32\PkgMgr.exe
2013-11-08 06:20:04 9223A2810B73069F4A03A636052EF14A 264616 —-a-w- C:\Windows\System32\javaws.exe
2013-11-08 06:19:34 DC1342498BEE7EF1646E9D63138B69CC 175016 —-a-w- C:\Windows\System32\javaw.exe
2013-11-08 06:19:34 658633D255FEF154EA1CB8705B4468C5 174504 —-a-w- C:\Windows\System32\java.exe
2013-11-08 06:19:20 CC27986F45EF9FD700BC347355B002B3 15784 —-a-w- C:\Program Files\Java\jre7\bin\rmid.exe
2013-11-08 06:19:20 738AF811C60870FB218D47C628D350AA 15784 —-a-w- C:\Program Files\Java\jre7\bin\rmiregistry.exe
2013-11-08 06:19:20 707BFE32E04720B9D50562669A30F86C 49064 —-a-w- C:\Program Files\Java\jre7\bin\ssvagent.exe
2013-11-08 06:19:20 5FA3FFE74E893E8A9443C2CF3DFA7A64 15784 —-a-w- C:\Program Files\Java\jre7\bin\pack200.exe
2013-11-08 06:19:20 555651269833A415E1F9E594E8DD829F 146344 —-a-w- C:\Program Files\Java\jre7\bin\unpack200.exe
2013-11-08 06:19:20 54A30377949D4984EE72C5510C58B83D 16296 —-a-w- C:\Program Files\Java\jre7\bin\tnameserv.exe
2013-11-08 06:19:20 464358DE0429ABB319DFE3F5E5C85F77 15784 —-a-w- C:\Program Files\Java\jre7\bin\orbd.exe
2013-11-08 06:19:20 3FB1EAAB3CD35126D1F3B9A0A5B7B2DC 15784 —-a-w- C:\Program Files\Java\jre7\bin\policytool.exe
2013-11-08 06:19:20 15EBB4D4B54FCE42D8CB116145BB7EBA 15784 —-a-w- C:\Program Files\Java\jre7\bin\servertool.exe
2013-11-08 06:19:19 CE10E75E10EB6952A7D813FA587EC632 15784 —-a-w- C:\Program Files\Java\jre7\bin\ktab.exe
2013-11-08 06:19:19 CBFE91C51D4FA69FE9D140ABEB7E51DC 15784 —-a-w- C:\Program Files\Java\jre7\bin\kinit.exe
2013-11-08 06:19:19 7814B0A3E6FE8FFF31B7108D16FC4591 15784 —-a-w- C:\Program Files\Java\jre7\bin\keytool.exe
2013-11-08 06:19:19 5721DA732075E01569A287767CBCFA5A 15784 —-a-w- C:\Program Files\Java\jre7\bin\klist.exe
2013-11-08 06:19:18 80A79264302910C7C24BA7E44267EFEF 182696 —-a-w- C:\Program Files\Java\jre7\bin\jqs.exe
2013-11-08 06:19:18 7F55715977ECF32633857F16980F008E 52648 —-a-w- C:\Program Files\Java\jre7\bin\jp2launcher.exe
2013-11-08 06:19:17 DC1342498BEE7EF1646E9D63138B69CC 175016 —-a-w- C:\Program Files\Java\jre7\bin\javaw.exe
2013-11-08 06:19:17 A9743D2D69B80800FEA5F24E7C4B02B3 48040 —-a-w- C:\Program Files\Java\jre7\bin\jabswitch.exe
2013-11-08 06:19:17 9223A2810B73069F4A03A636052EF14A 264616 —-a-w- C:\Program Files\Java\jre7\bin\javaws.exe
2013-11-08 06:19:17 83D790AA563347A026771D50E3D07A9B 66984 —-a-w- C:\Program Files\Java\jre7\bin\javacpl.exe
2013-11-08 06:19:17 658633D255FEF154EA1CB8705B4468C5 174504 —-a-w- C:\Program Files\Java\jre7\bin\java.exe
2013-11-08 06:19:17 2F7EBCD8FB6557997F0583508FFFE6B1 15784 —-a-w- C:\Program Files\Java\jre7\bin\java-rmi.exe
2013-11-07 06:32:36 302964DCAC79D618CC7B72C778DA9FD2 295264 —-a-w- C:\Windows\System32\PresentationHost.exe
=== C: other files ==
2013-11-13 20:06:54 4470E3C1E0C3378E4CAB137893C12C3A 22856 —-a-w- C:\Windows\System32\drivers\mbam.sys
2013-11-11 07:10:14 DE9D36F91A4DF3D911626643DEBF11EA 40448 —-a-w- C:\Windows\System32\DriverStore\FileRepository\wpdmtp.inf_2a7adb02\WpdUsb.sys
2013-11-11 07:10:14 DE9D36F91A4DF3D911626643DEBF11EA 40448 —-a-w- C:\Windows\System32\drivers\WpdUsb.sys
2013-11-11 07:10:14 C034851122F667F26F813ED1E541C191 50688 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bthmtpenum.inf_201caa7f\BthMtpEnum.sys
2013-11-11 07:00:36 B972A66758577E0BFD1DE0F91AAA27B5 12800 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-11-11 06:27:59 867C301E8B790040AE9CF6486E8041DF 155136 —-a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-11-11 06:27:59 06E6F32C8D0A3F66D956F57B43A2E070 66560 —-a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-11-11 06:27:57 48704647CD2E9DAA2EB81BDE6D029EDB 47720 —-a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-11-11 06:27:55 30FC6E5448D0CBAAA95280EEEF7FEDAE 34944 —-a-w- C:\Windows\System32\DriverStore\FileRepository\winusb.inf_abb27f1e\winusb.sys
2013-11-11 06:27:55 30FC6E5448D0CBAAA95280EEEF7FEDAE 34944 —-a-w- C:\Windows\System32\DriverStore\FileRepository\winusb.inf_80bcffa4\winusb.sys
2013-11-11 06:27:55 30FC6E5448D0CBAAA95280EEEF7FEDAE 34944 —-a-w- C:\Windows\System32\DriverStore\FileRepository\winusb.inf_37e181dd\winusb.sys
2013-11-10 09:51:00 988670D8343EF9835FB3659DB71B2EFA 638400 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-11-10 09:50:57 F4EAA7ECBCB25DE901C9B7F2CDCDA0B3 24064 —-a-w- C:\Windows\System32\drivers\tssecsrv.sys
2013-11-10 09:50:43 D330803EAB2A15CAEC7F011F1D4CB30E 30208 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_426d1460\BTHUSB.SYS
2013-11-10 09:50:43 611FF3F2F095C8D4A6D4CFD9DCC09793 508416 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_426d1460\bthport.sys
2013-11-10 09:50:28 69A702C66FA35445DCF7DBF9EF32812C 2050048 —-a-w- C:\Windows\System32\win32k.sys
2013-11-10 09:49:56 D18D53974FD715D50FC76F9FFE1C830D 905664 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2013-11-10 09:49:41 B9C2B89F08670E159F7181891E449CD9 53120 —-a-w- C:\Windows\System32\drivers\partmgr.sys
2013-11-10 09:49:39 786DB5771F05EF300390399F626BF30A 224640 —-a-w- C:\Windows\System32\DriverStore\FileRepository\volume.inf_2abeaeba\volsnap.sys
2013-11-10 09:49:39 786DB5771F05EF300390399F626BF30A 224640 —-a-w- C:\Windows\System32\drivers\volsnap.sys
2013-11-10 09:49:38 8E6C378A885D6FFDA8F05E8D27B95C0E 27648 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mdmcpq.inf_fad2d0b6\usbser.sys
2013-11-10 09:48:47 2C1121F2B87E9A6B12485DF53CD848C7 1082232 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2013-11-10 09:48:46 AAB0B5F72D2D726FBFDC895A2902DE1D 73216 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usb.inf_4d475c8b\usbccgp.sys
2013-11-10 09:48:46 AAB0B5F72D2D726FBFDC895A2902DE1D 73216 —-a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-11-10 09:48:46 2AE6BCEBD85D31317E433733DAF25888 197632 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2aa7a50a\usbhub.sys
2013-11-10 09:48:46 2AE6BCEBD85D31317E433733DAF25888 197632 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usb.inf_4d475c8b\usbhub.sys
2013-11-10 09:48:46 2AE6BCEBD85D31317E433733DAF25888 197632 —-a-w- C:\Windows\System32\drivers\usbhub.sys
2013-11-10 09:48:45 FE619ED13CE12F5B43C04E3EA061BBD6 6016 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2aa7a50a\usbd.sys
2013-11-10 09:48:45 FE619ED13CE12F5B43C04E3EA061BBD6 6016 —-a-w- C:\Windows\System32\drivers\usbd.sys
2013-11-10 09:48:45 D457EBD0C3A8B3A3A144355B5EE91CBC 19456 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2aa7a50a\usbohci.sys
2013-11-10 09:48:45 B09C74A41F26B08149707EA5E7F956C2 226304 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2aa7a50a\usbport.sys
2013-11-10 09:48:45 B09C74A41F26B08149707EA5E7F956C2 226304 —-a-w- C:\Windows\System32\drivers\usbport.sys
2013-11-10 09:48:45 44056325428A8E4C755830426E29878F 23552 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2aa7a50a\usbuhci.sys
2013-11-10 09:48:45 44056325428A8E4C755830426E29878F 23552 —-a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-11-10 09:48:45 153E8515CB86F8BB5D1A8B478EBF4BB2 39936 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2aa7a50a\usbehci.sys
2013-11-10 09:48:45 153E8515CB86F8BB5D1A8B478EBF4BB2 39936 —-a-w- C:\Windows\System32\drivers\usbehci.sys
2013-11-10 09:48:42 73FF24E21B690625A58109637DDA0DF7 134272 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbvideo.inf_052c97ea\usbvideo.sys
2013-11-10 09:48:42 73FF24E21B690625A58109637DDA0DF7 134272 —-a-w- C:\Windows\System32\drivers\usbvideo.sys
2013-11-10 09:48:42 49A623C16E482F4D31AD0EBD801DD8EC 68608 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbcir.inf_933ee10a\usbcir.sys
2013-11-10 09:48:42 1114579556DB85E9FAF9590DBC64CD62 73344 —-a-w- C:\Windows\System32\DriverStore\FileRepository\wdma_usb.inf_e74ab35a\USBAUDIO.sys
2013-11-10 09:48:12 25944D2CC49E0A6C581D02A74B7D6645 527064 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-11-10 09:47:24 C127EBD5AFAB31524662C48DFCEB773A 180736 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-11-10 09:47:13 BE4AD4045D7A6C6AF4ECCBD5F6B7F8D8 25472 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_c7f006cc\hidparse.sys
2013-11-10 09:47:13 BE4AD4045D7A6C6AF4ECCBD5F6B7F8D8 25472 —-a-w- C:\Windows\System32\drivers\hidparse.sys
2013-11-10 09:47:13 1D714B8497CD68307806D5D3F60A5169 35328 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sti.inf_45d79eaa\usbscan.sys
2013-11-10 09:47:13 1D714B8497CD68307806D5D3F60A5169 35328 —-a-w- C:\Windows\System32\drivers\usbscan.sys
2013-11-10 09:46:43 4A1445EFA932A3BAF5BDB02D7131EE20 440704 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2013-11-10 09:38:02 8D31A140B55021BBD3A608F5A7AA2E18 15872 —-a-w- C:\Windows\System32\drivers\usb8023.sys
2013-11-10 09:38:01 228F444F9AF0D3B9ECA9FC3F4FEB12F2 15872 —-a-w- C:\Windows\System32\DriverStore\FileRepository\netrndis.inf_f705a06e\usb8023x.sys
2013-11-10 09:38:01 228F444F9AF0D3B9ECA9FC3F4FEB12F2 15872 —-a-w- C:\Windows\System32\drivers\usb8023x.sys
2013-11-08 07:07:11 A7F8BAD9590ADDC425B4003E94780DFA 684032 —-a-w- C:\Windows\System32\drivers\spsys.sys
2013-11-08 07:07:08 062452B7FFD68C8C042A6261FE8DFF4A 561152 —-a-w- C:\Windows\System32\DriverStore\FileRepository\hdaudbus.inf_9689af2f\hdaudbus.sys
2013-11-08 07:07:08 062452B7FFD68C8C042A6261FE8DFF4A 561152 —-a-w- C:\Windows\System32\drivers\hdaudbus.sys
2013-11-08 07:07:06 5A3ABAA2F8EECE7AEFB942773766E3DB 507904 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_00899617\bthport.sys
2013-11-08 07:06:55 6482707F9F4DA0ECBAB43B2E0398A101 148992 —-a-w- C:\Windows\System32\DriverStore\FileRepository\tdibth.inf_16daba33\rfcomm.sys
2013-11-08 07:06:53 7EBEC5EB56B90ED65A8BBD91464E5CFB 69096 —-a-w- C:\Windows\System32\DriverStore\FileRepository\hpcisss.inf_3d49a363\HpCISSs.sys
2013-11-08 07:06:31 B14C9D5B9ADD2F84F70570BBBFAA7935 225280 —-a-w- C:\Windows\System32\drivers\rdbss.sys
2013-11-08 07:06:30 37CA203F8CCF732CD272A27E55B268C4 82408 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sbp2.inf_dd2a3429\sbp2port.sys
2013-11-08 07:06:29 82CEA0395524AACFEB58BA1448E8325C 114688 —-a-w- C:\Windows\System32\drivers\mrxdav.sys
2013-11-08 07:06:29 5DA347912FD3AF24D7BFB3DE519D4BD0 107496 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mpio.inf_f6a6d96f\mpio.sys
2013-11-08 07:06:29 063EE4D3CB88A14EAB9901875CEE98B1 223208 —-a-w- C:\Windows\System32\drivers\netio.sys
2013-11-08 07:06:27 BE3DA31C191BC222D9AD503C5224F2AD 65536 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbstor.inf_72a6a3e5\USBSTOR.SYS
2013-11-08 07:06:27 BE3DA31C191BC222D9AD503C5224F2AD 65536 —-a-w- C:\Windows\System32\drivers\USBSTOR.SYS
2013-11-08 07:06:25 4673BBCB006AF60E7ABDDBE7A130BA42 196096 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2c537348\usbhub.sys
2013-11-08 07:06:25 4673BBCB006AF60E7ABDDBE7A130BA42 196096 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usb.inf_e9aaaa78\usbhub.sys
2013-11-08 07:06:18 232FA340531D940AAC623B121A595034 180712 —-a-w- C:\Windows\System32\DriverStore\FileRepository\iscsi.inf_7cf731e4\msiscsi.sys
2013-11-08 07:06:18 232FA340531D940AAC623B121A595034 180712 —-a-w- C:\Windows\System32\drivers\msiscsi.sys
2013-11-08 07:06:16 A1C100A87D981AD0774FBC0B4B82E913 226304 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2c537348\usbport.sys
2013-11-08 07:06:15 1357274D1883F68300AEADD15D7BBB42 527848 —-a-w- C:\Windows\System32\drivers\ndis.sys
2013-11-08 07:06:14 2C563AEF15B8D0014C36C5F27742AC7B 93160 —-a-w- C:\Windows\System32\DriverStore\FileRepository\msdsm.inf_2952f7e7\msdsm.sys
2013-11-08 07:06:12 5457DCFA7C0DA43522F4D9D4049C1472 27112 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\msahci.sys
2013-11-08 07:06:11 941DC1D19E7E8620F40BBC206981EFDB 149480 —-a-w- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\pci.sys
2013-11-08 07:06:11 941DC1D19E7E8620F40BBC206981EFDB 149480 —-a-w- C:\Windows\System32\drivers\pci.sys
2013-11-08 07:06:11 0767B09C74D935A590B4879D14463B64 125928 —-a-w- C:\Windows\System32\drivers\Classpnp.sys
2013-11-08 07:06:10 3CAD38910468EAB9A6479E2F01DB43C7 53224 —-a-w- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\termdd.sys
2013-11-08 07:06:10 3CAD38910468EAB9A6479E2F01DB43C7 53224 —-a-w- C:\Windows\System32\drivers\termdd.sys
2013-11-08 07:06:09 D7659D3B5B92C31E84E53C1431F35132 245736 —-a-w- C:\Windows\System32\clfs.sys
2013-11-08 07:06:09 BCDBB5CEA1E8AEA0FA353691EB003728 92918 —-a-w- C:\Windows\System32\slmgr.vbs
2013-11-08 07:06:09 82B296AE1892FE3DBEE00C9CF92F8AC7 265688 —-a-w- C:\Windows\System32\DriverStore\FileRepository\acpi.inf_62085e44\acpi.sys
2013-11-08 07:06:09 82B296AE1892FE3DBEE00C9CF92F8AC7 265688 —-a-w- C:\Windows\System32\drivers\acpi.sys
2013-11-08 07:06:09 64B0052340B8EC28FA8A56B708AE71CC 109032 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\ataport.sys
2013-11-08 07:06:09 64B0052340B8EC28FA8A56B708AE71CC 109032 —-a-w- C:\Windows\System32\drivers\ataport.sys
2013-11-08 07:06:09 47E55AFE1ED1D5AFF09690DB226F4A7A 122344 —-a-w- C:\Windows\System32\drivers\Storport.sys
2013-11-08 07:06:09 36975327EF03949CC378AB01E316B574 35304 —-a-w- C:\Windows\System32\drivers\crashdmp.sys
2013-11-08 07:06:06 6A57B5733D4CB702C8EA4542E836B96C 48104 —-a-w- C:\Windows\System32\drivers\mup.sys
2013-11-08 07:06:05 5D4AEFC3386920236A548271F8F1AF6A 53736 —-a-w- C:\Windows\System32\DriverStore\FileRepository\disk.inf_5c850fad\disk.sys
2013-11-08 07:06:05 5D4AEFC3386920236A548271F8F1AF6A 53736 —-a-w- C:\Windows\System32\drivers\disk.sys
2013-11-08 07:06:04 73594DBC99E22958150192EE99BC48CE 99816 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-11-08 07:06:04 6429D10C5D149AC9EB2D95052A390CFF 43496 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\pciidex.sys
2013-11-08 07:06:04 23E41B834759917BFD6B9A0D625D0C28 292840 —-a-w- C:\Windows\System32\drivers\volmgrx.sys
2013-11-08 07:06:04 147281C01FCB1DF9252DE2A10D5E7093 226280 —-a-w- C:\Windows\System32\DriverStore\FileRepository\volume.inf_1e6030e4\volsnap.sys
2013-11-08 07:06:04 01334F9EA68E6877C4EF05D3EA8ABB05 190424 —-a-w- C:\Windows\System32\drivers\fltMgr.sys
2013-11-08 07:06:03 B49456D70555DE905C311BCDA6EC6ADB 161752 —-a-w- C:\Windows\System32\drivers\msrpc.sys
2013-11-08 07:06:03 7F64EA048DCFAC7ACF8B4D7B4E6FE371 141288 —-a-w- C:\Windows\System32\drivers\ecache.sys
2013-11-08 07:06:03 3BB2244F343B610C29C98035504C9B75 177640 —-a-w- C:\Windows\System32\DriverStore\FileRepository\pcmcia.inf_5be8d19f\pcmcia.sys
2013-11-08 07:06:03 1636D43F10416AEB483BC6001097B26C 14312 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\pciide.sys
2013-11-08 07:06:02 C67EBF9C05531C406E1E079FF669A2E6 27624 —-a-w- C:\Windows\System32\drivers\Dumpata.sys
2013-11-08 07:06:01 1F05B78AB91C9075565A9D8A4B880BC4 19944 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
2013-11-08 07:06:01 1F05B78AB91C9075565A9D8A4B880BC4 19944 —-a-w- C:\Windows\System32\drivers\atapi.sys
2013-11-08 07:06:00 ECD64230A59CBD93C85F1CD1CAB9F3F6 185856 —-a-w- C:\Windows\System32\drivers\netbt.sys
2013-11-08 07:05:59 6D39C954799B63BA866910234CF7D726 22528 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_426d1460\bthenum.sys
2013-11-08 07:05:59 6D39C954799B63BA866910234CF7D726 22528 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_00899617\bthenum.sys
2013-11-08 07:05:51 79E96C23A97CE7B8F14D310DA2DB0C9B 39936 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2c537348\usbehci.sys
2013-11-08 07:05:50 FCB3F4BE408F72C1BD81BCABA87FC22F 30720 —-a-w- C:\Windows\System32\DriverStore\FileRepository\hidbth.inf_e1bc61a9\hidbth.sys
2013-11-08 07:05:49 4B9C0F4D4A3ACC535F9771039ECD6365 64512 —-a-w- C:\Windows\System32\DriverStore\FileRepository\ipmidrv.inf_a46ca46a\IPMIDrv.sys
2013-11-08 07:05:49 3F90E001369A07243763BD5A523D8722 236544 —-a-w- C:\Windows\System32\DriverStore\FileRepository\hdaudio.inf_6740f89c\HdAudio.sys
2013-11-08 07:05:48 EF73C1E29FBE7B0FD0274BF4394E346A 149504 —-a-w- C:\Windows\System32\drivers\ks.sys
2013-11-08 07:05:46 EDE59EC70E25C24581ADD1FBEC7325F7 17408 —-a-w- C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_f55d5e51\kbdhid.sys
2013-11-08 07:05:46 8F36B54688C31EED4580129040C6A3D3 89088 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sdbus.inf_cbadf2d2\sdbus.sys
2013-11-08 07:05:44 94E2941280E3756A5E0BCB467865C43A 29696 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bth.inf_00899617\BTHUSB.SYS
2013-11-08 07:05:44 943B18305EAE3935598A9B4A3D560B4C 248320 —-a-w- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\rdpdr.sys
2013-11-08 07:05:43 22B408651F9123527BCEE54B4F6C5CAE 136704 —-a-w- C:\Windows\System32\drivers\exfat.sys
2013-11-08 07:05:41 32DB9517628FF0D070682AAB61E688F0 73216 —-a-w- C:\Windows\System32\DriverStore\FileRepository\wdma_usb.inf_dc7189cc\USBAUDIO.sys
2013-11-08 07:05:40 218286724EC530FF252648369E05B090 167936 —-a-w- C:\Windows\System32\DriverStore\FileRepository\wdmaudio.inf_84db3286\portcls.sys
2013-11-08 07:05:40 218286724EC530FF252648369E05B090 167936 —-a-w- C:\Windows\System32\drivers\portcls.sys
2013-11-08 07:05:39 EAE017D3AA298374A1967B96C379C5AB 25856 —-a-w- C:\Windows\System32\drivers\USBCAMD2.sys
2013-11-08 07:05:39 D06F193F3E9CC3B356DF97F6A43C054A 25856 —-a-w- C:\Windows\System32\drivers\USBCAMD.sys
2013-11-08 07:05:38 D36F239D7CCE1931598E8FB90A0DBC26 35328 —-a-w- C:\Windows\System32\drivers\npfs.sys
2013-11-08 07:05:37 9A966A8E86D1771911AE34A20D11BFF3 41472 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mdmbtmdm.inf_ab57df1e\bthmodem.sys
2013-11-08 07:05:37 99514FAA8DF93D34B5589187DB3AA0BA 72192 —-a-w- C:\Windows\System32\drivers\pacer.sys
2013-11-08 07:05:37 76B06EB8A01FC8624D699E7045303E54 72192 —-a-w- C:\Windows\System32\drivers\tdx.sys
2013-11-08 07:05:35 1E9B9A70D332103C52995E957DC09EF8 142848 —-a-w- C:\Windows\System32\drivers\fastfat.sys
2013-11-08 07:05:34 EEC7EE5675294B03E88AA868540007C1 113664 —-a-w- C:\Windows\System32\drivers\rmcast.sys
2013-11-08 07:05:34 6F310E890D46E246E0E261A63D9B36B4 62208 —-a-w- C:\Windows\System32\DriverStore\FileRepository\1394.inf_5e025c7c\ohci1394.sys
2013-11-08 07:05:32 D575246188F63DE0ACCF6EAC5FB59E6A 27648 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mdmcpq.inf_a4839249\usbser.sys
2013-11-08 07:05:32 CCA4B519B17E23A00B826C55716809CC 12800 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_c7f006cc\hidusb.sys
2013-11-08 07:05:32 CCA4B519B17E23A00B826C55716809CC 12800 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_45f308e6\hidusb.sys
2013-11-08 07:05:32 CCA4B519B17E23A00B826C55716809CC 12800 —-a-w- C:\Windows\System32\drivers\hidusb.sys
2013-11-08 07:05:32 7B75299A4D201D6A6533603D6914AB04 66560 —-a-w- C:\Windows\System32\drivers\smb.sys
2013-11-08 07:05:32 4A5C31E2C1646034E6A60EBA4C747FF6 33280 —-a-w- C:\Windows\System32\drivers\watchdog.sys
2013-11-08 07:05:31 D9728AF68C4C7693CB100B8441CBDEC6 226816 —-a-w- C:\Windows\System32\drivers\udfs.sys
2013-11-08 07:05:29 818F648618AE34F729FDB47EC68345C3 121344 —-a-w- C:\Windows\System32\drivers\ndiswan.sys
2013-11-08 07:05:27 2005F4A1E05FA09389AC85840F0A9E4D 69120 —-a-w- C:\Windows\System32\drivers\rassstp.sys
2013-11-08 07:05:26 5961CADB7CAD938368D2028725EF771D 39424 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_c7f006cc\hidclass.sys
2013-11-08 07:05:26 5961CADB7CAD938368D2028725EF771D 39424 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_45f308e6\hidclass.sys
2013-11-08 07:05:26 5961CADB7CAD938368D2028725EF771D 39424 —-a-w- C:\Windows\System32\drivers\hidclass.sys
2013-11-08 07:05:25 D72BAF07A11DE1DD32855BB897518D53 29696 —-a-w- C:\Windows\System32\DriverStore\FileRepository\bthprint.inf_fa0c9014\BTHPRINT.SYS
2013-11-08 07:05:24 85C44FDFF9CF7E72A40DCB7EC06A4416 148480 —-a-w- C:\Windows\System32\drivers\nwifi.sys
2013-11-08 07:05:24 6B4BFFB9BECD728097024276430DB314 67072 —-a-w- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_c949a5b6\cdrom.sys
2013-11-08 07:05:24 6B4BFFB9BECD728097024276430DB314 67072 —-a-w- C:\Windows\System32\drivers\cdrom.sys
2013-11-08 07:05:22 676F4B665BDD8053EAA53AC1695B8074 31616 —-a-w- C:\Windows\System32\DriverStore\FileRepository\winusb.inf_c07c5ec4\winusb.sys
2013-11-08 07:05:22 676F4B665BDD8053EAA53AC1695B8074 31616 —-a-w- C:\Windows\System32\DriverStore\FileRepository\wceusbsh.inf_2fb04100\winusb.sys
2013-11-08 07:05:22 676F4B665BDD8053EAA53AC1695B8074 31616 —-a-w- C:\Windows\System32\DriverStore\FileRepository\transfercable.inf_9c53df5f\x86\winusb.sys
2013-11-08 07:05:21 C8D5369BFE193B5FB53337DCE77CE314 76288 —-a-w- C:\Windows\System32\drivers\dxg.sys
2013-11-08 07:05:21 494075282E23D838F43A4C9FB7143959 19456 —-a-w- C:\Windows\System32\drivers\Diskdump.sys
2013-11-08 07:05:19 32C068EAF37C92D7194EEE1FAA1E7853 30208 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbccid.inf_54511730\usbccid.sys
2013-11-08 07:05:18 E098C8F476C41E94C7665658EF8C61A5 33280 —-a-w- C:\Windows\System32\DriverStore\FileRepository\netrndis.inf_f705a06e\rndismpx.sys
2013-11-08 07:05:18 E098C8F476C41E94C7665658EF8C61A5 33280 —-a-w- C:\Windows\System32\DriverStore\FileRepository\netrndis.inf_e5fc9df6\rndismpx.sys
2013-11-08 07:05:18 E098C8F476C41E94C7665658EF8C61A5 33280 —-a-w- C:\Windows\System32\drivers\rndismpx.sys
2013-11-08 07:05:18 D9225D107E40D0FA5C5069446759C8E9 33280 —-a-w- C:\Windows\System32\drivers\RNDISMP.sys
2013-11-08 07:05:18 CE697FEE0D479290D89BEC80DFE793B7 19456 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_2c537348\usbohci.sys
2013-11-08 07:05:18 B1564976D98E91FC764D5DC28A0297DA 93696 —-a-w- C:\Windows\System32\drivers\bridge.sys
2013-11-08 07:05:18 A81AB23EDDB4693612014D87367D014C 6656 —-a-w- C:\Windows\System32\DriverStore\FileRepository\acpi.inf_62085e44\errdev.sys
2013-11-08 07:05:18 9F66A46C55D6F1CCABC79BB7AFCCC545 11776 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sffdisk.inf_f081f8b7\sffp_sd.sys
2013-11-08 07:05:18 78533A10D91C7EA6D5BA6A0CEA07CD62 26112 —-a-w- C:\Windows\System32\DriverStore\FileRepository\clusdisk.inf_1f8551c9\ClusDisk.sys
2013-11-08 07:05:18 70A92E46A2F459CDEDE3CA558CB26B6A 52992 —-a-w- C:\Windows\System32\drivers\stream.sys
2013-11-08 07:05:17 E5EAFE85815BD89095FEF3144A09AB68 12288 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sffdisk.inf_f081f8b7\sffp_mmc.sys
2013-11-08 07:05:17 65D1FF8AAFF4A7D8F787A290E5087816 19968 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sti.inf_45d79eaa\WSDScan.sys
2013-11-08 07:05:17 65D1FF8AAFF4A7D8F787A290E5087816 19968 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sti.inf_0bb72b9f\WSDScan.sys
2013-11-08 07:05:17 509A98DD18AF4375E1FC40BC175F1DEF 41472 —-a-w- C:\Windows\System32\drivers\raspppoe.sys
2013-11-08 07:05:17 35C9095FA7076466AFBFC5B9EC4B779E 15872 —-a-w- C:\Windows\System32\DriverStore\FileRepository\netrndis.inf_e5fc9df6\usb8023x.sys
2013-11-08 06:19:21 0A35B7026416325DE4A3EEC131F6EE2C 18636 —-a-w- C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip
==== Startup Registry Enabled ======================
“WindowsWelcomeCenter”=“rundll32.exe oobefldr.dll,ShowWelcomeCenter”
“Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /detectMem”
“WindowsWelcomeCenter”=“rundll32.exe oobefldr.dll,ShowWelcomeCenter”
“Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /detectMem”
“ehTray.exe”=“C:\Windows\ehome\ehTray.exe”
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe”
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe”
“NDSTray.exe”=“NDSTray.exe”
“cfFncEnabler.exe”=“cfFncEnabler.exe”
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
“Toshiba TEMPO”=“C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe”
“IgfxTray”=“C:\Windows\system32\igfxtray.exe”
“HotKeysCmds”=“C:\Windows\system32\hkcmd.exe”
“Persistence”=“C:\Windows\system32\igfxpers.exe”
“RtHDVCpl”=“RtHDVCpl.exe”
“Skytel”=“Skytel.exe”
“Toshiba Registration”=“C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe”
“Camera Assistant Software”=“C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe /start”
“AvastUI.exe”=“C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui”
“GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”
“DivXMediaServer”=“C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe”
“DivXUpdate”=“C:\Program Files\DivX\DivX Update\DivXUpdate.exe /CHECKNOW”
“SunJavaUpdateSched”=“C:\Program Files\Common Files\Java\Java Update\jusched.exe”
“Windows Defender”=“%ProgramFiles%\Windows Defender\MSASCui.exe -hide”
“TPwrMain”=“%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE”
“HSON”=“%ProgramFiles%\TOSHIBA\TBS\HSON.exe ”
“SmoothView”=“%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe ”
“00TCrdMain”=“%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe ”
“ehTray.exe”=“C:\Windows\ehome\ehTray.exe”
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe”
“AppInit_DLLs”=“C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL”
==== Startup Registry Disabled ======================
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“Google Desktop Search”
“hkey”=“HKLM”
“command”=“\”C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\“ /startup”
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“Google EULA Launcher”
“hkey”=“HKLM”
“command”=“c:\\Program Files\\Google\\Google EULA\\GoogleEULALauncher.exe IE PA”
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“GrooveMonitor”
“hkey”=“HKLM”
“command”=“\”C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\“”
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“HP Software Update”
“hkey”=“HKLM”
“command”=“C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe”
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“lxczbmgr.exe”
“hkey”=“HKLM”
“command”=“\”C:\\Program Files\\Lexmark 1200 Series\\lxczbmgr.exe\“”
“key”=“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run”
“item”=“topi”
“hkey”=“HKLM”
“command”=“C:\\Program Files\\TOSHIBA\\Toshiba Online Product Information\\topi.exe -startup”
“path”=“C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk”
“backup”=“C:\\Windows\\pss\\HP Digital Imaging Monitor.lnk.CommonStartup”
“backupExtension”=“.CommonStartup”
“command”=“C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe ”
“item”=“HP Digital Imaging Monitor”
“path”=“C:\\Users\\ans\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2007 Schermopname en Snel starten.lnk”
“backup”=“C:\\Windows\\pss\\OneNote 2007 Schermopname en Snel starten.lnk.Startup”
“backupExtension”=“.Startup”
“command”=“C:\\PROGRA~1\\MICROS~2\\Office12\\ONENOTEM.EXE /tsr”
“item”=“OneNote 2007 Schermopname en Snel starten”
==== Startup Folders ======================
2008-08-19 11:40:54 1835 —-a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
2008-08-19 11:40:54 1835 —-a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job –a—— C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==== Other Scheduled Tasks ======================
“C:\Windows\system32\tasks\Adobe Flash Player Updater”
“C:\Windows\system32\tasks\CCleanerSkipUAC”
“C:\Windows\system32\tasks\CreateChoiceProcessTask”
“C:\Windows\system32\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2394964391-1668799144-2153826031-1000”
“C:\Windows\system32\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2394964391-1668799144-2153826031-1000”
“C:\Windows\system32\tasks\User_Feed_Synchronization-{54650A72-F786-4C2D-963B-DEA61A3CF1CD}”
==== Folders in C:\ProgramData 0-6 Months Old ======================
2013-11-06 20:41:42 ——– d—–w- C:\ProgramData\AVAST Software
2013-11-06 21:14:27 ——– d—–w- C:\ProgramData\Real
2013-11-06 21:16:10 ——– d—–w- C:\ProgramData\DivX
2013-11-08 06:20:14 ——– d—–w- C:\ProgramData\Sun
2013-11-11 07:51:56 ——– d—–w- C:\ProgramData\Malwarebytes
==== Firefox Extensions Registry ======================
“{20a82645-c095-46ed-80e3-08825760534b}”=“C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension”
“smartwebprinting@hp.com”=“C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3”
==== Set IE to Default ======================
Old Values:
“Start Page”=“https://www.google.nl/”
“Default_Page_URL”=“http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;”
“Start Page”=“http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA”
“Default_Page_URL”=“http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA”
New Values:
“Default_Page_URL”=“http://go.microsoft.com/fwlink/?LinkId=69157”
“Start Page”=“https://www.google.nl/”
“Start Page”=“http://go.microsoft.com/fwlink/?LinkId=69157”
“Default_Page_URL”=“http://go.microsoft.com/fwlink/?LinkId=69157”
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
“DefaultScope”=“{60C27265-1B5E-4C42-86CC-31F4BEE321CF}”
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=“http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC”
{60C27265-1B5E-4C42-86CC-31F4BEE321CF} Google Url=“http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;”
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url=“http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}”
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxczbmgr.exe deleted successfully
==== HijackThis Entries ======================
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: NDSTray.exe
O4 - HKLM\..\Run: cfFncEnabler.exe
O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
O4 - HKLM\..\Run: C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
O4 - HKLM\..\Run: C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: RtHDVCpl.exe
O4 - HKLM\..\Run: Skytel.exe
O4 - HKLM\..\Run: %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: “C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe” /start
O4 - HKLM\..\Run: “C:\Program Files\AVAST Software\Avast\AvastUI.exe” /nogui
O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM\..\Run: C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: “C:\Program Files\DivX\DivX Update\DivXUpdate.exe” /CHECKNOW
O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\Run: rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘NETWORK SERVICE’)
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User ‘Default user’)
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?NL (file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
==== Empty IE Cache ======================
C:\Users\ans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\ans\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
“C:\Users\ans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not found
“C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not found
“C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not found
==== EOF on do 14-11-2013 at 9:08:57,45 ======================