FRST.txt (Teil 5) Code:
2014-12-10 22:56 - 2014-10-29 02:27 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\netsh.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\nslookup.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\esentprf.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00058368 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\net.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\setx.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\ftp.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\lodctr.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\HelpPaneProxy.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\mspatcha.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\signdrv.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\sscore.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\unlodctr.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\perfos.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\SecEdit.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\perfdisk.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\virtdisk.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\deviceassociation.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\format.com
2014-12-10 22:56 - 2014-10-29 02:27 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wcmapi.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\findstr.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\OnDemandConnRouteHelper.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00031744 _____ (Microsoft Corporation) C:\windows\system32\cacls.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\EventAggregation.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\dsparse.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\more.com
2014-12-10 22:56 - 2014-10-29 02:27 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\fltMC.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\sysntfy.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\fvecerts.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\ARP.EXE
2014-12-10 22:56 - 2014-10-29 02:27 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\schedcli.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\adhapi.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\PING.EXE
2014-12-10 22:56 - 2014-10-29 02:27 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\CSystemEventsBrokerClient.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\httpprxp.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00018432 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerClient.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\TRACERT.EXE
2014-12-10 22:56 - 2014-10-29 02:27 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\finger.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\Register-CimProvider.exe
2014-12-10 22:56 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\smphost.dll
2014-12-10 22:56 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\HOSTNAME.EXE
2014-12-10 22:56 - 2014-10-29 02:27 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\TetheringIeProvider.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\icm32.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\ntdsapi.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00120320 _____ (Microsoft Corporation) C:\windows\SysWOW64\EhStorAuthn.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00088576 _____ (Microsoft Corporation) C:\windows\system32\pnrpnsp.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\powercfg.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00080896 _____ (Microsoft Corporation) C:\windows\system32\w32tm.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\wlidnsp.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\Windows.Globalization.Fontgroups.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\fmifs.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00046592 _____ (Microsoft Corporation) C:\windows\system32\typeperf.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\srumapi.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\relog.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00038400 _____ (Microsoft Corporation) C:\windows\SysWOW64\FXSEXT32.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\NetEvtFwdr.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\MirrorDrvCompat.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\crypttpmeksvc.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00037376 _____ (Microsoft Corporation) C:\windows\SysWOW64\uicom.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\XInput1_4.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\winbrand.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appsruprov.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00034304 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscntrs.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00031744 _____ (Microsoft Corporation) C:\windows\system32\pots.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\eapprovp.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\WcnEapPeerProxy.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\WcnEapAuthProxy.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\VaultCmd.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\chkdsk.exe
2014-12-10 22:56 - 2014-10-29 02:26 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\userinitext.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimgvw.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\MRINFO.EXE
2014-12-10 22:56 - 2014-10-29 02:26 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\ProximityRtapiPal.dll
2014-12-10 22:56 - 2014-10-29 02:26 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wpcsvc.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00104960 _____ (Microsoft Corporation) C:\windows\system32\winbio.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\winipsec.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00102400 _____ (Microsoft Corporation) C:\windows\system32\DevDispItemProvider.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\winlogonext.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\xmlfilter.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00041472 _____ (Microsoft Corporation) C:\windows\SysWOW64\tpmcompc.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-12-10 22:56 - 2014-10-29 02:25 - 00027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\rtffilt.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\WPDShextAutoplay.exe
2014-12-10 22:56 - 2014-10-29 02:25 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\wfapigp.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\ncuprov.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\wininitext.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wlansvcpal.dll
2014-12-10 22:56 - 2014-10-29 02:25 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\dnsext.dll
2014-12-10 22:56 - 2014-10-29 02:24 - 00133632 _____ (Microsoft Corporation) C:\windows\SysWOW64\apprepapi.dll
2014-12-10 22:56 - 2014-10-29 02:24 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\wlanext.exe
2014-12-10 22:56 - 2014-10-29 02:24 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2014-12-10 22:56 - 2014-10-29 02:24 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\UserLanguageProfileCallback.dll
2014-12-10 22:56 - 2014-10-29 02:24 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\procinst.dll
2014-12-10 22:56 - 2014-10-29 02:23 - 00097280 _____ (Microsoft Corporation) C:\windows\SysWOW64\netid.dll
2014-12-10 22:56 - 2014-10-29 02:23 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\PCPKsp.dll
2014-12-10 22:56 - 2014-10-29 02:23 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Enumeration.ps.dll
2014-12-10 22:56 - 2014-10-29 02:23 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Custom.ps.dll
2014-12-10 22:56 - 2014-10-29 02:23 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Background.ps.dll
2014-12-10 22:56 - 2014-10-29 02:23 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\AppxStreamingDataSourcePS.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\fdProxy.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\msauserext.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\SubscriptionMgr.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\mmcss.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\vss_ps.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\TaskSchdPS.dll
2014-12-10 22:56 - 2014-10-29 02:22 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\keyiso.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00105472 _____ (Microsoft Corporation) C:\windows\system32\cngcredui.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\bcdsrv.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\wshbth.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\luainstall.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\catsrvps.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\perfctrs.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Portable.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Printers.Extensions.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\ipconfig.exe
2014-12-10 22:56 - 2014-10-29 02:21 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\cfmifs.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\BackgroundTransferHost.exe
2014-12-10 22:56 - 2014-10-29 02:21 - 00031744 _____ (Microsoft Corporation) C:\windows\system32\WsmAgent.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\nlmproxy.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\elsTrans.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\Windows.System.Display.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\Windows.System.Profile.SystemManufacturers.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\wpnsruprov.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\delegatorprovider.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\storagewmi_passthru.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\CallButtons.ProxyStub.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\ROUTE.EXE
2014-12-10 22:56 - 2014-10-29 02:21 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\Windows.System.RemoteDesktop.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\defragproxy.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\AuthHostProxy.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\TtlsExt.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\TimeSyncTask.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\cfmifsproxy.dll
2014-12-10 22:56 - 2014-10-29 02:21 - 00009216 _____ (Microsoft Corporation) C:\windows\system32\dllhst3g.exe
2014-12-10 22:56 - 2014-10-29 02:20 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\wersvc.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00072704 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapimig.exe
2014-12-10 22:56 - 2014-10-29 02:20 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\msimtf.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\NETSTAT.EXE
2014-12-10 22:56 - 2014-10-29 02:20 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\dimsjob.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\AuthExt.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\encapi.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\ProximityCommonPal.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\ReAgentTask.dll
2014-12-10 22:56 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\keepaliveprovider.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00094720 _____ (Microsoft Corporation) C:\windows\system32\dasHost.exe
2014-12-10 22:56 - 2014-10-29 02:19 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\stclient.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00058368 _____ (Microsoft Corporation) C:\windows\system32\rasmbmgr.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\profext.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\sxshared.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\pnrpauto.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\raschapext.dll
2014-12-10 22:56 - 2014-10-29 02:19 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\rastlsext.dll
2014-12-10 22:56 - 2014-10-29 02:18 - 00094720 _____ (Microsoft Corporation) C:\windows\system32\bthserv.dll
2014-12-10 22:56 - 2014-10-29 02:18 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\RoamingSecurity.dll
2014-12-10 22:56 - 2014-10-29 02:18 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\wsdchngr.dll
2014-12-10 22:56 - 2014-10-29 02:17 - 00231424 _____ (Microsoft Corporation) C:\windows\system32\onex.dll
2014-12-10 22:56 - 2014-10-29 02:17 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\WofTasks.dll
2014-12-10 22:56 - 2014-10-29 02:17 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\wfdprov.dll
2014-12-10 22:56 - 2014-10-29 02:16 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\FwRemoteSvr.dll
2014-12-10 22:56 - 2014-10-29 02:16 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\inetmib1.dll
2014-12-10 22:56 - 2014-10-29 02:16 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\xolehlp.dll
2014-12-10 22:56 - 2014-10-29 02:15 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\FDResPub.dll
2014-12-10 22:56 - 2014-10-29 02:15 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\winrshost.exe
2014-12-10 22:56 - 2014-10-29 02:14 - 00344576 _____ (Microsoft Corporation) C:\windows\system32\certCredProvider.dll
2014-12-10 22:56 - 2014-10-29 02:14 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\RDSPnf.exe
2014-12-10 22:56 - 2014-10-29 02:14 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\ProximityServicePal.dll
2014-12-10 22:56 - 2014-10-29 02:14 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\nci.dll
2014-12-10 22:56 - 2014-10-29 02:13 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\umb.dll
2014-12-10 22:56 - 2014-10-29 02:13 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\fdPnp.dll
2014-12-10 22:56 - 2014-10-29 02:12 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\msdtc.exe
2014-12-10 22:56 - 2014-10-29 02:12 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\wwaninst.dll
2014-12-10 22:56 - 2014-10-29 02:12 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\DsmUserTask.exe
2014-12-10 22:56 - 2014-10-29 02:11 - 00088576 _____ (Microsoft Corporation) C:\windows\SysWOW64\efsadu.dll
2014-12-10 22:56 - 2014-10-29 02:11 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\umpoext.dll
2014-12-10 22:56 - 2014-10-29 02:09 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\ifmon.dll
2014-12-10 22:56 - 2014-10-29 02:08 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\winrs.exe
2014-12-10 22:56 - 2014-10-29 02:06 - 00057344 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll
2014-12-10 22:56 - 2014-10-29 02:06 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmiclnt.dll
2014-12-10 22:56 - 2014-10-29 02:06 - 00026112 _____ (Microsoft Corporation) C:\windows\SysWOW64\httpapi.dll
2014-12-10 22:56 - 2014-10-29 02:06 - 00024064 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-12-10 22:56 - 2014-10-29 02:06 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapi.dll
2014-12-10 22:56 - 2014-10-29 02:06 - 00012288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mprext.dll
2014-12-10 22:56 - 2014-10-29 02:06 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\C_ISCII.DLL
2014-12-10 22:56 - 2014-10-29 02:06 - 00008704 _____ (Microsoft Corporation) C:\windows\SysWOW64\dabapi.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00589824 _____ (Microsoft Corporation) C:\windows\SysWOW64\elslad.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00222720 _____ (Microsoft Corporation) C:\windows\SysWOW64\C_G18030.DLL
2014-12-10 22:56 - 2014-10-29 02:05 - 00113152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mprmsg.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00111104 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\winrscmd.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00066560 _____ (Microsoft Corporation) C:\windows\SysWOW64\hbaapi.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00065024 _____ (Microsoft Corporation) C:\windows\SysWOW64\mspatchc.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\samlib.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\reg.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00060928 _____ (Microsoft Corporation) C:\windows\SysWOW64\sc.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\ndiscapCfg.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00045056 _____ (Microsoft Corporation) C:\windows\SysWOW64\mskeyprotect.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00043520 _____ (Microsoft Corporation) C:\windows\SysWOW64\lodctr.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfscli.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00042496 _____ (Microsoft Corporation) C:\windows\SysWOW64\rtutils.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\perfproc.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mspatcha.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\perfos.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00035840 _____ (Microsoft Corporation) C:\windows\SysWOW64\Websocket.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\unlodctr.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\perfdisk.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshhttp.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00031744 _____ (Microsoft Corporation) C:\windows\SysWOW64\vidcap.ax
2014-12-10 22:56 - 2014-10-29 02:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\virtdisk.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\icacls.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00028672 _____ (Microsoft Corporation) C:\windows\SysWOW64\w32topl.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00028160 _____ (Microsoft Corporation) C:\windows\SysWOW64\vpnikeapi.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\OnDemandConnRouteHelper.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcsubs.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\snmpapi.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\hid.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00023552 _____ (Microsoft Corporation) C:\windows\SysWOW64\tbs.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00023552 _____ (Microsoft Corporation) C:\windows\SysWOW64\more.com
2014-12-10 22:56 - 2014-10-29 02:05 - 00022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\userinit.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\perfnet.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\dsparse.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00019968 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Background.TimeBroker.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00019968 _____ (Microsoft Corporation) C:\windows\SysWOW64\bitsperf.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\schedcli.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00018432 _____ (Microsoft Corporation) C:\windows\SysWOW64\PING.EXE
2014-12-10 22:56 - 2014-10-29 02:05 - 00018432 _____ (Microsoft Corporation) C:\windows\SysWOW64\attrib.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mskeyprotcli.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00016896 _____ (Microsoft Corporation) C:\windows\SysWOW64\fltLib.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\SysWOW64\TimeBrokerClient.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\SysWOW64\PATHPING.EXE
2014-12-10 22:56 - 2014-10-29 02:05 - 00015872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshqos.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\mountvol.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00014848 _____ (Microsoft Corporation) C:\windows\SysWOW64\TRACERT.EXE
2014-12-10 22:56 - 2014-10-29 02:05 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\SystemEventsBrokerClient.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmsgapi.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\finger.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00012288 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasadhlp.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmplpxy.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\whhelper.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\C_IS2022.DLL
2014-12-10 22:56 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\winrssrv.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdBthProxy.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\TCPSVCS.EXE
2014-12-10 22:56 - 2014-10-29 02:05 - 00009216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msidle.dll
2014-12-10 22:56 - 2014-10-29 02:05 - 00008704 _____ (Microsoft Corporation) C:\windows\SysWOW64\backgroundTaskHost.exe
2014-12-10 22:56 - 2014-10-29 02:05 - 00006144 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimg32.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\GlobCollationHost.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\netsh.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00077312 _____ (Microsoft Corporation) C:\windows\SysWOW64\nslookup.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\pnrpnsp.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\esentprf.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\CertEnrollCtrl.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\setx.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00044544 _____ (Microsoft Corporation) C:\windows\SysWOW64\browcli.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00041472 _____ (Microsoft Corporation) C:\windows\SysWOW64\typeperf.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00038400 _____ (Microsoft Corporation) C:\windows\SysWOW64\relog.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00037376 _____ (Microsoft Corporation) C:\windows\SysWOW64\SecEdit.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\srumapi.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00031744 _____ (Microsoft Corporation) C:\windows\SysWOW64\sscore.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\deviceassociation.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00029184 _____ (Microsoft Corporation) C:\windows\SysWOW64\findstr.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00028160 _____ (Microsoft Corporation) C:\windows\SysWOW64\pots.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\wcmapi.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\cacls.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\eapprovp.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\fltMC.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ARP.EXE
2014-12-10 22:56 - 2014-10-29 02:04 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00016384 _____ (Microsoft Corporation) C:\windows\SysWOW64\userinitext.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\Register-CimProvider.exe
2014-12-10 22:56 - 2014-10-29 02:04 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\smphost.dll
2014-12-10 22:56 - 2014-10-29 02:04 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\HOSTNAME.EXE
2014-12-10 22:56 - 2014-10-29 02:04 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\wpcsvc.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00183808 _____ (Microsoft Corporation) C:\windows\system32\LaunchTM.exe
2014-12-10 22:56 - 2014-10-29 02:03 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\w32tm.exe
2014-12-10 22:56 - 2014-10-29 02:03 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlidnsp.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00042496 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Globalization.Fontgroups.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpkinstall.exe
2014-12-10 22:56 - 2014-10-29 02:03 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\MirrorDrvCompat.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypttpmeksvc.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\XInput1_4.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00029184 _____ (Microsoft Corporation) C:\windows\SysWOW64\winbrand.dll
2014-12-10 22:56 - 2014-10-29 02:03 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\chkdsk.exe
2014-12-10 22:56 - 2014-10-29 02:03 - 00013824 _____ (Microsoft Corporation) C:\windows\SysWOW64\MRINFO.EXE
2014-12-10 22:56 - 2014-10-29 02:03 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\ProximityRtapiPal.dll
2014-12-10 22:56 - 2014-10-29 02:02 - 00087552 _____ (Microsoft Corporation) C:\windows\SysWOW64\DevDispItemProvider.dll
2014-12-10 22:56 - 2014-10-29 02:02 - 00079360 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanext.exe
2014-12-10 22:56 - 2014-10-29 02:02 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\winbio.dll
2014-12-10 22:56 - 2014-10-29 02:02 - 00072704 _____ (Microsoft Corporation) C:\windows\SysWOW64\winipsec.dll
2014-12-10 22:56 - 2014-10-29 02:02 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2014-12-10 22:56 - 2014-10-29 02:02 - 00020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfapigp.dll
2014-12-10 22:56 - 2014-10-29 02:02 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininitext.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\PCPKsp.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\keyiso.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\TaskSchdPS.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\windows\SysWOW64\vss_ps.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdProxy.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Enumeration.ps.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\slpts.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Custom.ps.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00012288 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Background.ps.dll
2014-12-10 22:56 - 2014-10-29 02:01 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserLanguageProfileCallback.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00101376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngcredui.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshbth.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\luainstall.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00040960 _____ (Microsoft Corporation) C:\windows\SysWOW64\perfctrs.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Printers.Extensions.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Portable.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\NETSTAT.EXE
2014-12-10 22:56 - 2014-10-29 02:00 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ipconfig.exe
2014-12-10 22:56 - 2014-10-29 02:00 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsjob.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\mtxlegih.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00029184 _____ (Microsoft Corporation) C:\windows\SysWOW64\BackgroundTransferHost.exe
2014-12-10 22:56 - 2014-10-29 02:00 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\cfmifs.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00026112 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAgent.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\mtxdm.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\elsTrans.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\catsrvps.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.System.Display.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.System.Profile.SystemManufacturers.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\encapi.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\delegatorprovider.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00019968 _____ (Microsoft Corporation) C:\windows\SysWOW64\storagewmi_passthru.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00019456 _____ (Microsoft Corporation) C:\windows\SysWOW64\ROUTE.EXE
2014-12-10 22:56 - 2014-10-29 02:00 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.System.RemoteDesktop.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00016896 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlmproxy.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00013824 _____ (Microsoft Corporation) C:\windows\SysWOW64\TtlsExt.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00013824 _____ (Microsoft Corporation) C:\windows\SysWOW64\ProximityCommonPal.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\CallButtons.ProxyStub.dll
2014-12-10 22:56 - 2014-10-29 02:00 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\cfmifsproxy.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00058368 _____ (Microsoft Corporation) C:\windows\system32\dot3gpclnt.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\eappprxy.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00054272 _____ (Microsoft Corporation) C:\windows\SysWOW64\pautoenr.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00053760 _____ (Microsoft Corporation) C:\windows\SysWOW64\stclient.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00045568 _____ (Microsoft Corporation) C:\windows\SysWOW64\profext.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\raschapext.dll
2014-12-10 22:56 - 2014-10-29 01:59 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastlsext.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\PSModuleDiscoveryProvider.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimtf.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsdchngr.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00024064 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfdprov.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\fdPHost.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\sxshared.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\Startupscan.dll
2014-12-10 22:56 - 2014-10-29 01:58 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\bootim.exe
2014-12-10 22:56 - 2014-10-29 01:57 - 00203264 _____ (Microsoft Corporation) C:\windows\SysWOW64\onex.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00133120 _____ (Microsoft Corporation) C:\windows\system32\mssprxy.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\NcdAutoSetup.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00053760 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetmib1.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\FwRemoteSvr.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\dataclen.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\datusage.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\ByteCodeGenerator.exe
2014-12-10 22:56 - 2014-10-29 01:57 - 00023552 _____ (Microsoft Corporation) C:\windows\SysWOW64\winrshost.exe
2014-12-10 22:56 - 2014-10-29 01:57 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\energytask.dll
2014-12-10 22:56 - 2014-10-29 01:57 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\msshooks.dll
2014-12-10 22:56 - 2014-10-29 01:56 - 00337920 _____ (Microsoft Corporation) C:\windows\SysWOW64\certCredProvider.dll
2014-12-10 22:56 - 2014-10-29 01:56 - 00090112 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwcfg.dll
2014-12-10 22:56 - 2014-10-29 01:56 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\PrintIsolationProxy.dll
2014-12-10 22:56 - 2014-10-29 01:56 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\xolehlp.dll
2014-12-10 22:56 - 2014-10-29 01:56 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\nci.dll
2014-12-10 22:56 - 2014-10-29 01:55 - 00044544 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdPnp.dll
2014-12-10 22:56 - 2014-10-29 01:55 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\CheckNetIsolation.exe
2014-12-10 22:56 - 2014-10-29 01:55 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\RdpSaProxy.exe
2014-12-10 22:56 - 2014-10-29 01:54 - 00077312 _____ (Microsoft Corporation) C:\windows\SysWOW64\DHCPQEC.DLL
2014-12-10 22:56 - 2014-10-29 01:54 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\RdpSaUacHelper.exe
2014-12-10 22:56 - 2014-10-29 01:53 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\WSDPrintProxy.DLL
2014-12-10 22:56 - 2014-10-29 01:53 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\CredentialMigrationHandler.dll
2014-12-10 22:56 - 2014-10-29 01:53 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\ifmon.dll
2014-12-10 22:56 - 2014-10-29 01:52 - 00041472 _____ (Microsoft Corporation) C:\windows\SysWOW64\winrs.exe
2014-12-10 22:56 - 2014-10-29 01:51 - 00095744 _____ (Microsoft Corporation) C:\windows\SysWOW64\winrscmd.dll
2014-12-10 22:56 - 2014-10-29 01:51 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\ndiscapCfg.dll
2014-12-10 22:56 - 2014-10-29 01:50 - 00182784 _____ (Microsoft Corporation) C:\windows\SysWOW64\LaunchTM.exe
2014-12-10 22:56 - 2014-10-29 01:50 - 00041472 _____ (Microsoft Corporation) C:\windows\SysWOW64\CertEnrollCtrl.exe
2014-12-10 22:56 - 2014-10-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2014-12-10 22:56 - 2014-10-29 01:48 - 00014848 _____ (Microsoft Corporation) C:\windows\SysWOW64\slpts.dll
2014-12-10 22:56 - 2014-10-29 01:47 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dot3gpclnt.dll
2014-12-10 22:56 - 2014-10-29 01:46 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssprxy.dll
2014-12-10 22:56 - 2014-10-29 01:46 - 00038912 _____ (Microsoft Corporation) C:\windows\SysWOW64\PSModuleDiscoveryProvider.dll
2014-12-10 22:56 - 2014-10-29 01:46 - 00028672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ByteCodeGenerator.exe
2014-12-10 22:56 - 2014-10-29 01:46 - 00014848 _____ (Microsoft Corporation) C:\windows\SysWOW64\Startupscan.dll
2014-12-10 22:56 - 2014-10-29 01:45 - 00035840 _____ (Microsoft Corporation) C:\windows\SysWOW64\dataclen.dll
2014-12-10 22:56 - 2014-10-29 01:45 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\msshooks.dll
2014-12-10 22:56 - 2014-10-29 01:44 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\CheckNetIsolation.exe
2014-12-10 22:56 - 2014-10-29 01:44 - 00022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\RdpSaUacHelper.exe
2014-12-10 22:56 - 2014-10-29 01:44 - 00022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\RdpSaProxy.exe
2014-12-10 22:56 - 2014-10-29 01:43 - 00027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\CredentialMigrationHandler.dll
2014-12-10 22:56 - 2014-10-29 01:42 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncPolicy.dll
2014-12-10 22:56 - 2014-10-29 01:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSyncPolicy.dll
2014-12-10 22:56 - 2014-10-15 09:32 - 00921920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\refs.sys
2014-12-10 22:56 - 2014-10-07 07:54 - 00324928 ____C (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2014-12-10 22:56 - 2014-10-07 07:54 - 00189248 ____C (Microsoft Corporation) C:\windows\system32\Drivers\UCX01000.SYS
2014-12-10 22:56 - 2014-10-07 07:44 - 00069952 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vpci.sys
2014-12-10 22:56 - 2014-06-21 08:33 - 00212736 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2014-12-10 22:52 - 2014-10-31 05:50 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\BulkOperationHost.exe
2014-12-10 22:52 - 2014-10-31 04:30 - 00120832 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll
2014-12-10 22:52 - 2014-10-31 04:22 - 00291840 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll
2014-12-10 22:52 - 2014-10-31 03:12 - 00266752 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll
2014-12-10 22:45 - 2014-11-17 21:17 - 00672984 _____ (Microsoft Corporation) C:\windows\system32\MDMAgent.exe
2014-12-10 22:45 - 2014-11-17 21:17 - 00273240 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlows.exe
2014-12-10 22:45 - 2014-11-14 07:58 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsDatabase.dll
2014-12-10 22:45 - 2014-11-14 07:54 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\SystemSettings.Handlers.dll
2014-12-10 22:45 - 2014-11-14 07:46 - 02171904 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlowUI.dll
2014-12-10 22:45 - 2014-11-14 07:46 - 01091072 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
2014-12-10 22:45 - 2014-11-14 07:39 - 02819584 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll
2014-12-10 22:45 - 2014-11-14 05:53 - 00790528 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll
2014-12-10 22:44 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-12-10 22:44 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-12-10 22:44 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-12-10 22:44 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-12-10 22:44 - 2014-11-15 20:05 - 00801584 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2014-12-10 22:44 - 2014-11-15 07:29 - 00962216 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2014-12-10 22:44 - 2014-11-14 15:36 - 00055776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-12-10 22:44 - 2014-11-14 08:10 - 03558400 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-12-10 22:44 - 2014-11-14 07:58 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2014-12-10 22:44 - 2014-11-14 07:57 - 01027584 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
2014-12-10 22:44 - 2014-11-14 07:57 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2014-12-10 22:44 - 2014-11-14 07:54 - 00407552 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2014-12-10 22:44 - 2014-11-14 07:54 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2014-12-10 22:44 - 2014-11-14 07:53 - 00894976 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2014-12-10 22:44 - 2014-11-14 07:52 - 01714176 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-12-10 22:44 - 2014-11-14 06:04 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2014-12-10 22:44 - 2014-11-14 06:03 - 00885760 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
2014-12-10 22:44 - 2014-11-14 06:03 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2014-12-10 22:44 - 2014-11-14 06:01 - 00723968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2014-12-10 22:44 - 2014-11-14 06:01 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2014-12-10 22:44 - 2014-11-11 01:39 - 22290560 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-12-10 22:44 - 2014-11-11 01:17 - 19731824 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-12-10 22:44 - 2014-11-10 19:06 - 02485056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-12-10 22:44 - 2014-11-10 19:06 - 00473408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2014-12-10 22:44 - 2014-11-10 19:06 - 00428864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-12-10 22:44 - 2014-11-10 19:06 - 00136512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wfplwfs.sys
2014-12-10 22:44 - 2014-11-10 03:57 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\agilevpn.sys
2014-12-10 22:44 - 2014-11-10 02:37 - 00845312 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL
2014-12-10 22:44 - 2014-11-10 02:34 - 01084416 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2014-12-10 22:44 - 2014-11-10 02:26 - 00422400 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2014-12-10 22:44 - 2014-11-10 02:20 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\vpnike.dll
2014-12-10 22:44 - 2014-11-10 02:09 - 00272384 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2014-12-10 22:44 - 2014-11-10 02:08 - 00702464 _____ (Microsoft Corporation) C:\windows\system32\rasapi32.dll
2014-12-10 22:44 - 2014-11-10 02:06 - 00713216 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2014-12-10 22:44 - 2014-11-10 01:57 - 00624640 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasapi32.dll
2014-12-10 22:44 - 2014-11-10 01:57 - 00561664 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2014-12-10 22:44 - 2014-11-08 11:42 - 01390928 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2014-12-10 22:44 - 2014-11-08 11:23 - 01127976 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2014-12-10 22:44 - 2014-11-08 05:00 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndproxy.sys
2014-12-10 22:44 - 2014-11-08 05:00 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndistapi.sys
2014-12-10 22:44 - 2014-11-08 04:58 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rasl2tp.sys
2014-12-10 22:44 - 2014-11-08 04:58 - 00080896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wanarp.sys
2014-12-10 22:44 - 2014-11-08 04:56 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\kmddsp.tsp
2014-12-10 22:44 - 2014-11-08 04:56 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\rasmxs.dll
2014-12-10 22:44 - 2014-11-08 04:56 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\rasser.dll
2014-12-10 22:44 - 2014-11-08 04:24 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\rasdiag.dll
2014-12-10 22:44 - 2014-11-08 04:13 - 00039424 _____ (Microsoft Corporation) C:\windows\SysWOW64\kmddsp.tsp
2014-12-10 22:44 - 2014-11-08 04:13 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasmxs.dll
2014-12-10 22:44 - 2014-11-08 04:13 - 00022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasser.dll
2014-12-10 22:44 - 2014-11-08 03:48 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasdiag.dll
2014-12-10 22:44 - 2014-11-08 03:38 - 00166912 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
2014-12-10 22:44 - 2014-11-08 03:17 - 00143360 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
2014-12-10 22:44 - 2014-11-08 03:09 - 00182784 _____ (Microsoft Corporation) C:\windows\system32\rascfg.dll
2014-12-10 22:44 - 2014-11-08 03:03 - 00733696 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll
2014-12-10 22:44 - 2014-11-08 02:59 - 00162304 _____ (Microsoft Corporation) C:\windows\SysWOW64\rascfg.dll
2014-12-10 22:44 - 2014-11-08 02:58 - 04837376 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll
2014-12-10 22:44 - 2014-11-08 02:49 - 01154048 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe
2014-12-10 22:44 - 2014-11-07 04:58 - 00952896 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
2014-12-10 22:44 - 2014-11-07 04:20 - 00786120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
2014-12-10 22:44 - 2014-11-05 03:12 - 00211968 _____ (Microsoft Corporation) C:\windows\system32\QSHVHOST.DLL
2014-12-10 22:44 - 2014-11-05 03:12 - 00128000 _____ (Microsoft Corporation) C:\windows\system32\QSVRMGMT.DLL
2014-12-10 22:44 - 2014-11-05 03:06 - 00514048 _____ (Microsoft Corporation) C:\windows\system32\DevicePairing.dll
2014-12-10 22:44 - 2014-11-05 02:44 - 00657920 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll
2014-12-10 22:44 - 2014-11-05 02:43 - 00252416 _____ (Microsoft Corporation) C:\windows\system32\dnsrslvr.dll
2014-12-10 22:44 - 2014-11-05 02:41 - 00558080 _____ (Microsoft Corporation) C:\windows\system32\untfs.dll
2014-12-10 22:44 - 2014-11-05 02:39 - 00155648 _____ (Microsoft Corporation) C:\windows\SysWOW64\QSHVHOST.DLL
2014-12-10 22:44 - 2014-11-05 02:39 - 00094208 _____ (Microsoft Corporation) C:\windows\SysWOW64\QSVRMGMT.DLL
2014-12-10 22:44 - 2014-11-05 02:33 - 00465408 _____ (Microsoft Corporation) C:\windows\SysWOW64\DevicePairing.dll
2014-12-10 22:44 - 2014-11-05 02:21 - 00658432 _____ (Microsoft Corporation) C:\windows\system32\WSDApi.dll
2014-12-10 22:44 - 2014-11-05 02:20 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll
2014-12-10 22:44 - 2014-11-05 02:18 - 00507392 _____ (Microsoft Corporation) C:\windows\SysWOW64\untfs.dll
2014-12-10 22:44 - 2014-11-05 02:14 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\WSDMon.dll
2014-12-10 22:44 - 2014-11-05 02:06 - 00555520 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSDApi.dll
2014-12-10 22:44 - 2014-11-04 20:33 - 00058176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dam.sys
2014-12-10 22:44 - 2014-11-04 20:25 - 00059712 ____C (Microsoft Corporation) C:\windows\system32\Drivers\kbdclass.sys
2014-12-10 22:44 - 2014-11-04 20:25 - 00051008 ____C (Microsoft Corporation) C:\windows\system32\Drivers\mouclass.sys
2014-12-10 22:44 - 2014-11-04 07:55 - 00026112 ____C (Microsoft Corporation) C:\windows\system32\Drivers\sermouse.sys
2014-12-10 22:44 - 2014-11-04 07:54 - 00108544 ____C (Microsoft Corporation) C:\windows\system32\Drivers\i8042prt.sys
2014-12-10 22:44 - 2014-11-04 07:54 - 00032256 ____C (Microsoft Corporation) C:\windows\system32\Drivers\kbdhid.sys
2014-12-10 22:44 - 2014-11-04 07:54 - 00030208 ____C (Microsoft Corporation) C:\windows\system32\Drivers\mouhid.sys
2014-12-10 22:44 - 2014-11-04 07:27 - 00128512 _____ (Microsoft Corporation) C:\windows\splwow64.exe
2014-12-10 22:44 - 2014-11-04 06:01 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2014-12-10 22:44 - 2014-10-31 01:51 - 18823168 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll
2014-12-10 22:44 - 2014-10-31 01:10 - 15158784 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll
2014-12-10 22:44 - 2014-10-31 00:39 - 01970432 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2014-12-10 22:44 - 2014-10-31 00:38 - 01612992 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2014-12-10 22:44 - 2014-10-30 06:55 - 07473472 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-12-10 22:44 - 2014-10-30 06:47 - 01499384 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2014-12-10 22:44 - 2014-10-30 06:41 - 01733952 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2014-12-10 22:44 - 2014-10-29 04:05 - 00551232 ____C (Microsoft Corporation) C:\windows\system32\Drivers\vhdmp.sys
2014-12-10 22:44 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-12-10 22:44 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-12-10 22:44 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-12-10 22:44 - 2014-10-29 02:55 - 00242176 _____ (Microsoft Corporation) C:\windows\system32\WinSCard.dll
2014-12-10 22:44 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-12-10 22:44 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-12-10 22:44 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-12-10 22:44 - 2014-10-29 02:13 - 00169984 _____ (Microsoft Corporation) C:\windows\SysWOW64\WinSCard.dll
2014-12-10 22:44 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-12-10 22:44 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-12-10 22:44 - 2014-10-26 23:10 - 00390841 _____ () C:\windows\system32\ApnDatabase.xml
2014-12-10 22:44 - 2014-10-21 02:59 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\eventcls.dll
2014-12-10 22:44 - 2014-10-21 02:19 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\eventcls.dll
2014-12-10 22:44 - 2014-10-21 01:50 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\vsstrace.dll
2014-12-10 22:44 - 2014-10-21 01:31 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\vssapi.dll
2014-12-10 22:44 - 2014-10-21 01:31 - 00055296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vsstrace.dll
2014-12-10 22:44 - 2014-10-21 01:30 - 01454080 _____ (Microsoft Corporation) C:\windows\system32\VSSVC.exe
2014-12-10 22:44 - 2014-10-21 01:20 - 01142272 _____ (Microsoft Corporation) C:\windows\SysWOW64\vssapi.dll
2014-12-10 22:44 - 2014-10-17 05:56 - 00238912 ____C (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2014-12-10 22:44 - 2014-10-17 05:56 - 00153920 ____C (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2014-12-10 22:44 - 2014-10-17 05:56 - 00039744 ____C (Microsoft Corporation) C:\windows\system32\Drivers\intelpep.sys
2014-12-10 22:44 - 2014-10-17 04:35 - 00086336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pdc.sys
2014-12-10 22:43 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-12-10 22:43 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-12-10 22:43 - 2014-11-22 03:49 - 00417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2014-12-10 22:43 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-12-10 22:43 - 2014-11-22 03:35 - 00812544 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-12-10 22:43 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-12-10 22:43 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-12-10 22:43 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-12-10 22:43 - 2014-11-22 03:06 - 00340992 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2014-12-10 22:43 - 2014-11-22 03:06 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2014-12-10 22:43 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-12-10 22:43 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-12-10 22:43 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-12-10 22:43 - 2014-11-22 02:59 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2014-12-10 22:43 - 2014-11-22 02:55 - 00661504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-12-10 22:43 - 2014-11-22 02:52 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2014-12-10 22:43 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-12-10 22:43 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-12-10 22:43 - 2014-11-22 02:49 - 00373760 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-12-10 22:43 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-12-10 22:43 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-12-10 22:43 - 2014-11-22 02:34 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2014-12-10 22:43 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-12-10 22:43 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-12-10 22:43 - 2014-11-22 02:29 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2014-12-10 22:43 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-12-10 22:43 - 2014-11-22 02:25 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2014-12-10 22:43 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-12-10 22:43 - 2014-11-22 02:23 - 00326656 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-12-10 22:43 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-12-10 22:43 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-12-10 22:43 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-12-10 22:43 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-12-10 22:43 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-12-10 22:43 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-12-10 22:43 - 2014-11-10 03:29 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\DeviceSetupStatusProvider.dll
2014-12-10 22:43 - 2014-11-10 02:51 - 00028672 _____ (Microsoft Corporation) C:\windows\SysWOW64\DeviceSetupStatusProvider.dll
2014-12-10 22:42 - 2014-11-07 05:16 - 01762840 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-12-10 22:42 - 2014-11-07 04:26 - 01489072 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-12-07 21:32 - 2014-12-07 21:32 - 00000197 _____ () C:\windows\system32\2014-12-07-20-32-38.083-AvastVBoxSVC.exe-1704.log
2014-12-01 21:54 - 2014-12-01 21:57 - 00010323 _____ () C:\Users\Katrin\Desktop\Weihnachten.xlsx
2014-11-30 22:30 - 2014-11-30 22:30 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-11-30 22:30 - 2014-11-30 22:30 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-11-30 22:30 - 2014-11-30 22:30 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-11-30 22:30 - 2014-11-30 22:30 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-11-30 22:30 - 2014-11-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-11-30 22:30 - 2014-11-30 22:30 - 00000000 ____D () C:\Program Files (x86)\Java
2014-11-30 22:04 - 2014-11-30 22:04 - 00000247 _____ () C:\windows\system32\2014-11-30-21-04-02.084-aswFe.exe-6644.log
2014-11-30 22:00 - 2014-11-30 22:03 - 00000247 _____ () C:\windows\system32\2014-11-30-21-00-51.080-aswFe.exe-1604.log
2014-11-30 22:00 - 2014-11-30 22:00 - 00000197 _____ () C:\windows\system32\2014-11-30-21-00-50.050-AvastVBoxSVC.exe-2496.log
2014-11-30 21:55 - 2014-11-30 21:55 - 00003736 _____ () C:\windows\System32\Tasks\SettingsHibernateMonitor
2014-11-30 21:55 - 2014-11-30 21:55 - 00003656 _____ () C:\windows\System32\Tasks\SettingsEventHandlerMonitor
2014-11-30 21:55 - 2014-11-30 21:55 - 00003548 _____ () C:\windows\System32\Tasks\LaunchSettings
2014-11-30 21:54 - 2014-11-30 21:54 - 00002049 _____ () C:\Users\Public\Desktop\Settings.lnk
2014-11-30 17:16 - 2014-11-30 17:16 - 00000197 _____ () C:\windows\system32\2014-11-30-16-16-20.067-AvastVBoxSVC.exe-2464.log
2014-11-30 17:13 - 2014-11-30 17:13 - 01050432 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2014-11-30 17:13 - 2014-11-30 17:13 - 00000197 _____ () C:\windows\system32\2014-11-30-16-13-30.080-AvastVBoxSVC.exe-2388.log
2014-11-30 13:10 - 2014-11-30 13:11 - 00000197 _____ () C:\windows\system32\2014-11-30-12-10-24.039-AvastVBoxSVC.exe-2356.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-28 18:00 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\sru
2014-12-28 17:57 - 2014-11-16 20:52 - 00001154 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-307033961-950837161-3123351550-1002UA.job
2014-12-28 17:55 - 2014-01-02 19:51 - 00765582 _____ () C:\windows\system32\perfh007.dat
2014-12-28 17:55 - 2014-01-02 19:51 - 00159366 _____ () C:\windows\system32\perfc007.dat
2014-12-28 17:55 - 2013-08-27 05:56 - 01776918 _____ () C:\windows\system32\PerfStringBackup.INI
2014-12-28 17:54 - 2014-01-01 02:23 - 00000000 ____D () C:\ProgramData\WinClon
2014-12-28 17:53 - 2014-03-16 21:32 - 00000000 ____D () C:\Users\wolfg_000\AppData\Local\CrashDumps
2014-12-28 17:51 - 2014-11-17 18:46 - 00001132 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-28 17:51 - 2014-02-15 12:55 - 00000000 ___RD () C:\Users\wolfg_000\Dropbox
2014-12-28 17:51 - 2014-02-14 21:26 - 00000000 ____D () C:\Users\wolfg_000\AppData\Roaming\Skype
2014-12-28 17:51 - 2014-02-12 23:11 - 00000000 ____D () C:\Users\wolfg_000\AppData\Roaming\Dropbox
2014-12-28 17:51 - 2014-02-11 19:48 - 00000000 ___DO () C:\Users\wolfg_000\SkyDrive
2014-12-28 17:51 - 2013-08-27 05:50 - 00714474 _____ () C:\windows\PFRO.log
2014-12-28 17:51 - 2013-08-22 15:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-12-28 17:24 - 2014-02-16 23:15 - 00000000 ____D () C:\Users\wolfg_000\Documents\Mein Steuer-Sparbuch Heute
2014-12-28 17:21 - 2014-02-11 19:45 - 00000000 ____D () C:\Users\wolfg_000
2014-12-28 17:13 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\MediaViewer
2014-12-28 16:51 - 2014-11-17 18:46 - 00001136 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-28 16:47 - 2014-02-11 19:11 - 00003594 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-307033961-950837161-3123351550-1001
2014-12-28 16:46 - 2014-07-21 20:06 - 00000000 ____D () C:\Users\Katrin\AppData\Roaming\Skype
2014-12-28 16:45 - 2014-02-11 19:10 - 00003934 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{8C84DF45-4AC6-4741-A6CC-DA15D484A84C}
2014-12-28 16:42 - 2014-07-17 19:39 - 00000000 ___RD () C:\Users\Katrin\Dropbox
2014-12-28 16:42 - 2014-07-17 19:30 - 00000000 ____D () C:\Users\Katrin\AppData\Roaming\Dropbox
2014-12-28 16:42 - 2014-02-11 19:08 - 00000000 __RDO () C:\Users\Katrin\SkyDrive
2014-12-28 16:41 - 2013-08-22 14:25 - 00786432 ___SH () C:\windows\system32\config\BBI
2014-12-28 16:25 - 2014-02-15 16:22 - 00000000 ____D () C:\Users\wolfg_000\AppData\Roaming\KeePass
2014-12-28 13:32 - 2014-02-11 19:02 - 01369227 _____ () C:\windows\WindowsUpdate.log
2014-12-28 13:28 - 2014-02-11 19:52 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-307033961-950837161-3123351550-1002
2014-12-28 12:16 - 2014-02-16 12:46 - 00003946 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{65295CD0-FC02-470D-BFFB-97735C9D9882}
2014-12-27 23:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\rescache
2014-12-26 17:28 - 2014-09-19 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R
2014-12-26 16:28 - 2013-08-22 15:46 - 00042911 _____ () C:\windows\setupact.log
2014-12-26 16:15 - 2014-02-17 21:08 - 00000000 ____D () C:\Temp
2014-12-23 10:45 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\AppReadiness
2014-12-21 20:57 - 2014-11-16 20:52 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-307033961-950837161-3123351550-1002Core.job
2014-12-21 19:53 - 2013-08-22 16:20 - 00000000 ____D () C:\windows\CbsTemp
2014-12-16 19:51 - 2014-07-17 19:31 - 00000000 ____D () C:\Users\Katrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-12-16 14:42 - 2014-06-25 18:55 - 00000000 ____D () C:\R
2014-12-16 14:41 - 2014-02-12 20:13 - 00000000 ____D () C:\Program Files\R
2014-12-14 22:09 - 2014-05-13 15:56 - 00126976 ___SH () C:\Users\Katrin\Desktop\Thumbs.db
2014-12-14 21:34 - 2014-02-16 20:48 - 00000000 ____D () C:\Users\Katrin\AppData\Roaming\KeePass
2014-12-14 20:09 - 2014-11-17 18:03 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-12-12 20:51 - 2014-02-12 23:12 - 00000000 ____D () C:\Users\wolfg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-12-12 19:52 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\NDF
2014-12-12 18:57 - 2014-02-15 12:56 - 00000000 ____D () C:\Users\wolfg_000\AppData\Local\GHISLER
2014-12-12 17:34 - 2014-03-06 19:36 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-12-11 07:21 - 2013-08-22 15:44 - 02417488 _____ () C:\windows\system32\FNTCACHE.DAT
2014-12-11 07:19 - 2013-08-22 20:12 - 00000000 ____D () C:\Program Files\Windows Journal
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___SD () C:\windows\system32\dsc
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\windows\ToastData
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\WinStore
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\SysWOW64\sppui
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\SysWOW64\setup
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\SysWOW64\migwiz
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\SysWOW64\Com
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\WinBioPlugIns
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\SystemResetPlatform
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\sr-Latn-RS
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\sr-Latn-CS
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\sppui
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\setup
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\migwiz
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\Com
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\IME
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\FileManager
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\Camera
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-12-11 07:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2014-12-11 07:19 - 2013-08-22 14:36 - 00000000 ____D () C:\windows\SysWOW64\oobe
2014-12-11 07:19 - 2013-08-22 14:36 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-12-11 07:19 - 2013-08-22 14:36 - 00000000 ____D () C:\windows\system32\Sysprep
2014-12-11 07:19 - 2013-08-22 14:36 - 00000000 ____D () C:\windows\system32\oobe
2014-12-11 07:19 - 2013-08-22 14:36 - 00000000 ____D () C:\windows\system32\Dism
2014-12-11 07:19 - 2013-08-22 14:36 - 00000000 ____D () C:\windows\servicing
2014-12-10 23:13 - 2014-02-15 12:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 23:12 - 2014-02-11 20:01 - 00000000 ____D () C:\windows\system32\MRT
2014-12-10 23:11 - 2014-02-11 19:05 - 00000000 ____D () C:\Users\Katrin
2014-12-10 23:10 - 2014-02-11 20:01 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-11-30 22:30 - 2014-02-16 12:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-11-30 21:54 - 2014-01-01 02:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2014-11-30 21:54 - 2014-01-01 02:12 - 00000000 ____D () C:\Program Files (x86)\Samsung
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
Some content of TEMP:
====================
C:\Users\Katrin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgcuzdb.dll
C:\Users\Katrin\AppData\Local\Temp\Quarantine.exe
C:\Users\Katrin\AppData\Local\Temp\sqlite3.dll
C:\Users\wolfg_000\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpih2yly.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-27 23:13
==================== End Of Log ============================ Addition.txt
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2014
Ran by wolfg_000 at 2014-12-28 18:06:59
Running from C:\Users\wolfg_000\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat 8.1.3 Professional (HKLM-x32\...\Adobe Acrobat 8 Professional - English, Français, Deutsch) (Version: 8.1.3 - )
Adobe Creative Suite 3 Design Premium hinzufügen oder entfernen (HKLM-x32\...\Adobe_dba14d7ef3aa07282d2b5a7a98d902a) (Version: 1.0 - Adobe Systems Incorporated)
Adobe ExtendScript Toolkit 2 (HKLM-x32\...\Adobe_3e054d2218e7aa282c2369d939e58ff) (Version: 2.0.2 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (HKLM-x32\...\{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Flash Player 9 Plugin (HKLM-x32\...\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
AHV content for Acrobat and Flash (x32 Version: 1 - Adobe Systems Incorporated) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bonjour (HKLM\...\{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}) (Version: 2.0.2.0 - Apple Inc.)
ChromecastApp (HKU\S-1-5-21-307033961-950837161-3123351550-1002\...\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1383.0 - Google Inc.)
Dropbox (HKU\S-1-5-21-307033961-950837161-3123351550-1002\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Edraw Mind Map 7.7 (HKLM-x32\...\Edraw Mind Map Freeware_is1) (Version: - EdrawSoft)
ETDWare X64 11.7.19.9_WHQL (HKLM\...\Elantech) (Version: 11.7.19.9 - ELAN Microelectronic Corp.)
foobar2000 v1.3.6 (HKLM-x32\...\foobar2000) (Version: 1.3.6 - Peter Pawlowski)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Help Desk (HKLM\...\{AEC9D273-E162-4614-83F1-722B8C74B185}) (Version: 1.0.96 - Samsung Electronics CO., LTD.)
ImageMagick 6.8.9-7 Q16 (64-bit) (2014-09-15) (HKLM\...\ImageMagick 6.8.9 Q16 (64-bit)_is1) (Version: 6.8.9 - ImageMagick Studio LLC)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3643 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.3.1000 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) Audiodienst (HKLM-x32\...\{C35703F7-D1F4-42DE-8C15-E1A1AAF0A48E}) (Version: 17.0.1430.01 - Intel Corporation)
Intel(R) Wireless Bluetooth(R)(patch version 17.1.1431.1) (HKLM\...\{302600C1-6BDF-4FD1-1407-148929CC1385}) (Version: 17.1.1407.0480 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{7991b5ae-96d7-4df2-97fb-a605b7cb638b}) (Version: 17.12.0 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
KeePass Password Safe 2.28 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.28 - Dominik Reichl)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
PDF Settings (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 2.0.0.21 - RSUPPORT)
posterXXL Designer 5.2 (HKLM-x32\...\posterXXL Designer)_is1) (Version: - )
PuTTY version 0.63 (HKLM-x32\...\PuTTY_is1) (Version: 0.63 - Simon Tatham)
Quick Starter (HKLM\...\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.2 - Samsung Electronics CO., LTD.)
R for Windows 3.1.2 (HKLM\...\R for Windows 3.1.2_is1) (Version: 3.1.2 - R Core Team)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7218 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.12.18 - Samsung Electronics CO., LTD.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RStudio (HKLM-x32\...\RStudio) (Version: 0.98.1062 - RStudio) <==== ATTENTION!
Rtools 3.1 (HKLM-x32\...\Rtools_is1) (Version: - The R Foundation)
S Agent (Version: 1.1.50 - Samsung Electronics CO., LTD.) Hidden
Samsung Link (HKLM-x32\...\{82EC241F-DFCA-4166-A8C3-EA5D2B9A41C4}) (Version: 1.8.0.39 - Samsung Electronics CO., LTD.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.)
Settings (HKLM-x32\...\{3BB58176-B3A7-47FD-9F18-C3576431D193}) (Version: 2.2.0 - Samsung Electronics CO., LTD.)
SideSync (HKLM-x32\...\{59687468-8CE9-4ABF-9C6A-5C31F0E09F8B}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
SRS Premium Sound (HKLM-x32\...\{2E59FB6B-EAB0-4AA6-98EB-09F4027F180B}) (Version: 1.00.5300 - DTS, Inc.)
SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 2.4 - Krzysztof Kowalczyk)
Support Center (HKLM\...\{AB0DEFBB-1A16-47B5-86D2-39F0A2B24AE4}) (Version: 2.1.1210 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.14 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\...\{4F1936F8-82B4-437E-BC47-FAB9136A04B2}) (Version: 2.2.2 - Samsung Electronics CO., LTD.)
System Requirements Lab for Intel (HKLM-x32\...\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Universal Adb Driver (HKLM-x32\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_PROPLUS_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_PROPLUS_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_PROPLUS_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.)
WISO Steuer-Sparbuch 2014 (HKLM-x32\...\{AC40712E-3752-4BB0-B18C-6F0D47D681B0}) (Version: 21.00.8480 - Buhl Data Service GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\wolfg_000\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\wolfg_000\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\wolfg_000\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\wolfg_000\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-307033961-950837161-3123351550-1002_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\wolfg_000\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
10-12-2014 23:00:56 Windows Update
21-12-2014 19:52:12 Windows Update
26-12-2014 16:23:35 Installed Universal Adb Driver
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2014-12-26 16:03 - 00450771 ____R C:\windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0242F8B4-074E-4EA7-A5EE-2AA61C2489B3} - System32\Tasks\{2A89F481-CC1A-4F85-B432-FD0ECF1E7CDD} => pcalua.exe -a E:\isreik.exe -d E:\
Task: {14B236DF-9EAB-4F60-9EEA-292754FD3D6F} - System32\Tasks\LaunchSettings => C:\Program Files (x86)\Samsung\Settings\Settings.exe [2014-10-28] ()
Task: {14B7B6E6-6684-4195-B9BA-AB2E5D3C5253} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-307033961-950837161-3123351550-1002UA => C:\Users\wolfg_000\AppData\Local\Google\Update\GoogleUpdate.exe [2014-04-19] (Google Inc.)
Task: {1B0DE5EB-44A1-459D-B752-D41CCF169477} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-10-10] (Samsung Electronics CO., LTD.)
Task: {267B77EA-DB0B-41B8-A39F-A20AC58E8C70} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-03-21] (Realtek Semiconductor)
Task: {3D66DD8F-C252-4609-9F92-A8CCBFD3B91A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-307033961-950837161-3123351550-1002Core => C:\Users\wolfg_000\AppData\Local\Google\Update\GoogleUpdate.exe [2014-04-19] (Google Inc.)
Task: {513EF43C-DCE0-4AF0-85D3-54D142886C0E} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {572EC7A0-1026-41D8-AFC1-74A41B0909F3} - System32\Tasks\RtHDVBg_SRSSA => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-04-07] (Realtek Semiconductor)
Task: {67E6F2C3-10E6-4E06-A7D7-F028F29B3E41} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-17] (AVAST Software)
Task: {78DD27DC-8F19-4EF2-BFC9-9C10ACFCD8F6} - System32\Tasks\{E24C30E6-AFCA-4730-AD8A-8C8AA0D78A2B} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {7E2ECC56-7FDE-436D-AE6A-A17D0BB46F88} - System32\Tasks\ShutdownOpt => C:ProgramData\Samsung\ShutdownEvent.exe
Task: {845587C7-B9E2-4F0B-8065-BA5F4038771B} - System32\Tasks\SamsungLinkPC => C:\Program Files (x86)\Samsung\HomeSync Lite\RefreshToken.exe
Task: {A5334AA8-6CED-4F7A-9188-AB6D7560D75E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-11] (Google Inc.)
Task: {AD129012-49EA-440D-BB64-C158812D9EE7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-11] (Google Inc.)
Task: {B1EAC676-5034-44C6-AFF7-9F9FC87B6017} - System32\Tasks\SettingsHibernateMonitor => C:\Program Files (x86)\Samsung\Settings\SettingsHibernateMonitor.exe [2014-10-28] (Samsung Electronics CO., LTD.)
Task: {BE8CB203-45EA-4A0E-A794-F4C29F206773} - System32\Tasks\IdleStateFanCtrl => C:\ProgramData\Samsung\SamsungSystemConfiguration\IdleStateFanCtrl.exe [2014-03-18] (Samsung Electronics CO., LTD.)
Task: {C4468B5C-1CC1-4A84-AAEE-36DCF350947C} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2014-11-12] (SEC)
Task: {D52BB4B5-4CC3-4068-8CFD-79E010B336C8} - System32\Tasks\IntelGfxColorWA2 => C:\ProgramData\Samsung\GFXPatch\IntelGfxColorWA2.exe [2014-07-24] (Samsung Electronics Co., Ltd.)
Task: {E8472DCC-C686-490B-B239-3FAC679E03DD} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-12-10] (Microsoft Corporation)
Task: {F7DE8E6A-5173-4EBF-A586-B26E37CE2270} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {FF5B2FAD-ABA2-43B4-87C1-0A18BD89F0CF} - System32\Tasks\SettingsEventHandlerMonitor => C:\Program Files (x86)\Samsung\Settings\CmdServer\RSSettingEventHandler.exe [2014-10-28] (Samsung Electronics CO., LTD.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-307033961-950837161-3123351550-1002Core.job => C:\Users\wolfg_000\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-307033961-950837161-3123351550-1002UA.job => C:\Users\wolfg_000\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2006-11-29 11:07 - 2007-05-11 01:31 - 00921600 _____ () C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AdistRes.DEU
2014-11-17 18:02 - 2014-11-17 18:02 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-11-17 18:02 - 2014-11-17 18:02 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01428760 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe
2014-10-10 20:35 - 2014-10-10 20:35 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll
2014-12-28 12:42 - 2014-12-28 12:42 - 02908160 _____ () C:\Program Files\AVAST Software\Avast\defs\14122800\algo.dll
2014-11-17 18:02 - 2014-11-17 18:02 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2014-10-28 15:11 - 2014-10-28 15:11 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2014-11-17 18:02 - 2014-11-17 18:02 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 09726232 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wgui14.dll
2014-09-18 14:18 - 2014-09-18 13:51 - 03902232 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wcore14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 00035608 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\rsdcom48.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 00322840 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\rsguiwinapi48.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 00309016 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\rscorewinapi48.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 02752280 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wfvie14.dll
2014-02-12 14:25 - 2014-02-11 10:53 - 01043456 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-core.dll
2014-02-12 14:25 - 2014-02-11 10:53 - 00250368 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-contribs-lib.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 00136472 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\rsodbc48.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 02125592 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wsteu14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01933080 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wreli14.dll
2014-02-12 14:25 - 2014-02-11 10:53 - 00094720 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\clucene-shared.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 04325656 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wauff14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01572632 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wmain14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 05302040 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wbae114.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01740568 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wbae214.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01812248 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wbae314.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01633560 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wbae414.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01117976 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\whau114.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01340696 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\whau214.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01312536 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wwerb14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 07357208 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wkont14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01287448 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wimp14.dll
2014-09-18 14:18 - 2014-09-18 13:50 - 01331480 _____ () C:\Program Files (x86)\WISO\Steuersoftware 2014\wfabu14.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00750080 _____ () C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2014-12-28 17:51 - 2014-12-28 17:51 - 00043008 _____ () c:\users\wolfg_000\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpih2yly.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00047616 _____ () C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\libEGL.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00863744 _____ () C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00200704 _____ () C:\Users\wolfg_000\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2014-01-01 02:17 - 2013-09-16 20:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-12-12 17:51 - 2014-12-06 02:50 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
2014-12-12 17:51 - 2014-12-06 02:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll
2014-12-12 17:51 - 2014-12-06 02:50 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll
2014-12-12 17:51 - 2014-12-06 02:50 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
2014-12-12 17:51 - 2014-12-06 02:50 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll
2010-12-17 04:56 - 2010-12-17 04:56 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
2013-03-07 04:53 - 2013-03-07 04:53 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
2010-12-17 04:56 - 2010-12-17 04:56 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
2010-12-17 04:56 - 2010-12-17 04:56 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
2010-01-12 08:55 - 2010-01-12 08:55 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
2010-01-12 08:55 - 2010-01-12 08:55 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
2010-12-16 04:16 - 2010-12-16 04:16 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
2010-01-17 15:34 - 2010-01-17 15:34 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
2013-03-07 04:55 - 2013-03-07 04:55 - 00472576 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
2013-03-07 04:58 - 2013-03-07 04:58 - 00499488 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
2013-03-07 04:54 - 2013-03-07 04:54 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Katrin\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\wolfg_000\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-307033961-950837161-3123351550-500 - Administrator - Disabled)
Gast (S-1-5-21-307033961-950837161-3123351550-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-307033961-950837161-3123351550-1004 - Limited - Enabled)
Katrin (S-1-5-21-307033961-950837161-3123351550-1001 - Administrator - Enabled) => C:\Users\Katrin
wolfg_000 (S-1-5-21-307033961-950837161-3123351550-1002 - Administrator - Enabled) => C:\Users\wolfg_000
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/28/2014 05:53:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x13e0
Startzeit der fehlerhaften Anwendung: 0xGmer-19357.exe0
Pfad der fehlerhaften Anwendung: Gmer-19357.exe1
Pfad des fehlerhaften Moduls: Gmer-19357.exe2
Berichtskennung: Gmer-19357.exe3
Vollständiger Name des fehlerhaften Pakets: Gmer-19357.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Gmer-19357.exe5
Error: (12/28/2014 05:53:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x10f4
Startzeit der fehlerhaften Anwendung: 0xGmer-19357.exe0
Pfad der fehlerhaften Anwendung: Gmer-19357.exe1
Pfad des fehlerhaften Moduls: Gmer-19357.exe2
Berichtskennung: Gmer-19357.exe3
Vollständiger Name des fehlerhaften Pakets: Gmer-19357.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Gmer-19357.exe5
Error: (12/28/2014 05:52:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x928
Startzeit der fehlerhaften Anwendung: 0xGmer-19357.exe0
Pfad der fehlerhaften Anwendung: Gmer-19357.exe1
Pfad des fehlerhaften Moduls: Gmer-19357.exe2
Berichtskennung: Gmer-19357.exe3
Vollständiger Name des fehlerhaften Pakets: Gmer-19357.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Gmer-19357.exe5
Error: (12/28/2014 05:36:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ymey3olj.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: ymey3olj.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x66c
Startzeit der fehlerhaften Anwendung: 0xymey3olj.exe0
Pfad der fehlerhaften Anwendung: ymey3olj.exe1
Pfad des fehlerhaften Moduls: ymey3olj.exe2
Berichtskennung: ymey3olj.exe3
Vollständiger Name des fehlerhaften Pakets: ymey3olj.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ymey3olj.exe5
System errors:
=============
Microsoft Office Sessions:
=========================
Error: (07/03/2014 11:04:11 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1242726 seconds with 180 seconds of active time. This session ended with a crash.
CodeIntegrity Errors:
===================================
Date: 2014-11-17 21:20:41.295
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:40.805
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:40.622
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:40.437
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:40.265
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:40.080
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:39.899
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:39.729
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:39.550
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-11-17 21:20:39.372
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 28%
Total physical RAM: 8106.79 MB
Available physical RAM: 5757.66 MB
Total Pagefile: 12074.79 MB
Available Pagefile: 9624.96 MB
Total Virtual: 131072 MB
Available Virtual: 131071.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:113.33 GB) (Free:51 GB) NTFS
Drive d: (Volume) (Fixed) (Total:110.23 GB) (Free:70.13 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 8CF7B0A5)
Partition: GPT Partition Type.
==================== End Of Log ============================ --- --- ---
Defogger: Code:
d e f o g g e r _ d i s a b l e b y j p s h o r t s t u f f ( 2 3 . 0 2 . 1 0 . 1 )
L o g c r e a t e d a t 1 7 : 2 1 o n 2 8 / 1 2 / 2 0 1 4 ( w o l f g _ 0 0 0 )
C h e c k i n g f o r a u t o s t a r t v a l u e s . . .
H K C U \ ~ \ R u n v a l u e s r e t r i e v e d .
H K L M \ ~ \ R u n v a l u e s r e t r i e v e d .
C h e c k i n g f o r s e r v i c e s / d r i v e r s . . .
- = E . O . F = - AdwCleaner:
[CODE]
AdwCleaner Logfile:AdwCleaner Logfile: Code:
# AdwCleaner v4.106 - Bericht erstellt am 28/12/2014 um 18:55:45
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-28.1 [Live]
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : wolfg_000 - SCHLEPPI
# Gestartet von : C:\Users\wolfg_000\Downloads\adwcleaner_4.106.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Google Chrome v39.0.2171.95
[C:\Users\wolfg_000\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gefunden [Startup_URLs] : hxxp://websearch.searchoholic.info/?pid=20495&r=2014/12/26&hid=17085418371598843895&lg=EN&cc=DE&unqvl=72
*************************
AdwCleaner[R0].txt - [3878 octets] - [28/12/2014 13:16:37]
AdwCleaner[R1].txt - [1173 octets] - [28/12/2014 16:36:12]
AdwCleaner[R2].txt - [2196 octets] - [28/12/2014 16:41:22]
AdwCleaner[R3].txt - [1114 octets] - [28/12/2014 16:48:20]
AdwCleaner[R4].txt - [2699 octets] - [28/12/2014 16:53:57]
AdwCleaner[R5].txt - [2775 octets] - [28/12/2014 17:05:07]
AdwCleaner[R6].txt - [2682 octets] - [28/12/2014 17:49:53]
AdwCleaner[R7].txt - [1601 octets] - [28/12/2014 17:56:21]
AdwCleaner[R8].txt - [1314 octets] - [28/12/2014 18:55:45]
AdwCleaner[S0].txt - [3939 octets] - [28/12/2014 13:18:01]
AdwCleaner[S1].txt - [1189 octets] - [28/12/2014 16:36:47]
AdwCleaner[S2].txt - [2257 octets] - [28/12/2014 16:41:35]
AdwCleaner[S3].txt - [1176 octets] - [28/12/2014 16:48:57]
AdwCleaner[S4].txt - [2760 octets] - [28/12/2014 16:54:18]
AdwCleaner[S5].txt - [2836 octets] - [28/12/2014 17:05:20]
AdwCleaner[S6].txt - [2743 octets] - [28/12/2014 17:50:47]
########## EOF - C:\AdwCleaner\AdwCleaner[R8].txt - [1794 octets] ##########
--- --- ---
--- --- ---
Gmer stürzt beim mir nach dem Start immer mit einer Fehlermeldung ab (trotz deaktivierten Virenscanners, etc): Zitat:
C:\windows\system32\config\system: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird
| Konnte gmer nun im abgesicherten Modus laufen lassen (die Fehlermeldung kam zwar auch, das Programm ist aber nicht abgestürzt), hier das Log: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-12-29 12:21:11
Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\00000032 SAMSUNG_MZMTE256HMHP-000 rev.EXT46K0Q 238,47GB
Running: Gmer-19357.exe; Driver: C:\Users\Katrin\AppData\Local\Temp\uxliypod.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\windows\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff802437d6800 4 bytes [80, 57, A9, FF]
---- Threads - GMER 2.1 ----
Thread C:\windows\system32\csrss.exe [460:296] fffff960009512d0
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |