Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 09.12.2014, 20:24   #31
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



btw......ok.

Ich lass mal paar Tage laufen. und geb dann nochmal ein Feedback.

Danke für die Unterstützung.

Ich war kurz vorm....


Alt 09.12.2014, 20:31   #32
Machiavelli
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



OK
__________________

__________________

Alt 10.12.2014, 12:32   #33
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Grad noch ein Programm namens Startfenster entdeckt.....
Deinstalliert.....
nu lese ich im Forum das ich nicht der einzige bin. Software war vom 7.12.
Hab ich also mit dem Vlc-Player runtergeladen......

Reicht deinstallieren aus oder erfordert des wieder weitere Maßnamen??

So....irgendwie wird's jetzt schräg.

Wie schon erwähnt, hab ich beim aufräumen der hier benötigen Tools das mir unbekannte Startfenster entdeckt und voller Euphorie einfach deinstallieren. Wo ich es mir eingefangen habe, konnte ich hier im Blog schon rausfinden. Also den VlcPlayer auch gleich mit runtergeschmissen. So weit so gut.....erstmal nix weiter aufgefallen.
Nun begann Windows mit Updates.....hab ich laufen lassen. Installiert-Neustart-frische Updates....ok runterladen. Windows soll ja auf dem neusten Stand sein. Nach 2 weitern Neustarts, bedingt durch die Updates....würde mir wieder angezeigt "neue Updates" gefunden.
Stückzahl 187, ca. 800-900 MB, weiß i nicht mehr so genau. Mmmhhh....wenn's denn sein muss....runterladen und installieren. Und damit ging das gleiche Spiel von vorne los.

----GData-Symbol in der Taskleiste war weg....unter Anzeigeoptionen wurde mir gesagt, das Symbol wird angezeigt, sobald es wieder aktiv ist. GData selbst zeigte mir keinen Fehler und alle Wächter an Virensignaturen aktuell.....
Ca. 2 Std später....Update fast fertig beginnt der Laptop zu arbeiten....
Da waren sie wieder diese Hintergrunddienste.
Momentane Probleme: GDatasymbol nicht aktiv-GData selbst sagt mir alles okay
Trotz ausschalten des W-Lan am Laptop zeigt mir GData eine aktive Internetverbindung über Lan mit einer mir unbekannten IP....über diese war etwas später auch das von mir ausgeschaltete W-Lan am Laptop verbunden-IP änderte sich in unregelmäßigen Abständen. Rechner arbeitete von Min zu Min mehr....
Also trennte ich mit meinem Handy via RouterIP die Internetverbindung direkt im Router. Promt hat mich der Router aus dem W-Lan verbannt....Neuverbindung nur mit eingabe des Routerpin.....hab ich nicht gemacht....ist im Handy gespeichert und verbindet sich normalerweise automatisch. Versuch mit dem Tablet-ebenso erfolglos. Blieb mir nur noch, den Router den Stecker zu ziehen. Nach dem er neu gestartet hat....Handy/Tablet wieder ganz normal verbunden. Laptop weiß ich nicht....fasse ich vorerst nicht an.

Nützt alles nix....der DRECK muss weg!!!

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 11:14 on 10/12/2014 (srsrsrsfser3)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         
#

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-12-2014 02
Ran by srsrsrsfser3 (administrator) on SRSRSRSFSER3-PC on 10-12-2014 11:16:11
Running from C:\Users\srsrsrsfser3\Desktop
Loaded Profiles: srsrsrsfser3 & UpdatusUser (Available profiles: srsrsrsfser3 & UpdatusUser)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(G Data Software AG) C:\Program Files (x86)\G DATA\TotalProtection\AVK\AVKWCtlx64.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G DATA\TotalProtection\AVK\AVKService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(G Data Software AG) C:\Program Files (x86)\G DATA\TotalProtection\AVKBackup\AVKBackupService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(G Data Software AG) C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFwSvcx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(G Data Software AG) C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM-x32\...\Run: [DpAgent] => C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe [842816 2009-07-01] (DigitalPersona, Inc.)
HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [320056 2009-06-24] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe [1756792 2014-05-20] (G Data Software AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Java\jre1.8.0_25\bin\jusched.exe"
HKLM-x32\...\Run: [G Data ASM] => C:\Program Files (x86)\G DATA\TotalProtection\DelayLoader\AutorunDelayLoader.exe [431224 2013-12-19] (G Data Software AG)
HKU\S-1-5-21-2386857783-215228460-2573036698-1001\...\Policies\system: [WallpaperStyle] 2
Lsa: [Notification Packages] scecli DPPWDFLT
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2386857783-215228460-2573036698-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2386857783-215228460-2573036698-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_DE&c=94&bd=Pavilion&pf=cnnb
HKU\S-1-5-21-2386857783-215228460-2573036698-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome_first&locale=de_DE&c=94&bd=Pavilion&pf=cnnb
HKU\S-1-5-21-2386857783-215228460-2573036698-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_DE&c=94&bd=Pavilion&pf=cnnb
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2386857783-215228460-2573036698-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: DigitalPersona Personal Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DigitalPersona Personal Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default
FF Homepage: https://www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31010.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31010.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Extension: DOM Inspector - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\inspector@mozilla.org [2014-12-07]
FF Extension: DownloadHelper - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-12-07]
FF Extension: CSHelper - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\{d91a2be6-3b56-4dfb-97f5-5e48fe3ed473} [2014-12-07]
FF Extension: Firebug - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\firebug@software.joehewitt.com.xpi [2014-12-07]
FF Extension: Ghostery - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\firefox@ghostery.com.xpi [2014-12-07]
FF Extension: Web Developer - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2014-12-07]
FF Extension: Adblock Plus - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-07]
FF Extension: DownThemAll! - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-12-07]
FF Extension: Adblock Edge - C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla\Firefox\Profiles\9d0j8mdd.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-12-07]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt [2014-12-07]
         
Code:
ATTFilter
FF HKU\S-1-5-21-2386857783-215228460-2573036698-1000\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\firefoxext

Chrome: 
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [72192 2009-07-14] (Microsoft Corporation) [File not signed]
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation) [File not signed]
S3 ALG; C:\Windows\System32\alg.exe [79360 2009-07-14] (Microsoft Corporation) [File not signed]
S3 AppIDSvc; C:\Windows\System32\appidsvc.dll [32256 2009-07-14] (Microsoft Corporation) [File not signed]
R3 Appinfo; C:\Windows\System32\appinfo.dll [70144 2013-02-27] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [680960 2014-10-03] (Microsoft Corporation) [File not signed]
R2 AudioSrv; C:\Windows\System32\Audiosrv.dll [680960 2014-10-03] (Microsoft Corporation) [File not signed]
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G DATA\TotalProtection\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G DATA\TotalProtection\AVK\AVKWCtlx64.exe [2683760 2014-05-20] (G Data Software AG)
S3 AxInstSV; C:\Windows\System32\AxInstSV.dll [114688 2010-11-20] (Microsoft Corporation) [File not signed]
S3 BDESVC; C:\Windows\System32\bdesvc.dll [100864 2009-07-14] (Microsoft Corporation) [File not signed]
R2 BFE; C:\Windows\System32\bfe.dll [705024 2010-11-20] (Microsoft Corporation) [File not signed]
R3 BITS; C:\Windows\System32\qmgr.dll [849920 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Browser; C:\Windows\System32\browser.dll [136704 2012-07-04] (Microsoft Corporation) [File not signed]
S3 bthserv; C:\Windows\system32\bthserv.dll [83968 2009-07-14] (Microsoft Corporation) [File not signed]
S3 CertPropSvc; C:\Windows\System32\certprop.dll [80384 2010-11-20] (Microsoft Corporation) [File not signed]
S3 COMSysApp; C:\Windows\system32\dllhost.exe [9728 2009-07-14] (Microsoft Corporation) [File not signed]
S3 COMSysApp; C:\Windows\SysWOW64\dllhost.exe [7168 2009-07-14] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [187904 2014-07-07] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\Windows\SysWOW64\cryptsvc.dll [143872 2014-07-07] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [512000 2010-11-20] (Microsoft Corporation) [File not signed]
S3 defragsvc; C:\Windows\System32\defragsvc.dll [291328 2009-07-14] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\system32\dhcpcore.dll [317952 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\SysWOW64\dhcpcore.dll [254464 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Dnscache; C:\Windows\System32\dnsrslvr.dll [183296 2011-03-03] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [252416 2010-11-20] (Microsoft Corporation) [File not signed]
R2 DpHost; C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe [322624 2009-07-01] (DigitalPersona, Inc.) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [162816 2010-11-20] (Microsoft Corporation) [File not signed]
R3 EapHost; C:\Windows\System32\eapsvc.dll [111104 2009-07-14] (Microsoft Corporation) [File not signed]
S3 EFS; C:\Windows\System32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed]
R2 ehRecvr; C:\Windows\ehome\ehRecvr.exe [696832 2010-11-20] (Microsoft Corporation) [File not signed]
S2 ehSched; C:\Windows\ehome\ehsched.exe [127488 2009-07-14] (Microsoft Corporation) [File not signed]
R2 eventlog; C:\Windows\System32\wevtsvc.dll [1646080 2010-11-20] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\system32\es.dll [402944 2009-07-14] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\SysWOW64\es.dll [271360 2009-07-14] (Microsoft Corporation) [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129584 2009-02-22] (EasyBits Sofware AS) [File not signed]
S3 Fax; C:\Windows\system32\fxssvc.exe [689152 2010-11-20] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\Windows\system32\fdPHost.dll [16384 2009-07-14] (Microsoft Corporation) [File not signed]
R2 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2009-07-14] (Microsoft Corporation) [File not signed]
R2 FontCache; C:\Windows\system32\FntCache.dll [1175552 2014-12-10] (Microsoft Corporation) [File not signed]
R2 GDBackupSvc; C:\Program Files (x86)\G DATA\TotalProtection\AVKBackup\AVKBackupService.exe [3844216 2014-08-21] (G Data Software AG)
R3 GDFwSvc; C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFwSvcx64.exe [3228136 2014-08-21] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
S3 GDTunerSvc; C:\Program Files (x86)\G DATA\TotalProtection\AVKTuner\AVKTunerService.exe [1637496 2014-05-28] (G Data Software AG)
R2 gpsvc; C:\Windows\System32\gpsvc.dll [777728 2010-11-20] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\Windows\system32\hidserv.dll [38912 2009-07-14] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\Windows\SysWOW64\hidserv.dll [49152 2009-07-14] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\Windows\system32\kmsvc.dll [90624 2010-11-20] (Microsoft Corporation) [File not signed]
S3 HomeGroupListener; C:\Windows\system32\ListSvc.dll [232448 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\Windows\system32\provsvc.dll [187904 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\Windows\SysWOW64\provsvc.dll [165376 2010-11-20] (Microsoft Corporation) [File not signed]
R2 HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [124928 2009-07-09] (Hewlett-Packard) [File not signed]
S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [114688 2014-12-10] (Microsoft Corporation) [File not signed]
S3 IKEEXT; C:\Windows\System32\ikeext.dll [859648 2013-10-12] (Microsoft Corporation) [File not signed]
S3 IPBusEnum; C:\Windows\system32\ipbusenum.dll [101888 2009-07-14] (Microsoft Corporation) [File not signed]
R2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [569344 2012-10-03] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed]
S3 KtmRm; C:\Windows\system32\msdtckrm.dll [368640 2009-07-14] (Microsoft Corporation) [File not signed]
R2 LanmanServer; C:\Windows\system32\srvsvc.dll [236032 2010-11-20] (Microsoft Corporation) [File not signed]
R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [118784 2010-11-20] (Microsoft Corporation) [File not signed]
S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [300032 2009-07-14] (Microsoft Corporation) [File not signed]
R2 lmhosts; C:\Windows\System32\lmhsvc.dll [23552 2009-07-14] (Microsoft Corporation) [File not signed]
S4 Mcx2Svc; C:\Windows\system32\Mcx2Svc.dll [84992 2010-11-20] (Microsoft Corporation) [File not signed]
R2 MMCSS; C:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation) [File not signed]
R2 MpsSvc; C:\Windows\system32\mpssvc.dll [828416 2010-11-20] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [141824 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MSiSCSI; C:\Windows\system32\iscsiexe.dll [156672 2009-07-14] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\System32\msiexec.exe [128000 2010-11-20] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\SysWOW64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 napagent; C:\Windows\system32\qagentRT.dll [476160 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed]
R3 Netman; C:\Windows\System32\netman.dll [360448 2009-07-14] (Microsoft Corporation) [File not signed]
R3 netprofm; C:\Windows\System32\netprofm.dll [459776 2009-07-14] (Microsoft Corporation) [File not signed]
R3 netprofm; C:\Windows\SysWOW64\netprofm.dll [360448 2009-07-14] (Microsoft Corporation) [File not signed]
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [303104 2012-10-03] (Microsoft Corporation) [File not signed]
R2 nsi; C:\Windows\system32\nsisvc.dll [25600 2009-07-14] (Microsoft Corporation) [File not signed]
S3 p2pimsvc; C:\Windows\system32\pnrpsvc.dll [327168 2009-07-14] (Microsoft Corporation) [File not signed]
S3 p2psvc; C:\Windows\system32\p2psvc.dll [438784 2009-07-14] (Microsoft Corporation) [File not signed]
R2 PcaSvc; C:\Windows\System32\pcasvc.dll [186368 2009-07-14] (Microsoft Corporation) [File not signed]
S3 PerfHost; C:\Windows\SysWow64\perfhost.exe [20992 2009-07-14] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1389056 2010-11-20] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\SysWOW64\pla.dll [1508864 2010-11-20] (Microsoft Corporation) [File not signed]
R2 PlugPlay; C:\Windows\system32\umpnpmgr.dll [404480 2011-05-24] (Microsoft Corporation) [File not signed]
S3 PNRPAutoReg; C:\Windows\system32\pnrpauto.dll [25088 2009-07-14] (Microsoft Corporation) [File not signed]
S3 PNRPsvc; C:\Windows\system32\pnrpsvc.dll [327168 2009-07-14] (Microsoft Corporation) [File not signed]
S3 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [501248 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Power; C:\Windows\system32\umpo.dll [163840 2009-07-14] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [209920 2012-05-01] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\system32\qwave.dll [242688 2009-07-14] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [99328 2009-07-14] (Microsoft Corporation) [File not signed]
S3 RasMan; C:\Windows\System32\rasmans.dll [344064 2010-11-20] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\System32\mprdim.dll [97792 2009-07-14] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\SysWOW64\mprdim.dll [75264 2009-07-14] (Microsoft Corporation) [File not signed]
S3 RemoteRegistry; C:\Windows\system32\regsvc.dll [159232 2009-07-14] (Microsoft Corporation) [File not signed]
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-01-21] ()
R2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [67072 2009-07-14] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\Windows\system32\locator.exe [10240 2009-07-14] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\Windows\system32\rpcss.dll [512000 2010-11-20] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\Windows\System32\SCardSvr.dll [190976 2009-07-14] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\Windows\system32\schedsvc.dll [1110016 2010-11-20] (Microsoft Corporation) [File not signed]
         
Code:
ATTFilter
S3 SCPolicySvc; C:\Windows\System32\certprop.dll [80384 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [170496 2010-11-20] (Microsoft Corporation) [File not signed]
S3 seclogon; C:\Windows\system32\seclogon.dll [30720 2010-11-20] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [64512 2009-07-14] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\SysWOW64\sens.dll [49664 2009-07-14] (Microsoft Corporation) [File not signed]
S3 SensrSvc; C:\Windows\system32\sensrsvc.dll [29184 2009-07-14] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\system32\sessenv.dll [121856 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\SysWOW64\sessenv.dll [113664 2010-11-20] (Microsoft Corporation) [File not signed]
S4 SharedAccess; C:\Windows\System32\ipnathlp.dll [359424 2009-07-14] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [370688 2010-11-20] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\SysWOW64\shsvcs.dll [328192 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [14336 2009-07-14] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\Windows\System32\spoolsv.exe [559104 2010-11-20] (Microsoft Corporation) [File not signed]
S2 sppsvc; C:\Windows\system32\sppsvc.exe [3524608 2010-11-20] (Microsoft Corporation) [File not signed]
S3 sppuinotify; C:\Windows\system32\sppuinotify.dll [65536 2009-07-14] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [193024 2009-07-14] (Microsoft Corporation) [File not signed]
S3 SstpSvc; C:\Windows\system32\sstpsvc.dll [75264 2009-07-14] (Microsoft Corporation) [File not signed]
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe [247808 2010-03-23] (IDT, Inc.) [File not signed]
S2 stisvc; C:\Windows\System32\wiaservc.dll [580096 2010-11-20] (Microsoft Corporation) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [524288 2009-07-14] (Microsoft Corporation) [File not signed]
R2 SysMain; C:\Windows\system32\sysmain.dll [1743360 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TabletInputService; C:\Windows\System32\TabSvc.dll [92672 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TapiSrv; C:\Windows\System32\tapisrv.dll [316928 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TapiSrv; C:\Windows\SysWOW64\tapisrv.dll [242176 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TBS; C:\Windows\System32\tbssvc.dll [65536 2009-07-14] (Microsoft Corporation) [File not signed]
R2 TermService; C:\Windows\System32\termsrv.dll [683520 2014-10-14] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2009-07-14] (Microsoft Corporation) [File not signed]
S3 THREADORDER; C:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\Windows\System32\trkwks.dll [119808 2009-07-14] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [194048 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TSNxGService; C:\Program Files (x86)\G DATA\TotalProtection\TSNxG\TSNxGService.exe [255608 2014-07-01] (G DATA Software)
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [40960 2009-07-14] (Microsoft Corporation) [File not signed]
R3 upnphost; C:\Windows\System32\upnphost.dll [353792 2009-07-14] (Microsoft Corporation) [File not signed]
R3 upnphost; C:\Windows\SysWOW64\upnphost.dll [266752 2009-07-14] (Microsoft Corporation) [File not signed]
R2 UxSms; C:\Windows\System32\uxsms.dll [38912 2009-07-14] (Microsoft Corporation) [File not signed]
S3 VaultSvc; C:\Windows\system32\lsass.exe [31232 2014-04-12] (Microsoft Corporation) [File not signed]
R3 vds; C:\Windows\System32\vds.exe [533504 2010-11-20] (Microsoft Corporation) [File not signed]
S3 VSS; C:\Windows\system32\vssvc.exe [1600512 2010-11-20] (Microsoft Corporation) [File not signed]
S3 W32Time; C:\Windows\system32\w32time.dll [381952 2009-07-14] (Microsoft Corporation) [File not signed]
S3 wbengine; C:\Windows\system32\wbengine.exe [1504256 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WbioSrvc; C:\Windows\System32\wbiosrvc.dll [202240 2009-07-14] (Microsoft Corporation) [File not signed]
S3 wcncsvc; C:\Windows\System32\wcncsvc.dll [367104 2010-11-20] (Microsoft Corporation) [File not signed]
S3 wcncsvc; C:\Windows\SysWOW64\wcncsvc.dll [276992 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [40960 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\SysWOW64\WcsPlugInService.dll [32768 2009-07-14] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [90624 2009-07-14] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\SysWOW64\wdi.dll [76288 2009-07-14] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [90624 2009-07-14] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\SysWOW64\wdi.dll [76288 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WebClient; C:\Windows\System32\webclnt.dll [259584 2013-07-04] (Microsoft Corporation) [File not signed]
S3 WebClient; C:\Windows\SysWOW64\webclnt.dll [205824 2013-07-04] (Microsoft Corporation) [File not signed]
S3 Wecsvc; C:\Windows\system32\wecsvc.dll [237568 2009-07-14] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\Windows\System32\wercplsupport.dll [84480 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WerSvc; C:\Windows\System32\WerSvc.dll [76800 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) [File not signed]
R3 WinHttpAutoProxySvc; C:\Windows\system32\winhttp.dll [444416 2010-11-20] (Microsoft Corporation) [File not signed]
R3 WinHttpAutoProxySvc; C:\Windows\SysWOW64\winhttp.dll [351232 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [242688 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\system32\WsmSvc.dll [2020352 2014-10-03] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\SysWOW64\WsmSvc.dll [1177088 2014-10-03] (Microsoft Corporation) [File not signed]
R2 Wlansvc; C:\Windows\System32\wlansvc.dll [886784 2009-07-14] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [203264 2009-07-14] (Microsoft Corporation) [File not signed]
R2 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1525248 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [12288 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\SysWOW64\wpcsvc.dll [10752 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WPDBusEnum; C:\Windows\system32\wpdbusenum.dll [117248 2010-11-20] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\Windows\system32\wscsvc.dll [97280 2009-07-14] (Microsoft Corporation) [File not signed]
R2 WSearch; C:\Windows\system32\SearchIndexer.exe [591872 2011-05-04] (Microsoft Corporation) [File not signed]
R2 WSearch; C:\Windows\SysWOW64\SearchIndexer.exe [427520 2011-05-04] (Microsoft Corporation) [File not signed]
R3 wudfsvc; C:\Windows\System32\WUDFSvc.dll [84992 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WwanSvc; C:\Windows\System32\wwansvc.dll [228864 2014-01-28] (Microsoft Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 1394ohci; C:\Windows\system32\drivers\1394ohci.sys [229888 2010-11-20] (Microsoft Corporation) [File not signed]
S3 AcpiPmi; C:\Windows\system32\drivers\acpipmi.sys [12800 2010-11-20] (Microsoft Corporation) [File not signed]
R1 AFD; C:\Windows\system32\drivers\afd.sys [497152 2014-05-30] (Microsoft Corporation) [File not signed]
S3 AgereSoftModem; C:\Windows\System32\DRIVERS\agrsm64.sys [1146880 2009-06-10] (LSI Corp) [File not signed]
S3 AmdK8; C:\Windows\system32\DRIVERS\amdk8.sys [64512 2009-07-14] (Microsoft Corporation) [File not signed]
S3 AmdPPM; C:\Windows\system32\DRIVERS\amdppm.sys [60928 2009-07-14] (Microsoft Corporation) [File not signed]
S3 AppID; C:\Windows\system32\drivers\appid.sys [61440 2010-11-20] (Microsoft Corporation) [File not signed]
S3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [23040 2009-07-14] (Microsoft Corporation) [File not signed]
R3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [311424 2009-05-22] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
S3 b06bdrv; C:\Windows\system32\DRIVERS\bxvbda.sys [468480 2009-06-10] (Broadcom Corporation) [File not signed]
S3 b57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [270848 2009-06-10] (Broadcom Corporation) [File not signed]
R1 Beep; C:\Windows\System32\Drivers\Beep.sys [6656 2009-07-14] (Microsoft Corporation) [File not signed]
R1 blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [45056 2009-07-14] (Microsoft Corporation) [File not signed]
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [90624 2011-02-23] (Microsoft Corporation) [File not signed]
S3 BrFiltLo; C:\Windows\system32\DRIVERS\BrFiltLo.sys [18432 2009-06-10] (Brother Industries, Ltd.) [File not signed]
S3 BrFiltUp; C:\Windows\system32\DRIVERS\BrFiltUp.sys [8704 2009-06-10] (Brother Industries, Ltd.) [File not signed]
S3 Brserid; C:\Windows\System32\Drivers\Brserid.sys [286720 2009-07-14] (Brother Industries Ltd.) [File not signed]
S3 BrSerWdm; C:\Windows\System32\Drivers\BrSerWdm.sys [47104 2009-06-10] (Brother Industries Ltd.) [File not signed]
S3 BrUsbMdm; C:\Windows\System32\Drivers\BrUsbMdm.sys [14976 2009-06-10] (Brother Industries Ltd.) [File not signed]
S3 BrUsbSer; C:\Windows\System32\Drivers\BrUsbSer.sys [14720 2009-06-10] (Brother Industries Ltd.) [File not signed]
S3 BthEnum; C:\Windows\system32\drivers\BthEnum.sys [41984 2009-07-14] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\system32\DRIVERS\bthmodem.sys [72192 2009-07-14] (Microsoft Corporation) [File not signed]
S3 BthPan; C:\Windows\System32\DRIVERS\bthpan.sys [118784 2009-07-14] (Microsoft Corporation) [File not signed]
S3 BTHPORT; C:\Windows\System32\Drivers\BTHport.sys [552448 2010-11-20] (Microsoft Corporation) [File not signed]
S3 BTHUSB; C:\Windows\System32\Drivers\BTHUSB.sys [80384 2010-11-20] (Microsoft Corporation) [File not signed]
S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [92160 2009-07-14] (Microsoft Corporation) [File not signed]
R1 cdrom; C:\Windows\system32\drivers\cdrom.sys [147456 2010-11-20] (Microsoft Corporation) [File not signed]
R3 circlass; C:\Windows\System32\DRIVERS\circlass.sys [45568 2009-07-14] (Microsoft Corporation) [File not signed]
R3 CmBatt; C:\Windows\system32\DRIVERS\CmBatt.sys [17664 2009-07-14] (Microsoft Corporation) [File not signed]
R3 CompositeBus; C:\Windows\system32\drivers\CompositeBus.sys [38912 2010-11-20] (Microsoft Corporation) [File not signed]
R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [102400 2010-11-20] (Microsoft Corporation) [File not signed]
R1 discache; C:\Windows\System32\drivers\discache.sys [40448 2009-07-14] (Microsoft Corporation) [File not signed]
S3 drmkaud; C:\Windows\system32\drivers\drmkaud.sys [5632 2009-07-14] (Microsoft Corporation) [File not signed]
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) [File not signed]
         
Code:
ATTFilter
R3 enecir; C:\Windows\System32\DRIVERS\enecir.sys [70656 2009-06-29] (ENE TECHNOLOGY INC.) [File not signed]
S3 ErrDev; C:\Windows\system32\drivers\errdev.sys [9728 2009-07-14] (Microsoft Corporation) [File not signed]
S3 exfat; C:\Windows\System32\Drivers\exfat.sys [195072 2009-07-14] (Microsoft Corporation) [File not signed]
R3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [204800 2009-07-14] (Microsoft Corporation) [File not signed]
S3 fdc; C:\Windows\system32\DRIVERS\fdc.sys [29696 2009-07-14] (Microsoft Corporation) [File not signed]
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [34304 2009-07-14] (Microsoft Corporation) [File not signed]
S3 flpydisk; C:\Windows\system32\DRIVERS\flpydisk.sys [24576 2009-07-14] (Microsoft Corporation) [File not signed]
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-12-07] (G Data Software AG)
R3 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-12-07] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-12-07] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-12-07] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64512 2014-12-07] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-12-07] (G Data Software)
S3 hcw85cir; C:\Windows\system32\drivers\hcw85cir.sys [31232 2009-06-10] (Hauppauge Computer Works, Inc.) [File not signed]
S3 HdAudAddService; C:\Windows\system32\drivers\HdAudio.sys [350208 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HDAudBus; C:\Windows\system32\drivers\HDAudBus.sys [122368 2010-11-20] (Microsoft Corporation) [File not signed]
S3 HidBatt; C:\Windows\system32\DRIVERS\HidBatt.sys [26624 2009-07-14] (Microsoft Corporation) [File not signed]
S3 HidBth; C:\Windows\system32\DRIVERS\hidbth.sys [100864 2009-07-14] (Microsoft Corporation) [File not signed]
R3 HidIr; C:\Windows\System32\DRIVERS\hidir.sys [46592 2009-07-14] (Microsoft Corporation) [File not signed]
R3 HidUsb; C:\Windows\system32\drivers\hidusb.sys [30208 2010-11-20] (Microsoft Corporation) [File not signed]
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-12-07] (G Data Software AG)
R3 HpqKbFiltr; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [18432 2009-04-29] (Hewlett-Packard Development Company, L.P.) [File not signed]
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [753664 2010-11-20] (Microsoft Corporation) [File not signed]
R3 i8042prt; C:\Windows\system32\drivers\i8042prt.sys [105472 2009-07-14] (Microsoft Corporation) [File not signed]
S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [6108416 2009-06-10] (Intel Corporation) [File not signed]
R3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [62464 2009-07-14] (Microsoft Corporation) [File not signed]
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [82944 2010-11-20] (Microsoft Corporation) [File not signed]
S3 IPMIDRV; C:\Windows\system32\drivers\IPMIDrv.sys [78848 2010-11-20] (Microsoft Corporation) [File not signed]
S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [116224 2009-07-14] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [17920 2009-07-14] (Microsoft Corporation) [File not signed]
R3 JMCR; C:\Windows\System32\DRIVERS\jmcr.sys [140712 2009-07-21] (JMicron Technology Corporation) [File not signed]
R3 kbdhid; C:\Windows\system32\drivers\kbdhid.sys [33280 2010-11-20] (Microsoft Corporation) [File not signed]
R3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-14] (Microsoft Corporation) [File not signed]
R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [60928 2009-07-14] (Microsoft Corporation) [File not signed]
R2 luafv; C:\Windows\system32\drivers\luafv.sys [113152 2009-07-14] (Microsoft Corporation) [File not signed]
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [49264 2014-07-28] (Visicom Media Inc.)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35440 2014-05-13] (Visicom Media Inc.)
S3 Modem; C:\Windows\System32\drivers\modem.sys [40448 2009-07-14] (Microsoft Corporation) [File not signed]
R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [30208 2009-07-14] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [31232 2009-07-14] (Microsoft Corporation) [File not signed]
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [77312 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [140800 2013-07-04] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [158208 2011-04-27] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [288768 2011-07-09] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [128000 2011-04-27] (Microsoft Corporation) [File not signed]
R1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [26112 2009-07-14] (Microsoft Corporation) [File not signed]
S3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [8192 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [11136 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [7168 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [6784 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [8064 2009-07-14] (Microsoft Corporation) [File not signed]
S3 MTConfig; C:\Windows\system32\DRIVERS\MTConfig.sys [15360 2009-07-14] (Microsoft Corporation) [File not signed]
R3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [318976 2009-07-14] (Microsoft Corporation) [File not signed]
S3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [35328 2009-07-14] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [24064 2009-07-14] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [56832 2010-11-20] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [164352 2010-11-20] (Microsoft Corporation) [File not signed]
R3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [57856 2010-11-20] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [44544 2009-07-14] (Microsoft Corporation) [File not signed]
R1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [261632 2010-11-20] (Microsoft Corporation) [File not signed]
R3 NETw5s64; C:\Windows\System32\DRIVERS\NETw5s64.sys [7675392 2010-01-13] (Intel Corporation) [File not signed]
S3 netw5v64; C:\Windows\System32\DRIVERS\netw5v64.sys [5435904 2009-07-23] (Intel Corporation) [File not signed]
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [44032 2009-07-14] (Microsoft Corporation) [File not signed]
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [24576 2009-07-14] (Microsoft Corporation) [File not signed]
R1 Null; C:\Windows\System32\Drivers\Null.sys [6144 2009-07-14] (Microsoft Corporation) [File not signed]
S3 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [72832 2009-07-14] (Microsoft Corporation) [File not signed]
S3 Parport; C:\Windows\system32\DRIVERS\parport.sys [97280 2009-07-14] (Microsoft Corporation) [File not signed]
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [651264 2009-07-14] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [111104 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Processor; C:\Windows\system32\DRIVERS\processr.sys [60416 2009-07-14] (Microsoft Corporation) [File not signed]
R1 Psched; C:\Windows\System32\DRIVERS\pacer.sys [131584 2010-11-20] (Microsoft Corporation) [File not signed]
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [46592 2009-07-14] (Microsoft Corporation) [File not signed]
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [14848 2009-07-14] (Microsoft Corporation) [File not signed]
R3 RasAgileVpn; C:\Windows\System32\DRIVERS\AgileVpn.sys [60416 2009-07-14] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [129536 2010-11-20] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [92672 2009-07-14] (Microsoft Corporation) [File not signed]
R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [83968 2009-07-14] (Microsoft Corporation) [File not signed]
R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [309248 2010-11-20] (Microsoft Corporation) [File not signed]
S3 rdpbus; C:\Windows\system32\DRIVERS\rdpbus.sys [24064 2009-07-14] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [7680 2009-07-14] (Microsoft Corporation) [File not signed]
R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [7680 2009-07-14] (Microsoft Corporation) [File not signed]
R1 RDPREFMP; C:\Windows\System32\drivers\rdprefmp.sys [8192 2009-07-14] (Microsoft Corporation) [File not signed]
S3 RDPWD; C:\Windows\System32\Drivers\RDPWD.sys [212480 2014-07-17] (Microsoft Corporation) [File not signed]
S3 RFCOMM; C:\Windows\System32\DRIVERS\rfcomm.sys [158720 2009-07-14] (Microsoft Corporation) [File not signed]
R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [76800 2009-07-14] (Microsoft Corporation) [File not signed]
R3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [233472 2009-07-13] (Realtek                                            ) [File not signed]
S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [29696 2010-11-20] (Microsoft Corporation) [File not signed]
S3 sdbus; C:\Windows\system32\drivers\sdbus.sys [109056 2010-11-20] (Microsoft Corporation) [File not signed]
R2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [23040 2009-06-10] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 Serenum; C:\Windows\system32\DRIVERS\serenum.sys [23552 2009-07-14] (Microsoft Corporation) [File not signed]
S1 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) [File not signed]
S3 sermouse; C:\Windows\system32\DRIVERS\sermouse.sys [26624 2009-07-14] (Microsoft Corporation) [File not signed]
S3 sffdisk; C:\Windows\system32\drivers\sffdisk.sys [14336 2009-07-14] (Microsoft Corporation) [File not signed]
S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [13824 2009-07-14] (Microsoft Corporation) [File not signed]
S3 sffp_sd; C:\Windows\system32\drivers\sffp_sd.sys [14336 2010-11-20] (Microsoft Corporation) [File not signed]
S3 sfloppy; C:\Windows\system32\DRIVERS\sfloppy.sys [16896 2009-07-14] (Microsoft Corporation) [File not signed]
S3 Smb; C:\Windows\System32\DRIVERS\smb.sys [93184 2009-07-14] (Microsoft Corporation) [File not signed]
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [467456 2011-04-29] (Microsoft Corporation) [File not signed]
R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [410112 2011-04-29] (Microsoft Corporation) [File not signed]
S3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Conexant Systems, Inc.) [File not signed]
S3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Conexant Systems, Inc.) [File not signed]
S3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Conexant Systems, Inc.) [File not signed]
R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [168448 2011-04-29] (Microsoft Corporation) [File not signed]
R3 STHDA; C:\Windows\System32\DRIVERS\stwrt64.sys [505344 2010-03-23] (IDT, Inc.) [File not signed]
         
__________________

Alt 10.12.2014, 12:36   #34
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Code:
ATTFilter
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [45568 2012-10-03] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [15872 2009-07-14] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [23552 2012-02-17] (Microsoft Corporation) [File not signed]
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [119296 2014-11-11] (Microsoft Corporation) [File not signed]
R0 TS4NT; C:\Windows\System32\Drivers\TS4nt.sys [98760 2014-12-07] (G Data Software)
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [39936 2014-07-17] (Microsoft Corporation) [File not signed]
S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [59392 2010-11-20] (Microsoft Corporation) [File not signed]
R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [125440 2010-11-20] (Microsoft Corporation) [File not signed]
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [328192 2010-11-20] (Microsoft Corporation) [File not signed]
R3 umbus; C:\Windows\system32\drivers\umbus.sys [48640 2010-11-20] (Microsoft Corporation) [File not signed]
S3 UmPass; C:\Windows\system32\DRIVERS\umpass.sys [9728 2009-07-14] (Microsoft Corporation) [File not signed]
R3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [99840 2013-11-27] (Microsoft Corporation) [File not signed]
S3 usbcir; C:\Windows\system32\drivers\usbcir.sys [100864 2013-07-12] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\Windows\system32\drivers\usbehci.sys [53248 2013-11-27] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [343040 2013-11-27] (Microsoft Corporation) [File not signed]
S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2013-11-27] (Microsoft Corporation) [File not signed]
S3 usbprint; C:\Windows\system32\DRIVERS\usbprint.sys [25088 2009-07-14] (Microsoft Corporation) [File not signed]
S3 USBSTOR; C:\Windows\system32\drivers\USBSTOR.SYS [91648 2010-11-20] (Microsoft Corporation) [File not signed]
S3 usbuhci; C:\Windows\system32\drivers\usbuhci.sys [30720 2013-11-27] (Microsoft Corporation) [File not signed]
R3 usbvideo; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation) [File not signed]
S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [29184 2009-07-14] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\Windows\System32\drivers\vga.sys [29184 2009-07-14] (Microsoft Corporation) [File not signed]
R3 vwifibus; C:\Windows\System32\DRIVERS\vwifibus.sys [24576 2009-07-14] (Microsoft Corporation) [File not signed]
R1 vwififlt; C:\Windows\System32\DRIVERS\vwififlt.sys [59904 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WacomPen; C:\Windows\system32\DRIVERS\wacompen.sys [27776 2009-07-14] (Microsoft Corporation) [File not signed]
S3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-20] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-20] (Microsoft Corporation) [File not signed]
R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [12800 2009-07-14] (Microsoft Corporation) [File not signed]
R3 WinUSB; C:\Windows\System32\DRIVERS\WinUSB.sys [41984 2010-11-20] (Microsoft Corporation) [File not signed]
R3 WmiAcpi; C:\Windows\system32\drivers\wmiacpi.sys [14336 2009-07-14] (Microsoft Corporation) [File not signed]
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [21504 2009-07-14] (Microsoft Corporation) [File not signed]
R3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [87040 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) [File not signed]
S3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [389120 2009-06-10] (Marvell) [File not signed]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2009-07-23] (CyberLink Corp.)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-10 11:16 - 2014-12-10 11:16 - 00051990 _____ () C:\Users\srsrsrsfser3\Desktop\FRST.txt
2014-12-10 11:16 - 2014-12-10 11:16 - 00000000 ____D () C:\FRST
2014-12-10 11:14 - 2014-12-10 11:14 - 00000486 _____ () C:\Users\srsrsrsfser3\Desktop\defogger_disable.log
2014-12-10 11:14 - 2014-12-10 11:14 - 00000000 _____ () C:\Users\srsrsrsfser3\defogger_reenable
2014-12-10 07:07 - 2014-12-10 07:07 - 00000000 ____D () C:\Users\srsrsrsfser3\Documents\Fax
2014-12-10 04:53 - 2014-12-10 07:34 - 00000000 ____D () C:\Users\srsrsrsfser3\Desktop\beteiligtachtung
2014-12-10 02:20 - 2014-12-10 02:20 - 01559996 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-12-10 01:21 - 2014-12-10 01:21 - 00000085 _____ () C:\Windows\wininit.ini
2014-12-10 01:17 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-12-10 01:12 - 2014-12-09 18:32 - 00000855 _____ () C:\Windows\system32\Drivers\etc\hosts.20141210-011259.backup
2014-12-10 01:05 - 2014-12-10 01:05 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-10 01:05 - 2014-12-10 01:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-10 01:05 - 2014-12-10 01:05 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-10 01:05 - 2014-12-10 01:05 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-10 01:05 - 2014-12-10 01:05 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-12-10 01:05 - 2014-12-10 01:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-12-10 01:05 - 2014-12-10 01:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-12-10 01:05 - 2014-12-10 01:05 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-12-10 01:05 - 2014-12-10 01:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-12-10 01:05 - 2014-12-10 01:05 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-12-10 01:05 - 2014-12-10 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-12-10 01:05 - 2014-12-10 01:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-12-10 01:05 - 2014-12-10 01:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-10 00:53 - 2014-12-10 00:53 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-09 23:32 - 2014-12-09 23:32 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Oracle
2014-12-09 23:22 - 2014-12-10 11:15 - 00000000 ____D () C:\Users\srsrsrsfser3\Desktop\Neuer Ordner
2014-12-09 23:22 - 2014-12-09 23:24 - 00000000 ____D () C:\ProgramData\Oracle
2014-12-09 23:22 - 2014-12-09 23:22 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-12-09 23:22 - 2014-12-09 23:22 - 00000000 ____D () C:\ProgramData\Sun
2014-12-09 23:22 - 2014-12-09 23:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-12-09 23:21 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-09 23:21 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-09 23:21 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-09 23:21 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-09 23:21 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-09 23:21 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-09 23:21 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-09 23:21 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-09 23:21 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-09 23:21 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-09 23:14 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-12-09 23:14 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-12-09 23:14 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-12-09 23:14 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-12-09 23:13 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-12-09 23:13 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-12-09 23:13 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-12-09 23:13 - 2012-06-02 15:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-12-09 23:00 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-12-09 23:00 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-12-09 23:00 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-12-09 22:50 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-12-09 22:50 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-12-09 22:50 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-12-09 22:50 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-12-09 22:50 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-12-09 22:50 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-12-09 22:50 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-12-09 22:50 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-12-09 22:47 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-09 22:47 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-09 22:47 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-09 22:47 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-09 22:47 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-09 22:47 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-09 22:47 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-09 22:47 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-09 22:47 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-09 22:47 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-09 22:47 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-12-09 22:47 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-12-09 22:47 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-12-09 22:47 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-12-09 22:46 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-12-09 22:45 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-12-09 22:45 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-12-09 22:45 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-12-09 22:45 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-12-09 22:45 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-12-09 22:45 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-12-09 22:45 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-12-09 22:44 - 2014-10-30 03:04 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-12-09 22:44 - 2014-10-30 02:46 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-12-09 22:44 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-12-09 22:44 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-12-09 22:44 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-12-09 22:44 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-12-09 22:44 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-12-09 22:44 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-12-09 22:44 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-12-09 22:44 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-12-09 22:44 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-12-09 22:44 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-12-09 22:44 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-12-09 22:44 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-12-09 22:44 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-12-09 22:44 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-12-09 22:44 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-12-09 22:44 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-12-09 22:44 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-12-09 22:44 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-12-09 22:44 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-12-09 22:44 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-12-09 22:44 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-12-09 22:44 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-12-09 22:44 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-12-09 22:44 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-12-09 22:44 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2014-12-09 22:44 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2014-12-09 22:44 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-12-09 22:44 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-12-09 22:44 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-12-09 22:44 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2014-12-09 22:44 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2014-12-09 22:44 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-12-09 22:44 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2014-12-09 22:43 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-12-09 22:43 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-12-09 22:43 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-12-09 22:43 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-12-09 22:43 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-12-09 22:41 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-12-09 22:41 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-12-09 22:41 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-12-09 22:41 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-12-09 22:41 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-12-09 22:41 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-12-09 22:41 - 2014-03-26 15:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-12-09 22:41 - 2014-03-26 15:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-12-09 22:41 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-12-09 22:41 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-12-09 22:41 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-12-09 22:41 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-12-09 22:41 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-12-09 22:41 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-12-09 22:41 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-12-09 22:41 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-12-09 22:41 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-12-09 22:41 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-12-09 22:41 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-12-09 22:41 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-12-09 22:40 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-12-09 22:40 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-12-09 22:40 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-12-09 22:40 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-12-09 22:40 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-12-09 22:40 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-12-09 22:40 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-12-09 22:40 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-12-09 22:39 - 2014-04-05 03:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-12-09 22:39 - 2014-04-05 03:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-12-09 22:39 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-12-09 22:39 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-12-09 22:39 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-12-09 22:39 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-12-09 22:39 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-12-09 22:39 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-12-09 22:39 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-12-09 22:39 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-12-09 22:39 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-12-09 22:39 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-12-09 22:39 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-12-09 22:39 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-12-09 22:39 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-12-09 22:39 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-12-09 22:39 - 2012-01-04 11:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-12-09 22:39 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-12-09 22:39 - 2011-10-26 06:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-12-09 22:39 - 2011-10-26 05:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-12-09 22:39 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-12-09 22:39 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-12-09 22:39 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-12-09 22:39 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-12-09 22:39 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-12-09 22:39 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-12-09 22:39 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-12-09 22:39 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-12-09 22:39 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-12-09 22:39 - 2010-12-23 11:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-12-09 22:39 - 2010-12-23 11:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-12-09 22:39 - 2010-12-23 11:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-12-09 22:39 - 2010-12-23 06:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-12-09 22:39 - 2010-12-23 06:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-12-09 22:39 - 2010-12-23 06:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-12-09 22:38 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-09 22:38 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-12-09 22:38 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-12-09 22:38 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-12-09 22:38 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-12-09 22:38 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-12-09 22:38 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-12-09 22:38 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-12-09 22:38 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-12-09 22:38 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-12-09 22:38 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-12-09 22:38 - 2014-06-06 11:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-12-09 22:38 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-12-09 22:38 - 2014-05-30 07:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-12-09 22:38 - 2014-04-25 03:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-12-09 22:38 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-12-09 22:38 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-12-09 22:38 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-12-09 22:38 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-12-09 22:38 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-12-09 22:38 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-12-09 22:38 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-12-09 22:38 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-12-09 22:38 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-12-09 22:38 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-12-09 22:38 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-12-09 22:38 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-12-09 22:38 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-12-09 22:38 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-12-09 22:38 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-12-09 22:38 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-12-09 22:38 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-12-09 22:38 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-12-09 22:38 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-12-09 22:38 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-12-09 22:38 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-12-09 22:38 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-12-09 22:38 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-12-09 22:38 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-12-09 22:38 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-12-09 22:38 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-12-09 22:38 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-12-09 22:38 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-12-09 22:38 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-12-09 22:38 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-12-09 22:38 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-12-09 22:38 - 2012-11-28 23:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-12-09 22:38 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-12-09 22:38 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-12-09 22:38 - 2011-12-30 07:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-12-09 22:38 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-12-09 22:38 - 2011-07-09 03:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-12-09 22:38 - 2011-06-16 06:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-12-09 22:38 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2014-12-09 22:38 - 2011-04-29 04:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-12-09 22:38 - 2011-04-29 04:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-12-09 22:38 - 2011-04-29 04:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-12-09 22:38 - 2011-04-27 03:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-12-09 22:38 - 2011-04-27 03:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-12-09 22:38 - 2011-03-11 07:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-12-09 22:38 - 2011-03-11 07:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-12-09 22:38 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-12-09 22:38 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-12-09 22:37 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-12-09 22:37 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-12-09 22:37 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-12-09 22:37 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-12-09 22:36 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-12-09 22:36 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-12-09 22:36 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-12-09 22:36 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-12-09 22:34 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-09 22:34 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-09 22:34 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-12-09 22:34 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-12-09 22:34 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-12-09 22:34 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-12-09 22:34 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-12-09 22:34 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-12-09 22:34 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-12-09 22:34 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-12-09 22:34 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-12-09 22:34 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-12-09 22:34 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-12-09 22:34 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-12-09 22:34 - 2011-03-03 07:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-12-09 22:34 - 2011-03-03 07:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-12-09 22:34 - 2011-03-03 07:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-12-09 22:34 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-12-09 22:34 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-12-09 22:00 - 2014-03-04 10:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-12-09 22:00 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-12-09 22:00 - 2014-03-04 10:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-12-09 22:00 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-12-09 22:00 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-12-09 22:00 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-12-09 22:00 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-12-09 22:00 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-12-09 22:00 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-12-09 22:00 - 2014-03-04 10:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-12-09 22:00 - 2014-03-04 10:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-12-09 22:00 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-12-09 22:00 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-12-09 22:00 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-12-09 22:00 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-12-09 22:00 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-12-09 22:00 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-12-09 22:00 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-12-09 22:00 - 2014-03-04 10:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-12-09 22:00 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-12-09 22:00 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-12-09 22:00 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-12-09 22:00 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-12-09 21:59 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-12-09 21:59 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-12-09 21:59 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-12-09 21:59 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-12-09 21:59 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-12-09 21:59 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-12-09 21:59 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-12-09 21:59 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-12-09 21:59 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-12-09 21:59 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-12-09 21:59 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-12-09 21:59 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-12-09 21:59 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-12-09 21:59 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-12-09 21:59 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-12-09 21:59 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-12-09 21:59 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-12-09 21:59 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-12-09 21:59 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-12-09 21:59 - 2014-04-12 03:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-12-09 21:59 - 2014-04-12 03:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-12-09 21:59 - 2014-04-12 03:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-12-09 21:59 - 2014-04-12 03:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-12-09 21:59 - 2014-04-12 03:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-12-09 21:59 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-12-09 21:59 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-12-09 21:59 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-12-09 21:59 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-12-09 21:59 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-12-09 21:59 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-12-09 21:59 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-12-09 21:59 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-12-09 21:59 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-12-09 21:59 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-12-09 21:59 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-12-09 21:58 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-12-09 21:58 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-12-09 21:58 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-12-09 21:58 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-12-09 21:58 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-12-09 21:58 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-12-09 21:58 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-12-09 21:58 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-12-09 21:58 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-12-09 21:58 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-12-09 21:58 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-12-09 21:58 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-12-09 21:58 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-12-09 21:58 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-12-09 21:58 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-12-09 21:58 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-12-09 21:58 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-12-09 21:58 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-12-09 21:58 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-12-09 21:58 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-12-09 21:58 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-12-09 21:58 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-12-09 21:58 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-12-09 21:58 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-12-09 21:58 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-12-09 21:58 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-12-09 21:57 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-12-09 21:57 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-12-09 21:57 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-12-09 21:57 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-12-09 21:56 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-12-09 21:56 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-12-09 21:56 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-12-09 21:56 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-12-09 21:56 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-12-09 21:56 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-12-09 21:56 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-12-09 21:56 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-12-09 21:56 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-12-09 21:56 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-12-09 21:56 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-12-09 21:56 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-12-09 21:56 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-12-09 21:56 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-12-09 21:55 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-12-09 21:55 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-12-09 21:55 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-12-09 21:55 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-12-09 21:55 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-12-09 21:55 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-12-09 21:55 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-12-09 21:55 - 2011-02-05 18:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-12-09 21:55 - 2011-02-05 18:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-12-09 21:55 - 2011-02-05 18:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-12-09 21:55 - 2011-02-05 18:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-12-09 21:55 - 2011-02-05 18:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-12-09 21:55 - 2011-02-05 18:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-12-09 21:55 - 2011-02-05 18:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-12-09 21:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-09 21:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 21:54 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-12-09 21:54 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-12-09 21:54 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-12-09 21:54 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-12-09 21:54 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-12-09 21:53 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-12-09 21:53 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-12-09 21:53 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-12-09 21:53 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-12-09 21:53 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-12-09 21:53 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-12-09 21:53 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-12-09 21:53 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-12-09 21:53 - 2014-09-25 03:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-12-09 21:53 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-12-09 21:53 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-12-09 21:53 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-12-09 21:53 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-12-09 21:53 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-12-09 21:53 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-12-09 21:53 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-12-09 21:53 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-12-09 21:53 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-12-09 21:53 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-12-09 21:53 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-12-09 21:53 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-12-09 21:53 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-12-09 21:52 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-12-09 21:52 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-12-09 21:52 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-12-09 21:52 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-12-09 21:52 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-12-09 21:52 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-12-09 21:52 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-12-09 21:52 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-12-09 21:52 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-12-09 21:51 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-12-09 21:51 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-12-09 21:51 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-12-09 21:51 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-12-09 21:51 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-12-09 21:51 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-12-09 21:51 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-12-09 21:51 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-12-09 21:51 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-12-09 21:51 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-12-09 21:51 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-12-09 21:51 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-12-09 21:51 - 2014-01-24 03:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-12-09 21:51 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-12-09 21:51 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-12-09 21:51 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-12-09 21:51 - 2012-06-06 07:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-12-09 21:51 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-12-09 21:51 - 2012-05-14 06:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-12-09 21:51 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-12-09 21:51 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-12-09 21:51 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-12-09 21:51 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-12-09 21:51 - 2011-05-03 06:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-12-09 21:51 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-12-09 21:51 - 2011-02-18 11:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-12-09 21:51 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2014-12-09 21:48 - 2014-12-09 21:48 - 04095448 _____ (BrightFort LLC ) C:\Users\srsrsrsfser3\Desktop\spywareblastersetup50.exe
2014-12-09 21:40 - 2014-12-09 21:40 - 24743106 _____ () C:\Users\srsrsrsfser3\Downloads\vlc-2.1.5-win32.exe
2014-12-09 21:39 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-12-09 21:39 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-12-09 21:39 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-12-09 21:39 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-12-09 21:39 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-12-09 21:39 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-12-09 21:39 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-12-09 21:39 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-12-09 21:39 - 2011-10-15 07:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-12-09 21:39 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-12-09 21:39 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-12-09 21:39 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-12-09 21:38 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-12-09 21:38 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-12-09 21:38 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-12-09 21:38 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-12-09 21:38 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-12-09 21:37 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-12-09 21:37 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-12-09 21:37 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-12-09 21:37 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-12-09 21:37 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-12-09 21:37 - 2011-02-23 05:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-12-09 20:50 - 2014-12-09 20:51 - 00000801 _____ () C:\DelFix.txt
2014-12-09 17:35 - 2014-12-09 17:35 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-SRSRSRSFSER3-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-12-09 17:35 - 2014-12-09 17:35 - 00000000 ____D () C:\RegBackup
2014-12-09 15:51 - 2014-12-09 15:51 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-12-09 15:49 - 2014-12-09 15:49 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\PowerCinema
2014-12-09 15:49 - 2014-12-09 15:49 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\CyberLink
2014-12-09 02:23 - 2014-12-09 02:23 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2014-12-08 17:47 - 2014-12-09 20:50 - 00000000 ____D () C:\Windows\ERUNT
2014-12-08 17:21 - 2014-12-08 17:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-08 08:32 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-12-08 08:32 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-12-08 08:32 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-12-08 08:32 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-12-08 08:32 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-12-08 08:32 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-12-08 08:32 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-12-08 08:32 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-12-08 08:32 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-12-08 08:32 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-12-08 08:32 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-12-08 08:32 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-12-08 08:32 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-12-08 08:32 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-12-08 05:03 - 2014-12-08 05:03 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\dvdcss
2014-12-07 23:42 - 2014-12-07 23:42 - 02119680 _____ (Farbar) C:\Users\srsrsrsfser3\Desktop\FRST64.exe
2014-12-07 23:39 - 2014-12-07 23:39 - 00050477 _____ () C:\Users\srsrsrsfser3\Desktop\Defogger.exe
2014-12-07 21:32 - 2014-12-07 21:32 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2014-12-07 21:31 - 2014-12-07 21:31 - 05049344 _____ (Crawler.com ) C:\Users\srsrsrsfser3\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2014-12-07 21:00 - 2014-12-07 21:08 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\ManyCam
2014-12-07 20:59 - 2014-12-07 20:59 - 00000989 _____ () C:\Users\Public\Desktop\ManyCam.lnk
2014-12-07 20:59 - 2014-12-07 20:59 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\ManyCam
2014-12-07 20:59 - 2014-12-07 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManyCam
2014-12-07 20:58 - 2014-12-07 20:59 - 00000000 ____D () C:\ProgramData\ManyCam
2014-12-07 20:58 - 2014-12-07 20:59 - 00000000 ____D () C:\Program Files (x86)\ManyCam
2014-12-07 20:58 - 2014-12-07 20:58 - 00000000 ____D () C:\ProgramData\EmailNotifier
2014-12-07 20:55 - 2014-12-07 20:56 - 00217904 _____ () C:\Users\srsrsrsfser3\Downloads\ManyCamWebInstaller.exe
2014-12-07 20:23 - 2014-12-07 20:23 - 00000000 ____D () C:\Windows\system32\SPReview
2014-12-07 20:23 - 2014-12-07 20:23 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-12-07 20:04 - 2010-11-20 14:39 - 05066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2014-12-07 20:04 - 2010-11-20 14:33 - 00299392 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 14633472 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 03860992 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 03650560 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 03027968 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2014-12-07 20:04 - 2010-11-20 14:27 - 03008000 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 02086912 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01753088 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01646080 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01556992 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01326080 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01197056 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 00867840 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2014-12-07 20:04 - 2010-11-20 14:27 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 03391488 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 03205120 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 02067456 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 01866240 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 01340416 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 00828416 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-12-07 20:04 - 2010-11-20 14:26 - 00777728 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-12-07 20:04 - 2010-11-20 14:25 - 03957760 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2014-12-07 20:04 - 2010-11-20 14:25 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-12-07 20:04 - 2010-11-20 14:25 - 01600512 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-12-07 20:04 - 2010-11-20 14:25 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2014-12-07 20:04 - 2010-11-20 14:25 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2014-12-07 20:04 - 2010-11-20 14:24 - 02872320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-12-07 20:04 - 2010-11-20 13:32 - 05066752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthFWSnapin.dll
2014-12-07 20:04 - 2010-11-20 13:21 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-12-07 20:04 - 2010-11-20 13:21 - 01115136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RacEngn.dll
2014-12-07 20:04 - 2010-11-20 13:19 - 01698816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2014-12-07 20:04 - 2010-11-20 13:19 - 00954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2014-12-07 20:04 - 2010-11-20 13:19 - 00954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2014-12-07 20:04 - 2010-11-20 13:18 - 01334272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2014-12-07 20:04 - 2010-11-20 12:07 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-12-07 20:04 - 2010-11-20 12:05 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2014-12-07 20:04 - 2010-11-20 10:25 - 00753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2014-12-07 20:04 - 2010-11-05 03:20 - 00347904 _____ () C:\Windows\system32\systemsf.ebd
2014-12-07 20:04 - 2010-11-05 02:58 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2014-12-07 20:04 - 2010-11-05 02:57 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2014-12-07 20:04 - 2010-11-05 02:57 - 00048976 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2014-12-07 20:04 - 2010-11-05 02:53 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2014-12-07 20:04 - 2010-11-05 02:53 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2014-12-07 20:04 - 2010-11-05 02:53 - 00109928 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2014-12-07 20:04 - 2010-11-05 02:53 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2014-12-07 20:03 - 2010-11-20 14:44 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2014-12-07 20:03 - 2010-11-20 14:34 - 00363392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2014-12-07 20:03 - 2010-11-20 14:34 - 00295808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-12-07 20:03 - 2010-11-20 14:34 - 00215936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2014-12-07 20:03 - 2010-11-20 14:34 - 00071552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00366976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00289664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00263040 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-12-07 20:03 - 2010-11-20 14:33 - 00213888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00184704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00171392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scsiport.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00140672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00103808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sbp2port.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00078720 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\HpSAMD.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00063360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2014-12-07 20:03 - 2010-11-20 14:33 - 00031104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2014-12-07 20:03 - 2010-11-20 14:32 - 02217856 _____ (Microsoft Corporation) C:\Windows\system32\bootres.dll
2014-12-07 20:03 - 2010-11-20 14:32 - 00334208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-12-07 20:03 - 2010-11-20 14:32 - 00179072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-12-07 20:03 - 2010-11-20 14:32 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-12-07 20:03 - 2010-11-20 14:32 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-12-07 20:03 - 2010-11-20 14:29 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-12-07 20:03 - 2010-11-20 14:28 - 00780008 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-12-07 20:03 - 2010-11-20 14:28 - 00298104 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2014-12-07 20:03 - 2010-11-20 14:28 - 00166784 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02652160 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02543616 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02262528 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02250752 _____ (Microsoft Corporation) C:\Windows\system32\SensorsCpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02193920 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02072576 _____ (Microsoft Corporation) C:\Windows\system32\WMPEncEn.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 02055680 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01900544 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01808384 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01689600 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01509888 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01363968 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01281024 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01243136 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01212416 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2014-12-07 20:03 - 2010-11-20 14:27 - 01158656 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01098240 _____ (Microsoft Corporation) C:\Windows\system32\Vault.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01082880 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01050624 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01024512 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 01008128 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00849920 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00812032 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00799744 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00695808 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00691200 _____ (Microsoft Corporation) C:\Windows\system32\VAN.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00633344 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00605696 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00582656 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00577536 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\mspbda.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\msdri.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00481280 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL
2014-12-07 20:03 - 2010-11-20 14:27 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\wiadefui.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\nshipsec.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00418816 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\netdiagfx.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\QAGENT.DLL
2014-12-07 20:03 - 2010-11-20 14:27 - 00264192 _____ (Microsoft Corporation) C:\Windows\system32\upnp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00232448 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\wmpsrcwp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\QSHVHOST.DLL
2014-12-07 20:03 - 2010-11-20 14:27 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\netjoin.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\provsvc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\prncache.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\QUTIL.DLL
2014-12-07 20:03 - 2010-11-20 14:27 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\nci.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\samcli.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\RpcRtRemote.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-12-07 20:03 - 2010-11-20 14:27 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\vpnikeapi.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 01457664 _____ (Microsoft Corporation) C:\Windows\system32\DxpTaskSync.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 01244160 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\DiagCpl.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 01066496 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00934912 _____ (Microsoft Corporation) C:\Windows\system32\FirewallControlPanel.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00675328 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\localsec.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2014-12-07 20:03 - 2010-11-20 14:26 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00422912 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00317952 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00281600 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dskquoui.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\hgprint.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00232448 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\fde.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00166912 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\dps.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
2014-12-07 20:03 - 2010-11-20 14:26 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00116224 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\fms.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\dot3api.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\lsmproxy.dll
2014-12-07 20:03 - 2010-11-20 14:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 03524608 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 01504256 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 01264640 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00974336 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00958464 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00897536 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00749568 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-12-07 20:03 - 2010-11-20 14:25 - 00594432 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\biocpl.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\cfgmgr32.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\bcdsrv.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00128000 _____ (Microsoft) C:\Windows\system32\Robocopy.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2014-12-07 20:03 - 2010-11-20 14:25 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\setupcl.exe
2014-12-07 20:03 - 2010-11-20 14:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00957440 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2014-12-07 20:03 - 2010-11-20 14:24 - 00793088 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00777728 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00763904 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2014-12-07 20:03 - 2010-11-20 14:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\FXSSVC.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
2014-12-07 20:03 - 2010-11-20 14:24 - 00653312 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2014-12-07 20:03 - 2010-11-20 14:24 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-12-07 20:03 - 2010-11-20 14:24 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\lsm.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00300032 _____ (Microsoft Corporation) C:\Windows\system32\msconfig.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-12-07 20:03 - 2010-11-20 14:24 - 00272896 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
         

Alt 10.12.2014, 12:38   #35
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Code:
ATTFilter
2014-12-07 20:03 - 2010-11-20 14:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2014-12-07 20:03 - 2010-11-20 14:24 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv
2014-12-07 20:03 - 2010-11-20 14:24 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2014-12-07 20:03 - 2010-11-20 14:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\WSTPager.ax
2014-12-07 20:03 - 2010-11-20 13:51 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-07 20:03 - 2010-11-20 13:23 - 00144768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 02983424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 02146304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncCenter.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01712640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsservices.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01667584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01624064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPEncEn.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01363456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01326592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanpref.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01227776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01128448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vssapi.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 01003008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMNetMgr.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00933376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Vault.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00782336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00778240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqlsrv32.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00505856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00458752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00411648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlangpui.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxs.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00352256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpeffects.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00350208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shlwapi.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00346624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSATAPI.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsvcs.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00307712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srchadmin.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00246272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scansetting.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00228352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnp.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00181760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tcpipcfg.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spp.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00113664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SessEnv.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\regapi.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samcli.dll
2014-12-07 20:03 - 2010-11-20 13:21 - 00046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RpcRtRemote.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 02504192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2014-12-07 20:03 - 2010-11-20 13:20 - 02494464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 01750528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pnidui.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 01508864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00932352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\printui.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00801280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NaturalLanguage6.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00563712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00547840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PortableDeviceApi.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercpl.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00406528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00225792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netdiagfx.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\onex.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\QAGENT.DLL
2014-12-07 20:03 - 2010-11-20 13:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\QSHVHOST.DLL
2014-12-07 20:03 - 2010-11-20 13:20 - 00166400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiohlp.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netid.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prncache.dll
2014-12-07 20:03 - 2010-11-20 13:20 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nci.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 02151936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 01493504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2014-12-07 20:03 - 2010-11-20 13:19 - 00732160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00488448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ipsmsnap.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00213504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00167936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msutb.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fde.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IPHLPAPI.DLL
2014-12-07 20:03 - 2010-11-20 13:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hbaapi.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mimefilt.dll
2014-12-07 20:03 - 2010-11-20 13:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 02522624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 01828352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 01555456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certmgr.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DxpTaskSync.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 01371136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 01040384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00854016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00762880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\azroles.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuxiliaryDisplayCpl.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00630784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00252928 _____ (Microsoft) C:\Windows\SysWOW64\DShowRdpFilter.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00222208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2014-12-07 20:03 - 2010-11-20 13:18 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3api.dll
2014-12-07 20:03 - 2010-11-20 13:17 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00302592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskmgr.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mcbuilder.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\net1.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00098816 _____ (Microsoft) C:\Windows\SysWOW64\Robocopy.exe
2014-12-07 20:03 - 2010-11-20 13:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\proquota.exe
2014-12-07 20:03 - 2010-11-20 13:16 - 00905216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2014-12-07 20:03 - 2010-11-20 13:16 - 00776192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2014-12-07 20:03 - 2010-11-20 13:16 - 00679424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2014-12-07 20:03 - 2010-11-20 13:16 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2014-12-07 20:03 - 2010-11-20 13:16 - 00658944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2014-12-07 20:03 - 2010-11-20 13:16 - 00320000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2014-12-07 20:03 - 2010-11-20 13:16 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2014-12-07 20:03 - 2010-11-20 13:08 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2014-12-07 20:03 - 2010-11-20 12:04 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-12-07 20:03 - 2010-11-20 11:52 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2014-12-07 20:03 - 2010-11-20 11:52 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rasl2tp.sys
2014-12-07 20:03 - 2010-11-20 11:52 - 00111104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspptp.sys
2014-12-07 20:03 - 2010-11-20 11:52 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2014-12-07 20:03 - 2010-11-20 11:52 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipfltdrv.sys
2014-12-07 20:03 - 2010-11-20 11:44 - 00552448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2014-12-07 20:03 - 2010-11-20 11:44 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\1394ohci.sys
2014-12-07 20:03 - 2010-11-20 11:44 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-12-07 20:03 - 2010-11-20 11:44 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2014-12-07 20:03 - 2010-11-20 11:43 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winusb.sys
2014-12-07 20:03 - 2010-11-20 11:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-12-07 20:03 - 2010-11-20 10:27 - 00309248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-12-07 20:03 - 2010-11-20 10:26 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2014-12-07 20:03 - 2010-11-20 10:23 - 00261632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2014-12-07 20:03 - 2010-11-05 03:11 - 00433512 _____ (Microsoft Corporation) C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2014-12-07 20:03 - 2010-11-05 02:58 - 00049488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll
2014-12-07 20:03 - 2009-07-14 02:16 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tcpmonui.dll
2014-12-07 20:02 - 2010-11-20 14:44 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\NAPHLPR.DLL
2014-12-07 20:02 - 2010-11-20 14:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\NAPCRYPT.DLL
2014-12-07 20:02 - 2010-11-20 14:33 - 00155008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpio.sys
2014-12-07 20:02 - 2010-11-20 14:33 - 00094592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2014-12-07 20:02 - 2010-11-20 14:33 - 00014720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys
2014-12-07 20:02 - 2010-11-20 14:27 - 02146816 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 01911808 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 01672704 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2014-12-07 20:02 - 2010-11-20 14:27 - 01080320 _____ (Microsoft Corporation) C:\Windows\system32\onexui.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2014-12-07 20:02 - 2010-11-20 14:27 - 00898560 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00781312 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\sdcpl.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2014-12-07 20:02 - 2010-11-20 14:27 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00636416 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00527872 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmnet.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00451072 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\sqlcese30.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00435712 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceStatus.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00431104 _____ (Microsoft Corporation) C:\Windows\system32\WPDSp.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\termmgr.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\prnfldr.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00403968 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00358400 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00344576 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00337920 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00300032 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2014-12-07 20:02 - 2010-11-20 14:27 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\wavemsp.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\qdv.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\taskbarcpl.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\mstask.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceSyncProvider.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00221696 _____ (Microsoft Corporation) C:\Windows\system32\OnLineIDCpl.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\wpdwcn.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00207360 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00200192 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\qcap.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\twext.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\sdrsvc.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00154624 _____ (Microsoft Corporation) C:\Windows\system32\uxlib.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\remotepg.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\recovery.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\mydocs.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\wmpshell.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\ntlanman.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\srvcli.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\wiavideo.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\QSVRMGMT.DLL
2014-12-07 20:02 - 2010-11-20 14:27 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\WPDShServiceObj.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountControlSettings.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\QCLIPROV.DLL
2014-12-07 20:02 - 2010-11-20 14:27 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\unimdmat.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\napdsnap.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\wkscli.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\vfwwdm32.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\rdpd3d.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\WavDest.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\umb.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\PrintIsolationProxy.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\shimgvw.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\wdiasqmmodule.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\msdmo.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\profprov.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\netutils.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\shgina.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\sisbkup.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\schedcli.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\rdprefdrvapi.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\TRAPI.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\spopk.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\syssetup.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\nrpsrv.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wshirda.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\shunimpl.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\riched32.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\rdpcfgex.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-12-07 20:02 - 2010-11-20 14:27 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-12-07 20:02 - 2010-11-20 14:27 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\dsuiext.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\FXSAPI.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCenter.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00495104 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\dot3ui.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\iTVData.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\dxdiagn.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00240640 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\defaultlocationcpl.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingFolder.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\fphc.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\KMSVC.DLL
2014-12-07 20:02 - 2010-11-20 14:26 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\Mcx2Svc.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\inetmib1.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\luainstall.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\FXSMON.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\mciqtz32.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\iscsium.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dsauth.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\HotStartUserAgent.dll
2014-12-07 20:02 - 2010-11-20 14:26 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\elsTrans.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 03745792 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 01065984 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00840192 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00780800 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00549888 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenterCPL.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00472064 _____ (Microsoft Corporation) C:\Windows\system32\azroleui.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00349696 _____ (Microsoft Corporation) C:\Windows\system32\slui.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\recdisc.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\net1.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\cca.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\cabinet.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\amstream.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\CertPolEng.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\takeown.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\tzutil.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\runonce.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\repair-bde.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\MultiDigiMon.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\proquota.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\AzSqlExt.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\userinit.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2014-12-07 20:02 - 2010-11-20 14:25 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\bitsperf.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\BWUnpairElevated.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll
2014-12-07 20:02 - 2010-11-20 14:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\C_ISCII.DLL
2014-12-07 20:02 - 2010-11-20 14:25 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00899584 _____ (Microsoft Corporation) C:\Windows\system32\Bubbles.scr
2014-12-07 20:02 - 2010-11-20 14:24 - 00721408 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2014-12-07 20:02 - 2010-11-20 14:24 - 00606208 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\main.cpl
2014-12-07 20:02 - 2010-11-20 14:24 - 00474112 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2014-12-07 20:02 - 2010-11-20 14:24 - 00373248 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2014-12-07 20:02 - 2010-11-20 14:24 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\sysdm.cpl
2014-12-07 20:02 - 2010-11-20 14:24 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\ssText3d.scr
2014-12-07 20:02 - 2010-11-20 14:24 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2014-12-07 20:02 - 2010-11-20 14:24 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\Mystify.scr
2014-12-07 20:02 - 2010-11-20 14:24 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\Ribbons.scr
2014-12-07 20:02 - 2010-11-20 14:24 - 00232448 _____ (Microsoft Corporation) C:\Windows\system32\bitsadmin.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\fsquirt.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2014-12-07 20:02 - 2010-11-20 14:24 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\iscsicli.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\MdSched.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\desk.cpl
2014-12-07 20:02 - 2010-11-20 14:24 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\kstvtune.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\mobsync.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\cmstp.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\isoburn.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00071168 _____ (Microsoft Corporation) C:\Windows\bfsvc.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\ksxbar.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\djoin.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\g711codc.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\vbisurf.ax
2014-12-07 20:02 - 2010-11-20 14:24 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\choice.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\LogonUI.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\FXSUNATD.exe
2014-12-07 20:02 - 2010-11-20 14:24 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2014-12-07 20:02 - 2010-11-20 14:16 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-12-07 20:02 - 2010-11-20 14:15 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2014-12-07 20:02 - 2010-11-20 14:14 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwizres.dll
2014-12-07 20:02 - 2010-11-20 14:13 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\RDPENCDD.dll
2014-12-07 20:02 - 2010-11-20 14:13 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2014-12-07 20:02 - 2010-11-20 14:12 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\pifmgr.dll
2014-12-07 20:02 - 2010-11-20 14:02 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2014-12-07 20:02 - 2010-11-20 14:02 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2014-12-07 20:02 - 2010-11-20 14:02 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUQ.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUF.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDSG.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\kbdlk41a.dll
2014-12-07 20:02 - 2010-11-20 14:02 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDGKL.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDCZ1.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDSF.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDPO.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDNEPR.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDGR1.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDUS.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDUGHR1.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTURME.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAJIK.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDMON.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDMAORI.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDLT1.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBULG.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBLR.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-12-07 20:02 - 2010-11-20 14:02 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGEO.DLL
2014-12-07 20:02 - 2010-11-20 13:58 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2014-12-07 20:02 - 2010-11-20 13:54 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\BlbEvents.dll
2014-12-07 20:02 - 2010-11-20 13:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-ums-l1-1-0.dll
2014-12-07 20:02 - 2010-11-20 13:36 - 00107008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NAPHLPR.DLL
2014-12-07 20:02 - 2010-11-20 13:36 - 00046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NAPCRYPT.DLL
2014-12-07 20:02 - 2010-11-20 13:21 - 02202624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsCpl.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 02157568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themecpl.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00902656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2014-12-07 20:02 - 2010-11-20 13:21 - 00755200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sud.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2014-12-07 20:02 - 2010-11-20 13:21 - 00738816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00638976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VAN.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00616960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2014-12-07 20:02 - 2010-11-20 13:21 - 00507392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmdev.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00473600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\riched20.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00436736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmnet.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00428544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shwebsvc.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00416768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiadefui.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00410112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanui.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00406528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\termmgr.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwizeng.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00350720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WPDSp.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00327680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\raschap.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqlcese30.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpdxm.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tapisrv.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00222208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wavemsp.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVolSSO.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdwcn.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcomapi.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00186368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpsrcwp.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasppp.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vdsbas.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\syncui.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remotepg.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twext.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpps.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxlib.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsetup.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiavideo.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WPDShServiceObj.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpshell.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppinst.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srvcli.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\QUTIL.DLL
2014-12-07 20:02 - 2010-11-20 13:21 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserAccountControlSettings.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdmat.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vfwwdm32.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpd3d.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsnmp32.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00051200 _____ (Twain Working Group) C:\Windows\twain_32.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wkscli.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wtsapi32.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshbth.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimgvw.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\utildll.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vpnikeapi.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsdchngr.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TRAPI.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdprefdrvapi.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shgina.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spopk.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sisbkup.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schedcli.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\syssetup.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00011264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshirda.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shunimpl.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\riched32.dll
2014-12-07 20:02 - 2010-11-20 13:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-12-07 20:02 - 2010-11-20 13:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 02130944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\networkmap.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 01661440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\networkexplorer.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 01644032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcenter.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 01160192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 01111552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\onexui.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00859648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OobeFldr.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00600576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PerfCenterCPL.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PortableDeviceStatus.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prnfldr.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00346112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshipsec.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00324608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdv.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00236544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OnLineIDCpl.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00190976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qcap.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00183296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PortableDeviceSyncProvider.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ocsetapi.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\provsvc.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netjoin.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mydocs.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00121344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prntvpt.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\QSVRMGMT.DLL
2014-12-07 20:02 - 2010-11-20 13:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00077824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olethk32.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\QCLIPROV.DLL
2014-12-07 20:02 - 2010-11-20 13:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntlanman.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\napdsnap.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptui.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netutils.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfts.dll
2014-12-07 20:02 - 2010-11-20 13:20 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00856576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallControlPanel.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontext.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00592384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00429056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\localsec.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hgcpl.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MediaMetadataHandler.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00226304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAC3ENC.DLL
2014-12-07 20:02 - 2010-11-20 13:19 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iTVData.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstask.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrad.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprapi.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrecst.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvfw32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fphc.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00093696 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\SysWOW64\fms.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00082944 _____ (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasacct.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdeploy.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetmib1.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\luainstall.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mciqtz32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\httpapi.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdmo.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iscsium.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lsmproxy.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll
2014-12-07 20:02 - 2010-11-20 13:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 03727872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\accessibilitycpl.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 01003520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00744448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00743424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00740864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\batmeter.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00685056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsuiext.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00537600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenterCPL.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00484864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceCenter.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00402944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00333824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3ui.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\azroleui.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpx.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00243712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\audiodev.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00242176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\defaultlocationcpl.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00211456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairingFolder.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxdiagn.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00205312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efscore.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\activeds.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dskquoui.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsldp.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoplay.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EhStorAPI.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3msm.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscmmc.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3cfg.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cabinet.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\amstream.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cca.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertPolEng.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\acppage.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscapi.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsauth.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00028160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzSqlExt.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscdll.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elsTrans.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bitsperf.dll
2014-12-07 20:02 - 2010-11-20 13:18 - 00011264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\C_ISCII.DLL
2014-12-07 20:02 - 2010-11-20 13:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browseui.dll
2014-12-07 20:02 - 2010-11-20 13:17 - 00586752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfrgui.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00327680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimserv.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SndVol.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eudcedit.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00276480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskraid.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PkgMgr.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00197632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ocsetup.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iscsicli.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskpart.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00101376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mobsync.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nslookup.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logagent.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\isoburn.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmstp.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MuiUnattend.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\w32tm.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\findstr.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\takeown.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\runonce.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzutil.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftp.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unlodctr.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userinit.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiougc.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2014-12-07 20:02 - 2010-11-20 13:17 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe
2014-12-07 20:02 - 2010-11-20 13:16 - 00878592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Bubbles.scr
2014-12-07 20:02 - 2010-11-20 13:16 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00649216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00516096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\main.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00413696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
2014-12-07 20:02 - 2010-11-20 13:16 - 00389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2014-12-07 20:02 - 2010-11-20 13:16 - 00345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysdm.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00293888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ssText3d.scr
2014-12-07 20:02 - 2010-11-20 13:16 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2014-12-07 20:02 - 2010-11-20 13:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mystify.scr
2014-12-07 20:02 - 2010-11-20 13:16 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Ribbons.scr
2014-12-07 20:02 - 2010-11-20 13:16 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00186368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bitsadmin.exe
2014-12-07 20:02 - 2010-11-20 13:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdmaud.drv
2014-12-07 20:02 - 2010-11-20 13:16 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VBICodec.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\desk.cpl
2014-12-07 20:02 - 2010-11-20 13:16 - 00107008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Kswdmcap.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kstvtune.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00068608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSTPager.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksxbar.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\g711codc.ax
2014-12-07 20:02 - 2010-11-20 13:16 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbisurf.ax
2014-12-07 20:02 - 2010-11-20 13:08 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00119808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imm32.dll
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTUQ.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTUF.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDSG.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdlk41a.dll
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDGR1.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDGKL.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDCZ1.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDSF.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDPO.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDNEPR.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTAM.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINORI.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAR.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINKAN.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINHIN.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBEN.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDUS.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDUGHR1.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTURME.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAJIK.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDMON.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDMAORI.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDLT1.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTEL.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDGEO.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBULG.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBLR.DLL
2014-12-07 20:02 - 2010-11-20 13:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-12-07 20:02 - 2010-11-20 13:07 - 01164800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2014-12-07 20:02 - 2010-11-20 13:07 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwizres.dll
2014-12-07 20:02 - 2010-11-20 13:06 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2014-12-07 20:02 - 2010-11-20 13:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pifmgr.dll
2014-12-07 20:02 - 2010-11-20 13:00 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2014-12-07 20:02 - 2010-11-20 13:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2014-12-07 20:02 - 2010-11-20 12:57 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll
2014-12-07 20:02 - 2010-11-20 12:37 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2014-12-07 20:02 - 2010-11-20 11:52 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2014-12-07 20:02 - 2010-11-20 11:52 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2014-12-07 20:02 - 2010-11-20 11:51 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2014-12-07 20:02 - 2010-11-20 11:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndisuio.sys
2014-12-07 20:02 - 2010-11-20 11:49 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2014-12-07 20:02 - 2010-11-20 11:44 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2014-12-07 20:02 - 2010-11-20 11:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\umbus.sys
2014-12-07 20:02 - 2010-11-20 11:44 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys
2014-12-07 20:02 - 2010-11-20 11:43 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-12-07 20:02 - 2010-11-20 11:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2014-12-07 20:02 - 2010-11-20 11:34 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_sd.sys
2014-12-07 20:02 - 2010-11-20 11:33 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\CompositeBus.sys
2014-12-07 20:02 - 2010-11-20 11:33 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2014-12-07 20:02 - 2010-11-20 11:14 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-12-07 20:02 - 2010-11-20 11:09 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2014-12-07 20:02 - 2010-11-20 11:04 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-12-07 20:02 - 2010-11-20 10:37 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2014-12-07 20:02 - 2010-11-20 10:30 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpipmi.sys
2014-12-07 20:02 - 2010-11-20 10:26 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-12-07 20:02 - 2010-11-20 10:22 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdi.sys
2014-12-07 20:02 - 2010-11-20 10:19 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2014-12-07 20:02 - 2010-11-10 02:48 - 00010429 _____ () C:\Windows\system32\ScavengeSpace.xml
2014-12-07 20:02 - 2010-11-05 03:11 - 00312168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCEWMDRMNDBootstrap.dll
2014-12-07 20:01 - 2010-11-20 14:26 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\dpx.dll
2014-12-07 20:01 - 2010-11-20 13:21 - 00363008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wbemcomn.dll
2014-12-07 20:01 - 2010-11-20 13:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdscore.dll
2014-12-07 20:01 - 2010-11-05 03:20 - 00105559 _____ () C:\Windows\SysWOW64\RacRules.xml
2014-12-07 20:01 - 2010-11-05 03:20 - 00105559 _____ () C:\Windows\system32\RacRules.xml
2014-12-07 20:01 - 2009-06-10 22:39 - 00001041 _____ () C:\Windows\SysWOW64\tcpbidi.xml
2014-12-07 19:56 - 2010-11-20 14:27 - 00529408 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn.dll
2014-12-07 19:18 - 2014-12-07 19:18 - 00000000 __SHD () C:\#GDATA.Trash.Store#
2014-12-07 19:03 - 2014-12-07 19:03 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Macromedia
2014-12-07 18:57 - 2014-12-07 18:57 - 00000000 __RSD () C:\Users\srsrsrsfser3\Documents\My Stationery
2014-12-07 18:56 - 2014-12-07 18:56 - 00000000 ____D () C:\Users\srsrsrsfser3\Documents\My PSP Files
2014-12-07 18:56 - 2014-12-07 18:56 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Corel
2014-12-07 18:49 - 2014-12-07 18:49 - 00262144 _____ () C:\Windows\SysWOW64\18
2014-12-07 18:26 - 2014-12-07 18:26 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-07 18:26 - 2014-12-07 18:26 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-07 18:26 - 2014-12-07 18:26 - 00000000 ____D () C:\Windows\system32\Macromed
2014-12-07 18:25 - 2014-12-07 18:27 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Adobe
2014-12-07 18:20 - 2014-12-07 18:20 - 00000000 ____D () C:\Users\srsrsrsfser3\Documents\ProcAlyzer Dumps
2014-12-07 17:43 - 2009-06-10 22:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20141207-174311.backup
2014-12-07 17:12 - 2014-12-10 05:15 - 00007615 _____ () C:\Users\srsrsrsfser3\AppData\Local\Resmon.ResmonCfg
2014-12-07 16:57 - 2014-12-10 01:21 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-12-07 16:57 - 2014-12-07 16:57 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-12-07 16:56 - 2014-12-10 01:53 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-12-07 16:55 - 2014-12-07 16:56 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\srsrsrsfser3\Downloads\spybot-2.4.exe
2014-12-07 15:32 - 2014-12-07 15:38 - 00000502 _____ () C:\Windows\SynInst.log
2014-12-07 15:11 - 2014-12-07 15:11 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-12-07 15:07 - 2014-12-07 15:07 - 00000000 ____D () C:\Users\srsrsrsfser3\Documents\Bluetooth-Exchange-Ordner
2014-12-07 15:07 - 2014-12-07 15:07 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Broadcom
2014-12-07 14:47 - 2014-12-07 14:47 - 00000020 ___SH () C:\Users\UpdatusUser\ntuser.ini
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Vorlagen
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Startmenü
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Netzwerkumgebung
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Lokale Einstellungen
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Eigene Dateien
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Druckumgebung
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Musik
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Documents\Eigene Bilder
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Verlauf
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 _SHDL () C:\Users\UpdatusUser\Anwendungsdaten
2014-12-07 14:47 - 2014-12-07 14:47 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-12-07 14:47 - 2014-12-07 04:03 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2014-12-07 14:47 - 2009-08-25 18:07 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery Manager
2014-12-07 14:47 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-07 14:47 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-07 14:46 - 2013-10-27 09:04 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-12-07 14:46 - 2013-10-27 09:04 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-12-07 14:44 - 2014-12-07 14:47 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-12-07 14:44 - 2014-12-07 14:44 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-12-07 14:43 - 2014-12-10 01:17 - 00018587 _____ () C:\Windows\IE11_main.log
2014-12-07 14:42 - 2014-12-07 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2014-12-07 14:41 - 2014-12-07 14:42 - 65446536 _____ (Microsoft Corporation) C:\Users\srsrsrsfser3\Downloads\EIE11_DE-DE_MSE_WIN764.EXE
2014-12-07 14:40 - 2014-12-07 14:40 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-12-07 14:40 - 2014-12-07 14:40 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-12-07 14:40 - 2014-12-07 14:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-12-07 14:40 - 2014-12-07 14:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_EhStorPwdDrv_01_09_00.Wdf
2014-12-07 14:38 - 2014-12-07 15:11 - 00283138 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2014-12-07 14:36 - 2014-12-07 15:11 - 00286234 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2014-12-07 14:35 - 2010-02-23 09:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe
2014-12-07 14:32 - 2014-12-07 14:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2014-12-07 14:30 - 2014-12-07 14:30 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Microsoft Help
2014-12-07 14:27 - 2014-12-09 22:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-07 14:26 - 2014-12-10 01:53 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-07 14:26 - 2014-12-10 01:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-07 14:22 - 2014-12-10 00:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-07 14:22 - 2014-12-10 00:13 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-07 14:21 - 2014-12-07 14:42 - 00002155 _____ () C:\Windows\epplauncher.mif
2014-12-07 14:20 - 2014-12-07 14:41 - 00002119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-12-07 14:20 - 2014-12-07 14:41 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-12-07 14:20 - 2014-12-07 14:41 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-12-07 14:18 - 2014-12-07 14:18 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00098760 _____ (G Data Software) C:\Windows\system32\Drivers\TS4nt.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00064512 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00061440 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00020992 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys
2014-12-07 14:18 - 2014-12-07 14:18 - 00002005 _____ () C:\Users\Public\Desktop\G DATA TOTAL PROTECTION.lnk
2014-12-07 14:18 - 2014-12-07 14:18 - 00000779 _____ () C:\Users\srsrsrsfser3\AppData\Roaming\gdscan.log
2014-12-07 14:18 - 2014-12-07 14:18 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf
2014-12-07 14:18 - 2014-12-07 14:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA TOTAL PROTECTION
2014-12-07 14:18 - 2014-12-07 14:18 - 00000000 _____ () C:\Users\srsrsrsfser3\AppData\Roaming\gdfw.log
2014-12-07 14:17 - 2014-12-07 14:17 - 00000000 ____D () C:\ProgramData\G DATA Software
2014-12-07 14:17 - 2014-12-07 14:17 - 00000000 ____D () C:\Program Files (x86)\G DATA
2014-12-07 14:16 - 2014-12-07 18:34 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Notepad++
2014-12-07 14:16 - 2014-12-07 14:17 - 00001021 _____ () C:\Users\srsrsrsfser3\Desktop\Notepad++.lnk
2014-12-07 14:16 - 2014-12-07 14:17 - 00000000 ____D () C:\Program Files (x86)\Notepad++
2014-12-07 14:16 - 2014-12-07 14:16 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-12-07 14:16 - 2014-12-07 14:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-12-07 14:14 - 2014-12-07 14:14 - 07624808 _____ () C:\Users\srsrsrsfser3\Downloads\npp.6.5.5.Installer.exe
2014-12-07 14:07 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-07 14:07 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-07 14:06 - 2014-12-07 14:53 - 00000000 ____D () C:\ProgramData\G Data
2014-12-07 14:03 - 2014-10-30 12:25 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-07 14:00 - 2014-12-07 14:05 - 237965560 _____ (G Data Software AG) C:\Users\srsrsrsfser3\Downloads\INT_R_BASE_2015_TP.exe
2014-12-07 13:57 - 2014-12-09 21:23 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-07 13:57 - 2014-12-07 13:57 - 00000000 ____D () C:\ProgramData\Mozilla
2014-12-07 13:57 - 2014-12-07 13:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-07 13:55 - 2014-12-07 13:57 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Mozilla
2014-12-07 13:55 - 2014-12-07 13:55 - 00244264 _____ () C:\Users\srsrsrsfser3\Downloads\Firefox Setup Stub 34.0.5.exe
2014-12-07 13:55 - 2014-12-07 13:55 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Mozilla
2014-12-07 13:51 - 2014-12-09 23:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-07 13:51 - 2014-12-09 21:23 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-07 13:51 - 2014-12-07 13:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
2014-12-07 12:51 - 2014-12-07 12:51 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Adobe
2014-12-07 12:50 - 2014-12-07 12:50 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\HpUpdate
2014-12-07 12:47 - 2014-12-07 12:47 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Macromedia
2014-12-07 12:46 - 2014-12-07 12:46 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Macrovision
2014-12-07 12:45 - 2014-12-10 02:10 - 00001411 _____ () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-07 12:45 - 2014-12-07 12:45 - 00001407 _____ () C:\Users\srsrsrsfser3\Desktop\Internet Explorer (64-bit).lnk
2014-12-07 12:45 - 2014-12-07 12:45 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Hewlett-Packard
2014-12-07 12:45 - 2014-12-07 12:45 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\DigitalPersona
2014-12-07 12:45 - 2014-12-07 12:45 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\DigitalPersona
2014-12-07 12:45 - 2014-12-07 12:45 - 00000000 _____ () C:\Users\srsrsrsfser3\AppData\Local\QSwitch.txt
2014-12-07 12:45 - 2014-12-07 12:45 - 00000000 _____ () C:\Users\srsrsrsfser3\AppData\Local\DSwitch.txt
2014-12-07 12:45 - 2014-12-07 12:45 - 00000000 _____ () C:\Users\srsrsrsfser3\AppData\Local\AtStart.txt
2014-12-07 12:44 - 2014-12-10 02:10 - 00096456 _____ () C:\Users\srsrsrsfser3\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-07 12:44 - 2014-12-07 15:33 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\VirtualStore
2014-12-07 12:44 - 2014-12-07 12:44 - 00003988 _____ () C:\Windows\System32\Tasks\RecoveryCDWin7
2014-12-07 12:44 - 2014-12-07 12:44 - 00003796 _____ () C:\Windows\System32\Tasks\Registration
2014-12-07 12:44 - 2014-12-07 12:44 - 00003290 _____ () C:\Windows\System32\Tasks\RMCreator
2014-12-07 12:44 - 2014-12-07 12:44 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\hpqlog
2014-12-07 12:44 - 2014-12-07 12:44 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Hewlett-Packard_Company
2014-12-07 12:34 - 2014-12-09 18:42 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-12-07 12:34 - 2009-06-10 21:30 - 00048265 _____ () C:\Windows\HomePremium.xml
2014-12-07 04:46 - 2014-12-07 04:46 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\HP TCS
2014-12-07 04:44 - 2014-12-10 11:14 - 00000000 ____D () C:\Users\srsrsrsfser3
2014-12-07 04:44 - 2014-12-07 12:45 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Local\Hewlett-Packard
2014-12-07 04:44 - 2014-12-07 04:44 - 00000020 ___SH () C:\Users\srsrsrsfser3\ntuser.ini
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Vorlagen
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Startmenü
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Netzwerkumgebung
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Lokale Einstellungen
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Eigene Dateien
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Druckumgebung
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Documents\Eigene Musik
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Documents\Eigene Bilder
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\AppData\Local\Verlauf
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\AppData\Local\Anwendungsdaten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\srsrsrsfser3\Anwendungsdaten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Programme
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\ProgramData\Favoriten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 __RSH () C:\Windows\SysWOW64\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_QCNF9450ZTR_E572001-041_4A_I363C_SQuanta_V32.16_F.04_T090910_WU3-0_L407_M6135_J500_7Intel_86E5_91.60_#141207_N10EC8168;80864237_(VT343EA#ABD)_XMOBILE_CN10_Z.MRK
2014-12-07 04:44 - 2014-12-07 04:44 - 00000000 __RSH () C:\Windows\system32\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_QCNF9450ZTR_E572001-041_4A_I363C_SQuanta_V32.16_F.04_T090910_WU3-0_L407_M6135_J500_7Intel_86E5_91.60_#141207_N10EC8168;80864237_(VT343EA#ABD)_XMOBILE_CN10_Z.MRK
2014-12-07 04:44 - 2014-12-07 04:03 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2014-12-07 04:44 - 2009-08-25 18:07 - 00000000 ____D () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery Manager
2014-12-07 04:44 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-07 04:44 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\srsrsrsfser3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-07 04:34 - 2014-12-07 04:34 - 00000000 ____D () C:\ProgramData\Recovery
2014-12-07 04:32 - 2014-12-07 15:03 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-07 04:14 - 2014-12-07 12:38 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2014-12-07 04:14 - 2014-12-07 04:14 - 00001140 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewShortcut1.lnk
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\tr
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\sv
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\ru
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\no
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\ko
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\ja
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\it
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\fr
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\es
2014-12-07 04:14 - 2014-12-07 04:14 - 00000000 ____D () C:\Windows\system32\da
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\tr
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\sv
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\ru
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\no
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\ko
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\ja
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\it
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\fr
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\es
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\SysWOW64\da
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Windows\DPDrv
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\ProgramData\Macrovision
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Program Files\DigitalPersona
2014-12-07 04:13 - 2014-12-07 04:13 - 00000000 ____D () C:\Program Files (x86)\DigitalPersona
2014-12-07 04:12 - 2014-12-07 04:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel Paint Shop Pro Photo X2
2014-12-07 04:11 - 2014-12-07 04:13 - 00000000 ____D () C:\ProgramData\Corel
2014-12-07 04:10 - 2014-12-07 04:10 - 00000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
2014-12-07 04:10 - 2014-12-07 04:10 - 00000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2014-12-07 04:10 - 2014-12-07 04:10 - 00000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2014-12-07 04:10 - 2014-12-07 04:10 - 00000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2014-12-07 04:09 - 2014-12-07 04:09 - 00000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2014-12-07 04:08 - 2014-12-07 04:08 - 00198698 _____ () C:\Windows\DirectX.log
2014-12-07 04:08 - 2014-12-07 04:08 - 00000000 ____D () C:\Windows\RegisteredPackages
2014-12-07 04:08 - 2014-12-07 04:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media
2014-12-07 04:08 - 2014-12-07 04:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel VideoStudio 12
2014-12-07 04:08 - 2014-12-07 04:08 - 00000000 ____D () C:\ProgramData\InterVideo
2014-12-07 04:08 - 2008-04-01 21:40 - 00209040 _____ () C:\Windows\SysWOW64\IVIresizeW7.dll
2014-12-07 04:08 - 2008-04-01 21:40 - 00204944 _____ () C:\Windows\SysWOW64\IVIresizeA6.dll
2014-12-07 04:08 - 2008-04-01 21:40 - 00196752 _____ () C:\Windows\SysWOW64\IVIresizeP6.dll
2014-12-07 04:08 - 2008-04-01 21:40 - 00196752 _____ () C:\Windows\SysWOW64\IVIresizeM6.dll
2014-12-07 04:08 - 2008-04-01 21:40 - 00192656 _____ () C:\Windows\SysWOW64\IVIresizePX.dll
2014-12-07 04:08 - 2008-04-01 21:40 - 00024720 _____ () C:\Windows\SysWOW64\IVIresize.dll
2014-12-07 04:08 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2014-12-07 04:08 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2014-12-07 04:08 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2014-12-07 04:08 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2014-12-07 04:08 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2014-12-07 04:08 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2014-12-07 04:08 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2014-12-07 04:08 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2014-12-07 04:08 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2014-12-07 04:08 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2014-12-07 04:08 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2014-12-07 04:08 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2014-12-07 04:08 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2014-12-07 04:08 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2014-12-07 04:08 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2014-12-07 04:08 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2014-12-07 04:08 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2014-12-07 04:08 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2014-12-07 04:08 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2014-12-07 04:08 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2014-12-07 04:08 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2014-12-07 04:08 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2014-12-07 04:08 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2014-12-07 04:08 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2014-12-07 04:08 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2014-12-07 04:08 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2014-12-07 04:08 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2014-12-07 04:08 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2014-12-07 04:08 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-12-07 04:08 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2014-12-07 04:08 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2014-12-07 04:08 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2014-12-07 04:08 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2014-12-07 04:08 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2014-12-07 04:08 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2014-12-07 04:08 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2014-12-07 04:08 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2014-12-07 04:08 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2014-12-07 04:08 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2014-12-07 04:08 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2014-12-07 04:08 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2014-12-07 04:08 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2014-12-07 04:08 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-12-07 04:08 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2014-12-07 04:08 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2014-12-07 04:08 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2014-12-07 04:08 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-12-07 04:08 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2014-12-07 04:08 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2014-12-07 04:08 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2014-12-07 04:08 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2014-12-07 04:08 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2014-12-07 04:08 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2014-12-07 04:08 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2014-12-07 04:08 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2014-12-07 04:08 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2014-12-07 04:08 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2014-12-07 04:08 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2014-12-07 04:08 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2014-12-07 04:08 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2014-12-07 04:08 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2014-12-07 04:08 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2014-12-07 04:08 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2014-12-07 04:08 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2014-12-07 04:08 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2014-12-07 04:08 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2014-12-07 04:08 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2014-12-07 04:08 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2014-12-07 04:08 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2014-12-07 04:08 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2014-12-07 04:08 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2014-12-07 04:08 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2014-12-07 04:08 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2014-12-07 04:08 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2014-12-07 04:08 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2014-12-07 04:08 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-12-07 04:08 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2014-12-07 04:08 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2014-12-07 04:05 - 2014-12-07 04:11 - 00000000 ____D () C:\Program Files (x86)\Corel
2014-12-07 04:05 - 2014-12-07 04:05 - 00000000 ____D () C:\ProgramData\Ulead Systems
2014-12-07 04:03 - 2014-12-07 04:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2014-12-07 04:03 - 2014-12-07 04:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2014-12-07 04:01 - 2014-12-07 04:01 - 00003170 _____ () C:\Windows\System32\Tasks\TVAgent
2014-12-07 04:01 - 2014-12-07 04:01 - 00002824 _____ () C:\Windows\System32\Tasks\CapSchedInst
2014-12-07 04:01 - 2014-12-07 04:01 - 00002820 _____ () C:\Windows\System32\Tasks\CapSvcInst
2014-12-07 04:01 - 2014-12-07 04:01 - 00002818 _____ () C:\Windows\System32\Tasks\CapUninst
2014-12-07 03:59 - 2014-12-07 03:59 - 00003200 _____ () C:\Windows\System32\Tasks\CLMLSvc
2014-12-07 03:54 - 2014-12-07 03:54 - 00003164 _____ () C:\Windows\System32\Tasks\DVDAgent
2014-12-07 03:51 - 2014-12-10 02:26 - 00236772 _____ () C:\Windows\PFRO.log
2014-12-07 03:49 - 2009-06-04 18:54 - 00408600 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys
2014-12-07 03:48 - 2014-12-07 03:48 - 00000000 ____D () C:\Program Files\WIDCOMM
2014-12-07 03:48 - 2009-07-17 21:58 - 00132648 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2014-12-07 03:48 - 2009-07-17 21:58 - 00098344 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2014-12-07 03:48 - 2009-07-17 21:58 - 00035104 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2014-12-07 03:48 - 2009-07-17 21:58 - 00021160 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2014-12-07 03:47 - 2014-12-07 03:47 - 00000000 ____D () C:\Windows\Hewlett-Packard
         


Alt 10.12.2014, 12:41   #36
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Code:
ATTFilter
2014-12-07 03:47 - 2014-12-07 03:47 - 00000000 ____D () C:\Windows\Driver Cache
2014-12-07 03:47 - 2014-12-07 03:47 - 00000000 ____D () C:\Program Files (x86)\AVerMedia
2014-12-07 03:47 - 2009-05-22 07:32 - 00311424 _____ (AVerMedia TECHNOLOGIES, Inc.) C:\Windows\system32\Drivers\AVerAF15.sys
2014-12-07 03:47 - 2009-05-11 10:21 - 00000350 _____ () C:\Windows\system32\AP6RMHV.BIN
2014-12-07 03:47 - 2009-05-11 10:21 - 00000308 _____ () C:\Windows\system32\AP6RMKV.BIN
2014-12-07 03:47 - 2009-05-11 10:21 - 00000252 _____ () C:\Windows\system32\AP6RMJH.BIN
2014-12-07 03:47 - 2009-05-11 10:21 - 00000238 _____ () C:\Windows\system32\AP6RMFP.BIN
2014-12-07 03:47 - 2009-05-11 10:21 - 00000189 _____ () C:\Windows\system32\AP6RMKS.BIN
2014-12-07 03:47 - 2009-05-11 10:21 - 00000126 _____ () C:\Windows\system32\AP6RMHR.BIN
2014-12-07 03:46 - 2014-12-07 03:46 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-12-07 03:46 - 2009-07-23 18:02 - 05435904 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETw5v64.sys
2014-12-07 03:46 - 2009-07-13 23:31 - 00233472 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2014-12-07 03:46 - 2009-05-27 04:30 - 00076288 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2014-12-07 03:46 - 2009-03-05 23:54 - 00067584 _____ () C:\Windows\system32\RtNicProp64.dll
2014-12-07 03:45 - 2014-12-10 11:01 - 01969092 _____ () C:\Windows\WindowsUpdate.log
2014-12-07 03:45 - 2014-12-07 03:46 - 00000000 ____D () C:\Program Files\IDT
2014-12-07 03:45 - 2014-12-07 03:45 - 00000000 ____D () C:\Windows\system32\SRSLabs
2014-12-07 03:45 - 2010-03-23 14:53 - 12772352 _____ (IDT, Inc.) C:\Windows\system32\idtcpl64.cpl
2014-12-07 03:45 - 2010-03-23 14:53 - 03348480 _____ (IDT, Inc.) C:\Windows\system32\stlang64.dll
2014-12-07 03:45 - 2010-03-23 14:53 - 00564224 _____ (IDT, Inc.) C:\Windows\system32\idt64mp1.exe
2014-12-07 03:45 - 2010-03-23 14:53 - 00487424 _____ (IDT, Inc.) C:\Windows\sttray64.exe
2014-12-07 03:45 - 2010-01-26 18:30 - 00162816 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTAC64.dll
2014-12-07 03:45 - 2009-10-09 16:45 - 00442368 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTEC64.dll
2014-12-07 03:45 - 2009-03-02 17:58 - 00068608 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTAR64.dll
2014-12-07 03:45 - 2009-03-02 17:47 - 00090624 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTCo64.dll
2014-12-07 03:44 - 2014-12-07 03:44 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2014-12-07 03:44 - 2014-12-07 03:44 - 00000000 ____D () C:\Program Files\Validity Sensors
2014-12-07 03:44 - 2014-12-07 03:44 - 00000000 ____D () C:\Program Files\DIFX
2014-12-07 03:43 - 2014-12-07 14:17 - 00028532 _____ () C:\Windows\DPINST.LOG
2014-12-07 03:43 - 2014-12-07 03:43 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01007.Wdf
2014-12-07 03:43 - 2014-12-07 03:43 - 00000000 ____D () C:\Program Files\Synaptics
2014-12-07 03:43 - 2014-12-07 03:43 - 00000000 ____D () C:\Program Files (x86)\JMicron
2014-12-07 03:42 - 2009-07-22 08:57 - 00539680 _____ (NVIDIA Corporation) C:\Windows\system32\NVUNINST.EXE
2014-12-07 03:38 - 2014-12-07 03:38 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2014-12-07 03:38 - 2014-12-07 03:38 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-11-18 14:56 - 2014-11-18 14:56 - 01202848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FM20.DLL

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-10 10:58 - 2009-07-14 05:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-10 10:58 - 2009-07-14 05:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-10 10:52 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-10 10:52 - 2009-07-14 05:51 - 00043174 _____ () C:\Windows\setupact.log
2014-12-10 09:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-10 05:02 - 2009-08-26 02:25 - 00685218 _____ () C:\Windows\system32\perfh007.dat
2014-12-10 05:02 - 2009-08-26 02:25 - 00145018 _____ () C:\Windows\system32\perfc007.dat
2014-12-10 05:02 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-10 02:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-12-10 02:23 - 2009-08-25 17:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 02:01 - 2009-07-14 05:45 - 00368224 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-10 01:57 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-12-10 01:57 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-12-10 01:57 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-10 01:45 - 2009-07-14 06:08 - 00011970 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-09 23:42 - 2009-08-25 17:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-12-09 23:22 - 2009-08-25 18:59 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-12-09 23:22 - 2009-08-25 18:59 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-12-09 23:22 - 2009-08-25 18:59 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-12-09 23:22 - 2009-08-25 18:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-12-09 21:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-09 18:31 - 2009-07-14 03:34 - 00000439 _____ () C:\Windows\win.ini
2014-12-08 07:16 - 2009-08-25 18:46 - 00588472 _____ (EasyBits Software AS) C:\Windows\SysWOW64\ezsvc7x.dll
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2014-12-07 22:36 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\sppui
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\manifeststore
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\AdvancedInstallers
2014-12-07 22:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing
2014-12-07 22:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sppui
2014-12-07 22:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Setup
2014-12-07 22:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe
2014-12-07 22:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\migwiz
2014-12-07 22:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\manifeststore
2014-12-07 22:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2014-12-07 20:32 - 2009-07-14 03:36 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2014-12-07 20:32 - 2009-07-14 03:36 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2014-12-07 17:43 - 2009-07-14 03:34 - 00450771 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_793
2014-12-07 14:34 - 2009-08-25 17:32 - 00001151 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works-Start.lnk
2014-12-07 14:34 - 2009-08-25 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
2014-12-07 14:34 - 2009-08-25 17:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-12-07 13:43 - 2009-08-25 16:52 - 00000000 ____D () C:\ProgramData\Norton
2014-12-07 13:40 - 2009-08-25 17:23 - 00000000 ____D () C:\ProgramData\WildTangent
2014-12-07 13:40 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-07 13:35 - 2009-08-25 16:36 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-12-07 13:33 - 2009-08-25 19:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard
2014-12-07 12:44 - 2009-07-17 00:15 - 00000000 ____D () C:\SwSetup
2014-12-07 12:43 - 2009-08-25 16:38 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-12-07 12:38 - 2009-08-25 17:30 - 00000000 ___RD () C:\Program Files\Online Services
2014-12-07 12:38 - 2009-08-25 17:23 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2014-12-07 12:35 - 2009-08-25 17:53 - 00000000 ____D () C:\Windows\SHELLNEW
2014-12-07 12:35 - 2009-08-25 17:16 - 00000012 _____ () C:\Windows\CSUP.txt
2014-12-07 12:34 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-12-07 12:33 - 2009-07-14 06:38 - 00029696 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-12-07 12:33 - 2009-07-14 06:32 - 00032768 _____ () C:\Windows\system32\config\BCD-Template
2014-12-07 04:45 - 2009-07-25 06:17 - 00000000 __SHD () C:\Recovery
2014-12-07 04:45 - 2009-07-17 00:15 - 00000000 ___HD () C:\SYSTEM.SAV
2014-12-07 04:45 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore
2014-12-07 04:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-12-07 04:44 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-07 04:44 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Windows NT
2014-12-07 04:40 - 2009-07-25 07:11 - 00000000 ____D () C:\Windows\Panther
2014-12-07 04:33 - 2009-07-14 05:46 - 00004059 _____ () C:\Windows\DtcInstall.log
2014-12-07 04:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep
2014-12-07 04:15 - 2009-08-25 16:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2014-12-07 04:15 - 2009-08-25 16:40 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-12-07 04:14 - 2009-08-26 02:25 - 00000000 ____D () C:\Windows\system32\de
2014-12-07 04:14 - 2009-08-26 02:12 - 00000000 ___HD () C:\HP
2014-12-07 04:13 - 2009-08-26 02:25 - 00000000 ____D () C:\Windows\SysWOW64\de
2014-12-07 04:10 - 2009-08-25 18:30 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2014-12-07 04:10 - 2009-08-25 18:07 - 00000000 ____D () C:\ProgramData\Temp
2014-12-07 04:10 - 2009-08-25 16:38 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-12-07 04:09 - 2009-08-25 18:30 - 00000000 ____D () C:\ProgramData\CyberLink
2014-12-07 04:04 - 2009-08-25 16:36 - 00000000 ____D () C:\Program Files\Hewlett-Packard
2014-12-07 03:55 - 2009-08-25 19:23 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-12-07 03:49 - 2009-08-25 17:16 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-12-07 03:48 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-07 03:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-12-07 03:38 - 2009-07-25 06:14 - 00005767 _____ () C:\Windows\TSSysprep.log

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-10 09:16

==================== End Of Log ============================
         
Addition

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-12-2014 02
Ran by srsrsrsfser3 at 2014-12-10 11:18:12
Running from C:\Users\srsrsrsfser3\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: G DATA TOTAL PROTECTION (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: G DATA TOTAL PROTECTION (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: G DATA Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.1 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.22.87 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Reader 9.1 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
AVerMedia TV Tuner Card 1.0.0.4 (HKLM-x32\...\AVerMedia TV Tuner Card) (Version: 1.0.0.4 - AVerMedia TECHNOLOGIES, Inc.)
Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Corel Paint Shop Pro Photo X2 (HKLM-x32\...\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}) (Version: 12.50.0001 - Corel Corporation)
Corel VideoStudio 12 (HKLM-x32\...\InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}) (Version: 12.0.0.0000 - Corel Corporation)
CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.3101 - CyberLink Corp.)
DigitalPersona Personal 4.10 (HKLM\...\{DD3BF908-F6B0-45A5-BED3-79E8888DDA93}) (Version: 4.10.3787 - DigitalPersona, Inc.)
ENE CIR Receiver Driver (HKLM\...\FFE7D41DF3C645075BB149E21988B63996C34187) (Version: 2.7.4.0 - ENE)
G DATA TOTAL PROTECTION (HKLM-x32\...\{6715BEB5-01F1-41AC-B44B-0A78CD50C433}) (Version: 25.0.2.2 - G DATA Software AG)
HP 3D DriveGuard (HKLM\...\{7FD7F421-39B2-4CAC-BC41-7D83DDBAB329}) (Version: 4.0.3.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM-x32\...\{5B295588-59C1-4386-9F85-BB4BEDCB0D22}) (Version: 5.7.0.3036 - Hewlett-Packard)
HP Integrated Module with Bluetooth wireless technology (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.0.9600 - Broadcom Corporation)
HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 3.0.3123 - Hewlett-Packard)
HP MediaSmart Internet TV (HKLM-x32\...\InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}) (Version: 3.0.1916 - Hewlett-Packard)
HP MediaSmart Live TV (HKLM-x32\...\InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}) (Version: 3.0.1924 - Hewlett-Packard)
HP MediaSmart Movie Themes (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 3.0.3102 - Hewlett-Packard)
HP MediaSmart Music/Photo/Video (HKLM-x32\...\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 3.0.3123 - Hewlett-Packard)
HP MediaSmart SmartMenu (HKLM\...\{88E60521-1E4E-4785-B9F1-1798A4BD0C30}) (Version: 3.0.30.1 - Hewlett-Packard)
HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.1913 - Hewlett-Packard)
HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.3.1 - Hewlett-Packard)
HP Setup (HKLM-x32\...\{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}) (Version: 1.2.3220.3079 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{4F46FDB9-B906-47BF-B3D5-C62E01B3C5EE}) (Version: 4.1.11.3 - Hewlett-Packard)
HP Update (HKLM-x32\...\{D46D081B-F60E-467E-A7C4-117B70D76731}) (Version: 5.001.000.014 - Hewlett-Packard)
HP User Guides 0153 (HKLM-x32\...\{2EBA8202-FBD5-4004-81EA-BDC38C054CE2}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM-x32\...\{54CC7901-804D-4155-B353-21F0CC9112AB}) (Version: 3.50.9.1 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6225.0 - IDT)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.32.1 - JMicron Technology Corp.)
Junk Mail filter update (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1913 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.1913 - CyberLink Corp.) Hidden
ManyCam 4.0.110 (HKLM-x32\...\ManyCam) (Version: 4.0.110 - Visicom Media Inc.)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31010.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.5 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.5615 - CyberLink Corp.)
PhotoNow! (x32 Version: 1.1.5615 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3101 - CyberLink Corp.)
Power2Go (x32 Version: 6.0.3101 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3101 - CyberLink Corp.)
PowerDirector (x32 Version: 7.0.3101 - CyberLink Corp.) Hidden
PowerRecover (x32 Version: 5.5.1923 - CyberLink Corp.) Hidden
QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden
Realtek 8136 8168 8169 Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0007 - Realtek)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Validity Sensors DDK (HKLM\...\{62A20ECA-920E-4052-BF77-88C78DD20FAA}) (Version: 3.1.366 - Validity Sensors, Inc.)
VideoStudio (x32 Version: 12.0.0.0000 - Corel Corporation) Hidden
Windows Live Anmelde-Assistent (HKLM-x32\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8064.0206 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

09-12-2014 19:51:09 Ende der Bereinigung
09-12-2014 21:49:26 Windows Update
10-12-2014 01:13:30 Windows Update
10-12-2014 01:32:33 Windows Update
10-12-2014 01:41:13 Windows Update
10-12-2014 01:44:31 Windows Update
10-12-2014 01:47:24 Windows Update
10-12-2014 01:51:03 Windows Update
10-12-2014 01:57:08 Windows Update
10-12-2014 03:54:29 Windows Update
10-12-2014 06:54:45 Windows Update
10-12-2014 09:56:24 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-12-10 01:12 - 00450796 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1	localhost
127.0.0.1	www.007guard.com
127.0.0.1	007guard.com
127.0.0.1	008i.com
127.0.0.1	www.008k.com
127.0.0.1	008k.com
127.0.0.1	www.00hq.com
127.0.0.1	00hq.com
127.0.0.1	010402.com
127.0.0.1	www.032439.com
127.0.0.1	032439.com
127.0.0.1	www.0scan.com
127.0.0.1	0scan.com
127.0.0.1	1000gratisproben.com
127.0.0.1	www.1000gratisproben.com
127.0.0.1	1001namen.com
127.0.0.1	www.1001namen.com
127.0.0.1	100888290cs.com
127.0.0.1	www.100888290cs.com
127.0.0.1	www.100sexlinks.com
127.0.0.1	100sexlinks.com
127.0.0.1	10sek.com
127.0.0.1	www.10sek.com
127.0.0.1	www.1-2005-search.com
127.0.0.1	1-2005-search.com
127.0.0.1	123fporn.info
127.0.0.1	www.123fporn.info
127.0.0.1	123haustiereundmehr.com
127.0.0.1	www.123haustiereundmehr.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1E1B8F80-421A-4751-9583-E837DC7DF6FF} - System32\Tasks\CapSvcInst => c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\CapSvcInst.exe [2009-07-24] (CL)
Task: {2675AEED-CAB8-4C7D-8291-BB6C5C8630F7} - System32\Tasks\RMCreator => C:\Program Files (x86)\Hewlett-Packard\Recovery\Reminder.exe [2009-07-23] (CyberLink)
Task: {344FA916-0043-440E-AFFC-F87733D8B70F} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2009-07-08] ()
Task: {3748D883-B1EF-4C68-8717-03766CA00BEF} - System32\Tasks\DVDAgent => c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [2009-07-23] (CyberLink Corp.)
Task: {39AB06C3-2461-4383-957D-92C8EB15384C} - System32\Tasks\CLMLSvc => c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2009-07-23] (CyberLink)
Task: {87FA7DA2-0D5F-4C63-843A-67364C9C9066} - System32\Tasks\CapSchedInst => c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\CapSchedInst.exe [2009-07-24] (CL)
Task: {AE5DD575-F0CF-4CCB-BDA5-187FA1BAB30C} - System32\Tasks\Hewlett-Packard\HP Assistant\First Boot => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2009-07-09] (Hewlett-Packard)
Task: {D2B55315-9CE5-49ED-B4C5-F5EEB876A344} - System32\Tasks\TVAgent => c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe [2009-07-24] (CyberLink Corp.)
Task: {DFAB2D2E-A83A-4DFA-B0B1-ED04074F1032} - System32\Tasks\CapUninst => c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\CapUninst.exe [2009-07-24] (CL)
Task: {FEB81587-E050-4613-A8AB-810876934A43} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2009-07-08] ()

==================== Loaded Modules (whitelisted) =============

2009-08-25 18:35 - 2009-01-21 19:47 - 00247152 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-12-07 14:46 - 2013-10-23 09:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-05-20 02:38 - 2014-05-20 02:38 - 00340088 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll
2014-05-12 10:49 - 2014-05-12 10:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2009-07-16 15:09 - 2009-07-16 15:09 - 00074536 ____N () c:\Program Files (x86)\Hewlett-Packard\Media\iTV\Kernel\Common\MCEMediaStatus64.dll
2009-07-23 11:37 - 2009-07-23 11:37 - 00931112 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-2386857783-215228460-2573036698-500 - Administrator - Disabled)
Gast (S-1-5-21-2386857783-215228460-2573036698-501 - Limited - Disabled)
srsrsrsfser3 (S-1-5-21-2386857783-215228460-2573036698-1000 - Administrator - Enabled) => C:\Users\srsrsrsfser3
UpdatusUser (S-1-5-21-2386857783-215228460-2573036698-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Faulty Device Manager Devices =============

Name: HP Integrated Module with Bluetooth 2.1 Wireless Technology
Description: HP Integrated Module with Bluetooth 2.1 Wireless Technology
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/10/2014 11:13:46 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (12/10/2014 11:13:19 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (12/10/2014 09:37:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AVKProxy.exe, Version: 1.5.14211.177, Zeitstempel: 0x53d842e7
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00630069
ID des fehlerhaften Prozesses: 0x1ba8
Startzeit der fehlerhaften Anwendung: 0xAVKProxy.exe0
Pfad der fehlerhaften Anwendung: AVKProxy.exe1
Pfad des fehlerhaften Moduls: AVKProxy.exe2
Berichtskennung: AVKProxy.exe3

Error: (12/10/2014 09:35:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AVKProxy.exe, Version: 1.5.14211.177, Zeitstempel: 0x53d842e7
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x41754a6f
ID des fehlerhaften Prozesses: 0x820
Startzeit der fehlerhaften Anwendung: 0xAVKProxy.exe0
Pfad der fehlerhaften Anwendung: AVKProxy.exe1
Pfad des fehlerhaften Moduls: AVKProxy.exe2
Berichtskennung: AVKProxy.exe3

Error: (12/10/2014 09:21:08 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (12/10/2014 06:57:28 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (12/10/2014 02:00:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: daemonu.exe, Version: 1.15.2.0, Zeitstempel: 0x526769f5
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x74a071fc
ID des fehlerhaften Prozesses: 0xec0
Startzeit der fehlerhaften Anwendung: 0xdaemonu.exe0
Pfad der fehlerhaften Anwendung: daemonu.exe1
Pfad des fehlerhaften Moduls: daemonu.exe2
Berichtskennung: daemonu.exe3

Error: (12/10/2014 01:59:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RichVideo.exe, Version: 2.0.0.3027, Zeitstempel: 0x4864c8fb
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x74a071fc
ID des fehlerhaften Prozesses: 0xa1c
Startzeit der fehlerhaften Anwendung: 0xRichVideo.exe0
Pfad der fehlerhaften Anwendung: RichVideo.exe1
Pfad des fehlerhaften Moduls: RichVideo.exe2
Berichtskennung: RichVideo.exe3

Error: (12/10/2014 01:59:58 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: PsiService_2.exe, Version: 2.0.1.124, Zeitstempel: 0x46a641af
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x74a071fc
ID des fehlerhaften Prozesses: 0x9b8
Startzeit der fehlerhaften Anwendung: 0xPsiService_2.exe0
Pfad der fehlerhaften Anwendung: PsiService_2.exe1
Pfad des fehlerhaften Moduls: PsiService_2.exe2
Berichtskennung: PsiService_2.exe3

Error: (12/10/2014 01:59:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x74a071fc
ID des fehlerhaften Prozesses: 0x874
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3


System errors:
=============
Error: (12/10/2014 11:00:20 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800706f7 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB2847077)

Error: (12/10/2014 10:54:31 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {7D1933CB-86F6-4A98-8628-01BE94C9A575}

Error: (12/10/2014 09:54:11 AM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist.

Error: (12/10/2014 09:37:00 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "G DATA ANTIVIRUS Proxy" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: 
%%1056

Error: (12/10/2014 09:36:00 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "G DATA ANTIVIRUS Proxy" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/10/2014 07:55:15 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800706f7 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB2847077)

Error: (12/10/2014 07:37:42 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎10.‎12.‎2014 um 07:35:39 unerwartet heruntergefahren.

Error: (12/10/2014 07:35:37 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/10/2014 06:22:04 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Biometrischer Authentifizierungsdienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (12/10/2014 06:12:07 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Bluetooth Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7 CPU Q 720 @ 1.60GHz
Percentage of memory in use: 28%
Total physical RAM: 6134.88 MB
Available physical RAM: 4388.06 MB
Total Pagefile: 12267.94 MB
Available Pagefile: 9950.92 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:450.21 GB) (Free:397.19 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:465.76 GB) (Free:464.86 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:15.25 GB) (Free:2.48 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 4B7D9E39)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0B761687)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Gmer

Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-12-10 11:40:09
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.0006 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\SRSRSR~1\AppData\Local\Temp\kxrcqaow.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                           fffff800031aa000 54 bytes [84, DB, 02, 00, 00, 48, 3B, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 583                                                                           fffff800031aa037 21 bytes [8B, 84, 24, 20, 01, 00, 00, ...]

---- User code sections - GMER 2.1 ----

.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                          0000000075d11401 2 bytes JMP 754cb21b C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                            0000000075d11419 2 bytes JMP 754cb346 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                          0000000075d11431 2 bytes JMP 75548ea9 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                          0000000075d1144a 2 bytes CALL 754a48ad C:\Windows\syswow64\kernel32.dll
.text     ...                                                                                                                                          * 9
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                             0000000075d114dd 2 bytes JMP 755487a2 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                      0000000075d114f5 2 bytes JMP 75548978 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                             0000000075d1150d 2 bytes JMP 75548698 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                      0000000075d11525 2 bytes JMP 75548a62 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                            0000000075d1153d 2 bytes JMP 754bfca8 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                 0000000075d11555 2 bytes JMP 754c68ef C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                          0000000075d1156d 2 bytes JMP 75548f61 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                            0000000075d11585 2 bytes JMP 75548ac2 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                               0000000075d1159d 2 bytes JMP 7554865c C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                            0000000075d115b5 2 bytes JMP 754bfd41 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                          0000000075d115cd 2 bytes JMP 754cb2dc C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                      0000000075d116b2 2 bytes JMP 75548e24 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                      0000000075d116bd 2 bytes JMP 755485f1 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17      0000000075d11401 2 bytes JMP 754cb21b C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17        0000000075d11419 2 bytes JMP 754cb346 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17      0000000075d11431 2 bytes JMP 75548ea9 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42      0000000075d1144a 2 bytes CALL 754a48ad C:\Windows\syswow64\kernel32.dll
.text     ...                                                                                                                                          * 9
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17         0000000075d114dd 2 bytes JMP 755487a2 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17  0000000075d114f5 2 bytes JMP 75548978 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17         0000000075d1150d 2 bytes JMP 75548698 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17  0000000075d11525 2 bytes JMP 75548a62 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17        0000000075d1153d 2 bytes JMP 754bfca8 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17             0000000075d11555 2 bytes JMP 754c68ef C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17      0000000075d1156d 2 bytes JMP 75548f61 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17        0000000075d11585 2 bytes JMP 75548ac2 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17           0000000075d1159d 2 bytes JMP 7554865c C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17        0000000075d115b5 2 bytes JMP 754bfd41 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17      0000000075d115cd 2 bytes JMP 754cb2dc C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20  0000000075d116b2 2 bytes JMP 75548e24 C:\Windows\syswow64\kernel32.dll
.text     C:\Program Files (x86)\G DATA\TotalProtection\Firewall\GDFirewallTray.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31  0000000075d116bd 2 bytes JMP 755485f1 C:\Windows\syswow64\kernel32.dll

---- Disk sectors - GMER 2.1 ----

Disk      \Device\Harddisk0\DR0                                                                                                                        unknown MBR code

---- EOF - GMER 2.1 ----
         

Alt 10.12.2014, 14:31   #37
Machiavelli
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Das Log ist an sich sauber.

Zitat:
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: G DATA TOTAL PROTECTION (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
Da liegt das Problem. Du hast 2 AVs aktiv, solltest nur eines laufen lassen. Entweder Du deinstallierst eins von beiden, oder deaktivierst eins von beiden.

Das alleine könnte die Auslastung Deines Systems erklären.
__________________
Proud member of Unite

Alt 10.12.2014, 16:53   #38
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Sorry aber normal war das nicht diese Nacht. Ich hab an mir selbst gezweifelt.
Irgendwas legt im Hintergrund komplette Kopien vom Rechner an....und das alle paar stunden....Es laufen ominöse Bluetooth Anwendungen,sehen aus wie Bluetooth ihre Beschreibung deutet auf Bluetooth.....aber schreiben und lesen....das sind Prozesse, die ich nicht stoppen kann....wenn ich sie anhalte starten sie wieder....habe die Anwendungen runtergeschmissen....gehe aus dem ordner raus...wieder rein...alles wieder da. hab mal paar Bilder angehängt.....ich weiß nicht wie ich das erklären soll....hab das gefühl, programme gaukeln mir nur vor das zu sein,was sie sein sollten.

Code:
ATTFilter
[12/10/2014, 2:16:2] === Logging started: 2014/12/10 02:16:02 ===
[12/10/2014, 2:16:2] Executable: C:\Windows\SoftwareDistribution\Download\Install\NDP451-KB2858725-x86-x64-ENU.exe v4.5.50938.18408
[12/10/2014, 2:16:2] --- logging level: standard ---
[12/10/2014, 2:16:3] Successfully bound to the ClusApi.dll
[12/10/2014, 2:16:3] Error 0x80070424: Failed to open the current cluster
[12/10/2014, 2:16:3] Cluster drive map: ''
[12/10/2014, 2:16:3] Considering drive: 'C:\'...
[12/10/2014, 2:16:3] Considering drive: 'D:\'...
[12/10/2014, 2:16:3] Considering drive: 'E:\'...
[12/10/2014, 2:16:3] Considering drive: 'F:\'...
[12/10/2014, 2:16:3] Drive 'F:\' is rejected because of the unknown or unsuitable drive type
[12/10/2014, 2:16:3] Drive 'D:\' has been selected as the largest fixed drive
[12/10/2014, 2:16:3] Directory 'D:\0a5d06cdf6260be764b38f\' has been selected for file extraction
[12/10/2014, 2:16:3] Extracting files to: D:\0a5d06cdf6260be764b38f\
[12/10/2014, 2:16:23] Extraction took 19.968 seconds
[12/10/2014, 2:16:23] Executing command line: 'D:\0a5d06cdf6260be764b38f\\Setup.exe  /q /norestart /SkipMSUInstall /chainingpackage NETFX45WURTM /x86 /x64 /redist'
[12/10/2014, 2:23:5] Exiting with result code: 0x0
[12/10/2014, 2:23:5] === Logging stopped: 2014/12/10 02:23:05 ===
         
Miniaturansicht angehängter Grafiken
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-pic1.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-pic2.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-krass.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-wasistdas.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-wiegehtdas.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-wtf.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-beispiel.jpg  

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-sowas.jpg  

Alt 10.12.2014, 17:18   #39
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Code:
ATTFilter
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "hxxp://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<!-- The Extended Copyright/Trademark Language Resides At: hxxp://www.microsoft.com/info/cpyrtInfrg.htm -->
<html xmlns="hxxp://www.w3.org/1999/xhtml">
<head>
	<meta http-equiv="Content-Type" content="text/html; charset=utf-16"/><base target="_blank"/>
	<style type="text/css">
		html{overflow:scroll}
		body{font-size:10pt;font-family:Verdana;color:#000000;background-color:#F0F0F0}
		.header{overflow:hidden;white-space:nowrap}td{padding-top:0.2em;padding-bottom:0.2em}
		.searchbox{padding-top:0.2em;font-size:9pt}.button{background-color:#F0F0F0;border-width:1px}
		.messages{  font-size:9pt;
					font-family:Arial;
					background-color:#FFFFFF;
					border-top-width:medium;
					border-top-style:solid;
					border-top-color:#C0C0C0;
					overflow:hidden;
					position:relative;
					width:95%;					
					}.hilight{background-color:#FFFF40}
		.sectionHdr{margin-left:0.8em;font-weight:bold} 
		.sectionExp{font-weight:bold} 
		.sectionExp2{font-weight:bold;display:none}		
		.section{margin-left:0.8em} 

		div.t{display:none} 
		div.f{display:none} 
		.pointer{   cursor: pointer; 
					cursor:hand;
				} 
		a{text-decoration:none} 
		div.vbe{display:none}

		a:link{color:#0000FF} 
		a:visited{color:#0000FF} 
		a:active{color:#0000FF} 
		a:hover{color:#0000FF}

		.err{color:#000000;background-color:#FFD0D0;font-weight:bold} 
		.f{color:#208080} 
		.wrn{color:#000000;font-weight:bold}
		.msg{color:#000000} 
		.ver{color:#808080} 
		.r{font-size: 120%; font-weight:bolder} 

		div.r{display:inline}
		div.err{display:inline} 
		div.wrn{display:inline} 
		div.msg{display:inline} 
		div.dbg{display:inline} 
		div.itn{display:inline} 
		div.ver{display:none} 
		div.vbe{display:inline} 
		div.t{display:inline}  
		div.f{display:inline} 
		div.act{display:inline}

		span.t{display:none} 
		span.f{display:none} 
		span.r{display:inline}
	</style>
	<script type="text/javascript">
	
		// This function is used to present the install summary information.
		function showResult(sClassName, fDisplayResult)
		{
			showClass(sClassName, fDisplayResult);

			// Expand all nodes and turn off all classes except result.
			if (true == fDisplayResult) 
			{
				// Uncheck all checkboxes.
				document.getElementById("errCB").checked = false;
				document.getElementById("vbeCB").checked = false;
				document.getElementById("msgCB").checked = false;
				document.getElementById("tCB").checked = false;
			 
				// Hide respective contents.
				showClass("err",0);
				showClass("vbe",0);
				showClass("msg",0);
				showClass("dbg",0);
				showClass("itn",0);
				showClass("t",0);
				addRule(document.styleSheets[0], "div.sectionHdr", "display:none");	 
			}
			else
			{
				addRule(document.styleSheets[0], "div.sectionHdr", "display:inline");	 
			}
		}

		// This function is the entry for hiding/displaying a class of entries.
		function showClass(sClassName , fDisplayClass) 
		{
			// Need to bring back the sectionHdr because it may potentially be hidden by ShowResult()
			addRule(document.styleSheets[0], "div.sectionHdr", "display:inline");
			var type="span";
			var display="inline";
			addRule(document.styleSheets[0], type + "." + sClassName, "display:" + ( fDisplayClass ? display : "none" ) );
			updateSections();
		}
		
		function updateSections() 
		{
			var nodeList = document.getElementById("messages").childNodes;
			var totalNodes = nodeList.length;
			for (var i = 0; i < totalNodes; i++)
			{
				if(nodeList[i].className == "section")
				{
					updateSection(nodeList[i]);
				}
			}		  
		}
		
		// Display entries based on the status of checkbox
		function updateSection(node) 
		{
			var fFoundVis = false;
			var nodeList = node.children;
			var totalNodes = nodeList.length;
			for (var i = 0; i < totalNodes; i++)
			{
				if(nodeList[i].className == "section") 
				{
					var fVis = updateSection(nodeList[i]);
					if (fVis)
					{ 
						fFoundVis = true;
					}
				} 
				else 
				{
					var checkName = nodeList[i].className + "CB";
					if (document.getElementById(checkName) && document.getElementById(checkName).checked)
					{
						fFoundVis = true;
					}
				}	
			}
			node.previousSibling.style.display = (fFoundVis ? "block" : "none");
			return fFoundVis;
		}
		
		function expandAll(fExpand, xLast) 
		{
			if (fExpand == 0) 
			{
				// If none of the check boxes are checked, meaning we are in summary mode, don't collapse
				var bChecked = false;
				bChecked = document.getElementById("errCB").checked || 
							document.getElementById("vbeCB").checked || 
							document.getElementById("msgCB").checked ||
							document.getElementById("tCB").checked ;
		  
				if (bChecked == false)
				{
					return;
				}
			}

			var nodeList = document.getElementsByTagName("*");
			var last = null;

			var totalNodes = nodeList.length;
			for (var i = 0; i < totalNodes; i++)
			{
				if(nodeList[i].className == "section") 
				{
					expand(nodeList[i], fExpand);
					if (xLast && nodeList[i].parentElement.className == "messages") 
					{
						last = nodeList[i];
					}
				}
			}
				
			if(last)
			{ 
				expand(last, !fExpand);
			}
		}

		function toggleSection() 
		{
			var node = event.srcElement.parentElement.parentElement.nextSibling;
			
			// Handle node being null when we are trying to expand the time span.
			if (node == null)
			{
				node = event.srcElement.parentElement.parentElement.parentElement.nextSibling;
			}
			expand(node, node.style.display == "none");			
		}
	 
		function expand(el, fExpand) 
		{
			el.style.display = (fExpand ? "block" : "none");
			el.previousSibling.childNodes[0].childNodes[1].style.display = (fExpand ? "none" : "inline");
		}
			 
		// Abstract the addRule/InsertRule functionality for cross-browser support.
		function addRule(sheet, sSelector , sRule)
		{
			if(sheet.insertRule)
			{
				sheet.insertRule(sSelector + "{" + sRule + "}", sheet.cssRules.length);
			}
			else if(sheet.addRule)
			{
				sheet.addRule(sSelector, sRule);
			}
		}		
	</script>
</head>

<body onload="expandAll(0,1);updateSections();showResult('r',true)";">
	<div class="header">
		<center><h1>Installation Log</h1></center>
		<table width=100%>
			<tr>
				<td>
					<b>Message Types: </b>
				</td>
				<td>
					<input id="errCB" type="checkbox" onclick="showClass('err',document.getElementById('errCB').checked);"/>
					<label for="errCB" class="pointer">Errors</label>&nbsp;&nbsp;

					<input id="vbeCB" type="checkbox" onclick="showClass('vbe',document.getElementById('vbeCB').checked);showClass('dbg',document.getElementById('vbeCB').checked)"/>
					<label for="vbeCB" class="pointer">Verbose</label>&nbsp;&nbsp;

					<input id="msgCB" type="checkbox" onclick="showClass('msg',document.getElementById('msgCB').checked);"/>
					<label for="msgCB" class="pointer">Messages</label>&nbsp;&nbsp;					
				</td>
				<td>
							
				</td>
			</tr>
			<tr>
				<td>
					  <b>Message Details: </b>
				</td>
				<td>
					 <input id="tCB" type="checkbox" onclick="showClass('t',document.getElementById('tCB').checked);"/>
					 <label for="tCB" class="pointer">Date Time</label>&nbsp;&nbsp;
				 
				</td>
				<td align="right">  
				   <input type="button" class="button" onclick="showResult('r',true)" value="Summary"/>&nbsp;
				   <input type="button" class="button" onclick="expandAll(1)" value="Expand All"/>&nbsp;
				   <input type="button" class="button" onclick="expandAll(0)" value="Collapse All"/>&nbsp;		   
				</td>
			</tr>
		</table>
	</div>
	<center><A HREF="hxxp://www.microsoft.com/info/cpyrtInfrg.htm"> &copy; 2009 Microsoft Corporation. All rights reserved. Terms of Use.</A></center>
	<form action="" id="messages" class="messages" />

<!-- End of header -->


<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:24] </span>OS Version Information:  </span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:24]</span>OS Version = 6.1.7601, SP = 1.0, Platform 2, Service Pack 1<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:24]</span>OS Description = Windows 7 - x64 Home Premium Edition Service Pack 1<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:24] </span>OS Version Information <BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:24] </span>Installer version details:  </span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:24]</span>MSI = 5.0.7601.18637<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:26]</span>Windows version = amd64_windowsfoundation_31bf3856ad364e35_6.1.7600.16385_none_5f2ecc1aaa4ac3b2.manifest<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:26]</span>Windows servicing = 6.1.7601.17592<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:26] </span>Installer version details <BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:26] </span>Environment details:  </span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:26]</span>CommandLine = D:\0a5d06cdf6260be764b38f\\Setup.exe  /q /norestart /SkipMSUInstall /chainingpackage NETFX45WURTM /x86 /x64 /redist<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:26]</span>TimeZone = Mitteleuropäische Zeit<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:26]</span>Initial LCID = 1031<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:26] </span>Environment details <BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:26]</span>Loading localized engine data for language 1031 from D:\0a5d06cdf6260be764b38f\1031\LocalizedData.xml<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:26] </span>Entering Function: LocalizedData::CreateLocalizedData</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:26]</span> exiting function/method<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:26] </span>succeeded<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:27] </span>Entering Function: EngineData::CreateEngineData</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:27]</span>Current SetupVersion = 1.0<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:27]</span>SetupVersion specified in ParameterInfo.xml is '1.0'<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "Exe", local path SetupUtility.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "ServiceControl", local path (not applicable)<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "ServiceControl", local path (not applicable)<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "ServiceControl", local path (not applicable)<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "ServiceControl", local path (not applicable)<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "File", local path Windows6.0-KB956250-v6001-x86.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "Exe", local path Windows6.0-KB956250-v6001-x86.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "File", local path Windows6.0-KB956250-v6001-x64.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "Exe", local path Windows6.0-KB956250-v6001-x64.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "File", local path Windows6.1-KB958488-v6001-x86.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:27]</span>Adding Item type "Exe", local path Windows6.1-KB958488-v6001-x86.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "File", local path Windows6.1-KB958488-v6001-x64.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "Exe", local path Windows6.1-KB958488-v6001-x64.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "Exe", local path SetupUtility.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "File", local path netfx_Full_LDR.mzz<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "File", local path netfx_Full_LDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "MSI", local path netfx_Full_LDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "MSI", local path netfx_Full_LDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "MSI", local path netfx_Full_LDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "File", local path netfx_Full_LDR.mzz<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "File", local path netfx_Full_LDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:28]</span>Adding Item type "MSI", local path netfx_Full_LDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:29]</span>Adding Item type "MSI", local path netfx_Full_LDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:29]</span>Adding Item type "MSI", local path netfx_Full_LDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:29]</span>Adding Item type "File", local path netfx_Full_GDR.mzz<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:29]</span>Adding Item type "MSI", local path netfx_Full_GDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:30]</span>Adding Item type "MSI", local path netfx_Full_GDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:30]</span>Adding Item type "MSI", local path netfx_Full_GDR_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:30]</span>Adding Item type "File", local path netfx_Full_GDR.mzz<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:30]</span>Adding Item type "MSI", local path netfx_Full_GDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "MSI", local path netfx_Full_GDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "MSI", local path netfx_Full_GDR_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "File", local path netfx_core_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "File", local path netfx_extended_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "File", local path netfx_core_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "File", local path netfx_extended_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "File", local path netfx_Full_x86.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "File", local path netfx_Full_x64.msi<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "Exe", local path NDP451-KB2858725-x86-DEU.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "Exe", local path NDP451-KB2858725-x86-x64-DEU.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "Exe", local path NDP451-KB2858725-x86-DEU.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "Exe", local path NDP451-KB2858725-x86-x64-DEU.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>For upgradecode {A7B31EFD-0E46-39F6-9D02-9B2B00D42285}, [1] related products were found.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>RelatedProducts item Setup.exe has 1 related products.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "RelatedProducts", local path (not applicable)<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "Exe", local path SetupUtility.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "Exe", local path SetupUtility.exe<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>Adding Item type "ServiceControl", local path (not applicable)<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:31]</span>No ProcessBlock element<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:31]</span>No ServiceBlock element<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:31]</span>Disabled CommandLineSwitch added: createlayout<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:31]</span>Using Simultaneous Download and Install mechanism<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:31]</span> exiting function/method<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>succeeded<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>MaintenanceMode determination: evaluating EnterMaintenanceModeIf</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>evaluating EnterMaintenanceModeIf:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Not evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>TargetArchitecture is x64<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Equals evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>MsiGetProductInfo with product code {4903D172-DCCB-392F-93A3-34CA9D47FE3D} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Exists evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>MsiGetProductInfo with product code {7F66508F-100B-380E-A7BB-379CDC3FE30A} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Or evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>And evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>TargetArchitecture is x64<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Equals evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Exists evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:31] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:31]</span>MsiGetProductInfo with product code {7E59919F-564E-3FB5-B1FC-884251B18B06} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Or evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>And evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:31] </span>Or evaluated to false<BR></div></span>
         
Code:
ATTFilter
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>MsiGetProductInfo with product code {7E59919F-564E-3FB5-B1FC-884251B18B06} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>Current Operation value is Installing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>Current Operation value is Installing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning false<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>evaluating ApplicableIf:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThan: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>TargetOS is 6.1.1<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:32]</span>all numeric characters - canonicalizing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThan evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>TargetArchitecture is x64<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThanOrEqualTo: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Version does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning BoolWhenNonExistent's value: true<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThanOrEqualTo evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>MsiGetProductInfo with product code {7E59919F-564E-3FB5-B1FC-884251B18B06} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>Current Operation value is Installing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 4.5\Baseliner\BaselinerInstalled does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\LDR does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning false<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>evaluating ApplicableIf:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThan: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>TargetOS is 6.1.1<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:32]</span>all numeric characters - canonicalizing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThan evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>TargetArchitecture is x64<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 4.5\Baseliner\BaselinerInstalled does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\LDR does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Or evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:32] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:32] </span>GreaterThanOrEqualTo: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:32]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Version does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: true<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThanOrEqualTo evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Current Operation value is Installing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Current Operation value is Installing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating ApplicableIf:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThan: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>TargetOS is 6.1.1<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>all numeric characters - canonicalizing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThan evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>TargetArchitecture is x64<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 4.5\Baseliner\BaselinerInstalled does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\LDR does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThanOrEqualTo: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Version does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: true<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThanOrEqualTo evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating ApplicableIf:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThan: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>TargetOS is 6.1.1<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>all numeric characters - canonicalizing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThan evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>TargetArchitecture is x64<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 4.5\Baseliner\BaselinerInstalled does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Equals: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\LDR does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Equals evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThanOrEqualTo: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>RegKeyValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Version does NOT exist.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning BoolWhenNonExistent's value: true<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThanOrEqualTo evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Or: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section"></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to false<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Not: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Not evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Or evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to false<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating ApplicableIf:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>And: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThan: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>TargetOS is 6.1.1<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>all numeric characters - canonicalizing<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>GreaterThan evaluated to true<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>MsiGetProductInfo with product code {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}, returned: 4.0.30319<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Exists evaluated to true<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>And evaluated to true<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning false<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Applicability for Installing determination is complete<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Applicability Result Count:  </span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:33]</span>Number of applicable items: 12<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Applicability Result Count <BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: System Requirement Checks</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: Disk space check for items being downloaded</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Drive:[C:\] Bytes Needed:[2974510730] Bytes Available:[430585724928]<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Action complete<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: Enumerating incompatible processes</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>No Blocking Processes<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Action complete<BR></div></span>

<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: Enumerating incompatible services</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>No Blocking Services<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Action complete<BR></div></span>
</div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Action complete<BR></div></span>

<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Launching Download and Install operations simultaneously.<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: Downloading and/or Verifying Items</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\Windows6.1-KB958488-v6001-x64.msu<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning false<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>D:\0a5d06cdf6260be764b38f\Windows6.1-KB958488-v6001-x64.msu: Verifying signature for Windows6.1-KB958488-v6001-x64.msu</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning false<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>returning false<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:34]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:34]</span>returning false<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:41]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:41]</span>D:\0a5d06cdf6260be764b38f\Windows6.1-KB958488-v6001-x64.msu -  Signature verified successfully for Windows6.1-KB958488-v6001-x64.msu<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:41] </span>D:\0a5d06cdf6260be764b38f\Windows6.1-KB958488-v6001-x64.msu Signature verified successfully for Windows6.1-KB958488-v6001-x64.msu<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:41]</span>Signature verification succeeded for Windows6.1-KB958488-v6001-x64.msu<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:41]</span>File D:\0a5d06cdf6260be764b38f\Windows6.1-KB958488-v6001-x64.msu, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:41]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\Windows6.1-KB958488-v6001-x64.msu Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:41]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\SetupUtility.exe<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:41] </span>D:\0a5d06cdf6260be764b38f\SetupUtility.exe: Verifying signature for SetupUtility.exe</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>D:\0a5d06cdf6260be764b38f\SetupUtility.exe -  Signature verified successfully for SetupUtility.exe<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:47] </span>D:\0a5d06cdf6260be764b38f\SetupUtility.exe Signature verified successfully for SetupUtility.exe<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:47]</span>Signature verification succeeded for SetupUtility.exe<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>File D:\0a5d06cdf6260be764b38f\SetupUtility.exe, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:47]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\SetupUtility.exe Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:47]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_LDR.mzz<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:47] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_LDR.mzz: Verifying signature for netfx_Full_LDR.mzz</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:47]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:47]</span>returning false<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>D:\0a5d06cdf6260be764b38f\netfx_Full_LDR.mzz -  Signature verified successfully for netfx_Full_LDR.mzz<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:48] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_LDR.mzz Signature verified successfully for netfx_Full_LDR.mzz<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>Signature verification succeeded for netfx_Full_LDR.mzz<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>File D:\0a5d06cdf6260be764b38f\netfx_Full_LDR.mzz, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_LDR.mzz Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_LDR_x64.msi<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:48] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_LDR_x64.msi: Verifying signature for netfx_Full_LDR_x64.msi</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>D:\0a5d06cdf6260be764b38f\netfx_Full_LDR_x64.msi -  Signature verified successfully for netfx_Full_LDR_x64.msi<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:48] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_LDR_x64.msi Signature verified successfully for netfx_Full_LDR_x64.msi<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>Signature verification succeeded for netfx_Full_LDR_x64.msi<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>File D:\0a5d06cdf6260be764b38f\netfx_Full_LDR_x64.msi, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_LDR_x64.msi Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_GDR.mzz<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:48] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_GDR.mzz: Verifying signature for netfx_Full_GDR.mzz</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>D:\0a5d06cdf6260be764b38f\netfx_Full_GDR.mzz -  Signature verified successfully for netfx_Full_GDR.mzz<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_GDR.mzz Signature verified successfully for netfx_Full_GDR.mzz<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Signature verification succeeded for netfx_Full_GDR.mzz<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>File D:\0a5d06cdf6260be764b38f\netfx_Full_GDR.mzz, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_GDR.mzz Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi: Verifying signature for netfx_Full_GDR_x64.msi</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi -  Signature verified successfully for netfx_Full_GDR_x64.msi<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi Signature verified successfully for netfx_Full_GDR_x64.msi<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Signature verification succeeded for netfx_Full_GDR_x64.msi<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>File D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\SetupUtility.exe<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\SetupUtility.exe: Verifying signature for SetupUtility.exe</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>D:\0a5d06cdf6260be764b38f\SetupUtility.exe -  Signature verified successfully for SetupUtility.exe<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\SetupUtility.exe Signature verified successfully for SetupUtility.exe<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Signature verification succeeded for SetupUtility.exe<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>File lock postponed for D:\0a5d06cdf6260be764b38f\SetupUtility.exe.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\SetupUtility.exe Success<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_core_x64.msi<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\netfx_core_x64.msi: Verifying signature for netfx_core_x64.msi</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Signature verified, verifying signer<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>D:\0a5d06cdf6260be764b38f\netfx_core_x64.msi -  Signature verified successfully for netfx_core_x64.msi<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:51] </span>D:\0a5d06cdf6260be764b38f\netfx_core_x64.msi Signature verified successfully for netfx_core_x64.msi<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Signature verification succeeded for netfx_core_x64.msi<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>File D:\0a5d06cdf6260be764b38f\netfx_core_x64.msi, locked for install. <BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>Verifying Digital Signatures: D:\0a5d06cdf6260be764b38f\netfx_core_x64.msi Success<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:51] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>evaluating IsPresent:<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:51] </span>Exists: evaluating</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>MsiGetProductInfo with product code {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} found no matches<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:51] </span>Exists evaluated to false<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:23:4]</span>evaluating IsPresent:<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:23:4]</span>returning false<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>calling PerformAction on an installing performer<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: Performing actions on all Items</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Restart manager will not be used since ui mode is silent and no external chainer is connected.<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Wait for Item (clr_optimization_v2.0.50727_32) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>clr_optimization_v2.0.50727_32 is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Creating new Performer for ServiceControl item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: ServiceControl - Stop clr_optimization_v2.0.50727_32</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:33]</span>ServiceControl operation succeeded!<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Error 0 is mapped to Custom Error: <BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Wait for Item (clr_optimization_v2.0.50727_64) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>clr_optimization_v2.0.50727_64 is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Creating new Performer for ServiceControl item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: ServiceControl - Stop clr_optimization_v2.0.50727_64</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:33]</span>ServiceControl operation succeeded!<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:33] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:33]</span>Error 0 is mapped to Custom Error: <BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Wait for Item (clr_optimization_v4.0.30319_32) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>clr_optimization_v4.0.30319_32 is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:33]</span>Creating new Performer for ServiceControl item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:33] </span>Action: ServiceControl - Stop clr_optimization_v4.0.30319_32</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:34]</span>ServiceControl operation succeeded!<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:34] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:34]</span>Error 0 is mapped to Custom Error: <BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:34]</span>Wait for Item (clr_optimization_v4.0.30319_64) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:34]</span>clr_optimization_v4.0.30319_64 is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:34]</span>Creating new Performer for ServiceControl item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:34] </span>Action: ServiceControl - Stop clr_optimization_v4.0.30319_64</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:16:35]</span>ServiceControl operation succeeded!<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:35] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:35]</span>Error 0 is mapped to Custom Error: <BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:35]</span>Wait for Item (Windows6.1-KB958488-v6001-x64.msu) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:41]</span>Windows6.1-KB958488-v6001-x64.msu is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:41]</span>Created new DoNothingPerformer for File item<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:41]</span>No CustomError defined for this item.<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:41]</span>Wait for Item (SetupUtility.exe) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>SetupUtility.exe is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Creating new Performer for Exe item<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Created new ExePerformer for Exe item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:47] </span>Action: Performing Action on Exe at D:\0a5d06cdf6260be764b38f\SetupUtility.exe</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Launching CreateProcess with command line = SetupUtility.exe /screboot<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Exe log file(s) :<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>C:\Windows\TEMP\dd_SetupUtility.txt<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Log File C:\Windows\TEMP\dd_SetupUtility.txt exists and will be added to the Watson upload list<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:47]</span>Exe (D:\0a5d06cdf6260be764b38f\SetupUtility.exe) succeeded.<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:16:47]</span>Exe Log File: <a href=".\dd_SetupUtility.txt">dd_SetupUtility.txt</a><BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:16:47] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:16:47]</span>Error 0 is mapped to Custom Error: <BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:47]</span>Wait for Item (netfx_Full_LDR.mzz) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>netfx_Full_LDR.mzz is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>Created new DoNothingPerformer for File item<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>No CustomError defined for this item.<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>Wait for Item (netfx_Full_LDR_x64.msi) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>netfx_Full_LDR_x64.msi is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>Created new DoNothingPerformer for File item<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:48]</span>No CustomError defined for this item.<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:48]</span>Wait for Item (netfx_Full_GDR.mzz) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>netfx_Full_GDR.mzz is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Created new DoNothingPerformer for File item<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:16:51]</span>No CustomError defined for this item.<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Wait for Item (netfx_Full_GDR_x64.msi) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>netfx_Full_GDR_x64.msi is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Creating new Performer for MSI item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:16:51] </span>Action: Performing Action on MSI at D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Log File C:\Windows\TEMP\Microsoft .NET Framework 4.5.1 Setup_20141210_021631175-MSI_netfx_Full_GDR_x64.msi.txt does not yet exist but may do at Watson upload time<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:16:51]</span>Calling MsiInstallProduct(D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi, EXTUI=1<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:18:20]</span>File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll" was in use<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:18:20]</span>Will ignore file "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll", running applications must be restarted to load the file.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:18:20]</span>Determining which applications are holding the file in use.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:18:20]</span>Application "HP Wireless Assistant Main Program" was holding file "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll" in use and will be ignored.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:18:20]</span>Application "HP Health Check Service" was holding file "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll" in use and will be ignored.<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:18:20]</span>FINAL: Will ignore file "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll", all applications holding this file were ignored.<BR></span>
<span class="wrn"><span class="t">[12/10/2014, 2:23:3]</span> Returning IDNO. INSTALLMESSAGE_USER [Sie müssen den Computer neu starten, damit die geänderte Konfiguration von Microsoft .NET Framework 4.5.1 wirksam wird. Klicken Sie auf "Ja", um den Computer jetzt neu zu starten, oder auf "Nein", um den Computer später manuell neu zu starten.]<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>MSI succeeded and requires reboot, but the reboot will be ignored.<BR></span>
<span class="r"><span class="t">[12/10/2014, 2:23:4]</span>MSI (D:\0a5d06cdf6260be764b38f\netfx_Full_GDR_x64.msi) Installation succeeded.  Msi Log: <a href="Microsoft .NET Framework 4.5.1 Setup_20141210_021631175-MSI_netfx_Full_GDR_x64.msi.txt">Microsoft .NET Framework 4.5.1 Setup_20141210_021631175-MSI_netfx_Full_GDR_x64.msi.txt</a><BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>:  no error<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:23:4] </span>Action complete<BR></div></span>

<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>Wait for Item (netfx_core_x64.msi) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>netfx_core_x64.msi is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>Created new DoNothingPerformer for File item<BR></span>
<span class="msg"><span class="t">[12/10/2014, 2:23:4]</span>No CustomError defined for this item.<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>Wait for Item (MSIServer) to be available<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>MSIServer is now available to install<BR></span>
<span class="vbe"><span class="t">[12/10/2014, 2:23:4]</span>Creating new Performer for ServiceControl item<BR></span>
<span class="act"><div class="sectionHdr"><a href="#" onclick="toggleSection(); event.returnValue=false;"><span class="sectionExp"><span class="t">[12/10/2014, 2:23:4] </span>Action: ServiceControl - Stop MSIServer</span><span class="sectionExp2">...<BR></span></a></div><div class="section">
<span class="r"><span class="t">[12/10/2014, 2:23:5]</span>ServiceControl operation succeeded!<BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:23:5] </span>Action complete<BR></div></span>

<span class="msg"><span class="t">[12/10/2014, 2:23:5]</span>Error 0 is mapped to Custom Error: <BR></span></div><div class="sectionHdr"><span class="t">[12/10/2014, 2:23:5] </span>Action complete<BR></div></span>

<span class="r"><span class="t">[12/10/2014, 2:23:5]</span>Final Result: Installation completed successfully with success code: (0x00000000), "Der Vorgang wurde erfolgreich beendet.
" (Elapsed time: 0 00:06:34).<BR></span>
         
....solche logs hab i gefunden, verstehe nicht alles aber aber verstecken, arbeite im stillen....

die komische Bluetooth anwendung hab ich mal in secunia PSI geladen... imOrdner wird sie so... BtITunesPlugIn angezeigt und in secunia steht C:fakepath.....


Ich weiß nicht was hier los ist.

Klingt zwar jetzt etwas paraniod aber des hier beschreibt meine Sympthome ganz gut....

h**p://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/regin-analysis.pdf

Manipulation von Benutzeroberflächen (Fernsteuern der Computermaus, Anfertigen von Screenshots usw.)
Erfassen von Prozess- und Speicherinformationen
Forensische Fähigkeiten (beispielsweise gelöschte Dateien wiederherstellen)
Überwachen des Netzwerkverkehrs
Auslesen von Daten über verschiedene Kanäle (TCP, UDP, ICMP, HTTP)
Auslesen eines Base Station Controller, der die Funkverbindungen in GSM-Mobilfunknetzen überwacht

Die Infektion kann je nach Ziel auf unterschiedliche Weise erfolgen. Ein reproduzierbarer Infektionsprozess konnte bisher noch nicht bestätigt werden. Die Attacke kann in einem ersten Schritte einen Nutzer dazu verleiten, gefälschte oder infizierte Versionen bekannter Websites aufzurufen. Die Bedrohung kann dann möglicherweise über eine Sicherheitslücke in einem Webbrowser oder durch Infizierung einer Anwendung installiert werden. Bei einem erfolgreichen Angriff konnte sich Regin beispielsweise über eine bekannte Instant Messenger-Anwendung verbreiten.

darauf bin ich gestoßen als ich die zertifikate von diesen komischen Programmen gefolgt bin...

Alt 10.12.2014, 17:48   #40
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Hmmmm....und nu? bleibt doch nur noch.....
Miniaturansicht angehängter Grafiken
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-stehts.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-bluetooth2.jpg   Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.-bluetooth3.jpg  

Alt 10.12.2014, 18:32   #41
Machiavelli
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Zitat:
Klingt zwar jetzt etwas paraniod aber des hier beschreibt meine Sympthome ganz gut....
Ja, die Bluetooth Anwendung ist legitim, siehe hier: https://www.google.de/webhp?sourceid...ns.exe+Widcomm

Nun zu Regin: http://de.wikipedia.org/wiki/Regin_(Spionagesoftware)
Schön, die Malware zieht vorallem auf Unternehmen an, weniger auf Einzelpersonen. Kandidaten sind laut Wikipedia NSA oder GCHQ, das würde heißen, du würdest aus irgendwelchen Gründen von diesen Firmen verfolgt werden. Das ist Irrsinn!

Du machst Dir viel zu viel Sorgen. Dein System ist laut Logs clean. Ehrlichgesagt, dass was Du machst (dll Dateien mit Notepad öffnen), ist ziemlich gefährlich. Machst Du versehentlich was falsch, fehlt Dir möglicherweise eine Systemdatei.

Nimm das jetzt nicht persönlich, aber Du bist etwas paranoid, die Probleme, dass Dein System "heiß" läuft, kann viele verschiedene Gründe haben. Und die Ursache in einer Malware zu suchen, die ich persönlich noch NIE in freier Wildbahn gesehen habe, ist sehr, sehr unwahrscheinlich (v.a. wenn sie wirklich von einem Geheimdienst "programmiert" wurde - d.h. Du müsstest bei vielen Ländern auf der "Top Watched" List des Geheimdienstes stehen, dass sie vielleicht solche Malware einsetzen, wenn es sie wirklich gibt).

Wenn ich Du wäre, würde ich nach der Ursache der Probleme suchen. Ich persönlich kann sagen, dass laut den Logs (sofern ich nichts übersehen habe) das System sauber ist.
__________________
Proud member of Unite

Alt 10.12.2014, 20:22   #42
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Ok.....mir geht es nicht um irgend nen ausländischen Geheimdienst. Ich hab irgendwie versucht die Symptome erklären,beschreiben wollen....und das traf es so ziemlich genau.

Windowsupdate bricht ab.... Fehler Code 800706F7
GData: Taskicon immernoch verschwunden
Programm Update verfügbar----> lädt Programmdatein erfolgreich,muss das Programm zur instalation beenden "OK"-----> Abbruch!!!!! Die Aktualisierung konnte nicht durchgeführt werden. Wie schonmal erwähnt, W-Lan Schalter "Aus", dennoch zeigt mir GData zunächst 1 aktive Verbindung mit dem Internet und kurze Zeit später ist auch das ausgeschaltete W-Lan mit dem "Internet" verbunden. IP-siehe Foto aus dem letzten Anhang. Mit dieser "Verbindung" wurden auch erfolgreich Virensignaturen aktualisiert wurden. Was ist das Für eine Verbindung....Wo kommt sie her???

Was das Bluetooth betrifft.....das war die beste Möglichkeit zu erklären was passiert. Das gleiche machen die Anwendungen von: CyberLink, AVerMedia, Corel, DigitalPersona, Hewlett-Packard,HP, JMicron,Microsoft, das "Symbolicon" myHPgames, Realtek, DIFX, DVD MAKER, IDT, Synaptics, Vallidity Sensors, "WIDCOMM"........Es wird in so ziemlich jedem Ordner aus C: an Textdokumenten, .bin, .sys, setup informationen, konfigurationseinstellungen, .dll, .xml und sonst was gearbeitet....nach jetzigem Stand an jedem Ordner der auf C: das erstelldatum 07.12.2014 hat. Diese Datein wandern über dieses "ominöse Netzwerk" in von heute Morgen an mitlerweil13..(02:44, 02:47, 02:51, 04:54, 07:55, 10:56, 13:15, 13:40, 14:02, 18:16, 18:56, 19:00)...Kein Plan....Wiederherstellungspunkte oder sonst was. das alles machen dann alle Prozesse,Dienste...gleichzeitig gesteuert von "??" mit Diensten wie AppIDsvc, CertPropSvc, CryptSvc, dot3svc, hideserv, Homegroupprovider,und so fast jeder ander Dienst..... es flackern kurz fenster auf Drahtlos+Lanverbindung läüft ganz gut der Arbeitsspeicher 80-95% CPU auf und ab.... Ist doch nicht normal.
Wärend ich des hier schreib ist der Arbeitsspeicher kontinuirlich von anfangs 1GB auf 5GB angewachsen.....was auch erst wieder weniger wird,wenn ich aus dem Netz gehe.

Hmmm.....vielleicht ist das Ding einfach zu alt und geht dem Ende entgegen. ich weiß es nicht. Vielleicht habe ich auch einen Fehler gemacht,als ich mir die ein oder andere Anwendung im Notepad betrachtet habe um zu erfahren....was zum Henker passiert hier eigentlich.

ok....du sagst das System ist sauber.


Dann bedanke ich mich erneut



Momentan läuft er wieder super ruhig. ))
kann er auch ich hab vorerst kein Bock mehr...hat mir genug Nerven gekosten in den letzten Tagen....


Also vielen Dank und falls was seien sollte ich meld mich.

Alt 10.12.2014, 21:08   #43
Machiavelli
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Zitat:
Was ist das Für eine Verbindung....Wo kommt sie her???
Von welchem Screenshot sprichst Du genau?

Zitat:
Es wird in so ziemlich jedem Ordner aus C: an Textdokumenten, .bin, .sys, setup informationen, konfigurationseinstellungen, .dll, .xml und sonst was gearbeitet....nach jetzigem Stand an jedem Ordner der auf C: das erstelldatum 07.12.2014 hat. Diese Datein wandern über dieses "ominöse Netzwerk" in von heute Morgen an mitlerweil13..(
Ich versteh nicht was Du meinst, sorry.

Zitat:
es flackern kurz fenster auf Drahtlos+Lanverbindung läüft ganz gut der Arbeitsspeicher 80-95% CPU auf und ab
Keine Ahnung was Du mir sagen willst.

========================

Ich kann schon was gegen diese Probleme machen. Du musst mir aber eine sehr detailreiche Zusammenfassung über die Probleme geben.
__________________
Proud member of Unite

Alt 11.12.2014, 21:15   #44
Grüni
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



GData hab ich selbst deinstalliert und neu runtergeladen. Funktioniert wieder.
Ein Programm von Corel läßt sich nicht deinstallieren ohne das ich eine funktionierende Internetverbindung habe und mir das Programm vorerst neu runterlade und neu installiere????? Es handelt sich hierbei um einen vorinstallierten "Photoviewer". Warum bitte macht so ein Programm so nen Aufstand?

Paranoid hin oder her....es kann nicht sein, das Programme wie zB Hp-Dvd starter oder so jeden Tag ihre Daten auffrischen oder was auch immer da passiert. Wenn diese Aktion läuft sind alle Ordner vom 7.12 auf dem aktuellsten Datum, nach nem Neustart sieht alles wieder so aus wie vorher. Es sind aber teilweise unzählige .dll Datein und neue Anwendungen in Ordnern von zB HP Smart Menue.......das war vorher einfach nicht so. Ich weiß einfach nicht wie ich das Detailliert beschrieben soll.....das immer zu unterschiedlichen Zeiten. Teilweise läuft der Rechner ganz normal. Aber wenn es losgeht ist alles das reinste Chaos. Arbeitsspeicher voll CPU Höchstleistung mehrmals am Tag, jeden Tag.

Alt 11.12.2014, 23:06   #45
Machiavelli
 
Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - Standard

Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
CloseProcesses:
Folder:C:\Users\srsrsrsfser3\AppData\Roaming\hpqlog
Folder:C:\Users\srsrsrsfser3\AppData\Roaming\HpUpdate
Folder:C:\Program Files\Hp-Dvd 
cmd:netsh winsock reset
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Das wird Deine Probleme beheben (es reguliert alle System Prozesse, verringert die Ausnutzung des Arbeitsspeichers, und wird vermutlich auch diese Ordner Probleme bezüglich HP DVD beheben etc.). Die Internet Probleme sollten weitgehenst behoben sein.

Es geht hier erst mal um die Allgemeinfunktion des Rechners. Wenn die CPU / RAM Auslastung geringer ist, passts. Wenn nicht ist es blöd.
__________________
Proud member of Unite

Antwort

Themen zu Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.
anleitung, anwendungen, appdata, autostart, bytes, c:\windows, code, festplatte, firewall, folge, harddisk, hintergrund, ide, launch, neu, nicht öffnen, not, problem, programme, registry, scan, spy spionage überwachung, spybot, systemwiederherstellung, temp, trojaner - adware - ram - software - virus, webcam, widows7, windows, wärend, öffnen




Ähnliche Themen: Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin.


  1. Windows 7: Reinigung des Rechners nach Viren-/Trojanerbefall, bitte um Prüfung.
    Log-Analyse und Auswertung - 29.10.2014 (5)
  2. GVU/BKA Trojaner/virus PC neu aufgesetzt aber trotzdem Probleme
    Plagegeister aller Art und deren Bekämpfung - 24.01.2013 (41)
  3. HDD Repair - nach Anleitung entfernt - weiterhin Probleme
    Log-Analyse und Auswertung - 18.11.2012 (28)
  4. BSOD nach Trojanerbefall bei Windows7
    Log-Analyse und Auswertung - 27.09.2012 (1)
  5. möglicher Viren oder Trojanerbefall..
    Plagegeister aller Art und deren Bekämpfung - 11.01.2012 (1)
  6. Weiterhin Probleme nach BKA-Scareware-Befall
    Log-Analyse und Auswertung - 25.07.2011 (23)
  7. Rustock-Botnetz: Nach Abschaltung weiterhin viele PCs infiziert
    Nachrichten - 06.07.2011 (0)
  8. XP-Recovery entfernt, aber weiterhin Probleme
    Log-Analyse und Auswertung - 10.06.2011 (1)
  9. Ultra-Defragger | nach Forenanleitung entfernt, weiterhin Probleme!
    Log-Analyse und Auswertung - 18.04.2011 (5)
  10. Nach Neueinrichtung weiterhin Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 03.04.2011 (3)
  11. Weiterhin Probleme nach Entfernen von Ultimate Defragger
    Log-Analyse und Auswertung - 21.11.2010 (35)
  12. plötzlicher viren und trojanerbefall
    Log-Analyse und Auswertung - 29.01.2010 (4)
  13. Cablecom meldet Viren-/Trojanerbefall :(
    Log-Analyse und Auswertung - 25.02.2009 (10)
  14. Nach virus neu aufgesetzt...
    Log-Analyse und Auswertung - 17.02.2009 (1)
  15. System neu aufgesetzt nach Trojanerbefall
    Log-Analyse und Auswertung - 07.10.2008 (1)
  16. Viren- und Trojanerbefall
    Mülltonne - 09.08.2008 (0)
  17. Windows neu aufgesetzt aber PC langsam
    Mülltonne - 29.01.2007 (0)

Zum Thema Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. - btw......ok. Ich lass mal paar Tage laufen. und geb dann nochmal ein Feedback. Danke für die Unterstützung. Ich war kurz vorm.... - Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin....
Archiv
Du betrachtest: Windows7 nach Viren/Trojanerbefall neu aufgesetzt(zum 3.mal) aber das Problembesteht weiterhin. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.