Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Super slow browsing and pc [Solved]


  • This topic is locked This topic is locked

#1
assaf1

assaf1

    Member

  • Member
  • PipPip
  • 26 posts
Hi,who can help me please resolve this issue?
It's a brand new Lenovo all in one PC.all the details in the screenshot attached.
Browsing on the net is my only usage and yet the pc is very slow.trying different types of browsers didn't really helped.
Any assistance would be highly appreciated.

Thanks!

Attached Thumbnails

  • Untitled1.jpg

  • 0

Advertisements


#2
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts
Hello and welcome to Geeks to Go! My nickname is Pystryker :) , and I will be helping you with your issue today.

Please note: I am currently in training and all my fixes must be approved by my teacher before being posted. This gives you the advantage of having two people working to solve your problems.

Before we get started, I have a few things I need to go over with you

  • Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process.
  • Please subscribe to this topic. By subscribing, the board will notify you when a new reply is added to your topic. You can find instructions on how to do that by clicking here.
  • If any of your security programs give you a warning about any tool I ask you to use, please do not worry. All the links and tools I provide to you will be safe.

  • Please read through my instructions carefully and completely before executing them.
  • Please make sure that all the programs I ask you to download are downloaded to and run from your Desktop.
  • Please make sure you print out these instructions so that you will be able to refer to them while working on your machine. Part of the solution(s) to your problem may involve us working in Safe Mode and you will need them to go by.
  • Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
  • Please read through my instructions carefully and make sure you complete them from start to finish. I will make sure that I lay the instructions out in a step by step order to make them easy to follow
  • This is a complicated process. It requires several steps, patience, and careful following of my instructions in the order they are given to diagnose your problems to get your machine back in working order.
  • Please stay with me until the end of all steps and procedures and I declare your system clean. Just because there is a lack of symptoms does not indicate a clean machine. I promise to do the same for you.
  • Please make sure you reply within 3 days to my responses, if there is no reply within 3 days, the topic will be closed and you will need to request the topic be reopened.
  • Before we get started, please remember we will do our best to get your machine repaired. However, there are some cases where the only solution is a reformat and reinstall of the operating system. This is a worst case scenario though.
  • It is impossible for me to know what interactions may happen between your computer's software and the tools we will use to clean your machine. Therefore, I highly recommend you backup any critical personal files on your machine before we start.
  • If possible, please have your original Windows installation disks handy, just in case.
  • If you have any questions at all, please don't hesitate to ask. There's no such thing as a stupid question when dealing with malware.
  • If you are unsure of an instruction I give you, or if something unexepected occurs, Do NOT proceed! Stop and ask for clarification of the instruction or tell me what occurred.
  • Please copy and paste the contents of any requested logs in your replies. Do not attach the log files in your replies unless requested to do so.
  • Please remember, the fixes are for your machine and your machine ONLY!



Once we have cleaned your machine, we'll have some cleanup and prevention steps to go through. We will also provide you with some information about how to reduce your chances of infection and get some protections in place to help defend you against this in the future

Please be patient while I am analyzing your logs. I know you are probably scared and very frustrated with this problem, but I am a volunteer and sometimes life does get in the way. :)

Now, let's get started, shall we? :thumbsup:


Let's get a look at your system and see if there's anything nefarious going on. Please follow the instructions below:

Please disable your antivirus for the duration of my instructions. Don't forget to re-enable them after you have completed the steps.


Step 1: Scan with Farbar's Recovery Scan Tool


Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.


Step 2: Scan with aswMBR


  • Please download aswMBR.exe to your desktop.
  • Double click the file to run it.
  • It will ask if you want to download the latest Avast! virus definitions, please answer yes.

Posted Image

  • Click the Scan button to begin the scan.

Posted Image

  • Once the scan has finished, click on Save Log, save it to your desktop as asw.txt, and please post it in your next reply.
  • Click Exit


Things I need to see in your next post:

FRST Log

Additions.txt Log

aswMBR Log

  • 0

#3
assaf1

assaf1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts

Hello and welcome to Geeks to Go! My nickname is Pystryker :) , and I will be helping you with your issue today.

Please note: I am currently in training and all my fixes must be approved by my teacher before being posted. This gives you the advantage of having two people working to solve your problems.

Before we get started, I have a few things I need to go over with you

  • Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process.
  • Please subscribe to this topic. By subscribing, the board will notify you when a new reply is added to your topic. You can find instructions on how to do that by clicking here.
  • If any of your security programs give you a warning about any tool I ask you to use, please do not worry. All the links and tools I provide to you will be safe.

  • Please read through my instructions carefully and completely before executing them.
  • Please make sure that all the programs I ask you to download are downloaded to and run from your Desktop.
  • Please make sure you print out these instructions so that you will be able to refer to them while working on your machine. Part of the solution(s) to your problem may involve us working in Safe Mode and you will need them to go by.
  • Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
  • Please read through my instructions carefully and make sure you complete them from start to finish. I will make sure that I lay the instructions out in a step by step order to make them easy to follow
  • This is a complicated process. It requires several steps, patience, and careful following of my instructions in the order they are given to diagnose your problems to get your machine back in working order.
  • Please stay with me until the end of all steps and procedures and I declare your system clean. Just because there is a lack of symptoms does not indicate a clean machine. I promise to do the same for you.
  • Please make sure you reply within 3 days to my responses, if there is no reply within 3 days, the topic will be closed and you will need to request the topic be reopened.
  • Before we get started, please remember we will do our best to get your machine repaired. However, there are some cases where the only solution is a reformat and reinstall of the operating system. This is a worst case scenario though.
  • It is impossible for me to know what interactions may happen between your computer's software and the tools we will use to clean your machine. Therefore, I highly recommend you backup any critical personal files on your machine before we start.
  • If possible, please have your original Windows installation disks handy, just in case.
  • If you have any questions at all, please don't hesitate to ask. There's no such thing as a stupid question when dealing with malware.
  • If you are unsure of an instruction I give you, or if something unexepected occurs, Do NOT proceed! Stop and ask for clarification of the instruction or tell me what occurred.
  • Please copy and paste the contents of any requested logs in your replies. Do not attach the log files in your replies unless requested to do so.
  • Please remember, the fixes are for your machine and your machine ONLY!



Once we have cleaned your machine, we'll have some cleanup and prevention steps to go through. We will also provide you with some information about how to reduce your chances of infection and get some protections in place to help defend you against this in the future

Please be patient while I am analyzing your logs. I know you are probably scared and very frustrated with this problem, but I am a volunteer and sometimes life does get in the way. :)

Now, let's get started, shall we? :thumbsup:


Let's get a look at your system and see if there's anything nefarious going on. Please follow the instructions below:

Please disable your antivirus for the duration of my instructions. Don't forget to re-enable them after you have completed the steps.


Step 1: Scan with Farbar's Recovery Scan Tool


Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.


Step 2: Scan with aswMBR


  • Please download aswMBR.exe to your desktop.
  • Double click the file to run it.
  • It will ask if you want to download the latest Avast! virus definitions, please answer yes.

Posted Image

  • Click the Scan button to begin the scan.

Posted Image

  • Once the scan has finished, click on Save Log, save it to your desktop as asw.txt, and please post it in your next reply.
  • Click Exit


Things I need to see in your next post:

FRST Log

Additions.txt Log

aswMBR Log


  • 0

#4
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts
Have you run the requested scans? :) Is there something in my instructions that you need assistance with?
  • 0

#5
assaf1

assaf1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Hi Pystryker,

Many thanks for the fast reply!

please fine the attached files you've asked for.

Many thanks!

shlomi

Attached Files


  • 0

#6
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Hi Pystryker,

Many thanks for the fast reply!

please fine the attached files you've asked for.

Many thanks!


Hello :) You are welcome, glad I can be of assistance. :thumbsup:

One thing I need you to do when posting the logs is post them in the body of the message. It makes it easier to analyze them. :) I'll post these and get to work on them asap. :thumbsup



Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2014 01
Ran by Shlomi (administrator) on SHLOMI-PC on 22-02-2014 22:20:17
Running from C:\Users\Shlomi\Desktop
Windows 8.1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\WINDOWS\system32\atiesrxx.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft) C:\Program Files (x86)\Lenovo\Lenovo Dashboard\DdMgr.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft) C:\Program Files (x86)\Lenovo\EducationPortal\Services\IdeaTouch.LocalDataServer.Education.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\windows\SysWOW64\NLSSRV32.EXE
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Pokki) C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Primax Electronics Ltd.) C:\Program Files\Lenovo\Lenovo Black Silk USB Keyboard\Pelico.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Pokki) C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Free Time) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe
(Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-30] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor)
HKLM\...\Run: [Lenovo Black Silk Input Device Main Program] - C:\Program Files\Lenovo\Lenovo Black Silk USB Keyboard\Pelico.exe [118272 2011-04-19] (Primax Electronics Ltd.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-04-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LVT] - C:\Program Files\Lenovo\LVT\LJYZ.exe [886112 2011-11-24] (Lenovo)
HKLM-x32\...\Run: [Lenovo Eye Distance System] - C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe [270680 2012-07-19] (Lenovo)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-05] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [Lenovo Dynamic Brightness System] - C:\Program Files\Lenovo\Lenovo Brightness System\RunLDBS.exe [1753432 2012-09-18] (Lenovo)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-01-31] (AVAST Software)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2014-02-02] (RealNetworks, Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [20131224] - C:\Program Files\AVAST Software\Avast\setup\emupdate\0469b657-0fe5-4248-90d0-a61dafd387a6.exe /check [181136 2014-02-21] (AVAST Software)
HKU\S-1-5-21-424950133-3584039098-4252772914-1002\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-01-31] (Google Inc.)
HKU\S-1-5-21-424950133-3584039098-4252772914-1002\...\RunOnce: [Application Restart #2] - C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe [8285512 2013-12-05] (Pokki)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ynet.co.il/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://home.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKLM - {F0CA0484-E725-4EC5-ACE7-C9F3A5A7BC7D} URL = http://www.bing.com/...E10TR&pc=MALNJS
SearchScopes: HKLM-x32 - {F0CA0484-E725-4EC5-ACE7-C9F3A5A7BC7D} URL = http://www.bing.com/...E10TR&pc=MALNJS
SearchScopes: HKCU - {F0CA0484-E725-4EC5-ACE7-C9F3A5A7BC7D} URL =
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095}
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.57.2.5 192.168.123.254

FireFox:
========
FF ProfilePath: C:\Users\Shlomi\AppData\Roaming\Mozilla\Firefox\Profiles\i4qccxnu.default
FF Homepage: www.ynet.co.il
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @exent.com/npExentControl,version=7.1.0.1 - C:\Program Files (x86)\FreeRide Games\npExentControl.dll (Exent Technologies Ltd.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Ant Video Downloader - C:\Users\Shlomi\AppData\Roaming\Mozilla\Firefox\Profiles\i4qccxnu.default\Extensions\[email protected] [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-31]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-02-02]

Chrome:
=======
CHR HomePage: hxxp://www.ynet.co.il/home/0,7340,L-8,00.html
CHR DefaultSearchKeyword: google.co.il
CHR Extension: (Google Docs) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-31]
CHR Extension: (Google Drive) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-31]
CHR Extension: (YouTube) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-31]
CHR Extension: (Google Search) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-31]
CHR Extension: (Block Yourself from Analytics) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgflmigmogfionelcpalhohefbnehm [2014-02-01]
CHR Extension: (avast! Online Security) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-31]
CHR Extension: (RealDownloader) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-02-02]
CHR Extension: (FastestFox for Chrome) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm [2014-02-01]
CHR Extension: (Google Wallet) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-31]
CHR Extension: (Gmail) - C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-31]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-01-31]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]

==================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-18] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-31] (AVAST Software)
R2 Dashboard Service; C:\Program Files (x86)\Lenovo\Lenovo Dashboard\DdMgr.exe [25936 2013-03-22] (Microsoft)
R2 IdeaTouch.LocalDataServer.Education; C:\Program Files (x86)\Lenovo\EducationPortal\Services\IdeaTouch.LocalDataServer.Education.exe [7680 2012-05-17] (Microsoft)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-26] ()
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-12-14] (Nitro PDF Software)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [78648 2014-01-31] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2014-01-31] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-31] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1038072 2014-01-31] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [421704 2014-01-31] (AVAST Software)
R3 aswStm; C:\windows\system32\drivers\aswStm.sys [80184 2014-01-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-31] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [94208 2013-02-14] (Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows ® Win 7 DDK provider)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows ® Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows ® Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-02-04] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288328 2013-01-23] (Realtek Semiconductor Corp.)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-02-04] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
R3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
R3 VMC412; C:\Windows\System32\Drivers\VMC412.sys [232576 2012-09-24] (Vimicro Corporation)
R3 vmuacflt; C:\Windows\System32\Drivers\vmuacflt.sys [15872 2013-04-22] (Vimicro Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
R0 WinI2C-DDC; C:\Windows\System32\drivers\DDCDrv.sys [20832 2008-04-08] (Nicomsoft Ltd.)
R0 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [15712 2010-03-23] (Nicomsoft Ltd.)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
R2 X5XSEx_Pr148; C:\Program Files (x86)\FreeRide Games\X5XSEx_Pr148.Sys [56136 2012-08-03] (Exent Technologies Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-22 22:20 - 2014-02-22 22:20 - 00022108 ____C () C:\Users\Shlomi\Desktop\FRST.txt
2014-02-22 22:19 - 2014-02-22 22:20 - 00000000 ___DC () C:\FRST
2014-02-22 22:15 - 2014-02-22 22:16 - 02154496 _____ (Farbar) C:\Users\Shlomi\Desktop\FRST64.exe
2014-02-21 16:46 - 2014-02-21 16:46 - 00118149 ____C () C:\Users\Shlomi\Downloads\wmpChrome.crx
2014-02-20 21:35 - 2014-02-20 21:35 - 17858952 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2014-02-15 11:25 - 2014-02-15 11:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-14 00:16 - 2012-08-01 21:16 - 427196718 ____C () C:\Users\Shlomi\Desktop\Extreme Engineering 1x07 Building Hong Kong's Airport - YouTube.mp4
2014-02-14 00:16 - 2012-08-01 21:16 - 217844079 ____C () C:\Users\Shlomi\Desktop\Extreme Engineering 1x07 Building Hong Kong's Airport - YouTube.flv
2014-02-12 09:09 - 2014-01-07 07:00 - 02397184 ____C (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2014-02-12 09:09 - 2014-01-07 06:30 - 02071552 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2014-02-12 09:09 - 2013-12-09 02:27 - 02152448 ____C (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-02-12 09:09 - 2013-12-09 02:19 - 00570880 ____C (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2014-02-12 09:09 - 2013-12-09 01:55 - 00444928 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll
2014-02-12 09:09 - 2013-12-09 01:54 - 01317376 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-02-12 09:09 - 2013-11-21 08:42 - 04604416 ____C (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2014-02-12 09:09 - 2013-11-21 07:44 - 03936256 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2014-02-12 09:08 - 2014-02-06 14:16 - 23170048 ____C (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-12 09:08 - 2014-02-06 13:30 - 02724864 ____C (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-02-12 09:08 - 2014-02-06 13:30 - 00004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-02-12 09:08 - 2014-02-06 13:12 - 02765824 ____C (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-12 09:08 - 2014-02-06 13:07 - 00066048 ____C (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-02-12 09:08 - 2014-02-06 13:06 - 00048640 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-02-12 09:08 - 2014-02-06 12:57 - 00053760 ____C (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-12 09:08 - 2014-02-06 12:56 - 00033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-02-12 09:08 - 2014-02-06 12:49 - 00139264 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-02-12 09:08 - 2014-02-06 12:48 - 00708608 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-02-12 09:08 - 2014-02-06 12:48 - 00111616 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-02-12 09:08 - 2014-02-06 12:38 - 17103872 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-02-12 09:08 - 2014-02-06 12:32 - 00218624 ____C (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-12 09:08 - 2014-02-06 12:20 - 02724864 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-02-12 09:08 - 2014-02-06 12:17 - 00195584 ____C (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-02-12 09:08 - 2014-02-06 12:11 - 05768704 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-02-12 09:08 - 2014-02-06 12:01 - 00061952 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-02-12 09:08 - 2014-02-06 12:00 - 00051200 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-02-12 09:08 - 2014-02-06 11:57 - 02168320 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-02-12 09:08 - 2014-02-06 11:57 - 00627200 ____C (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-12 09:08 - 2014-02-06 11:52 - 00043008 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-02-12 09:08 - 2014-02-06 11:52 - 00032768 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-02-12 09:08 - 2014-02-06 11:50 - 02041856 ____C (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-12 09:08 - 2014-02-06 11:47 - 00112128 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-02-12 09:08 - 2014-02-06 11:46 - 00553472 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-02-12 09:08 - 2014-02-06 11:25 - 04244480 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-02-12 09:08 - 2014-02-06 11:25 - 00164864 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-02-12 09:08 - 2014-02-06 11:24 - 02334208 ____C (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-12 09:08 - 2014-02-06 11:22 - 13051392 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-12 09:08 - 2014-02-06 11:13 - 00524288 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-02-12 09:08 - 2014-02-06 11:09 - 01964032 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-02-12 09:08 - 2014-02-06 11:03 - 11266048 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-02-12 09:08 - 2014-02-06 10:55 - 01393664 ____C (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-12 09:08 - 2014-02-06 10:41 - 01820160 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-02-12 09:08 - 2014-02-06 10:40 - 00817664 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-02-12 09:08 - 2014-02-06 10:36 - 01156096 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-02-12 09:08 - 2014-02-06 10:34 - 00703488 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-02-12 09:07 - 2014-01-04 22:50 - 01462216 ____C (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-02-12 09:07 - 2014-01-04 21:22 - 01202888 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-02-12 09:07 - 2014-01-04 16:30 - 13209088 ____C (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-02-12 09:07 - 2014-01-04 16:23 - 11702272 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-02-12 09:07 - 2014-01-04 15:42 - 01105408 ____C (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-02-12 09:07 - 2014-01-04 15:40 - 07416832 ____C (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-02-12 09:07 - 2014-01-04 15:36 - 00830976 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-02-12 09:07 - 2014-01-04 15:28 - 04961792 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-02-12 09:07 - 2013-12-21 04:10 - 00009701 ____C () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms
2014-02-12 09:07 - 2013-12-21 04:10 - 00009701 ____C () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms
2014-02-12 09:07 - 2013-12-09 04:57 - 00548864 ____C (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-02-12 09:07 - 2013-12-09 03:51 - 00454656 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-02-12 09:06 - 2014-01-07 09:03 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2014-02-12 09:06 - 2014-01-07 07:59 - 00017408 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2014-02-12 09:06 - 2013-12-20 12:10 - 01113040 ____C (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-02-12 09:06 - 2013-12-20 08:13 - 00835584 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-02-12 09:05 - 2014-01-09 10:25 - 02804224 ____C (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-02-12 09:05 - 2014-01-09 09:59 - 01020928 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-02-12 09:05 - 2014-01-09 09:59 - 00115712 ____C (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-02-12 09:05 - 2014-01-09 09:49 - 00919040 ____C (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-02-12 09:05 - 2014-01-09 09:44 - 00720384 ____C (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-02-12 09:05 - 2014-01-09 09:43 - 00121344 ____C (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-02-12 09:05 - 2014-01-09 09:29 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-02-12 09:05 - 2014-01-09 09:28 - 04217344 ____C (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-02-12 09:05 - 2014-01-09 09:28 - 00628736 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-02-12 09:05 - 2014-01-09 09:18 - 00870912 ____C (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-02-10 23:29 - 2014-02-10 23:29 - 00002050 ____C () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-02-10 22:08 - 2014-02-10 22:08 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Nitro
2014-02-09 23:06 - 2014-02-09 23:06 - 00000000 ____D () C:\Users\Shlomi\AppData\Local\Macromedia
2014-02-09 23:03 - 2014-02-16 23:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-09 23:03 - 2014-02-09 23:04 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Mozilla
2014-02-09 23:03 - 2014-02-09 23:04 - 00000000 ____D () C:\Users\Shlomi\AppData\Local\Mozilla
2014-02-09 23:03 - 2014-02-09 23:03 - 00001170 ____C () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-02-09 23:03 - 2014-02-09 23:03 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-09 22:47 - 2014-02-09 22:47 - 00001852 ____C () C:\Users\Public\Desktop\Opera.lnk
2014-02-09 22:47 - 2014-02-09 22:47 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Opera
2014-02-09 22:47 - 2014-02-09 22:47 - 00000000 ____D () C:\Users\Shlomi\AppData\Local\Opera
2014-02-09 22:47 - 2014-02-09 22:47 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-09 22:45 - 2014-02-09 22:46 - 13156120 ____C (Opera Software ASA) C:\Users\Shlomi\Downloads\Opera_1216_int_Setup.exe
2014-02-05 04:47 - 2014-02-05 04:47 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-05 04:47 - 2014-02-05 04:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-04 09:08 - 2014-02-04 09:08 - 00000000 _SHDC () C:\Recovery
2014-02-04 09:08 - 2014-02-03 23:44 - 00000000 ___DC () C:\WINDOWS\Panther
2014-02-04 09:06 - 2014-02-04 09:06 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2014-02-04 09:06 - 2014-02-04 09:06 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-02-04 09:05 - 2014-02-04 09:05 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01642016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2014-02-04 09:03 - 2014-02-04 09:03 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 01506680 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2014-02-04 09:03 - 2014-02-04 09:03 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00372568 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2014-02-04 09:03 - 2014-02-04 09:03 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2014-02-04 09:01 - 2014-02-04 09:01 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-02-04 08:58 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-02-04 08:58 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files\MSBuild
2014-02-04 08:58 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-02-04 08:58 - 2014-02-03 23:27 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-02-04 08:57 - 2013-08-03 06:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2014-02-04 08:57 - 2013-08-03 06:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2014-02-04 08:57 - 2013-08-03 06:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-02-04 08:57 - 2013-08-03 06:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2014-02-04 08:57 - 2013-08-03 06:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-02-04 08:57 - 2013-08-03 06:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2014-02-04 01:03 - 2013-12-09 02:34 - 01227264 ____C (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-02-04 01:03 - 2013-12-09 02:04 - 00980480 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-02-04 01:03 - 2013-11-27 17:34 - 03210528 ____C (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2014-02-04 01:03 - 2013-11-27 17:27 - 00809872 ____C (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-02-04 01:03 - 2013-11-27 16:00 - 00663680 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-02-04 01:03 - 2013-11-27 15:47 - 02804528 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2014-02-04 01:03 - 2013-11-27 14:02 - 00142848 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys
2014-02-04 01:03 - 2013-11-27 12:54 - 00461824 ____C (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-02-04 01:03 - 2013-11-27 12:24 - 00306688 ____C (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll
2014-02-04 01:03 - 2013-11-27 12:08 - 00336384 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-02-04 01:03 - 2013-11-27 11:46 - 00273920 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll
2014-02-04 01:03 - 2013-11-27 11:41 - 00136704 ____C (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2014-02-04 01:03 - 2013-11-27 11:17 - 00263168 ____C (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2014-02-04 01:03 - 2013-11-27 11:10 - 00273408 ____C (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2014-02-04 01:03 - 2013-11-27 10:58 - 01503232 ____C (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-02-04 01:03 - 2013-11-27 10:56 - 00218112 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2014-02-04 01:03 - 2013-11-27 06:01 - 00385614 ____C () C:\WINDOWS\system32\ApnDatabase.xml
2014-02-04 01:03 - 2013-11-26 15:22 - 01928144 ____C (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2014-02-04 01:03 - 2013-11-26 15:20 - 02131120 ____C (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-02-04 01:03 - 2013-11-26 15:20 - 01399176 ____C (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-02-04 01:03 - 2013-11-26 15:20 - 01374384 ____C (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-02-04 01:03 - 2013-11-26 13:50 - 01371312 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2014-02-04 01:03 - 2013-11-26 13:44 - 02142936 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-02-04 01:03 - 2013-11-26 13:44 - 01204968 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2014-02-04 01:03 - 2013-11-26 12:13 - 04191232 ____C (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-02-04 01:03 - 2013-11-26 11:21 - 18577920 ____C (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-02-04 01:03 - 2013-11-26 10:28 - 13925888 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-02-04 01:03 - 2013-11-25 03:45 - 00142680 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-02-04 01:03 - 2013-11-25 03:32 - 01119064 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2014-02-04 01:03 - 2013-11-25 01:30 - 00513536 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-02-04 01:03 - 2013-11-25 01:28 - 00589824 ____C (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-02-04 01:03 - 2013-11-23 14:47 - 00032088 ____C (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-02-04 01:03 - 2013-11-23 13:49 - 21196664 ____C (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-02-04 01:03 - 2013-11-23 10:19 - 18642504 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-02-04 01:03 - 2013-11-23 09:13 - 00024064 ____C (Microsoft Corporation) C:\WINDOWS\system32\bi.dll
2014-02-04 01:03 - 2013-11-23 09:13 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys
2014-02-04 01:03 - 2013-11-23 09:08 - 00403456 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-02-04 01:03 - 2013-11-23 06:50 - 00282112 ____C (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-02-04 01:03 - 2013-11-23 05:57 - 00637952 ____C (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2014-02-04 01:03 - 2013-11-23 05:48 - 00479744 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2014-02-04 01:03 - 2013-11-23 05:25 - 00744448 ____C (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2014-02-04 01:03 - 2013-11-23 05:25 - 00584192 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2014-02-04 01:03 - 2013-11-23 05:19 - 02617344 ____C (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-02-04 01:03 - 2013-11-23 05:15 - 02295808 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-02-04 01:03 - 2013-11-21 08:58 - 00207872 ____C (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll
2014-02-04 01:03 - 2013-11-21 08:26 - 01415680 ____C (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-02-04 01:03 - 2013-11-16 07:11 - 00764856 ____C (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-02-04 01:03 - 2013-11-15 20:19 - 00669344 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-02-04 01:03 - 2013-11-15 16:59 - 00470016 ____C (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2014-02-04 01:03 - 2013-11-15 16:25 - 00433664 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2014-02-04 01:03 - 2013-11-15 16:08 - 00202240 ____C (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-02-04 01:03 - 2013-11-15 15:24 - 00834048 ____C (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-02-04 01:03 - 2013-11-05 22:12 - 02551128 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-02-04 01:03 - 2013-10-31 02:29 - 00745336 ____C (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-02-04 01:03 - 2013-10-31 01:41 - 00552624 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-02-04 00:02 - 2014-01-19 09:38 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-02-03 23:55 - 2014-02-03 23:55 - 00003118 _____ () C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2014-02-03 23:55 - 2014-02-03 23:55 - 00003092 _____ () C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2014-02-03 23:55 - 2014-02-03 23:55 - 00003090 _____ () C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2014-02-03 23:54 - 2014-02-03 23:54 - 00003062 _____ () C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2014-02-03 23:54 - 2014-02-03 23:54 - 00003060 _____ () C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2014-02-03 23:53 - 2014-02-03 23:53 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center
2014-02-03 23:47 - 2014-02-17 22:40 - 00000000 __RDO () C:\Users\Shlomi\SkyDrive
2014-02-03 23:44 - 2014-02-03 23:44 - 00001453 _____ () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-03 23:44 - 2014-02-03 23:44 - 00000020 ___SH () C:\Users\Shlomi\ntuser.ini
2014-02-03 23:35 - 2014-02-22 12:01 - 01957160 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-03 23:34 - 2014-02-03 23:34 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-02-03 23:18 - 2014-02-03 23:18 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
2014-02-03 23:16 - 2014-02-03 23:47 - 00000000 ____D () C:\Users\Shlomi
2014-02-03 23:16 - 2014-02-03 23:34 - 00024768 _____ () C:\WINDOWS\diagwrn.xml
2014-02-03 23:16 - 2014-02-03 23:34 - 00024768 _____ () C:\WINDOWS\diagerr.xml
2014-02-03 23:16 - 2014-02-03 23:18 - 00000000 ___RD () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-02-03 23:16 - 2014-02-03 23:18 - 00000000 ___RD () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-02-03 23:16 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-02-03 23:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ___DC () C:\AMD
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\WINDOWS\VMC412
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\Program Files\Realtek
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\Program Files\AMD
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 _____ () C:\WINDOWS\system32\spu_storage.bin
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin
2014-02-03 22:28 - 2014-02-03 23:34 - 00006696 ____C () C:\WINDOWS\comsetup.log
2014-02-03 20:47 - 2014-02-17 22:37 - 00000059 ____C () C:\Users\Shlomi\Desktop\1.אסא.txt
2014-02-02 23:46 - 2014-02-17 22:40 - 00003366 _____ () C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-02 23:46 - 2014-02-17 22:40 - 00003312 _____ () C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-02 23:45 - 2014-02-02 23:45 - 00003386 ____C () C:\WINDOWS\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-02 23:03 - 2014-02-15 23:06 - 00003344 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-02 23:03 - 2014-02-15 23:06 - 00003290 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-02 23:01 - 2014-02-02 23:01 - 457815770 _____ () C:\WINDOWS\MEMORY.DMP
2014-02-02 22:00 - 2014-02-02 22:00 - 00000000 ___HC () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-02-02 21:54 - 2014-02-02 22:00 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Apple Computer
2014-02-02 21:54 - 2014-02-02 21:54 - 00001794 ____C () C:\Users\Public\Desktop\iTunes.lnk
2014-02-02 21:54 - 2014-02-02 21:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Apple Computer
2014-02-02 21:54 - 2012-08-21 13:01 - 00033240 ____C (GEAR Software Inc.) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2014-02-02 21:52 - 2014-02-02 21:53 - 00000000 ___DC () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-02-02 21:52 - 2014-02-02 21:53 - 00000000 ___DC () C:\Program Files\iTunes
2014-02-02 21:52 - 2014-02-02 21:53 - 00000000 ___DC () C:\Program Files (x86)\iTunes
2014-02-02 21:52 - 2014-02-02 21:52 - 00000000 ___DC () C:\ProgramData\Apple Computer
2014-02-02 21:52 - 2014-02-02 21:52 - 00000000 ___DC () C:\Program Files\iPod
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\WINDOWS\System32\Tasks\Apple
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Apple
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\Program Files\Common Files\Apple
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\Program Files (x86)\Apple Software Update
2014-02-02 21:49 - 2014-02-02 21:50 - 00000000 ___DC () C:\ProgramData\Apple
2014-02-02 21:49 - 2014-02-02 21:49 - 00000000 ___DC () C:\Program Files\Bonjour
2014-02-02 21:49 - 2014-02-02 21:49 - 00000000 ___DC () C:\Program Files (x86)\Bonjour
2014-02-02 19:41 - 2014-02-02 19:41 - 00001275 ____C () C:\Users\Public\Desktop\RealPlayer.lnk
2014-02-02 19:41 - 2014-02-02 19:41 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\RealNetworks
2014-02-02 19:40 - 2014-02-02 19:41 - 00000000 ___DC () C:\Program Files (x86)\RealNetworks
2014-02-02 19:40 - 2014-02-02 19:40 - 00272896 ____C (Progressive Networks) C:\WINDOWS\SysWOW64\pncrt.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00201872 ____C (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\rmoc3260.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00006656 ____C (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\pndx5016.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00005632 ____C (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\pndx5032.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00000000 ___DC () C:\ProgramData\RealNetworks
2014-02-02 19:40 - 2014-02-02 19:40 - 00000000 ___DC () C:\Program Files (x86)\Real
2014-02-02 19:39 - 2014-02-11 00:55 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Real
2014-02-02 19:37 - 2014-02-02 19:41 - 00000000 ___DC () C:\ProgramData\Real
2014-02-02 01:19 - 2014-02-02 01:19 - 00000000 ___DC () C:\ProgramData\WEBREG
2014-02-02 01:18 - 2014-02-02 01:20 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\HP
2014-02-02 01:18 - 2014-02-02 01:18 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\HP
2014-02-02 01:14 - 2014-02-03 23:25 - 00000000 ___DC () C:\WINDOWS\SysWOW64\spool
2014-02-02 01:14 - 2014-02-02 01:14 - 00001108 ____C () C:\Users\Public\Desktop\HP Photo Creations.lnk
2014-02-02 01:14 - 2014-02-02 01:14 - 00000000 ___DC () C:\ProgramData\HP Photo Creations
2014-02-02 01:14 - 2014-02-02 01:14 - 00000000 ___DC () C:\Program Files (x86)\HP Photo Creations
2014-02-02 01:13 - 2014-02-09 01:20 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\HpUpdate
2014-02-02 01:12 - 2014-02-02 01:12 - 00001326 ____C () C:\Users\Public\Desktop\HP Solution Center.lnk
2014-02-02 01:12 - 2014-02-02 01:12 - 00000000 ___DC () C:\ProgramData\HP Product Assistant
2014-02-02 01:11 - 2014-02-02 01:11 - 00001172 ____C () C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2014-02-02 01:07 - 2014-02-02 01:14 - 00000000 ___DC () C:\Program Files (x86)\HP
2014-02-02 01:06 - 2014-02-02 01:19 - 00203610 ____C () C:\WINDOWS\hpoins19.dat
2014-02-02 01:06 - 2014-02-02 01:19 - 00000832 ____C () C:\ProgramData\hpzinstall.log
2014-02-02 01:06 - 2012-10-14 14:03 - 00015561 ____C () C:\WINDOWS\hpomdl19.dat
2014-02-02 01:05 - 2009-07-08 12:51 - 00861184 _____ (Hewlett-Packard) C:\WINDOWS\system32\hpowiav1.dll
2014-02-02 01:05 - 2009-07-08 12:51 - 00730624 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpotscl1.dll
2014-02-02 01:05 - 2009-07-08 12:51 - 00498176 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpovst01.dll
2014-02-01 23:50 - 2014-02-01 23:50 - 00847344 ____C (Google Inc.) C:\Users\Shlomi\Downloads\ChromeSetup (1).exe
2014-02-01 23:49 - 2014-02-01 23:49 - 00847344 ____C (Google Inc.) C:\Users\Shlomi\Downloads\ChromeSetup.exe
2014-02-01 21:50 - 2014-02-22 12:32 - 00000000 ___DC () C:\FFOutput
2014-02-01 21:48 - 2014-02-03 23:27 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-02-01 21:48 - 2014-02-01 21:48 - 00001209 ____C () C:\Users\Shlomi\Desktop\Format Factory.lnk
2014-02-01 21:47 - 2014-02-01 21:47 - 00000000 ___DC () C:\Program Files (x86)\FreeTime
2014-02-01 21:43 - 2014-02-01 21:45 - 58014512 ____C (Free Time) C:\Users\Shlomi\Downloads\FFSetup3-3-1-0.exe
2014-02-01 21:12 - 2014-02-03 23:27 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-02-01 21:12 - 2014-02-01 21:12 - 00001117 ____C () C:\Users\Public\Desktop\Picasa 3.lnk
2014-02-01 21:10 - 2014-02-01 21:11 - 17660184 ____C (Google Inc.) C:\Users\Shlomi\Downloads\picasa39-setup.exe
2014-02-01 20:50 - 2014-02-02 01:20 - 00000000 ___DC () C:\ProgramData\HP
2014-02-01 20:49 - 2014-02-01 20:49 - 02338824 ____C () C:\Users\Shlomi\Downloads\hppiw.exe
2014-02-01 15:41 - 2014-02-22 16:40 - 00390144 __SHC () C:\Users\Shlomi\Desktop\Thumbs.db
2014-02-01 00:43 - 2014-02-13 21:50 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Skype
2014-02-01 00:43 - 2014-02-01 00:43 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Skype
2014-02-01 00:42 - 2014-02-01 00:42 - 00002697 ____C () C:\Users\Public\Desktop\Skype.lnk
2014-02-01 00:42 - 2014-02-01 00:42 - 00000000 __RDC () C:\Program Files (x86)\Skype
2014-02-01 00:42 - 2014-02-01 00:42 - 00000000 ___DC () C:\ProgramData\Skype
2014-02-01 00:38 - 2014-02-01 00:38 - 00002917 ____C () C:\Users\Shlomi\Desktop\Microsoft Word 2010.lnk
2014-02-01 00:36 - 2014-02-22 21:35 - 00000830 ____C () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-01 00:36 - 2014-02-20 21:35 - 00003718 ____C () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-01-31 21:49 - 2014-02-16 22:17 - 00000000 ___DC () C:\WINDOWS\system32\MRT
2014-01-31 21:49 - 2014-02-16 22:14 - 88567024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-31 21:00 - 2014-01-31 21:00 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Synchronization Services
2014-01-31 20:58 - 2014-01-31 20:58 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Sync Framework
2014-01-31 20:58 - 2014-01-31 20:58 - 00000000 ___DC () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-01-31 20:53 - 2014-01-31 20:53 - 00000000 ___DC () C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-01-31 20:50 - 2014-01-31 20:50 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-01-31 20:49 - 2014-01-31 20:49 - 00000000 ___DC () C:\Program Files\Microsoft Office
2014-01-31 20:47 - 2014-01-31 20:47 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Microsoft Help
2014-01-31 20:47 - 2014-01-31 20:47 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Analysis Services
2014-01-31 20:46 - 2014-02-12 20:12 - 00000000 ___DC () C:\ProgramData\Microsoft Help
2014-01-31 20:45 - 2014-01-31 20:45 - 00000000 _RHDC () C:\MSOCache
2014-01-31 18:32 - 2014-01-31 19:32 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Google
2014-01-31 17:58 - 2014-01-31 17:58 - 00000000 ___HC () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-01-31 13:47 - 2014-01-31 13:47 - 00001977 ____C () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-01-31 13:47 - 2014-01-31 13:47 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\AVAST Software
2014-01-31 13:46 - 2014-02-22 06:02 - 00002214 ____C () C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-31 13:46 - 2014-02-18 13:47 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2014-01-31 13:46 - 2014-01-31 13:46 - 00000000 ___DC () C:\ProgramData\Google
2014-01-31 13:46 - 2014-01-31 13:46 - 00000000 ___DC () C:\Program Files\Google
2014-01-31 13:45 - 2014-02-22 22:02 - 00000918 ____C () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-31 13:45 - 2014-02-22 06:02 - 00000914 ____C () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-31 13:45 - 2014-02-12 05:57 - 00003890 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-31 13:45 - 2014-02-12 05:57 - 00003654 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-31 13:45 - 2014-02-01 21:24 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Google
2014-01-31 13:45 - 2014-02-01 21:11 - 00000000 ___DC () C:\Program Files (x86)\Google
2014-01-31 13:45 - 2014-01-31 13:45 - 01038072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00421704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00334136 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-01-31 13:45 - 2014-01-31 13:45 - 00207904 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00092544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00080184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00078648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00065776 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-01-31 13:45 - 2014-01-31 13:45 - 00000000 ___DC () C:\Program Files\AVAST Software
2014-01-31 13:37 - 2014-01-31 13:37 - 00421704 ____C (AVAST Software) C:\WINDOWS\system32\Drivers\wgvxqvuq.sys
2014-01-31 13:20 - 2014-01-31 13:20 - 00421704 ____C (AVAST Software) C:\WINDOWS\system32\Drivers\njqlkmxh.sys
2014-01-31 13:17 - 2014-01-31 13:44 - 00000000 ___DC () C:\ProgramData\AVAST Software
2014-01-31 13:17 - 2014-01-31 13:17 - 00421704 ____C (AVAST Software) C:\WINDOWS\system32\Drivers\okduzbru.sys
2014-01-31 13:11 - 2014-02-22 22:17 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Pokki
2014-01-31 13:11 - 2014-01-31 13:11 - 00002123 ____C () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-01-31 13:10 - 2014-02-01 00:57 - 00000000 ___DC () C:\ldiag
2014-01-31 13:10 - 2014-01-31 13:17 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\LSC
2014-01-31 13:10 - 2014-01-31 13:10 - 00002002 ____C () C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2014-01-31 13:10 - 2014-01-31 13:10 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\OEMSoftwareEngine
2014-01-31 13:02 - 2014-02-10 23:31 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Adobe
2014-01-31 13:02 - 2014-02-02 01:20 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Nitro PDF
2014-01-31 13:02 - 2014-01-31 13:02 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\LSC
2014-01-31 13:01 - 2014-02-22 06:07 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-424950133-3584039098-4252772914-1002
2014-01-31 12:58 - 2014-01-31 12:58 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\AMD
2014-01-31 12:56 - 2014-01-31 12:56 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\ATI
2014-01-31 12:56 - 2014-01-31 12:56 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\ATI
2014-01-31 12:56 - 2014-01-31 12:56 - 00000000 ___DC () C:\ProgramData\ATI
2014-01-31 12:54 - 2014-02-03 23:45 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2014-01-31 12:54 - 2014-01-31 12:55 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Lenovo
2014-01-31 12:54 - 2014-01-31 12:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Lenovo
2014-01-31 12:54 - 2014-01-31 12:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Power2Go
2014-01-31 12:53 - 2014-02-10 23:31 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Adobe
2014-01-31 12:53 - 2014-02-04 01:13 - 00000000 __RDC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-31 12:53 - 2014-02-04 01:13 - 00000000 __RDC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-31 12:52 - 2014-01-31 12:52 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\VirtualStore
2014-01-31 12:51 - 2014-02-04 05:04 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Packages
2014-01-31 12:51 - 2013-09-15 01:34 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Macromedia

==================== One Month Modified Files and Folders =======

2014-02-22 22:20 - 2014-02-22 22:20 - 00022108 ____C () C:\Users\Shlomi\Desktop\FRST.txt
2014-02-22 22:20 - 2014-02-22 22:19 - 00000000 ___DC () C:\FRST
2014-02-22 22:17 - 2014-01-31 13:11 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Pokki
2014-02-22 22:16 - 2014-02-22 22:15 - 02154496 _____ (Farbar) C:\Users\Shlomi\Desktop\FRST64.exe
2014-02-22 22:02 - 2014-01-31 13:45 - 00000918 ____C () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-22 22:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-02-22 21:35 - 2014-02-01 00:36 - 00000830 ____C () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-22 16:40 - 2014-02-01 15:41 - 00390144 __SHC () C:\Users\Shlomi\Desktop\Thumbs.db
2014-02-22 12:32 - 2014-02-01 21:50 - 00000000 ___DC () C:\FFOutput
2014-02-22 12:01 - 2014-02-03 23:35 - 01957160 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-22 06:07 - 2014-01-31 13:01 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-424950133-3584039098-4252772914-1002
2014-02-22 06:02 - 2014-01-31 13:46 - 00002214 ____C () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-22 06:02 - 2014-01-31 13:45 - 00000914 ____C () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-21 19:48 - 2013-11-14 09:28 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-21 16:46 - 2014-02-21 16:46 - 00118149 ____C () C:\Users\Shlomi\Downloads\wmpChrome.crx
2014-02-20 21:35 - 2014-02-20 21:35 - 17858952 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2014-02-20 21:35 - 2014-02-01 00:36 - 00003718 ____C () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-02-19 22:51 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-02-18 13:47 - 2014-01-31 13:46 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2014-02-17 23:00 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-02-17 23:00 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-17 22:40 - 2014-02-03 23:47 - 00000000 __RDO () C:\Users\Shlomi\SkyDrive
2014-02-17 22:40 - 2014-02-02 23:46 - 00003366 _____ () C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-17 22:40 - 2014-02-02 23:46 - 00003312 _____ () C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-17 22:39 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-17 22:39 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-02-17 22:37 - 2014-02-03 20:47 - 00000059 ____C () C:\Users\Shlomi\Desktop\1.אסא.txt
2014-02-16 23:49 - 2014-02-09 23:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-16 22:17 - 2014-01-31 21:49 - 00000000 ___DC () C:\WINDOWS\system32\MRT
2014-02-16 22:14 - 2014-01-31 21:49 - 88567024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-15 23:06 - 2014-02-02 23:03 - 00003344 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-15 23:06 - 2014-02-02 23:03 - 00003290 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-15 11:25 - 2014-02-15 11:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-15 04:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-02-14 20:28 - 2013-11-14 09:20 - 00006100 _____ () C:\WINDOWS\PFRO.log
2014-02-14 20:26 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-02-14 20:26 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-02-14 20:26 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-02-14 20:26 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-02-14 20:24 - 2013-08-22 16:46 - 00289957 _____ () C:\WINDOWS\setupact.log
2014-02-13 21:50 - 2014-02-01 00:43 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Skype
2014-02-12 20:12 - 2014-01-31 20:46 - 00000000 ___DC () C:\ProgramData\Microsoft Help
2014-02-12 19:59 - 2012-07-26 07:26 - 00000202 ____C () C:\WINDOWS\win.ini
2014-02-12 05:57 - 2014-01-31 13:45 - 00003890 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-12 05:57 - 2014-01-31 13:45 - 00003654 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-11 00:55 - 2014-02-02 19:39 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Real
2014-02-10 23:31 - 2014-01-31 13:02 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Adobe
2014-02-10 23:31 - 2014-01-31 12:53 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Adobe
2014-02-10 23:31 - 2013-09-15 01:34 - 00000000 ___DC () C:\ProgramData\Adobe
2014-02-10 23:29 - 2014-02-10 23:29 - 00002050 ____C () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-02-10 23:28 - 2013-09-15 01:34 - 00000000 ___DC () C:\Program Files (x86)\Adobe
2014-02-10 22:08 - 2014-02-10 22:08 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Nitro
2014-02-09 23:06 - 2014-02-09 23:06 - 00000000 ____D () C:\Users\Shlomi\AppData\Local\Macromedia
2014-02-09 23:04 - 2014-02-09 23:03 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Mozilla
2014-02-09 23:04 - 2014-02-09 23:03 - 00000000 ____D () C:\Users\Shlomi\AppData\Local\Mozilla
2014-02-09 23:03 - 2014-02-09 23:03 - 00001170 ____C () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-02-09 23:03 - 2014-02-09 23:03 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-09 22:47 - 2014-02-09 22:47 - 00001852 ____C () C:\Users\Public\Desktop\Opera.lnk
2014-02-09 22:47 - 2014-02-09 22:47 - 00000000 ____D () C:\Users\Shlomi\AppData\Roaming\Opera
2014-02-09 22:47 - 2014-02-09 22:47 - 00000000 ____D () C:\Users\Shlomi\AppData\Local\Opera
2014-02-09 22:47 - 2014-02-09 22:47 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-09 22:46 - 2014-02-09 22:45 - 13156120 ____C (Opera Software ASA) C:\Users\Shlomi\Downloads\Opera_1216_int_Setup.exe
2014-02-09 01:20 - 2014-02-02 01:13 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\HpUpdate
2014-02-06 17:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2014-02-06 14:16 - 2014-02-12 09:08 - 23170048 ____C (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-06 13:30 - 2014-02-12 09:08 - 02724864 ____C (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-02-06 13:30 - 2014-02-12 09:08 - 00004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-02-06 13:12 - 2014-02-12 09:08 - 02765824 ____C (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-06 13:07 - 2014-02-12 09:08 - 00066048 ____C (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-02-06 13:06 - 2014-02-12 09:08 - 00048640 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-02-06 12:57 - 2014-02-12 09:08 - 00053760 ____C (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-06 12:56 - 2014-02-12 09:08 - 00033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-02-06 12:49 - 2014-02-12 09:08 - 00139264 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-02-06 12:48 - 2014-02-12 09:08 - 00708608 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-02-06 12:48 - 2014-02-12 09:08 - 00111616 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-02-06 12:38 - 2014-02-12 09:08 - 17103872 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-02-06 12:32 - 2014-02-12 09:08 - 00218624 ____C (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-06 12:20 - 2014-02-12 09:08 - 02724864 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-02-06 12:17 - 2014-02-12 09:08 - 00195584 ____C (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-02-06 12:11 - 2014-02-12 09:08 - 05768704 ____C (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-02-06 12:01 - 2014-02-12 09:08 - 00061952 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-02-06 12:00 - 2014-02-12 09:08 - 00051200 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-12 09:08 - 02168320 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-02-06 11:57 - 2014-02-12 09:08 - 00627200 ____C (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-06 11:52 - 2014-02-12 09:08 - 00043008 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-02-06 11:52 - 2014-02-12 09:08 - 00032768 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-02-06 11:50 - 2014-02-12 09:08 - 02041856 ____C (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-06 11:47 - 2014-02-12 09:08 - 00112128 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-02-06 11:46 - 2014-02-12 09:08 - 00553472 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-02-06 11:25 - 2014-02-12 09:08 - 04244480 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-02-06 11:25 - 2014-02-12 09:08 - 00164864 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-02-06 11:24 - 2014-02-12 09:08 - 02334208 ____C (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-06 11:22 - 2014-02-12 09:08 - 13051392 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-06 11:13 - 2014-02-12 09:08 - 00524288 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-02-06 11:09 - 2014-02-12 09:08 - 01964032 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-02-06 11:03 - 2014-02-12 09:08 - 11266048 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-02-06 10:55 - 2014-02-12 09:08 - 01393664 ____C (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-06 10:41 - 2014-02-12 09:08 - 01820160 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-02-06 10:40 - 2014-02-12 09:08 - 00817664 ____C (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-02-06 10:36 - 2014-02-12 09:08 - 01156096 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-02-06 10:34 - 2014-02-12 09:08 - 00703488 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-02-05 04:47 - 2014-02-05 04:47 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-05 04:47 - 2014-02-05 04:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-04 09:08 - 2014-02-04 09:08 - 00000000 _SHDC () C:\Recovery
2014-02-04 09:06 - 2014-02-04 09:06 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2014-02-04 09:06 - 2014-02-04 09:06 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2014-02-04 09:06 - 2013-08-22 17:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
2014-02-04 09:05 - 2014-02-04 09:05 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-02-04 09:05 - 2014-02-04 09:05 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
2014-02-04 09:05 - 2014-02-04 09:05 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2014-02-04 09:05 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-02-04 09:03 - 2014-02-04 09:03 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01642016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2014-02-04 09:03 - 2014-02-04 09:03 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 01506680 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2014-02-04 09:03 - 2014-02-04 09:03 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2014-02-04 09:03 - 2014-02-04 09:03 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00372568 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2014-02-04 09:03 - 2014-02-04 09:03 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-02-04 09:03 - 2014-02-04 09:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-02-04 09:03 - 2014-02-04 09:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2014-02-04 09:01 - 2014-02-04 09:01 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-02-04 08:58 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-02-04 08:58 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files\MSBuild
2014-02-04 08:58 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-02-04 05:04 - 2014-01-31 12:51 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Packages
2014-02-04 01:13 - 2014-01-31 12:53 - 00000000 __RDC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-04 01:13 - 2014-01-31 12:53 - 00000000 __RDC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-04 01:12 - 2013-08-22 16:44 - 00514744 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-04 01:10 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2014-02-04 01:10 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\Dism
2014-02-03 23:55 - 2014-02-03 23:55 - 00003118 _____ () C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2014-02-03 23:55 - 2014-02-03 23:55 - 00003092 _____ () C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2014-02-03 23:55 - 2014-02-03 23:55 - 00003090 _____ () C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2014-02-03 23:54 - 2014-02-03 23:54 - 00003062 _____ () C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2014-02-03 23:54 - 2014-02-03 23:54 - 00003060 _____ () C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2014-02-03 23:53 - 2014-02-03 23:53 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center
2014-02-03 23:52 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\restore
2014-02-03 23:47 - 2014-02-03 23:16 - 00000000 ____D () C:\Users\Shlomi
2014-02-03 23:45 - 2014-01-31 12:54 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2014-02-03 23:44 - 2014-02-04 09:08 - 00000000 ___DC () C:\WINDOWS\Panther
2014-02-03 23:44 - 2014-02-03 23:44 - 00001453 _____ () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-03 23:44 - 2014-02-03 23:44 - 00000020 ___SH () C:\Users\Shlomi\ntuser.ini
2014-02-03 23:35 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Registration
2014-02-03 23:34 - 2014-02-03 23:34 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat
2014-02-03 23:34 - 2014-02-03 23:16 - 00024768 _____ () C:\WINDOWS\diagwrn.xml
2014-02-03 23:34 - 2014-02-03 23:16 - 00024768 _____ () C:\WINDOWS\diagerr.xml
2014-02-03 23:34 - 2014-02-03 22:28 - 00006696 ____C () C:\WINDOWS\comsetup.log
2014-02-03 23:31 - 2013-08-22 17:36 - 00000000 __RHD () C:\Users\Public\Libraries
2014-02-03 23:27 - 2014-02-04 08:58 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-02-03 23:27 - 2014-02-01 21:48 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-02-03 23:27 - 2014-02-01 21:12 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-02-03 23:27 - 2013-11-14 09:17 - 00000000 ____D () C:\WINDOWS\ShellNew
2014-02-03 23:27 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2014-02-03 23:27 - 2013-08-22 15:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-02-03 23:25 - 2014-02-03 23:25 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-02-03 23:25 - 2014-02-02 01:14 - 00000000 ___DC () C:\WINDOWS\SysWOW64\spool
2014-02-03 23:25 - 2013-09-15 00:58 - 00000000 ___DC () C:\WINDOWS\SysWOW64\sda
2014-02-03 23:25 - 2013-08-22 17:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log
2014-02-03 23:25 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2014-02-03 23:25 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME
2014-02-03 23:25 - 2012-07-26 07:37 - 00000000 ___DC () C:\Users\Default.migrated
2014-02-03 23:24 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\IME
2014-02-03 23:24 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-02-03 23:23 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-02-03 23:23 - 2012-10-10 01:10 - 00000000 ___DC () C:\ProgramData\PRICache
2014-02-03 23:18 - 2014-02-03 23:18 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
2014-02-03 23:18 - 2014-02-03 23:16 - 00000000 ___RD () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-02-03 23:18 - 2014-02-03 23:16 - 00000000 ___RD () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-02-03 23:18 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ___DC () C:\AMD
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\WINDOWS\VMC412
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\Program Files\Realtek
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 ____D () C:\Program Files\AMD
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 _____ () C:\WINDOWS\system32\spu_storage.bin
2014-02-03 23:10 - 2014-02-03 23:10 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin
2014-02-03 23:09 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
2014-02-03 22:50 - 2013-09-15 00:53 - 01981838 ____C () C:\WINDOWS\WindowsUpdate (1).log
2014-02-03 21:56 - 2012-07-26 10:12 - 00000000 ___DC () C:\WINDOWS\AUInstallAgent
2014-02-02 23:45 - 2014-02-02 23:45 - 00003386 ____C () C:\WINDOWS\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002
2014-02-02 23:01 - 2014-02-02 23:01 - 457815770 _____ () C:\WINDOWS\MEMORY.DMP
2014-02-02 22:00 - 2014-02-02 22:00 - 00000000 ___HC () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-02-02 22:00 - 2014-02-02 21:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Apple Computer
2014-02-02 21:54 - 2014-02-02 21:54 - 00001794 ____C () C:\Users\Public\Desktop\iTunes.lnk
2014-02-02 21:54 - 2014-02-02 21:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Apple Computer
2014-02-02 21:53 - 2014-02-02 21:52 - 00000000 ___DC () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-02-02 21:53 - 2014-02-02 21:52 - 00000000 ___DC () C:\Program Files\iTunes
2014-02-02 21:53 - 2014-02-02 21:52 - 00000000 ___DC () C:\Program Files (x86)\iTunes
2014-02-02 21:52 - 2014-02-02 21:52 - 00000000 ___DC () C:\ProgramData\Apple Computer
2014-02-02 21:52 - 2014-02-02 21:52 - 00000000 ___DC () C:\Program Files\iPod
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\WINDOWS\System32\Tasks\Apple
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Apple
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\Program Files\Common Files\Apple
2014-02-02 21:50 - 2014-02-02 21:50 - 00000000 ___DC () C:\Program Files (x86)\Apple Software Update
2014-02-02 21:50 - 2014-02-02 21:49 - 00000000 ___DC () C:\ProgramData\Apple
2014-02-02 21:49 - 2014-02-02 21:49 - 00000000 ___DC () C:\Program Files\Bonjour
2014-02-02 21:49 - 2014-02-02 21:49 - 00000000 ___DC () C:\Program Files (x86)\Bonjour
2014-02-02 19:41 - 2014-02-02 19:41 - 00001275 ____C () C:\Users\Public\Desktop\RealPlayer.lnk
2014-02-02 19:41 - 2014-02-02 19:41 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\RealNetworks
2014-02-02 19:41 - 2014-02-02 19:40 - 00000000 ___DC () C:\Program Files (x86)\RealNetworks
2014-02-02 19:41 - 2014-02-02 19:37 - 00000000 ___DC () C:\ProgramData\Real
2014-02-02 19:40 - 2014-02-02 19:40 - 00272896 ____C (Progressive Networks) C:\WINDOWS\SysWOW64\pncrt.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00201872 ____C (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\rmoc3260.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00006656 ____C (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\pndx5016.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00005632 ____C (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\pndx5032.dll
2014-02-02 19:40 - 2014-02-02 19:40 - 00000000 ___DC () C:\ProgramData\RealNetworks
2014-02-02 19:40 - 2014-02-02 19:40 - 00000000 ___DC () C:\Program Files (x86)\Real
2014-02-02 19:40 - 2013-09-15 01:27 - 00499712 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll
2014-02-02 19:40 - 2013-09-15 01:27 - 00348160 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll
2014-02-02 01:20 - 2014-02-02 01:18 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\HP
2014-02-02 01:20 - 2014-02-01 20:50 - 00000000 ___DC () C:\ProgramData\HP
2014-02-02 01:20 - 2014-01-31 13:02 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Nitro PDF
2014-02-02 01:19 - 2014-02-02 01:19 - 00000000 ___DC () C:\ProgramData\WEBREG
2014-02-02 01:19 - 2014-02-02 01:06 - 00203610 ____C () C:\WINDOWS\hpoins19.dat
2014-02-02 01:19 - 2014-02-02 01:06 - 00000832 ____C () C:\ProgramData\hpzinstall.log
2014-02-02 01:18 - 2014-02-02 01:18 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\HP
2014-02-02 01:14 - 2014-02-02 01:14 - 00001108 ____C () C:\Users\Public\Desktop\HP Photo Creations.lnk
2014-02-02 01:14 - 2014-02-02 01:14 - 00000000 ___DC () C:\ProgramData\HP Photo Creations
2014-02-02 01:14 - 2014-02-02 01:14 - 00000000 ___DC () C:\Program Files (x86)\HP Photo Creations
2014-02-02 01:14 - 2014-02-02 01:07 - 00000000 ___DC () C:\Program Files (x86)\HP
2014-02-02 01:12 - 2014-02-02 01:12 - 00001326 ____C () C:\Users\Public\Desktop\HP Solution Center.lnk
2014-02-02 01:12 - 2014-02-02 01:12 - 00000000 ___DC () C:\ProgramData\HP Product Assistant
2014-02-02 01:11 - 2014-02-02 01:11 - 00001172 ____C () C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2014-02-01 23:50 - 2014-02-01 23:50 - 00847344 ____C (Google Inc.) C:\Users\Shlomi\Downloads\ChromeSetup (1).exe
2014-02-01 23:49 - 2014-02-01 23:49 - 00847344 ____C (Google Inc.) C:\Users\Shlomi\Downloads\ChromeSetup.exe
2014-02-01 21:48 - 2014-02-01 21:48 - 00001209 ____C () C:\Users\Shlomi\Desktop\Format Factory.lnk
2014-02-01 21:47 - 2014-02-01 21:47 - 00000000 ___DC () C:\Program Files (x86)\FreeTime
2014-02-01 21:45 - 2014-02-01 21:43 - 58014512 ____C (Free Time) C:\Users\Shlomi\Downloads\FFSetup3-3-1-0.exe
2014-02-01 21:24 - 2014-01-31 13:45 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Google
2014-02-01 21:12 - 2014-02-01 21:12 - 00001117 ____C () C:\Users\Public\Desktop\Picasa 3.lnk
2014-02-01 21:11 - 2014-02-01 21:10 - 17660184 ____C (Google Inc.) C:\Users\Shlomi\Downloads\picasa39-setup.exe
2014-02-01 21:11 - 2014-01-31 13:45 - 00000000 ___DC () C:\Program Files (x86)\Google
2014-02-01 20:49 - 2014-02-01 20:49 - 02338824 ____C () C:\Users\Shlomi\Downloads\hppiw.exe
2014-02-01 00:57 - 2014-01-31 13:10 - 00000000 ___DC () C:\ldiag
2014-02-01 00:43 - 2014-02-01 00:43 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Skype
2014-02-01 00:42 - 2014-02-01 00:42 - 00002697 ____C () C:\Users\Public\Desktop\Skype.lnk
2014-02-01 00:42 - 2014-02-01 00:42 - 00000000 __RDC () C:\Program Files (x86)\Skype
2014-02-01 00:42 - 2014-02-01 00:42 - 00000000 ___DC () C:\ProgramData\Skype
2014-02-01 00:38 - 2014-02-01 00:38 - 00002917 ____C () C:\Users\Shlomi\Desktop\Microsoft Word 2010.lnk
2014-01-31 21:00 - 2014-01-31 21:00 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Synchronization Services
2014-01-31 20:58 - 2014-01-31 20:58 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Sync Framework
2014-01-31 20:58 - 2014-01-31 20:58 - 00000000 ___DC () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-01-31 20:58 - 2013-09-15 01:12 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Office
2014-01-31 20:53 - 2014-01-31 20:53 - 00000000 ___DC () C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-01-31 20:50 - 2014-01-31 20:50 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-01-31 20:49 - 2014-01-31 20:49 - 00000000 ___DC () C:\Program Files\Microsoft Office
2014-01-31 20:47 - 2014-01-31 20:47 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Microsoft Help
2014-01-31 20:47 - 2014-01-31 20:47 - 00000000 ___DC () C:\Program Files (x86)\Microsoft Analysis Services
2014-01-31 20:45 - 2014-01-31 20:45 - 00000000 _RHDC () C:\MSOCache
2014-01-31 19:32 - 2014-01-31 18:32 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Google
2014-01-31 17:58 - 2014-01-31 17:58 - 00000000 ___HC () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-01-31 13:47 - 2014-01-31 13:47 - 00001977 ____C () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-01-31 13:47 - 2014-01-31 13:47 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\AVAST Software
2014-01-31 13:46 - 2014-01-31 13:46 - 00000000 ___DC () C:\ProgramData\Google
2014-01-31 13:46 - 2014-01-31 13:46 - 00000000 ___DC () C:\Program Files\Google
2014-01-31 13:45 - 2014-01-31 13:45 - 01038072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00421704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00334136 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-01-31 13:45 - 2014-01-31 13:45 - 00207904 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00092544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00080184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00078648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00065776 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-01-31 13:45 - 2014-01-31 13:45 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-01-31 13:45 - 2014-01-31 13:45 - 00000000 ___DC () C:\Program Files\AVAST Software
2014-01-31 13:44 - 2014-01-31 13:17 - 00000000 ___DC () C:\ProgramData\AVAST Software
2014-01-31 13:40 - 2013-09-15 01:12 - 00000000 ___DC () C:\ProgramData\McAfee
2014-01-31 13:37 - 2014-01-31 13:37 - 00421704 ____C (AVAST Software) C:\WINDOWS\system32\Drivers\wgvxqvuq.sys
2014-01-31 13:20 - 2014-01-31 13:20 - 00421704 ____C (AVAST Software) C:\WINDOWS\system32\Drivers\njqlkmxh.sys
2014-01-31 13:17 - 2014-01-31 13:17 - 00421704 ____C (AVAST Software) C:\WINDOWS\system32\Drivers\okduzbru.sys
2014-01-31 13:17 - 2014-01-31 13:10 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\LSC
2014-01-31 13:11 - 2014-01-31 13:11 - 00002123 ____C () C:\Users\Shlomi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-01-31 13:10 - 2014-01-31 13:10 - 00002002 ____C () C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2014-01-31 13:10 - 2014-01-31 13:10 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\OEMSoftwareEngine
2014-01-31 13:10 - 2013-09-15 01:04 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo
2014-01-31 13:10 - 2013-09-15 01:01 - 00000000 ___DC () C:\Program Files\Lenovo
2014-01-31 13:08 - 2013-09-15 01:34 - 00000000 ___DC () C:\WINDOWS\Downloaded Installations
2014-01-31 13:02 - 2014-01-31 13:02 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\LSC
2014-01-31 12:58 - 2014-01-31 12:58 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\AMD
2014-01-31 12:56 - 2014-01-31 12:56 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\ATI
2014-01-31 12:56 - 2014-01-31 12:56 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\ATI
2014-01-31 12:56 - 2014-01-31 12:56 - 00000000 ___DC () C:\ProgramData\ATI
2014-01-31 12:55 - 2014-01-31 12:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Lenovo
2014-01-31 12:54 - 2014-01-31 12:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Roaming\Lenovo
2014-01-31 12:54 - 2014-01-31 12:54 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\Power2Go
2014-01-31 12:53 - 2013-09-15 02:41 - 00077479 ___HC () C:\WINDOWS\modules.log
2014-01-31 12:52 - 2014-01-31 12:52 - 00000000 ___DC () C:\Users\Shlomi\AppData\Local\VirtualStore

Files to move or delete:
====================
C:\ProgramData\Lenovo-23150.vbs
C:\ProgramData\Lenovo-23238.vbs


Some content of TEMP:
====================
C:\Users\Shlomi\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-16 12:18

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-02-2014 01
Ran by Shlomi at 2014-02-22 22:22:38
Running from C:\Users\Shlomi\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

5600 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
5600_Help (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
5600Trb (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
AIO_CDB_ProductContext (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
AIO_CDB_Software (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden
Amazon Browser App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.0 - Amazon)
AMD Accelerated Video Transcoding (Version: 12.10.100.30418 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{0C51297F-4056-7831-8157-10BE4E27CBE4}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2013.0418.1206.19803 - Advanced Micro Devices, Inc.) Hidden
AMD VISION Engine Control Center (x32 Version: 2013.0418.1206.19803 - Advanced Micro Devices, Inc.) Hidden
Apple Application Support (HKLM-x32\...\{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}) (Version: 3.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2013 - Avast Software)
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.0418.1206.19803 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0418.1206.19803 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Desktop (x32 Version: 2013.0418.1206.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0418.1205.19803 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0418.1206.19803 - Advanced Micro Devices, Inc.) Hidden
Comparing (HKLM-x32\...\InstallShield_{233EE2F2-EDA8-4C70-ABC3-D656D67D2CD5}) (Version: 1.00.2012.0921 - Tong child Research & Planning Co.,Ltd)
Comparing (x32 Version: 1.00.2012.0921 - Tong child Research & Planning Co.,Ltd) Hidden
Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}) (Version: - Microsoft)
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.17 - Dolby Laboratories Inc)
Driver & Application Installation (HKLM-x32\...\{BFECCF2A-F094-4066-8BFA-29CCBB7F6602}) (Version: 6.13.0423 - Lenovo)
EducationPortal (HKLM-x32\...\{65487538-FF20-421B-91DB-F6634B8D264C}) (Version: 5.00.012.0617 - Lenovo)
Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden
Find the Differences (HKLM-x32\...\InstallShield_{EAA04F6D-6E10-4267-B824-C35D3B9E0155}) (Version: 1.00.2012.0920 - Tong child Research & Planning Co.,Ltd)
Find the Differences (x32 Version: 1.00.2012.0920 - Tong child Research & Planning Co.,Ltd) Hidden
Finding the Letters (HKLM-x32\...\InstallShield_{535FB733-FFCF-4460-8694-664A2F6C53B4}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd)
Finding the Letters (x32 Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) Hidden
FormatFactory 3.3.1.0 (HKLM-x32\...\FormatFactory) (Version: 3.3.1.0 - Format Factory)
FreeRide Games (HKLM-x32\...\{6C26A305-4549-4A8A-9F03-25719C03B0FB}) (Version: 07.05.80.00 - Exent Technologies)
Fruits (HKLM-x32\...\InstallShield_{AA39BFDE-71E5-46A6-A10B-44C2F45A341E}) (Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd)
Fruits (x32 Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.3 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.4805.320 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.2024 - HP Photo Creations Powered by RocketLife)
HP Photosmart Officejet and Deskjet All-In-One Driver Software (HKLM\...\{6F5B70F0-EA6C-4A5B-BB16-8390BD66B251}) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33057) (Version: 3.6.1.33057.10 - Intel)
iTunes (HKLM\...\{0D924CB2-2EA4-4044-BAF7-770202D6BD0D}) (Version: 11.1.4.62 - Apple Inc.)
Lenovo Assistant (HKLM-x32\...\{B2DE4F30-B8C7-49C0-85B9-2F37A5290F00}) (Version: 2.0.0.28 - Lenovo)
Lenovo Black Silk USB Keyboard (HKLM\...\Lenovo Black Silk USB Keyboard) (Version: 1.22 - Lenovo)
Lenovo Dashboard (HKLM-x32\...\{FEF1833C-244C-4DF2-AB67-1E1D26921ED8}) (Version: 2.0.0.13 - Lenovo)
Lenovo Dynamic Brightness System (HKLM-x32\...\{D9ED6D06-6002-495E-A7BC-46E6AE386996}) (Version: 4.0.01.52020 - Lenovo)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.3.0 - Lenovo)
Lenovo Eye Distance System (HKLM-x32\...\{5183D7AB-D09B-411F-A74E-BBAEA61C6505}) (Version: 4.0.01.42160 - Lenovo)
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.5 - CEWE COLOR AG u Co. OHG)
Lenovo Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.6418 - CyberLink Corp.)
Lenovo Power2Go (x32 Version: 6.0.6418 - CyberLink Corp.) Hidden
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4521.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.4521.52 - CyberLink Corp.) Hidden
Lenovo Rescue System (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 4.0.0.1511 - CyberLink Corp.)
Lenovo Rescue System (Version: 4.0.0.1511 - CyberLink Corp.) Hidden
Lenovo Solution Center (HKLM\...\{D60E3A84-5DDC-49ED-B9A5-E3466996EB36}) (Version: 2.3.002.00 - Lenovo Group Limited)
Lenovo USB2.0 UVC Camera (HKLM-x32\...\{70D2C5B8-EB22-45B1-9EAA-5E8C1C408A3B}) (Version: 1.00.0000 - Vimicro Corporation)
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3127 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 4.1.3127 - CyberLink Corp.) Hidden
LVT (HKLM-x32\...\{9E3469A6-443A-452C-BF44-8D7CE3A9A7E2}) (Version: 5.00.0914 - Lenovo)
Mammals (HKLM-x32\...\InstallShield_{ACA58CEB-2F74-4095-ADB6-4C1BFB170F64}) (Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd)
Mammals (x32 Version: 1.00.2012.0809 - Tong child Research & Planning Co.,Ltd) Hidden
MarketResearch (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Matching Roles (HKLM-x32\...\InstallShield_{92736E44-7608-4D80-9333-E40C82B7E8B3}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd)
Matching Roles (x32 Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) Hidden
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Office Access MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Arabic) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Russian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Hebrew) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Hebrew) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 en-US)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
Nitro Pro 8 (HKLM\...\{34BE77EE-B563-49D7-A8A0-FFD76D29BBD3}) (Version: 8.0.10.7 - Nitro)
OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)
Opera 12.16 (HKLM-x32\...\Opera 12.16.1860) (Version: 12.16.1860 - Opera Software ASA)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Pokki (HKCU\...\Pokki) (Version: 0.267.1.208 - Pokki)
Puzzle (HKLM-x32\...\InstallShield_{6EB7ECE3-E3BE-481D-821B-F1AFFA244D64}) (Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd)
Puzzle (x32 Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd) Hidden
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.10.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6937 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.29053 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Skype™ 6.13 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.13.104 - Skype Technologies S.A.)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
sudoku (HKLM-x32\...\InstallShield_{8C4715DF-8AC9-4F0A-8E35-F9B4CF318FF1}) (Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd)
sudoku (x32 Version: 1.00.2012.0807 - Tong child Research & Planning Co.,Ltd) Hidden
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.61.90905 - SugarSync, Inc.)
timer (HKLM-x32\...\InstallShield_{9CC4B8EE-A96B-4800-B674-0CF8B4560F45}) (Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd)
timer (x32 Version: 1.00.2012.0512 - Tong child Research & Planning Co.,Ltd) Hidden
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837583) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{E21274CE-CA0C-49FA-93F4-DC292A052264}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0401-0000-0000000FF1CE}_Office14.PROPLUSR_{F63A5E34-3E66-4E59-8314-1CAA9D7B12C6}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{B5C70C99-B109-42FD-B219-FF12CA543F19}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040D-0000-0000000FF1CE}_Office14.PROPLUSR_{BE08E87B-F850-412C-A543-38326E215CE1}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0419-0000-0000000FF1CE}_Office14.PROPLUSR_{1CF9A6C6-EB13-4A0B-8D52-E52A5EB5B70E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-040D-0000-0000000FF1CE}_Office14.PROPLUSR_{0C2F1EBB-1F4D-49B5-AD10-F27181F4C6FB}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-040D-0000-0000000FF1CE}_Office14.PROPLUSR_{6A7DF78C-66F2-4F76-B82C-C00C04B9F8FC}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden

==================== Restore Points =========================

12-02-2014 17:54:19 Windows Update
16-02-2014 20:13:55 Windows Update
22-02-2014 01:11:30 Windows Update

==================== Hosts content: ==========================

2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ___AC C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0787AB4D-8392-4368-A786-F3324EDF24C5} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {10EBEB21-F8D9-4675-A971-25E2CDBA5C64} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {18D52EE4-42DB-4D03-9A63-3F2EFA4B8001} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [2012-03-08] ()
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {26D6644F-292B-4A33-A975-D2DDDA3E4DC6} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.)
Task: {28FD1F32-7EA9-4B87-A3B5-2F68ECC8E76E} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)"
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {2E91D64C-76AB-482C-A800-C15C41056491} - System32\Tasks\Lenovo\Lenovo-23150 => C:\ProgramData\Lenovo-23150.vbs [2013-09-15] ()
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3E3C3245-B521-4DA2-929C-E85A92F07594} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-424950133-3584039098-4252772914-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4D0D9442-1A40-4D82-B329-C244179483E7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-31] (Google Inc.)
Task: {5767A39A-BB1C-46B8-AD69-02F24A64607E} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-20] (Adobe Systems Incorporated)
Task: {633F423F-BDAF-479C-A85F-8ABFAE530949} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {78230324-EAF2-4032-96AD-B40EE6A6B8F2} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2012-09-01] (Dolby Laboratories Inc.)
Task: {7D05EE95-E0A7-4F37-9232-D8BC9AA59652} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-02-16] (Microsoft Corporation)
Task: {8119C782-8213-4C69-8650-8E0045AB052D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-01-31] (AVAST Software)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8A99884B-E548-480B-8604-F8151B69D4F1} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {973910CD-21AA-404D-BCEE-B1E70AFA456D} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-424950133-3584039098-4252772914-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {9AECF46A-071B-4539-9B94-DED074DF3BD3} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-424950133-3584039098-4252772914-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {9F3FF0EE-CBF7-4696-96DC-7801D791009B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A6FA6F24-E6AB-4CFF-AC9C-E6836254ECF7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-31] (Google Inc.)
Task: {AA6FA679-24EA-42CE-903E-531F837CA11F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {B6FB2300-3658-4CEA-A194-6E758CA34603} - System32\Tasks\Lenovo\Lenovo-23238 => C:\ProgramData\Lenovo-23238.vbs [2013-09-15] ()
Task: {BDB1232D-4547-497A-8440-EC18EDDE9FA3} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-09-26] (Lenovo)
Task: {C208F6F7-0C29-4A95-9F2E-20D916874D56} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-09-26] (Lenovo)
Task: {CBA84765-D8FC-4348-8075-7C854C2485CC} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-26] ()
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D4E26DB8-70AC-4DA3-A747-13863E697261} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DEA43EA9-1108-427B-BEF7-C60DB7420047} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2013-03-14] (Lenovo)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {E7639ECE-39F8-4D21-A314-5F5534CCB1D8} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-04-18 21:19 - 2013-04-18 21:19 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 ____C () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2013-12-05 20:24 - 2013-12-05 20:24 - 02330440 _____ () C:\Users\Shlomi\AppData\Local\Pokki\ocdeskband_0.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 ____C () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-04-18 21:19 - 2013-04-18 21:19 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-02-17 11:52 - 2014-02-17 10:23 - 02180608 _____ () C:\Program Files\AVAST Software\Avast\defs\14021700\algo.dll
2014-02-22 19:27 - 2014-02-22 15:20 - 02181120 _____ () C:\Program Files\AVAST Software\Avast\defs\14022201\algo.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 ____C () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 ____C () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2009-12-05 01:59 - 2009-12-05 01:59 - 00619816 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll
2009-12-05 02:04 - 2009-12-05 02:04 - 00013096 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll
2014-01-31 13:45 - 2014-01-31 13:45 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-09-07 04:11 - 2013-09-07 04:11 - 00569856 _____ () C:\Users\Shlomi\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2013-09-07 04:11 - 2013-09-07 04:11 - 01400846 _____ () C:\Users\Shlomi\AppData\Local\Pokki\Engine\avcodec-54.dll
2013-09-07 04:11 - 2013-09-07 04:11 - 00151054 _____ () C:\Users\Shlomi\AppData\Local\Pokki\Engine\avutil-51.dll
2013-09-07 04:11 - 2013-09-07 04:11 - 00222734 _____ () C:\Users\Shlomi\AppData\Local\Pokki\Engine\avformat-54.dll
2014-02-15 11:25 - 2014-02-15 11:25 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 ____C () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2014-02-20 04:21 - 2014-02-19 22:03 - 00065352 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\chrome_elf.dll
2014-02-20 04:21 - 2014-02-19 22:03 - 00673608 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\libglesv2.dll
2014-02-20 04:21 - 2014-02-19 22:03 - 00093000 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\libegl.dll
2014-02-20 04:21 - 2014-02-19 22:03 - 04080968 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\pdf.dll
2014-02-20 04:21 - 2014-02-19 22:03 - 00390472 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\ppGoogleNaClPluginChrome.dll
2014-02-20 04:21 - 2014-02-19 22:03 - 01647432 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\ffmpegsumo.dll
2014-02-20 04:21 - 2014-02-19 22:03 - 13632840 ____C () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.3\PepperFlash\pepflashplayer.dll
2014-01-15 08:04 - 2014-01-15 08:04 - 01441280 ____C () C:\Program Files (x86)\FreeTime\FormatFactory\PicConvert.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\Shlomi\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/22/2014 06:12:58 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/21/2014 05:39:48 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/20/2014 09:22:05 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/19/2014 05:20:31 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/18/2014 04:04:16 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/18/2014 01:33:54 AM) (Source: Perflib) (User: )
Description: Outlook

Error: (02/18/2014 01:33:54 AM) (Source: Perflib) (User: )
Description: Outlook8

Error: (02/18/2014 01:32:03 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/16/2014 00:18:48 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (02/15/2014 01:21:36 PM) (Source: Application Error) (User: )
Description: Faulting application name: PortChanger.exe, version: 0.0.0.0, time stamp: 0x50123cc9
Faulting module name: PortChanger.exe, version: 0.0.0.0, time stamp: 0x50123cc9
Exception code: 0xc0000005
Fault offset: 0x0000000000004be7
Faulting process id: 0x23cc
Faulting application start time: 0xPortChanger.exe0
Faulting application path: PortChanger.exe1
Faulting module path: PortChanger.exe2
Report Id: PortChanger.exe3
Faulting package full name: PortChanger.exe4
Faulting package-relative application ID: PortChanger.exe5


System errors:
=============
Error: (02/22/2014 10:00:00 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/22/2014 03:12:04 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}

Error: (02/21/2014 07:48:37 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}

Error: (02/21/2014 07:48:36 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}

Error: (02/21/2014 07:48:33 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}

Error: (02/21/2014 07:44:38 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}

Error: (02/21/2014 07:44:37 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -Embedding193{10DA4F3C-CC99-4190-BE4D-58330754E882}

Error: (02/21/2014 10:00:02 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/20/2014 10:00:00 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/19/2014 10:00:00 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable


Microsoft Office Sessions:
=========================
Error: (02/22/2014 06:12:58 AM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/21/2014 05:39:48 AM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/20/2014 09:22:05 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/19/2014 05:20:31 AM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/18/2014 04:04:16 AM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/18/2014 01:33:54 AM) (Source: Perflib)(User: )
Description: Outlook

Error: (02/18/2014 01:33:54 AM) (Source: Perflib)(User: )
Description: Outlook8

Error: (02/18/2014 01:32:03 AM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/16/2014 00:18:48 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (02/15/2014 01:21:36 PM) (Source: Application Error)(User: )
Description: PortChanger.exe0.0.0.050123cc9PortChanger.exe0.0.0.050123cc9c00000050000000000004be723cc01cf2a400c726248C:\WINDOWS\system32\PortChanger.exeC:\WINDOWS\system32\PortChanger.exe5478d3d6-9633-11e3-be7c-0025ab3fd8a1


==================== Memory info ===========================

Percentage of memory in use: 69%
Total physical RAM: 3517.29 MB
Available physical RAM: 1074.13 MB
Total Pagefile: 7101.29 MB
Available Pagefile: 3708.99 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:904.91 GB) (Free:864.45 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (FreeAgent Drive) (Fixed) (Total:931.51 GB) (Free:691.25 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 6D3E53DC)

Partition: GPT Partition Type.

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 68F76CFC)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================




aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-02-22 22:27:26
-----------------------------
22:27:26.547 OS Version: Windows x64 6.2.9200
22:27:26.548 Number of processors: 2 586 0x1
22:27:26.550 ComputerName: SHLOMI-PC UserName: Shlomi
22:27:26.692 Initialze error 1
22:27:30.291 AVAST engine defs: 14022201
22:27:35.227 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000028
22:27:35.232 Disk 0 Vendor: ST1000DM003-1CH162 CC56 Size: 953869MB BusType: 11
22:27:35.254 Disk 0 MBR read successfully
22:27:35.259 Disk 0 MBR scan
22:27:35.265 Disk 0 unknown MBR code
22:27:35.272 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
22:27:35.280 Disk 0 scanning C:\WINDOWS\system32\drivers
22:27:35.288 Service scanning
22:27:35.939 Modules scanning
22:27:35.945 Disk 0 trace - called modules:
22:27:35.955 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
22:27:35.962 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe0000142a060]
22:27:35.972 3 CLASSPNP.SYS[fffff80000b5cabb] -> nt!IofCallDriver -> [0xffffe00001306b30]
22:27:35.987 5 amd_xata.sys[fffff8000066f634] -> nt!IofCallDriver -> \Device\00000028[0xffffe00001308060]
22:27:35.998 AVAST engine scan C:\WINDOWS
22:27:36.011 AVAST engine scan C:\WINDOWS\system32
22:27:36.023 AVAST engine scan C:\WINDOWS\system32\drivers
22:27:36.035 AVAST engine scan C:\Users\Shlomi
22:27:36.045 AVAST engine scan C:\ProgramData
22:27:36.057 Scan finished successfully
22:28:21.428 Disk 0 MBR has been saved successfully to "C:\Users\Shlomi\Desktop\MBR.dat"
22:28:21.440 The log file has been saved successfully to "C:\Users\Shlomi\Desktop\asw.txt"
  • 0

#7
assaf1

assaf1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Hi :)

Many thanks!! (sorry i'm new here)
  • 0

#8
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Hi :)

Many thanks!! (sorry i'm new here)


No worries and nothing to be sorry about. :) :thumbsup:
  • 0

#9
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts
Hello, we have some work to do, so let's get started. :)


Step 1: Program Uninstall

Please uninstall this program from your machine:

Pokki Version: 0.267.1.208

We're going to replace that program with this one: http://www.classicshell.net/

Please click on the link and install Classic Shell on your machine once you have removed Pokki.


Step 2: Disable Avast Online Security


Avast Online Security has been know to cause issues with Windows 8 and we're going to disable it. Please follow the instructions below to disable it


How to disable in FireFox:

1.) Click on Tools and then select Extensions

2.) Find Avast Online Security in the list and click Disable


How to disable in Chrome:

  • Start Chrome and type this into the address bar: chrome:extensions
  • This will display a page of all the installed extensions. Please remove the extensions in the list below by clicking the trash can icon beside each one.


Once you have completed these steps, please let me know if you have any remaining problems. :) :thumbsup:
  • 0

#10
assaf1

assaf1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Hi,

Thanks for the fast reply :)

I followed your instructions but unfortunately there is no significant change.

The pc is still slow and the CPU usage indicates a 98-99 % values.(by the way, i noticed the flash player is consuming a significant rate of CPU as well)

Sometimes when i type on the keyboard there is a delay till i see the letters typed on screen.

As i mentioned before, my only use on this pc is on the internet field.i generally have 6 -8 tabs open ( some of them are social networks like Facebook etc.)

if you have more ideas what to do i'd be very grateful
  • 0

Advertisements


#11
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Thanks for the fast reply :)

I followed your instructions but unfortunately there is no significant change.

The pc is still slow and the CPU usage indicates a 98-99 % values.(by the way, i noticed the flash player is consuming a significant rate of CPU as well)

Sometimes when i type on the keyboard there is a delay till i see the letters typed on screen.

As i mentioned before, my only use on this pc is on the internet field.i generally have 6 -8 tabs open ( some of them are social networks like Facebook etc.)

if you have more ideas what to do i'd be very grateful


You're very welcome. :) Let's get rid of a couple minor things and run some scans.


Please disable your antivirus for the duration of my instructions. Don't forget to re-enable them after you have completed the steps.


Step 1: FRST Fix


  • Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy.
  • Right-click in the open notepad and select Paste).
  • Save it on your Desktop as fixlist.txt

Start
(Pokki) C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe
HKLM-x32\...\Run: [] - [X]
HKU\S-1-5-21-424950133-3584039098-4252772914-1002\...\RunOnce: [Application Restart #2] - C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe [8285512 2013-12-05] (Pokki)
C:\Users\Shlomi\AppData\Local\Pokki
C:\ProgramData\Lenovo-23150.vbs
C:\ProgramData\Lenovo-23238.vbs
End


NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait. The tool will make a log on the desktop (Fixlog.txt) please post it in your next reply.



Step 2: AdwCleaner


Download ADWcleaner by clicking here. Please save it to your Desktop


Posted Image

  • Double click (Vista and 7 Users)right click the adwcleaner.exe file and click Run as Adminstrator and accept the UAC prompt to run AdwCleaner
  • Close any open windows or browsers.
  • Pause your Anti-Virus program if it is running.
  • Once it starts, click on the Scan button.
  • Let the scan complete itself. This may take a few minutes.
  • Once the scan has finished, "Pending, uncheck elements you don't want to remove."
    click the Clean button. When finished, it will ask to reboot. Please reboot.
  • When the machine has rebooted, a log will be produced. Please copy/paste that in your next reply. Here's how:
  • Click the Report button and the log will open. Copy and Paste the contents of the log file into your next reply.
This report is also saved at C:\AdwCleaner[R0].txt

Step 3: Junkware Removal Tool


Posted Image Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


Step 4: Scan with aswMBR


  • Please download aswMBR.exe to your desktop.
  • Double click the file to run it.
  • It will ask if you want to download the latest Avast! virus definitions, please answer yes.

Posted Image

  • Click the Scan button to begin the scan.

Posted Image

  • Once the scan has finished, click on Save Log, save it to your desktop as asw.txt, and please post it in your next reply.
  • Click Exit


Things I need to see in your next post:

FRST Fix Log

AdwCleaner Log

Junkware Removal Tool Log

aswMBR Log

Question: How is the computer running now?

  • 0

#12
assaf1

assaf1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Hi :)

There is some improvement ! thanks!!

after i reboot the PC there was an error message : "can not find script file "C:\ProgramData\Lenovo-23150.vbs".

Here are the logs you've requested:

FRST Fix Log

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-02-2014 01
Ran by Shlomi at 2014-02-23 22:14:54 Run:1
Running from C:\Users\Shlomi\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
(Pokki) C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe
HKLM-x32\...\Run: [] - [X]
HKU\S-1-5-21-424950133-3584039098-4252772914-1002\...\RunOnce: [Application Restart #2] - C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe [8285512 2013-12-05] (Pokki)
C:\Users\Shlomi\AppData\Local\Pokki
C:\ProgramData\Lenovo-23150.vbs
C:\ProgramData\Lenovo-23238.vbs
End
*****************

C:\Users\Shlomi\AppData\Local\Pokki\Engine\pokki.exe => No running process found
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKU\S-1-5-21-424950133-3584039098-4252772914-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #2 => Value deleted successfully.
"C:\Users\Shlomi\AppData\Local\Pokki" => File/Directory not found.
C:\ProgramData\Lenovo-23150.vbs => Moved successfully.
C:\ProgramData\Lenovo-23238.vbs => Moved successfully.

==== End of Fixlog ====


AdwCleaner Log

# AdwCleaner v3.019 - Report created 23/02/2014 at 22:18:55
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Shlomi - SHLOMI-PC
# Running from : C:\Users\Shlomi\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found : C:\Users\Shlomi\AppData\Roaming\Mozilla\Firefox\Profiles\i4qccxnu.default\Extensions\[email protected]

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Classes\pokki
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Shlomi\AppData\Roaming\Mozilla\Firefox\Profiles\i4qccxnu.default\prefs.js ]


-\\ Google Chrome v34.0.1847.3

[ File : C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1191 octets] - [23/02/2014 22:18:55]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1251 octets] ##########


Junkware Removal Tool Log


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 8.1 x64
Ran by Shlomi on 23-Feb-14 at 22:30:09.69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Shlomi\AppData\Roaming\mozilla\firefox\profiles\i4qccxnu.default\minidumps [2 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23-Feb-14 at 22:42:58.78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

aswMBR Log

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-02-22 22:27:26
-----------------------------
22:27:26.547 OS Version: Windows x64 6.2.9200
22:27:26.548 Number of processors: 2 586 0x1
22:27:26.550 ComputerName: SHLOMI-PC UserName: Shlomi
22:27:26.692 Initialze error 1
22:27:30.291 AVAST engine defs: 14022201
22:27:35.227 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000028
22:27:35.232 Disk 0 Vendor: ST1000DM003-1CH162 CC56 Size: 953869MB BusType: 11
22:27:35.254 Disk 0 MBR read successfully
22:27:35.259 Disk 0 MBR scan
22:27:35.265 Disk 0 unknown MBR code
22:27:35.272 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
22:27:35.280 Disk 0 scanning C:\WINDOWS\system32\drivers
22:27:35.288 Service scanning
22:27:35.939 Modules scanning
22:27:35.945 Disk 0 trace - called modules:
22:27:35.955 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
22:27:35.962 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe0000142a060]
22:27:35.972 3 CLASSPNP.SYS[fffff80000b5cabb] -> nt!IofCallDriver -> [0xffffe00001306b30]
22:27:35.987 5 amd_xata.sys[fffff8000066f634] -> nt!IofCallDriver -> \Device\00000028[0xffffe00001308060]
22:27:35.998 AVAST engine scan C:\WINDOWS
22:27:36.011 AVAST engine scan C:\WINDOWS\system32
22:27:36.023 AVAST engine scan C:\WINDOWS\system32\drivers
22:27:36.035 AVAST engine scan C:\Users\Shlomi
22:27:36.045 AVAST engine scan C:\ProgramData
22:27:36.057 Scan finished successfully
22:28:21.428 Disk 0 MBR has been saved successfully to "C:\Users\Shlomi\Desktop\MBR.dat"
22:28:21.440 The log file has been saved successfully to "C:\Users\Shlomi\Desktop\asw.txt"


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-02-23 22:46:28
-----------------------------
22:46:28.840 OS Version: Windows x64 6.2.9200
22:46:28.840 Number of processors: 2 586 0x1
22:46:28.840 ComputerName: SHLOMI-PC UserName: Shlomi
22:46:34.857 Initialze error 1
22:46:38.501 AVAST engine defs: 14022301
22:46:43.159 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000028
22:46:43.159 Disk 0 Vendor: ST1000DM003-1CH162 CC56 Size: 953869MB BusType: 11
22:46:43.174 Disk 0 MBR read successfully
22:46:43.190 Disk 0 MBR scan
22:46:43.190 Disk 0 unknown MBR code
22:46:43.190 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
22:46:43.206 Disk 0 scanning C:\WINDOWS\system32\drivers
22:46:43.206 Service scanning
22:46:43.846 Modules scanning
22:46:43.846 Disk 0 trace - called modules:
22:46:43.862 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
22:46:43.878 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000016084e0]
22:46:43.878 3 CLASSPNP.SYS[fffff80000d63abb] -> nt!IofCallDriver -> [0xffffe00000ee42c0]
22:46:43.893 5 amd_xata.sys[fffff800007f5634] -> nt!IofCallDriver -> \Device\00000028[0xffffe00000f437f0]
22:46:43.909 AVAST engine scan C:\WINDOWS
22:46:43.909 AVAST engine scan C:\WINDOWS\system32
22:46:43.925 AVAST engine scan C:\WINDOWS\system32\drivers
22:46:43.940 AVAST engine scan C:\Users\Shlomi
22:46:43.940 AVAST engine scan C:\ProgramData
22:46:43.956 Scan finished successfully
22:47:26.259 Disk 0 MBR has been saved successfully to "C:\Users\Shlomi\Desktop\MBR.dat"
22:47:26.259 The log file has been saved successfully to "C:\Users\Shlomi\Desktop\asw.txt"
  • 0

#13
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

There is some improvement ! thanks!!

after i reboot the PC there was an error message : "can not find script file "C:\ProgramData\Lenovo-23150.vbs".


Hi, good to hear that there is improvement. :)

Please re-run AdwCleaner and when the Scan finishes, press the Clean button. When it is finished, it will reboot, please post the log it will generate and let me know if the error happens again. :)
  • 0

#14
assaf1

assaf1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Hi :)

Well there is a substantial improvement! thanks :)

well this time i got two error messages :

1."can not find script file "C:\ProgramData\Lenovo-23150.vbs".
2."can not find script file "C:\ProgramData\Lenovo-23238.vbs".

Here is the new log of AdwCleaner :

# AdwCleaner v3.019 - Report created 23/02/2014 at 23:57:55
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Shlomi - SHLOMI-PC
# Running from : C:\Users\Shlomi\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Shlomi\AppData\Roaming\Mozilla\Firefox\Profiles\i4qccxnu.default\prefs.js ]


-\\ Google Chrome v34.0.1847.3

[ File : C:\Users\Shlomi\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1335 octets] - [23/02/2014 22:18:55]
AdwCleaner[R1].txt - [996 octets] - [23/02/2014 23:52:02]
AdwCleaner[S0].txt - [1408 octets] - [23/02/2014 22:20:12]
AdwCleaner[S1].txt - [918 octets] - [23/02/2014 23:57:55]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [977 octets] ##########
  • 0

#15
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts
Hi :)

Just wanted to update you, I'm awaiting my teacher's approval for the next steps, then we can proceed. :thumbsup:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP