Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Folgende Fehlermeldung legt meinen LapTop lahm: "ihr computer wurde durch das system der automatischen informationskontrolle gesperrt" (https://www.trojaner-board.de/123903-folgende-fehlermeldung-legt-meinen-laptop-lahm-computer-wurde-system-automatischen-informationskontrolle-gesperrt.html)

Rai3 11.09.2012 16:22

Folgende Fehlermeldung legt meinen LapTop lahm: "ihr computer wurde durch das system der automatischen informationskontrolle gesperrt"
 
Hallo zusammen,
ich habe mir heute wohl den Bundestrojaner eingefangen.
Ich bekomme eine hochoffiziell aussehende Seite die mit folgendem Satz beginnt und mich auffordert 100€ zu bezahlen. :nono:
"ihr computer wurde durch das system der automatischen informationskontrolle gesperrt"

Da ich hier gelesen habe, dass ich nicht einfach die Anleitungen eines anderen threats abarbeiten soll, habe ich diesen "eigenen" threat eröffnet.

Ich habe die Anweisungen "Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten?" durchgelesen und befolgt.

Da mein Laptop nur noch im abgesicherten Modus läuft, habe ich folgendes in diesem Modus durchgefürt:
  • defogger als Administrator durchgeführt
  • OTL als Administrator durchgeführt

OTL hat mir jedoch nur eine otl.txt und keine extra.txt erstellt.
msinfo32 hat mir gesagt dass ich ein 64 bit System habe. Also habe ich Gmer nicht ausgeführt.

Wäre super nett, wenn mir jemand helfen könnte.

Schönen Dank schonmal
Rainer

Nachfolgend meine otl.txt:OTL Logfile:
Code:

OTL logfile created on: 11.09.2012 16:53:55 - Run 2
OTL by OldTimer - Version 3.2.61.3    Folder = C:\Users\Rainer\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 3,44 Gb Available Physical Memory | 85,98% Memory free
7,99 Gb Paging File | 7,45 Gb Available in Paging File | 93,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,73 Gb Total Space | 98,27 Gb Free Space | 21,76% Space Free | Partition Type: NTFS
Drive D: | 13,73 Gb Total Space | 2,28 Gb Free Space | 16,57% Space Free | Partition Type: NTFS
Drive E: | 99,02 Mb Total Space | 96,45 Mb Free Space | 97,41% Space Free | Partition Type: FAT32
Drive G: | 249,71 Mb Total Space | 67,76 Mb Free Space | 27,14% Space Free | Partition Type: FAT
 
Computer Name: RAINER-LT | User Name: Rainer | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Rainer\Desktop\OTL.exe (OldTimer Tools)
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (ZuneWlanCfgSvc) -- C:\Programme\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) -- C:\Programme\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) -- C:\Programme\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (VmbService) -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BrYNSvc) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe (IDT, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (tbhsd) -- C:\Windows\SysNative\drivers\tbhsd.sys (RapidSolution Software AG)
DRV:64bit: - (RRNetCapMP) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV:64bit: - (RRNetCap) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\androidusb.sys (Google Inc)
DRV:64bit: - (ewusbnet) -- C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwusbfake) -- C:\Windows\SysNative\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (JMCR) -- C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (irda) -- C:\Windows\SysNative\drivers\irda.sys (Microsoft Corporation)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (grmnusb) -- C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (AtiPcie) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (MosIrUsb) -- C:\Windows\SysNative\drivers\MosIrUsb.sys ()
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {D46C4E68-1B27-4A56-A357-D2A42680986A}
IE:64bit: - HKLM\..\SearchScopes\{D46C4E68-1B27-4A56-A357-D2A42680986A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKLM\..\SearchScopes,DefaultScope = {D46C4E68-1B27-4A56-A357-D2A42680986A}
IE - HKLM\..\SearchScopes\{D46C4E68-1B27-4A56-A357-D2A42680986A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKCU\..\SearchScopes,DefaultScope = {D46C4E68-1B27-4A56-A357-D2A42680986A}
IE - HKCU\..\SearchScopes\{D46C4E68-1B27-4A56-A357-D2A42680986A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "De-En Beolingus"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.3-ling.de/li/"
FF - prefs.js..extensions.enabledAddons: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1.0
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.9
FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.14
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012.02.10 09:53:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.09 18:44:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012.02.10 09:53:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.09 18:44:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011.11.28 23:45:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rainer\AppData\Roaming\mozilla\Extensions
[2012.09.05 08:00:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rainer\AppData\Roaming\mozilla\Firefox\Profiles\9237osy0.default\extensions
[2011.12.26 18:41:13 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Rainer\AppData\Roaming\mozilla\Firefox\Profiles\9237osy0.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012.03.30 11:12:57 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Rainer\AppData\Roaming\mozilla\Firefox\Profiles\9237osy0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.05 08:00:07 | 000,699,353 | ---- | M] () (No name found) -- C:\Users\Rainer\AppData\Roaming\mozilla\firefox\profiles\9237osy0.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2012.01.17 17:00:34 | 000,001,963 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\mozilla\firefox\profiles\9237osy0.default\searchplugins\de-en-beolingus.xml
[2012.09.09 18:44:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.09.09 18:44:18 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.17 00:18:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.30 08:08:00 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.17 00:18:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.17 00:18:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.17 00:18:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.17 00:18:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.03.21 15:02:42 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files (x86)\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKCU..\Run: [ytmxlumuwztkmdk] C:\ProgramData\ytmxlumu.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: fritz.repeater ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F0BCE1B-AEB9-4B97-A04E-AB60D56A3DC0}: DhcpNameServer = 192.168.0.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E86FB72F-040B-4E3D-B82E-9D4A702A7D1E}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.11 16:53:32 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Rainer\Desktop\OTL.exe
[2012.09.11 16:20:15 | 000,000,000 | ---D | C] -- C:\Users\Rainer\AppData\Roaming\Malwarebytes
[2012.09.11 16:19:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.11 16:19:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.11 16:19:24 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.11 16:19:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.11 15:57:32 | 000,000,000 | ---D | C] -- C:\ProgramData\ngcrzjgawoarflb
[2012.09.09 18:44:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.08.28 10:30:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
[2012.08.20 10:54:15 | 000,000,000 | ---D | C] -- C:\Users\Rainer\restore
[2012.08.19 17:48:03 | 000,000,000 | ---D | C] -- C:\ProgramData\tmp
[2012.08.19 17:48:03 | 000,000,000 | ---D | C] -- C:\ProgramData\hps
[2012.08.19 17:48:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SCHLECKER Foto Digital Service
[2012.08.19 17:33:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Schlecker Fotobuch
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.11 16:48:52 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Rainer\Desktop\OTL.exe
[2012.09.11 16:47:14 | 000,000,000 | ---- | M] () -- C:\Users\Rainer\defogger_reenable
[2012.09.11 16:45:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.11 16:45:26 | 3218,235,392 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.11 16:41:48 | 000,050,477 | ---- | M] () -- C:\Users\Rainer\Desktop\Defogger.exe
[2012.09.11 16:20:12 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.11 16:20:12 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.11 16:20:12 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.11 16:20:12 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.11 16:20:12 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.11 16:19:35 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 16:11:51 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 16:11:51 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 15:57:33 | 000,000,051 | ---- | M] () -- C:\ProgramData\moosqcexoxzyqux
[2012.09.11 15:57:20 | 000,053,760 | ---- | M] () -- C:\ProgramData\ytmxlumu.exe
[2012.09.11 15:26:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.11 15:04:34 | 000,001,344 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.02 19:55:49 | 000,441,104 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.08.25 10:10:39 | 000,040,210 | ---- | M] () -- C:\Users\Rainer\Desktop\D2-Abwesenheitsplaner 2012.pdf
[2012.08.19 17:48:01 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
 
========== Files Created - No Company Name ==========
 
[2012.09.11 16:47:14 | 000,000,000 | ---- | C] () -- C:\Users\Rainer\defogger_reenable
[2012.09.11 16:46:40 | 000,050,477 | ---- | C] () -- C:\Users\Rainer\Desktop\Defogger.exe
[2012.09.11 16:19:35 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 15:57:33 | 000,053,760 | ---- | C] () -- C:\ProgramData\ytmxlumu.exe
[2012.09.11 15:57:23 | 000,000,051 | ---- | C] () -- C:\ProgramData\moosqcexoxzyqux
[2012.08.25 10:10:39 | 000,040,210 | ---- | C] () -- C:\Users\Rainer\Desktop\D2-Abwesenheitsplaner 2012.pdf
[2012.08.19 17:48:01 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
[2012.05.16 15:06:36 | 000,053,554 | ---- | C] () -- C:\Users\Rainer\GPSDATA-20120516.kmz
[2012.05.16 15:06:24 | 000,864,851 | ---- | C] () -- C:\Users\Rainer\GPSDATA-20120516.kml
[2012.05.16 15:04:01 | 000,234,928 | ---- | C] () -- C:\Users\Rainer\GPSDATA-20120516.gpx
[2012.05.16 15:02:55 | 000,065,536 | ---- | C] () -- C:\Users\Rainer\BT747log.bin
[2012.05.16 09:50:07 | 000,002,629 | ---- | C] () -- C:\Users\Rainer\BT747SettingsJ2SE.pdb
[2012.04.02 16:29:36 | 000,000,577 | ---- | C] () -- C:\Windows\asfbinwin.INI
[2012.03.21 14:50:09 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.03.21 14:50:09 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.03.21 14:50:09 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.03.21 14:50:09 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.03.21 14:50:09 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.03.02 11:17:35 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012.01.15 16:53:52 | 000,000,000 | ---- | C] () -- C:\Windows\OpPrintServer.INI
[2012.01.03 15:51:45 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.01.03 15:47:55 | 000,031,864 | ---- | C] () -- C:\Windows\maxlink.ini
[2011.12.05 22:52:52 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.05.26 17:41:30 | 000,157,382 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
 
========== LOP Check ==========
 
[2011.12.09 14:25:15 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\calibre
[2011.12.12 08:17:39 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Canon
[2012.08.28 10:29:55 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\GARMIN
[2011.12.30 00:33:42 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\iWin
[2011.11.30 11:16:31 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Juniper Networks
[2012.02.10 09:53:48 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Nokia
[2011.11.30 16:37:47 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Nokia Suite
[2012.07.16 08:44:23 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\PC Suite
[2012.01.03 15:52:38 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\ScanSoft
[2011.12.06 14:48:59 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Vodafone
[2011.12.30 00:30:30 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\WildTangent
[2012.01.03 15:52:43 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Zeon
[2012.07.19 07:44:46 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---

cosinus 12.09.2012 10:55

Funktioniert noch der abgesicherte Modus mit Netzwerktreibern? Mit Internetverbindung?



Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

Rai3 12.09.2012 11:06

Wenn ich Abgesicherten Modus mit Netzwerktreiber starte, fährt er so noch ohne Fehler hoch.
Eine WLAN Verbindung scheint er auch aufzubauen. Auf jeden FAll meldet er mir in der Statusleiste dass er Internetzugriff hätte

VG Rainer

cosinus 12.09.2012 14:22

Wenn dieser Modus funktioniert, kannst du erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Rai3 12.09.2012 14:29

Malwarebytes habe ich soeben aktualisiert und den Vollscan gestartet.
Das Ergebnis werde ich posten und anschließend ESET starten.

So der Malwarebytes ist nun durch.

Hier die Logs:

mbam-log-2012-09-11 (16-21-24)
Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.07.13

Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus)
Internet Explorer 8.0.7601.17514
Rainer :: RAINER-LT [Administrator]

11.09.2012 16:21:24
mbam-log-2012-09-11 (16-21-24).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 202274
Laufzeit: 2 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Rainer\0.38153547693077494.exe (Exploit.Drop.UR.2) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

mbam-log-2012-09-12 (15-28-23)
Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.12.04

Windows 7 Service Pack 1 x64 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 8.0.7601.17514
Rainer :: RAINER-LT [Administrator]

12.09.2012 15:28:23
mbam-log-2012-09-12 (15-28-23).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 487185
Laufzeit: 53 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Qoobox\Quarantine\C\Users\Rainer\AppData\Local\Skype\SkypePM.exe.vir (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Der ESET läuft noch

So nach 2,5 Stunden war dann auch das ESET durch. Hier das Logfile:
Code:

C:\ProgramData\ytmxlumu.exe        a variant of Win32/Injector.WID trojan
C:\ProgramData\ngcrzjgawoarflb\main.html        HTML/Ransom.B trojan
C:\Users\Rainer\AppData\Local\Temp\jar_cache8220929430149892645.tmp        a variant of Java/Exploit.CVE-2012-0507.B trojan
C:\Users\Rainer\AppData\Local\Temp\plugtmp-4\plugin-ap2.php        JS/Exploit.Pdfka.PKA.Gen trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\1a31830a-4f07c439        multiple threats
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\5bfcf48c-5a7bbc24        Java/Exploit.CVE-2012-0507.W trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\605824e-43160529        probably a variant of Java/Exploit.CVE-2012-0507.AO trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\59c87217-4e8115d6        Java/Exploit.Agent.NBC trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\63f68c9d-34dde7d6        Java/Exploit.Agent.NBR trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\d9b7edf-74a06515        a variant of Java/Exploit.Agent.NBC trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\5745c821-1588cc49        multiple threats
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\4f2142e2-12f5c935        a variant of Java/Exploit.CVE-2012-0507.B trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\bce3366-254b2b20        Java/Agent.EI trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\744012f4-5f0cd6b8        a variant of Java/Exploit.CVE-2011-3544.BR trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\2103fc78-2fae9ca8        probably a variant of Java/Exploit.CVE-2012-0507.AO trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\43325238-371cb5bd        a variant of Java/Exploit.CVE-2011-3544.BR trojan
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\68f40bc-3d7f7823        multiple threats
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\4c4772ff-2d49d9d3        Java/Exploit.CVE-2012-0507.DB trojan

Irgendwie postet der mir alle neuen Antworten immer wieder in den alten threat.
So erkennt man ja gar nicht, das ich was neues geschrieben habe.
Wie auch immer, alle Anweisungen sind abgearbeitet ;-)

Was nun?

Irgendwie postet der mir alle neuen Antworten immer wieder in den alten threat.
So erkennt man ja gar nicht, das ich was neues geschrieben habe.
Wie auch immer, alle Anweisungen sind abgearbeitet ;-)

Was nun?

cosinus 14.09.2012 10:46

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

Rai3 14.09.2012 11:50

Hallo cosinus,

hier das Log vom AdwCleaner

Code:

# AdwCleaner v2.001 - Datei am 09/14/2012 um 12:46:53 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Rainer - RAINER-LT
# Bootmodus : Abgesicherter Modus mit Netzwerkunterstützung
# Ausgeführt unter : C:\Users\Rainer\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Ordner Gefunden : C:\Users\Rainer\AppData\Local\vghd

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v15.0 (de)

Profilname : default
Datei : C:\Users\Rainer\AppData\Roaming\Mozilla\Firefox\Profiles\9237osy0.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [2076 octets] - [14/09/2012 12:46:53]

########## EOF - C:\AdwCleaner[R1].txt - [2136 octets] ##########

Schöne Grüße und danke schon mal bis hierher ;)
Rainer

cosinus 14.09.2012 15:20

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

Rai3 14.09.2012 18:34

Hallo cosinus,

habe den adwCleaner laufen gelassen und auf Löschen geklickt.
Er hat dann auch wie beschrieben neu gebootet und ist dann im normalen Modus hochgefahren. Aber direkt danach kam wieder der weiße Bildschirm.

Ich haben den Rechner dann wieder hart ausgeschaltet und im abgesicherten Modus neu hochgefahren. Unter C: habe ich dann das Logfile gesucht und unten angehängt.

Code:

# AdwCleaner v2.001 - Datei am 09/14/2012 um 19:25:59 erstellt
# Aktualisiert am 09/09/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Rainer - RAINER-LT
# Bootmodus : Abgesicherter Modus mit Netzwerkunterstützung
# Ausgeführt unter : C:\Users\Rainer\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Ordner Gelöscht : C:\Users\Rainer\AppData\Local\vghd

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.7601.17514

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v15.0 (de)

Profilname : default
Datei : C:\Users\Rainer\AppData\Roaming\Mozilla\Firefox\Profiles\9237osy0.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [2201 octets] - [14/09/2012 12:46:53]
AdwCleaner[S1].txt - [2795 octets] - [14/09/2012 19:25:59]

########## EOF - C:\AdwCleaner[S1].txt - [2855 octets] ##########

Schöne Grüße
Rainer

cosinus 14.09.2012 22:58

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Rai3 15.09.2012 08:36

hallo cosinus,

otl neu geladen. als administrator gestartet, quickscan durchgeführt.

Hier das Log-File
Code:

OTL logfile created on: 15.09.2012 09:12:28 - Run 3
OTL by OldTimer - Version 3.2.61.4    Folder = C:\Users\Rainer\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 3,42 Gb Available Physical Memory | 85,69% Memory free
7,99 Gb Paging File | 7,44 Gb Available in Paging File | 93,15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,73 Gb Total Space | 97,72 Gb Free Space | 21,63% Space Free | Partition Type: NTFS
Drive D: | 13,73 Gb Total Space | 2,28 Gb Free Space | 16,57% Space Free | Partition Type: NTFS
Drive E: | 99,02 Mb Total Space | 96,44 Mb Free Space | 97,40% Space Free | Partition Type: FAT32
Drive G: | 249,71 Mb Total Space | 65,36 Mb Free Space | 26,17% Space Free | Partition Type: FAT
 
Computer Name: RAINER-LT | User Name: Rainer | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Rainer\Desktop\OTL.exe (OldTimer Tools)
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (ZuneWlanCfgSvc) -- C:\Programme\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) -- C:\Programme\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) -- C:\Programme\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (VmbService) -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BrYNSvc) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe (IDT, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (tbhsd) -- C:\Windows\SysNative\drivers\tbhsd.sys (RapidSolution Software AG)
DRV:64bit: - (RRNetCapMP) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV:64bit: - (RRNetCap) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\androidusb.sys (Google Inc)
DRV:64bit: - (ewusbnet) -- C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwusbfake) -- C:\Windows\SysNative\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (JMCR) -- C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (irda) -- C:\Windows\SysNative\drivers\irda.sys (Microsoft Corporation)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (grmnusb) -- C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (AtiPcie) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (MosIrUsb) -- C:\Windows\SysNative\drivers\MosIrUsb.sys ()
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{D46C4E68-1B27-4A56-A357-D2A42680986A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{D46C4E68-1B27-4A56-A357-D2A42680986A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\..\SearchScopes\{D46C4E68-1B27-4A56-A357-D2A42680986A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "De-En Beolingus"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.3-ling.de/li/"
FF - prefs.js..extensions.enabledAddons: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1.0
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.9
FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.14
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012.02.10 09:53:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.09 18:44:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files (x86)\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012.02.10 09:53:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.09 18:44:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011.11.28 23:45:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rainer\AppData\Roaming\mozilla\Extensions
[2012.09.05 08:00:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rainer\AppData\Roaming\mozilla\Firefox\Profiles\9237osy0.default\extensions
[2011.12.26 18:41:13 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Rainer\AppData\Roaming\mozilla\Firefox\Profiles\9237osy0.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012.03.30 11:12:57 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Rainer\AppData\Roaming\mozilla\Firefox\Profiles\9237osy0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.05 08:00:07 | 000,699,353 | ---- | M] () (No name found) -- C:\Users\Rainer\AppData\Roaming\mozilla\firefox\profiles\9237osy0.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2012.01.17 17:00:34 | 000,001,963 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\mozilla\firefox\profiles\9237osy0.default\searchplugins\de-en-beolingus.xml
[2012.09.09 18:44:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.09.09 18:44:18 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.17 00:18:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.30 08:08:00 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.17 00:18:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.17 00:18:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.17 00:18:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.17 00:18:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.03.21 15:02:42 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files (x86)\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000..\Run: [ytmxlumuwztkmdk] C:\ProgramData\ytmxlumu.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript File not found
O4 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000..\RunOnce: [Report] C:\AdwCleaner[S1].txt ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\..Trusted Domains: fritz.repeater ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F0BCE1B-AEB9-4B97-A04E-AB60D56A3DC0}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E86FB72F-040B-4E3D-B82E-9D4A702A7D1E}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: ezSharedSvc - C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
 
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.12 16:30:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.09.12 16:29:41 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Rainer\Desktop\esetsmartinstaller_enu.exe
[2012.09.11 16:53:32 | 000,599,552 | ---- | C] (OldTimer Tools) -- C:\Users\Rainer\Desktop\OTL.exe
[2012.09.11 16:20:15 | 000,000,000 | ---D | C] -- C:\Users\Rainer\AppData\Roaming\Malwarebytes
[2012.09.11 16:19:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.09.11 16:19:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.09.11 16:19:24 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.11 16:19:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.11 15:57:32 | 000,000,000 | ---D | C] -- C:\ProgramData\ngcrzjgawoarflb
[2012.09.09 18:44:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.08.28 10:30:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
[2012.08.20 10:54:15 | 000,000,000 | ---D | C] -- C:\Users\Rainer\restore
[2012.08.19 17:48:03 | 000,000,000 | ---D | C] -- C:\ProgramData\tmp
[2012.08.19 17:48:03 | 000,000,000 | ---D | C] -- C:\ProgramData\hps
[2012.08.19 17:48:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SCHLECKER Foto Digital Service
[2012.08.19 17:33:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Schlecker Fotobuch
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.15 09:07:02 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Users\Rainer\Desktop\OTL.exe
[2012.09.14 19:29:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.14 19:29:21 | 3218,235,392 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.14 12:44:34 | 000,512,399 | ---- | M] () -- C:\Users\Rainer\Desktop\adwcleaner.exe
[2012.09.12 16:29:48 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Rainer\Desktop\esetsmartinstaller_enu.exe
[2012.09.12 16:24:18 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.12 16:24:18 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.12 16:24:18 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.12 16:24:18 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.12 16:24:18 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.11 16:47:14 | 000,000,000 | ---- | M] () -- C:\Users\Rainer\defogger_reenable
[2012.09.11 16:41:48 | 000,050,477 | ---- | M] () -- C:\Users\Rainer\Desktop\Defogger.exe
[2012.09.11 16:19:35 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 16:11:51 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 16:11:51 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.11 15:57:33 | 000,000,051 | ---- | M] () -- C:\ProgramData\moosqcexoxzyqux
[2012.09.11 15:57:20 | 000,053,760 | ---- | M] () -- C:\ProgramData\ytmxlumu.exe
[2012.09.11 15:26:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.11 15:04:34 | 000,001,344 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.09.02 19:55:49 | 000,441,104 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.08.25 10:10:39 | 000,040,210 | ---- | M] () -- C:\Users\Rainer\Desktop\D2-Abwesenheitsplaner 2012.pdf
[2012.08.19 17:48:01 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
 
========== Files Created - No Company Name ==========
 
[2012.09.14 12:46:40 | 000,512,399 | ---- | C] () -- C:\Users\Rainer\Desktop\adwcleaner.exe
[2012.09.11 16:47:14 | 000,000,000 | ---- | C] () -- C:\Users\Rainer\defogger_reenable
[2012.09.11 16:46:40 | 000,050,477 | ---- | C] () -- C:\Users\Rainer\Desktop\Defogger.exe
[2012.09.11 16:19:35 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.11 15:57:33 | 000,053,760 | ---- | C] () -- C:\ProgramData\ytmxlumu.exe
[2012.09.11 15:57:23 | 000,000,051 | ---- | C] () -- C:\ProgramData\moosqcexoxzyqux
[2012.08.25 10:10:39 | 000,040,210 | ---- | C] () -- C:\Users\Rainer\Desktop\D2-Abwesenheitsplaner 2012.pdf
[2012.08.19 17:48:01 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
[2012.05.16 15:06:36 | 000,053,554 | ---- | C] () -- C:\Users\Rainer\GPSDATA-20120516.kmz
[2012.05.16 15:06:24 | 000,864,851 | ---- | C] () -- C:\Users\Rainer\GPSDATA-20120516.kml
[2012.05.16 15:04:01 | 000,234,928 | ---- | C] () -- C:\Users\Rainer\GPSDATA-20120516.gpx
[2012.05.16 15:02:55 | 000,065,536 | ---- | C] () -- C:\Users\Rainer\BT747log.bin
[2012.05.16 09:50:07 | 000,002,629 | ---- | C] () -- C:\Users\Rainer\BT747SettingsJ2SE.pdb
[2012.04.02 16:29:36 | 000,000,577 | ---- | C] () -- C:\Windows\asfbinwin.INI
[2012.03.21 14:50:09 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.03.21 14:50:09 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.03.21 14:50:09 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.03.21 14:50:09 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.03.21 14:50:09 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.03.02 11:17:35 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012.01.15 16:53:52 | 000,000,000 | ---- | C] () -- C:\Windows\OpPrintServer.INI
[2012.01.03 15:51:45 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.01.03 15:47:55 | 000,031,864 | ---- | C] () -- C:\Windows\maxlink.ini
[2011.12.05 22:52:52 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010.05.26 17:41:30 | 000,157,382 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
 
========== LOP Check ==========
 
[2011.12.09 14:25:15 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\calibre
[2011.12.12 08:17:39 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Canon
[2012.08.28 10:29:55 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\GARMIN
[2011.12.30 00:33:42 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\iWin
[2011.11.30 11:16:31 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Juniper Networks
[2012.02.10 09:53:48 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Nokia
[2011.11.30 16:37:47 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Nokia Suite
[2012.07.16 08:44:23 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\PC Suite
[2012.01.03 15:52:38 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\ScanSoft
[2011.12.06 14:48:59 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Vodafone
[2011.12.30 00:30:30 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\WildTangent
[2012.01.03 15:52:43 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Zeon
[2012.07.19 07:44:46 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.02.28 16:26:50 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Adobe
[2012.02.27 13:59:54 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Adobe-BackupByPhotoshopCS5Portable
[2011.12.14 09:02:28 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Apple Computer
[2011.11.28 22:04:28 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\ATI
[2011.11.28 23:50:20 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Avira
[2012.01.15 21:18:25 | 000,000,000 | R--D | M] -- C:\Users\Rainer\AppData\Roaming\Brother
[2011.12.09 14:25:15 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\calibre
[2011.12.12 08:17:39 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Canon
[2011.11.29 11:47:36 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\CyberLink
[2012.01.20 22:33:48 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\DivX
[2011.12.06 15:08:28 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\FLEXnet
[2012.08.28 10:29:55 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\GARMIN
[2012.02.04 10:06:02 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Hewlett-Packard
[2011.12.05 09:45:49 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\HP Support Assistant
[2011.12.05 09:56:28 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\hpqlog
[2011.12.05 09:45:51 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\HpUpdate
[2011.11.28 21:54:10 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Identities
[2012.01.03 15:49:20 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\InstallShield
[2011.12.30 00:33:42 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\iWin
[2011.11.30 10:12:17 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Jasc Software Inc
[2011.11.30 11:16:31 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Juniper Networks
[2011.11.28 23:45:31 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Macromedia
[2012.09.11 16:20:15 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Malwarebytes
[2010.01.24 11:07:54 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Media Center Programs
[2012.08.21 15:01:32 | 000,000,000 | --SD | M] -- C:\Users\Rainer\AppData\Roaming\Microsoft
[2011.11.28 23:45:34 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Mozilla
[2012.02.10 09:53:48 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Nokia
[2011.11.30 16:37:47 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Nokia Suite
[2012.07.16 08:44:23 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\PC Suite
[2012.01.03 15:52:38 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\ScanSoft
[2012.05.24 15:06:00 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\vlc
[2011.12.06 14:48:59 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Vodafone
[2011.12.30 00:30:30 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\WildTangent
[2012.01.12 23:04:59 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\WinRAR
[2012.01.03 15:52:43 | 000,000,000 | ---D | M] -- C:\Users\Rainer\AppData\Roaming\Zeon
 
< %APPDATA%\*.exe /s >
[2009.11.13 04:14:10 | 000,132,392 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\Juniper Networks\Setup Client\dsmmf.exe
[2009.11.13 04:14:08 | 000,496,936 | ---- | M] (Juniper Networks) -- C:\Users\Rainer\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe
[2009.11.13 04:13:34 | 000,329,752 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClientOCX.exe
[2009.11.13 04:12:06 | 000,217,800 | ---- | M] () -- C:\Users\Rainer\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupXP.exe
[2009.11.13 04:14:14 | 000,050,776 | ---- | M] (Juniper Networks) -- C:\Users\Rainer\AppData\Roaming\Juniper Networks\Setup Client\uninstall.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\ERDNT\cache64\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache86\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\ERDNT\cache64\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.05.17 22:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\ERDNT\cache64\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\ERDNT\cache86\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\ERDNT\cache86\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\ERDNT\cache64\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\ERDNT\cache86\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\ERDNT\cache64\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\ERDNT\cache86\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\ERDNT\cache64\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\ERDNT\cache64\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache86\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\ERDNT\cache64\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

schöne Grüße
Rainer

cosinus 15.09.2012 14:08

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000..\Run: [ytmxlumuwztkmdk] C:\ProgramData\ytmxlumu.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1154562761-1198328465-1791081454-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
:Files
C:\ProgramData\moosqcexoxzyqux
C:\ProgramData\ytmxlumu.exe
C:\ProgramData\ngcrzjgawoarflb
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Rai3 15.09.2012 18:26

Hallo cosinus,
ich habe den Fix durchgeführt, er hat dann auch einen reboot durchgeführt. Beim Hochstart hatte ich F8 gedrückt und im abgesicherten Modus mit Netztwerktreibern gestartet.
Als er dann wieder neu gestartet ist, hat er mir aber kein Logfile angezeigt.

Kann man das Logfile sonst irgendwo sehen?

Schöne Grüße
Rainer

cosinus 16.09.2012 16:03

Sieh mal bitte in C:\_OTL nach

Rai3 16.09.2012 16:11

Hallo cosinus,

hier habe ich 2 Dateien gefunden:

09152012_191036.txt
Code:

Error: Unable to interpret <%ALLUSERSPROFILE%\Application Data\*.> in the current context!
Error: Unable to interpret <%ALLUSERSPROFILE%\Application Data\*.exe /s> in the current context!
Error: Unable to interpret <%APPDATA%\*.> in the current context!
Error: Unable to interpret <%APPDATA%\*.exe /s> in the current context!
Error: Unable to interpret <%SYSTEMDRIVE%\*.exe> in the current context!
Error: Unable to interpret </md5start> in the current context!
Error: Unable to interpret <wininit.exe> in the current context!
Error: Unable to interpret <userinit.exe> in the current context!
Error: Unable to interpret <eventlog.dll> in the current context!
Error: Unable to interpret <scecli.dll> in the current context!
Error: Unable to interpret <netlogon.dll> in the current context!
Error: Unable to interpret <cngaudit.dll> in the current context!
Error: Unable to interpret <ws2ifsl.sys> in the current context!
Error: Unable to interpret <sceclt.dll> in the current context!
Error: Unable to interpret <ntelogon.dll> in the current context!
Error: Unable to interpret <winlogon.exe> in the current context!
Error: Unable to interpret <logevent.dll> in the current context!
Error: Unable to interpret <user32.DLL> in the current context!
Error: Unable to interpret <iaStor.sys> in the current context!
Error: Unable to interpret <nvstor.sys> in the current context!
Error: Unable to interpret <atapi.sys> in the current context!
Error: Unable to interpret <IdeChnDr.sys> in the current context!
Error: Unable to interpret <viasraid.sys> in the current context!
Error: Unable to interpret <AGP440.sys> in the current context!
Error: Unable to interpret <vaxscsi.sys> in the current context!
Error: Unable to interpret <nvatabus.sys> in the current context!
Error: Unable to interpret <viamraid.sys> in the current context!
Error: Unable to interpret <nvata.sys> in the current context!
Error: Unable to interpret <nvgts.sys> in the current context!
Error: Unable to interpret <iastorv.sys> in the current context!
Error: Unable to interpret <ViPrt.sys> in the current context!
Error: Unable to interpret <eNetHook.dll> in the current context!
Error: Unable to interpret <ahcix86.sys> in the current context!
Error: Unable to interpret <KR10N.sys> in the current context!
Error: Unable to interpret <nvstor32.sys> in the current context!
Error: Unable to interpret <ahcix86s.sys> in the current context!
Error: Unable to interpret </md5stop> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\System32\config\*.sav> in the current context!
Error: Unable to interpret <%systemroot%\*. /mp /s> in the current context!
Error: Unable to interpret <%systemroot%\system32\*.dll /lockedfiles> in the current context!
 
OTL by OldTimer - Version 3.2.61.4 log created on 09152012_191036

und
09152012_191628
Code:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_USERS\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_USERS\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ytmxlumuwztkmdk deleted successfully.
C:\ProgramData\ytmxlumu.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1154562761-1198328465-1791081454-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1154562761-1198328465-1791081454-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
========== FILES ==========
C:\ProgramData\moosqcexoxzyqux moved successfully.
File\Folder C:\ProgramData\ytmxlumu.exe not found.
C:\ProgramData\ngcrzjgawoarflb folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Rainer\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Rainer\Desktop\cmd.bat deleted successfully.
C:\Users\Rainer\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
 
User: Public
->Temp folder emptied: 0 bytes
 
User: Rainer
->Temp folder emptied: 601869818 bytes
->Temporary Internet Files folder emptied: 73311670 bytes
->FireFox cache emptied: 60997380 bytes
->Flash cache emptied: 532 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 666406345 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 301095 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67698 bytes
RecycleBin emptied: 4455 bytes
 
Total Files Cleaned = 1.338,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.4 log created on 09152012_191628

Schöne Grüße und danke bis hierher
Rainer

cosinus 16.09.2012 18:56

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

Rai3 16.09.2012 21:47

hallo cosinus,

der Recher ist tatsächlich im normalen Modus gestartet und hat keinen weißen Bildschirm mehr angezeigt :D

Ich habe den avira Echtzeitscan deaktiviert (der Schirm ist in der Taskleiste geschlossen)
Anschließend habe ich TDSSKiller als Administrator ausgeführt.

Hier das Log:
Code:

22:41:20.0760 5268  TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
22:41:20.0797 5268  ============================================================
22:41:20.0797 5268  Current date / time: 2012/09/16 22:41:20.0797
22:41:20.0797 5268  SystemInfo:
22:41:20.0797 5268 
22:41:20.0798 5268  OS Version: 6.1.7601 ServicePack: 1.0
22:41:20.0798 5268  Product type: Workstation
22:41:20.0798 5268  ComputerName: RAINER-LT
22:41:20.0798 5268  UserName: Rainer
22:41:20.0798 5268  Windows directory: C:\Windows
22:41:20.0798 5268  System windows directory: C:\Windows
22:41:20.0798 5268  Running under WOW64
22:41:20.0798 5268  Processor architecture: Intel x64
22:41:20.0798 5268  Number of processors: 2
22:41:20.0798 5268  Page size: 0x1000
22:41:20.0798 5268  Boot type: Normal boot
22:41:20.0798 5268  ============================================================
22:41:23.0161 5268  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:41:23.0171 5268  Drive \Device\Harddisk1\DR1 - Size: 0xFA00000 (0.24 Gb), SectorSize: 0x200, Cylinders: 0x1F, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
22:41:23.0180 5268  ============================================================
22:41:23.0180 5268  \Device\Harddisk0\DR0:
22:41:23.0180 5268  MBR partitions:
22:41:23.0180 5268  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
22:41:23.0180 5268  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x38777800
22:41:23.0180 5268  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x387DB800, BlocksNum 0x1B76800
22:41:23.0180 5268  \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x3A352000, BlocksNum 0x33830
22:41:23.0180 5268  \Device\Harddisk1\DR1:
22:41:23.0182 5268  MBR partitions:
22:41:23.0182 5268  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x7CFDF
22:41:23.0182 5268  ============================================================
22:41:23.0245 5268  C: <-> \Device\Harddisk0\DR0\Partition2
22:41:23.0459 5268  D: <-> \Device\Harddisk0\DR0\Partition3
22:41:23.0518 5268  E: <-> \Device\Harddisk0\DR0\Partition4
22:41:23.0519 5268  ============================================================
22:41:23.0519 5268  Initialize success
22:41:23.0519 5268  ============================================================
22:42:13.0142 6072  ============================================================
22:42:13.0142 6072  Scan started
22:42:13.0142 6072  Mode: Manual; SigCheck; TDLFS;
22:42:13.0142 6072  ============================================================
22:42:16.0136 6072  ================ Scan system memory ========================
22:42:16.0136 6072  System memory - ok
22:42:16.0137 6072  ================ Scan services =============================
22:42:17.0168 6072  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
22:42:17.0411 6072  1394ohci - ok
22:42:17.0481 6072  [ 1CFFE9C06E66A57DAE1452E449A58240 ] Accelerometer  C:\Windows\system32\DRIVERS\Accelerometer.sys
22:42:17.0600 6072  Accelerometer - ok
22:42:17.0724 6072  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
22:42:17.0779 6072  ACPI - ok
22:42:17.0843 6072  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
22:42:17.0953 6072  AcpiPmi - ok
22:42:18.0095 6072  [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:42:18.0114 6072  AdobeFlashPlayerUpdateSvc - ok
22:42:18.0185 6072  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
22:42:18.0209 6072  adp94xx - ok
22:42:18.0231 6072  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
22:42:18.0252 6072  adpahci - ok
22:42:18.0294 6072  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
22:42:18.0312 6072  adpu320 - ok
22:42:18.0405 6072  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
22:42:18.0517 6072  AeLookupSvc - ok
22:42:18.0663 6072  [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
22:42:18.0726 6072  AESTFilters - ok
22:42:18.0777 6072  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
22:42:18.0866 6072  AFD - ok
22:42:18.0945 6072  [ 98022774D9930ECBB292E70DB7601DF6 ] AgereSoftModem  C:\Windows\system32\DRIVERS\agrsm64.sys
22:42:19.0006 6072  AgereSoftModem - ok
22:42:19.0046 6072  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
22:42:19.0062 6072  agp440 - ok
22:42:19.0087 6072  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
22:42:19.0137 6072  ALG - ok
22:42:19.0202 6072  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
22:42:19.0238 6072  aliide - ok
22:42:19.0295 6072  [ BCC32BF5EBB5DFD4380FA053D3651949 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
22:42:19.0362 6072  AMD External Events Utility - ok
22:42:19.0400 6072  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
22:42:19.0413 6072  amdide - ok
22:42:19.0453 6072  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
22:42:19.0537 6072  AmdK8 - ok
22:42:19.0582 6072  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
22:42:19.0647 6072  AmdPPM - ok
22:42:19.0676 6072  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
22:42:19.0693 6072  amdsata - ok
22:42:19.0720 6072  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
22:42:19.0739 6072  amdsbs - ok
22:42:19.0765 6072  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
22:42:19.0782 6072  amdxata - ok
22:42:19.0842 6072  [ 363571BC0C79E394E69300D1F2E3DDAE ] androidusb      C:\Windows\system32\Drivers\androidusb.sys
22:42:19.0898 6072  androidusb - ok
22:42:19.0978 6072  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:42:19.0993 6072  AntiVirSchedulerService - ok
22:42:20.0016 6072  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:42:20.0031 6072  AntiVirService - ok
22:42:20.0094 6072  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
22:42:20.0378 6072  AppID - ok
22:42:20.0425 6072  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
22:42:20.0574 6072  AppIDSvc - ok
22:42:20.0664 6072  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo        C:\Windows\System32\appinfo.dll
22:42:20.0730 6072  Appinfo - ok
22:42:20.0801 6072  [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
22:42:20.0827 6072  Apple Mobile Device - ok
22:42:20.0875 6072  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\DRIVERS\arc.sys
22:42:20.0893 6072  arc - ok
22:42:20.0906 6072  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
22:42:20.0921 6072  arcsas - ok
22:42:20.0937 6072  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
22:42:21.0007 6072  AsyncMac - ok
22:42:21.0034 6072  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
22:42:21.0049 6072  atapi - ok
22:42:21.0114 6072  [ 38562A6A9CB10844759EAF2B01A7FCD3 ] athr            C:\Windows\system32\DRIVERS\athrx.sys
22:42:21.0187 6072  athr - ok
22:42:21.0239 6072  [ 3B9014FB7CE9E20FD726321C7DB7D8B0 ] AtiHdmiService  C:\Windows\system32\drivers\AtiHdmi.sys
22:42:21.0253 6072  AtiHdmiService - ok
22:42:21.0482 6072  [ A29087680A1C3B049E3C05438E8FF2B8 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
22:42:21.0606 6072  atikmdag - ok
22:42:21.0659 6072  [ 7C5D273E29DCC5505469B299C6F29163 ] AtiPcie        C:\Windows\system32\DRIVERS\AtiPcie.sys
22:42:21.0674 6072  AtiPcie - ok
22:42:21.0751 6072  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:42:21.0817 6072  AudioEndpointBuilder - ok
22:42:21.0828 6072  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
22:42:21.0869 6072  AudioSrv - ok
22:42:21.0897 6072  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
22:42:21.0910 6072  avgntflt - ok
22:42:21.0931 6072  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
22:42:21.0945 6072  avipbb - ok
22:42:21.0955 6072  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
22:42:21.0967 6072  avkmgr - ok
22:42:22.0006 6072  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
22:42:22.0040 6072  AxInstSV - ok
22:42:22.0079 6072  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbda.sys
22:42:22.0128 6072  b06bdrv - ok
22:42:22.0166 6072  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
22:42:22.0216 6072  b57nd60a - ok
22:42:22.0297 6072  [ 01A24B415926BB5F772DBE12459D97DE ] BBSvc          C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
22:42:22.0324 6072  BBSvc - ok
22:42:22.0350 6072  [ 785DE7ABDA13309D6065305542829E76 ] BBUpdate        C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
22:42:22.0366 6072  BBUpdate - ok
22:42:22.0401 6072  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
22:42:22.0435 6072  BDESVC - ok
22:42:22.0462 6072  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
22:42:22.0511 6072  Beep - ok
22:42:22.0567 6072  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
22:42:22.0611 6072  BFE - ok
22:42:22.0660 6072  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\system32\qmgr.dll
22:42:22.0731 6072  BITS - ok
22:42:22.0765 6072  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
22:42:22.0791 6072  blbdrive - ok
22:42:22.0839 6072  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:42:22.0867 6072  Bonjour Service - ok
22:42:22.0907 6072  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
22:42:22.0942 6072  bowser - ok
22:42:22.0974 6072  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:42:23.0058 6072  BrFiltLo - ok
22:42:23.0090 6072  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:42:23.0107 6072  BrFiltUp - ok
22:42:23.0160 6072  [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
22:42:23.0258 6072  BridgeMP - ok
22:42:23.0296 6072  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
22:42:23.0320 6072  Browser - ok
22:42:23.0341 6072  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
22:42:23.0379 6072  Brserid - ok
22:42:23.0394 6072  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
22:42:23.0420 6072  BrSerWdm - ok
22:42:23.0452 6072  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
22:42:23.0508 6072  BrUsbMdm - ok
22:42:23.0538 6072  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
22:42:23.0554 6072  BrUsbSer - ok
22:42:23.0617 6072  [ EA7E57F87D6FEE5FD6C5F813C04E8CD2 ] BrYNSvc        C:\Program Files (x86)\Browny02\BrYNSvc.exe
22:42:23.0637 6072  BrYNSvc ( UnsignedFile.Multi.Generic ) - warning
22:42:23.0637 6072  BrYNSvc - detected UnsignedFile.Multi.Generic (1)
22:42:23.0660 6072  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
22:42:23.0703 6072  BTHMODEM - ok
22:42:23.0819 6072  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
22:42:23.0975 6072  bthserv - ok
22:42:24.0013 6072  catchme - ok
22:42:24.0092 6072  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
22:42:24.0165 6072  cdfs - ok
22:42:24.0249 6072  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
22:42:24.0300 6072  cdrom - ok
22:42:24.0405 6072  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
22:42:24.0613 6072  CertPropSvc - ok
22:42:24.0746 6072  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
22:42:24.0884 6072  circlass - ok
22:42:24.0977 6072  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
22:42:25.0016 6072  CLFS - ok
22:42:25.0196 6072  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:42:25.0265 6072  clr_optimization_v2.0.50727_32 - ok
22:42:25.0327 6072  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:42:25.0440 6072  clr_optimization_v2.0.50727_64 - ok
22:42:25.0752 6072  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:42:25.0943 6072  clr_optimization_v4.0.30319_32 - ok
22:42:26.0040 6072  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:42:26.0055 6072  clr_optimization_v4.0.30319_64 - ok
22:42:26.0139 6072  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
22:42:26.0236 6072  CmBatt - ok
22:42:26.0316 6072  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
22:42:26.0339 6072  cmdide - ok
22:42:26.0436 6072  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
22:42:26.0500 6072  CNG - ok
22:42:26.0672 6072  [ F9A79C5B27037821112C50A9C8FB367A ] Com4QLBEx      C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
22:42:26.0702 6072  Com4QLBEx - ok
22:42:26.0789 6072  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
22:42:26.0816 6072  Compbatt - ok
22:42:26.0851 6072  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
22:42:26.0944 6072  CompositeBus - ok
22:42:26.0982 6072  COMSysApp - ok
22:42:27.0024 6072  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
22:42:27.0086 6072  crcdisk - ok
22:42:27.0134 6072  [ 4F5414602E2544A4554D95517948B705 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
22:42:27.0161 6072  CryptSvc - ok
22:42:27.0235 6072  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
22:42:27.0303 6072  DcomLaunch - ok
22:42:27.0342 6072  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
22:42:27.0401 6072  defragsvc - ok
22:42:27.0447 6072  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
22:42:27.0505 6072  DfsC - ok
22:42:27.0534 6072  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
22:42:27.0594 6072  Dhcp - ok
22:42:27.0653 6072  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
22:42:27.0691 6072  discache - ok
22:42:27.0722 6072  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
22:42:27.0734 6072  Disk - ok
22:42:27.0762 6072  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
22:42:27.0791 6072  Dnscache - ok
22:42:27.0824 6072  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
22:42:27.0877 6072  dot3svc - ok
22:42:27.0909 6072  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
22:42:27.0955 6072  DPS - ok
22:42:27.0973 6072  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
22:42:28.0013 6072  drmkaud - ok
22:42:28.0071 6072  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
22:42:28.0101 6072  DXGKrnl - ok
22:42:28.0156 6072  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
22:42:28.0241 6072  EapHost - ok
22:42:28.0312 6072  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\DRIVERS\evbda.sys
22:42:28.0390 6072  ebdrv - ok
22:42:28.0424 6072  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
22:42:28.0465 6072  EFS - ok
22:42:28.0567 6072  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
22:42:28.0612 6072  ehRecvr - ok
22:42:28.0633 6072  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
22:42:28.0661 6072  ehSched - ok
22:42:28.0691 6072  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
22:42:28.0713 6072  elxstor - ok
22:42:28.0744 6072  [ 524C79054636D2E5751169005006460B ] enecir          C:\Windows\system32\DRIVERS\enecir.sys
22:42:28.0774 6072  enecir - ok
22:42:28.0809 6072  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
22:42:28.0827 6072  ErrDev - ok
22:42:28.0879 6072  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
22:42:28.0931 6072  EventSystem - ok
22:42:28.0980 6072  [ 8ADACFFAD67394C711698EA074CE3BAB ] ewusbnet        C:\Windows\system32\DRIVERS\ewusbnet.sys
22:42:29.0029 6072  ewusbnet - ok
22:42:29.0056 6072  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
22:42:29.0114 6072  exfat - ok
22:42:29.0153 6072  ezSharedSvc - ok
22:42:29.0213 6072  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
22:42:29.0274 6072  fastfat - ok
22:42:29.0389 6072  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
22:42:29.0429 6072  Fax - ok
22:42:29.0439 6072  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
22:42:29.0452 6072  fdc - ok
22:42:29.0479 6072  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
22:42:29.0530 6072  fdPHost - ok
22:42:29.0548 6072  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
22:42:29.0593 6072  FDResPub - ok
22:42:29.0620 6072  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
22:42:29.0634 6072  FileInfo - ok
22:42:29.0650 6072  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
22:42:29.0693 6072  Filetrace - ok
22:42:29.0710 6072  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
22:42:29.0727 6072  flpydisk - ok
22:42:29.0775 6072  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
22:42:29.0793 6072  FltMgr - ok
22:42:29.0851 6072  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache      C:\Windows\system32\FntCache.dll
22:42:29.0916 6072  FontCache - ok
22:42:29.0964 6072  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:42:29.0994 6072  FontCache3.0.0.0 - ok
22:42:30.0024 6072  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
22:42:30.0044 6072  FsDepends - ok
22:42:30.0072 6072  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
22:42:30.0085 6072  Fs_Rec - ok
22:42:30.0140 6072  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
22:42:30.0163 6072  fvevol - ok
22:42:30.0204 6072  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
22:42:30.0219 6072  gagp30kx - ok
22:42:30.0292 6072  [ C1BBCE4B30B45410178EE674C818D10C ] GameConsoleService C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
22:42:30.0327 6072  GameConsoleService - ok
22:42:30.0358 6072  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
22:42:30.0370 6072  GEARAspiWDM - ok
22:42:30.0436 6072  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
22:42:30.0499 6072  gpsvc - ok
22:42:30.0550 6072  [ 2ED7FF3E1ADA4092632393781518B3A7 ] grmnusb        C:\Windows\system32\drivers\grmnusb.sys
22:42:30.0562 6072  grmnusb - ok
22:42:30.0588 6072  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
22:42:30.0621 6072  hcw85cir - ok
22:42:30.0673 6072  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:42:30.0715 6072  HdAudAddService - ok
22:42:30.0746 6072  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
22:42:30.0775 6072  HDAudBus - ok
22:42:30.0788 6072  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
22:42:30.0824 6072  HidBatt - ok
22:42:30.0851 6072  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
22:42:30.0894 6072  HidBth - ok
22:42:30.0934 6072  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
22:42:30.0988 6072  HidIr - ok
22:42:31.0021 6072  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\System32\hidserv.dll
22:42:31.0081 6072  hidserv - ok
22:42:31.0145 6072  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
22:42:31.0169 6072  HidUsb - ok
22:42:31.0202 6072  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
22:42:31.0263 6072  hkmsvc - ok
22:42:31.0305 6072  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:42:31.0324 6072  HomeGroupListener - ok
22:42:31.0369 6072  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:42:31.0407 6072  HomeGroupProvider - ok
22:42:31.0451 6072  [ 13BB1114451C63BFB41BA7DAA4D70A29 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
22:42:31.0465 6072  HP Support Assistant Service - ok
22:42:31.0515 6072  [ BCC4A8B2E2E902F52E7F2E7D8E125765 ] HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
22:42:31.0524 6072  HPDrvMntSvc.exe - ok
22:42:31.0572 6072  [ 05712FDDBD45A5864EB326FAABC6A4E3 ] hpdskflt        C:\Windows\system32\DRIVERS\hpdskflt.sys
22:42:31.0584 6072  hpdskflt - ok
22:42:31.0609 6072  [ 9AF482D058BE59CC28BCE52E7C4B747C ] HpqKbFiltr      C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
22:42:31.0642 6072  HpqKbFiltr - ok
22:42:31.0722 6072  [ EC9739A46F1F83C6E52A7A4697F44A65 ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
22:42:31.0742 6072  hpqwmiex - ok
22:42:31.0781 6072  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
22:42:31.0793 6072  HpSAMD - ok
22:42:31.0809 6072  [ AA036CC5F5221D9B915F4D4DCE74BA9A ] hpsrv          C:\Windows\system32\Hpservice.exe
22:42:31.0822 6072  hpsrv - ok
22:42:31.0915 6072  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
22:42:31.0975 6072  HTTP - ok
22:42:32.0042 6072  [ D969D0E26C5B1E813B17066A8318D5D4 ] hwdatacard      C:\Windows\system32\DRIVERS\ewusbmdm.sys
22:42:32.0068 6072  hwdatacard - ok
22:42:32.0102 6072  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
22:42:32.0115 6072  hwpolicy - ok
22:42:32.0171 6072  [ B45B3647BA32749B94FA689175EC8C26 ] hwusbfake      C:\Windows\system32\DRIVERS\ewusbfake.sys
22:42:32.0223 6072  hwusbfake - ok
22:42:32.0264 6072  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
22:42:32.0280 6072  i8042prt - ok
22:42:32.0311 6072  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
22:42:32.0334 6072  iaStorV - ok
22:42:32.0424 6072  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:42:32.0468 6072  idsvc - ok
22:42:32.0619 6072  [ A87261EF1546325B559374F5689CF5BC ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
22:42:32.0730 6072  igfx - ok
22:42:32.0766 6072  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
22:42:32.0777 6072  iirsp - ok
22:42:32.0827 6072  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
22:42:32.0906 6072  IKEEXT - ok
22:42:32.0921 6072  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
22:42:32.0934 6072  intelide - ok
22:42:32.0968 6072  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
22:42:32.0991 6072  intelppm - ok
22:42:33.0017 6072  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
22:42:33.0067 6072  IPBusEnum - ok
22:42:33.0100 6072  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:42:33.0136 6072  IpFilterDriver - ok
22:42:33.0165 6072  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
22:42:33.0229 6072  iphlpsvc - ok
22:42:33.0268 6072  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
22:42:33.0335 6072  IPMIDRV - ok
22:42:33.0368 6072  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
22:42:33.0434 6072  IPNAT - ok
22:42:33.0520 6072  [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
22:42:33.0554 6072  iPod Service - ok
22:42:33.0594 6072  [ 05360B1EA5A2ABF620D1D96EBD8BD8F1 ] irda            C:\Windows\system32\DRIVERS\irda.sys
22:42:33.0688 6072  irda - ok
22:42:33.0722 6072  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
22:42:33.0750 6072  IRENUM - ok
22:42:33.0774 6072  [ 3848384AB383F0A8F506C4370635C1F9 ] Irmon          C:\Windows\System32\irmon.dll
22:42:33.0792 6072  Irmon - ok
22:42:33.0812 6072  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
22:42:33.0825 6072  isapnp - ok
22:42:33.0858 6072  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
22:42:33.0876 6072  iScsiPrt - ok
22:42:33.0920 6072  [ F8844B00C10E386C704C610E95A9847D ] JMCR            C:\Windows\system32\DRIVERS\jmcr.sys
22:42:33.0939 6072  JMCR - ok
22:42:33.0961 6072  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
22:42:33.0975 6072  kbdclass - ok
22:42:33.0996 6072  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
22:42:34.0031 6072  kbdhid - ok
22:42:34.0058 6072  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
22:42:34.0071 6072  KeyIso - ok
22:42:34.0112 6072  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
22:42:34.0126 6072  KSecDD - ok
22:42:34.0141 6072  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
22:42:34.0160 6072  KSecPkg - ok
22:42:34.0184 6072  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
22:42:34.0234 6072  ksthunk - ok
22:42:34.0269 6072  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
22:42:34.0327 6072  KtmRm - ok
22:42:34.0383 6072  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\System32\srvsvc.dll
22:42:34.0469 6072  LanmanServer - ok
22:42:34.0506 6072  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:42:34.0588 6072  LanmanWorkstation - ok
22:42:34.0653 6072  [ 2238B91AC1A12CC6CC4C4FED41258B2A ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
22:42:34.0685 6072  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
22:42:34.0685 6072  LightScribeService - detected UnsignedFile.Multi.Generic (1)
22:42:34.0715 6072  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
22:42:34.0780 6072  lltdio - ok
22:42:34.0805 6072  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
22:42:34.0891 6072  lltdsvc - ok
22:42:34.0918 6072  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
22:42:34.0975 6072  lmhosts - ok
22:42:35.0003 6072  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
22:42:35.0038 6072  LSI_FC - ok
22:42:35.0053 6072  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
22:42:35.0089 6072  LSI_SAS - ok
22:42:35.0106 6072  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:42:35.0140 6072  LSI_SAS2 - ok
22:42:35.0155 6072  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:42:35.0191 6072  LSI_SCSI - ok
22:42:35.0211 6072  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
22:42:35.0290 6072  luafv - ok
22:42:35.0329 6072  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
22:42:35.0401 6072  Mcx2Svc - ok
22:42:35.0418 6072  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
22:42:35.0455 6072  megasas - ok
22:42:35.0484 6072  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
22:42:35.0523 6072  MegaSR - ok
22:42:35.0614 6072  Microsoft SharePoint Workspace Audit Service - ok
22:42:35.0642 6072  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
22:42:35.0719 6072  MMCSS - ok
22:42:35.0738 6072  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
22:42:35.0807 6072  Modem - ok
22:42:35.0850 6072  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
22:42:35.0884 6072  monitor - ok
22:42:35.0971 6072  [ 54F44C3A4F6C1C4D00D4157FBD531EB1 ] MosIrUsb        C:\Windows\system32\DRIVERS\MosIrUsb.sys
22:42:36.0012 6072  MosIrUsb - ok
22:42:36.0050 6072  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
22:42:36.0076 6072  mouclass - ok
22:42:36.0121 6072  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
22:42:36.0157 6072  mouhid - ok
22:42:36.0188 6072  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
22:42:36.0224 6072  mountmgr - ok
22:42:36.0298 6072  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:42:36.0362 6072  MozillaMaintenance - ok
22:42:36.0396 6072  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
22:42:36.0430 6072  mpio - ok
22:42:36.0474 6072  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
22:42:36.0551 6072  mpsdrv - ok
22:42:36.0625 6072  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
22:42:36.0706 6072  MpsSvc - ok
22:42:36.0739 6072  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
22:42:36.0810 6072  MRxDAV - ok
22:42:36.0838 6072  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
22:42:36.0938 6072  mrxsmb - ok
22:42:36.0963 6072  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:42:37.0028 6072  mrxsmb10 - ok
22:42:37.0062 6072  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:42:37.0097 6072  mrxsmb20 - ok
22:42:37.0121 6072  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
22:42:37.0155 6072  msahci - ok
22:42:37.0176 6072  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
22:42:37.0211 6072  msdsm - ok
22:42:37.0223 6072  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
22:42:37.0261 6072  MSDTC - ok
22:42:37.0287 6072  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
22:42:37.0363 6072  Msfs - ok
22:42:37.0395 6072  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
22:42:37.0452 6072  mshidkmdf - ok
22:42:37.0470 6072  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
22:42:37.0504 6072  msisadrv - ok
22:42:37.0534 6072  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
22:42:37.0637 6072  MSiSCSI - ok
22:42:37.0642 6072  msiserver - ok
22:42:37.0675 6072  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
22:42:37.0721 6072  MSKSSRV - ok
22:42:37.0733 6072  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
22:42:37.0797 6072  MSPCLOCK - ok
22:42:37.0824 6072  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
22:42:37.0888 6072  MSPQM - ok
22:42:37.0923 6072  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
22:42:37.0959 6072  MsRPC - ok
22:42:37.0977 6072  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
22:42:38.0011 6072  mssmbios - ok
22:42:38.0030 6072  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
22:42:38.0093 6072  MSTEE - ok
22:42:38.0107 6072  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
22:42:38.0142 6072  MTConfig - ok
22:42:38.0159 6072  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
22:42:38.0193 6072  Mup - ok
22:42:38.0231 6072  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
22:42:38.0303 6072  napagent - ok
22:42:38.0338 6072  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
22:42:38.0393 6072  NativeWifiP - ok
22:42:38.0420 6072  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\Windows\system32\drivers\ndis.sys
22:42:38.0469 6072  NDIS - ok
22:42:38.0484 6072  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
22:42:38.0543 6072  NdisCap - ok
22:42:38.0585 6072  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
22:42:38.0634 6072  NdisTapi - ok
22:42:38.0668 6072  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
22:42:38.0737 6072  Ndisuio - ok
22:42:38.0770 6072  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
22:42:38.0844 6072  NdisWan - ok
22:42:38.0875 6072  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
22:42:38.0957 6072  NDProxy - ok
22:42:38.0998 6072  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
22:42:39.0093 6072  NetBIOS - ok
22:42:39.0123 6072  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
22:42:39.0195 6072  NetBT - ok
22:42:39.0208 6072  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
22:42:39.0238 6072  Netlogon - ok
22:42:39.0267 6072  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
22:42:39.0343 6072  Netman - ok
22:42:39.0368 6072  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
22:42:39.0443 6072  netprofm - ok
22:42:39.0469 6072  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:42:39.0503 6072  NetTcpPortSharing - ok
22:42:39.0635 6072  [ 64428DFDAF6E88366CB51F45A79C5F69 ] netw5v64        C:\Windows\system32\DRIVERS\netw5v64.sys
22:42:39.0807 6072  netw5v64 - ok
22:42:39.0847 6072  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
22:42:39.0884 6072  nfrd960 - ok
22:42:39.0964 6072  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
22:42:40.0038 6072  NlaSvc - ok
22:42:40.0069 6072  [ 5FE6F8C05F0769BBB74AFAC11453B182 ] nmwcd          C:\Windows\system32\drivers\ccdcmbx64.sys
22:42:40.0152 6072  nmwcd - ok
22:42:40.0198 6072  [ 73C929945C0850B8D1FE2FEA05FDF05D ] nmwcdc          C:\Windows\system32\drivers\ccdcmbox64.sys
22:42:40.0247 6072  nmwcdc - ok
22:42:40.0260 6072  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
22:42:40.0317 6072  Npfs - ok
22:42:40.0343 6072  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
22:42:40.0401 6072  nsi - ok
22:42:40.0422 6072  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
22:42:40.0491 6072  nsiproxy - ok
22:42:40.0551 6072  [ A2F74975097F52A00745F9637451FDD8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
22:42:40.0615 6072  Ntfs - ok
22:42:40.0626 6072  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
22:42:40.0728 6072  Null - ok
22:42:40.0780 6072  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
22:42:40.0834 6072  nvraid - ok
22:42:40.0844 6072  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
22:42:40.0882 6072  nvstor - ok
22:42:40.0919 6072  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
22:42:40.0958 6072  nv_agp - ok
22:42:40.0973 6072  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
22:42:41.0009 6072  ohci1394 - ok
22:42:41.0057 6072  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:42:41.0078 6072  ose - ok
22:42:41.0252 6072  [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:42:41.0386 6072  osppsvc - ok
22:42:41.0430 6072  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
22:42:41.0476 6072  p2pimsvc - ok
22:42:41.0495 6072  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
22:42:41.0532 6072  p2psvc - ok
22:42:41.0568 6072  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\DRIVERS\parport.sys
22:42:41.0604 6072  Parport - ok
22:42:41.0636 6072  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
22:42:41.0652 6072  partmgr - ok
22:42:41.0672 6072  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
22:42:41.0707 6072  PcaSvc - ok
22:42:41.0740 6072  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
22:42:41.0794 6072  pccsmcfd - ok
22:42:41.0837 6072  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
22:42:41.0873 6072  pci - ok
22:42:41.0885 6072  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
22:42:41.0921 6072  pciide - ok
22:42:41.0965 6072  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
22:42:42.0024 6072  pcmcia - ok
22:42:42.0049 6072  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
22:42:42.0069 6072  pcw - ok
22:42:42.0100 6072  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
22:42:42.0194 6072  PEAUTH - ok
22:42:42.0282 6072  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
22:42:42.0340 6072  PerfHost - ok
22:42:42.0418 6072  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
22:42:42.0529 6072  pla - ok
22:42:42.0601 6072  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
22:42:42.0657 6072  PlugPlay - ok
22:42:42.0677 6072  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
22:42:42.0737 6072  PNRPAutoReg - ok
22:42:42.0772 6072  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
22:42:42.0809 6072  PNRPsvc - ok
22:42:42.0848 6072  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
22:42:42.0912 6072  PolicyAgent - ok
22:42:42.0942 6072  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
22:42:43.0015 6072  Power - ok
22:42:43.0042 6072  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
22:42:43.0099 6072  PptpMiniport - ok
22:42:43.0127 6072  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\DRIVERS\processr.sys
22:42:43.0178 6072  Processor - ok
22:42:43.0237 6072  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
22:42:43.0276 6072  ProfSvc - ok
22:42:43.0308 6072  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
22:42:43.0345 6072  ProtectedStorage - ok
22:42:43.0390 6072  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
22:42:43.0447 6072  Psched - ok
22:42:43.0484 6072  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
22:42:43.0546 6072  ql2300 - ok
22:42:43.0563 6072  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
22:42:43.0599 6072  ql40xx - ok
22:42:43.0620 6072  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
22:42:43.0664 6072  QWAVE - ok
22:42:43.0678 6072  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
22:42:43.0731 6072  QWAVEdrv - ok
22:42:43.0811 6072  [ A55E7D0D873B2C97585B3B5926AC6ADE ] RapiMgr        C:\Windows\WindowsMobile\rapimgr.dll
22:42:43.0876 6072  RapiMgr - ok
22:42:43.0908 6072  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
22:42:44.0008 6072  RasAcd - ok
22:42:44.0040 6072  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
22:42:44.0103 6072  RasAgileVpn - ok
22:42:44.0147 6072  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
22:42:44.0228 6072  RasAuto - ok
22:42:44.0270 6072  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
22:42:44.0329 6072  Rasl2tp - ok
22:42:44.0369 6072  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
22:42:44.0463 6072  RasMan - ok
22:42:44.0496 6072  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
22:42:44.0571 6072  RasPppoe - ok
22:42:44.0591 6072  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
22:42:44.0660 6072  RasSstp - ok
22:42:44.0709 6072  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
22:42:44.0809 6072  rdbss - ok
22:42:44.0830 6072  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
22:42:44.0879 6072  rdpbus - ok
22:42:44.0893 6072  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
22:42:44.0951 6072  RDPCDD - ok
22:42:44.0964 6072  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
22:42:45.0041 6072  RDPENCDD - ok
22:42:45.0048 6072  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
22:42:45.0095 6072  RDPREFMP - ok
22:42:45.0131 6072  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
22:42:45.0169 6072  RDPWD - ok
22:42:45.0241 6072  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
22:42:45.0289 6072  rdyboost - ok
22:42:45.0326 6072  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
22:42:45.0401 6072  RemoteAccess - ok
22:42:45.0442 6072  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
22:42:45.0528 6072  RemoteRegistry - ok
22:42:45.0594 6072  [ 498EB62A160674E793FA40FD65390625 ] RichVideo      C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
22:42:45.0610 6072  RichVideo - ok
22:42:45.0648 6072  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
22:42:45.0725 6072  RpcEptMapper - ok
22:42:45.0762 6072  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
22:42:45.0788 6072  RpcLocator - ok
22:42:45.0832 6072  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
22:42:45.0879 6072  RpcSs - ok
22:42:45.0946 6072  [ 2ABD2B3BA2EF0C3BA82284C2A5E28675 ] RRNetCap        C:\Windows\system32\DRIVERS\rrnetcap.sys
22:42:45.0960 6072  RRNetCap - ok
22:42:45.0968 6072  [ 2ABD2B3BA2EF0C3BA82284C2A5E28675 ] RRNetCapMP      C:\Windows\system32\DRIVERS\rrnetcap.sys
22:42:45.0981 6072  RRNetCapMP - ok
22:42:46.0020 6072  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
22:42:46.0086 6072  rspndr - ok
22:42:46.0131 6072  [ B49DC435AE3695BAC5623DD94B05732D ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
22:42:46.0167 6072  RTL8167 - ok
22:42:46.0183 6072  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
22:42:46.0195 6072  SamSs - ok
22:42:46.0224 6072  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
22:42:46.0236 6072  sbp2port - ok
22:42:46.0260 6072  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
22:42:46.0325 6072  SCardSvr - ok
22:42:46.0379 6072  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
22:42:46.0412 6072  scfilter - ok
22:42:46.0470 6072  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
22:42:46.0532 6072  Schedule - ok
22:42:46.0588 6072  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
22:42:46.0620 6072  SCPolicySvc - ok
22:42:46.0657 6072  [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus          C:\Windows\system32\drivers\sdbus.sys
22:42:46.0690 6072  sdbus - ok
22:42:46.0728 6072  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
22:42:46.0753 6072  SDRSVC - ok
22:42:46.0795 6072  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
22:42:46.0844 6072  secdrv - ok
22:42:46.0885 6072  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
22:42:46.0940 6072  seclogon - ok
22:42:46.0976 6072  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\system32\sens.dll
22:42:47.0013 6072  SENS - ok
22:42:47.0048 6072  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
22:42:47.0080 6072  SensrSvc - ok
22:42:47.0114 6072  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
22:42:47.0134 6072  Serenum - ok
22:42:47.0158 6072  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
22:42:47.0196 6072  Serial - ok
22:42:47.0262 6072  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
22:42:47.0302 6072  sermouse - ok
22:42:47.0408 6072  [ F31E9531AF225CA25350D5E87E999B31 ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
22:42:47.0428 6072  ServiceLayer - ok
22:42:47.0481 6072  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
22:42:47.0526 6072  SessionEnv - ok
22:42:47.0569 6072  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
22:42:47.0611 6072  sffdisk - ok
22:42:47.0748 6072  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
22:42:47.0809 6072  sffp_mmc - ok
22:42:47.0828 6072  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
22:42:47.0855 6072  sffp_sd - ok
22:42:47.0889 6072  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
22:42:47.0916 6072  sfloppy - ok
22:42:47.0968 6072  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
22:42:48.0018 6072  SharedAccess - ok
22:42:48.0064 6072  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:42:48.0113 6072  ShellHWDetection - ok
22:42:48.0136 6072  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:42:48.0148 6072  SiSRaid2 - ok
22:42:48.0169 6072  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
22:42:48.0181 6072  SiSRaid4 - ok
22:42:48.0224 6072  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
22:42:48.0273 6072  Smb - ok
22:42:48.0369 6072  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
22:42:48.0396 6072  SNMPTRAP - ok
22:42:48.0429 6072  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
22:42:48.0440 6072  spldr - ok
22:42:48.0489 6072  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler        C:\Windows\System32\spoolsv.exe
22:42:48.0508 6072  Spooler - ok
22:42:48.0607 6072  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
22:42:48.0712 6072  sppsvc - ok
22:42:48.0753 6072  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
22:42:48.0796 6072  sppuinotify - ok
22:42:48.0832 6072  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
22:42:48.0866 6072  srv - ok
22:42:48.0888 6072  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
22:42:48.0917 6072  srv2 - ok
22:42:48.0962 6072  [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA      C:\Windows\system32\DRIVERS\VSTAZL6.SYS
22:42:48.0978 6072  SrvHsfHDA - ok
22:42:49.0010 6072  [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92      C:\Windows\system32\DRIVERS\VSTDPV6.SYS
22:42:49.0067 6072  SrvHsfV92 - ok
22:42:49.0104 6072  [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac    C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
22:42:49.0125 6072  SrvHsfWinac - ok
22:42:49.0157 6072  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
22:42:49.0182 6072  srvnet - ok
22:42:49.0213 6072  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
22:42:49.0272 6072  SSDPSRV - ok
22:42:49.0293 6072  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
22:42:49.0339 6072  SstpSvc - ok
22:42:49.0472 6072  [ 810199DCC3BDC38304D7D649992EA7BC ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
22:42:49.0512 6072  STacSV - ok
22:42:49.0599 6072  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
22:42:49.0610 6072  stexstor - ok
22:42:49.0721 6072  [ ED1722F43CE61409EF68340402D6267D ] STHDA          C:\Windows\system32\DRIVERS\stwrt64.sys
22:42:49.0751 6072  STHDA - ok
22:42:49.0808 6072  [ DECACB6921DED1A38642642685D77DAC ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
22:42:49.0838 6072  StillCam - ok
22:42:49.0900 6072  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
22:42:49.0944 6072  stisvc - ok
22:42:49.0989 6072  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
22:42:49.0999 6072  swenum - ok
22:42:50.0046 6072  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
22:42:50.0109 6072  swprv - ok
22:42:50.0174 6072  [ 929C9FA0B18AD2EBC8340591C4BF00FF ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
22:42:50.0191 6072  SynTP - ok
22:42:50.0279 6072  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
22:42:50.0357 6072  SysMain - ok
22:42:50.0394 6072  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:42:50.0421 6072  TabletInputService - ok
22:42:50.0470 6072  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
22:42:50.0561 6072  TapiSrv - ok
22:42:50.0647 6072  [ 4430E9B4C60AAB672D16E801BAD0555E ] tbhsd          C:\Windows\system32\drivers\tbhsd.sys
22:42:50.0658 6072  tbhsd - ok
22:42:50.0688 6072  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
22:42:50.0773 6072  TBS - ok
22:42:50.0849 6072  [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
22:42:50.0904 6072  Tcpip - ok
22:42:50.0941 6072  [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
22:42:50.0979 6072  TCPIP6 - ok
22:42:51.0035 6072  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
22:42:51.0117 6072  tcpipreg - ok
22:42:51.0167 6072  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
22:42:51.0198 6072  TDPIPE - ok
22:42:51.0240 6072  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
22:42:51.0266 6072  TDTCP - ok
22:42:51.0322 6072  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
22:42:51.0357 6072  tdx - ok
22:42:51.0382 6072  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
22:42:51.0400 6072  TermDD - ok
22:42:51.0446 6072  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
22:42:51.0519 6072  TermService - ok
22:42:51.0593 6072  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
22:42:51.0642 6072  Themes - ok
22:42:51.0710 6072  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
22:42:51.0753 6072  THREADORDER - ok
22:42:51.0781 6072  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
22:42:51.0837 6072  TrkWks - ok
22:42:51.0940 6072  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:42:51.0974 6072  TrustedInstaller - ok
22:42:52.0061 6072  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
22:42:52.0123 6072  tssecsrv - ok
22:42:52.0228 6072  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
22:42:52.0276 6072  TsUsbFlt - ok
22:42:52.0349 6072  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
22:42:52.0388 6072  tunnel - ok
22:42:52.0426 6072  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
22:42:52.0456 6072  uagp35 - ok
22:42:52.0520 6072  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
22:42:52.0601 6072  udfs - ok
22:42:52.0657 6072  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
22:42:52.0684 6072  UI0Detect - ok
22:42:52.0719 6072  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
22:42:52.0742 6072  uliagpkx - ok
22:42:52.0810 6072  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
22:42:52.0838 6072  umbus - ok
22:42:52.0875 6072  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
22:42:52.0921 6072  UmPass - ok
22:42:52.0973 6072  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
22:42:53.0034 6072  upnphost - ok
22:42:53.0137 6072  [ 34AFB83C7BBA370E404E52CC2290350C ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
22:42:53.0224 6072  upperdev - ok
22:42:53.0265 6072  [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
22:42:53.0328 6072  USBAAPL64 - ok
22:42:53.0380 6072  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
22:42:53.0450 6072  usbccgp - ok
22:42:53.0500 6072  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
22:42:53.0548 6072  usbcir - ok
22:42:53.0582 6072  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
22:42:53.0624 6072  usbehci - ok
22:42:53.0673 6072  [ 44D9C773FEBFF10593B50DDFC2D6BC27 ] usbfilter      C:\Windows\system32\DRIVERS\usbfilter.sys
22:42:53.0688 6072  usbfilter - ok
22:42:53.0727 6072  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
22:42:53.0760 6072  usbhub - ok
22:42:53.0830 6072  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
22:42:53.0915 6072  usbohci - ok
22:42:54.0007 6072  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
22:42:54.0082 6072  usbprint - ok
22:42:54.0114 6072  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
22:42:54.0137 6072  usbscan - ok
22:42:54.0208 6072  [ 4ACEE387FA8FD39F83564FCD2FC234F2 ] usbser          C:\Windows\system32\drivers\usbser.sys
22:42:54.0290 6072  usbser - ok
22:42:54.0355 6072  [ AA75E1EFBEE7186B4CBAAACF1F15E6CA ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
22:42:54.0417 6072  UsbserFilt - ok
22:42:54.0449 6072  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:42:54.0482 6072  USBSTOR - ok
22:42:54.0505 6072  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
22:42:54.0531 6072  usbuhci - ok
22:42:54.0600 6072  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
22:42:54.0622 6072  usbvideo - ok
22:42:54.0660 6072  [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx      C:\Windows\system32\DRIVERS\usb8023x.sys
22:42:54.0675 6072  usb_rndisx - ok
22:42:54.0699 6072  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
22:42:54.0785 6072  UxSms - ok
22:42:54.0808 6072  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
22:42:54.0819 6072  VaultSvc - ok
22:42:54.0889 6072  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
22:42:54.0905 6072  vdrvroot - ok
22:42:54.0959 6072  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
22:42:55.0004 6072  vds - ok
22:42:55.0048 6072  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
22:42:55.0066 6072  vga - ok
22:42:55.0084 6072  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
22:42:55.0140 6072  VgaSave - ok
22:42:55.0171 6072  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
22:42:55.0190 6072  vhdmp - ok
22:42:55.0220 6072  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
22:42:55.0235 6072  viaide - ok
22:42:55.0381 6072  [ 4DE25C5721B6C7B74A62DBDC7FA8B577 ] VmbService      C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
22:42:55.0481 6072  VmbService ( UnsignedFile.Multi.Generic ) - warning
22:42:55.0481 6072  VmbService - detected UnsignedFile.Multi.Generic (1)
22:42:55.0512 6072  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
22:42:55.0528 6072  volmgr - ok
22:42:55.0591 6072  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
22:42:55.0614 6072  volmgrx - ok
22:42:55.0656 6072  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
22:42:55.0677 6072  volsnap - ok
22:42:55.0713 6072  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
22:42:55.0731 6072  vsmraid - ok
22:42:55.0787 6072  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
22:42:55.0891 6072  VSS - ok
22:42:55.0918 6072  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
22:42:55.0986 6072  vwifibus - ok
22:42:55.0998 6072  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
22:42:56.0034 6072  vwififlt - ok
22:42:56.0098 6072  [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp        C:\Windows\system32\DRIVERS\vwifimp.sys
22:42:56.0116 6072  vwifimp - ok
22:42:56.0141 6072  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
22:42:56.0187 6072  W32Time - ok
22:42:56.0216 6072  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
22:42:56.0283 6072  WacomPen - ok
22:42:56.0371 6072  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
22:42:56.0437 6072  WANARP - ok
22:42:56.0458 6072  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
22:42:56.0499 6072  Wanarpv6 - ok
22:42:56.0575 6072  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc    C:\Windows\system32\Wat\WatAdminSvc.exe
22:42:56.0616 6072  WatAdminSvc - ok
22:42:56.0698 6072  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
22:42:56.0814 6072  wbengine - ok
22:42:56.0847 6072  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
22:42:56.0867 6072  WbioSrvc - ok
22:42:56.0984 6072  [ 8BDA6DB43AA54E8BB5E0794541DDC209 ] WcesComm        C:\Windows\WindowsMobile\wcescomm.dll
22:42:57.0001 6072  WcesComm - ok
22:42:57.0087 6072  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
22:42:57.0123 6072  wcncsvc - ok
22:42:57.0151 6072  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:42:57.0178 6072  WcsPlugInService - ok
22:42:57.0213 6072  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
22:42:57.0229 6072  Wd - ok
22:42:57.0280 6072  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
22:42:57.0312 6072  Wdf01000 - ok
22:42:57.0329 6072  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
22:42:57.0374 6072  WdiServiceHost - ok
22:42:57.0399 6072  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
22:42:57.0423 6072  WdiSystemHost - ok
22:42:57.0507 6072  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
22:42:57.0605 6072  WebClient - ok
22:42:57.0681 6072  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
22:42:57.0799 6072  Wecsvc - ok
22:42:57.0831 6072  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
22:42:57.0917 6072  wercplsupport - ok
22:42:57.0973 6072  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
22:42:58.0037 6072  WerSvc - ok
22:42:58.0063 6072  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
22:42:58.0105 6072  WfpLwf - ok
22:42:58.0126 6072  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
22:42:58.0142 6072  WIMMount - ok
22:42:58.0159 6072  WinDefend - ok
22:42:58.0171 6072  WinHttpAutoProxySvc - ok
22:42:58.0225 6072  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
22:42:58.0278 6072  Winmgmt - ok
22:42:58.0350 6072  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
22:42:58.0429 6072  WinRM - ok
22:42:58.0471 6072  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
22:42:58.0505 6072  WinUsb - ok
22:42:58.0576 6072  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
22:42:58.0614 6072  Wlansvc - ok
22:42:58.0629 6072  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
22:42:58.0640 6072  WmiAcpi - ok
22:42:58.0677 6072  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
22:42:58.0701 6072  wmiApSrv - ok
22:42:58.0723 6072  WMPNetworkSvc - ok
22:42:58.0826 6072  [ 83B6CA03C846FCD47F9883D77D1EB27B ] WMZuneComm      C:\Program Files\Zune\WMZuneComm.exe
22:42:58.0851 6072  WMZuneComm - ok
22:42:58.0903 6072  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
22:42:58.0924 6072  WPCSvc - ok
22:42:58.0967 6072  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
22:42:58.0992 6072  WPDBusEnum - ok
22:42:59.0021 6072  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
22:42:59.0059 6072  ws2ifsl - ok
22:42:59.0093 6072  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\system32\wscsvc.dll
22:42:59.0136 6072  wscsvc - ok
22:42:59.0144 6072  WSearch - ok
22:42:59.0220 6072  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
22:42:59.0291 6072  wuauserv - ok
22:42:59.0310 6072  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
22:42:59.0367 6072  WudfPf - ok
22:42:59.0421 6072  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
22:42:59.0464 6072  WUDFRd - ok
22:42:59.0504 6072  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
22:42:59.0582 6072  wudfsvc - ok
22:42:59.0621 6072  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc        C:\Windows\System32\wwansvc.dll
22:42:59.0651 6072  WwanSvc - ok
22:42:59.0720 6072  [ B3EEACF62445E24FBB2CD4B0FB4DB026 ] yukonw7        C:\Windows\system32\DRIVERS\yk62x64.sys
22:42:59.0760 6072  yukonw7 - ok
22:42:59.0953 6072  [ 67B787C34FB2888D01B130AE007042D8 ] ZuneNetworkSvc  C:\Program Files\Zune\ZuneNss.exe
22:43:00.0296 6072  ZuneNetworkSvc - ok
22:43:00.0338 6072  [ 4D89FC1C20CF655739EFAC5DA81A67BC ] ZuneWlanCfgSvc  C:\Program Files\Zune\ZuneWlanCfgSvc.exe
22:43:00.0366 6072  ZuneWlanCfgSvc - ok
22:43:00.0468 6072  [ 74983ADDCA2D9618512C088D856D6615 ] {55662437-DA8C-40c0-AADA-2C816A897A49} c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
22:43:00.0489 6072  {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
22:43:00.0517 6072  ================ Scan global ===============================
22:43:00.0538 6072  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
22:43:00.0595 6072  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
22:43:00.0607 6072  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
22:43:00.0634 6072  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
22:43:00.0649 6072  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
22:43:00.0652 6072  [Global] - ok
22:43:00.0653 6072  ================ Scan MBR ==================================
22:43:00.0666 6072  [ 8984F18DD8E146A77981E1351781B768 ] \Device\Harddisk0\DR0
22:43:00.0942 6072  \Device\Harddisk0\DR0 - ok
22:43:00.0953 6072  [ E5FA06ACA0D60BA9C870D0EF3D9898C9 ] \Device\Harddisk1\DR1
22:43:03.0664 6072  \Device\Harddisk1\DR1 - ok
22:43:03.0667 6072  ================ Scan VBR ==================================
22:43:03.0682 6072  [ 9696C4DEAD668E741B8F42BF45FD656B ] \Device\Harddisk0\DR0\Partition1
22:43:03.0684 6072  \Device\Harddisk0\DR0\Partition1 - ok
22:43:03.0691 6072  [ 485EC08F06B6601A12027367D5447F87 ] \Device\Harddisk0\DR0\Partition2
22:43:03.0693 6072  \Device\Harddisk0\DR0\Partition2 - ok
22:43:03.0728 6072  [ 55700F10103953DB5313D698F97B0EB8 ] \Device\Harddisk0\DR0\Partition3
22:43:03.0729 6072  \Device\Harddisk0\DR0\Partition3 - ok
22:43:03.0748 6072  [ D49B93372EDF509F8BC21587296DD922 ] \Device\Harddisk0\DR0\Partition4
22:43:03.0749 6072  \Device\Harddisk0\DR0\Partition4 - ok
22:43:03.0757 6072  [ D334B0A88E1AFE44EEA7499E01B19BE2 ] \Device\Harddisk1\DR1\Partition1
22:43:03.0758 6072  \Device\Harddisk1\DR1\Partition1 - ok
22:43:03.0763 6072  ============================================================
22:43:03.0763 6072  Scan finished
22:43:03.0763 6072  ============================================================
22:43:03.0778 6064  Detected object count: 3
22:43:03.0778 6064  Actual detected object count: 3
22:43:18.0864 6064  BrYNSvc ( UnsignedFile.Multi.Generic ) - skipped by user
22:43:18.0864 6064  BrYNSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:43:18.0867 6064  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
22:43:18.0867 6064  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:43:18.0869 6064  VmbService ( UnsignedFile.Multi.Generic ) - skipped by user
22:43:18.0870 6064  VmbService ( UnsignedFile.Multi.Generic ) - User select action: Skip

Schöne Grüße
Rainer

Als ich den Rechner nach dem TDSSKiller heruntergefahren habe, hat er 6 Updates installiert.
Ich hoffe das war kein Problem.

Schöne Grüße
Rainer

cosinus 19.09.2012 14:15

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Rai3 19.09.2012 15:20

Hallo cosinus,

combofix ist durch, hier das Log (Teil1/3):
Code:

ComboFix 12-09-18.07 - Rainer 19.09.2012  15:25:52.2.2 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4092.2543 [GMT 2:00]
ausgeführt von:: c:\users\Rainer\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Rainer\BT747log.bin
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-19 bis 2012-09-19  ))))))))))))))))))))))))))))))
.
.
2012-09-19 13:40 . 2012-09-19 13:40        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-09-19 13:40 . 2012-09-19 13:40        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-16 20:45 . 2012-08-22 18:12        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-09-16 20:45 . 2012-07-04 20:26        41472        ----a-w-        c:\windows\system32\drivers\rndismpx.sys
2012-09-16 20:45 . 2012-07-04 20:26        41472        ----a-w-        c:\windows\system32\drivers\RNDISMP.sys
2012-09-16 20:45 . 2012-08-02 17:58        574464        ----a-w-        c:\windows\system32\d3d10level9.dll
2012-09-16 20:45 . 2012-08-02 16:57        490496        ----a-w-        c:\windows\SysWow64\d3d10level9.dll
2012-09-16 20:45 . 2012-08-22 18:12        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-09-16 20:45 . 2012-08-22 18:12        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-09-16 20:45 . 2012-08-22 18:12        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-15 17:10 . 2012-09-15 17:10        --------        d-----w-        C:\_OTL
2012-09-12 14:30 . 2012-09-12 14:30        --------        d-----w-        c:\program files (x86)\ESET
2012-09-11 14:20 . 2012-09-11 14:20        --------        d-----w-        c:\users\Rainer\AppData\Roaming\Malwarebytes
2012-09-11 14:19 . 2012-09-11 14:19        --------        d-----w-        c:\programdata\Malwarebytes
2012-09-11 14:19 . 2012-09-11 14:19        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-11 14:19 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-11 08:37 . 2012-08-23 08:26        9310152        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{670AF659-184C-4DF5-AEDA-A1B06BEE7ECB}\mpengine.dll
2012-08-23 20:14 . 2012-08-23 20:14        --------        d-----w-        c:\users\Public\CyberLink
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-16 20:50 . 2011-11-29 09:41        64462936        ----a-w-        c:\windows\system32\MRT.exe
2012-08-27 04:20 . 2012-05-03 07:06        696520        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-27 04:20 . 2011-12-01 09:55        73416        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-06 15:26 . 2011-12-01 12:42        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2012-08-06 15:25 . 2011-12-01 12:42        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2012-08-06 15:25 . 2011-12-06 08:25        1236816        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-08-03 19:35 . 2011-12-06 08:25        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-08-03 19:34 . 2011-12-06 08:25        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2012-08-03 19:34 . 2011-12-01 12:42        1236816        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-07-18 18:15 . 2012-08-15 08:42        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-07-04 22:16 . 2012-08-15 08:42        73216        ----a-w-        c:\windows\system32\netapi32.dll
2012-07-04 22:13 . 2012-08-15 08:42        59392        ----a-w-        c:\windows\system32\browcli.dll
2012-07-04 22:13 . 2012-08-15 08:42        136704        ----a-w-        c:\windows\system32\browser.dll
2012-07-04 21:14 . 2012-08-15 08:42        41984        ----a-w-        c:\windows\SysWow64\browcli.dll
2012-06-27 07:06 . 2012-08-15 08:42        1188864        ----a-w-        c:\windows\system32\wininet.dll
2012-06-27 07:06 . 2012-08-15 08:42        1494016        ----a-w-        c:\windows\system32\urlmon.dll
2012-06-27 07:06 . 2012-08-15 08:42        134144        ----a-w-        c:\windows\system32\url.dll
2012-06-27 07:03 . 2012-08-15 08:42        9059840        ----a-w-        c:\windows\system32\mshtml.dll
2012-06-27 07:03 . 2012-08-15 08:42        97792        ----a-w-        c:\windows\system32\mshtmled.dll
2012-06-27 07:03 . 2012-08-15 08:42        735744        ----a-w-        c:\windows\system32\msfeeds.dll
2012-06-27 07:02 . 2012-08-15 08:42        64512        ----a-w-        c:\windows\system32\jsproxy.dll
2012-06-27 07:02 . 2012-08-15 08:42        247808        ----a-w-        c:\windows\system32\ieui.dll
2012-06-27 07:02 . 2012-08-15 08:42        2453504        ----a-w-        c:\windows\system32\iertutil.dll
2012-06-27 07:02 . 2012-08-15 08:42        12297216        ----a-w-        c:\windows\system32\ieframe.dll
2012-06-27 05:53 . 2012-08-15 08:42        981504        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-06-27 04:53 . 2012-08-15 08:42        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2012-06-27 04:10 . 2012-08-15 08:42        1638912        ----a-w-        c:\windows\SysWow64\mshtml.tlb
.
.
(((((((((((((((((((((((((((((  SnapShot@2012-03-21_13.03.29  )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-05-31 07:20 . 2007-05-31 07:20        31624              c:\windows\WindowsMobile\wmdsyncproxy32.dll
+ 2007-05-31 08:11 . 2007-05-31 08:11        60296              c:\windows\WindowsMobile\wmdsyncproxy.dll
+ 2007-05-31 08:11 . 2007-05-31 08:11        66440              c:\windows\WindowsMobile\wmdsyncman.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        50568              c:\windows\WindowsMobile\WmdHost.exe
+ 2007-05-31 07:20 . 2007-05-31 07:20        20872              c:\windows\WindowsMobile\VoiceFrm.exe
+ 2007-05-31 07:20 . 2007-05-31 07:20        38792              c:\windows\WindowsMobile\VoiceBar.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        70536              c:\windows\WindowsMobile\VCOMCtl.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        29576              c:\windows\WindowsMobile\updatewmc.exe
+ 2007-05-31 15:10 . 2007-05-31 15:10        28040              c:\windows\WindowsMobile\tcp2udp.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        41352              c:\windows\WindowsMobile\SyncStat.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        12288              c:\windows\WindowsMobile\ru\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        36232              c:\windows\WindowsMobile\riresdll.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        10240              c:\windows\WindowsMobile\pl\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        18824              c:\windows\WindowsMobile\olregdll.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        10240              c:\windows\WindowsMobile\ja\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:10 . 2007-05-31 08:10        27016              c:\windows\WindowsMobile\IrmActivate.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        32648              c:\windows\WindowsMobile\InstallForm.exe
+ 2007-05-31 08:11 . 2007-05-31 08:11        38792              c:\windows\WindowsMobile\inplace.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        32136              c:\windows\WindowsMobile\Inkx.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        36232              c:\windows\WindowsMobile\inkres.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        60296              c:\windows\WindowsMobile\InkProps.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        20872              c:\windows\WindowsMobile\InkForm.exe
+ 2007-05-31 07:21 . 2007-05-31 07:21        95112              c:\windows\WindowsMobile\HttpSys.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        10240              c:\windows\WindowsMobile\fr\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        59784              c:\windows\WindowsMobile\Formdll.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        12800              c:\windows\WindowsMobile\el\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 15:10 . 2007-05-31 15:10        21896              c:\windows\WindowsMobile\dtptdns.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        10240              c:\windows\WindowsMobile\de\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        44936              c:\windows\WindowsMobile\CEFStore.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        36232              c:\windows\WindowsMobile\BthASPlugin.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        46472              c:\windows\WindowsMobile\ASSvrEng.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        32648              c:\windows\WindowsMobile\ASStatusL.dll
+ 2007-05-31 07:20 . 2007-05-31 07:20        47496              c:\windows\WindowsMobile\ASDsktpEng.dll
+ 2007-05-31 14:20 . 2007-05-31 14:20        24968              c:\windows\SysWOW64\wcescommproxy.dll
- 2012-01-16 05:24 . 2011-11-17 05:28        96768              c:\windows\SysWOW64\sspicli.dll
+ 2012-07-11 05:44 . 2012-06-02 04:34        96768              c:\windows\SysWOW64\sspicli.dll
- 2009-07-13 23:23 . 2009-07-14 01:16        43008              c:\windows\SysWOW64\srclient.dll
+ 2012-08-15 08:43 . 2012-05-05 07:46        43008              c:\windows\SysWOW64\srclient.dll
- 2012-01-16 05:24 . 2011-11-17 05:34        22016              c:\windows\SysWOW64\secur32.dll
+ 2012-07-11 05:44 . 2012-06-02 04:40        22016              c:\windows\SysWOW64\secur32.dll
+ 2007-05-31 14:20 . 2007-05-31 14:20        24456              c:\windows\SysWOW64\rapiproxystub.dll
+ 2012-08-15 08:42 . 2012-07-04 21:16        57344              c:\windows\SysWOW64\netapi32.dll
+ 2012-08-15 08:42 . 2012-06-27 05:51        67584              c:\windows\SysWOW64\mshtmled.dll
- 2012-02-15 13:03 . 2011-12-16 07:54        68608              c:\windows\SysWOW64\migration\WininetPlugin.dll
+ 2012-08-15 08:42 . 2012-06-27 05:53        68608              c:\windows\SysWOW64\migration\WininetPlugin.dll
+ 2012-08-15 08:42 . 2012-06-27 05:50        48128              c:\windows\SysWOW64\jsproxy.dll
- 2012-02-15 13:03 . 2011-12-16 07:52        48128              c:\windows\SysWOW64\jsproxy.dll
+ 2009-07-14 04:54 . 2012-09-18 19:40        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-03-20 20:02        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-03-20 20:02        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-09-16 20:51 . 2012-09-18 19:40        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-09-18 19:40        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-20 20:02        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-05-31 14:21 . 2007-05-31 14:21        75144              c:\windows\SysWOW64\ceutil.dll
+ 2012-06-22 06:18 . 2012-06-02 22:19        44056              c:\windows\system32\wups2.dll
+ 2012-06-22 06:18 . 2012-06-02 22:19        38424              c:\windows\system32\wups.dll
+ 2012-06-22 06:18 . 2012-06-02 22:15        99840              c:\windows\system32\wudriver.dll
+ 2012-06-22 06:18 . 2012-06-02 22:19        57880              c:\windows\system32\wuauclt.exe
- 2011-12-01 08:38 . 2010-11-20 13:25        36864              c:\windows\system32\wuapp.exe
+ 2012-06-22 06:18 . 2012-06-02 13:15        36864              c:\windows\system32\wuapp.exe
+ 2007-05-31 15:11 . 2007-05-31 15:11        53128              c:\windows\system32\wmcoinst-070531-0952.dll
+ 2009-11-13 14:52 . 2012-09-19 06:01        54592              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-09-19 06:01        60876              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-28 20:05 . 2012-09-19 06:01        14710              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1154562761-1198328465-1791081454-1000_UserData.bin
+ 2007-05-31 15:11 . 2007-05-31 15:11        40840              c:\windows\system32\wcescommproxy.dll
- 2012-03-14 07:30 . 2012-01-25 06:38        77312              c:\windows\system32\rdpwsx.dll
+ 2012-06-14 03:32 . 2012-04-26 05:41        77312              c:\windows\system32\rdpwsx.dll
+ 2007-05-31 15:10 . 2007-05-31 15:10        34696              c:\windows\system32\rapiproxystub.dll
+ 2012-08-15 08:42 . 2012-06-27 07:06        95232              c:\windows\system32\migration\WininetPlugin.dll
- 2012-02-15 13:03 . 2011-12-16 08:47        95232              c:\windows\system32\migration\WininetPlugin.dll
+ 2012-04-13 15:20 . 2012-03-01 06:33        81408              c:\windows\system32\imagehlp.dll
+ 2009-07-14 05:30 . 2012-09-18 06:00        86016              c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2012-03-12 07:02        86016              c:\windows\system32\DriverStore\infpub.dat
+ 2011-07-22 14:47 . 2011-07-22 14:47        67072              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneTcp2Udp.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        60928              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneRegUtil.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        45568              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZunePTDNS.dll
+ 2007-05-31 14:20 . 2007-05-31 14:20        24968              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wow64-wcescpxy.dll
+ 2007-05-31 14:20 . 2007-05-31 14:20        24456              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wow64-rapispxy.dll
+ 2007-05-31 14:21 . 2007-05-31 14:21        75144              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wow64-ceutil.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        53128              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wmcoinst-070531-0952.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        40840              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wcescpxy.dll
+ 2007-05-31 15:10 . 2007-05-31 15:10        28040              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\tcp2udp.dll
+ 2007-05-31 15:10 . 2007-05-31 15:10        34696              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\rapispxy.dll
+ 2007-05-31 15:10 . 2007-05-31 15:10        21896              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\dtptdns.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        74120              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\ceutil.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        36232              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\btplugin.dll
+ 2012-02-15 10:01 . 2012-02-15 10:01        52736              c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_509d7a31d0ee45f2\usbaapl64.sys
+ 2009-07-14 00:09 . 2009-07-14 00:09        19968              c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\usb8023x.sys
+ 2009-07-14 00:09 . 2009-07-14 00:09        19968              c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\usb80236.sys
+ 2012-09-16 20:45 . 2012-07-04 20:26        41472              c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\rndismpx.sys
+ 2012-09-16 20:45 . 2012-07-04 20:26        35840              c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\rndismp6.sys
+ 2011-08-02 16:38 . 2011-08-02 16:38        22528              c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_bf785db627c6d127\netaapl64.sys
+ 2012-04-18 08:05 . 2012-04-18 08:05        19304              c:\windows\system32\DriverStore\FileRepository\grmnusb.inf_amd64_neutral_d77b1dda68556870\Amd64\grmnusb.sys
+ 2012-04-18 08:05 . 2012-04-18 08:05        30568              c:\windows\system32\DriverStore\FileRepository\grmnusb.inf_amd64_neutral_d77b1dda68556870\Amd64\grmngen.sys
+ 2011-11-29 13:16 . 2011-04-28 03:54        80384              c:\windows\system32\DriverStore\FileRepository\bth.inf_amd64_neutral_de0494b6391d872c\BTHUSB.SYS
+ 2009-07-14 00:06 . 2009-07-14 00:06        41984              c:\windows\system32\DriverStore\FileRepository\bth.inf_amd64_neutral_de0494b6391d872c\bthenum.sys
+ 2010-04-29 04:55 . 2010-04-29 04:55        32768              c:\windows\system32\DriverStore\FileRepository\android_usb.inf_amd64_neutral_05094f7e231a9498\androidusb.sys
+ 2009-07-14 00:09 . 2009-07-14 00:09        19968              c:\windows\system32\drivers\usb8023x.sys
+ 2012-05-12 06:48 . 2012-03-17 07:58        75120              c:\windows\system32\drivers\partmgr.sys
- 2012-01-16 05:24 . 2011-11-17 06:49        95600              c:\windows\system32\drivers\ksecdd.sys
+ 2012-07-11 05:44 . 2012-06-02 05:48        95600              c:\windows\system32\drivers\ksecdd.sys
+ 2009-05-08 10:08 . 2009-05-08 10:08        20520              c:\windows\system32\drivers\grmnusb.sys
+ 2009-05-12 14:28 . 2009-05-12 14:28        31784              c:\windows\system32\drivers\grmngen.sys
+ 2012-04-13 15:20 . 2012-03-01 06:46        23408              c:\windows\system32\drivers\fs_rec.sys
+ 2011-11-28 21:44 . 2012-05-08 11:39        98848              c:\windows\system32\drivers\avgntflt.sys
+ 2010-04-29 04:55 . 2010-04-29 04:55        32768              c:\windows\system32\drivers\androidusb.sys
+ 2010-01-24 00:18 . 2012-09-19 06:03        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-24 00:18 . 2012-03-20 23:22        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-09-16 20:41 . 2012-09-19 06:03        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-24 00:18 . 2012-03-20 23:22        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-09-19 06:03        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-20 23:22        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-05-31 15:11 . 2007-05-31 15:11        74120              c:\windows\system32\ceutil.dll
+ 2012-08-15 08:43 . 2012-02-11 06:36        67072              c:\windows\splwow64.exe
- 2011-12-01 08:40 . 2010-11-20 13:25        67072              c:\windows\splwow64.exe
- 2011-11-28 20:12 . 2012-03-21 11:26        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-28 20:12 . 2012-09-19 06:02        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:46 . 2012-03-15 08:02        91720              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-07-14 04:46 . 2012-09-18 19:35        91720              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2012-01-09 07:11 . 2012-01-26 07:39        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-09 07:11 . 2012-07-30 06:25        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-09 07:11 . 2012-07-30 06:25        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
- 2012-01-09 07:11 . 2012-01-26 07:39        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2012-01-09 07:11 . 2012-07-30 06:25        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2012-01-09 07:11 . 2012-01-26 07:39        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2011-11-28 20:12 . 2012-03-21 11:26        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-11-28 20:12 . 2012-09-19 06:02        32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-11-28 20:12 . 2012-09-19 06:02        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-28 20:12 . 2012-03-21 11:26        16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-28 19:52 . 2012-09-19 13:03        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-28 19:52 . 2012-03-21 12:02        16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-28 19:52 . 2012-03-21 12:02        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-28 19:52 . 2012-09-19 13:03        16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-15 12:01 . 2011-12-15 12:01        68880              c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
- 2011-11-21 22:57 . 2011-11-21 22:57        68880              c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        57616              c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        57616              c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        87408              c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        87408              c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        93024              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        93024              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        35688              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        35688              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        11120              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        11120              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        17784              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        17784              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        58240              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        58240              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        44920              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        44920              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        37240              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        37240              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        64352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        64352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        51032              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        51032              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        50552              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        50552              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        81784              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        81784              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        81800              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        81800              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        39784              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        39784              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        68952              c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        68952              c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        12128              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        12128              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        97680              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        97680              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        17240              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        17240              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        94552              c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        94552              c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        91488              c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        91488              c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2012-03-13 14:48 . 2012-03-13 14:48        78168              c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        78168              c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-03-13 14:48 . 2012-03-13 14:48        81248              c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        81248              c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-04-11 02:55 . 2012-04-11 02:55        41472              c:\windows\Installer\4bc6f.msi
- 2011-12-14 17:04 . 2011-12-14 17:04        49936              c:\windows\Installer\{95120000-00AF-0407-0000-0000000FF1CE}\ppvwicon.exe
+ 2012-08-15 20:05 . 2012-08-15 20:05        49936              c:\windows\Installer\{95120000-00AF-0407-0000-0000000FF1CE}\ppvwicon.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        34144              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        34144              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        43608              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\msouc.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        19296              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        19296              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2011-12-14 17:04 . 2011-12-14 17:04        35600              c:\windows\Installer\{90120000-0020-0407-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2012-08-15 20:05 . 2012-08-15 20:05        35600              c:\windows\Installer\{90120000-0020-0407-0000-0000000FF1CE}\O12ConvIcon.exe
- 2009-11-13 15:25 . 2011-11-29 17:01        25214              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\MSWorks.exe
+ 2009-11-13 15:25 . 2012-04-13 15:29        25214              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\MSWorks.exe
+ 2011-02-04 12:40 . 2011-02-04 12:40        49488              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\VBAJET32.DLL
+ 2010-10-20 15:32 . 2010-10-20 15:32        32160              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\SOCIALPROVIDER.DLL
+ 2011-01-12 17:59 . 2011-01-12 17:59        43352              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OUTLRPC.DLL
+ 2010-10-22 14:05 . 2010-10-22 14:05        28000              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OUTLACCT.DLL
+ 2010-12-20 23:48 . 2010-12-20 23:48        44992              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACERCLR.DLL
+ 2012-05-13 01:21 . 2012-05-13 01:21        10240              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\7fa267d10b2df6dbd00d00d130715f0a\System.Xml.Serialization.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        43520              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\054fce9466c6cef615b2f7cc9ff4e7f8\System.Windows.Presentation.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        86016              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\ff78ec1b5bf38a8fb74c2d4f41bb308a\System.Web.ApplicationServices.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        97792              c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\e144d0028365c62178eb0662911ac910\System.AddIn.Contract.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        14336              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\93295f3771dc9e5be2d49d5f5d76a7a6\Microsoft.VisualC.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        55808              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\ae1aa0da6c3f69ae100effa75c1e2316\Microsoft.Office.Tools.v4.0.Framework.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        28160              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\3f51f3b0ffc904203234c8b32f98c31f\Microsoft.Office.Tools.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        10752              c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\5ea625ce2d6c08687f70cb81a003a28b\dfsvc.ni.exe
+ 2012-05-13 01:13 . 2012-05-13 01:13        58368              c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\061cbee19075e086d675a9e1f65725d7\Accessibility.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        96768              c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\05787d96761cf20b76b927ace10ef1d3\UIAutomationProvider.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        35328              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\f3a9c6e87bfa4bab3689ec1cdb56964f\System.Windows.Presentation.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        71680              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\9b418f37f4594806e1f4b0ed6d083a95\System.Web.ApplicationServices.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        82432              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d09c237ee72af3935f1a01388ef8e315\System.ServiceModel.Channels.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        78848              c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\59be5fb54e018032511415f0b0523ee3\System.AddIn.Contract.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        11776              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\46f273930666397a8cb538ffe9190eef\Microsoft.VisualC.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        21504              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\d1863e1b75c767daef24a3b149faddac\Microsoft.Office.Tools.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        45056              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\31173593560b0b4db1a7b6025dabc5e5\Microsoft.Office.Tools.v4.0.Framework.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        44544              c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\62c1a496dff99a6e5f5e4278d31ca4c1\Accessibility.ni.dll
+ 2012-07-25 13:49 . 2012-07-25 13:49        73728              c:\windows\assembly\NativeImages_v2.0.50727_64\UIXControls\06a00b053b8b2b76e787c73c289e71ec\UIXControls.ni.dll
+ 2012-05-13 01:55 . 2012-05-13 01:55        60416              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\fb4bc14964a1d415bdbe55b62ce73a52\System.Windows.Presentation.ni.dll
+ 2012-06-15 10:03 . 2012-06-15 10:03        54784              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\eef76dd965ea0a8ae5fb0c734d84389c\System.Web.DynamicData.Design.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        90624              c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\ee709a01b51c82626f4b2c1173f2db28\stdole.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        72192              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\78f495970511b726a0ca7b8119360e25\PresentationFontCache.ni.exe
+ 2012-05-13 01:39 . 2012-05-13 01:39        61952              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\1a359e9b908a2565c546a8ca04b241c2\PresentationCFFRasterizer.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        33792              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\9d57c4bbbc0b3243046fc7839da71b00\Microsoft.WSMan.Runtime.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        43520              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\d6578432220dbabf2b15027681327bf8\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        40448              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\66deb65a87750efddf62d1e0c0655352\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        36864              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\4b6402dc918e41b8de8c501f29833d91\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        45056              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\28545d2b6a0aaef4aa168f9808603bc5\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        70144              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\1d8a17a2c1416a8ad4d6ad2a28b4c5fd\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        59904              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\0abc7256549c204f39af7dcc52c9e5d5\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        45056              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d84c14e69b88aeac74de3f6805b900e7\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        71680              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\abd9d2880ca61bf077d60419f5ec1114\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        59904              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\90084df18546aa62b4341a272ea71d30\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        93696              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\75909fbd25e848d0425e03df4c06a00b\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        43520              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7003996ae5bd140e50c6a12a7c419910\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        86016              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\397ef046a0d464801359654f6df589be\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        59904              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\317ca97e8f47080ea7950654db36ece0\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        84992              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\2d07593d9552f036c38c9b15b6355390\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        87040              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\07f7dae1df42a6bce3126ce63ea0564e\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:37 . 2012-05-13 01:37        32256              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\3c3a6cce983114e7406e0a6e6116ecd8\Microsoft.VisualC.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        65536              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6ab0575bf49b60fd4b697d47e1754072\Microsoft.MediaCenter.iTv.Hosting.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        40960              c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\1569a004b1f41193818e3b3777f2c73d\LoadMxf.ni.exe
+ 2012-05-13 01:50 . 2012-05-13 01:50        49664              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\3ee98e8b2084e27d65953bbd7e362bf8\ehiUPnP.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        93184              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\1cd9f92749d29b9fd61fcb1c4ae84294\ehiTVMSMusic.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        28672              c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0811f67973c32efb2bfad62a4a2592b5\dfsvc.ni.exe
+ 2012-05-13 01:38 . 2012-05-13 01:38        78848              c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\ae9311dcb0e713330a2a86b04cf361dc\Accessibility.ni.dll
+ 2012-06-15 07:17 . 2012-06-15 07:17        47616              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\b2854071ec4656c370d884ca390e462f\WindowsLiveWriter.ni.exe
+ 2012-06-15 07:18 . 2012-06-15 07:18        99840              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e64203688b7bb9596f2c9be84884e87f\WindowsLive.Writer.Api.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\66d750f3f8dde0cc865f921497ab3545\System.Windows.Presentation.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\2b97ccae44726f13c418f1406180c3e8\System.Web.DynamicData.Design.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\543b0e12423bcec010bdd2ac27c5dc04\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        82944              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f34410ab8e82063735d876533db26c49\System.AddIn.Contract.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        44032              c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\d246780b91fd9f6393e85fb13bde94a6\stdole.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\d24744f15243e28ea541a459ff7ff5d5\PresentationFontCache.ni.exe
+ 2012-05-13 01:42 . 2012-05-13 01:42        39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5a9d0ff936810991cedd098fe006a9be\PresentationCFFRasterizer.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        79872              c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\87a30ba337ed55d0905f19742e2985bc\napcrypt.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        17920              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\9f2e8e0df9ff39ad21088f1d66cfadb1\Microsoft.WSMan.Runtime.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        23040              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\d797123d55bb7b823120d0a7ffbbc2a7\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        32256              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb8ad29814d9e5589bd400d38e7a0b10\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        21504              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb42a0f25b7608b2675080081b03f6e5\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        25088              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\c6e9143be5afb36345875d56b61c444f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        19968              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\91767cf3facefe10e00734c815e925ad\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        27136              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\66cd99d2f576cde047074e98bd5e1848\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        86528              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\4308e1bdc640e1c3f1ea966e84e48900\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\06fcf2fbbe38d9425fc49d935498ec93\Microsoft.Vsa.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        51712              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\be59506a77d76e325dbb02a4ef651eff\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        66560              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a516cad7285e7506dc477e03c7468aac\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        35328              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a3d7d37ccd26595b9858116ac8e78e42\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        58368              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a306bdd890d9250b9cb4c03876f3b146\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        60928              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9e572d1a5f468ae4226d9c74a54dbf5a\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        86016              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\51a968dddeccf2f51b63a8b847e0ec9a\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        43008              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4d661ba2b6ac1a23427070f799fd540c\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        28160              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\443eceb48c4c76162ef874395f612590\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        42496              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\11852ce9e3c8a47a9f194e2671a2597f\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        28160              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\03f7e17a9422755c383ec2100e178a32\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        15872              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\55c57057dc81a5e8c5bde3a230f0bcb9\Microsoft.VisualC.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        19968              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\b340ffecf18f545373cc05827462d6cb\Microsoft.Office.InfoPath.Permission.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e3ef400b1f37e4d3b79a42a8a602ea02\Microsoft.Build.Framework.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        65024              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2095344bf8c40f8baa94ba53a993fb4c\Microsoft.Build.Framework.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        37888              c:\windows\assembly\NativeImages_v2.0.50727_32\ipdmctrl\1746deeb1c6c9609c1c59c852bf0bcbb\ipdmctrl.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        60416              c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\dc93539af5a961641a26ada75f730136\ehiUserXp.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        14336              c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\53d03b0e238c77cf7e5ac88e02aecd2c\dfsvc.ni.exe
+ 2012-05-13 01:42 . 2012-05-13 01:42        25600              c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
- 2009-11-13 23:28 . 2009-11-13 23:28        24576              c:\windows\assembly\GAC_MSIL\System.Drawing.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-04-12 17:40 . 2010-11-13 00:08        24576              c:\windows\assembly\GAC_MSIL\System.Drawing.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9216              c:\windows\WindowsMobile\zh-CHT\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9216              c:\windows\WindowsMobile\zh-CHS\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\tr\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\sv\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\sk\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\ro\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\pt\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\pt-BR\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9216              c:\windows\WindowsMobile\no\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\nl\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\ko\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\it\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\hu\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\fi\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\es\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 07:58 . 2007-05-31 07:58        9728              c:\windows\WindowsMobile\en\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\da\Microsoft.WindowsMobile.DeviceManager.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        9728              c:\windows\WindowsMobile\cs\Microsoft.WindowsMobile.DeviceManager.resources.dll
- 2009-07-14 00:19 . 2009-07-14 01:11        5120              c:\windows\SysWOW64\wmi.dll
+ 2012-04-13 15:20 . 2012-03-01 05:29        5120              c:\windows\SysWOW64\wmi.dll
- 2009-07-14 00:19 . 2009-07-14 01:07        2048              c:\windows\SysWOW64\msxml3r.dll
+ 2012-07-11 05:45 . 2010-06-26 03:24        2048              c:\windows\SysWOW64\msxml3r.dll
- 2009-07-14 00:41 . 2009-07-14 01:33        5120              c:\windows\system32\wmi.dll
+ 2012-04-13 15:20 . 2012-03-01 06:28        5120              c:\windows\system32\wmi.dll
+ 2011-12-05 05:47 . 2012-09-10 15:00        6668              c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-06-14 03:32 . 2012-04-26 05:34        9216              c:\windows\system32\rdrmemptylst.exe
- 2012-03-14 07:30 . 2012-01-25 06:33        9216              c:\windows\system32\rdrmemptylst.exe
- 2009-07-14 00:41 . 2009-07-14 01:30        2048              c:\windows\system32\msxml3r.dll
+ 2012-07-11 05:45 . 2010-06-26 03:55        2048              c:\windows\system32\msxml3r.dll
- 2012-03-21 11:23 . 2012-03-21 11:23        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-09-19 05:59 . 2012-09-19 05:59        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-03-21 11:23 . 2012-03-21 11:23        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-09-19 05:59 . 2012-09-19 05:59        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-05-13 01:25 . 2012-05-13 01:25        9216              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\4b540b784465ca3f0742990e5af444e3\System.Xml.Serialization.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        9728              c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\fd866b4158c3bd2a26c875f2896c5573\dfsvc.ni.exe
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\zh-CHT\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        344064              c:\windows\WindowsMobile\zh-CHS\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        660360              c:\windows\WindowsMobile\wmdcBase.exe
+ 2007-05-31 08:11 . 2007-05-31 08:11        660360              c:\windows\WindowsMobile\wmdc.exe
+ 2007-05-31 15:11 . 2007-05-31 15:11        443784              c:\windows\WindowsMobile\wcescomm.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\tr\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        344064              c:\windows\WindowsMobile\sv\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        352256              c:\windows\WindowsMobile\sk\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        127368              c:\windows\WindowsMobile\setup.exe
+ 2007-05-31 08:08 . 2007-05-31 08:08        368640              c:\windows\WindowsMobile\ru\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        356352              c:\windows\WindowsMobile\ro\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        206728              c:\windows\WindowsMobile\richink.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        225672              c:\windows\WindowsMobile\rapimgr.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\pt\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\pt-BR\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        356352              c:\windows\WindowsMobile\pl\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        270728              c:\windows\WindowsMobile\outstore.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\no\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        360448              c:\windows\WindowsMobile\nl\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:11 . 2007-05-31 08:11        128392              c:\windows\WindowsMobile\Microsoft.WindowsMobile.Rapi.dll
+ 2007-05-31 08:11 . 2007-05-31 08:11        382344              c:\windows\WindowsMobile\Microsoft.WindowsMobile.DeviceManager.dll
+ 2007-05-31 08:11 . 2007-05-31 08:11        132488              c:\windows\WindowsMobile\Microsoft.WindowsMobile.Common.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        100232              c:\windows\WindowsMobile\mailsync.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        228744              c:\windows\WindowsMobile\legacysyncengine.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\ko\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        352256              c:\windows\WindowsMobile\ja\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        352256              c:\windows\WindowsMobile\it\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        160648              c:\windows\WindowsMobile\InkStore.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        360840              c:\windows\WindowsMobile\inkeng.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        176520              c:\windows\WindowsMobile\INetRepl.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        360448              c:\windows\WindowsMobile\hu\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        352256              c:\windows\WindowsMobile\fr\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\fi\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        356352              c:\windows\WindowsMobile\es\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 07:59 . 2007-05-31 07:59        376832              c:\windows\WindowsMobile\en\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        380928              c:\windows\WindowsMobile\el\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        356352              c:\windows\WindowsMobile\de\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        348160              c:\windows\WindowsMobile\da\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 08:08 . 2007-05-31 08:08        352256              c:\windows\WindowsMobile\cs\Microsoft.WindowsMobile.DeviceCenter.resources.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        173960              c:\windows\WindowsMobile\CertAuth.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        102792              c:\windows\WindowsMobile\ceappmgr.exe
+ 2007-05-31 08:11 . 2007-05-31 08:11        169864              c:\windows\WindowsMobile\BakRestr.dll
+ 2007-05-31 08:11 . 2007-05-31 08:11        148872              c:\windows\WindowsMobile\AnimationLibrary.dll
+ 2007-05-31 07:21 . 2007-05-31 07:21        895880              c:\windows\WindowsMobile\AirSyncEngine.dll
+ 2012-04-13 15:20 . 2012-03-01 05:37        172544              c:\windows\SysWOW64\wintrust.dll
+ 2012-08-15 08:43 . 2012-02-11 05:43        492032              c:\windows\SysWOW64\win32spl.dll
- 2011-12-01 08:40 . 2010-11-20 12:21        492032              c:\windows\SysWOW64\win32spl.dll
- 2011-11-29 03:05 . 2011-02-18 05:43        428032              c:\windows\SysWOW64\vbscript.dll
+ 2012-08-15 08:42 . 2012-06-16 04:26        428032              c:\windows\SysWOW64\vbscript.dll
- 2012-02-15 13:03 . 2011-12-16 07:54        132096              c:\windows\SysWOW64\url.dll
+ 2012-08-15 08:42 . 2012-06-27 05:53        132096              c:\windows\SysWOW64\url.dll
+ 2012-07-11 05:44 . 2012-06-02 04:40        225280              c:\windows\SysWOW64\schannel.dll
+ 2007-05-31 14:21 . 2007-05-31 14:21        223112              c:\windows\SysWOW64\rapistub.dll
+ 2007-05-31 14:21 . 2007-05-31 14:21        105352              c:\windows\SysWOW64\rapi.dll
+ 2012-05-15 06:53 . 2002-12-06 06:02        272896              c:\windows\SysWOW64\pncrt.dll
+ 2012-06-18 04:38 . 2012-05-04 17:29        772504              c:\windows\SysWOW64\npDeployJava1.dll
+ 2012-07-11 05:44 . 2012-06-02 04:39        219136              c:\windows\SysWOW64\ncrypt.dll
- 2009-07-13 23:33 . 2009-07-14 01:16        219136              c:\windows\SysWOW64\ncrypt.dll
+ 2012-08-15 08:42 . 2012-06-27 05:51        627712              c:\windows\SysWOW64\msfeeds.dll
+ 2012-08-27 04:20 . 2012-08-27 04:20        690888              c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_Plugin.exe
+ 2012-05-03 07:06 . 2012-08-27 04:20        250568              c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-08-15 08:42 . 2012-06-16 04:26        717824              c:\windows\SysWOW64\jscript.dll
+ 2012-06-18 04:38 . 2012-05-04 17:29        227720              c:\windows\SysWOW64\javaws.exe
+ 2012-06-18 04:38 . 2012-06-18 04:37        174064              c:\windows\SysWOW64\javaw.exe
+ 2012-06-18 04:38 . 2012-06-18 04:37        174064              c:\windows\SysWOW64\java.exe
+ 2012-04-13 15:20 . 2012-03-01 05:33        159232              c:\windows\SysWOW64\imagehlp.dll
+ 2012-08-15 08:42 . 2012-06-27 05:50        176640              c:\windows\SysWOW64\ieui.dll
- 2012-02-15 13:03 . 2011-12-16 07:52        176640              c:\windows\SysWOW64\ieui.dll
- 2012-03-02 09:17 . 2010-05-12 15:09        108032              c:\windows\SysWOW64\ff_vfw.dll
+ 2012-03-02 09:17 . 2010-05-12 14:09        108032              c:\windows\SysWOW64\ff_vfw.dll
+ 2011-11-29 12:25 . 2012-05-04 17:29        687504              c:\windows\SysWOW64\deployJava1.dll
+ 2012-06-14 03:32 . 2012-04-24 04:36        140288              c:\windows\SysWOW64\cryptsvc.dll
+ 2012-06-14 03:32 . 2012-04-24 04:36        103936              c:\windows\SysWOW64\cryptnet.dll
+ 2012-07-11 05:44 . 2012-06-06 05:03        805376              c:\windows\SysWOW64\cdosys.dll
- 2011-12-01 08:38 . 2010-11-20 12:18        805376              c:\windows\SysWOW64\cdosys.dll
+ 2012-06-22 06:18 . 2012-06-02 13:19        186752              c:\windows\system32\wuwebv.dll
+ 2012-06-22 06:18 . 2012-06-02 22:19        701976              c:\windows\system32\wuapi.dll
+ 2012-04-13 15:20 . 2012-03-01 06:38        220672              c:\windows\system32\wintrust.dll
- 2011-12-01 08:41 . 2010-11-20 13:27        220672              c:\windows\system32\wintrust.dll
- 2011-12-01 08:41 . 2010-11-20 13:27        751104              c:\windows\system32\win32spl.dll
+ 2012-08-15 08:43 . 2012-02-11 06:43        751104              c:\windows\system32\win32spl.dll
+ 2011-11-28 20:04 . 2012-09-19 08:39        362986              c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2012-08-15 08:42 . 2012-06-16 05:16        609792              c:\windows\system32\vbscript.dll
+ 2012-08-15 08:43 . 2012-05-05 08:36        503808              c:\windows\system32\srcore.dll
- 2011-12-01 08:41 . 2010-11-20 13:25        559104              c:\windows\system32\spoolsv.exe
+ 2012-08-15 08:43 . 2012-02-11 06:36        559104              c:\windows\system32\spoolsv.exe
+ 2012-05-13 01:03 . 2010-11-20 13:09        762368              c:\windows\system32\spool\drivers\x64\unires.dll
+ 2012-05-13 01:03 . 2010-11-20 13:27        884224              c:\windows\system32\spool\drivers\x64\unidrvui.dll
+ 2012-05-13 01:03 . 2010-11-20 13:27        479232              c:\windows\system32\spool\drivers\x64\unidrv.dll
+ 2011-11-29 10:57 . 2010-11-20 13:27        715776              c:\windows\system32\spool\drivers\x64\mxdwdrv.dll
- 2012-01-16 05:25 . 2011-11-17 06:35        340992              c:\windows\system32\schannel.dll
+ 2012-07-11 05:44 . 2012-06-02 05:45        340992              c:\windows\system32\schannel.dll
- 2012-03-14 07:30 . 2012-01-25 06:38        149504              c:\windows\system32\rdpcorekmts.dll
+ 2012-06-14 03:32 . 2012-04-26 05:41        149504              c:\windows\system32\rdpcorekmts.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        253832              c:\windows\system32\rapistub.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        123272              c:\windows\system32\rapi.dll
- 2011-12-01 08:40 . 2010-11-20 13:27        209920              c:\windows\system32\profsvc.dll
+ 2012-06-14 03:32 . 2012-05-01 05:40        209920              c:\windows\system32\profsvc.dll
+ 2009-07-14 02:36 . 2012-09-19 06:04        616242              c:\windows\system32\perfh009.dat
+ 2009-11-13 23:29 . 2012-09-19 06:04        654400              c:\windows\system32\perfh007.dat
+ 2009-07-14 02:36 . 2012-09-19 06:04        106622              c:\windows\system32\perfc009.dat
+ 2009-11-13 23:29 . 2012-09-19 06:04        130240              c:\windows\system32\perfc007.dat
- 2009-07-13 23:49 . 2009-07-14 01:41        307200              c:\windows\system32\ncrypt.dll
+ 2012-07-11 05:44 . 2012-06-02 05:44        307200              c:\windows\system32\ncrypt.dll
- 2011-11-28 20:53 . 2012-02-23 08:18        279656              c:\windows\system32\MpSigStub.exe
+ 2011-11-28 20:53 . 2012-05-31 10:25        279656              c:\windows\system32\MpSigStub.exe
+ 2012-08-27 04:20 . 2012-08-27 04:20        420552              c:\windows\system32\Macromed\Flash\FlashUtil64_11_4_402_265_Plugin.exe
+ 2012-08-15 08:42 . 2012-05-14 05:26        956928              c:\windows\system32\localspl.dll
+ 2012-08-15 08:42 . 2012-06-16 05:15        911360              c:\windows\system32\jscript.dll
+ 2009-07-14 04:45 . 2012-09-02 17:55        441104              c:\windows\system32\FNTCACHE.DAT
- 2009-07-14 05:30 . 2012-03-12 07:02        143360              c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2012-09-18 06:00        143360              c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2012-09-18 06:00        143360              c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:30 . 2012-03-10 18:32        143360              c:\windows\system32\DriverStore\infstor.dat
+ 2011-07-22 14:47 . 2011-07-22 14:47        149504              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneUsbTransport.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        405504              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneNetProxy.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        249344              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneMTPZ.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        128000              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneIPTransport.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        354304              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneCoInst.dll
+ 2011-06-06 11:49 . 2011-06-06 11:49        708168              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\WinUSBCoInstaller.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        276872              c:\windows\system32\DriverStore\FileRepository\wpdrapi.inf_amd64_neutral_a093053dd72737eb\WpdRapi.dll
+ 2011-06-06 11:49 . 2011-06-06 11:49        708168              c:\windows\system32\DriverStore\FileRepository\wmzuneserusb.inf_amd64_neutral_0612991c2e85953e\WinUSBCoInstaller.dll
+ 2007-05-31 14:21 . 2007-05-31 14:21        223112              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wow64-rapistub.dll
+ 2007-05-31 14:21 . 2007-05-31 14:21        105352              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wow64-rapi.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        660360              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wmdc.exe
+ 2007-05-31 15:11 . 2007-05-31 15:11        443784              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wcescomm.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        127368              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\setup.exe
+ 2007-05-31 15:11 . 2007-05-31 15:11        253832              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\rapistub.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        225672              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\rapimgr.dll
+ 2007-05-31 15:11 . 2007-05-31 15:11        123272              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\rapi.dll
+ 2011-11-29 13:16 . 2010-11-20 13:24        229376              c:\windows\system32\DriverStore\FileRepository\bth.inf_amd64_neutral_de0494b6391d872c\fsquirt.exe
+ 2012-08-15 20:05 . 2012-07-06 20:07        552960              c:\windows\system32\DriverStore\FileRepository\bth.inf_amd64_neutral_de0494b6391d872c\bthport.sys
+ 2009-07-14 05:31 . 2012-09-18 06:00        399360              c:\windows\system32\DriverStore\drvindex.dat
- 2009-07-14 05:31 . 2011-12-02 17:18        399360              c:\windows\system32\DriverStore\drvindex.dat
+ 2007-05-31 15:11 . 2007-05-31 15:11        276872              c:\windows\system32\drivers\UMDF\WpdRapi2.dll
+ 2012-06-14 03:32 . 2012-04-28 03:55        210944              c:\windows\system32\drivers\rdpwd.sys
- 2012-03-14 07:30 . 2012-02-17 04:58        210944              c:\windows\system32\drivers\rdpwd.sys
+ 2012-07-11 05:44 . 2012-06-02 05:48        151920              c:\windows\system32\drivers\ksecpkg.sys
+ 2012-07-11 05:44 . 2012-06-02 05:50        458704              c:\windows\system32\drivers\cng.sys
+ 2011-11-28 21:44 . 2012-05-08 11:39        132832              c:\windows\system32\drivers\avipbb.sys
+ 2012-06-14 03:32 . 2012-04-24 05:37        184320              c:\windows\system32\cryptsvc.dll
+ 2012-06-14 03:32 . 2012-04-24 05:37        140288              c:\windows\system32\cryptnet.dll
+ 2009-07-14 05:12 . 2012-07-27 13:35        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:12 . 2012-03-17 07:54        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2011-11-28 20:12 . 2012-03-17 07:53        262144              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2011-11-28 20:12 . 2012-07-27 13:13        262144              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-08-01 00:11 . 2012-08-01 00:11        219368              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\reliability\Sqm\Manifest\Sqm27.bin
+ 2011-11-28 19:55 . 2012-09-18 21:15        718400              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2012-09-18 21:15        406388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-12-15 12:01 . 2011-12-15 12:01        226600              c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2012-04-21 09:03 . 2012-04-21 09:03        616024              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        156440              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll
+ 2011-12-15 12:01 . 2011-12-15 12:01        598784              c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
- 2011-11-21 22:57 . 2011-11-21 22:57        598784              c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
+ 2012-05-12 06:48 . 2012-02-10 23:29        172320              c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationHostDLL.dll
+ 2012-06-14 03:31 . 2012-04-23 22:33        630784              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.dll
+ 2012-05-12 06:48 . 2012-01-04 03:34        486144              c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        182056              c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2012-04-21 09:03 . 2012-04-21 09:03        616024              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        156440              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        518400              c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        518400              c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        957200              c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        957200              c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        386824              c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        131360              c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2012-06-14 03:31 . 2012-04-23 22:35        630784              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2012-05-12 06:48 . 2012-01-04 02:51        389888              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2012-05-12 06:48 . 2012-01-04 02:50        364816              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2012-05-12 06:48 . 2012-01-04 02:50        996624              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        350592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        350592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        163168              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        163168              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        138592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        138592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        699224              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        699224              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        857960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        857960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        675672              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        675672              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        113512              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        113512              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        129912              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        129912              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        390008              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        390008              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        505208              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        505208              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        261472              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        261472              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        122264              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        122264              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        291184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        291184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        349568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        349568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        236880              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        236880              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        253280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        253280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        378720              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        378720              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        134528              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        134528              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        123736              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        123736              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        392552              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        392552              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        125816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        125816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        120152              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        120152              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        616024              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        395120              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        395120              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        182144              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        182144              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        285072              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        285072              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        829280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        829280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        747360              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        747360              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        436600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        436600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        683872              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        683872              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        409448              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        409448              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        210816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        210816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        156440              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        122248              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        122248              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        525704              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        525704              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        112976              c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        112976              c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        581464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        581464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        832856              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        832856              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        194424              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        194424              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        478576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        478576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        167288              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        167288              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        232304              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        232304              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        661352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        661352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        349576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        349576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        387960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        387960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        746336              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        746336              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        505184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        505184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        288616              c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        288616              c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        335712              c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        335712              c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        125440              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        125440              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        237424              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        237424              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        187776              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        187776              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        269672              c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        269672              c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        334688              c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        334688              c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        109568              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-03-13 14:48 . 2012-03-13 14:48        109568              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        246128              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-03-13 14:48 . 2012-03-13 14:48        246128              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        170368              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        170368              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-06-18 04:39 . 2012-06-18 04:39        179200              c:\windows\Installer\cd8dda4.msi
+ 2012-06-18 04:38 . 2012-06-18 04:38        461824              c:\windows\Installer\cd8dd9d.msi
+ 2008-07-30 18:27 . 2008-07-30 18:27        234496              c:\windows\Installer\c1093fa.msi
+ 2012-02-09 05:27 . 2012-02-09 05:27        206848              c:\windows\Installer\4958d.msp
+ 2012-03-21 03:55 . 2012-03-21 03:55        133632              c:\windows\Installer\4950d.msp
+ 2012-07-04 05:59 . 2012-07-04 05:59        261120              c:\windows\Installer\282343c.msp
+ 2011-08-05 13:04 . 2011-08-05 13:04        147456              c:\windows\Installer\19eb5f2.msi
+ 2011-08-05 13:16 . 2011-08-05 13:16        167936              c:\windows\Installer\19eb5ea.msi
+ 2011-08-05 12:32 . 2011-08-05 12:32        167936              c:\windows\Installer\19eb5e2.msi
+ 2011-08-05 14:39 . 2011-08-05 14:39        172032              c:\windows\Installer\19eb5da.msi
+ 2011-08-05 13:28 . 2011-08-05 13:28        172032              c:\windows\Installer\19eb5d2.msi
+ 2011-08-05 12:20 . 2011-08-05 12:20        184320              c:\windows\Installer\19eb5ca.msi
+ 2011-08-05 11:57 . 2011-08-05 11:57        176128              c:\windows\Installer\19eb5c2.msi
+ 2011-08-05 11:34 . 2011-08-05 11:34        196608              c:\windows\Installer\19eb5ba.msi
+ 2011-08-05 11:14 . 2011-08-05 11:14        176128              c:\windows\Installer\19eb5b2.msi
+ 2011-08-05 11:01 . 2011-08-05 11:01        184320              c:\windows\Installer\19eb5aa.msi
+ 2011-08-05 15:01 . 2011-08-05 15:01        143360              c:\windows\Installer\19eb5a2.msi
+ 2011-08-05 14:27 . 2011-08-05 14:27        184320              c:\windows\Installer\19eb59a.msi
+ 2011-08-05 13:52 . 2011-08-05 13:52        188416              c:\windows\Installer\19eb592.msi
+ 2011-08-05 14:50 . 2011-08-05 14:50        143360              c:\windows\Installer\19eb58a.msi
+ 2011-08-05 12:53 . 2011-08-05 12:53        151552              c:\windows\Installer\19eb582.msi
+ 2011-08-05 14:06 . 2011-08-05 14:06        176128              c:\windows\Installer\19eb57a.msi
+ 2011-08-05 14:16 . 2011-08-05 14:16        180224              c:\windows\Installer\19eb572.msi
+ 2011-08-05 13:40 . 2011-08-05 13:40        180224              c:\windows\Installer\19eb56a.msi
+ 2011-08-05 12:42 . 2011-08-05 12:42        176128              c:\windows\Installer\19eb562.msi
+ 2011-08-05 11:25 . 2011-08-05 11:25        184320              c:\windows\Installer\19eb55a.msi
+ 2011-08-05 12:08 . 2011-08-05 12:08        180224              c:\windows\Installer\19eb552.msi
+ 2011-08-05 11:46 . 2011-08-05 11:46        180224              c:\windows\Installer\19eb54a.msi
+ 2011-08-05 15:14 . 2011-08-05 15:14        458752              c:\windows\Installer\19eb542.msi
+ 2011-11-29 11:01 . 2012-09-16 20:50        415584              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        415584              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        303456              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        303456              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        571232              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        571232              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        326496              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\joticon.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        326496              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\joticon.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        470616              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        178528              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\grvicons.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        178528              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\grvicons.exe
+ 2012-06-14 04:59 . 2012-06-14 04:59        380928              c:\windows\Installer\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}\iTunesIco.exe
+ 2012-05-18 12:09 . 2012-05-18 12:09        660360              c:\windows\Installer\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}\wmdc.exe
+ 2009-11-13 15:25 . 2012-04-13 15:29        693600              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\WksWP.exe
- 2009-11-13 15:25 . 2011-11-29 17:01        693600              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\WksWP.exe
+ 2009-11-13 15:25 . 2012-04-13 15:29        947552              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\wksss.exe
- 2009-11-13 15:25 . 2011-11-29 17:01        947552              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\wksss.exe
- 2009-11-13 15:25 . 2011-11-29 17:01        709984              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\WksCal.exe
+ 2009-11-13 15:25 . 2012-04-13 15:29        709984              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\WksCal.exe

Weiter mit Teil 2/3 ==>

Rai3 19.09.2012 15:22

Teil 2/3
Code:

+ 2010-03-18 12:16 . 2010-03-18 12:16        181096              c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_X86.dll
+ 2010-03-18 13:27 . 2010-03-18 13:27        225640              c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_AMD64.dll
+ 2010-10-20 14:10 . 2010-10-20 14:10        105344              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\TRANSMGR.DLL
+ 2010-12-21 01:58 . 2010-12-21 01:58        294768              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\SHAREPOINTPROVIDER.DLL
+ 2010-10-22 14:05 . 2010-10-22 14:05        423280              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\RTFHTML.DLL
+ 2011-03-18 22:08 . 2011-03-18 22:08        329616              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OUTLPH.DLL
+ 2010-10-20 15:08 . 2010-10-20 15:08        122720              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OUTLCTL.DLL
+ 2011-09-02 00:15 . 2011-09-02 00:15        140656              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ONENOTEMANAGED.DLL
+ 2011-09-02 00:15 . 2011-09-02 00:15        227712              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ONENOTEM.EXE
+ 2010-12-27 23:52 . 2010-12-27 23:52        233360              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OMSXP32.DLL
+ 2010-12-27 23:52 . 2010-12-27 23:52        724864              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OMSMAIN.DLL
+ 2011-02-04 22:52 . 2011-02-04 22:52        403320              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\OFFXML.DLL
+ 2011-01-07 09:38 . 2011-01-07 09:38        121208              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\MSCONV97.DLL
+ 2010-10-20 15:06 . 2010-10-20 15:06        169352              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\IPOLK.DLL
+ 2010-10-20 15:08 . 2010-10-20 15:08        135528              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\IMPMAIL.DLL
+ 2011-09-02 00:13 . 2011-09-02 00:13        577960              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\IECONTENTSERVICE.EXE
+ 2011-02-04 12:40 . 2011-02-04 12:40        452936              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\EXPSRV.DLL
+ 2011-03-17 09:34 . 2011-03-17 09:34        155008              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ENVELOPE.DLL
+ 2010-10-22 14:05 . 2010-10-22 14:05        135032              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\CONTAB32.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        362904              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEXBE.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        220560              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACETXT.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        527776              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEREP.DLL
+ 2010-12-20 23:48 . 2010-12-20 23:48        329624              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACER3X.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        383904              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEOLEDB.DLL
+ 2010-12-20 23:48 . 2010-12-20 23:48        278448              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEODBC.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        644504              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEEXCL.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        334752              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEEXCH.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        686504              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEES.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        548792              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEDAO.DLL
+ 2010-12-27 23:49 . 2010-12-27 23:49        548792              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACACEDAO.DLL
+ 2012-05-13 01:21 . 2012-05-13 01:21        337408              c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\65f25960625d91ca79a40f9067adc021\WindowsFormsIntegration.ni.dll
+ 2012-06-15 10:08 . 2012-06-15 10:08        337408              c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\08becdcc9bd647c4e4d07ceea7fe4895\WindowsFormsIntegration.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        231424              c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\fb43d84bc59b21e8a7f3e36d616eea90\UIAutomationTypes.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        122368              c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\26f12a0a3baed2a227cf30aaeae03913\UIAutomationProvider.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        645120              c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\1c3c298326e9ac14796516ac1da09a16\UIAutomationClient.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        528896              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\307eea660f877dc40ae90882ce554757\System.Xml.Linq.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        256000              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\b4afa252d0f0e27b0b5e8fcb2cc5b3a7\System.Windows.Input.Manipulations.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        903168              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\8c0ee7b970cc4e8c2986c7898af71661\System.Transactions.ni.dll
+ 2012-06-15 10:08 . 2012-06-15 10:08        281088              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\ca5505a49a075ee7ad2535f89d9ea992\System.ServiceProcess.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        281088              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\85810fe277a718273eb946a460ae8010\System.ServiceProcess.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        108032              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\eb4fb369926faaffede7aaf317fd6532\System.ServiceModel.Channels.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        517120              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\e5ab3c37897bb578bdbfe6b7e0558ad8\System.ServiceModel.Routing.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        946688              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\e48b6a8c491a96d1bc601795532af605\System.Security.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        376832              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\7590828d50338d512b11a4d3f87d69a2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        987648              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\21d5b44ef01ccfa69e79674a51707de0\System.Runtime.Remoting.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        176640              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\5f2bfb0585061dc256ee9587d430959f\System.Numerics.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        933376              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\6996a415485a84fef2d2556b0462336f\System.Net.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        781824              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\a3849a373beeb3509d8c22d5751dfad3\System.Messaging.ni.dll
+ 2012-06-15 10:08 . 2012-06-15 10:08        781824              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\0d8257087be3e57b071d1d5ccd705c2f\System.Messaging.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        521728              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\92d266f677605e5475b7f39c063c4a9d\System.Management.Instrumentation.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        531456              c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\07a0e1efc063042be3e8faf62b413a12\System.IO.Log.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        290816              c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\7fd39b9a208214e6e5eba4e9396409f1\System.IdentityModel.Selectors.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        348672              c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.Wrapper.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        512000              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\521f5bccf74318a4777597b0c01fda1e\System.Dynamic.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        632832              c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\6a8bd7d373c988a585e90bb61c5ec8cc\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        141824              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\78dd02d104bb15bc3820c06bd2876239\System.Device.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        176128              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\97d1aaf3733b107ecdbecb9d21050ff4\System.Data.DataSetExtensions.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        181760              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c3d7a7ff58ff502887d8f1b77e61adbc\System.Configuration.Install.ni.dll
+ 2012-06-15 10:07 . 2012-06-15 10:07        181760              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\52792a7ce63196551c29f5201562c1ae\System.Configuration.Install.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        255488              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\a4f91f2dfd1656ef2e42917963f6bf50\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        871936              c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\b1c67ee2e0e6e78c31985069fbc82596\System.AddIn.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        560640              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\c69fb0f955adc7ca80cd5f2fd730edea\System.Activities.DurableInstancing.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        432128              c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\11fc863fa4f5092fca4f2ce25a9ac361\SMSvcHost.ni.exe
+ 2012-05-13 01:16 . 2012-05-13 01:16        185344              c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\50e8e826488639e549589ba34666933e\SMDiagnostics.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        428032              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\722c0236432dd5ccc047481d3ebbd49e\PresentationFramework.Royale.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        622592              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\6739c3715c9e38dbdfbfd57b424a3094\PresentationFramework.Aero.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        802304              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\3e7359f5f0fb68565314f88f6ec2d67a\PresentationFramework.Luna.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        349184              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\263748f3d18955b9e467710da1e8546f\PresentationFramework.Classic.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        864768              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\e4aa78e299b615e1fc92ba19a78071b8\Microsoft.VisualStudio.Tools.Office.Runtime.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        247808              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\e1725f0aad2d375efdcfeea0f428df59\Microsoft.VisualStudio.Tools.Office.Runtime.Internal.ni.dll
+ 2012-06-15 10:05 . 2012-06-15 10:05        232960              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\db2b738efe91eed6c4413faf44707248\Microsoft.VisualStudio.Tools.Office.ContainerControl.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        232960              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\b3f49d9c0a98c18ef8ed20a3acdbebb7\Microsoft.VisualStudio.Tools.Office.ContainerControl.ni.dll
+ 2012-06-15 10:05 . 2012-06-15 10:05        247808              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\b3b3284d16359533332c3424e1330c5c\Microsoft.VisualStudio.Tools.Office.Runtime.Internal.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        475136              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\ac6c6882341a572604fa25b32836a4c0\Microsoft.VisualStudio.Tools.Applications.Hosting.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        169984              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\45da98c4ff3a12f7438f2b7cd10752b9\Microsoft.VisualStudio.Tools.Applications.Runtime.ni.dll
+ 2012-06-15 10:05 . 2012-06-15 10:05        864768              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\13f2ca7a3f3c6cf653896f76a7b167b6\Microsoft.VisualStudio.Tools.Office.Runtime.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        992256              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\136e31ba5378e99c0439d13a53b6227f\Microsoft.VisualStudio.Tools.Applications.ServerDocument.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        422912              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\6493bbb60833072904ad141a5a4d08ac\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-06-15 10:05 . 2012-06-15 10:05        422912              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\097137b03ff37196b4b8ba62db34d64a\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        600064              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\6480551111832c83ee88bcf756a72533\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        432128              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\f669d7c64bbabbc41a4dc0221b5e8fb9\Microsoft.Office.Tools.Common.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        408576              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\91247db3b5591e446721aa42f25015c2\Microsoft.Office.Tools.Outlook.Implementation.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        199680              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\90d90e963577dcdcf1474cb98bd76781\Microsoft.Office.Tools.Outlook.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        199680              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\73487c1ce2fd1b35d59ae1e54c76520d\Microsoft.Office.Tools.Outlook.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        993280              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\644f5d4e386c5f2d2602e7348cc8a4a5\Microsoft.Office.Tools.Excel.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        432128              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\63be7108c18a21c22b8305b24c57473e\Microsoft.Office.Tools.Common.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        993280              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\40323c86511b6413f4192e4e589b723a\Microsoft.Office.Tools.Excel.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        408576              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\02f4b5d19820efd8881511ed829d97dc\Microsoft.Office.Tools.Outlook.Implementation.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        279552              c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\0e81a3996f7cbff23fc01bea4185a918\CustomMarshalers.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        253952              c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\44752ffa92ebb7170951a41898d8b9c6\WindowsFormsIntegration.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        196096              c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\0a80fd3af7e48eb9cc9099fee5814dff\UIAutomationTypes.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        484352              c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\7a9f70fa774076a7ec19bc03e7064d0d\UIAutomationClient.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        393216              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\4837a5c6204d53e7aa4f7dd94b98207c\System.Xml.Linq.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        189440              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\c477bbff1e4662263255a1bf17bd9c2a\System.Windows.Input.Manipulations.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        649728              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\67a386434938003bceb0752e979dabb3\System.Transactions.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        221696              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\5552b27237c3dbe4f21a10e97adf2edc\System.ServiceProcess.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        369664              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dc86fe1c7a6e3a7ce9e9c1f13d9b1e8e\System.ServiceModel.Routing.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        736768              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\5a3beae8b211b91bfc620c029cf4c2d4\System.Security.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        311296              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\5a4d233916a69d48fa12a9f7f103d893\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        762880              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\65f0d70169a0e73b45307dddbd86f92b\System.Runtime.Remoting.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        145408              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\7b7719d46a4da2e91e8c501347e48ab9\System.Numerics.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        657408              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\dd25ddcfa0417d40e3f1385e30abcd6f\System.Net.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        626176              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\a730931e386537e3c229e049c9a6d271\System.Messaging.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        395264              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\08397796343d5730a29f42e61c7f6ee7\System.Management.Instrumentation.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        413696              c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\ff1250d2409bd16283c423650d6fd3f6\System.IO.Log.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        229888              c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\e60675d3ba7fa94924489dc8466ebff5\System.IdentityModel.Selectors.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        236032              c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.Wrapper.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        787456              c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        377856              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\a9b1e597aaa263dea2cf8754440bd271\System.Dynamic.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        470528              c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\e41e86da56bb60523251e0e08210a77b\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        913920              c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\94d45f7f28d81304d7fa83bcea849141\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        112640              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\4c50d8a951546d6dffdc8bcb23f47a7b\System.Device.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        134656              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\7803f4398a527a87d5cace8023e93e8b\System.Data.DataSetExtensions.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        982528              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        148480              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\c7d60a49e43964b1ae17e9a080376c6d\System.Configuration.Install.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        693760              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\877ef74350e6d374ca8f80b489a8cc8e\System.ComponentModel.Composition.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        194048              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\4330e93f9d0ef85f1a972e11c2ac5156\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        624128              c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\0c67d9fc14856eb7d8b4e405aef79960\System.AddIn.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        411136              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\2b046f2d5f056b906d7b25b75ca23575\System.Activities.DurableInstancing.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        317952              c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\4847f66153121ec4ed532909f7c152be\SMSvcHost.ni.exe
+ 2012-05-13 01:23 . 2012-05-13 01:23        143360              c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\bb97517e4ca64e02282fca24612ce8ad\SMDiagnostics.ni.dll
+ 2012-05-13 01:11 . 2012-05-13 01:11        309760              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\ef6e3eb351fe12a5766be7c956c35d95\PresentationFramework.Classic.ni.dll
+ 2012-05-13 01:11 . 2012-05-13 01:11        387072              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\e49a124fdad0f1db135f03a49f18fb48\PresentationFramework.Royale.ni.dll
+ 2012-05-13 01:11 . 2012-05-13 01:11        595968              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll
+ 2012-05-13 01:11 . 2012-05-13 01:11        755712              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\141f0a8fbfb83604fa3dd43dbe8fa0f4\PresentationFramework.Luna.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        708608              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\f120c1f17850a7b8d105f22907a09dd0\Microsoft.VisualStudio.Tools.Office.Runtime.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        364544              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\bdfc721f7e94acba00c2e92153307b70\Microsoft.VisualStudio.Tools.Applications.Hosting.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        135680              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\b2adaa453df6c958d3cf66ae051787de\Microsoft.VisualStudio.Tools.Applications.Runtime.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        177152              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\740410269afdf2276525e1dfd870fee8\Microsoft.VisualStudio.Tools.Office.ContainerControl.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        738304              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\6e4e81d647b98053d4b580d5afcf682f\Microsoft.VisualStudio.Tools.Applications.ServerDocument.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        210432              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\39817a23777554d968852971b91a4f78\Microsoft.VisualStudio.Tools.Office.Runtime.Internal.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        303104              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\8cc4dd9babffe370cf375925fba15f84\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        418816              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\01c5ff7a1ea0463414736df5d449e0a9\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        864768              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\ec9a55a16c6613554d1a7409811b7a2c\Microsoft.Office.Tools.Common.Implementation.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        336384              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\54ab02cb617ed9070723032361c72de6\Microsoft.Office.Tools.Common.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        152064              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\42a5e49641bff019e55a8228560fc541\Microsoft.Office.Tools.Outlook.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        730624              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\282f3b9bd8dc8a67787e210a9b0e78e3\Microsoft.Office.Tools.Excel.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        312320              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\27ba2637821bb8b8b79ccb4f4d4e3114\Microsoft.Office.Tools.Outlook.Implementation.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        676864              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\14ae412fbc10916dda33ce1616a63cf1\Microsoft.Office.Tools.Word.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        194048              c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\f11d5fea7ded12068e8cdb8b2f1bdbd9\CustomMarshalers.ni.dll
+ 2012-05-13 01:55 . 2012-05-13 01:55        468992              c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\ad7f43afb4f124acae4d503b40f591c1\WsatConfig.ni.exe
+ 2012-06-15 10:04 . 2012-06-15 10:04        329216              c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\f4d304fcbfda323997083a1f88b83719\WindowsFormsIntegration.ni.dll
+ 2012-05-13 01:38 . 2012-05-13 01:38        253952              c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\bf634b0e2e28466c6ed6ae1eb602b09f\UIAutomationTypes.ni.dll
+ 2012-05-13 01:38 . 2012-05-13 01:38        120832              c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\1ff8fb81d6f045f1dc6f50be95444292\UIAutomationProvider.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        653312              c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\1f36e020c3563e0ff414f13138e238e1\UIAutomationClient.ni.dll
+ 2012-06-15 07:24 . 2012-06-15 07:24        731648              c:\windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP2D76.tmp\System.Web.DynamicData.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        304128              c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\681410f842337dccc72eb059738c3ced\TaskScheduler.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        529920              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\de45d043775d8c805f6feca40d7a9ed2\System.Xml.Linq.ni.dll
+ 2012-06-15 07:24 . 2012-06-15 07:24        187392              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\72b4992e45d232251a273a59eb3333d5\System.Web.Routing.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        261120              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\76662ce36d2141e45513e64386073cc2\System.Web.RegularExpressions.ni.dll
+ 2012-06-15 10:03 . 2012-06-15 10:03        449024              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\b905eb57b631a30c60caa4d68c186963\System.Web.Entity.ni.dll
+ 2012-06-15 10:03 . 2012-06-15 10:03        398848              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\e412dfbf1aa49bbe345a02a4d23104f5\System.Web.Entity.Design.ni.dll
+ 2012-06-15 10:03 . 2012-06-15 10:03        753664              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\815769f953ebe3f84439d522c97317b8\System.Web.DynamicData.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        204800              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\c8144ee08dccdac183527e53c86aa901\System.Web.Abstractions.ni.dll
+ 2012-05-13 01:40 . 2012-05-13 01:40        921600              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\ec95ad2463c5588fc8ef552b3f375ee6\System.Transactions.ni.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        295424              c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\f71d2f65d0f149c75ac7a569dbcc8500\System.ServiceProcess.ni.dll
+ 2012-05-13 01:38 . 2012-05-13 01:38        928768              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\1875b50d0228f29aef00bed38ab594d6\System.Security.ni.dll
+ 2012-05-13 01:39 . 2012-05-13 01:39        396288              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\807759890a40e4047c35a24e64dc76d5\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        916480              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\3b3581851a728bef36f319e9d4c72499\System.Net.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        783360              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\d5d612f7d372f500e3062e3814e79d75\System.Messaging.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        534016              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\599954438a668c94dd38e8e7e506ac2a\System.Management.Instrumentation.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        569856              c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\fd51741bfd973ad507bbd141e98932f8\System.IO.Log.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        294400              c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\ef6abe121bb11bff2514bfdfb7e76b7a\System.IdentityModel.Selectors.ni.dll
+ 2012-05-13 01:40 . 2012-05-13 01:40        446464              c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.Wrapper.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        288768              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\fbc02e9f5a14bb93082ebc88bc577413\System.Drawing.Design.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        649728              c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\4bb1134d9b166434327385ddf3c5dd54\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        629760              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\7c4ce1b8a2f83ef29aa6d5f126ab5b71\System.Data.Services.Design.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        194560              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\19d1414f1ca718ce4d0c07e7305b3450\System.Data.DataSetExtensions.ni.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        192000              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\a88ca70ab9641b8236149bc5dd8d1564\System.Configuration.Install.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        132096              c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\9536bb262c4f1ea389d287ab669767d4\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        890880              c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\84262138e2e9f34c88fd282caa82baa5\System.AddIn.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        156672              c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\176899be7b920fb20408ff49e636a776\System.AddIn.Contract.ni.dll
+ 2012-05-13 01:55 . 2012-05-13 01:55        297984              c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\ee0608cd62dfb37016016884fc39e425\sysglobl.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        525824              c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\9fa1abf006689e262527ae50d452e97e\SMSvcHost.ni.exe
+ 2012-05-13 01:49 . 2012-05-13 01:49        349184              c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\2eac9c598de3341eba5c16787c74f220\SMDiagnostics.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        282624              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\89de197bdde5984658045ade41c2c9b9\PresentationFramework.Classic.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        620544              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\7ffb91db770d0b09921f623bc5d68b4f\PresentationFramework.Luna.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        463360              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\4f3567165e2a444fc9a62980c4d0ea82\PresentationFramework.Aero.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        317440              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\205bb33cef9ae6b906ceadd6f2861c86\PresentationFramework.Royale.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        855040              c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\2f1bad2fb963482a02443d5e7fece2b6\napsnap.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        162816              c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\bb4947f0ecc925a7bcfd129b6eec8f9b\napinit.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        175104              c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\5f0ae15f9d1cade37fbfaacff7e64bff\naphlpr.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        127488              c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\5346ceca518baf5e5fa3fed9f900f792\napcrypt.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        184320              c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\8f792883d0adad8c7beccf24aed65817\MSBuild.ni.exe
+ 2012-06-15 07:22 . 2012-06-15 07:22        417792              c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\67240ddde494b9cc05cd732ccd099668\MMCFxCommon.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        681984              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\b78beede8a3c9720095dde4a4a162acc\Microsoft.WSMan.Management.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        122368              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\83222514e209f186ad3a1c3794168bfd\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        105984              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\a843956bb452503139683304de4cc8f6\Microsoft.Vsa.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        305664              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\fda2f68162063c54d2e669e85de7dfb1\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        202752              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\f91011762717be2cbc01f328a806c37c\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        232448              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d506bcf38b89f1fb1cd41e01a7d94298\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        226304              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d1ffef140ded6229eb2681594a992395\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        209920              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\cfaa030ecf4e968aecd91ddca97d650e\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        225280              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\cf9c858a00058974b41c67bbd68e45c4\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        446464              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c8c461dbe6ab47066c7890e6546a8907\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        956416              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9522b90955f403c723b945cf1b201cf5\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        499200              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\902522b8368cc353596494d2e51bd34c\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        311296              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\8c26f5c227dfd2587be648dd63fb0e58\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        124928              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7744e263e680176825a6341c381483c6\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        495616              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7521a6224a26851550e2c903367e7a3b\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        390656              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\639acfa01f065f3a0f8d41648ed5e1bc\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        773120              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\3adbee43498cd363d94881c0a329d519\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        270336              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\35394cb8a9296f0a52b6bd89ab45454d\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        215040              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\093667a607b62f44786300f557c30d04\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        584192              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\c56d6513e4b239b1b1dbe29b0588321a\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        713216              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\fb0d102ca78bd05fe7064b9e6be30fc7\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        237056              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b21fa6ff448b99a97319e18c166c03e2\Microsoft.PowerShell.Security.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        999936              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6c3fe42a14ac5b48ebd43be290973d24\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        416768              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\2572e94f9d0b412cdc529c8d74fdb689\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        244224              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\c28d0d3c7d9214d676526f0f3b5eb305\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        253952              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\795e07cc078bee3396f1d946f734c871\Microsoft.Office.Tools.v9.0.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        164864              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f04ccbbf5199d2b264f1b1175be44686\Microsoft.MediaCenter.Mheg.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        219648              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f015188310f7613f819fcf032f98705a\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        312320              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\e29cbd30a31d3c8dae19eb17f70c4ec4\Microsoft.MediaCenter.iTv.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        370176              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6dbd502a13b5e3caae0b1f2b4847612f\Microsoft.MediaCenter.Playback.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        522240              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\514667153fd74307d21e7f50b79858c9\Microsoft.MediaCenter.Interop.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        152576              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\409dae089f2e041343cff71f822cd505\Microsoft.MediaCenter.ITVVM.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        965632              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\18367b9a0b9e9261d1d9e371230af87c\Microsoft.MediaCenter.Sports.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        798720              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\803188573fb19785a94284e097c48a67\Microsoft.ManagementConsole.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        244736              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\d68a27daca73749e4438a47e61643c3c\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        198656              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\3151235c1c38db94fd44e3c6f290ff38\Microsoft.Build.Utilities.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        121344              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\cf5e9b5d10682467a9e03358a6d6258f\Microsoft.Build.Framework.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        142336              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\0f233d0eb396065719e83ab573a72cc5\Microsoft.Build.Framework.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        294912              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\2416af06edb993f98a751acb69f67016\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        107520              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\69286d5692277a166404cb897a8b2e7a\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        380928              c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\74e4adc90675c3b1365825c7e78b5ce9\Mcx2Dvcs.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        547328              c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\4a1f9a648a3928d42b77a91666d9aa8a\mcupdate.ni.exe
+ 2012-05-13 01:50 . 2012-05-13 01:50        533504              c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\40d70417c04f9ccb5fdecb5b9be5a6a3\mcstoredb.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        549376              c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\4ae6ccc32dafb4e3765b9db05585bd48\mcplayerinterop.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        696320              c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\b0db345fd62a84c98fd8b0bf3c72e8bb\mcGlidHostObj.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        156672              c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\3fc113fe40d0145cd87afca2d107bf6d\MCESidebarCtrl.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        659456              c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\bc5df15ee827e248dd6f819874a85718\EventViewer.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        969216              c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\584d419d4c837ea19f7f450a807b0273\ehRecObj.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        661504              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\20c3505378a50f4859c9b2e7dcbb5fa2\ehiWUapi.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        933888              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\2f9f48ad6496c9103043db1c21a651fd\ehiwmp.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        145408              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\0955237aa3c1cb3a643248b8c58ec34c\ehiUserXp.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        196096              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\7998173654fa518876cc97e37b86d465\ehiiTv.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        397824              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\6c97aa6908f96ac9816ce74e4f6251ac\ehiExtens.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        110080              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\a501747a95523297a8a1f119df8b1642\ehiBmlDataCarousel.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        126976              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\414bbac4e1d7761a336bb9d74b9b243a\ehiActivScp.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        389120              c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\08c9aa18b306aa47ddc0ae4a63b05d04\ehExtHost.ni.exe
+ 2012-05-13 01:50 . 2012-05-13 01:50        313856              c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\ff7ef4caed03d6934669d1a39877a8ac\ehCIR.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        348672              c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\b7916689137fd0bc9ba1ba5a27e2a38a\CustomMarshalers.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        640000              c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\cc6e6febcd804604bf4d92d0eb8ec6ae\ComSvcConfig.ni.exe
+ 2012-05-13 01:49 . 2012-05-13 01:49        971264              c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\d18719c2df1334364cac199bb9c86adf\BDATunePIA.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        321024              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\9d60139fdead64a892985181d663989f\WsatConfig.ni.exe
+ 2012-06-15 07:18 . 2012-06-15 07:18        633856              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\df0359a76d328cac78d2eb8187dedc29\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        851968              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f2b8292f10120babf7e0bef15500757d\WindowsLive.Writer.BlogClient.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        313856              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dbbb5914ff727ce0f6793177c4da31ba\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        108544              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d8ef9a917c6ae2af0629ec779879bd8e\WindowsLive.Writer.Passport.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        119296              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\cca051320b90ccdff24499d39b3f95df\WindowsLive.Writer.FileDestinations.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        319488              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\91eaa4412030c5f993ae12cee84c8be9\WindowsLive.Writer.Interop.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        843776              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8cbb193835d1c56734d4e1ce810bdb07\WindowsLive.Writer.Controls.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        594944              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7d5b1cab9a5bd55b13e9edf36c53a5c5\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\760dd39014baf3be47ced54f99465d7a\WindowsLive.Writer.SpellChecker.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        117760              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6d2e8a42e5eb6dcb8c5ea9a7c883b3d9\WindowsLive.Writer.Instrumentation.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        118784              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\49f36717a3e8d62dba630434d8e93f5d\WindowsLive.Writer.Extensibility.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        428032              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\49615853d101d2904b8949988fa05de8\WindowsLive.Writer.Localization.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        152064              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2d682c7c8f1a3d806989d2149f79d625\WindowsLive.Writer.HtmlParser.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        334848              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\233d02a1f648e60c273df807d0240b43\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        174080              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1099eeb1f6f9792d80dea9ac5243d491\WindowsLive.Writer.BrowserControl.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        258560              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\01d1ef447119fc58961adff850921e35\WindowsLive.Writer.Mshtml.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        145920              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\66da5ccbc8ef08451164bfba524d88b4\WindowsLive.Client.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f2f8201dd3453250dfd9ed1afce630a0\WindowsFormsIntegration.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        185344              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        452096              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\779b08c46960a1824503aa6f089673fa\UIAutomationClient.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        245248              c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\f3e052584df9c614407da662dd3c3df3\TaskScheduler.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        401408              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\64de6810023adccdc56ddae13bdd6b03\System.Xml.Linq.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\64ba8bd1d5ee5cd0cb83fd2a4a9cd900\System.Web.Routing.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\2b129372a27469195acbe3b6b81786ef\System.Web.RegularExpressions.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        860160              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\4f13c2c06fb97f6659473f02802b377b\System.Web.Extensions.Design.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        328192              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\bc239944bca7cc6b6ddb473259183c7d\System.Web.Entity.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        301568              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\3701488fb9e601ebe963db25b784d684\System.Web.Entity.Design.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        547328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\2096122aa65149e0ebd06df7981cc678\System.Web.DynamicData.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\0de19693eb75a6e89e872c4ae6bf2e83\System.Web.Abstractions.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        627200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        680448              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        310784              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        771584              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        624128              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\0b5f082230e3486412e0fa333290e85a\System.Net.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        593408              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\2b4d6976393bf5643a4ef2d8dffdf75b\System.Messaging.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        330240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\8280490a2939075b726fd051d9010cc0\System.Management.Instrumentation.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        381440              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\a03191ed937f6c1dc827b53d94ea0176\System.IO.Log.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\100d39c2f8985cb93e26feef86ba5212\System.IdentityModel.Selectors.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        280064              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.Wrapper.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        628224              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        208384              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\912a0776c2bfd35ff76bd0b8ba977ed4\System.Drawing.Design.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        455680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\55545e89f96539ef93375524d1145a6f\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        888320              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4d73a7649876bb6e54a01ccbf235919b\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        462336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e36e03067b12bc35fcc3787dc81022c8\System.Data.Services.Design.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        763392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\5a29fff52e2c3d13ec15e8701027ab17\System.Data.Entity.Design.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        135680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\940f62a5d077405e0b324422afb6ff2c\System.Data.DataSetExtensions.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        971264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\498d2033c60fe5b777cf923b71b25972\System.Configuration.Install.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        634368              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\a90ec436f1d2c5cb0133a53c2e47d61a\System.AddIn.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        232448              c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\1ed79278fe139272e868e3a53d736f22\sysglobl.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        366080              c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1b0b19607668635281fa260707f4352f\SMSvcHost.ni.exe
+ 2012-05-13 01:45 . 2012-05-13 01:45        256000              c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        226816              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae55e761d480fe15781156d1311a1837\PresentationFramework.Classic.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        368128              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        258048              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7df1f379457aa5f39183903d115b5479\PresentationFramework.Royale.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        539648              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\496bc57a53989bb83ec58865fa34be1d\PresentationFramework.Luna.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        723456              c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\acfafa161ea232928cb02b01c50acf1c\napsnap.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        117760              c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\0abec246c5ca6ec4858bfd3ab84da0ec\napinit.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        114176              c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\e0c40329b9cdd7f141a3702d79eb4bda\naphlpr.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        133632              c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\74a8b6419deb005337a1e43ec2502134\MSBuild.ni.exe
+ 2012-06-15 07:18 . 2012-06-15 07:18        287232              c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\1e03b7c2539c5376f0665a4aba04efbd\MMCFxCommon.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        531968              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\070505350ec9daa3343b3cd2bc8cf59e\Microsoft.WSMan.Management.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        617472              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\e439c12c9e047a5252fc0870a0edad57\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2012-06-15 07:17 . 2012-06-15 07:17        215040              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\d7f1a24f4ab28ff9859120d65b72d688\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        179200              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\ce7dab699ded0a263c9aae0c8bdedcc9\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        337408              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\cbaa2c3a4e91129440a784827d1d26bb\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        285184              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a9f6c9b07b5450581322eada5a828b89\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        303104              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\913fce36cb050a091d692e8d090ee3ae\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        161280              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\787f2a870ba9d0895455ccd8578f1a20\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        133120              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\783a4e24531ee190eb826509f8cc2a45\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        112128              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\6c7ccf3f7fa572b45a31097585b9be71\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2012-06-15 07:17 . 2012-06-15 07:17        134144              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\5cf1523c2ba7740089a3dc1b543e7ddc\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        161792              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\5cdbdb1386f3060d12c31352910d59d3\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        145920              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\54aa66ae5ce18ece1133102c5de4a105\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        650752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4bc310439d3df869c82d0064c3e1180a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        363008              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\3d016be961a0f7e1941e0ceca394ed9d\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
+ 2012-06-15 07:17 . 2012-06-15 07:17        196608              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\3862dc75c8e0945fea9016eb9258b63e\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        386560              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1e639225ba30d7f182b893ddacea506b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        291328              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d4c36b363fcd1ca494218e74ba606e99\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        786432              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ba2ca86f5d270f493501848843d2f227\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        729088              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\607324a312b1c6d7fbede8300e8cee91\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        167424              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1f1185444c8a12ace85ba4c2d49f41f8\Microsoft.PowerShell.Security.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        515584              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\12715b7e3e89758161053520b57764b2\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        167424              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\e1a8a0ddc283db83528f343abaa74ac5\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        854528              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\b70bc4c745dd9a2e5e90e46bcedfe1dc\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        816128              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\78dd5caf7a28d0b1b122483818205cf0\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2012-06-15 07:17 . 2012-06-15 07:17        152064              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\51ad304ce7ae5aa72a6afdbce7661195\Microsoft.Office.Tools.v9.0.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        375808              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\67ba34f9106034f481597e4e7ce3e197\Microsoft.Office.Interop.InfoPath.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        114688              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\20ff7a71560e4becdc686b2c2ab73da5\Microsoft.Office.InfoPath.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        206848              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\1f513d51b62f58e6152da6c69354c3e4\Microsoft.Office.InfoPath.Client.Internal.Host.Interop.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        268800              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.Bu#\3b7e2d4895e100c465d87d12a7d4fab2\Microsoft.Office.BusinessApplications.Diagnostics.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        561664              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\622b582866fca37f113bd97ae4c6d1f6\Microsoft.ManagementConsole.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        343552              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessD#\fffcd9e63e3068533e45ba0dde5d17be\Microsoft.BusinessData.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        175104              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\7e59b3b84ca3c61adfc0dc74a65ea177\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        144384              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\07e346ee0e3f7433f2de7a72fadd6713\Microsoft.Build.Utilities.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        839680              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\432160eff3b1f9301c6a74c2e647e03d\Microsoft.Build.Engine.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        222720              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\8297305de86377d0070a983d99a7f943\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        364032              c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\541a5bb4d0f8490e506f885a4b435566\mcstoredb.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        553472              c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\02577b78c6ed2f9bda301de888dccad8\EventViewer.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        693248              c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\5ae5c6732ef8e7115baaeb66fd69cdd2\ehRecObj.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        875520              c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\c4a5ce4f89c53b9601d13d22d01cf0bf\ehiVidCtl.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        442880              c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\cbf3a07d3ab873b19f47d6a24f06c796\ehiProxy.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        161280              c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\5cc4a5672758f4732ef430b3431f47fc\ehiExtens.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        254464              c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\a6b8eb80cfbdd927b2fa4ecb69fc0209\ehExtHost32.ni.exe
+ 2012-05-13 01:45 . 2012-05-13 01:45        220672              c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        410112              c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\3912b69593af13d0922279a063e5af66\ComSvcConfig.ni.exe
+ 2012-05-13 01:45 . 2012-05-13 01:45        621568              c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\e1c3540ffb669448747187f76c6ebe82\BDATunePIA.ni.dll
+ 2011-12-03 07:57 . 2010-11-13 00:08        434176              c:\windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.Resources.dll
- 2011-12-03 07:57 . 2010-11-12 23:26        434176              c:\windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.Resources.dll
+ 2012-06-14 03:31 . 2012-04-23 22:35        630784              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-06-14 03:32 . 2010-11-12 23:26        544768              c:\windows\assembly\GAC_MSIL\System.Design.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Design.Resources.dll
- 2009-11-13 23:28 . 2009-11-13 23:28        544768              c:\windows\assembly\GAC_MSIL\System.Design.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Design.Resources.dll
- 2011-12-01 08:37 . 2010-11-05 01:53        163840              c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-05-12 06:48 . 2012-01-04 02:50        163840              c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
- 2011-12-01 08:41 . 2010-11-05 01:53        532480              c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        532480              c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2011-12-03 07:57 . 2010-11-13 00:08        315392              c:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
- 2011-12-03 07:57 . 2010-11-12 23:26        315392              c:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
+ 2012-02-04 07:56 . 2012-03-28 06:24        877952              c:\windows\assembly\GAC_MSIL\HP.SupportFramework\1.0.0.0__2a4860322af7ba08\HP.SupportFramework.dll
- 2011-12-01 08:40 . 2010-11-05 01:52        358912              c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-12 06:48 . 2012-02-10 23:29        358912              c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        372736              c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2011-12-01 08:40 . 2010-11-05 01:53        372736              c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2007-05-31 08:12 . 2007-05-31 08:12        2061704              c:\windows\WindowsMobile\Microsoft.WindowsMobile.DeviceCenter.dll
+ 2012-08-15 08:42 . 2012-06-27 05:53        1231360              c:\windows\SysWOW64\urlmon.dll
- 2012-02-15 13:03 . 2011-12-16 07:54        1231360              c:\windows\SysWOW64\urlmon.dll
+ 2012-06-14 03:32 . 2012-05-04 10:03        3913072              c:\windows\SysWOW64\ntoskrnl.exe
+ 2012-06-14 03:32 . 2012-05-04 10:03        3968368              c:\windows\SysWOW64\ntkrnlpa.exe
- 2012-03-14 14:05 . 2011-11-19 14:50        3968368              c:\windows\SysWOW64\ntkrnlpa.exe
- 2011-12-01 08:41 . 2010-11-20 12:19        1390080              c:\windows\SysWOW64\msxml6.dll
+ 2012-07-11 05:45 . 2012-06-06 05:05        1390080              c:\windows\SysWOW64\msxml6.dll
- 2011-12-01 08:40 . 2010-11-20 12:19        1236992              c:\windows\SysWOW64\msxml3.dll
+ 2012-07-11 05:45 . 2012-06-06 05:05        1236992              c:\windows\SysWOW64\msxml3.dll
+ 2012-06-14 03:32 . 2012-04-07 11:26        2342400              c:\windows\SysWOW64\msi.dll
+ 2012-08-15 08:42 . 2012-06-27 05:51        6027776              c:\windows\SysWOW64\mshtml.dll
+ 2012-08-27 04:20 . 2012-08-27 04:20        9813704              c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
+ 2012-08-27 04:20 . 2012-08-27 04:20        1807560              c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
- 2012-02-15 13:03 . 2011-12-16 07:52        2073600              c:\windows\SysWOW64\iertutil.dll
+ 2012-08-15 08:42 . 2012-06-27 05:50        2073600              c:\windows\SysWOW64\iertutil.dll
+ 2012-05-12 06:49 . 2012-03-03 05:31        1077248              c:\windows\SysWOW64\DWrite.dll
- 2012-03-14 07:31 . 2012-02-10 05:38        1077248              c:\windows\SysWOW64\DWrite.dll
+ 2012-06-14 03:32 . 2012-04-24 04:36        1158656              c:\windows\SysWOW64\crypt32.dll
+ 2012-06-22 06:18 . 2012-06-02 22:15        2622464              c:\windows\system32\wucltux.dll
+ 2012-06-22 06:18 . 2012-06-02 22:19        2428952              c:\windows\system32\wuaueng.dll
+ 2011-11-29 10:57 . 2010-11-20 13:27        1576448              c:\windows\system32\spool\drivers\x64\XpsSvcs.dll
- 2011-11-29 10:57 . 2009-07-14 01:41        1576448              c:\windows\system32\spool\drivers\x64\XpsSvcs.dll
+ 2012-06-14 03:32 . 2012-05-04 11:06        5559664              c:\windows\system32\ntoskrnl.exe
+ 2012-07-11 05:45 . 2012-06-06 06:06        2004480              c:\windows\system32\msxml6.dll
- 2011-12-01 08:41 . 2010-11-20 13:27        2004480              c:\windows\system32\msxml6.dll
+ 2012-07-11 05:45 . 2012-06-06 06:06        1881600              c:\windows\system32\msxml3.dll
+ 2012-06-14 03:32 . 2012-04-07 12:31        3216384              c:\windows\system32\msi.dll
+ 2012-05-12 06:49 . 2012-03-03 06:35        1544704              c:\windows\system32\DWrite.dll
+ 2011-07-22 14:47 . 2011-07-22 14:47        1093632              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\ZuneDriver.dll
+ 2011-06-06 11:49 . 2011-06-06 11:49        2152176              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\WUDFUpdate_01009.dll
+ 2011-06-06 11:49 . 2011-06-06 11:49        1721576              c:\windows\system32\DriverStore\FileRepository\zune.inf_amd64_neutral_bae1a2a65e3c2cfb\WdfCoInstaller01009.dll
+ 2011-06-06 11:49 . 2011-06-06 11:49        1721576              c:\windows\system32\DriverStore\FileRepository\wmzuneserusb.inf_amd64_neutral_0612991c2e85953e\WdfCoInstaller01009.dll
+ 2012-02-15 10:01 . 2012-02-15 10:01        4547944              c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_509d7a31d0ee45f2\usbaaplrc.dll
+ 2011-08-02 16:38 . 2011-08-02 16:38        1721576              c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_bf785db627c6d127\wdfcoinstaller01009.dll
+ 2009-07-14 04:21 . 2009-07-14 04:21        1721576              c:\windows\system32\DriverStore\FileRepository\android_usb.inf_amd64_neutral_05094f7e231a9498\wdfcoinstaller01009.dll
+ 2012-06-14 03:32 . 2012-04-24 05:37        1462272              c:\windows\system32\crypt32.dll
+ 2012-07-11 05:44 . 2012-06-06 06:02        1133568              c:\windows\system32\cdosys.dll
- 2011-12-01 08:38 . 2010-11-20 13:25        1133568              c:\windows\system32\cdosys.dll
- 2009-07-14 04:45 . 2012-03-15 07:28        7100066              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-09-18 06:04        7100066              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2011-11-28 19:55 . 2012-09-18 21:15        4420868              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1154562761-1198328465-1791081454-1000-8192.dat
+ 2011-11-29 09:45 . 2012-08-03 20:39        1117552              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1154562761-1198328465-1791081454-1000-12288.dat
+ 2012-01-19 11:08 . 2012-01-19 11:08        1369872              c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 11:08 . 2012-01-19 11:08        6429992              c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 11:52 . 2012-01-19 11:52        3825952              c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
+ 2012-03-15 11:17 . 2012-03-15 11:17        5029672              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        3512072              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        3512072              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
- 2011-11-21 22:57 . 2011-11-21 22:57        4970768              c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2011-12-15 12:01 . 2011-12-15 12:01        4970768              c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2011-12-15 12:01 . 2011-12-15 12:01        1455376              c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
- 2011-11-21 22:57 . 2011-11-21 22:57        1455376              c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
+ 2011-12-15 12:01 . 2011-12-15 12:01        1515792              c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
- 2011-11-21 22:57 . 2011-11-21 22:57        1515792              c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
+ 2011-12-15 12:01 . 2011-12-15 12:01        1512712              c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
- 2011-11-21 22:57 . 2011-11-21 22:57        9793280              c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
+ 2011-12-15 12:01 . 2011-12-15 12:01        9793280              c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
+ 2012-05-12 06:48 . 2012-02-10 23:29        2256152              c:\windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
- 2011-12-03 07:57 . 2011-03-29 22:32        5025792              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
+ 2012-06-14 03:32 . 2012-03-21 22:30        5025792              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
- 2012-02-15 13:04 . 2011-10-31 23:15        3190784              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
+ 2012-05-12 06:48 . 2012-01-04 03:34        3190784              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
- 2011-12-01 08:37 . 2010-11-05 01:56        4927488              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll
+ 2012-06-14 03:32 . 2012-03-21 22:30        4927488              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll
+ 2012-05-12 06:49 . 2012-01-04 03:34        9992464              c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
+ 2012-05-12 06:49 . 2012-01-04 03:34        4567040              c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
- 2011-12-03 07:57 . 2011-07-08 22:31        4567040              c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-05-12 06:48 . 2012-01-04 03:34        1577232              c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
+ 2012-05-12 06:48 . 2012-01-04 03:34        1756432              c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
+ 2012-01-19 11:08 . 2012-01-19 11:08        1369872              c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 11:08 . 2012-01-19 11:08        6429992              c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 11:08 . 2012-01-19 11:08        3790112              c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
+ 2012-03-15 11:17 . 2012-03-15 11:17        5029672              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        3512072              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        3512072              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        5201168              c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        5201168              c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        1143568              c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        1143568              c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2011-12-15 11:08 . 2011-12-15 11:08        6727424              c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
- 2011-11-21 21:31 . 2011-11-21 21:31        6727424              c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        1737496              c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
+ 2012-06-14 03:32 . 2012-03-21 22:32        5025792              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2011-12-03 07:57 . 2011-03-29 22:33        5025792              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2012-05-12 06:48 . 2012-01-04 02:51        3190784              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2012-02-15 13:04 . 2011-10-31 23:16        3190784              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2012-06-14 03:32 . 2012-03-21 22:32        4927488              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
- 2011-12-01 08:37 . 2010-11-05 01:58        4927488              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2012-05-12 06:49 . 2012-01-04 02:51        5925136              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-12-03 07:57 . 2011-07-08 22:33        4550656              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2012-05-12 06:48 . 2012-01-04 02:50        4550656              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1369872              c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        3512072              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        3512072              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        2207568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        2207568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        5029672              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        1711496              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1711496              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        6097256              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        6097256              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1026936              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        1026936              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        4464480              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        4464480              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        1354584              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1354584              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1199968              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        1199968              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1462648              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        1462648              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        6429992              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        3116376              c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        3116376              c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        3825952              c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        4970768              c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        4970768              c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        3563408              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        3563408              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2012-03-13 14:48 . 2012-03-13 14:48        2975064              c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        2975064              c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        3790112              c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2012-03-13 14:48 . 2012-03-13 14:48        5201168              c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        5201168              c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        2989456              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2012-03-13 14:49 . 2012-03-13 14:49        2989456              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-08-29 20:39 . 2012-08-29 20:39        3463680              c:\windows\Installer\c70c2.msp
+ 2012-01-22 08:20 . 2012-01-22 08:20        1707520              c:\windows\Installer\49598.msp
+ 2012-02-22 13:16 . 2012-02-22 13:16        2221568              c:\windows\Installer\49576.msp
+ 2012-03-07 13:02 . 2012-03-07 13:02        1939456              c:\windows\Installer\49565.msp
+ 2012-04-01 14:27 . 2012-04-01 14:27        3463168              c:\windows\Installer\4953d.msp
+ 2012-02-17 01:50 . 2012-02-17 01:50        1236480              c:\windows\Installer\49525.msp
+ 2012-03-21 03:57 . 2012-03-21 03:57        1591808              c:\windows\Installer\49505.msp
+ 2012-04-23 08:32 . 2012-04-23 08:32        3460096              c:\windows\Installer\3f0eac6.msp
+ 2012-04-04 20:38 . 2012-04-04 20:38        2831360              c:\windows\Installer\3f0eaae.msp
+ 2012-04-04 20:38 . 2012-04-04 20:38        3620864              c:\windows\Installer\3f0ea6a.msp
+ 2012-04-28 19:43 . 2012-04-28 19:43        8459264              c:\windows\Installer\3f0ea37.msp
+ 2012-03-15 11:12 . 2012-03-15 11:12        4968960              c:\windows\Installer\3f0ea2d.msp
+ 2012-03-15 11:11 . 2012-03-15 11:11        1989632              c:\windows\Installer\3f0e9fb.msp
+ 2012-06-26 16:03 . 2012-06-26 16:03        3875840              c:\windows\Installer\28234e6.msp
+ 2012-07-19 00:45 . 2012-07-19 00:45        3464704              c:\windows\Installer\28234dc.msp
+ 2012-07-04 06:04 . 2012-07-04 06:04        1292288              c:\windows\Installer\28234c4.msp
+ 2012-07-04 06:12 . 2012-07-04 06:12        4772352              c:\windows\Installer\28234b9.msp
+ 2012-07-04 06:09 . 2012-07-04 06:09        1284096              c:\windows\Installer\28234a0.msp
+ 2012-07-04 06:01 . 2012-07-04 06:01        9082368              c:\windows\Installer\2823488.msp
+ 2012-07-04 05:58 . 2012-07-04 05:58        6163456              c:\windows\Installer\2823467.msp
+ 2012-05-17 00:58 . 2012-05-17 00:58        3462144              c:\windows\Installer\1d19cee.msp
+ 2012-04-22 20:46 . 2012-04-22 20:46        1187328              c:\windows\Installer\1d19cd7.msp
+ 2012-03-15 12:26 . 2012-03-15 12:26        4212736              c:\windows\Installer\1d19ccd.msp
+ 2012-08-07 15:59 . 2012-08-07 15:59        6733824              c:\windows\Installer\17c2ea.msi
+ 2012-05-10 15:12 . 2012-05-10 15:12        1821696              c:\windows\Installer\17c2c5.msi
+ 2012-06-19 23:29 . 2012-06-19 23:29        5262848              c:\windows\Installer\17bdbe2.msp
+ 2012-06-20 00:00 . 2012-06-20 00:00        3461120              c:\windows\Installer\17bdbc7.msp
+ 2012-04-04 23:56 . 2012-04-04 23:56        2820096              c:\windows\Installer\17bdbaf.msp
+ 2012-04-04 23:54 . 2012-04-04 23:54        8301056              c:\windows\Installer\17bdb97.msp
+ 2012-06-20 00:06 . 2012-06-20 00:06        1839104              c:\windows\Installer\17bdb7d.msp
+ 2012-06-12 12:24 . 2012-06-12 12:24        1376768              c:\windows\Installer\14861d7.msi
+ 2011-11-29 11:01 . 2012-09-16 20:50        1479520              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        1479520              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        1858400              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        1858400              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        3792736              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pptico.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        3792736              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2011-11-29 11:01 . 2012-09-16 20:50        1449312              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2011-11-29 11:01 . 2012-03-14 13:59        1449312              c:\windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-11-13 15:25 . 2012-04-13 15:29        1099104              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\WksSb.exe
- 2009-11-13 15:25 . 2011-11-29 17:01        1099104              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\WksSb.exe
+ 2009-11-13 15:25 . 2012-04-13 15:29        1242464              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\wksdb.exe
- 2009-11-13 15:25 . 2011-11-29 17:01        1242464              c:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\wksdb.exe
+ 2010-10-22 16:12 . 2010-10-22 16:12        5496688              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\IPEDITOR.DLL
+ 2011-01-12 19:33 . 2011-01-12 19:33        5867896              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\IPDESIGN.DLL
+ 2010-10-22 16:12 . 2010-10-22 16:12        1734000              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\INFOPATH.EXE
+ 2011-03-17 00:22 . 2011-03-17 00:22        4301184              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\GRAPH.EXE
+ 2010-10-22 17:55 . 2010-10-22 17:55        3049376              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACEWDAT.DLL
+ 2011-03-11 16:46 . 2011-03-11 16:46        2194312              c:\windows\Installer\$PatchCache$\Managed\00004119110000000000000000F01FEC\14.0.6029\ACECORE.DLL
+ 2011-08-17 08:49 . 2011-08-17 08:49        4683624              c:\windows\Installer\$PatchCache$\Managed\00002109020070400000000000F01FEC\12.0.6612\WRD12CNV.DLL
+ 2011-07-07 01:58 . 2011-07-07 01:58        1616240              c:\windows\Installer\$PatchCache$\Managed\00002109020070400000000000F01FEC\12.0.6612\OGL.DLL

Weiter mit Teil 3/3 ==>

Rai3 19.09.2012 15:22

Und zuletzt noch Teil 3/3
Code:

+ 2012-05-13 01:14 . 2012-05-13 01:14        5237248              c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e41f5739292f4771c64a55940369efd2\WindowsBase.ni.dll
+ 2012-06-15 10:05 . 2012-06-15 10:05        5237248              c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e286701acf74012d3aa4a21953f03b6b\WindowsBase.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        1430016              c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\6ee9d76d9f1e618cd6fb94b13355bcc9\UIAutomationClientsideProviders.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        7037952              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\28ca4f076264ab07f1d00a6c9623dc49\System.Xml.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        2449408              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\df013cbfec0defc7e9997cdaa90b89bc\System.Xaml.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        5645824              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\9e50e3bca6cb19f9acab815d46f5e7e5\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-06-15 10:08 . 2012-06-15 10:08        5645824              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\950f64ba9fb22ca06c5b2b9cf6f5f4b4\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        2236416              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\bc6df78c506c89659ab7be738179b2ba\System.Web.Services.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        2735616              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\cd7c3aed4408c3554c30a8f0236b90e1\System.Speech.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        1918976              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\94289b88c5b494f572cd7114fa995487\System.ServiceModel.Activities.ni.dll
+ 2012-05-13 01:21 . 2012-05-13 01:21        1579008              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\2dbc7aabd92cc0d470acb455c498d919\System.ServiceModel.Discovery.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        3412992              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\affb28e2d9cc3c19de0758e7e8c68e8f\System.Runtime.Serialization.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        1348096              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\b37e6f4b1d742031f328504eb99d0f6c\System.Runtime.DurableInstancing.ni.dll
+ 2012-06-15 10:07 . 2012-06-15 10:07        1467392              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\d2de16284459454472a6875185c64d08\System.Printing.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        1467392              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\682ea473b36fc9043d982c4f5a667568\System.Printing.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        1470464              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\b83f2453b4538b2e80fe09cfd94dce00\System.Management.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        1416192              c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\60bf6251873ef465abcebeb9a24b7932\System.IdentityModel.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        1098752              c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        2303488              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\dadeee26c90fecbf3196eba10dc077b4\System.Drawing.ni.dll
+ 2012-06-15 10:06 . 2012-06-15 10:06        2305024              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\1225ef41527a975de83f22328d0a3b93\System.Drawing.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        1217024              c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\a68116468a194678fd04167067134712\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        1622528              c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\3a737af86a6a819af97a6d1a04c0e944\System.DirectoryServices.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        2403328              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\f20144fba069563333d0f6be2e0b6e06\System.Deployment.ni.dll
+ 2012-06-15 10:07 . 2012-06-15 10:07        2403328              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\ad9ff5d55f7ea22e80c39e0ff0240984\System.Deployment.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        8601600              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\0ec8effb7b9d03ae69d37922813bc880\System.Data.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        3390976              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\0eb72df497fad5c273ff16f88b0fb950\System.Data.SqlXml.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        1799168              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\536e12016ad3adc78e0708b77e6b9219\System.Data.Services.Client.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        3386368              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\86553c1d7f3e66c17fc3e0274de7a2de\System.Data.Linq.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        1257472              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\6aea67f24827961ce1d48356715389d8\System.Configuration.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        1007616              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\eac19ca5a18a6d08cd247e68b618ba68\System.ComponentModel.Composition.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        5695488              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\3869077874ba987242c791b3a18b2f8b\System.Activities.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        5048832              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\a7c19841c70fbce3b17ad3a46ee410d8\System.Activities.Presentation.ni.dll
+ 2012-06-15 10:07 . 2012-06-15 10:07        5048832              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\707f90689caf41ad429bf3ad373503cb\System.Activities.Presentation.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        2064896              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\96083298999a677341c98fc2bf01b248\System.Activities.Core.Presentation.ni.dll
+ 2012-05-13 01:18 . 2012-05-13 01:18        4233216              c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\fe1704ff12348776e6b70dd4a2c69163\ReachFramework.ni.dll
+ 2012-06-15 10:07 . 2012-06-15 10:07        4233216              c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\16c9569b75a9f47c38b60ba733936e1a\ReachFramework.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        2056704              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\b0b05b1ecbfb813474f685de13027585\PresentationUI.ni.dll
+ 2012-06-15 10:06 . 2012-06-15 10:06        2056704              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\9c3d6b3ddef66cac069b6ab1fec514f8\PresentationUI.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        1843712              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e4d308f69077903e24de92fe4fc06d29\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        1843712              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\a36cd27bd492b55a5f443a4b4029f569\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        2317312              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\93536d93a44ce7d5a60faf1aeb55f49e\Microsoft.VisualBasic.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        2317312              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\70e2694fe050bd480b9f61f935ca2da5\Microsoft.VisualBasic.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        1623040              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\16425c121db8083cbaa51f619c9e51e7\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        1526784              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\5284682fcf04815a86233bcaf696da66\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        2035200              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\dcf5f8fda71421c771c20f95f0deb3bb\Microsoft.Office.Tools.Excel.Implementation.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        1070080              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\8da91be67f85f2d15c39ff4857bf123e\Microsoft.Office.Tools.Word.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        1470464              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\5440b9f8109c45d2b291effaecb843da\Microsoft.Office.Tools.Word.Implementation.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        1470464              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\317b22e8057114acda41eab332cdc76a\Microsoft.Office.Tools.Word.Implementation.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        1070080              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\2addc9e043f4007adc64e3a617c780e0\Microsoft.Office.Tools.Word.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        1118208              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\0eb383b1584a85ff34e528f5b5baffbe\Microsoft.Office.Tools.Common.Implementation.ni.dll
+ 2012-05-13 01:14 . 2012-05-13 01:14        1118208              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\0c67944e3750a5ba5dcf6dd0bed5cb3d\Microsoft.Office.Tools.Common.Implementation.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        2035200              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\0b603091e974a68414f405af8e110955\Microsoft.Office.Tools.Excel.Implementation.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        3313664              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\4b1d24a96b3882f9e77445e48a7c59ee\Microsoft.JScript.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        2009600              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\1ff62486cdefbfc2dab41b686a9aa4e2\Microsoft.CSharp.ni.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        3858432              c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        1063424              c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\24ed0e1df6a605cdb2088f87ae2ab8ff\UIAutomationClientsideProviders.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        9091584              c:\windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        5617664              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        1782272              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        4587008              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\7f0476e4df01ca2219f7db531408e91c\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        1885696              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\b37cc0aa41e7feaba9f290da4da91d71\System.Web.Services.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        2012160              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\f368c85283c4e6c9650dd1c8d369dcc5\System.Speech.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        1140736              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ec057796972ce41b751eaa3a8306fbcb\System.ServiceModel.Discovery.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        1393152              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\5055b60e339143bbace5871f5fe4b114\System.ServiceModel.Activities.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        2647040              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        1021952              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\79ac99fe5274fb82ffcff2c15f71854c\System.Runtime.DurableInstancing.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        1060864              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\f87f8bc0bc9563096150f23f6c220e7b\System.Printing.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        1218560              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        1072640              c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\bd28f26b18b8ffeee1a0fbaa98f5810e\System.IdentityModel.ni.dll
+ 2012-06-14 14:53 . 2012-06-14 14:53        1666048              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        1172992              c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\0fe1e56d17858b6156a3a46330f75f27\System.DirectoryServices.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        1880064              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\e899cda47704280f54949c69b78c55cc\System.Deployment.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        6815232              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\99d0f7ba920eea1117e45dcd9fec0eb5\System.Data.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        2550272              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\fdb98c6d783fe167c1dc0022f27b7cd6\System.Data.SqlXml.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        1343488              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\b894a1df3e6d58ada8f1aa303465ca23\System.Data.Services.Client.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        2517504              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\82c0c56ff8259e1440cfd0d5727a26d8\System.Data.Linq.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        7069184              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        4129280              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\51025a1c89f6fd752a5396a059d608b2\System.Activities.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        3757568              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\36299fad6b7b591cfb6bd9e50dbd33df\System.Activities.Presentation.ni.dll
+ 2012-05-13 01:23 . 2012-05-13 01:23        1546752              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\66893548d2b2cad29cabf3b3578f356f\System.Activities.Core.Presentation.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        2906624              c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\442af6f7c8b447bdec3ad8d23da89c5a\ReachFramework.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        1641984              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\cf455da9b8fedf66767c1a7ab3eea9c9\PresentationUI.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        1172480              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\42a7f127f3fda82fb12c6a6e144d08c1\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        1139712              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2ed0173a2e75b1a3943bd2d96649a50c\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        1838080              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\09c2f8f606e09d85cfe6e0ad89fbe729\Microsoft.VisualBasic.ni.dll
+ 2012-05-13 01:22 . 2012-05-13 01:22        1085952              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\9a37f4e64ce5b856ac3892fef064c7de\Microsoft.Transactions.Bridge.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        1551872              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\7cfb808ac13b9432c5b771d64ff37f8d\Microsoft.Office.Tools.Excel.Implementation.ni.dll
+ 2012-06-15 07:20 . 2012-06-15 07:20        1117696              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\6527620d41718b44e7a784b20255835a\Microsoft.Office.Tools.Word.Implementation.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        2452480              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\cfcc92c125ddfaabad24abe61cfc0471\Microsoft.JScript.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        1616896              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\9912b6d76c1017b5af6ef24730f550ca\Microsoft.CSharp.ni.dll
+ 2012-07-25 13:49 . 2012-07-25 13:49        5660672              c:\windows\assembly\NativeImages_v2.0.50727_64\ZuneShell\ab8fc72e8a9373dc5138ddd5e971949b\ZuneShell.ni.dll
+ 2012-07-25 13:49 . 2012-07-25 13:49        3635712              c:\windows\assembly\NativeImages_v2.0.50727_64\ZuneDBApi\4e166bf1c0246de09382a8013e1d0164\ZuneDBApi.ni.dll
+ 2012-05-13 01:38 . 2012-05-13 01:38        4962816              c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\4bcc5a6e9e9d25e068fc304bd7eda6af\WindowsBase.ni.dll
+ 2012-07-25 13:49 . 2012-07-25 13:49        6220288              c:\windows\assembly\NativeImages_v2.0.50727_64\UIX\be6346434fc9c9ea2f97833d26354308\UIX.ni.dll
+ 2012-07-25 13:49 . 2012-07-25 13:49        2632704              c:\windows\assembly\NativeImages_v2.0.50727_64\UIX.RenderApi\cd060f5dbb750fe0f4c150e5d8773b5b\UIX.RenderApi.ni.dll
+ 2012-05-13 01:55 . 2012-05-13 01:55        1459712              c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\783df1ee260d3df406fa80afa38502d4\UIAutomationClientsideProviders.ni.dll
+ 2012-05-13 01:37 . 2012-05-13 01:37        6948864              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\24d1b7ccbedaa3602bae6a6acea9929e\System.Xml.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        1818112              c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\70cc5e8a5a3372fe0b104c1b20392cd2\System.WorkflowServices.ni.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        2711040              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\aa638ba79250284eb4af4adaa4a4117b\System.Workflow.Runtime.ni.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        5957632              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\996dc2af3b9e5c111130935f298908c6\System.Workflow.ComponentModel.ni.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        3895296              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\178797db84abae2eeaed835bd28ca52c\System.Workflow.Activities.ni.dll
+ 2012-06-14 19:39 . 2012-06-14 19:39        2292224              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\a32734087cd0db5607d5744ca63235d7\System.Web.Services.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        3336704              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\af7689e8cbec5d2755497be23c30e293\System.Web.Mobile.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        3044352              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\768ea257d75839979b4efb2d49d653f6\System.Web.Extensions.ni.dll
+ 2012-06-15 10:04 . 2012-06-15 10:04        1155072              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\2c47bc5d426a7cf9ffef1425eda08184\System.Web.Extensions.Design.ni.dll
+ 2012-05-13 01:55 . 2012-05-13 01:55        2727936              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\ca51f026916139f886519fdf6d6c73e9\System.Speech.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        2312704              c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\56ee9b5f220583c1c7374a61ad904044\System.ServiceModel.Web.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        3073536              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\265531568722647aab229a2cec195b3d\System.Runtime.Serialization.ni.dll
+ 2012-05-13 01:40 . 2012-05-13 01:40        1022976              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\2a02b172fa4cf3d93ce7388b67b2a199\System.Runtime.Remoting.ni.dll
+ 2012-06-14 14:44 . 2012-06-14 14:44        1463808              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\b964519964d302b4977e1380d8d15f1a\System.Printing.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        1472000              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\fd4a8227569e64d657b80483da8ffe78\System.Management.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        1444352              c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\d1f21a29e79e73b5401fae156f339f67\System.IdentityModel.ni.dll
+ 2012-05-13 01:40 . 2012-05-13 01:40        1081344              c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.ni.dll
+ 2012-06-14 14:40 . 2012-06-14 14:40        2318848              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\222eb8aa336953a6b0216db2b0c4770d\System.Drawing.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        1230848              c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\39d16229a3d5c6e7c1594ef10758bf75\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-13 01:40 . 2012-05-13 01:40        1640448              c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\152ef61928f1c300fdad8fa6d5905880\System.DirectoryServices.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        2444288              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\6e4e9b07f376d445df1718c0011fa99b\System.Deployment.ni.dll
+ 2012-05-13 01:40 . 2012-05-13 01:40        8681472              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\ea1848ec07c70f3d3c3445f4fbdae87a\System.Data.ni.dll
+ 2012-05-13 01:38 . 2012-05-13 01:38        3463680              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7f6f74f1cc0ea6c40a2d6707b12af818\System.Data.SqlXml.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        2805760              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0679fe5f3f9164f499e50cdade962ba3\System.Data.Services.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        1868288              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\2e9de1acfb7974cad94b747442ca325f\System.Data.Services.Client.ni.dll
+ 2012-05-13 01:41 . 2012-05-13 01:41        1506816              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\97429a1c70c94c49850be3f944a32a2e\System.Data.OracleClient.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        3480576              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\2ec3d436b861d35c586b710a570e170d\System.Data.Linq.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        1080320              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7b5364bc524988f7ca5b8c20a24119d\System.Data.Entity.Design.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        3315200              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\766ce7ee1a2e4f2a85fd90e7572f5d53\System.Core.ni.dll
+ 2012-05-13 01:37 . 2012-05-13 01:37        1308160              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\193d03ca60573c92f92d9b07fa5bc243\System.Configuration.ni.dll
+ 2012-06-14 14:44 . 2012-06-14 14:44        3116032              c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\1f88a3693c8ddd527a130aff49dc58b3\ReachFramework.ni.dll
+ 2012-06-14 19:39 . 2012-06-14 19:39        2109952              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\b91c32fab08ba62d8c7681cc596895be\PresentationUI.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        1884160              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\4fbff79b8ebf082d08c0080923ff5036\PresentationBuildTasks.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        3601920              c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\ac1ba76ed19d668ce53a74593f040453\Narrator.ni.exe
+ 2012-06-15 07:23 . 2012-06-15 07:23        2327552              c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\df2557ab1b8e4389d846e13dc82eba57\MMCEx.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        7970304              c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\61812970c4743b686a67f28687e1dcb6\MIGUIControls.ni.dll
+ 2012-05-13 01:53 . 2012-05-13 01:53        1877504              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\1dcc7a3940f5e4be8da3dd0b66bc38c0\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        2131968              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\1586ee919f86130df9771cf9b8d95d3a\Microsoft.VisualBasic.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        1598976              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\28ba52bc122353647f1b547506e2df7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        1131008              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f5790625975320b1ffad63b476da9132\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        5350912              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\ca7e936eed0de2436d87b2601ee3a20a\Microsoft.PowerShell.Editor.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        2176512              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6caa366471176a065a96d77e8ba01eeb\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-06-15 07:23 . 2012-06-15 07:23        2105344              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\3040e2de07177c0a6a66a49de61fdc59\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        1186304              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\91391297ea9428993774313f05e98dd2\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        1875456              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\6ecfa88a42ba7c5c3a4580cd479d0d21\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        1093632              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\0929a1a8f19d58cca0ff9bf5f9086dc1\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        1170432              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c057be8bb6614cce013af3721fe34983\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        1516544              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b2afc0af3d89ae00e973b4e6e9db382c\Microsoft.MediaCenter.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        1508864              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\73bfbdccdc1b0ae87f70a0ec594fee3c\Microsoft.MediaCenter.Bml.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        8979456              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\653e1ee01f10d658d52ca42e17e74283\Microsoft.MediaCenter.UI.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        1142784              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\260d83ee2128a3388051cf416d4450b0\Microsoft.MediaCenter.Shell.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        3213312              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\094f6a515ca31504f96b4bad5848d692\Microsoft.JScript.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        2365952              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\dac69844e6333484159a4cf544190906\Microsoft.Ink.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        2218496              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\4b362e9e25c33e371f06403edec8849a\Microsoft.Build.Tasks.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        2682880              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\33730d136a34d2f4e56a0322f49ee9b6\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        1137152              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f1a0df6a86ceb708c5e50338f12b77ba\Microsoft.Build.Engine.ni.dll
+ 2012-05-13 01:51 . 2012-05-13 01:51        2544640              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\6b727c7aa69ae3e04a869908bfbae696\Microsoft.Build.Engine.ni.dll
+ 2012-06-15 07:21 . 2012-06-15 07:21        2801664              c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\cc4844e7242c1e35d145bf2439f944c5\mcstore.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        4088320              c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\596902addad034f4df2caf291b12d61d\mcepg.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        2184192              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\cdad46cd58389f53308b735e6f29ce1f\ehiVidCtl.ni.dll
+ 2012-05-13 01:50 . 2012-05-13 01:50        1201664              c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\0423915e377ec85d71ac216fafa77ab0\ehiProxy.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1105408              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b711e4f9c27aab65278296a924e29ee6\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        2002432              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\579e9f2d0d25b50996964b4976002535\WindowsLive.Writer.CoreServices.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        6394368              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\15957be56fa7f94a83dd1b1d61341c71\WindowsLive.Writer.PostEditor.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        3347968              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        1047552              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\3b452cde57280624e1085699fe8beb03\UIAutomationClientsideProviders.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        7967232              c:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        5452800              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        1358336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\e3e5aa45736b95804bf6bb7eca08a57b\System.WorkflowServices.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        1917952              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\88bfc62ac0195a8ae673c444a3339505\System.Workflow.Runtime.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        4516352              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\cfb739be21092d5b8f7b4fde529e6aaa\System.Workflow.ComponentModel.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        2994688              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\a815fffab98375c1919df68b5b292725\System.Workflow.Activities.ni.dll
+ 2012-06-14 19:37 . 2012-06-14 19:37        1840640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\761fd1afc17f11bf6d49c3a7d16465ca\System.Web.Services.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        2209792              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4a90802e36dee6e10d9bf54832cbf549\System.Web.Mobile.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        2404352              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\9d9e4f4a15abf23db8fd5767896dce7a\System.Web.Extensions.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        1917952              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\83053c3eeb3255672d84c1ddc0ce8ef3\System.Speech.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        1707008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        2347008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
+ 2012-06-14 14:46 . 2012-06-14 14:46        1044480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\991dbe40be5b114ed705bb5b48e6b330\System.Printing.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        1051136              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        8872960              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a8495b797e6f7adddc5811a4e1f97db5\System.Management.Automation.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        1083392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll
+ 2012-06-14 14:45 . 2012-06-14 14:45        1591808              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        1117184              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
+ 2012-06-14 19:36 . 2012-06-14 19:36        1806848              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        6611456              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        2508288              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e9774272e9fc6ca49e6c616a31783040\System.Data.SqlXml.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        2029568              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\3285887b33030a7ce453573d3bed4e95\System.Data.Services.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        1378816              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\330d3ad45a00455b537047183e128def\System.Data.Services.Client.ni.dll
+ 2012-05-13 01:43 . 2012-05-13 01:43        1116672              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\0f4e07fb8b1b7e7133a98f478856f70c\System.Data.OracleClient.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        2516992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\2fe1658f05b0a96fe25c956a31d27b06\System.Data.Linq.ni.dll
+ 2012-05-13 01:48 . 2012-05-13 01:48        9921536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        2297856              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
+ 2012-06-14 14:46 . 2012-06-14 14:46        2157056              c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\87f73de6e080d37be93adfc7d5c31d7a\ReachFramework.ni.dll
+ 2012-06-14 19:37 . 2012-06-14 19:37        1658368              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\163517c8a195fb48f7ef6ee17c585bdb\PresentationUI.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        1451520              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b3f13707cbd5d48aabaa9ef5264c8a30\PresentationBuildTasks.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        2623488              c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\17add09c98fa34255142d42697db53df\Narrator.ni.exe
+ 2012-06-15 07:19 . 2012-06-15 07:19        1545216              c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\21abde8efab609732b2ade3f05234e79\MMCEx.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        6438912              c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\0e7da0df83f0619e3b0e0a7d7ee05fa3\MIGUIControls.ni.dll
+ 2012-05-13 01:47 . 2012-05-13 01:47        1300992              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0849dd848383994c63dc00278f64ddae\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        1670144              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        1093120              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\cd9e47effec6549cdec61eb3aef99f7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        1681920              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\99ae5f32cd1dc3618659bc3c77f2b2a9\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        1704960              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\77b5496d214dd5034294b058c0bb0e8d\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-06-15 07:19 . 2012-06-15 07:19        3724288              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\72765e5fab12761eb6d3f58180fa34d7\Microsoft.PowerShell.Editor.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1354752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\63513a219edd166209b039f0681f1d59\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1787904              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\fb4866eac162b305cc84d1c7cc8da1f5\Microsoft.Office.InfoPath.Client.Internal.Host.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        1183744              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\6372f4d109a72f968a6a089ef5cfa23e\Microsoft.Office.Interop.InfoPath.SemiTrust.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1564672              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.Bu#\5190887d5ed2ef28d1596fd2f48bd935\Microsoft.Office.BusinessApplications.Runtime.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        4752384              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.Bu#\48c93c9b5095c25bc4fde40f25c014ea\Microsoft.Office.BusinessApplications.SyncServices.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        3238400              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.Bu#\2db98cd03e8f4be6c6b33bee3bdbfc30\Microsoft.Office.BusinessData.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        2091520              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.Bu#\2983eeeb5d0c013e215bf9fc069710a6\Microsoft.Office.BusinessApplications.RuntimeUi.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        6499840              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\8ce1d10f94b40f054017865757552f2d\Microsoft.MediaCenter.UI.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1009664              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7fab1ec8f5ed6a55a8a73b2c590bd7cd\Microsoft.MediaCenter.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        2335744              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\e3d2577e00aef6bc9b3e235eb83634f3\Microsoft.JScript.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1361408              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\4d381048e3b9c0914c0f72c6aa0a599d\Microsoft.Ink.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1620992              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3893fa9a19b52dee8b2cc424840d5d08\Microsoft.Build.Tasks.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        1970176              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\1d2250044b1ecff755e26ed12f6d27cb\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        1888768              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6b66f52dbd8f87e53c3c9a1de7ca5bba\Microsoft.Build.Engine.ni.dll
+ 2012-06-15 07:18 . 2012-06-15 07:18        2035712              c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\3a4e56a8d1075cf0af0619c383b3e592\mcstore.ni.dll
+ 2012-05-13 01:46 . 2012-05-13 01:46        3025920              c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\69b8de21b08c3412422c5918399ed702\mcepg.ni.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        1253376              c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2011-12-01 08:42 . 2010-11-05 01:53        1253376              c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2012-02-15 13:04 . 2011-10-31 23:16        3190784              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-12 06:48 . 2012-01-04 02:51        3190784              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-06-14 03:32 . 2012-03-21 22:32        5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-12-03 07:57 . 2011-03-29 22:33        5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-12-01 08:37 . 2010-11-05 01:58        4927488              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-06-14 03:32 . 2012-03-21 22:32        4927488              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        5283840              c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-05-12 06:48 . 2012-02-10 23:29        2256152              c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-05-12 06:48 . 2012-02-10 23:29        3998208              c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-05-12 06:49 . 2012-01-04 03:34        4567040              c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-12-03 07:57 . 2011-07-08 22:31        4567040              c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        1737496              c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
- 2011-12-01 08:42 . 2010-11-05 01:53        4218880              c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-05-12 06:48 . 2012-02-10 23:31        4218880              c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-12-03 07:57 . 2011-07-08 22:33        4550656              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-12 06:48 . 2012-01-04 02:50        4550656              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2007-05-31 15:22 . 2007-05-31 15:22        11752960              c:\windows\WindowsMobile\wmupdate.msi
+ 2012-07-11 05:44 . 2012-06-09 04:41        12873728              c:\windows\SysWOW64\shell32.dll
+ 2012-08-15 08:42 . 2012-06-27 05:50        11020800              c:\windows\SysWOW64\ieframe.dll
+ 2009-07-14 02:34 . 2012-09-18 06:00        10747904              c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-07-11 05:44 . 2012-06-09 05:43        14172672              c:\windows\system32\shell32.dll
- 2012-02-15 13:04 . 2012-01-04 10:44        14172672              c:\windows\system32\shell32.dll
+ 2012-08-27 04:20 . 2012-08-27 04:20        12812488              c:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll
+ 2007-05-31 15:22 . 2007-05-31 15:22        11752960              c:\windows\system32\DriverStore\FileRepository\wcerndis.inf_amd64_neutral_7f46c8a40bd97188\wmupdate.msi
+ 2012-06-18 04:36 . 2012-06-18 04:36        17379328              c:\windows\Installer\cd8dd99.msi
+ 2007-05-31 15:22 . 2007-05-31 15:22        11752960              c:\windows\Installer\6091792.msi
+ 2012-05-17 08:07 . 2012-05-17 08:07        53217792              c:\windows\Installer\4bc78.msp
+ 2012-03-07 13:03 . 2012-03-07 13:03        23710208              c:\windows\Installer\4955b.msp
+ 2012-01-19 12:20 . 2012-01-19 12:20        11997696              c:\windows\Installer\3f0eaa5.msp
+ 2011-12-15 12:54 . 2011-12-15 12:54        39732736              c:\windows\Installer\3f0ea97.msp
+ 2012-03-15 11:09 . 2012-03-15 11:09        17165312              c:\windows\Installer\3f0ea57.msp
+ 2012-03-15 11:11 . 2012-03-15 11:11        66812928              c:\windows\Installer\3f0ea14.msp
+ 2012-07-18 13:53 . 2012-07-18 13:53        10937344              c:\windows\Installer\2823446.msp
+ 2012-06-14 04:50 . 2012-06-14 04:50        52033024              c:\windows\Installer\1f77f0d.msi
+ 2012-06-14 04:49 . 2012-06-14 04:49        11071488              c:\windows\Installer\1f7733f.msi
+ 2012-06-14 04:49 . 2012-06-14 04:49        20403200              c:\windows\Installer\1f7730b.msi
+ 2012-06-14 04:47 . 2012-06-14 04:47        26820096              c:\windows\Installer\1f772ee.msi
+ 2011-08-05 15:14 . 2011-08-05 15:14        52322304              c:\windows\Installer\19eb53a.msi
+ 2011-08-03 18:53 . 2011-08-03 18:53        17324928              c:\windows\Installer\$PatchCache$\Managed\00002109020070400000000000F01FEC\12.0.6612\MSO.DLL
+ 2012-05-13 01:07 . 2012-05-13 01:07        11880448              c:\windows\assembly\NativeImages_v4.0.30319_64\System\935aea6e7eae16674abdd96a68ec97af\System.ni.dll
+ 2012-06-15 10:07 . 2012-06-15 10:07        17355264              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\e883d90a0210bf99ca88f3b4ade53a24\System.Windows.Forms.ni.dll
+ 2012-05-13 01:17 . 2012-05-13 01:17        17353728              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\401ebcc2dd54ce1e0d63a544f7ed7b8a\System.Windows.Forms.ni.dll
+ 2012-05-13 01:20 . 2012-05-13 01:20        24551936              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\c4cc7eb7733c4221c32caccfd66ae320\System.ServiceModel.ni.dll
+ 2012-05-13 01:19 . 2012-05-13 01:19        18479616              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\9df4e7ae75baa7bbb1af30c8061a6e9b\System.Data.Entity.ni.dll
+ 2012-05-13 01:13 . 2012-05-13 01:13        10440192              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\b64f213e823a591607c45fac4997801e\System.Core.ni.dll
+ 2012-06-15 10:06 . 2012-06-15 10:06        24407552              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a3c3789d54894008501ce5891f1eeb40\PresentationFramework.ni.dll
+ 2012-05-13 01:16 . 2012-05-13 01:16        24407552              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\34c2013b5f730680bd610d6a98d2977f\PresentationFramework.ni.dll
+ 2012-06-15 10:05 . 2012-06-15 10:05        15908864              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\9d69a7a407bbc43a1bcb2da603af5840\PresentationCore.ni.dll
+ 2012-05-13 01:15 . 2012-05-13 01:15        15908864              c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\4464e9df7184e3393b4cbb0f6dc286ba\PresentationCore.ni.dll
+ 2012-05-13 01:07 . 2012-05-13 01:07        19353600              c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\6087fce8f76d9af69af496cb10b7d1ee\mscorlib.ni.dll
+ 2012-06-14 14:54 . 2012-06-14 14:54        13198336              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
+ 2012-05-13 01:25 . 2012-05-13 01:25        18058752              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll
+ 2012-05-13 01:24 . 2012-05-13 01:24        13345792              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\7aa839fb16503243d6ae454ab334bcf4\System.Data.Entity.ni.dll
+ 2012-06-14 14:54 . 2012-06-14 14:54        18000896              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\199683f6e79076b634ee6cc0a82c0654\PresentationFramework.ni.dll
+ 2012-06-14 14:54 . 2012-06-14 14:54        11451904              c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll
+ 2012-05-13 01:08 . 2012-05-13 01:08        14412800              c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
+ 2012-05-13 01:37 . 2012-05-13 01:37        10624512              c:\windows\assembly\NativeImages_v2.0.50727_64\System\c40ec0f4cd203c880298f94c0427dd54\System.ni.dll
+ 2012-06-14 19:39 . 2012-06-14 19:39        17383424              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\dc5bb74eefdbf954cdfb70dd534d5564\System.Windows.Forms.ni.dll
+ 2012-06-14 19:39 . 2012-06-14 19:39        15270912              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\95f38e7485bbe2b73b6055c45196fedd\System.Web.ni.dll
+ 2012-05-13 01:49 . 2012-05-13 01:49        23913984              c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\f74b2d1b8cf279ff6bfe479f79e70fe9\System.ServiceModel.ni.dll
+ 2012-05-13 01:52 . 2012-05-13 01:52        11900928              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\00c4a761d0a5cafc00f34d763fe76ac4\System.Management.Automation.ni.dll
+ 2012-06-14 19:40 . 2012-06-14 19:40        13609472              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\582144c0ee317038621aebc626187b56\System.Design.ni.dll
+ 2012-05-13 01:54 . 2012-05-13 01:54        13760000              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\daaff9fe9c85fc171d426a3cb6766dbb\System.Data.Entity.ni.dll
+ 2012-06-14 14:43 . 2012-06-14 14:43        19198464              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\47054c4d5b7e522c21a9d57797410302\PresentationFramework.ni.dll
+ 2012-06-14 14:40 . 2012-06-14 14:40        16543232              c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\3a9d13514a8c4c710fa5ce8e9b5393fe\PresentationCore.ni.dll
+ 2012-05-13 01:37 . 2012-05-13 01:37        15570944              c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\f73f0a9c9a83dcd3ff428be509a7992f\mscorlib.ni.dll
+ 2012-06-15 07:22 . 2012-06-15 07:22        25470976              c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\0c1f96a4136efe532bbb8eb91d3de300\ehshell.ni.dll
+ 2012-06-14 19:36 . 2012-06-14 19:36        12436480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
+ 2012-06-14 19:37 . 2012-06-14 19:37        11833344              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\6dc7ae907d0a57aa19331225f5192ca7\System.Web.ni.dll
+ 2012-05-13 01:45 . 2012-05-13 01:45        17478656              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\107779ca2708d2b31b2e1560e47f6d15\System.ServiceModel.ni.dll
+ 2012-06-14 19:38 . 2012-06-14 19:38        10580480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7c144f89b1f8f292d6940a1b2f8ffbec\System.Design.ni.dll
+ 2012-06-14 14:46 . 2012-06-14 14:46        14340608              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
+ 2012-06-14 14:45 . 2012-06-14 14:45        12237824              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
+ 2012-05-13 01:42 . 2012-05-13 01:42        11492864              c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
.
-- Snapshot auf jetziges Datum zurückgesetzt --
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-08-20 2363392]
"NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2012-01-10 1083264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-08-20 322104]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 60464]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-05-28 253440]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2009-09-05 385024]
"SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files (x86)\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984]
"IndexSearch"="c:\program files (x86)\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368]
"PPort11reminder"="c:\program files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"Easy-PrintToolBox"="c:\program files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\users\Rainer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-27 250568]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-03-25 246224]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-03-25 114304]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 140712]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MosIrUsb;MosIrUsb.sys;c:\windows\system32\DRIVERS\MosIrUsb.sys [2007-10-11 27648]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-09 114144]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 RRNetCap;RRNetCap Service;c:\windows\system32\DRIVERS\rrnetcap.sys [2012-01-03 37480]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-02 1255736]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2011-08-05 306400]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-19 27760]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2010/01/24 01:24];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2009-10-02 21:38 146928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-03-02 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-05 203264]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 30520]
S2 VmbService;Vodafone-Mobile-Broadband-Dienst;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-05-28 9216]
S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760]
S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 70656]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RRNetCapMP;RRNetCapMP;c:\windows\system32\DRIVERS\rrnetcap.sys [2012-01-03 37480]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 36408]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 12:24        451872        ----a-w-        c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-03 04:20]
.
2012-09-19 c:\windows\Tasks\HPCeeScheduleForRainer.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 03:22]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-07-22 450048]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-08-25 610872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-13 171520]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1
FF - ProfilePath - c:\users\Rainer\AppData\Roaming\Mozilla\Firefox\Profiles\9237osy0.default\
FF - prefs.js: browser.search.selectedEngine - De-En Beolingus
FF - prefs.js: browser.startup.homepage - hxxp://www.3-ling.de/li/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Openfietsmap (hike) - c:\rad karten\Karten\OFM_hike\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-19  16:09:30
ComboFix-quarantined-files.txt  2012-09-19 14:09
ComboFix2.txt  2012-03-21 13:23
.
Vor Suchlauf: 20 Verzeichnis(se), 102.298.595.328 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 105.174.392.832 Bytes frei
.
- - End Of File - - 20C34418A8E05BFC0F7EA11CFE3378A2

Schöne Grüße
Rainer

cosinus 19.09.2012 16:25

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Rai3 19.09.2012 22:37

Hallo cosinus,
gmer ist problemlos gelaufen, hat aber nichts gefunden.

Hier das osam.log
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 23:35:24 on 19.09.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"HPCeeScheduleForRainer.job" - "Hewlett-Packard" - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"HP 3D DriveGuard" - ? - C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\hpaccelerometercp.CPL  (File not found)
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"Garmin USB Driver" (grmnusb) - "GARMIN Corp." - C:\Windows\System32\drivers\grmnusb.sys

[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - ? - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll  (File not found)
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{E54729E8-BB3D-4270-9D49-7389EA579090} "EasyBits ShellExecute Hook" - "EasyBits Software Corp." - C:\Windows\SysWow64\EZUPBH~1.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{5E2121EE-0300-11D4-8D3B-444553540000} "Catalyst Context Menu extension" - ? -  (File not found | COM-object registry key not found)
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\MLSHEXT.DLL
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files (x86)\WinRAR\rarext.dll
{B41DB860-64E4-11D2-9906-E49FADC173CA} "WinRAR shell extension" - ? -  (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{F27237D7-93C8-44C2-AC6E-D6057B9A918F} "JuniperSetupClientControl Class" - "Juniper Networks" - C:\Windows\Downloaded Program Files\JuniperSetupClient.ocx / https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "@C:\Windows\WindowsMobile\INetRepl.dll,-222" - "Microsoft Corporation" - C:\Windows\WindowsMobile\INetRepl.dll
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "ClsidExtension" - "Microsoft Corporation" - C:\Windows\WindowsMobile\INetRepl.dll
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{8dcb7100-df86-4384-8842-8fa844297b3f} "Bing Bar" - "Microsoft Corporation." - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - ? - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll  (File not found)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} "Bing Bar Helper" - "Microsoft Corporation." - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"LightScribe Control Panel" - "Hewlett-Packard Company" - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
"NokiaSuite.exe" - "Nokia" - C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"BCSSync" - "Microsoft Corporation" - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"BrStsMon00" - "Brother Industries, Ltd." - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
"ControlCenter3" - "Brother Industries, Ltd." - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
"DivXUpdate" - ? - "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Easy-PrintToolBox" - "CANON INC." - C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
"Easybits Recovery" - "EasyBits Software AS" - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
"FreePDF Assistant" - "shbox.de" - C:\Program Files (x86)\FreePDF_XP\fpassist.exe
"HP Software Update" - "Hewlett-Packard" - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
"HPCam_Menu" - "CyberLink Corp." - "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
"IndexSearch" - "Nuance Communications, Inc." - "C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe"
"iTunesHelper" - "Apple Inc." - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"MobileBroadband" - "Vodafone" - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
"PaperPort PTD" - "Nuance Communications, Inc." - "C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe"
"PPort11reminder" - "Nuance Communications, Inc." - "C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
"QlbCtrl.exe" - " Hewlett-Packard Development Company, L.P." - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"SSBkgdUpdate" - "Nuance Communications, Inc." - "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"WirelessAssistant" - "Hewlett-Packard" - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Redirected Port" - ? - C:\Windows\system32\redmonnt.dll  (File found, but it contains no detailed information)

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"BBUpdate" (BBUpdate) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
"Bing Bar Update Service" (BBSvc) - "Microsoft Corporation." - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
"BrYNSvc" (BrYNSvc) - "Brother Industries, Ltd." - C:\Program Files (x86)\Browny02\BrYNSvc.exe
"Com4QLBEx" (Com4QLBEx) - "Hewlett-Packard Development Company, L.P." - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Easybits Shared Services for Windows" (ezSharedSvc) - ? - C:\Windows\System32\ezsvc7.dll  (File not found)
"GameConsoleService" (GameConsoleService) - "WildTangent, Inc." - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
"HP Quick Synchronization Service" (HPDrvMntSvc.exe) - "Hewlett-Packard Company" - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
"HP Software Framework Service" (hpqwmiex) - "Hewlett-Packard Company" - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
"HP Support Assistant Service" (HP Support Assistant Service) - "Hewlett-Packard Company" - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"ServiceLayer" (ServiceLayer) - "Nokia" - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
"Vodafone-Mobile-Broadband-Dienst" (VmbService) - "Vodafone" - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
"Zune Network Sharing Service" (ZuneNetworkSvc) - "Microsoft Corporation" - C:\Program Files\Zune\ZuneNss.exe
"Zune Windows Mobile Connectivity Service" (WMZuneComm) - "Microsoft Corporation" - C:\Program Files\Zune\WMZuneComm.exe
"Zune Wireless Configuration Service" (ZuneWlanCfgSvc) - "Microsoft Corporation" - C:\Program Files\Zune\ZuneWlanCfgSvc.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files (x86)\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


aswMBR ist tatsächlich abgestürzt. Ich habe es dann nach deinen Anweisungen (none) nochmals laufen lassen. Dann hat es funktioniert.
Hier das Log:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-19 23:48:13
-----------------------------
23:48:13.549    OS Version: Windows x64 6.1.7601 Service Pack 1
23:48:13.550    Number of processors: 2 586 0x602
23:48:13.551    ComputerName: RAINER-LT  UserName: Rainer
23:48:14.935    Initialize success
23:48:24.786    AVAST engine defs: 12091901
23:48:47.588    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:48:47.593    Disk 0 Vendor: Hitachi_HTS725050A9A364 PC4OC70E Size: 476940MB BusType: 11
23:48:47.620    Disk 0 MBR read successfully
23:48:47.626    Disk 0 MBR scan
23:48:47.635    Disk 0 unknown MBR code
23:48:47.643    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
23:48:47.662    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      462575 MB offset 409600
23:48:47.698    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        14061 MB offset 947763200
23:48:47.726    Disk 0 Partition 4 00    0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
23:48:47.779    Disk 0 scanning C:\Windows\system32\drivers
23:49:02.586    Service scanning
23:49:37.755    Modules scanning
23:49:37.774    Disk 0 trace - called modules:
23:49:37.790   
23:49:37.801    Scan finished successfully
23:49:48.492    Disk 0 MBR has been saved successfully to "C:\Users\Rainer\Desktop\MBR.dat"
23:49:48.499    The log file has been saved successfully to "C:\Users\Rainer\Desktop\aswMBR.txt"

Schöne Grüße
Rainer

cosinus 20.09.2012 14:33

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

Rai3 21.09.2012 07:05

Avira abgeschaltet,
FixMBR durchgeführt
FixMBR meldet
Code:

Disk 0 windows 601 MBR fixed successfully
Danach Windows neu gestartet und mit aswMBR einen erneuten scan durchgeführt. (hierbei AV scan wieder auf (none))
Hier das Log:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-21 08:09:03
-----------------------------
08:09:03.282    OS Version: Windows x64 6.1.7601 Service Pack 1
08:09:03.282    Number of processors: 2 586 0x602
08:09:03.283    ComputerName: RAINER-LT  UserName: Rainer
08:09:04.554    Initialize success
08:09:18.478    AVAST engine defs: 12092001
08:10:53.353    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
08:10:53.364    Disk 0 Vendor: Hitachi_HTS725050A9A364 PC4OC70E Size: 476940MB BusType: 11
08:10:53.377    Disk 0 MBR read successfully
08:10:53.384    Disk 0 MBR scan
08:10:53.404    Disk 0 Windows 7 default MBR code
08:10:53.418    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
08:10:53.435    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      462575 MB offset 409600
08:10:53.472    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        14061 MB offset 947763200
08:10:53.492    Disk 0 Partition 4 00    0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
08:10:53.537    Disk 0 scanning C:\Windows\system32\drivers
08:11:06.809    Service scanning
08:11:41.496    Modules scanning
08:11:41.516    Disk 0 trace - called modules:
08:11:41.554    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
08:11:41.561    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004691060]
08:11:41.568    3 CLASSPNP.SYS[fffff880010ee43f] -> nt!IofCallDriver -> [0xfffffa80046908b0]
08:11:41.576    5 hpdskflt.sys[fffff880021c0289] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80045fe680]
08:11:41.583    Scan finished successfully
08:12:03.178    Disk 0 MBR has been saved successfully to "C:\Users\Rainer\Desktop\MBR.dat"
08:12:03.185    The log file has been saved successfully to "C:\Users\Rainer\Desktop\aswMBR.txt"

Schöne Grüße
Rainer

cosinus 21.09.2012 15:05

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Rai3 24.09.2012 09:49

Hallo cosinus,

hier das Log von Malwarebytes:
Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.24.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Rainer :: RAINER-LT [Administrator]

24.09.2012 08:35:45
mbam-log-2012-09-24 (08-35-45).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 488605
Laufzeit: 2 Stunde(n), 11 Minute(n), 29 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

SuperAntiSpyware folgt

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/24/2012 at 01:41 PM

Application Version : 5.5.1016

Core Rules Database Version : 9275
Trace Rules Database Version: 7087

Scan type      : Complete Scan
Total Scan Time : 02:44:50

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned      : 830
Memory threats detected  : 0
Registry items scanned    : 68820
Registry threats detected : 0
File items scanned        : 247476
File threats detected    : 55

Adware.Tracking Cookie
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\WMBZ43PZ.txt [ /ad.zanox.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\BEOMOHX4.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\HJ61RZM7.txt [ /2o7.net ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\F39VXB6M.txt [ /atdmt.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\K9FCURCT.txt [ /adfarm1.adition.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\JIII91K0.txt [ /track.adform.net ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\2PBFFRSG.txt [ /www.zanox-affiliate.de ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\WNX0QSSC.txt [ /adform.net ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\K6EJEHAE.txt [ /smartadserver.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\IP7UYTB3.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\2R6E9ZCJ.txt [ /apmebf.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\RE61N48X.txt [ /doubleclick.net ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\8VAOV3BF.txt [ /xiti.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\DRJ8R6W7.txt [ /stats.paypal.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\VD5QS7NT.txt [ /atdmt.combing.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\6IU9J0ND.txt [ /stat.aldi.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\W58NUMB8.txt [ /stat.aldi.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\FNAL6XM5.txt [ /dyntracker.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\BFAAP0RD.txt [ /mediaplex.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\B9RNAEO3.txt [ /fastclick.net ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\3RXKS9HT.txt [ /pmi.rotator.hadj7.adjuggler.net ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\LGP65NNR.txt [ /zanox.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\0XSI6O0Z.txt [ /imrworldwide.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\XLG0SPTQ.txt [ /tracking.quisma.com ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\BER6B76R.txt [ /eas.apm.emediate.eu ]
        C:\Users\Rainer\AppData\Roaming\Microsoft\Windows\Cookies\BH5YMU3P.txt [ /zanox-affiliate.de ]
        C:\USERS\RAINER\AppData\Roaming\Microsoft\Windows\Cookies\Low\TIRLOACT.txt [ Cookie:rainer@sexlist.com/ ]
        C:\USERS\RAINER\AppData\Roaming\Microsoft\Windows\Cookies\Low\rainer@in.getclicky[1].txt [ Cookie:rainer@in.getclicky.com/ ]
        C:\USERS\RAINER\AppData\Roaming\Microsoft\Windows\Cookies\Low\HT4N6XY5.txt [ Cookie:rainer@atdmt.com/ ]
        C:\USERS\RAINER\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q7AY7S9K.txt [ Cookie:rainer@c.atdmt.com/ ]
        C:\USERS\RAINER\AppData\Roaming\Microsoft\Windows\Cookies\Low\G845NUSP.txt [ Cookie:rainer@doubleclick.net/ ]
        C:\USERS\RAINER\AppData\Roaming\Microsoft\Windows\Cookies\Low\QVR143I7.txt [ Cookie:rainer@serving-sys.com/ ]
        C:\USERS\RAINER\Cookies\WMBZ43PZ.txt [ Cookie:rainer@ad.zanox.com/ ]
        C:\USERS\RAINER\Cookies\BEOMOHX4.txt [ Cookie:rainer@ad2.adfarm1.adition.com/ ]
        C:\USERS\RAINER\Cookies\HJ61RZM7.txt [ Cookie:rainer@2o7.net/ ]
        C:\USERS\RAINER\Cookies\F39VXB6M.txt [ Cookie:rainer@atdmt.com/ ]
        C:\USERS\RAINER\Cookies\IP7UYTB3.txt [ Cookie:rainer@ad1.adfarm1.adition.com/ ]
        C:\USERS\RAINER\Cookies\2R6E9ZCJ.txt [ Cookie:rainer@apmebf.com/ ]
        C:\USERS\RAINER\Cookies\RE61N48X.txt [ Cookie:rainer@doubleclick.net/ ]
        C:\USERS\RAINER\Cookies\DRJ8R6W7.txt [ Cookie:rainer@stats.paypal.com/ ]
        C:\USERS\RAINER\Cookies\VD5QS7NT.txt [ Cookie:rainer@atdmt.combing.com/ ]
        C:\USERS\RAINER\Cookies\6IU9J0ND.txt [ Cookie:rainer@stat.aldi.com/dcsfq2jxwixy5f1mioa8p9lnl_5x1d ]
        C:\USERS\RAINER\Cookies\W58NUMB8.txt [ Cookie:rainer@stat.aldi.com/ ]
        C:\USERS\RAINER\Cookies\FNAL6XM5.txt [ Cookie:rainer@dyntracker.com/ ]
        C:\USERS\RAINER\Cookies\BFAAP0RD.txt [ Cookie:rainer@mediaplex.com/ ]
        C:\USERS\RAINER\Cookies\B9RNAEO3.txt [ Cookie:rainer@fastclick.net/ ]
        C:\USERS\RAINER\Cookies\3RXKS9HT.txt [ Cookie:rainer@pmi.rotator.hadj7.adjuggler.net/ ]
        C:\USERS\RAINER\Cookies\0XSI6O0Z.txt [ Cookie:rainer@imrworldwide.com/cgi-bin ]
        C:\USERS\RAINER\Cookies\XLG0SPTQ.txt [ Cookie:rainer@tracking.quisma.com/ ]
        C:\USERS\RAINER\Cookies\BER6B76R.txt [ Cookie:rainer@eas.apm.emediate.eu/ ]
        .doubleclick.net [ C:\USERS\RAINER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9237OSY0.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\RAINER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9237OSY0.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\RAINER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9237OSY0.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-FakeAv
        C:\PROGRAM FILES (X86)\MOBILE PARTNER\GPSPLUGIN.DLL

Trojan.Agent/Gen-Yoddos
        C:\PROGRAM FILES (X86)\WINRAR\DEFAULT.SFX

Soweit fertig jetzt.
Was mache ich mit den Funden von SUPERAntiSpyware?

Schöne Grüße
Rainer

cosinus 24.09.2012 17:51

Code:

C:\PROGRAM FILES (X86)\MOBILE PARTNER\GPSPLUGIN.DLL
Bitte diese Datei bei Virustotal auswerten lassen und den Ergebnislink posten. Falls Du die Datei nicht siehst, musst Du sie evtl. vorher sichtbar machen.
Wenn die Datei schon ausgewertet sein sollte, bitte eine weitere Auswertung starten.

Rai3 25.09.2012 07:21

Hallo cosinus,

habe das File von Virustotal auswerten lassen. Hier der Link:

https://www.virustotal.com/file/86a27cf36fc67bf8d5c0b6d2989b89bb225dd6e021d7d7f55be54895aeaa1cff/analysis/1348553822/



Ich hoffe das ist das was du meinst.

Schöne Grüße
Rainer

cosinus 25.09.2012 12:50

Tpyischer SASW Fehlalarm!

Sieht ok aus, da wurden nur Cookies gefunden, der angebliche Fund bei WinRAR ist ein Fehalarm.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Rai3 25.09.2012 13:22

Hallo cosinus,

eigentlich hatte ich aus meiner Sicht den FireFox so eingestellt, dass er keine Cookies speichert, aber da muss ich wohl dann noch mal ran.

Weitere Funde habe ich so direkt nicht, allerdings will er mir seid längerem ein Java Update aufzwingen und popt in diesem Zuge immer eine Jucheck.exe auf, die er installieren will.

Ist das in Ordnung, oder wie kann ich ihm das abgewöhnen?


Kann oder soll ich die installierten Virenscanner deinstallieren?

Schöne Grüße und bis hier hin schon mal vielen, vielen, vielen, vielen ,... Dank
Rainer

cosinus 25.09.2012 14:51

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Rai3 28.09.2012 07:22

Hallo cosinus,

vielen dank für deine Hilfe, du hast mir sehr geholfen. Ich hatte schon echte Panik vor einem kompletten Neuaufsetzen.

Vielen vielen Dank :dankeschoen:

Rainer


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:59 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20