Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windows 8.1: Nur noch Verknüpfungen auf USB-Sticks (https://www.trojaner-board.de/164883-windows-8-1-nur-noch-verknuepfungen-usb-sticks.html)

Oktavius 09.03.2015 13:07

Windows 8.1: Nur noch Verknüpfungen auf USB-Sticks
 
Hallo Ihr Experten an der Computerfront!

Danke erst einmal für eure Mühe!
Ich glaube ich habe mir im Copyshop um die Ecke irgendwas fieses eingefangen. Nun möchte ich den PC neu aufsetzen, würde zuvor aber gerne damit meine externen Festplatten nicht auch noch betroffen sind, die Angreifer gerne vom PC entfernen.

Wie in den Regeln zum Eröffnen eines Themas beschrieben hier mein Problem:

Jedes mal wenn ich meinen USB Stick an den PC stecke und Daten auf diesen Kopieren möchte, so werden auf dem Medium nur Verknüpfungen der Dateien sowie die Verknüpfung "System Volume Information" angezeigt.
Auch ein anzeigen versteckter Dateien im System wie teilweise in anderen Themen beschrieben brachte keinen Erfolg. Teilweise bleiben die Daten sichtbar, teilweise verschwinden sie aber auch.


Anbei die entsprechenden Logfiles.
Meinen Namen habe ich wie beschrieben durch **** ersetzt.

Bei der Erstellung des Logfiles durch frst64.exe, wurde der scan zwar durchgeführt er hat ganz am Anfang jedoch folgende Mitteilung ausgespuckt: " C:\WINDOWS\system32\config\system Der Prozess kann nicht auf die Datei zugreifen da sie von einem Prozess verwendet wird."

Dabei habe ich mich genau an die Anleitung gehalten und alle Programme zuvor beendet.

Ich danke euch riesig und meine Studienarbeit würde sich auch freuen!

Liebe Grüße


defogger_disable.log
Code:

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:23 on 09/03/2015 (*****)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-


FRST.log

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2015 03
Ran by **** (administrator) on JUSTUSHOFFMANN on 09-03-2015 12:25:52
Running from C:\Users\****\Desktop\Virus
Loaded Profiles: **** (Available profiles: **** & Andrea & DefaultAppPool)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\DptfParticipantProcessorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe
() C:\Windows\SysWOW64\DptfPolicyCriticalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Spotify Ltd) C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\nacl64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coNatHst.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Martin Klinzmann) C:\Users\****\Desktop\LicenseCrawler\LicenseCrawler.exe
(Martin Klinzmann) C:\Users\****\Desktop\LicenseCrawler\LicenseCrawler.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\SysWOW64\DptfPolicyLpmServiceHelper.exe [13824 2012-02-20] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2409272 2012-10-06] (Logitech, Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 7\MMReminderService.exe [37392 2007-05-17] (Mindjet)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-01-28] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Spotify Web Helper] => C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> {28684E8B-8FB1-4DE8-A201-BC65A5751191} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=35025C00-9B86-4F41-8DE4-7FBA746076A1&apn_sauid=CD45874C-A6D3-4477-A1EF-B0C407F5B97A
SearchScopes: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=360&chn=retail&geo=DE&ver=21&locale=de_DE&gct=kwd&qsrc=2869
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: CmjBrowserHelperObject Object -> {07A11D74-9D25-4fea-A833-8B0D76A5577A} -> C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll [2007-05-17] (Mindjet)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2012-10-06] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1

FireFox:
========
FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\hcof00pn.default
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Ask.com
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2283723822-742349386-183045315-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll [2013-03-12] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-03-04]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-10-03]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2012-11-02]
FF HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (Logitech SetPoint) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2012-11-04]
CHR Extension: (iCloud Bookmarks) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2014-02-15]
CHR Extension: (Isoball 3) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj [2013-10-13]
CHR Extension: (Norton Security Toolbar) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-11-05]
CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Citavi Picker) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-04-01]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-11-02]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-10] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
R2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
R2 DptfPolicyCriticalService; C:\Windows\SysWOW64\DptfPolicyCriticalService.exe [19456 2012-02-20] ()
S2 DptfPolicyLpmService; C:\Windows\SysWOW64\DptfPolicyLpmService.exe [24576 2012-02-20] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Users\****\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-04-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-07] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] ()
S3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-07-14] (Windows (R) Win 7 DDK provider)
S3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [19104 2012-07-14] (ASUS)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-10-11] (ASIX Electronics Corp.)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150224.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2014-05-08] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150306.001\IDSvia64.sys [669400 2015-02-13] (Symantec Corporation)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [26504 2012-04-10] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-07] (Microsoft Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150308.001\ENG64.SYS [129752 2015-01-21] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150308.001\EX64.SYS [2137304 2015-01-21] (Symantec Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1506000.020\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-10] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2015-01-28] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
U3 idsvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-09 12:25 - 2015-03-09 12:26 - 00000000 ____D () C:\FRST
2015-03-09 12:23 - 2015-03-09 12:25 - 00000000 ____D () C:\Users\****\Desktop\Virus
2015-03-09 12:23 - 2015-03-09 12:23 - 00000000 _____ () C:\Users\****\defogger_reenable
2015-03-09 12:20 - 2015-03-09 12:21 - 11587952 _____ (McAfee Inc) C:\Users\****\Desktop\stinger32.exe
2015-03-09 12:18 - 2015-03-09 12:19 - 00000000 ____D () C:\Users\****\Desktop\LicenseCrawler
2015-03-09 12:17 - 2015-03-09 12:17 - 01393511 _____ () C:\Users\****\Desktop\licensecrawler_1.43.732.zip
2015-03-07 19:12 - 2015-03-07 19:12 - 00698568 _____ () C:\Users\****\Desktop\handyhuelle_oettinger.jpg.zip
2015-03-04 22:27 - 2015-03-08 17:11 - 00000000 ____D () C:\Users\****\Desktop\Studienarbeit
2015-03-04 10:13 - 2015-03-04 10:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-03-04 10:13 - 2015-01-28 20:49 - 00112496 ____R (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\acsock64.sys
2015-03-04 10:04 - 2015-03-04 10:07 - 03345776 _____ (Cisco Systems, Inc.) C:\Users\****\Desktop\anyconnect-win-3.1.06079-web-deploy-k9.exe
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls
2015-02-25 12:18 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2015-02-24 03:41 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-24 03:41 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-16 09:24 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-16 09:24 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-16 09:24 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-16 09:24 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-16 09:24 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-16 09:24 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-16 09:24 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-16 09:24 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-16 09:24 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-16 09:24 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-16 09:24 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-16 09:24 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-16 09:24 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-16 09:24 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-16 09:24 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-16 09:23 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-16 09:23 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-16 09:23 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-16 09:23 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-16 09:23 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-16 09:23 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-16 09:23 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-16 09:23 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-16 09:23 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-16 09:23 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-16 09:23 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-16 09:23 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-16 09:23 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-16 09:23 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-16 09:23 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-16 09:23 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-09 12:23 - 2013-11-07 04:18 - 00000000 ____D () C:\Users\****
2015-03-09 12:17 - 2012-10-03 16:18 - 00000000 ____D () C:\Users\****\Documents\Outlook-Dateien
2015-03-09 12:06 - 2014-03-22 16:30 - 00000000 ____D () C:\Users\****\Documents\Citavi 4
2015-03-09 12:01 - 2013-03-20 13:23 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-09 12:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-09 12:00 - 2012-02-24 03:29 - 00001148 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-09 12:00 - 2012-02-24 03:29 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-09 11:59 - 2013-11-07 04:23 - 02092683 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-09 11:41 - 2012-10-03 15:32 - 00000000 ___RD () C:\Users\****\Dropbox
2015-03-09 11:01 - 2013-09-30 05:14 - 02072588 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-09 11:01 - 2013-09-30 04:56 - 00889374 _____ () C:\WINDOWS\system32\perfh007.dat
2015-03-09 11:01 - 2013-09-30 04:56 - 00205446 _____ () C:\WINDOWS\system32\perfc007.dat
2015-03-09 10:59 - 2014-02-15 05:49 - 00000000 ____D () C:\Users\****\AppData\Local\769A133B-0AED-452E-A98A-A2C94FEF5322.aplzod
2015-03-08 17:02 - 2013-11-06 22:08 - 01165312 ___SH () C:\Users\****\Desktop\Thumbs.db
2015-03-08 16:41 - 2012-12-02 23:43 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype
2015-03-07 17:16 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-07 13:38 - 2012-10-16 00:46 - 00003994 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{579749A9-A7ED-4DBF-B3BE-1B7363949C56}
2015-03-05 14:45 - 2013-11-06 22:12 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2283723822-742349386-183045315-1001
2015-03-04 22:27 - 2013-08-22 15:46 - 00339736 _____ () C:\WINDOWS\setupact.log
2015-03-04 20:02 - 2013-11-07 08:40 - 00000000 __RDO () C:\Users\****\SkyDrive
2015-03-04 20:02 - 2013-11-07 01:00 - 00000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2015-03-04 20:02 - 2012-10-03 15:30 - 00000000 ____D () C:\Users\****\AppData\Roaming\Dropbox
2015-03-04 20:01 - 2013-09-29 20:04 - 00218246 _____ () C:\WINDOWS\PFRO.log
2015-03-04 20:01 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-04 10:13 - 2013-11-24 16:20 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-04 10:13 - 2013-11-06 23:43 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-04 10:12 - 2012-10-03 16:24 - 00000000 ____D () C:\Users\****\Desktop\Programme
2015-03-04 10:11 - 2014-12-04 20:56 - 00000000 ____D () C:\Users\****\Desktop\Schwerpunkt
2015-03-04 09:55 - 2012-10-17 17:52 - 00000000 ____D () C:\Users\****\Documents\Corps
2015-03-04 09:55 - 2012-10-03 16:20 - 00000000 ____D () C:\Users\****\Documents\Uni
2015-03-02 13:34 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-03-02 13:33 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-02 13:21 - 2012-10-03 16:19 - 00000000 ____D () C:\Users\****\AppData\Roaming\Swiss Academic Software
2015-02-25 13:18 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-21 00:48 - 2012-10-03 15:32 - 00001107 _____ () C:\Users\****\Desktop\Dropbox.lnk
2015-02-21 00:48 - 2012-10-03 15:31 - 00000000 ____D () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-20 11:21 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-20 10:10 - 2013-08-22 15:44 - 00479376 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-20 10:08 - 2012-10-03 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-20 10:08 - 2009-07-14 03:34 - 00000545 _____ () C:\WINDOWS\win.ini
2015-02-16 09:28 - 2013-07-25 10:43 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-16 09:24 - 2012-10-03 16:28 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-13 11:55 - 2012-02-24 03:29 - 00004120 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-13 11:55 - 2012-02-24 03:29 - 00003884 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2013-11-07 08:42 - 2013-11-07 08:42 - 0000021 _____ () C:\Users\****\AppData\Roaming\my_intel.sys
2013-11-07 01:00 - 2015-03-04 20:02 - 0000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2014-08-05 02:05 - 2014-08-05 02:05 - 0002203 _____ () C:\Users\****\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2013-11-07 01:36 - 2013-11-07 01:38 - 0037795 _____ () C:\Users\****\AppData\Local\WiDiSetupLog.20131107.013659.wdl
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2012-10-05 14:19 - 2013-11-14 20:12 - 0003349 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpenflld.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-04 21:18

==================== End Of Log ============================

--- --- ---



GMER.txt
Code:

GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-09 12:42:48
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ADATA_XM rev.5.0. 238,47GB
Running: s5ezzdql.exe; Driver: C:\Users\JUSTUS~1\AppData\Local\Temp\awtdapob.sys


---- Kernel code sections - GMER 2.1 ----

.text    C:\WINDOWS\System32\win32k.sys!W32pServiceTable                                                                                                                                                                                                                              fffff960001fb200 15 bytes [00, 65, F4, 01, 80, 7D, 6A, ...]
.text    C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 17                                                                                                                                                                                                                          fffff960001fb211 10 bytes [F3, FB, FF, 00, 17, C7, 00, ...]

---- User code sections - GMER 2.1 ----

.text    C:\WINDOWS\system32\WLANExt.exe[1364] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                                  00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\WLANExt.exe[1364] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                                  00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\WLANExt.exe[1364] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                                    00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\WLANExt.exe[1364] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                                    00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\System32\spoolsv.exe[1524] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                                  00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\System32\spoolsv.exe[1524] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                                  00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\System32\spoolsv.exe[1524] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                                    00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\System32\spoolsv.exe[1524] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                                    00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1108] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                      00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1108] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                      00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1108] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                          00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1108] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                          00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2544] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                  00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2544] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                  00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2544] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                      00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2544] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                      00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                            00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                            00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                              00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                              00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe[2800] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe[2800] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe[2800] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                  00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe[2800] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                  00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\Windows\system32\EscSvc64.exe[2840] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                                00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\Windows\system32\EscSvc64.exe[2840] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                                00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\Windows\system32\EscSvc64.exe[2840] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                                    00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\Windows\system32\EscSvc64.exe[2840] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                                    00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\wbem\wmiprvse.exe[3236] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                            00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\wbem\wmiprvse.exe[3236] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                            00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\wbem\wmiprvse.exe[3236] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                              00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\system32\wbem\wmiprvse.exe[3236] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                              00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\Explorer.EXE[4176] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                                          00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\Explorer.EXE[4176] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                                          00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\Explorer.EXE[4176] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                                            00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\Explorer.EXE[4176] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                                            00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]
.text    C:\WINDOWS\Explorer.EXE[4176] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194                                                                                                                                                                                                00007ff89aad1f6a 4 bytes [AD, 9A, F8, 7F]
.text    C:\WINDOWS\Explorer.EXE[4176] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218                                                                                                                                                                                                00007ff89aad1f82 4 bytes [AD, 9A, F8, 7F]
.text    C:\Program Files\Logitech\SetPointP\SetPoint.exe[6096] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                                                                                                                                                00007ff8a2e6169a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Logitech\SetPointP\SetPoint.exe[6096] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                                                                                                                                                00007ff8a2e616a2 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Logitech\SetPointP\SetPoint.exe[6096] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                                                                                                                                    00007ff8a2e6181a 4 bytes [E6, A2, F8, 7F]
.text    C:\Program Files\Logitech\SetPointP\SetPoint.exe[6096] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                                                                                                                                    00007ff8a2e61832 4 bytes [E6, A2, F8, 7F]

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\system32\csrss.exe [660:684]                                                                                                                                                                                                                                      fffff96000874b90
---- Processes - GMER 2.1 ----

Library  c:\users\justus~1\appdata\local\temp\7zs6fc2\hpslpsvc64.dll (*** suspicious ***) @ C:\WINDOWS\system32\svchost.exe [3644] (HP Network Devices Support/Hewlett-Packard Co.)(2013-11-11 08:28:27)                                                                              0000000180000000
Process  C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (FILE NOT FOUND)                                                                                              0000000000400000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Widgets.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:28)        00000000654a0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Gui.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)            0000000065190000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Core.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)          0000000064860000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\libGLESv2.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416](2015-02-10 21:00:30)                                                                                        0000000067fe0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\icuin52.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (ICU I18N DLL/The ICU Project)(2015-02-10 21:00:30)                                                          000000004a900000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\icuuc52.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (ICU Common DLL/The ICU Project)(2015-02-10 21:00:30)                                                        00000000041f0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\icudt52.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (ICU Data DLL/The ICU Project)(2015-02-10 21:00:30)                                                          000000004ad00000
Library  c:\users\justus~1\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpenflld.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416](2015-03-04 19:02:44)                                              0000000003d40000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Network.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)        0000000067ba0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5WebKit.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:26)        0000000065df0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Quick.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)          0000000067980000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Qml.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)            0000000067720000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5Sql.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)            00000000680c0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\libEGL.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416](2015-02-10 21:00:30)                                                                                          00000000680b0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5WebKitWidgets.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:26)  00000000676f0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5OpenGL.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)        00000000676b0000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\Qt5PrintSupport.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-02-10 21:00:24)  0000000067660000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416](2015-02-10 21:00:28)                                                                      0000000067580000
Library  C:\Users\*****\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll (*** suspicious ***) @ C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe [6416](2015-02-10 21:00:28)                                                                      0000000067540000

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                                                                                                                                                                                                                        unknown MBR code

---- EOF - GMER 2.1 ----


schrauber 09.03.2015 13:08

HI,

Addition.txt von FRST bitte noch posten.

Oktavius 09.03.2015 13:12

Oh, wohl übersehen! Danke

Addition.txt
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2015 03
Ran by ***** at 2015-03-09 12:27:52
Running from C:\Users\*****\Desktop\Virus
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton 360 (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton 360 (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader X (10.1.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS Backtracker (HKLM-x32\...\{C15C060C-ED1C-49EB-83B3-F7C0FD1CD661}) (Version: 3.0.3 - ASUS)
ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.5 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.7 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.7 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.1.7 - ASUS)
ASUS PWR Option (HKLM-x32\...\{B7B60C4F-0DB8-42EF-8EDC-5F21D4C2D73F}) (Version: 1.2.1 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.1.3 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0004 - ASUS)
ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.4 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.4 - ASUS)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0025 - ASUS)
AX88772B Windows 7 Drivers (HKLM-x32\...\InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}) (Version: 1.0.2.0 - ASIX Electronics Corporation)
AX88772B Windows 7 Drivers (x32 Version: 1.0.2.0 - ASIX Electronics Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
C5300 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.06079 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.06079 - Cisco Systems, Inc.) Hidden
Citavi (HKLM-x32\...\{E12C6653-1FF0-4686-ADB8-589C13AE761F}) (Version: 3.3.0.0 - Swiss Academic Software)
Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.3.0.15 - Swiss Academic Software)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
doPDF 7.3 printer (HKLM\...\doPDF 7 printer_is1) (Version:  - Softland)
Dropbox (HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON WF-2510 Series Printer Uninstall (HKLM\...\EPSON WF-2510 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart C5300 All-In-One Driver Software 13.0 Rel. 4 (HKLM\...\{6FA29B87-FED3-45A1-8A95-2FDEE0F6DD18}) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_PaperLabel (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_PrintOnDisc (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
hpphotosmartdisclabelplugin (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)
Intel(R) Dynamic Platform & Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 6.0.1.1067 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3308 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1024 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
Intel(R) WiDi (HKLM\...\{BE7E45FA-7F97-4155-87CF-2DEA398995DA}) (Version: 4.2.21.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® AT Service signup (HKLM-x32\...\{CD49AEDB-FFB4-4A9A-A3C2-E9AF814FE6FE}) (Version: 2.0.0.3 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.550 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech SetPoint 6.50 (HKLM\...\sp6) (Version: 6.50.152 - Logitech)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mindjet MindManager Pro 7 (HKLM-x32\...\{3CDFEE23-66D2-4DB0-8269-12634E871725}) (Version: 7.0.429 - Mindjet LLC)
MOBackup - Datensicherung für Outlook (Vollversion) (HKLM-x32\...\MOBackup-DatensicherungfürOutlook) (Version: 7.0 - Heiko Schröder)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
Norton 360 (HKLM-x32\...\N360) (Version: 21.6.0.32 - Symantec Corporation)
PDF-XChange 3 (HKLM-x32\...\PDF-XChange 3_is1) (Version:  - Tracker Software)
PS_AIO_04_C5300_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6809 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spotify (HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC)
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.16642 - TeamViewer)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\...\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.31 - ASUS)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation)
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)

==================== Restore Points  =========================

20-02-2015 10:07:11 Windows Update
24-02-2015 12:18:15 Windows Update
04-03-2015 10:12:36 Installed Cisco AnyConnect Secure Mobility Client

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {01C995FF-D178-4E7B-AC4A-9E950006A207} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {0824384A-6E02-4601-9650-D83C1EB8C205} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {0837D897-84CB-4E30-A8DD-807937A81DFC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-30] (Google Inc.)
Task: {0F1FC558-90E6-41AA-8D37-4FBE69053762} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {118314BB-772D-4B9C-8430-8FFEE872FB3C} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-10-24] (ASUS)
Task: {11E2634C-A98E-419D-B2A1-26B51596D6E5} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86) [2015-02-13] ()
Task: {148318FC-5974-4508-A415-B3AFD16E5DDB} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {20716D4A-7F53-4BCC-A396-90A79DBC0493} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.)
Task: {29308477-8F7E-4D4F-92D5-F1534E61B6F5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {2A12FA94-AE78-4CE3-BCAB-CA6A4798002A} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3C9616B2-742C-4820-AFAE-F3D2459E9677} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {3D966D87-5FE5-4FBC-8E90-DB0F48E454DB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {3E3E65EA-6693-4ACC-947D-206853F50D65} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {42145BE5-4059-431F-919A-1A381C5966DE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {480307B7-D62C-40B4-AC2B-958F633F286F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation)
Task: {56A5C30C-CC9F-40CE-8C9A-A4D7C1696920} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS)
Task: {6913925B-8807-4944-9DC4-D2106FAF17F0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {6FECF9BE-AED8-4627-80ED-91FF5361960F} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {773492A6-4F08-4DAF-9C1B-778BC17ACAED} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {78588675-6CF3-4E50-B5B1-1EC34EAA2F6B} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {7DDF9673-8D0B-4652-B795-1BEAD1206B65} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {81443F6F-8608-4F5F-9746-49BD355F1F44} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-01-16] (AsusTek)
Task: {8687A636-6CDE-4487-A3BA-E2518973B7CC} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2013-11-27] ()
Task: {8BBF993A-7ACF-4CD2-84BA-1E8BC24671C6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-30] (Google Inc.)
Task: {9FC31335-F46F-48D5-87F9-A1A2E33222C1} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {AA921623-B84A-4EC8-A6DA-5D46323FC6D9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {AE1822A9-629F-44BA-9C16-D1B008EE3111} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {B1417ABA-38A5-4959-9D99-9958D486088B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-02-16] (Microsoft Corporation)
Task: {B7874F98-7A73-4D9D-B14B-1FEAB9D5BAB6} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-16] (ASUSTek Computer Inc.)
Task: {C0804079-4CDF-45AB-B431-AAA2FD56F1C8} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {C778374C-94FE-41B0-B705-5FC952201AC0} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {CC4FC069-845E-4644-BE5E-360DE6B864A3} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-06-29] (ASUSTeK Computer Inc.)
Task: {DD548504-31EE-43FF-A573-1E9BCB56DC76} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {E959E007-A71C-4952-8EA8-22DE146D6227} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {EA49544F-8E18-47FB-85D3-2FD3C8A971D5} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86) [2015-02-13] ()
Task: {F0496437-71B1-4E96-9E9C-3BC2F52CDE46} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {F3BBF756-D937-4E6C-84DA-87C055AF2E05} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {F4B55B2F-BFE3-478B-A5C0-97DDC4A506EF} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {FACB8164-0888-403B-B4E6-7F59329EA90F} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {FBC8485F-A585-489F-8E2C-C65FEABC1BEF} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {FCAB4EAD-2FA5-48CB-88C3-AEAED4EF25CD} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {FFEE4F98-789F-4BC5-9EBF-91D4AC658C46} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2013-01-26 17:51 - 2012-09-18 15:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll
2013-01-26 17:51 - 2012-09-18 15:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll
2012-07-30 03:50 - 2012-02-20 04:31 - 00018944 _____ () C:\WINDOWS\SysWOW64\DptfParticipantProcessorService.exe
2012-07-30 03:50 - 2012-02-20 04:31 - 00019968 _____ () C:\WINDOWS\SysWOW64\DptfPolicyConfigTDPService.exe
2012-07-30 03:50 - 2012-02-20 04:31 - 00019456 _____ () C:\WINDOWS\SysWOW64\DptfPolicyCriticalService.exe
2012-08-24 17:26 - 2012-08-24 17:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2009-03-02 03:08 - 2009-03-02 03:08 - 00003584 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\LogicNP.PropSheetExtensionHelper_x64.dll
2012-10-06 09:15 - 2012-10-06 09:15 - 01976632 _____ () C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll
2012-10-06 09:14 - 2012-10-06 09:14 - 00071992 _____ () C:\Program Files\Logitech\SetPointP\WinRTProxy.DLL
2015-01-28 21:08 - 2015-01-28 21:08 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-01-31 17:25 - 2012-01-31 17:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2012-08-24 17:17 - 2012-08-24 17:17 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\*****\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 20:02 - 2015-03-04 20:02 - 00043008 _____ () c:\Users\*****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpenflld.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\*****\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\*****\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\*****\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2007-05-17 23:05 - 2007-05-17 23:05 - 00116240 ____R () C:\Program Files (x86)\Mindjet\MindManager 7\zlib.dll
2012-09-08 22:57 - 2012-06-25 18:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 14:46 - 2013-02-14 14:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libglesv2.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libegl.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\*****\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\*****\Documents\duschkabine.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\*****\Documents\duschkabine.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\*****\Documents\duschkabine2.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\*****\Documents\duschkabine2.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\asus\wallpapers\asus.jpg
DNS Servers: 192.168.188.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-2283723822-742349386-183045315-500 - Administrator - Disabled)
Andrea (S-1-5-21-2283723822-742349386-183045315-1007 - Limited - Enabled) => C:\Users\Andrea
Gast (S-1-5-21-2283723822-742349386-183045315-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2283723822-742349386-183045315-1006 - Limited - Enabled)
***** (S-1-5-21-2283723822-742349386-183045315-1001 - Administrator - Enabled) => C:\Users\*****

==================== Faulty Device Manager Devices =============

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/09/2015 11:34:13 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 707641

Error: (03/09/2015 11:34:13 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 707641

Error: (03/09/2015 11:34:13 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/09/2015 11:22:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1188

Error: (03/09/2015 11:22:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1188

Error: (03/09/2015 11:22:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/09/2015 11:22:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: smartlogon.exe, Version: 1.0.14.4, Zeitstempel: 0x4f41f50c
Name des fehlerhaften Moduls: smartlogon.exe, Version: 1.0.14.4, Zeitstempel: 0x4f41f50c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008a8e
ID des fehlerhaften Prozesses: 0x23ac
Startzeit der fehlerhaften Anwendung: 0xsmartlogon.exe0
Pfad der fehlerhaften Anwendung: smartlogon.exe1
Pfad des fehlerhaften Moduls: smartlogon.exe2
Berichtskennung: smartlogon.exe3
Vollständiger Name des fehlerhaften Pakets: smartlogon.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: smartlogon.exe5

Error: (03/08/2015 05:16:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1156

Error: (03/08/2015 05:16:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1156

Error: (03/08/2015 05:16:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (03/09/2015 00:29:56 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:29:25 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:28:54 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:28:24 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:27:53 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:27:22 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:26:51 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:26:21 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:25:50 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe

Error: (03/09/2015 00:25:19 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    29f4C:\Windows\System32\wscript.exe


Microsoft Office Sessions:
=========================
Error: (03/09/2015 11:34:13 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 707641

Error: (03/09/2015 11:34:13 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 707641

Error: (03/09/2015 11:34:13 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/09/2015 11:22:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1188

Error: (03/09/2015 11:22:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1188

Error: (03/09/2015 11:22:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (03/09/2015 11:22:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: smartlogon.exe1.0.14.44f41f50csmartlogon.exe1.0.14.44f41f50cc000000500008a8e23ac01d05a52eedcba84C:\Program Files (x86)\ASUS\FaceLogon\smartlogon.exeC:\Program Files (x86)\ASUS\FaceLogon\smartlogon.exe2e74a531-c646-11e4-bec4-c48508316da6

Error: (03/08/2015 05:16:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1156

Error: (03/08/2015 05:16:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1156

Error: (03/08/2015 05:16:50 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


CodeIntegrity Errors:
===================================
  Date: 2015-02-20 10:27:13.246
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:13.139
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:13.059
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:12.854
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:12.781
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:12.701
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:10.041
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:09.326
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:23:01.423
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:23:01.301
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
Percentage of memory in use: 75%
Total physical RAM: 3981.72 MB
Available physical RAM: 973.29 MB
Total Pagefile: 8077.72 MB
Available Pagefile: 4255.23 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:102.2 GB) (Free:18.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:121.61 GB) (Free:117.4 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: C14CBD8D)

Partition: GPT Partition Type.

==================== End Of Log ============================


schrauber 09.03.2015 19:02

USB Stick anklemmen, nicht mehr abklemmen.


http://www.filepony.de/icon/panda_usb_vaccine.png Panda USB Vaccine

Bitte lade Dir von hier Panda USB Vaccine herunter.



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

Oktavius 10.03.2015 01:09

Super Danke dir bereits im Voraus!

:dankeschoen:
Hier die Logfiles:

FRST.txt

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2015 03
Ran by **** (administrator) on **** on 10-03-2015 01:01:04
Running from C:\Users\****\Desktop\Virus
Loaded Profiles: **** (Available profiles: **** & Andrea & DefaultAppPool)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\DptfParticipantProcessorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe
() C:\Windows\SysWOW64\DptfPolicyCriticalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(Panda Security) C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Spotify Ltd) C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\SysWOW64\DptfPolicyLpmServiceHelper.exe [13824 2012-02-20] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2409272 2012-10-06] (Logitech, Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 7\MMReminderService.exe [37392 2007-05-17] (Mindjet)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-01-28] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Spotify Web Helper] => C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: CmjBrowserHelperObject Object -> {07A11D74-9D25-4fea-A833-8B0D76A5577A} -> C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll [2007-05-17] (Mindjet)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2012-10-06] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1

FireFox:
========
FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\hcof00pn.default
FF DefaultSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2283723822-742349386-183045315-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll [2013-03-12] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-03-10]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-10-03]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2012-11-02]
FF HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (Logitech SetPoint) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2012-11-04]
CHR Extension: (iCloud Bookmarks) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2014-02-15]
CHR Extension: (Isoball 3) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj [2013-10-13]
CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Citavi Picker) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-04-01]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-11-02]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-10] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
R2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
R2 DptfPolicyCriticalService; C:\Windows\SysWOW64\DptfPolicyCriticalService.exe [19456 2012-02-20] ()
S2 DptfPolicyLpmService; C:\Windows\SysWOW64\DptfPolicyLpmService.exe [24576 2012-02-20] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Users\****\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-04-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-07] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] ()
S3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-07-14] (Windows (R) Win 7 DDK provider)
S3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [19104 2012-07-14] (ASUS)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-10-11] (ASIX Electronics Corp.)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150224.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2014-05-08] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150306.001\IDSvia64.sys [669400 2015-02-13] (Symantec Corporation)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [26504 2012-04-10] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-07] (Microsoft Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150308.001\ENG64.SYS [129752 2015-01-21] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150308.001\EX64.SYS [2137304 2015-01-21] (Symantec Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1506000.020\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-10] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2015-01-28] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
U3 idsvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-10 01:00 - 2015-03-10 01:00 - 00001120 _____ () C:\Users\****\Desktop\JRT.txt
2015-03-10 00:55 - 2015-03-10 00:55 - 01388333 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe
2015-03-10 00:47 - 2015-03-10 00:50 - 00000000 ____D () C:\AdwCleaner
2015-03-09 23:38 - 2015-03-10 00:52 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-09 23:38 - 2015-03-09 23:38 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-09 23:37 - 2015-03-09 23:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\****\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-09 23:37 - 2015-03-09 23:37 - 02171392 _____ () C:\Users\****\Desktop\AdwCleaner_4.112.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00848856 _____ (Panda Security ) C:\Users\****\Desktop\USBVaccineSetup.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00003108 _____ () C:\WINDOWS\System32\Tasks\PandaUSBVaccine
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Panda Security
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\Program Files (x86)\Panda USB Vaccine
2015-03-09 13:56 - 2015-03-09 13:56 - 01483336 _____ (Microsoft Corporation) C:\Users\****\Desktop\mediacreationtool.exe
2015-03-09 12:31 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\****\Desktop\Neues Textdokument.txt
2015-03-09 12:29 - 2015-03-09 12:29 - 00002530 _____ () C:\Users\****\Desktop\Lizenzen.txt
2015-03-09 12:28 - 2015-03-09 12:28 - 00380416 _____ () C:\Users\****\Desktop\s5ezzdql.exe
2015-03-09 12:25 - 2015-03-10 01:01 - 00000000 ____D () C:\FRST
2015-03-09 12:23 - 2015-03-10 01:01 - 00000000 ____D () C:\Users\****\Desktop\Virus
2015-03-09 12:23 - 2015-03-09 12:23 - 00000000 _____ () C:\Users\****\defogger_reenable
2015-03-09 12:20 - 2015-03-09 12:21 - 11587952 _____ (McAfee Inc) C:\Users\****\Desktop\stinger32.exe
2015-03-09 12:18 - 2015-03-09 12:19 - 00000000 ____D () C:\Users\****\Desktop\LicenseCrawler
2015-03-09 12:17 - 2015-03-09 12:17 - 01393511 _____ () C:\Users\****\Desktop\licensecrawler_1.43.732.zip
2015-03-04 22:27 - 2015-03-08 17:11 - 00000000 ____D () C:\Users\****\Desktop\Studienarbeit
2015-03-04 10:13 - 2015-03-04 10:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-03-04 10:13 - 2015-01-28 20:49 - 00112496 ____R (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\acsock64.sys
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls
2015-02-25 12:18 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2015-02-24 03:41 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-24 03:41 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-16 09:24 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-16 09:24 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-16 09:24 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-16 09:24 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-16 09:24 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-16 09:24 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-16 09:24 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-16 09:24 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-16 09:24 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-16 09:24 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-16 09:24 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-16 09:24 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-16 09:24 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-16 09:24 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-16 09:24 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-16 09:23 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-16 09:23 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-16 09:23 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-16 09:23 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-16 09:23 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-16 09:23 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-16 09:23 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-16 09:23 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-16 09:23 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-16 09:23 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-16 09:23 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-16 09:23 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-16 09:23 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-16 09:23 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-16 09:23 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-16 09:23 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-10 01:01 - 2013-03-20 13:23 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-10 01:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-10 01:00 - 2012-02-24 03:29 - 00001148 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-10 00:56 - 2013-09-30 05:14 - 02072588 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-10 00:56 - 2013-09-30 04:56 - 00889374 _____ () C:\WINDOWS\system32\perfh007.dat
2015-03-10 00:56 - 2013-09-30 04:56 - 00205446 _____ () C:\WINDOWS\system32\perfc007.dat
2015-03-10 00:54 - 2013-11-06 11:51 - 00000000 ____D () C:\Users\****\AppData\Local\CrashDumps
2015-03-10 00:54 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-03-10 00:54 - 2012-12-02 23:43 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype
2015-03-10 00:53 - 2012-10-03 15:32 - 00000000 ___RD () C:\Users\****\Dropbox
2015-03-10 00:53 - 2012-10-03 15:30 - 00000000 ____D () C:\Users\****\AppData\Roaming\Dropbox
2015-03-10 00:52 - 2013-11-07 08:40 - 00000000 __RDO () C:\Users\****\SkyDrive
2015-03-10 00:52 - 2013-11-07 01:00 - 00000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2015-03-10 00:52 - 2012-02-24 03:29 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-10 00:51 - 2013-09-29 20:04 - 00220874 _____ () C:\WINDOWS\PFRO.log
2015-03-10 00:51 - 2013-08-22 15:46 - 00339813 _____ () C:\WINDOWS\setupact.log
2015-03-10 00:51 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-10 00:51 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-10 00:46 - 2012-10-03 16:18 - 00000000 ____D () C:\Users\****\Documents\Outlook-Dateien
2015-03-09 23:54 - 2013-11-07 04:23 - 01202574 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-09 23:54 - 2013-11-06 22:12 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2283723822-742349386-183045315-1001
2015-03-09 23:35 - 2014-02-15 05:49 - 00000000 ____D () C:\Users\****\AppData\Local\769A133B-0AED-452E-A98A-A2C94FEF5322.aplzod
2015-03-09 14:03 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-03-09 13:56 - 2012-12-15 13:27 - 00000000 __RHD () C:\ESD
2015-03-09 13:55 - 2012-10-16 00:46 - 00003994 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{579749A9-A7ED-4DBF-B3BE-1B7363949C56}
2015-03-09 13:53 - 2014-03-22 16:30 - 00000000 ____D () C:\Users\****\Documents\Citavi 4
2015-03-09 13:53 - 2013-11-07 04:18 - 00000000 ____D () C:\Users\****
2015-03-09 13:52 - 2012-10-17 17:52 - 00000000 ____D () C:\Users\****\Documents\Corps
2015-03-09 13:22 - 2012-10-03 16:20 - 00000000 ____D () C:\Users\****\Documents\Uni
2015-03-08 17:02 - 2013-11-06 22:08 - 01165312 ___SH () C:\Users\****\Desktop\Thumbs.db
2015-03-07 17:16 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-04 10:13 - 2013-11-24 16:20 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-04 10:13 - 2013-11-06 23:43 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-04 10:12 - 2012-10-03 16:24 - 00000000 ____D () C:\Users\****\Desktop\Programme
2015-03-04 10:11 - 2014-12-04 20:56 - 00000000 ____D () C:\Users\****\Desktop\Schwerpunkt
2015-03-02 13:21 - 2012-10-03 16:19 - 00000000 ____D () C:\Users\****\AppData\Roaming\Swiss Academic Software
2015-02-25 13:18 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-21 00:48 - 2012-10-03 15:32 - 00001107 _____ () C:\Users\****\Desktop\Dropbox.lnk
2015-02-21 00:48 - 2012-10-03 15:31 - 00000000 ____D () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-20 11:21 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-20 10:10 - 2013-08-22 15:44 - 00479376 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-20 10:08 - 2012-10-03 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-20 10:08 - 2009-07-14 03:34 - 00000545 _____ () C:\WINDOWS\win.ini
2015-02-16 09:28 - 2013-07-25 10:43 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-16 09:24 - 2012-10-03 16:28 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-13 11:55 - 2012-02-24 03:29 - 00004120 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-13 11:55 - 2012-02-24 03:29 - 00003884 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2013-11-07 08:42 - 2013-11-07 08:42 - 0000021 _____ () C:\Users\****\AppData\Roaming\my_intel.sys
2013-11-07 01:00 - 2015-03-10 00:52 - 0000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2014-08-05 02:05 - 2014-08-05 02:05 - 0002203 _____ () C:\Users\****\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2013-11-07 01:36 - 2013-11-07 01:38 - 0037795 _____ () C:\Users\****\AppData\Local\WiDiSetupLog.20131107.013659.wdl
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2012-10-05 14:19 - 2013-11-14 20:12 - 0003349 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjmrte2.dll
C:\Users\****\AppData\Local\Temp\Quarantine.exe
C:\Users\****\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-04 21:18

==================== End Of Log ============================

--- --- ---



JRT.txt
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 8.1 Pro x64
Ran by **** on 10.03.2015 at  0:55:40,99
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\****\appdata\local\{74B5754B-6441-41FD-93F7-FD93D702156C}
Successfully deleted: [Empty Folder] C:\Users\****\appdata\local\{9A347B3E-2EBD-4058-A9D3-456CC1AE830B}
Successfully deleted: [Empty Folder] C:\Users\****\appdata\local\{A50460B5-DEB3-46DF-99DF-BE3A9B6B9DD2}



~~~ FireFox

Emptied folder: C:\Users\****\AppData\Roaming\mozilla\firefox\profiles\hcof00pn.default\minidumps [34 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.03.2015 at  1:00:11,02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


mbam.txt

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 09.03.2015
Scan Time: 23:46:11
Logfile: mbam.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.03.09.06
Rootkit Database: v2015.02.25.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: ****

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 480808
Time Elapsed: 7 min, 4 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

AdwCleaner[S0].txt

Code:

# AdwCleaner v4.112 - Bericht erstellt 10/03/2015 um 00:50:53
# Aktualisiert 09/03/2015 von Xplode
# Datenbank : 2015-03-05.1 [Server]
# Betriebssystem : Windows 8.1 Pro  (x64)
# Benutzername : **** - ****
# Gestarted von : C:\Users\****\Desktop\AdwCleaner_4.112.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\Users\Andrea\AppData\LocalLow\HPAppData
Ordner Gelöscht : C:\Users\****\AppData\LocalLow\HPAppData
Ordner Gelöscht : C:\Users\Andrea\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Ordner Gelöscht : C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Datei Gelöscht : C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
Datei Gelöscht : C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{28684E8B-8FB1-4DE8-A201-BC65A5751191}
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.loc;*.lo

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v29.0.1 (de)

[hcof00pn.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Ask.com");

-\\ Google Chrome v40.0.2214.115


*************************

AdwCleaner[R0].txt - [2542 Bytes] - [10/03/2015 00:47:46]
AdwCleaner[S0].txt - [2105 Bytes] - [10/03/2015 00:50:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2164  Bytes] ##########


schrauber 10.03.2015 19:42


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)

Oktavius 11.03.2015 00:21

Moin Moin, Danke erst einmal für deine Hilfe

Das Problem liegt allerdings immer noch vor.
Kopiere Datei auf den gerade erst formatierten USB-Stick und die Datei erscheint auf dem Stick zusammen mit seiner Verknüpfung sowie der Verknüpfung mit dem Namen "System Volume Informaton".

Liegt es vielleicht daran, dass der securitycheck nicht funktionierte??

die log.txt von ESET

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=baf9460723b20740a3877d778023e657
# engine=22845
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-03-10 11:08:59
# local_time=2015-03-11 12:08:59 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Norton 360'
# compatibility_mode=3598 16777213 100 100 2712 176691435 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 9447764 50910232 0 0
# scanned=234933
# found=0
# cleaned=0
# scan_time=2475

der Security Check sagte nur folgendes:
Code:

UNSUPPORTED OPERATING SYSTEM! ABORTED!

und hier der frische FRST


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2015 03
Ran by **** (administrator) on **** on 11-03-2015 00:19:22
Running from C:\Users\****\Desktop\Virus
Loaded Profiles: **** (Available profiles: **** & Andrea & DefaultAppPool)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\DptfParticipantProcessorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe
() C:\Windows\SysWOW64\DptfPolicyCriticalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(Panda Security) C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Spotify Ltd) C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\SysWOW64\DptfPolicyLpmServiceHelper.exe [13824 2012-02-20] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2409272 2012-10-06] (Logitech, Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 7\MMReminderService.exe [37392 2007-05-17] (Mindjet)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-01-28] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Spotify Web Helper] => C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: CmjBrowserHelperObject Object -> {07A11D74-9D25-4fea-A833-8B0D76A5577A} -> C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll [2007-05-17] (Mindjet)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2012-10-06] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1

FireFox:
========
FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\hcof00pn.default
FF DefaultSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2283723822-742349386-183045315-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll [2013-03-12] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-03-10]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-10-03]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2012-11-02]
FF HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (Logitech SetPoint) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2012-11-04]
CHR Extension: (iCloud Bookmarks) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2014-02-15]
CHR Extension: (Isoball 3) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj [2013-10-13]
CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Citavi Picker) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-04-01]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-11-02]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-10] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
R2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
R2 DptfPolicyCriticalService; C:\Windows\SysWOW64\DptfPolicyCriticalService.exe [19456 2012-02-20] ()
S2 DptfPolicyLpmService; C:\Windows\SysWOW64\DptfPolicyLpmService.exe [24576 2012-02-20] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Users\****\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-04-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-07] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] ()
S3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-07-14] (Windows (R) Win 7 DDK provider)
S3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [19104 2012-07-14] (ASUS)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-10-11] (ASIX Electronics Corp.)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150309.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2014-05-08] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150308.003\IDSvia64.sys [669400 2015-02-13] (Symantec Corporation)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [26504 2012-04-10] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-07] (Microsoft Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150310.003\ENG64.SYS [129752 2015-01-21] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150310.003\EX64.SYS [2137304 2015-01-21] (Symantec Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1506000.020\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-10] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2015-01-28] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
U3 idsvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-10 23:22 - 2015-03-10 23:22 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-03-10 01:00 - 2015-03-10 01:00 - 00001120 _____ () C:\Users\****\Desktop\JRT.txt
2015-03-10 00:55 - 2015-03-10 00:55 - 01388333 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe
2015-03-10 00:47 - 2015-03-10 00:50 - 00000000 ____D () C:\AdwCleaner
2015-03-09 23:38 - 2015-03-10 11:53 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-09 23:38 - 2015-03-09 23:38 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-09 23:37 - 2015-03-09 23:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\****\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-09 23:37 - 2015-03-09 23:37 - 02171392 _____ () C:\Users\****\Desktop\AdwCleaner_4.112.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00848856 _____ (Panda Security ) C:\Users\****\Desktop\USBVaccineSetup.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00003108 _____ () C:\WINDOWS\System32\Tasks\PandaUSBVaccine
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Panda Security
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\Program Files (x86)\Panda USB Vaccine
2015-03-09 13:56 - 2015-03-09 13:56 - 01483336 _____ (Microsoft Corporation) C:\Users\****\Desktop\mediacreationtool.exe
2015-03-09 12:31 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\****\Desktop\Neues Textdokument.txt
2015-03-09 12:29 - 2015-03-09 12:29 - 00002530 _____ () C:\Users\****\Desktop\Lizenzen.txt
2015-03-09 12:28 - 2015-03-09 12:28 - 00380416 _____ () C:\Users\****\Desktop\s5ezzdql.exe
2015-03-09 12:25 - 2015-03-11 00:19 - 00000000 ____D () C:\FRST
2015-03-09 12:23 - 2015-03-11 00:19 - 00000000 ____D () C:\Users\****\Desktop\Virus
2015-03-09 12:23 - 2015-03-09 12:23 - 00000000 _____ () C:\Users\****\defogger_reenable
2015-03-09 12:20 - 2015-03-09 12:21 - 11587952 _____ (McAfee Inc) C:\Users\****\Desktop\stinger32.exe
2015-03-09 12:18 - 2015-03-09 12:19 - 00000000 ____D () C:\Users\****\Desktop\LicenseCrawler
2015-03-09 12:17 - 2015-03-09 12:17 - 01393511 _____ () C:\Users\****\Desktop\licensecrawler_1.43.732.zip
2015-03-04 22:27 - 2015-03-08 17:11 - 00000000 ____D () C:\Users\****\Desktop\Studienarbeit
2015-03-04 10:13 - 2015-03-04 10:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-03-04 10:13 - 2015-01-28 20:49 - 00112496 ____R (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\acsock64.sys
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls
2015-02-25 12:18 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2015-02-24 03:41 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-24 03:41 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-16 09:24 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-16 09:24 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-16 09:24 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-16 09:24 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-16 09:24 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-16 09:24 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-16 09:24 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-16 09:24 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-16 09:24 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-16 09:24 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-16 09:24 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-16 09:24 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-16 09:24 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-16 09:24 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-16 09:24 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-16 09:23 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-16 09:23 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-16 09:23 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-16 09:23 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-16 09:23 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-16 09:23 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-16 09:23 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-16 09:23 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-16 09:23 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-16 09:23 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-16 09:23 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-16 09:23 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-16 09:23 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-16 09:23 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-16 09:23 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-16 09:23 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-11 00:01 - 2013-03-20 13:23 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-11 00:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-11 00:00 - 2012-02-24 03:29 - 00001148 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-10 23:26 - 2013-11-07 04:23 - 01397932 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-10 23:22 - 2012-10-03 16:18 - 00000000 ____D () C:\Users\****\Documents\Outlook-Dateien
2015-03-10 23:21 - 2013-09-30 05:14 - 02072588 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-10 23:21 - 2013-09-30 04:56 - 00889374 _____ () C:\WINDOWS\system32\perfh007.dat
2015-03-10 23:21 - 2013-09-30 04:56 - 00205446 _____ () C:\WINDOWS\system32\perfc007.dat
2015-03-10 23:16 - 2013-08-22 15:46 - 00340608 _____ () C:\WINDOWS\setupact.log
2015-03-10 23:16 - 2012-10-16 00:46 - 00003994 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{579749A9-A7ED-4DBF-B3BE-1B7363949C56}
2015-03-10 23:12 - 2014-02-15 05:49 - 00000000 ____D () C:\Users\****\AppData\Local\769A133B-0AED-452E-A98A-A2C94FEF5322.aplzod
2015-03-10 12:00 - 2012-02-24 03:29 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-10 00:54 - 2013-11-06 11:51 - 00000000 ____D () C:\Users\****\AppData\Local\CrashDumps
2015-03-10 00:54 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-03-10 00:54 - 2012-12-02 23:43 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype
2015-03-10 00:53 - 2012-10-03 15:32 - 00000000 ___RD () C:\Users\****\Dropbox
2015-03-10 00:53 - 2012-10-03 15:30 - 00000000 ____D () C:\Users\****\AppData\Roaming\Dropbox
2015-03-10 00:52 - 2013-11-07 08:40 - 00000000 __RDO () C:\Users\****\SkyDrive
2015-03-10 00:52 - 2013-11-07 01:00 - 00000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2015-03-10 00:51 - 2013-09-29 20:04 - 00220874 _____ () C:\WINDOWS\PFRO.log
2015-03-10 00:51 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-10 00:51 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-09 23:54 - 2013-11-06 22:12 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2283723822-742349386-183045315-1001
2015-03-09 14:03 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-03-09 13:56 - 2012-12-15 13:27 - 00000000 __RHD () C:\ESD
2015-03-09 13:53 - 2014-03-22 16:30 - 00000000 ____D () C:\Users\****\Documents\Citavi 4
2015-03-09 13:53 - 2013-11-07 04:18 - 00000000 ____D () C:\Users\****
2015-03-09 13:52 - 2012-10-17 17:52 - 00000000 ____D () C:\Users\****\Documents\Corps
2015-03-09 13:22 - 2012-10-03 16:20 - 00000000 ____D () C:\Users\****\Documents\Uni
2015-03-08 17:02 - 2013-11-06 22:08 - 01165312 ___SH () C:\Users\****\Desktop\Thumbs.db
2015-03-07 17:16 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-04 10:13 - 2013-11-24 16:20 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-04 10:13 - 2013-11-06 23:43 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-04 10:12 - 2012-10-03 16:24 - 00000000 ____D () C:\Users\****\Desktop\Programme
2015-03-04 10:11 - 2014-12-04 20:56 - 00000000 ____D () C:\Users\****\Desktop\Schwerpunkt
2015-03-02 13:21 - 2012-10-03 16:19 - 00000000 ____D () C:\Users\****\AppData\Roaming\Swiss Academic Software
2015-02-25 13:18 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-21 00:48 - 2012-10-03 15:32 - 00001107 _____ () C:\Users\****\Desktop\Dropbox.lnk
2015-02-21 00:48 - 2012-10-03 15:31 - 00000000 ____D () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-20 11:21 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-20 10:10 - 2013-08-22 15:44 - 00479376 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-20 10:08 - 2012-10-03 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-20 10:08 - 2009-07-14 03:34 - 00000545 _____ () C:\WINDOWS\win.ini
2015-02-16 09:28 - 2013-07-25 10:43 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-16 09:24 - 2012-10-03 16:28 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-13 11:55 - 2012-02-24 03:29 - 00004120 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-13 11:55 - 2012-02-24 03:29 - 00003884 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2013-11-07 08:42 - 2013-11-07 08:42 - 0000021 _____ () C:\Users\****\AppData\Roaming\my_intel.sys
2013-11-07 01:00 - 2015-03-10 00:52 - 0000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2014-08-05 02:05 - 2014-08-05 02:05 - 0002203 _____ () C:\Users\****\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2013-11-07 01:36 - 2013-11-07 01:38 - 0037795 _____ () C:\Users\****\AppData\Local\WiDiSetupLog.20131107.013659.wdl
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2012-10-05 14:19 - 2013-11-14 20:12 - 0003349 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjmrte2.dll
C:\Users\****\AppData\Local\Temp\Quarantine.exe
C:\Users\****\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-10 11:08

==================== End Of Log ============================

--- --- ---

--- --- ---

schrauber 11.03.2015 18:05

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.





Nochmal frisches FRST log bitte. Wenn sich dann keine neuen Dateien mehr erstellen entfernen wir noch die Verknüpfungen.

Oktavius 11.03.2015 23:06

Moin, also während der Fix ausgeführt wurde, hat sich windows einmal runtergefahren und neu gestartet, ist das normal?

Hier der Fixlog.txt

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by **** at 2015-03-11 22:43:53 Run:1
Running from C:\Users\****\Desktop\Virus
Loaded Profiles: **** (Available profiles: **** & Andrea & DefaultAppPool)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Emptytemp:
*****************

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Windows\CurrentVersion\Run\\MerciJacquieMichel => value deleted successfully.
Could not move "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" => Scheduled to move on reboot.
C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
EmptyTemp: => Removed 3.7 GB temporary data.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-03-11 22:51:12)<=

C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe => Is moved successfully.

==== End of Fixlog 22:51:12 ====

Als ich das FRST icon angelickt habe, ist der norton scanner sofort angesprungen und hat die Datei entfernt. Auch ein erneuter download brachte das selbe ergebnis.
Nun habe ich die frst64.exe aus dem Ordner "Alte Version FRST" gestartet, er hat sich automatisch das update geladen und nun kann ich dir hier die ergebnisse anzeigen.

FRST.txt

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by **** (administrator) on "****" on 11-03-2015 23:01:13
Running from C:\Users\****\Desktop\Virus\FRST-OlderVersion
Loaded Profiles: **** (Available profiles: **** & Andrea & DefaultAppPool)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\DptfParticipantProcessorService.exe
() C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Windows\SysWOW64\DptfPolicyCriticalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Panda Security) C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Spotify Ltd) C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\SysWOW64\DptfPolicyLpmServiceHelper.exe [13824 2012-02-20] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2409272 2012-10-06] (Logitech, Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 7\MMReminderService.exe [37392 2007-05-17] (Mindjet)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-01-28] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Spotify Web Helper] => C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: CmjBrowserHelperObject Object -> {07A11D74-9D25-4fea-A833-8B0D76A5577A} -> C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll [2007-05-17] (Mindjet)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2012-10-06] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1

FireFox:
========
FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\hcof00pn.default
FF DefaultSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2283723822-742349386-183045315-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll [2013-03-12] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-03-11]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-10-03]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2012-11-02]
FF HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (Logitech SetPoint) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2012-11-04]
CHR Extension: (iCloud Bookmarks) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2014-02-15]
CHR Extension: (Isoball 3) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj [2013-10-13]
CHR Extension: (Google Wallet) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Citavi Picker) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-04-01]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-11-02]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-10] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
R2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
R2 DptfPolicyCriticalService; C:\Windows\SysWOW64\DptfPolicyCriticalService.exe [19456 2012-02-20] ()
S2 DptfPolicyLpmService; C:\Windows\SysWOW64\DptfPolicyLpmService.exe [24576 2012-02-20] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-04-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-07] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
S2 HPSLPSVC; C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] ()
S3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-07-14] (Windows (R) Win 7 DDK provider)
S3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [19104 2012-07-14] (ASUS)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-10-11] (ASIX Electronics Corp.)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150309.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2014-05-08] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2015-03-10] (Emsisoft GmbH)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150310.001\IDSvia64.sys [669400 2015-02-13] (Symantec Corporation)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [26504 2012-04-10] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-11] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-07] (Microsoft Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150310.040\ENG64.SYS [129752 2015-01-21] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150310.040\EX64.SYS [2137304 2015-01-21] (Symantec Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1506000.020\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-10] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2015-01-28] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
U3 idsvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-11 01:41 - 2015-03-11 01:41 - 00051944 _____ () C:\Users\****\Desktop\FRST.txt
2015-03-11 01:39 - 2015-03-11 01:39 - 00003192 _____ () C:\Users\****\Desktop\a2scan_150311-011001.txt
2015-03-11 01:05 - 2015-03-11 01:05 - 00000757 _____ () C:\Users\****\Desktop\Start Emsisoft Emergency Kit.lnk
2015-03-11 01:05 - 2015-03-11 01:05 - 00000000 ____D () C:\EEK
2015-03-11 00:22 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\****\Desktop\Neues Textdokument - Kopie.txt
2015-03-10 01:00 - 2015-03-10 01:00 - 00001120 _____ () C:\Users\****\Desktop\JRT.txt
2015-03-10 00:55 - 2015-03-10 00:55 - 01388333 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe
2015-03-10 00:47 - 2015-03-10 00:50 - 00000000 ____D () C:\AdwCleaner
2015-03-09 23:38 - 2015-03-11 22:51 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-09 23:38 - 2015-03-09 23:38 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-09 23:37 - 2015-03-09 23:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\****\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-09 23:37 - 2015-03-09 23:37 - 02171392 _____ () C:\Users\****\Desktop\AdwCleaner_4.112.exe
2015-03-09 23:36 - 2015-03-11 02:01 - 00003108 _____ () C:\WINDOWS\System32\Tasks\PandaUSBVaccine
2015-03-09 23:36 - 2015-03-11 02:01 - 00000000 ____D () C:\Program Files (x86)\Panda USB Vaccine
2015-03-09 23:36 - 2015-03-09 23:36 - 00848856 _____ (Panda Security ) C:\Users\****\Desktop\USBVaccineSetup.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Panda Security
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2015-03-09 13:56 - 2015-03-09 13:56 - 01483336 _____ (Microsoft Corporation) C:\Users\****\Desktop\mediacreationtool.exe
2015-03-09 12:31 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\****\Desktop\Neues Textdokument.txt
2015-03-09 12:29 - 2015-03-09 12:29 - 00002530 _____ () C:\Users\****\Desktop\Lizenzen.txt
2015-03-09 12:28 - 2015-03-09 12:28 - 00380416 _____ () C:\Users\****\Desktop\s5ezzdql.exe
2015-03-09 12:25 - 2015-03-11 23:01 - 00000000 ____D () C:\FRST
2015-03-09 12:23 - 2015-03-11 22:58 - 00000000 ____D () C:\Users\****\Desktop\Virus
2015-03-09 12:23 - 2015-03-09 12:23 - 00000000 _____ () C:\Users\****\defogger_reenable
2015-03-09 12:20 - 2015-03-09 12:21 - 11587952 _____ (McAfee Inc) C:\Users\****\Desktop\stinger32.exe
2015-03-09 12:18 - 2015-03-09 12:19 - 00000000 ____D () C:\Users\****\Desktop\LicenseCrawler
2015-03-09 12:17 - 2015-03-09 12:17 - 01393511 _____ () C:\Users\****\Desktop\licensecrawler_1.43.732.zip
2015-03-04 22:27 - 2015-03-08 17:11 - 00000000 ____D () C:\Users\****\Desktop\Studienarbeit
2015-03-04 10:13 - 2015-03-04 10:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-03-04 10:13 - 2015-01-28 20:49 - 00112496 ____R (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\acsock64.sys
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls
2015-02-25 12:18 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2015-02-24 03:41 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-24 03:41 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-16 09:24 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-16 09:24 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-16 09:24 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-16 09:24 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-16 09:24 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-16 09:24 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-16 09:24 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-16 09:24 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-16 09:24 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-16 09:24 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-16 09:24 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-16 09:24 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-16 09:24 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-16 09:24 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-16 09:24 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-16 09:23 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-16 09:23 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-16 09:23 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-16 09:23 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-16 09:23 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-16 09:23 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-16 09:23 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-16 09:23 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-16 09:23 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-16 09:23 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-16 09:23 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-16 09:23 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-16 09:23 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-16 09:23 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-16 09:23 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-16 09:23 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-11 23:01 - 2013-11-07 04:23 - 01905712 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-11 23:01 - 2013-03-20 13:23 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-11 23:01 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-03-11 23:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-11 23:00 - 2012-02-24 03:29 - 00001148 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-11 22:58 - 2013-09-30 05:14 - 02072588 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-11 22:58 - 2013-09-30 04:56 - 00889374 _____ () C:\WINDOWS\system32\perfh007.dat
2015-03-11 22:58 - 2013-09-30 04:56 - 00205446 _____ () C:\WINDOWS\system32\perfc007.dat
2015-03-11 22:56 - 2013-11-06 22:12 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2283723822-742349386-183045315-1001
2015-03-11 22:55 - 2012-10-03 15:32 - 00000000 ___RD () C:\Users\****\Dropbox
2015-03-11 22:55 - 2012-10-03 15:30 - 00000000 ____D () C:\Users\****\AppData\Roaming\Dropbox
2015-03-11 22:52 - 2013-11-07 01:00 - 00000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2015-03-11 22:52 - 2012-12-02 23:43 - 00000000 ____D () C:\Users\****\AppData\Roaming\Skype
2015-03-11 22:51 - 2013-11-07 08:40 - 00000000 __RDO () C:\Users\****\SkyDrive
2015-03-11 22:51 - 2012-02-24 03:29 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-11 22:50 - 2013-09-29 20:04 - 00225360 _____ () C:\WINDOWS\PFRO.log
2015-03-11 22:50 - 2013-08-22 15:46 - 00340762 _____ () C:\WINDOWS\setupact.log
2015-03-11 22:50 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-11 22:50 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-11 22:45 - 2012-10-03 16:18 - 00000000 ____D () C:\Users\****\Documents\Outlook-Dateien
2015-03-11 22:37 - 2012-10-03 15:32 - 00001107 _____ () C:\Users\****\Desktop\Dropbox.lnk
2015-03-11 22:37 - 2012-10-03 15:31 - 00000000 ____D () C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-03-11 22:33 - 2014-02-15 05:49 - 00000000 ____D () C:\Users\****\AppData\Local\769A133B-0AED-452E-A98A-A2C94FEF5322.aplzod
2015-03-11 02:14 - 2012-10-03 16:50 - 00000000 ____D () C:\Users\****\AppData\Local\Apple Computer
2015-03-10 23:16 - 2012-10-16 00:46 - 00003994 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{579749A9-A7ED-4DBF-B3BE-1B7363949C56}
2015-03-10 00:54 - 2013-11-06 11:51 - 00000000 ____D () C:\Users\****\AppData\Local\CrashDumps
2015-03-10 00:54 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-03-09 14:03 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-03-09 13:56 - 2012-12-15 13:27 - 00000000 __RHD () C:\ESD
2015-03-09 13:53 - 2014-03-22 16:30 - 00000000 ____D () C:\Users\****\Documents\Citavi 4
2015-03-09 13:53 - 2013-11-07 04:18 - 00000000 ____D () C:\Users\****
2015-03-09 13:52 - 2012-10-17 17:52 - 00000000 ____D () C:\Users\****\Documents\Corps
2015-03-09 13:22 - 2012-10-03 16:20 - 00000000 ____D () C:\Users\****\Documents\Uni
2015-03-08 17:02 - 2013-11-06 22:08 - 01165312 ___SH () C:\Users\****\Desktop\Thumbs.db
2015-03-07 17:16 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-04 10:13 - 2013-11-24 16:20 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-04 10:13 - 2013-11-06 23:43 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-04 10:12 - 2012-10-03 16:24 - 00000000 ____D () C:\Users\****\Desktop\Programme
2015-03-04 10:11 - 2014-12-04 20:56 - 00000000 ____D () C:\Users\****\Desktop\Schwerpunkt
2015-03-02 13:21 - 2012-10-03 16:19 - 00000000 ____D () C:\Users\****\AppData\Roaming\Swiss Academic Software
2015-02-20 11:21 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-20 10:10 - 2013-08-22 15:44 - 00479376 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-20 10:08 - 2012-10-03 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-20 10:08 - 2009-07-14 03:34 - 00000545 _____ () C:\WINDOWS\win.ini
2015-02-16 09:28 - 2013-07-25 10:43 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-16 09:24 - 2012-10-03 16:28 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-13 11:55 - 2012-02-24 03:29 - 00004120 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-13 11:55 - 2012-02-24 03:29 - 00003884 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2013-11-07 08:42 - 2013-11-07 08:42 - 0000021 _____ () C:\Users\****\AppData\Roaming\my_intel.sys
2013-11-07 01:00 - 2015-03-11 22:52 - 0000401 _____ () C:\Users\****\AppData\Roaming\sp_data.sys
2014-08-05 02:05 - 2014-08-05 02:05 - 0002203 _____ () C:\Users\****\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2013-11-07 01:36 - 2013-11-07 01:38 - 0037795 _____ () C:\Users\****\AppData\Local\WiDiSetupLog.20131107.013659.wdl
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2012-10-05 14:19 - 2013-11-14 20:12 - 0003349 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplz1cue.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-11 00:46

==================== End Of Log ============================

--- --- ---



Addition.txt

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by **** at 2015-03-11 23:02:00
Running from C:\Users\****\Desktop\Virus\FRST-OlderVersion
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton 360 (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton 360 (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader X (10.1.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS Backtracker (HKLM-x32\...\{C15C060C-ED1C-49EB-83B3-F7C0FD1CD661}) (Version: 3.0.3 - ASUS)
ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.5 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.7 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.7 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.1.7 - ASUS)
ASUS PWR Option (HKLM-x32\...\{B7B60C4F-0DB8-42EF-8EDC-5F21D4C2D73F}) (Version: 1.2.1 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.1.3 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0004 - ASUS)
ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.4 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.4 - ASUS)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0025 - ASUS)
AX88772B Windows 7 Drivers (HKLM-x32\...\InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}) (Version: 1.0.2.0 - ASIX Electronics Corporation)
AX88772B Windows 7 Drivers (x32 Version: 1.0.2.0 - ASIX Electronics Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
C5300 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.06079 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.06079 - Cisco Systems, Inc.) Hidden
Citavi (HKLM-x32\...\{E12C6653-1FF0-4686-ADB8-589C13AE761F}) (Version: 3.3.0.0 - Swiss Academic Software)
Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.3.0.15 - Swiss Academic Software)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
doPDF 7.3 printer (HKLM\...\doPDF 7 printer_is1) (Version:  - Softland)
Dropbox (HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Dropbox) (Version: 3.2.9 - Dropbox, Inc.)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON WF-2510 Series Printer Uninstall (HKLM\...\EPSON WF-2510 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart C5300 All-In-One Driver Software 13.0 Rel. 4 (HKLM\...\{6FA29B87-FED3-45A1-8A95-2FDEE0F6DD18}) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_PaperLabel (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabel_PrintOnDisc (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
hpphotosmartdisclabelplugin (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)
Intel(R) Dynamic Platform & Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 6.0.1.1067 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3308 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1024 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
Intel(R) WiDi (HKLM\...\{BE7E45FA-7F97-4155-87CF-2DEA398995DA}) (Version: 4.2.21.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® AT Service signup (HKLM-x32\...\{CD49AEDB-FFB4-4A9A-A3C2-E9AF814FE6FE}) (Version: 2.0.0.3 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.550 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech SetPoint 6.50 (HKLM\...\sp6) (Version: 6.50.152 - Logitech)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mindjet MindManager Pro 7 (HKLM-x32\...\{3CDFEE23-66D2-4DB0-8269-12634E871725}) (Version: 7.0.429 - Mindjet LLC)
MOBackup - Datensicherung für Outlook (Vollversion) (HKLM-x32\...\MOBackup-DatensicherungfürOutlook) (Version: 7.0 - Heiko Schröder)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
Norton 360 (HKLM-x32\...\N360) (Version: 21.6.0.32 - Symantec Corporation)
Panda USB Vaccine 1.0.1.4 (HKLM-x32\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version:  - Panda Security)
PDF-XChange 3 (HKLM-x32\...\PDF-XChange 3_is1) (Version:  - Tracker Software)
PS_AIO_04_C5300_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6809 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spotify (HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC)
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.16642 - TeamViewer)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\...\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.31 - ASUS)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation)
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2283723822-742349386-183045315-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)

==================== Restore Points  =========================

20-02-2015 10:07:11 Windows Update
24-02-2015 12:18:15 Windows Update
04-03-2015 10:12:36 Installed Cisco AnyConnect Secure Mobility Client

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {01C995FF-D178-4E7B-AC4A-9E950006A207} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {0824384A-6E02-4601-9650-D83C1EB8C205} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {0837D897-84CB-4E30-A8DD-807937A81DFC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-30] (Google Inc.)
Task: {0F1FC558-90E6-41AA-8D37-4FBE69053762} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {118314BB-772D-4B9C-8430-8FFEE872FB3C} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-10-24] (ASUS)
Task: {11E2634C-A98E-419D-B2A1-26B51596D6E5} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86) [2015-03-11] ()
Task: {148318FC-5974-4508-A415-B3AFD16E5DDB} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {20716D4A-7F53-4BCC-A396-90A79DBC0493} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.)
Task: {29308477-8F7E-4D4F-92D5-F1534E61B6F5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {2A12FA94-AE78-4CE3-BCAB-CA6A4798002A} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3C9616B2-742C-4820-AFAE-F3D2459E9677} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {3D966D87-5FE5-4FBC-8E90-DB0F48E454DB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {3E3E65EA-6693-4ACC-947D-206853F50D65} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {42145BE5-4059-431F-919A-1A381C5966DE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {480307B7-D62C-40B4-AC2B-958F633F286F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation)
Task: {56A5C30C-CC9F-40CE-8C9A-A4D7C1696920} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS)
Task: {6913925B-8807-4944-9DC4-D2106FAF17F0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {6FECF9BE-AED8-4627-80ED-91FF5361960F} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {773492A6-4F08-4DAF-9C1B-778BC17ACAED} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {78588675-6CF3-4E50-B5B1-1EC34EAA2F6B} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {7BE4EAA3-492B-441B-9E15-9F5319ECAAB3} - System32\Tasks\PandaUSBVaccine => C:\Program Files (x86)\Panda USB Vaccine\RunInteractiveWin.exe [2009-09-23] ()
Task: {7DDF9673-8D0B-4652-B795-1BEAD1206B65} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {81443F6F-8608-4F5F-9746-49BD355F1F44} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-01-16] (AsusTek)
Task: {8687A636-6CDE-4487-A3BA-E2518973B7CC} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2013-11-27] ()
Task: {8BBF993A-7ACF-4CD2-84BA-1E8BC24671C6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-30] (Google Inc.)
Task: {9FC31335-F46F-48D5-87F9-A1A2E33222C1} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {AA921623-B84A-4EC8-A6DA-5D46323FC6D9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {AE1822A9-629F-44BA-9C16-D1B008EE3111} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {B7874F98-7A73-4D9D-B14B-1FEAB9D5BAB6} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-16] (ASUSTek Computer Inc.)
Task: {C0804079-4CDF-45AB-B431-AAA2FD56F1C8} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {C778374C-94FE-41B0-B705-5FC952201AC0} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {CC4FC069-845E-4644-BE5E-360DE6B864A3} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-06-29] (ASUSTeK Computer Inc.)
Task: {DD548504-31EE-43FF-A573-1E9BCB56DC76} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {DEE297C6-FCCB-4550-833A-ABA172AB4895} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-02-16] (Microsoft Corporation)
Task: {E959E007-A71C-4952-8EA8-22DE146D6227} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {EA49544F-8E18-47FB-85D3-2FD3C8A971D5} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86) [2015-03-11] ()
Task: {F0496437-71B1-4E96-9E9C-3BC2F52CDE46} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {F3BBF756-D937-4E6C-84DA-87C055AF2E05} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {F4B55B2F-BFE3-478B-A5C0-97DDC4A506EF} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {FACB8164-0888-403B-B4E6-7F59329EA90F} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {FBC8485F-A585-489F-8E2C-C65FEABC1BEF} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {FCAB4EAD-2FA5-48CB-88C3-AEAED4EF25CD} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {FFEE4F98-789F-4BC5-9EBF-91D4AC658C46} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2013-01-26 17:51 - 2012-09-18 15:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll
2013-01-26 17:51 - 2012-09-18 15:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll
2012-07-30 03:50 - 2012-02-20 04:31 - 00018944 _____ () C:\WINDOWS\SysWOW64\DptfParticipantProcessorService.exe
2012-07-30 03:50 - 2012-02-20 04:31 - 00019968 _____ () C:\WINDOWS\SysWOW64\DptfPolicyConfigTDPService.exe
2012-07-30 03:50 - 2012-02-20 04:31 - 00019456 _____ () C:\WINDOWS\SysWOW64\DptfPolicyCriticalService.exe
2012-08-24 17:26 - 2012-08-24 17:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2014-11-26 23:46 - 2014-11-26 23:46 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\ErrorReporting.dll
2012-10-06 09:15 - 2012-10-06 09:15 - 01976632 _____ () C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll
2012-10-06 09:14 - 2012-10-06 09:14 - 00071992 _____ () C:\Program Files\Logitech\SetPointP\WinRTProxy.DLL
2015-01-28 21:08 - 2015-01-28 21:08 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-01-31 17:25 - 2012-01-31 17:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2012-08-24 17:17 - 2012-08-24 17:17 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2015-03-04 23:08 - 2015-03-04 23:08 - 00750080 _____ () C:\Users\****\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-11 22:52 - 2015-03-11 22:52 - 00043008 _____ () c:\Users\****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplz1cue.dll
2015-03-04 23:08 - 2015-03-04 23:08 - 00047616 _____ () C:\Users\****\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 23:08 - 2015-03-04 23:08 - 00865280 _____ () C:\Users\****\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 23:07 - 2015-03-04 23:07 - 00200704 _____ () C:\Users\****\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2007-05-17 23:05 - 2007-05-17 23:05 - 00116240 ____R () C:\Program Files (x86)\Mindjet\MindManager 7\zlib.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libglesv2.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libegl.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll
2012-09-08 22:57 - 2012-06-25 18:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-02-24 15:02 - 2015-02-17 23:44 - 14965064 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\****\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\****\Documents\duschkabine.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\****\Documents\duschkabine.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\Users\****\Documents\duschkabine2.jpeg:3or4kl4x13tuuug3Byamue2s4b
AlternateDataStreams: C:\Users\****\Documents\duschkabine2.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\asus\wallpapers\asus.jpg
DNS Servers: 192.168.188.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-2283723822-742349386-183045315-500 - Administrator - Disabled)
Andrea (S-1-5-21-2283723822-742349386-183045315-1007 - Limited - Enabled) => C:\Users\Andrea
Gast (S-1-5-21-2283723822-742349386-183045315-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2283723822-742349386-183045315-1006 - Limited - Enabled)
**** (S-1-5-21-2283723822-742349386-183045315-1001 - Administrator - Enabled) => C:\Users\****

==================== Faulty Device Manager Devices =============

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/11/2015 10:54:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm notepad.exe, Version 6.3.9600.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 11ac

Startzeit: 01d05c4591c66ba3

Endzeit: 8

Anwendungspfad: C:\WINDOWS\system32\notepad.exe

Berichts-ID: 1bd3ae99-c839-11e4-bec7-85a08d3aaed6

Vollständiger Name des fehlerhaften Pakets:

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (03/11/2015 10:52:00 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperWinMain:  CreateSharedMemory() failed.

Error: (03/11/2015 10:52:00 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperCreateSharedMemory:  CreateFileMapping() failed.Last error = [0x00000005]

Error: (03/11/2015 10:50:31 PM) (Source: DptfPolicyCriticalService) (EventID: 1) (User: )
Description: DptfPolicyCriticalServiceServiceMainThread:  NotifyServiceStatusRunning() failed.

Error: (03/11/2015 10:50:31 PM) (Source: DptfPolicyCriticalService) (EventID: 1) (User: )
Description: DptfPolicyCriticalServiceNotifyServiceStatusRunning:  DeviceIoControl() failed.Last error = [0x00000001]

Error: (03/11/2015 10:31:20 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperWinMain:  CreateSharedMemory() failed.

Error: (03/11/2015 10:31:20 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperCreateSharedMemory:  CreateFileMapping() failed.Last error = [0x00000005]

Error: (03/11/2015 00:57:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1047

Error: (03/11/2015 00:57:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1047

Error: (03/11/2015 00:57:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (03/11/2015 11:02:43 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 11:02:12 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 11:01:41 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 11:01:10 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 11:00:39 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 11:00:08 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 10:59:37 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 10:59:06 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 10:58:35 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe

Error: (03/11/2015 10:58:04 PM) (Source: DCOM) (EventID: 10028) (User: JUSTUSHOFFMANN)
Description: localglcaslhhtt    18e0C:\Windows\System32\wscript.exe


Microsoft Office Sessions:
=========================
Error: (03/11/2015 10:54:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: notepad.exe6.3.9600.1638411ac01d05c4591c66ba38C:\WINDOWS\system32\notepad.exe1bd3ae99-c839-11e4-bec7-85a08d3aaed6

Error: (03/11/2015 10:52:00 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperWinMain:  CreateSharedMemory() failed.

Error: (03/11/2015 10:52:00 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperCreateSharedMemory:  CreateFileMapping() failed.Last error = [0x00000005]

Error: (03/11/2015 10:50:31 PM) (Source: DptfPolicyCriticalService) (EventID: 1) (User: )
Description: DptfPolicyCriticalServiceServiceMainThread:  NotifyServiceStatusRunning() failed.

Error: (03/11/2015 10:50:31 PM) (Source: DptfPolicyCriticalService) (EventID: 1) (User: )
Description: DptfPolicyCriticalServiceNotifyServiceStatusRunning:  DeviceIoControl() failed.Last error = [0x00000001]

Error: (03/11/2015 10:31:20 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperWinMain:  CreateSharedMemory() failed.

Error: (03/11/2015 10:31:20 PM) (Source: DptfPolicyLpmServiceHelper) (EventID: 1) (User: )
Description: DptfPolicyLpmServiceHelperCreateSharedMemory:  CreateFileMapping() failed.Last error = [0x00000005]

Error: (03/11/2015 00:57:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1047

Error: (03/11/2015 00:57:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1047

Error: (03/11/2015 00:57:09 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


CodeIntegrity Errors:
===================================
  Date: 2015-02-20 10:27:13.246
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:13.139
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:13.059
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:12.854
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:12.781
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:12.701
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:10.041
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:27:09.326
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:23:01.423
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-02-20 10:23:01.301
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
Percentage of memory in use: 67%
Total physical RAM: 3981.72 MB
Available physical RAM: 1288.67 MB
Total Pagefile: 8077.72 MB
Available Pagefile: 5081.51 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:102.2 GB) (Free:22.34 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:121.61 GB) (Free:117.4 GB) NTFS
Drive e: () (Removable) (Total:1.78 GB) (Free:1.76 GB) FAT
Drive f: () (Removable) (Total:0.25 GB) (Free:0.23 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: C14CBD8D)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 251.9 MB) (Disk ID: 0018DBB5)
Partition 1: (Active) - (Size=252 MB) - (Type=06)

========================================================
Disk: 2 (Size: 1.8 GB) (Disk ID: 342749BA)
Partition 1: (Not Active) - (Size=1.8 GB) - (Type=06)

==================== End Of Log ============================


Das Problem gibt es leider immer noch.
Soll ich das ganze Prozedere, also von deinem ersten Beitrag an, nochmal machen, nur zur Sicherheit, dass ich nichts falsch gemacht habe???

Danke dir!

schrauber 12.03.2015 12:18

Nee, die Datei ist nur hartnäckig. Da gehen wir von aussen ran:


Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).


Oktavius 12.03.2015 15:54

Moin, bin bei meinem Win8.1 wie beschrieben vorgegangen.
Hier das FRST Logfile.
Als ich dieses vom Stick geöffnet habe, hat dieser sich natürlich auch wieder infiziert mit dem Murks. Habe nicht bedacht diesen Post von einem anderen Rechner aus zu tätigen.

Hier aber FRST.txt


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by SYSTEM on MININT-2SU0EUL on 12-03-2015 15:48:39
Running from F:\
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\SysWOW64\DptfPolicyLpmServiceHelper.exe [13824 2012-02-20] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2409272 2012-10-06] (Logitech, Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 7\MMReminderService.exe [37392 2007-05-17] (Mindjet)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-01-28] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\Justus Hoffmann\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\Justus Hoffmann\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\Justus Hoffmann\...\Run: [Spotify Web Helper] => C:\Users\Justus Hoffmann\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\Justus Hoffmann\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\Justus Hoffmann\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\windows\system32\config\systemprofile\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
S2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-10] (Intel Corporation)
S2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
S2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
S2 DptfPolicyCriticalService; C:\Windows\SysWOW64\DptfPolicyCriticalService.exe [19456 2012-02-20] ()
S2 DptfPolicyLpmService; C:\Windows\SysWOW64\DptfPolicyLpmService.exe [24576 2012-02-20] ()
S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
S2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
S2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-04-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-07] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
S2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-07] (Microsoft Corporation)
S2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
S2 HPSLPSVC; C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] ()
S3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-07-14] (Windows (R) Win 7 DDK provider)
S3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [19104 2012-07-14] (ASUS)
S1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-10-11] (ASIX Electronics Corp.)
S1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150309.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2014-05-08] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
S1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2015-03-10] (Emsisoft GmbH)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
S3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
S3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
S3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
S3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
S3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-15] (Symantec Corporation)
S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
S1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150311.001\IDSvia64.sys [669400 2015-02-13] (Symantec Corporation)
S3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [26504 2012-04-10] (Intel Corporation)
S3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
S3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-07] (Microsoft Corporation)
S3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150311.020\ENG64.SYS [129752 2015-01-21] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150311.020\EX64.SYS [2137304 2015-01-21] (Symantec Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
S3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
S1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
S0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
S0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1506000.020\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-10] (Symantec Corporation)
S1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
S1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2015-01-28] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 idsvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-12 08:08 - 2015-03-12 08:17 - 00000000 ____D () C:\UsbFix
2015-03-12 08:08 - 2015-03-12 08:08 - 00001458 _____ () C:\Users\Justus Hoffmann\Desktop\UsbFix.lnk
2015-03-11 01:41 - 2015-03-11 01:41 - 00051944 _____ () C:\Users\Justus Hoffmann\Desktop\FRST.txt
2015-03-11 01:39 - 2015-03-11 01:39 - 00003192 _____ () C:\Users\Justus Hoffmann\Desktop\a2scan_150311-011001.txt
2015-03-11 01:05 - 2015-03-11 01:05 - 00000757 _____ () C:\Users\Justus Hoffmann\Desktop\Start Emsisoft Emergency Kit.lnk
2015-03-11 01:05 - 2015-03-11 01:05 - 00000000 ____D () C:\EEK
2015-03-11 00:22 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\Justus Hoffmann\Desktop\Neues Textdokument - Kopie.txt
2015-03-10 01:00 - 2015-03-10 01:00 - 00001120 _____ () C:\Users\Justus Hoffmann\Desktop\JRT.txt
2015-03-10 00:55 - 2015-03-10 00:55 - 01388333 _____ (Thisisu) C:\Users\Justus Hoffmann\Desktop\JRT.exe
2015-03-10 00:47 - 2015-03-12 00:09 - 00000000 ____D () C:\AdwCleaner
2015-03-09 23:38 - 2015-03-12 14:41 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2015-03-09 23:38 - 2015-03-09 23:38 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2015-03-09 23:37 - 2015-03-09 23:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Justus Hoffmann\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-09 23:37 - 2015-03-09 23:37 - 02171392 _____ () C:\Users\Justus Hoffmann\Desktop\AdwCleaner_4.112.exe
2015-03-09 23:36 - 2015-03-11 02:01 - 00003108 _____ () C:\Windows\System32\Tasks\PandaUSBVaccine
2015-03-09 23:36 - 2015-03-11 02:01 - 00000000 ____D () C:\Program Files (x86)\Panda USB Vaccine
2015-03-09 23:36 - 2015-03-09 23:36 - 00848856 _____ (Panda Security ) C:\Users\Justus Hoffmann\Desktop\USBVaccineSetup.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Panda Security
2015-03-09 13:56 - 2015-03-09 13:56 - 01483336 _____ (Microsoft Corporation) C:\Users\Justus Hoffmann\Desktop\mediacreationtool.exe
2015-03-09 12:31 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\Justus Hoffmann\Desktop\Neues Textdokument.txt
2015-03-09 12:29 - 2015-03-09 12:29 - 00002530 _____ () C:\Users\Justus Hoffmann\Desktop\Lizenzen.txt
2015-03-09 12:28 - 2015-03-09 12:28 - 00380416 _____ () C:\Users\Justus Hoffmann\Desktop\s5ezzdql.exe
2015-03-09 12:25 - 2015-03-12 09:38 - 00000000 ____D () C:\FRST
2015-03-09 12:23 - 2015-03-12 14:42 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Virus
2015-03-09 12:23 - 2015-03-09 12:23 - 00000000 _____ () C:\Users\Justus Hoffmann\defogger_reenable
2015-03-09 12:20 - 2015-03-09 12:21 - 11587952 _____ (McAfee Inc) C:\Users\Justus Hoffmann\Desktop\stinger32.exe
2015-03-09 12:18 - 2015-03-09 12:19 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\LicenseCrawler
2015-03-09 12:17 - 2015-03-09 12:17 - 01393511 _____ () C:\Users\Justus Hoffmann\Desktop\licensecrawler_1.43.732.zip
2015-03-04 22:27 - 2015-03-08 17:11 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Studienarbeit
2015-03-04 10:13 - 2015-01-28 20:49 - 00112496 ____R (Cisco Systems, Inc.) C:\Windows\System32\Drivers\acsock64.sys
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\Windows\System32\locale.nls
2015-02-25 12:18 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\Windows\System32\GlobCollationHost.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GlobCollationHost.dll
2015-02-24 03:41 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2015-02-24 03:41 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-16 09:24 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2015-02-16 09:24 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2015-02-16 09:24 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
2015-02-16 09:24 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-02-16 09:24 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-16 09:24 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2015-02-16 09:24 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2015-02-16 09:24 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-02-16 09:24 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2015-02-16 09:24 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-16 09:24 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-16 09:24 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\Windows\System32\scesrv.dll
2015-02-16 09:24 - 2014-12-09 00:12 - 00391526 _____ () C:\Windows\System32\ApnDatabase.xml
2015-02-16 09:24 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2015-02-16 09:24 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-02-16 09:24 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-02-16 09:23 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\System32\sppobjs.dll
2015-02-16 09:23 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2015-02-16 09:23 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2015-02-16 09:23 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-16 09:23 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-16 09:23 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2015-02-16 09:23 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-16 09:23 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-16 09:23 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\Windows\System32\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-02-16 09:23 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2015-02-16 09:23 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-02-16 09:23 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\Windows\System32\actxprxy.dll
2015-02-16 09:23 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2015-02-16 09:23 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-16 09:23 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-16 09:23 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2015-02-16 09:23 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2015-02-16 09:23 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-16 09:23 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-16 09:23 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-16 09:23 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2015-02-16 09:23 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2015-02-16 09:23 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-12 15:46 - 2013-08-22 15:46 - 00341788 _____ () C:\Windows\setupact.log
2015-03-12 15:46 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-12 15:43 - 2014-11-08 18:59 - 00000401 _____ () C:\Users\Andrea\AppData\Roaming\sp_data.sys
2015-03-12 15:43 - 2013-11-07 04:23 - 01661735 _____ () C:\Windows\WindowsUpdate.log
2015-03-12 15:43 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\System32\config\BBI
2015-03-12 15:43 - 2012-02-24 03:29 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-12 15:40 - 2012-10-03 16:18 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Outlook-Dateien
2015-03-12 15:37 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\System32\sru
2015-03-12 15:37 - 2012-12-02 23:43 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Skype
2015-03-12 14:42 - 2014-02-15 05:49 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Local\769A133B-0AED-452E-A98A-A2C94FEF5322.aplzod
2015-03-12 14:07 - 2013-09-30 05:14 - 02072588 _____ () C:\Windows\System32\PerfStringBackup.INI
2015-03-12 14:07 - 2013-09-30 04:56 - 00889374 _____ () C:\Windows\System32\perfh007.dat
2015-03-12 14:07 - 2013-09-30 04:56 - 00205446 _____ () C:\Windows\System32\perfc007.dat
2015-03-12 14:06 - 2013-11-07 08:40 - 00000000 __RDO () C:\Users\Justus Hoffmann\SkyDrive
2015-03-12 14:06 - 2013-11-07 01:00 - 00000401 _____ () C:\Users\Justus Hoffmann\AppData\Roaming\sp_data.sys
2015-03-12 14:06 - 2012-10-03 15:32 - 00000000 ___RD () C:\Users\Justus Hoffmann\Dropbox
2015-03-12 14:06 - 2012-10-03 15:30 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox
2015-03-12 10:01 - 2013-03-20 13:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-12 10:00 - 2012-02-24 03:29 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-12 09:41 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-03-12 09:38 - 2013-09-29 20:04 - 00225738 _____ () C:\Windows\PFRO.log
2015-03-12 08:07 - 2012-10-16 00:46 - 00003994 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{579749A9-A7ED-4DBF-B3BE-1B7363949C56}
2015-03-12 00:31 - 2013-11-06 22:12 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2283723822-742349386-183045315-1001
2015-03-11 23:03 - 2012-07-26 08:59 - 00000000 ____D () C:\Windows\CbsTemp
2015-03-11 22:37 - 2012-10-03 15:32 - 00001107 _____ () C:\Users\Justus Hoffmann\Desktop\Dropbox.lnk
2015-03-11 02:14 - 2012-10-03 16:50 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Local\Apple Computer
2015-03-10 00:54 - 2013-11-06 11:51 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Local\CrashDumps
2015-03-10 00:54 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\System32\config\ELAM
2015-03-09 14:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\System32\FxsTmp
2015-03-09 13:56 - 2012-12-15 13:27 - 00000000 __RHD () C:\ESD
2015-03-09 13:53 - 2014-03-22 16:30 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Citavi 4
2015-03-09 13:53 - 2013-11-07 04:18 - 00000000 ____D () C:\users\Justus Hoffmann
2015-03-09 13:52 - 2012-10-17 17:52 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Corps
2015-03-09 13:22 - 2012-10-03 16:20 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Uni
2015-03-08 17:02 - 2013-11-06 22:08 - 01165312 ___SH () C:\Users\Justus Hoffmann\Desktop\Thumbs.db
2015-03-04 10:13 - 2013-11-24 16:20 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-04 10:13 - 2013-11-06 23:43 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-04 10:12 - 2012-10-03 16:24 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Programme
2015-03-04 10:11 - 2014-12-04 20:56 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Schwerpunkt
2015-03-02 13:21 - 2012-10-03 16:19 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Swiss Academic Software
2015-02-20 11:21 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2015-02-20 10:10 - 2013-08-22 15:44 - 00479376 _____ () C:\Windows\System32\FNTCACHE.DAT
2015-02-20 10:08 - 2012-10-03 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-20 10:08 - 2009-07-14 03:34 - 00000545 _____ () C:\Windows\win.ini
2015-02-16 09:28 - 2013-07-25 10:43 - 00000000 ____D () C:\Windows\System32\MRT
2015-02-16 09:24 - 2012-10-03 16:28 - 116773704 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-02-13 11:55 - 2012-02-24 03:29 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-13 11:55 - 2012-02-24 03:29 - 00003884 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Justus Hoffmann\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppmujbv.dll


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2015-03-04 10:12:44
Restore point made on: 2015-03-12 00:17:52

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 3981.71 MB
Available physical RAM: 3238.2 MB
Total Pagefile: 3981.71 MB
Available Pagefile: 3259.61 MB
Total Virtual: 131072 MB
Available Virtual: 131071.87 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:102.2 GB) (Free:21.67 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:121.61 GB) (Free:117.4 GB) NTFS
Drive e: () (Removable) (Total:1.78 GB) (Free:1.76 GB) FAT
Drive f: () (Removable) (Total:0.12 GB) (Free:0.12 GB) FAT
Drive g: () (Fixed) (Total:0.34 GB) (Free:0.05 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: C14CBD8D)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 1.8 GB) (Disk ID: 342749BA)
Partition 1: (Not Active) - (Size=1.8 GB) - (Type=06)

========================================================
Disk: 2 (Size: 125 MB) (Disk ID: 11CE3EC4)
Partition 1: (Active) - (Size=125 MB) - (Type=06)


LastRegBack: 2015-03-12 09:48

==================== End Of Log ============================

--- --- ---


Gruß

schrauber 13.03.2015 08:37

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

S2 HPSLPSVC; C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [X]
C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2
HKU\Justus Hoffmann\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Emptytemp:

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.


Jetzt bitte nochmal ein FRST log aus dem normalen Modus.

Oktavius 13.03.2015 11:21

Moin Moin,
Also alles wie erklärt gemacht.

hier die fixlog.txt

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by SYSTEM at 2015-03-13 11:06:44 Run:3
Running from F:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
S2 HPSLPSVC; C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2\hpslpsvc64.dll [X]
C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2
HKU\Justus Hoffmann\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
Emptytemp:
*****************

HPSLPSVC => Service deleted successfully.
"C:\Users\JUSTUS~1\AppData\Local\Temp\7zS6FC2" => File/Directory not found.
HKU\Justus Hoffmann\Software\Microsoft\Windows\CurrentVersion\Run\\MerciJacquieMichel => value deleted successfully.
C:\Users\JUSTUS~1\AppData\Local\Temp\MerciJacquieMichel.vbe => Moved successfully.
C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe => Moved successfully.
Emptytemp: => Error: This directive works only outside recovery mode.

==== End of Fixlog 11:06:46 ====


und hier aus dem normalen Modus:

Beim Ausführen der Frst64.exe ist jedoch mein Norton360 angesprungen und hat sie gelöscht. Ich habe für 15 min Norton ausgemacht, hier die FRST.txt

Er will es immer noch nicht posten, da zu lang. Hier also ein upload hxxp://speedy.sh/FhbK2/FRST.TXT

Heißt das der PC ist befreit? Könntest du mir dann auch noch helfen die USB-Sticks zu befreien? :dankeschoen:

Nochmal danke!

schrauber 13.03.2015 15:25

Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.
Ich kann auf Arbeit keine Anhänge öffnen, danke.

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307



UNd ja, im Anschluss machen wir die Sticks :)

Oktavius 13.03.2015 16:33

Okay dann in mehreren :-)....

FRST.txt
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Justus Hoffmann (administrator) on JUSTUSHOFFMANN on 13-03-2015 11:12:26
Running from C:\Users\Justus Hoffmann\Desktop\Virus\FRST-OlderVersion
Loaded Profiles: Justus Hoffmann (Available profiles: Justus Hoffmann & Andrea & DefaultAppPool)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\DptfParticipantProcessorService.exe
() C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Windows\SysWOW64\DptfPolicyCriticalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Panda Security) C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\Justus Hoffmann\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Dropbox, Inc.) C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\Dropbox.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\APRP\aprp.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\SysWOW64\DptfPolicyLpmServiceHelper.exe [13824 2012-02-20] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2409272 2012-10-06] (Logitech, Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 7\MMReminderService.exe [37392 2007-05-17] (Mindjet)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-01-28] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [Spotify Web Helper] => C:\Users\Justus Hoffmann\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-2283723822-742349386-183045315-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: CmjBrowserHelperObject Object -> {07A11D74-9D25-4fea-A833-8B0D76A5577A} -> C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll [2007-05-17] (Mindjet)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2012-10-06] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-2283723822-742349386-183045315-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1

FireFox:
========
FF ProfilePath: C:\Users\Justus Hoffmann\AppData\Roaming\Mozilla\Firefox\Profiles\hcof00pn.default
FF DefaultSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-04-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2283723822-742349386-183045315-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101799.dll [2013-03-12] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-03-12]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-10-03]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2012-11-02]
FF HKU\S-1-5-21-2283723822-742349386-183045315-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (Logitech SetPoint) - C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2012-11-04]
CHR Extension: (iCloud Bookmarks) - C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2014-02-15]
CHR Extension: (Isoball 3) - C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\iajlkcpgcnbhfhpdeooockfaincfkjjj [2013-10-13]
CHR Extension: (Google Wallet) - C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Citavi Picker) - C:\Users\Justus Hoffmann\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-04-01]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-11-02]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-10] (Intel Corporation)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 DptfParticipantProcessorService; C:\Windows\SysWOW64\DptfParticipantProcessorService.exe [18944 2012-02-20] ()
R2 DptfPolicyConfigTDPService; C:\Windows\SysWOW64\DptfPolicyConfigTDPService.exe [19968 2012-02-20] ()
R2 DptfPolicyCriticalService; C:\Windows\SysWOW64\DptfPolicyCriticalService.exe [19456 2012-02-20] ()
S2 DptfPolicyLpmService; C:\Windows\SysWOW64\DptfPolicyLpmService.exe [24576 2012-02-20] ()
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-04-10] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-07] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-26] ()
S3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-07-14] (Windows (R) Win 7 DDK provider)
S3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [19104 2012-07-14] (ASUS)
R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-10-11] (ASIX Electronics Corp.)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150309.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2014-05-08] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-05] (Motorola Solutions, Inc.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2015-03-10] (Emsisoft GmbH)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107288 2012-02-20] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42776 2012-02-20] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64792 2012-02-20] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96024 2012-02-20] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [220952 2012-02-20] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [357656 2012-02-20] (Intel Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150311.001\IDSvia64.sys [669400 2015-02-13] (Symantec Corporation)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [26504 2012-04-10] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-13] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-07] (Microsoft Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150311.020\ENG64.SYS [129752 2015-01-21] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150311.020\EX64.SYS [2137304 2015-01-21] (Symantec Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1506000.020\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-10] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2015-01-28] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
U3 idsvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-13 10:58 - 2015-03-13 10:58 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-03-12 08:08 - 2015-03-12 08:17 - 00000000 ____D () C:\UsbFix
2015-03-12 08:08 - 2015-03-12 08:08 - 00001458 _____ () C:\Users\Justus Hoffmann\Desktop\UsbFix.lnk
2015-03-11 23:53 - 2014-10-29 05:03 - 00116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2015-03-11 23:53 - 2014-10-29 04:59 - 03460472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2015-03-11 23:53 - 2014-10-29 04:59 - 00014144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\swenum.sys
2015-03-11 23:53 - 2014-10-29 03:45 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2015-03-11 23:53 - 2014-10-29 03:22 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2015-03-11 23:53 - 2014-10-29 03:19 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-03-11 23:53 - 2014-10-29 03:08 - 18822656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-03-11 23:53 - 2014-10-29 03:00 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2015-03-11 23:53 - 2014-10-29 02:45 - 03607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-03-11 23:53 - 2014-10-29 02:42 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2015-03-11 23:53 - 2014-10-29 02:33 - 15157760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-03-11 23:53 - 2014-10-29 02:17 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2015-03-11 23:53 - 2014-10-29 02:10 - 02344960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-03-11 23:53 - 2014-10-29 02:09 - 03557376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-03-11 23:53 - 2014-10-29 02:02 - 14354944 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-03-11 23:53 - 2014-10-29 01:52 - 15432704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-03-11 23:53 - 2014-10-29 01:51 - 01554432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-03-11 23:53 - 2014-10-29 01:50 - 12749824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-03-11 23:53 - 2014-10-29 01:46 - 09530368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-03-11 23:53 - 2014-10-29 01:45 - 13318144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-03-11 23:52 - 2014-10-29 05:10 - 01816008 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2015-03-11 23:52 - 2014-10-29 05:00 - 02314952 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2015-03-11 23:52 - 2014-10-29 05:00 - 02229168 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-03-11 23:52 - 2014-10-29 04:59 - 02529856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-03-11 23:52 - 2014-10-29 04:59 - 00055776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-03-11 23:52 - 2014-10-29 04:58 - 00014528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\drmkaud.sys
2015-03-11 23:52 - 2014-10-29 04:57 - 03138720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2015-03-11 23:52 - 2014-10-29 04:57 - 03118096 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2015-03-11 23:52 - 2014-10-29 04:57 - 02745160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2015-03-11 23:52 - 2014-10-29 04:57 - 02450216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVENCOD.DLL
2015-03-11 23:52 - 2014-10-29 04:57 - 01286048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2015-03-11 23:52 - 2014-10-29 04:55 - 02174976 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2015-03-11 23:52 - 2014-10-29 04:55 - 01660528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-03-11 23:52 - 2014-10-29 04:55 - 01543768 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 02485056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-03-11 23:52 - 2014-10-29 04:52 - 02334080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 01518504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 01509688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 01288096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 01165744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 01064720 _____ (Microsoft Corporation) C:\WINDOWS\system32\drmv2clt.dll
2015-03-11 23:52 - 2014-10-29 04:52 - 00952384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-03-11 23:52 - 2014-10-29 04:51 - 01310912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-03-11 23:52 - 2014-10-29 04:13 - 01901240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-03-11 23:52 - 2014-10-29 04:12 - 01946144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2015-03-11 23:52 - 2014-10-29 04:12 - 01907384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-03-11 23:52 - 2014-10-29 04:11 - 02689392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2015-03-11 23:52 - 2014-10-29 04:11 - 02528760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2015-03-11 23:52 - 2014-10-29 04:11 - 02447104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVENCOD.DLL
2015-03-11 23:52 - 2014-10-29 04:11 - 01024200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2015-03-11 23:52 - 2014-10-29 04:10 - 01564464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2015-03-11 23:52 - 2014-10-29 04:10 - 01209624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-03-11 23:52 - 2014-10-29 04:07 - 02324208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-03-11 23:52 - 2014-10-29 04:07 - 01321192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-03-11 23:52 - 2014-10-29 04:07 - 01115104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2015-03-11 23:52 - 2014-10-29 04:07 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2015-03-11 23:52 - 2014-10-29 03:59 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-03-11 23:52 - 2014-10-29 03:29 - 04483072 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-03-11 23:52 - 2014-10-29 03:28 - 01502208 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpssvcs.dll
2015-03-11 23:52 - 2014-10-29 03:25 - 00785920 _____ (Microsoft Corporation) C:\WINDOWS\system32\blackbox.dll
2015-03-11 23:52 - 2014-10-29 03:24 - 04418560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2015-03-11 23:52 - 2014-10-29 03:17 - 02003456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2015-03-11 23:52 - 2014-10-29 03:10 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-03-11 23:52 - 2014-10-29 03:08 - 01540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll
2015-03-11 23:52 - 2014-10-29 03:00 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-03-11 23:52 - 2014-10-29 02:57 - 02924032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2015-03-11 23:52 - 2014-10-29 02:56 - 03754496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2015-03-11 23:52 - 2014-10-29 02:55 - 01697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2015-03-11 23:52 - 2014-10-29 02:51 - 00941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2015-03-11 23:52 - 2014-10-29 02:47 - 02072064 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2015-03-11 23:52 - 2014-10-29 02:45 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinput.exe
2015-03-11 23:52 - 2014-10-29 02:44 - 02984448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2015-03-11 23:52 - 2014-10-29 02:43 - 07075328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glcndFilter.dll
2015-03-11 23:52 - 2014-10-29 02:42 - 01999872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-03-11 23:52 - 2014-10-29 02:40 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2015-03-11 23:52 - 2014-10-29 02:39 - 02896384 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-03-11 23:52 - 2014-10-29 02:38 - 04690432 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2015-03-11 23:52 - 2014-10-29 02:35 - 04709888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2015-03-11 23:52 - 2014-10-29 02:35 - 03256320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2015-03-11 23:52 - 2014-10-29 02:31 - 02941952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2015-03-11 23:52 - 2014-10-29 02:28 - 03820544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2015-03-11 23:52 - 2014-10-29 02:26 - 03561984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-03-11 23:52 - 2014-10-29 02:24 - 02464768 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2015-03-11 23:52 - 2014-10-29 02:24 - 02364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2015-03-11 23:52 - 2014-10-29 02:23 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2015-03-11 23:52 - 2014-10-29 02:22 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-03-11 23:52 - 2014-10-29 02:22 - 02410496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2015-03-11 23:52 - 2014-10-29 02:22 - 01084416 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2015-03-11 23:52 - 2014-10-29 02:22 - 00945152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistCacheProvider.dll
2015-03-11 23:52 - 2014-10-29 02:21 - 01250816 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-03-11 23:52 - 2014-10-29 02:21 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2015-03-11 23:52 - 2014-10-29 02:18 - 01753600 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2015-03-11 23:52 - 2014-10-29 02:17 - 01360896 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2015-03-11 23:52 - 2014-10-29 02:16 - 05267968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glcndFilter.dll
2015-03-11 23:52 - 2014-10-29 02:14 - 03553280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2015-03-11 23:52 - 2014-10-29 02:12 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-03-11 23:52 - 2014-10-29 02:11 - 01639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-03-11 23:52 - 2014-10-29 02:10 - 02469888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2015-03-11 23:52 - 2014-10-29 02:08 - 02608640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2015-03-11 23:52 - 2014-10-29 02:08 - 02542080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-03-11 23:52 - 2014-10-29 02:08 - 02174976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2015-03-11 23:52 - 2014-10-29 02:08 - 01822720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2015-03-11 23:52 - 2014-10-29 02:08 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-03-11 23:52 - 2014-10-29 02:05 - 03273216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2015-03-11 23:52 - 2014-10-29 02:03 - 04067840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2015-03-11 23:52 - 2014-10-29 02:03 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2015-03-11 23:52 - 2014-10-29 02:03 - 02487296 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2015-03-11 23:52 - 2014-10-29 02:00 - 01705984 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2015-03-11 23:52 - 2014-10-29 01:59 - 02252800 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSvc.dll
2015-03-11 23:52 - 2014-10-29 01:59 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2015-03-11 23:52 - 2014-10-29 01:58 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-03-11 23:52 - 2014-10-29 01:57 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-03-11 23:52 - 2014-10-29 01:56 - 01337344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-03-11 23:52 - 2014-10-29 01:56 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-03-11 23:52 - 2014-10-29 01:54 - 07784960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-03-11 23:52 - 2014-10-29 01:54 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-03-11 23:52 - 2014-10-29 01:54 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-03-11 23:52 - 2014-10-29 01:52 - 02554880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-03-11 23:52 - 2014-10-29 01:52 - 02170368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2015-03-11 23:52 - 2014-10-29 01:52 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-03-11 23:52 - 2014-10-29 01:52 - 01461248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2015-03-11 23:52 - 2014-10-29 01:52 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-03-11 23:52 - 2014-10-29 01:52 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-03-11 23:52 - 2014-10-29 01:50 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2015-03-11 23:52 - 2014-10-29 01:50 - 01482752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2015-03-11 23:52 - 2014-10-29 01:48 - 03056128 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2015-03-11 23:52 - 2014-10-29 01:47 - 02090496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-03-11 23:52 - 2014-10-29 01:46 - 01919488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2015-03-11 23:52 - 2014-10-29 01:46 - 01348096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-03-11 23:52 - 2014-10-29 01:46 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-03-11 23:52 - 2014-10-29 01:46 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-03-11 23:52 - 2014-10-29 01:45 - 01725952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-03-11 23:52 - 2014-10-29 01:43 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-03-11 23:52 - 2014-10-29 01:43 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-03-11 23:52 - 2014-10-29 01:43 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-03-11 23:52 - 2014-10-29 01:42 - 01922560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-03-11 23:52 - 2014-10-29 01:42 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-03-11 23:52 - 2014-10-29 01:41 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-03-11 23:52 - 2014-10-29 01:41 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2015-03-11 23:52 - 2014-10-29 01:39 - 02814464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-03-11 23:52 - 2014-10-29 01:39 - 01000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-03-11 23:52 - 2014-10-29 01:38 - 07032320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2015-03-11 23:52 - 2014-10-29 01:37 - 06386176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-03-11 23:52 - 2014-10-29 01:35 - 01668096 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-03-11 23:52 - 2014-10-29 01:34 - 01544192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-03-11 23:52 - 2014-10-29 01:33 - 06213632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2015-03-11 23:52 - 2014-10-15 09:32 - 02025792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-03-11 23:52 - 2014-10-07 07:45 - 03307112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-03-11 23:52 - 2014-10-07 04:44 - 02890296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-03-11 23:52 - 2014-09-25 04:42 - 00373568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-03-11 23:51 - 2014-10-29 05:09 - 01950280 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2015-03-11 23:51 - 2014-10-29 05:09 - 01239576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2015-03-11 23:51 - 2014-10-29 05:04 - 00105872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2015-03-11 23:51 - 2014-10-29 05:03 - 00435008 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-03-11 23:51 - 2014-10-29 05:00 - 01540696 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2015-03-11 23:51 - 2014-10-29 05:00 - 01385216 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-03-11 23:51 - 2014-10-29 05:00 - 00740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2015-03-11 23:51 - 2014-10-29 05:00 - 00544408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-03-11 23:51 - 2014-10-29 05:00 - 00379568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-03-11 23:51 - 2014-10-29 04:57 - 01576312 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2015-03-11 23:51 - 2014-10-29 04:57 - 01552704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-03-11 23:51 - 2014-10-29 04:57 - 01210176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2015-03-11 23:51 - 2014-10-29 04:57 - 00643064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-03-11 23:51 - 2014-10-29 04:57 - 00557832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSDECD.DLL
2015-03-11 23:51 - 2014-10-29 04:55 - 01133200 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2015-03-11 23:51 - 2014-10-29 04:55 - 01063432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2015-03-11 23:51 - 2014-10-29 04:55 - 00730824 _____ (Microsoft Corporation) C:\WINDOWS\system32\clbcatq.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00988544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00962216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00850656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00821696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00734448 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00634768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00580024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00497936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00444728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2015-03-11 23:51 - 2014-10-29 04:52 - 00405456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2015-03-11 23:51 - 2014-10-29 04:18 - 01782912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2015-03-11 23:51 - 2014-10-29 04:18 - 01103768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2015-03-11 23:51 - 2014-10-29 04:18 - 00848568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2015-03-11 23:51 - 2014-10-29 04:18 - 00016504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psapi.dll
2015-03-11 23:51 - 2014-10-29 04:12 - 00616704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2015-03-11 23:51 - 2014-10-29 04:11 - 01037656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2015-03-11 23:51 - 2014-10-29 04:11 - 00914648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2015-03-11 23:51 - 2014-10-29 04:10 - 01287112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2015-03-11 23:51 - 2014-10-29 04:10 - 01178104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2015-03-11 23:51 - 2014-10-29 04:10 - 00492232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00857384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00801584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00785568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00705008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00700328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00584120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00551064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00482360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmdev.dll
2015-03-11 23:51 - 2014-10-29 04:07 - 00409040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2015-03-11 23:51 - 2014-10-29 04:05 - 00890128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drmv2clt.dll
2015-03-11 23:51 - 2014-10-29 03:56 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2015-03-11 23:51 - 2014-10-29 03:50 - 01192960 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-03-11 23:51 - 2014-10-29 03:48 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
2015-03-11 23:51 - 2014-10-29 03:48 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-03-11 23:51 - 2014-10-29 03:44 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2015-03-11 23:51 - 2014-10-29 03:43 - 00685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\riched20.dll
2015-03-11 23:51 - 2014-10-29 03:36 - 00546304 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqlcese40.dll
2015-03-11 23:51 - 2014-10-29 03:33 - 07558144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Data0011.dll
2015-03-11 23:51 - 2014-10-29 03:33 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqlsrv32.dll
2015-03-11 23:51 - 2014-10-29 03:31 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqlceqp40.dll
2015-03-11 23:51 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB70804.dll
2015-03-11 23:51 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB70404.dll
2015-03-11 23:51 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB7001E.dll
2015-03-11 23:51 - 2014-10-29 03:30 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB70011.dll
2015-03-11 23:51 - 2014-10-29 03:29 - 01246720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ogldrv.dll
2015-03-11 23:51 - 2014-10-29 03:29 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsound.dll
2015-03-11 23:51 - 2014-10-29 03:27 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx.dll
2015-03-11 23:51 - 2014-10-29 03:27 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsRasterService.dll
2015-03-11 23:51 - 2014-10-29 03:26 - 00771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll
2015-03-11 23:51 - 2014-10-29 03:18 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe
2015-03-11 23:51 - 2014-10-29 03:17 - 00537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-03-11 23:51 - 2014-10-29 03:11 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2015-03-11 23:51 - 2014-10-29 03:09 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\psisdecd.dll
2015-03-11 23:51 - 2014-10-29 03:08 - 00858624 _____ (Microsoft Corporation) C:\WINDOWS\system32\comuid.dll
2015-03-11 23:51 - 2014-10-29 03:08 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2015-03-11 23:51 - 2014-10-29 03:08 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmnet.dll
2015-03-11 23:51 - 2014-10-29 03:07 - 06692352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2015-03-11 23:51 - 2014-10-29 03:07 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2015-03-11 23:51 - 2014-10-29 03:06 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2015-03-11 23:51 - 2014-10-29 03:04 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\WavDest.dll
2015-03-11 23:51 - 2014-10-29 03:03 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2015-03-11 23:51 - 2014-10-29 03:03 - 00832000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
2015-03-11 23:51 - 2014-10-29 03:00 - 00652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2015-03-11 23:51 - 2014-10-29 02:59 - 00670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
2015-03-11 23:51 - 2014-10-29 02:59 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\riched20.dll
2015-03-11 23:51 - 2014-10-29 02:57 - 01038336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2015-03-11 23:51 - 2014-10-29 02:56 - 01526784 _____ (Microsoft Corporation) C:\WINDOWS\system32\pla.dll
2015-03-11 23:51 - 2014-10-29 02:56 - 00603648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-03-11 23:51 - 2014-10-29 02:53 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2015-03-11 23:51 - 2014-10-29 02:53 - 01065984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8.dll
2015-03-11 23:51 - 2014-10-29 02:53 - 00881152 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe
2015-03-11 23:51 - 2014-10-29 02:52 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-03-11 23:51 - 2014-10-29 02:50 - 01289216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2015-03-11 23:51 - 2014-10-29 02:50 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqlsrv32.dll
2015-03-11 23:51 - 2014-10-29 02:49 - 01358336 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmclient.dll
2015-03-11 23:51 - 2014-10-29 02:49 - 00742400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqlceqp40.dll
2015-03-11 23:51 - 2014-10-29 02:48 - 01080832 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
2015-03-11 23:51 - 2014-10-29 02:48 - 00825856 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll
2015-03-11 23:51 - 2014-10-29 02:48 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-03-11 23:51 - 2014-10-29 02:47 - 01096192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ogldrv.dll
2015-03-11 23:51 - 2014-10-29 02:47 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpssvcs.dll
2015-03-11 23:51 - 2014-10-29 02:46 - 01497600 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-03-11 23:51 - 2014-10-29 02:45 - 00717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-03-11 23:51 - 2014-10-29 02:45 - 00672768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll
2015-03-11 23:51 - 2014-10-29 02:45 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\blackbox.dll
2015-03-11 23:51 - 2014-10-29 02:43 - 01092608 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdosys.dll
2015-03-11 23:51 - 2014-10-29 02:43 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2015-03-11 23:51 - 2014-10-29 02:42 - 03724800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2015-03-11 23:51 - 2014-10-29 02:42 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\PurchaseWindowsLicense.dll
2015-03-11 23:51 - 2014-10-29 02:40 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2015-03-11 23:51 - 2014-10-29 02:39 - 01571328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2015-03-11 23:51 - 2014-10-29 02:39 - 00898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2015-03-11 23:51 - 2014-10-29 02:37 - 01563136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2015-03-11 23:51 - 2014-10-29 02:37 - 01436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll
2015-03-11 23:51 - 2014-10-29 02:36 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2015-03-11 23:51 - 2014-10-29 02:36 - 01252864 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2015-03-11 23:51 - 2014-10-29 02:36 - 01008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-03-11 23:51 - 2014-10-29 02:36 - 00609792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll
2015-03-11 23:51 - 2014-10-29 02:35 - 00532480 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2015-03-11 23:51 - 2014-10-29 02:34 - 01114624 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2015-03-11 23:51 - 2014-10-29 02:34 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2015-03-11 23:51 - 2014-10-29 02:33 - 01056768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2015-03-11 23:51 - 2014-10-29 02:33 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2015-03-11 23:51 - 2014-10-29 02:32 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2015-03-11 23:51 - 2014-10-29 02:32 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-03-11 23:51 - 2014-10-29 02:32 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comuid.dll
2015-03-11 23:51 - 2014-10-29 02:32 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmnet.dll
2015-03-11 23:51 - 2014-10-29 02:31 - 01278464 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2015-03-11 23:51 - 2014-10-29 02:31 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2015-03-11 23:51 - 2014-10-29 02:30 - 06465536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2015-03-11 23:51 - 2014-10-29 02:30 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2015-03-11 23:51 - 2014-10-29 02:29 - 00833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2015-03-11 23:51 - 2014-10-29 02:27 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2015-03-11 23:51 - 2014-10-29 02:26 - 00838656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2015-03-11 23:51 - 2014-10-29 02:25 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-03-11 23:51 - 2014-10-29 02:25 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pla.dll
2015-03-11 23:51 - 2014-10-29 02:24 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-03-11 23:51 - 2014-10-29 02:24 - 00845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2015-03-11 23:51 - 2014-10-29 02:23 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-03-11 23:51 - 2014-10-29 02:21 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2015-03-11 23:51 - 2014-10-29 02:20 - 01492480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2015-03-11 23:51 - 2014-10-29 02:19 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2015-03-11 23:51 - 2014-10-29 02:19 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSync.dll
2015-03-11 23:51 - 2014-10-29 02:18 - 01050624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2015-03-11 23:51 - 2014-10-29 02:18 - 00967680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmclient.dll
2015-03-11 23:51 - 2014-10-29 02:17 - 01402368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2015-03-11 23:51 - 2014-10-29 02:17 - 00829952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbe.dll
2015-03-11 23:51 - 2014-10-29 02:16 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2015-03-11 23:51 - 2014-10-29 02:14 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdosys.dll
2015-03-11 23:51 - 2014-10-29 02:14 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-03-11 23:51 - 2014-10-29 02:14 - 00737280 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-03-11 23:51 - 2014-10-29 02:14 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-03-11 23:51 - 2014-10-29 02:12 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2015-03-11 23:51 - 2014-10-29 02:12 - 00702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2015-03-11 23:51 - 2014-10-29 02:12 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll
2015-03-11 23:51 - 2014-10-29 02:12 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2015-03-11 23:51 - 2014-10-29 02:12 - 00516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll
2015-03-11 23:51 - 2014-10-29 02:11 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll
2015-03-11 23:51 - 2014-10-29 02:10 - 01096704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-03-11 23:51 - 2014-10-29 02:10 - 00516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll
2015-03-11 23:51 - 2014-10-29 02:09 - 01335296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2015-03-11 23:51 - 2014-10-29 02:09 - 00873984 _____ (Microsoft Corporation) C:\WINDOWS\system32\provcore.dll
2015-03-11 23:51 - 2014-10-29 02:09 - 00809984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2015-03-11 23:51 - 2014-10-29 02:09 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-03-11 23:51 - 2014-10-29 02:09 - 00658944 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll
2015-03-11 23:51 - 2014-10-29 02:09 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-03-11 23:51 - 2014-10-29 02:08 - 01478144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2015-03-11 23:51 - 2014-10-29 02:08 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2015-03-11 23:51 - 2014-10-29 02:07 - 01396736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2015-03-11 23:51 - 2014-10-29 02:07 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2015-03-11 23:51 - 2014-10-29 02:07 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2015-03-11 23:51 - 2014-10-29 02:07 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-03-11 23:51 - 2014-10-29 02:07 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2015-03-11 23:51 - 2014-10-29 02:07 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2015-03-11 23:51 - 2014-10-29 02:06 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2015-03-11 23:51 - 2014-10-29 02:06 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-03-11 23:51 - 2014-10-29 02:06 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2015-03-11 23:51 - 2014-10-29 02:05 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-03-11 23:51 - 2014-10-29 02:04 - 01376256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2015-03-11 23:51 - 2014-10-29 02:04 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2015-03-11 23:51 - 2014-10-29 02:03 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-03-11 23:51 - 2014-10-29 02:03 - 00740352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2015-03-11 23:51 - 2014-10-29 02:02 - 00880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-03-11 23:51 - 2014-10-29 02:02 - 00695296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2015-03-11 23:51 - 2014-10-29 02:01 - 01710592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2015-03-11 23:51 - 2014-10-29 02:01 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\perftrack.dll
2015-03-11 23:51 - 2014-10-29 02:01 - 00843776 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2015-03-11 23:51 - 2014-10-29 02:00 - 01574400 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2015-03-11 23:51 - 2014-10-29 02:00 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2015-03-11 23:51 - 2014-10-29 01:59 - 01636864 _____ (Microsoft Corporation) C:\WINDOWS\system32\RacEngn.dll
2015-03-11 23:51 - 2014-10-29 01:59 - 01454080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2015-03-11 23:51 - 2014-10-29 01:59 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2015-03-11 23:51 - 2014-10-29 01:59 - 01021440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-03-11 23:51 - 2014-10-29 01:59 - 01010688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2015-03-11 23:51 - 2014-10-29 01:59 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2015-03-11 23:51 - 2014-10-29 01:59 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSync.dll
2015-03-11 23:51 - 2014-10-29 01:58 - 00926208 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2015-03-11 23:51 - 2014-10-29 01:56 - 01248256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2015-03-11 23:51 - 2014-10-29 01:56 - 01001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2015-03-11 23:51 - 2014-10-29 01:56 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2015-03-11 23:51 - 2014-10-29 01:56 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-03-11 23:51 - 2014-10-29 01:56 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-03-11 23:51 - 2014-10-29 01:55 - 00719360 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll
2015-03-11 23:51 - 2014-10-29 01:54 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2015-03-11 23:51 - 2014-10-29 01:54 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2015-03-11 23:51 - 2014-10-29 01:53 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2015-03-11 23:51 - 2014-10-29 01:52 - 01265152 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-03-11 23:51 - 2014-10-29 01:52 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-03-11 23:51 - 2014-10-29 01:52 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
2015-03-11 23:51 - 2014-10-29 01:52 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2015-03-11 23:51 - 2014-10-29 01:52 - 00801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2015-03-11 23:51 - 2014-10-29 01:52 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2015-03-11 23:51 - 2014-10-29 01:51 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\duser.dll
2015-03-11 23:51 - 2014-10-29 01:51 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2015-03-11 23:51 - 2014-10-29 01:50 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2015-03-11 23:51 - 2014-10-29 01:48 - 01344000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2015-03-11 23:51 - 2014-10-29 01:48 - 01142272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
2015-03-11 23:51 - 2014-10-29 01:48 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-03-11 23:51 - 2014-10-29 01:48 - 00562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2015-03-11 23:51 - 2014-10-29 01:47 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2015-03-11 23:51 - 2014-10-29 01:47 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2015-03-11 23:51 - 2014-10-29 01:46 - 01265152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RacEngn.dll
2015-03-11 23:51 - 2014-10-29 01:46 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-03-11 23:51 - 2014-10-29 01:45 - 00918016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
2015-03-11 23:51 - 2014-10-29 01:45 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-03-11 23:51 - 2014-10-29 01:45 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2015-03-11 23:51 - 2014-10-29 01:45 - 00573952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll
2015-03-11 23:51 - 2014-10-29 01:45 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-03-11 23:51 - 2014-10-29 01:43 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
2015-03-11 23:51 - 2014-10-29 01:42 - 01207808 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.dll
2015-03-11 23:51 - 2014-10-29 01:42 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2015-03-11 23:51 - 2014-10-29 01:42 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2015-03-11 23:51 - 2014-10-29 01:42 - 00608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll


Oktavius 13.03.2015 16:37

Teil Nr.2

Code:

2015-03-11 23:51 - 2014-10-29 01:41 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-03-11 23:51 - 2014-10-29 01:40 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2015-03-11 23:51 - 2014-10-29 01:40 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-03-11 23:51 - 2014-10-29 01:38 - 01262080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2015-03-11 23:51 - 2014-10-29 01:37 - 00724480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-03-11 23:51 - 2014-10-29 01:36 - 00955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-03-11 23:51 - 2014-10-29 01:36 - 00954880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-03-11 23:51 - 2014-10-29 01:35 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.dll
2015-03-11 23:51 - 2014-10-29 01:35 - 00772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmIndexer.dll
2015-03-11 23:51 - 2014-10-29 01:35 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-03-11 23:51 - 2014-10-29 01:35 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2015-03-11 23:51 - 2014-10-29 01:35 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.ContentPrefetchTask.dll
2015-03-11 23:51 - 2014-10-29 01:33 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2015-03-11 23:51 - 2014-10-29 01:32 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-03-11 23:51 - 2014-10-29 01:31 - 00626176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-03-11 23:51 - 2014-10-29 01:30 - 00602624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmIndexer.dll
2015-03-11 23:51 - 2014-10-08 23:09 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-03-11 23:51 - 2014-07-04 22:29 - 00478528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-03-11 23:50 - 2014-10-29 05:10 - 00430728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2015-03-11 23:50 - 2014-10-29 05:09 - 01309744 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2015-03-11 23:50 - 2014-10-29 05:04 - 00397192 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2015-03-11 23:50 - 2014-10-29 05:04 - 00324864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-03-11 23:50 - 2014-10-29 04:59 - 00520536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-03-11 23:50 - 2014-10-29 04:59 - 00498496 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2015-03-11 23:50 - 2014-10-29 04:57 - 01150208 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2015-03-11 23:50 - 2014-10-29 04:57 - 00725672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2015-03-11 23:50 - 2014-10-29 04:57 - 00662120 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.exe
2015-03-11 23:50 - 2014-10-29 04:57 - 00389952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-03-11 23:50 - 2014-10-29 04:57 - 00295432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMASF.DLL
2015-03-11 23:50 - 2014-10-29 04:57 - 00256744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2015-03-11 23:50 - 2014-10-29 04:55 - 00426120 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2015-03-11 23:50 - 2014-10-29 04:55 - 00359496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsta.dll
2015-03-11 23:50 - 2014-10-29 04:54 - 00685408 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2015-03-11 23:50 - 2014-10-29 04:53 - 00411128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-03-11 23:50 - 2014-10-29 04:52 - 00356936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-03-11 23:50 - 2014-10-29 04:52 - 00311448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-03-11 23:50 - 2014-10-29 04:52 - 00020160 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2015-03-11 23:50 - 2014-10-29 04:51 - 00363080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2015-03-11 23:50 - 2014-10-29 04:51 - 00360992 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-03-11 23:50 - 2014-10-29 04:18 - 00320736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2015-03-11 23:50 - 2014-10-29 04:15 - 00340288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-03-11 23:50 - 2014-10-29 04:15 - 00245296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-03-11 23:50 - 2014-10-29 04:12 - 00430176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-03-11 23:50 - 2014-10-29 04:12 - 00403776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2015-03-11 23:50 - 2014-10-29 04:11 - 00492704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSDECD.DLL
2015-03-11 23:50 - 2014-10-29 04:11 - 00488064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2015-03-11 23:50 - 2014-10-29 04:11 - 00463744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP4SDECD.DLL
2015-03-11 23:50 - 2014-10-29 04:10 - 00569128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clbcatq.dll
2015-03-11 23:50 - 2014-10-29 04:10 - 00547992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2015-03-11 23:50 - 2014-10-29 04:10 - 00367248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2015-03-11 23:50 - 2014-10-29 04:07 - 00399752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-03-11 23:50 - 2014-10-29 04:07 - 00331048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2015-03-11 23:50 - 2014-10-29 04:07 - 00320256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-03-11 23:50 - 2014-10-29 04:06 - 00800008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcrt.dll
2015-03-11 23:50 - 2014-10-29 04:06 - 00507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2015-03-11 23:50 - 2014-10-29 03:45 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\glmf32.dll
2015-03-11 23:50 - 2014-10-29 03:45 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\msls31.dll
2015-03-11 23:50 - 2014-10-29 03:44 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-03-11 23:50 - 2014-10-29 03:42 - 01091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll
2015-03-11 23:50 - 2014-10-29 03:40 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxs.dll
2015-03-11 23:50 - 2014-10-29 03:37 - 02329088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Data0404.dll
2015-03-11 23:50 - 2014-10-29 03:34 - 03438592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Data0804.dll
2015-03-11 23:50 - 2014-10-29 03:31 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll
2015-03-11 23:50 - 2014-10-29 03:31 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax
2015-03-11 23:50 - 2014-10-29 03:28 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
2015-03-11 23:50 - 2014-10-29 03:26 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartCardSimulator.dll
2015-03-11 23:50 - 2014-10-29 03:26 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2015-03-11 23:50 - 2014-10-29 03:25 - 00995328 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi3.dll
2015-03-11 23:50 - 2014-10-29 03:25 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdohlp.dll
2015-03-11 23:50 - 2014-10-29 03:25 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2015-03-11 23:50 - 2014-10-29 03:24 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WmpDui.dll
2015-03-11 23:50 - 2014-10-29 03:24 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSNP.ax
2015-03-11 23:50 - 2014-10-29 03:23 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\offfilt.dll
2015-03-11 23:50 - 2014-10-29 03:21 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassdo.dll
2015-03-11 23:50 - 2014-10-29 03:21 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-03-11 23:50 - 2014-10-29 03:20 - 00802304 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscsvc.dll
2015-03-11 23:50 - 2014-10-29 03:20 - 00397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnp.dll
2015-03-11 23:50 - 2014-10-29 03:19 - 09732096 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000a.dll
2015-03-11 23:50 - 2014-10-29 03:18 - 06259712 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-03-11 23:50 - 2014-10-29 03:18 - 04616704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData001d.dll
2015-03-11 23:50 - 2014-10-29 03:18 - 02403328 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000c.dll
2015-03-11 23:50 - 2014-10-29 03:18 - 02140672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0007.dll
2015-03-11 23:50 - 2014-10-29 03:17 - 04621312 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0414.dll
2015-03-11 23:50 - 2014-10-29 03:17 - 04620288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0816.dll
2015-03-11 23:50 - 2014-10-29 03:17 - 03231232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData004b.dll
2015-03-11 23:50 - 2014-10-29 03:17 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000d.dll
2015-03-11 23:50 - 2014-10-29 03:16 - 04621312 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0010.dll
2015-03-11 23:50 - 2014-10-29 03:16 - 04616704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0416.dll
2015-03-11 23:50 - 2014-10-29 03:16 - 03235840 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0039.dll
2015-03-11 23:50 - 2014-10-29 03:16 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData004a.dll
2015-03-11 23:50 - 2014-10-29 03:16 - 00546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData004e.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0047.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0046.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0020.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0026.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0024.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData001b.dll
2015-03-11 23:50 - 2014-10-29 03:15 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0002.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData004c.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0045.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02075136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0027.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0c1a.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData081a.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData001a.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0018.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000f.dll
2015-03-11 23:50 - 2014-10-29 03:14 - 02073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0003.dll
2015-03-11 23:50 - 2014-10-29 03:12 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-03-11 23:50 - 2014-10-29 03:11 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2015-03-11 23:50 - 2014-10-29 03:11 - 00478720 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmon.ocx
2015-03-11 23:50 - 2014-10-29 03:11 - 00435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswmdm.dll
2015-03-11 23:50 - 2014-10-29 03:08 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll
2015-03-11 23:50 - 2014-10-29 03:08 - 00390656 _____ (Microsoft Corporation) C:\WINDOWS\system32\difxapi.dll
2015-03-11 23:50 - 2014-10-29 03:06 - 02902016 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2015-03-11 23:50 - 2014-10-29 03:06 - 01313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2015-03-11 23:50 - 2014-10-29 03:06 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAC3ENC.DLL
2015-03-11 23:50 - 2014-10-29 03:05 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll
2015-03-11 23:50 - 2014-10-29 03:04 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\system32\filemgmt.dll
2015-03-11 23:50 - 2014-10-29 03:04 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
2015-03-11 23:50 - 2014-10-29 03:03 - 02334720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2015-03-11 23:50 - 2014-10-29 03:01 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2015-03-11 23:50 - 2014-10-29 03:01 - 00453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroleui.dll
2015-03-11 23:50 - 2014-10-29 03:01 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-03-11 23:50 - 2014-10-29 03:00 - 01861632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2015-03-11 23:50 - 2014-10-29 03:00 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2015-03-11 23:50 - 2014-10-29 02:59 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpedit.dll
2015-03-11 23:50 - 2014-10-29 02:59 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncInfrastructure.dll
2015-03-11 23:50 - 2014-10-29 02:59 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2015-03-11 23:50 - 2014-10-29 02:58 - 01040384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2015-03-11 23:50 - 2014-10-29 02:57 - 02592256 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2015-03-11 23:50 - 2014-10-29 02:57 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2015-03-11 23:50 - 2014-10-29 02:57 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll
2015-03-11 23:50 - 2014-10-29 02:56 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2015-03-11 23:50 - 2014-10-29 02:56 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxs.dll
2015-03-11 23:50 - 2014-10-29 02:56 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDSp.dll
2015-03-11 23:50 - 2014-10-29 02:55 - 00669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2015-03-11 23:50 - 2014-10-29 02:54 - 00833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2015-03-11 23:50 - 2014-10-29 02:54 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscp.dll
2015-03-11 23:50 - 2014-10-29 02:54 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DfpCommon.dll
2015-03-11 23:50 - 2014-10-29 02:54 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2015-03-11 23:50 - 2014-10-29 02:54 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\qasf.dll
2015-03-11 23:50 - 2014-10-29 02:53 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2015-03-11 23:50 - 2014-10-29 02:53 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqlcese40.dll
2015-03-11 23:50 - 2014-10-29 02:52 - 02829312 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2015-03-11 23:50 - 2014-10-29 02:52 - 00809984 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2015-03-11 23:50 - 2014-10-29 02:52 - 00680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\objsel.dll
2015-03-11 23:50 - 2014-10-29 02:52 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-03-11 23:50 - 2014-10-29 02:52 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll
2015-03-11 23:50 - 2014-10-29 02:51 - 07331840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NL7Data0011.dll
2015-03-11 23:50 - 2014-10-29 02:51 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2015-03-11 23:50 - 2014-10-29 02:50 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdri.dll
2015-03-11 23:50 - 2014-10-29 02:49 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\certmgr.dll
2015-03-11 23:50 - 2014-10-29 02:49 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe
2015-03-11 23:50 - 2014-10-29 02:49 - 00478720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll
2015-03-11 23:50 - 2014-10-29 02:48 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipsmsnap.dll
2015-03-11 23:50 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB70804.dll
2015-03-11 23:50 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB70404.dll
2015-03-11 23:50 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB7001E.dll
2015-03-11 23:50 - 2014-10-29 02:48 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB70011.dll
2015-03-11 23:50 - 2014-10-29 02:47 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2015-03-11 23:50 - 2014-10-29 02:47 - 00517120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsound.dll
2015-03-11 23:50 - 2014-10-29 02:47 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
2015-03-11 23:50 - 2014-10-29 02:46 - 01001472 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2015-03-11 23:50 - 2014-10-29 02:46 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsRasterService.dll
2015-03-11 23:50 - 2014-10-29 02:45 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2015-03-11 23:50 - 2014-10-29 02:44 - 00872960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi3.dll
2015-03-11 23:50 - 2014-10-29 02:44 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2015-03-11 23:50 - 2014-10-29 02:43 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2015-03-11 23:50 - 2014-10-29 02:43 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSNP.ax
2015-03-11 23:50 - 2014-10-29 02:42 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2015-03-11 23:50 - 2014-10-29 02:41 - 01411584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2015-03-11 23:50 - 2014-10-29 02:41 - 00459264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgr.dll
2015-03-11 23:50 - 2014-10-29 02:41 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnp.dll
2015-03-11 23:50 - 2014-10-29 02:38 - 04945920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-03-11 23:50 - 2014-10-29 02:38 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMPOSE.dll
2015-03-11 23:50 - 2014-10-29 02:36 - 00943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2015-03-11 23:50 - 2014-10-29 02:36 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2015-03-11 23:50 - 2014-10-29 02:36 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2015-03-11 23:50 - 2014-10-29 02:34 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2015-03-11 23:50 - 2014-10-29 02:34 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysmon.ocx
2015-03-11 23:50 - 2014-10-29 02:34 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswmdm.dll
2015-03-11 23:50 - 2014-10-29 02:33 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2015-03-11 23:50 - 2014-10-29 02:33 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2015-03-11 23:50 - 2014-10-29 02:33 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll
2015-03-11 23:50 - 2014-10-29 02:32 - 00794624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll
2015-03-11 23:50 - 2014-10-29 02:32 - 00512512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisdecd.dll
2015-03-11 23:50 - 2014-10-29 02:31 - 00761344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll
2015-03-11 23:50 - 2014-10-29 02:31 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2015-03-11 23:50 - 2014-10-29 02:30 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2015-03-11 23:50 - 2014-10-29 02:30 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2015-03-11 23:50 - 2014-10-29 02:30 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll
2015-03-11 23:50 - 2014-10-29 02:30 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2015-03-11 23:50 - 2014-10-29 02:30 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-03-11 23:50 - 2014-10-29 02:30 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2015-03-11 23:50 - 2014-10-29 02:29 - 02848768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2015-03-11 23:50 - 2014-10-29 02:29 - 00464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll
2015-03-11 23:50 - 2014-10-29 02:29 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2015-03-11 23:50 - 2014-10-29 02:29 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-03-11 23:50 - 2014-10-29 02:29 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2015-03-11 23:50 - 2014-10-29 02:28 - 02213888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncCenter.dll
2015-03-11 23:50 - 2014-10-29 02:27 - 00397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2015-03-11 23:50 - 2014-10-29 02:26 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2015-03-11 23:50 - 2014-10-29 02:26 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-03-11 23:50 - 2014-10-29 02:25 - 01058816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpedit.dll
2015-03-11 23:50 - 2014-10-29 02:24 - 01335296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2015-03-11 23:50 - 2014-10-29 02:24 - 00902144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2015-03-11 23:50 - 2014-10-29 02:24 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2015-03-11 23:50 - 2014-10-29 02:23 - 01826304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2015-03-11 23:50 - 2014-10-29 02:23 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\livessp.dll
2015-03-11 23:50 - 2014-10-29 02:23 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll
2015-03-11 23:50 - 2014-10-29 02:22 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2015-03-11 23:50 - 2014-10-29 02:22 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2015-03-11 23:50 - 2014-10-29 02:22 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdelta.dll
2015-03-11 23:50 - 2014-10-29 02:22 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2015-03-11 23:50 - 2014-10-29 02:22 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2015-03-11 23:50 - 2014-10-29 02:21 - 00482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmvsc.dll
2015-03-11 23:50 - 2014-10-29 02:21 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2015-03-11 23:50 - 2014-10-29 02:21 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscp.dll
2015-03-11 23:50 - 2014-10-29 02:21 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedynos.dll
2015-03-11 23:50 - 2014-10-29 02:21 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFHost.exe
2015-03-11 23:50 - 2014-10-29 02:21 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2015-03-11 23:50 - 2014-10-29 02:20 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll
2015-03-11 23:50 - 2014-10-29 02:20 - 00517120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbemcomn.dll
2015-03-11 23:50 - 2014-10-29 02:20 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2015-03-11 23:50 - 2014-10-29 02:20 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2015-03-11 23:50 - 2014-10-29 02:19 - 02714624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2015-03-11 23:50 - 2014-10-29 02:19 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2015-03-11 23:50 - 2014-10-29 02:19 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2015-03-11 23:50 - 2014-10-29 02:19 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2015-03-11 23:50 - 2014-10-29 02:18 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certmgr.dll
2015-03-11 23:50 - 2014-10-29 02:18 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2015-03-11 23:50 - 2014-10-29 02:18 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsExt.dll
2015-03-11 23:50 - 2014-10-29 02:17 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe
2015-03-11 23:50 - 2014-10-29 02:17 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-03-11 23:50 - 2014-10-29 02:17 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipsmsnap.dll
2015-03-11 23:50 - 2014-10-29 02:17 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2015-03-11 23:50 - 2014-10-29 02:16 - 01242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10.dll
2015-03-11 23:50 - 2014-10-29 02:16 - 00795136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2015-03-11 23:50 - 2014-10-29 02:16 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMActivate_isv.exe
2015-03-11 23:50 - 2014-10-29 02:16 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\secproc.dll
2015-03-11 23:50 - 2014-10-29 02:16 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\secproc_isv.dll
2015-03-11 23:50 - 2014-10-29 02:16 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2015-03-11 23:50 - 2014-10-29 02:16 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll
2015-03-11 23:50 - 2014-10-29 02:15 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-03-11 23:50 - 2014-10-29 02:15 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMActivate.exe
2015-03-11 23:50 - 2014-10-29 02:15 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Proximity.dll
2015-03-11 23:50 - 2014-10-29 02:14 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2015-03-11 23:50 - 2014-10-29 02:13 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-03-11 23:50 - 2014-10-29 02:13 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-03-11 23:50 - 2014-10-29 02:12 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ninput.dll
2015-03-11 23:50 - 2014-10-29 02:12 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgr.dll
2015-03-11 23:50 - 2014-10-29 02:11 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2015-03-11 23:50 - 2014-10-29 02:11 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2015-03-11 23:50 - 2014-10-29 02:10 - 00516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2015-03-11 23:50 - 2014-10-29 02:10 - 00442880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2015-03-11 23:50 - 2014-10-29 02:09 - 00633344 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2015-03-11 23:50 - 2014-10-29 02:09 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll
2015-03-11 23:50 - 2014-10-29 02:09 - 00345088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2015-03-11 23:50 - 2014-10-29 02:08 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2015-03-11 23:50 - 2014-10-29 02:07 - 01197056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2015-03-11 23:50 - 2014-10-29 02:07 - 00594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll
2015-03-11 23:50 - 2014-10-29 02:07 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2015-03-11 23:50 - 2014-10-29 02:06 - 01086976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2015-03-11 23:50 - 2014-10-29 02:06 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2015-03-11 23:50 - 2014-10-29 02:06 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2015-03-11 23:50 - 2014-10-29 02:06 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2015-03-11 23:50 - 2014-10-29 02:05 - 00534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-03-11 23:50 - 2014-10-29 02:05 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2015-03-11 23:50 - 2014-10-29 02:04 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsvcs.dll
2015-03-11 23:50 - 2014-10-29 02:04 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2015-03-11 23:50 - 2014-10-29 02:04 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlangpui.dll
2015-03-11 23:50 - 2014-10-29 02:04 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2015-03-11 23:50 - 2014-10-29 02:03 - 00781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2015-03-11 23:50 - 2014-10-29 02:03 - 00474112 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2015-03-11 23:50 - 2014-10-29 02:03 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-03-11 23:50 - 2014-10-29 02:03 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-03-11 23:50 - 2014-10-29 02:01 - 01241600 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSh.dll
2015-03-11 23:50 - 2014-10-29 02:01 - 00706048 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2015-03-11 23:50 - 2014-10-29 02:01 - 00657408 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmscan.dll
2015-03-11 23:50 - 2014-10-29 02:01 - 00573952 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2015-03-11 23:50 - 2014-10-29 02:01 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2015-03-11 23:50 - 2014-10-29 02:01 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll
2015-03-11 23:50 - 2014-10-29 02:00 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wbemcomn.dll
2015-03-11 23:50 - 2014-10-29 02:00 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-03-11 23:50 - 2014-10-29 01:59 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2015-03-11 23:50 - 2014-10-29 01:59 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxApplicabilityEngine.dll
2015-03-11 23:50 - 2014-10-29 01:59 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2015-03-11 23:50 - 2014-10-29 01:58 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-03-11 23:50 - 2014-10-29 01:58 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-03-11 23:50 - 2014-10-29 01:58 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2015-03-11 23:50 - 2014-10-29 01:58 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2015-03-11 23:50 - 2014-10-29 01:58 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll
2015-03-11 23:50 - 2014-10-29 01:57 - 01065472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10.dll
2015-03-11 23:50 - 2014-10-29 01:57 - 00562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RMActivate_isv.exe
2015-03-11 23:50 - 2014-10-29 01:57 - 00543744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RMActivate.exe
2015-03-11 23:50 - 2014-10-29 01:57 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll
2015-03-11 23:50 - 2014-10-29 01:57 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc_isv.dll
2015-03-11 23:50 - 2014-10-29 01:57 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
2015-03-11 23:50 - 2014-10-29 01:56 - 00512512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-03-11 23:50 - 2014-10-29 01:56 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00887808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dim700.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistCleaner.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\es.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\DaOtpCredentialProvider.dll
2015-03-11 23:50 - 2014-10-29 01:55 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ninput.dll
2015-03-11 23:50 - 2014-10-29 01:54 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-03-11 23:50 - 2014-10-29 01:53 - 00612352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provcore.dll
2015-03-11 23:50 - 2014-10-29 01:53 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-03-11 23:50 - 2014-10-29 01:53 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-03-11 23:50 - 2014-10-29 01:52 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2015-03-11 23:50 - 2014-10-29 01:52 - 00544256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll
2015-03-11 23:50 - 2014-10-29 01:52 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2015-03-11 23:50 - 2014-10-29 01:51 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2015-03-11 23:50 - 2014-10-29 01:51 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2015-03-11 23:50 - 2014-10-29 01:51 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\provsvc.dll
2015-03-11 23:50 - 2014-10-29 01:51 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-03-11 23:50 - 2014-10-29 01:50 - 00624128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2015-03-11 23:50 - 2014-10-29 01:50 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskeng.exe
2015-03-11 23:50 - 2014-10-29 01:50 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-03-11 23:50 - 2014-10-29 01:50 - 00399360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlangpui.dll
2015-03-11 23:50 - 2014-10-29 01:48 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2015-03-11 23:50 - 2014-10-29 01:48 - 00454144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll
2015-03-11 23:50 - 2014-10-29 01:47 - 00527872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2015-03-11 23:50 - 2014-10-29 01:47 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrv.dll
2015-03-11 23:50 - 2014-10-29 01:47 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2015-03-11 23:50 - 2014-10-29 01:47 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2015-03-11 23:50 - 2014-10-29 01:47 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2015-03-11 23:50 - 2014-10-29 01:46 - 00455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-03-11 23:50 - 2014-10-29 01:45 - 00397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-03-11 23:50 - 2014-10-29 01:44 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-03-11 23:50 - 2014-10-29 01:44 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2015-03-11 23:50 - 2014-10-29 01:43 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2015-03-11 23:50 - 2014-10-29 01:42 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2015-03-11 23:50 - 2014-10-29 01:42 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2015-03-11 23:50 - 2014-10-29 01:42 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provsvc.dll
2015-03-11 23:50 - 2014-10-29 01:42 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2015-03-11 23:50 - 2014-10-29 01:40 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2015-03-11 23:50 - 2014-10-29 01:39 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2015-03-11 23:50 - 2014-10-29 01:39 - 00454144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2015-03-11 23:50 - 2014-10-29 01:39 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrv.dll
2015-03-11 23:50 - 2014-10-29 01:37 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2015-03-11 23:50 - 2014-10-29 01:35 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2015-03-11 23:50 - 2014-10-15 09:32 - 00551232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2015-03-11 23:50 - 2014-10-08 08:33 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2015-03-11 23:50 - 2014-10-08 08:32 - 00405504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-03-11 23:50 - 2014-10-07 07:44 - 00533824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-03-11 23:49 - 2014-10-29 05:09 - 00315576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll
2015-03-11 23:49 - 2014-10-29 05:09 - 00294880 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
2015-03-11 23:49 - 2014-10-29 05:09 - 00233448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityUxHost.exe
2015-03-11 23:49 - 2014-10-29 05:09 - 00214360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2015-03-11 23:49 - 2014-10-29 05:04 - 00217912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2015-03-11 23:49 - 2014-10-29 05:04 - 00181816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2015-03-11 23:49 - 2014-10-29 05:04 - 00136912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncrypt.dll
2015-03-11 23:49 - 2014-10-29 05:00 - 00142000 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxva2.dll
2015-03-11 23:49 - 2014-10-29 04:59 - 00415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2015-03-11 23:49 - 2014-10-29 04:59 - 00230816 _____ (Microsoft Corporation) C:\WINDOWS\system32\xmllite.dll
2015-03-11 23:49 - 2014-10-29 04:58 - 01797944 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
2015-03-11 23:49 - 2014-10-29 04:57 - 01913128 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplaySwitch.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2015-03-11 23:49 - 2014-10-29 04:57 - 00629576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP4SDECD.DLL
2015-03-11 23:49 - 2014-10-29 04:57 - 00339312 _____ (Microsoft Corporation) C:\WINDOWS\system32\shlwapi.dll
2015-03-11 23:49 - 2014-10-29 04:57 - 00271152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00217432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2015-03-11 23:49 - 2014-10-29 04:57 - 00216920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVol.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00034568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountBroker.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00031496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraSettingsUIHost.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00029408 _____ (Microsoft Corporation) C:\WINDOWS\system32\PickerHost.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00027360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsRemoveDevice.exe
2015-03-11 23:49 - 2014-10-29 04:57 - 00018584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SlideToShutDown.exe
2015-03-11 23:49 - 2014-10-29 04:55 - 00305192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpendp.dll
2015-03-11 23:49 - 2014-10-29 04:53 - 00687496 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcrt.dll
2015-03-11 23:49 - 2014-10-29 04:52 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2015-03-11 23:49 - 2014-10-29 04:52 - 00244272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-03-11 23:49 - 2014-10-29 04:52 - 00225696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2015-03-11 23:49 - 2014-10-29 04:52 - 00161120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmmbase.dll
2015-03-11 23:49 - 2014-10-29 04:51 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2015-03-11 23:49 - 2014-10-29 04:51 - 00179736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2015-03-11 23:49 - 2014-10-29 04:18 - 00241168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll
2015-03-11 23:49 - 2014-10-29 04:15 - 00340848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2015-03-11 23:49 - 2014-10-29 04:15 - 00192096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2015-03-11 23:49 - 2014-10-29 04:15 - 00089856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2015-03-11 23:49 - 2014-10-29 04:13 - 00185880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xmllite.dll
2015-03-11 23:49 - 2014-10-29 04:12 - 00416760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-03-11 23:49 - 2014-10-29 04:11 - 00245296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMASF.DLL
2015-03-11 23:49 - 2014-10-29 04:11 - 00191104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2015-03-11 23:49 - 2014-10-29 04:11 - 00187488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2015-03-11 23:49 - 2014-10-29 04:10 - 01906872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplaySwitch.exe
2015-03-11 23:49 - 2014-10-29 04:10 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shlwapi.dll
2015-03-11 23:49 - 2014-10-29 04:10 - 00276816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsta.dll
2015-03-11 23:49 - 2014-10-29 04:10 - 00272648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp.dll
2015-03-11 23:49 - 2014-10-29 04:07 - 00336680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2015-03-11 23:49 - 2014-10-29 04:07 - 00260800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-03-11 23:49 - 2014-10-29 04:07 - 00202440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2015-03-11 23:49 - 2014-10-29 04:07 - 00019096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksuser.dll
2015-03-11 23:49 - 2014-10-29 04:05 - 00321248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2015-03-11 23:49 - 2014-10-29 04:05 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-03-11 23:49 - 2014-10-29 03:56 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfh264enc.dll
2015-03-11 23:49 - 2014-10-29 03:49 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp60.dll
2015-03-11 23:49 - 2014-10-29 03:46 - 00559104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys
2015-03-11 23:49 - 2014-10-29 03:46 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFRd.sys
2015-03-11 23:49 - 2014-10-29 03:45 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2015-03-11 23:49 - 2014-10-29 03:45 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
2015-03-11 23:49 - 2014-10-29 03:42 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2015-03-11 23:49 - 2014-10-29 03:41 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2015-03-11 23:49 - 2014-10-29 03:41 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2015-03-11 23:49 - 2014-10-29 03:41 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-03-11 23:49 - 2014-10-29 03:40 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput8.dll
2015-03-11 23:49 - 2014-10-29 03:36 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\prncache.dll
2015-03-11 23:49 - 2014-10-29 03:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsldp.dll
2015-03-11 23:49 - 2014-10-29 03:33 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Data001E.dll
2015-03-11 23:49 - 2014-10-29 03:32 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\migflt.dll
2015-03-11 23:49 - 2014-10-29 03:32 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqlceoledb40.dll
2015-03-11 23:49 - 2014-10-29 03:31 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\cewmdm.dll
2015-03-11 23:49 - 2014-10-29 03:31 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSyncMetastore.dll
2015-03-11 23:49 - 2014-10-29 03:30 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsClassExtension.dll
2015-03-11 23:49 - 2014-10-29 03:29 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhengine.dll
2015-03-11 23:49 - 2014-10-29 03:29 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\diskpart.exe
2015-03-11 23:49 - 2014-10-29 03:28 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
2015-03-11 23:49 - 2014-10-29 03:27 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\diskraid.exe
2015-03-11 23:49 - 2014-10-29 03:27 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmdskmgr.dll
2015-03-11 23:49 - 2014-10-29 03:27 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdv.dll
2015-03-11 23:49 - 2014-10-29 03:27 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssha.dll
2015-03-11 23:49 - 2014-10-29 03:27 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll
2015-03-11 23:49 - 2014-10-29 03:27 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmvdspa.dll
2015-03-11 23:49 - 2014-10-29 03:27 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfdvdec.dll
2015-03-11 23:49 - 2014-10-29 03:26 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\termmgr.dll
2015-03-11 23:49 - 2014-10-29 03:26 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2015-03-11 23:49 - 2014-10-29 03:26 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpresult.exe
2015-03-11 23:49 - 2014-10-29 03:24 - 00644608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVXENCD.DLL
2015-03-11 23:49 - 2014-10-29 03:22 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll
2015-03-11 23:49 - 2014-10-29 03:22 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrecst.dll
2015-03-11 23:49 - 2014-10-29 03:21 - 01664000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2015-03-11 23:49 - 2014-10-29 03:21 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2015-03-11 23:49 - 2014-10-29 03:20 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\QAGENTRT.DLL
2015-03-11 23:49 - 2014-10-29 03:20 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll
2015-03-11 23:49 - 2014-10-29 03:19 - 00451072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSENCD.DLL
2015-03-11 23:49 - 2014-10-29 03:18 - 01609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0000.dll
2015-03-11 23:49 - 2014-10-29 03:18 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscandui.dll
2015-03-11 23:49 - 2014-10-29 03:18 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasppp.dll
2015-03-11 23:49 - 2014-10-29 03:17 - 01926144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0022.dll
2015-03-11 23:49 - 2014-10-29 03:16 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsnap.dll
2015-03-11 23:49 - 2014-10-29 03:16 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\lltdapi.dll
2015-03-11 23:49 - 2014-10-29 03:15 - 03209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0049.dll
2015-03-11 23:49 - 2014-10-29 03:15 - 01904640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData002a.dll
2015-03-11 23:49 - 2014-10-29 03:14 - 01904640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData003e.dll
2015-03-11 23:49 - 2014-10-29 03:14 - 01904640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0021.dll
2015-03-11 23:49 - 2014-10-29 03:13 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll
2015-03-11 23:49 - 2014-10-29 03:13 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wavemsp.dll
2015-03-11 23:49 - 2014-10-29 03:12 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcat.dll
2015-03-11 23:49 - 2014-10-29 03:11 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2015-03-11 23:49 - 2014-10-29 03:11 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgprint.dll
2015-03-11 23:49 - 2014-10-29 03:10 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfh264enc.dll
2015-03-11 23:49 - 2014-10-29 03:09 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppIdPolicyEngineApi.dll
2015-03-11 23:49 - 2014-10-29 03:09 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\lltdsvc.dll
2015-03-11 23:49 - 2014-10-29 03:08 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdprint.dll
2015-03-11 23:49 - 2014-10-29 03:07 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrptadm.dll
2015-03-11 23:49 - 2014-10-29 03:05 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\srchadmin.dll
2015-03-11 23:49 - 2014-10-29 03:04 - 00612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IasMigPlugin.dll
2015-03-11 23:49 - 2014-10-29 03:04 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\devmgr.dll
2015-03-11 23:49 - 2014-10-29 03:04 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2015-03-11 23:49 - 2014-10-29 03:04 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2015-03-11 23:49 - 2014-10-29 03:04 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2015-03-11 23:49 - 2014-10-29 03:03 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-03-11 23:49 - 2014-10-29 03:03 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\xwtpdui.dll
2015-03-11 23:49 - 2014-10-29 03:02 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\localsec.dll
2015-03-11 23:49 - 2014-10-29 03:02 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xwizards.dll
2015-03-11 23:49 - 2014-10-29 03:02 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmontr.dll
2015-03-11 23:49 - 2014-10-29 03:02 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmstormod.dll
2015-03-11 23:49 - 2014-10-29 03:01 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2015-03-11 23:49 - 2014-10-29 03:01 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2015-03-11 23:49 - 2014-10-29 03:01 - 00475136 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2015-03-11 23:49 - 2014-10-29 03:00 - 03814400 _____ (Microsoft Corporation) C:\WINDOWS\system32\accessibilitycpl.dll
2015-03-11 23:49 - 2014-10-29 03:00 - 00435200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glmf32.dll
2015-03-11 23:49 - 2014-10-29 03:00 - 00371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe
2015-03-11 23:49 - 2014-10-29 03:00 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msls31.dll
2015-03-11 23:49 - 2014-10-29 03:00 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\riched32.dll
2015-03-11 23:49 - 2014-10-29 02:58 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-03-11 23:49 - 2014-10-29 02:58 - 00423424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2015-03-11 23:49 - 2014-10-29 02:57 - 01431552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxpTaskSync.dll
2015-03-11 23:49 - 2014-10-29 02:57 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll
2015-03-11 23:49 - 2014-10-29 02:57 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2015-03-11 23:49 - 2014-10-29 02:57 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-03-11 23:49 - 2014-10-29 02:56 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mblctr.exe
2015-03-11 23:49 - 2014-10-29 02:56 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-03-11 23:49 - 2014-10-29 02:54 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dim.dll
2015-03-11 23:49 - 2014-10-29 02:53 - 02238464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NL7Data0404.dll
2015-03-11 23:49 - 2014-10-29 02:53 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2015-03-11 23:49 - 2014-10-29 02:53 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2015-03-11 23:49 - 2014-10-29 02:52 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NL7Data0804.dll
2015-03-11 23:49 - 2014-10-29 02:52 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipsecsnp.dll
2015-03-11 23:49 - 2014-10-29 02:52 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netdiagfx.dll
2015-03-11 23:49 - 2014-10-29 02:52 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2015-03-11 23:49 - 2014-10-29 02:52 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsldp.dll
2015-03-11 23:49 - 2014-10-29 02:51 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2015-03-11 23:49 - 2014-10-29 02:50 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqlceoledb40.dll
2015-03-11 23:49 - 2014-10-29 02:49 - 00771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2015-03-11 23:49 - 2014-10-29 02:49 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2015-03-11 23:49 - 2014-10-29 02:49 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cewmdm.dll
2015-03-11 23:49 - 2014-10-29 02:49 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax
2015-03-11 23:49 - 2014-10-29 02:49 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmime.dll
2015-03-11 23:49 - 2014-10-29 02:48 - 01364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\connect.dll
2015-03-11 23:49 - 2014-10-29 02:48 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe
2015-03-11 23:49 - 2014-10-29 02:47 - 01041920 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2015-03-11 23:49 - 2014-10-29 02:47 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
2015-03-11 23:49 - 2014-10-29 02:47 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
2015-03-11 23:49 - 2014-10-29 02:46 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdv.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsnt.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\diskraid.exe
2015-03-11 23:49 - 2014-10-29 02:46 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoeacct.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmvdspa.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll
2015-03-11 23:49 - 2014-10-29 02:46 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfdvdec.dll
2015-03-11 23:49 - 2014-10-29 02:45 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Vault.dll
2015-03-11 23:49 - 2014-10-29 02:45 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdohlp.dll
2015-03-11 23:49 - 2014-10-29 02:45 - 00378880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\termmgr.dll
2015-03-11 23:49 - 2014-10-29 02:45 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\drmmgrtn.dll
2015-03-11 23:49 - 2014-10-29 02:45 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpresult.exe
2015-03-11 23:49 - 2014-10-29 02:44 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2015-03-11 23:49 - 2014-10-29 02:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2015-03-11 23:49 - 2014-10-29 02:43 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-03-11 23:49 - 2014-10-29 02:43 - 00736256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVXENCD.DLL
2015-03-11 23:49 - 2014-10-29 02:43 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2015-03-11 23:49 - 2014-10-29 02:43 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WmpDui.dll
2015-03-11 23:49 - 2014-10-29 02:43 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll
2015-03-11 23:49 - 2014-10-29 02:43 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offfilt.dll
2015-03-11 23:49 - 2014-10-29 02:42 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2015-03-11 23:49 - 2014-10-29 02:41 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassdo.dll
2015-03-11 23:49 - 2014-10-29 02:40 - 02036224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0007.dll
2015-03-11 23:49 - 2014-10-29 02:40 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshipsec.dll
2015-03-11 23:49 - 2014-10-29 02:40 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll
2015-03-11 23:49 - 2014-10-29 02:39 - 09604608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000a.dll
2015-03-11 23:49 - 2014-10-29 02:39 - 04531712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0416.dll
2015-03-11 23:49 - 2014-10-29 02:39 - 04530688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData001d.dll
2015-03-11 23:49 - 2014-10-29 02:39 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSENCD.DLL
2015-03-11 23:49 - 2014-10-29 02:39 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscandui.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 04530688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0010.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 04530176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0414.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 04529664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0816.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 02387456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000d.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 02307072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000c.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 02012160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0026.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 02012160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000f.dll
2015-03-11 23:49 - 2014-10-29 02:38 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2015-03-11 23:49 - 2014-10-29 02:37 - 03149824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0039.dll
2015-03-11 23:49 - 2014-10-29 02:37 - 01829376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData002a.dll
2015-03-11 23:49 - 2014-10-29 02:37 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsnap.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData004e.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData004c.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData004b.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData004a.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0049.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0047.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0046.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0045.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0020.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01999360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0027.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0c1a.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData081a.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0024.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData001b.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData001a.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0018.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0003.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0002.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01829376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData003e.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01829376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0022.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 01829376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0021.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
2015-03-11 23:49 - 2014-10-29 02:36 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbeio.dll
2015-03-11 23:49 - 2014-10-29 02:35 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2015-03-11 23:49 - 2014-10-29 02:34 - 00473600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll
2015-03-11 23:49 - 2014-10-29 02:34 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-03-11 23:49 - 2014-10-29 02:34 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapisrv.dll
2015-03-11 23:49 - 2014-10-29 02:31 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\netjoin.dll
2015-03-11 23:49 - 2014-10-29 02:30 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmdial32.dll
2015-03-11 23:49 - 2014-10-29 02:30 - 00482304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrptadm.dll
2015-03-11 23:49 - 2014-10-29 02:29 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IasMigPlugin.dll
2015-03-11 23:49 - 2014-10-29 02:29 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll
2015-03-11 23:49 - 2014-10-29 02:29 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devmgr.dll
2015-03-11 23:49 - 2014-10-29 02:29 - 00434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-03-11 23:49 - 2014-10-29 02:29 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2015-03-11 23:49 - 2014-10-29 02:28 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
2015-03-11 23:49 - 2014-10-29 02:28 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2015-03-11 23:49 - 2014-10-29 02:28 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2015-03-11 23:49 - 2014-10-29 02:28 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2015-03-11 23:49 - 2014-10-29 02:28 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptnet.dll
2015-03-11 23:49 - 2014-10-29 02:28 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ulib.dll
2015-03-11 23:49 - 2014-10-29 02:28 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasman.dll
2015-03-11 23:49 - 2014-10-29 02:27 - 00763392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2015-03-11 23:49 - 2014-10-29 02:27 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll
2015-03-11 23:49 - 2014-10-29 02:27 - 00397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xwizards.dll
2015-03-11 23:49 - 2014-10-29 02:27 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwizeng.dll
2015-03-11 23:49 - 2014-10-29 02:27 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2015-03-11 23:49 - 2014-10-29 02:27 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasmontr.dll
2015-03-11 23:49 - 2014-10-29 02:27 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-03-11 23:49 - 2014-10-29 02:26 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2015-03-11 23:49 - 2014-10-29 02:26 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-03-11 23:49 - 2014-10-29 02:25 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2015-03-11 23:49 - 2014-10-29 02:25 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncInfrastructure.dll
2015-03-11 23:49 - 2014-10-29 02:25 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe
2015-03-11 23:49 - 2014-10-29 02:25 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2015-03-11 23:49 - 2014-10-29 02:25 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2015-03-11 23:49 - 2014-10-29 02:24 - 01389056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxpTaskSync.dll
2015-03-11 23:49 - 2014-10-29 02:24 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2015-03-11 23:49 - 2014-10-29 02:24 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Geolocation.dll
2015-03-11 23:49 - 2014-10-29 02:24 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2015-03-11 23:49 - 2014-10-29 02:23 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDSp.dll
2015-03-11 23:49 - 2014-10-29 02:23 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2015-03-11 23:49 - 2014-10-29 02:22 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-03-11 23:49 - 2014-10-29 02:22 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-03-11 23:49 - 2014-10-29 02:22 - 00517120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-03-11 23:49 - 2014-10-29 02:22 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qasf.dll
2015-03-11 23:49 - 2014-10-29 02:21 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2015-03-11 23:49 - 2014-10-29 02:21 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe
2015-03-11 23:49 - 2014-10-29 02:21 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-03-11 23:49 - 2014-10-29 02:21 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2015-03-11 23:49 - 2014-10-29 02:21 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2015-03-11 23:49 - 2014-10-29 02:21 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipsecsnp.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdscore.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedyn.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssphtb.dll
2015-03-11 23:49 - 2014-10-29 02:20 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2015-03-11 23:49 - 2014-10-29 02:19 - 00701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2015-03-11 23:49 - 2014-10-29 02:19 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10_1core.dll
2015-03-11 23:49 - 2014-10-29 02:19 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10core.dll
2015-03-11 23:49 - 2014-10-29 02:19 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll
2015-03-11 23:49 - 2014-10-29 02:19 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-03-11 23:49 - 2014-10-29 02:18 - 00743936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFWMAAEC.DLL
2015-03-11 23:49 - 2014-10-29 02:18 - 00194560 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2015-03-11 23:49 - 2014-10-29 02:17 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\energy.dll
2015-03-11 23:49 - 2014-10-29 02:17 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2PGraph.dll
2015-03-11 23:49 - 2014-10-29 02:17 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-03-11 23:49 - 2014-10-29 02:17 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2015-03-11 23:49 - 2014-10-29 02:17 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2015-03-11 23:49 - 2014-10-29 02:16 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authfwcfg.dll
2015-03-11 23:49 - 2014-10-29 02:16 - 00283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drmmgrtn.dll
2015-03-11 23:49 - 2014-10-29 02:16 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2015-03-11 23:49 - 2014-10-29 02:16 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoeacct.dll
2015-03-11 23:49 - 2014-10-29 02:15 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-03-11 23:49 - 2014-10-29 02:14 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMActivate_ssp_isv.exe
2015-03-11 23:49 - 2014-10-29 02:14 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMActivate_ssp.exe
2015-03-11 23:49 - 2014-10-29 02:14 - 00301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2015-03-11 23:49 - 2014-10-29 02:13 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-03-11 23:49 - 2014-10-29 02:12 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
2015-03-11 23:49 - 2014-10-29 02:12 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hotspotauth.dll
2015-03-11 23:49 - 2014-10-29 02:12 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2015-03-11 23:49 - 2014-10-29 02:12 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-03-11 23:49 - 2014-10-29 02:12 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2015-03-11 23:49 - 2014-10-29 02:11 - 00672768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-03-11 23:49 - 2014-10-29 02:11 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtckrm.dll
2015-03-11 23:49 - 2014-10-29 02:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-03-11 23:49 - 2014-10-29 02:10 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpsrv.dll
2015-03-11 23:49 - 2014-10-29 02:10 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdmaud.drv
2015-03-11 23:49 - 2014-10-29 02:08 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll
2015-03-11 23:49 - 2014-10-29 02:08 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wecsvc.dll
2015-03-11 23:49 - 2014-10-29 02:07 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2015-03-11 23:49 - 2014-10-29 02:06 - 00301568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-03-11 23:49 - 2014-10-29 02:05 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2015-03-11 23:49 - 2014-10-29 02:05 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmd.exe
2015-03-11 23:49 - 2014-10-29 02:05 - 00309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsCfg.dll
2015-03-11 23:49 - 2014-10-29 02:05 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2015-03-11 23:49 - 2014-10-29 02:05 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2015-03-11 23:49 - 2014-10-29 02:05 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptnet.dll
2015-03-11 23:49 - 2014-10-29 02:04 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPTpm12.dll
2015-03-11 23:49 - 2014-10-29 02:04 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2015-03-11 23:49 - 2014-10-29 02:04 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netjoin.dll
2015-03-11 23:49 - 2014-10-29 02:04 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2015-03-11 23:49 - 2014-10-29 02:04 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2015-03-11 23:49 - 2014-10-29 02:04 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifsutil.dll
2015-03-11 23:49 - 2014-10-29 02:03 - 00608256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
2015-03-11 23:49 - 2014-10-29 02:03 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2015-03-11 23:49 - 2014-10-29 02:03 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2015-03-11 23:49 - 2014-10-29 02:03 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2015-03-11 23:49 - 2014-10-29 02:02 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Geolocation.dll
2015-03-11 23:49 - 2014-10-29 02:01 - 00397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdelta.dll
2015-03-11 23:49 - 2014-10-29 02:01 - 00214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2015-03-11 23:49 - 2014-10-29 02:00 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10_1core.dll
2015-03-11 23:49 - 2014-10-29 02:00 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedynos.dll
2015-03-11 23:49 - 2014-10-29 02:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-03-11 23:49 - 2014-10-29 02:00 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedyn.dll
2015-03-11 23:49 - 2014-10-29 02:00 - 00200192 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2015-03-11 23:49 - 2014-10-29 01:59 - 00603648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2015-03-11 23:49 - 2014-10-29 01:59 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10core.dll
2015-03-11 23:49 - 2014-10-29 01:59 - 00302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2015-03-11 23:49 - 2014-10-29 01:59 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-03-11 23:49 - 2014-10-29 01:59 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll
2015-03-11 23:49 - 2014-10-29 01:59 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2015-03-11 23:49 - 2014-10-29 01:58 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2015-03-11 23:49 - 2014-10-29 01:58 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll
2015-03-11 23:49 - 2014-10-29 01:58 - 00214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-03-11 23:49 - 2014-10-29 01:57 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2PGraph.dll
2015-03-11 23:49 - 2014-10-29 01:57 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authfwcfg.dll
2015-03-11 23:49 - 2014-10-29 01:57 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Proximity.dll
2015-03-11 23:49 - 2014-10-29 01:57 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2015-03-11 23:49 - 2014-10-29 01:56 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-03-11 23:49 - 2014-10-29 01:56 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RMActivate_ssp_isv.exe
2015-03-11 23:49 - 2014-10-29 01:56 - 00482304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RMActivate_ssp.exe
2015-03-11 23:49 - 2014-10-29 01:56 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2015-03-11 23:49 - 2014-10-29 01:56 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\activeds.dll
2015-03-11 23:49 - 2014-10-29 01:56 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2015-03-11 23:49 - 2014-10-29 01:55 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanpref.dll
2015-03-11 23:49 - 2014-10-29 01:55 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-03-11 23:49 - 2014-10-29 01:55 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2015-03-11 23:49 - 2014-10-29 01:55 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NAPMONTR.DLL
2015-03-11 23:49 - 2014-10-29 01:54 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceTypes.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.HardwareId.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2015-03-11 23:49 - 2014-10-29 01:54 - 00178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00550400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSATAPI.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_8.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-03-11 23:49 - 2014-10-29 01:53 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-03-11 23:49 - 2014-10-29 01:52 - 01024512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll
2015-03-11 23:49 - 2014-10-29 01:52 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2015-03-11 23:49 - 2014-10-29 01:52 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-03-11 23:49 - 2014-10-29 01:52 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2015-03-11 23:49 - 2014-10-29 01:52 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.SpeechSynthesis.dll
2015-03-11 23:49 - 2014-10-29 01:51 - 00244224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2015-03-11 23:49 - 2014-10-29 01:51 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2015-03-11 23:49 - 2014-10-29 01:50 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallControlPanel.dll
2015-03-11 23:49 - 2014-10-29 01:50 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-03-11 23:49 - 2014-10-29 01:49 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsvcs.dll
2015-03-11 23:49 - 2014-10-29 01:49 - 00559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2015-03-11 23:49 - 2014-10-29 01:49 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2015-03-11 23:49 - 2014-10-29 01:49 - 00300032 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll
2015-03-11 23:49 - 2014-10-29 01:49 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-03-11 23:49 - 2014-10-29 01:48 - 01170432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PeerDistSh.dll
2015-03-11 23:49 - 2014-10-29 01:48 - 00481280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmscan.dll
2015-03-11 23:49 - 2014-10-29 01:48 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2015-03-11 23:49 - 2014-10-29 01:47 - 00628224 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-03-11 23:49 - 2014-10-29 01:46 - 01305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-03-11 23:49 - 2014-10-29 01:46 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2015-03-11 23:49 - 2014-10-29 01:45 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\activeds.dll
2015-03-11 23:49 - 2014-10-29 01:44 - 00732672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanpref.dll
2015-03-11 23:49 - 2014-10-29 01:44 - 00561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2015-03-11 23:49 - 2014-10-29 01:44 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2015-03-11 23:49 - 2014-10-29 01:44 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll
2015-03-11 23:49 - 2014-10-29 01:44 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-03-11 23:49 - 2014-10-29 01:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2015-03-11 23:49 - 2014-10-29 01:43 - 00724480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-03-11 23:49 - 2014-10-29 01:43 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2015-03-11 23:49 - 2014-10-29 01:43 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSATAPI.dll
2015-03-11 23:49 - 2014-10-29 01:43 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
2015-03-11 23:49 - 2014-10-29 01:43 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.HardwareId.dll
2015-03-11 23:49 - 2014-10-29 01:42 - 00865280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallControlPanel.dll
2015-03-11 23:49 - 2014-10-29 01:41 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskeng.exe
2015-03-11 23:49 - 2014-10-29 01:41 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-03-11 23:49 - 2014-10-29 01:41 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2015-03-11 23:49 - 2014-10-29 01:38 - 00565760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2015-03-11 23:49 - 2014-10-29 01:35 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2015-03-11 23:49 - 2014-10-29 01:35 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2015-03-11 23:49 - 2014-10-29 01:30 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2015-03-11 23:49 - 2014-10-15 09:32 - 00337728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2015-03-11 23:49 - 2014-10-08 10:24 - 00467776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-03-11 23:49 - 2014-09-27 05:59 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-03-11 23:49 - 2014-08-26 04:30 - 00354112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2015-03-11 23:48 - 2014-10-29 05:10 - 00177688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2015-03-11 23:48 - 2014-10-29 05:10 - 00089344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhost.exe
2015-03-11 23:48 - 2014-10-29 05:09 - 00371304 _____ (Microsoft Corporation) C:\WINDOWS\system32\verifier.dll
2015-03-11 23:48 - 2014-10-29 05:09 - 00155456 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll
2015-03-11 23:48 - 2014-10-29 05:09 - 00145144 _____ (Microsoft Corporation) C:\WINDOWS\system32\cabinet.dll
2015-03-11 23:48 - 2014-10-29 05:09 - 00103744 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe
2015-03-11 23:48 - 2014-10-29 05:09 - 00017560 _____ (Microsoft Corporation) C:\WINDOWS\system32\psapi.dll
2015-03-11 23:48 - 2014-10-29 05:04 - 00196264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntmarta.dll
2015-03-11 23:48 - 2014-10-29 05:04 - 00153336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2015-03-11 23:48 - 2014-10-29 05:04 - 00135304 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2015-03-11 23:48 - 2014-10-29 05:04 - 00120384 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2015-03-11 23:48 - 2014-10-29 05:04 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\msasn1.dll
2015-03-11 23:48 - 2014-10-29 05:00 - 00297512 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2015-03-11 23:48 - 2014-10-29 05:00 - 00210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll
2015-03-11 23:48 - 2014-10-29 05:00 - 00125504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-03-11 23:48 - 2014-10-29 04:59 - 00105944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpr.dll
2015-03-11 23:48 - 2014-10-29 04:57 - 00447256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2015-03-11 23:48 - 2014-10-29 04:57 - 00299048 _____ (Microsoft Corporation) C:\WINDOWS\system32\VIDRESZR.DLL
2015-03-11 23:48 - 2014-10-29 04:57 - 00250488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPG4DECD.DLL
2015-03-11 23:48 - 2014-10-29 04:57 - 00248408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP43DECD.DLL
2015-03-11 23:48 - 2014-10-29 04:57 - 00246832 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2015-03-11 23:48 - 2014-10-29 04:57 - 00203504 _____ (Microsoft Corporation) C:\WINDOWS\system32\COLORCNV.DLL
2015-03-11 23:48 - 2014-10-29 04:57 - 00111024 _____ (Microsoft Corporation) C:\WINDOWS\system32\RestoreOptIn.exe
2015-03-11 23:48 - 2014-10-29 04:57 - 00022208 _____ (Microsoft Corporation) C:\WINDOWS\system32\PurchaseWindowsLicense.exe
2015-03-11 23:48 - 2014-10-29 04:55 - 00278392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkspbroker.exe
2015-03-11 23:48 - 2014-10-29 04:55 - 00019264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
2015-03-11 23:48 - 2014-10-29 04:52 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-03-11 23:48 - 2014-10-29 04:52 - 00132232 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
2015-03-11 23:48 - 2014-10-29 04:52 - 00126056 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmm.dll
2015-03-11 23:48 - 2014-10-29 04:51 - 00159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPHLPAPI.DLL
2015-03-11 23:48 - 2014-10-29 04:18 - 00348048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\verifier.dll
2015-03-11 23:48 - 2014-10-29 04:18 - 00164264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2015-03-11 23:48 - 2014-10-29 04:18 - 00148728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2015-03-11 23:48 - 2014-10-29 04:18 - 00127552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll
2015-03-11 23:48 - 2014-10-29 04:18 - 00120352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cabinet.dll
2015-03-11 23:48 - 2014-10-29 04:15 - 00154392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntmarta.dll
2015-03-11 23:48 - 2014-10-29 04:15 - 00119800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncrypt.dll
2015-03-11 23:48 - 2014-10-29 04:15 - 00115672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
2015-03-11 23:48 - 2014-10-29 04:15 - 00098152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2015-03-11 23:48 - 2014-10-29 04:12 - 00241680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2015-03-11 23:48 - 2014-10-29 04:12 - 00116696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxva2.dll
2015-03-11 23:48 - 2014-10-29 04:12 - 00102728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-03-11 23:48 - 2014-10-29 04:12 - 00087224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpr.dll
2015-03-11 23:48 - 2014-10-29 04:11 - 00275280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MPG4DECD.DLL
2015-03-11 23:48 - 2014-10-29 04:11 - 00274256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP43DECD.DLL
2015-03-11 23:48 - 2014-10-29 04:11 - 00229248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2015-03-11 23:48 - 2014-10-29 04:11 - 00190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVol.exe
2015-03-11 23:48 - 2014-10-29 04:11 - 00184888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\COLORCNV.DLL
2015-03-11 23:48 - 2014-10-29 04:11 - 00183832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VIDRESZR.DLL
2015-03-11 23:48 - 2014-10-29 04:11 - 00099104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2015-03-11 23:48 - 2014-10-29 04:10 - 00094464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RestoreOptIn.exe
2015-03-11 23:48 - 2014-10-29 04:09 - 00017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dllhost.exe
2015-03-11 23:48 - 2014-10-29 04:07 - 00136840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmm.dll
2015-03-11 23:48 - 2014-10-29 04:07 - 00134280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmmbase.dll
2015-03-11 23:48 - 2014-10-29 04:06 - 00111064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
2015-03-11 23:48 - 2014-10-29 04:05 - 00120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IPHLPAPI.DLL
2015-03-11 23:48 - 2014-10-29 03:48 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SSShim.dll
2015-03-11 23:48 - 2014-10-29 03:46 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-03-11 23:48 - 2014-10-29 03:46 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFPf.sys
2015-03-11 23:48 - 2014-10-29 03:45 - 01198080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-03-11 23:48 - 2014-10-29 03:44 - 00107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SPInf.dll
2015-03-11 23:48 - 2014-10-29 03:42 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\aelupsvc.dll
2015-03-11 23:48 - 2014-10-29 03:42 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\uudf.dll
2015-03-11 23:48 - 2014-10-29 03:42 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbnetlib.dll
2015-03-11 23:48 - 2014-10-29 03:41 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\drt.dll
2015-03-11 23:48 - 2014-10-29 03:41 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2015-03-11 23:48 - 2014-10-29 03:41 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsldpc.dll
2015-03-11 23:48 - 2014-10-29 03:41 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-03-11 23:48 - 2014-10-29 03:41 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-03-11 23:48 - 2014-10-29 03:39 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtfwd.dll
2015-03-11 23:48 - 2014-10-29 03:37 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput.dll
2015-03-11 23:48 - 2014-10-29 03:37 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfui.dll
2015-03-11 23:48 - 2014-10-29 03:36 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll
2015-03-11 23:48 - 2014-10-29 03:36 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\chartv.dll
2015-03-11 23:48 - 2014-10-29 03:35 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB7.dll
2015-03-11 23:48 - 2014-10-29 03:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionQueue.dll
2015-03-11 23:48 - 2014-10-29 03:34 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsdyn.dll
2015-03-11 23:48 - 2014-10-29 03:34 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2015-03-11 23:48 - 2014-10-29 03:34 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rgb9rast.dll
2015-03-11 23:48 - 2014-10-29 03:34 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fms.dll
2015-03-11 23:48 - 2014-10-29 03:33 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2015-03-11 23:48 - 2014-10-29 03:33 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2015-03-11 23:48 - 2014-10-29 03:33 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl.dll
2015-03-11 23:48 - 2014-10-29 03:32 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2015-03-11 23:48 - 2014-10-29 03:32 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqlcecompact40.dll
2015-03-11 23:48 - 2014-10-29 03:32 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\amstream.dll
2015-03-11 23:48 - 2014-10-29 03:31 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSTPager.ax
2015-03-11 23:48 - 2014-10-29 03:31 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\cca.dll
2015-03-11 23:48 - 2014-10-29 03:30 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaatext.dll
2015-03-11 23:48 - 2014-10-29 03:29 - 00350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcbase.dll
2015-03-11 23:48 - 2014-10-29 03:29 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassvcs.dll
2015-03-11 23:48 - 2014-10-29 03:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmusic.dll
2015-03-11 23:48 - 2014-10-29 03:28 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2015-03-11 23:48 - 2014-10-29 03:28 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2015-03-11 23:48 - 2014-10-29 03:27 - 00354816 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsnt.dll
2015-03-11 23:48 - 2014-10-29 03:27 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\NAPSTAT.EXE
2015-03-11 23:48 - 2014-10-29 03:27 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\mycomput.dll
2015-03-11 23:48 - 2014-10-29 03:27 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll
2015-03-11 23:48 - 2014-10-29 03:27 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdiageng.dll
2015-03-11 23:48 - 2014-10-29 03:27 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmvscmgr.exe
2015-03-11 23:48 - 2014-10-29 03:27 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Kswdmcap.ax
2015-03-11 23:48 - 2014-10-29 03:27 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Workplace.WorkplaceSettings.dll
2015-03-11 23:48 - 2014-10-29 03:26 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-03-11 23:48 - 2014-10-29 03:26 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Mpeg2Data.ax
2015-03-11 23:48 - 2014-10-29 03:26 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSDvbNP.ax
2015-03-11 23:48 - 2014-10-29 03:25 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2015-03-11 23:48 - 2014-10-29 03:25 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevPropMgr.dll
2015-03-11 23:48 - 2014-10-29 03:24 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2015-03-11 23:48 - 2014-10-29 03:24 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdaplgin.ax
2015-03-11 23:48 - 2014-10-29 03:23 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3gpui.dll
2015-03-11 23:48 - 2014-10-29 03:23 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\elshyph.dll
2015-03-11 23:48 - 2014-10-29 03:23 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssText3d.scr
2015-03-11 23:48 - 2014-10-29 03:23 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Tabbtn.dll
2015-03-11 23:48 - 2014-10-29 03:22 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\recimg.exe
2015-03-11 23:48 - 2014-10-29 03:22 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-03-11 23:48 - 2014-10-29 03:20 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2015-03-11 23:48 - 2014-10-29 03:19 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe
2015-03-11 23:48 - 2014-10-29 03:19 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dskquoui.dll
2015-03-11 23:48 - 2014-10-29 03:19 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\auditcse.dll
2015-03-11 23:48 - 2014-10-29 03:19 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\softkbd.dll
2015-03-11 23:48 - 2014-10-29 03:19 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2015-03-11 23:48 - 2014-10-29 03:18 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2015-03-11 23:48 - 2014-10-29 03:18 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\unattend.dll
2015-03-11 23:48 - 2014-10-29 03:18 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsadmin.exe
2015-03-11 23:48 - 2014-10-29 03:17 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\itircl.dll
2015-03-11 23:48 - 2014-10-29 03:17 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2015-03-11 23:48 - 2014-10-29 03:17 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi.dll
2015-03-11 23:48 - 2014-10-29 03:17 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSyncProviders.dll


Oktavius 13.03.2015 16:38

Teil Nr.3

Code:

2015-03-11 23:48 - 2014-10-29 03:16 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-03-11 23:48 - 2014-10-29 03:16 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-03-11 23:48 - 2014-10-29 03:14 - 00378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysFxUI.dll
2015-03-11 23:48 - 2014-10-29 03:14 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationSettings.exe
2015-03-11 23:48 - 2014-10-29 03:13 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\scansetting.dll
2015-03-11 23:48 - 2014-10-29 03:12 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2015-03-11 23:48 - 2014-10-29 03:12 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapisrv.dll
2015-03-11 23:48 - 2014-10-29 03:12 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddpchunk.dll
2015-03-11 23:48 - 2014-10-29 03:12 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhshl.dll
2015-03-11 23:48 - 2014-10-29 03:11 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SnippingTool.exe
2015-03-11 23:48 - 2014-10-29 03:11 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmdlgs.dll
2015-03-11 23:48 - 2014-10-29 03:10 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsprop.dll
2015-03-11 23:48 - 2014-10-29 03:09 - 00601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\psr.exe
2015-03-11 23:48 - 2014-10-29 03:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceSyncProvider.dll
2015-03-11 23:48 - 2014-10-29 03:09 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll
2015-03-11 23:48 - 2014-10-29 03:09 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dskquota.dll
2015-03-11 23:48 - 2014-10-29 03:09 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\psisrndr.ax
2015-03-11 23:48 - 2014-10-29 03:08 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.cpl
2015-03-11 23:48 - 2014-10-29 03:08 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContent.dll
2015-03-11 23:48 - 2014-10-29 03:07 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\els.dll
2015-03-11 23:48 - 2014-10-29 03:07 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
2015-03-11 23:48 - 2014-10-29 03:06 - 02134528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsCpl.dll
2015-03-11 23:48 - 2014-10-29 03:06 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssadmin.exe
2015-03-11 23:48 - 2014-10-29 03:04 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiadefui.dll
2015-03-11 23:48 - 2014-10-29 03:04 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp60.dll
2015-03-11 23:48 - 2014-10-29 03:03 - 00849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2015-03-11 23:48 - 2014-10-29 03:03 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsquery.dll
2015-03-11 23:48 - 2014-10-29 03:03 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\xwtpw32.dll
2015-03-11 23:48 - 2014-10-29 03:02 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercpl.dll
2015-03-11 23:48 - 2014-10-29 03:02 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2015-03-11 23:48 - 2014-10-29 03:02 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2015-03-11 23:48 - 2014-10-29 03:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\VBICodec.ax
2015-03-11 23:48 - 2014-10-29 03:01 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabletPC.cpl
2015-03-11 23:48 - 2014-10-29 03:00 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2015-03-11 23:48 - 2014-10-29 03:00 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlhtml.dll
2015-03-11 23:48 - 2014-10-29 03:00 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2015-03-11 23:48 - 2014-10-29 02:59 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe
2015-03-11 23:48 - 2014-10-29 02:59 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2015-03-11 23:48 - 2014-10-29 02:59 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\QAGENT.DLL
2015-03-11 23:48 - 2014-10-29 02:59 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll
2015-03-11 23:48 - 2014-10-29 02:58 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe
2015-03-11 23:48 - 2014-10-29 02:58 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSHVHOST.DLL
2015-03-11 23:48 - 2014-10-29 02:58 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrdc.dll
2015-03-11 23:48 - 2014-10-29 02:58 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uudf.dll
2015-03-11 23:48 - 2014-10-29 02:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbnetlib.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 01047040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagCpl.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthHFSrv.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOVER.exe
2015-03-11 23:48 - 2014-10-29 02:57 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2015-03-11 23:48 - 2014-10-29 02:57 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drt.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpdMtp.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
2015-03-11 23:48 - 2014-10-29 02:57 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll
2015-03-11 23:48 - 2014-10-29 02:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcjt32.dll
2015-03-11 23:48 - 2014-10-29 02:56 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2015-03-11 23:48 - 2014-10-29 02:55 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2015-03-11 23:48 - 2014-10-29 02:55 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput8.dll
2015-03-11 23:48 - 2014-10-29 02:55 - 00142848 _____ () C:\WINDOWS\system32\OEMLicense.dll
2015-03-11 23:48 - 2014-10-29 02:55 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput.dll
2015-03-11 23:48 - 2014-10-29 02:54 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmidx.dll
2015-03-11 23:48 - 2014-10-29 02:54 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcmiplugin.dll
2015-03-11 23:48 - 2014-10-29 02:54 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDShServiceObj.dll
2015-03-11 23:48 - 2014-10-29 02:54 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfui.dll
2015-03-11 23:48 - 2014-10-29 02:53 - 00449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\shwebsvc.dll
2015-03-11 23:48 - 2014-10-29 02:53 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll
2015-03-11 23:48 - 2014-10-29 02:52 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2015-03-11 23:48 - 2014-10-29 02:52 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll
2015-03-11 23:48 - 2014-10-29 02:52 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB7.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00782848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NL7Data001E.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdListen.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmstyle.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl.dll
2015-03-11 23:48 - 2014-10-29 02:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcompos.dll
2015-03-11 23:48 - 2014-10-29 02:50 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2015-03-11 23:48 - 2014-10-29 02:50 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2015-03-11 23:48 - 2014-10-29 02:50 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqlcecompact40.dll
2015-03-11 23:48 - 2014-10-29 02:49 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFWMAAEC.DLL
2015-03-11 23:48 - 2014-10-29 02:49 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll
2015-03-11 23:48 - 2014-10-29 02:49 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2015-03-11 23:48 - 2014-10-29 02:49 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSyncMetastore.dll
2015-03-11 23:48 - 2014-10-29 02:49 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\immersivetpmvscmgrsvr.exe
2015-03-11 23:48 - 2014-10-29 02:49 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmvscmgrsvr.exe
2015-03-11 23:48 - 2014-10-29 02:49 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmttpmvscmgrsvr.exe
2015-03-11 23:48 - 2014-10-29 02:49 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSTPager.ax
2015-03-11 23:48 - 2014-10-29 02:49 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cca.dll
2015-03-11 23:48 - 2014-10-29 02:49 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\amstream.dll
2015-03-11 23:48 - 2014-10-29 02:48 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll
2015-03-11 23:48 - 2014-10-29 02:48 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgmts.dll
2015-03-11 23:48 - 2014-10-29 02:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll
2015-03-11 23:48 - 2014-10-29 02:48 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmusic.dll
2015-03-11 23:48 - 2014-10-29 02:47 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsec.dll
2015-03-11 23:48 - 2014-10-29 02:47 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\diskpart.exe
2015-03-11 23:48 - 2014-10-29 02:46 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmdskmgr.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrad.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssha.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdiageng.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msnetobj.dll
2015-03-11 23:48 - 2014-10-29 02:46 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Kswdmcap.ax
2015-03-11 23:48 - 2014-10-29 02:46 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.WorkplaceSettings.dll
2015-03-11 23:48 - 2014-10-29 02:45 - 00879104 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2015-03-11 23:48 - 2014-10-29 02:45 - 00658944 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSSVC.exe
2015-03-11 23:48 - 2014-10-29 02:45 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ppcsnap.dll
2015-03-11 23:48 - 2014-10-29 02:45 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqad.dll
2015-03-11 23:48 - 2014-10-29 02:45 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2015-03-11 23:48 - 2014-10-29 02:45 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-03-11 23:48 - 2014-10-29 02:45 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Mpeg2Data.ax
2015-03-11 23:48 - 2014-10-29 02:44 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2015-03-11 23:48 - 2014-10-29 02:43 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3gpui.dll
2015-03-11 23:48 - 2014-10-29 02:43 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\elshyph.dll
2015-03-11 23:48 - 2014-10-29 02:43 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ssText3d.scr
2015-03-11 23:48 - 2014-10-29 02:42 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi32.dll
2015-03-11 23:48 - 2014-10-29 02:42 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrecst.dll
2015-03-11 23:48 - 2014-10-29 02:41 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\apds.dll
2015-03-11 23:48 - 2014-10-29 02:41 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2015-03-11 23:48 - 2014-10-29 02:41 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2015-03-11 23:48 - 2014-10-29 02:40 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe
2015-03-11 23:48 - 2014-10-29 02:40 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dskquoui.dll
2015-03-11 23:48 - 2014-10-29 02:40 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\softkbd.dll
2015-03-11 23:48 - 2014-10-29 02:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2015-03-11 23:48 - 2014-10-29 02:40 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olethk32.dll
2015-03-11 23:48 - 2014-10-29 02:39 - 00382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2015-03-11 23:48 - 2014-10-29 02:39 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsadmin.exe
2015-03-11 23:48 - 2014-10-29 02:39 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasppp.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 01548800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0000.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollUI.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itircl.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2015-03-11 23:48 - 2014-10-29 02:38 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2015-03-11 23:48 - 2014-10-29 02:38 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fde.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi.dll
2015-03-11 23:48 - 2014-10-29 02:38 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSyncProviders.dll
2015-03-11 23:48 - 2014-10-29 02:37 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-03-11 23:48 - 2014-10-29 02:35 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scansetting.dll
2015-03-11 23:48 - 2014-10-29 02:35 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wavemsp.dll
2015-03-11 23:48 - 2014-10-29 02:34 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmdlgs.dll
2015-03-11 23:48 - 2014-10-29 02:34 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\difxapi.dll
2015-03-11 23:48 - 2014-10-29 02:34 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eudcedit.exe
2015-03-11 23:48 - 2014-10-29 02:34 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
2015-03-11 23:48 - 2014-10-29 02:32 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psr.exe
2015-03-11 23:48 - 2014-10-29 02:32 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppIdPolicyEngineApi.dll
2015-03-11 23:48 - 2014-10-29 02:32 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsprop.dll
2015-03-11 23:48 - 2014-10-29 02:32 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceSyncProvider.dll
2015-03-11 23:48 - 2014-10-29 02:32 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisrndr.ax
2015-03-11 23:48 - 2014-10-29 02:31 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2015-03-11 23:48 - 2014-10-29 02:31 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdprint.dll
2015-03-11 23:48 - 2014-10-29 02:31 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.cpl
2015-03-11 23:48 - 2014-10-29 02:31 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rshx32.dll
2015-03-11 23:48 - 2014-10-29 02:30 - 02118144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsCpl.dll
2015-03-11 23:48 - 2014-10-29 02:30 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2015-03-11 23:48 - 2014-10-29 02:30 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\els.dll
2015-03-11 23:48 - 2014-10-29 02:29 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srchadmin.dll
2015-03-11 23:48 - 2014-10-29 02:29 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2015-03-11 23:48 - 2014-10-29 02:29 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00812032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\localsec.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiadefui.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00402944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsquery.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\audiodev.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xwtpdui.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmstormod.dll
2015-03-11 23:48 - 2014-10-29 02:28 - 00182272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2015-03-11 23:48 - 2014-10-29 02:27 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercpl.dll
2015-03-11 23:48 - 2014-10-29 02:27 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2015-03-11 23:48 - 2014-10-29 02:27 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrokerLib.dll
2015-03-11 23:48 - 2014-10-29 02:27 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VBICodec.ax
2015-03-11 23:48 - 2014-10-29 02:26 - 03788288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accessibilitycpl.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\provthrd.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
2015-03-11 23:48 - 2014-10-29 02:26 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifsutil.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDist.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mimofcodec.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ufat.dll
2015-03-11 23:48 - 2014-10-29 02:26 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2015-03-11 23:48 - 2014-10-29 02:25 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrdc.dll
2015-03-11 23:48 - 2014-10-29 02:25 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-03-11 23:48 - 2014-10-29 02:25 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mibincodec.dll
2015-03-11 23:48 - 2014-10-29 02:25 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-03-11 23:48 - 2014-10-29 02:25 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlhtml.dll
2015-03-11 23:48 - 2014-10-29 02:25 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\negoexts.dll
2015-03-11 23:48 - 2014-10-29 02:24 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe
2015-03-11 23:48 - 2014-10-29 02:24 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll
2015-03-11 23:48 - 2014-10-29 02:23 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2015-03-11 23:48 - 2014-10-29 02:23 - 00107008 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
2015-03-11 23:48 - 2014-10-29 02:22 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-03-11 23:48 - 2014-10-29 02:22 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sstpsvc.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Winlangdb.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\dps.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Compression.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidx.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2015-03-11 23:48 - 2014-10-29 02:21 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFSvc.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shwebsvc.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netdiagfx.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmidcom.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\comrepl.dll
2015-03-11 23:48 - 2014-10-29 02:20 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00465408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmitomi.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2015-03-11 23:48 - 2014-10-29 02:19 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\txflog.dll
2015-03-11 23:48 - 2014-10-29 02:18 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll
2015-03-11 23:48 - 2014-10-29 02:18 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\fundisc.dll
2015-03-11 23:48 - 2014-10-29 02:18 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\IDStore.dll
2015-03-11 23:48 - 2014-10-29 02:17 - 01296896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\connect.dll
2015-03-11 23:48 - 2014-10-29 02:17 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2015-03-11 23:48 - 2014-10-29 02:17 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsec.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00675328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Vault.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanui.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RADCUI.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mlang.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2015-03-11 23:48 - 2014-10-29 02:16 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtstocom.exe
2015-03-11 23:48 - 2014-10-29 02:16 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msnetobj.dll
2015-03-11 23:48 - 2014-10-29 02:15 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2015-03-11 23:48 - 2014-10-29 02:15 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqad.dll
2015-03-11 23:48 - 2014-10-29 02:14 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2015-03-11 23:48 - 2014-10-29 02:13 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apds.dll
2015-03-11 23:48 - 2014-10-29 02:12 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2015-03-11 23:48 - 2014-10-29 02:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollUI.dll
2015-03-11 23:48 - 2014-10-29 02:12 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsAuth.dll
2015-03-11 23:48 - 2014-10-29 02:12 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2015-03-11 23:48 - 2014-10-29 02:11 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2015-03-11 23:48 - 2014-10-29 02:10 - 00396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxclu.dll
2015-03-11 23:48 - 2014-10-29 02:10 - 00302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2015-03-11 23:48 - 2014-10-29 02:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_8.dll
2015-03-11 23:48 - 2014-10-29 02:10 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2015-03-11 23:48 - 2014-10-29 02:10 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbeio.dll
2015-03-11 23:48 - 2014-10-29 02:08 - 00397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL
2015-03-11 23:48 - 2014-10-29 02:08 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll
2015-03-11 23:48 - 2014-10-29 02:07 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-03-11 23:48 - 2014-10-29 02:06 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-03-11 23:48 - 2014-10-29 02:06 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
2015-03-11 23:48 - 2014-10-29 02:06 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2015-03-11 23:48 - 2014-10-29 02:05 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdigest.dll
2015-03-11 23:48 - 2014-10-29 02:05 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2015-03-11 23:48 - 2014-10-29 02:05 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2015-03-11 23:48 - 2014-10-29 02:05 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ulib.dll
2015-03-11 23:48 - 2014-10-29 02:04 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
2015-03-11 23:48 - 2014-10-29 02:04 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2015-03-11 23:48 - 2014-10-29 02:04 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ufat.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provthrd.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringStation.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00178688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PeerDist.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasman.dll
2015-03-11 23:48 - 2014-10-29 02:03 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2015-03-11 23:48 - 2014-10-29 02:03 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\negoexts.dll
2015-03-11 23:48 - 2014-10-29 02:02 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2015-03-11 23:48 - 2014-10-29 02:02 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-03-11 23:48 - 2014-10-29 02:02 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mibincodec.dll
2015-03-11 23:48 - 2014-10-29 02:01 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowslivelogin.dll
2015-03-11 23:48 - 2014-10-29 02:01 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2015-03-11 23:48 - 2014-10-29 02:00 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-03-11 23:48 - 2014-10-29 02:00 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2015-03-11 23:48 - 2014-10-29 02:00 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdscore.dll
2015-03-11 23:48 - 2014-10-29 02:00 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
2015-03-11 23:48 - 2014-10-29 02:00 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
2015-03-11 23:48 - 2014-10-29 02:00 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2015-03-11 23:48 - 2014-10-29 02:00 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dllhst3g.exe
2015-03-11 23:48 - 2014-10-29 01:59 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll
2015-03-11 23:48 - 2014-10-29 01:59 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistWSDDiscoProv.dll
2015-03-11 23:48 - 2014-10-29 01:59 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmitomi.dll
2015-03-11 23:48 - 2014-10-29 01:59 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-03-11 23:48 - 2014-10-29 01:59 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comrepl.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmshell.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fundisc.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IDStore.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\txflog.dll
2015-03-11 23:48 - 2014-10-29 01:58 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndfapi.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qwave.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpmon.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mlang.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2015-03-11 23:48 - 2014-10-29 01:57 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2015-03-11 23:48 - 2014-10-29 01:57 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtstocom.exe
2015-03-11 23:48 - 2014-10-29 01:57 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConfigureExpandedStorage.dll
2015-03-11 23:48 - 2014-10-29 01:55 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2015-03-11 23:48 - 2014-10-29 01:55 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2015-03-11 23:48 - 2014-10-29 01:55 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2015-03-11 23:48 - 2014-10-29 01:55 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdeploy.dll
2015-03-11 23:48 - 2014-10-29 01:55 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\adrclient.dll
2015-03-11 23:48 - 2014-10-29 01:55 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvcext.dll
2015-03-11 23:48 - 2014-10-29 01:54 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
2015-03-11 23:48 - 2014-10-29 01:54 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2015-03-11 23:48 - 2014-10-29 01:54 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2015-03-11 23:48 - 2014-10-29 01:53 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\raschap.dll
2015-03-11 23:48 - 2014-10-29 01:53 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2015-03-11 23:48 - 2014-10-29 01:53 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdmaud.drv
2015-03-11 23:48 - 2014-10-29 01:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AltTab.dll
2015-03-11 23:48 - 2014-10-29 01:52 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWSD.dll
2015-03-11 23:48 - 2014-10-29 01:52 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2015-03-11 23:48 - 2014-10-29 01:51 - 03317248 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2015-03-11 23:48 - 2014-10-29 01:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2015-03-11 23:48 - 2014-10-29 01:51 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsCfg.dll
2015-03-11 23:48 - 2014-10-29 01:51 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiohlp.dll
2015-03-11 23:48 - 2014-10-29 01:49 - 00831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll
2015-03-11 23:48 - 2014-10-29 01:47 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
2015-03-11 23:48 - 2014-10-29 01:47 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-03-11 23:48 - 2014-10-29 01:45 - 01197568 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-03-11 23:48 - 2014-10-29 01:45 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstask.dll
2015-03-11 23:48 - 2014-10-29 01:45 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2015-03-11 23:48 - 2014-10-29 01:45 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll
2015-03-11 23:48 - 2014-10-29 01:44 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2015-03-11 23:48 - 2014-10-29 01:44 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2015-03-11 23:48 - 2014-10-29 01:44 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2015-03-11 23:48 - 2014-10-29 01:43 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NAPMONTR.DLL
2015-03-11 23:48 - 2014-10-29 01:43 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceTypes.dll
2015-03-11 23:48 - 2014-10-29 01:43 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2015-03-11 23:48 - 2014-10-29 01:43 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-03-11 23:48 - 2014-10-29 01:42 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.SpeechSynthesis.dll
2015-03-11 23:48 - 2014-10-29 01:42 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlancfg.dll
2015-03-11 23:48 - 2014-10-29 01:42 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2015-03-11 23:48 - 2014-10-29 01:39 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2015-03-11 23:48 - 2014-10-29 01:39 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingMonitor.dll
2015-03-11 23:48 - 2014-10-29 01:38 - 01232896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-03-11 23:48 - 2014-10-29 01:37 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-03-11 23:48 - 2014-10-29 01:37 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
2015-03-11 23:48 - 2014-10-29 01:35 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2015-03-11 23:48 - 2014-10-29 01:35 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2015-03-11 23:48 - 2014-10-29 01:35 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2015-03-11 23:48 - 2014-10-29 01:31 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
2015-03-11 23:47 - 2014-10-29 05:10 - 00084184 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostex.exe
2015-03-11 23:47 - 2014-10-29 05:09 - 00191032 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2015-03-11 23:47 - 2014-10-29 05:09 - 00092992 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeyboardFilterSvc.dll
2015-03-11 23:47 - 2014-10-29 05:04 - 00224600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntasn1.dll
2015-03-11 23:47 - 2014-10-29 05:04 - 00197832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssenh.dll
2015-03-11 23:47 - 2014-10-29 05:04 - 00122912 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsp.dll
2015-03-11 23:47 - 2014-10-29 05:04 - 00097608 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdll.dll
2015-03-11 23:47 - 2014-10-29 05:04 - 00093000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2015-03-11 23:47 - 2014-10-29 05:03 - 00196928 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2015-03-11 23:47 - 2014-10-29 05:00 - 00030472 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogHost.exe
2015-03-11 23:47 - 2014-10-29 04:59 - 00136512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2015-03-11 23:47 - 2014-10-29 04:57 - 00116696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2015-03-11 23:47 - 2014-10-29 04:57 - 00098664 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2015-03-11 23:47 - 2014-10-29 04:57 - 00089816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfvdsp.dll
2015-03-11 23:47 - 2014-10-29 04:55 - 00076432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sessionmsg.exe
2015-03-11 23:47 - 2014-10-29 04:53 - 00080528 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2015-03-11 23:47 - 2014-10-29 04:52 - 00106384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msacm32.dll
2015-03-11 23:47 - 2014-10-29 04:52 - 00101736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfAACEnc.dll
2015-03-11 23:47 - 2014-10-29 04:52 - 00100672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2015-03-11 23:47 - 2014-10-29 04:52 - 00090880 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2015-03-11 23:47 - 2014-10-29 04:51 - 00070288 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll
2015-03-11 23:47 - 2014-10-29 04:18 - 00255136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powrprof.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00168256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00165728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntasn1.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00156992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dssenh.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00099104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptxml.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00096032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptsp.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00073840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.CredentialPicker.dll
2015-03-11 23:47 - 2014-10-29 04:15 - 00051608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msasn1.dll
2015-03-11 23:47 - 2014-10-29 04:11 - 00076912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfvdsp.dll
2015-03-11 23:47 - 2014-10-29 04:10 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2015-03-11 23:47 - 2014-10-29 04:07 - 00110512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-03-11 23:47 - 2014-10-29 04:07 - 00089816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msacm32.dll
2015-03-11 23:47 - 2014-10-29 04:07 - 00081008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2015-03-11 23:47 - 2014-10-29 04:07 - 00018040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2015-03-11 23:47 - 2014-10-29 04:06 - 00090368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfAACEnc.dll
2015-03-11 23:47 - 2014-10-29 04:06 - 00074824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2015-03-11 23:47 - 2014-10-29 03:45 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2015-03-11 23:47 - 2014-10-29 03:45 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpnpmgr.dll
2015-03-11 23:47 - 2014-10-29 03:45 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2015-03-11 23:47 - 2014-10-29 03:45 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rassstp.sys
2015-03-11 23:47 - 2014-10-29 03:44 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll
2015-03-11 23:47 - 2014-10-29 03:44 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolss.dll
2015-03-11 23:47 - 2014-10-29 03:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\fmapi.dll
2015-03-11 23:47 - 2014-10-29 03:42 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll
2015-03-11 23:47 - 2014-10-29 03:41 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpapi.dll
2015-03-11 23:47 - 2014-10-29 03:40 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll
2015-03-11 23:47 - 2014-10-29 03:36 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2015-03-11 23:47 - 2014-10-29 03:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasdatastore.dll
2015-03-11 23:47 - 2014-10-29 03:34 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprovisionsp.dll
2015-03-11 23:47 - 2014-10-29 03:34 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsigd.dll
2015-03-11 23:47 - 2014-10-29 03:33 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2015-03-11 23:47 - 2014-10-29 03:33 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbceip.dll
2015-03-11 23:47 - 2014-10-29 03:33 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\oledlg.dll
2015-03-11 23:47 - 2014-10-29 03:33 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\system32\KMSVC.DLL
2015-03-11 23:47 - 2014-10-29 03:33 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2015-03-11 23:47 - 2014-10-29 03:32 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\avifil32.dll
2015-03-11 23:47 - 2014-10-29 03:32 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\g711codc.ax
2015-03-11 23:47 - 2014-10-29 03:31 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\PkgMgr.exe
2015-03-11 23:47 - 2014-10-29 03:31 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveprompt.exe
2015-03-11 23:47 - 2014-10-29 03:31 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmview.ocx
2015-03-11 23:47 - 2014-10-29 03:31 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsrchph.dll
2015-03-11 23:47 - 2014-10-29 03:30 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-03-11 23:47 - 2014-10-29 03:30 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgmts.dll
2015-03-11 23:47 - 2014-10-29 03:29 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\verifier.exe
2015-03-11 23:47 - 2014-10-29 03:29 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll
2015-03-11 23:47 - 2014-10-29 03:29 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsrchapi.dll
2015-03-11 23:47 - 2014-10-29 03:28 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2015-03-11 23:47 - 2014-10-29 03:27 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2015-03-11 23:47 - 2014-10-29 03:27 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2015-03-11 23:47 - 2014-10-29 03:27 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2015-03-11 23:47 - 2014-10-29 03:27 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll
2015-03-11 23:47 - 2014-10-29 03:27 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabbtnEx.dll
2015-03-11 23:47 - 2014-10-29 03:27 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasads.dll
2015-03-11 23:47 - 2014-10-29 03:26 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2015-03-11 23:47 - 2014-10-29 03:26 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\NdisImPlatform.dll
2015-03-11 23:47 - 2014-10-29 03:26 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\QUTIL.DLL
2015-03-11 23:47 - 2014-10-29 03:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlahc.dll
2015-03-11 23:47 - 2014-10-29 03:26 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksxbar.ax
2015-03-11 23:47 - 2014-10-29 03:26 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-03-11 23:47 - 2014-10-29 03:25 - 00427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2015-03-11 23:47 - 2014-10-29 03:25 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
2015-03-11 23:47 - 2014-10-29 03:25 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Ribbons.scr
2015-03-11 23:47 - 2014-10-29 03:25 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\iashlpr.dll
2015-03-11 23:47 - 2014-10-29 03:24 - 00788480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Bubbles.scr
2015-03-11 23:47 - 2014-10-29 03:24 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Mystify.scr
2015-03-11 23:47 - 2014-10-29 03:24 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fphc.dll
2015-03-11 23:47 - 2014-10-29 03:24 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2015-03-11 23:47 - 2014-10-29 03:23 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi32.dll
2015-03-11 23:47 - 2014-10-29 03:23 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3mm.dll
2015-03-11 23:47 - 2014-10-29 03:23 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\scripto.dll
2015-03-11 23:47 - 2014-10-29 03:22 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2015-03-11 23:47 - 2014-10-29 03:22 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\advpack.dll
2015-03-11 23:47 - 2014-10-29 03:22 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-03-11 23:47 - 2014-10-29 03:22 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\igdDiag.dll
2015-03-11 23:47 - 2014-10-29 03:21 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\kstvtune.ax
2015-03-11 23:47 - 2014-10-29 03:20 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\desk.cpl
2015-03-11 23:47 - 2014-10-29 03:20 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2015-03-11 23:47 - 2014-10-29 03:20 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqmigplugin.dll
2015-03-11 23:47 - 2014-10-29 03:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll
2015-03-11 23:47 - 2014-10-29 03:19 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsigd.dll
2015-03-11 23:47 - 2014-10-29 03:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll
2015-03-11 23:47 - 2014-10-29 03:19 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinMsoIrmProtector.dll
2015-03-11 23:47 - 2014-10-29 03:19 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinOpcIrmProtector.dll
2015-03-11 23:47 - 2014-10-29 03:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2015-03-11 23:47 - 2014-10-29 03:18 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMM.dll
2015-03-11 23:47 - 2014-10-29 03:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\TapiMigPlugin.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SNTSearch.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmgp.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\fde.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2015-03-11 23:47 - 2014-10-29 03:17 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2015-03-11 23:47 - 2014-10-29 03:17 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CscMig.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdart.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndfhcdiscovery.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbccu32.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbccr32.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\correngine.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\playlistfolder.dll
2015-03-11 23:47 - 2014-10-29 03:17 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersGPExt.dll
2015-03-11 23:47 - 2014-10-29 03:16 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\eudcedit.exe
2015-03-11 23:47 - 2014-10-29 03:16 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msconfig.exe
2015-03-11 23:47 - 2014-10-29 03:16 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndfetw.dll
2015-03-11 23:47 - 2014-10-29 03:13 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2015-03-11 23:47 - 2014-10-29 03:12 - 00660480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dccw.exe
2015-03-11 23:47 - 2014-10-29 03:12 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceStatus.dll
2015-03-11 23:47 - 2014-10-29 03:12 - 00096256 _____ () C:\WINDOWS\system32\BthpanContextHandler.dll
2015-03-11 23:47 - 2014-10-29 03:12 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WABSyncProvider.dll
2015-03-11 23:47 - 2014-10-29 03:11 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\scavengeui.dll
2015-03-11 23:47 - 2014-10-29 03:10 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\RASMM.dll
2015-03-11 23:47 - 2014-10-29 03:09 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\cttune.exe
2015-03-11 23:47 - 2014-10-29 03:09 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2015-03-11 23:47 - 2014-10-29 03:08 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdiagprv.dll
2015-03-11 23:47 - 2014-10-29 03:08 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiadss.dll
2015-03-11 23:47 - 2014-10-29 03:07 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2015-03-11 23:47 - 2014-10-29 03:07 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\EhStorShell.dll
2015-03-11 23:47 - 2014-10-29 03:06 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2015-03-11 23:47 - 2014-10-29 03:06 - 00517120 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmdial32.dll
2015-03-11 23:47 - 2014-10-29 03:06 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2015-03-11 23:47 - 2014-10-29 03:06 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
2015-03-11 23:47 - 2014-10-29 03:06 - 00113664 _____ (Microsoft) C:\WINDOWS\system32\SMBHelperClass.dll
2015-03-11 23:47 - 2014-10-29 03:06 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndishc.dll
2015-03-11 23:47 - 2014-10-29 03:05 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\systeminfo.exe
2015-03-11 23:47 - 2014-10-29 03:05 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiascanprofiles.dll
2015-03-11 23:47 - 2014-10-29 03:04 - 00546304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
2015-03-11 23:47 - 2014-10-29 03:04 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2015-03-11 23:47 - 2014-10-29 03:04 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingFolder.dll
2015-03-11 23:47 - 2014-10-29 03:04 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskkill.exe
2015-03-11 23:47 - 2014-10-29 03:04 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Utilman.exe
2015-03-11 23:47 - 2014-10-29 03:03 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\remotepg.dll
2015-03-11 23:47 - 2014-10-29 03:03 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SoundRecorder.exe
2015-03-11 23:47 - 2014-10-29 03:03 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SSShim.dll
2015-03-11 23:47 - 2014-10-29 03:02 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2015-03-11 23:47 - 2014-10-29 03:01 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2pnetsh.dll
2015-03-11 23:47 - 2014-10-29 03:01 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnshc.dll
2015-03-11 23:47 - 2014-10-29 03:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2015-03-11 23:47 - 2014-10-29 03:00 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\syncui.dll
2015-03-11 23:47 - 2014-10-29 03:00 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SPInf.dll
2015-03-11 23:47 - 2014-10-29 03:00 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2015-03-11 23:47 - 2014-10-29 02:59 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdadiag.dll
2015-03-11 23:47 - 2014-10-29 02:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll
2015-03-11 23:47 - 2014-10-29 02:59 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2015-03-11 23:47 - 2014-10-29 02:59 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\networkitemfactory.dll
2015-03-11 23:47 - 2014-10-29 02:58 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2015-03-11 23:47 - 2014-10-29 02:58 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2015-03-11 23:47 - 2014-10-29 02:58 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSVRMGMT.DLL
2015-03-11 23:47 - 2014-10-29 02:58 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2015-03-11 23:47 - 2014-10-29 02:58 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\radardt.dll
2015-03-11 23:47 - 2014-10-29 02:57 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwlauncher.dll
2015-03-11 23:47 - 2014-10-29 02:57 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsldpc.dll
2015-03-11 23:47 - 2014-10-29 02:57 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpdMtpUS.dll
2015-03-11 23:47 - 2014-10-29 02:57 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\raserver.exe
2015-03-11 23:47 - 2014-10-29 02:57 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ssdpapi.dll
2015-03-11 23:47 - 2014-10-29 02:56 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiashext.dll
2015-03-11 23:47 - 2014-10-29 02:56 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlandlg.dll
2015-03-11 23:47 - 2014-10-29 02:56 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkspbrokerAx.dll
2015-03-11 23:47 - 2014-10-29 02:56 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtfwd.dll
2015-03-11 23:47 - 2014-10-29 02:56 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\l2gpstore.dll
2015-03-11 23:47 - 2014-10-29 02:55 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-03-11 23:47 - 2014-10-29 02:55 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\rekeywiz.exe
2015-03-11 23:47 - 2014-10-29 02:54 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanHC.dll
2015-03-11 23:47 - 2014-10-29 02:54 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll
2015-03-11 23:47 - 2014-10-29 02:54 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-03-11 23:47 - 2014-10-29 02:53 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2015-03-11 23:47 - 2014-10-29 02:53 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prncache.dll
2015-03-11 23:47 - 2014-10-29 02:53 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chartv.dll
2015-03-11 23:47 - 2014-10-29 02:53 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winethc.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\L2SecHC.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrahc.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fms.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc_ssp_isv.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc_ssp.dll
2015-03-11 23:47 - 2014-10-29 02:52 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertPolEng.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsdmo.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvfw32.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oledlg.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\logagent.exe
2015-03-11 23:47 - 2014-10-29 02:51 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmscript.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2015-03-11 23:47 - 2014-10-29 02:51 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2015-03-11 23:47 - 2014-10-29 02:50 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2015-03-11 23:47 - 2014-10-29 02:50 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\avifil32.dll
2015-03-11 23:47 - 2014-10-29 02:49 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2015-03-11 23:47 - 2014-10-29 02:49 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmview.ocx
2015-03-11 23:47 - 2014-10-29 02:48 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcbase.dll
2015-03-11 23:47 - 2014-10-29 02:48 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-03-11 23:47 - 2014-10-29 02:48 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\verifier.exe
2015-03-11 23:47 - 2014-10-29 02:48 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaatext.dll
2015-03-11 23:47 - 2014-10-29 02:48 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Syncreg.dll
2015-03-11 23:47 - 2014-10-29 02:47 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassvcs.dll
2015-03-11 23:47 - 2014-10-29 02:47 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2015-03-11 23:47 - 2014-10-29 02:46 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mycomput.dll
2015-03-11 23:47 - 2014-10-29 02:46 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbccp32.dll
2015-03-11 23:47 - 2014-10-29 02:46 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2015-03-11 23:47 - 2014-10-29 02:46 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2015-03-11 23:47 - 2014-10-29 02:46 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasacct.dll
2015-03-11 23:47 - 2014-10-29 02:45 - 01678336 _____ (Microsoft Corporation) C:\WINDOWS\system32\networkexplorer.dll
2015-03-11 23:47 - 2014-10-29 02:45 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsuiext.dll
2015-03-11 23:47 - 2014-10-29 02:45 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NAPSTAT.EXE
2015-03-11 23:47 - 2014-10-29 02:45 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSDvbNP.ax
2015-03-11 23:47 - 2014-10-29 02:45 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksxbar.ax
2015-03-11 23:47 - 2014-10-29 02:44 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Bubbles.scr
2015-03-11 23:47 - 2014-10-29 02:44 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Mystify.scr
2015-03-11 23:47 - 2014-10-29 02:44 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Ribbons.scr
2015-03-11 23:47 - 2014-10-29 02:44 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2015-03-11 23:47 - 2014-10-29 02:43 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2015-03-11 23:47 - 2014-10-29 02:43 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2015-03-11 23:47 - 2014-10-29 02:43 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fphc.dll
2015-03-11 23:47 - 2014-10-29 02:43 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.UserConsentVerifier.dll

2015-03-11 23:47 - 2014-10-29 02:43 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bdaplgin.ax
2015-03-11 23:47 - 2014-10-29 02:42 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advpack.dll
2015-03-11 23:47 - 2014-10-29 02:42 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-03-11 23:47 - 2014-10-29 02:41 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\modemui.dll
2015-03-11 23:47 - 2014-10-29 02:41 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsicpl.dll
2015-03-11 23:47 - 2014-10-29 02:41 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqmigplugin.dll
2015-03-11 23:47 - 2014-10-29 02:41 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kstvtune.ax
2015-03-11 23:47 - 2014-10-29 02:40 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll
2015-03-11 23:47 - 2014-10-29 02:40 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\desk.cpl
2015-03-11 23:47 - 2014-10-29 02:40 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinMsoIrmProtector.dll
2015-03-11 23:47 - 2014-10-29 02:40 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinOpcIrmProtector.dll
2015-03-11 23:47 - 2014-10-29 02:39 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icsigd.dll
2015-03-11 23:47 - 2014-10-29 02:39 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2015-03-11 23:47 - 2014-10-29 02:38 - 00898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2015-03-11 23:47 - 2014-10-29 02:38 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmgp.dll
2015-03-11 23:47 - 2014-10-29 02:38 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2015-03-11 23:47 - 2014-10-29 02:38 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdart.dll
2015-03-11 23:47 - 2014-10-29 02:38 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logman.exe
2015-03-11 23:47 - 2014-10-29 02:38 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmstp.exe
2015-03-11 23:47 - 2014-10-29 02:38 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbccr32.dll
2015-03-11 23:47 - 2014-10-29 02:37 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbccu32.dll
2015-03-11 23:47 - 2014-10-29 02:34 - 00644608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dccw.exe
2015-03-11 23:47 - 2014-10-29 02:34 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceStatus.dll
2015-03-11 23:47 - 2014-10-29 02:34 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2015-03-11 23:47 - 2014-10-29 02:34 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
2015-03-11 23:47 - 2014-10-29 02:32 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dfrgui.exe
2015-03-11 23:47 - 2014-10-29 02:32 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cttune.exe
2015-03-11 23:47 - 2014-10-29 02:32 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
2015-03-11 23:47 - 2014-10-29 02:32 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll
2015-03-11 23:47 - 2014-10-29 02:32 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dskquota.dll
2015-03-11 23:47 - 2014-10-29 02:31 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2015-03-11 23:47 - 2014-10-29 02:31 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdiagprv.dll
2015-03-11 23:47 - 2014-10-29 02:31 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiadss.dll
2015-03-11 23:47 - 2014-10-29 02:30 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2015-03-11 23:47 - 2014-10-29 02:30 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssadmin.exe
2015-03-11 23:47 - 2014-10-29 02:30 - 00085504 _____ (Microsoft) C:\WINDOWS\SysWOW64\SMBHelperClass.dll
2015-03-11 23:47 - 2014-10-29 02:29 - 00528896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
2015-03-11 23:47 - 2014-10-29 02:29 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairingFolder.dll
2015-03-11 23:47 - 2014-10-29 02:29 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credui.dll
2015-03-11 23:47 - 2014-10-29 02:29 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systeminfo.exe
2015-03-11 23:47 - 2014-10-29 02:28 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remotepg.dll
2015-03-11 23:47 - 2014-10-29 02:28 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xwtpw32.dll
2015-03-11 23:47 - 2014-10-29 02:28 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tasklist.exe
2015-03-11 23:47 - 2014-10-29 02:28 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskkill.exe
2015-03-11 23:47 - 2014-10-29 02:28 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\samcli.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptuiwizard.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallButtons.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll
2015-03-11 23:47 - 2014-10-29 02:27 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\xcopy.exe
2015-03-11 23:47 - 2014-10-29 02:26 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\p2pnetsh.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QAGENT.DLL
2015-03-11 23:47 - 2014-10-29 02:26 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\uexfat.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wecapi.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncobjapi.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeservice.dll
2015-03-11 23:47 - 2014-10-29 02:26 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscapi.dll
2015-03-11 23:47 - 2014-10-29 02:25 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSHVHOST.DLL
2015-03-11 23:47 - 2014-10-29 02:25 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-03-11 23:47 - 2014-10-29 02:25 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2015-03-11 23:47 - 2014-10-29 02:25 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wecutil.exe
2015-03-11 23:47 - 2014-10-29 02:25 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2015-03-11 23:47 - 2014-10-29 02:25 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSVRMGMT.DLL
2015-03-11 23:47 - 2014-10-29 02:24 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiashext.dll
2015-03-11 23:47 - 2014-10-29 02:24 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceWMDRM.dll
2015-03-11 23:47 - 2014-10-29 02:24 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2015-03-11 23:47 - 2014-10-29 02:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceWiaCompat.dll
2015-03-11 23:47 - 2014-10-29 02:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2015-03-11 23:47 - 2014-10-29 02:24 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\raserver.exe
2015-03-11 23:47 - 2014-10-29 02:23 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlandlg.dll
2015-03-11 23:47 - 2014-10-29 02:23 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkspbrokerAx.dll
2015-03-11 23:47 - 2014-10-29 02:22 - 00194560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2015-03-11 23:47 - 2014-10-29 02:22 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rekeywiz.exe
2015-03-11 23:47 - 2014-10-29 02:22 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmInit.exe
2015-03-11 23:47 - 2014-10-29 02:22 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDShServiceObj.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\korwbrkr.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\trkwks.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcmiplugin.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\alg.exe
2015-03-11 23:47 - 2014-10-29 02:21 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdi.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdprov.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Sockets.PushEnabledApplication.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\nduprov.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\threadpoolwinrt.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddrawex.dll
2015-03-11 23:47 - 2014-10-29 02:21 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxdm.dll
2015-03-11 23:47 - 2014-10-29 02:20 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
2015-03-11 23:47 - 2014-10-29 02:20 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2015-03-11 23:47 - 2014-10-29 02:20 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSXP32.dll
2015-03-11 23:47 - 2014-10-29 02:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmtrace.dll
2015-03-11 23:47 - 2014-10-29 02:20 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\prvdmofcomp.dll
2015-03-11 23:47 - 2014-10-29 02:20 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ELSCore.dll
2015-03-11 23:47 - 2014-10-29 02:19 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\smbwmiv2.dll
2015-03-11 23:47 - 2014-10-29 02:19 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtclog.dll
2015-03-11 23:47 - 2014-10-29 02:19 - 00092672 _____ (Microsoft) C:\WINDOWS\system32\VaultRoaming.dll


Oktavius 13.03.2015 16:39

Nr.4

Code:

2015-03-11 23:47 - 2014-10-29 02:19 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logagent.exe
2015-03-11 23:47 - 2014-10-29 02:19 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\colbact.dll
2015-03-11 23:47 - 2014-10-29 02:18 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10_1.dll
2015-03-11 23:47 - 2014-10-29 02:18 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2015-03-11 23:47 - 2014-10-29 02:17 - 00303104 _____ (Microsoft Corporation) C:\WINDOWS\system32\qwave.dll
2015-03-11 23:47 - 2014-10-29 02:17 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysdm.cpl
2015-03-11 23:47 - 2014-10-29 02:17 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2015-03-11 23:47 - 2014-10-29 02:17 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2015-03-11 23:47 - 2014-10-29 02:17 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAPQEC.DLL
2015-03-11 23:47 - 2014-10-29 02:17 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsdwmdr.dll
2015-03-11 23:47 - 2014-10-29 02:16 - 01669632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\networkexplorer.dll
2015-03-11 23:47 - 2014-10-29 02:16 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmifw.dll
2015-03-11 23:47 - 2014-10-29 02:15 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsuiext.dll
2015-03-11 23:47 - 2014-10-29 02:15 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2015-03-11 23:47 - 2014-10-29 02:15 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
2015-03-11 23:47 - 2014-10-29 02:14 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-03-11 23:47 - 2014-10-29 02:14 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapsvc.dll
2015-03-11 23:47 - 2014-10-29 02:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2015-03-11 23:47 - 2014-10-29 02:12 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2015-03-11 23:47 - 2014-10-29 02:11 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-03-11 23:47 - 2014-10-29 02:10 - 00465408 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschap.dll
2015-03-11 23:47 - 2014-10-29 02:10 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2015-03-11 23:47 - 2014-10-29 02:09 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafupnp.dll
2015-03-11 23:47 - 2014-10-29 02:09 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2015-03-11 23:47 - 2014-10-29 02:07 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unregmp2.exe
2015-03-11 23:47 - 2014-10-29 02:06 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2015-03-11 23:47 - 2014-10-29 02:06 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2015-03-11 23:47 - 2014-10-29 02:05 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2015-03-11 23:47 - 2014-10-29 02:05 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\loadperf.dll
2015-03-11 23:47 - 2014-10-29 02:05 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samcli.dll
2015-03-11 23:47 - 2014-10-29 02:04 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\net1.exe
2015-03-11 23:47 - 2014-10-29 02:04 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mi.dll
2015-03-11 23:47 - 2014-10-29 02:04 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallButtons.dll
2015-03-11 23:47 - 2014-10-29 02:04 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uexfat.dll
2015-03-11 23:47 - 2014-10-29 02:04 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntlanman.dll
2015-03-11 23:47 - 2014-10-29 02:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncobjapi.dll
2015-03-11 23:47 - 2014-10-29 02:04 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xcopy.exe
2015-03-11 23:47 - 2014-10-29 02:03 - 00968192 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll
2015-03-11 23:47 - 2014-10-29 02:03 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mimofcodec.dll
2015-03-11 23:47 - 2014-10-29 02:03 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2015-03-11 23:47 - 2014-10-29 02:02 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Winlangdb.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\korwbrkr.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Compression.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdi.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vaultcli.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Sockets.PushEnabledApplication.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll
2015-03-11 23:47 - 2014-10-29 02:00 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ELSCore.dll
2015-03-11 23:47 - 2014-10-29 01:59 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidcom.dll
2015-03-11 23:47 - 2014-10-29 01:59 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2015-03-11 23:47 - 2014-10-29 01:59 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2015-03-11 23:47 - 2014-10-29 01:59 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2015-03-11 23:47 - 2014-10-29 01:59 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\colbact.dll
2015-03-11 23:47 - 2014-10-29 01:58 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10_1.dll
2015-03-11 23:47 - 2014-10-29 01:58 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2015-03-11 23:47 - 2014-10-29 01:57 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2015-03-11 23:47 - 2014-10-29 01:57 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidfdp.dll
2015-03-11 23:47 - 2014-10-29 01:57 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2015-03-11 23:47 - 2014-10-29 01:57 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2015-03-11 23:47 - 2014-10-29 01:57 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmifw.dll
2015-03-11 23:47 - 2014-10-29 01:56 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2015-03-11 23:47 - 2014-10-29 01:56 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstask.dll
2015-03-11 23:47 - 2014-10-29 01:56 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2015-03-11 23:47 - 2014-10-29 01:56 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll
2015-03-11 23:47 - 2014-10-29 01:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDSAppXHelper.dll
2015-03-11 23:47 - 2014-10-29 01:56 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AepRoam.dll
2015-03-11 23:47 - 2014-10-29 01:55 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-03-11 23:47 - 2014-10-29 01:55 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsAuth.dll
2015-03-11 23:47 - 2014-10-29 01:55 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
2015-03-11 23:47 - 2014-10-29 01:54 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-03-11 23:47 - 2014-10-29 01:54 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2015-03-11 23:47 - 2014-10-29 01:53 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2015-03-11 23:47 - 2014-10-29 01:53 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2015-03-11 23:47 - 2014-10-29 01:51 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
2015-03-11 23:47 - 2014-10-29 01:51 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
2015-03-11 23:47 - 2014-10-29 01:51 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceElementSource.dll
2015-03-11 23:47 - 2014-10-29 01:51 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2015-03-11 23:47 - 2014-10-29 01:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2015-03-11 23:47 - 2014-10-29 01:50 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eqossnap.dll
2015-03-11 23:47 - 2014-10-29 01:49 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2015-03-11 23:47 - 2014-10-29 01:48 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowslivelogin.dll
2015-03-11 23:47 - 2014-10-29 01:47 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2015-03-11 23:47 - 2014-10-29 01:46 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2015-03-11 23:47 - 2014-10-29 01:46 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.dll
2015-03-11 23:47 - 2014-10-29 01:46 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmshell.dll
2015-03-11 23:47 - 2014-10-29 01:46 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2015-03-11 23:47 - 2014-10-29 01:46 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
2015-03-11 23:47 - 2014-10-29 01:45 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndfapi.dll
2015-03-11 23:47 - 2014-10-29 01:45 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2015-03-11 23:47 - 2014-10-29 01:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2015-03-11 23:47 - 2014-10-29 01:44 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll
2015-03-11 23:47 - 2014-10-29 01:44 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdeploy.dll
2015-03-11 23:47 - 2014-10-29 01:44 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adrclient.dll
2015-03-11 23:47 - 2014-10-29 01:43 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2015-03-11 23:47 - 2014-10-29 01:43 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll
2015-03-11 23:47 - 2014-10-29 01:43 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-03-11 23:47 - 2014-10-29 01:42 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2015-03-11 23:47 - 2014-10-29 01:41 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl
2015-03-11 23:47 - 2014-10-29 01:40 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2015-03-11 23:47 - 2014-10-29 01:37 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2015-03-11 23:47 - 2014-10-29 01:34 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2015-03-11 23:47 - 2014-10-29 01:30 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2015-03-11 23:47 - 2014-10-15 09:32 - 00088896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2015-03-11 23:47 - 2014-10-12 09:53 - 00054592 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdusb.dll
2015-03-11 23:47 - 2014-08-08 17:55 - 00172344 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2015-03-11 23:46 - 2014-10-29 05:11 - 00038792 _____ (Microsoft Corporation) C:\WINDOWS\system32\svchost.exe
2015-03-11 23:46 - 2014-10-29 05:09 - 00277368 _____ (Microsoft Corporation) C:\WINDOWS\system32\powrprof.dll
2015-03-11 23:46 - 2014-10-29 05:09 - 00044912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2015-03-11 23:46 - 2014-10-29 05:09 - 00040256 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmbeddedAppLauncherConfig.dll
2015-03-11 23:46 - 2014-10-29 05:04 - 00149240 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2015-03-11 23:46 - 2014-10-29 05:04 - 00131648 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2015-03-11 23:46 - 2014-10-29 05:04 - 00124992 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptxml.dll
2015-03-11 23:46 - 2014-10-29 05:04 - 00086744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2015-03-11 23:46 - 2014-10-29 05:04 - 00080056 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2015-03-11 23:46 - 2014-10-29 05:04 - 00044368 _____ (Microsoft Corporation) C:\WINDOWS\system32\netutils.dll
2015-03-11 23:46 - 2014-10-29 04:57 - 00045464 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe
2015-03-11 23:46 - 2014-10-29 04:57 - 00038736 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialUIBroker.exe
2015-03-11 23:46 - 2014-10-29 04:57 - 00035664 _____ (Microsoft Corporation) C:\WINDOWS\system32\avrt.dll
2015-03-11 23:46 - 2014-10-29 04:57 - 00031968 _____ (Microsoft Corporation) C:\WINDOWS\system32\PasswordOnWakeSettingFlyout.exe
2015-03-11 23:46 - 2014-10-29 04:56 - 00089368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2015-03-11 23:46 - 2014-10-29 04:55 - 00067656 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcRtRemote.dll
2015-03-11 23:46 - 2014-10-29 04:55 - 00064040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wtsapi32.dll
2015-03-11 23:46 - 2014-10-29 04:52 - 00029408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-03-11 23:46 - 2014-10-29 04:52 - 00022208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksuser.dll
2015-03-11 23:46 - 2014-10-29 04:51 - 00047024 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2015-03-11 23:46 - 2014-10-29 04:17 - 00033088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\svchost.exe
2015-03-11 23:46 - 2014-10-29 04:15 - 00110512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2015-03-11 23:46 - 2014-10-29 04:15 - 00074352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdll.dll
2015-03-11 23:46 - 2014-10-29 04:15 - 00068168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2015-03-11 23:46 - 2014-10-29 04:15 - 00064552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2015-03-11 23:46 - 2014-10-29 04:15 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2015-03-11 23:46 - 2014-10-29 04:15 - 00035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netutils.dll
2015-03-11 23:46 - 2014-10-29 04:15 - 00021696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsrole.dll
2015-03-11 23:46 - 2014-10-29 04:12 - 00051096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2015-03-11 23:46 - 2014-10-29 04:11 - 00150776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpps.dll
2015-03-11 23:46 - 2014-10-29 04:11 - 00031496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\avrt.dll
2015-03-11 23:46 - 2014-10-29 04:11 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraSettingsUIHost.exe
2015-03-11 23:46 - 2014-10-29 04:10 - 00052664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wtsapi32.dll
2015-03-11 23:46 - 2014-10-29 04:10 - 00052664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RpcRtRemote.dll
2015-03-11 23:46 - 2014-10-29 04:10 - 00040816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2015-03-11 23:46 - 2014-10-29 04:10 - 00038184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\utildll.dll
2015-03-11 23:46 - 2014-10-29 04:10 - 00034016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialUIBroker.exe
2015-03-11 23:46 - 2014-10-29 04:10 - 00030944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountBroker.exe
2015-03-11 23:46 - 2014-10-29 04:10 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PasswordOnWakeSettingFlyout.exe
2015-03-11 23:46 - 2014-10-29 04:10 - 00026304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\version.dll
2015-03-11 23:46 - 2014-10-29 04:10 - 00026304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PickerHost.exe
2015-03-11 23:46 - 2014-10-29 04:07 - 00039720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdmo.dll
2015-03-11 23:46 - 2014-10-29 04:07 - 00029960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imaadp32.acm
2015-03-11 23:46 - 2014-10-29 04:07 - 00028896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msadp32.acm
2015-03-11 23:46 - 2014-10-29 04:06 - 00080016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-03-11 23:46 - 2014-10-29 04:05 - 00052152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll
2015-03-11 23:46 - 2014-10-29 03:49 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcirt.dll
2015-03-11 23:46 - 2014-10-29 03:47 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\drmk.sys
2015-03-11 23:46 - 2014-10-29 03:46 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2015-03-11 23:46 - 2014-10-29 03:45 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2015-03-11 23:46 - 2014-10-29 03:45 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncui.dll
2015-03-11 23:46 - 2014-10-29 03:45 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pacer.sys
2015-03-11 23:46 - 2014-10-29 03:45 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2015-03-11 23:46 - 2014-10-29 03:45 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\sfc_os.dll
2015-03-11 23:46 - 2014-10-29 03:45 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2015-03-11 23:46 - 2014-10-29 03:45 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2015-03-11 23:46 - 2014-10-29 03:44 - 02022912 _____ (Microsoft Corporation) C:\WINDOWS\system32\batmeter.dll
2015-03-11 23:46 - 2014-10-29 03:44 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdadiag.dll
2015-03-11 23:46 - 2014-10-29 03:44 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\spfileq.dll
2015-03-11 23:46 - 2014-10-29 03:44 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2015-03-11 23:46 - 2014-10-29 03:44 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\bderepair.dll
2015-03-11 23:46 - 2014-10-29 03:44 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\cnvfat.dll
2015-03-11 23:46 - 2014-10-29 03:43 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\radardt.dll
2015-03-11 23:46 - 2014-10-29 03:43 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2015-03-11 23:46 - 2014-10-29 03:42 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2015-03-11 23:46 - 2014-10-29 03:42 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmiv2.dll
2015-03-11 23:46 - 2014-10-29 03:42 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\makecab.exe
2015-03-11 23:46 - 2014-10-29 03:42 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NapiNSP.dll
2015-03-11 23:46 - 2014-10-29 03:42 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcbcp.dll
2015-03-11 23:46 - 2014-10-29 03:41 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dispdiag.exe
2015-03-11 23:46 - 2014-10-29 03:40 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2015-03-11 23:46 - 2014-10-29 03:37 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2015-03-11 23:46 - 2014-10-29 03:37 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelineprxy.dll
2015-03-11 23:46 - 2014-10-29 03:36 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
2015-03-11 23:46 - 2014-10-29 03:36 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcshext.dll
2015-03-11 23:46 - 2014-10-29 03:36 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2015-03-11 23:46 - 2014-10-29 03:36 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2015-03-11 23:46 - 2014-10-29 03:36 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlaySndSrv.dll
2015-03-11 23:46 - 2014-10-29 03:35 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertPolEng.dll
2015-03-11 23:46 - 2014-10-29 03:35 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-03-11 23:46 - 2014-10-29 03:35 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3dlg.dll
2015-03-11 23:46 - 2014-10-29 03:35 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToStatusProvider.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ocsetapi.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\secproc_ssp_isv.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\secproc_ssp.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxproxy.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmloader.dll
2015-03-11 23:46 - 2014-10-29 03:34 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistAD.dll
2015-03-11 23:46 - 2014-10-29 03:33 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsdmo.dll
2015-03-11 23:46 - 2014-10-29 03:33 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvfw32.dll
2015-03-11 23:46 - 2014-10-29 03:33 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmsynth.dll
2015-03-11 23:46 - 2014-10-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhevents.dll
2015-03-11 23:46 - 2014-10-29 03:33 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2015-03-11 23:46 - 2014-10-29 03:33 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsRdpWebAccess.dll
2015-03-11 23:46 - 2014-10-29 03:32 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdiagschd.dll
2015-03-11 23:46 - 2014-10-29 03:32 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDisplayStatusManager.dll
2015-03-11 23:46 - 2014-10-29 03:31 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\gacinstall.dll
2015-03-11 23:46 - 2014-10-29 03:31 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcleanup.dll
2015-03-11 23:46 - 2014-10-29 03:30 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Syncreg.dll
2015-03-11 23:46 - 2014-10-29 03:30 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuditPolicyGPInterop.dll
2015-03-11 23:46 - 2014-10-29 03:30 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwanRadioManager.dll
2015-03-11 23:46 - 2014-10-29 03:30 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciqtz32.dll
2015-03-11 23:46 - 2014-10-29 03:29 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanHC.dll
2015-03-11 23:46 - 2014-10-29 03:29 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdchange.exe
2015-03-11 23:46 - 2014-10-29 03:28 - 00177152 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\WINDOWS\system32\l3codecp.acm
2015-03-11 23:46 - 2014-10-29 03:28 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\gcdef.dll
2015-03-11 23:46 - 2014-10-29 03:28 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbccp32.dll
2015-03-11 23:46 - 2014-10-29 03:27 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\loghours.dll
2015-03-11 23:46 - 2014-10-29 03:27 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\vfwwdm32.dll
2015-03-11 23:46 - 2014-10-29 03:27 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsvd.dll
2015-03-11 23:46 - 2014-10-29 03:27 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssec.dll
2015-03-11 23:46 - 2014-10-29 03:26 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll
2015-03-11 23:46 - 2014-10-29 03:26 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\synceng.dll
2015-03-11 23:46 - 2014-10-29 03:26 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbui.dll
2015-03-11 23:46 - 2014-10-29 03:26 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbisurf.ax
2015-03-11 23:46 - 2014-10-29 03:25 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2015-03-11 23:46 - 2014-10-29 03:25 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\QCLIPROV.DLL
2015-03-11 23:46 - 2014-10-29 03:25 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.dll
2015-03-11 23:46 - 2014-10-29 03:25 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bidispl.dll
2015-03-11 23:46 - 2014-10-29 03:24 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2015-03-11 23:46 - 2014-10-29 03:23 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AtBroker.exe
2015-03-11 23:46 - 2014-10-29 03:21 - 01086464 _____ (Microsoft Corporation) C:\WINDOWS\system32\onexui.dll
2015-03-11 23:46 - 2014-10-29 03:21 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmictimeprovider.dll
2015-03-11 23:46 - 2014-10-29 03:20 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshipsec.dll
2015-03-11 23:46 - 2014-10-29 03:19 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mydocs.dll
2015-03-11 23:46 - 2014-10-29 03:19 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2015-03-11 23:46 - 2014-10-29 03:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ustprov.dll
2015-03-11 23:46 - 2014-10-29 03:18 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\isoburn.exe
2015-03-11 23:46 - 2014-10-29 03:18 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2015-03-11 23:46 - 2014-10-29 03:18 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\RegCtrl.dll
2015-03-11 23:46 - 2014-10-29 03:18 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncHost.exe
2015-03-11 23:46 - 2014-10-29 03:18 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ThumbnailExtractionHost.exe
2015-03-11 23:46 - 2014-10-29 03:17 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhmanagew.exe
2015-03-11 23:46 - 2014-10-29 03:17 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\logman.exe
2015-03-11 23:46 - 2014-10-29 03:17 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmstp.exe
2015-03-11 23:46 - 2014-10-29 03:17 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3hc.dll
2015-03-11 23:46 - 2014-10-29 03:17 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\DfsShlEx.dll
2015-03-11 23:46 - 2014-10-29 03:17 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2nacp.dll
2015-03-11 23:46 - 2014-10-29 03:17 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhtask.dll
2015-03-11 23:46 - 2014-10-29 03:17 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucmhc.dll
2015-03-11 23:46 - 2014-10-29 03:17 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\hcproviders.dll
2015-03-11 23:46 - 2014-10-29 03:17 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\tvratings.dll
2015-03-11 23:46 - 2014-10-29 03:16 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\cabview.dll
2015-03-11 23:46 - 2014-10-29 03:16 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwsso.dll
2015-03-11 23:46 - 2014-10-29 03:13 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SrpUxNativeSnapIn.dll
2015-03-11 23:46 - 2014-10-29 03:13 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PNPXAssoc.dll
2015-03-11 23:46 - 2014-10-29 03:13 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Query.dll
2015-03-11 23:46 - 2014-10-29 03:13 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2015-03-11 23:46 - 2014-10-29 03:13 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConnectedAccountState.dll
2015-03-11 23:46 - 2014-10-29 03:13 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetNetworkLocation.dll
2015-03-11 23:46 - 2014-10-29 03:12 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
2015-03-11 23:46 - 2014-10-29 03:12 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EhStorAPI.dll
2015-03-11 23:46 - 2014-10-29 03:12 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddptrace.dll
2015-03-11 23:46 - 2014-10-29 03:12 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\xwreg.dll
2015-03-11 23:46 - 2014-10-29 03:12 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddputils.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\McxDriv.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\profprov.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdiag.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\btpanui.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00053248 _____ () C:\WINDOWS\system32\BWContextHandler.dll
2015-03-11 23:46 - 2014-10-29 03:11 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\FdDevQuery.dll
2015-03-11 23:46 - 2014-10-29 03:10 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpclean.dll
2015-03-11 23:46 - 2014-10-29 03:10 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshext.dll
2015-03-11 23:46 - 2014-10-29 03:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsockhc.dll
2015-03-11 23:46 - 2014-10-29 03:10 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\frprov.dll
2015-03-11 23:46 - 2014-10-29 03:10 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountControlSettings.dll
2015-03-11 23:46 - 2014-10-29 03:09 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfrgui.exe
2015-03-11 23:46 - 2014-10-29 03:09 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2015-03-11 23:46 - 2014-10-29 03:09 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
2015-03-11 23:46 - 2014-10-29 03:09 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\remotesp.tsp
2015-03-11 23:46 - 2014-10-29 03:09 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
2015-03-11 23:46 - 2014-10-29 03:09 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeXmlParser.dll
2015-03-11 23:46 - 2014-10-29 03:09 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoveDeviceContextHandler.dll
2015-03-11 23:46 - 2014-10-29 03:08 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\acppage.dll
2015-03-11 23:46 - 2014-10-29 03:07 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\EhStorPwdMgr.dll
2015-03-11 23:46 - 2014-10-29 03:07 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\MaintenanceUI.dll
2015-03-11 23:46 - 2014-10-29 03:07 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mimefilt.dll
2015-03-11 23:46 - 2014-10-29 03:06 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\colorui.dll
2015-03-11 23:46 - 2014-10-29 03:06 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2015-03-11 23:46 - 2014-10-29 03:06 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhlisten.dll
2015-03-11 23:46 - 2014-10-29 03:06 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAConn.dll
2015-03-11 23:46 - 2014-10-29 03:05 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\credui.dll
2015-03-11 23:46 - 2014-10-29 03:05 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dsui.dll
2015-03-11 23:46 - 2014-10-29 03:05 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\getmac.exe
2015-03-11 23:46 - 2014-10-29 03:04 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\srrstr.dll
2015-03-11 23:46 - 2014-10-29 03:04 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaacmgr.exe
2015-03-11 23:46 - 2014-10-29 03:04 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\driverquery.exe
2015-03-11 23:46 - 2014-10-29 03:04 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2015-03-11 23:46 - 2014-10-29 03:04 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcirt.dll
2015-03-11 23:46 - 2014-10-29 03:04 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2015-03-11 23:46 - 2014-10-29 03:03 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\fsquirt.exe
2015-03-11 23:46 - 2014-10-29 03:03 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\system32\tasklist.exe
2015-03-11 23:46 - 2014-10-29 03:03 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-03-11 23:46 - 2014-10-29 03:02 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\signdrv.dll
2015-03-11 23:46 - 2014-10-29 03:02 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpSa.exe
2015-03-11 23:46 - 2014-10-29 03:01 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\irftp.exe
2015-03-11 23:46 - 2014-10-29 03:01 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOM.dll
2015-03-11 23:46 - 2014-10-29 03:01 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HelpPaneProxy.dll
2015-03-11 23:46 - 2014-10-29 03:00 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll
2015-03-11 23:46 - 2014-10-29 03:00 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spfileq.dll
2015-03-11 23:46 - 2014-10-29 03:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SortWindows6Compat.dll
2015-03-11 23:46 - 2014-10-29 03:00 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sfc_os.dll
2015-03-11 23:46 - 2014-10-29 03:00 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2015-03-11 23:46 - 2014-10-29 03:00 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2015-03-11 23:46 - 2014-10-29 02:59 - 02013696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\batmeter.dll
2015-03-11 23:46 - 2014-10-29 02:59 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-03-11 23:46 - 2014-10-29 02:59 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciavi32.dll
2015-03-11 23:46 - 2014-10-29 02:59 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-03-11 23:46 - 2014-10-29 02:59 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cnvfat.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmiv2.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00085504 _____ (Radius Inc.) C:\WINDOWS\SysWOW64\iccvid.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\makecab.exe
2015-03-11 23:46 - 2014-10-29 02:58 - 00069120 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\WINDOWS\SysWOW64\l3codeca.acm
2015-03-11 23:46 - 2014-10-29 02:58 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdmat.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xmlfilter.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NapiNSP.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2015-03-11 23:46 - 2014-10-29 02:58 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rrinstaller.exe
2015-03-11 23:46 - 2014-10-29 02:57 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmInit.exe
2015-03-11 23:46 - 2014-10-29 02:57 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\recovery.dll
2015-03-11 23:46 - 2014-10-29 02:57 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regapi.dll
2015-03-11 23:46 - 2014-10-29 02:57 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cliconfg.dll
2015-03-11 23:46 - 2014-10-29 02:57 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tlscsp.dll
2015-03-11 23:46 - 2014-10-29 02:56 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\netid.dll
2015-03-11 23:46 - 2014-10-29 02:56 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvinst.exe
2015-03-11 23:46 - 2014-10-29 02:56 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2015-03-11 23:46 - 2014-10-29 02:55 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcwutl.dll
2015-03-11 23:46 - 2014-10-29 02:54 - 00244224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
2015-03-11 23:46 - 2014-10-29 02:54 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSUTILITY.dll
2015-03-11 23:46 - 2014-10-29 02:54 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcshext.dll
2015-03-11 23:46 - 2014-10-29 02:54 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2015-03-11 23:46 - 2014-10-29 02:54 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2015-03-11 23:46 - 2014-10-29 02:54 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\avicap32.dll
2015-03-11 23:46 - 2014-10-29 02:53 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2015-03-11 23:46 - 2014-10-29 02:53 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fsutil.exe
2015-03-11 23:46 - 2014-10-29 02:53 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\traffic.dll
2015-03-11 23:46 - 2014-10-29 02:52 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitagent.exe
2015-03-11 23:46 - 2014-10-29 02:52 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSROUTE.dll
2015-03-11 23:46 - 2014-10-29 02:52 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-03-11 23:46 - 2014-10-29 02:52 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3dlg.dll
2015-03-11 23:46 - 2014-10-29 02:52 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdhui.dll
2015-03-11 23:46 - 2014-10-29 02:52 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToStatusProvider.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usbceip.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olecli32.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasdatastore.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dxof.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprovisionsp.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\takeown.exe
2015-03-11 23:46 - 2014-10-29 02:51 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msports.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmloader.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthExt.dll
2015-03-11 23:46 - 2014-10-29 02:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmband.dll
2015-03-11 23:46 - 2014-10-29 02:50 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-03-11 23:46 - 2014-10-29 02:50 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmsynth.dll
2015-03-11 23:46 - 2014-10-29 02:50 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\g711codc.ax
2015-03-11 23:46 - 2014-10-29 02:50 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsRdpWebAccess.dll
2015-03-11 23:46 - 2014-10-29 02:49 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-03-11 23:46 - 2014-10-29 02:49 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciqtz32.dll
2015-03-11 23:46 - 2014-10-29 02:49 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceDisplayStatusManager.dll
2015-03-11 23:46 - 2014-10-29 02:48 - 00466944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\main.cpl
2015-03-11 23:46 - 2014-10-29 02:48 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcaSvc.dll
2015-03-11 23:46 - 2014-10-29 02:48 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\whoami.exe
2015-03-11 23:46 - 2014-10-29 02:48 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuditPolicyGPInterop.dll
2015-03-11 23:46 - 2014-10-29 02:48 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmdl32.exe
2015-03-11 23:46 - 2014-10-29 02:47 - 00186368 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\WINDOWS\SysWOW64\l3codecp.acm
2015-03-11 23:46 - 2014-10-29 02:47 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\charmap.exe
2015-03-11 23:46 - 2014-10-29 02:47 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gcdef.dll
2015-03-11 23:46 - 2014-10-29 02:47 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bootcfg.exe
2015-03-11 23:46 - 2014-10-29 02:47 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\console.dll
2015-03-11 23:46 - 2014-10-29 02:47 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\openfiles.exe
2015-03-11 23:46 - 2014-10-29 02:46 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\loghours.dll
2015-03-11 23:46 - 2014-10-29 02:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll
2015-03-11 23:46 - 2014-10-29 02:46 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasads.dll
2015-03-11 23:46 - 2014-10-29 02:46 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vfwwdm32.dll
2015-03-11 23:46 - 2014-10-29 02:46 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dssec.dll
2015-03-11 23:46 - 2014-10-29 02:45 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iashlpr.dll
2015-03-11 23:46 - 2014-10-29 02:45 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QUTIL.DLL
2015-03-11 23:46 - 2014-10-29 02:45 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\synceng.dll
2015-03-11 23:46 - 2014-10-29 02:45 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usbui.dll
2015-03-11 23:46 - 2014-10-29 02:45 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.dll
2015-03-11 23:46 - 2014-10-29 02:45 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbisurf.ax
2015-03-11 23:46 - 2014-10-29 02:45 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bidispl.dll
2015-03-11 23:46 - 2014-10-29 02:44 - 01152000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2015-03-11 23:46 - 2014-10-29 02:44 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2015-03-11 23:46 - 2014-10-29 02:44 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QCLIPROV.DLL
2015-03-11 23:46 - 2014-10-29 02:44 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3cfg.dll
2015-03-11 23:46 - 2014-10-29 02:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scripto.dll
2015-03-11 23:46 - 2014-10-29 02:43 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngprovider.dll
2015-03-11 23:46 - 2014-10-29 02:43 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capiprovider.dll
2015-03-11 23:46 - 2014-10-29 02:43 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2015-03-11 23:46 - 2014-10-29 02:43 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredprovider.dll
2015-03-11 23:46 - 2014-10-29 02:42 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wusa.exe
2015-03-11 23:46 - 2014-10-29 02:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2015-03-11 23:46 - 2014-10-29 02:42 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Groupinghc.dll
2015-03-11 23:46 - 2014-10-29 02:42 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Storprop.dll
2015-03-11 23:46 - 2014-10-29 02:42 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpapiprovider.dll
2015-03-11 23:46 - 2014-10-29 02:41 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\onexui.dll
2015-03-11 23:46 - 2014-10-29 02:40 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxlib.dll
2015-03-11 23:46 - 2014-10-29 02:40 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhsetup.dll
2015-03-11 23:46 - 2014-10-29 02:40 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\docprop.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mydocs.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\isoburn.exe
2015-03-11 23:46 - 2014-10-29 02:39 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TapiMigPlugin.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ustprov.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RegCtrl.dll
2015-03-11 23:46 - 2014-10-29 02:39 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncHost.exe
2015-03-11 23:46 - 2014-10-29 02:38 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hdwwiz.cpl
2015-03-11 23:46 - 2014-10-29 02:38 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsadu.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndfhcdiscovery.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DfsShlEx.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\l2nacp.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3hc.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msident.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\playlistfolder.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucmhc.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hcproviders.dll
2015-03-11 23:46 - 2014-10-29 02:38 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndfetw.dll
2015-03-11 23:46 - 2014-10-29 02:37 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SrpUxNativeSnapIn.dll
2015-03-11 23:46 - 2014-10-29 02:37 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cabview.dll
2015-03-11 23:46 - 2014-10-29 02:35 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfmon.exe
2015-03-11 23:46 - 2014-10-29 02:35 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xwreg.dll
2015-03-11 23:46 - 2014-10-29 02:35 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Query.dll
2015-03-11 23:46 - 2014-10-29 02:35 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WABSyncProvider.dll
2015-03-11 23:46 - 2014-10-29 02:35 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConnectedAccountState.dll
2015-03-11 23:46 - 2014-10-29 02:34 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shrpubw.exe
2015-03-11 23:46 - 2014-10-29 02:34 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdminst.dll
2015-03-11 23:46 - 2014-10-29 02:34 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EhStorAPI.dll
2015-03-11 23:46 - 2014-10-29 02:34 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptext.dll
2015-03-11 23:46 - 2014-10-29 02:34 - 00054272 _____ (Twain Working Group) C:\WINDOWS\twain_32.dll
2015-03-11 23:46 - 2014-10-29 02:34 - 00046080 _____ () C:\WINDOWS\SysWOW64\BWContextHandler.dll
2015-03-11 23:46 - 2014-10-29 02:34 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FdDevQuery.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uireng.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remotesp.tsp
2015-03-11 23:46 - 2014-10-29 02:33 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshext.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsockhc.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountControlSettings.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\btpanui.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\frprov.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdiag.dll
2015-03-11 23:46 - 2014-10-29 02:33 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpmonui.dll
2015-03-11 23:46 - 2014-10-29 02:32 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srclient.dll
2015-03-11 23:46 - 2014-10-29 02:32 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\acppage.dll
2015-03-11 23:46 - 2014-10-29 02:32 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoveDeviceContextHandler.dll
2015-03-11 23:46 - 2014-10-29 02:31 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2015-03-11 23:46 - 2014-10-29 02:31 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EhStorPwdMgr.dll
2015-03-11 23:46 - 2014-10-29 02:31 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mimefilt.dll
2015-03-11 23:46 - 2014-10-29 02:30 - 00605696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\colorui.dll
2015-03-11 23:46 - 2014-10-29 02:30 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2015-03-11 23:46 - 2014-10-29 02:30 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoplay.dll
2015-03-11 23:46 - 2014-10-29 02:30 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiascanprofiles.dll
2015-03-11 23:46 - 2014-10-29 02:30 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndishc.dll
2015-03-11 23:46 - 2014-10-29 02:29 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\keymgr.dll
2015-03-11 23:46 - 2014-10-29 02:29 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Dsui.dll
2015-03-11 23:46 - 2014-10-29 02:29 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaacmgr.exe
2015-03-11 23:46 - 2014-10-29 02:29 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Utilman.exe
2015-03-11 23:46 - 2014-10-29 02:29 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\driverquery.exe
2015-03-11 23:46 - 2014-10-29 02:29 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\getmac.exe
2015-03-11 23:46 - 2014-10-29 02:29 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpapi.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcEpMap.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2015-03-11 23:46 - 2014-10-29 02:28 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\vidcap.ax
2015-03-11 23:46 - 2014-10-29 02:28 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\hid.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\system32\elslad.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2015-03-11 23:46 - 2014-10-29 02:27 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\regsvc.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mi.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOM.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntlanman.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\net.exe
2015-03-11 23:46 - 2014-10-29 02:27 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2015-03-11 23:46 - 2014-10-29 02:27 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HelpPaneProxy.dll
2015-03-11 23:46 - 2014-10-29 02:27 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\signdrv.dll
2015-03-11 23:46 - 2014-10-29 02:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\net1.exe
2015-03-11 23:46 - 2014-10-29 02:26 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdsapi.dll
2015-03-11 23:46 - 2014-10-29 02:26 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EhStorAuthn.exe
2015-03-11 23:46 - 2014-10-29 02:26 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\racpldlg.dll
2015-03-11 23:46 - 2014-10-29 02:26 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2015-03-11 23:46 - 2014-10-29 02:26 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.Fontgroups.dll
2015-03-11 23:46 - 2014-10-29 02:26 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2015-03-11 23:46 - 2014-10-29 02:26 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\fmifs.dll
2015-03-11 23:46 - 2014-10-29 02:25 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2015-03-11 23:46 - 2014-10-29 02:25 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevDispItemProvider.dll
2015-03-11 23:46 - 2014-10-29 02:25 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2015-03-11 23:46 - 2014-10-29 02:25 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xmlfilter.dll
2015-03-11 23:46 - 2014-10-29 02:25 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\networkitemfactory.dll
2015-03-11 23:46 - 2014-10-29 02:25 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rrinstaller.exe
2015-03-11 23:46 - 2014-10-29 02:24 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2015-03-11 23:46 - 2014-10-29 02:24 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguageProfileCallback.dll
2015-03-11 23:46 - 2014-10-29 02:23 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2015-03-11 23:46 - 2014-10-29 02:23 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netid.dll
2015-03-11 23:46 - 2014-10-29 02:22 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlgpclnt.dll
2015-03-11 23:46 - 2014-10-29 02:22 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2015-03-11 23:46 - 2014-10-29 02:22 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcss.dll
2015-03-11 23:46 - 2014-10-29 02:22 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\keyiso.dll
2015-03-11 23:46 - 2014-10-29 02:21 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\luainstall.dll
2015-03-11 23:46 - 2014-10-29 02:21 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Portable.dll
2015-03-11 23:46 - 2014-10-29 02:21 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.Extensions.dll
2015-03-11 23:46 - 2014-10-29 02:20 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\L2SecHC.dll
2015-03-11 23:46 - 2014-10-29 02:20 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll
2015-03-11 23:46 - 2014-10-29 02:20 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanRadioManager.dll
2015-03-11 23:46 - 2014-10-29 02:20 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimtf.dll
2015-03-11 23:46 - 2014-10-29 02:20 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthExt.dll
2015-03-11 23:46 - 2014-10-29 02:19 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2015-03-11 23:46 - 2014-10-29 02:19 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsstrace.dll
2015-03-11 23:46 - 2014-10-29 02:19 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\stclient.dll
2015-03-11 23:46 - 2014-10-29 02:19 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\pautoenr.dll
2015-03-11 23:46 - 2014-10-29 02:19 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmbmgr.dll
2015-03-11 23:46 - 2014-10-29 02:18 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-03-11 23:46 - 2014-10-29 02:18 - 00184832 _____ (Microsoft Corp.) C:\WINDOWS\system32\Defrag.exe
2015-03-11 23:46 - 2014-10-29 02:18 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbussdapi.dll
2015-03-11 23:46 - 2014-10-29 02:18 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RoamingSecurity.dll
2015-03-11 23:46 - 2014-10-29 02:17 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\onex.dll
2015-03-11 23:46 - 2014-10-29 02:17 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2015-03-11 23:46 - 2014-10-29 02:17 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpowmi.dll
2015-03-11 23:46 - 2014-10-29 02:16 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2015-03-11 23:46 - 2014-10-29 02:16 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pnrphc.dll
2015-03-11 23:46 - 2014-10-29 02:15 - 01129984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2015-03-11 23:46 - 2014-10-29 02:14 - 00344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\certCredProvider.dll
2015-03-11 23:46 - 2014-10-29 02:14 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2015-03-11 23:46 - 2014-10-29 02:14 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDSPnf.exe
2015-03-11 23:46 - 2014-10-29 02:14 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityServicePal.dll
2015-03-11 23:46 - 2014-10-29 02:13 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwcfg.dll
2015-03-11 23:46 - 2014-10-29 02:13 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\umb.dll
2015-03-11 23:46 - 2014-10-29 02:13 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdPnp.dll
2015-03-11 23:46 - 2014-10-29 02:12 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll
2015-03-11 23:46 - 2014-10-29 02:11 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHCPQEC.DLL
2015-03-11 23:46 - 2014-10-29 02:11 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsadu.dll
2015-03-11 23:46 - 2014-10-29 02:10 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\elslad.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrscmd.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hbaapi.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndiscapCfg.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2015-03-11 23:46 - 2014-10-29 02:05 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mskeyprotect.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2015-03-11 23:46 - 2014-10-29 02:05 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vidcap.ax
2015-03-11 23:46 - 2014-10-29 02:04 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdsapi.dll
2015-03-11 23:46 - 2014-10-29 02:04 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netsh.exe
2015-03-11 23:46 - 2014-10-29 02:04 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\eqossnap.dll
2015-03-11 23:46 - 2014-10-29 02:04 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nslookup.exe
2015-03-11 23:46 - 2014-10-29 02:04 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\auditpol.exe
2015-03-11 23:46 - 2014-10-29 02:04 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setx.exe
2015-03-11 23:46 - 2014-10-29 02:04 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\net.exe
2015-03-11 23:46 - 2014-10-29 02:04 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscapi.dll
2015-03-11 23:46 - 2014-10-29 02:04 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\format.com
2015-03-11 23:46 - 2014-10-29 02:03 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icm32.dll
2015-03-11 23:46 - 2014-10-29 02:03 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\w32tm.exe
2015-03-11 23:46 - 2014-10-29 02:03 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.exe
2015-03-11 23:46 - 2014-10-29 02:03 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wecapi.dll
2015-03-11 23:46 - 2014-10-29 02:03 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fmifs.dll
2015-03-11 23:46 - 2014-10-29 02:03 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
2015-03-11 23:46 - 2014-10-29 02:02 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2015-03-11 23:46 - 2014-10-29 02:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevDispItemProvider.dll
2015-03-11 23:46 - 2014-10-29 02:02 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wecutil.exe
2015-03-11 23:46 - 2014-10-29 02:02 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanext.exe
2015-03-11 23:46 - 2014-10-29 02:02 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2015-03-11 23:46 - 2014-10-29 02:01 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll
2015-03-11 23:46 - 2014-10-29 02:01 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlgpclnt.dll
2015-03-11 23:46 - 2014-10-29 02:01 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\keyiso.dll
2015-03-11 23:46 - 2014-10-29 02:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguageProfileCallback.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmtrace.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\threadpoolwinrt.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\luainstall.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddrawex.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Printers.Extensions.dll
2015-03-11 23:46 - 2014-10-29 02:00 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Portable.dll
2015-03-11 23:46 - 2014-10-29 01:59 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prvdmofcomp.dll
2015-03-11 23:46 - 2014-10-29 01:59 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pautoenr.dll
2015-03-11 23:46 - 2014-10-29 01:59 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stclient.dll
2015-03-11 23:46 - 2014-10-29 01:58 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingHost.exe
2015-03-11 23:46 - 2014-10-29 01:58 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EAPQEC.DLL
2015-03-11 23:46 - 2014-10-29 01:58 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbussdapi.dll
2015-03-11 23:46 - 2014-10-29 01:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\PSModuleDiscoveryProvider.dll
2015-03-11 23:46 - 2014-10-29 01:58 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimtf.dll
2015-03-11 23:46 - 2014-10-29 01:57 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\onex.dll
2015-03-11 23:46 - 2014-10-29 01:57 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-03-11 23:46 - 2014-10-29 01:57 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dataclen.dll
2015-03-11 23:46 - 2014-10-29 01:56 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwcfg.dll
2015-03-11 23:46 - 2014-10-29 01:56 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
2015-03-11 23:46 - 2014-10-29 01:55 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2015-03-11 23:46 - 2014-10-29 01:55 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdPnp.dll
2015-03-11 23:46 - 2014-10-29 01:54 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-03-11 23:46 - 2014-10-29 01:54 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WfHC.dll
2015-03-11 23:46 - 2014-10-29 01:54 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DHCPQEC.DLL
2015-03-11 23:46 - 2014-10-29 01:54 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll
2015-03-11 23:46 - 2014-10-29 01:51 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrscmd.dll
2015-03-11 23:46 - 2014-10-29 01:50 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Renewal.dll
2015-03-11 23:46 - 2014-10-29 01:46 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidfdp.dll
2015-03-11 23:46 - 2014-10-29 01:46 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingHost.exe
2015-03-11 23:46 - 2014-10-29 01:45 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dataclen.dll
2015-03-11 23:46 - 2014-10-29 01:43 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WfHC.dll
2015-03-11 23:46 - 2014-10-29 01:43 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2015-03-11 23:46 - 2014-10-29 01:35 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2015-03-11 23:46 - 2014-10-15 09:32 - 00921920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2015-03-11 23:46 - 2014-10-15 09:32 - 00061248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2015-03-11 23:46 - 2014-10-07 07:54 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-03-11 23:46 - 2014-10-07 07:44 - 00102208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-03-11 23:45 - 2014-10-29 05:13 - 00021824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tbs.sys
2015-03-11 23:45 - 2014-10-29 05:09 - 00108864 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootsect.exe
2015-03-11 23:45 - 2014-10-29 05:09 - 00041280 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeyboardFilterCore.dll
2015-03-11 23:45 - 2014-10-29 05:09 - 00033600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-03-11 23:45 - 2014-10-29 05:09 - 00033088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2015-03-11 23:45 - 2014-10-29 05:09 - 00033064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll
2015-03-11 23:45 - 2014-10-29 05:09 - 00028480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2015-03-11 23:45 - 2014-10-29 05:04 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2015-03-11 23:45 - 2014-10-29 05:04 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlrmdr.exe
2015-03-11 23:45 - 2014-10-29 05:04 - 00025352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsrole.dll
2015-03-11 23:45 - 2014-10-29 04:59 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2015-03-11 23:45 - 2014-10-29 04:59 - 00025920 _____ (Microsoft Corporation) C:\WINDOWS\system32\streamci.dll
2015-03-11 23:45 - 2014-10-29 04:57 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-03-11 23:45 - 2014-10-29 04:57 - 00029960 _____ (Microsoft Corporation) C:\WINDOWS\system32\version.dll
2015-03-11 23:45 - 2014-10-29 04:57 - 00027872 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2015-03-11 23:45 - 2014-10-29 04:56 - 00097048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2015-03-11 23:45 - 2014-10-29 04:56 - 00061208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhv.sys
2015-03-11 23:45 - 2014-10-29 04:56 - 00049944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys
2015-03-11 23:45 - 2014-10-29 04:55 - 00043888 _____ (Microsoft Corporation) C:\WINDOWS\system32\utildll.dll
2015-03-11 23:45 - 2014-10-29 04:55 - 00033576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuntimeBroker.exe
2015-03-11 23:45 - 2014-10-29 04:53 - 00095048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-03-11 23:45 - 2014-10-29 04:52 - 00043888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdmo.dll
2015-03-11 23:45 - 2014-10-29 04:52 - 00041880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msgsm32.acm
2015-03-11 23:45 - 2014-10-29 04:52 - 00035664 _____ (Microsoft Corporation) C:\WINDOWS\system32\imaadp32.acm
2015-03-11 23:45 - 2014-10-29 04:52 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msadp32.acm
2015-03-11 23:45 - 2014-10-29 04:52 - 00025312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msg711.acm
2015-03-11 23:45 - 2014-10-29 04:51 - 00033032 _____ (Microsoft Corporation) C:\WINDOWS\system32\winnsi.dll
2015-03-11 23:45 - 2014-10-29 04:51 - 00031528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptbase.dll
2015-03-11 23:45 - 2014-10-29 04:51 - 00024800 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsi.dll
2015-03-11 23:45 - 2014-10-29 04:18 - 00034112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KeyboardFilterCore.dll
2015-03-11 23:45 - 2014-10-29 04:18 - 00029920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll
2015-03-11 23:45 - 2014-10-29 04:07 - 00036136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msgsm32.acm
2015-03-11 23:45 - 2014-10-29 04:07 - 00026816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-03-11 23:45 - 2014-10-29 04:07 - 00022720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msg711.acm
2015-03-11 23:45 - 2014-10-29 04:05 - 00030984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptbase.dll
2015-03-11 23:45 - 2014-10-29 04:05 - 00026304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winnsi.dll
2015-03-11 23:45 - 2014-10-29 04:05 - 00020120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nsi.dll
2015-03-11 23:45 - 2014-10-29 03:49 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-03-11 23:45 - 2014-10-29 03:48 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-03-11 23:45 - 2014-10-29 03:48 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-03-11 23:45 - 2014-10-29 03:48 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
2015-03-11 23:45 - 2014-10-29 03:48 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\lmhsvc.dll
2015-03-11 23:45 - 2014-10-29 03:48 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll
2015-03-11 23:45 - 2014-10-29 03:46 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nsiproxy.sys
2015-03-11 23:45 - 2014-10-29 03:45 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NdisImPlatform.sys
2015-03-11 23:45 - 2014-10-29 03:45 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2015-03-11 23:45 - 2014-10-29 03:45 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2015-03-11 23:45 - 2014-10-29 03:45 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\shgina.dll
2015-03-11 23:45 - 2014-10-29 03:45 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiatrace.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds_ps.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciavi32.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\efslsaext.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\feclient.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmocx.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsutil.dll
2015-03-11 23:45 - 2014-10-29 03:44 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmpbk32.dll
2015-03-11 23:45 - 2014-10-29 03:43 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\repair-bde.exe
2015-03-11 23:45 - 2014-10-29 03:43 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\kmddsp.tsp
2015-03-11 23:45 - 2014-10-29 03:43 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mode.com
2015-03-11 23:45 - 2014-10-29 03:43 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ureg.dll
2015-03-11 23:45 - 2014-10-29 03:43 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\comp.exe
2015-03-11 23:45 - 2014-10-29 03:43 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fc.exe
2015-03-11 23:45 - 2014-10-29 03:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\replace.exe
2015-03-11 23:45 - 2014-10-29 03:43 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\tree.com
2015-03-11 23:45 - 2014-10-29 03:42 - 00082432 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\WINDOWS\system32\l3codeca.acm
2015-03-11 23:45 - 2014-10-29 03:42 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdmat.dll
2015-03-11 23:45 - 2014-10-29 03:42 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\drttransport.dll
2015-03-11 23:45 - 2014-10-29 03:42 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcicda.dll
2015-03-11 23:45 - 2014-10-29 03:42 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmmon32.exe
2015-03-11 23:45 - 2014-10-29 03:42 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2015-03-11 23:45 - 2014-10-29 03:42 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\convert.exe
2015-03-11 23:45 - 2014-10-29 03:42 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\chkntfs.exe
2015-03-11 23:45 - 2014-10-29 03:42 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\IconCodecService.dll
2015-03-11 23:45 - 2014-10-29 03:41 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\regapi.dll
2015-03-11 23:45 - 2014-10-29 03:41 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\expand.exe
2015-03-11 23:45 - 2014-10-29 03:41 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll
2015-03-11 23:45 - 2014-10-29 03:41 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidphone.tsp
2015-03-11 23:45 - 2014-10-29 03:41 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\serwvdrv.dll
2015-03-11 23:45 - 2014-10-29 03:41 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\xmlprovi.dll
2015-03-11 23:45 - 2014-10-29 03:40 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\djoin.exe
2015-03-11 23:45 - 2014-10-29 03:40 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\dimsroam.dll
2015-03-11 23:45 - 2014-10-29 03:40 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\linkinfo.dll
2015-03-11 23:45 - 2014-10-29 03:39 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2015-03-11 23:45 - 2014-10-29 03:39 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\easconsent.dll
2015-03-11 23:45 - 2014-10-29 03:38 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcln.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpsapi.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\avicap32.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\drtprov.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsiCofire.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxstrace.exe
2015-03-11 23:45 - 2014-10-29 03:37 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LldpNotify.dll
2015-03-11 23:45 - 2014-10-29 03:37 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msacm32.drv
2015-03-11 23:45 - 2014-10-29 03:36 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsidsc.dll
2015-03-11 23:45 - 2014-10-29 03:36 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnification.dll
2015-03-11 23:45 - 2014-10-29 03:36 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgrprxy.dll
2015-03-11 23:45 - 2014-10-29 03:36 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\traffic.dll
2015-03-11 23:45 - 2014-10-29 03:36 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzSqlExt.dll
2015-03-11 23:45 - 2014-10-29 03:36 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bridgeunattend.exe
2015-03-11 23:45 - 2014-10-29 03:36 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe
2015-03-11 23:45 - 2014-10-29 03:35 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\fsutil.exe
2015-03-11 23:45 - 2014-10-29 03:35 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpmib.dll
2015-03-11 23:45 - 2014-10-29 03:35 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscisvif.dll
2015-03-11 23:45 - 2014-10-29 03:34 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-03-11 23:45 - 2014-10-29 03:34 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiarpc.dll
2015-03-11 23:45 - 2014-10-29 03:34 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmutil.dll
2015-03-11 23:45 - 2014-10-29 03:34 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll
2015-03-11 23:45 - 2014-10-29 03:34 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\regsvr32.exe
2015-03-11 23:45 - 2014-10-29 03:33 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msports.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\cttunesvr.exe
2015-03-11 23:45 - 2014-10-29 03:33 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthpanapi.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxsstore.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MemoryDiagnostic.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dswave.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsldr.exe
2015-03-11 23:45 - 2014-10-29 03:33 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshcon.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetmon.dll
2015-03-11 23:45 - 2014-10-29 03:33 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pstask.dll
2015-03-11 23:45 - 2014-10-29 03:31 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-03-11 23:45 - 2014-10-29 03:31 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsCtfMonitor.dll
2015-03-11 23:45 - 2014-10-29 03:30 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\certenc.dll
2015-03-11 23:45 - 2014-10-29 03:30 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmdl32.exe
2015-03-11 23:45 - 2014-10-29 03:30 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll
2015-03-11 23:45 - 2014-10-29 03:30 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\RotMgr.dll
2015-03-11 23:45 - 2014-10-29 03:30 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfdts.dll
2015-03-11 23:45 - 2014-10-29 03:30 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\sfc.exe
2015-03-11 23:45 - 2014-10-29 03:29 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\charmap.exe
2015-03-11 23:45 - 2014-10-29 03:29 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\whoami.exe
2015-03-11 23:45 - 2014-10-29 03:29 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddodiag.exe
2015-03-11 23:45 - 2014-10-29 03:29 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSTheme.exe
2015-03-11 23:45 - 2014-10-29 03:29 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapilua.dll
2015-03-11 23:45 - 2014-10-29 03:28 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll
2015-03-11 23:45 - 2014-10-29 03:27 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2015-03-11 23:45 - 2014-10-29 03:27 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompMgmtLauncher.exe


Oktavius 13.03.2015 16:40

Nr. 5 :-)

Code:

2015-03-11 23:45 - 2014-10-29 03:27 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2015-03-11 23:45 - 2014-10-29 03:27 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dtsh.dll
2015-03-11 23:45 - 2014-10-29 03:27 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dot3Conn.dll
2015-03-11 23:45 - 2014-10-29 03:26 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiexe.dll
2015-03-11 23:45 - 2014-10-29 03:26 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\cipher.exe
2015-03-11 23:45 - 2014-10-29 03:26 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfg.exe
2015-03-11 23:45 - 2014-10-29 03:26 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmiprop.dll
2015-03-11 23:45 - 2014-10-29 03:26 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\chkwudrv.dll
2015-03-11 23:45 - 2014-10-29 03:25 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
2015-03-11 23:45 - 2014-10-29 03:25 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfg.exe
2015-03-11 23:45 - 2014-10-29 03:25 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3cfg.dll
2015-03-11 23:45 - 2014-10-29 03:24 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2015-03-11 23:45 - 2014-10-29 03:24 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\xwizard.exe
2015-03-11 23:45 - 2014-10-29 03:24 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmcfg32.dll
2015-03-11 23:45 - 2014-10-29 03:24 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwlauncher.exe
2015-03-11 23:45 - 2014-10-29 03:23 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngprovider.dll
2015-03-11 23:45 - 2014-10-29 03:23 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\capiprovider.dll
2015-03-11 23:45 - 2014-10-29 03:23 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\adprovider.dll
2015-03-11 23:45 - 2014-10-29 03:23 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredprovider.dll
2015-03-11 23:45 - 2014-10-29 03:22 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2015-03-11 23:45 - 2014-10-29 03:22 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
2015-03-11 23:45 - 2014-10-29 03:22 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdmps.dll
2015-03-11 23:45 - 2014-10-29 03:22 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Storprop.dll
2015-03-11 23:45 - 2014-10-29 03:22 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapiprovider.dll
2015-03-11 23:45 - 2014-10-29 03:20 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\modemui.dll
2015-03-11 23:45 - 2014-10-29 03:20 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintIsolationHost.exe
2015-03-11 23:45 - 2014-10-29 03:20 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2015-03-11 23:45 - 2014-10-29 03:20 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\deskadp.dll
2015-03-11 23:45 - 2014-10-29 03:20 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\docprop.dll
2015-03-11 23:45 - 2014-10-29 03:19 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\joy.cpl
2015-03-11 23:45 - 2014-10-29 03:19 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2015-03-11 23:45 - 2014-10-29 03:19 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhautoplay.dll
2015-03-11 23:45 - 2014-10-29 03:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhsetup.dll
2015-03-11 23:45 - 2014-10-29 03:19 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
2015-03-11 23:45 - 2014-10-29 03:19 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\deskmon.dll
2015-03-11 23:45 - 2014-10-29 03:19 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdmlog.dll
2015-03-11 23:45 - 2014-10-29 03:19 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\prevhost.exe
2015-03-11 23:45 - 2014-10-29 03:18 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWGP.dll
2015-03-11 23:45 - 2014-10-29 03:18 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuditNativeSnapIn.dll
2015-03-11 23:45 - 2014-10-29 03:18 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\napdsnap.dll
2015-03-11 23:45 - 2014-10-29 03:18 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2015-03-11 23:45 - 2014-10-29 03:18 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2015-03-11 23:45 - 2014-10-29 03:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthMtpContextHandler.dll
2015-03-11 23:45 - 2014-10-29 03:18 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcdProp.dll
2015-03-11 23:45 - 2014-10-29 03:18 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DefaultPrinterProvider.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msident.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmlua.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcsPlugInService.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\runonce.exe
2015-03-11 23:45 - 2014-10-29 03:17 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\witnesswmiv2provider.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsepno.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsDeviceAccessRevocation.dll
2015-03-11 23:45 - 2014-10-29 03:17 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shpafact.dll
2015-03-11 23:45 - 2014-10-29 03:16 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\cleanmgr.exe
2015-03-11 23:45 - 2014-10-29 03:16 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprnext.dll
2015-03-11 23:45 - 2014-10-29 03:16 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2015-03-11 23:45 - 2014-10-29 03:16 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2015-03-11 23:45 - 2014-10-29 03:16 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWNet.dll
2015-03-11 23:45 - 2014-10-29 03:12 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\shrpubw.exe
2015-03-11 23:45 - 2014-10-29 03:12 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfmon.exe
2015-03-11 23:45 - 2014-10-29 03:11 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\uireng.dll
2015-03-11 23:45 - 2014-10-29 03:11 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2015-03-11 23:45 - 2014-10-29 03:11 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptext.dll
2015-03-11 23:45 - 2014-10-29 03:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
2015-03-11 23:45 - 2014-10-29 03:11 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistHttpTrans.dll
2015-03-11 23:45 - 2014-10-29 03:10 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpmonui.dll
2015-03-11 23:45 - 2014-10-29 03:10 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentHost.dll
2015-03-11 23:45 - 2014-10-29 03:09 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hotplug.dll
2015-03-11 23:45 - 2014-10-29 03:08 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti_ci.dll
2015-03-11 23:45 - 2014-10-29 03:08 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\DFDWiz.exe
2015-03-11 23:45 - 2014-10-29 03:08 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDriverRetrievalClient.dll
2015-03-11 23:45 - 2014-10-29 03:05 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\keymgr.dll
2015-03-11 23:45 - 2014-10-29 03:04 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\srhelper.dll
2015-03-11 23:45 - 2014-10-29 03:04 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDScanProxy.dll
2015-03-11 23:45 - 2014-10-29 03:04 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SrTasks.exe
2015-03-11 23:45 - 2014-10-29 03:03 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-03-11 23:45 - 2014-10-29 03:03 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetProxyCredential.dll
2015-03-11 23:45 - 2014-10-29 03:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\brdgcfg.dll
2015-03-11 23:45 - 2014-10-29 03:02 - 00423424 _____ (Microsoft Corporation) C:\WINDOWS\system32\irprops.cpl
2015-03-11 23:45 - 2014-10-29 03:02 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2015-03-11 23:45 - 2014-10-29 03:02 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXST30.dll
2015-03-11 23:45 - 2014-10-29 03:02 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinFax.dll
2015-03-11 23:45 - 2014-10-29 03:01 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptuiwizard.dll
2015-03-11 23:45 - 2014-10-29 03:01 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\EhStorAuthn.exe
2015-03-11 23:45 - 2014-10-29 03:00 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\uicom.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SortServer2003Compat.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\idndl.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shgina.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davhlpr.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmutil.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shimgvw.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shunimpl.dll
2015-03-11 23:45 - 2014-10-29 03:00 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netbios.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsnmp32.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vds_ps.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmocx.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regini.exe
2015-03-11 23:45 - 2014-10-29 02:59 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\feclient.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\htui.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpui.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtffilt.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfp.exe
2015-03-11 23:45 - 2014-10-29 02:59 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hidserv.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsutil.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmpbk32.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comp.exe
2015-03-11 23:45 - 2014-10-29 02:59 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fc.exe
2015-03-11 23:45 - 2014-10-29 02:59 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sisbkup.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mgmtapi.dll
2015-03-11 23:45 - 2014-10-29 02:59 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\replace.exe
2015-03-11 23:45 - 2014-10-29 02:59 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\doskey.exe
2015-03-11 23:45 - 2014-10-29 02:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\find.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00857088 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSST.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drttransport.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kmddsp.tsp
2015-03-11 23:45 - 2014-10-29 02:58 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcbcp.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcicda.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmmon32.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasmxs.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvidc32.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDShextAutoplay.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mode.com
2015-03-11 23:45 - 2014-10-29 02:58 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ureg.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netbtugc.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbnmpntw.dll
2015-03-11 23:45 - 2014-10-29 02:58 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chkntfs.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\convert.exe
2015-03-11 23:45 - 2014-10-29 02:58 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tree.com
2015-03-11 23:45 - 2014-10-29 02:58 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiltcfg.dll
2015-03-11 23:45 - 2014-10-29 02:57 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
2015-03-11 23:45 - 2014-10-29 02:57 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\expand.exe
2015-03-11 23:45 - 2014-10-29 02:57 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hidphone.tsp
2015-03-11 23:45 - 2014-10-29 02:57 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\syskey.exe
2015-03-11 23:45 - 2014-10-29 02:57 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdlg.dll
2015-03-11 23:45 - 2014-10-29 02:57 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2015-03-11 23:45 - 2014-10-29 02:57 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
2015-03-11 23:45 - 2014-10-29 02:57 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\serwvdrv.dll
2015-03-11 23:45 - 2014-10-29 02:57 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xmlprovi.dll
2015-03-11 23:45 - 2014-10-29 02:56 - 00107008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.ps.dll
2015-03-11 23:45 - 2014-10-29 02:56 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dimsroam.dll
2015-03-11 23:45 - 2014-10-29 02:56 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\linkinfo.dll
2015-03-11 23:45 - 2014-10-29 02:56 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icmui.dll
2015-03-11 23:45 - 2014-10-29 02:56 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capisp.dll
2015-03-11 23:45 - 2014-10-29 02:55 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcln.dll
2015-03-11 23:45 - 2014-10-29 02:55 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pid.dll
2015-03-11 23:45 - 2014-10-29 02:55 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxstrace.exe
2015-03-11 23:45 - 2014-10-29 02:54 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpsapi.dll
2015-03-11 23:45 - 2014-10-29 02:54 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2015-03-11 23:45 - 2014-10-29 02:54 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfp.dll
2015-03-11 23:45 - 2014-10-29 02:54 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintBrmUi.exe
2015-03-11 23:45 - 2014-10-29 02:54 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drtprov.dll
2015-03-11 23:45 - 2014-10-29 02:54 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsidsc.dll
2015-03-11 23:45 - 2014-10-29 02:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsauth.dll
2015-03-11 23:45 - 2014-10-29 02:54 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\extrac32.exe
2015-03-11 23:45 - 2014-10-29 02:54 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RpcPing.exe
2015-03-11 23:45 - 2014-10-29 02:54 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msacm32.drv
2015-03-11 23:45 - 2014-10-29 02:54 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-03-11 23:45 - 2014-10-29 02:53 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlaySndSrv.dll
2015-03-11 23:45 - 2014-10-29 02:53 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnification.dll
2015-03-11 23:45 - 2014-10-29 02:53 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcnsh.dll
2015-03-11 23:45 - 2014-10-29 02:53 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsium.dll
2015-03-11 23:45 - 2014-10-29 02:53 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzSqlExt.dll
2015-03-11 23:45 - 2014-10-29 02:53 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icsunattend.exe
2015-03-11 23:45 - 2014-10-29 02:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ocsetapi.dll
2015-03-11 23:45 - 2014-10-29 02:52 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmutil.dll
2015-03-11 23:45 - 2014-10-29 02:52 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxproxy.dll
2015-03-11 23:45 - 2014-10-29 02:52 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpmib.dll
2015-03-11 23:45 - 2014-10-29 02:52 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ias.dll
2015-03-11 23:45 - 2014-10-29 02:52 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscisvif.dll
2015-03-11 23:45 - 2014-10-29 02:52 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compact.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasphone.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdrleakdiag.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\where.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialer.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olesvr32.dll
2015-03-11 23:45 - 2014-10-29 02:51 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timeout.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clip.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dswave.dll
2015-03-11 23:45 - 2014-10-29 02:51 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshcon.dll
2015-03-11 23:45 - 2014-10-29 02:51 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
2015-03-11 23:45 - 2014-10-29 02:51 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winusb.dll
2015-03-11 23:45 - 2014-10-29 02:51 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorSvc.dll
2015-03-11 23:45 - 2014-10-29 02:51 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetmon.dll
2015-03-11 23:45 - 2014-10-29 02:50 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cttunesvr.exe
2015-03-11 23:45 - 2014-10-29 02:50 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxsstore.dll
2015-03-11 23:45 - 2014-10-29 02:50 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdiagnhost.exe
2015-03-11 23:45 - 2014-10-29 02:49 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
2015-03-11 23:45 - 2014-10-29 02:49 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PkgMgr.exe
2015-03-11 23:45 - 2014-10-29 02:49 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fsutilext.dll
2015-03-11 23:45 - 2014-10-29 02:49 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certenc.dll
2015-03-11 23:45 - 2014-10-29 02:49 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlaninst.dll
2015-03-11 23:45 - 2014-10-29 02:48 - 01497600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\diskcopy.dll
2015-03-11 23:45 - 2014-10-29 02:48 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsicli.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdchange.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\forfiles.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sfc.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eventcreate.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\waitfor.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\choice.exe
2015-03-11 23:45 - 2014-10-29 02:48 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsCtfMonitor.dll
2015-03-11 23:45 - 2014-10-29 02:48 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshelper.dll
2015-03-11 23:45 - 2014-10-29 02:47 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iaspolcy.dll
2015-03-11 23:45 - 2014-10-29 02:47 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSTheme.exe
2015-03-11 23:45 - 2014-10-29 02:47 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddodiag.exe
2015-03-11 23:45 - 2014-10-29 02:46 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2015-03-11 23:45 - 2014-10-29 02:46 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmci.dll
2015-03-11 23:45 - 2014-10-29 02:46 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtsh.dll
2015-03-11 23:45 - 2014-10-29 02:45 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cipher.exe
2015-03-11 23:45 - 2014-10-29 02:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\napipsec.dll
2015-03-11 23:45 - 2014-10-29 02:45 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmiprop.dll
2015-03-11 23:45 - 2014-10-29 02:44 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontview.exe
2015-03-11 23:45 - 2014-10-29 02:44 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmcfg32.dll
2015-03-11 23:45 - 2014-10-29 02:43 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2015-03-11 23:45 - 2014-10-29 02:43 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xwizard.exe
2015-03-11 23:45 - 2014-10-29 02:43 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adprovider.dll
2015-03-11 23:45 - 2014-10-29 02:43 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AtBroker.exe
2015-03-11 23:45 - 2014-10-29 02:42 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\radarrs.dll
2015-03-11 23:45 - 2014-10-29 02:40 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\joy.cpl
2015-03-11 23:45 - 2014-10-29 02:40 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rundll32.exe
2015-03-11 23:45 - 2014-10-29 02:40 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deskadp.dll
2015-03-11 23:45 - 2014-10-29 02:40 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdmlog.dll
2015-03-11 23:45 - 2014-10-29 02:40 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shutdown.exe
2015-03-11 23:45 - 2014-10-29 02:40 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\proquota.exe
2015-03-11 23:45 - 2014-10-29 02:39 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWGP.dll
2015-03-11 23:45 - 2014-10-29 02:39 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuditNativeSnapIn.dll
2015-03-11 23:45 - 2014-10-29 02:39 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\napdsnap.dll
2015-03-11 23:45 - 2014-10-29 02:39 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deskmon.dll
2015-03-11 23:45 - 2014-10-29 02:39 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2015-03-11 23:45 - 2014-10-29 02:39 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ThumbnailExtractionHost.exe
2015-03-11 23:45 - 2014-10-29 02:39 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dvdupgrd.exe
2015-03-11 23:45 - 2014-10-29 02:39 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NcdProp.dll
2015-03-11 23:45 - 2014-10-29 02:39 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DefaultPrinterProvider.dll
2015-03-11 23:45 - 2014-10-29 02:39 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prevhost.exe
2015-03-11 23:45 - 2014-10-29 02:38 - 00212480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cleanmgr.exe
2015-03-11 23:45 - 2014-10-29 02:38 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmlua.dll
2015-03-11 23:45 - 2014-10-29 02:38 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\runonce.exe
2015-03-11 23:45 - 2014-10-29 02:38 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcsPlugInService.dll
2015-03-11 23:45 - 2014-10-29 02:38 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tvratings.dll
2015-03-11 23:45 - 2014-10-29 02:38 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shpafact.dll
2015-03-11 23:45 - 2014-10-29 02:38 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmstplua.dll
2015-03-11 23:45 - 2014-10-29 02:37 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprnext.dll
2015-03-11 23:45 - 2014-10-29 02:37 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2015-03-11 23:45 - 2014-10-29 02:37 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2015-03-11 23:45 - 2014-10-29 02:36 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWNet.dll
2015-03-11 23:45 - 2014-10-29 02:34 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pwrshplugin.dll
2015-03-11 23:45 - 2014-10-29 02:32 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\unregmp2.exe
2015-03-11 23:45 - 2014-10-29 02:31 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credwiz.exe
2015-03-11 23:45 - 2014-10-29 02:30 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MuiUnattend.exe
2015-03-11 23:45 - 2014-10-29 02:29 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2015-03-11 23:45 - 2014-10-29 02:29 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\secur32.dll
2015-03-11 23:45 - 2014-10-29 02:29 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsisvc.dll
2015-03-11 23:45 - 2014-10-29 02:29 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileAppxStreamingDataSource.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2015-03-11 23:45 - 2014-10-29 02:28 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspatchc.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\hbaapi.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mskeyprotect.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\scext.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Websocket.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RdpSa.exe
2015-03-11 23:45 - 2014-10-29 02:28 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcsubs.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32topl.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbs.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinFax.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsperf.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.TimeBroker.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\attrib.exe
2015-03-11 23:45 - 2014-10-29 02:28 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshqos.dll
2015-03-11 23:45 - 2014-10-29 02:28 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\irprops.cpl
2015-03-11 23:45 - 2014-10-29 02:27 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\loadperf.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\netsh.exe
2015-03-11 23:45 - 2014-10-29 02:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\auditpol.exe
2015-03-11 23:45 - 2014-10-29 02:27 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscore.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfos.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\format.com
2015-03-11 23:45 - 2014-10-29 02:27 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.exe
2015-03-11 23:45 - 2014-10-29 02:27 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\findstr.exe
2015-03-11 23:45 - 2014-10-29 02:27 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\EventAggregation.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsparse.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\more.com
2015-03-11 23:45 - 2014-10-29 02:27 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysntfy.dll
2015-03-11 23:45 - 2014-10-29 02:27 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ARP.EXE
2015-03-11 23:45 - 2014-10-29 02:26 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\icm32.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpnsp.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.exe
2015-03-11 23:45 - 2014-10-29 02:26 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe
2015-03-11 23:45 - 2014-10-29 02:26 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidnsp.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSEXT32.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetEvtFwdr.exe
2015-03-11 23:45 - 2014-10-29 02:26 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MirrorDrvCompat.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypttpmeksvc.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uicom.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInput1_4.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapprovp.dll
2015-03-11 23:45 - 2014-10-29 02:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\chkdsk.exe
2015-03-11 23:45 - 2014-10-29 02:26 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shimgvw.dll
2015-03-11 23:45 - 2014-10-29 02:25 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipsec.dll
2015-03-11 23:45 - 2014-10-29 02:25 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtffilt.dll
2015-03-11 23:45 - 2014-10-29 02:25 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDShextAutoplay.exe
2015-03-11 23:45 - 2014-10-29 02:25 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2015-03-11 23:45 - 2014-10-29 02:25 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2015-03-11 23:45 - 2014-10-29 02:24 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanext.exe
2015-03-11 23:45 - 2014-10-29 02:24 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2015-03-11 23:45 - 2014-10-29 02:23 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.ps.dll
2015-03-11 23:45 - 2014-10-29 02:22 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngcredui.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdsrv.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfmifs.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
2015-03-11 23:45 - 2014-10-29 02:21 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\elsTrans.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Display.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.SystemManufacturers.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2015-03-11 23:45 - 2014-10-29 02:21 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.RemoteDesktop.dll
2015-03-11 23:45 - 2014-10-29 02:20 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2015-03-11 23:45 - 2014-10-29 02:20 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dimsjob.dll
2015-03-11 23:45 - 2014-10-29 02:20 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2015-03-11 23:45 - 2014-10-29 02:20 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommonPal.dll
2015-03-11 23:45 - 2014-10-29 02:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2015-03-11 23:45 - 2014-10-29 02:19 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxshared.dll
2015-03-11 23:45 - 2014-10-29 02:18 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2015-03-11 23:45 - 2014-10-29 02:18 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2015-03-11 23:45 - 2014-10-29 02:17 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WofTasks.dll
2015-03-11 23:45 - 2014-10-29 02:17 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-03-11 23:45 - 2014-10-29 02:16 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xolehlp.dll
2015-03-11 23:45 - 2014-10-29 02:15 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\FDResPub.dll
2015-03-11 23:45 - 2014-10-29 02:15 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrshost.exe
2015-03-11 23:45 - 2014-10-29 02:12 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtc.exe
2015-03-11 23:45 - 2014-10-29 02:06 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2015-03-11 23:45 - 2014-10-29 02:06 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmiclnt.dll
2015-03-11 23:45 - 2014-10-29 02:06 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\httpapi.dll
2015-03-11 23:45 - 2014-10-29 02:06 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secur32.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspatchc.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\reg.exe
2015-03-11 23:45 - 2014-10-29 02:05 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sc.exe
2015-03-11 23:45 - 2014-10-29 02:05 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lodctr.exe
2015-03-11 23:45 - 2014-10-29 02:05 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dfscli.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfproc.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspatcha.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfos.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Websocket.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfdisk.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icacls.exe
2015-03-11 23:45 - 2014-10-29 02:05 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\w32topl.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcsubs.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpapi.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hid.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbs.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\more.com
2015-03-11 23:45 - 2014-10-29 02:05 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userinit.exe
2015-03-11 23:45 - 2014-10-29 02:05 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsparse.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.TimeBroker.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsperf.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\attrib.exe
2015-03-11 23:45 - 2014-10-29 02:05 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mskeyprotcli.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fltLib.dll
2015-03-11 23:45 - 2014-10-29 02:05 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshqos.dll
2015-03-11 23:45 - 2014-10-29 02:04 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pnrpnsp.dll
2015-03-11 23:45 - 2014-10-29 02:04 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentprf.dll
2015-03-11 23:45 - 2014-10-29 02:04 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2015-03-11 23:45 - 2014-10-29 02:04 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\typeperf.exe
2015-03-11 23:45 - 2014-10-29 02:04 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\relog.exe
2015-03-11 23:45 - 2014-10-29 02:04 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SecEdit.exe
2015-03-11 23:45 - 2014-10-29 02:04 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumapi.dll
2015-03-11 23:45 - 2014-10-29 02:04 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sscore.dll
2015-03-11 23:45 - 2014-10-29 02:04 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.exe
2015-03-11 23:45 - 2014-10-29 02:04 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findstr.exe
2015-03-11 23:45 - 2014-10-29 02:04 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cacls.exe
2015-03-11 23:45 - 2014-10-29 02:04 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapprovp.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidnsp.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.Fontgroups.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MirrorDrvCompat.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypttpmeksvc.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInput1_4.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll
2015-03-11 23:45 - 2014-10-29 02:03 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chkdsk.exe
2015-03-11 23:45 - 2014-10-29 02:02 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2015-03-11 23:45 - 2014-10-29 02:02 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2015-03-11 23:45 - 2014-10-29 02:01 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngcredui.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfctrs.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NETSTAT.EXE
2015-03-11 23:45 - 2014-10-29 02:00 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipconfig.exe
2015-03-11 23:45 - 2014-10-29 02:00 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dimsjob.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxlegih.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
2015-03-11 23:45 - 2014-10-29 02:00 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfmifs.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxdm.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\elsTrans.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Display.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.SystemManufacturers.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
2015-03-11 23:45 - 2014-10-29 02:00 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.RemoteDesktop.dll
2015-03-11 23:45 - 2014-10-29 01:59 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3gpclnt.dll
2015-03-11 23:45 - 2014-10-29 01:59 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vsstrace.dll
2015-03-11 23:45 - 2014-10-29 01:59 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2015-03-11 23:45 - 2014-10-29 01:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.dll
2015-03-11 23:45 - 2014-10-29 01:58 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2015-03-11 23:45 - 2014-10-29 01:58 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-03-11 23:45 - 2014-10-29 01:58 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdPHost.dll
2015-03-11 23:45 - 2014-10-29 01:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcdAutoSetup.dll
2015-03-11 23:45 - 2014-10-29 01:57 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetmib1.dll
2015-03-11 23:45 - 2014-10-29 01:57 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll
2015-03-11 23:45 - 2014-10-29 01:57 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\datusage.dll
2015-03-11 23:45 - 2014-10-29 01:57 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe
2015-03-11 23:45 - 2014-10-29 01:57 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrshost.exe
2015-03-11 23:45 - 2014-10-29 01:56 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certCredProvider.dll
2015-03-11 23:45 - 2014-10-29 01:56 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintIsolationProxy.dll
2015-03-11 23:45 - 2014-10-29 01:55 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpSaProxy.exe
2015-03-11 23:45 - 2014-10-29 01:53 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDPrintProxy.DLL
2015-03-11 23:45 - 2014-10-29 01:53 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2015-03-11 23:45 - 2014-10-29 01:53 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifmon.dll
2015-03-11 23:45 - 2014-10-29 01:52 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrs.exe
2015-03-11 23:45 - 2014-10-29 01:51 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndiscapCfg.dll
2015-03-11 23:45 - 2014-10-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2015-03-11 23:45 - 2014-10-29 01:47 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3gpclnt.dll
2015-03-11 23:45 - 2014-10-29 01:46 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2015-03-11 23:45 - 2014-10-29 01:46 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PSModuleDiscoveryProvider.dll
2015-03-11 23:45 - 2014-10-29 01:46 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe
2015-03-11 23:45 - 2014-10-29 01:44 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CheckNetIsolation.exe
2015-03-11 23:45 - 2014-10-29 01:44 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RdpSaProxy.exe
2015-03-11 23:45 - 2014-10-29 01:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2015-03-11 23:45 - 2014-10-29 01:35 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2015-03-11 23:45 - 2014-10-07 07:54 - 00324928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-03-11 23:45 - 2014-10-07 07:54 - 00189248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS
2015-03-11 23:45 - 2014-10-07 07:54 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-03-11 23:45 - 2014-10-07 07:44 - 00069952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
2015-03-11 23:45 - 2014-06-21 08:33 - 00212736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2015-03-11 23:44 - 2014-10-29 04:54 - 05120000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWSnapin.dll
2015-03-11 23:44 - 2014-10-29 04:07 - 05120000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWSnapin.dll
2015-03-11 23:44 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\txfw32.dll
2015-03-11 23:44 - 2014-10-29 03:48 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Locator.exe
2015-03-11 23:44 - 2014-10-29 03:47 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2015-03-11 23:44 - 2014-10-29 03:46 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc63.sys
2015-03-11 23:44 - 2014-10-29 03:46 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2015-03-11 23:44 - 2014-10-29 03:46 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2015-03-11 23:44 - 2014-10-29 03:45 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\miguiresource.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SortWindows6Compat.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvcfg.exe
2015-03-11 23:44 - 2014-10-29 03:45 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SortWindows61.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\netbios.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensApi.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\browseui.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\regidle.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AutoWorkplaceN.dll
2015-03-11 23:44 - 2014-10-29 03:45 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\osuninst.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\fthsvc.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsnmp32.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsmproxy.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\SortServer2003Compat.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\regini.exe
2015-03-11 23:44 - 2014-10-29 03:44 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\htui.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\idndl.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Nlsdl.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidserv.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrnr.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscdll.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\blb_ps.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmutil.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\davhlpr.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\sisbkup.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mgmtapi.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shunimpl.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WofUtil.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\clb.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsock32.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\msidcrl40.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sas.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlS0WndH.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiwer.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscat32.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcfgex.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\nddeapi.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInput9_1_0.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\softpub.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OskSupport.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\riched32.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\getuname.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxex.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssip32.dll
2015-03-11 23:44 - 2014-10-29 03:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\comcat.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\telephon.cpl
2015-03-11 23:44 - 2014-10-29 03:43 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzutil.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmxs.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasser.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\osbaseln.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\sort.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbnmpntw.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiltcfg.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasctrs.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\doskey.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\hh.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\find.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\print.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\label.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\subst.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfts.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diskcomp.com
2015-03-11 23:44 - 2014-10-29 03:43 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MUILanguageCleanup.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LangCleanupSysprepAction.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwinsat.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpts.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\chcp.com
2015-03-11 23:44 - 2014-10-29 03:43 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\recover.exe
2015-03-11 23:44 - 2014-10-29 03:43 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\diskcopy.com
2015-03-11 23:44 - 2014-10-29 03:43 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapiperf.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeDateMUICallback.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsied.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spmpm.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\acledit.dll
2015-03-11 23:44 - 2014-10-29 03:43 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\plasrv.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iyuv_32.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrcomp.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\efssvc.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvidc32.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\klist.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDOIProxy.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\syskey.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnscacheugc.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdlg.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\cliconfg.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\drprov.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msyuv.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wephostsvc.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\jnwmon.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\WINSRPC.DLL
2015-03-11 23:44 - 2014-10-29 03:42 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcacli.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\netbtugc.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\midimap.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe
2015-03-11 23:44 - 2014-10-29 03:42 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\umdmxfrm.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\muifontsetup.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrle32.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsbyuv.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifsutilx.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshnetbs.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbperf.dll
2015-03-11 23:44 - 2014-10-29 03:42 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonUI.exe
2015-03-11 23:44 - 2014-10-29 03:41 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysclass.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cliconfg.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmintf.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxpps.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dispex.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
2015-03-11 23:44 - 2014-10-29 03:41 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe
2015-03-11 23:44 - 2014-10-29 03:41 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpupdate.exe
2015-03-11 23:44 - 2014-10-29 03:41 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\syssetup.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\localui.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe


Oktavius 13.03.2015 16:41

Nr.6

Das wars! :-)

Code:

2015-03-11 23:44 - 2014-10-29 03:41 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpSaPs.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshirda.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncHostps.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcico.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\panmap.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmcodecdspps.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\spnet.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CIRCoInst.dll
2015-03-11 23:44 - 2014-10-29 03:41 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\shfolder.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\sccls.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncInfrastructureps.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx5.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.proxystub.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\irclass.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSChannel.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx7.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx6.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx3.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx4.dll
2015-03-11 23:44 - 2014-10-29 03:40 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2015-03-11 23:44 - 2014-10-29 03:39 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2015-03-11 23:44 - 2014-10-29 03:39 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddp_ps.dll
2015-03-11 23:44 - 2014-10-29 03:39 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksetup.exe
2015-03-11 23:44 - 2014-10-29 03:39 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\srm_ps.dll
2015-03-11 23:44 - 2014-10-29 03:39 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\icmui.dll
2015-03-11 23:44 - 2014-10-29 03:38 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2015-03-11 23:44 - 2014-10-29 03:38 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\pid.dll
2015-03-11 23:44 - 2014-10-29 03:38 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\capisp.dll
2015-03-11 23:44 - 2014-10-29 03:38 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\nbtstat.exe
2015-03-11 23:44 - 2014-10-29 03:38 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfime.ime
2015-03-11 23:44 - 2014-10-29 03:37 - 15789568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDORes.dll
2015-03-11 23:44 - 2014-10-29 03:37 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdiasqmmodule.dll
2015-03-11 23:44 - 2014-10-29 03:37 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsauth.dll
2015-03-11 23:44 - 2014-10-29 03:37 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcPing.exe
2015-03-11 23:44 - 2014-10-29 03:37 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VscMgrPS.dll
2015-03-11 23:44 - 2014-10-29 03:37 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\secinit.exe
2015-03-11 23:44 - 2014-10-29 03:36 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\extrac32.exe
2015-03-11 23:44 - 2014-10-29 03:36 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsium.dll
2015-03-11 23:44 - 2014-10-29 03:36 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcnsh.dll
2015-03-11 23:44 - 2014-10-29 03:36 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-03-11 23:44 - 2014-10-29 03:36 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ktmutil.exe
2015-03-11 23:44 - 2014-10-29 03:36 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bitsprx2.dll
2015-03-11 23:44 - 2014-10-29 03:36 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\verclsid.exe
2015-03-11 23:44 - 2014-10-29 03:36 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\acproxy.dll
2015-03-11 23:44 - 2014-10-29 03:35 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdhui.dll
2015-03-11 23:44 - 2014-10-29 03:35 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\cofiredm.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsicpl.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\eventvwr.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\hdwwiz.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winver.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasphone.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UI0Detect.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\where.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdrleakdiag.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialer.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\timeout.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\clip.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\at.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEject.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\uniplat.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spopk.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\compact.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernelceip.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdial.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\fsavailux.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcmonitor.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2015-03-11 23:44 - 2014-10-29 03:34 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TapiSysprep.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmdext.dll
2015-03-11 23:44 - 2014-10-29 03:34 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\regedt32.exe
2015-03-11 23:44 - 2014-10-29 03:33 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndadmin.exe
2015-03-11 23:44 - 2014-10-29 03:33 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetVscCoinstall.dll
2015-03-11 23:44 - 2014-10-29 03:33 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmdCoinstall.dll
2015-03-11 23:44 - 2014-10-29 03:33 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\takeown.exe
2015-03-11 23:44 - 2014-10-29 03:33 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Apphlpdm.dll
2015-03-11 23:44 - 2014-10-29 03:33 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\winusb.dll
2015-03-11 23:44 - 2014-10-29 03:33 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdiagnhost.exe
2015-03-11 23:44 - 2014-10-29 03:33 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetppui.dll
2015-03-11 23:44 - 2014-10-29 03:33 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2015-03-11 23:44 - 2014-10-29 03:33 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\svsvc.dll
2015-03-11 23:44 - 2014-10-29 03:33 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LAPRXY.DLL
2015-03-11 23:44 - 2014-10-29 03:32 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2015-03-11 23:44 - 2014-10-29 03:32 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CHxReadingStringIME.dll
2015-03-11 23:44 - 2014-10-29 03:31 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\fsutilext.dll
2015-03-11 23:44 - 2014-10-29 03:31 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingProxy.dll
2015-03-11 23:44 - 2014-10-29 03:31 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlaninst.dll
2015-03-11 23:44 - 2014-10-29 03:31 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2015-03-11 23:44 - 2014-10-29 03:31 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-03-11 23:44 - 2014-10-29 03:30 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sigverif.exe
2015-03-11 23:44 - 2014-10-29 03:30 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\forfiles.exe
2015-03-11 23:44 - 2014-10-29 03:30 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\eventcreate.exe
2015-03-11 23:44 - 2014-10-29 03:30 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\choice.exe
2015-03-11 23:44 - 2014-10-29 03:30 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
2015-03-11 23:44 - 2014-10-29 03:29 - 01502720 _____ (Microsoft Corporation) C:\WINDOWS\system32\diskcopy.dll
2015-03-11 23:44 - 2014-10-29 03:29 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\main.cpl
2015-03-11 23:44 - 2014-10-29 03:29 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsicli.exe
2015-03-11 23:44 - 2014-10-29 03:29 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\console.dll
2015-03-11 23:44 - 2014-10-29 03:29 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\openfiles.exe
2015-03-11 23:44 - 2014-10-29 03:29 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\waitfor.exe
2015-03-11 23:44 - 2014-10-29 03:29 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\setspn.exe
2015-03-11 23:44 - 2014-10-29 03:29 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvcctl.dll
2015-03-11 23:44 - 2014-10-29 03:29 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshelper.dll
2015-03-11 23:44 - 2014-10-29 03:28 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootcfg.exe
2015-03-11 23:44 - 2014-10-29 03:28 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcad32.exe
2015-03-11 23:44 - 2014-10-29 03:28 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSMON.dll
2015-03-11 23:44 - 2014-10-29 03:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\eventcls.dll
2015-03-11 23:44 - 2014-10-29 03:27 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmci.dll
2015-03-11 23:44 - 2014-10-29 03:27 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\serialui.dll
2015-03-11 23:44 - 2014-10-29 03:26 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthSQM.dll
2015-03-11 23:44 - 2014-10-29 03:25 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrreg.exe
2015-03-11 23:44 - 2014-10-29 03:25 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontview.exe
2015-03-11 23:44 - 2014-10-29 03:25 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe
2015-03-11 23:44 - 2014-10-29 03:25 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\napipsec.dll
2015-03-11 23:44 - 2014-10-29 03:24 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountControlSettings.exe
2015-03-11 23:44 - 2014-10-29 03:24 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\baaupdate.exe
2015-03-11 23:44 - 2014-10-29 03:24 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcaApi.dll
2015-03-11 23:44 - 2014-10-29 03:24 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcwrun.exe
2015-03-11 23:44 - 2014-10-29 03:23 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dispci.dll
2015-03-11 23:44 - 2014-10-29 03:23 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\montr_ci.dll
2015-03-11 23:44 - 2014-10-29 03:23 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wowreg32.exe
2015-03-11 23:44 - 2014-10-29 03:22 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.exe
2015-03-11 23:44 - 2014-10-29 03:22 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\radarrs.dll
2015-03-11 23:44 - 2014-10-29 03:22 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\PNPXAssocPrx.dll
2015-03-11 23:44 - 2014-10-29 03:22 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFCoinstaller.dll
2015-03-11 23:44 - 2014-10-29 03:22 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndproxystub.dll
2015-03-11 23:44 - 2014-10-29 03:22 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgwdi.dll
2015-03-11 23:44 - 2014-10-29 03:20 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsicpl.dll
2015-03-11 23:44 - 2014-10-29 03:20 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncpa.cpl
2015-03-11 23:44 - 2014-10-29 03:20 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdown.exe
2015-03-11 23:44 - 2014-10-29 03:20 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WallpaperHost.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\control.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabcal.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingWizard.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MultiDigiMon.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Netplwiz.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Eap3Host.exe
2015-03-11 23:44 - 2014-10-29 03:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\DefaultDeviceManager.dll
2015-03-11 23:44 - 2014-10-29 03:18 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartScreenSettings.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OptionalFeatures.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Fondue.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdRes.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DpiScaling.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dvdupgrd.exe
2015-03-11 23:44 - 2014-10-29 03:18 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\grpconv.exe
2015-03-11 23:44 - 2014-10-29 03:17 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hdwwiz.cpl
2015-03-11 23:44 - 2014-10-29 03:17 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbctrac.dll
2015-03-11 23:44 - 2014-10-29 03:17 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdSched.exe
2015-03-11 23:44 - 2014-10-29 03:17 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mobsync.exe
2015-03-11 23:44 - 2014-10-29 03:17 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsUsbGDCoInstaller.dll
2015-03-11 23:44 - 2014-10-29 03:17 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\aecache.dll
2015-03-11 23:44 - 2014-10-29 03:17 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmstplua.dll
2015-03-11 23:44 - 2014-10-29 03:17 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSUNATD.exe
2015-03-11 23:44 - 2014-10-29 03:17 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDACLSys.dll
2015-03-11 23:44 - 2014-10-29 03:17 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoveDeviceElevated.dll
2015-03-11 23:44 - 2014-10-29 03:12 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthci.dll
2015-03-11 23:44 - 2014-10-29 03:11 - 00212480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdminst.dll
2015-03-11 23:44 - 2014-10-29 03:10 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srwmi.dll
2015-03-11 23:44 - 2014-10-29 03:09 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthudtask.exe
2015-03-11 23:44 - 2014-10-29 03:09 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntlanui2.dll
2015-03-11 23:44 - 2014-10-29 03:08 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MuiUnattend.exe
2015-03-11 23:44 - 2014-10-29 03:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\credwiz.exe
2015-03-11 23:44 - 2014-10-29 03:08 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2015-03-11 23:44 - 2014-10-29 03:05 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gptext.dll
2015-03-11 23:44 - 2014-10-29 03:03 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\txfw32.dll
2015-03-11 23:44 - 2014-10-29 03:03 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wship6.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00594944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dramp.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miguiresource.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmcompc.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SortWindows61.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Nlsdl.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciwave.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mciseq.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscdll.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscpxl32.dLL
2015-03-11 23:44 - 2014-10-29 03:00 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiatrace.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscat32.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browseui.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensApi.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\softpub.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nddeapi.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiwer.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssip32.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir50_32.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir41_32.ax
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OskSupport.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir50_qcx.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir50_qc.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir41_qcx.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir41_qc.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ir32_32.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\getuname.dll
2015-03-11 23:44 - 2014-10-29 03:00 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osuninst.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PnPUnattend.exe
2015-03-11 23:44 - 2014-10-29 02:59 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrnr.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lsmproxy.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vdmdbg.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsock32.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clb.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subst.exe
2015-03-11 23:44 - 2014-10-29 02:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\print.exe
2015-03-11 23:44 - 2014-10-29 02:59 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msidcrl40.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlS0WndH.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sas.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInput9_1_0.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comcat.dll
2015-03-11 23:44 - 2014-10-29 02:59 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxex.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00107008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\telephon.cpl
2015-03-11 23:44 - 2014-10-29 02:58 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\colorcpl.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iyuv_32.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzutil.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cliconfg.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msyuv.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasser.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drprov.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sort.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osbaseln.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\umdmxfrm.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\midimap.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WINSRPC.DLL
2015-03-11 23:44 - 2014-10-29 02:58 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\diskperf.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasctrs.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hh.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\diskcomp.com
2015-03-11 23:44 - 2014-10-29 02:58 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshrm.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\label.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfts.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrle32.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsbyuv.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TapiUnattend.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwinsat.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\recover.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmsprep.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chcp.com
2015-03-11 23:44 - 2014-10-29 02:58 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\diskcopy.com
2015-03-11 23:44 - 2014-10-29 02:58 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dvdplay.exe
2015-03-11 23:44 - 2014-10-29 02:58 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsied.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapiperf.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeDateMUICallback.dll
2015-03-11 23:44 - 2014-10-29 02:58 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\acledit.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSTIFF.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmintf.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcacli.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\npmproxy.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpupdate.exe
2015-03-11 23:44 - 2014-10-29 02:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcmsetup.exe
2015-03-11 23:44 - 2014-10-29 02:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\syssetup.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\muifontsetup.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\panmap.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifsutilx.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usbperf.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshirda.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RdpSaPs.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcico.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IconCodecService.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrnsave.scr
2015-03-11 23:44 - 2014-10-29 02:57 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spnet.dll
2015-03-11 23:44 - 2014-10-29 02:57 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shfolder.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsprx5.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncInfrastructureps.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srm_ps.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\irclass.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dispex.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSChannel.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsprx6.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsprx7.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsprx3.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncHostps.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsprx4.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmcodecdspps.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcji32.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odtext32.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odpdx32.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odfox32.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oddbse32.dll
2015-03-11 23:44 - 2014-10-29 02:56 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odexl32.dll
2015-03-11 23:44 - 2014-10-29 02:55 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfime.ime
2015-03-11 23:44 - 2014-10-29 02:54 - 15784448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DDORes.dll
2015-03-11 23:44 - 2014-10-29 02:54 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secinit.exe
2015-03-11 23:44 - 2014-10-29 02:54 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VscMgrPS.dll
2015-03-11 23:44 - 2014-10-29 02:54 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ctfmon.exe
2015-03-11 23:44 - 2014-10-29 02:53 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapimig.exe
2015-03-11 23:44 - 2014-10-29 02:53 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qmgrprxy.dll
2015-03-11 23:44 - 2014-10-29 02:53 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ktmutil.exe
2015-03-11 23:44 - 2014-10-29 02:53 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bitsprx2.dll
2015-03-11 23:44 - 2014-10-29 02:53 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\verclsid.exe
2015-03-11 23:44 - 2014-10-29 02:53 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\winhlp32.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsicpl.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msra.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eventvwr.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hdwwiz.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winver.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spopk.dll
2015-03-11 23:44 - 2014-10-29 02:52 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regsvr32.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedt32.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmdext.dll
2015-03-11 23:44 - 2014-10-29 02:52 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\write.exe
2015-03-11 23:44 - 2014-10-29 02:52 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TapiSysprep.dll
2015-03-11 23:44 - 2014-10-29 02:52 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-03-11 23:44 - 2014-10-29 02:51 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndadmin.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\at.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\runas.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uniplat.dll
2015-03-11 23:44 - 2014-10-29 02:51 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdial.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcmonitor.dll
2015-03-11 23:44 - 2014-10-29 02:51 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LAPRXY.DLL
2015-03-11 23:44 - 2014-10-29 02:51 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InfDefaultInstall.exe
2015-03-11 23:44 - 2014-10-29 02:51 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systray.exe
2015-03-11 23:44 - 2014-10-29 02:50 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Apphlpdm.dll
2015-03-11 23:44 - 2014-10-29 02:49 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairingProxy.dll
2015-03-11 23:44 - 2014-10-29 02:49 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wksprtPS.dll
2015-03-11 23:44 - 2014-10-29 02:49 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2015-03-11 23:44 - 2014-10-29 02:49 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-03-11 23:44 - 2014-10-29 02:49 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CHxReadingStringIME.dll
2015-03-11 23:44 - 2014-10-29 02:48 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RmClient.exe
2015-03-11 23:44 - 2014-10-29 02:47 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eventcls.dll
2015-03-11 23:44 - 2014-10-29 02:46 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcad32.exe
2015-03-11 23:44 - 2014-10-29 02:46 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\serialui.dll
2015-03-11 23:44 - 2014-10-29 02:45 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resmon.exe
2015-03-11 23:44 - 2014-10-29 02:45 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2015-03-11 23:44 - 2014-10-29 02:44 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountControlSettings.exe
2015-03-11 23:44 - 2014-10-29 02:44 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Narrator.exe
2015-03-11 23:44 - 2014-10-29 02:44 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationNotifications.exe
2015-03-11 23:44 - 2014-10-29 02:43 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NcaApi.dll
2015-03-11 23:44 - 2014-10-29 02:43 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wowreg32.exe
2015-03-11 23:44 - 2014-10-29 02:42 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.exe
2015-03-11 23:44 - 2014-10-29 02:42 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdmps.dll
2015-03-11 23:44 - 2014-10-29 02:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndproxystub.dll
2015-03-11 23:44 - 2014-10-29 02:40 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncpa.cpl
2015-03-11 23:44 - 2014-10-29 02:40 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairingWizard.exe
2015-03-11 23:44 - 2014-10-29 02:40 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Netplwiz.exe
2015-03-11 23:44 - 2014-10-29 02:40 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DefaultDeviceManager.dll
2015-03-11 23:44 - 2014-10-29 02:39 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartScreenSettings.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\control.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Fondue.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesRemote.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesProtection.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesHardware.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesDataExecutionPrevention.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesComputerName.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesAdvanced.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DpiScaling.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RunLegacyCPLElevated.exe
2015-03-11 23:44 - 2014-10-29 02:39 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe
2015-03-11 23:44 - 2014-10-29 02:38 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbctrac.dll
2015-03-11 23:44 - 2014-10-29 02:38 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mobsync.exe
2015-03-11 23:44 - 2014-10-29 02:38 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\grpconv.exe
2015-03-11 23:44 - 2014-10-29 02:38 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DDACLSys.dll
2015-03-11 23:44 - 2014-10-29 02:38 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoveDeviceElevated.dll
2015-03-11 23:44 - 2014-10-29 02:34 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsui.exe
2015-03-11 23:44 - 2014-10-29 02:32 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntlanui2.dll
2015-03-11 23:44 - 2014-10-29 02:32 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2015-03-11 23:44 - 2014-10-29 02:29 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmiclnt.dll
2015-03-11 23:44 - 2014-10-29 02:29 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gptext.dll
2015-03-11 23:44 - 2014-10-29 02:29 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapi.dll
2015-03-11 23:44 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprext.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2015-03-11 23:44 - 2014-10-29 02:28 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprmsg.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\KdsCli.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\reg.exe
2015-03-11 23:44 - 2014-10-29 02:28 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\sc.exe
2015-03-11 23:44 - 2014-10-29 02:28 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfscli.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfproc.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnikeapi.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\icacls.exe
2015-03-11 23:44 - 2014-10-29 02:28 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdhcinst.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpapi.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
2015-03-11 23:44 - 2014-10-29 02:28 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltLib.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mskeyprotcli.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\PATHPING.EXE
2015-03-11 23:44 - 2014-10-29 02:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nrpsrv.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2015-03-11 23:44 - 2014-10-29 02:28 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrssrv.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\whhelper.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBthProxy.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TCPSVCS.EXE
2015-03-11 23:44 - 2014-10-29 02:28 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\msidle.dll
2015-03-11 23:44 - 2014-10-29 02:28 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\backgroundTaskHost.exe
2015-03-11 23:44 - 2014-10-29 02:28 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nslookup.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentprf.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\setx.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspatcha.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecEdit.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfdisk.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\virtdisk.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmapi.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\cacls.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltMC.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecerts.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedcli.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhapi.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PING.EXE
2015-03-11 23:44 - 2014-10-29 02:27 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerClient.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\finger.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Register-CimProvider.exe
2015-03-11 23:44 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2015-03-11 23:44 - 2014-10-29 02:27 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringIeProvider.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\typeperf.exe
2015-03-11 23:44 - 2014-10-29 02:26 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\relog.exe
2015-03-11 23:44 - 2014-10-29 02:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\pots.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnEapPeerProxy.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnEapAuthProxy.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VaultCmd.exe
2015-03-11 23:44 - 2014-10-29 02:26 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\userinitext.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityRtapiPal.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpcsvc.dll
2015-03-11 23:44 - 2014-10-29 02:26 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeSysprep.dll
2015-03-11 23:44 - 2014-10-29 02:25 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogonext.dll
2015-03-11 23:44 - 2014-10-29 02:25 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tpmcompc.dll
2015-03-11 23:44 - 2014-10-29 02:25 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncuprov.dll
2015-03-11 23:44 - 2014-10-29 02:25 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininitext.dll
2015-03-11 23:44 - 2014-10-29 02:25 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsext.dll
2015-03-11 23:44 - 2014-10-29 02:24 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\procinst.dll
2015-03-11 23:44 - 2014-10-29 02:23 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2015-03-11 23:44 - 2014-10-29 02:23 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll
2015-03-11 23:44 - 2014-10-29 02:23 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.ps.dll
2015-03-11 23:44 - 2014-10-29 02:22 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-03-11 23:44 - 2014-10-29 02:22 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2015-03-11 23:44 - 2014-10-29 02:22 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskSchdPS.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfctrs.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipconfig.exe
2015-03-11 23:44 - 2014-10-29 02:21 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnsruprov.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallButtons.ProxyStub.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragproxy.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHostProxy.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsExt.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeSyncTask.dll
2015-03-11 23:44 - 2014-10-29 02:21 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfmifsproxy.dll
2015-03-11 23:44 - 2014-10-29 02:20 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpapimig.exe
2015-03-11 23:44 - 2014-10-29 02:20 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\NETSTAT.EXE
2015-03-11 23:44 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentTask.dll
2015-03-11 23:44 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2015-03-11 23:44 - 2014-10-29 02:19 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpauto.dll
2015-03-11 23:44 - 2014-10-29 02:19 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschapext.dll
2015-03-11 23:44 - 2014-10-29 02:19 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2015-03-11 23:44 - 2014-10-29 02:16 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
2015-03-11 23:44 - 2014-10-29 02:16 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetmib1.dll
2015-03-11 23:44 - 2014-10-29 02:14 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\nci.dll
2015-03-11 23:44 - 2014-10-29 02:12 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwaninst.dll
2015-03-11 23:44 - 2014-10-29 02:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2015-03-11 23:44 - 2014-10-29 02:11 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2015-03-11 23:44 - 2014-10-29 02:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifmon.dll
2015-03-11 23:44 - 2014-10-29 02:08 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrs.exe
2015-03-11 23:44 - 2014-10-29 02:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpapi.dll
2015-03-11 23:44 - 2014-10-29 02:06 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprext.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2015-03-11 23:44 - 2014-10-29 02:05 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprmsg.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unlodctr.exe
2015-03-11 23:44 - 2014-10-29 02:05 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\virtdisk.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vpnikeapi.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schedcli.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PING.EXE
2015-03-11 23:44 - 2014-10-29 02:05 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PATHPING.EXE
2015-03-11 23:44 - 2014-10-29 02:05 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mountvol.exe
2015-03-11 23:44 - 2014-10-29 02:05 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TRACERT.EXE
2015-03-11 23:44 - 2014-10-29 02:05 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemEventsBrokerClient.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmsgapi.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\finger.exe
2015-03-11 23:44 - 2014-10-29 02:05 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\whhelper.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2015-03-11 23:44 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrssrv.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBthProxy.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TCPSVCS.EXE
2015-03-11 23:44 - 2014-10-29 02:05 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msidle.dll
2015-03-11 23:44 - 2014-10-29 02:05 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2015-03-11 23:44 - 2014-10-29 02:04 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pots.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcmapi.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fltMC.exe
2015-03-11 23:44 - 2014-10-29 02:04 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ARP.EXE
2015-03-11 23:44 - 2014-10-29 02:04 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userinitext.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Register-CimProvider.exe
2015-03-11 23:44 - 2014-10-29 02:04 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
2015-03-11 23:44 - 2014-10-29 02:04 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HOSTNAME.EXE
2015-03-11 23:44 - 2014-10-29 02:04 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpcsvc.dll
2015-03-11 23:44 - 2014-10-29 02:03 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MRINFO.EXE
2015-03-11 23:44 - 2014-10-29 02:03 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityRtapiPal.dll
2015-03-11 23:44 - 2014-10-29 02:02 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipsec.dll
2015-03-11 23:44 - 2014-10-29 02:02 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininitext.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TaskSchdPS.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vss_ps.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.ps.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\slpts.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll
2015-03-11 23:44 - 2014-10-29 02:01 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.ps.dll
2015-03-11 23:44 - 2014-10-29 02:00 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvps.dll
2015-03-11 23:44 - 2014-10-29 02:00 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ROUTE.EXE
2015-03-11 23:44 - 2014-10-29 02:00 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmproxy.dll
2015-03-11 23:44 - 2014-10-29 02:00 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsExt.dll
2015-03-11 23:44 - 2014-10-29 02:00 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommonPal.dll
2015-03-11 23:44 - 2014-10-29 02:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfmifsproxy.dll
2015-03-11 23:44 - 2014-10-29 01:59 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\raschapext.dll
2015-03-11 23:44 - 2014-10-29 01:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2015-03-11 23:44 - 2014-10-29 01:58 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxshared.dll
2015-03-11 23:44 - 2014-10-29 01:58 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Startupscan.dll
2015-03-11 23:44 - 2014-10-29 01:57 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\energytask.dll
2015-03-11 23:44 - 2014-10-29 01:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\msshooks.dll
2015-03-11 23:44 - 2014-10-29 01:56 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nci.dll
2015-03-11 23:44 - 2014-10-29 01:55 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\CheckNetIsolation.exe
2015-03-11 23:44 - 2014-10-29 01:54 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpSaUacHelper.exe
2015-03-11 23:44 - 2014-10-29 01:50 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe
2015-03-11 23:44 - 2014-10-29 01:50 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2015-03-11 23:44 - 2014-10-29 01:48 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slpts.dll
2015-03-11 23:44 - 2014-10-29 01:46 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Startupscan.dll
2015-03-11 23:44 - 2014-10-29 01:45 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msshooks.dll
2015-03-11 23:44 - 2014-10-29 01:44 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RdpSaUacHelper.exe
2015-03-11 23:43 - 2014-10-29 04:54 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWWizFwk.dll
2015-03-11 23:43 - 2014-10-29 04:07 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWWizFwk.dll
2015-03-11 23:43 - 2014-10-29 03:50 - 02628608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-03-11 23:43 - 2014-10-29 03:49 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUxRes.dll
2015-03-11 23:43 - 2014-10-29 03:49 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2015-03-11 23:43 - 2014-10-29 03:49 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Firewall.cpl
2015-03-11 23:43 - 2014-10-29 03:49 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2help.dll
2015-03-11 23:43 - 2014-10-29 03:49 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2015-03-11 23:43 - 2014-10-29 03:49 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rnr20.dll
2015-03-11 23:43 - 2014-10-29 03:48 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\usp10.dll
2015-03-11 23:43 - 2014-10-29 03:48 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ktmw32.dll
2015-03-11 23:43 - 2014-10-29 03:48 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasacd.sys
2015-03-11 23:43 - 2014-10-29 03:48 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\workerdd.dll
2015-03-11 23:43 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSHTCPIP.DLL
2015-03-11 23:43 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wship6.dll
2015-03-11 23:43 - 2014-10-29 03:48 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2015-03-11 23:43 - 2014-10-29 03:48 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmi.dll
2015-03-11 23:43 - 2014-10-29 03:47 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbcir.sys
2015-03-11 23:43 - 2014-10-29 03:47 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\qwavedrv.sys
2015-03-11 23:43 - 2014-10-29 03:47 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2015-03-11 23:43 - 2014-10-29 03:47 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpials.sys
2015-03-11 23:43 - 2014-10-29 03:46 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2015-03-11 23:43 - 2014-10-29 03:46 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-03-11 23:43 - 2014-10-29 03:46 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2015-03-11 23:43 - 2014-10-29 03:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiscap.sys
2015-03-11 23:43 - 2014-10-29 03:46 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2015-03-11 23:43 - 2014-10-29 03:46 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\TsUsbGD.sys
2015-03-11 23:43 - 2014-10-29 03:45 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\OobeFldr.dll
2015-03-11 23:43 - 2014-10-29 03:45 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\srm.dll
2015-03-11 23:43 - 2014-10-29 03:45 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2015-03-11 23:43 - 2014-10-29 03:45 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys
2015-03-11 23:43 - 2014-10-29 03:45 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mslldp.sys
2015-03-11 23:43 - 2014-10-29 03:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciwave.dll
2015-03-11 23:43 - 2014-10-29 03:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciseq.dll
2015-03-11 23:43 - 2014-10-29 03:45 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\shimeng.dll
2015-03-11 23:43 - 2014-10-29 03:45 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2015-03-11 23:43 - 2014-10-29 03:45 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2015-03-11 23:43 - 2014-10-29 03:45 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\normaliz.dll
2015-03-11 23:43 - 2014-10-29 03:44 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSchedExe.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\chgusr.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\diskperf.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\reset.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmdkey.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\change.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\query.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dvdplay.exe
2015-03-11 23:43 - 2014-10-29 03:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\help.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\colorcpl.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\qprocess.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msg.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\quser.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\chgport.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tskill.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsdiscon.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscon.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\rwinsta.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoff.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\TapiUnattend.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomcnfg.exe
2015-03-11 23:43 - 2014-10-29 03:42 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcNs4.dll
2015-03-11 23:43 - 2014-10-29 03:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qwinsta.exe
2015-03-11 23:43 - 2014-10-29 03:41 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\qappsrv.exe
2015-03-11 23:43 - 2014-10-29 03:41 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcmsetup.exe
2015-03-11 23:43 - 2014-10-29 03:41 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrnsave.scr
2015-03-11 23:43 - 2014-10-29 03:41 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetupproxyserv.dll
2015-03-11 23:43 - 2014-10-29 03:40 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\chglogon.exe
2015-03-11 23:43 - 2014-10-29 03:40 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-03-11 23:43 - 2014-10-29 03:38 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pstorec.dll
2015-03-11 23:43 - 2014-10-29 03:37 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ctfmon.exe
2015-03-11 23:43 - 2014-10-29 03:35 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PnPutil.exe
2015-03-11 23:43 - 2014-10-29 03:34 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\cofire.exe
2015-03-11 23:43 - 2014-10-29 03:34 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\write.exe
2015-03-11 23:43 - 2014-10-29 03:34 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\write.exe
2015-03-11 23:43 - 2014-10-29 03:34 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\systray.exe
2015-03-11 23:43 - 2014-10-29 03:33 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\runas.exe
2015-03-11 23:43 - 2014-10-29 03:33 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\InfDefaultInstall.exe
2015-03-11 23:43 - 2014-10-29 03:30 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\RmClient.exe
2015-03-11 23:43 - 2014-10-29 03:25 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\resmon.exe
2015-03-11 23:43 - 2014-10-29 03:24 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationNotifications.exe
2015-03-11 23:43 - 2014-10-29 03:23 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizardElev.exe
2015-03-11 23:43 - 2014-10-29 03:23 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizard.exe
2015-03-11 23:43 - 2014-10-29 03:20 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\proquota.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceProperties.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesRemote.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesProtection.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesPerformance.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesHardware.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesDataExecutionPrevention.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesComputerName.exe
2015-03-11 23:43 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesAdvanced.exe
2015-03-11 23:43 - 2014-10-29 03:18 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RunLegacyCPLElevated.exe
2015-03-11 23:43 - 2014-10-29 03:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsui.exe
2015-03-11 23:43 - 2014-10-29 03:05 - 02628608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-03-11 23:43 - 2014-10-29 03:04 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-03-11 23:43 - 2014-10-29 03:04 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceUxRes.dll
2015-03-11 23:43 - 2014-10-29 03:04 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2015-03-11 23:43 - 2014-10-29 03:04 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2help.dll
2015-03-11 23:43 - 2014-10-29 03:04 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2015-03-11 23:43 - 2014-10-29 03:04 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rnr20.dll
2015-03-11 23:43 - 2014-10-29 03:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usp10.dll
2015-03-11 23:43 - 2014-10-29 03:03 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ktmw32.dll
2015-03-11 23:43 - 2014-10-29 03:03 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSHTCPIP.DLL
2015-03-11 23:43 - 2014-10-29 03:03 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmi.dll
2015-03-11 23:43 - 2014-10-29 03:00 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OobeFldr.dll
2015-03-11 23:43 - 2014-10-29 03:00 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srm.dll
2015-03-11 23:43 - 2014-10-29 03:00 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shimeng.dll
2015-03-11 23:43 - 2014-10-29 03:00 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2015-03-11 23:43 - 2014-10-29 03:00 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2015-03-11 23:43 - 2014-10-29 03:00 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\normaliz.dll
2015-03-11 23:43 - 2014-10-29 03:00 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprop.dll
2015-03-11 23:43 - 2014-10-29 02:59 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\help.exe
2015-03-11 23:43 - 2014-10-29 02:58 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmdkey.exe
2015-03-11 23:43 - 2014-10-29 02:58 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomcnfg.exe
2015-03-11 23:43 - 2014-10-29 02:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DDOIProxy.dll
2015-03-11 23:43 - 2014-10-29 02:57 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RpcNs4.dll
2015-03-11 23:43 - 2014-10-29 02:56 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pstorec.dll
2015-03-11 23:43 - 2014-10-29 02:39 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceProperties.exe
2015-03-11 23:43 - 2014-10-29 02:32 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthudtask.exe
2015-03-11 23:43 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dabapi.dll
2015-03-11 23:43 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_ISCII.DLL
2015-03-11 23:43 - 2014-10-29 02:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mountvol.exe
2015-03-11 23:43 - 2014-10-29 02:28 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TcpipSetup.dll
2015-03-11 23:43 - 2014-10-29 02:27 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\lodctr.exe
2015-03-11 23:43 - 2014-10-29 02:27 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\unlodctr.exe
2015-03-11 23:43 - 2014-10-29 02:27 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\TRACERT.EXE
2015-03-11 23:43 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\HOSTNAME.EXE
2015-03-11 23:43 - 2014-10-29 02:26 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRINFO.EXE
2015-03-11 23:43 - 2014-10-29 02:23 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxStreamingDataSourcePS.dll
2015-03-11 23:43 - 2014-10-29 02:21 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ROUTE.EXE
2015-03-11 23:43 - 2014-10-29 02:21 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllhst3g.exe
2015-03-11 23:43 - 2014-10-29 02:06 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_ISCII.DLL
2015-03-11 23:43 - 2014-10-29 02:06 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dabapi.dll
2015-03-11 23:43 - 2014-10-29 02:05 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\backgroundTaskHost.exe
2015-03-11 23:43 - 2014-10-29 02:03 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe
2015-03-11 23:43 - 2014-10-29 02:00 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallButtons.ProxyStub.dll
2015-03-11 23:43 - 2014-10-29 01:58 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootim.exe
2015-03-11 23:43 - 2014-10-29 00:16 - 00002412 _____ () C:\WINDOWS\system32\KeyboardFilterShim.sdb
2015-03-11 23:43 - 2014-10-07 04:30 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-03-11 23:43 - 2014-10-07 04:29 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-03-11 23:43 - 2014-10-07 04:29 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-03-11 23:43 - 2014-10-07 04:29 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-03-11 23:12 - 2015-02-07 00:09 - 00396419 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-03-11 23:12 - 2015-02-04 00:58 - 00264000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-03-11 23:12 - 2015-02-04 00:58 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-03-11 23:12 - 2015-02-04 00:58 - 00044024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-03-11 23:12 - 2015-02-03 00:53 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2015-03-11 23:12 - 2015-02-03 00:53 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2015-03-11 23:12 - 2015-01-27 04:44 - 00933888 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-03-11 23:12 - 2015-01-24 02:51 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-03-11 23:11 - 2015-03-06 03:53 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-03-11 23:11 - 2015-03-06 03:33 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-03-11 23:11 - 2015-02-26 00:26 - 04178944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-03-11 23:11 - 2015-02-20 04:03 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-03-11 23:11 - 2015-02-20 03:58 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-03-11 23:11 - 2015-02-20 03:20 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-03-11 23:11 - 2015-02-20 03:15 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-03-11 23:11 - 2015-02-06 02:28 - 02257408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-03-11 23:11 - 2015-02-06 02:08 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-03-11 23:11 - 2015-02-05 21:24 - 01113920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-03-11 23:11 - 2015-02-03 01:03 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2015-03-11 23:11 - 2015-02-03 01:02 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-11 23:11 - 2015-01-31 00:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-03-11 23:11 - 2015-01-31 00:29 - 02484224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-03-11 23:11 - 2015-01-31 00:20 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2015-03-11 23:11 - 2015-01-30 04:01 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2015-03-11 23:11 - 2015-01-30 04:00 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
2015-03-11 23:11 - 2015-01-30 03:03 - 01488896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2015-03-11 23:11 - 2015-01-30 03:03 - 01464832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2015-03-11 23:11 - 2015-01-30 03:02 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2015-03-11 23:11 - 2015-01-30 02:44 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42u.dll
2015-03-11 23:11 - 2015-01-30 02:42 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42.dll
2015-03-11 23:11 - 2015-01-30 02:40 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2015-03-11 23:11 - 2015-01-30 02:37 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2015-03-11 23:11 - 2015-01-30 02:29 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2015-03-11 23:11 - 2015-01-30 02:24 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2015-03-11 23:11 - 2015-01-30 02:24 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2015-03-11 23:11 - 2015-01-30 02:16 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2015-03-11 23:11 - 2015-01-30 02:08 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2015-03-11 23:11 - 2015-01-30 02:06 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2015-03-11 23:11 - 2015-01-29 02:58 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
2015-03-11 23:11 - 2015-01-29 02:29 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
2015-03-11 23:11 - 2015-01-29 02:11 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 23:11 - 2015-01-29 02:04 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-03-11 23:11 - 2015-01-29 02:04 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2015-03-11 23:11 - 2015-01-29 02:00 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 23:11 - 2015-01-29 01:59 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-03-11 23:11 - 2015-01-29 01:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-03-11 23:11 - 2015-01-29 01:50 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-03-11 23:11 - 2015-01-29 01:49 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-03-11 23:11 - 2015-01-28 16:41 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-03-11 23:11 - 2015-01-28 16:41 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-03-11 23:11 - 2015-01-28 16:41 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-03-11 23:11 - 2015-01-28 03:24 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-11 23:11 - 2015-01-28 02:47 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorageContextHandler.dll
2015-03-11 23:11 - 2015-01-27 05:22 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-03-11 23:11 - 2015-01-27 03:11 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-03-11 23:11 - 2015-01-23 08:17 - 00723072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-03-11 23:11 - 2015-01-23 06:02 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2015-03-11 23:11 - 2014-10-29 04:56 - 00027456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2015-03-11 23:11 - 2014-10-29 03:37 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2015-03-11 23:11 - 2014-10-29 03:34 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2015-03-11 23:11 - 2014-10-29 03:34 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2015-03-11 23:11 - 2014-10-29 02:28 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\atlthunk.dll
2015-03-11 23:11 - 2014-10-29 02:19 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll
2015-03-11 23:11 - 2014-10-29 02:13 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-03-11 23:11 - 2014-10-29 01:59 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll
2015-03-11 23:11 - 2014-10-29 01:55 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-03-11 23:10 - 2015-02-21 02:16 - 25021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-03-11 23:10 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-03-11 23:10 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-03-11 23:10 - 2015-02-21 01:27 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-03-11 23:10 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-03-11 23:10 - 2015-02-21 00:58 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-03-11 23:10 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-03-11 23:10 - 2015-02-20 03:49 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-03-11 23:10 - 2015-02-20 03:48 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-03-11 23:10 - 2015-02-20 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-03-11 23:10 - 2015-02-20 03:35 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-03-11 23:10 - 2015-02-20 03:34 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-03-11 23:10 - 2015-02-20 03:32 - 06035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-03-11 23:10 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-03-11 23:10 - 2015-02-20 03:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-03-11 23:10 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-03-11 23:10 - 2015-02-20 03:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-03-11 23:10 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-03-11 23:10 - 2015-02-20 02:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-03-11 23:10 - 2015-02-20 02:56 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-03-11 23:10 - 2015-02-20 02:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-03-11 23:10 - 2015-02-20 02:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-03-11 23:10 - 2015-02-20 02:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-03-11 23:10 - 2015-02-20 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-03-11 23:10 - 2015-02-20 02:43 - 14398976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-03-11 23:10 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-03-11 23:10 - 2015-02-20 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-03-11 23:10 - 2015-02-20 02:29 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-03-11 23:10 - 2015-02-20 02:28 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-03-11 23:10 - 2015-02-20 02:26 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-03-11 23:10 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-03-11 23:10 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-03-11 23:10 - 2015-02-20 02:16 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-03-11 23:10 - 2015-02-20 02:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-03-11 23:10 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-03-11 23:10 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-03-11 23:10 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-03-11 23:10 - 2015-01-29 19:45 - 01763352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-11 23:10 - 2015-01-29 19:34 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-03-11 23:10 - 2014-12-11 06:36 - 00046456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-11 23:09 - 2015-02-12 18:40 - 22291584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-03-11 23:09 - 2015-02-12 18:34 - 19731824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-03-11 23:08 - 2015-02-08 00:57 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-03-11 23:08 - 2015-02-08 00:49 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-03-11 23:08 - 2015-01-28 02:31 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2015-03-11 23:08 - 2015-01-28 02:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2015-03-11 23:08 - 2015-01-28 00:47 - 02501368 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-03-11 23:08 - 2015-01-28 00:41 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-03-11 23:08 - 2015-01-21 06:54 - 01384712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-03-11 23:08 - 2015-01-21 06:15 - 01123848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-03-11 23:08 - 2014-10-31 05:50 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe
2015-03-11 23:08 - 2014-10-31 04:30 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2015-03-11 23:08 - 2014-10-31 04:23 - 00733696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-03-11 23:08 - 2014-10-31 04:22 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2015-03-11 23:08 - 2014-10-31 04:18 - 04840960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2015-03-11 23:08 - 2014-10-31 04:09 - 01154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2015-03-11 23:08 - 2014-10-31 03:12 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2015-03-11 01:41 - 2015-03-12 15:49 - 00031741 _____ () C:\Users\Justus Hoffmann\Desktop\FRST.txt
2015-03-11 01:39 - 2015-03-11 01:39 - 00003192 _____ () C:\Users\Justus Hoffmann\Desktop\a2scan_150311-011001.txt
2015-03-11 01:05 - 2015-03-11 01:05 - 00000757 _____ () C:\Users\Justus Hoffmann\Desktop\Start Emsisoft Emergency Kit.lnk
2015-03-11 01:05 - 2015-03-11 01:05 - 00000000 ____D () C:\EEK
2015-03-11 00:22 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\Justus Hoffmann\Desktop\Neues Textdokument - Kopie.txt
2015-03-10 01:00 - 2015-03-10 01:00 - 00001120 _____ () C:\Users\Justus Hoffmann\Desktop\JRT.txt
2015-03-10 00:55 - 2015-03-10 00:55 - 01388333 _____ (Thisisu) C:\Users\Justus Hoffmann\Desktop\JRT.exe
2015-03-10 00:47 - 2015-03-12 00:09 - 00000000 ____D () C:\AdwCleaner
2015-03-09 23:38 - 2015-03-13 11:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2015-03-13 11:10 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-09 23:38 - 2015-03-09 23:38 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-09 23:38 - 2015-03-09 23:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-09 23:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-03-09 23:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-09 23:37 - 2015-03-09 23:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Justus Hoffmann\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-09 23:37 - 2015-03-09 23:37 - 02171392 _____ () C:\Users\Justus Hoffmann\Desktop\AdwCleaner_4.112.exe
2015-03-09 23:36 - 2015-03-11 02:01 - 00003108 _____ () C:\WINDOWS\System32\Tasks\PandaUSBVaccine
2015-03-09 23:36 - 2015-03-11 02:01 - 00000000 ____D () C:\Program Files (x86)\Panda USB Vaccine
2015-03-09 23:36 - 2015-03-09 23:36 - 00848856 _____ (Panda Security ) C:\Users\Justus Hoffmann\Desktop\USBVaccineSetup.exe
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Panda Security
2015-03-09 23:36 - 2015-03-09 23:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2015-03-09 13:56 - 2015-03-09 13:56 - 01483336 _____ (Microsoft Corporation) C:\Users\Justus Hoffmann\Desktop\mediacreationtool.exe
2015-03-09 12:31 - 2015-03-09 12:34 - 00000891 _____ () C:\Users\Justus Hoffmann\Desktop\Neues Textdokument.txt
2015-03-09 12:29 - 2015-03-09 12:29 - 00002530 _____ () C:\Users\Justus Hoffmann\Desktop\Lizenzen.txt
2015-03-09 12:28 - 2015-03-09 12:28 - 00380416 _____ () C:\Users\Justus Hoffmann\Desktop\s5ezzdql.exe
2015-03-09 12:25 - 2015-03-13 11:12 - 00000000 ____D () C:\FRST
2015-03-09 12:23 - 2015-03-13 11:11 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Virus
2015-03-09 12:23 - 2015-03-09 12:23 - 00000000 _____ () C:\Users\Justus Hoffmann\defogger_reenable
2015-03-09 12:20 - 2015-03-09 12:21 - 11587952 _____ (McAfee Inc) C:\Users\Justus Hoffmann\Desktop\stinger32.exe
2015-03-09 12:18 - 2015-03-09 12:19 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\LicenseCrawler
2015-03-09 12:17 - 2015-03-09 12:17 - 01393511 _____ () C:\Users\Justus Hoffmann\Desktop\licensecrawler_1.43.732.zip
2015-03-04 22:27 - 2015-03-08 17:11 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Studienarbeit
2015-03-04 10:13 - 2015-03-04 10:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-03-04 10:13 - 2015-01-28 20:49 - 00112496 ____R (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\acsock64.sys
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls
2015-02-25 12:18 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls
2015-02-25 12:18 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2015-02-25 12:18 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2015-02-17 15:26 - 2015-02-17 15:26 - 01217184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FM20.DLL
2015-02-16 09:24 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-16 09:24 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-16 09:24 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-16 09:24 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-16 09:24 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-16 09:24 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-16 09:24 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-16 09:24 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-16 09:24 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-16 09:24 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-16 09:24 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-16 09:24 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-16 09:24 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-16 09:24 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-16 09:24 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-16 09:23 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-16 09:23 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-16 09:23 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-16 09:23 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-13 11:12 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-03-13 11:11 - 2013-11-07 04:23 - 01055091 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-13 11:11 - 2012-10-03 15:32 - 00000000 ___RD () C:\Users\Justus Hoffmann\Dropbox
2015-03-13 11:11 - 2012-10-03 15:30 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Dropbox
2015-03-13 11:10 - 2013-11-07 08:40 - 00000000 __RDO () C:\Users\Justus Hoffmann\SkyDrive
2015-03-13 11:10 - 2013-11-07 01:00 - 00000401 _____ () C:\Users\Justus Hoffmann\AppData\Roaming\sp_data.sys
2015-03-13 11:10 - 2013-09-30 05:14 - 02072588 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-13 11:10 - 2013-09-30 04:56 - 00889374 _____ () C:\WINDOWS\system32\perfh007.dat
2015-03-13 11:10 - 2013-09-30 04:56 - 00205446 _____ () C:\WINDOWS\system32\perfc007.dat
2015-03-13 11:10 - 2013-08-22 15:46 - 00343124 _____ () C:\WINDOWS\setupact.log
2015-03-13 11:10 - 2012-12-02 23:43 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Skype
2015-03-13 11:10 - 2012-02-24 03:29 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-13 11:08 - 2013-09-29 20:04 - 00236212 _____ () C:\WINDOWS\PFRO.log
2015-03-13 11:08 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-13 11:01 - 2013-03-20 13:23 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-13 11:00 - 2013-08-22 16:37 - 00005217 _____ () C:\WINDOWS\DtcInstall.log
2015-03-13 11:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-13 11:00 - 2013-08-22 15:44 - 00479376 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-03-13 11:00 - 2012-02-24 03:29 - 00001148 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-13 10:59 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-13 10:58 - 2013-09-30 04:59 - 00000000 __SHD () C:\WINDOWS\BitLockerDiscoveryVolumeContents
2015-03-13 10:58 - 2013-09-30 04:59 - 00000000 ____D () C:\Program Files\Windows Journal
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ___SD () C:\WINDOWS\system32\dsc
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\sppui
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\inetsrv
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Com
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\SystemResetPlatform
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sppui
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\migwiz
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\inetsrv
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\Com
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\IME
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-03-13 10:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2015-03-13 10:58 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\oobe
2015-03-13 10:58 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2015-03-13 10:58 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2015-03-13 10:58 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2015-03-13 10:58 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Dism
2015-03-13 10:58 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\servicing
2015-03-13 10:57 - 2012-10-03 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-13 10:56 - 2009-07-14 03:34 - 00000545 _____ () C:\WINDOWS\win.ini
2015-03-13 10:42 - 2013-08-22 16:36 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2015-03-13 10:42 - 2013-08-22 16:36 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2015-03-13 10:33 - 2013-07-25 10:43 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-03-13 10:33 - 2012-10-03 16:28 - 122905848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-03-13 10:28 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-13 10:27 - 2012-10-03 16:18 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Outlook-Dateien
2015-03-13 10:23 - 2014-02-15 05:49 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Local\769A133B-0AED-452E-A98A-A2C94FEF5322.aplzod
2015-03-13 10:23 - 2012-10-16 00:46 - 00003994 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{579749A9-A7ED-4DBF-B3BE-1B7363949C56}
2015-03-12 15:43 - 2014-11-08 18:59 - 00000401 _____ () C:\Users\Andrea\AppData\Roaming\sp_data.sys
2015-03-12 09:42 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-12 00:31 - 2013-11-06 22:12 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2283723822-742349386-183045315-1001
2015-03-11 22:37 - 2012-10-03 15:32 - 00001107 _____ () C:\Users\Justus Hoffmann\Desktop\Dropbox.lnk
2015-03-11 22:37 - 2012-10-03 15:31 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-03-11 02:14 - 2012-10-03 16:50 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Local\Apple Computer
2015-03-10 00:54 - 2013-11-06 11:51 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Local\CrashDumps
2015-03-10 00:54 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-03-09 14:03 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-03-09 13:56 - 2012-12-15 13:27 - 00000000 __RHD () C:\ESD
2015-03-09 13:53 - 2014-03-22 16:30 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Citavi 4
2015-03-09 13:53 - 2013-11-07 04:18 - 00000000 ____D () C:\Users\Justus Hoffmann
2015-03-09 13:52 - 2012-10-17 17:52 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Corps
2015-03-09 13:22 - 2012-10-03 16:20 - 00000000 ____D () C:\Users\Justus Hoffmann\Documents\Uni
2015-03-08 17:02 - 2013-11-06 22:08 - 01165312 ___SH () C:\Users\Justus Hoffmann\Desktop\Thumbs.db
2015-03-04 22:24 - 2014-09-16 13:48 - 00792032 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-03-04 22:24 - 2014-09-16 13:48 - 00178144 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-04 10:13 - 2013-11-24 16:20 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-04 10:13 - 2013-11-06 23:43 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-04 10:12 - 2012-10-03 16:24 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Programme
2015-03-04 10:11 - 2014-12-04 20:56 - 00000000 ____D () C:\Users\Justus Hoffmann\Desktop\Schwerpunkt
2015-03-02 13:21 - 2012-10-03 16:19 - 00000000 ____D () C:\Users\Justus Hoffmann\AppData\Roaming\Swiss Academic Software
2015-02-20 11:21 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-13 11:55 - 2012-02-24 03:29 - 00004120 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-13 11:55 - 2012-02-24 03:29 - 00003884 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2013-11-07 08:42 - 2013-11-07 08:42 - 0000021 _____ () C:\Users\Justus Hoffmann\AppData\Roaming\my_intel.sys
2013-11-07 01:00 - 2015-03-13 11:10 - 0000401 _____ () C:\Users\Justus Hoffmann\AppData\Roaming\sp_data.sys
2014-08-05 02:05 - 2014-08-05 02:05 - 0002203 _____ () C:\Users\Justus Hoffmann\AppData\Local\Citavi Picker Internet Explorer Protocol.txt
2013-11-07 01:36 - 2013-11-07 01:38 - 0037795 _____ () C:\Users\Justus Hoffmann\AppData\Local\WiDiSetupLog.20131107.013659.wdl
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2012-10-05 14:19 - 2013-11-14 20:12 - 0003349 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\Justus Hoffmann\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgvwwpw.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-12 09:48

==================== End Of Log ============================


schrauber 14.03.2015 09:31

Das sieht schon sehr viel besser aus. Infektion ist weg, jetzt die Sticks.

WIeviele sind es? Bitte alle anklemmen, Systemsteuerung Ordnerptionen Haken raus bei geschützte Systemdateien ausblenden, und versteckte Dateien anzeigen lassen.

Kontrolliere die Sticks, du solltest jetzt einmal die Verknüpfung und einmal das Original sehen.

Oktavius 14.03.2015 10:47

Moin Moin!

Es waren glaube ich drei Sticks.
Bei dem einen sehe ich einmal die Verknüpfung und einmal die Originaldatei,
sowie die Datei "Autorun" und einen Ordner System Volume Information ( beide eigentlich versteckt)
bei den bei den beiden anderen sehe ich nur Autorun und System Value Information.

Heißt das bei den beiden letzten Sticks, dass diese nicht befallen sind??

Lg und :dankeschoen:

schrauber 14.03.2015 16:40

Wenn Du dort kein Original und Verknüpfung siehst sind die gut, einfach die autorun löschen. Bei dem anderen wie folt vorgehen:

CMD als Admin starten und folgendes eintippen

attrib -s -h E:\Datei

wobei E für den Stick steht, also anpassen. Und Datei musst Du ersetzen durch den Dateinamen inkl Endung. Dann die Zeile für jede Datei und Ordner wiederholen.

Oktavius 14.03.2015 17:12

Erledigt! :-)

Ist der PC jetzt "geheilt" ;-)??

Danke danke danke!!!

schrauber 15.03.2015 07:10

Jetzt kannst du die Verknüpfungen auf dem Stick löschen, auch die Autoruns. Dann in den Ordneroptionen wieder alles auf Original umstellen.

Fertig :)



http://deeprybka.trojaner-board.de/b...cleanupneu.png
Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
http://deeprybka.trojaner-board.de/b.../combofix2.pngCombofix deinstallieren
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte http://filepony.de/icon/tiny/delfix.pngDelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:

http://deeprybka.trojaner-board.de/b...ast/schild.png
Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.

Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank.
Meine Empfehlung:
http://filepony.de/icon/emsisoft_anti_malware.png
Emsisoft

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen.

Optional:
http://filepony.de/icon/noscript.png NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen.
http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie http://filepony.de/images/microbanner.gif.
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:56 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131