TechSpot

win64/Patched.A in services.exe

Inactive
By Matthew Robin
Jun 17, 2013
  1. Hi,
    My AVG antivirus has recently found win64/patched.A in my services.exe, since then I have been getting trojan virus alerts every 2 minutes. AVG is able to clear the other trojans, but not the patched.A. I'm hoping someone might be able to help me on this.
    I'll put the mbam and dds logs in a seperate post.
    Thanks for any help.
  2. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    Unfortunately I set this up as Hungarian language.
    If you need me to translate anything, let me know.

    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Adatbázis verzió: v2013.06.17.05

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 10.0.9200.16614
    Matthew :: MR [rendszergazda]

    2013.06.17. 20:23:19
    mbam-log-2013-06-17 (20-23-19).txt

    Vizsgálat típusa: Gyorsvizsgálat
    Engedélyezett vizsgálati beállítások: Memória | Indítópult | Rendszerleíró | Rendszerfájlok | Heurisztikus/Extra | Heurisztikus/Shuriken | PUP | PUM
    Letiltott vizsgálati beállítások: P2P
    Átvizsgált objektumok: 225793
    Eltelt idő: 9 perc, 56 másodperc

    Fertőzött memóriafolyamatok: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött memória modulok: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött Rendszerleíró kulcsok: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött Rendszerleíró értékek: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött Rendszerleíró adatelemek: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött mappák: 0
    (Nem találhatók rosszindulatú elemek)

    Fertőzött fájlok: 2
    C:\$Recycle.Bin\S-1-5-21-44171343-4250847152-466202584-1001\$R00179E4D (Trojan.FakeMS) -> A karanténba helyezés, és a törlés sikerült.
    C:\Windows\Installer\{e6ee990c-9063-77fe-1e2e-748aeaaf0b40}\U\000000cb.@ (Rootkit.0Access) -> A karanténba helyezés, és a törlés sikerült.

    (befejezés)
  3. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 10.0.9200.16611 BrowserJavaVersion: 10.21.2
    Run by Matthew at 20:42:23 on 2013-06-17
    Microsoft Windows 7 Home Premium 6.1.7601.1.1250.36.1038.18.4063.2207 [GMT 2:00]
    .
    AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvservice.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
    C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    C:\ProgramData\KS\FbDatabaseServer\bin\fbguard.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Sony\VAIO Power Management\SPMService.exe
    C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
    C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
    C:\ProgramData\KS\FbDatabaseServer\bin\fbserver.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Windows\System32\WUDFHost.exe
    C:\Windows\SysWOW64\C2MP\TrayMenu.exe
    C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
    C:\Program Files (x86)\AVG\AVG2013\avgui.exe
    C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\ProgramData\KS\Bin\KS.TransferSvc.exe
    C:\Windows\splwow64.exe
    C:\ProgramData\KS\Bin\KSWebSvc.exe
    C:\Windows\system32\sppsvc.exe
    C:\Windows\system32\prevhost.exe
    C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxps://www.google.hu/
    uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEA&bmod=EU01
    uURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
    uURLSearchHooks: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files (x86)\Softonic-Eng7\tbSoft.dll
    mURLSearchHooks: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files (x86)\Softonic-Eng7\tbSoft.dll
    mWinlogon: Userinit = userinit.exe,
    BHO: AutorunsDisabled - <orphaned>
    BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - LocalServer32 - <no file>
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    BHO: Microsoft-fiók bejelentkezési segédje: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    TB: Softonic-Eng7 Toolbar: {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - C:\Program Files (x86)\Softonic-Eng7\tbSoft.dll
    TB: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    uRun: [AdobeBridge] <no file>
    mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
    mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
    mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\CODECP~1.LNK - C:\Windows\SysWOW64\C2MP\TrayMenu.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\CODECP~2.LNK - C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableLUA = dword:0
    mPolicies-System: EnableUIADesktopToggle = dword:0
    mPolicies-System: PromptOnSecureDesktop = dword:0
    IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
    IE: SmarThru4 Kijelölt szöveg mentése - C:\Program Files (x86)\SmarThru 4\WebCapture.dll.htm
    IE: SmarThru4 Mentés HTML formátumban - C:\Program Files (x86)\SmarThru 4\WebCapture.dll1.htm
    IE: SmarThru4 Rögzítés kijelölése - C:\Program Files (x86)\SmarThru 4\WebCapture.dll2.htm
    IE: SmarThru4 Web Capture - C:\Program Files (x86)\SmarThru 4\WebCapture.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    LSP: mswsock.dll
    DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
    DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
    DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    TCP: NameServer = 192.168.4.1
    TCP: Interfaces\{073F4FC3-AFF5-498B-B373-A96FA60B0E6F} : NameServer = 84.2.46.1 84.2.44.1
    TCP: Interfaces\{82AFFD91-4C31-42C3-A2D2-746AF5AB4947} : NameServer = 84.2.46.1 84.2.44.1
    TCP: Interfaces\{A4295FC5-0413-4647-A81D-D9DA20787226} : NameServer = 84.2.46.1 84.2.44.1
    TCP: Interfaces\{DA6540E2-DC52-46E5-A631-7257FBAF6E37} : DHCPNameServer = 192.168.4.1
    TCP: Interfaces\{F7744F15-0800-4B47-9FDD-D1CFDEC7DC7D} : DHCPNameServer = 192.168.4.1
    TCP: Interfaces\{F7744F15-0800-4B47-9FDD-D1CFDEC7DC7D}\240585949494 : DHCPNameServer = 10.77.0.254
    TCP: Interfaces\{F7744F15-0800-4B47-9FDD-D1CFDEC7DC7D}\24638333 : DHCPNameServer = 192.168.1.1 192.168.1.1
    Handler: AutorunsDisabled - <Clsid value has no data>
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    Notify: VESWinlogon - VESWinlogon.dll
    SSODL: WebCheck - <orphaned>
    x64-BHO: AutorunsDisabled - <orphaned>
    x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - LocalServer32 - <no file>
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    x64-DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    x64-DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    x64-Handler: AutorunsDisabled - <Clsid value has no data>
    x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
    x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
    x64-SSODL: WebCheck - <orphaned>
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Matthew\AppData\Roaming\Mozilla\Firefox\Profiles\bthtdvkg.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://websearch.good-results.info/?l=1&q=
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=888596&p=
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
    FF - plugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
    FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin.dll
    FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin2.dll
    FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin3.dll
    FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin4.dll
    FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin5.dll
    FF - plugin: C:\Program Files (x86)\QuickTime Alternative\Plugins\npqtplugin6.dll
    FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
    FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
    FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
    FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
    FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
    FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
    FF - plugin: C:\Users\Matthew\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
    FF - plugin: C:\Users\Matthew\AppData\Roaming\Mozilla\Firefox\Profiles\bthtdvkg.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}\plugins\np-mswmp.dll
    FF - plugin: C:\Users\Matthew\AppData\Roaming\Mozilla\Firefox\Profiles\bthtdvkg.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}\plugins\npConduitFirefoxPlugin.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
    FF - ExtSQL: 2013-05-14 14:06; {bee6eb20-01e0-ebd1-da83-080329fb9a3a}; C:\Users\Matthew\AppData\Roaming\Mozilla\Firefox\Profiles\bthtdvkg.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-10-15 63328]
    R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
    R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-11-16 111968]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
    R0 BMLoad;Bytemobile Boot Time Load Driver;C:\Windows\System32\drivers\BMLoad.sys [2011-11-16 16512]
    R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-11-28 55856]
    R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\drivers\SmartDefragDriver.sys [2013-1-3 17720]
    R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-10-22 154464]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
    R2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2009-12-22 814344]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-16 5814904]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
    R2 FirebirdGuardianks;Firebird Guardian - ks;C:\ProgramData\KS\FbDatabaseServer\bin\fbguard.exe -s ks --> C:\ProgramData\KS\FbDatabaseServer\bin\fbguard.exe -s ks [?]
    R2 KS.TransferSvc;KS.TransferSvc;C:\ProgramData\KS\Bin\KS.TransferSvc.exe [2013-4-26 21504]
    R2 KSWebSvc;KSWebSvc;C:\ProgramData\KS\Bin\KSWebSvc.exe [2013-4-26 134376]
    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-1-4 418376]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-1-4 701512]
    R2 nvservice;NVIDIA GuardService;C:\Windows\System32\nvservice.exe [2013-3-24 192800]
    R2 rimspci;rimspci;C:\Windows\System32\drivers\rimssne64.sys [2009-11-24 91648]
    R2 risdsnpe;risdsnpe;C:\Windows\System32\drivers\risdsne64.sys [2009-11-24 75776]
    R2 SSPORT;SSPORT;C:\Windows\System32\drivers\SSPORT.SYS [2007-10-22 11576]
    R2 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2009-11-28 411496]
    R2 VSNService;VSNService;C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2010-11-3 845312]
    R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2009-11-28 19968]
    R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2013-1-21 66728]
    R3 FirebirdServerks;Firebird Server - ks;C:\ProgramData\KS\FbDatabaseServer\bin\fbserver.exe -s ks --> C:\ProgramData\KS\FbDatabaseServer\bin\fbserver.exe -s ks [?]
    R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2011-11-16 86016]
    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-1-4 25928]
    R3 NETw5s64;Intel(R) Wireless WiFi Link adapter illesztőprogram 64 bites Windows 7;C:\Windows\System32\drivers\NETw5s64.sys [2009-9-15 6952960]
    R3 SFEP;Sony Firmware Extension Parser;C:\Windows\System32\drivers\SFEP.sys [2009-11-24 11392]
    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-11-24 393216]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-28 161384]
    S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2009-11-24 35104]
    S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2011-11-16 117248]
    S3 ew_usbenumfilter;huawei_CompositeFilter;C:\Windows\System32\drivers\ew_usbenumfilter.sys [2011-11-16 13952]
    S3 huawei_cdcacm;huawei_cdcacm;C:\Windows\System32\drivers\ew_jucdcacm.sys [2011-11-16 98816]
    S3 huawei_ext_ctrl;huawei_ext_ctrl;C:\Windows\System32\drivers\ew_juextctrl.sys [2011-11-16 28672]
    S3 huawei_wwanecm;huawei_wwanecm;C:\Windows\System32\drivers\ew_juwwanecm.sys [2011-11-16 212992]
    S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2009-6-8 5435904]
    S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\Windows\System32\drivers\pccsmcfdx64.sys [2012-8-20 26112]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-4-24 19456]
    S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2013-6-13 31800]
    S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2010-3-11 35112]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-4-24 57856]
    S3 WatAdminSvc;Windows aktiválási technológiák szolgáltatás;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-23 1255736]
    S4 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-1 33736]
    S4 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
    S4 Internet Manager. RunOuc;Internet Manager. OUC;C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [2011-11-16 224096]
    S4 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\System32\drivers\nmwcdnsucx64.sys [2012-6-11 12800]
    S4 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\System32\drivers\nmwcdnsux64.sys [2012-6-11 171008]
    S4 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-3-6 39056]
    S4 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-6-26 313840]
    S4 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-6-26 362992]
    S4 SOHCImp;VAIO Media plus Content Importer;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-11-28 120104]
    S4 SOHDBSvr;VAIO Media plus Database Manager;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-11-28 70952]
    S4 SOHDms;VAIO Media plus Digital Media Server;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-11-28 427304]
    S4 SOHDs;VAIO Media plus Device Searcher;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-11-28 75048]
    S4 SOHPlMgr;VAIO Media plus Playlist Manager;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-11-28 91432]
    S4 SynoDrService;SynoDrService;C:\Program Files (x86)\Synology Data Replicator 3\SynoDrServicex64.exe [2012-6-28 381312]
    S4 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-7-16 2673064]
    S4 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects 2\uCamMonitor.exe [2009-11-28 104960]
    S4 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-7-23 642920]
    S4 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2010-7-9 480624]
    S4 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-7-9 361840]
    S4 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2009-11-28 110888]
    S4 VUAgent;VUAgent;C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [2010-3-12 1223024]
    S4 yksvc;Marvell Yukon Service;C:\Windows\System32\svchost.exe -k yksvcs [2009-7-14 27136]
    .
    =============== File Associations ===============
    .
    ShellExec: VCExporterLaunch.exe: open="C:\Program Files (x86)\Sony\VAIO VP Utilities\VCELaunch.exe" "%1"
    .
    =============== Created Last 30 ================
    .
    2013-06-17 06:19:22--------d-----w-C:\FRST
    2013-06-15 21:59:01225280----a-w-C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll
    2013-06-15 21:58:37--------d-----w-C:\Program Files (x86)\x264 Video Codec
    2013-06-13 20:54:39--------d-----w-C:\Users\Matthew\AppData\Local\OutlookFreeware.com
    2013-06-13 17:40:16--------d-----w-C:\Windows\PCHEALTH
    2013-06-13 17:36:09--------d-----w-C:\Users\Matthew\AppData\Local\Windows Live
    2013-06-13 15:59:27--------d-----w-C:\Users\Matthew\AppData\Local\VS Revo Group
    2013-06-13 15:59:20--------d-----w-C:\ProgramData\VS Revo Group
    2013-06-13 15:59:1931800----a-w-C:\Windows\System32\drivers\revoflt.sys
    2013-06-13 15:59:17--------d-----w-C:\Program Files\VS Revo Group
    2013-06-13 14:54:5977656----a-w-C:\Windows\System32\XAPOFX1_5.dll
    2013-06-13 14:54:5974072----a-w-C:\Windows\SysWow64\XAPOFX1_5.dll
    2013-06-13 14:54:59527192----a-w-C:\Windows\SysWow64\XAudio2_7.dll
    2013-06-13 14:54:59518488----a-w-C:\Windows\System32\XAudio2_7.dll
    2013-06-13 14:54:572526056----a-w-C:\Windows\System32\D3DCompiler_43.dll
    2013-06-13 14:54:572106216----a-w-C:\Windows\SysWow64\D3DCompiler_43.dll
    2013-06-13 14:54:56276832----a-w-C:\Windows\System32\d3dx11_43.dll
    2013-06-13 14:54:56248672----a-w-C:\Windows\SysWow64\d3dx11_43.dll
    2013-06-13 14:13:40--------d-----w-C:\Users\Matthew\AppData\Roaming\FixIt
    2013-06-12 22:44:52--------d-----w-C:\Users\Matthew\AppData\Local\{4BF9D083-61FC-4592-B7FE-70A103021650}
    2013-06-12 10:46:151424384----a-w-C:\Windows\System32\WindowsCodecs.dll
    2013-06-12 10:46:151230336----a-w-C:\Windows\SysWow64\WindowsCodecs.dll
    2013-06-12 10:46:141910632----a-w-C:\Windows\System32\drivers\tcpip.sys
    2013-06-12 10:46:141887232----a-w-C:\Windows\System32\d3d11.dll
    2013-06-12 10:46:131505280----a-w-C:\Windows\SysWow64\d3d11.dll
    2013-06-12 10:46:11751104----a-w-C:\Windows\System32\win32spl.dll
    2013-06-12 10:46:11492544----a-w-C:\Windows\SysWow64\win32spl.dll
    2013-06-12 10:46:0130720----a-w-C:\Windows\System32\cryptdlg.dll
    2013-06-12 10:46:0124576----a-w-C:\Windows\SysWow64\cryptdlg.dll
    2013-06-12 10:45:47903168----a-w-C:\Windows\SysWow64\certutil.exe
    2013-06-12 10:45:4752224----a-w-C:\Windows\System32\certenc.dll
    2013-06-12 10:45:4743008----a-w-C:\Windows\SysWow64\certenc.dll
    2013-06-12 10:45:47184320----a-w-C:\Windows\System32\cryptsvc.dll
    2013-06-12 10:45:471464320----a-w-C:\Windows\System32\crypt32.dll
    2013-06-12 10:45:47140288----a-w-C:\Windows\SysWow64\cryptsvc.dll
    2013-06-12 10:45:47139776----a-w-C:\Windows\System32\cryptnet.dll
    2013-06-12 10:45:471192448----a-w-C:\Windows\System32\certutil.exe
    2013-06-12 10:45:471160192----a-w-C:\Windows\SysWow64\crypt32.dll
    2013-06-12 10:45:47103936----a-w-C:\Windows\SysWow64\cryptnet.dll
    2013-06-12 10:44:20--------d-----w-C:\Users\Matthew\AppData\Local\{693C9475-22A3-4D5A-9DE5-B71672B67838}
    2013-06-11 22:43:49--------d-----w-C:\Users\Matthew\AppData\Local\{E4078F45-7571-4EDA-A9BA-1E10309FE078}
    2013-06-11 10:43:22--------d-----w-C:\Users\Matthew\AppData\Local\{672ECD9C-B3B8-45E9-9FEA-C27BAA8AFAA1}
    2013-06-11 09:15:40--------d-----w-C:\Users\Matthew\AppData\Local\{72B17DF5-CEA8-4061-83D0-0EE2C5B4BC13}
    2013-06-10 21:15:04--------d-----w-C:\Users\Matthew\AppData\Local\{CF67F8E2-B0F3-4F29-AE90-20E6A14E4EFC}
    2013-06-10 09:14:34--------d-----w-C:\Users\Matthew\AppData\Local\{480B359B-A643-4F4B-8D52-B7349EBF6C5F}
    2013-06-09 21:13:55--------d-----w-C:\Users\Matthew\AppData\Local\{6A5CE5BC-09A9-4277-BFCE-144C9A43EC9B}
    2013-06-09 09:13:20--------d-----w-C:\Users\Matthew\AppData\Local\{80363C8A-C98B-4C6C-8A53-7877721B28AE}
    2013-06-08 12:11:4839896----a-w-C:\Windows\SysWow64\dischandler.exe
    2013-06-08 11:57:544012544----a-w-C:\Windows\System32\ffmpeg.dll
    2013-06-08 11:57:10474624----a-w-C:\Windows\System32\ff_kernelDeint.dll
    2013-06-08 11:56:58127488----a-w-C:\Windows\System32\ff_vfw.dll
    2013-06-08 11:56:544372992----a-w-C:\Windows\System32\ffdshow.ax
    2013-06-08 11:56:50156672----a-w-C:\Windows\System32\ff_libmad.dll
    2013-06-08 11:56:18631296----a-w-C:\Windows\System32\TomsMoComp_ff.dll
    2013-06-08 11:55:52114688----a-w-C:\Windows\System32\ff_wmv9.dll
    2013-06-08 11:55:501532928----a-w-C:\Windows\System32\ff_samplerate.dll
    2013-06-08 11:55:50116224----a-w-C:\Windows\System32\ff_liba52.dll
    2013-06-08 11:55:48222720----a-w-C:\Windows\System32\ff_libdts.dll
    2013-06-08 11:55:48183296----a-w-C:\Windows\System32\ff_unrar.dll
    2013-06-08 11:55:46190464----a-w-C:\Windows\System32\libmpeg2_ff.dll
    2013-06-08 11:54:103915776----a-w-C:\Windows\SysWow64\ffmpeg.dll
    2013-06-08 11:53:06112640----a-w-C:\Windows\SysWow64\ff_vfw.dll
    2013-06-08 11:53:023501568----a-w-C:\Windows\SysWow64\ffdshow.ax
    2013-06-08 11:52:30271360----a-w-C:\Windows\SysWow64\TomsMoComp_ff.dll
    2013-06-08 11:52:12157184----a-w-C:\Windows\SysWow64\ff_unrar.dll
    2013-06-08 11:52:1099840----a-w-C:\Windows\SysWow64\ff_wmv9.dll
    2013-06-08 11:52:10147456----a-w-C:\Windows\SysWow64\ff_libmad.dll
    2013-06-08 11:52:08211968----a-w-C:\Windows\SysWow64\ff_libdts.dll
    2013-06-08 11:52:081525760----a-w-C:\Windows\SysWow64\ff_samplerate.dll
    2013-06-08 11:52:08114688----a-w-C:\Windows\SysWow64\ff_liba52.dll
    2013-06-08 11:52:06136704----a-w-C:\Windows\SysWow64\libmpeg2_ff.dll
    2013-06-08 08:19:53--------d-----w-C:\Users\Matthew\AppData\Local\{1CF3A187-BF39-4987-82A8-45C396CE9CB8}
    2013-06-07 10:37:56--------d-----w-C:\Users\Matthew\AppData\Local\{2DCAE9DA-A087-43D8-8ED7-1D61D12354DE}
    2013-06-06 18:35:51--------d-----w-C:\Users\Matthew\AppData\Local\{CC4E7B6C-7A19-45B2-93F7-C79E7349E9AF}
    2013-06-06 06:03:25--------d-----w-C:\Users\Matthew\AppData\Local\{1962E97A-D21D-4BB9-863B-D74695C37665}
    2013-06-05 09:27:58--------d-----w-C:\Users\Matthew\AppData\Local\{91511563-AA58-4D05-B2B8-96C0E8A1ABB0}
    2013-06-04 21:27:31--------d-----w-C:\Users\Matthew\AppData\Local\{34694F47-941C-49F3-88FC-C69CAD00AEA4}
    2013-06-04 13:29:26--------d-----w-C:\Program Files (x86)\NirSoft
    2013-06-04 08:02:25--------d-----w-C:\Users\Matthew\AppData\Local\{2BF36FBB-C7C4-45BB-8DB2-A8421EA72FCE}
    2013-06-03 20:01:48--------d-----w-C:\Users\Matthew\AppData\Local\{42611709-A35C-4207-8532-C5DA63D5C78E}
    2013-06-03 08:01:10--------d-----w-C:\Users\Matthew\AppData\Local\{6FD50C7E-85E9-458A-9888-CBB4D8DF26F9}
    2013-06-02 20:00:46--------d-----w-C:\Users\Matthew\AppData\Local\{4A125A5F-3BDA-40DE-8724-84A301BFAEB2}
    2013-06-02 06:54:54--------d-----w-C:\Users\Matthew\AppData\Local\{5E938FF8-66AF-4599-A4D9-861500CCC3AC}
    2013-06-01 07:49:19--------d-----w-C:\Users\Matthew\AppData\Local\{F90E7281-3419-4576-9817-8D75C9EF2F62}
    2013-05-31 18:51:58--------d-----w-C:\Users\Matthew\AppData\Local\{2B8DAE0B-EB64-47BA-A8EC-5DBB647E1F3A}
    2013-05-31 06:12:15--------d-----w-C:\Users\Matthew\AppData\Local\{BAA63AD4-374B-4723-899A-FAF8266B18CB}
    2013-05-30 18:11:45--------d-----w-C:\Users\Matthew\AppData\Local\{0BD09CF9-134F-4AB4-BF52-761B1AE0B663}
    2013-05-30 04:49:45--------d-----w-C:\Users\Matthew\AppData\Local\{F2DC59E3-D845-4514-B0C8-271276788E14}
    2013-05-29 10:59:02--------d-----w-C:\Users\Matthew\AppData\Local\{F64705A9-6E74-4513-938F-AFB79A132CC8}
    2013-05-28 19:56:08--------d-----w-C:\Users\Matthew\AppData\Local\{DD63EE21-C48D-4338-A247-610F9EA738D2}
    2013-05-28 07:55:30--------d-----w-C:\Users\Matthew\AppData\Local\{B0D35795-4335-4DE8-B336-9D08961A0493}
    2013-05-27 19:54:52--------d-----w-C:\Users\Matthew\AppData\Local\{EB5144F0-B9A9-49C2-AECD-D51E6F76DF96}
    2013-05-27 08:30:56--------d-----w-C:\Program Files (x86)\JDownloader
    2013-05-27 07:54:39--------d-----w-C:\Users\Matthew\AppData\Local\{75180D18-C6DC-4646-97EA-7A8513F3E935}
    2013-05-26 19:54:00--------d-----w-C:\Users\Matthew\AppData\Local\{754E4D21-0EC0-4A50-8563-E8B549EF075D}
    2013-05-26 07:53:13--------d-----w-C:\Users\Matthew\AppData\Local\{DBF9861E-6D0F-49B1-A0C8-21F095F0B351}
    2013-05-25 19:22:41--------d-----w-C:\Users\Matthew\AppData\Local\{D540B30C-ACD1-4343-A458-969F047734BA}
    2013-05-25 01:00:38--------d-----w-C:\Users\Matthew\AppData\Local\{E7A2106A-C03B-4B72-AED0-B03D7C3C3C3B}
    2013-05-24 11:11:51--------d-----w-C:\Users\Matthew\AppData\Local\{0B9EFA73-5A94-4D77-A07C-89F6F4316DC0}
    2013-05-23 23:11:24--------d-----w-C:\Users\Matthew\AppData\Local\{E4A77B80-77E9-4311-8F83-DEEF62403960}
    2013-05-23 07:32:51--------d-----w-C:\Users\Matthew\AppData\Local\{DF1332F7-5BC8-464C-8717-44DC568C42AA}
    2013-05-22 19:32:38--------d-----w-C:\Users\Matthew\AppData\Local\{7566F208-64C7-45B1-8D0A-E9F68161EDA6}
    2013-05-22 05:55:12--------d-----w-C:\Users\Matthew\AppData\Local\{3FB7FC37-6FD9-4764-8E51-3BE05D60038A}
    2013-05-21 17:17:46--------d-----w-C:\Users\Matthew\AppData\Local\{FB799B09-EE16-4793-BAB7-3AB3D3305D60}
    2013-05-21 07:22:32--------d-----w-C:\Users\Matthew\abevjava
    2013-05-21 07:21:54--------d-----w-C:\Users\Matthew\.abevjava
    2013-05-21 05:17:21--------d-----w-C:\Users\Matthew\AppData\Local\{3A371223-F5DB-4617-9CAE-D32A0123D909}
    2013-05-20 13:38:51--------d-----w-C:\Users\Matthew\AppData\Local\{58F8F17D-C141-4F46-A62F-67ABBDB541E3}
    2013-05-19 19:51:07--------d-----w-C:\Users\Matthew\AppData\Local\{6ACD7A64-1E8E-49E5-A3F1-EBB16EE9F134}
    .
    ==================== Find3M ====================
    .
    2013-05-17 01:25:571767936----a-w-C:\Windows\SysWow64\wininet.dll
    2013-05-17 01:25:272877440----a-w-C:\Windows\SysWow64\jscript9.dll
    2013-05-17 01:25:2661440----a-w-C:\Windows\SysWow64\iesetup.dll
    2013-05-17 01:25:26109056----a-w-C:\Windows\SysWow64\iesysprep.dll
    2013-05-17 00:59:032241024----a-w-C:\Windows\System32\wininet.dll
    2013-05-17 00:58:103958784----a-w-C:\Windows\System32\jscript9.dll
    2013-05-17 00:58:0867072----a-w-C:\Windows\System32\iesetup.dll
    2013-05-17 00:58:08136704----a-w-C:\Windows\System32\iesysprep.dll
    2013-05-14 13:14:012706432----a-w-C:\Windows\System32\mshtml.tlb
    2013-05-14 12:23:2589600----a-w-C:\Windows\System32\RegisterIEPKEYs.exe
    2013-05-14 09:23:312706432----a-w-C:\Windows\SysWow64\mshtml.tlb
    2013-05-14 08:40:1371680----a-w-C:\Windows\SysWow64\RegisterIEPKEYs.exe
    2013-05-06 11:13:5131----a-w-C:\Windows\System32\scadoqw.dll
    2013-04-30 05:15:59599552----a-w-C:\Windows\System32\vbscript.dll
    2013-04-30 05:15:59167424----a-w-C:\Windows\System32\iexpress.exe
    2013-04-30 05:15:59144896----a-w-C:\Windows\System32\wextract.exe
    2013-04-30 05:15:5892160----a-w-C:\Windows\System32\SetIEInstalledDate.exe
    2013-04-30 05:15:5851200----a-w-C:\Windows\System32\imgutil.dll
    2013-04-30 05:15:58173568----a-w-C:\Windows\System32\ieUnatt.exe
    2013-04-30 05:15:5813824----a-w-C:\Windows\System32\mshta.exe
    2013-04-30 05:15:58135680----a-w-C:\Windows\System32\IEAdvpack.dll
    2013-04-30 05:15:5777312----a-w-C:\Windows\System32\tdc.ocx
    2013-04-30 05:15:5748640----a-w-C:\Windows\System32\mshtmler.dll
    2013-04-26 10:16:3227648----a-w-C:\Windows\System32\OKLMON64.DLL
    2013-04-26 10:16:3074701----a-w-C:\Windows\SysWow64\Uninstal.exe
    2013-04-13 05:49:23135168----a-w-C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
    2013-04-13 05:49:19350208----a-w-C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2013-04-13 05:49:19308736----a-w-C:\Windows\apppatch\AppPatch64\AcGenral.dll
    2013-04-13 05:49:19111104----a-w-C:\Windows\apppatch\AppPatch64\acspecfc.dll
    2013-04-13 04:45:16474624----a-w-C:\Windows\apppatch\AcSpecfc.dll
    2013-04-13 04:45:152176512----a-w-C:\Windows\apppatch\AcGenral.dll
    2013-04-12 14:45:081656680----a-w-C:\Windows\System32\drivers\ntfs.sys
    2013-04-10 06:01:54265064----a-w-C:\Windows\System32\drivers\dxgmms1.sys
    2013-04-10 06:01:53983400----a-w-C:\Windows\System32\drivers\dxgkrnl.sys
    2013-04-10 03:30:503153920----a-w-C:\Windows\System32\win32k.sys
    2013-04-04 12:50:3225928----a-w-C:\Windows\System32\drivers\mbam.sys
    2013-04-04 03:35:0595648----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
    2013-03-24 19:52:03130560----a-w-C:\Windows\SysWow64\audio.dll
    2012-06-06 04:06:502174976----a-w-C:\Program Files (x86)\Common Files\atimpenc.dll
    .
    ============= FINISH: 20:45:24,62 ===============
  4. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 2010.03.04. 20:36:53
    System Uptime: 2013.06.17. 20:35:58 (0 hours ago)
    .
    Motherboard: Sony Corporation | | VAIO
    Processor: Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz | N/A | 1599/266mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 165 GiB total, 5,897 GiB free.
    D: is Removable
    E: is Removable
    F: is CDROM ()
    G: is FIXED (NTFS) - 117 GiB total, 17,78 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0000
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0000
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0001
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0001
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0002
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0002
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0003
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0003
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0004
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0004
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0005
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0005
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0006
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0006
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0007
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0007
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\WPD\0008
    Manufacturer:
    Name:
    PNP Device ID: ROOT\WPD\0008
    Service:
    .
    ==== System Restore Points ===================
    .
    RP745: 2013.06.14. 23:12:41 - Windows Update
    RP746: 2013.06.17. 8:23:43 - Windows biztonsági másolat
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    ĹíçěĺńůěÝíç Ýęäďóç Microsoft Office Excel 2007 Help (KB963678)
    ĹíçěĺńůěÝíç Ýęäďóç Microsoft Office Powerpoint 2007 Help (KB963669)
    ĹíçěĺńůěÝíç Ýęäďóç Microsoft Office Word 2007 Help (KB963665)
    2007 Microsoft Office system
    A Microsoft .NET-keretrendszer 4-es verziójához tartozó ügyfélprofil HUN nyelvi csomagja
    ABBYY FineReader 10 Professional Edition
    Actualizare Microsoft Office Excel 2007 Help (KB963678)
    Actualizare Microsoft Office Powerpoint 2007 Help (KB963669)
    Actualizare Microsoft Office Word 2007 Help (KB963665)
    Actualizaçăo do Microsoft Office Excel 2007 Help (KB963678)
    Actualizaçăo do Microsoft Office Powerpoint 2007 Help (KB963669)
    Actualizaçăo do Microsoft Office Word 2007 Help (KB963665)
    Adobe Acrobat XI Pro
    Adobe AIR
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Help Manager
    Adobe Illustrator CS6
    Adobe InDesign CS6
    Adobe Photoshop CS6
    Adobe Reader 9.5.2
    Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678)
    Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669)
    Aktualizace produktu Microsoft Office Word 2007 Help (KB963665)
    Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678)
    Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669)
    Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665)
    Aktualizácia Microsoft Office Excel 2007 Help (KB963678)
    Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669)
    Aktualizácia Microsoft Office Word 2007 Help (KB963665)
    AP Tuner 3.06
    Apple Application Support
    Apple Software Update
    ArcSoft Magic-I Visual Effects 2
    ArcSoft WebCam Companion 3
    µTorrent
    Audacity 2.0
    AVG 2013
    BDE_ENT
    Bulk Rename Utility 2.7.1.2
    Business Contact Manager for Outlook 2007 SP2
    CCleaner
    Clear Admin Számlázó
    Click to Disc
    Click to Disc Editor
    Compatibility Pack for the 2007 Office system
    Conduit Engine
    CutePDF Writer 2.8
    D3DX10
    DHTML Editing Component
    DigiFoto24 Fotovilag
    e-Sword
    e-Szignó 3.2.5.2
    Easy Video Splitter 1.28
    Email Sender Deluxe
    Encore
    Facebook Video Calling 1.2.0.159
    FFmpeg v0.6.2 for Audacity
    FileZilla Client 3.7.0.2
    FormatFactory 2.20
    Free CD to MP3 Converter
    FreeOCR v4.2
    Google Chrome
    Google Earth Plug-in
    Google Update Helper
    GPL MPEG-1/2 DirectShow Decoder Filter
    GroupMail :: Free Edition
    HP Photo Creations Sooters
    I-Sound Pro 6.9.6.0
    I-Sound Recorder Pro 7.02
    InCash InComm Toner Plaza
    Intel® Matrix Storage Manager
    Internet Manager
    Java 7 Update 21
    Java Auto Updater
    Java(TM) 6 Update 14 (64-bit)
    Java(TM) 6 Update 33
    JDownloader 0.9
    Junk Mail filter update
    Karaoke for DirectX (remove only)
    Kulcs-Ügyvitel
    LADSPA_plugins-win-0.4.15
    LAME v3.99.3 (for Windows)
    Malwarebytes Anti-Malware 1.75.0.1300 verzió
    Media Gallery
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Client Profile HUN Language Pack
    Microsoft Application Error Reporting
    Microsoft Office 2003 webösszetevők
    Microsoft Office 2007 Primary Interop Assemblies
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office Access MUI (Hungarian) 2007
    Microsoft Office Excel 2007 Help-frissítés (KB963678)
    Microsoft Office Excel 2007 Help Ŕęňóŕëčçŕöč˙ (KB963678)
    Microsoft Office Excel 2007 Help Güncelleţtirmesi (KB963678)
    Microsoft Office Excel 2007 Help Uppdatering (KB963678)
    Microsoft Office Excel MUI (Bulgarian) 2007
    Microsoft Office Excel MUI (Czech) 2007
    Microsoft Office Excel MUI (Danish) 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Excel MUI (Finnish) 2007
    Microsoft Office Excel MUI (Greek) 2007
    Microsoft Office Excel MUI (Hungarian) 2007
    Microsoft Office Excel MUI (Polish) 2007
    Microsoft Office Excel MUI (Portuguese (Portugal)) 2007
    Microsoft Office Excel MUI (Romanian) 2007
    Microsoft Office Excel MUI (Slovak) 2007
    Microsoft Office Excel MUI (Swedish) 2007
    Microsoft Office Excel MUI (Turkish) 2007
    Microsoft Office File Validation Add-In
    Microsoft Office Home and Student 2007
    Microsoft Office Office 64-bit Components 2007
    Microsoft Office OneNote MUI (Bulgarian) 2007
    Microsoft Office OneNote MUI (Czech) 2007
    Microsoft Office OneNote MUI (Danish) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office OneNote MUI (Finnish) 2007
    Microsoft Office OneNote MUI (Greek) 2007
    Microsoft Office OneNote MUI (Hungarian) 2007
    Microsoft Office OneNote MUI (Polish) 2007
    Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007
    Microsoft Office OneNote MUI (Romanian) 2007
    Microsoft Office OneNote MUI (Slovak) 2007
    Microsoft Office OneNote MUI (Swedish) 2007
    Microsoft Office OneNote MUI (Turkish) 2007
    Microsoft Office Outlook Connector
    Microsoft Office Outlook MUI (Hungarian) 2007
    Microsoft Office Powerpoint 2007 Help-frissítés (KB963669)
    Microsoft Office Powerpoint 2007 Help Ŕęňóŕëčçŕöč˙ (KB963669)
    Microsoft Office Powerpoint 2007 Help Güncelleţtirmesi (KB963669)
    Microsoft Office Powerpoint 2007 Help Uppdatering (KB963669)
    Microsoft Office PowerPoint MUI (Bulgarian) 2007
    Microsoft Office PowerPoint MUI (Czech) 2007
    Microsoft Office PowerPoint MUI (Danish) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint MUI (Finnish) 2007
    Microsoft Office PowerPoint MUI (Greek) 2007
    Microsoft Office PowerPoint MUI (Hungarian) 2007
    Microsoft Office PowerPoint MUI (Polish) 2007
    Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007
    Microsoft Office PowerPoint MUI (Romanian) 2007
    Microsoft Office PowerPoint MUI (Slovak) 2007
    Microsoft Office PowerPoint MUI (Swedish) 2007
    Microsoft Office PowerPoint MUI (Turkish) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Professional 2007
    Microsoft Office Professional Hybrid 2007
    Microsoft Office Proof (Bulgarian) 2007
    Microsoft Office Proof (Czech) 2007
    Microsoft Office Proof (Danish) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (Finnish) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (German) 2007
    Microsoft Office Proof (Greek) 2007
    Microsoft Office Proof (Hungarian) 2007
    Microsoft Office Proof (Polish) 2007
    Microsoft Office Proof (Portuguese (Portugal)) 2007
    Microsoft Office Proof (Romanian) 2007
    Microsoft Office Proof (Russian) 2007
    Microsoft Office Proof (Slovak) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proof (Swedish) 2007
    Microsoft Office Proof (Turkish) 2007
    Microsoft Office Proofing (Bulgarian) 2007
    Microsoft Office Proofing (Czech) 2007
    Microsoft Office Proofing (Danish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing (Finnish) 2007
    Microsoft Office Proofing (Greek) 2007
    Microsoft Office Proofing (Hungarian) 2007
    Microsoft Office Proofing (Polish) 2007
    Microsoft Office Proofing (Portuguese (Portugal)) 2007
    Microsoft Office Proofing (Romanian) 2007
    Microsoft Office Proofing (Slovak) 2007
    Microsoft Office Proofing (Swedish) 2007
    Microsoft Office Proofing (Turkish) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (Hungarian) 2007
    Microsoft Office Shared 64-bit MUI (Bulgarian) 2007
    Microsoft Office Shared 64-bit MUI (Czech) 2007
    Microsoft Office Shared 64-bit MUI (Danish) 2007
    Microsoft Office Shared 64-bit MUI (English) 2007
    Microsoft Office Shared 64-bit MUI (Finnish) 2007
    Microsoft Office Shared 64-bit MUI (Greek) 2007
    Microsoft Office Shared 64-bit MUI (Hungarian) 2007
    Microsoft Office Shared 64-bit MUI (Polish) 2007
    Microsoft Office Shared 64-bit MUI (Portuguese (Portugal)) 2007
    Microsoft Office Shared 64-bit MUI (Romanian) 2007
    Microsoft Office Shared 64-bit MUI (Slovak) 2007
    Microsoft Office Shared 64-bit MUI (Swedish) 2007
    Microsoft Office Shared 64-bit MUI (Turkish) 2007
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
    Microsoft Office Shared MUI (Bulgarian) 2007
    Microsoft Office Shared MUI (Czech) 2007
    Microsoft Office Shared MUI (Danish) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared MUI (Finnish) 2007
    Microsoft Office Shared MUI (Greek) 2007
    Microsoft Office Shared MUI (Hungarian) 2007
    Microsoft Office Shared MUI (Polish) 2007
    Microsoft Office Shared MUI (Portuguese (Portugal)) 2007
    Microsoft Office Shared MUI (Romanian) 2007
    Microsoft Office Shared MUI (Slovak) 2007
    Microsoft Office Shared MUI (Swedish) 2007
    Microsoft Office Shared MUI (Turkish) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Small Business csatlakozási összetevők
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word 2007 Help-frissítés (KB963665)
    Microsoft Office Word 2007 Help Ŕęňóŕëčçŕöč˙ (KB963665)
    Microsoft Office Word 2007 Help Güncelleţtirmesi (KB963665)
    Microsoft Office Word 2007 Help Uppdatering (KB963665)
    Microsoft Office Word MUI (Bulgarian) 2007
    Microsoft Office Word MUI (Czech) 2007
    Microsoft Office Word MUI (Danish) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Office Word MUI (Finnish) 2007
    Microsoft Office Word MUI (Greek) 2007
    Microsoft Office Word MUI (Hungarian) 2007
    Microsoft Office Word MUI (Polish) 2007
    Microsoft Office Word MUI (Portuguese (Portugal)) 2007
    Microsoft Office Word MUI (Romanian) 2007
    Microsoft Office Word MUI (Slovak) 2007
    Microsoft Office Word MUI (Swedish) 2007
    Microsoft Office Word MUI (Turkish) 2007
    Microsoft Reader
    Microsoft Silverlight
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable (x64)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft Works
    Microsoft_VC100_CRT_SP1_x64
    Microsoft_VC100_CRT_SP1_x86
    Microsoft_VC80_ATL_x86
    Microsoft_VC80_CRT_x86
    Microsoft_VC80_MFC_x86
    Microsoft_VC80_MFCLOC_x86
    Microsoft_VC90_ATL_x86
    Microsoft_VC90_ATL_x86_x64
    Microsoft_VC90_CRT_x86
    Microsoft_VC90_CRT_x86_x64
    Microsoft_VC90_MFC_x86
    Microsoft_VC90_MFC_x86_x64
    Microsoft_VC90_MFCLOC_x86
    MID Converter 4.2
    MIDI Maestro MM4
    MIDI TO WAV MAKER version 2.22
    MixPad Audio Mixer
    Mobipocket Reader 6.2
    Mozilla Firefox 14.0.1 (x86 hu)
    Mp3tag v2.50
    MSVC80_x64_v2
    MSVC80_x86_v2
    MSVC90_x64
    MSVC90_x86
    MSVCRT
    MSVCRT_amd64
    MSVCRT110
    MSVCRT110_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB2721691)
    MSXML 4.0 SP3 Parser (KB2758694)
    MSXML 4.0 SP3 Parser (KB973685)
    MuseScore 1.2 MuseScore score typesetter
    Music Transfer
    NirSoft BlueScreenView
    Nokia Connectivity Cable Driver
    Nokia Suite
    Norton Online Backup
    Null FTP Client 1.3.0.0
    NVIDIA Display Control Panel
    NVIDIA Drivers
    NVIDIA Guard Service 1.3
    NVIDIA HD audio-illesztőprogram 1.3.18.0
    NVIDIA Install Application
    Octoshape add-in for Adobe Flash Player
    Ohjelman Microsoft Office Excel 2007 Help päivitys (KB963678)
    Ohjelman Microsoft Office Powerpoint 2007 Help päivitys (KB963669)
    Ohjelman Microsoft Office Word 2007 Help päivitys (KB963665)
    Opdatering til Microsoft Office Excel 2007 Help (KB963678)
    Opdatering til Microsoft Office Powerpoint 2007 Help (KB963669)
    Opdatering til Microsoft Office Word 2007 Help (KB963665)
    OutlookFreeware.com Utilities
    PC Connectivity Solution
    PDF Settings CS6
    pdfsam
    Photo Common
    Primo
    PVSonyDll
    QuickTime
    QuickTime Alternative 3.2.2
    Readiris Pro 10
    RealDownloader
    RealNetworks - Microsoft Visual C++ 2008 Runtime
    RealNetworks - Microsoft Visual C++ 2010 Runtime
    RealPlayer
    Realtek High Definition Audio Driver
    RealUpgrade 1.1
    REAPER (x64)
    Recuva
    Revo Uninstaller Pro 3.0.5
    Roxio Central Audio
    Roxio Central Copy
    Roxio Central Core
    Roxio Central Data
    Roxio Central Tools
    Roxio Easy Media Creator 10 LJ
    Roxio Easy Media Creator Home
    Runtime
    Samsung CLX-3170 Series
    Search-NewTab
    Search Assistant MocaFlix 1.66
    Search Assistant WebSearch 1.74
    Security Update for A Microsoft .NET-keretrendszer 4-es verziójához tartozó ügyfélprofil HUN nyelvi csomagja (KB2478663)
    Security Update for A Microsoft .NET-keretrendszer 4-es verziójához tartozó ügyfélprofil HUN nyelvi csomagja (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
    Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
    Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
    Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
    Setting Utility Series
    Sibelius Scorch (ActiveX Only)
    Sibelius Scorch (Firefox, Opera, Netscape only)
    Simple Free FTP 1.01
    Skype Click to Call
    Skype™ 6.3
    Smart Defrag 2
    SmartFTP Client
    SmartFTP Client Setup Files 4.1 (x64) (remove only)
    SmarThru 4
    SmarThru PC Fax
    Softonic-Eng7 Toolbar
    Sony Home Network Library
    Sony Picture Utility
    StuffIt Expander 2010
    Synaptics Pointing Device Driver
    Synology Assistant (remove only)
    Synology Data Replicator 3
    SZÁMADÓ-13 számlázó free
    TeamViewer 7
    theWord
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586) 32-Bit Edition
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    VAIO Content Metadata Intelligent Analyzing Manager
    VAIO Content Metadata Intelligent Network Service Manager
    VAIO Content Metadata Manager Settings
    VAIO Content Metadata XML Interface Library
    VAIO Content Monitoring Settings
    VAIO Control Center
    VAIO Data Restore Tool
    VAIO DVD Menu Data Basic
    VAIO Entertainment Platform
    VAIO Event Service
    VAIO Gate
    VAIO Marketing Tools
    VAIO Media plus
    VAIO Media plus Opening Movie
    VAIO Movie Story
    VAIO Movie Story 1.5 Upgrade
    VAIO Movie Story Template Data
    VAIO Original Function Settings
    VAIO Personalization Manager
    VAIO Power Management
    VAIO Premium Partners 1.00
    VAIO Presentation Support
    VAIO Quick Web Access
    VAIO Sample Contents
    VAIO Smart Network
    VAIO Transfer Support
    VAIO Update
    VAIO Wallpaper Contents
    VC80CRTRedist - 8.0.50727.4053
    VectorEye3
    Virtual Audio Cable 4.10
    Visual C++ 8.0 Runtime Setup Package (x64)
    Visual Studio 2008 x64 Redistributables
    Visual Studio 2010 x64 Redistributables
    VLC media player 2.0.6
    WavePad Sound Editor
    WIDCOMM Bluetooth Software
    Windows 7 Codec Pack 4.0.7
    Windows illesztőprogram-csomag - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
    Windows Installer Clean Up
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Mail
    Windows Live MIME IFilter
    Windows Live Photo Common
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows Resource Kit Tools - SubInAcl.exe
    WinRAR archiváló
    WinX Free DVD to MPEG Ripper 4.4.18
    Wondershare Streaming Video Recorder(Build 2.0.1.4)
    Xilisoft DVD Audio Ripper 5
    Xilisoft DVD to DPG Converter 6
    .
    ==== End Of File ===========================
  5. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    I hope I uploaded everything correctly.
  6. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ============================================

    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
  7. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    Dear Broni, Thank you for taking this issue on. I have downloaded the Rogue Killer and got it scanning, however AVG goes crazy with Generic31, Generic32, Backdoor, viruses etc. Then, before the scan is finished, I get blue death with the comment rimssne64.sys. I ran this twice with the same result. The second time a log was made, which I will post seperately. How should I proceed? Should I turn off AVG while the scan is running?
  8. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    The debug.txt from Rogue Killer is over 1 million characters. I can't upload it, how should I proceed?
  9. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    Skip RogueKiller and go ahead with MBAR.
  10. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    Hi Broni, I've had an interesting morning... I made a new restore point and then went ahead with MBAR. It found 9 malwares: services.exe + 8 in windows/installer folder. I cleaned them, restarted, and ran the scan again, this time it found nothing. I had a problem with Windows office wanting to reinstall itself - but I've had that before and know how to "get around it". I worked on the computer for 1/2 hour and AVG did not complain about any viruses, so good news. I went for a short break before posting the MBAR results. When I got back the computer was in the middle of a system restore trying to run startup repair. It did this for over half an hour and nothing changed. I rebooted the computer and this time tried to run the system restore to the point before running MBAR, its now been "restoring files" for over an hour with no apparent progress. I'm writing from a different computer now - but don't know how to proceed - any help much appreciated.
  11. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    After 2 hours I have turned it off. Let me know you suggest I do next? Thanks, Matthew
     
  12. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.

    If you are using Vista or Windows 7 enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:


    • [*]Startup Repair
      [*]System Restore
      [*]Windows Complete PC Restore
      [*]Windows Memory Diagnostic Tool
      [*]Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
  13. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    I'll put it in two posts, because its too big:

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-06-2013
    Ran by SYSTEM on 20-06-2013 03:06:58
    Running from H:\
    Windows 7 Home Premium (X64) OS Language: English(US)
    Internet Explorer Version 10
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [444904 2012-09-20] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [3147384 2012-12-11] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot [295512 2013-03-18] (RealNetworks, Inc.)
    HKU\Matthew\...\Run: [] [x]
    HKU\Matthew\...\Run: [AdobeBridge] [x]
    Startup: C:\ProgramData\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk
    ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\SysWOW64\C2MP\TrayMenu.exe ()
    Startup: C:\ProgramData\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
    ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ()

    ==================== Services (Whitelisted) =================

    S2 ABBYY.Licensing.FineReader.Professional.10.0; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [814344 2009-12-21] (ABBYY)
    S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
    S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.)
    S2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.)
    S2 FirebirdGuardianks; C:\ProgramData\KS\FbDatabaseServer\bin\fbguard.exe [98304 2013-04-26] (Firebird Project)
    S3 FirebirdServerks; C:\ProgramData\KS\FbDatabaseServer\bin\fbserver.exe [3735552 2013-04-26] (Firebird Project)
    S4 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
    S4 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-11-16] ()
    S2 KSWebSvc; C:\ProgramData\KS\Bin\KSWebSvc.exe [134376 2013-04-26] (Kulcs-Soft Számítástechnika Nyrt.)
    S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
    S4 MSSQL$MSSMLBIZ; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
    S2 nvservice; C:\Windows\system32\nvservice.exe [192800 2013-02-04] (NVIDIA Corporation)
    S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
    S4 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions)
    S4 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions)
    S4 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-28] (Sony Corporation)
    S4 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-28] (Sony Corporation)
    S4 SynoDrService; C:\Program Files (x86)\Synology Data Replicator 3\SynoDrServicex64.exe [381312 2012-06-28] ()
    S4 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
    S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation)
    S4 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation)
    S4 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1223024 2010-04-09] (Sony Corporation)
    S4 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [206336 2009-07-23] (Sony Corporation)
    S4 yksvc; C:\Windows\System32\yk62x64.dll [382976 2009-07-31] (Marvell)

    ==================== Drivers (Whitelisted) ====================

    S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
    S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [154464 2012-10-22] (AVG Technologies CZ, s.r.o. )
    S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [63328 2012-10-15] (AVG Technologies CZ, s.r.o. )
    S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [185696 2012-10-02] (AVG Technologies CZ, s.r.o.)
    S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [225120 2012-09-21] (AVG Technologies CZ, s.r.o.)
    S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.)
    S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40800 2012-09-14] (AVG Technologies CZ, s.r.o.)
    S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [200032 2012-09-21] (AVG Technologies CZ, s.r.o.)
    S0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2011-11-16] (Bytemobile, Inc.)
    S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-25] (Samsung Electronics Co., Ltd.)
    S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-25] (Samsung Electronics Co., Ltd.)
    S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [212992 2011-11-16] (Huawei Technologies Co., Ltd.)
    S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [36680 2013-06-19] ()
    S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [36680 2013-06-19] ()
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
    S3 mbamswissarmy; C:\Windows\system32\drivers\mbamswissarmy.sys [162008 2013-06-19] (Malwarebytes Corporation)
    S3 mbamswissarmy; C:\Windows\system32\drivers\mbamswissarmy.sys [162008 2013-06-19] (Malwarebytes Corporation)
    S0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2010-11-26] ()
    S1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2011-11-16] (Bytemobile, Inc.)
    S1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2011-11-16] (Bytemobile, Inc.)

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-06-20 02:21 - 2013-06-20 02:21 - 00000034 ____A C:\Users\Matthew\Desktop\music2.tar.gz
    2013-06-20 02:20 - 2013-06-20 02:20 - 00000034 ____A C:\Users\Matthew\Desktop\music.tar.gz
    2013-06-19 08:34 - 2013-06-19 08:34 - 00001634 ____A C:\Users\Matthew\Desktop\WINWORD parancsikonja.lnk
    2013-06-19 08:20 - 2013-06-19 08:20 - 00001634 ____A C:\Users\Matthew\Desktop\OUTLOOK parancsikonja.lnk
    2013-06-19 07:54 - 2013-06-19 07:54 - 00162008 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
    2013-06-19 07:41 - 2013-06-08 12:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-06-19 07:41 - 2013-06-08 11:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-06-19 07:40 - 2013-06-08 14:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-06-19 07:40 - 2013-06-08 14:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-06-19 07:40 - 2013-06-08 14:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-06-19 07:40 - 2013-06-08 14:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-06-19 07:40 - 2013-06-08 14:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-06-19 07:40 - 2013-06-08 11:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-06-19 07:40 - 2013-06-08 11:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-06-19 07:40 - 2013-06-08 11:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-06-19 07:40 - 2013-06-08 11:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-06-19 07:40 - 2013-06-08 11:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-06-19 07:34 - 2013-06-19 07:34 - 07940761 ____A C:\Users\Matthew\Downloads\Flying Fairy to verify (1).zip
    2013-06-19 07:02 - 2013-06-19 07:02 - 00000000 ____D C:\Users\Matthew\Desktop\WWD to verify
    2013-06-19 07:01 - 2013-06-19 07:02 - 16024350 ____A C:\Users\Matthew\Downloads\WWD to verify.zip
    2013-06-19 06:36 - 2013-06-19 06:36 - 00036680 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
    2013-06-19 06:35 - 2013-06-19 09:04 - 00000000 ____D C:\Users\Matthew\Desktop\mbar
    2013-06-19 06:34 - 2013-06-19 06:35 - 13169742 ____A C:\Users\Matthew\Desktop\mbar-1.06.0.1003.zip
    2013-06-18 20:03 - 2013-06-18 20:04 - 00294640 ____A C:\Windows\Minidump\061813-155517-01.dmp
    2013-06-18 06:08 - 2013-06-18 06:08 - 00000000 ____D C:\Users\Matthew\Desktop\Fairies
    2013-06-18 06:06 - 2013-06-18 06:08 - 70179748 ____A C:\Users\Matthew\Downloads\Fairies.zip
    2013-06-17 18:45 - 2013-06-17 18:45 - 00033731 ____A C:\Users\Matthew\Desktop\dds.txt
    2013-06-17 18:45 - 2013-06-17 18:45 - 00021338 ____A C:\Users\Matthew\Desktop\attach.txt
    2013-06-17 18:36 - 2013-06-19 10:15 - 00003560 ____A C:\Windows\PFRO.log
    2013-06-17 18:22 - 2013-06-17 18:22 - 00001065 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-06-17 18:19 - 2013-06-17 18:20 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Matthew\Downloads\mbam-setup-1.75.0.1300.exe
    2013-06-17 06:22 - 2013-06-17 06:22 - 00093795 ____A C:\Users\Matthew\Downloads\FRST.txt
    2013-06-17 06:19 - 2013-06-17 06:19 - 00000000 ____D C:\FRST
    2013-06-17 06:18 - 2013-06-17 06:18 - 01926844 ____A (Farbar) C:\Users\Matthew\Downloads\FRST64.exe
    2013-06-15 21:58 - 2013-06-15 21:58 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
    2013-06-15 21:08 - 2013-06-15 21:08 - 00030860 ____A C:\Users\Matthew\Downloads\Grown Ups 2 2013 English [DVDRip].torrent
    2013-06-14 13:07 - 2013-06-19 07:35 - 00000000 ____D C:\Users\Matthew\Desktop\Flying Fairy to verify
    2013-06-14 13:07 - 2013-06-14 13:07 - 07940761 ____A C:\Users\Matthew\Downloads\Flying Fairy to verify.zip
    2013-06-14 12:35 - 2013-06-17 23:40 - 00008745 ____A C:\Users\Matthew\Desktop\{6d2b5079-2f0b-48dd-ab7f-97cec514d30b}.xlsx
    2013-06-14 12:25 - 2013-06-14 12:25 - 00078083 ____A C:\Users\Matthew\Desktop\export_kelt___20130614142534.CSV
    2013-06-13 22:59 - 2013-06-13 22:59 - 00065481 ____A C:\Users\Matthew\Downloads\POSTINGS_00435774_20130429.xml
    2013-06-13 22:59 - 2013-06-13 22:59 - 00065481 ____A C:\Users\Matthew\Downloads\POSTINGS_00435774_20130429 (1).xml
    2013-06-13 21:11 - 2013-06-13 21:11 - 00012113 ____A C:\Users\Matthew\Desktop\export_kelt_2013-05-01_2013-06-13_20130613231121.CSV
    2013-06-13 20:55 - 2013-06-13 20:55 - 00250144 ____A (Relief Software) C:\Users\Matthew\Downloads\OutlookMessagesImportEMLSetup.exe
    2013-06-13 20:54 - 2013-06-13 20:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\OutlookFreeware.com
    2013-06-13 20:54 - 2013-06-13 20:54 - 00003039 ____A C:\Users\Matthew\Desktop\OutlookFreeware.com Utilities.lnk
    2013-06-13 20:51 - 2013-06-13 20:51 - 04588320 ____A (Relief Software) C:\Users\Matthew\Downloads\OutlookFreewareSetup.exe
    2013-06-13 17:40 - 2013-06-13 17:40 - 00000000 ____D C:\Windows\PCHEALTH
    2013-06-13 17:40 - 2013-06-13 17:40 - 00000000 ____D C:\Program Files\Windows Live
    2013-06-13 17:39 - 2013-06-13 17:41 - 00000000 ____D C:\Program Files (x86)\Windows Live
    2013-06-13 17:36 - 2013-06-13 18:12 - 00000000 ____D C:\Users\Matthew\AppData\Local\Windows Live
    2013-06-13 17:35 - 2013-06-13 17:35 - 01244144 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\wlsetup-web (2).exe
    2013-06-13 17:21 - 2013-06-13 17:21 - 00000020 ____A C:\Windows\8o
    2013-06-13 15:59 - 2013-06-13 15:59 - 00000000 ____D C:\Users\Matthew\AppData\Local\VS Revo Group
    2013-06-13 15:59 - 2013-06-13 15:59 - 00000000 ____D C:\ProgramData\VS Revo Group
    2013-06-13 15:59 - 2013-06-13 15:59 - 00000000 ____D C:\Program Files\VS Revo Group
    2013-06-13 15:59 - 2009-12-30 09:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys
    2013-06-13 15:58 - 2013-06-13 15:58 - 09916056 ____A (VS Revo Group ) C:\Users\Matthew\Downloads\RevoUninProSetup.exe
    2013-06-13 15:32 - 2013-06-13 15:32 - 00000020 ____A C:\Windows\¸o’
    2013-06-13 14:59 - 2013-06-14 11:02 - 00000000 ____D C:\Users\Matthew\Desktop\TRANSLATION
    2013-06-13 14:58 - 2013-06-13 14:58 - 03457900 ____A C:\Users\Matthew\Downloads\TRANSLATION.zip
    2013-06-13 14:54 - 2010-06-02 02:55 - 00527192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
    2013-06-13 14:54 - 2010-06-02 02:55 - 00518488 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_7.dll
    2013-06-13 14:54 - 2010-06-02 02:55 - 00077656 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_5.dll
    2013-06-13 14:54 - 2010-06-02 02:55 - 00074072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
    2013-06-13 14:54 - 2010-05-26 09:41 - 02526056 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_43.dll
    2013-06-13 14:54 - 2010-05-26 09:41 - 02106216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
    2013-06-13 14:54 - 2010-05-26 09:41 - 00276832 ____A (Microsoft Corporation) C:\Windows\System32\d3dx11_43.dll
    2013-06-13 14:54 - 2010-05-26 09:41 - 00248672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
    2013-06-13 14:49 - 2013-06-13 14:49 - 01244144 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\wlsetup-web (1).exe
    2013-06-13 14:32 - 2013-06-13 14:33 - 01244144 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\wlsetup-web.exe
    2013-06-13 14:13 - 2013-06-13 14:13 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\FixIt
    2013-06-13 14:12 - 2013-06-13 14:12 - 00665088 ____A C:\Users\Matthew\Downloads\MicrosoftFixit50604.msi
    2013-06-13 13:42 - 2013-06-19 07:47 - 00001120 ____A C:\Windows\setupact.log
    2013-06-13 13:42 - 2013-06-13 13:42 - 00000000 ____A C:\Windows\setuperr.log
    2013-06-13 13:30 - 2013-06-13 15:38 - 00001528 ____A C:\Windows\DirectX.log
    2013-06-13 11:19 - 2013-06-19 07:50 - 00000384 ____A C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Matthew.job
    2013-06-13 11:19 - 2013-06-17 18:21 - 00000374 ____A C:\Windows\Tasks\ReclaimerUpdateXML_Matthew.job
    2013-06-13 11:19 - 2013-06-16 07:10 - 00000378 ____A C:\Windows\Tasks\ReclaimerUpdateFiles_Matthew.job
    2013-06-12 23:37 - 2013-05-17 01:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2013-06-12 23:37 - 2013-05-17 01:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2013-06-12 23:37 - 2013-05-17 00:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2013-06-12 23:37 - 2013-05-17 00:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2013-06-12 23:37 - 2013-05-17 00:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2013-06-12 23:37 - 2013-05-17 00:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2013-06-12 23:37 - 2013-05-17 00:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2013-06-12 23:37 - 2013-05-17 00:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2013-06-12 23:37 - 2013-05-17 00:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2013-06-12 23:37 - 2013-05-17 00:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2013-06-12 23:37 - 2013-05-17 00:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2013-06-12 23:37 - 2013-05-14 12:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
    2013-06-12 23:37 - 2013-05-14 08:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2013-06-12 22:44 - 2013-06-12 22:45 - 00000000 ____D C:\Users\Matthew\AppData\Local\{4BF9D083-61FC-4592-B7FE-70A103021650}
    2013-06-12 22:28 - 2013-06-12 22:28 - 00003604 ____A C:\Users\Matthew\Downloads\szamlatetelek_1593468.xls
    2013-06-12 10:46 - 2013-05-10 05:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
    2013-06-12 10:46 - 2013-05-10 03:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
    2013-06-12 10:46 - 2013-05-08 06:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
    2013-06-12 10:46 - 2013-04-26 05:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
    2013-06-12 10:46 - 2013-04-26 04:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2013-06-12 10:46 - 2013-04-25 23:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
    2013-06-12 10:46 - 2013-04-17 07:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2013-06-12 10:46 - 2013-04-17 06:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
    2013-06-12 10:46 - 2013-03-31 22:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
    2013-06-12 10:45 - 2013-05-13 05:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2013-06-12 10:45 - 2013-05-13 05:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
    2013-06-12 10:45 - 2013-05-13 05:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
    2013-06-12 10:45 - 2013-05-13 05:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
    2013-06-12 10:45 - 2013-05-13 04:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2013-06-12 10:45 - 2013-05-13 04:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2013-06-12 10:45 - 2013-05-13 04:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2013-06-12 10:45 - 2013-05-13 03:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
    2013-06-12 10:45 - 2013-05-13 03:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
    2013-06-12 10:45 - 2013-05-13 03:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
    2013-06-12 10:44 - 2013-06-12 10:50 - 00008823 ____A C:\Users\Matthew\Desktop\formatex trash grp.xlsx
    2013-06-12 10:44 - 2013-06-12 10:44 - 00000000 ____D C:\Users\Matthew\AppData\Local\{693C9475-22A3-4D5A-9DE5-B71672B67838}
    2013-06-12 07:16 - 2013-06-17 06:51 - 00011099 ____A C:\Users\Matthew\Desktop\cobi 2013 aw marketing offers.xlsx
    2013-06-12 07:16 - 2013-06-12 07:16 - 00009814 ____A C:\Users\Matthew\Documents\cobi 2013 aw marketing offers.xlsx
    2013-06-11 22:43 - 2013-06-11 22:44 - 00000000 ____D C:\Users\Matthew\AppData\Local\{E4078F45-7571-4EDA-A9BA-1E10309FE078}
    2013-06-11 18:56 - 2013-06-11 13:12 - 00000000 ___AD C:\Users\Matthew\Desktop\termekek
    2013-06-11 18:43 - 2013-06-11 15:36 - 138770546 ____A C:\Users\Matthew\Desktop\termekek.zip
    2013-06-11 18:28 - 2013-06-11 18:28 - 00006831 ____A C:\Users\Matthew\Downloads\IR97518_2013-06-11.xlsx
    2013-06-11 15:36 - 2013-06-11 15:36 - 00013824 ____A C:\Users\Matthew\Downloads\kosar-1368276-2013_06_11_17_36_40.xls
    2013-06-11 14:52 - 2013-06-15 21:59 - 00000000 ____D C:\Users\Matthew\Downloads\Buena Vista - Disney gyujtemény 1937-2007
    2013-06-11 14:51 - 2013-06-11 14:51 - 00379443 ____A C:\Users\Matthew\Downloads\[µBit][#110900]Walt.Disney.gyujtemeny.1937-2007.torrent
    2013-06-11 14:38 - 2013-06-12 22:56 - 00015338 ____A C:\Users\Matthew\Desktop\IR75930_2013-06-11.xlsx
    2013-06-11 14:35 - 2013-06-11 14:35 - 00008780 ____A C:\Users\Matthew\Downloads\IR75930_2013-06-11.xlsx
    2013-06-11 14:34 - 2013-06-11 14:34 - 00006828 ____A C:\Users\Matthew\Downloads\IR98198_2013-06-11.xlsx
    2013-06-11 10:43 - 2013-06-11 10:43 - 00000000 ____D C:\Users\Matthew\AppData\Local\{672ECD9C-B3B8-45E9-9FEA-C27BAA8AFAA1}
    2013-06-11 09:15 - 2013-06-11 09:15 - 00000000 ____D C:\Users\Matthew\AppData\Local\{72B17DF5-CEA8-4061-83D0-0EE2C5B4BC13}
    2013-06-10 21:15 - 2013-06-10 21:15 - 00000000 ____D C:\Users\Matthew\AppData\Local\{CF67F8E2-B0F3-4F29-AE90-20E6A14E4EFC}
    2013-06-10 09:14 - 2013-06-10 09:14 - 00000000 ____D C:\Users\Matthew\AppData\Local\{480B359B-A643-4F4B-8D52-B7349EBF6C5F}
    2013-06-10 07:15 - 2013-06-10 07:18 - 30473048 ____A C:\Users\Matthew\Downloads\POWER TRAINS 2 wave (1).zip
    2013-06-09 21:13 - 2013-06-09 21:14 - 00000000 ____D C:\Users\Matthew\AppData\Local\{6A5CE5BC-09A9-4277-BFCE-144C9A43EC9B}
    2013-06-09 09:13 - 2013-06-09 09:13 - 00000000 ____D C:\Users\Matthew\AppData\Local\{80363C8A-C98B-4C6C-8A53-7877721B28AE}
    2013-06-08 12:11 - 2013-06-08 12:11 - 00039896 ____A C:\Windows\SysWOW64\dischandler.exe
    2013-06-08 11:57 - 2013-06-08 11:57 - 04012544 ____A C:\Windows\System32\ffmpeg.dll
    2013-06-08 11:57 - 2013-06-08 11:57 - 00474624 ____A C:\Windows\System32\ff_kernelDeint.dll
    2013-06-08 11:56 - 2013-06-08 11:56 - 04372992 ____A C:\Windows\System32\ffdshow.ax
    2013-06-08 11:56 - 2013-06-08 11:56 - 00631296 ____A C:\Windows\System32\TomsMoComp_ff.dll
    2013-06-08 11:56 - 2013-06-08 11:56 - 00156672 ____A C:\Windows\System32\ff_libmad.dll
    2013-06-08 11:56 - 2013-06-08 11:56 - 00127488 ____A C:\Windows\System32\ff_vfw.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 01532928 ____A C:\Windows\System32\ff_samplerate.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00222720 ____A C:\Windows\System32\ff_libdts.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00190464 ____A C:\Windows\System32\libmpeg2_ff.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00183296 ____A C:\Windows\System32\ff_unrar.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00116224 ____A C:\Windows\System32\ff_liba52.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00114688 ____A C:\Windows\System32\ff_wmv9.dll
    2013-06-08 11:54 - 2013-06-08 11:54 - 03915776 ____A C:\Windows\SysWOW64\ffmpeg.dll
    2013-06-08 11:53 - 2013-06-08 11:53 - 03501568 ____A C:\Windows\SysWOW64\ffdshow.ax
    2013-06-08 11:53 - 2013-06-08 11:53 - 00112640 ____A C:\Windows\SysWOW64\ff_vfw.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 01525760 ____A C:\Windows\SysWOW64\ff_samplerate.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00271360 ____A C:\Windows\SysWOW64\TomsMoComp_ff.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00211968 ____A C:\Windows\SysWOW64\ff_libdts.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00157184 ____A C:\Windows\SysWOW64\ff_unrar.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00147456 ____A C:\Windows\SysWOW64\ff_libmad.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00136704 ____A C:\Windows\SysWOW64\libmpeg2_ff.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00114688 ____A C:\Windows\SysWOW64\ff_liba52.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00099840 ____A C:\Windows\SysWOW64\ff_wmv9.dll
    2013-06-08 08:19 - 2013-06-08 08:20 - 00000000 ____D C:\Users\Matthew\AppData\Local\{1CF3A187-BF39-4987-82A8-45C396CE9CB8}
    2013-06-07 10:37 - 2013-06-07 10:40 - 00000000 ____D C:\Users\Matthew\AppData\Local\{2DCAE9DA-A087-43D8-8ED7-1D61D12354DE}
    2013-06-06 22:17 - 2013-06-06 22:19 - 31815152 ____A C:\Users\Matthew\Downloads\R4i V1.68b English.zip
    2013-06-06 20:59 - 2013-06-06 20:59 - 00008374 ____A C:\Users\Matthew\Downloads\IR20050_2013-06-06.xlsx
    2013-06-06 20:58 - 2013-06-06 20:58 - 00008199 ____A C:\Users\Matthew\Downloads\IR41325_2013-06-06.xlsx
    2013-06-06 18:35 - 2013-06-06 18:36 - 00000000 ____D C:\Users\Matthew\AppData\Local\{CC4E7B6C-7A19-45B2-93F7-C79E7349E9AF}
    2013-06-06 13:28 - 2013-06-06 13:29 - 30473048 ____A C:\Users\Matthew\Downloads\POWER TRAINS 2 wave.zip
    2013-06-06 09:02 - 2013-06-06 09:02 - 00263877 ____A C:\Users\Matthew\Downloads\Szamla_00033615021305300001146.x132
    2013-06-06 06:03 - 2013-06-06 06:03 - 00000000 ____D C:\Users\Matthew\AppData\Local\{1962E97A-D21D-4BB9-863B-D74695C37665}
    2013-06-05 14:46 - 2013-06-05 14:48 - 76634107 ____A C:\Users\Matthew\Downloads\Spy Gear labels to verify.zip
    2013-06-05 14:46 - 2013-06-05 14:46 - 16612869 ____A C:\Users\Matthew\Downloads\Power Trains Instructions1.zip
    2013-06-05 09:27 - 2013-06-05 09:28 - 00000000 ____D C:\Users\Matthew\AppData\Local\{91511563-AA58-4D05-B2B8-96C0E8A1ABB0}
    2013-06-04 21:27 - 2013-06-04 21:27 - 00000000 ____D C:\Users\Matthew\AppData\Local\{34694F47-941C-49F3-88FC-C69CAD00AEA4}
    2013-06-04 13:29 - 2013-06-04 13:29 - 00000000 ____D C:\Program Files (x86)\NirSoft
    2013-06-04 08:02 - 2013-06-04 08:02 - 00000000 ____D C:\Users\Matthew\AppData\Local\{2BF36FBB-C7C4-45BB-8DB2-A8421EA72FCE}
    2013-06-03 20:01 - 2013-06-03 20:02 - 00000000 ____D C:\Users\Matthew\AppData\Local\{42611709-A35C-4207-8532-C5DA63D5C78E}
    2013-06-03 19:01 - 2013-06-03 19:01 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
    2013-06-03 19:00 - 2013-06-03 19:01 - 04808816 ____A (FileZilla Project) C:\Users\Matthew\Downloads\FileZilla_3.7.0.2_win32-setup.exe
    2013-06-03 11:12 - 2013-06-03 11:13 - 20623712 ____A C:\Users\Matthew\Downloads\Translation Power Trains.zip
    2013-06-03 08:01 - 2013-06-03 08:01 - 00000000 ____D C:\Users\Matthew\AppData\Local\{6FD50C7E-85E9-458A-9888-CBB4D8DF26F9}
    2013-06-03 07:18 - 2013-06-03 08:13 - 00012042 ____A C:\Users\Matthew\Downloads\IR27584_2013-06-03.xlsx
    2013-06-02 20:00 - 2013-06-02 20:00 - 00000000 ____D C:\Users\Matthew\AppData\Local\{4A125A5F-3BDA-40DE-8724-84A301BFAEB2}
    2013-06-02 06:54 - 2013-06-02 06:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\{5E938FF8-66AF-4599-A4D9-861500CCC3AC}
    2013-06-01 18:51 - 2013-06-13 22:35 - 00000000 ____D C:\Users\Matthew\Downloads\Sherlock Holmes A Game of Shadows (2011) DVDRip XviD-MAXSPEED
    2013-06-01 07:50 - 2013-06-01 07:51 - 15047367 ____A C:\Users\Matthew\Downloads\113872.phone_h264_800k.mp4
    2013-06-01 07:49 - 2013-06-01 07:49 - 00000000 ____D C:\Users\Matthew\AppData\Local\{F90E7281-3419-4576-9817-8D75C9EF2F62}
    2013-05-31 18:51 - 2013-05-31 18:52 - 00000000 ____D C:\Users\Matthew\AppData\Local\{2B8DAE0B-EB64-47BA-A8EC-5DBB647E1F3A}
    2013-05-31 10:36 - 2013-05-31 10:36 - 00012535 ____A C:\Users\Matthew\Desktop\Cobi 2013 AW Marketing plan.xlsx
    2013-05-31 10:31 - 2013-05-31 10:35 - 00012537 ____A C:\Users\Matthew\Documents\Cobi 2013 AW Marketing plan.xlsx
    2013-05-31 06:12 - 2013-05-31 06:12 - 00000000 ____D C:\Users\Matthew\AppData\Local\{BAA63AD4-374B-4723-899A-FAF8266B18CB}
    2013-05-30 20:08 - 2013-05-30 20:08 - 02592509 ____A C:\Users\Matthew\Downloads\Peter Lerangis - Seven Wonders Book 1, The Colossus Rises.rar
    2013-05-30 19:57 - 2013-05-30 19:57 - 06347998 ____A C:\Users\Matthew\Downloads\The Maelstrom Book Four of The Tapestry by Henry H. Neff.zip
    2013-05-30 18:11 - 2013-05-30 18:11 - 00000000 ____D C:\Users\Matthew\AppData\Local\{0BD09CF9-134F-4AB4-BF52-761B1AE0B663}
    2013-05-30 15:15 - 2013-05-30 15:15 - 00009666 ____A C:\Users\Matthew\Downloads\torzs_20130530171505.zip
    2013-05-30 14:51 - 2013-05-30 14:55 - 00000000 ____D C:\Users\Matthew\Desktop\isk 2013
    2013-05-30 14:51 - 2013-05-30 14:55 - 00000000 ____D C:\Users\Matthew\Desktop\cp 2013
    2013-05-30 13:47 - 2013-05-30 13:47 - 00000000 ____D C:\Users\Matthew\Desktop\isk 2012
    2013-05-30 13:40 - 2013-05-30 13:40 - 00000000 ____D C:\Users\Matthew\Desktop\cp 2012
    2013-05-30 06:05 - 2013-05-30 06:05 - 00007474 ____A C:\Users\Matthew\Downloads\IR19961_2013-05-30.xlsx
    2013-05-30 06:05 - 2013-05-30 06:05 - 00006802 ____A C:\Users\Matthew\Downloads\IR54507_2013-05-30.xlsx
    2013-05-30 04:49 - 2013-05-30 04:50 - 00000000 ____D C:\Users\Matthew\AppData\Local\{F2DC59E3-D845-4514-B0C8-271276788E14}
    2013-05-29 21:03 - 2013-05-29 21:03 - 07590912 ____A C:\Users\Matthew\Downloads\Magyarorszag_a_XVIII_betelepules.ppt
    2013-05-29 10:59 - 2013-05-29 10:59 - 00000000 ____D C:\Users\Matthew\AppData\Local\{F64705A9-6E74-4513-938F-AFB79A132CC8}
    2013-05-28 19:56 - 2013-05-28 19:56 - 00000000 ____D C:\Users\Matthew\AppData\Local\{DD63EE21-C48D-4338-A247-610F9EA738D2}
    2013-05-28 07:55 - 2013-05-28 07:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\{B0D35795-4335-4DE8-B336-9D08961A0493}
    2013-05-27 19:54 - 2013-05-27 19:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\{EB5144F0-B9A9-49C2-AECD-D51E6F76DF96}
    2013-05-27 08:30 - 2013-05-27 08:38 - 00000000 ____D C:\Program Files (x86)\JDownloader
    2013-05-27 08:29 - 2013-05-27 08:29 - 00081488 ____A (AppWork UG (haftungsbeschränkt)) C:\Users\Matthew\Downloads\WebInstaller.exe
    2013-05-27 07:54 - 2013-05-27 07:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\{75180D18-C6DC-4646-97EA-7A8513F3E935}
    2013-05-26 19:54 - 2013-05-26 19:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\{754E4D21-0EC0-4A50-8563-E8B549EF075D}
    2013-05-26 07:53 - 2013-05-26 07:53 - 00000000 ____D C:\Users\Matthew\AppData\Local\{DBF9861E-6D0F-49B1-A0C8-21F095F0B351}
    2013-05-25 19:22 - 2013-05-25 19:23 - 00000000 ____D C:\Users\Matthew\AppData\Local\{D540B30C-ACD1-4343-A458-969F047734BA}
    2013-05-25 01:00 - 2013-05-25 01:00 - 00000000 ____D C:\Users\Matthew\AppData\Local\{E7A2106A-C03B-4B72-AED0-B03D7C3C3C3B}
    2013-05-24 11:11 - 2013-05-24 11:12 - 00000000 ____D C:\Users\Matthew\AppData\Local\{0B9EFA73-5A94-4D77-A07C-89F6F4316DC0}
    2013-05-23 23:11 - 2013-05-23 23:11 - 00000000 ____D C:\Users\Matthew\AppData\Local\{E4A77B80-77E9-4311-8F83-DEEF62403960}
    2013-05-23 07:32 - 2013-05-23 07:33 - 00000000 ____D C:\Users\Matthew\AppData\Local\{DF1332F7-5BC8-464C-8717-44DC568C42AA}
    2013-05-22 19:32 - 2013-05-22 19:32 - 00000000 ____D C:\Users\Matthew\AppData\Local\{7566F208-64C7-45B1-8D0A-E9F68161EDA6}
    2013-05-22 05:55 - 2013-05-22 05:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\{3FB7FC37-6FD9-4764-8E51-3BE05D60038A}
    2013-05-21 17:17 - 2013-05-21 17:18 - 00000000 ____D C:\Users\Matthew\AppData\Local\{FB799B09-EE16-4793-BAB7-3AB3D3305D60}
    2013-05-21 09:00 - 2013-05-21 09:02 - 75732159 ____A C:\Users\Matthew\Downloads\TP to verify5.zip
    2013-05-21 08:50 - 2013-05-21 08:50 - 00009635 ____A C:\Users\Matthew\Downloads\V64371_2013-05-21.xlsx
    2013-05-21 08:49 - 2013-05-21 08:49 - 00007995 ____A C:\Users\Matthew\Downloads\V23762_2013-05-21.xlsx
    2013-05-21 08:48 - 2013-05-21 08:48 - 00009008 ____A C:\Users\Matthew\Downloads\V71155_2013-05-21.xlsx
    2013-05-21 08:48 - 2013-05-21 08:48 - 00007906 ____A C:\Users\Matthew\Downloads\V91340_2013-05-21.xlsx
    2013-05-21 08:46 - 2013-05-21 08:46 - 00009375 ____A C:\Users\Matthew\Downloads\V81332_2013-05-21.xlsx
    2013-05-21 07:51 - 2013-05-21 07:51 - 00000474 ____A C:\Users\Matthew\Downloads\NAV_doc_13T180.jnlp
    2013-05-21 07:29 - 2013-05-31 07:52 - 00003846 ____A C:\Users\Matthew\abevjava_Matthew.log
    2013-05-21 07:27 - 2013-05-21 07:27 - 00000466 ____A C:\Users\Matthew\Downloads\NAV_13t180.jnlp
    2013-05-21 07:22 - 2013-05-21 07:29 - 00000000 ____D C:\Users\Matthew\abevjava
    2013-05-21 07:22 - 2013-05-21 07:22 - 00001666 ____A C:\Users\Matthew\Desktop\ÁNYK.lnk
    2013-05-21 07:22 - 2013-05-21 07:22 - 00000042 ____A C:\Windows\abevjavapath.cfg
    2013-05-21 07:22 - 2013-05-21 07:22 - 00000000 ____D C:\Users\Public\abevjava
    2013-05-21 07:21 - 2013-05-21 07:22 - 00000000 ____D C:\Users\Matthew\.abevjava
    2013-05-21 07:20 - 2013-05-21 07:20 - 00000479 ____A C:\Users\Matthew\Downloads\abevjava_install.jnlp
    2013-05-21 05:17 - 2013-05-21 05:17 - 00000000 ____D C:\Users\Matthew\AppData\Local\{3A371223-F5DB-4617-9CAE-D32A0123D909}
  14. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    ==================== One Month Modified Files and Folders =======

    2013-06-20 02:21 - 2013-06-20 02:21 - 00000034 ____A C:\Users\Matthew\Desktop\music2.tar.gz
    2013-06-20 02:20 - 2013-06-20 02:20 - 00000034 ____A C:\Users\Matthew\Desktop\music.tar.gz
    2013-06-19 21:56 - 2009-11-28 12:10 - 00000000 ___HD C:\SPLASH.000
    2013-06-19 10:15 - 2013-06-17 18:36 - 00003560 ____A C:\Windows\PFRO.log
    2013-06-19 09:05 - 2010-03-10 12:04 - 00196608 ____A C:\Windows\System32\Ikeext.etl
    2013-06-19 09:04 - 2013-06-19 06:35 - 00000000 ____D C:\Users\Matthew\Desktop\mbar
    2013-06-19 08:49 - 2009-11-28 12:19 - 00000000 ____D C:\ProgramData\Microsoft Help
    2013-06-19 08:48 - 2013-01-21 22:29 - 01173789 ____A C:\Windows\WindowsUpdate.log
    2013-06-19 08:48 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\tracing
    2013-06-19 08:34 - 2013-06-19 08:34 - 00001634 ____A C:\Users\Matthew\Desktop\WINWORD parancsikonja.lnk
    2013-06-19 08:20 - 2013-06-19 08:20 - 00001634 ____A C:\Users\Matthew\Desktop\OUTLOOK parancsikonja.lnk
    2013-06-19 07:58 - 2009-07-14 04:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-06-19 07:58 - 2009-07-14 04:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-06-19 07:54 - 2013-06-19 07:54 - 00162008 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
    2013-06-19 07:53 - 2013-04-26 09:37 - 00000000 ____D C:\ProgramData\firebird
    2013-06-19 07:50 - 2013-06-13 11:19 - 00000384 ____A C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Matthew.job
    2013-06-19 07:49 - 2009-07-14 05:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-06-19 07:47 - 2013-06-13 13:42 - 00001120 ____A C:\Windows\setupact.log
    2013-06-19 07:45 - 2011-05-28 06:50 - 00000000 ____D C:\ProgramData\MFAData
    2013-06-19 07:35 - 2013-06-14 13:07 - 00000000 ____D C:\Users\Matthew\Desktop\Flying Fairy to verify
    2013-06-19 07:34 - 2013-06-19 07:34 - 07940761 ____A C:\Users\Matthew\Downloads\Flying Fairy to verify (1).zip
    2013-06-19 07:02 - 2013-06-19 07:02 - 00000000 ____D C:\Users\Matthew\Desktop\WWD to verify
    2013-06-19 07:02 - 2013-06-19 07:01 - 16024350 ____A C:\Users\Matthew\Downloads\WWD to verify.zip
    2013-06-19 06:36 - 2013-06-19 06:36 - 00036680 ____A C:\Windows\System32\Drivers\mbamchameleon.sys
    2013-06-19 06:35 - 2013-06-19 06:34 - 13169742 ____A C:\Users\Matthew\Desktop\mbar-1.06.0.1003.zip
    2013-06-18 20:13 - 2013-02-04 07:20 - 00000000 ____D C:\ProgramData\AVG2013
    2013-06-18 20:04 - 2013-06-18 20:03 - 00294640 ____A C:\Windows\Minidump\061813-155517-01.dmp
    2013-06-18 20:04 - 2010-03-04 19:37 - 00000000 ____D C:\users\Matthew
    2013-06-18 20:03 - 2010-05-05 11:37 - 00000000 ____D C:\Windows\Minidump
    2013-06-18 06:08 - 2013-06-18 06:08 - 00000000 ____D C:\Users\Matthew\Desktop\Fairies
    2013-06-18 06:08 - 2013-06-18 06:06 - 70179748 ____A C:\Users\Matthew\Downloads\Fairies.zip
    2013-06-18 06:08 - 2010-03-04 19:40 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\Skype
    2013-06-17 23:40 - 2013-06-14 12:35 - 00008745 ____A C:\Users\Matthew\Desktop\{6d2b5079-2f0b-48dd-ab7f-97cec514d30b}.xlsx
    2013-06-17 18:45 - 2013-06-17 18:45 - 00033731 ____A C:\Users\Matthew\Desktop\dds.txt
    2013-06-17 18:45 - 2013-06-17 18:45 - 00021338 ____A C:\Users\Matthew\Desktop\attach.txt
    2013-06-17 18:22 - 2013-06-17 18:22 - 00001065 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2013-06-17 18:22 - 2013-01-03 22:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2013-06-17 18:21 - 2013-06-13 11:19 - 00000374 ____A C:\Windows\Tasks\ReclaimerUpdateXML_Matthew.job
    2013-06-17 18:20 - 2013-06-17 18:19 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Matthew\Downloads\mbam-setup-1.75.0.1300.exe
    2013-06-17 12:03 - 2010-03-05 00:53 - 00000000 ____D C:\Users\Matthew\AppData\Local\CutePDF Writer
    2013-06-17 10:25 - 2013-04-25 05:59 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\vlc
    2013-06-17 06:51 - 2013-06-12 07:16 - 00011099 ____A C:\Users\Matthew\Desktop\cobi 2013 aw marketing offers.xlsx
    2013-06-17 06:22 - 2013-06-17 06:22 - 00093795 ____A C:\Users\Matthew\Downloads\FRST.txt
    2013-06-17 06:20 - 2009-11-24 01:21 - 00690620 ____A C:\Windows\System32\perfh00E.dat
    2013-06-17 06:20 - 2009-11-24 01:21 - 00167432 ____A C:\Windows\System32\perfc00E.dat
    2013-06-17 06:20 - 2009-07-14 05:13 - 01645748 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-06-17 06:19 - 2013-06-17 06:19 - 00000000 ____D C:\FRST
    2013-06-17 06:18 - 2013-06-17 06:18 - 01926844 ____A (Farbar) C:\Users\Matthew\Downloads\FRST64.exe
    2013-06-16 07:10 - 2013-06-13 11:19 - 00000378 ____A C:\Windows\Tasks\ReclaimerUpdateFiles_Matthew.job
    2013-06-16 00:18 - 2011-12-07 16:07 - 00031702 ____A C:\Users\Matthew\Downloads\kórus lista 20110212.xlsx
    2013-06-15 22:36 - 2013-01-03 12:33 - 00000000 ____D C:\ProgramData\SaveAs
    2013-06-15 22:34 - 2013-01-25 20:03 - 00000000 ____D C:\Program Files (x86)\WebSearch
    2013-06-15 22:05 - 2010-06-24 20:23 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\uTorrent
    2013-06-15 21:59 - 2013-06-11 14:52 - 00000000 ____D C:\Users\Matthew\Downloads\Buena Vista - Disney gyujtemény 1937-2007
    2013-06-15 21:58 - 2013-06-15 21:58 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
    2013-06-15 21:08 - 2013-06-15 21:08 - 00030860 ____A C:\Users\Matthew\Downloads\Grown Ups 2 2013 English [DVDRip].torrent
    2013-06-14 13:07 - 2013-06-14 13:07 - 07940761 ____A C:\Users\Matthew\Downloads\Flying Fairy to verify.zip
    2013-06-14 12:25 - 2013-06-14 12:25 - 00078083 ____A C:\Users\Matthew\Desktop\export_kelt___20130614142534.CSV
    2013-06-14 11:02 - 2013-06-13 14:59 - 00000000 ____D C:\Users\Matthew\Desktop\TRANSLATION
    2013-06-13 22:59 - 2013-06-13 22:59 - 00065481 ____A C:\Users\Matthew\Downloads\POSTINGS_00435774_20130429.xml
    2013-06-13 22:59 - 2013-06-13 22:59 - 00065481 ____A C:\Users\Matthew\Downloads\POSTINGS_00435774_20130429 (1).xml
    2013-06-13 22:35 - 2013-06-01 18:51 - 00000000 ____D C:\Users\Matthew\Downloads\Sherlock Holmes A Game of Shadows (2011) DVDRip XviD-MAXSPEED
    2013-06-13 21:11 - 2013-06-13 21:11 - 00012113 ____A C:\Users\Matthew\Desktop\export_kelt_2013-05-01_2013-06-13_20130613231121.CSV
    2013-06-13 20:55 - 2013-06-13 20:55 - 00250144 ____A (Relief Software) C:\Users\Matthew\Downloads\OutlookMessagesImportEMLSetup.exe
    2013-06-13 20:55 - 2013-06-13 20:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\OutlookFreeware.com
    2013-06-13 20:54 - 2013-06-13 20:54 - 00003039 ____A C:\Users\Matthew\Desktop\OutlookFreeware.com Utilities.lnk
    2013-06-13 20:51 - 2013-06-13 20:51 - 04588320 ____A (Relief Software) C:\Users\Matthew\Downloads\OutlookFreewareSetup.exe
    2013-06-13 18:12 - 2013-06-13 17:36 - 00000000 ____D C:\Users\Matthew\AppData\Local\Windows Live
    2013-06-13 17:41 - 2013-06-13 17:39 - 00000000 ____D C:\Program Files (x86)\Windows Live
    2013-06-13 17:40 - 2013-06-13 17:40 - 00000000 ____D C:\Windows\PCHEALTH
    2013-06-13 17:40 - 2013-06-13 17:40 - 00000000 ____D C:\Program Files\Windows Live
    2013-06-13 17:40 - 2009-07-14 03:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2013-06-13 17:35 - 2013-06-13 17:35 - 01244144 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\wlsetup-web (2).exe
    2013-06-13 17:21 - 2013-06-13 17:21 - 00000020 ____A C:\Windows\8o
    2013-06-13 15:59 - 2013-06-13 15:59 - 00000000 ____D C:\Users\Matthew\AppData\Local\VS Revo Group
    2013-06-13 15:59 - 2013-06-13 15:59 - 00000000 ____D C:\ProgramData\VS Revo Group
    2013-06-13 15:59 - 2013-06-13 15:59 - 00000000 ____D C:\Program Files\VS Revo Group
    2013-06-13 15:58 - 2013-06-13 15:58 - 09916056 ____A (VS Revo Group ) C:\Users\Matthew\Downloads\RevoUninProSetup.exe
    2013-06-13 15:38 - 2013-06-13 13:30 - 00001528 ____A C:\Windows\DirectX.log
    2013-06-13 15:32 - 2013-06-13 15:32 - 00000020 ____A C:\Windows\¸o’
    2013-06-13 14:58 - 2013-06-13 14:58 - 03457900 ____A C:\Users\Matthew\Downloads\TRANSLATION.zip
    2013-06-13 14:49 - 2013-06-13 14:49 - 01244144 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\wlsetup-web (1).exe
    2013-06-13 14:33 - 2013-06-13 14:32 - 01244144 ____A (Microsoft Corporation) C:\Users\Matthew\Downloads\wlsetup-web.exe
    2013-06-13 14:13 - 2013-06-13 14:13 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\FixIt
    2013-06-13 14:12 - 2013-06-13 14:12 - 00665088 ____A C:\Users\Matthew\Downloads\MicrosoftFixit50604.msi
    2013-06-13 14:01 - 2013-04-24 05:57 - 00000000 ____D C:\Windows\rescache
    2013-06-13 14:01 - 2010-07-17 00:45 - 00000000 ____D C:\ProgramData\Real
    2013-06-13 14:01 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\AppCompat
    2013-06-13 14:00 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\registration
    2013-06-13 13:42 - 2013-06-13 13:42 - 00000000 ____A C:\Windows\setuperr.log
    2013-06-13 13:24 - 2013-04-22 19:18 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\FileZilla
    2013-06-13 13:15 - 2009-11-24 00:25 - 00000000 ____D C:\Windows\Panther
    2013-06-12 23:38 - 2010-03-08 06:58 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2013-06-12 22:56 - 2013-06-11 14:38 - 00015338 ____A C:\Users\Matthew\Desktop\IR75930_2013-06-11.xlsx
    2013-06-12 22:45 - 2013-06-12 22:44 - 00000000 ____D C:\Users\Matthew\AppData\Local\{4BF9D083-61FC-4592-B7FE-70A103021650}
    2013-06-12 22:28 - 2013-06-12 22:28 - 00003604 ____A C:\Users\Matthew\Downloads\szamlatetelek_1593468.xls
    2013-06-12 10:50 - 2013-06-12 10:44 - 00008823 ____A C:\Users\Matthew\Desktop\formatex trash grp.xlsx
    2013-06-12 10:44 - 2013-06-12 10:44 - 00000000 ____D C:\Users\Matthew\AppData\Local\{693C9475-22A3-4D5A-9DE5-B71672B67838}
    2013-06-12 07:16 - 2013-06-12 07:16 - 00009814 ____A C:\Users\Matthew\Documents\cobi 2013 aw marketing offers.xlsx
    2013-06-11 22:44 - 2013-06-11 22:43 - 00000000 ____D C:\Users\Matthew\AppData\Local\{E4078F45-7571-4EDA-A9BA-1E10309FE078}
    2013-06-11 18:28 - 2013-06-11 18:28 - 00006831 ____A C:\Users\Matthew\Downloads\IR97518_2013-06-11.xlsx
    2013-06-11 15:36 - 2013-06-11 18:43 - 138770546 ____A C:\Users\Matthew\Desktop\termekek.zip
    2013-06-11 15:36 - 2013-06-11 15:36 - 00013824 ____A C:\Users\Matthew\Downloads\kosar-1368276-2013_06_11_17_36_40.xls
    2013-06-11 14:51 - 2013-06-11 14:51 - 00379443 ____A C:\Users\Matthew\Downloads\[µBit][#110900]Walt.Disney.gyujtemeny.1937-2007.torrent
    2013-06-11 14:35 - 2013-06-11 14:35 - 00008780 ____A C:\Users\Matthew\Downloads\IR75930_2013-06-11.xlsx
    2013-06-11 14:34 - 2013-06-11 14:34 - 00006828 ____A C:\Users\Matthew\Downloads\IR98198_2013-06-11.xlsx
    2013-06-11 13:12 - 2013-06-11 18:56 - 00000000 ___AD C:\Users\Matthew\Desktop\termekek
    2013-06-11 10:43 - 2013-06-11 10:43 - 00000000 ____D C:\Users\Matthew\AppData\Local\{672ECD9C-B3B8-45E9-9FEA-C27BAA8AFAA1}
    2013-06-11 09:15 - 2013-06-11 09:15 - 00000000 ____D C:\Users\Matthew\AppData\Local\{72B17DF5-CEA8-4061-83D0-0EE2C5B4BC13}
    2013-06-10 21:15 - 2013-06-10 21:15 - 00000000 ____D C:\Users\Matthew\AppData\Local\{CF67F8E2-B0F3-4F29-AE90-20E6A14E4EFC}
    2013-06-10 09:14 - 2013-06-10 09:14 - 00000000 ____D C:\Users\Matthew\AppData\Local\{480B359B-A643-4F4B-8D52-B7349EBF6C5F}
    2013-06-10 07:18 - 2013-06-10 07:15 - 30473048 ____A C:\Users\Matthew\Downloads\POWER TRAINS 2 wave (1).zip
    2013-06-09 21:14 - 2013-06-09 21:13 - 00000000 ____D C:\Users\Matthew\AppData\Local\{6A5CE5BC-09A9-4277-BFCE-144C9A43EC9B}
    2013-06-09 09:13 - 2013-06-09 09:13 - 00000000 ____D C:\Users\Matthew\AppData\Local\{80363C8A-C98B-4C6C-8A53-7877721B28AE}
    2013-06-08 15:14 - 2009-07-14 05:08 - 00032554 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2013-06-08 14:08 - 2013-06-19 07:40 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2013-06-08 14:07 - 2013-06-19 07:40 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2013-06-08 14:06 - 2013-06-19 07:40 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2013-06-08 14:06 - 2013-06-19 07:40 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2013-06-08 14:06 - 2013-06-19 07:40 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2013-06-08 12:28 - 2013-06-19 07:41 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2013-06-08 12:11 - 2013-06-08 12:11 - 00039896 ____A C:\Windows\SysWOW64\dischandler.exe
    2013-06-08 11:57 - 2013-06-08 11:57 - 04012544 ____A C:\Windows\System32\ffmpeg.dll
    2013-06-08 11:57 - 2013-06-08 11:57 - 00474624 ____A C:\Windows\System32\ff_kernelDeint.dll
    2013-06-08 11:56 - 2013-06-08 11:56 - 04372992 ____A C:\Windows\System32\ffdshow.ax
    2013-06-08 11:56 - 2013-06-08 11:56 - 00631296 ____A C:\Windows\System32\TomsMoComp_ff.dll
    2013-06-08 11:56 - 2013-06-08 11:56 - 00156672 ____A C:\Windows\System32\ff_libmad.dll
    2013-06-08 11:56 - 2013-06-08 11:56 - 00127488 ____A C:\Windows\System32\ff_vfw.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 01532928 ____A C:\Windows\System32\ff_samplerate.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00222720 ____A C:\Windows\System32\ff_libdts.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00190464 ____A C:\Windows\System32\libmpeg2_ff.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00183296 ____A C:\Windows\System32\ff_unrar.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00116224 ____A C:\Windows\System32\ff_liba52.dll
    2013-06-08 11:55 - 2013-06-08 11:55 - 00114688 ____A C:\Windows\System32\ff_wmv9.dll
    2013-06-08 11:54 - 2013-06-08 11:54 - 03915776 ____A C:\Windows\SysWOW64\ffmpeg.dll
    2013-06-08 11:53 - 2013-06-08 11:53 - 03501568 ____A C:\Windows\SysWOW64\ffdshow.ax
    2013-06-08 11:53 - 2013-06-08 11:53 - 00112640 ____A C:\Windows\SysWOW64\ff_vfw.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 01525760 ____A C:\Windows\SysWOW64\ff_samplerate.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00271360 ____A C:\Windows\SysWOW64\TomsMoComp_ff.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00211968 ____A C:\Windows\SysWOW64\ff_libdts.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00157184 ____A C:\Windows\SysWOW64\ff_unrar.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00147456 ____A C:\Windows\SysWOW64\ff_libmad.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00136704 ____A C:\Windows\SysWOW64\libmpeg2_ff.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00114688 ____A C:\Windows\SysWOW64\ff_liba52.dll
    2013-06-08 11:52 - 2013-06-08 11:52 - 00099840 ____A C:\Windows\SysWOW64\ff_wmv9.dll
    2013-06-08 11:42 - 2013-06-19 07:40 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2013-06-08 11:40 - 2013-06-19 07:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2013-06-08 11:40 - 2013-06-19 07:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2013-06-08 11:40 - 2013-06-19 07:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2013-06-08 11:40 - 2013-06-19 07:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2013-06-08 11:13 - 2013-06-19 07:41 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2013-06-08 08:20 - 2013-06-08 08:19 - 00000000 ____D C:\Users\Matthew\AppData\Local\{1CF3A187-BF39-4987-82A8-45C396CE9CB8}
    2013-06-07 18:29 - 2011-09-21 21:35 - 00000000 ____D C:\Users\Matthew\Documents\restore
    2013-06-07 10:40 - 2013-06-07 10:37 - 00000000 ____D C:\Users\Matthew\AppData\Local\{2DCAE9DA-A087-43D8-8ED7-1D61D12354DE}
    2013-06-06 22:19 - 2013-06-06 22:17 - 31815152 ____A C:\Users\Matthew\Downloads\R4i V1.68b English.zip
    2013-06-06 20:59 - 2013-06-06 20:59 - 00008374 ____A C:\Users\Matthew\Downloads\IR20050_2013-06-06.xlsx
    2013-06-06 20:58 - 2013-06-06 20:58 - 00008199 ____A C:\Users\Matthew\Downloads\IR41325_2013-06-06.xlsx
    2013-06-06 18:36 - 2013-06-06 18:35 - 00000000 ____D C:\Users\Matthew\AppData\Local\{CC4E7B6C-7A19-45B2-93F7-C79E7349E9AF}
    2013-06-06 13:29 - 2013-06-06 13:28 - 30473048 ____A C:\Users\Matthew\Downloads\POWER TRAINS 2 wave.zip
    2013-06-06 09:02 - 2013-06-06 09:02 - 00263877 ____A C:\Users\Matthew\Downloads\Szamla_00033615021305300001146.x132
    2013-06-06 06:03 - 2013-06-06 06:03 - 00000000 ____D C:\Users\Matthew\AppData\Local\{1962E97A-D21D-4BB9-863B-D74695C37665}
    2013-06-05 14:48 - 2013-06-05 14:46 - 76634107 ____A C:\Users\Matthew\Downloads\Spy Gear labels to verify.zip
    2013-06-05 14:46 - 2013-06-05 14:46 - 16612869 ____A C:\Users\Matthew\Downloads\Power Trains Instructions1.zip
    2013-06-05 09:28 - 2013-06-05 09:27 - 00000000 ____D C:\Users\Matthew\AppData\Local\{91511563-AA58-4D05-B2B8-96C0E8A1ABB0}
    2013-06-04 22:26 - 2012-07-10 08:40 - 00000000 ____D C:\Users\Matthew\Desktop\Horae Apocalypticae
    2013-06-04 21:27 - 2013-06-04 21:27 - 00000000 ____D C:\Users\Matthew\AppData\Local\{34694F47-941C-49F3-88FC-C69CAD00AEA4}
    2013-06-04 13:29 - 2013-06-04 13:29 - 00000000 ____D C:\Program Files (x86)\NirSoft
    2013-06-04 08:02 - 2013-06-04 08:02 - 00000000 ____D C:\Users\Matthew\AppData\Local\{2BF36FBB-C7C4-45BB-8DB2-A8421EA72FCE}
    2013-06-03 21:41 - 2013-02-05 08:39 - 00000000 ____D C:\Users\Matthew\Desktop\Közösség
    2013-06-03 20:17 - 2010-09-06 11:54 - 00000000 ____D C:\Users\Matthew\AppData\Roaming\dvdcss
    2013-06-03 20:02 - 2013-06-03 20:01 - 00000000 ____D C:\Users\Matthew\AppData\Local\{42611709-A35C-4207-8532-C5DA63D5C78E}
    2013-06-03 19:01 - 2013-06-03 19:01 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
    2013-06-03 19:01 - 2013-06-03 19:00 - 04808816 ____A (FileZilla Project) C:\Users\Matthew\Downloads\FileZilla_3.7.0.2_win32-setup.exe
    2013-06-03 11:13 - 2013-06-03 11:12 - 20623712 ____A C:\Users\Matthew\Downloads\Translation Power Trains.zip
    2013-06-03 08:13 - 2013-06-03 07:18 - 00012042 ____A C:\Users\Matthew\Downloads\IR27584_2013-06-03.xlsx
    2013-06-03 08:01 - 2013-06-03 08:01 - 00000000 ____D C:\Users\Matthew\AppData\Local\{6FD50C7E-85E9-458A-9888-CBB4D8DF26F9}
    2013-06-02 20:00 - 2013-06-02 20:00 - 00000000 ____D C:\Users\Matthew\AppData\Local\{4A125A5F-3BDA-40DE-8724-84A301BFAEB2}
    2013-06-02 06:55 - 2013-06-02 06:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\{5E938FF8-66AF-4599-A4D9-861500CCC3AC}
    2013-06-01 07:51 - 2013-06-01 07:50 - 15047367 ____A C:\Users\Matthew\Downloads\113872.phone_h264_800k.mp4
    2013-06-01 07:49 - 2013-06-01 07:49 - 00000000 ____D C:\Users\Matthew\AppData\Local\{F90E7281-3419-4576-9817-8D75C9EF2F62}
    2013-05-31 18:52 - 2013-05-31 18:51 - 00000000 ____D C:\Users\Matthew\AppData\Local\{2B8DAE0B-EB64-47BA-A8EC-5DBB647E1F3A}
    2013-05-31 10:36 - 2013-05-31 10:36 - 00012535 ____A C:\Users\Matthew\Desktop\Cobi 2013 AW Marketing plan.xlsx
    2013-05-31 10:35 - 2013-05-31 10:31 - 00012537 ____A C:\Users\Matthew\Documents\Cobi 2013 AW Marketing plan.xlsx
    2013-05-31 07:52 - 2013-05-21 07:29 - 00003846 ____A C:\Users\Matthew\abevjava_Matthew.log
    2013-05-31 06:12 - 2013-05-31 06:12 - 00000000 ____D C:\Users\Matthew\AppData\Local\{BAA63AD4-374B-4723-899A-FAF8266B18CB}
    2013-05-30 20:08 - 2013-05-30 20:08 - 02592509 ____A C:\Users\Matthew\Downloads\Peter Lerangis - Seven Wonders Book 1, The Colossus Rises.rar
    2013-05-30 19:59 - 2011-12-21 10:52 - 00000000 ____D C:\Users\Matthew\Documents\My eBooks
    2013-05-30 19:57 - 2013-05-30 19:57 - 06347998 ____A C:\Users\Matthew\Downloads\The Maelstrom Book Four of The Tapestry by Henry H. Neff.zip
    2013-05-30 18:11 - 2013-05-30 18:11 - 00000000 ____D C:\Users\Matthew\AppData\Local\{0BD09CF9-134F-4AB4-BF52-761B1AE0B663}
    2013-05-30 15:15 - 2013-05-30 15:15 - 00009666 ____A C:\Users\Matthew\Downloads\torzs_20130530171505.zip
    2013-05-30 14:55 - 2013-05-30 14:51 - 00000000 ____D C:\Users\Matthew\Desktop\isk 2013
    2013-05-30 14:55 - 2013-05-30 14:51 - 00000000 ____D C:\Users\Matthew\Desktop\cp 2013
    2013-05-30 13:47 - 2013-05-30 13:47 - 00000000 ____D C:\Users\Matthew\Desktop\isk 2012
    2013-05-30 13:40 - 2013-05-30 13:40 - 00000000 ____D C:\Users\Matthew\Desktop\cp 2012
    2013-05-30 06:05 - 2013-05-30 06:05 - 00007474 ____A C:\Users\Matthew\Downloads\IR19961_2013-05-30.xlsx
    2013-05-30 06:05 - 2013-05-30 06:05 - 00006802 ____A C:\Users\Matthew\Downloads\IR54507_2013-05-30.xlsx
    2013-05-30 04:50 - 2013-05-30 04:49 - 00000000 ____D C:\Users\Matthew\AppData\Local\{F2DC59E3-D845-4514-B0C8-271276788E14}
    2013-05-29 21:03 - 2013-05-29 21:03 - 07590912 ____A C:\Users\Matthew\Downloads\Magyarorszag_a_XVIII_betelepules.ppt
    2013-05-29 10:59 - 2013-05-29 10:59 - 00000000 ____D C:\Users\Matthew\AppData\Local\{F64705A9-6E74-4513-938F-AFB79A132CC8}
    2013-05-28 19:56 - 2013-05-28 19:56 - 00000000 ____D C:\Users\Matthew\AppData\Local\{DD63EE21-C48D-4338-A247-610F9EA738D2}
    2013-05-28 07:55 - 2013-05-28 07:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\{B0D35795-4335-4DE8-B336-9D08961A0493}
    2013-05-27 19:55 - 2013-05-27 19:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\{EB5144F0-B9A9-49C2-AECD-D51E6F76DF96}
    2013-05-27 08:38 - 2013-05-27 08:30 - 00000000 ____D C:\Program Files (x86)\JDownloader
    2013-05-27 08:29 - 2013-05-27 08:29 - 00081488 ____A (AppWork UG (haftungsbeschränkt)) C:\Users\Matthew\Downloads\WebInstaller.exe
    2013-05-27 07:54 - 2013-05-27 07:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\{75180D18-C6DC-4646-97EA-7A8513F3E935}
    2013-05-26 21:25 - 2009-11-28 12:34 - 00000000 ____D C:\ProgramData\Skype
    2013-05-26 19:54 - 2013-05-26 19:54 - 00000000 ____D C:\Users\Matthew\AppData\Local\{754E4D21-0EC0-4A50-8563-E8B549EF075D}
    2013-05-26 07:53 - 2013-05-26 07:53 - 00000000 ____D C:\Users\Matthew\AppData\Local\{DBF9861E-6D0F-49B1-A0C8-21F095F0B351}
    2013-05-25 19:23 - 2013-05-25 19:22 - 00000000 ____D C:\Users\Matthew\AppData\Local\{D540B30C-ACD1-4343-A458-969F047734BA}
    2013-05-25 01:00 - 2013-05-25 01:00 - 00000000 ____D C:\Users\Matthew\AppData\Local\{E7A2106A-C03B-4B72-AED0-B03D7C3C3C3B}
    2013-05-24 11:12 - 2013-05-24 11:11 - 00000000 ____D C:\Users\Matthew\AppData\Local\{0B9EFA73-5A94-4D77-A07C-89F6F4316DC0}
    2013-05-23 23:11 - 2013-05-23 23:11 - 00000000 ____D C:\Users\Matthew\AppData\Local\{E4A77B80-77E9-4311-8F83-DEEF62403960}
    2013-05-23 07:33 - 2013-05-23 07:32 - 00000000 ____D C:\Users\Matthew\AppData\Local\{DF1332F7-5BC8-464C-8717-44DC568C42AA}
    2013-05-22 19:32 - 2013-05-22 19:32 - 00000000 ____D C:\Users\Matthew\AppData\Local\{7566F208-64C7-45B1-8D0A-E9F68161EDA6}
    2013-05-22 05:55 - 2013-05-22 05:55 - 00000000 ____D C:\Users\Matthew\AppData\Local\{3FB7FC37-6FD9-4764-8E51-3BE05D60038A}
    2013-05-21 17:18 - 2013-05-21 17:17 - 00000000 ____D C:\Users\Matthew\AppData\Local\{FB799B09-EE16-4793-BAB7-3AB3D3305D60}
    2013-05-21 09:02 - 2013-05-21 09:00 - 75732159 ____A C:\Users\Matthew\Downloads\TP to verify5.zip
    2013-05-21 08:50 - 2013-05-21 08:50 - 00009635 ____A C:\Users\Matthew\Downloads\V64371_2013-05-21.xlsx
    2013-05-21 08:49 - 2013-05-21 08:49 - 00007995 ____A C:\Users\Matthew\Downloads\V23762_2013-05-21.xlsx
    2013-05-21 08:48 - 2013-05-21 08:48 - 00009008 ____A C:\Users\Matthew\Downloads\V71155_2013-05-21.xlsx
    2013-05-21 08:48 - 2013-05-21 08:48 - 00007906 ____A C:\Users\Matthew\Downloads\V91340_2013-05-21.xlsx
    2013-05-21 08:46 - 2013-05-21 08:46 - 00009375 ____A C:\Users\Matthew\Downloads\V81332_2013-05-21.xlsx
    2013-05-21 07:51 - 2013-05-21 07:51 - 00000474 ____A C:\Users\Matthew\Downloads\NAV_doc_13T180.jnlp
    2013-05-21 07:29 - 2013-05-21 07:22 - 00000000 ____D C:\Users\Matthew\abevjava
    2013-05-21 07:27 - 2013-05-21 07:27 - 00000466 ____A C:\Users\Matthew\Downloads\NAV_13t180.jnlp
    2013-05-21 07:22 - 2013-05-21 07:22 - 00001666 ____A C:\Users\Matthew\Desktop\ÁNYK.lnk
    2013-05-21 07:22 - 2013-05-21 07:22 - 00000042 ____A C:\Windows\abevjavapath.cfg
    2013-05-21 07:22 - 2013-05-21 07:22 - 00000000 ____D C:\Users\Public\abevjava
    2013-05-21 07:22 - 2013-05-21 07:21 - 00000000 ____D C:\Users\Matthew\.abevjava
    2013-05-21 07:20 - 2013-05-21 07:20 - 00000479 ____A C:\Users\Matthew\Downloads\abevjava_install.jnlp
    2013-05-21 05:17 - 2013-05-21 05:17 - 00000000 ____D C:\Users\Matthew\AppData\Local\{3A371223-F5DB-4617-9CAE-D32A0123D909}

    ==================== Known DLLs (Whitelisted) ================


    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe
    [2009-07-13 23:19] - [2009-07-14 01:39] - 0328704 ____A () E12D5B098734ED440B0CDD37E4680DB3

    C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!

    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================

    Restore point made on: 2013-06-17 06:23:49
    Restore point made on: 2013-06-19 06:32:27
    Restore point made on: 2013-06-19 07:37:08
    Restore point made on: 2013-06-19 07:40:10

    ==================== Memory info ===========================

    Percentage of memory in use: 16%
    Total physical RAM: 4063.03 MB
    Available physical RAM: 3395.25 MB
    Total Pagefile: 4061.18 MB
    Available Pagefile: 3398.3 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.86 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:165.47 GB) (Free:6.37 GB) NTFS (Disk=0 Partition=3)
    Drive d: (G tároló) (Fixed) (Total:117.19 GB) (Free:17.78 GB) NTFS (Disk=0 Partition=4)
    Drive f: (Recovery) (Fixed) (Total:15.33 GB) (Free:0.5 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]
    Drive h: () (Removable) (Total:3.74 GB) (Free:3.74 GB) FAT32 (Disk=1 Partition=1)
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.04 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0D5C3EC2)
    Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=165 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=117 GB) - (Type=OF Extended)

    ========================================================
    Disk: 1 (Size: 4 GB) (Disk ID: 00000000)
    Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)


    LastRegBack: 2013-06-13 11:50

    ==================== End Of Log ============================
  15. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    Re-run FRST again.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes in your reply.
  16. Matthew Robin

    Matthew Robin Newcomer, in training Topic Starter

    Hi Broni,

    I did do this and thought I posted it, but now see that I had not hit "post reply".
    Seeing that I did not get an answer (to the post I hadn't sent!), I reinstalled my windows.
    All is working fine now - just have to set everything up again - thanks for all your help,

    Matthew
  17. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    Thanks for posting back :)


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.