FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-11-2014
Ran by Admin (administrator) on LENOVO-PC on 18-11-2014 23:24:01
Running from C:\Users\Admin\Desktop
Loaded Profile: Admin (Available profiles: Admin)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\SystemAgent\SystemAgentService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe
(AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe
(Microsoft Corporation) C:\Windows\BrowserChoice\browserchoice.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\QuickSnipService\QuickSnipService.exe
(Lenovo) C:\Program Files\Lenovo\QuickSnipService\QuickSnipInput.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
() C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
() C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe
() C:\Program Files\Lenovo Fingerprint Reader\x86\IEWebSiteLogon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe
(Microsoft Corporation) C:\Windows\SysWOW64\backgroundTaskHost.exe
(AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-07] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-07] (Realtek Semiconductor)
HKLM\...\Run: [LenovoOptMouseUpdate] => C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-09-01] (Lenovo Group Limited)
HKLM\...\Run: [HotKeysCmds] => C:\WINDOWS\system32\hkcmd.exe
HKLM\...\Run: [Persistence] => C:\WINDOWS\system32\igfxpers.exe
HKLM\...\Run: [TpShocks] => C:\WINDOWS\system32\TpShocks.exe [382248 2013-02-12] (Lenovo.)
HKLM\...\Run: [LnvMobHotspotClient] => C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [937976 2013-04-11] (Lenovo)
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [594936 2013-04-15] (Lenovo Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2950456 2012-10-02] (Synaptics Incorporated)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [548864 2012-10-02] (Vimicro)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133440 2012-07-19] (Intel Corporation)
HKLM-x32\...\Run: [IntelSBA] => C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe [4267784 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [738032 2013-11-05] (Lenovo)
HKU\S-1-5-21-594300477-1147781278-1985161295-1001\...\Run: [BrowserChoice] => C:\Windows\BrowserChoice\browserchoice.exe [86816 2013-08-22] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-594300477-1147781278-1985161295-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13-comm.msn.com
HKU\S-1-5-21-594300477-1147781278-1985161295-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13-comm.msn.com
HKU\S-1-5-21-594300477-1147781278-1985161295-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/welcome/thinkpad
HKU\S-1-5-21-594300477-1147781278-1985161295-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad
SearchScopes: HKLM -> DefaultScope {DC65C37E-5A30-43D8-A0CB-77D67FED04B8} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALCJS
SearchScopes: HKLM -> {DC65C37E-5A30-43D8-A0CB-77D67FED04B8} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALCJS
SearchScopes: HKLM-x32 -> DefaultScope {DC65C37E-5A30-43D8-A0CB-77D67FED04B8} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALCJS
SearchScopes: HKLM-x32 -> {DC65C37E-5A30-43D8-A0CB-77D67FED04B8} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALCJS
SearchScopes: HKU\S-1-5-21-594300477-1147781278-1985161295-1001 -> DefaultScope {DC65C37E-5A30-43D8-A0CB-77D67FED04B8} URL =
SearchScopes: HKU\S-1-5-21-594300477-1147781278-1985161295-1001 -> {DC65C37E-5A30-43D8-A0CB-77D67FED04B8} URL =
BHO: TrueSuite Browser Helper Object -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: TrueSuite Browser Helper Object -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin-x32: @authentec.com/ffwloplugin -> C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin HKU\S-1-5-21-594300477-1147781278-1985161295-1001: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll (Intel)
FF Plugin HKU\S-1-5-21-594300477-1147781278-1985161295-1001: intel.com/AppUpx64 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll (Intel)
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn [2014-11-18]
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFFPlgn
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFFPlgn [2014-11-15]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\Exts\Chrome.crx [2014-11-15]
CHR HKLM-x32\...\Chrome\Extension: [iokmdlapebooifaijckgcmncjdpojmjl] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2012-08-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [148472 2013-04-15] (Lenovo Corporation)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959192 2013-02-04] (Broadcom Corporation.)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [140016 2013-11-05] (Lenovo)
R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139496 2012-08-31] (AuthenTec, Inc)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-19] (Intel Corporation)
R2 intelsba; C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [47368 2012-07-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-07-19] (Intel Corporation)
R2 Lenovo QuickSnip Service; C:\Program Files\lenovo\QuickSnipService\QuickSnipService.exe [219976 2013-06-05] (LENOVO INCORPORATED.)
R2 Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [1628664 2013-02-06] (Lenovo Group Limited)
R2 Lenovo System Agent Service; C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe [562504 2013-06-05] (LENOVO INCORPORATED.)
R3 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [681464 2013-04-15] (Lenovo Corporation)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited)
R2 LnvHotSpotSvc; C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [465912 2013-04-11] (Lenovo)
R2 LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [463352 2013-04-19] ()
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272776 2014-10-16] ()
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2013-03-25] (Nitro PDF Software)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-02-04] ()
R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401256 2012-07-16] (AuthenTec, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-11-17] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-11-17] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6824520 2013-11-05] (Broadcom Corporation)
R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\BASHDefs\20141107.001\BHDrvx64.sys [1587416 2014-11-07] (Symantec Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R3 btwpanfl; C:\WINDOWS\system32\drivers\btwpanfl.sys [44912 2013-01-20] (Broadcom Corporation.)
R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1405000.01C\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-11-14] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-11-14] (Symantec Corporation)
R0 Fastboot; C:\Windows\System32\DRIVERS\fastboot.sys [66288 2013-11-05] (Windows (R) Win 7 DDK provider)
R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\IPSDefs\20141114.002\IDSvia64.sys [637656 2014-11-18] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20141117.009\ENG64.SYS [129752 2014-11-14] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20141117.009\EX64.SYS [2137304 2014-11-14] (Symantec Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44344 2012-10-02] (Synaptics Incorporated)
R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1405000.01C\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1405000.01C\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R3 SymDS; C:\Windows\system32\drivers\NISx64\1405000.01C\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R3 SymEFA; C:\Windows\system32\drivers\NISx64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NISx64\1405000.01C\SymELAM.sys [23448 2012-11-15] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-11-15] (Symantec Corporation)
R3 SymIRON; C:\Windows\system32\drivers\NISx64\1405000.01C\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1405000.01C\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [991360 2012-10-04] (Vimicro Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-11-17] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-18 23:24 - 2014-11-18 23:24 - 00019437 _____ () C:\Users\Admin\Desktop\FRST.txt
2014-11-18 23:23 - 2014-11-18 23:24 - 00000000 ____D () C:\FRST
2014-11-18 23:23 - 2014-11-18 23:22 - 02117120 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2014-11-18 16:01 - 2014-11-18 16:01 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-11-18 16:01 - 2014-11-18 16:01 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-18 16:01 - 2014-11-18 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-18 16:01 - 2014-11-18 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-18 16:01 - 2014-11-18 16:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-18 16:01 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-11-18 16:01 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-11-18 16:01 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-11-18 09:26 - 2014-11-18 09:26 - 00000144 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-11-18 09:26 - 2013-08-22 07:57 - 00002143 ___RS () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Choice.lnk
2014-11-18 09:16 - 2014-11-18 09:16 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-11-18 09:08 - 2014-08-15 01:36 - 00146752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2014-11-18 09:05 - 2014-08-02 01:18 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2014-11-18 09:05 - 2014-07-15 19:16 - 03048880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-11-18 09:05 - 2014-07-15 09:29 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-11-18 09:05 - 2014-07-15 09:22 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-11-18 09:05 - 2014-07-15 09:03 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2014-11-18 09:04 - 2014-08-23 08:48 - 02374784 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-11-18 09:04 - 2014-08-23 08:13 - 02084520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2014-11-18 09:04 - 2014-08-23 07:10 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-11-18 09:04 - 2014-08-23 06:32 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-11-18 09:04 - 2014-08-23 05:33 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-11-18 09:04 - 2014-08-16 05:08 - 01507648 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-11-18 09:04 - 2014-08-16 05:01 - 01710184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-11-18 09:04 - 2014-08-16 04:58 - 01112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-11-18 09:04 - 2014-08-16 04:16 - 01205976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-11-18 09:04 - 2014-08-16 04:03 - 01467384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-11-18 09:04 - 2014-08-16 02:31 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-11-18 09:04 - 2014-08-16 02:04 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2014-11-18 09:04 - 2014-08-16 01:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-11-18 09:04 - 2014-08-16 01:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2014-11-18 09:04 - 2014-08-16 01:46 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2014-11-18 09:04 - 2014-08-16 01:45 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2014-11-18 09:04 - 2014-08-16 01:43 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2014-11-18 09:04 - 2014-08-16 01:43 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2014-11-18 09:04 - 2014-08-16 01:31 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2014-11-18 09:04 - 2014-08-16 01:31 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2014-11-18 09:04 - 2014-08-16 01:29 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-11-18 09:04 - 2014-08-16 01:23 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-11-18 09:04 - 2014-08-16 01:22 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-11-18 09:04 - 2014-08-16 01:22 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-11-18 09:04 - 2014-08-16 01:19 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-11-18 09:04 - 2014-08-16 01:18 - 04758528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-11-18 09:04 - 2014-08-16 01:17 - 08757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-11-18 09:04 - 2014-08-16 01:14 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-11-18 09:04 - 2014-08-16 01:13 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-11-18 09:04 - 2014-08-16 01:13 - 05902848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-11-18 09:04 - 2014-08-16 01:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-11-18 09:04 - 2014-08-16 01:11 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-11-18 09:04 - 2014-08-16 01:10 - 01120768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-11-18 09:04 - 2014-08-16 01:08 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-11-18 09:04 - 2014-08-16 01:07 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-11-18 09:04 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2014-11-18 09:04 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-11-18 09:04 - 2014-06-02 03:10 - 00423768 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2014-11-18 09:04 - 2014-05-31 07:27 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFPf.sys
2014-11-18 09:04 - 2014-05-31 07:26 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFRd.sys
2014-11-18 09:04 - 2014-05-31 05:01 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFHost.exe
2014-11-18 09:04 - 2014-05-31 05:01 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2014-11-18 09:04 - 2014-05-31 05:01 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFSvc.dll
2014-11-18 09:04 - 2014-05-27 10:56 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\DaOtpCredentialProvider.dll
2014-11-18 09:04 - 2014-05-27 10:53 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll
2014-11-18 09:04 - 2014-05-03 06:36 - 00997888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2014-11-18 09:04 - 2014-05-03 06:19 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncobjapi.dll
2014-11-18 09:04 - 2014-05-03 06:08 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedynos.dll
2014-11-18 09:04 - 2014-05-03 06:07 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedyn.dll
2014-11-18 09:04 - 2014-05-03 05:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncobjapi.dll
2014-11-18 09:04 - 2014-05-03 05:37 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedynos.dll
2014-11-18 09:04 - 2014-05-03 05:37 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedyn.dll
2014-11-18 09:04 - 2014-05-03 00:26 - 00050745 _____ () C:\WINDOWS\system32\srms.dat
2014-11-18 09:04 - 2014-04-30 07:43 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2014-11-18 09:04 - 2014-04-30 07:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-11-18 09:04 - 2014-04-30 07:41 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2014-11-18 09:04 - 2014-04-30 07:41 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2014-11-18 09:04 - 2014-04-30 06:45 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2014-11-18 09:04 - 2014-04-30 05:48 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2014-11-18 09:04 - 2014-04-30 05:24 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2014-11-18 09:04 - 2014-04-30 05:23 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2014-11-18 09:04 - 2014-04-30 05:23 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2014-11-18 09:04 - 2014-04-30 05:23 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2014-11-18 09:04 - 2014-04-30 05:14 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2014-11-18 09:04 - 2014-04-30 04:59 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2014-11-18 09:04 - 2014-04-30 04:46 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2014-11-18 09:04 - 2014-04-30 04:46 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2014-11-18 09:04 - 2014-04-30 04:46 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2014-11-18 09:04 - 2014-04-30 04:45 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2014-11-18 09:04 - 2014-04-30 04:42 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2014-11-18 09:04 - 2014-04-28 23:40 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2014-11-18 09:04 - 2014-04-26 17:39 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2014-11-18 09:04 - 2014-04-14 10:37 - 02125344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2014-11-18 09:04 - 2014-04-14 09:08 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2014-11-18 09:04 - 2014-04-14 06:18 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2014-11-18 09:02 - 2014-07-12 05:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-11-18 09:01 - 2014-07-24 04:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2014-11-18 09:01 - 2014-07-24 04:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-11-18 08:59 - 2014-07-10 05:08 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lockscreencn.dll
2014-11-18 01:51 - 2014-11-18 01:51 - 00000000 __SHD () C:\Users\Admin\AppData\Local\EmieUserList
2014-11-18 01:51 - 2014-11-18 01:51 - 00000000 __SHD () C:\Users\Admin\AppData\Local\EmieSiteList
2014-11-18 01:51 - 2014-11-18 01:51 - 00000000 __SHD () C:\Users\Admin\AppData\Local\EmieBrowserModeList
2014-11-18 00:55 - 2014-11-18 00:55 - 00000963 _____ () C:\WINDOWS\SysWOW64\InstallUtil.InstallLog
2014-11-17 03:44 - 2014-11-17 03:44 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Norton Internet Security
2014-11-17 03:42 - 2014-11-17 03:42 - 00001744 _____ () C:\{1C80764C-D279-45FB-9F64-BBCD0566C7D7}
2014-11-17 03:39 - 2014-11-17 03:39 - 00001461 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-17 03:39 - 2014-11-17 03:39 - 00000451 _____ () C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-11-17 03:38 - 2014-11-17 03:38 - 00000020 ___SH () C:\Users\Admin\ntuser.ini
2014-11-17 02:21 - 2014-11-18 23:23 - 00850335 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-11-17 02:21 - 2014-11-17 02:21 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-11-17 02:20 - 2014-11-17 02:20 - 00022960 _____ () C:\WINDOWS\system32\emptyregdb.dat
2014-11-17 02:13 - 2014-11-17 02:13 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-11-17 02:13 - 2014-11-17 02:13 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-11-17 02:13 - 2014-11-17 02:13 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-11-17 02:11 - 2014-11-17 02:11 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
2014-11-17 02:10 - 2014-11-17 03:39 - 00000000 ____D () C:\Users\Admin
2014-11-17 02:10 - 2014-11-17 02:20 - 00020958 _____ () C:\WINDOWS\diagwrn.xml
2014-11-17 02:10 - 2014-11-17 02:20 - 00020958 _____ () C:\WINDOWS\diagerr.xml
2014-11-17 02:10 - 2014-11-17 02:11 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-17 02:10 - 2014-11-17 02:11 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Vorlagen
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Startmenü
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Netzwerkumgebung
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Lokale Einstellungen
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Eigene Dateien
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Druckumgebung
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Documents\Eigene Musik
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Documents\Eigene Bilder
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\AppData\Local\Verlauf
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\AppData\Local\Anwendungsdaten
2014-11-17 02:10 - 2014-11-17 02:10 - 00000000 _SHDL () C:\Users\Admin\Anwendungsdaten
2014-11-17 02:10 - 2014-09-24 07:18 - 00000369 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-11-17 02:10 - 2014-09-24 07:18 - 00000369 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-11-17 02:10 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-17 02:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-17 02:04 - 2014-11-17 02:12 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-11-17 02:04 - 2014-11-17 02:04 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job
2014-11-17 02:04 - 2014-11-17 02:04 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2014-11-17 02:04 - 2014-11-17 02:04 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01009.Wdf
2014-11-17 02:04 - 2014-11-17 02:04 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
2014-11-17 02:04 - 2014-11-17 02:04 - 00000000 ____D () C:\Program Files\Synaptics
2014-11-17 02:04 - 2014-11-17 02:04 - 00000000 ____D () C:\Program Files\Realtek
2014-11-17 02:04 - 2014-11-17 02:04 - 00000000 ____D () C:\Program Files (x86)\USB Camera
2014-11-17 02:03 - 2014-10-01 19:54 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2014-11-17 02:03 - 2014-10-01 19:54 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2014-11-17 02:00 - 2014-11-17 03:39 - 00000000 ___DC () C:\WINDOWS\Panther
2014-11-17 02:00 - 2014-11-17 02:00 - 00000000 __SHD () C:\Recovery
2014-11-17 01:59 - 2014-11-17 01:59 - 02149376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00789184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00602768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-11-17 01:59 - 2014-11-17 01:59 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00108432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-11-17 01:59 - 2014-11-17 01:59 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 03607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00238912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2014-11-17 01:58 - 2014-11-17 01:58 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00153920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2014-11-17 01:58 - 2014-11-17 01:58 - 00116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-11-17 01:58 - 2014-11-17 01:58 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00104336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00088800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-11-17 01:58 - 2014-11-17 01:58 - 00054592 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdusb.dll
2014-11-17 01:58 - 2014-11-17 01:58 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 25110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 19781632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 14390272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 12819456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 06040064 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 02884096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 02365440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 02277376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 02124288 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-11-17 01:57 - 2014-11-17 01:57 - 02051072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-11-17 01:57 - 2014-11-17 01:57 - 01892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01550336 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01519488 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00563976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-11-17 01:57 - 2014-11-17 01:57 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2014-11-17 01:57 - 2014-11-17 01:57 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00258368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\url.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iexpress.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iexpress.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wextract.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wextract.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\IEAdvpack.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\occache.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IEAdvpack.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inseng.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2014-11-17 01:57 - 2014-11-17 01:57 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2014-11-17 01:57 - 2014-11-17 01:57 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pngfilt.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\imgutil.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imgutil.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00035320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00027456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2014-11-17 01:57 - 2014-11-17 01:57 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licmgr10.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshta.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2014-11-17 01:57 - 2014-11-17 01:57 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshta.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2014-11-17 01:57 - 2014-11-17 01:57 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2014-11-17 01:54 - 2014-11-17 01:54 - 21197152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 18723112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 13424128 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 11820544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 07484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-11-17 01:54 - 2014-11-17 01:54 - 02714112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 02497344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-11-17 01:54 - 2014-11-17 01:54 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 02030592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00836176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00670384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00474432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2014-11-17 01:54 - 2014-11-17 01:54 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-11-17 01:54 - 2014-11-17 01:54 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-11-17 01:54 - 2014-11-17 01:54 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-11-17 01:54 - 2014-11-17 01:54 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-11-17 01:54 - 2014-11-17 01:54 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe
2014-11-17 01:53 - 2014-11-17 01:53 - 04182016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-11-17 01:53 - 2014-11-17 01:53 - 03557376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00055776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-11-17 01:53 - 2014-11-17 01:53 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-11-17 01:53 - 2014-11-17 01:53 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-11-17 01:53 - 2014-11-17 01:53 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-11-17 01:53 - 2014-11-17 01:53 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2014-11-17 01:52 - 2014-11-17 01:52 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
2014-11-17 01:50 - 2014-11-17 01:50 - 00000000 ____D () C:\WINDOWS\SysWOW64\XPSViewer
2014-11-17 01:50 - 2014-11-17 01:50 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-11-17 01:50 - 2014-11-17 01:50 - 00000000 ____D () C:\Program Files\MSBuild
2014-11-17 01:50 - 2014-11-17 01:50 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-11-17 01:50 - 2014-11-17 01:50 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-11-17 01:49 - 2013-08-03 05:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2014-11-17 01:49 - 2013-08-03 05:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2014-11-17 01:49 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2014-11-17 01:49 - 2013-08-03 05:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-11-17 01:19 - 2014-11-17 02:20 - 00006611 _____ () C:\WINDOWS\comsetup.log
2014-11-16 23:14 - 2014-11-16 23:49 - 00000000 ____D () C:\AdwCleaner
2014-11-15 22:57 - 2014-11-18 09:24 - 00000000 ____D () C:\WINDOWS\system32\AutoUpdateLicense
2014-11-15 22:56 - 2014-10-22 04:34 - 00010777 ____N () C:\WINDOWS\system32\AutoconfigV2.cab
2014-11-15 22:56 - 2014-10-22 04:33 - 00581016 ____N () C:\WINDOWS\system32\AutoUpdate.exe
2014-11-15 22:49 - 2014-11-18 09:26 - 00003552 _____ () C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask
2014-11-15 20:25 - 2014-11-15 20:26 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-11-15 20:25 - 2014-10-31 23:26 - 103374192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-15 20:10 - 2013-05-04 05:51 - 00014848 ____N (Microsoft) C:\WINDOWS\system32\rars.rs
2014-11-15 20:10 - 2013-05-04 05:10 - 00014848 ____N (Microsoft) C:\WINDOWS\SysWOW64\rars.rs
2014-11-15 18:31 - 2014-11-15 18:31 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_ldiagio_uefi_01009.Wdf
2014-11-15 18:29 - 2014-11-15 18:29 - 00002002 _____ () C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2014-11-15 17:41 - 2014-11-15 17:41 - 00000000 _____ () C:\WINDOWS\SysWOW64\agent.log
2014-11-15 17:21 - 2014-11-15 17:21 - 00000000 ____D () C:\sources
2014-11-15 16:59 - 2014-11-18 17:09 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-594300477-1147781278-1985161295-1001
2014-11-15 05:03 - 2014-11-15 18:29 - 00000000 ____D () C:\Users\Admin\AppData\Local\LSC
2014-11-15 04:59 - 2014-11-15 04:59 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2014-11-15 04:58 - 2014-11-15 18:30 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\LSC
2014-11-15 03:03 - 2014-11-15 03:03 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Intel(R) Small Business Advantage
2014-11-15 03:01 - 2014-11-18 10:03 - 00001492 _____ () C:\Users\Admin\AppData\Roaming\AbsoluteReminder.xml
2014-11-15 03:01 - 2014-11-18 09:27 - 00000290 _____ () C:\Users\Admin\AppData\Local\RegisteredPackageInformation.xml
2014-11-15 03:01 - 2014-11-18 09:27 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Nitro PDF
2014-11-15 03:01 - 2014-11-15 04:58 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Adobe
2014-11-15 03:01 - 2014-11-15 03:01 - 00000000 ____D () C:\Users\Admin\Documents\Bluetooth-Exchange-Ordner
2014-11-15 03:01 - 2014-11-15 03:01 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Lenovo
2014-11-15 03:01 - 2014-11-15 03:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\Broadcom
2014-11-15 03:01 - 2014-11-15 03:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\AuthenTec
2014-11-15 03:01 - 2014-11-15 03:01 - 00000000 ____D () C:\Users\Admin\AppData\Local\Absolute_Software
2014-11-15 03:00 - 2014-11-18 09:16 - 00000000 ____D () C:\Users\Admin\AppData\Local\Packages
2014-11-15 03:00 - 2014-11-17 02:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Password Vault
2014-11-15 03:00 - 2014-11-15 03:00 - 00000000 ____D () C:\Users\Admin\AppData\Local\VirtualStore
2014-11-15 03:00 - 2014-11-15 03:00 - 00000000 ____D () C:\AuthLog
2014-11-15 02:59 - 2013-11-05 01:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Macromedia
2014-11-15 02:59 - 2013-01-14 19:58 - 00001599 _____ () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LenovoToast.lnk
2014-11-14 05:36 - 2014-11-14 05:36 - 00084208 _____ (Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
2014-11-14 05:36 - 2014-11-14 05:36 - 00072432 _____ (Lenovo.) C:\WINDOWS\system32\ibmpmctl.exe
2014-11-14 05:36 - 2014-11-14 05:36 - 00060112 _____ (Lenovo.) C:\WINDOWS\system32\Drivers\ibmpmdrv.sys
2014-11-14 05:36 - 2014-11-14 05:36 - 00040176 _____ (Lenovo.) C:\WINDOWS\system32\tpinspm.dll
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Vorlagen
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Startmenü
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Netzwerkumgebung
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Lokale Einstellungen
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Eigene Dateien
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Druckumgebung
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Documents\Eigene Musik
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Documents\Eigene Bilder
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\AppData\Local\Verlauf
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\AppData\Local\Anwendungsdaten
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Users\Default.migrated\Anwendungsdaten
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Programme
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-11-08 21:11 - 2014-11-08 21:11 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-11-08 21:10 - 2014-11-08 21:10 - 00000000 _____ () C:\Recovery.txt
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-18 23:23 - 2013-08-22 15:46 - 00285951 _____ () C:\WINDOWS\setupact.log
2014-11-18 17:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-11-18 16:03 - 2014-09-24 07:17 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-18 16:03 - 2014-09-24 06:43 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2014-11-18 16:03 - 2014-09-24 06:43 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2014-11-18 11:07 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-11-18 09:27 - 2013-11-05 01:58 - 723054592 ___SH () C:\WINDOWS\lenovo_fastboot.img
2014-11-18 09:24 - 2014-09-23 22:06 - 00008246 _____ () C:\WINDOWS\PFRO.log
2014-11-18 09:24 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-18 09:24 - 2012-07-26 09:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2014-11-18 09:22 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-11-18 09:21 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-11-18 09:20 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-11-18 09:20 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-11-18 09:16 - 2013-08-22 15:46 - 00000262 _____ () C:\WINDOWS\setuperr.log
2014-11-18 09:09 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\restore
2014-11-18 00:55 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Registration
2014-11-17 03:39 - 2012-07-26 06:37 - 00000000 ____D () C:\Users\Default.migrated
2014-11-17 03:38 - 2013-11-05 02:02 - 00003234 _____ () C:\WINDOWS\System32\Tasks\Norton WSC Integration
2014-11-17 02:22 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-11-17 02:21 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-11-17 02:21 - 2013-08-22 14:36 - 00000000 __RHD () C:\Users\Default
2014-11-17 02:19 - 2013-08-22 16:36 - 00000000 __RSD () C:\WINDOWS\Media
2014-11-17 02:18 - 2013-08-22 16:36 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-17 02:14 - 2013-11-05 02:01 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2014-11-17 02:14 - 2013-11-05 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Absolute Software
2014-11-17 02:14 - 2013-11-05 01:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel AppUp(R) center
2014-11-17 02:14 - 2013-11-05 01:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-11-17 02:14 - 2013-11-05 01:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2014-11-17 02:14 - 2013-11-05 01:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2014-11-17 02:14 - 2013-11-05 01:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2014-11-17 02:14 - 2013-11-05 01:38 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-11-17 02:14 - 2013-08-22 15:44 - 00338016 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-11-17 02:14 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2014-11-17 02:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-11-17 02:13 - 2014-09-24 06:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN
2014-11-17 02:13 - 2014-09-24 06:43 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep
2014-11-17 02:13 - 2014-09-24 06:43 - 00000000 ____D () C:\WINDOWS\system32\WCN
2014-11-17 02:13 - 2013-11-05 02:05 - 00000000 ____D () C:\WINDOWS\SysWOW64\sda
2014-11-17 02:13 - 2013-08-22 16:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log
2014-11-17 02:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2014-11-17 02:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME
2014-11-17 02:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2014-11-17 02:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\spool
2014-11-17 02:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\IME
2014-11-17 02:13 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI
2014-11-17 02:13 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-11-17 02:12 - 2013-08-22 16:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker
2014-11-17 02:12 - 2013-08-22 16:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar
2014-11-17 02:12 - 2013-08-22 16:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar
2014-11-17 02:12 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\IME
2014-11-17 02:12 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Help
2014-11-17 02:12 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-11-17 02:12 - 2013-03-25 22:03 - 00000000 ____D () C:\ProgramData\PRICache
2014-11-17 02:11 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery
2014-11-17 02:04 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\System
2014-11-17 02:00 - 2013-08-22 16:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
2014-11-17 01:58 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-17 01:58 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-17 01:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-11-17 01:58 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-11-17 01:56 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-11-17 01:55 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-11-17 01:55 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-11-17 01:55 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-11-17 01:55 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-11-17 01:50 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI
2014-11-17 01:50 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\MUI
2014-11-17 01:42 - 2013-11-05 01:30 - 01345890 _____ () C:\WINDOWS\WindowsUpdate (1).log
2014-11-17 01:05 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-11-15 22:32 - 2013-11-05 02:01 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NISx64
2014-11-15 18:29 - 2013-11-05 10:09 - 00000000 ____D () C:\ProgramData\Lenovo
2014-11-15 18:29 - 2013-11-05 01:56 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo
2014-11-15 18:29 - 2013-11-05 01:36 - 00000000 ____D () C:\Program Files\Lenovo
2014-11-15 18:28 - 2013-11-05 01:56 - 00000000 ____D () C:\WINDOWS\Downloaded Installations
2014-11-15 18:10 - 2013-11-05 02:02 - 00177312 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
2014-11-15 18:10 - 2013-11-05 02:02 - 00007631 _____ () C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
2014-11-15 03:05 - 2013-11-05 01:56 - 00000000 ____D () C:\WINDOWS\System32\Tasks\TVT
2014-11-15 03:02 - 2013-11-05 02:01 - 00000000 ____D () C:\ProgramData\Norton
2014-11-15 03:01 - 2013-11-05 01:39 - 00000000 ____D () C:\ProgramData\Intel
2014-11-15 03:00 - 2013-11-05 11:08 - 00077090 _____ () C:\WINDOWS\modules.log
2014-10-30 01:55 - 2014-09-24 08:46 - 00714208 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-10-30 01:55 - 2014-09-24 08:46 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-17 02:01
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-11-2014
Ran by Admin at 2014-11-18 23:25:05
Running from C:\Users\Admin\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Internet Security (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Internet Security (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.1.0.9 - Absolute Software)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 7.11.20 - )
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 6.30.59.26 - Broadcom Corporation)
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc)
Intel AppUp(R) center (HKLM-x32\...\Intel AppUp(R) center 41651) (Version: 3.8.0.41651.58 - Intel)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Update Manager (x32 Version: 1.0.0.34813 - Intel Corporation) Hidden
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.01 - )
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.5400 - Broadcom Corporation)
Lenovo Dependency Package (HKLM-x32\...\Lenovo Dependency Package_is1) (Version: 1.5.37.0 - Lenovo Group Limited)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.3.0 - Lenovo)
Lenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.09.03 - )
Lenovo Settings - Camera Audio (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 4.0.97.0 - Lenovo Corporation)
Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 1.1.1.11 - Lenovo Group Limited)
Lenovo Settings Mobile Hotspot (HKLM\...\{42603F7D-B08D-436B-B0D8-3E2DEF1AFD41}_is1) (Version: 1.1.0.57 - Lenovo)
Lenovo Solution Center (HKLM\...\{4C2B6F96-3AED-4E3F-8DCE-917863D1E6B1}) (Version: 2.7.003.00 - Lenovo Group Limited)
Lenovo Solutions for Small Business (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 1.1.22.3687 - Intel(R) Corporation)
Lenovo Solutions for Small Business Customizations (HKLM-x32\...\{AFD7B869-3B70-40C7-8983-769256BA3BD2}) (Version: 1.1.0005.00 - Lenovo Group Limited)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.02.0007 - Lenovo)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Nitro Pro 8 (HKLM\...\{35E1FF5F-E8E1-4DE2-B3EC-BBE296B27336}) (Version: 8.5.2.10 - Nitro)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 20.5.0.28 - Symantec Corporation)
Password Vault (HKLM\...\{1CACE706-D749-44CA-BBFE-AF60946D1B18}) (Version: 6.0.200.75 - AuthenTec, Inc.)
RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 2.1.1.0 - Lenovo)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.28123 - Realtek Semiconductor Corp.)
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.80.99066 - SugarSync, Inc.)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.17.3 - )
ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.77.0.11 - Lenovo)
Windows-Treiberpaket - Intel Corporation (iaStorA) HDC (09/01/2012 11.6.0.1030) (HKLM\...\C5447D3383070620C3892FF393F522D6225CBA13) (Version: 09/01/2012 11.6.0.1030 - Intel Corporation)
Windows-Treiberpaket - Lenovo 1.66.00.22 (11/30/2012 1.66.00.22) (HKLM\...\16E722986C4293F5D6BF43595DFFD631398D5F21) (Version: 11/30/2012 1.66.00.22 - Lenovo)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-594300477-1147781278-1985161295-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-594300477-1147781278-1985161295-1001_Classes\CLSID\{9E506282-69D3-5ABA-9C1D-15994B37F4AC}\InprocServer32 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll (Intel)
CustomCLSID: HKU\S-1-5-21-594300477-1147781278-1985161295-1001_Classes\CLSID\{9E506282-69D3-5ABA-9C1D-15994B37F4AD}\InprocServer32 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll (Intel)
==================== Restore Points =========================
18-11-2014 08:09:33 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {08C3FC77-8AA4-4D9F-BBF6-88012D9B0552} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {1863905A-F7A9-428C-A940-90109DB23B84} - System32\Tasks\Lenovo\LenovoWarrantyChinaTask => C:\Program Files\lenovo\SystemAgent\ChinaWarrantyService.exe [2013-06-05] ()
Task: {197DBFAE-1EC8-4822-A480-524082A7020D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-10-31] (Microsoft Corporation)
Task: {1DD4134E-52ED-4636-81B0-D0143086FA99} - System32\Tasks\Lenovo\LenovoDependencyVersionTask => C:\Program Files\lenovo\SystemAgent\DependencyVersion.exe [2013-06-05] ()
Task: {244F20EB-0AA9-45FC-9381-E34A8992A250} - System32\Tasks\Intel\Intel Service Manager => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-12-14] (Intel Corporation)
Task: {3CB2CF15-0059-4F0B-A434-1FCA97FE9501} - System32\Tasks\Lenovo\LenovoUserguidesCopy => C:\Program Files\lenovo\SystemAgent\UserguidesCopy.exe [2013-06-05] ()
Task: {4AE017EC-F65F-44B0-B131-F1DB05743C1A} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2014-10-16] (Lenovo)
Task: {59D1B1DB-C1B5-43B3-8A4C-CC4FE610EDFE} - System32\Tasks\Lenovo\LenovoMachineInformation => C:\Program Files\lenovo\SystemAgent\MachineInformation.exe [2013-06-05] ()
Task: {6731E394-A0A1-414F-98AA-D487F309B64B} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-10-16] (Lenovo)
Task: {78BB4A8E-D88C-4395-B499-99453BC69B80} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\WSCStub.exe [2014-04-29] (Symantec Corporation)
Task: {796ABB49-AC67-4C9E-9B02-1BC4F0E40369} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2013-08-22] (Microsoft Corporation)
Task: {8CD2CB36-D5E5-49A2-B4F6-E1868E889E30} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2014-10-16] (Lenovo)
Task: {8DD0C664-BE20-4A03-9350-72ACF30BC54F} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {91485626-12EB-4E4B-8124-6475D3FC2F49} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-10-16] (Lenovo)
Task: {ABCF5294-6431-4F82-B533-4888C8F56F40} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-02-04] ()
Task: {C74D8488-FD08-4AE7-88CD-CA3956E4A3B6} - System32\Tasks\Dolby => c:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2012-07-25] (Dolby Laboratories Inc.)
Task: {E1B7F72C-ABF9-4E81-9FD1-7C026F1CACBD} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2014-10-16] (Lenovo)
Task: {ED19B939-6D4B-4540-BAEC-67DB0398B629} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-10-16] ()
Task: {FF7401A4-E5C9-4AF9-A9AB-3988AA577726} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2013-03-13] (Lenovo)
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
==================== Loaded Modules (whitelisted) =============
2013-02-04 18:38 - 2013-02-04 18:38 - 00049368 _____ () C:\Program Files\Lenovo\Bluetooth Software\btwleapi.dll
2013-11-05 02:02 - 2013-04-18 07:32 - 00115712 _____ () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL
2013-08-22 08:19 - 2013-08-22 07:54 - 00112640 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Networking.winmd
2013-08-22 08:19 - 2013-08-22 07:54 - 00030208 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Foundation.winmd
2013-04-19 11:50 - 2013-04-19 11:50 - 00463352 _____ () C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
2013-04-19 11:50 - 2013-04-19 11:50 - 00014328 _____ () C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
2012-08-31 04:44 - 2012-08-31 04:44 - 04622184 _____ () C:\Program Files\Lenovo Fingerprint Reader\x86\IEWebSiteLogon.exe
2013-08-22 08:19 - 2013-08-22 07:54 - 00174592 _____ () C:\WINDOWS\system32\WinMetadata\Windows.UI.winmd
2012-08-31 04:43 - 2012-08-31 04:43 - 01130344 _____ () C:\Program Files\Lenovo Fingerprint Reader\DataManager.dll
2012-08-31 04:43 - 2012-08-31 04:43 - 00087400 _____ () C:\Program Files\Lenovo Fingerprint Reader\ssutil.dll
2013-11-05 01:58 - 2013-11-05 01:58 - 00033520 _____ () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00016896 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\featureController.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\osEvents.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00322048 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\log4cplus.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00400384 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\sqlite3.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00195584 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\libgsoap.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00020480 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\eventsSender.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00062464 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\zlib1.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00446976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\deviceProfile.dll
2013-11-05 01:58 - 2012-12-14 18:55 - 00064512 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManagerStarter.dll
2014-11-15 21:28 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.5.0.28\wincfi39.dll
2013-11-05 01:38 - 2012-07-18 20:55 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-11-05 01:57 - 2012-07-12 10:30 - 00030472 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\ProcessPrivileges.dll
2013-11-05 01:57 - 2012-07-12 10:30 - 00215304 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\System.ComponentModel.Composition.dll
2013-11-05 01:57 - 2012-07-12 10:30 - 00051464 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Interop.TaskScheduler.dll
2013-11-05 01:57 - 2012-07-12 10:30 - 00076040 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Interop.WUApiLib.dll
2013-11-05 01:57 - 2012-07-12 10:31 - 00215304 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\System.ComponentModel.Composition.dll
2013-11-05 01:57 - 2012-07-12 10:31 - 00051464 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\Interop.TaskScheduler.dll
2012-08-31 04:44 - 2012-08-31 04:44 - 00900456 _____ () C:\Program Files\Lenovo Fingerprint Reader\x86\DataManager.dll
2013-11-05 02:02 - 2013-02-28 12:53 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll
2013-11-05 02:02 - 2013-02-28 12:53 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Admin (S-1-5-21-594300477-1147781278-1985161295-1001 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-594300477-1147781278-1985161295-500 - Administrator - Disabled)
Gast (S-1-5-21-594300477-1147781278-1985161295-501 - Limited - Disabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/18/2014 00:55:55 AM) (Source: Intel(R) Small Business Advantage Service) (EventID: 28672) (User: )
Description: Es ist ein schwerwiegender Fehler aufgetreten. Wenn ein Neustart des Computers das Problem nicht behebt, installieren Sie Intel(R) Small Business Advantage neu.
System.Exception: Eine Ausnahme vom Typ "System.Exception" wurde ausgelöst.
bei Intel.SBA.Utils.SBA_InstallerHelper.StartProcess(String filename, String arguments)
bei Intel.SBA.Utils.SBA_InstallerHelper.InstallUtils(String[] assemblies)
bei Intel.SBA.ServiceManager.MessageEvent.SBA_MessageEvent.ReinstallMessageEvent()
bei Intel.SBA.ServiceManager.MessageEvent.SBA_MessageEvent.Fire(SbaMessage alert)
bei Intel.SBA.ServiceManager.Service.Messages.AddMessage(SbaMessage message)
bei Intel.SBA.ServiceManager.Service.Messages.AddMessage(Guid applicationId, String applicationName, String unlocalizedApplicationName, MessagesId eventId, SeverityLevel eventSeverityLevel, SeverityLevel applicationSeverityLevel, Object[] args)
bei Intel.SBA.ServiceManager.Service.Messages.AddMessage(Guid applicationId, MessagesId applicationName, MessagesId eventId, SeverityLevel eventSeverityLevel, SeverityLevel applicationSeverityLevel, Object[] args)
bei Intel.SBA.EnergySaver.Service.EnergySaver.OnPowerEvent(PowerBroadcastStatus powerStatus)
bei Intel.SBA.EnergySaver.Service.EnergySaverServicePiece.OnPowerEvent(PowerBroadcastStatus powerStatus)
bei Intel.SBA.WindowsService.ServiceHost.<>c__DisplayClass8.<OnPowerEvent>b__5()
bei System.Threading.ThreadHelper.ThreadStart_Context(Object state)
bei System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
bei System.Threading.ThreadHelper.ThreadStart()
Error: (11/17/2014 02:20:47 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT)
Description: Vom Ereignisanbieter "Intel.SmallBusinessAdvantage.General.MessageEvent_SN_4b71cab8d8e4499f_Version_1.1.22.3687" wurde versucht, die Abfrage "select * from SBA_MessageEvent" zu registrieren, deren Zielklasse "SBA_MessageEvent" im Namespace "//./ROOT/Intel_SBA" nicht vorhanden ist. Die Abfrage wird ignoriert.
Error: (11/17/2014 02:20:47 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT)
Description: Vom Ereignisanbieter "" wurde versucht, die Abfrage "select * from SBA_MessageEvent" zu registrieren, deren Zielklasse "SBA_MessageEvent" im Namespace "//./ROOT/Intel_SBA" nicht vorhanden ist. Die Abfrage wird ignoriert.
Error: (11/16/2014 07:34:57 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 10.0.9200.17148 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 17c8
Startzeit: 01d001450a3f9cec
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: 314d8596-6dbf-11e4-be7b-b00594ebec3f
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (11/16/2014 07:34:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Lenovo-PC)
Description: Das Paket „DefaultBrowser_NOPUBLISHERID“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (11/15/2014 05:21:02 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm LenovoToast.exe, Version 1.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 18dc
Startzeit: 01d000ec11af15a9
Endzeit: 4294967295
Anwendungspfad: C:\ProgramData\NoiseSuppressionTips\LenovoToast.exe
Berichts-ID: 3d4747e9-6ce3-11e4-be72-b00594ebec3f
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (11/15/2014 03:00:50 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0x80072EE7
Befehlszeilenargumente:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e4b231b-3e45-41f4-967f-c914f178b6ac;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (11/15/2014 03:00:50 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Fehler beim Erwerb der Endbenutzerlizenz. hr=0x80072EE7
SKU-ID=9e4b231b-3e45-41f4-967f-c914f178b6ac
Error: (11/15/2014 03:00:50 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Lizenzerwerb-Fehlerdetails.
hr=0x80072EE7
System errors:
=============
Error: (11/18/2014 09:36:26 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (11/18/2014 09:35:56 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (11/18/2014 09:22:38 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet:
%%1062
Error: (11/18/2014 00:55:55 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Intel(R) Small Business Advantage" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/17/2014 02:21:15 AM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als
Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser
Konfiguration nicht gestartet zu sein.
Error: (11/17/2014 02:02:34 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IP-Hilfsdienst" wurde mit folgendem Fehler beendet:
%%1058
Error: (11/16/2014 03:19:12 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070002 fehlgeschlagen: Lenovo - LCD, Other hardware - ThinkPad Display 1366x768
Error: (11/16/2014 03:19:12 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80246010 fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB3000853)
Error: (11/16/2014 03:19:12 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070002 fehlgeschlagen: Lenovo - Other hardware - Lenovo PM Device
Error: (11/16/2014 01:55:43 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Microsoft Office Sessions:
=========================
Error: (11/18/2014 00:55:55 AM) (Source: Intel(R) Small Business Advantage Service) (EventID: 28672) (User: )
Description: Es ist ein schwerwiegender Fehler aufgetreten. Wenn ein Neustart des Computers das Problem nicht behebt, installieren Sie Intel(R) Small Business Advantage neu.
System.Exception: Eine Ausnahme vom Typ "System.Exception" wurde ausgelöst.
bei Intel.SBA.Utils.SBA_InstallerHelper.StartProcess(String filename, String arguments)
bei Intel.SBA.Utils.SBA_InstallerHelper.InstallUtils(String[] assemblies)
bei Intel.SBA.ServiceManager.MessageEvent.SBA_MessageEvent.ReinstallMessageEvent()
bei Intel.SBA.ServiceManager.MessageEvent.SBA_MessageEvent.Fire(SbaMessage alert)
bei Intel.SBA.ServiceManager.Service.Messages.AddMessage(SbaMessage message)
bei Intel.SBA.ServiceManager.Service.Messages.AddMessage(Guid applicationId, String applicationName, String unlocalizedApplicationName, MessagesId eventId, SeverityLevel eventSeverityLevel, SeverityLevel applicationSeverityLevel, Object[] args)
bei Intel.SBA.ServiceManager.Service.Messages.AddMessage(Guid applicationId, MessagesId applicationName, MessagesId eventId, SeverityLevel eventSeverityLevel, SeverityLevel applicationSeverityLevel, Object[] args)
bei Intel.SBA.EnergySaver.Service.EnergySaver.OnPowerEvent(PowerBroadcastStatus powerStatus)
bei Intel.SBA.EnergySaver.Service.EnergySaverServicePiece.OnPowerEvent(PowerBroadcastStatus powerStatus)
bei Intel.SBA.WindowsService.ServiceHost.<>c__DisplayClass8.<OnPowerEvent>b__5()
bei System.Threading.ThreadHelper.ThreadStart_Context(Object state)
bei System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state)
bei System.Threading.ThreadHelper.ThreadStart()
Error: (11/17/2014 02:20:47 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT)
Description: Intel.SmallBusinessAdvantage.General.MessageEvent_SN_4b71cab8d8e4499f_Version_1.1.22.3687select * from SBA_MessageEventSBA_MessageEvent//./ROOT/Intel_SBA
Error: (11/17/2014 02:20:47 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT-AUTORITÄT)
Description: select * from SBA_MessageEventSBA_MessageEvent//./ROOT/Intel_SBA
Error: (11/16/2014 07:34:57 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe10.0.9200.1714817c801d001450a3f9cec4294967295C:\Program Files\Internet Explorer\iexplore.exe314d8596-6dbf-11e4-be7b-b00594ebec3f
Error: (11/16/2014 07:34:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Lenovo-PC)
Description: DefaultBrowser_NOPUBLISHERID
Error: (11/15/2014 05:21:02 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LenovoToast.exe1.0.0.018dc01d000ec11af15a94294967295C:\ProgramData\NoiseSuppressionTips\LenovoToast.exe3d4747e9-6ce3-11e4-be72-b00594ebec3f
Error: (11/15/2014 03:00:50 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0x80072EE7RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e4b231b-3e45-41f4-967f-c914f178b6ac;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (11/15/2014 03:00:50 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: hr=0x80072EE79e4b231b-3e45-41f4-967f-c914f178b6ac
Error: (11/15/2014 03:00:50 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: hr=0x80072EE700010001(0x00000000, 03:00:49:569 - https://activation.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=DM)
00020001(0x00000000, 03:00:50:053)
00030001(0x00000000, 03:00:50:069 - https://activation.sls.microsoft.com)
00030002(0x00000000, 03:00:50:069 - 0)
00040001(0x00000000, 03:00:50:069 - https://activation.sls.microsoft.com)
00040002(0x00000000, 03:00:50:084 - 1, <NULL>, <NULL>, <NULL>)
00050002(0x80072F94, 03:00:50:084 - 0, 1)
00040006(0x00000001, 03:00:50:084 - 0, https://activation.sls.microsoft.com, <N/A>, <N/A>)
00020005(0x00000000, 03:00:50:084 - 0)
00020008(0x80072EE7, 03:00:50:194 - SOAPAction: "http://microsoft.com/SL/ProductActivationService/IssueToken"
Content-Type: text/xml; charset=utf-8
, <soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenc="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><RequestSecurityToken xmlns="http://schemas.xmlsoap.org/ws/2004/04/security/trust"><TokenType>ProductActivation</TokenType><RequestType>http://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue</RequestType><UseKey><Values xmlns:q1="http://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[1]"><TokenEntry><Name>PublishLicense</Name><Value>HPZRDu+ahj2sNpWH8ynPPlbACWHqW12oKYMNQreSeIPdMw01iQow7JUMajnfEYfPl0hjuq037sfTJeGS0+t0IrS1gxR6mqwJ1tZvMjNNEkL/sXFGzBL27va12l7eySRn5ChlJnl6qXTsk/1X4oNvxmpYNP3fuVshWp9BVZNaBgea44oPQrq52u7pKJ9zv5piQtGgLZiqenKHZRJ2Eu4Y6HKveg4rv7ilC+gAAlzcuNw/uLI40rRjhN0OdPbBcQo3B3c98q10hdutFiWPade0ayCpRcRMhJsNXRkD/rOi7a9+KBmMkSc+aH+bHdcEnhOqtfN/7OzhSKyv6RY7W/hsK3xOCBe8YyELK+O7TjFKcLsXUmuZpTPoc9ChaR8s+JHuefm0PnthUqlO8OtkMtnEsnVajcCT0o8f7Stv3u31ViQZ6EaVxqj0nz1EqTUpV0L9F9dCAtOfyGnwgjcvzPPriA6a/DH1XSEPe2a22mpKOj/i19iTU4zmlqrooitw1KTxjYxEhmnAqOS69PJfzinlhreLcA1JUdJT4bNYOUxfgKPu8rGps0gS5eQw6sgU93B/gJraxTiI7JJWnOigtWiY+ZhEmJRVdN8+RKfPh59+k7P5j1v130CG9U5+rH0c+LPcTIE0SSkQ5coW1Av475Zo8Cw/0A39Op8W3WXi1Lp6TbbBR/qACesO7eO9xeX6h4oI7VYjK/L9y985ZVK9JY06PmaBkG2cY/XcAXcZqi4CZatITwF1O+TJErEK1agkUTJ+TnMg9vb4fi9953zNwASLYrbch1aFQvKYXzHYf09+h+31RHsDgT585MHx0CaEMJ4F/0IZv7NH3uZa/0Qvq84Mfs44hgm3dKvxumUs9bYWqPV/W7Yv40YCxKCJbNDQyRYVenwDWTFG/j1syJRcRCV02sZHaVYsW8wof5OGezTHVAJugl+gsQaARtYb+umoNiHrfMbs76q7fE7vhl77oiNNDuzDLasWB7Y10KR36cR2ih6xmEPaLN2l+tbz9jzu3Zp9/ryvgdfYXhPp5IyYke9qjYNaDeCdykm0fijl/EQ+KyWDK47MvvZ6qVdLxOp9iQn81ouGBVVw55q0UaNni0hRYOM3ibxhk2xs1VfCudxTMvf5RjvqBjDWxievmTa71EDuWoDtWEIZ084QTA32qfnk4XRcYb+tQYGQyzQQ5bpvVuEqs1emmCsz+/36lyyRajUpyXVZxIrS089bf/eua9x7PnpEQ6cdO/WPw8uTC9b3iJFWyQEf05+CEmga7ByHNvLb4qxB/+GxYtReX2ugmvJxPOaEM9Fuk9y5XaK4GA/7t1rEww3odUMncLvHyOXddXgGgvFQXhVWLXXTaMor8aBZ80MvxdWAXIoRPtWu7C4khjZTGYiMtyi/v9Qc59uiuRMeBr9eSIajKD90Hv+3fS7UPajtg6Efbdoui98K968h5wtAtSmtyIHnrT5vK2rWXvEgTEScYMxQiRIpl8K6hr5atEqm1DYecM/4dZaV47R4LBpFajBpjgcyYCjWmJuJKANiB/sZJ0BcngrskJ/Lt0zBznRoegl1ldT2B3/eJ8dh1TeZdXfGbz9Xn8mEXWDyfEUqnRbUbZWVTMG72+1oOzZ+uCsTR0GL/WmW81munxJcy0zw1QF9px+n9u3F2CGaTaO0wXjTNkcTyJQRTBrBhVOiMeD1xUCOrVBIWn7RNkmMsPBIQHzT/XIarG8OS1aJHptGZFP8nooEoiFSwqYD7/apNVfqfogfXwT3rr7x4NAQMqi9NOKxMfTo/BQf950URaupaMrYqZA/DaFT6RisP9oDAZh6E/Rvd2+DD1/C6jPWPjpbpFy5cf0g+s5yZjwC2nRNpprMVaZcODZf3Gpmz4hmZZEB0BZzGSyNjtx4N5rKtqyR8VH20fNc5m6siv1FYEFljJWCZBel7TyIJQsYnqHf3FMLvVxTg4DWE5QAV1d/JOCdaJJtScE7t20y557krx2mfdisPi9ngsU/ZkAbfzYzIfvxZjUxDXTPDD5PRgmnbJ50/iwrcBOfdFWXz/UTip4JoQYf+918h/KO37uPvDECHk07R576JExmPKnfJac9X1eWEI8t79D3PQUYCX/2l5bj6+nPqP5N0TA33Kr5/E1x6hW3r9l06NvPx3vgDAN7nOjQa+d+C8u8ydWcYI9EV8jv/CzZXrWWDP9ZV8L8LWhDLdL17+CzBQFPgpMwybFOmheKuC1tPkJylRqU10+mEQn1muZRpCEiqQGUvntfMBT+BfbKuXG2jo90ZAHjXVxQKDVEhyEk8dXKCMO3Dh7oqH7P+V5ZVYckjQ9kVWbMvutdppGJQC+sZ/TMyof+0cMKN6YQope7UfLEBYuFMpIGtR3sYYtA15Jg+QCZBL8I+AwUkdEMGZ8M4OxnPyhHQ50/o1AbZyMmVC4nCfb/3eXgI9Li0vueVGIqJ2kN1Ce0CSB8AidkrHtErg+RoiWUiicomwHwhl6zkpNS1aWTuAClbY7BJkRNh293NbHP4og6AwdybYbPY/0pGEXhyi7bZANGBkU+7sldFTIr8O1DFVHchfhnMso9+mYOqZGf2HyzXqabtchdzVkm31dzv0vFSfgTHRBbXVJq/ZzD8czV5YRLDISwkJGRqT6IHlVFepZNiU1Vgh5aTlkG+dKFOt0bMajrXajiZuuRQliBHtR/BMEQBjaAvaXYwtbrM5TfICLkTQxT8WTgKZeFSyqkD1+Rv8wR2A1lXTjrmZcqBCVndIGpVH8ZhvpojTEd0O71RqXjL5HWJn3ARbgskvvwXI2iHfxCNgSrHEVJc3DDLUUjoJHsjoWPxAdXl8d+TMjnfVqI+0i9n8jjRjUA8zYF2vZYEY/QyC5XufZ6s53iERyroVDS8UIpvtBoyzVBfR9Z3dk1C2F8i/E9Phct9FyVDHlM6WZNoYQ9a6YvDIM6me6i7C7L8J5/r7BL5fF2E4Bccm52/bq7PucFbBrK8Ryb44JtOf2CXeAgGcQ++Z4tbMnQz53VNotmB7lwnaThwBSj001e0IcdhOr5SoQqMfh2HQCHXUVPWAFSEncmsCCA7CgPXErz0yhY+c8Z6DfovqxVnaQvupcdMJXs4v0GONva7L+1q0S04Wte4eWuWFO46UvLD/4UOrvHsdaV5EHp2+Whtkyf3azF8lRBlc3v1dPf8tNCAcyhBaN0hUrY9VFVAodh50JXOaiQ11BZmCoiWIYjCA3lulB9BmVG+jGBAoz3GwxXGjxezj6YaSMgfyMHy713c0s25CUHxqtclIJYVQFAal0NJ2l+b22JEeL9FVO0mtNQDjERxKlaCUuY6QHaXj/E53295P5tKv5u0z2Pcdff7Uhi7P/S3wikWyF9MgGX+XPM6BjwySMB8ynEj0Gp7nBuBfiFLgXVEOJL5B2aF6q7Xus+qWWuywwEdQ0Yo9a+mtBVEnVDNB29nPRoEGXT5Rj8d/eO1fub1BP95hUN3UAkhB/Yq6c+TNjcI4lvX6EJtUVI9QJvG0xcqDptfk4GOx5ee29hpjUFQCeN84eRt3h6f6d8JxYwaHyuKqvsPhqHJkYaqhcua8VhlEgedER7XjHDayxBWhPPAF6jM+9FV0DF+AXG+DJ1XEXWmjv1WHVj0dqslb01TlIoyfyITGe2skA5CHxVVlqMqFeQaKYLqBplvBH1WWD4FcieT3sMjO56GhRH7c5gDzWfXGlDhfRjqbcdHV0vu/vi200fZjm6YusNupO80nFEZClGh7dcHPw2czVEb2OHdZx1Q/cEhh3wW/wBhCSK44UXFUPb/IMBSFwkmFgkpqORY8aU+7Q6k8ItkgzEnNRSk8EHlUeae8rCb7TMxeMOtCoRHhPex3OABWWApJZ4EJZcuqeAqiDIyctrdZUlkYNsPP807IPCjzGPIpAJXIm54Ds7qXBPKTDkYTtJzJYI0TR/tZfXVAM9g82BsbbNefa10IgcdDWdCvAR0GuM+zVaz9DcfiZ5QXKl9WOYr2oNXUvmQCl2xl4AwvbEyE9WTza35IgieZFPdmgddPl/kO6uTYXaDT34WYFhVHWML0Qv/YQBrfsD0/l3m96Or9UYnZwZKuzbbEZIV8Hxm4TQf2v1Nt6sSgGTBeRLcodQFDfR5kVYyKBzhJEIiqhi1o1isR0ay0YbU8A4wspFAyyARW0Km/jcLa5lVExYMLvTxM1TyGBU21eiR2I6IhsRbADN+5/KuEFCBLrJQbzU1/2LsYVVBuXWrTGYDrxukXkXgiZHx2n5LUxw8iMfg9Tro9VHVix6ZAi4yfc/BLGgxTFkvhyn3bD+K+GI8z3DF+DUv89wC8GAKRTT3AYCQEqelMXBYx2dARvgTm3okxw4GUgJfvHgKk0vqh6MucSstH+UaG+3FBRgFNe3R6zxrfM1JO/uf/yKIBppNoAFuigmyxgoanLGaC7gjBzQa0PeWkfkhb8fQ8yjA4ALUOCdgV97zc2VRDvMMI18vwTO2emAUEBj2wXyIKPv52SkBUoRn9wzPDz0Hjf14unaqEhCm0ffy0B0vKcojywkleuCezKmH3vrAdXcvmw75vGnQ/ORmz3F98xFg8YY7f8r6qDuaGt3OuUtAt5AF5kGbZM54EA2Ej0j14vmcFZLrmUz9yedT6c2k9rC5O0tAD0sDLmRSEaRdtgavZGjTxFNfmZcBxd3xxylsDVdCuHFLboG3PWYSpGqAWT1uw0eiEquBhNb6ycuWIREUrdqlO9n4EuqR3b42LiHnzMr4yqqXb0JeITZfyYPD1OR1MXmWTJ8827ZU9fSAMoYu1jGTyZA98zMmEnEb3p1HwOkj5D0zv5DQEjt55WrBQfgI4bqeYklXqPTjq1iPSTjGkL+PHHYheyrcySFjnK2aB+5hSj3FfQKwlR4BbWYCBcgrQvG4YxJUO1D4q75FVa+IvJVHWvkS6sQAMYC5HY61C6rtV3bM4UOao/Ex4Npse69R8IgJ7IdyweV7tLjkDWbsTxCzhqgSIyXfftt3hx+AdQ6hReeClnFFajp/kJD3bpGaQ67mtw8qD8wG6NA2eWgZGodUQX1BJIN48EjuLCEbsZ6QTDmvc3a1QYjF2gXwNcgM9otNoHNqwqmB96Vv5kgqah2on4Nc7jjGWIxsYmWknq/HUJPbALPn1oG+iTTA5JMS/NBjSIXuz6Hkbb9apcmZZqa9/dvKrze7C+LncsmfXvcJh3IAhABsyTaotzN46WRORiZDXqHO1bcnVisESrXtiuzoEGyTzF/llFpnDgPs11J3dJHy4Y8HxX/kj59uAB2bH0Az1NBD7wuca0pBPMNEegk7Fvy1ZbWiZLz+YJzN0erYbheJhwCGFjNC0lPH7T4hiBfOfHWVqv/ChxW9ZkaC5EXCHC7JNCPEtWrL+ymiv4fxu8FY1JVz6Nnftz1gz9j/5co/OxGdW+XlmkG99qTV9s/ZeT14qEtJW+lcqUz2n8uus187bwFs/VyD1dLhKMRKg0Pg1wQAv0xPFTIOl9JC0jwokvfBCcCXpgfv19fnIau5vehHJ7ordI+so1iIYE79nTrBiDz61U6KMoUNeY4lpsHmgJJebaR/l5U/Py6JglhPnqOxCpKmsFscbfRT9yLU1yxqYgU15e15Gab7pFmKB0JWhyiEVLZ6o98bcQH4gSnwAXCpOPgLspD/OBS4xyC5VvnDpaNrgBBE+loz9sbdorK+Hun4XioqAqcgEwsnH5BpK2+ZmcmSFBTL+dvSAfiz93CWBjDGqYEZJ90s3sBDE11ddPP3WDaL7flHPCjCNRb3v3Iaba0ERPZeuxF9kVD9Ek1bMNbqAyacb4PgKY7ePmL8oSjahA0ZCIzvF01/Qd0RFbLjVlub9ztorA4jUZzalP7948GPVvGDdoAzo1xlB6Wo/Hr2U5WfizlWboAgVLRxX4uJmbfox5E/Th7N7oSuGWr60gy9pNwSu6whaKU8jjejHOXn1Lkqvc9S4CH6/FVHJ+nARVhZ34RGCEH9nTI4RgR2bESzGMcPv0D4nI8nwoS7WlU3HWA4KKJqqhf5/e1X3IS+XhfcmkFGy4AsUfL9KMqWZ1XVQVk8gCJHW3iXyXPRjf/BbF9aYEfo4umRfSdbkUBFEvLDUXM3pmz0xpGFYLhIuEzAN10Mi+TylcmEYeLJdaKK7Q/c3lkG/pJHUy0aH11YBxeSkLr0Lb5CykGUyXD2tncf9wkhY+8Do09rMgPt/hxyoqGbQn1qtr4R7nsNXIcmqnHkRVOnBCC21gSUnTv7oVaq+hCpNrJzaFbHa7Pj3AYbmJucKBQChy/NjTyqzuZgjxGsvHnLIFgUaDxQs3J9X0r3IoCUZ3wdxa/VHODQEQa5fPqrLXTAgMoOB42lpC5sbn3jwitRkkJwU82bNeKLl5oYdEMwMINL5jqr4qexQ/yP/0ShpVZcw+zG+6slOkQ2Q2zwhY/meGvoJxQhzN3PqU9nH8XqHzL4p2sQAqjTd/whEf3+XU9SxFSx8EuiJ8N+2hfpYS7gU1jfhwZDTeUZsKjLPGTSD4pVvfOrDWQhO0Wmozn1mOy46aol5bw5EgC52QY8UokxlkrwHSCkrAHPcL5NIspnFCymEjRjOEuNFFaKFbfFoBSTpXBPeZu5AeEhTzsAzB1l43B2vOQoBl9+GZRqwAa6VFJwoqSVCHALVsTrc6GZuuSzCeEAAOVBs2ODph7POertXAcOlGecB1XDr2tD5P6C4aatHjQkrilXDG9LwW/NF7osmls3f+Cbj9wCSA1tH6UKSoFiuqlgsaJ5IhegI7goRfuZRA/thOaYtyA6sIcd9Uu/CG1Xwru848KCmeIAAl91ac/6wjhnAbd2t7JqifLUHNCuFHl8Ru2PmluOK80ti5s40rWkXplDUh8TZgctitYpzBw0jMmkfXYpWKibKPB1EWEQ5TL6NUoUOXzXL3ym/u3l/c5syuJIyba658OwQj/RRUFCigYEIOh0dFAwgf2Rm84R1xJEN1mca0hxBUXyZprufZXZuGm7q4IMqpFtJ+IhESv0MvcOBaPC5s76wGiUxMkGlfKBJzZ0XvHHZDpyWeWscWvsDsqah9XNSHcOwTwx1ZiUBgl+RRT7O+NvZZ0FEaDfanIvki3x8q1zywelRpoUpibYLN/cLMJHTIzRHYHCDvJ3kOAkDsdFMIRF2g+QERQ6tO9FB6P9cCWL5H2BxXTzG3P8jkhdBl/kzvSlR3MaV1ReLD+i+IrF3UMYB34ZQDLmG4XpS68ydsHboKilDspylXm/1mHipJw7XePUjDvQAHiH0RSDyb2B/MOlKHIdFwFWk5h0JS7BxIrO3ef3xnRgJmhnFzcGdAp1uWo4EhrRIWhL9XLdyiQM1I8ZK9XWhC2fQIyGFXZffxV3g+Td3rLDEIi7WLPEwre3c5SMk8bQMeiyVknvG7InhYm/l8/h3PF6l1Ewksva361usbwiirKj3MUExNtqfBlja3dzL9yaXqDLejxJU1dim2jrWhDJ+oobsBSFmLflXNzB9xkpy4ZRA5YgVGnhrcJvjT6lhM+N63lqyU/9c9EaeMdRb9dxYkwE3kObwlvLbmBrkqsUWeL0adqECb4dYMLo/sUKrSwIeGMNcwV1oZTnEzeI/KPHiKwLNnXNI/rNV6aokRgzyMSYQd78HouLFhqk3kJAB0z6qZZJQPLKuvdo04w1nES+hMhLgxnrJv0ouYaEFCfim0AEkqM15FJGX0R1HlGa5GD8tzIdqBczIug8VJ6i/WlWhqqi0q/KnrJDfd8kLNZSRRbpD9gM1ZotrgR4tKRpvV7o6hmqoYnjH9C4Q2sc8QyPnE2yeShelNJ86f4gNfodQz74xvaWjLKqbAaZIkgjvdgauRvJQTRhG3SeH6lpJjHG2n3K39Gon1NaRM1AVwGbLVNfIoSSTkNEOjvwQVGyZLYEqB7aKCXT6DlNP0AuvlKxkkBYxsY6M7qBoio4A8yvVPWO3Y9yNY1yv6/6BsYxx7wc5rewhPNx+TIjz2n6nrEN5nbURa+u1qIPGOmCEf6cSXs9vAKJO+/cJ4XZOvRsMzQWCgaALf9x2Fr7xIpkO87eYAE8wDlyowOC5JemLOVEGgAHJreplWJH9PguU5QRxRc3JHpt8c15vJOH2hkcKyjjpPYF/Q9Gn2nkSiT8HGYIHDBffS/o4vODW5NXRTaNHvHWbYm3xKCcsI+eQjzMLT9WQ9lVGTFD09j3vXK1EewzeOhETjued+dc45rUWBBctgwp3I5CpZI5MBibo5qUyBkxmngAs42lavGQYI11eZweu3DglwNxOep3vuJNnLcmit7U0wWrZqpjxDNhCL++/ex6AQa5Mb/pav4lW8dQfqDnKIP7cNJ0RW3n/oFc+/AEhfMB+4VrhyGN5ezy7NfAbwPPOoKMyt+o2EYY9ySpyDNukFCh1xgeV3kdwXC1WLaCvquEmiSaMCT/f6fFVw8wU7VALq9PBoX0kJ9M7YkUlLpxWXGiw4A95r6aQkyaB+0BuuDSkoN4P6DN2C9aHoF7aeh62YRrzPW4/Po2sisGDVfDwwAUH1IGt3W8P3TebxX/mY+RW1wfho4for9I+Rh0qZxTYCtlkHXSETQtByimRr9qHx8O+JbmG3YYZAudQs3h795Yp4o22K7UpdYQYpcZteA10MnunXCjNDp/GCOcAIn2amdzJZWVci/0K0GOMecbXyNNfIoPe6xskVfwy8kgoLJnXSBQIxErLPzgfclv4dO4rsUZIWHEbS3aDO4POq77aNDuk26yT3SKA/lHrG0VnnYrhAXqDSe1qyNfzp6cCC12vMbjmATNgUoK1Mh0qh9PQ2+kSrqtnYeDB9N/oWsE2/HSGiS+K6TG1M7W5RV2+rm18/P7KDAAbBlhqx9Gt5u4b++SfSRGcbwJfuX5VnUbQSn4nA7ZBh7xUc/AySeGALAW0aTmq32pRI6RAd5piFYhLh3WrllXi/ZoifPU5FPfxJ9RNUx0pR2bDQHCNkEqYWgWXgzQMpkIl47QGl2fIP/IIrJB0hcD8bLfttqKvS6Q7y/YALIc6zzGHxEMCoge7mQeUCVmvSKGSFkYZYy8c7tf7ian16wGpReRj0ca4SfQxZ2qur6YM3gXFcvrOTr3nzMGXQ2le47IwEgtFd+xfm/gtdZnL/xDepb+snuroTObvA81v5TVRiZXsvq0buCBKSsUAi1BdiGNdxi76Odyjv2NzbjLdXm2z9pWuxILTiZzlNw70N0+JhtDYQcIKBN8popfnn5YtXtjIkqm8TWcZPa9Q6VxJuXv5MI8hXVI+mjrShod17Cu+cDDkcpuEcRw1mUjzwx0TaBDmA23RYUFKwCXzs57zYAmW7Eo50L+14A6rFZZTFi6vm70QkBEVUZ08kb9F3ostdiDQy+t4rz7kd3m3Dfln31BIyl3vzCc9u6lBIALfUXPit6v2apXwXw21gGmttqi86c67Nyf4xa/ogeCuNFW8/Hq19JNlo90zEmhdDJjhMjt/4YWYk8AiYaeo13UjolkPy2dcw/+HfU24Xt/JIDnWGBpsM52MvXuvyXEWvxkCxXUcopG6oLvo9odDHeSUbu2JcC0tMFkENVkxS7n91tguCD72CmV1L8x/38gf9IBlFo3DcFUs0j5KwF6wYmv4KhnS2ZWYzB1uKgiGa6+5gJRBUHgKot2yZbTZIryMdhtAt1hsej1LPAagGsuY/V2qHgxwzWmd+Lv7eh95TD/ngj6pAhaQJfzsddOfQCEGYR0WjKM3hnM60ehVCr/cA3QlOGQiJ2ZgNnzMEv5Y1bH7ELpt8572jzojyYTIzls1WeO0uRRuevkcuIRsRFgU/3Vv6dY+z5R/JZnzmh5c0bC5KhfAajZjPMx208110t2WWHfe38CJx2Q36ZLXIokbly+D6hR1Y9F3vqnxcQYB/c4fNlGJbmKDxvhikwy/Q2nGpYC/vqtPyEkf02Mt3ow2i2ApHtrDnnqRrVfy8xdKaJZ0QCcOR7xU1qcrpTBLcG2+PFKNyXExtkKDIXALridIO/YQmGeEkMen9/nR/SweJ5eFfHpzLYL3QB9bdK2l40xBzWfq8jD3d2ud+ydYYJn4EscTT83zImWlZtw/FmYOulAYSIYHnzRInia+AhOVoBMw22UIlZXa9yCEHicANXOTgGmpcKCXA5Rvc8lv/ADDEudXSPrT9YrzWdnB2qQI/qB6CdfMN8ILTwh81U+T0YZ0Ioi0GW7ASqDIYuBzsSFC15/IXTQ1FiiDp/iB09dTia0rdUqsTa/0Cs/m/rcRKjYUzVsE326vuDBGfAOeULozvRWool5lyn2tedvleZcbS0OtUATbzGXJYAhYkUna3f6a5MrFsq2cLQvaF8aS6OY0Iy3oXGcZShzz8WObW6zaVAgppS838BstiQ0pgkWD16GRNo0/56zEsAeSp62/93YccbyT9F4CajmXyO4KCpmTxtFwqpSnWwGtbVTNPvDxk2KhPB/1oPM34kF8odkC2LF2aEFEE4eQFGkUT4UbfZlHEhacc6O4tpYjL64WdKWBF0z0Dwj8iM5eA7n44A70DLzTazUgX0VBcyqCrwcd+uRUmy4WQfzO/BxjaaDR5hvUQFKXcf8/iYFp+/w4XVI4C+FGzha3RMyvR8QYAlz9KyBOmhjRArkbE05zRyv/o8cS8We7Jm+AfzS56NbpJgL3AOnJw+6yncsHrJDmn6P0XO7UBQOPkFQF5z4MVqsxABTsQ6xu+jr7irbpIs7M63FDTPl5ipCeickD2LwlMG2rsg6EdJvRBqgbLApar6bdrcphF4czQWoAI3J5EVE6NDfkUvOZ06RjN2WnZBqQERip/cVxfkLpPldfAcLGlZPEPjfC1PEsxhamv70qJKaUxcuNqk9NQUo2zfCS/6lVFKF9Vx0zbKPzJb24aMUihI8XTRWtNcU7+PJXiwCS0laJk7NJUs88dwJQoxpF7gVUM+/TdC+XIGWbVzkyaQTfzSmlch4gXxIHo6Y58tUsOoWUtPRdxDRSrldq2l6qKBmMZr9QFZ/fFrgi7i9HGi6ORHYvJhESagy56eN3Uq9XhVBPRA4VDP/OCwCUQD/NO6+essQY+xJISMM0xow/CE0yFuNo8l8CsCS+eE6l26forOuk8ZmUVkjdbt4v/enO5SZVeDK7cWTmTnadsVR89dFW6jCjpcw2VH8k/G/Zsy5f+uj/npoiWii2x/uubRP9bd+DtjyFh2+rygE+LuG/coafly2DxteGhovzYBTY8z1I7+YEQmwQJTNSNlHNqohrlRhYJ2r5THjig6UCwm7HMH6oa/lRM5wnw0hyP+WUEex8E2Kt0bJINkDipoTRR3e0sEP0b2oT8X1LHCraxj+phoS5T1Be6gj8OXZAZ2KfK6R2xm0DXTOIAOPdtjBD90/OlcZjykoAfQPrewjji1xWAA8p6XoEM98aug8PVFti9YCrT+d+LH9TpsEYEU5hl5CfGZRupDOvjRLRPXkaQbli9IQ/iQZSC4javBkRi0HE0jYdX4M9/wezhObHFh0cE+huloQPgfbLKWYy0mcDTYJndJEBc64uYE219C6Regh9VGshmyZvRzKrofnHLirDH8dMIXnBpD3xUbzicD5yt+8HZ808SCXx8R04SFUbn3MZXW3KZtPwkbxrRSGfYcjq/YvOlD2hWDBOINZWBo5ZRnoD9LxLRer9rvzfvyKSqwjRKVPq1dYXOiL3abgrXq8s8m4MyJTaLjh534aLCroX4qdlQeaEdi68ylgC2a6aySuAFZW2Ut8++2UPSeA16HKztQjfI8/SiZ5hC41VD3SvvmAsJAJli9Vlzeo4IclJJ/nf8GnuQF+HW9ErJEEr8NLfRyL7Y2vAPbPnmy2zmpjjEqU+5xA7/3XtGaW54w3DRkU+WuNi5nUgwvnc28W/9RbpVNiKssSw1eW+In6rJRYRZc5i8ZpCguXw1eZeqpfLdgg4swzLA5OdbQDghcRWNiNGV4WjWzclr8BxfqfLchjGhqWxv9x3LeKH+boKgfHDgihT+kuV/lzMaqo28k5n77Ti81eT3raat8708FKvHKflXjXs8bd8jHRi595409d9PFkycG9CCRPz0+pUhRuhaVaIicBkHoFGcW0ouiaZCKDwpSalEpzwa7yzY0ync3TB+6z4NdgO1I1gdM82xaGaCM1ALuyyUoRHYAQQhZgznybEeHFQ2gNdxy5yk+ITunWlXex0T/X0UGZxxHvyqBXoVYb99otHFgLMXyFZIIx76q0aoxaaIkdnIo2eeroGF6eHpYMPj2Ds+EGipwSz4+peX2o/MOSb5yfXSWOLVrytxd9SLcLv+Tp8zrIMSt/cd0PHx1cGNypW4vNhB/+l9FR213Y886VXI0/kCsO+PHKKK0tCtqFcZkLK2+5ASmLAF9QsKicqhb9tT9afIWfibwggV4tovH4G6CITDUVdXstEY46QzD6S3MQ8+llRsaHKc9WCpOXf6dPbNgMR9FoJOXoZ2lQW5P35HjPzbRsEAcVVBgtW+NqqaCLpMnPpY1F8u65U/gMgpHQUkvUjdj22xbZnZPnaxSTHpUyCWK7i3B1J/cXL9rWPvPGx6ZRfiQL0Z0IMCMD1Z67LOVaAHzvMqwg8MEOa4+0j0phDprNaZdIDIH0Eu2t64o1i1VShwF88V1WGUYfJoXB/1br361tqJSE8mtea2NHyx82oipiBC9twwb3AgGXXRTDE0SMc2OoA0HrHoj5DLgDtzrEi8Oh5JGjJR/p4raDLeK6ldIvppllnvLq64cC7NHhhIX/048EEMk5Dcr7mX1fG7zRwLhCERcyWLqUkHiBtWTVAfJmvTtUbXpRY5SU3/OGHQ/PMVpDzqDKblxUV0OCfMwNQYmIBA3/En9MdxcNJIkK7VQq7dzZiuTVK0eRBiiSN+Ep17SX57IMz6WOsYasADym3OWtuH3Y1KpnxAnppT6cpmlVqRAtdZgI9zWZJ7f5uoK6XiTgzkvlRtuY37CVU5zJLI+LLr2rp72GRjPXUR8Ix6MjK8nnTgF4pB8nUkJK7PGi49FRMIrea/2kxXOjRLNIEdqmobQ1IcsjvCLJGwHqEP/rrbawHJPyy/ptoPvsxSQ42bLVN8XGWY04P1WL8jB8wbcATckQLr07k8ApoDy3+qDzzem8uM/0xWQA0lZOf/pMBDD8BK+lqIR9eMlI3XxHxTKPY51M2dTLz5s0xSugYlKrsBkHzuh9bBlcFRlZlLLxuEpGGOdVP6CPXnsXD+OfJ01Or3Xn3pO/4fJnorINWMjqo0ptf3NNwMvtw2x9Hbi1O+f57vfBVxcd4MSSUUrmo5tCWDd9LNYc8zgqmM6sEPYqIIg+edGoj9o7FC7sr1huMOLEe0RyNmirj2tMHErDlfelfWnM3xHxph5wzr3aE3p1NTaQOwdsDqciah+HqbIY09ynSDbJ6A1ua0JWQZFrxnG87U+rjSuCmGtp07iccrPsKOTMfCxyfDOk6AVNU0yfo0Qqbund5cPtQrfhxWQuB1j0nAebmhBb38FFgsW5EjzutT8KjnzdVM2sLKPnWuPa3m4dPhgtabG9DCFbbOmmcWUkOUVwHynmtHevrhwbkYTsbyb4lLhJKf7j41qnB6CvThB6VN3O+JVOLp9rdygb7JyWo5B6cUsiLwey0voNnA+tTUybGtWZTfl2TT7Y+IZ+zfnxKl2Qmb37MB1wzbM/5DB6f9QbTViu+atLXVnITHXF3Woy5k8X9sQrwvyTGn411x0/8r9jLrz6fo42LcUdQuHzssmv6cEjDr+fSB4BxYW2oC88jiOdwRmZ9TkACeDoQbUn+kXWtXUg8q1qhLla1C5qe19Et9gkFZKHSj5PMstIqMQakkvTcYBWYZG5eGwtGRbcEeBd/c4Sle729v9HnbImvZMceeJlHcsKK7sinVjW16IDEXtF3QsndkqHwJhxU/SgnE/o8/Qjn3ELydp+k8HMIJxgmtQFErgniwpAQ9QOpqbUWvvNODz+N/6bCJw1vvHHJgHnQ26YCC6fdKIX/beAWEHMTQtdvVeQyy/tY0DU2uBcOfzzQSidTylb0NE3VPZ9i+411zp7lnjaLFn/QB3Xe6U0RUVf2KkTxP7QDohzwnSov8VEaMmzCrYtBFkmDIozkGtwMnmlptPZ3DO44Egz7xWKToz3uMd48aL1nflRCkBy2HqzHLqLuhVzqND71dYrv06DiHtc/Z9mv7N3+1dyMW6zrGIILSOIHMrKdUipbcqlPvLgQ4N9rIzYMJUrJ3dfwZ9iGVDSvCEJdUZz8MhUeK8G2evNAguKJFC3sW+/Q4RQjsbD7JvrwJJh4Ju9bvqTY/Atea7UvoVmJUOHBdmzdtjsMgOcWEb3vA8u8FN1xvlVw==</Value></TokenEntry></Values></UseKey><Claims><Values xmlns:q1="http://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[16]"><TokenEntry><Name>SessionKey</Name><Value>p916pCIgxbSeR5+UxUHZ8EosslhyspdGf5AxUSQmWv4PtEMftIsABmIz6TCfyeV8h1ioH3rnwp8jTKGFTZJzOMKsEoaK3rnsrB7qrPdj4WXgClraYjX4l+Toyxvm1Jc3lXOk35aFsrFNccSvQy09lFziMCDuzrT2BQjzSmI/mcAvd+8+kLnUHKoATY9exvs7HcGvd0JPdh2aGqn3dxJptDXAK02TOCu5mrK26TGXF0QcTWBWpF8lNgI5yIuDOrZLoL14V6o6MUmDv1gRuA1RO7CgNJAPcK0qVhz3uoIxL+jcqRAln4hLVf2eGEhCAYtz19aAldCjEf0kFMnZyL420A==</Value></TokenEntry><TokenEntry><Name>BindingType</Name><Value>S4QjLLFArJjqGeb36HjLFAvTHkYh76OFgANGcHMFOfU=</Value></TokenEntry><TokenEntry><Name>Binding</Name><Value>crxwtRde6X0U/2LlvmDcS75dL1yTIfG/hQ3oR8mYv4NoO8pCaKOeEOzmxt8BfKD9LsBvkTbtYiVybiiwBLWGjhsPA6ofWyLTxfj1cy1Ce5Y=</Value></TokenEntry><TokenEntry><Name>ProductKey</Name><Value>zLmNDmAsk3Um5kO5zbbDNBb/Zgv+OnWn+KyWeyouWhA=</Value></TokenEntry><TokenEntry><Name>ProductKeyType</Name><Value>S4QjLLFArJjqGeb36HjLFIs7EYCKGzOMHi/fXmLeHi0=</Value></TokenEntry><TokenEntry><Name>ProductKeyActConfigId</Name><Value>/50zqPFxqnzvxqQxao5wglY0PPxU1AHBfdS+6IzQM2IX28kWalN6CYiqkxsCk7bsam3uBfkUflpFWF772a40e4WqHKxf8Bks9xak7DiYgT4=</Value></TokenEntry><TokenEntry><Name>otherInfoPublic.licenseCategory</Name><Value>3Q2RK8iGEFclHjdVbKVh4J11NfxKwo/xoikXQJptjAg=</Value></TokenEntry><TokenEntry><Name>otherInfoPrivate.licenseCategory</Name><Value>3Q2RK8iGEFclHjdVbKVh4FLKRkIStIs/kV1NLz6nXPc=</Value></TokenEntry><TokenEntry><Name>otherInfoPublic.sysprepAction</Name><Value>dSSkEZmsBLnF9bF5eKfJ4Q==</Value></TokenEntry><TokenEntry><Name>otherInfoPrivate.sysprepAction</Name><Value>dSSkEZmsBLnF9bF5eKfJ4Q==</Value></TokenEntry><TokenEntry><Name>ClientInformation</Name><Value>Zh0Pv84nGe6FpaQypspeSsAIeOS/XaaA2AsCOqlW7aYluw35YayJQonYwwcoQZKy0mNQrlROu2fPCIOR99iCEg==</Value></TokenEntry><TokenEntry><Name>ReferralInformation</Name><Value>TCBUNywvg+LSFAKM2NsAtPdQi+4Jd6FLRNvO6jpbkzIgVKIIZGsh8L24d/VYDfYIi+AkgDF72qIGlIqs1u6l1g==</Value></TokenEntry><TokenEntry><Name>ClientSystemTime</Name><Value>rmpsMmdi3t/+hO0flS2kKwFqDz8RMIf3ZFE4UmjYee8=</Value></TokenEntry><TokenEntry><Name>ClientSystemTimeUtc</Name><Value>rmpsMmdi3t/+hO0flS2kKwFqDz8RMIf3ZFE4UmjYee8=</Value></TokenEntry><TokenEntry><Name>otherInfoPublic.secureStoreId</Name><Value>mQYUeqC2RSvrGSRctEAExAP4qw5oVF6nkHmCli+FK2feoH2Crg5KaghL29HfyrSP</Value></TokenEntry><TokenEntry><Name>otherInfoPrivate.secureStoreId</Name><Value>mQYUeqC2RSvrGSRctEAExAP4qw5oVF6nkHmCli+FK2feoH2Crg5KaghL29HfyrSP</Value></TokenEntry></Values></Claims></RequestSecurityToken></soap:Body></soap:Envelope>)
00010002(0x80072EE7, 03:00:50:194 - <NULL>)
00010003(0x80072EE7, 03:00:50:194)
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz
Percentage of memory in use: 44%
Total physical RAM: 3940.22 MB
Available physical RAM: 2193.58 MB
Total Pagefile: 5348.22 MB
Available Pagefile: 3383.66 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:452.03 GB) (Free:427.34 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (8 NH) (Removable) (Total:7.73 GB) (Free:1.46 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 00624645)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 7.8 GB) (Disk ID: 00000000)
Partition: GPT Partition Type. |