Schwertwalin | 06.07.2014 10:47 | Ich vermute als Antwort hier?
FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01
Ran by Anastasiya (administrator) on SCHWERTWALIN on 06-07-2014 09:14:17
Running from C:\Users\Anastasiya\Downloads
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2014-01-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1368792 2014-01-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1368792 2014-01-08] (Realtek Semiconductor)
HKLM-x32\...\Run: [AnyProtect Scanner] => "C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe"
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-303033151-1771499194-1607332238-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [184048 2013-12-26] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [156256 2013-12-26] (NVIDIA Corporation)
Startup: C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QLjHhzRk9TgBUkCFI52JreQmT-0z2xSCJDd1iNWS_xjFJXZmuMOqw42x-RiI-xdrasFoHIPFMChW_yy1vzdBTUtsZ9L-S9sYmmxA,,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QH68atdBzLkBx0fNeq2IDnXEwzbpJweQj5sPvrBLGjDC36V04vEAJY-qLK8-IOYYGFLAYRTZmzZp62n-XEBYWAlilghovrDYYFGg,,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QLjHhzRk9TgBUkCFI52JreQmT-0z2xSCJDd1iNWS_xjFJXZmuMOqw42x-RiI-xdrasFoHIPFMChW_yy1vzdBTUtsZ9L-S9sYmmxA,,&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QLjHhzRk9TgBUkCFI52JreQmT-0z2xSCJDd1iNWS_xjFJXZmuMOqw42x-RiI-xdrasFoHIPFMChW_yy1v0aW-eNcJCkqTczpsHrw,,&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QLjHhzRk9TgBUkCFI52JreQmT-0z2xSCJDd1iNWS_xjFJXZmuMOqw42x-RiI-xdrasFoHIPFMChW_yy1v0aW-eNcJCkqTczpsHrw,,&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QLjHhzRk9TgBUkCFI52JreQmT-0z2xSCJDd1iNWS_xjFJXZmuMOqw42x-RiI-xdrasFoHIPFMChW_yy1v0aW-eNcJCkqTczpsHrw,,&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52AcuP5Bv7pYjbQo04xdRYhQpgwhCE4Oq6zoAXB5oX-V9G6pIUVJLB-db3uoyCfg1QLjHhzRk9TgBUkCFI52JreQmT-0z2xSCJDd1iNWS_xjFJXZmuMOqw42x-RiI-xdrasFoHIPFMChW_yy1v0aW-eNcJCkqTczpsHrw,,&q={searchTerms}
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 - C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 - C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR HomePage:
CHR StartupUrls: ""
CHR Extension: (Google Docs) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-06]
CHR Extension: (Google Drive) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-06]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-07-06]
CHR Extension: (YouTube) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-06]
CHR Extension: (Adblock Plus) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-06]
CHR Extension: (Google Search) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-06]
CHR Extension: (Google Wallet) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-06]
CHR Extension: (Evernote Web Clipper) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-07-06]
CHR Extension: (Gmail) - C:\Users\Anastasiya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-06]
==================== Services (Whitelisted) =================
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-06] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-06] (globalUpdate) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-25] (Intel Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-06 09:05 - 2014-07-06 09:06 - 00380416 _____ () C:\Users\Anastasiya\Downloads\n6vi3mc1.exe
2014-07-06 09:04 - 2014-07-06 09:04 - 00016594 _____ () C:\Users\Anastasiya\Downloads\Addition.txt
2014-07-06 09:03 - 2014-07-06 09:14 - 00011916 _____ () C:\Users\Anastasiya\Downloads\FRST.txt
2014-07-06 09:03 - 2014-07-06 09:14 - 00000000 ____D () C:\FRST
2014-07-06 09:02 - 2014-07-06 09:02 - 02084352 _____ (Farbar) C:\Users\Anastasiya\Downloads\FRST64.exe
2014-07-06 09:00 - 2014-07-06 09:00 - 00000482 _____ () C:\Users\Anastasiya\Downloads\defogger_disable.log
2014-07-06 09:00 - 2014-07-06 09:00 - 00000000 _____ () C:\Users\Anastasiya\defogger_reenable
2014-07-06 08:59 - 2014-07-06 08:59 - 00050477 _____ () C:\Users\Anastasiya\Downloads\Defogger.exe
2014-07-06 08:50 - 2014-07-06 09:03 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-06 08:50 - 2014-07-06 08:50 - 00000975 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-07-06 08:50 - 2014-07-06 08:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-06 08:41 - 2014-07-06 08:41 - 00961360 _____ (Chip Digital GmbH) C:\Users\Anastasiya\Downloads\Steam - CHIP-Installer.exe
2014-07-06 08:41 - 2014-07-06 08:41 - 00961360 _____ (Chip Digital GmbH) C:\Users\Anastasiya\Downloads\Calibre 64 Bit - CHIP-Installer.exe
2014-07-06 07:43 - 2014-07-06 07:43 - 00002523 _____ () C:\Users\Public\Desktop\Evernote.lnk
2014-07-06 07:43 - 2014-07-06 07:43 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Evernote
2014-07-06 07:43 - 2014-07-06 07:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2014-07-06 07:43 - 2014-07-06 07:43 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-07-06 07:42 - 2014-07-06 07:43 - 86995808 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Anastasiya\Downloads\Evernote_5.4.1.3962.exe
2014-07-06 07:35 - 2014-07-06 08:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-06 07:35 - 2014-07-06 07:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-06 07:35 - 2014-07-06 07:35 - 00001403 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-07-06 07:35 - 2014-07-06 07:35 - 00001391 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-07-06 07:35 - 2014-07-06 07:35 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2014-07-06 07:35 - 2014-07-06 07:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-07-06 07:35 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2014-07-06 07:34 - 2014-07-06 07:34 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Anastasiya\Downloads\spybot-2.4.exe
2014-07-06 07:31 - 2014-07-06 07:31 - 00002226 _____ () C:\WINDOWS\PFRO.log
2014-07-06 07:30 - 2014-05-31 08:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-07-06 07:30 - 2014-05-15 00:47 - 04720640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-07-06 07:30 - 2014-05-13 09:01 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe
2014-07-06 07:30 - 2014-05-13 07:07 - 02844160 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-07-06 07:30 - 2014-05-13 06:41 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-07-06 07:30 - 2014-05-13 06:27 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-07-06 07:30 - 2014-05-13 06:26 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-07-06 07:30 - 2014-05-13 05:59 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-07-06 07:30 - 2014-05-13 05:41 - 01118720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-07-06 07:30 - 2014-05-13 05:31 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-07-06 07:30 - 2014-05-05 08:11 - 00440664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2014-07-06 07:30 - 2014-05-05 08:11 - 00418136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2014-07-06 07:30 - 2014-05-05 08:11 - 00089944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbehci.sys
2014-07-06 07:30 - 2014-05-05 08:11 - 00027480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys
2014-07-06 07:30 - 2014-05-03 13:29 - 01726224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-07-06 07:30 - 2014-05-03 11:20 - 01473080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-07-06 07:30 - 2014-05-03 09:41 - 04190208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-07-06 07:30 - 2014-05-03 09:40 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbuhci.sys
2014-07-06 07:30 - 2014-05-03 07:36 - 00997888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2014-07-06 07:30 - 2014-05-03 07:19 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncobjapi.dll
2014-07-06 07:30 - 2014-05-03 07:08 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedynos.dll
2014-07-06 07:30 - 2014-05-03 07:07 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedyn.dll
2014-07-06 07:30 - 2014-05-03 06:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncobjapi.dll
2014-07-06 07:30 - 2014-05-03 06:37 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedynos.dll
2014-07-06 07:30 - 2014-05-03 06:37 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedyn.dll
2014-07-06 07:30 - 2014-05-03 05:30 - 02641920 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-07-06 07:30 - 2014-05-03 05:27 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-07-06 07:30 - 2014-05-03 01:26 - 00050745 _____ () C:\WINDOWS\system32\srms.dat
2014-07-06 07:30 - 2014-05-01 15:19 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-07-06 07:30 - 2014-05-01 07:44 - 01025536 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-07-06 07:30 - 2014-05-01 07:34 - 03464192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-07-06 07:30 - 2014-04-30 09:11 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-07-06 07:30 - 2014-04-30 08:43 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2014-07-06 07:30 - 2014-04-30 08:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-07-06 07:30 - 2014-04-30 08:41 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2014-07-06 07:30 - 2014-04-30 08:41 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2014-07-06 07:30 - 2014-04-30 08:10 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-07-06 07:30 - 2014-04-30 07:45 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2014-07-06 07:30 - 2014-04-30 06:48 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2014-07-06 07:30 - 2014-04-30 06:24 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2014-07-06 07:30 - 2014-04-30 06:23 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2014-07-06 07:30 - 2014-04-30 06:23 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2014-07-06 07:30 - 2014-04-30 06:23 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2014-07-06 07:30 - 2014-04-30 06:21 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-07-06 07:30 - 2014-04-30 06:14 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2014-07-06 07:30 - 2014-04-30 05:59 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2014-07-06 07:30 - 2014-04-30 05:46 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2014-07-06 07:30 - 2014-04-30 05:46 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2014-07-06 07:30 - 2014-04-30 05:46 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2014-07-06 07:30 - 2014-04-30 05:45 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2014-07-06 07:30 - 2014-04-30 05:42 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2014-07-06 07:30 - 2014-04-29 00:40 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2014-07-06 07:30 - 2014-04-27 00:03 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-07-06 07:30 - 2014-04-26 22:14 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-07-06 07:30 - 2014-04-26 20:41 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfg.exe
2014-07-06 07:30 - 2014-04-26 20:22 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2014-07-06 07:30 - 2014-04-26 20:04 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2014-07-06 07:30 - 2014-04-26 19:36 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2014-07-06 07:30 - 2014-04-26 18:39 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2014-07-06 07:30 - 2014-04-14 11:37 - 02125344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-07-06 07:30 - 2014-04-14 10:08 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2014-07-06 07:30 - 2014-04-14 07:18 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2014-07-06 07:30 - 2014-04-09 08:11 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2014-07-06 07:30 - 2014-04-09 07:20 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2014-07-06 07:21 - 2014-07-06 07:21 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-07-06 07:10 - 2014-07-06 07:10 - 00002782 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2014-07-06 07:10 - 2014-07-06 07:10 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-06 07:10 - 2014-07-06 07:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-07-06 07:09 - 2014-07-06 07:10 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-06 07:08 - 2014-07-06 07:08 - 03736040 _____ (Piriform Ltd) C:\Users\Anastasiya\Downloads\ccsetup415_slim.exe
2014-07-06 07:07 - 2014-07-06 07:07 - 00752728 _____ ( ) C:\Users\Anastasiya\Downloads\ccleaner_setup.exe
2014-07-06 07:03 - 2014-07-06 07:03 - 00000144 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-07-06 06:57 - 2014-07-06 07:15 - 00000000 ____D () C:\Program Files (x86)\raving reyven
2014-07-06 06:57 - 2014-07-06 06:57 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\dlg
2014-07-06 06:54 - 2014-07-06 06:54 - 00471008 _____ () C:\Users\Anastasiya\Downloads\ccleaner.exe
2014-07-06 06:52 - 2014-07-06 06:52 - 00000312 _____ () C:\Users\Anastasiya\AppData\Roaming\aps.uninstall.scan.results
2014-07-06 06:51 - 2014-07-06 07:34 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-06 06:51 - 2014-07-06 07:32 - 00000940 _____ () C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-07-06 06:51 - 2014-07-06 07:12 - 00000378 _____ () C:\WINDOWS\Tasks\APSnotifierPP1.job
2014-07-06 06:51 - 2014-07-06 07:03 - 00000376 _____ () C:\WINDOWS\Tasks\APSnotifierPP3.job
2014-07-06 06:51 - 2014-07-06 07:03 - 00000376 _____ () C:\WINDOWS\Tasks\APSnotifierPP2.job
2014-07-06 06:51 - 2014-07-06 07:01 - 00000944 _____ () C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-07-06 06:51 - 2014-07-06 06:56 - 00003916 _____ () C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-07-06 06:51 - 2014-07-06 06:56 - 00003680 _____ () C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-07-06 06:51 - 2014-07-06 06:52 - 00002818 _____ () C:\WINDOWS\System32\Tasks\APSnotifierPP1
2014-07-06 06:51 - 2014-07-06 06:52 - 00002816 _____ () C:\WINDOWS\System32\Tasks\APSnotifierPP3
2014-07-06 06:51 - 2014-07-06 06:52 - 00002816 _____ () C:\WINDOWS\System32\Tasks\APSnotifierPP2
2014-07-06 06:51 - 2014-07-06 06:51 - 00002565 _____ () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\Macromedia
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\globalUpdate
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-07-06 06:50 - 2014-07-06 09:00 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-06 06:50 - 2014-07-06 07:32 - 00001140 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-06 06:50 - 2014-07-06 07:15 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Genesis_07060450
2014-07-06 06:50 - 2014-07-06 06:55 - 00004116 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-07-06 06:50 - 2014-07-06 06:55 - 00003880 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-07-06 06:50 - 2014-07-06 06:51 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Google
2014-07-06 06:50 - 2014-07-06 06:51 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-06 06:50 - 2014-07-06 06:50 - 00591320 _____ (ClickMeIn Limited) C:\Users\Anastasiya\AppData\Local\nsb51BD.tmp
2014-07-06 06:50 - 2014-07-06 06:50 - 00000000 _____ () C:\END
2014-07-06 06:48 - 2014-07-06 06:48 - 00000000 __SHD () C:\Users\Anastasiya\AppData\Local\EmieUserList
2014-07-06 06:48 - 2014-07-06 06:48 - 00000000 __SHD () C:\Users\Anastasiya\AppData\Local\EmieSiteList
2014-07-06 06:47 - 2014-01-19 09:38 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-07-06 06:46 - 2014-07-06 06:46 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-07-06 06:44 - 2014-07-06 06:45 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-06 06:44 - 2014-06-01 17:17 - 95414520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-06 06:43 - 2014-03-20 06:19 - 01291200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-07-06 06:43 - 2014-03-20 05:41 - 02013016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-07-06 06:43 - 2014-03-20 05:41 - 00376152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2014-07-06 06:43 - 2014-03-20 05:40 - 01112536 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-07-06 06:43 - 2014-03-20 02:53 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2014-07-06 06:43 - 2014-03-20 02:48 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2014-07-06 06:43 - 2014-03-20 01:55 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-07-06 06:43 - 2014-03-20 01:39 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2014-07-06 06:43 - 2014-03-20 01:36 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2014-07-06 06:43 - 2014-03-19 09:13 - 00836096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-07-06 06:43 - 2014-03-19 07:57 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-07-06 06:43 - 2014-03-19 07:50 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe
2014-07-06 06:43 - 2014-03-19 07:31 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2014-07-06 06:43 - 2014-03-19 07:20 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\w32tm.exe
2014-07-06 06:43 - 2014-03-19 07:08 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2014-07-06 06:43 - 2014-03-13 14:35 - 00157016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2014-07-06 06:43 - 2014-03-12 15:45 - 00387210 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-07-06 06:43 - 2014-03-11 17:18 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2014-07-06 06:43 - 2014-03-11 16:28 - 00887296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2014-07-06 06:43 - 2014-03-08 22:47 - 00565536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-07-06 06:43 - 2014-03-08 22:47 - 00180056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-07-06 06:43 - 2014-03-08 22:40 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2014-07-06 06:43 - 2014-03-08 22:38 - 01542768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2014-07-06 06:43 - 2014-03-08 22:35 - 00467800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2014-07-06 06:43 - 2014-03-08 17:29 - 00356848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2014-07-06 06:43 - 2014-03-08 13:34 - 01095488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2014-07-06 06:43 - 2014-03-08 11:02 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxproxy.dll
2014-07-06 06:43 - 2014-03-08 10:33 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll
2014-07-06 06:43 - 2014-03-08 10:25 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SetNetworkLocation.dll
2014-07-06 06:43 - 2014-03-08 10:12 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxproxy.dll
2014-07-06 06:43 - 2014-03-08 09:53 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-07-06 06:43 - 2014-03-08 09:47 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll
2014-07-06 06:43 - 2014-03-08 09:12 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2014-07-06 06:43 - 2014-03-08 09:04 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2014-07-06 06:43 - 2014-03-08 09:03 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2014-07-06 06:43 - 2014-03-08 08:48 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-07-06 06:43 - 2014-03-08 08:41 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2014-07-06 06:43 - 2014-03-08 08:40 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2014-07-06 06:43 - 2014-03-08 08:37 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2014-07-06 06:43 - 2014-03-08 08:31 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2014-07-06 06:43 - 2014-03-08 08:30 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2014-07-06 06:43 - 2014-03-08 08:25 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2014-07-06 06:43 - 2014-03-08 08:04 - 00717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2014-07-06 06:43 - 2014-03-08 07:58 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2014-07-06 06:43 - 2014-03-08 07:41 - 01306624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-07-06 06:43 - 2014-03-08 07:11 - 00924160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-07-06 06:43 - 2014-03-06 16:34 - 02331000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2014-07-06 06:43 - 2014-03-06 16:34 - 00113648 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2014-07-06 06:43 - 2014-03-06 14:53 - 02141912 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2014-07-06 06:43 - 2014-03-06 14:53 - 00518552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-07-06 06:43 - 2014-03-06 14:51 - 01557848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-07-06 06:43 - 2014-03-06 14:51 - 00488280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2014-07-06 06:43 - 2014-03-06 14:51 - 00379224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2014-07-06 06:43 - 2014-03-06 14:39 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2014-07-06 06:43 - 2014-03-06 13:19 - 00390488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2014-07-06 06:43 - 2014-03-06 13:19 - 00094016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2014-07-06 06:43 - 2014-03-06 13:13 - 01779800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2014-07-06 06:43 - 2014-03-06 13:13 - 00406912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-07-06 06:43 - 2014-03-06 12:46 - 01679128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2014-07-06 06:43 - 2014-03-06 11:24 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2014-07-06 06:43 - 2014-03-06 11:24 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
2014-07-06 06:43 - 2014-03-06 11:24 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2014-07-06 06:43 - 2014-03-06 11:22 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2014-07-06 06:43 - 2014-03-06 11:22 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2014-07-06 06:43 - 2014-03-06 11:19 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2014-07-06 06:43 - 2014-03-06 11:19 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpnpmgr.dll
2014-07-06 06:43 - 2014-03-06 11:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys
2014-07-06 06:43 - 2014-03-06 11:19 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2014-07-06 06:43 - 2014-03-06 11:08 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll
2014-07-06 06:43 - 2014-03-06 10:41 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevPropMgr.dll
2014-07-06 06:43 - 2014-03-06 10:38 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2014-07-06 06:43 - 2014-03-06 10:20 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2014-07-06 06:43 - 2014-03-06 10:10 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\l2gpstore.dll
2014-07-06 06:43 - 2014-03-06 10:00 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2014-07-06 06:43 - 2014-03-06 09:46 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2014-07-06 06:43 - 2014-03-06 09:16 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2014-07-06 06:43 - 2014-03-06 09:02 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2014-07-06 06:43 - 2014-03-06 08:51 - 02900992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2014-07-06 06:43 - 2014-03-06 08:39 - 02133504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-07-06 06:43 - 2014-03-06 08:31 - 02479616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-07-06 06:43 - 2014-03-06 08:29 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2014-07-06 06:43 - 2014-03-06 08:27 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2014-07-06 06:43 - 2014-03-06 08:24 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlangpui.dll
2014-07-06 06:43 - 2014-03-06 08:23 - 02270208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2014-07-06 06:43 - 2014-03-06 08:23 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2014-07-06 06:43 - 2014-03-06 08:21 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2014-07-06 06:43 - 2014-03-06 08:13 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2014-07-06 06:43 - 2014-03-06 08:11 - 02030080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2014-07-06 06:43 - 2014-03-06 08:09 - 01764864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2014-07-06 06:43 - 2014-03-06 08:06 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlangpui.dll
2014-07-06 06:43 - 2014-03-06 08:04 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2014-07-06 06:43 - 2014-03-06 08:01 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2014-07-06 06:43 - 2014-03-06 07:51 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2014-07-06 06:43 - 2014-03-06 07:47 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2014-07-06 06:43 - 2014-03-06 07:42 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2014-07-06 06:43 - 2014-03-04 14:25 - 02373784 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-07-06 06:43 - 2014-03-04 14:14 - 00360512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2014-07-06 06:43 - 2014-03-04 13:16 - 02088160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2014-07-06 06:43 - 2014-03-04 13:10 - 00355832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2014-07-06 06:43 - 2014-03-04 10:11 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
2014-07-06 06:43 - 2014-03-04 09:26 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll
2014-07-06 06:43 - 2014-03-04 09:16 - 00655360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2014-07-06 06:43 - 2014-03-04 09:13 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2014-07-06 06:43 - 2014-03-04 09:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2014-07-06 06:43 - 2014-03-04 09:00 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2014-07-06 06:43 - 2014-03-04 08:56 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2014-07-06 06:43 - 2014-03-04 08:50 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2014-07-06 06:43 - 2014-03-04 08:42 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2014-07-06 06:43 - 2014-03-04 08:39 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2014-07-06 06:43 - 2014-03-04 08:32 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2014-07-06 06:43 - 2014-03-04 08:15 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2014-07-06 06:43 - 2014-03-04 08:05 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2014-07-06 06:43 - 2014-03-04 08:03 - 00669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2014-07-06 06:43 - 2014-03-04 08:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-07-06 06:43 - 2014-03-04 07:54 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2014-07-06 06:43 - 2014-03-04 07:52 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2014-07-06 06:43 - 2013-12-24 01:28 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2014-07-06 06:43 - 2013-12-24 01:26 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2014-07-06 06:42 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-06 06:42 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-06 06:42 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-07-06 06:42 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-07-06 06:42 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-06 06:42 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-06 06:42 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-06 06:42 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-06 06:42 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-06 06:42 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-07-06 06:42 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-06 06:42 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-06 06:42 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-06 06:42 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-07-06 06:42 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-06 06:42 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-06 06:42 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-06 06:42 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-06 06:42 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-06 06:42 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-06 06:42 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-06 06:42 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-06 06:42 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-06 06:42 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-06 06:42 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-06 06:42 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-06 06:42 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-06 06:42 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-07-06 06:42 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-07-06 06:42 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvcfg.exe
2014-07-06 06:42 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2014-07-06 06:42 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvinst.exe
2014-07-06 06:42 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-07-06 06:42 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-07-06 06:42 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-07-06 06:42 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2014-07-06 06:42 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2014-07-06 06:42 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2014-07-06 06:42 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-07-06 06:42 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-07-06 06:42 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-07-06 06:42 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2014-07-06 06:42 - 2014-04-18 11:32 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-07-06 06:42 - 2014-04-18 10:58 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-07-06 06:42 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-07-06 06:42 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-07-06 06:42 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-07-06 06:42 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-07-06 06:42 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-07-06 06:42 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2014-07-06 06:42 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2014-07-06 06:42 - 2014-04-11 08:13 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2014-07-06 06:42 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2014-07-06 06:42 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2014-07-06 06:42 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-07-06 06:42 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-07-06 06:42 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2014-07-06 06:42 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2014-07-06 06:42 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2014-07-06 06:42 - 2014-04-09 00:46 - 00086688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll
2014-07-06 06:42 - 2014-04-09 00:46 - 00028320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll
2014-07-06 06:42 - 2014-04-08 20:54 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt_map.dll
2014-07-06 06:42 - 2014-04-08 20:54 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt100.dll
2014-07-06 06:42 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2014-07-06 06:42 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2014-07-06 06:42 - 2014-04-06 18:34 - 00275800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2014-07-06 06:42 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-07-06 06:42 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-07-06 06:42 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2014-07-06 06:42 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2014-07-06 06:42 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-07-06 06:42 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-07-06 06:42 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2014-07-06 06:42 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2014-07-06 06:42 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-07-06 06:42 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-07-06 06:42 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-07-06 06:42 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll
2014-07-06 06:42 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2014-07-06 06:42 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2014-07-06 06:42 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2014-07-06 06:42 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srclient.dll
2014-07-06 06:42 - 2014-04-06 13:55 - 16872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-07-06 06:42 - 2014-04-06 13:54 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-07-06 06:42 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2014-07-06 06:42 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-07-06 06:42 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-07-06 06:42 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-07-06 06:42 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2014-07-06 06:42 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-07-06 06:42 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2014-07-06 06:42 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2014-07-06 06:42 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2014-07-06 06:42 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2014-07-06 06:42 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2014-07-06 06:42 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2014-07-06 06:42 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
2014-07-06 06:42 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-07-06 06:42 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2014-07-06 06:42 - 2014-04-03 04:23 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-07-06 06:42 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tlscsp.dll
2014-07-06 06:42 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll
2014-07-06 06:42 - 2014-04-01 08:23 - 00384856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-07-06 06:42 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-07-06 06:42 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2014-07-06 06:42 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2014-07-06 06:42 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2014-07-06 06:42 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-07-06 06:42 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-07-06 06:42 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2014-07-06 06:42 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-07-06 06:42 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2014-07-06 06:42 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2014-07-06 06:42 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2014-07-06 06:42 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2014-07-06 06:42 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-07-06 06:42 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2014-07-06 06:42 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2014-07-06 06:42 - 2014-03-24 04:30 - 00257880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-07-06 06:42 - 2014-03-24 04:30 - 00123224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-07-06 06:42 - 2014-03-24 04:27 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-07-06 06:42 - 2014-03-21 06:14 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
2014-07-06 06:42 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-07-06 06:42 - 2014-03-20 02:51 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2014-07-06 06:42 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-07-06 06:42 - 2014-03-20 01:38 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2014-07-06 06:42 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-07-06 06:42 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2014-07-06 06:42 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2014-07-06 06:42 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2014-07-06 06:42 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2014-07-06 06:42 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-07-06 06:42 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2014-07-06 06:42 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2014-07-06 06:42 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2014-07-06 06:42 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2014-07-06 06:42 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-07-06 06:42 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2014-07-06 06:42 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2014-07-06 06:42 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-07-06 06:42 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-07-06 06:42 - 2014-03-18 10:19 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-07-06 06:42 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2014-07-06 06:42 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2014-07-06 06:42 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-07-06 06:42 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-07-06 06:42 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2014-07-06 06:42 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2014-07-06 06:42 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2014-07-06 06:42 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2014-07-06 06:42 - 2014-03-13 09:42 - 00308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2014-07-06 06:42 - 2014-03-13 08:51 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wusa.exe
2014-07-06 06:42 - 2014-03-06 14:42 - 00310616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-07-06 06:42 - 2014-02-06 13:30 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-07-06 06:42 - 2014-02-06 13:30 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-07-06 06:42 - 2014-02-06 13:07 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-07-06 06:42 - 2014-02-06 13:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-07-06 06:42 - 2014-02-06 12:56 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-07-06 06:42 - 2014-02-06 12:49 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-07-06 06:42 - 2014-02-06 12:48 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-07-06 06:42 - 2014-02-06 12:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-07-06 06:42 - 2014-02-06 12:17 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-07-06 06:42 - 2014-02-06 12:00 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-07-06 06:42 - 2014-02-06 11:52 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-07-06 06:42 - 2014-02-06 11:52 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-07-06 06:42 - 2014-02-06 11:47 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-07-06 06:42 - 2014-02-06 11:25 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-07-06 06:42 - 2014-01-27 20:21 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2014-07-06 06:41 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2014-07-06 06:41 - 2014-05-03 09:14 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-07-06 06:41 - 2014-05-03 06:21 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-06 06:41 - 2014-05-03 06:07 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-06 06:41 - 2014-05-03 05:41 - 00921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-07-06 06:41 - 2014-05-03 05:38 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-07-06 06:41 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-07-06 06:41 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2014-07-06 06:41 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-07-06 06:41 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-07-06 06:41 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2014-07-06 06:41 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2014-07-06 06:41 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-07-06 06:41 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-07-06 06:41 - 2014-04-11 12:03 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-07-06 06:41 - 2014-04-11 10:25 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2014-07-06 06:41 - 2014-04-11 08:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-07-06 06:41 - 2014-04-11 07:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-07-06 06:41 - 2014-04-11 05:54 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-07-06 06:41 - 2014-04-11 05:06 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-07-06 06:41 - 2014-04-11 05:05 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-07-06 06:41 - 2014-04-11 05:02 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-07-06 06:41 - 2014-04-11 05:01 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-07-06 06:41 - 2014-04-11 05:00 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-07-06 06:41 - 2014-04-11 04:59 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-07-06 06:41 - 2014-04-11 04:57 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-07-06 06:41 - 2014-04-11 04:56 - 00381440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-07-06 06:41 - 2014-04-11 04:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-07-06 06:41 - 2014-04-11 04:53 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-07-06 06:41 - 2014-04-11 04:46 - 01705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-07-06 06:41 - 2014-04-11 04:36 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-07-06 06:41 - 2014-04-11 04:29 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-07-06 06:41 - 2014-04-03 09:59 - 02518872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-07-06 06:41 - 2014-04-03 09:59 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-07-06 06:41 - 2014-03-11 15:21 - 00918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-07-06 06:41 - 2014-03-11 15:02 - 00629760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-07-06 06:40 - 2014-07-06 08:57 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-303033151-1771499194-1607332238-1001
2014-07-06 06:36 - 2014-07-06 07:32 - 00000000 ___DO () C:\Users\Anastasiya\OneDrive
2014-07-06 06:35 - 2014-07-06 06:35 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\PackageStaging
2014-07-06 06:34 - 2014-07-06 09:00 - 00000000 ____D () C:\Users\Anastasiya
2014-07-06 06:34 - 2014-07-06 07:13 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Packages
2014-07-06 06:34 - 2014-07-06 06:34 - 00001450 _____ () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-06 06:34 - 2014-07-06 06:34 - 00000451 _____ () C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-07-06 06:34 - 2014-07-06 06:34 - 00000020 ___SH () C:\Users\Anastasiya\ntuser.ini
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Vorlagen
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Startmenü
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Netzwerkumgebung
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Lokale Einstellungen
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Eigene Dateien
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Druckumgebung
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Documents\Eigene Musik
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Documents\Eigene Bilder
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\AppData\Local\Verlauf
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\AppData\Local\Anwendungsdaten
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Anwendungsdaten
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\Adobe
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\VirtualStore
2014-07-06 06:34 - 2014-03-18 12:32 - 00000000 ___RD () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-06 06:34 - 2014-03-18 12:32 - 00000000 ___RD () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-06 06:34 - 2014-03-18 12:12 - 00000369 _____ () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-07-06 06:34 - 2014-03-18 12:12 - 00000369 _____ () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-07-06 06:34 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-06 06:34 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-06 06:30 - 2014-07-06 06:30 - 00000000 ____D () C:\WINDOWS\CSC
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-07-06 00:19 - 2014-07-06 07:24 - 00000000 ___DC () C:\WINDOWS\Panther
2014-07-06 00:19 - 2014-07-06 00:19 - 00000000 ____D () C:\Windows.old
2014-07-06 00:18 - 2014-07-06 00:18 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-07-05 23:24 - 2014-07-05 23:24 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-07-05 23:23 - 2014-07-05 23:23 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-07-05 23:22 - 2014-07-06 06:29 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV
2014-07-05 23:22 - 2014-07-06 06:29 - 00000000 ____D () C:\WINDOWS\system32\NV
2014-07-05 23:22 - 2014-07-05 23:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
2014-07-05 23:22 - 2014-07-05 23:22 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-05 23:22 - 2014-07-05 23:22 - 00000000 ____D () C:\Program Files\Realtek
2014-07-05 23:21 - 2014-07-06 08:29 - 00953144 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\Program Files\Intel
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-07-05 23:21 - 2014-05-21 00:33 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2014-07-05 23:21 - 2014-05-21 00:33 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2014-07-05 23:21 - 2013-10-29 01:39 - 06610720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2014-07-05 23:21 - 2013-10-29 01:39 - 03477280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2014-07-05 23:21 - 2013-10-29 01:38 - 02559776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2014-07-05 23:21 - 2013-10-29 01:38 - 01042720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2014-07-05 23:21 - 2013-10-29 01:38 - 00920864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2014-07-05 23:21 - 2013-10-29 01:38 - 00580384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2014-07-05 23:21 - 2013-10-29 01:38 - 00219424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2014-07-05 23:21 - 2013-10-29 01:38 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2014-07-05 23:21 - 2013-10-29 01:38 - 00063776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2014-07-05 23:21 - 2013-10-25 13:44 - 03435888 _____ () C:\WINDOWS\system32\nvcoproc.bin
2014-07-05 23:03 - 2014-07-05 23:07 - 00000000 ___HD () C:\$WINDOWS.~BT
2014-07-05 21:16 - 2014-07-05 21:16 - 00000000 __RHD () C:\ESD
2014-07-04 19:03 - 2014-07-04 19:03 - 00000000 ____D () C:\Intel
2014-07-04 16:24 - 2014-07-04 16:24 - 00000000 _SHDL () C:\Programme
2014-07-04 16:24 - 2014-07-04 16:24 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
2014-07-06 09:14 - 2014-07-06 09:03 - 00011916 _____ () C:\Users\Anastasiya\Downloads\FRST.txt
2014-07-06 09:14 - 2014-07-06 09:03 - 00000000 ____D () C:\FRST
2014-07-06 09:06 - 2014-07-06 09:05 - 00380416 _____ () C:\Users\Anastasiya\Downloads\n6vi3mc1.exe
2014-07-06 09:04 - 2014-07-06 09:04 - 00016594 _____ () C:\Users\Anastasiya\Downloads\Addition.txt
2014-07-06 09:03 - 2014-07-06 08:50 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-07-06 09:02 - 2014-07-06 09:02 - 02084352 _____ (Farbar) C:\Users\Anastasiya\Downloads\FRST64.exe
2014-07-06 09:00 - 2014-07-06 09:00 - 00000482 _____ () C:\Users\Anastasiya\Downloads\defogger_disable.log
2014-07-06 09:00 - 2014-07-06 09:00 - 00000000 _____ () C:\Users\Anastasiya\defogger_reenable
2014-07-06 09:00 - 2014-07-06 06:50 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-06 09:00 - 2014-07-06 06:34 - 00000000 ____D () C:\Users\Anastasiya
2014-07-06 09:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-06 08:59 - 2014-07-06 08:59 - 00050477 _____ () C:\Users\Anastasiya\Downloads\Defogger.exe
2014-07-06 08:57 - 2014-07-06 06:40 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-303033151-1771499194-1607332238-1001
2014-07-06 08:50 - 2014-07-06 08:50 - 00000975 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-07-06 08:50 - 2014-07-06 08:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-06 08:41 - 2014-07-06 08:41 - 00961360 _____ (Chip Digital GmbH) C:\Users\Anastasiya\Downloads\Steam - CHIP-Installer.exe
2014-07-06 08:41 - 2014-07-06 08:41 - 00961360 _____ (Chip Digital GmbH) C:\Users\Anastasiya\Downloads\Calibre 64 Bit - CHIP-Installer.exe
2014-07-06 08:29 - 2014-07-05 23:21 - 00953144 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-06 08:28 - 2014-07-06 07:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-06 07:43 - 2014-07-06 07:43 - 00002523 _____ () C:\Users\Public\Desktop\Evernote.lnk
2014-07-06 07:43 - 2014-07-06 07:43 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Evernote
2014-07-06 07:43 - 2014-07-06 07:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2014-07-06 07:43 - 2014-07-06 07:43 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-07-06 07:43 - 2014-07-06 07:42 - 86995808 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\Anastasiya\Downloads\Evernote_5.4.1.3962.exe
2014-07-06 07:38 - 2014-03-18 12:04 - 01686150 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-06 07:38 - 2014-03-18 11:25 - 00727930 _____ () C:\WINDOWS\system32\perfh007.dat
2014-07-06 07:38 - 2014-03-18 11:25 - 00151586 _____ () C:\WINDOWS\system32\perfc007.dat
2014-07-06 07:36 - 2014-07-06 07:35 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-06 07:35 - 2014-07-06 07:35 - 00001403 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-07-06 07:35 - 2014-07-06 07:35 - 00001391 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-07-06 07:35 - 2014-07-06 07:35 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2014-07-06 07:35 - 2014-07-06 07:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-07-06 07:34 - 2014-07-06 07:34 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Anastasiya\Downloads\spybot-2.4.exe
2014-07-06 07:34 - 2014-07-06 06:51 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-06 07:32 - 2014-07-06 06:51 - 00000940 _____ () C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-07-06 07:32 - 2014-07-06 06:50 - 00001140 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-06 07:32 - 2014-07-06 06:36 - 00000000 ___DO () C:\Users\Anastasiya\OneDrive
2014-07-06 07:32 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-06 07:32 - 2013-08-22 16:44 - 00335992 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-06 07:31 - 2014-07-06 07:31 - 00002226 _____ () C:\WINDOWS\PFRO.log
2014-07-06 07:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-07-06 07:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-07-06 07:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-07-06 07:30 - 2013-08-22 17:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-07-06 07:24 - 2014-07-06 00:19 - 00000000 ___DC () C:\WINDOWS\Panther
2014-07-06 07:21 - 2014-07-06 07:21 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-07-06 07:16 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-07-06 07:16 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-07-06 07:15 - 2014-07-06 06:57 - 00000000 ____D () C:\Program Files (x86)\raving reyven
2014-07-06 07:15 - 2014-07-06 06:50 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Genesis_07060450
2014-07-06 07:13 - 2014-07-06 06:34 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Packages
2014-07-06 07:12 - 2014-07-06 06:51 - 00000378 _____ () C:\WINDOWS\Tasks\APSnotifierPP1.job
2014-07-06 07:10 - 2014-07-06 07:10 - 00002782 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2014-07-06 07:10 - 2014-07-06 07:10 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-06 07:10 - 2014-07-06 07:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-07-06 07:10 - 2014-07-06 07:09 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-06 07:08 - 2014-07-06 07:08 - 03736040 _____ (Piriform Ltd) C:\Users\Anastasiya\Downloads\ccsetup415_slim.exe
2014-07-06 07:07 - 2014-07-06 07:07 - 00752728 _____ ( ) C:\Users\Anastasiya\Downloads\ccleaner_setup.exe
2014-07-06 07:03 - 2014-07-06 07:03 - 00000144 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-07-06 07:03 - 2014-07-06 06:51 - 00000376 _____ () C:\WINDOWS\Tasks\APSnotifierPP3.job
2014-07-06 07:03 - 2014-07-06 06:51 - 00000376 _____ () C:\WINDOWS\Tasks\APSnotifierPP2.job
2014-07-06 07:01 - 2014-07-06 06:51 - 00000944 _____ () C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-07-06 07:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-07-06 07:01 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-07-06 06:57 - 2014-07-06 06:57 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\dlg
2014-07-06 06:56 - 2014-07-06 06:51 - 00003916 _____ () C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-07-06 06:56 - 2014-07-06 06:51 - 00003680 _____ () C:\WINDOWS\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-07-06 06:55 - 2014-07-06 06:50 - 00004116 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-07-06 06:55 - 2014-07-06 06:50 - 00003880 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-07-06 06:54 - 2014-07-06 06:54 - 00471008 _____ () C:\Users\Anastasiya\Downloads\ccleaner.exe
2014-07-06 06:52 - 2014-07-06 06:52 - 00000312 _____ () C:\Users\Anastasiya\AppData\Roaming\aps.uninstall.scan.results
2014-07-06 06:52 - 2014-07-06 06:51 - 00002818 _____ () C:\WINDOWS\System32\Tasks\APSnotifierPP1
2014-07-06 06:52 - 2014-07-06 06:51 - 00002816 _____ () C:\WINDOWS\System32\Tasks\APSnotifierPP3
2014-07-06 06:52 - 2014-07-06 06:51 - 00002816 _____ () C:\WINDOWS\System32\Tasks\APSnotifierPP2
2014-07-06 06:51 - 2014-07-06 06:51 - 00002565 _____ () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\Macromedia
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\globalUpdate
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-06 06:51 - 2014-07-06 06:51 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-07-06 06:51 - 2014-07-06 06:50 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\Google
2014-07-06 06:51 - 2014-07-06 06:50 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-06 06:50 - 2014-07-06 06:50 - 00591320 _____ (ClickMeIn Limited) C:\Users\Anastasiya\AppData\Local\nsb51BD.tmp
2014-07-06 06:50 - 2014-07-06 06:50 - 00000000 _____ () C:\END
2014-07-06 06:48 - 2014-07-06 06:48 - 00000000 __SHD () C:\Users\Anastasiya\AppData\Local\EmieUserList
2014-07-06 06:48 - 2014-07-06 06:48 - 00000000 __SHD () C:\Users\Anastasiya\AppData\Local\EmieSiteList
2014-07-06 06:47 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-06 06:46 - 2014-07-06 06:46 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-07-06 06:45 - 2014-07-06 06:44 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-06 06:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-07-06 06:43 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\restore
2014-07-06 06:35 - 2014-07-06 06:35 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\PackageStaging
2014-07-06 06:34 - 2014-07-06 06:34 - 00001450 _____ () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-06 06:34 - 2014-07-06 06:34 - 00000451 _____ () C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-07-06 06:34 - 2014-07-06 06:34 - 00000020 ___SH () C:\Users\Anastasiya\ntuser.ini
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Vorlagen
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Startmenü
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Netzwerkumgebung
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Lokale Einstellungen
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Eigene Dateien
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Druckumgebung
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Documents\Eigene Musik
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Documents\Eigene Bilder
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\AppData\Local\Verlauf
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\AppData\Local\Anwendungsdaten
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 _SHDL () C:\Users\Anastasiya\Anwendungsdaten
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 ____D () C:\Users\Anastasiya\AppData\Roaming\Adobe
2014-07-06 06:34 - 2014-07-06 06:34 - 00000000 ____D () C:\Users\Anastasiya\AppData\Local\VirtualStore
2014-07-06 06:30 - 2014-07-06 06:30 - 00000000 ____D () C:\WINDOWS\CSC
2014-07-06 06:29 - 2014-07-05 23:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV
2014-07-06 06:29 - 2014-07-05 23:22 - 00000000 ____D () C:\WINDOWS\system32\NV
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-07-06 00:49 - 2014-07-06 00:49 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-07-06 00:49 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-07-06 00:49 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
2014-07-06 00:19 - 2014-07-06 00:19 - 00000000 ____D () C:\Windows.old
2014-07-06 00:19 - 2013-08-22 17:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
2014-07-06 00:19 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery
2014-07-06 00:18 - 2014-07-06 00:18 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-07-05 23:24 - 2014-07-05 23:24 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-07-05 23:23 - 2014-07-05 23:23 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-07-05 23:22 - 2014-07-05 23:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
2014-07-05 23:22 - 2014-07-05 23:22 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-05 23:22 - 2014-07-05 23:22 - 00000000 ____D () C:\Program Files\Realtek
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\Program Files\Intel
2014-07-05 23:21 - 2014-07-05 23:21 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-07-05 23:07 - 2014-07-05 23:03 - 00000000 ___HD () C:\$WINDOWS.~BT
2014-07-05 21:16 - 2014-07-05 21:16 - 00000000 __RHD () C:\ESD
2014-07-04 19:03 - 2014-07-04 19:03 - 00000000 ____D () C:\Intel
2014-07-04 16:24 - 2014-07-04 16:24 - 00000000 _SHDL () C:\Programme
2014-07-04 16:24 - 2014-07-04 16:24 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-05 23:20
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2014 01
Ran by Anastasiya at 2014-07-06 09:14:39
Running from C:\Users\Anastasiya\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform)
Evernote v. 5.4.1 (HKLM-x32\...\{A5F7DF42-F67D-11E3-B7EB-00163E98E7D6}) (Version: 5.4.1.3962 - Evernote Corp.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
NVIDIA Install Application (Version: 2.1002.141.953 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 327.62 (Version: 327.62 - NVIDIA Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7133 - Realtek Semiconductor Corp.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
==================== Restore Points =========================
06-07-2014 04:43:45 Windows Update
==================== Hosts content: ==========================
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {00ED9891-2D82-41D8-9933-C85F54CBE262} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0B6C2C81-1F71-4FD2-8E73-164DB26BC50D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {0BC32B2D-93F4-45F4-B338-9BC59A6EB744} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {1F2D7BAE-62D4-4467-A97F-CD9E86C0B564} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {227579FD-4F58-4C78-ADEB-0FE6AB99ACE2} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-06] (globalUpdate) <==== ATTENTION
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {2CEF6D05-D023-4BD5-BB41-C3DF770B30C9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-06] (Google Inc.)
Task: {2EB0213E-A3A8-44F2-9DBC-44161868CFFF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-06] (Google Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4ADDD630-84E3-4F14-B501-36F294F295D9} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {53F5F330-C562-4015-95AB-DF43DE9BCAB3} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7F91C56A-A7C0-44D2-8D63-328A8C5AF6DC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd)
Task: {84BB362A-7412-4E4B-A5E9-16B2B96DB101} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2013-08-22] (Microsoft Corporation)
Task: {86125F53-1C16-46EC-84D6-DB5886E8DD51} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {870C782B-E021-464E-8020-D4FA65750A14} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-06-01] (Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9A21CB77-ED4E-4CFD-877B-C63B0CCCA059} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A9B946C6-71F6-4504-A414-449D3B0347DF} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {ACCA3503-CB35-4EE9-9E64-EDD30DC458D4} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {C24E2F06-349A-4AD8-8088-87C08BA65D21} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DCE3D606-9E17-4E65-B72D-0EF3F4603DE5} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {E18CA23B-423F-4F77-91E7-90ACDCE1B107} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-06] (globalUpdate) <==== ATTENTION
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: C:\WINDOWS\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-12-26 19:42 - 2013-12-26 19:42 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2014-07-06 07:35 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-07-06 07:35 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-07-06 07:35 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-07-06 07:35 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-06-17 18:10 - 2014-06-17 18:10 - 21118304 _____ () C:\Program Files (x86)\Evernote\Evernote\libcef.dll
2014-06-17 18:10 - 2014-06-17 18:10 - 00436576 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2014-06-17 18:10 - 2014-06-17 18:10 - 00318304 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2014-06-17 18:10 - 2014-06-17 18:10 - 00985968 _____ () C:\Program Files (x86)\Evernote\Evernote\avcodec-54.dll
2014-06-17 18:10 - 2014-06-17 18:10 - 00136048 _____ () C:\Program Files (x86)\Evernote\Evernote\avutil-51.dll
2014-06-17 18:10 - 2014-06-17 18:10 - 00192368 _____ () C:\Program Files (x86)\Evernote\Evernote\avformat-54.dll
2014-07-06 06:51 - 2014-06-05 15:58 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
2014-07-06 06:51 - 2014-06-05 15:58 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libegl.dll
2014-07-06 06:51 - 2014-06-05 15:58 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-07-06 06:51 - 2014-06-05 15:58 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-07-06 06:51 - 2014-06-05 15:58 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Anastasiya\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: SM-Bus-Controller
Description: SM-Bus-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/06/2014 06:56:17 AM) (Source: MsiInstaller) (EventID: 11309) (User: SCHWERTWALIN)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it.
Error: (07/06/2014 06:34:45 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0xC004E028
Befehlszeilenargumente:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=8da2dfae-e4f5-4e6a-9272-96f8470e033e;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
System errors:
=============
Error: (07/06/2014 08:52:10 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/06/2014 08:52:10 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.
Error: (07/06/2014 07:30:46 AM) (Source: DCOM) (EventID: 10010) (User: SCHWERTWALIN)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (07/06/2014 07:30:46 AM) (Source: DCOM) (EventID: 10010) (User: SCHWERTWALIN)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (07/06/2014 06:49:02 AM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (07/06/2014 06:37:58 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "SCHWERTWALIN",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{157909F1-8F80-4284-938B-6D7939CF7530}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (07/06/2014 04:18:21 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "Controller der Familie Realtek PCIe GBE, {6264749B-B5D7-4A33-9025-3EDB3E9D9097}" ist das Ereignis "74" aufgetreten.
Error: (07/06/2014 00:48:59 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "BranchCache" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%1260
Error: (07/06/2014 00:48:54 AM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als
Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser
Konfiguration nicht gestartet zu sein.
Error: (07/05/2014 11:26:59 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%2148007941
Microsoft Office Sessions:
=========================
Error: (07/06/2014 06:56:17 AM) (Source: MsiInstaller) (EventID: 11309) (User: SCHWERTWALIN)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/06/2014 06:34:45 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0xC004E028RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=8da2dfae-e4f5-4e6a-9272-96f8470e033e;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
==================== Memory info ===========================
Percentage of memory in use: 31%
Total physical RAM: 7948.36 MB
Available physical RAM: 5480.75 MB
Total Pagefile: 9868.36 MB
Available Pagefile: 6439.98 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.42 GB) (Free:430.4 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DEFCAD68)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465 GB) - (Type=07 NTFS)
==================== End Of Log ============================ GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-07-06 09:24:12
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002c ST500LM000-1EJ162 rev.LVD3 465,76GB
Running: n6vi3mc1.exe; Driver: C:\Users\ANASTA~1\AppData\Local\Temp\ufryruoc.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960001e3f00 15 bytes [00, 44, 0A, 02, 80, 09, 72, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960001e3f10 11 bytes [00, DD, FB, FF, 00, B7, D5, ...]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleInformation 00007ff9561a28c0 7 bytes JMP 00007ffa558502d0
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!RegQueryValueExW 00007ff9561a43d8 7 bytes JMP 00007ffa55850308
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExA 00007ff956251f20 7 bytes JMP 00007ffa55850378
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExW 00007ff9562540b4 7 bytes JMP 00007ffa558503b0
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!RegDeleteValueW 00007ff956254510 7 bytes JMP 00007ffa55850340
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ff956254af0 7 bytes JMP 00007ffa55850260
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ff95627cea0 7 bytes JMP 00007ffa55850228
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ff95627cf10 7 bytes JMP 00007ffa55850298
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleW 00007ff955862300 7 bytes JMP 00007ffa558500d8
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary 00007ff955865770 5 bytes JMP 00007ffa55850180
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW 00007ff955865860 5 bytes JMP 00007ffa55850148
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff955865a30 5 bytes JMP 00007ffa55850110
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ff95602b6f4 10 bytes JMP 00007ffa55850490
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesW 00007ff9560345d8 5 bytes JMP 00007ffa55850458
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ff956034750 9 bytes JMP 00007ffa558503e8
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesA 00007ff956044fc0 5 bytes JMP 00007ffa55850420
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ff957f11500 8 bytes JMP 00007ffa558501b8
.text C:\WINDOWS\system32\dwm.exe[876] C:\WINDOWS\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ff957f11750 8 bytes JMP 00007ffa558501f0
.text C:\WINDOWS\system32\nvvsvc.exe[920] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff95642169a 4 bytes [42, 56, F9, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[920] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff9564216a2 4 bytes [42, 56, F9, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[920] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff95642181a 4 bytes [42, 56, F9, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[920] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff956421832 4 bytes [42, 56, F9, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1664] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff95642169a 4 bytes [42, 56, F9, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1664] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff9564216a2 4 bytes [42, 56, F9, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1664] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff95642181a 4 bytes [42, 56, F9, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1664] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff956421832 4 bytes [42, 56, F9, 7F]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [544:568] fffff960008c5b90
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{244907A2-3D81-43F7-8D45-97153E2C3E27}\Connection@Name isatap.Speedport_W_303V_Typ_A
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed -1818228081
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0c8bfdcad144
Reg HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{244907A2-3D81-43F7-8D45-97153E2C3E27}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{244907A2-3D81-43F7-8D45-97153E2C3E27}@DefunctTimestamp 0x2D 0xDF 0xB8 0x53 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 754
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 19
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile@EnableFirewall 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile@EnableFirewall 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Brightness@ 100
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband@FavoritesChanges 11
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\Grid@Logo100 %USERPROFILE%\AppData\Local\Microsoft\Windows\Explorer\TileCacheLogo-20834468_100.dat
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\Grid@StartView100 %USERPROFILE%\AppData\Local\Microsoft\Windows\Explorer\TileCacheStartView-20838593_100.dat
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\Grid@Default100 %USERPROFILE%\AppData\Local\Microsoft\Windows\Explorer\TileCacheDefault-20841609_100.dat
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsRequestBucketDrainTime 0xCE 0x1F 0xE0 0x20 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsLargeRequestBucketDrainTime 0xCE 0x1F 0xE0 0x20 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherBandwidthBucketCounter 11166
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherRequestBucketCounter 897
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastOtherRequestBucketDrainTime 0xCE 0x1F 0xE0 0x20 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalBandwidthBucketCounter 75456
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalRequestBucketCounter 1395
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastGlobalRequestBucketDrainTime 0xCE 0x1F 0xE0 0x20 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@RoamingSyncToken LM%3d63540221742737%3bID%3d9C189D96CAF9335E!106%3bLR%3d63540220596700%3bEP%3d4%3bTD%3dTrue%3bSO%3d0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastUploadTime 0xAB 0x1C 0xD7 0x20 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@LastRenewCollectionsInterest 0x37 0x52 0xC1 0xA9 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData@PendingOperations 0
---- EOF - GMER 2.1 ---- Ich weiß leider nicht, welche Dateien du genau von Spybot brauchst, da sind einige dabei.
Liebe Grüße! |