FRST - Teil2: Code:
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 22:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 21:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-07-19 22:37 - 2013-08-01 20:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 20:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 20:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-07-19 22:37 - 2013-08-01 20:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-07-19 22:37 - 2013-07-04 08:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-07-19 22:37 - 2013-07-04 08:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-07-19 22:37 - 2013-07-04 07:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-07-19 22:37 - 2013-07-04 07:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-07-19 22:37 - 2013-07-04 06:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-07-19 22:36 - 2014-06-05 10:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-19 22:36 - 2014-05-30 02:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-19 22:36 - 2014-04-24 22:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-07-19 22:36 - 2014-04-24 22:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-07-19 22:36 - 2014-04-11 22:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-07-19 22:36 - 2013-10-29 22:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-07-19 22:36 - 2013-10-29 22:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-07-19 22:36 - 2013-08-01 08:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-07-19 22:36 - 2013-07-04 08:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-07-19 22:36 - 2013-04-10 02:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-07-19 22:36 - 2011-10-15 02:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-07-19 22:36 - 2011-10-15 01:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-07-19 22:36 - 2011-02-03 07:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-07-19 22:35 - 2014-06-05 10:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-19 22:35 - 2014-06-05 10:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-19 22:35 - 2014-05-30 04:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-19 22:35 - 2014-05-30 03:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-19 22:35 - 2014-04-11 22:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-07-19 22:35 - 2014-04-11 22:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-07-19 22:35 - 2014-04-11 22:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-07-19 22:35 - 2014-04-11 22:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-07-19 22:35 - 2014-04-11 22:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-07-19 22:35 - 2013-02-27 02:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-07-19 22:35 - 2013-02-27 01:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-07-19 22:35 - 2012-05-05 04:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-07-19 22:35 - 2012-05-05 03:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-07-19 22:34 - 2013-04-26 01:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-07-19 22:34 - 2013-04-26 00:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-07-19 22:34 - 2012-12-07 09:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-07-19 22:34 - 2012-12-07 09:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-07-19 22:34 - 2012-12-07 08:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-07-19 22:34 - 2012-12-07 08:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-07-19 22:34 - 2012-12-07 07:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-07-19 22:34 - 2012-12-07 07:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-07-19 22:34 - 2012-12-07 07:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-07-19 22:34 - 2012-12-07 07:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-07-19 22:34 - 2012-12-07 07:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-07-19 22:34 - 2012-12-07 07:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-07-19 22:34 - 2012-12-07 07:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-07-19 22:34 - 2012-12-07 07:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-07-19 22:34 - 2012-12-07 06:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-07-19 22:33 - 2014-02-03 22:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-07-19 22:33 - 2014-02-03 22:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-07-19 22:33 - 2014-02-03 22:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-07-19 22:33 - 2014-02-03 22:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-07-19 22:33 - 2014-02-03 22:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-07-19 22:33 - 2014-01-23 22:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-07-19 22:33 - 2013-11-11 22:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-07-19 22:33 - 2013-11-11 22:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-07-19 22:33 - 2013-06-06 01:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-07-19 22:33 - 2013-06-06 01:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-07-19 22:33 - 2013-06-06 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-07-19 22:33 - 2013-06-06 01:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-07-19 22:33 - 2013-06-06 00:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-07-19 22:33 - 2013-06-06 00:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-07-19 22:33 - 2013-06-06 00:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-07-19 22:33 - 2013-06-05 23:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-07-19 22:33 - 2013-06-05 23:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-07-19 22:33 - 2013-06-05 23:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-07-19 22:33 - 2013-05-13 01:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-07-19 22:33 - 2013-05-12 23:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-07-19 22:33 - 2013-05-12 23:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-07-19 22:33 - 2013-05-12 23:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-07-19 22:33 - 2012-11-02 01:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-07-19 22:33 - 2012-11-02 01:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-07-19 22:33 - 2012-08-21 17:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-07-19 22:33 - 2011-10-26 01:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-07-19 22:33 - 2011-10-26 00:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-07-19 22:32 - 2014-06-17 22:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-19 22:32 - 2014-06-17 21:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-19 22:32 - 2014-06-17 21:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-19 22:32 - 2014-01-28 22:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-07-19 22:32 - 2014-01-28 22:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-07-19 22:32 - 2013-08-04 22:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-07-19 22:32 - 2013-07-25 22:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-07-19 22:32 - 2013-07-25 21:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-07-19 22:32 - 2013-07-20 06:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-07-19 22:32 - 2013-07-20 06:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-07-19 22:32 - 2013-05-10 01:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-07-19 22:32 - 2013-05-09 23:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-07-19 22:32 - 2013-02-12 00:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-07-19 22:32 - 2012-10-03 13:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-07-19 22:32 - 2012-10-03 13:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-07-19 22:32 - 2012-10-03 13:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-07-19 22:32 - 2012-10-03 13:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-07-19 22:32 - 2012-10-03 13:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-07-19 22:32 - 2012-10-03 13:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-07-19 22:32 - 2012-10-03 12:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-07-19 22:32 - 2012-10-03 12:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-07-19 22:32 - 2012-10-03 12:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-07-19 22:32 - 2012-10-03 12:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-07-19 22:32 - 2012-05-14 01:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-07-19 22:32 - 2012-04-07 08:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-07-19 22:32 - 2012-04-07 07:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-07-19 22:32 - 2012-03-17 03:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-07-19 22:32 - 2012-01-13 03:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-07-19 22:32 - 2011-12-16 04:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-07-19 22:32 - 2011-12-16 03:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-07-19 22:32 - 2011-11-17 02:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-07-19 22:32 - 2011-11-17 01:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-07-19 22:31 - 2013-10-02 22:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-07-19 22:31 - 2013-10-02 22:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-07-19 22:31 - 2013-07-25 05:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-07-19 22:31 - 2013-07-25 04:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-07-19 22:31 - 2012-11-22 23:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-07-19 22:31 - 2012-08-22 14:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-07-19 22:31 - 2012-07-04 16:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-07-19 22:31 - 2012-04-27 23:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-07-19 22:31 - 2012-02-17 02:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-07-19 22:31 - 2012-02-17 01:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-07-19 22:31 - 2012-02-17 00:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-07-19 22:31 - 2011-12-30 02:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-07-19 22:31 - 2011-12-30 01:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-07-19 22:25 - 2013-12-03 22:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-07-19 22:25 - 2013-12-03 22:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-07-19 22:25 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-07-19 22:25 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-07-19 22:25 - 2013-12-03 22:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-07-19 22:25 - 2013-12-03 22:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-07-19 22:25 - 2013-12-03 22:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-07-19 22:25 - 2013-12-03 22:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-07-19 22:25 - 2013-12-03 22:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-07-19 22:25 - 2013-12-03 22:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-07-19 22:25 - 2013-12-03 22:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-07-19 22:25 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-07-19 22:25 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-07-19 22:25 - 2013-12-03 22:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-07-19 22:25 - 2013-12-03 21:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-07-19 22:25 - 2013-12-03 21:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-07-19 22:25 - 2013-12-03 21:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-07-19 22:25 - 2013-12-03 21:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-07-19 22:25 - 2013-09-07 22:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-07-19 22:25 - 2013-09-07 22:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-07-19 22:24 - 2014-06-06 06:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-19 22:24 - 2014-06-06 05:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-19 22:24 - 2014-04-04 22:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-07-19 22:24 - 2014-04-04 22:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-07-19 22:24 - 2013-11-26 07:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-07-19 22:24 - 2012-05-01 01:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-07-19 22:24 - 2012-01-04 06:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-07-19 22:24 - 2012-01-04 04:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-07-19 22:23 - 2013-12-31 19:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-07-19 22:23 - 2013-12-31 19:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-07-19 22:23 - 2013-10-18 22:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-07-19 22:23 - 2013-10-18 21:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-07-19 22:23 - 2013-10-11 22:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-07-19 22:23 - 2013-10-11 22:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-07-19 22:23 - 2013-10-11 22:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-07-19 22:23 - 2013-10-11 22:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-07-19 22:23 - 2013-10-11 21:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-07-19 22:23 - 2013-10-11 21:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-07-19 22:23 - 2013-10-11 21:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-07-19 22:23 - 2013-10-11 21:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-07-19 22:23 - 2013-10-03 22:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-07-19 22:23 - 2013-10-03 22:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-07-19 22:23 - 2013-10-03 22:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-07-19 22:23 - 2013-10-03 21:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-07-19 22:23 - 2013-10-03 21:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-07-19 22:23 - 2013-10-03 21:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-07-19 22:23 - 2013-07-04 08:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-07-19 22:23 - 2013-07-04 07:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-07-19 22:23 - 2012-07-04 18:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-07-19 22:23 - 2012-07-04 18:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-07-19 22:23 - 2012-07-04 18:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-07-19 22:23 - 2012-07-04 17:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-07-19 22:23 - 2012-07-04 17:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-07-19 22:23 - 2012-06-06 02:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-07-19 22:23 - 2012-06-06 01:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-07-19 22:18 - 2013-04-25 19:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-07-19 22:18 - 2013-03-31 18:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-07-19 22:16 - 2013-07-09 01:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-07-19 22:16 - 2013-07-09 00:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-07-19 22:14 - 2013-10-11 22:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-07-19 22:14 - 2013-10-11 22:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-07-19 22:14 - 2013-10-11 22:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-07-19 22:14 - 2013-10-11 22:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-07-19 22:14 - 2013-10-11 22:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-07-19 22:14 - 2013-08-27 21:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-07-19 22:14 - 2012-10-09 14:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-07-19 22:14 - 2012-10-09 14:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-07-19 22:14 - 2012-10-09 13:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-07-19 22:14 - 2012-10-09 13:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-07-19 22:10 - 2013-01-24 02:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-07-19 22:08 - 2014-03-04 05:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-07-19 22:08 - 2014-03-04 05:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-07-19 22:08 - 2014-03-04 05:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-07-19 22:08 - 2014-03-04 05:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-07-19 22:08 - 2014-03-04 05:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-07-19 22:08 - 2014-03-04 05:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-07-19 22:08 - 2014-03-04 05:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-07-19 22:08 - 2014-03-04 05:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-07-19 22:08 - 2014-03-04 05:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-07-19 22:08 - 2014-03-04 05:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-07-19 22:08 - 2014-03-04 05:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-07-19 22:08 - 2014-03-04 05:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-07-19 22:08 - 2014-03-04 05:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-07-19 22:08 - 2014-03-04 05:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-07-19 22:08 - 2014-03-04 05:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-07-19 22:08 - 2014-03-04 05:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-07-19 22:08 - 2014-03-04 05:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-07-19 22:08 - 2014-03-04 05:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-07-19 22:08 - 2014-03-04 05:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-07-19 22:08 - 2014-03-04 05:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-07-19 22:08 - 2013-08-01 22:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-07-19 22:08 - 2013-08-01 22:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-07-19 22:08 - 2013-08-01 21:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-07-19 22:08 - 2013-08-01 20:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-07-19 22:08 - 2012-09-25 18:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-07-19 22:08 - 2012-09-25 18:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-07-19 22:08 - 2011-11-19 10:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-07-19 22:08 - 2011-11-19 10:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-07-19 22:04 - 2012-04-26 01:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-07-19 22:04 - 2012-04-26 01:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-07-19 22:04 - 2012-04-26 01:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-07-19 22:00 - 2014-01-27 22:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-07-19 22:00 - 2013-03-19 01:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-07-19 21:12 - 2014-07-19 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt
2014-07-19 21:12 - 2014-07-19 21:12 - 00000000 ____D () C:\Program Files\Axantum
2014-07-19 21:03 - 2014-07-23 11:30 - 00000000 ____D () C:\Users\Eili\AppData\Local\Deployment
2014-07-19 21:03 - 2014-07-23 11:30 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-19 21:03 - 2014-07-23 11:07 - 00000000 ____D () C:\Users\MoD\AppData\Local\Google
2014-07-19 21:03 - 2014-07-20 16:07 - 00000000 ____D () C:\Users\Eili\AppData\Local\Google
2014-07-19 21:03 - 2014-07-19 21:03 - 00000000 ____D () C:\Users\Eili\AppData\Local\Apps\2.0
2014-07-19 11:39 - 2012-06-02 18:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-19 11:39 - 2012-06-02 18:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-19 11:39 - 2012-06-02 18:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-07-19 11:39 - 2012-06-02 18:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-19 11:32 - 2012-06-02 18:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-07-19 11:32 - 2012-06-02 18:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-07-19 11:32 - 2012-06-02 18:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-07-19 11:31 - 2012-06-02 09:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-07-19 11:31 - 2012-06-02 09:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-07-19 11:26 - 2014-07-19 11:26 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\Acronis
2014-07-19 11:20 - 2014-07-19 11:20 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\G Data
2014-07-19 11:19 - 2014-07-19 11:19 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys
2014-07-19 11:19 - 2014-07-19 11:19 - 00000197 _____ () C:\Users\MoD\AppData\Roaming\gdscan.log
2014-07-19 11:19 - 2014-07-19 11:19 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf
2014-07-19 11:19 - 2014-07-19 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data AntiVirus
2014-07-19 11:18 - 2014-07-19 11:18 - 00000000 ____D () C:\Users\Eili\AppData\Local\Clover
2014-07-19 11:16 - 2014-07-19 11:16 - 00000000 ____D () C:\Users\MoD\AppData\Local\Clover
2014-07-19 11:16 - 2014-07-19 11:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover
2014-07-19 11:16 - 2014-07-19 11:16 - 00000000 ____D () C:\Program Files (x86)\Clover
2014-07-19 11:15 - 2014-07-20 15:51 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\MyPhoneExplorer
2014-07-19 11:15 - 2014-07-19 11:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2014-07-19 11:09 - 2014-07-19 11:09 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-19 11:00 - 2014-07-19 11:00 - 00000000 ____D () C:\Windows\SysWOW64\tmp0000694f
2014-07-11 12:16 - 2014-07-11 12:16 - 01085264 _____ (Gemalto) C:\Windows\system32\axaltocm.dll
2014-07-11 12:16 - 2014-07-11 12:16 - 00834384 _____ (Gemalto) C:\Windows\SysWOW64\axaltocm.dll
2014-06-27 18:12 - 2014-06-27 18:12 - 00495376 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1c62x64.sys
2014-06-27 18:12 - 2014-06-27 18:12 - 00089888 _____ (Intel Corporation) C:\Windows\system32\NicInstC.dll
2014-06-27 18:12 - 2014-06-27 18:12 - 00073480 _____ (Intel Corporation) C:\Windows\system32\e1cmsg.dll
2014-06-27 18:12 - 2014-06-27 18:12 - 00003114 _____ () C:\Windows\system32\e1c62x64.din
==================== One Month Modified Files and Folders =======
2014-07-23 11:49 - 2014-07-23 11:49 - 00000000 ____D () C:\FRST
2014-07-23 11:49 - 2014-07-23 11:44 - 00000000 ____D () C:\Users\Eili\Desktop\Trojaner
2014-07-23 11:47 - 2014-07-23 11:47 - 00000168 _____ () C:\Users\MoD\defogger_reenable
2014-07-23 11:47 - 2011-10-10 10:30 - 00000000 ____D () C:\Users\MoD
2014-07-23 11:38 - 2009-07-14 01:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-23 11:36 - 2014-07-23 11:36 - 00000140 _____ () C:\Users\Eili\Desktop\Virensoftwer meldet folgenden unbekannten Schädling- Fingerprint- [6ed71ff3] - Trojaner-Board.url
2014-07-23 11:35 - 2014-07-23 11:30 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-23 11:35 - 2014-07-23 11:30 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-23 11:31 - 2014-07-23 11:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-23 11:30 - 2014-07-23 11:30 - 00003888 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-07-23 11:30 - 2014-07-23 11:30 - 00003636 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-07-23 11:30 - 2014-07-19 21:03 - 00000000 ____D () C:\Users\Eili\AppData\Local\Deployment
2014-07-23 11:30 - 2014-07-19 21:03 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-23 11:27 - 2009-07-14 00:45 - 00013792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-23 11:27 - 2009-07-14 00:45 - 00013792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-23 11:23 - 2011-10-09 15:27 - 01796036 _____ () C:\Windows\WindowsUpdate.log
2014-07-23 11:19 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-23 11:19 - 2009-07-14 00:51 - 00046524 _____ () C:\Windows\setupact.log
2014-07-23 11:08 - 2011-10-10 15:48 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{BD555A64-BA96-423B-9A04-5A52A7FAC1FD}
2014-07-23 11:07 - 2014-07-23 11:07 - 00000000 __SHD () C:\Users\MoD\AppData\Local\EmieUserList
2014-07-23 11:07 - 2014-07-23 11:07 - 00000000 __SHD () C:\Users\MoD\AppData\Local\EmieSiteList
2014-07-23 11:07 - 2014-07-19 21:03 - 00000000 ____D () C:\Users\MoD\AppData\Local\Google
2014-07-23 05:38 - 2014-07-20 17:53 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\MediaMonkey
2014-07-21 20:39 - 2014-07-20 14:59 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-21 20:38 - 2014-07-21 20:39 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-21 20:38 - 2014-07-21 20:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-21 20:38 - 2014-07-21 20:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-21 20:38 - 2014-07-21 20:38 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-21 20:38 - 2014-07-21 20:38 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-21 20:04 - 2014-07-21 19:28 - 00003810 _____ () C:\QcOSD.txt
2014-07-20 23:23 - 2011-10-12 16:41 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\Adobe
2014-07-20 23:15 - 2014-07-20 22:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpunkt-Sicherheit
2014-07-20 23:08 - 2014-07-20 20:20 - 00000000 ____D () C:\Users\Eili\AppData\Local\Citrix
2014-07-20 23:04 - 2014-07-20 20:25 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\ICAClient
2014-07-20 23:01 - 2011-10-12 12:21 - 00000000 ____D () C:\Users\Eili
2014-07-20 22:49 - 2014-07-20 20:27 - 00000000 ____D () C:\ProgramData\Citrix
2014-07-20 22:48 - 2014-07-20 22:48 - 00001615 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix Receiver.lnk
2014-07-20 22:48 - 2014-07-20 22:22 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\ICAClient
2014-07-20 22:48 - 2014-07-20 20:24 - 00000000 ____D () C:\Users\MoD\AppData\Local\Citrix
2014-07-20 22:48 - 2014-07-20 20:24 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-07-20 22:44 - 2009-07-14 00:45 - 00417024 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-20 22:42 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\registration
2014-07-20 22:27 - 2014-07-20 22:27 - 00000093 _____ () C:\Users\MoD\AppData\Roaming\ARCompanion.log
2014-07-20 22:22 - 2014-07-20 18:59 - 00000000 ____D () C:\Users\MoD\AppData\Local\Adobe
2014-07-20 22:22 - 2011-10-10 11:41 - 00109688 _____ () C:\Users\MoD\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-20 22:21 - 2014-07-20 22:21 - 00000000 ____D () C:\Users\Default\AppData\Local\Trusteer
2014-07-20 22:21 - 2014-07-20 22:21 - 00000000 ____D () C:\Users\Default User\AppData\Local\Trusteer
2014-07-20 22:16 - 2014-07-20 19:55 - 00000000 ____D () C:\Users\Eili\AppData\Local\Adobe
2014-07-20 20:07 - 2014-07-20 20:07 - 00000000 __SHD () C:\Users\Eili\AppData\Local\EmieUserList
2014-07-20 20:07 - 2014-07-20 20:07 - 00000000 __SHD () C:\Users\Eili\AppData\Local\EmieSiteList
2014-07-20 20:07 - 2011-10-12 12:23 - 00109688 _____ () C:\Users\Eili\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-20 20:03 - 2014-07-20 20:03 - 00000000 ____D () C:\Users\MoD\AppData\Local\Trusteer
2014-07-20 20:03 - 2014-07-20 20:03 - 00000000 ____D () C:\Program Files (x86)\Trusteer
2014-07-20 20:02 - 2014-07-20 20:02 - 00000000 ____D () C:\Users\Eili\AppData\Local\Trusteer
2014-07-20 20:02 - 2014-07-20 20:02 - 00000000 ____D () C:\ProgramData\Trusteer
2014-07-20 19:56 - 2014-07-20 19:46 - 00000000 ____D () C:\ProgramData\Adobe
2014-07-20 19:53 - 2014-07-20 19:49 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-07-20 19:53 - 2014-07-20 19:49 - 00002219 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-07-20 19:53 - 2014-07-20 19:49 - 00002058 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-07-20 18:59 - 2014-07-20 18:59 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-07-20 18:59 - 2011-10-10 11:23 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\Adobe
2014-07-20 18:54 - 2014-07-20 16:28 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-07-20 18:49 - 2014-07-20 18:49 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-07-20 18:23 - 2014-07-20 18:22 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\Notepad++
2014-07-20 18:16 - 2014-07-20 18:08 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\TeraCopy
2014-07-20 18:02 - 2014-07-20 18:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
2014-07-20 18:02 - 2014-07-20 18:01 - 00000000 ____D () C:\Program Files\TeraCopy
2014-07-20 17:56 - 2014-07-20 17:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf
2014-07-20 16:26 - 2014-07-20 16:26 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\Logishrd
2014-07-20 16:26 - 2014-07-20 16:26 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\Logitech
2014-07-20 16:26 - 2014-07-20 16:26 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\Logishrd
2014-07-20 16:26 - 2014-07-20 16:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-07-20 16:26 - 2014-07-20 16:26 - 00000000 ____D () C:\Program Files\Logitech
2014-07-20 16:26 - 2014-07-20 16:26 - 00000000 ____D () C:\Program Files\Common Files\Logishrd
2014-07-20 16:07 - 2014-07-20 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
2014-07-20 16:07 - 2014-07-19 21:03 - 00000000 ____D () C:\Users\Eili\AppData\Local\Google
2014-07-20 16:04 - 2014-07-20 16:03 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\Notepad++
2014-07-20 16:03 - 2014-07-20 16:03 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-07-20 16:03 - 2014-07-20 16:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-07-20 16:03 - 2014-07-20 16:03 - 00000000 ____D () C:\Program Files (x86)\Notepad++
2014-07-20 15:51 - 2014-07-19 11:15 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\MyPhoneExplorer
2014-07-20 15:27 - 2014-07-20 15:27 - 00000000 ____D () C:\Users\Eili\.android
2014-07-20 15:24 - 2011-10-15 02:54 - 00000000 ____D () C:\Users\MoD\Documents\FinePrint files
2014-07-20 15:20 - 2014-07-20 15:20 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-07-20 15:05 - 2014-07-20 13:14 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\Epson
2014-07-20 13:50 - 2014-07-20 13:51 - 00321448 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-20 13:50 - 2014-07-20 13:50 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-20 13:50 - 2014-07-20 13:50 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-20 13:50 - 2014-07-20 13:50 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-20 13:50 - 2014-07-20 13:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-20 13:50 - 2014-07-20 13:47 - 00000000 ____D () C:\Program Files\Java
2014-07-20 13:48 - 2014-07-20 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2014-07-20 13:28 - 2014-07-20 13:20 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\EPSON
2014-07-20 13:20 - 2014-07-20 13:05 - 00000000 ____D () C:\ProgramData\EPSON
2014-07-20 13:19 - 2009-07-14 01:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-07-20 13:18 - 2014-07-20 13:18 - 00000045 _____ () C:\Windows\WF-3540.ini
2014-07-20 13:18 - 2014-07-20 13:18 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\Leadertech
2014-07-20 13:17 - 2014-07-20 13:17 - 00000000 ____D () C:\Program Files\Common Files\EPSON
2014-07-20 13:17 - 2014-07-20 13:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-07-20 13:13 - 2014-07-20 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
2014-07-20 13:13 - 2014-07-20 13:09 - 00000000 ____D () C:\Program Files (x86)\EPSON Software
2014-07-20 13:13 - 2011-10-11 16:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-20 13:12 - 2014-07-20 13:12 - 00000000 ____D () C:\Program Files (x86)\epson
2014-07-20 13:10 - 2014-07-20 13:10 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\InstallShield
2014-07-20 13:10 - 2014-07-20 13:10 - 00000000 ____D () C:\Program Files\EpsonNet
2014-07-20 13:09 - 2014-07-20 13:09 - 00000000 ____D () C:\Program Files\EPSON
2014-07-20 13:06 - 2014-07-20 12:21 - 00000000 ____D () C:\Users\MoD\AppData\Roaming\MediaMonkey
2014-07-20 12:21 - 2014-07-20 12:21 - 00000000 ____D () C:\ProgramData\MediaMonkey
2014-07-20 12:21 - 2011-10-11 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaMonkey
2014-07-20 12:21 - 2011-10-11 15:51 - 00000000 ____D () C:\Program Files (x86)\MediaMonkey
2014-07-20 11:25 - 2014-07-20 11:25 - 00000065 _____ () C:\Users\Eili\Desktop\Drivers – Synaptics.url
2014-07-20 11:08 - 2011-10-11 18:42 - 00015836 _____ () C:\Windows\system32\results.xml
2014-07-20 11:01 - 2014-07-20 11:01 - 00000000 ____D () C:\Users\Eili\AppData\Local\Lenovo
2014-07-20 09:57 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-07-20 09:19 - 2011-10-10 10:54 - 00316614 _____ () C:\Windows\PFRO.log
2014-07-20 09:18 - 2011-10-11 17:26 - 00000000 ____D () C:\ProgramData\Intel
2014-07-20 09:18 - 2011-10-11 16:53 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\2C0A
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0C0A
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0C04
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0816
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0804
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0424
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\041F
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\041E
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\041D
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\041B
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0419
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0416
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0415
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0414
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0413
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0412
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0411
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0410
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\040E
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\040D
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\040C
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\040B
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\040A
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0408
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0407
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0406
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0405
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0404
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Windows\system32\0401
2014-07-20 09:15 - 2014-07-20 09:15 - 00000000 ____D () C:\Program Files\Common Files\Lenovo
2014-07-20 09:15 - 2009-07-14 01:37 - 00000000 ____D () C:\Windows\system32\0409
2014-07-20 09:14 - 2014-07-20 09:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
2014-07-20 09:14 - 2014-07-20 09:14 - 00000000 ____D () C:\Program Files (x86)\Renesas Electronics
2014-07-20 09:13 - 2014-07-20 09:13 - 00000000 ____D () C:\Windows\System32\Tasks\Lenovo
2014-07-20 09:13 - 2011-10-10 10:59 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2014-07-20 09:12 - 2014-07-20 09:12 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01009.Wdf
2014-07-20 09:12 - 2014-07-20 09:12 - 00000000 ____D () C:\Users\MoD\AppData\Local\Lenovo
2014-07-20 09:12 - 2014-07-20 07:51 - 00002982 _____ () C:\Windows\System32\Tasks\Synaptics TouchPad Enhancements
2014-07-20 09:12 - 2011-10-11 17:08 - 00020980 _____ () C:\Windows\DPINST.LOG
2014-07-20 09:12 - 2011-10-11 17:08 - 00001432 _____ () C:\Windows\Synaptics.log
2014-07-20 09:11 - 2014-07-20 09:11 - 00000000 ____D () C:\Program Files (x86)\Cisco
2014-07-20 09:11 - 2011-10-11 18:33 - 00000000 ____D () C:\Program Files (x86)\ThinkPad Wireless LAN Adapter Software
2014-07-20 09:10 - 2014-07-20 09:10 - 00000000 ____D () C:\ProgramData\Lenovo
2014-07-20 09:09 - 2011-10-11 17:13 - 00003020 _____ () C:\Windows\System32\Tasks\PMTask
2014-07-20 09:08 - 2009-07-13 23:20 - 00000000 __RSD () C:\Windows\Media
2014-07-20 09:06 - 2011-10-11 16:53 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-07-20 08:59 - 2011-10-11 16:55 - 00000000 ____D () C:\Program Files\ThinkVantage Fingerprint Software
2014-07-20 08:56 - 2014-07-20 08:56 - 00002768 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-20 08:56 - 2014-07-20 08:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-07-20 08:56 - 2014-07-20 08:56 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-20 08:56 - 2011-10-11 16:56 - 00000000 ____D () C:\Windows\Downloaded Installations
2014-07-20 08:55 - 2014-07-20 08:55 - 00000000 ____D () C:\Program Files\Common Files\SPBA
2014-07-20 08:55 - 2011-10-11 16:27 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2014-07-20 08:13 - 2011-10-10 10:31 - 00001422 _____ () C:\Users\MoD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-20 07:54 - 2009-07-13 23:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-20 07:51 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-20 07:45 - 2014-07-20 07:45 - 00000000 ____D () C:\Program Files\AuthenTec
2014-07-20 07:45 - 2009-07-14 01:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2014-07-20 07:41 - 2014-07-20 07:41 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-07-20 07:41 - 2011-10-14 11:49 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-07-20 07:12 - 2011-10-11 17:20 - 00766780 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-07-20 06:53 - 2011-10-12 12:22 - 00001422 _____ () C:\Users\Eili\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-20 06:31 - 2009-07-13 23:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-07-20 06:30 - 2009-07-14 03:47 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-20 06:30 - 2009-07-14 01:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-07-20 06:30 - 2009-07-14 01:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-07-20 06:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-07-20 06:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-07-20 06:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-20 06:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-07-20 06:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-07-20 06:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-20 01:26 - 2011-10-10 17:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-20 00:53 - 2014-07-20 00:39 - 00012163 _____ () C:\Windows\IE11_main.log
2014-07-20 00:48 - 2014-07-20 00:48 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-20 00:48 - 2014-07-20 00:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-20 00:48 - 2014-07-20 00:48 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-20 00:48 - 2014-07-20 00:48 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-20 00:48 - 2014-07-20 00:48 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-07-20 00:48 - 2014-07-20 00:48 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-07-20 00:48 - 2014-07-20 00:48 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-07-20 00:48 - 2014-07-20 00:48 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-07-20 00:48 - 2014-07-20 00:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-07-20 00:48 - 2014-07-20 00:48 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-07-20 00:48 - 2014-07-20 00:48 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-07-20 00:48 - 2014-07-20 00:48 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-20 00:48 - 2014-07-20 00:48 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-07-20 00:42 - 2014-07-20 00:42 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-07-20 00:24 - 2011-10-11 11:21 - 00000039 _____ () C:\Windows\vbaddin.ini
2014-07-20 00:09 - 2009-07-13 22:34 - 00000478 _____ () C:\Windows\win.ini
2014-07-19 23:55 - 2014-07-19 23:53 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-19 22:53 - 2014-07-19 22:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-19 22:52 - 2014-07-19 22:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-19 22:52 - 2014-07-19 22:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-19 21:56 - 2011-10-12 12:22 - 00000000 ____D () C:\Users\Eili\AppData\Local\VirtualStore
2014-07-19 21:12 - 2014-07-19 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt
2014-07-19 21:12 - 2014-07-19 21:12 - 00000000 ____D () C:\Program Files\Axantum
2014-07-19 21:03 - 2014-07-19 21:03 - 00000000 ____D () C:\Users\Eili\AppData\Local\Apps\2.0
2014-07-19 11:31 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-07-19 11:26 - 2014-07-19 11:26 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\Acronis
2014-07-19 11:23 - 2011-10-10 10:47 - 00000000 ____D () C:\ProgramData\G DATA
2014-07-19 11:20 - 2014-07-19 11:20 - 00000000 ____D () C:\Users\Eili\AppData\Roaming\G Data
2014-07-19 11:20 - 2011-10-12 17:55 - 00000000 ____D () C:\Users\Eili\Documents\Outlook Files
2014-07-19 11:19 - 2014-07-19 11:19 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys
2014-07-19 11:19 - 2014-07-19 11:19 - 00000197 _____ () C:\Users\MoD\AppData\Roaming\gdscan.log
2014-07-19 11:19 - 2014-07-19 11:19 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf
2014-07-19 11:19 - 2014-07-19 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data AntiVirus
2014-07-19 11:19 - 2011-10-10 10:48 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-07-19 11:19 - 2011-10-10 10:48 - 00068608 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-07-19 11:19 - 2011-10-10 10:48 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-07-19 11:19 - 2011-10-10 10:48 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-07-19 11:19 - 2011-10-10 10:48 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-07-19 11:19 - 2011-10-10 10:46 - 00000000 ____D () C:\Users\MoD\AppData\Local\Downloaded Installations
2014-07-19 11:18 - 2014-07-19 11:18 - 00000000 ____D () C:\Users\Eili\AppData\Local\Clover
2014-07-19 11:16 - 2014-07-19 11:16 - 00000000 ____D () C:\Users\MoD\AppData\Local\Clover
2014-07-19 11:16 - 2014-07-19 11:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover
2014-07-19 11:16 - 2014-07-19 11:16 - 00000000 ____D () C:\Program Files (x86)\Clover
2014-07-19 11:15 - 2014-07-19 11:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2014-07-19 11:15 - 2011-10-11 15:31 - 00000000 ____D () C:\Program Files (x86)\MyPhoneExplorer
2014-07-19 11:10 - 2011-10-12 17:03 - 00000000 ____D () C:\ProgramData\X1 Updater
2014-07-19 11:09 - 2014-07-19 11:09 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-19 11:00 - 2014-07-19 11:00 - 00000000 ____D () C:\Windows\SysWOW64\tmp0000694f
2014-07-11 12:16 - 2014-07-11 12:16 - 01085264 _____ (Gemalto) C:\Windows\system32\axaltocm.dll
2014-07-11 12:16 - 2014-07-11 12:16 - 00834384 _____ (Gemalto) C:\Windows\SysWOW64\axaltocm.dll
2014-06-27 18:12 - 2014-06-27 18:12 - 00495376 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1c62x64.sys
2014-06-27 18:12 - 2014-06-27 18:12 - 00089888 _____ (Intel Corporation) C:\Windows\system32\NicInstC.dll
2014-06-27 18:12 - 2014-06-27 18:12 - 00073480 _____ (Intel Corporation) C:\Windows\system32\e1cmsg.dll
2014-06-27 18:12 - 2014-06-27 18:12 - 00003114 _____ () C:\Windows\system32\e1c62x64.din
2014-06-26 17:40 - 2011-10-10 11:41 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-24 06:05 - 2011-10-11 17:10 - 02853664 _____ (Lenovo Group Limited) C:\Windows\system32\PWMCP64V.cpl
2014-06-24 06:05 - 2011-10-11 17:10 - 02692896 ____N (Lenovo Group Limited) C:\Windows\PWMBTHLV.EXE
2014-06-24 06:05 - 2011-10-11 17:10 - 00029512 _____ (Lenovo.) C:\Windows\system32\Drivers\DZHDD64.SYS
2014-06-24 06:05 - 2011-10-11 17:10 - 00020736 _____ (Lenovo Group Limited) C:\Windows\system32\Drivers\TPPWR64V.SYS
2014-06-23 12:15 - 2014-07-20 22:58 - 00358616 _____ (Trusteer Ltd.) C:\Windows\system32\Drivers\RapportKE64.sys
Some content of TEMP:
====================
C:\Users\MoD\AppData\Local\Temp\AskSLib.dll
C:\Users\MoD\AppData\Local\Temp\bassmod.dll
C:\Users\MoD\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\MoD\AppData\Local\Temp\ose00000.exe
C:\Users\MoD\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-20 09:50
==================== End Of Log ============================ defogger_disable: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 11:47 on 23/07/2014 (MoD)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU:DAEMON Tools Lite -> Removed
Checking for services/drivers...
-=E.O.F=- GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-07-23 12:04:58
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HN-M101MBB rev.2AR10001 931.51GB
Running: GMER.exe; Driver: C:\Users\MoD\AppData\Local\Temp\kxryrpob.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002df8000 45 bytes [00, 00, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002df802f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\SysWOW64\ntdll.dll!KiUserApcDispatcher 0000000077b30028 5 bytes JMP 0000000100314100
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000077652c9e 4 bytes CALL 71ab0000
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076044296 5 bytes JMP 0000000171a50022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\WS2_32.dll!GetAddrInfoW 0000000076044889 5 bytes JMP 0000000171a10022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\WS2_32.dll!GetAddrInfoExW 000000007604d1ea 5 bytes JMP 00000001719d0022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076057673 5 bytes JMP 0000000171ae0022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe[1192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000077652c9e 4 bytes CALL 71ac0000
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075668a29 6 bytes JMP 7178000a
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075668a65 6 bytes [68, 22, 00, A6, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\USER32.dll!RegisterClassExW 000000007566b17d 6 bytes [68, 22, 00, AE, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\USER32.dll!CreateWindowExA 000000007566d22e 6 bytes JMP 7174000a
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000756705ba 6 bytes [68, 22, 00, 7D, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\WS2_32.dll!WSAIoctl 0000000076042fe7 6 bytes [68, 22, 00, 81, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\WS2_32.dll!connect 0000000076046bdd 6 bytes [68, 22, 00, A3, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\WS2_32.dll!WSAConnect 000000007604cc3f 6 bytes [68, 22, 00, 8D, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\WS2_32.dll!WSAConnectByList 000000007605bfdd 6 bytes [68, 22, 00, 89, 71, C3]
.text C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE[4008] C:\Windows\syswow64\WS2_32.dll!WSAConnectByNameW 000000007605c52f 6 bytes [68, 22, 00, 85, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000077652c9e 4 bytes CALL 71ac0000
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075668a29 6 bytes JMP 7188000a
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075668a65 6 bytes [68, 22, 00, A6, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\USER32.dll!RegisterClassExW 000000007566b17d 6 bytes [68, 22, 00, AE, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\USER32.dll!CreateWindowExA 000000007566d22e 6 bytes JMP 7184000a
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000756705ba 6 bytes [68, 22, 00, 8D, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\WS2_32.dll!WSAIoctl 0000000076042fe7 6 bytes [68, 22, 00, 91, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\WS2_32.dll!connect 0000000076046bdd 6 bytes [68, 22, 00, A3, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\WS2_32.dll!WSAConnect 000000007604cc3f 6 bytes [68, 22, 00, 9D, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\WS2_32.dll!WSAConnectByList 000000007605bfdd 6 bytes [68, 22, 00, 99, 71, C3]
.text C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE[4028] C:\Windows\syswow64\WS2_32.dll!WSAConnectByNameW 000000007605c52f 6 bytes [68, 22, 00, 95, 71, C3]
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\SysWOW64\ntdll.dll!KiUserApcDispatcher 0000000077b30028 5 bytes JMP 0000000100cac710
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000077652c9e 4 bytes CALL 71ac0000
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076044296 5 bytes JMP 0000000171a20022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\WS2_32.dll!GetAddrInfoW 0000000076044889 5 bytes JMP 00000001719e0022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\WS2_32.dll!GetAddrInfoExW 000000007604d1ea 5 bytes JMP 00000001719a0022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076057673 5 bytes JMP 0000000171a60022
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe[4936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe[4936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[5148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[5148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[5452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[5452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe[5472] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe[5472] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe[5500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe[5500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe[5804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe[5804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\ICA Client\concentr.exe[5916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Citrix\ICA Client\concentr.exe[5916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\ICA Client\redirector.exe[5940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Citrix\ICA Client\redirector.exe[5940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\Receiver\Receiver.exe[6084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Citrix\Receiver\Receiver.exe[6084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Windows\SysWOW64\RunDll32.exe[5556] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Windows\SysWOW64\RunDll32.exe[5556] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe[6500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe[6500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe[6508] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe[6508] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Windows\SysWOW64\DllHost.exe[7156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Windows\SysWOW64\DllHost.exe[7156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[6672] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[6672] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Windows\explorer.exe[8212] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe907490 5 bytes JMP 000007fffbc40060
.text C:\Windows\explorer.exe[8212] C:\Windows\system32\dwmapi.dll!DwmExtendFrameIntoClientArea 000007fefbc53580 5 bytes JMP 000007fffbc40010
.text C:\Program Files (x86)\Clover\clover.exe[9208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Program Files (x86)\Clover\clover.exe[9208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
? C:\Windows\system32\mssprxy.dll [9208] entry point in ".rdata" section 00000000747a71e6
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000077652c9e 4 bytes CALL 71ac0000
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075668a29 6 bytes JMP 7188000a
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075668a65 6 bytes [68, 22, 00, A6, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\USER32.dll!RegisterClassExW 000000007566b17d 6 bytes [68, 22, 00, AE, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\USER32.dll!CreateWindowExA 000000007566d22e 6 bytes JMP 7184000a
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000756705ba 6 bytes [68, 22, 00, 8D, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077041465 2 bytes [04, 77]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770414bb 2 bytes [04, 77]
.text ... * 2
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\WS2_32.dll!WSAIoctl 0000000076042fe7 6 bytes [68, 22, 00, 91, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\WS2_32.dll!connect 0000000076046bdd 6 bytes [68, 22, 00, A3, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\WS2_32.dll!WSAConnect 000000007604cc3f 6 bytes [68, 22, 00, 9D, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\WS2_32.dll!WSAConnectByList 000000007605bfdd 6 bytes [68, 22, 00, 99, 71, C3]
.text C:\Users\Eili\Desktop\Trojaner\GMER.exe[9076] C:\Windows\syswow64\WS2_32.dll!WSAConnectByNameW 000000007605c52f 6 bytes [68, 22, 00, 95, 71, C3]
---- Processes - GMER 2.1 ----
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCP80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1192] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072d30000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCR80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1192] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072c90000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\baseline\MSVCP80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1192] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:38) 00000000729a0000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\baseline\MSVCR80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1192] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:38) 0000000072900000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCP80.dll (*** suspicious ***) @ C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE [4008] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072d30000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCR80.dll (*** suspicious ***) @ C:\PROGRA~1\Lenovo\Zoom\TPSCREX.EXE [4008] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072c90000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCP80.dll (*** suspicious ***) @ C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE [4028] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072d30000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCR80.dll (*** suspicious ***) @ C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE [4028] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072c90000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCP80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe [3664] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072d30000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCR80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe [3664] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072c90000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\baseline\MSVCP80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe [3664] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:38) 00000000729a0000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\baseline\MSVCR80.dll (*** suspicious ***) @ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe [3664] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:38) 0000000072900000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCP80.dll (*** suspicious ***) @ C:\Users\Eili\Desktop\Trojaner\GMER.exe [9076] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072d30000
Library C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\MSVCR80.dll (*** suspicious ***) @ C:\Users\Eili\Desktop\Trojaner\GMER.exe [9076] (Microsoft® C Runtime Library/Microsoft Corporation)(2014-07-21 02:58:37) 0000000072c90000
---- EOF - GMER 2.1 ---- GDATA Log: Code:
In Ihrem Browser wurde ein unbekannter Schädling
(Fingerprint: [88157299])
entdeckt.
Die Schadfunktionen wurden deaktiviert.
Trotzdem empfehlen wir Ihnen dringend, bis zur dauerhaften Entfernung des Schädlings keine Passwörter mehr im Browser einzugeben und insbesondere auf empfindliche Vorgänge, wie z.B. Online-Banking, zu verzichten.
Zur vollständigen Behebung des Sicherheits-Problems empfehlen wir, den Schädling mit der "G Data BootCD" zu entfernen. Sollte der Schädling wider Erwarten mit der BootCD nicht entfernt werden können: G Data arbeitet ständig mit Hochdruck an der Erkennung und Entfernung neuester Computer-Schädlinge und wird voraussichtlich innerhalb kürzester Zeit ein entsprechendes Update bereitstellen können.
Für weitere Informationen steht Ihnen der G Data Support zur Verfügung. |