OTL: Teil 1 Code:
OTL logfile created on: 01.07.2014 10:43:29 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\baustelle\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17031)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,88 Gb Total Physical Memory | 2,68 Gb Available Physical Memory | 69,06% Memory free
4,57 Gb Paging File | 3,29 Gb Available in Paging File | 71,89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 913,70 Gb Total Space | 876,05 Gb Free Space | 95,88% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: baustelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.07.01 09:37:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\baustelle\Desktop\OTL.exe
PRC - [2014.06.24 10:56:04 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2014.06.24 10:55:52 | 000,750,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2014.06.24 10:55:52 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2014.05.08 15:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014.05.02 21:46:46 | 002,800,896 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe
PRC - [2014.05.02 21:46:44 | 008,557,824 | ---- | M] (Acer Cloud Technology) -- C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
PRC - [2014.04.30 09:13:14 | 001,716,264 | ---- | M] (pdfforge GmbH) -- C:\Program Files (x86)\PDF Architect 2\ws.exe
PRC - [2013.10.29 01:51:04 | 001,364,256 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013.09.04 01:53:48 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2013.09.04 01:53:42 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2012.07.14 02:27:00 | 000,769,432 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV:64bit: - [2014.03.08 07:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014.03.06 09:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014.03.06 08:34:46 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2014.02.22 17:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014.02.22 11:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014.02.22 11:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014.02.22 11:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014.02.22 11:25:14 | 000,269,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014.02.22 11:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2014.01.27 17:38:59 | 001,584,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2013.12.10 09:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2013.11.23 06:50:00 | 000,282,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2013.10.19 07:37:49 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013.08.31 12:00:10 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2013.08.22 14:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2013.08.22 13:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2013.08.22 13:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2013.08.22 13:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2013.08.22 13:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2013.08.22 13:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2013.08.22 12:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2013.08.22 12:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2013.08.22 11:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2013.08.22 11:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2013.08.22 11:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013.08.22 11:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013.08.22 11:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2013.08.22 11:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2013.08.22 11:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2013.08.22 11:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2013.08.07 13:40:08 | 000,182,752 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2013.08.07 13:36:38 | 000,219,272 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2014.06.24 10:56:04 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2014.06.24 10:55:52 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2014.06.06 06:38:37 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.05.08 15:48:38 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014.05.02 21:46:46 | 002,800,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Acer Portal\CCDMonitorService.exe -- (CCDMonitorService)
SRV - [2014.04.30 09:13:14 | 001,716,264 | ---- | M] (pdfforge GmbH) [On_Demand | Running] -- C:\Program Files (x86)\PDF Architect 2\ws.exe -- (PDF Architect 2)
SRV - [2014.04.30 09:13:14 | 000,861,736 | ---- | M] (pdfforge GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe -- (pdfforge CrashHandler)
SRV - [2013.12.24 03:26:48 | 000,318,592 | ---- | M] (Windows (R) Win 7 DDK provider) [Auto | Running] -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2013.10.29 01:51:04 | 001,364,256 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013.10.08 18:33:11 | 000,279,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2013.09.04 01:53:48 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2013.09.04 01:53:42 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2013.08.31 11:25:30 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013.08.22 14:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2013.08.22 05:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013.08.22 04:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2013.08.02 19:47:44 | 000,457,768 | ---- | M] (Acer Incorporate) [Auto | Running] -- C:\Programme\Acer\Acer Launch Manager\LMSvc.exe -- (LMSvc)
SRV - [2013.08.02 19:33:16 | 000,448,040 | ---- | M] (Acer Incorporate) [On_Demand | Running] -- C:\Programme\Acer\Acer Quick Access\RMSvc.exe -- (RMSvc)
SRV - [2013.08.02 19:33:14 | 000,457,768 | ---- | M] (Acer Incorporate) [On_Demand | Running] -- C:\Programme\Acer\Acer Quick Access\QASvc.exe -- (QASvc)
SRV - [2013.07.05 17:19:04 | 000,663,592 | ---- | M] (Acer Incorporated) [On_Demand | Running] -- C:\Programme\Acer\Acer Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2013.05.11 18:45:54 | 000,822,232 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV - [2013.05.11 18:45:38 | 000,733,696 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2012.07.14 02:27:00 | 000,769,432 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014.06.24 10:55:52 | 000,117,712 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2014.05.09 11:16:43 | 000,130,584 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2014.05.09 11:16:43 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2014.03.20 05:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014.03.13 14:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014.03.08 22:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014.03.08 22:35:45 | 000,467,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2014.02.22 18:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2014.02.22 17:50:31 | 000,054,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014.02.22 17:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2014.02.22 17:49:49 | 000,384,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014.02.22 17:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014.02.22 17:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014.02.22 17:49:47 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014.02.22 17:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014.02.22 14:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2013.12.24 03:00:52 | 000,597,192 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2013.12.24 03:00:52 | 000,137,928 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2013.12.24 03:00:52 | 000,077,464 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2013.12.24 03:00:50 | 000,338,120 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2013.12.24 03:00:50 | 000,179,432 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2013.12.24 03:00:50 | 000,116,424 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2013.12.24 03:00:50 | 000,089,800 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2013.12.24 03:00:50 | 000,034,384 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2013.12.12 02:10:38 | 003,881,472 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athwbx.sys -- (athr)
DRV:64bit: - [2013.12.04 20:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:64bit: - [2013.11.11 04:48:41 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2013.11.01 13:39:53 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2013.10.31 02:29:36 | 000,236,888 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2013.10.31 02:29:36 | 000,124,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2013.10.31 02:28:47 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2013.10.26 03:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2013.10.05 17:25:54 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2013.10.02 03:31:08 | 000,370,504 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2013.10.01 19:25:25 | 000,449,528 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2013.10.01 19:16:26 | 004,185,600 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2013.09.26 11:08:22 | 000,039,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2013.09.26 11:08:22 | 000,027,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2013.09.14 16:06:57 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2013.09.04 01:53:44 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:64bit: - [2013.08.30 12:05:34 | 000,356,056 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2013.08.22 21:11:06 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2013.08.22 21:11:03 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2013.08.22 15:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013.08.22 15:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013.08.22 14:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013.08.22 14:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013.08.22 14:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013.08.22 14:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013.08.22 14:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013.08.22 14:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013.08.22 14:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013.08.22 14:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013.08.22 14:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013.08.22 14:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013.08.22 14:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013.08.22 14:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013.08.22 14:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013.08.22 14:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013.08.22 14:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013.08.22 14:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013.08.22 14:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013.08.22 14:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013.08.22 14:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013.08.22 14:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013.08.22 14:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013.08.22 14:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013.08.22 14:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013.08.22 14:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013.08.22 14:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013.08.22 14:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2013.08.22 14:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013.08.22 13:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2013.08.22 13:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013.08.22 13:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013.08.22 13:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013.08.22 13:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013.08.22 13:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013.08.22 13:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013.08.22 13:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013.08.22 13:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013.08.22 13:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013.08.22 13:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013.08.22 13:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013.08.22 13:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2013.08.22 13:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2013.08.22 13:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013.08.22 13:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013.08.22 13:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013.08.22 13:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2013.08.22 13:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013.08.22 13:36:17 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2013.08.22 13:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2013.08.22 13:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2013.08.22 10:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013.08.13 01:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013.08.10 02:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013.08.07 15:23:46 | 000,644,968 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2013.08.07 13:43:14 | 000,070,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2013.08.07 13:40:20 | 000,343,568 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2013.08.07 13:38:20 | 000,776,168 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2013.08.07 13:37:02 | 000,519,064 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2013.08.07 13:36:06 | 000,310,224 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2013.08.07 13:35:44 | 000,179,664 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2013.08.07 13:20:04 | 000,069,264 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mfeelamk.sys -- (mfeelamk)
DRV:64bit: - [2013.07.30 20:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013.07.25 21:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013.07.17 03:59:00 | 000,021,360 | ---- | M] (Acer Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMDriver.sys -- (LMDriver)
DRV:64bit: - [2013.07.17 03:59:00 | 000,014,680 | ---- | M] (Acer Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RadioShim.sys -- (RadioShim)
DRV:64bit: - [2013.06.18 16:45:14 | 000,425,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{4DD40821-DE39-4006-A6A0-21CEF77E4A9B}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4DD40821-DE39-4006-A6A0-21CEF77E4A9B}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:30.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\PDF Architect 2: C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
[2014.06.18 14:48:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\baustelle\AppData\Roaming\mozilla\Extensions
[2014.07.01 09:56:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\baustelle\AppData\Roaming\mozilla\Firefox\Profiles\zl2pf6t0.default\extensions
[2014.06.18 14:47:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014.06.18 14:47:52 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2013.08.22 15:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Free Games) - {0D5F364D-D6A9-43C1-BF0C-99B378972C5B} - C:\Program Files (x86)\Free Games\ScriptHost64.dll (BestOffers)
O2 - BHO: (Free Games) - {0D5F364D-D6A9-43C1-BF0C-99B378972C5B} - C:\Program Files (x86)\Free Games\ScriptHost.dll (BestOffers)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKCU..\Run: [AcerCloud] C:\Program Files (x86)\Acer\Acer Portal\acpanel_win.exe (Acer Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: BtvStack = "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe" (Atheros Communications)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{24F481C3-4E92-4BD6-A212-FF4BC8A5C97B}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7F563E37-67C6-4DFC-AEDC-F3B02C50ED5C}: DhcpNameServer = 127.0.0.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (bj.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.07.01 10:41:53 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Roaming\PDF Architect 2
[2014.07.01 10:24:11 | 000,000,000 | ---D | C] -- C:\FRST
[2014.07.01 10:02:29 | 002,083,328 | ---- | C] (Farbar) -- C:\Users\baustelle\Desktop\FRST64.exe
[2014.07.01 09:37:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\baustelle\Desktop\OTL.exe
[2014.06.27 18:45:29 | 000,000,000 | ---D | C] -- C:\Users\baustelle\Desktop\Rassenmäher
[2014.06.27 14:57:34 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\Diagnostics
[2014.06.25 14:05:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Uninstall Information
[2014.06.25 14:05:37 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\speedtest199
[2014.06.25 14:05:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Games
[2014.06.25 14:05:29 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\freegames197
[2014.06.25 13:43:08 | 000,000,000 | ---D | C] -- C:\ProgramData\CanonIJPLM
[2014.06.25 13:43:04 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonIJETV
[2014.06.25 13:42:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Canon
[2014.06.25 09:05:40 | 000,000,000 | -HSD | C] -- C:\Users\baustelle\AppData\Local\EmieUserList
[2014.06.25 09:05:40 | 000,000,000 | -HSD | C] -- C:\Users\baustelle\AppData\Local\EmieSiteList
[2014.06.24 21:04:29 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\CrashDumps
[2014.06.24 12:42:53 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Roaming\TuneUp Software
[2014.06.24 12:42:53 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\TuneUp Software
[2014.06.24 12:40:04 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2014.06.24 12:39:51 | 000,000,000 | -HSD | C] -- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
[2014.06.24 12:39:51 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2014.06.24 12:24:56 | 000,000,000 | ---D | C] -- C:\Users\baustelle\Desktop\Eigene_Dataien
[2014.06.23 10:01:45 | 000,000,000 | ---D | C] -- C:\Users\baustelle\Documents\gaeb AVA Projektablage
[2014.06.23 10:01:44 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Roaming\Nix & Keitel
[2014.06.23 10:01:28 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\Nix & Keitel
[2014.06.23 09:49:08 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Roaming\WinRAR
[2014.06.23 09:45:23 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2014.06.23 09:43:41 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014.06.23 09:43:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014.06.23 09:43:30 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2014.06.22 10:41:52 | 000,000,000 | ---D | C] -- C:\Users\baustelle\Documents\clear.fi
[2014.06.22 10:32:04 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\AcerCloud
[2014.06.22 10:31:33 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\Doc
[2014.06.22 10:31:01 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\ClearfiMedia
[2014.06.22 10:30:24 | 000,000,000 | ---D | C] -- C:\ProgramData\clear.fi
[2014.06.22 10:30:17 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\Acer
[2014.06.22 10:30:04 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Roaming\acer
[2014.06.22 10:29:53 | 000,000,000 | ---D | C] -- C:\Users\baustelle\AppData\Local\ClearfiPhoto
[2014.06.21 13:07:30 | 016,875,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll
[2014.06.21 13:07:28 | 012,732,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2014.06.21 13:07:26 | 008,653,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Search.dll
[2014.06.21 13:07:26 | 007,425,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014.06.21 13:07:26 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Shell.Search.UriHandler.dll
[2014.06.21 13:07:25 | 013,286,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll
[2014.06.21 13:07:23 | 006,641,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014.06.21 13:07:22 | 011,791,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2014.06.21 13:07:22 | 005,833,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Search.dll
[2014.06.21 13:07:22 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Shell.Search.UriHandler.dll
[2014.06.21 13:07:21 | 005,770,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014.06.21 13:07:20 | 004,268,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SyncEngine.dll
[2014.06.21 13:07:20 | 002,900,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll
[2014.06.21 13:07:19 | 002,373,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2014.06.21 13:07:18 | 002,641,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2014.06.21 13:07:18 | 002,133,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll
[2014.06.21 13:07:18 | 001,306,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll
[2014.06.21 13:07:17 | 002,317,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2014.06.21 13:07:17 | 002,141,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2014.06.21 13:07:17 | 002,088,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2014.06.21 13:07:17 | 001,542,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2014.06.21 13:07:17 | 001,054,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.appcore.dll
[2014.06.21 13:07:16 | 002,270,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll
[2014.06.21 13:07:16 | 001,411,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2014.06.21 13:07:16 | 001,112,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2014.06.21 13:07:15 | 001,779,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2014.06.21 13:07:15 | 001,764,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll
[2014.06.21 13:07:15 | 001,129,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFolder.dll
[2014.06.21 13:07:15 | 000,828,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.appcore.dll
[2014.06.21 13:07:14 | 001,291,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2014.06.21 13:07:14 | 001,230,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.dll
[2014.06.21 13:07:14 | 001,023,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2014.06.21 13:07:14 | 000,958,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFMediaEngine.dll
[2014.06.21 13:07:14 | 000,918,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MrmCoreR.dll
[2014.06.21 13:07:13 | 001,466,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll
[2014.06.21 13:07:13 | 001,339,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2014.06.21 13:07:13 | 000,950,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ReAgent.dll
[2014.06.21 13:07:13 | 000,888,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.dll
[2014.06.21 13:07:13 | 000,801,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFMediaEngine.dll
[2014.06.21 13:07:13 | 000,512,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidprov.dll
[2014.06.21 13:07:12 | 000,800,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReAgent.dll
[2014.06.21 13:07:12 | 000,655,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2014.06.21 13:07:12 | 000,629,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MrmCoreR.dll
[2014.06.21 13:07:12 | 000,492,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfsvr.dll
[2014.06.21 13:07:11 | 000,518,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2014.06.21 13:07:11 | 000,388,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfsvr.dll
[2014.06.21 13:07:11 | 000,356,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dcomp.dll
[2014.06.21 13:07:10 | 000,669,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasapi32.dll
[2014.06.21 13:07:10 | 000,379,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2014.06.21 13:07:10 | 000,364,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2014.06.21 13:07:10 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlidprov.dll
[2014.06.21 13:07:09 | 001,656,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GdiPlus.dll
[2014.06.21 13:07:09 | 000,834,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netlogon.dll
[2014.06.21 13:07:09 | 000,157,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wof.sys
[2014.06.21 13:07:08 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fveapi.dll
[2014.06.21 13:07:08 | 000,305,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2014.06.21 13:07:08 | 000,291,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.Sensors.dll
[2014.06.21 13:07:08 | 000,222,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dcomp.dll
[2014.06.21 13:07:07 | 001,351,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll
[2014.06.21 13:07:07 | 000,924,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2014.06.21 13:07:07 | 000,376,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\clfs.sys
[2014.06.21 13:07:06 | 000,872,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SkyDrive.exe
[2014.06.21 13:07:06 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SkyDriveTelemetry.dll
[2014.06.21 13:07:06 | 000,370,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll
[2014.06.21 13:07:06 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentClient.dll
[2014.06.21 13:07:06 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SensorsApi.dll
[2014.06.21 13:07:06 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.Sensors.dll
[2014.06.21 13:07:05 | 000,621,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MDMAgent.exe
[2014.06.21 13:07:05 | 000,488,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcfgx.dll
[2014.06.21 13:07:05 | 000,467,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2014.06.21 13:07:05 | 000,463,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2014.06.21 13:07:05 | 000,337,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys
[2014.06.21 13:07:05 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppXDeploymentClient.dll
[2014.06.21 13:07:04 | 000,390,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcfgx.dll
[2014.06.21 13:07:04 | 000,300,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanmsm.dll
[2014.06.21 13:07:04 | 000,201,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEndpointBuilder.dll
[2014.06.21 13:07:04 | 000,171,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SensorsApi.dll
[2014.06.21 13:07:03 | 000,467,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS
[2014.06.21 13:07:03 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MDEServer.exe
[2014.06.21 13:07:03 | 000,299,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pdh.dll
[2014.06.21 13:07:03 | 000,244,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2014.06.21 13:07:03 | 000,113,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userenv.dll
[2014.06.21 13:07:02 | 000,360,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2014.06.21 13:07:02 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2014.06.21 13:07:02 | 000,201,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ReInfo.dll
[2014.06.21 13:07:02 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppxAllUserStore.dll
[2014.06.21 13:07:02 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppxAllUserStore.dll
[2014.06.21 13:07:02 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2014.06.21 13:07:01 | 001,015,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aclui.dll
[2014.06.21 13:07:01 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlangpui.dll
[2014.06.21 13:07:01 | 000,412,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2014.06.21 13:07:01 | 000,355,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2014.06.21 13:07:01 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanapi.dll
[2014.06.21 13:07:01 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dafWfdProvider.dll
[2014.06.21 13:07:00 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Graphics.Printing.dll
[2014.06.21 13:07:00 | 000,428,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2014.06.21 13:07:00 | 000,298,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSDMon.dll
[2014.06.21 13:07:00 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spp.dll
[2014.06.21 13:07:00 | 000,254,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pdh.dll
[2014.06.21 13:07:00 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanapi.dll
[2014.06.21 13:07:00 | 000,136,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys
[2014.06.21 13:07:00 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvinst.exe
[2014.06.21 13:06:59 | 000,731,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2014.06.21 13:06:59 | 000,731,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2014.06.21 13:06:59 | 000,425,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\clusapi.dll
[2014.06.21 13:06:59 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2014.06.21 13:06:59 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\w32tm.exe
[2014.06.21 13:06:58 | 001,843,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Display.dll
[2014.06.21 13:06:58 | 001,816,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Display.dll
[2014.06.21 13:06:58 | 000,386,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlangpui.dll
[2014.06.21 13:06:58 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fveapibase.dll
[2014.06.21 13:06:58 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
[2014.06.21 13:06:58 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe
[2014.06.21 13:06:58 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\w32tm.exe
[2014.06.21 13:06:58 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvcfg.exe
[2014.06.21 13:06:58 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CredentialMigrationHandler.dll
[2014.06.21 13:06:57 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2014.06.21 13:06:57 | 000,887,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aclui.dll
[2014.06.21 13:06:57 | 000,402,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Graphics.Printing.dll
[2014.06.21 13:06:57 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationApi.dll
[2014.06.21 13:06:57 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.Scanners.dll
[2014.06.21 13:06:57 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMapi.dll
[2014.06.21 13:06:57 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CredentialMigrationHandler.dll
[2014.06.21 13:06:56 | 000,794,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fvewiz.dll
[2014.06.21 13:06:56 | 000,717,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2014.06.21 13:06:56 | 000,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\clusapi.dll
[2014.06.21 13:06:56 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LocationApi.dll
[2014.06.21 13:06:56 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReInfo.dll
[2014.06.21 13:06:56 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.Scanners.dll
[2014.06.21 13:06:56 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevPropMgr.dll
[2014.06.21 13:06:56 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BitLockerDeviceEncryption.exe
[2014.06.21 13:06:56 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sxproxy.dll
[2014.06.21 13:06:56 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2014.06.21 13:06:55 | 000,567,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2014.06.21 13:06:55 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetNetworkLocation.dll
[2014.06.21 13:06:55 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sxproxy.dll
[2014.06.21 13:06:54 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2014.06.21 13:06:54 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlansec.dll
[2014.06.21 13:06:54 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll
[2014.06.21 13:06:54 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\l2gpstore.dll
[2014.06.21 13:06:54 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanhlp.dll
[2014.06.21 13:06:54 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanhlp.dll
[2014.06.21 13:06:53 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BdeHdCfgLib.dll
[2014.06.21 13:06:53 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\l2gpstore.dll
[2014.06.21 13:06:53 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2014.06.21 13:05:32 | 002,678,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers.dll
[2014.06.21 13:05:10 | 001,705,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2014.06.21 13:05:10 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll
[2014.06.21 13:05:10 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\storewuauth.dll
[2014.06.21 13:05:10 | 000,054,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2014.06.21 13:02:56 | 011,742,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\glcndFilter.dll
[2014.06.21 13:02:55 | 003,394,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSService.dll
[2014.06.21 13:02:55 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OobeFldr.dll
[2014.06.21 13:02:55 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OobeFldr.dll
[2014.06.21 13:02:50 | 008,946,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\glcndFilter.dll
[2014.06.21 13:02:48 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014.06.21 13:02:45 | 008,874,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Data.Pdf.dll
[2014.06.21 13:02:41 | 013,933,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2014.06.21 13:02:41 | 001,435,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll
[2014.06.21 13:02:38 | 003,494,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2014.06.21 13:02:37 | 012,027,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Data.Pdf.dll
[2014.06.21 13:02:36 | 011,776,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2014.06.21 13:02:35 | 002,142,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll
[2014.06.21 13:02:30 | 001,927,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\combase.dll
[2014.06.21 13:02:29 | 002,368,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2014.06.21 13:02:29 | 001,576,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidsvc.dll
[2014.06.21 13:02:28 | 002,144,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll
[2014.06.21 13:02:27 | 002,643,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2014.06.21 13:02:27 | 001,374,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\combase.dll
[2014.06.21 13:02:26 | 002,943,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll
[2014.06.21 13:02:25 | 001,728,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dui70.dll
[2014.06.21 13:02:24 | 001,716,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2014.06.21 13:02:23 | 002,574,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2014.06.21 13:02:21 | 002,843,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\actxprxy.dll
[2014.06.21 13:02:21 | 001,445,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webservices.dll
[2014.06.21 13:02:21 | 001,132,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Globalization.dll
[2014.06.21 13:02:20 | 002,100,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettingsAdminFlowUI.dll
[2014.06.21 13:02:19 | 002,588,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpcMon.exe
[2014.06.21 13:02:19 | 001,640,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Immersive.dll
[2014.06.21 13:02:19 | 001,341,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dui70.dll
[2014.06.21 13:02:19 | 001,290,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2014.06.21 13:02:18 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Streaming.dll
[2014.06.21 13:02:18 | 000,628,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msTextPrediction.dll
[2014.06.21 13:02:17 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Security.Authentication.OnlineId.dll
[2014.06.21 13:02:17 | 000,647,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncHost.exe
[2014.06.21 13:02:15 | 001,727,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2014.06.21 13:02:15 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Globalization.dll
[2014.06.21 13:02:14 | 000,777,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncCore.dll
[2014.06.21 13:02:13 | 002,648,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpcWebSync.dll
[2014.06.21 13:02:13 | 001,215,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfnetsrc.dll
[2014.06.21 13:02:13 | 000,800,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfnetcore.dll
[2014.06.21 13:02:12 | 001,496,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Immersive.dll
[2014.06.21 13:02:12 | 001,077,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webservices.dll
[2014.06.21 13:02:12 | 001,000,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinTypes.dll
[2014.06.21 13:02:11 | 002,825,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2014.06.21 13:02:11 | 002,410,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2014.06.21 13:02:11 | 000,791,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uDWM.dll
[2014.06.21 13:02:10 | 001,929,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupapi.dll
[2014.06.21 13:02:10 | 000,978,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Streaming.dll
[2014.06.21 13:02:10 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll
[2014.06.21 13:02:10 | 000,526,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
[2014.06.21 13:02:10 | 000,390,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DfpCommon.dll
[2014.06.21 13:02:10 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WofTasks.dll
[2014.06.21 13:02:09 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.dll
[2014.06.21 13:02:08 | 001,621,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RacEngn.dll
[2014.06.21 13:02:07 | 001,011,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfnetsrc.dll
[2014.06.21 13:02:07 | 000,609,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2014.06.21 13:02:07 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2014.06.21 13:02:07 | 000,517,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSyncHost.exe
[2014.06.21 13:02:06 | 000,422,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2014.06.21 13:02:05 | 001,653,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2014.06.21 13:02:05 | 000,645,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SHCore.dll
[2014.06.21 13:02:04 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014.06.21 13:02:04 | 000,650,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfnetcore.dll
[2014.06.21 13:02:03 | 002,760,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpccpl.dll
[2014.06.21 13:02:03 | 000,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSyncCore.dll
[2014.06.21 13:02:02 | 002,220,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll
[2014.06.21 13:02:02 | 000,556,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinapi.dll
[2014.06.21 13:02:01 | 002,428,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2014.06.21 13:02:01 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uxtheme.dll
[2014.06.21 13:02:01 | 000,825,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll
[2014.06.21 13:02:01 | 000,518,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2014.06.21 13:02:00 | 001,519,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
[2014.06.21 13:01:59 | 000,576,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSync.dll
[2014.06.21 13:01:58 | 001,399,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmde.dll
[2014.06.21 13:01:58 | 000,881,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2014.06.21 13:01:58 | 000,424,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2014.06.21 13:01:58 | 000,366,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll
[2014.06.21 13:01:57 | 002,395,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\storagewmi.dll
[2014.06.21 13:01:57 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wimgapi.dll
[2014.06.21 13:01:57 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014.06.21 13:01:57 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WofUtil.dll
[2014.06.21 13:01:56 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014.06.21 13:01:56 | 000,477,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SHCore.dll
[2014.06.21 13:01:56 | 000,391,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MMDevAPI.dll
[2014.06.21 13:01:55 | 001,206,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Taskmgr.exe
[2014.06.21 13:01:55 | 000,997,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\reseteng.dll
[2014.06.21 13:01:55 | 000,555,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.appcore.dll
[2014.06.21 13:01:55 | 000,530,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppReadiness.dll
[2014.06.21 13:01:54 | 000,698,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSShared.dll
[2014.06.21 13:01:54 | 000,551,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wimgapi.dll
[2014.06.21 13:01:54 | 000,459,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSync.dll
[2014.06.21 13:01:53 | 001,258,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RacEngn.dll
[2014.06.21 13:01:53 | 001,063,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Taskmgr.exe
[2014.06.21 13:01:53 | 000,707,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2014.06.21 13:01:53 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\recimg.exe
[2014.06.21 13:01:53 | 000,569,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpncore.dll
[2014.06.21 13:01:53 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfp.exe
[2014.06.21 13:01:52 | 001,287,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mispace.dll
[2014.06.21 13:01:52 | 001,227,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usercpl.dll
[2014.06.21 13:01:52 | 001,107,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\perftrack.dll
[2014.06.21 13:01:51 | 001,162,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\usercpl.dll
[2014.06.21 13:01:51 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsm.dll
[2014.06.21 13:01:51 | 000,669,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2014.06.21 13:01:51 | 000,635,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WWAHost.exe
[2014.06.21 13:01:51 | 000,461,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe
[2014.06.21 13:01:51 | 000,269,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bisrv.dll
[2014.06.21 13:01:50 | 001,428,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RecoveryDrive.exe
[2014.06.21 13:01:50 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mispace.dll
[2014.06.21 13:01:50 | 000,467,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\energy.dll
[2014.06.21 13:01:49 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2014.06.21 13:01:49 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2014.06.21 13:01:49 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll
[2014.06.21 13:01:49 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WWAHost.exe
[2014.06.21 13:01:49 | 000,419,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinapi.appcore.dll
[2014.06.21 13:01:49 | 000,307,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2014.06.21 13:01:48 | 001,659,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2014.06.21 13:01:48 | 001,374,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2014.06.21 13:01:48 | 000,854,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSShared.dll
[2014.06.21 13:01:48 | 000,410,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe
[2014.06.21 13:01:46 | 001,584,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\workfolderssvc.dll
[2014.06.21 13:01:46 | 001,519,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2014.06.21 13:01:46 | 000,653,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DismApi.dll
[2014.06.21 13:01:46 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014.06.21 13:01:45 | 001,403,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\storagewmi.dll
[2014.06.21 13:01:44 | 000,562,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2014.06.21 13:01:44 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2014.06.21 13:01:43 | 001,487,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2014.06.21 13:01:43 | 001,356,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2014.06.21 13:01:43 | 000,384,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys
[2014.06.21 13:01:42 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014.06.21 13:01:42 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ActionCenter.dll
[2014.06.21 13:01:42 | 000,441,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2014.06.21 13:01:42 | 000,388,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcryptprimitives.dll
[2014.06.21 13:01:42 | 000,372,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvproc.dll
[2014.06.21 13:01:41 | 001,967,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014.06.21 13:01:41 | 001,224,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\werconcpl.dll
[2014.06.21 13:01:41 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2014.06.21 13:01:40 | 000,321,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll
[2014.06.21 13:01:39 | 001,791,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMALFXGFXDSP.dll
[2014.06.21 13:01:39 | 000,755,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctfuimanager.dll
[2014.06.21 13:01:39 | 000,320,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2014.06.21 13:01:38 | 001,206,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winmde.dll
[2014.06.21 13:01:38 | 000,824,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2014.06.21 13:01:38 | 000,531,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2014.06.21 13:01:38 | 000,407,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Faultrep.dll
[2014.06.21 13:01:36 | 000,761,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iuilp.dll
[2014.06.21 13:01:36 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2014.06.21 13:01:36 | 000,716,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll
[2014.06.21 13:01:36 | 000,709,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msctfuimanager.dll
[2014.06.21 13:01:36 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2014.06.21 13:01:36 | 000,244,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll
[2014.06.21 13:01:35 | 001,185,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printui.dll
[2014.06.21 13:01:35 | 000,832,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ActionCenter.dll
[2014.06.21 13:01:35 | 000,747,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidcli.dll
[2014.06.21 13:01:35 | 000,317,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvproc.dll
[2014.06.21 13:01:34 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MrmIndexer.dll
[2014.06.21 13:01:34 | 000,369,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Faultrep.dll
[2014.06.21 13:01:34 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vmrdvcore.dll
[2014.06.21 13:01:34 | 000,336,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bcryptprimitives.dll
[2014.06.21 13:01:34 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slc.dll
[2014.06.21 13:01:33 | 000,912,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nettrace.dll
[2014.06.21 13:01:33 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014.06.21 13:01:33 | 000,675,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2014.06.21 13:01:33 | 000,546,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppxPackaging.dll
[2014.06.21 13:01:33 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Dism.exe
[2014.06.21 13:01:33 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.Vpn.dll
[2014.06.21 13:01:32 | 000,609,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pnidui.dll
[2014.06.21 13:01:32 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll
[2014.06.21 13:01:31 | 001,757,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPDMC.exe
[2014.06.21 13:01:31 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmredir.dll
[2014.06.21 13:01:30 | 000,324,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFCaptureEngine.dll
[2014.06.21 13:01:30 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psmsrv.dll
[2014.06.21 13:01:29 | 001,008,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WlanMM.dll
[2014.06.21 13:01:29 | 000,834,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\osk.exe
[2014.06.21 13:01:28 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VAN.dll
[2014.06.21 13:01:28 | 000,388,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ninput.dll
[2014.06.21 13:01:28 | 000,372,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys
[2014.06.21 13:01:28 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InputSwitch.dll
[2014.06.21 13:01:27 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authz.dll
[2014.06.21 13:01:27 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\portcls.sys
[2014.06.21 13:01:26 | 002,288,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SyncCenter.dll
[2014.06.21 13:01:26 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2014.06.21 13:01:26 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rascustom.dll
[2014.06.21 13:01:25 | 002,862,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themeui.dll
[2014.06.21 13:01:25 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014.06.21 13:01:25 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014.06.21 13:01:25 | 000,469,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskeng.exe
[2014.06.21 13:01:24 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdbui.dll
[2014.06.21 13:01:24 | 000,289,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqmapi.dll
[2014.06.21 13:01:24 | 000,286,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidcredprov.dll
[2014.06.21 13:01:24 | 000,258,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettingsAdminFlows.exe
[2014.06.21 13:01:24 | 000,123,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmapi.dll
[2014.06.21 13:01:23 | 003,596,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2014.06.21 13:01:23 | 000,459,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DismApi.dll
[2014.06.21 13:01:23 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mdmregistration.dll
[2014.06.21 13:01:22 | 000,285,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFCaptureEngine.dll
[2014.06.21 13:01:22 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSClient.dll
[2014.06.21 13:01:22 | 000,105,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncryptsslp.dll
[2014.06.21 13:01:21 | 002,811,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themeui.dll
[2014.06.21 13:01:21 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MrmIndexer.dll
[2014.06.21 13:01:21 | 000,210,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVol.exe
[2014.06.21 13:01:21 | 000,089,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncryptsslp.dll
[2014.06.21 13:01:20 | 000,745,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2014.06.21 13:01:20 | 000,559,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.Connectivity.dll
[2014.06.21 13:01:20 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014.06.21 13:01:20 | 000,211,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Dism.exe
[2014.06.21 13:01:19 | 000,473,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppxPackaging.dll
[2014.06.21 13:01:19 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InputSwitch.dll
[2014.06.21 13:01:19 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SkyDriveShell.dll
[2014.06.21 13:01:19 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll
[2014.06.21 13:01:18 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcrypt.dll
[2014.06.21 13:01:16 | 000,591,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014.06.21 13:01:15 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.HumanInterfaceDevice.dll
[2014.06.21 13:01:15 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\clrhost.dll
[2014.06.21 13:01:14 | 001,144,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanmm.dll |