Hello and


2013-12-18 17:51 - 2013-12-18 17:51 - 02192805 _____ (Farbar) C:\Users\hsh\Downloads\FRST64.exe
2013-12-18 16:33 - 2013-12-18 16:38 - 00000000 ____D C:\AdwCleaner
2013-12-18 16:31 - 2013-12-18 16:32 - 01226750 _____ C:\Users\hsh\Desktop\AdwCleaner.exe
2013-12-18 16:26 - 2013-12-18 16:40 - 00000336 _____ C:\Windows\setupact.log
2013-12-18 16:26 - 2013-12-18 16:26 - 00000000 _____ C:\Windows\setuperr.log
2013-12-18 14:31 - 2013-12-18 14:31 - 00032901 _____ C:\Users\hsh\Desktop\dds.txt
2013-12-18 14:31 - 2013-12-18 14:31 - 00012171 _____ C:\Users\hsh\Desktop\attach.txt
2013-12-18 14:24 - 2013-12-18 14:24 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-18 14:24 - 2013-12-18 14:24 - 00000000 ____D C:\Users\hsh\AppData\Roaming\Malwarebytes
2013-12-18 14:24 - 2013-12-18 14:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-18 14:24 - 2013-12-18 14:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-18 14:24 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-18 14:11 - 2013-12-18 14:11 - 00000000 ____D C:\ProgramData\Sun
2013-12-18 14:11 - 2013-12-18 14:11 - 00000000 ____D C:\ProgramData\Oracle
2013-12-18 14:10 - 2013-12-18 14:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-18 14:10 - 2013-12-18 14:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-18 14:10 - 2013-12-18 14:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-18 14:10 - 2013-12-18 14:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-18 14:10 - 2013-12-18 14:10 - 00000000 ____D C:\ProgramData\McAfee
2013-12-18 14:10 - 2013-12-18 14:10 - 00000000 ____D C:\Program Files (x86)\Java
2013-12-18 14:09 - 2013-12-18 14:09 - 00915368 _____ (Oracle Corporation) C:\Users\hsh\Downloads\jxpiinstall.exe
2013-12-18 14:02 - 2013-12-18 14:02 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-12-18 14:02 - 2013-12-18 14:02 - 00000000 ____D C:\Windows\system32\NV
2013-12-18 13:53 - 2013-12-18 14:02 - 00001353 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2013-12-18 13:52 - 2013-12-18 13:52 - 00000000 ____D C:\Users\hsh\AppData\Local\NVIDIA Corporation
2013-12-18 13:39 - 2013-12-18 13:44 - 259454424 _____ (NVIDIA Corporation) C:\Users\hsh\Downloads\331.65-notebook-win8-win7-64bit-international-whql.exe
2013-12-18 13:32 - 2013-12-18 13:32 - 00688992 ____R (Swearware) C:\Users\hsh\Desktop\dds.scr
2013-12-18 13:32 - 2013-12-18 13:32 - 00688992 _____ (Swearware) C:\Users\hsh\Desktop\dds.com
2013-12-18 13:27 - 2013-12-18 13:27 - 00000000 ____D C:\Users\hsh\AppData\Local\Macromedia
2013-12-18 13:27 - 2013-12-18 13:27 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-12-18 13:25 - 2013-12-18 13:26 - 27923456 _____ C:\Users\hsh\Downloads\PhysX-9.13.0725-SystemSoftware.msi
2013-12-18 13:21 - 2013-12-18 13:24 - 00000000 ____D C:\Users\hsh\AppData\Local\Adobe
2013-12-18 12:22 - 2013-12-18 12:22 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\hsh\Desktop\mbam-setup-
2013-12-18 09:46 - 2013-12-18 09:56 - 00000000 ____D C:\Windows\pss
2013-12-18 08:46 - 2013-12-18 08:46 - 00000000 ____D C:\ProgramData\ESET
2013-12-18 08:46 - 2013-12-18 08:46 - 00000000 ____D C:\Program Files\ESET
2013-12-18 08:45 - 2013-12-18 13:15 - 00000000 ____D C:\Users\hsh\AppData\Roaming\EAST Technologies
2013-12-17 23:31 - 2013-12-17 23:31 - 00003118 _____ C:\Windows\System32\Tasks\{469FF7F0-E459-4D74-8370-0E052255AA5C}
2013-12-17 23:09 - 2013-12-17 23:09 - 00000000 ____D C:\Users\hsh\AppData\Roaming\HTML Executable
2013-12-17 23:05 - 2013-12-17 23:38 - 00000000 ____D C:\Users\hsh\AppData\Local\ESET
2013-12-17 23:05 - 2013-12-17 23:05 - 00000000 ____D C:\Users\hsh\AppData\Roaming\ESET
2013-12-17 22:54 - 2013-12-17 22:54 - 00250557 _____ C:\ProgramData\1387348882.bdinstall.bin
2013-12-17 22:21 - 2013-12-17 22:21 - 01298328 _____ C:\Users\hsh\Downloads\BatteryBarSetup-3.6.2.exe
2013-12-17 22:01 - 2013-12-17 22:01 - 00000385 _____ C:\Users\hsh\AppData\Roaminguser_gensett.xml
2013-12-17 21:48 - 2013-12-17 21:48 - 00445444 _____ C:\ProgramData\1387345493.bdinstall.bin
2013-12-17 21:48 - 2013-12-17 21:48 - 00000385 _____ C:\Windows\system32\user_gensett.xml
2013-12-17 21:48 - 2013-12-17 21:48 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2013-12-17 21:48 - 2013-12-17 21:48 - 00000000 ____D C:\ProgramData\BDLogging
2013-12-17 21:48 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2013-12-17 21:45 - 2013-12-17 22:56 - 00000000 ____D C:\Program Files\Bitdefender
2013-12-17 21:44 - 2013-12-17 22:54 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-12-17 21:44 - 2013-12-17 21:44 - 00000000 ____D C:\Users\hsh\AppData\Roaming\QuickScan
2013-12-17 21:35 - 2013-12-18 14:18 - 00000000 ____D C:\Program Files (x86)\TechSmith
2013-12-17 21:35 - 2013-12-17 21:35 - 00000000 ____D C:\Users\hsh\Documents\Snagit
2013-12-17 21:35 - 2013-12-17 21:35 - 00000000 ____D C:\Users\hsh\AppData\Local\TechSmith
2013-12-17 21:27 - 2013-12-17 21:27 - 00000000 ____D C:\Users\hsh\AppData\Local\VS Revo Group
2013-12-17 21:27 - 2013-12-17 21:27 - 00000000 ____D C:\ProgramData\VS Revo Group
2013-12-17 21:25 - 2013-12-17 21:25 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-17 21:25 - 2013-12-17 21:25 - 00000828 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-17 21:25 - 2013-12-17 21:25 - 00000000 ____D C:\Program Files\CCleaner
2013-12-17 21:17 - 2013-12-17 21:17 - 00000000 ____D C:\Users\hsh\Downloads\hjsplit
2013-12-17 21:16 - 2013-12-17 21:16 - 00194885 _____ C:\Users\hsh\Downloads\hjsplit.zip
2013-12-17 21:12 - 2013-12-17 21:14 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-17 21:12 - 2013-12-17 21:14 - 00000000 ____D C:\ProgramData\Skype
2013-12-17 21:12 - 2013-12-17 21:12 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2013-12-17 21:12 - 2013-12-17 21:12 - 00000000 ____D C:\Users\hsh\AppData\Roaming\Skype
2013-12-17 21:09 - 2013-12-17 21:11 - 04618136 _____ (Piriform Ltd) C:\Users\hsh\Downloads\ccsetup408.exe
2013-12-17 19:36 - 2013-12-17 19:38 - 00000000 ____D C:\ProgramData\InstallMate
2013-12-17 18:16 - 2013-12-17 18:16 - 00231376 ____N (TrueCrypt Foundation) C:\Windows\system32\Drivers\truecrypt.sys
2013-12-17 18:16 - 2013-12-17 18:16 - 00000881 _____ C:\Users\Public\Desktop\CT.lnk
2013-12-17 18:16 - 2013-12-17 18:16 - 00000000 ____D C:\Program Files\TrueCrypt
2013-12-17 15:44 - 2013-12-18 16:44 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-12-17 15:44 - 2013-12-17 15:44 - 00002043 _____ C:\Users\hsh\Desktop\JDownloader.lnk
2013-12-17 15:41 - 2013-12-17 15:41 - 00000000 ____D C:\Users\hsh\AppData\Local\CRE
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\wangzhisong
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\hsh\AppData\Local\Mobogenie
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\hsh\AppData\Local\cache
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 _____ C:\Users\hsh\daemonprocess.txt
2013-12-17 14:04 - 2013-12-17 15:53 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-12-17 13:28 - 2013-12-17 13:28 - 00000877 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-12-17 13:28 - 2013-12-17 13:28 - 00000000 ____D C:\Users\hsh\AppData\Roaming\vlc
2013-12-17 13:28 - 2013-12-17 13:28 - 00000000 ____D C:\Program Files\VideoLAN
2013-12-17 13:11 - 2013-12-17 17:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-17 13:11 - 2013-12-17 13:11 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\Users\hsh\AppData\Roaming\Mozilla
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\Users\hsh\AppData\Local\Mozilla
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\ProgramData\Mozilla
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-17 12:58 - 2013-12-18 16:38 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
2013-12-17 12:58 - 2013-12-17 12:58 - 00000000 ____D C:\ProgramData\Hotspot Shield
2013-12-17 12:58 - 2013-11-13 02:49 - 00044744 _____ (AnchorFree Inc.) C:\Windows\system32\Drivers\hssdrv6.sys
2013-12-17 12:45 - 2013-12-17 12:45 - 00000000 ____D C:\Users\hsh\AppData\Roaming\XnView
2013-12-17 12:36 - 2013-12-17 12:36 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-12-17 12:35 - 2013-12-17 12:35 - 03429528 _____ (Lenovo Group                                                ) C:\Users\hsh\Downloads\l1egc02us24.exe
2013-12-17 12:33 - 2013-12-17 12:33 - 00000000 ____D C:\Users\hsh\AppData\Roaming\PDF Architect
2013-12-17 12:23 - 2013-12-17 12:23 - 00001795 _____ C:\Users\hsh\Desktop\XnView.lnk
2013-12-17 12:23 - 2013-12-17 12:23 - 00000000 ____D C:\Program Files (x86)\XnView
2013-12-17 12:14 - 2013-12-17 12:14 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-12-17 09:38 - 2013-05-09 21:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-17 09:38 - 2013-05-09 21:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-17 09:38 - 2013-05-09 20:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-17 09:38 - 2013-05-09 20:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-17 09:37 - 2013-11-26 03:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-17 09:37 - 2013-11-26 02:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-17 09:37 - 2013-11-26 02:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-17 09:37 - 2013-11-26 02:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-17 09:37 - 2013-11-26 01:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-17 09:37 - 2013-11-26 01:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-17 09:37 - 2013-11-26 01:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-17 09:37 - 2013-11-26 01:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-17 09:37 - 2013-11-26 01:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-17 09:37 - 2013-11-26 01:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-17 09:37 - 2013-11-26 01:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-17 09:37 - 2013-11-26 01:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-17 09:37 - 2013-11-26 01:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-17 09:37 - 2013-11-26 01:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-17 09:37 - 2013-11-26 00:57 - 00218624 ____N (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-17 09:37 - 2013-11-26 00:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-17 09:37 - 2013-11-26 00:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-17 09:37 - 2013-11-26 00:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-17 09:37 - 2013-11-26 00:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-17 09:37 - 2013-11-26 00:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-17 09:37 - 2013-11-26 00:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-17 09:37 - 2013-11-26 00:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-17 09:37 - 2013-11-25 23:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-17 09:37 - 2013-11-25 23:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-17 09:37 - 2013-11-25 23:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-17 09:37 - 2013-11-25 23:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-17 09:37 - 2013-11-25 22:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-17 09:37 - 2013-11-25 22:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-17 09:37 - 2013-11-25 22:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-17 09:37 - 2013-11-25 22:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-17 09:37 - 2013-11-25 22:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-15 16:29 - 2013-11-23 10:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-15 16:29 - 2013-11-23 09:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-15 16:29 - 2013-11-11 18:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-15 16:29 - 2013-11-11 18:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-15 16:29 - 2013-10-29 18:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-15 16:29 - 2013-10-29 18:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-15 16:29 - 2013-10-29 17:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-15 16:29 - 2013-10-18 18:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-15 16:29 - 2013-10-18 17:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-15 16:29 - 2013-10-11 18:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-15 16:29 - 2013-10-11 18:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-15 16:29 - 2013-10-11 18:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-15 16:29 - 2013-10-11 18:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-15 16:29 - 2013-10-11 17:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-15 16:29 - 2013-10-11 17:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-15 16:29 - 2013-10-11 17:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-15 16:29 - 2013-10-11 17:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-15 16:29 - 2013-10-03 18:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-15 16:29 - 2013-10-03 17:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-11-30 22:27 - 2013-04-16 23:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-11-30 22:27 - 2013-04-16 22:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-11-30 22:27 - 2012-07-06 12:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2013-11-30 22:27 - 2011-04-27 19:54 - 00080384 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2013-11-30 22:27 - 2011-03-24 19:29 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-30 22:27 - 2011-03-24 19:29 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-30 22:27 - 2011-03-24 19:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-30 22:27 - 2011-03-24 19:29 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-30 22:27 - 2011-03-24 19:29 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-30 22:27 - 2011-03-24 19:29 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-30 22:27 - 2011-03-24 19:28 - 00007936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-30 22:27 - 2011-03-10 22:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2013-11-30 22:27 - 2011-03-10 22:41 - 00189824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2013-11-30 22:27 - 2011-03-10 22:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2013-11-30 22:27 - 2011-03-10 22:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2013-11-30 22:27 - 2011-03-10 22:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2013-11-30 22:27 - 2011-03-10 22:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2013-11-30 22:27 - 2011-03-10 22:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2013-11-30 22:27 - 2011-03-10 22:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2013-11-30 22:27 - 2011-03-10 21:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-11-30 22:27 - 2011-03-10 21:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2013-11-30 22:27 - 2011-03-10 20:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2013-11-30 22:20 - 2013-11-30 22:20 - 00000000 ____D C:\Users\hsh\AppData\Local\NVIDIA
2013-11-19 20:00 - 2013-10-05 12:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-19 20:00 - 2013-10-05 11:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-19 19:59 - 2013-10-03 18:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-19 19:59 - 2013-10-03 18:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-19 19:59 - 2013-10-03 18:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-19 19:59 - 2013-10-03 17:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-19 19:59 - 2013-10-03 17:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-19 19:59 - 2013-10-03 17:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-19 19:59 - 2013-09-24 18:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-19 19:59 - 2013-09-24 18:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-19 19:59 - 2013-09-24 18:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-19 19:59 - 2013-09-24 18:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-19 19:59 - 2013-09-24 18:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-19 19:59 - 2013-09-24 18:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-19 19:59 - 2013-09-24 18:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-19 19:59 - 2013-09-24 18:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-19 19:59 - 2013-09-24 17:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-19 19:59 - 2013-09-24 17:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-19 19:59 - 2013-09-24 17:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-19 19:59 - 2013-09-24 17:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-19 19:59 - 2013-09-24 17:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-19 19:59 - 2013-07-04 04:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-19 19:49 - 2013-12-18 09:08 - 00404640 _____ C:\Windows\system32\prfh0404.dat
2013-11-19 19:49 - 2013-12-18 09:08 - 00118430 _____ C:\Windows\system32\prfc0404.dat
2013-11-19 19:49 - 2013-11-19 19:41 - 00117840 _____ C:\Windows\system32\prfi0404.dat
2013-11-19 19:49 - 2013-11-19 19:41 - 00031548 _____ C:\Windows\system32\prfd0404.dat
2013-11-19 19:46 - 2013-11-19 19:46 - 00000000 ____D C:\Windows\SysWOW64\zh-CHT
2013-11-19 19:46 - 2013-11-19 19:46 - 00000000 ____D C:\Windows\system32\zh-CHT
2013-11-19 19:46 - 2013-11-19 19:46 - 00000000 ____D C:\Windows\system32\Drivers\zh-HK
2013-11-19 19:45 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-19 19:42 - 2013-11-19 19:42 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-19 19:42 - 2013-11-19 19:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-19 19:42 - 2013-11-19 19:42 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-19 19:42 - 2013-11-19 19:42 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-19 19:42 - 2013-11-19 19:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-19 19:42 - 2013-11-19 19:42 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-19 19:42 - 2013-11-19 19:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-19 19:37 - 2013-12-17 09:37 - 00000000 ____D C:\Windows\system32\MRT
2013-11-19 19:37 - 2013-12-17 09:35 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-19 18:13 - 2013-11-19 18:13 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-19 17:48 - 2012-07-25 19:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2013-11-19 17:48 - 2012-07-25 19:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2013-11-19 17:48 - 2012-07-25 19:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2013-11-19 17:48 - 2012-07-25 19:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2013-11-19 17:48 - 2012-07-25 19:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2013-11-19 17:48 - 2012-07-25 18:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2013-11-19 17:48 - 2012-07-25 18:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2013-11-19 17:48 - 2012-06-02 06:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2013-11-19 17:35 - 2012-02-29 22:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2013-11-19 17:35 - 2012-02-29 22:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2013-11-19 17:35 - 2012-02-29 21:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2013-11-19 17:32 - 2013-10-11 18:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-19 17:32 - 2013-10-11 18:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-19 17:32 - 2013-10-11 18:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-19 17:32 - 2013-10-11 18:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-19 17:32 - 2013-10-11 18:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-19 17:32 - 2013-10-02 18:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-19 17:32 - 2013-10-02 18:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-19 17:32 - 2013-09-27 17:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys

==================== One Month Modified Files and Folders =======

2013-12-18 17:53 - 2013-12-18 17:53 - 00014962 _____ C:\Users\hsh\Desktop\FRST.txt
2013-12-18 17:53 - 2013-12-18 17:53 - 00000000 ____D C:\FRST
2013-12-18 17:53 - 2009-07-13 19:20 - 00000000 __RHD C:\Users\Default
2013-12-18 17:51 - 2013-12-18 17:52 - 02192805 _____ (Farbar) C:\Users\hsh\Desktop\FRST64.exe
2013-12-18 17:51 - 2013-12-18 17:51 - 02192805 _____ (Farbar) C:\Users\hsh\Downloads\FRST64.exe
2013-12-18 17:48 - 2013-11-10 00:50 - 00000536 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-18 17:48 - 2013-11-09 08:25 - 01290983 _____ C:\Windows\WindowsUpdate.log
2013-12-18 17:42 - 2013-11-10 00:53 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-18 16:47 - 2009-07-13 20:45 - 00021472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-18 16:47 - 2009-07-13 20:45 - 00021472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-18 16:45 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\NDF
2013-12-18 16:44 - 2013-12-17 15:44 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-12-18 16:40 - 2013-12-18 16:26 - 00000336 _____ C:\Windows\setupact.log
2013-12-18 16:39 - 2013-11-10 00:53 - 00000888 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-18 16:39 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-18 16:38 - 2013-12-18 16:33 - 00000000 ____D C:\AdwCleaner
2013-12-18 16:38 - 2013-12-17 12:58 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
2013-12-18 16:32 - 2013-12-18 16:31 - 01226750 _____ C:\Users\hsh\Desktop\AdwCleaner.exe
2013-12-18 16:26 - 2013-12-18 16:26 - 00000000 _____ C:\Windows\setuperr.log
2013-12-18 14:31 - 2013-12-18 14:31 - 00032901 _____ C:\Users\hsh\Desktop\dds.txt
2013-12-18 14:31 - 2013-12-18 14:31 - 00012171 _____ C:\Users\hsh\Desktop\attach.txt
2013-12-18 14:24 - 2013-12-18 14:24 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-18 14:24 - 2013-12-18 14:24 - 00000000 ____D C:\Users\hsh\AppData\Roaming\Malwarebytes
2013-12-18 14:24 - 2013-12-18 14:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-18 14:24 - 2013-12-18 14:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-18 14:18 - 2013-12-17 21:35 - 00000000 ____D C:\Program Files (x86)\TechSmith
2013-12-18 14:11 - 2013-12-18 14:11 - 00000000 ____D C:\ProgramData\Sun
2013-12-18 14:11 - 2013-12-18 14:11 - 00000000 ____D C:\ProgramData\Oracle
2013-12-18 14:10 - 2013-12-18 14:10 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-18 14:10 - 2013-12-18 14:10 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-18 14:10 - 2013-12-18 14:10 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-18 14:10 - 2013-12-18 14:10 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-18 14:10 - 2013-12-18 14:10 - 00000000 ____D C:\ProgramData\McAfee
2013-12-18 14:10 - 2013-12-18 14:10 - 00000000 ____D C:\Program Files (x86)\Java
2013-12-18 14:09 - 2013-12-18 14:09 - 00915368 _____ (Oracle Corporation) C:\Users\hsh\Downloads\jxpiinstall.exe
2013-12-18 14:02 - 2013-12-18 14:02 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-12-18 14:02 - 2013-12-18 14:02 - 00000000 ____D C:\Windows\system32\NV
2013-12-18 14:02 - 2013-12-18 13:53 - 00001353 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2013-12-18 14:02 - 2013-11-10 01:05 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-18 13:52 - 2013-12-18 13:52 - 00000000 ____D C:\Users\hsh\AppData\Local\NVIDIA Corporation
2013-12-18 13:44 - 2013-12-18 13:39 - 259454424 _____ (NVIDIA Corporation) C:\Users\hsh\Downloads\331.65-notebook-win8-win7-64bit-international-whql.exe
2013-12-18 13:32 - 2013-12-18 13:32 - 00688992 ____R (Swearware) C:\Users\hsh\Desktop\dds.scr
2013-12-18 13:32 - 2013-12-18 13:32 - 00688992 _____ (Swearware) C:\Users\hsh\Desktop\dds.com
2013-12-18 13:27 - 2013-12-18 13:27 - 00000000 ____D C:\Users\hsh\AppData\Local\Macromedia
2013-12-18 13:27 - 2013-12-18 13:27 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-12-18 13:27 - 2013-11-10 01:04 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-12-18 13:26 - 2013-12-18 13:25 - 27923456 _____ C:\Users\hsh\Downloads\PhysX-9.13.0725-SystemSoftware.msi
2013-12-18 13:24 - 2013-12-18 13:21 - 00000000 ____D C:\Users\hsh\AppData\Local\Adobe
2013-12-18 13:23 - 2013-11-10 00:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-18 13:23 - 2013-11-10 00:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-18 13:23 - 2013-11-10 00:50 - 00003474 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-18 13:15 - 2013-12-18 08:45 - 00000000 ____D C:\Users\hsh\AppData\Roaming\EAST Technologies
2013-12-18 12:38 - 2013-11-09 08:20 - 00000000 ____D C:\Windows\Panther
2013-12-18 12:22 - 2013-12-18 12:22 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\hsh\Desktop\mbam-setup-
2013-12-18 09:59 - 2013-11-10 00:29 - 00000000 ___RD C:\Users\hsh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-18 09:56 - 2013-12-18 09:46 - 00000000 ____D C:\Windows\pss
2013-12-18 09:08 - 2013-11-19 19:49 - 00404640 _____ C:\Windows\system32\prfh0404.dat
2013-12-18 09:08 - 2013-11-19 19:49 - 00118430 _____ C:\Windows\system32\prfc0404.dat
2013-12-18 09:08 - 2011-04-12 06:46 - 00387538 _____ C:\Windows\system32\prfh0804.dat
2013-12-18 09:08 - 2011-04-12 06:46 - 00123344 _____ C:\Windows\system32\prfc0804.dat
2013-12-18 09:08 - 2009-07-13 21:13 - 01777034 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-18 08:46 - 2013-12-18 08:46 - 00000000 ____D C:\ProgramData\ESET
2013-12-18 08:46 - 2013-12-18 08:46 - 00000000 ____D C:\Program Files\ESET
2013-12-17 23:38 - 2013-12-17 23:05 - 00000000 ____D C:\Users\hsh\AppData\Local\ESET
2013-12-17 23:31 - 2013-12-17 23:31 - 00003118 _____ C:\Windows\System32\Tasks\{469FF7F0-E459-4D74-8370-0E052255AA5C}
2013-12-17 23:09 - 2013-12-17 23:09 - 00000000 ____D C:\Users\hsh\AppData\Roaming\HTML Executable
2013-12-17 23:05 - 2013-12-17 23:05 - 00000000 ____D C:\Users\hsh\AppData\Roaming\ESET
2013-12-17 22:56 - 2013-12-17 21:45 - 00000000 ____D C:\Program Files\Bitdefender
2013-12-17 22:54 - 2013-12-17 22:54 - 00250557 _____ C:\ProgramData\1387348882.bdinstall.bin
2013-12-17 22:54 - 2013-12-17 21:44 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-12-17 22:21 - 2013-12-17 22:21 - 01298328 _____ C:\Users\hsh\Downloads\BatteryBarSetup-3.6.2.exe
2013-12-17 22:01 - 2013-12-17 22:01 - 00000385 _____ C:\Users\hsh\AppData\Roaminguser_gensett.xml
2013-12-17 21:48 - 2013-12-17 21:48 - 00445444 _____ C:\ProgramData\1387345493.bdinstall.bin
2013-12-17 21:48 - 2013-12-17 21:48 - 00000385 _____ C:\Windows\system32\user_gensett.xml
2013-12-17 21:48 - 2013-12-17 21:48 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2013-12-17 21:48 - 2013-12-17 21:48 - 00000000 ____D C:\ProgramData\BDLogging
2013-12-17 21:48 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-17 21:44 - 2013-12-17 21:44 - 00000000 ____D C:\Users\hsh\AppData\Roaming\QuickScan
2013-12-17 21:35 - 2013-12-17 21:35 - 00000000 ____D C:\Users\hsh\Documents\Snagit
2013-12-17 21:35 - 2013-12-17 21:35 - 00000000 ____D C:\Users\hsh\AppData\Local\TechSmith
2013-12-17 21:29 - 2013-11-10 00:28 - 00000000 ____D C:\Users\hsh
2013-12-17 21:27 - 2013-12-17 21:27 - 00000000 ____D C:\Users\hsh\AppData\Local\VS Revo Group
2013-12-17 21:27 - 2013-12-17 21:27 - 00000000 ____D C:\ProgramData\VS Revo Group
2013-12-17 21:25 - 2013-12-17 21:25 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-12-17 21:25 - 2013-12-17 21:25 - 00000828 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-17 21:25 - 2013-12-17 21:25 - 00000000 ____D C:\Program Files\CCleaner
2013-12-17 21:17 - 2013-12-17 21:17 - 00000000 ____D C:\Users\hsh\Downloads\hjsplit
2013-12-17 21:16 - 2013-12-17 21:16 - 00194885 _____ C:\Users\hsh\Downloads\hjsplit.zip
2013-12-17 21:14 - 2013-12-17 21:12 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-17 21:14 - 2013-12-17 21:12 - 00000000 ____D C:\ProgramData\Skype
2013-12-17 21:12 - 2013-12-17 21:12 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2013-12-17 21:12 - 2013-12-17 21:12 - 00000000 ____D C:\Users\hsh\AppData\Roaming\Skype
2013-12-17 21:11 - 2013-12-17 21:09 - 04618136 _____ (Piriform Ltd) C:\Users\hsh\Downloads\ccsetup408.exe
2013-12-17 19:38 - 2013-12-17 19:36 - 00000000 ____D C:\ProgramData\InstallMate
2013-12-17 18:16 - 2013-12-17 18:16 - 00231376 ____N (TrueCrypt Foundation) C:\Windows\system32\Drivers\truecrypt.sys
2013-12-17 18:16 - 2013-12-17 18:16 - 00000881 _____ C:\Users\Public\Desktop\CT.lnk
2013-12-17 18:16 - 2013-12-17 18:16 - 00000000 ____D C:\Program Files\TrueCrypt
2013-12-17 17:05 - 2013-12-17 13:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-17 15:53 - 2013-12-17 14:04 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2013-12-17 15:44 - 2013-12-17 15:44 - 00002043 _____ C:\Users\hsh\Desktop\JDownloader.lnk
2013-12-17 15:41 - 2013-12-17 15:41 - 00000000 ____D C:\Users\hsh\AppData\Local\CRE
2013-12-17 14:54 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\wangzhisong
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\hsh\AppData\Local\Mobogenie
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 ____D C:\Users\hsh\AppData\Local\cache
2013-12-17 14:05 - 2013-12-17 14:05 - 00000000 _____ C:\Users\hsh\daemonprocess.txt
2013-12-17 13:28 - 2013-12-17 13:28 - 00000877 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-12-17 13:28 - 2013-12-17 13:28 - 00000000 ____D C:\Users\hsh\AppData\Roaming\vlc
2013-12-17 13:28 - 2013-12-17 13:28 - 00000000 ____D C:\Program Files\VideoLAN
2013-12-17 13:11 - 2013-12-17 13:11 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\Users\hsh\AppData\Roaming\Mozilla
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\Users\hsh\AppData\Local\Mozilla
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\ProgramData\Mozilla
2013-12-17 13:11 - 2013-12-17 13:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-17 12:58 - 2013-12-17 12:58 - 00000000 ____D C:\ProgramData\Hotspot Shield
2013-12-17 12:45 - 2013-12-17 12:45 - 00000000 ____D C:\Users\hsh\AppData\Roaming\XnView
2013-12-17 12:36 - 2013-12-17 12:36 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-12-17 12:36 - 2013-11-10 00:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-17 12:35 - 2013-12-17 12:35 - 03429528 _____ (Lenovo Group                                                ) C:\Users\hsh\Downloads\l1egc02us24.exe
2013-12-17 12:33 - 2013-12-17 12:33 - 00000000 ____D C:\Users\hsh\AppData\Roaming\PDF Architect
2013-12-17 12:33 - 2013-11-10 19:39 - 00000000 ____D C:\Windows\system32\appmgmt
2013-12-17 12:23 - 2013-12-17 12:23 - 00001795 _____ C:\Users\hsh\Desktop\XnView.lnk
2013-12-17 12:23 - 2013-12-17 12:23 - 00000000 ____D C:\Program Files (x86)\XnView
2013-12-17 12:14 - 2013-12-17 12:14 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-12-17 09:46 - 2009-07-13 20:45 - 00275712 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-17 09:37 - 2013-11-19 19:37 - 00000000 ____D C:\Windows\system32\MRT
2013-12-17 09:35 - 2013-11-19 19:37 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-15 16:22 - 2013-11-10 00:53 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-15 16:22 - 2013-11-10 00:53 - 00003636 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-30 22:22 - 2013-11-10 02:52 - 00003880 ____N C:\Windows\System32\Tasks\User_Feed_Synchronization-{6A3B83C9-7172-4005-94E2-2067C697B81C}
2013-11-30 22:20 - 2013-11-30 22:20 - 00000000 ____D C:\Users\hsh\AppData\Local\NVIDIA
2013-11-26 03:54 - 2013-12-17 09:37 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 02:19 - 2013-12-17 09:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 02:18 - 2013-12-17 09:37 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 02:11 - 2013-12-17 09:37 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 01:48 - 2013-12-17 09:37 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 01:46 - 2013-12-17 09:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 01:41 - 2013-12-17 09:37 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 01:29 - 2013-12-17 09:37 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 01:27 - 2013-12-17 09:37 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 01:23 - 2013-12-17 09:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 01:21 - 2013-12-17 09:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 01:18 - 2013-12-17 09:37 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 01:18 - 2013-12-17 09:37 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 01:16 - 2013-12-17 09:37 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 00:57 - 2013-12-17 09:37 - 00218624 ____N (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 00:38 - 2013-12-17 09:37 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 00:38 - 2013-12-17 09:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 00:35 - 2013-12-17 09:37 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 00:32 - 2013-12-17 09:37 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 00:28 - 2013-12-17 09:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 00:16 - 2013-12-17 09:37 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 00:02 - 2013-12-17 09:37 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-25 23:48 - 2013-12-17 09:37 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-25 23:32 - 2013-12-17 09:37 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-25 23:26 - 2013-12-17 09:37 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-25 23:07 - 2013-12-17 09:37 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-25 22:40 - 2013-12-17 09:37 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-25 22:34 - 2013-12-17 09:37 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-25 22:34 - 2013-12-17 09:37 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-25 22:33 - 2013-12-17 09:37 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-25 22:27 - 2013-12-17 09:37 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-23 10:26 - 2013-12-15 16:29 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 09:47 - 2013-12-15 16:29 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-20 10:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-11-20 10:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-11-20 10:21 - 2013-11-10 01:03 - 00000000 ____D C:\Users\Public\Thunder Network
2013-11-19 21:19 - 2013-11-10 18:33 - 00000000 ____D C:\Users\hsh\AppData\Roaming\DrvMgr
2013-11-19 19:51 - 2013-11-10 00:52 - 00058016 _____ C:\Users\hsh\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-19 19:46 - 2013-11-19 19:46 - 00000000 ____D C:\Windows\SysWOW64\zh-CHT
2013-11-19 19:46 - 2013-11-19 19:46 - 00000000 ____D C:\Windows\system32\zh-CHT
2013-11-19 19:46 - 2013-11-19 19:46 - 00000000 ____D C:\Windows\system32\Drivers\zh-HK
2013-11-19 19:46 - 2011-04-12 06:57 - 00000000 ____D C:\Program Files\Windows Journal
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\SysWOW64\winrm
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\SysWOW64\WCN
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\system32\winrm
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\system32\WCN
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\system32\slmgr
2013-11-19 19:46 - 2011-04-12 06:45 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\DVD Maker
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-11-19 19:46 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\com
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\sysprep
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\oobe
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\MUI
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\migwiz
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\Dism
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\com
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\servicing
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\IME
2013-11-19 19:46 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-19 19:42 - 2013-11-19 19:42 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-19 19:42 - 2013-11-19 19:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-19 19:42 - 2013-11-19 19:42 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-19 19:42 - 2013-11-19 19:42 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-19 19:42 - 2013-11-19 19:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-19 19:42 - 2013-11-19 19:42 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-19 19:42 - 2013-11-19 19:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-19 19:42 - 2013-11-19 19:42 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-19 19:42 - 2013-11-19 19:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-19 19:41 - 2013-11-19 19:49 - 00117840 _____ C:\Windows\system32\prfi0404.dat
2013-11-19 19:41 - 2013-11-19 19:49 - 00031548 _____ C:\Windows\system32\prfd0404.dat
2013-11-19 18:57 - 2013-11-10 00:29 - 00000000 ___RD C:\Users\hsh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-19 18:53 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-11-19 18:53 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-11-19 18:47 - 2013-11-10 01:02 - 01253978 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-11-19 18:13 - 2013-11-19 18:13 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-19 18:13 - 2013-11-19 18:13 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-11-19 17:24 - 2013-11-10 01:04 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-19 03:33 - 2010-11-20 19:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-12-17 14:43

==================== End Of Log ============================

ok, Ive tried several times to upload the "addition.txt" using both the basic loader and advanced loader. each time I keep getting an error: upload failed.

Ive tried this in both firefox and chrome browsers.

Also, chrome browsers still shows  "conduit" as the search when "startpage" was set as the default home page.

Farbar Service Scanner Version: 05-12-2013
Ran by hsh (administrator) on 18-12-2013 at 18:15:36
Running from "C:\Users\hsh\Desktop"
Microsoft Windows 7 Ultimate  Service Pack 1 (X64)
Boot Mode: Normal

Internet Services:

Connection Status:
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:

Firewall Disabled Policy:

System Restore:

System Restore Disabled Policy:

Action Center:

Windows Update:

Windows Autoupdate Disabled Policy:

Windows Defender:

Other Services:

File Check:
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit

**** End of log ****

Not sure what you zipped up but it certainly don`t look like addition.txt log file... Do the following:


Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST and press the Fix button just once and wait.

The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.




We still need to run an online AV scan to ensure there are no remnants of any infection left on your system that we may have missed. This scan is very thorough and well worth running, it can take several hours please be patient and let it complete:


Run Eset Online Scanner


**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin


Go to Eset web page http://www.eset.com/us/online-scanner/ to run an online scan from ESET.


  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    Click Start
  • When asked, allow the add/on to be installed
    Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings, ensure the options
  • Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
    Click Scan
  • wait for the virus definitions to be downloaded
  • Wait for the scan to finish


When the scan is complete


  • If no threats were found
  • put a checkmark in "Uninstall application on close"
  • close program
  • report to me that nothing was found


If threats were found


  • click on "list of threats found"
  • click on "export to text file" and save it as ESET SCAN and save to the desktop
  • Click on back
  • put a checkmark in "Uninstall application on close"
  • click on finish


close program


copy and paste the report in next reply




Download Security Check by screen317 from either of the following:

http://screen317.spywareinfoforum.org/SecurityCheck.exe or http://screen317.changelog.fr/SecurityCheck.exe

Save it to your Desktop. (If your security alerts either accept the alert, or turn the security off while Secuirity Check runs)

Double click SecurityCheck.exe (Vista or Windows 7 users right click and select "Run as Administrator") and follow the onscreen instructions inside of the black box. Press any key when asked.

A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Post those logs, let me know what issues/concerns remain....







Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-12-2013
Ran by hsh at 2013-12-19 14:46:42 Run:1
Running from C:\Users\hsh\Desktop
Boot Mode: Normal

Content of fixlist:
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearc...ults.php?f=4&q={searchTerms}&a=irmsd1202&cd=2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0F0AtA0A0CtBtD0D0FzytN0D0Tzu0SyBtCyBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=2001500293&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearc...ults.php?f=4&q={searchTerms}&a=irmsd1202&cd=2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0F0AtA0A0CtBtD0D0FzytN0D0Tzu0SyBtCyBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=2001500293&ir=
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearc...ults.php?f=4&q={searchTerms}&a=irmsd1202&cd=2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0F0AtA0A0CtBtD0D0FzytN0D0Tzu0SyBtCyBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=2001500293&ir=
SearchScopes: HKCU - {EFC5FB5C-3179-4C7A-9EF1-CB09C3FF1D87} URL = http://search.condui...ultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3309760&CUI=UN28176857679794237&UM=2
BHO: No Name - {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} -  No File
FF SelectedSearchEngine: XXXTOOLBARNAMEXXX Search
S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [x]
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [x]
S2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [x]
C:\Program Files (x86)\Hotspot Shield
C:\ProgramData\Hotspot Shield


HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EFC5FB5C-3179-4C7A-9EF1-CB09C3FF1D87} => Key deleted successfully.
HKCR\CLSID\{EFC5FB5C-3179-4C7A-9EF1-CB09C3FF1D87} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E} => Key deleted successfully.
HKCR\CLSID\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E} => Key not found.
Firefox SelectedSearchEngine deleted successfully.
hshld => Service deleted successfully.
HssTrayService => Service deleted successfully.
HssWd => Service deleted successfully.
C:\Program Files (x86)\Hotspot Shield => Moved successfully.
C:\ProgramData\Hotspot Shield => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\BatteryBarSetup-3.6.2.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\fp_pl_pfs_installer.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nsdDBA.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nsdF2EA.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nsi126E.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nsiD83C.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nsn9292.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nsoF80C.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\nssE12F.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\SPStub.exe => Moved successfully.
C:\Users\hsh\AppData\Local\Temp\xReflect.exe => Moved successfully.

==== End of Fixlog ====

Download Dr Web Cureit from here http://www.freedrweb.com/cureit save to your desktop. (Scroll to bottom of page)


  • The file will be randomly named
  • Reboot to safe mode
  • Run Dr Web
  • Tick the I agree box and select continue
  • Click select objects for scanning
  • Tick all boxes as shown
  • Click the wrench and select automatically apply actions to threats
  • Press start scan
  • The scan will now commence
  • Once the scan has finished click open report
  • A notepad will open
  • Select File > Save as..
  • Save it to your desktop


This log will be excessive,  Attach it to your next reply…

 Results of screen317's Security Check version 0.99.77  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Disabled!  
ESET Smart Security 4.2   
 Antivirus up to date!  (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware version  
 Java 7 Update 45  
 Adobe Flash Player 11.9.900.170  
 Mozilla Firefox (26.0)
 Google Chrome 31.0.1650.63  
````````Process Check: objlist.exe by Laurent````````  
 ESET NOD32 Antivirus egui.exe  
 ESET NOD32 Antivirus ekrn.exe  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbamgui.exe  
 Malwarebytes' Anti-Malware mbamscheduler.exe   
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````

