Plagegeister aller Art und deren Bekämpfung: Access Restricted u. Adobeplugin AbstürzeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
| ![]() Access Restricted u. Adobeplugin Abstürze Access Restricted u. Adobeplugin Abstürze Hallo Liebe Forumnutzer und Admins, ich habe folgende probleme mit meinem firefox ich bekomme auf fielen Seiten folgende fehlermeldung: Access Restricted. Im folgenden wird beschrieben dass ich oder ein andere pc in meinem netzwerk einen Virus hätten, der es erlaubt den infizierten PC als Spambot zu nutzen und andere Seiten zu beschädigen. des weiteren werde ich auf Seite weitergeleited damit mir bei der Reinigung meines pcs geholfen wird. Es wird dann eine Aktualisierung des Virenprogramms und ein anschließender Systhemcheck empfolen. Zum Schluss wird auf die Abfrage am oberen Teil der Seite hingewiesen mit der man beweist, dass man Mensch ist infolge dessen wird man temporär freigeschalted. Als ich mich auf der Suche nach einer Problemlösung wurde mir in 2 Foren empfolen mit Malewarebytes einen suchlauf zu starten das erste Forum verwies mich anschließend hirher womit beide Seiten genannt sind. dies ist die Logdatei des Suchlaufs: Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2013.01.16.05 Windows 7 x86 NTFS Internet Explorer 8.0.7600.16385 Patrick :: PATRICK-PC [Administrator] Schutz: Aktiviert 16.01.2013 16:27:02 MBAM-log-2013-01-16 (17-48-12).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|G:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 364166 Laufzeit: 49 Minute(n), 57 Sekunde(n) Infizierte Speicherprozesse: 1 D:\Windows\System32\dmwu.exe (PUP.InstallBrain) -> 1956 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 D:\Users\Patrick\Downloads\setup(1).exe (PUP.BundleInstaller.VG) -> Keine Aktion durchgeführt. D:\Users\Patrick\Downloads\setup.exe (PUP.BundleInstaller.VG) -> Keine Aktion durchgeführt. D:\Users\Patrick\Downloads\game booster.exe (PUP.BundleInstaller.SOL) -> Keine Aktion durchgeführt. D:\Windows\System32\dmwu.exe (PUP.InstallBrain) -> Keine Aktion durchgeführt. (Ende) |
![]() | #2 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Access Restricted u. Adobeplugin Abstürze hi
![]() | #3 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Access Restricted u. Adobeplugin Abstürze ok dann mal weiter:
__________________Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
![]() | #4 |
| ![]() Access Restricted u. Adobeplugin Abstürze OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 1/16/2013 6:27:19 PM - Run 1 OTL by OldTimer - Version Folder = D:\Users\Patrick\Downloads Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 1.98 Gb Available Physical Memory | 66.13% Memory free 6.00 Gb Paging File | 4.44 Gb Available in Paging File | 73.98% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files Drive C: | 19.53 Gb Total Space | 0.03 Gb Free Space | 0.13% Space Free | Partition Type: NTFS Drive D: | 446.22 Gb Total Space | 311.06 Gb Free Space | 69.71% Space Free | Partition Type: NTFS Drive F: | 2.78 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS Drive G: | 465.76 Gb Total Space | 184.79 Gb Free Space | 39.68% Space Free | Partition Type: NTFS Computer Name: PATRICK-PC | User Name: Patrick | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- D:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- D:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [runas] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3C9C22C9-FB7B-4B09-A32B-36F715C9E418}" = lport=56506 | protocol=6 | dir=in | name=pando media booster | "{4F3B0EEF-A78E-4355-89AE-7778C5335508}" = lport=56506 | protocol=17 | dir=in | name=pando media booster | "{51289927-90E1-4F5D-9F0D-A059D31E9505}" = lport=56506 | protocol=6 | dir=in | name=pando media booster | "{88193205-6858-401D-82E2-FF452F6A2A19}" = lport=56506 | protocol=17 | dir=in | name=pando media booster | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{020268DB-BB02-4E59-8567-077BEBA9DC66}" = protocol=6 | dir=in | app=d:\program files\icq7.6\icq.exe | "{21D68E29-F5F3-4A5B-B9BD-9504FA0C04D9}" = protocol=6 | dir=in | app=d:\windows\system32\pnkbstrb.exe | "{225833B8-FA25-480F-B0EF-6AA2395D7689}" = protocol=6 | dir=in | app=d:\program files\electronic arts\die schlacht um mittelerde ii\game.dat | "{27C80B3A-1358-4B49-B11B-BAC0964A38AC}" = protocol=6 | dir=in | app=d:\users\patrick\appdata\roaming\icqm\icq.exe | "{2BBF2C5B-4BB2-49DD-B20F-10CC7F0F0435}" = protocol=17 | dir=in | app=d:\program files\pando networks\media booster\pmb.exe | "{2D143008-741A-43F1-9F1F-17628E992C58}" = protocol=6 | dir=in | app=d:\windows\system32\msiexec.exe | "{3047D2E8-797A-4124-922E-4CF64948C7F1}" = protocol=6 | dir=in | app=d:\program files\icq7.6\icq.exe | "{46F58797-D5A9-4D56-B0F5-1F2B33D7F48C}" = protocol=17 | dir=in | app=d:\users\patrick\appdata\local\mediaget2\mediaget.exe | "{49B1DAC5-1EE9-4BAF-951C-87E1F6487776}" = protocol=17 | dir=in | app=d:\program files\electronic arts\aufstieg des hexenkönigs\game.dat | "{4BB8AB40-1742-4FB7-A783-58998A7234B2}" = dir=in | app=d:\program files\iminent\iminent.exe | "{4D99E4AD-28F2-45C8-901E-CFE52E70C0DD}" = protocol=17 | dir=in | app=d:\users\patrick\appdata\roaming\icqm\icq.exe | "{551459EB-BA09-4D5D-BAA5-3D9735445CC7}" = protocol=17 | dir=in | app=d:\program files\yourfiledownloader\yourfile.exe | "{5DEC9D0E-AFFF-4D7D-BD41-927BD530F746}" = protocol=17 | dir=in | app=d:\windows\system32\pnkbstra.exe | "{61E243D1-590D-4DD8-8C28-C2455E50AB8E}" = protocol=17 | dir=in | app=d:\windows\system32\arfc\wrtc.exe | "{6AF5AF15-8E35-4742-ABA4-C0F6A87D1C40}" = protocol=6 | dir=in | app=d:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{72805CA4-F653-4DB5-9673-0C083A642B21}" = protocol=17 | dir=in | app=d:\program files\electronic arts\die schlacht um mittelerde ii\game.dat | "{86072296-7B6C-4FA8-A689-2E59A88D1EB1}" = dir=in | app=d:\program files\pando networks\media booster\pmb.exe | "{8B266C4B-6334-4427-AF51-D23D52331438}" = protocol=6 | dir=in | app=d:\windows\system32\pnkbstra.exe | "{8D5ABF47-8A01-4864-8369-C543C4F00AD4}" = protocol=6 | dir=in | app=d:\program files\pando networks\media booster\pmb.exe | "{9074C957-7D38-4BFC-B285-71BC70C2237F}" = protocol=17 | dir=in | app=d:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{9BD693ED-9064-42B9-AB4C-FAC2C8E46619}" = protocol=6 | dir=in | app=d:\users\patrick\appdata\local\mediaget2\mediaget.exe | "{A0B586FB-6B66-44A4-B001-54AB8A2992A6}" = protocol=6 | dir=in | app=d:\program files\electronic arts\aufstieg des hexenkönigs\game.dat | "{A199FA4D-1694-44CC-B92A-CFF05580A982}" = dir=in | app=d:\program files\iminent\iminent.messengers.exe | "{A35AA089-A360-4329-8314-598ECB40BEB2}" = protocol=17 | dir=in | app=d:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{A69CB3C2-D212-4E2B-A342-445AB44105E6}" = protocol=17 | dir=in | app=d:\program files\icq7.6\icq.exe | "{A8B5017B-C8C0-4AF5-BB00-DEF30B64C966}" = protocol=17 | dir=in | app=d:\windows\system32\dmwu.exe | "{AB1A771B-76E5-4E58-933F-22C944A18188}" = protocol=17 | dir=in | app=d:\program files\yourfiledownloader\downloader.exe | "{B684B448-D3D1-4398-9A8F-CC4F4D3DEC04}" = protocol=6 | dir=in | app=d:\program files\icq7.6\icq.exe | "{B68AB7A1-A9F5-4AD1-9080-AB76F346B74C}" = protocol=6 | dir=in | app=d:\program files\pando networks\media booster\pmb.exe | "{B9351F14-F4F9-4F66-B82C-6F9B9F4E4E30}" = protocol=17 | dir=in | app=d:\windows\system32\msiexec.exe | "{BB1DE6BC-4B29-4B45-A4DC-1C1E2B600C36}" = protocol=6 | dir=in | app=d:\windows\system32\arfc\wrtc.exe | "{C5A5A238-4615-44F9-AC2C-D437558D486E}" = protocol=17 | dir=in | app=d:\program files\icq7.6\icq.exe | "{C5D60AF8-A22D-434B-96AA-47EBF0B1D475}" = protocol=6 | dir=in | app=d:\windows\system32\dmwu.exe | "{C897D83C-DEC5-4789-822E-D414B6FC89CD}" = protocol=6 | dir=in | app=d:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{CE5441EB-7A23-4777-8271-F5E44423ABFA}" = protocol=6 | dir=in | app=d:\program files\yourfiledownloader\yourfile.exe | "{D481EC4D-6627-4D65-8EF0-B62051D1FFD4}" = protocol=17 | dir=in | app=d:\windows\system32\pnkbstrb.exe | "{D636081F-1C35-4DC1-A57D-CB9BC2C719A0}" = protocol=6 | dir=in | app=d:\program files\origin games\battlefield 3\bf3.exe | "{E0C0CB75-05A3-4450-A13C-FEF7062B6D5D}" = protocol=6 | dir=in | app=d:\program files\yourfiledownloader\downloader.exe | "{E34FA44C-FEC9-4C82-9218-30677C5E7C0B}" = protocol=17 | dir=in | app=d:\program files\pando networks\media booster\pmb.exe | "{ECB49E7C-24C0-4E25-A5F0-863F6B1F8918}" = protocol=17 | dir=in | app=d:\program files\origin games\battlefield 3\bf3.exe | "{F08CAE64-30F6-4E09-90EE-0A57AF9AF997}" = protocol=17 | dir=in | app=d:\program files\icq7.6\icq.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD}" = ICQ Sparberater "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java(TM) 6 Update 27 "{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = Die Schlacht um Mittelerde™ II "{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = IB Updater "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3EB576DB-3B15-42DC-97B3-2CA67BDDD7F4}" = Linkury Smartbar "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10 "{60D32CDC-E3BE-4578-BA10-29322307CDDC}" = Logitech Gaming Software 5.10 "{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Security Suite CBE 11 "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™ "{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.03 "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" = Iminent Toolbar For Internet Explorer "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 310.70 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 310.70 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 310.70 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 310.70 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{BBC8F2F4-C823-4EE8-B176-74DCDEF8F68A}_is1" = F1 2012 Version V1.0 "{BC8BD878-91A4-4EDD-898F-68E0573468B4}" = Iminent "{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks "{DE042823-C359-4B87-B66B-308057E8B6AF}" = Camtasia Studio 7 "{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" = Update Manager for SweetPacks 1.1 "{EBC8C5A1-7745-419F-B6C6-B0DD87F24D52}" = LogMeIn Hamachi "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F72CC350-CDF1-47AF-A474-4E2404EBBEB9}_is1" = Bahrain International Circuit by CTDP V2.0 BETA "addlyrics@addlyrics.net" = AddLyrics "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Assassin's Creed III_is1" = Assassin's Creed III "AVMWLANCLI" = AVM FRITZ!WLAN "Battlelog Web Plugins" = Battlelog Web Plugins "ESN Sonar-0.70.4" = ESN Sonar "F1 2012_is1" = F1 2012 - Update 1 "F1RFT 2011 FINAL" = F1RFT 2011 FINAL "Formula One 1998 by GPTeam - Mod V 2.0" = Formula One 1998 by GPTeam - Mod V 2.0 "Formula One 1998 by GPTeam - Trackpack V 1.0" = Formula One 1998 by GPTeam - Trackpack V 1.0 "Formula One 1998 by GPTeam - Trackpack V 1.0 P2" = Formula One 1998 by GPTeam - Trackpack V 1.0 P2 "Fraps" = Fraps (remove only) "Game Booster_is1" = Game Booster 3 "ICQToolbar" = ICQ Toolbar "IMBoosterARP" = Iminent "incredibar" = Incredibar Toolbar on IE "InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Security Suite CBE 11 "KOREA CIRCUIT by macci dESIGN." = KOREA CIRCUIT by macci dESIGN. "Korea International Circuit1.0" = Korea International Circuit "LogMeIn Hamachi" = LogMeIn Hamachi "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "McAfee Security Scan" = McAfee Security Scan Plus "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Mozilla Firefox 18.0 (x86 en-US)" = Mozilla Firefox 18.0 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Origin" = Origin "PunkBusterSvc" = PunkBuster Services "rFactor" = rFactor (remove only) "Simraceway" = Simraceway 28.81 "TeamSpeak 3 Client" = TeamSpeak 3 Client "The Witcher 2 - Assassins of Kings Enhanced Edition_is1" = The Witcher 2 - Assassins of Kings Enhanced Edition "Uplay" = Uplay "WinRAR archiver" = WinRAR 4.20 (32-Bit) "WNLT" = IB Updater Service ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{4ce39058-355d-4dfe-b4d9-f6a2dac7a9da}" = Linkury Smartbar Engine "F1 1994 Season F1-S-R" = F1 1994 Season F1-S-R "F1 2000 RVR" = F1 2000 RVR "F1 2000 RVR v1.1 (Patch)" = F1 2000 RVR v1.1 (Patch) "F1RFT 2012 DRS TrackPack 1" = F1RFT 2012 DRS TrackPack 1 "F1RFT 2012 DRS TrackPack 2" = F1RFT 2012 DRS TrackPack 2 "F1RFT 2012 MP V1.0" = F1RFT 2012 MP V1.0 "F1-S-R - Track Pack 1994" = F1-S-R - Track Pack 1994 "MediaGet" = MediaGet ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 1/15/2013 1:10:24 PM | Computer Name = Patrick-PC | Source = | ID = 0 Description = Error - 1/15/2013 1:10:24 PM | Computer Name = Patrick-PC | Source = | ID = 0 Description = Error - 1/15/2013 1:10:24 PM | Computer Name = Patrick-PC | Source = | ID = 0 Description = Error - 1/16/2013 9:52:47 AM | Computer Name = Patrick-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht gelesen werden. Das erste DWORD im Datenbereich enthält den Win32-Fehlercode. Error - 1/16/2013 9:52:47 AM | Computer Name = Patrick-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht gelesen werden. Das erste DWORD im Datenbereich enthält den Win32-Fehlercode. Error - 1/16/2013 10:34:52 AM | Computer Name = Patrick-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version:, Zeitstempel: 0x50e79f4b Name des fehlerhaften Moduls: NPSWF32_11_5_502_146.dll, Version: 11.5.502.146, Zeitstempel: 0x50cfc317 Ausnahmecode: 0xc0000417 Fehleroffset: 0x006b3554 ID des fehlerhaften Prozesses: 0x102c Startzeit der fehlerhaften Anwendung: 0x01cdf3f6a49ab880 Pfad der fehlerhaften Anwendung: D:\Program Files\Mozilla Firefox\plugin-container.exe Pfad des fehlerhaften Moduls: D:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll Berichtskennung: e2b493c0-5fe9-11e2-ab83-bc054304de3a Error - 1/16/2013 10:35:23 AM | Computer Name = Patrick-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version:, Zeitstempel: 0x50e79f4b Name des fehlerhaften Moduls: NPSWF32_11_5_502_146.dll, Version: 11.5.502.146, Zeitstempel: 0x50cfc317 Ausnahmecode: 0xc0000417 Fehleroffset: 0x006b3554 ID des fehlerhaften Prozesses: 0x1078 Startzeit der fehlerhaften Anwendung: 0x01cdf3f6b77f73a0 Pfad der fehlerhaften Anwendung: D:\Program Files\Mozilla Firefox\plugin-container.exe Pfad des fehlerhaften Moduls: D:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll Berichtskennung: f59b98d0-5fe9-11e2-ab83-bc054304de3a Error - 1/16/2013 11:16:42 AM | Computer Name = Patrick-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_5_502_146.exe, Version: 11.5.502.146, Zeitstempel: 0x50cfc179 Name des fehlerhaften Moduls: FlashPlayerPlugin_11_5_502_146.exe, Version: 11.5.502.146, Zeitstempel: 0x50cfc179 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002a297 ID des fehlerhaften Prozesses: 0x15f4 Startzeit der fehlerhaften Anwendung: 0x01cdf3fc7d431970 Pfad der fehlerhaften Anwendung: D:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe Pfad des fehlerhaften Moduls: D:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe Berichtskennung: bb59c060-5fef-11e2-ab83-bc054304de3a Error - 1/16/2013 1:11:24 PM | Computer Name = Patrick-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht gelesen werden. Das erste DWORD im Datenbereich enthält den Win32-Fehlercode. Error - 1/16/2013 1:11:24 PM | Computer Name = Patrick-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht gelesen werden. Das erste DWORD im Datenbereich enthält den Win32-Fehlercode. [ System Events ] Error - 1/13/2013 11:22:37 AM | Computer Name = Patrick-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?13.?01.?2013 um 16:21:22 unerwartet heruntergefahren. Error - 1/13/2013 11:22:27 AM | Computer Name = Patrick-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten. Error - 1/14/2013 3:16:34 AM | Computer Name = Patrick-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?14.?01.?2013 um 07:50:01 unerwartet heruntergefahren. Error - 1/14/2013 3:16:21 AM | Computer Name = Patrick-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten. Error - 1/15/2013 3:32:22 AM | Computer Name = Patrick-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?15.?01.?2013 um 01:26:51 unerwartet heruntergefahren. Error - 1/15/2013 3:32:10 AM | Computer Name = Patrick-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten. Error - 1/16/2013 9:46:51 AM | Computer Name = Patrick-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?16.?01.?2013 um 02:39:10 unerwartet heruntergefahren. Error - 1/16/2013 9:46:40 AM | Computer Name = Patrick-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten. Error - 1/16/2013 1:05:24 PM | Computer Name = Patrick-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?16.?01.?2013 um 18:04:25 unerwartet heruntergefahren. Error - 1/16/2013 1:05:10 PM | Computer Name = Patrick-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten. < End of report > OTL Logfile: Code:
ATTFilter OTL logfile created on: 1/16/2013 6:14:49 PM - Run 1 OTL by OldTimer - Version Folder = D:\Users\Patrick\Downloads Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 3.00 Gb Total Physical Memory | 1.70 Gb Available Physical Memory | 56.59% Memory free 6.00 Gb Paging File | 4.09 Gb Available in Paging File | 68.19% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files Drive C: | 19.53 Gb Total Space | 0.03 Gb Free Space | 0.13% Space Free | Partition Type: NTFS Drive D: | 446.22 Gb Total Space | 311.06 Gb Free Space | 69.71% Space Free | Partition Type: NTFS Drive F: | 2.78 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS Drive G: | 465.76 Gb Total Space | 184.79 Gb Free Space | 39.68% Space Free | Partition Type: NTFS Computer Name: PATRICK-PC | User Name: Patrick | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013/01/16 18:14:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\Patrick\Downloads\OTL.exe PRC - [2013/01/16 18:11:34 | 000,050,477 | ---- | M] () -- D:\Users\Patrick\Downloads\Defogger.exe PRC - [2013/01/16 14:50:43 | 003,494,992 | ---- | M] (Electronic Arts) -- D:\Program Files\Origin\Origin.exe PRC - [2013/01/10 15:23:17 | 002,620,016 | ---- | M] (Iminent) -- D:\Program Files\Common Files\Umbrella\Umbrella.exe PRC - [2013/01/09 00:39:16 | 001,808,392 | ---- | M] (Adobe Systems, Inc.) -- D:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe PRC - [2013/01/08 17:36:36 | 000,013,824 | ---- | M] (Smartbar) -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Linkury.exe PRC - [2013/01/05 04:45:30 | 000,917,552 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012/12/18 17:49:20 | 001,046,016 | ---- | M] () -- D:\Program Files\SimracewayUpdater\SRWUpdate.exe PRC - [2012/12/15 20:45:29 | 010,183,400 | ---- | M] (MediaGet LLC) -- D:\Users\Patrick\AppData\Local\MediaGet2\mediaget.exe PRC - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012/12/14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2012/12/03 16:39:40 | 001,259,880 | ---- | M] (NVIDIA Corporation) -- D:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2012/12/01 05:38:02 | 001,821,032 | ---- | M] (NVIDIA Corporation) -- D:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2012/12/01 05:38:02 | 000,865,128 | ---- | M] (NVIDIA Corporation) -- D:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2012/11/30 22:43:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- D:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2012/11/22 09:59:24 | 001,073,784 | ---- | M] (Iminent) -- D:\Program Files\Iminent\Iminent.exe PRC - [2012/11/22 09:59:24 | 000,884,344 | ---- | M] (Iminent) -- D:\Program Files\Iminent\Iminent.Messengers.exe PRC - [2012/11/18 02:24:56 | 003,093,624 | ---- | M] () -- D:\Program Files\Pando Networks\Media Booster\PMB.exe PRC - [2012/11/16 03:01:18 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012/11/16 03:01:16 | 001,435,568 | ---- | M] (LogMeIn Inc.) -- D:\Program Files\LogMeIn Hamachi\hamachi-2.exe PRC - [2012/10/29 11:08:22 | 009,128,944 | ---- | M] (TeamSpeak Systems GmbH) -- D:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe PRC - [2012/10/04 14:06:46 | 000,188,760 | ---- | M] () -- D:\Program Files\IB Updater\ExtensionUpdaterService.exe PRC - [2012/09/05 16:57:26 | 000,271,808 | ---- | M] (McAfee, Inc.) -- D:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe PRC - [2012/08/15 19:08:34 | 000,231,768 | ---- | M] (SweetIM Technologies Ltd.) -- D:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe PRC - [2011/10/10 18:00:51 | 000,127,040 | ---- | M] (ICQ, LLC.) -- D:\Program Files\ICQ7.6\ICQ.exe PRC - [2011/04/14 00:39:50 | 000,387,696 | ---- | M] (Kaspersky Lab ZAO) -- D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe PRC - [2010/11/21 11:49:24 | 000,247,608 | ---- | M] () -- D:\Program Files\ICQ6Toolbar\ICQ Service.exe PRC - [2010/06/15 01:10:32 | 000,153,672 | ---- | M] (Logitech Inc.) -- D:\Program Files\Logitech\Gaming Software\LWEMon.exe PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- D:\Windows\System32\taskhost.exe PRC - [2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- D:\Windows\explorer.exe PRC - [2009/07/14 02:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- D:\Windows\System32\conhost.exe PRC - [2008/02/25 10:00:00 | 001,753,088 | ---- | M] (AVM Berlin) -- D:\Program Files\avmwlanstick\WLanGUI.exe PRC - [2008/02/25 10:00:00 | 000,364,544 | ---- | M] (AVM Berlin) -- D:\Program Files\avmwlanstick\WlanNetService.exe ========== Modules (No Company Name) ========== MOD - [2013/01/16 18:11:34 | 000,050,477 | ---- | M] () -- D:\Users\Patrick\Downloads\Defogger.exe MOD - [2013/01/16 14:50:43 | 000,062,976 | ---- | M] () -- D:\Program Files\Origin\tufao.dll MOD - [2013/01/09 00:39:16 | 014,586,888 | ---- | M] () -- D:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_146.dll MOD - [2013/01/08 17:36:34 | 000,023,040 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll MOD - [2013/01/08 17:36:32 | 001,575,424 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll MOD - [2013/01/08 17:36:32 | 000,037,376 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll MOD - [2013/01/08 17:36:30 | 000,007,680 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll MOD - [2013/01/08 17:32:12 | 000,650,240 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll MOD - [2013/01/08 17:32:08 | 000,040,960 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\MACTrackBarLib.dll MOD - [2013/01/08 17:32:06 | 000,044,032 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll MOD - [2013/01/08 17:32:06 | 000,028,672 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll MOD - [2013/01/08 17:32:02 | 000,050,688 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll MOD - [2013/01/08 17:32:00 | 000,073,216 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll MOD - [2013/01/08 17:32:00 | 000,006,144 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll MOD - [2013/01/08 17:31:58 | 000,062,976 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll MOD - [2013/01/08 17:31:58 | 000,018,944 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll MOD - [2013/01/08 17:31:58 | 000,013,312 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll MOD - [2013/01/08 17:31:56 | 000,012,800 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll MOD - [2013/01/08 17:31:56 | 000,007,168 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll MOD - [2013/01/08 17:31:54 | 000,074,752 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll MOD - [2013/01/08 17:31:54 | 000,012,288 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll MOD - [2013/01/08 17:31:54 | 000,009,728 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll MOD - [2013/01/08 17:31:54 | 000,007,168 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll MOD - [2013/01/05 04:45:33 | 003,021,872 | ---- | M] () -- D:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012/12/15 20:45:30 | 010,841,320 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtWebKit4.dll MOD - [2012/12/15 20:45:30 | 008,227,560 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtGui4.dll MOD - [2012/12/15 20:45:30 | 002,554,088 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtXmlPatterns4.dll MOD - [2012/12/15 20:45:30 | 002,430,184 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtDeclarative4.dll MOD - [2012/12/15 20:45:30 | 002,297,576 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtCore4.dll MOD - [2012/12/15 20:45:30 | 001,298,152 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtScript4.dll MOD - [2012/12/15 20:45:30 | 000,979,176 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtNetwork4.dll MOD - [2012/12/15 20:45:30 | 000,343,784 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtXml4.dll MOD - [2012/12/15 20:45:30 | 000,224,488 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\imageformats\qmng4.dll MOD - [2012/12/15 20:45:30 | 000,200,424 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\imageformats\qjpeg4.dll MOD - [2012/12/15 20:45:30 | 000,195,304 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\QtSql4.dll MOD - [2012/12/15 20:45:30 | 000,030,440 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\imageformats\qgif4.dll MOD - [2012/12/15 20:45:29 | 002,267,368 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\libvlccore.dll MOD - [2012/12/15 20:45:29 | 000,270,568 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\phonon4.dll MOD - [2012/12/15 20:45:29 | 000,105,192 | ---- | M] () -- D:\Users\Patrick\AppData\Local\MediaGet2\libvlc.dll MOD - [2012/11/18 02:24:56 | 003,093,624 | ---- | M] () -- D:\Program Files\Pando Networks\Media Booster\PMB.exe MOD - [2012/11/17 07:11:31 | 000,245,760 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\cc063533b04f9420d1aa571a36d1fabd\WindowsFormsIntegration.ni.dll MOD - [2012/11/17 07:10:38 | 001,065,984 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817\System.IdentityModel.ni.dll MOD - [2012/11/17 07:10:36 | 017,919,488 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766\System.ServiceModel.ni.dll MOD - [2012/11/17 07:09:06 | 000,145,920 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\aea1d325200e1a7b1ee7ec86fba33db4\System.Configuration.Install.ni.dll MOD - [2012/11/17 07:09:03 | 001,864,704 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\149f2dcb9c9706e592d1980a945850c2\System.Web.Services.ni.dll MOD - [2012/11/17 06:57:28 | 000,784,896 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\8b6e9d6171aad3561263ce2cd05c57df\System.EnterpriseServices.ni.dll MOD - [2012/11/17 06:57:28 | 000,230,912 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\8b6e9d6171aad3561263ce2cd05c57df\System.EnterpriseServices.Wrapper.dll MOD - [2012/11/17 06:57:27 | 000,645,632 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\dd9dbf82e44454689976a49a9e4ddb6d\System.Transactions.ni.dll MOD - [2012/11/17 06:57:26 | 001,011,200 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1\System.Runtime.DurableInstancing.ni.dll MOD - [2012/11/17 06:57:25 | 000,142,336 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4d2a51c03b27e615ff9f1c430f2014ba\SMDiagnostics.ni.dll MOD - [2012/11/17 06:57:24 | 002,625,024 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll MOD - [2012/11/17 06:56:54 | 001,776,640 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll MOD - [2012/11/17 03:43:19 | 008,013,664 | ---- | M] () -- D:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll MOD - [2012/11/17 03:43:19 | 000,145,240 | ---- | M] () -- D:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\\Interop.SHDocVw.dll MOD - [2012/11/17 03:10:33 | 013,006,336 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0\System.Windows.Forms.ni.dll MOD - [2012/11/17 03:10:26 | 001,651,200 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll MOD - [2012/11/17 03:10:15 | 006,754,816 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\92cccedc7cda413ff6fc6492cb256b58\System.Data.ni.dll MOD - [2012/11/17 03:10:09 | 000,450,048 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3555f5f74c56fa92c0ab7a635af91bfa\PresentationFramework.Aero.ni.dll MOD - [2012/11/17 03:10:07 | 017,629,184 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7f91eecda3ff7ce478146b6458580c98\PresentationFramework.ni.dll MOD - [2012/11/17 03:09:55 | 011,057,664 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\3963e9ce8d44f50e8367e92a8e3e42e6\PresentationCore.ni.dll MOD - [2012/11/17 03:09:47 | 003,779,072 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\d17606e813f01376bd0def23726ecc62\WindowsBase.ni.dll MOD - [2012/11/17 03:09:41 | 005,571,584 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll MOD - [2012/11/17 03:09:39 | 000,973,312 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716\System.Configuration.ni.dll MOD - [2012/11/17 03:09:36 | 007,025,664 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll MOD - [2012/11/17 03:09:31 | 009,000,960 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll MOD - [2012/11/17 03:09:24 | 014,415,872 | ---- | M] () -- D:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll MOD - [2012/10/29 11:08:22 | 000,236,016 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win32.dll MOD - [2012/10/29 11:08:22 | 000,230,384 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win32.dll MOD - [2012/10/29 11:08:18 | 007,859,200 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\QtGui4.dll MOD - [2012/10/29 11:08:18 | 002,210,816 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\QtCore4.dll MOD - [2012/10/29 11:08:18 | 000,814,080 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\QtNetwork4.dll MOD - [2012/10/29 11:08:18 | 000,426,480 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll MOD - [2012/10/29 11:08:18 | 000,414,720 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite4.dll MOD - [2012/10/29 11:08:18 | 000,195,584 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg4.dll MOD - [2012/10/29 11:08:18 | 000,184,320 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\QtSql4.dll MOD - [2012/10/29 11:08:18 | 000,159,216 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\plugins\appscanner_plugin.dll MOD - [2012/10/29 11:08:18 | 000,025,600 | ---- | M] () -- D:\Program Files\TeamSpeak 3 Client\imageformats\qgif4.dll MOD - [2009/07/14 05:45:52 | 000,220,672 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c0f61f9b73571f26b6e0e0757bc5f460\CustomMarshalers.ni.dll MOD - [2009/07/14 05:43:37 | 001,840,640 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\0929bf4ca3bc8e8b2131f27cdf500c7e\System.Web.Services.ni.dll MOD - [2009/07/14 05:43:04 | 012,430,848 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll MOD - [2009/07/14 05:42:57 | 001,586,688 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll MOD - [2009/07/14 05:42:40 | 005,452,800 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll MOD - [2009/07/14 05:42:37 | 000,971,264 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll MOD - [2009/07/14 05:42:36 | 007,949,312 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll MOD - [2009/07/14 05:42:30 | 011,490,816 | ---- | M] () -- D:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll MOD - [2009/06/10 22:22:50 | 000,069,120 | ---- | M] () -- D:\Windows\assembly\GAC_32\CustomMarshalers\\CustomMarshalers.dll ========== Services (SafeList) ========== SRV - [2013/01/11 11:31:30 | 000,115,760 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- D:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013/01/10 15:23:17 | 002,620,016 | ---- | M] (Iminent) [Auto | Running] -- D:\Program Files\Common Files\Umbrella\Umbrella.exe -- (SProtection) SRV - [2013/01/09 00:39:17 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- D:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/12/18 17:49:20 | 001,046,016 | ---- | M] () [Auto | Running] -- D:\Program Files\SimracewayUpdater\SRWUpdate.exe -- (Simraceway Update Service) SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/12/03 16:39:40 | 001,259,880 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- D:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012/11/30 22:43:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- D:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012/11/16 03:01:16 | 001,435,568 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- D:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012/10/04 14:06:46 | 000,188,760 | ---- | M] () [Auto | Running] -- D:\Program Files\IB Updater\ExtensionUpdaterService.exe -- (IB Updater) SRV - [2012/09/05 16:56:44 | 000,234,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- D:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe -- (McComponentHostService) SRV - [2011/04/14 00:39:50 | 000,387,696 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe -- (AVP) SRV - [2010/11/21 11:49:24 | 000,247,608 | ---- | M] () [Auto | Running] -- D:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- D:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2008/02/25 10:00:00 | 000,364,544 | ---- | M] (AVM Berlin) [Auto | Running] -- D:\Program Files\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service) ========== Driver Services (SafeList) ========== DRV - [2012/12/14 16:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- D:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012/12/03 16:39:40 | 009,373,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012/11/17 03:57:43 | 000,488,536 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- D:\Windows\System32\drivers\klif.sys -- (KLIF) DRV - [2010/11/01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- D:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0) DRV - [2010/06/10 02:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- D:\Windows\System32\drivers\kl2.sys -- (kl2) DRV - [2010/06/10 02:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- D:\Windows\System32\drivers\kl1.sys -- (KL1) DRV - [2010/04/28 01:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore) DRV - [2010/04/28 01:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid) DRV - [2010/04/28 01:57:24 | 000,031,816 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\WmHidLo.sys -- (WmHidLo) DRV - [2010/04/28 01:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum) DRV - [2010/04/27 23:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\WmFilter.sys -- (WmFilter) DRV - [2010/04/23 04:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- D:\Windows\System32\drivers\klim6.sys -- (KLIM6) DRV - [2009/11/03 05:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\klmouflt.sys -- (klmouflt) DRV - [2009/07/14 02:20:44 | 000,028,240 | ---- | M] (Мįćґοşσƒť Ĉоŗроřάтίøη) [Kernel | System | Running] -- D:\Windows\System32\drivers\mssmbios.sys -- (mssmbios) DRV - [2009/07/14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2009/07/14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- D:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009/07/14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2009/07/14 00:54:29 | 000,101,888 | ---- | M] (Μі¢řóѕοƒť Ċоřρǿгдтϊōи) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\ipnat.sys -- (IPNAT) DRV - [2009/07/14 00:52:09 | 000,258,560 | ---- | M] (Міćřõŝõƒŧ €σřрóяąŧĩоŋ) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\usbhub.sys -- (usbhub) DRV - [2009/07/14 00:52:00 | 000,163,328 | ---- | M] (Μιĉґθşøƒτ Ćσґφòřãťìòʼn) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\1394ohci.sys -- (1394ohci) DRV - [2009/07/14 00:51:47 | 000,304,128 | ---- | M] (Мϊςяοšǿƒт Çθŕφōŕдτίòⁿ) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService) DRV - [2009/07/14 00:51:39 | 000,039,936 | ---- | M] (Мįςŗőѕоƒτ Ĉθѓρőѓāťìǿń) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\umbus.sys -- (umbus) DRV - [2009/07/14 00:51:29 | 000,062,464 | ---- | M] (Мίćяøşόƒτ Ċбŕþóґàтìǿⁿ) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\ohci1394.sys -- (ohci1394) DRV - [2009/07/14 00:46:53 | 000,021,632 | ---- | M] (Мîċґοşόƒт Ĉøřрǿŗάτїθи) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\wacompen.sys -- (WacomPen) DRV - [2009/07/14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009/07/14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2009/07/14 00:15:13 | 000,309,760 | ---- | M] (Μĩсřбšθƒť €õřφòŗäтιôй) [File_System | On_Demand | Running] -- D:\Windows\System32\drivers\srv.sys -- (srv) DRV - [2009/07/14 00:11:04 | 000,055,296 | ---- | M] (Мίćŕőşǿƒт Сøгþóřάтíöή) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\amdk8.sys -- (AmdK8) DRV - [2009/07/14 00:11:04 | 000,053,760 | ---- | M] (Μìςřбśöƒţ Ćøřрǿŕǻтĭθń) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\intelppm.sys -- (intelppm) DRV - [2009/07/14 00:11:04 | 000,052,736 | ---- | M] (Μįčŗòšǿƒť Сοřρǿѓâŧίŏņ) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\amdppm.sys -- (AmdPPM) DRV - [2009/07/14 00:11:04 | 000,052,224 | ---- | M] (Мĩćѓόѕоƒţ €οŕρōřåтîоň) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\processr.sys -- (Processor) DRV - [2009/07/13 23:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD) DRV - [2009/03/19 01:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2007/12/19 10:00:00 | 000,401,920 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Running] -- D:\Windows\System32\drivers\fwlanusbn.sys -- (fwlanusbn) DRV - [2007/11/07 11:00:00 | 000,004,352 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- D:\Windows\System32\drivers\avmeject.sys -- (avmeject) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={4B9C0770-3587-11E2-A0AB-BC054304DE3A} IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=6ec5157d-0251-4478-8591-273ddbd1959c&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10031&barid={4B9C0770-3587-11E2-A0AB-BC054304DE3A} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=6ec5157d-0251-4478-8591-273ddbd1959c&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=6ec5157d-0251-4478-8591-273ddbd1959c&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Babylon Search IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 7F 7B 6E 69 C4 CD 01 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=6ec5157d-0251-4478-8591-273ddbd1959c&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=6ec5157d-0251-4478-8591-273ddbd1959c&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=6ec5157d-0251-4478-8591-273ddbd1959c&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd IE - HKCU\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = hxxp://search.iminent.com/?appId=[AppInstanceUid]&ref=toolbox&q={searchTerms} IE - HKCU\..\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}: "URL" = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = fritz.box ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.startup.homepage: "hxxp://search.iminent.com/?appId=8BD9B20E-7AFC-453E-8A40-E9447725B0A1" FF - prefs.js..extensions.enabledAddons: addlyrics%40addlyrics.net:1.0 FF - prefs.js..extensions.enabledAddons: ffxtlbr%40incredibar.com:1.5.0 FF - prefs.js..extensions.enabledAddons: %7B800b5000-a755-47e1-992b-48a1c1357f07%7D:1.5.3 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0 FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: D:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: D:\Program Files\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: D:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: D:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: D:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: D:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: D:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\webbooster@iminent.com: D:\Program Files\Iminent\webbooster@iminent.com [2012/11/25 20:57:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: D:\Program Files\IB Updater\Firefox [2013/01/06 02:47:12 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2013/01/16 15:35:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\addlyrics@addlyrics.net: D:\Program Files\AddLyrics\FF\ [2013/01/06 02:46:46 | 000,000,000 | ---D | M] [2012/11/17 03:20:05 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\Extensions [2013/01/11 17:50:05 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\bvx725t6.default-1357436136333\extensions [2013/01/11 17:50:05 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\bvx725t6.default-1357436136333\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2013/01/10 15:29:04 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\bvx725t6.default-1357436136333\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}1102013152901 [2013/01/06 02:47:46 | 000,000,000 | ---D | M] (incredibar.com) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\bvx725t6.default-1357436136333\extensions\ffxtlbr@incredibar.com [2013/01/10 15:29:48 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\xkm1f85g.default\extensions [2013/01/10 15:29:08 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\xkm1f85g.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012/10/23 15:20:32 | 000,000,000 | ---D | M] (IMinent Toolbar) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\xkm1f85g.default\extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444} [2013/01/10 15:29:48 | 000,000,000 | ---D | M] (ICQ Sparberater) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\xkm1f85g.default\extensions\ciuvo-extension@icq.de [2013/01/10 15:29:48 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\Firefox\Profiles\xkm1f85g.default\extensions\ciuvo-extension@icq.de\chrome [2013/01/11 16:35:42 | 000,101,871 | ---- | M] () (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\bvx725t6.default-1357436136333\extensions\ciuvo-extension@icq.de.xpi [2013/01/06 16:15:24 | 000,804,627 | ---- | M] () (No name found) -- D:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\bvx725t6.default-1357436136333\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/01/11 12:14:19 | 000,000,950 | ---- | M] () -- D:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\bvx725t6.default-1357436136333\searchplugins\icqplugin-1.xml [2013/01/16 15:36:01 | 000,000,950 | ---- | M] () -- D:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\bvx725t6.default-1357436136333\searchplugins\icqplugin-2.xml [2011/03/30 15:14:34 | 000,001,042 | ---- | M] () -- D:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\bvx725t6.default-1357436136333\searchplugins\icqplugin.xml [2013/01/06 02:46:52 | 000,002,203 | ---- | M] () -- D:\Users\Patrick\AppData\Roaming\mozilla\firefox\profiles\bvx725t6.default-1357436136333\searchplugins\MyStart Search.xml [2013/01/16 15:35:48 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files\mozilla firefox\extensions [2013/01/11 11:31:25 | 000,000,000 | ---D | M] (Anti-Banner) -- D:\Program Files\mozilla firefox\extensions\KavAntiBanner@Kaspersky.ru [2013/01/11 11:31:25 | 000,000,000 | ---D | M] (Modul zur Link-Untersuchung) -- D:\Program Files\mozilla firefox\extensions\linkfilter@kaspersky.ru [2013/01/06 02:46:46 | 000,000,000 | ---D | M] ("Add Lyrics") -- D:\PROGRAM FILES\ADDLYRICS\FF [2013/01/05 04:45:48 | 000,262,704 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browsercomps.dll [2012/11/30 18:47:58 | 000,002,349 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\babylon.xml [2013/01/05 04:45:12 | 000,002,465 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/11/22 09:49:44 | 000,002,157 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\SearchTheWeb.xml [2013/01/05 04:45:12 | 000,002,058 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\twitter.xml ========== Chrome ========== CHR - homepage: hxxp://search.iminent.com/?appId=8BD9B20E-7AFC-453E-8A40-E9447725B0A1 CHR - homepage: hxxp://search.iminent.com/?appId=8BD9B20E-7AFC-453E-8A40-E9447725B0A1 CHR - Extension: No name found = D:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\\ O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts O2 - BHO: (ICQ Sparberater) - {0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD} - D:\Program Files\icq\Internet Explorer\icq.dll (solute gmbh) O2 - BHO: (IB Updater) - {336D0C35-8A85-403a-B9D2-65C292C39087} - D:\Program Files\IB Updater\Extension32.dll () O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - D:\Program Files\IMinent Toolbar\tbcore3.dll () O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\ievkbd.dll (Kaspersky Lab ZAO) O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - D:\Program Files\Incredibar.com\incredibar\\bh\incredibar.dll (Montera Technologeis LTD) O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - D:\Program Files\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent) O2 - BHO: (AddLyrics) - {B40720CF-4DDD-40DC-86EA-26404E77C1E8} - D:\Program Files\AddLyrics\AddLyrics.dll (RVZR) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\klwtbbho.dll (Kaspersky Lab ZAO) O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - D:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - D:\Program Files\IMinent Toolbar\tbcore3.dll () O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - D:\Program Files\Incredibar.com\incredibar\\incredibarTlbr.dll (Montera Technologeis LTD) O3 - HKCU\..\Toolbar\WebBrowser: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - D:\Program Files\IMinent Toolbar\tbcore3.dll () O3 - HKCU\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O4 - HKLM..\Run: [addlyrics@addlyrics.net] D:\Program Files\AddLyrics\YTLUpdater.exe () O4 - HKLM..\Run: [AVMWlanClient] D:\Program Files\avmwlanstick\wlangui.exe (AVM Berlin) O4 - HKLM..\Run: [AVP] D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [Iminent] D:\Program Files\Iminent\Iminent.exe (Iminent) O4 - HKLM..\Run: [IminentMessenger] D:\Program Files\Iminent\Iminent.Messengers.exe (Iminent) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [Start WingMan Profiler] D:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.) O4 - HKLM..\Run: [Sweetpacks Communicator] D:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.) O4 - HKCU..\Run: [Best Codec Pack803601.exe] D:\Users\Patrick\AppData\Local\Temp\Best Codec Pack803601.exe () O4 - HKCU..\Run: [Browser Infrastructure Helper] D:\Users\Patrick\AppData\Local\Smartbar\Application\Linkury.exe (Smartbar) O4 - HKCU..\Run: [EADM] D:\Program Files\Origin\Origin.exe (Electronic Arts) O4 - HKCU..\Run: [ICQ] D:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [MediaGet2] D:\Users\Patrick\AppData\Local\MediaGet2\mediaget.exe (MediaGet LLC) O4 - HKCU..\Run: [Pando Media Booster] D:\Program Files\Pando Networks\Media Booster\PMB.exe () O4 - HKLM..\RunOnce: [SPUpdSentinel] D:\Program Files\Common Files\Umbrella\Umbrella_bkp.exe (Iminent) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Hinzufügen zu Anti-Banner - D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\ie_banner_deny.htm () O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - D:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - D:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.) O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\klwtbbho.dll (Kaspersky Lab ZAO) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A9A41DA-B631-4F8D-A26F-8CACA40BEC0E}: DhcpNameServer = O20 - AppInit_DLLs: (D:\PROGRA~3\KASPER~1\KASPER~1\mzvkbd3.dll) - D:\PROGRA~3\KASPER~1\KASPER~1\mzvkbd3.dll (Kaspersky Lab ZAO) O20 - AppInit_DLLs: (D:\PROGRA~3\KASPER~1\KASPER~1\kloehk.dll) - D:\PROGRA~3\KASPER~1\KASPER~1\kloehk.dll (Kaspersky Lab ZAO) O20 - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (D:\Windows\system32\userinit.exe) - D:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\klogon: DllName - (D:\Windows\system32\klogon.dll) - D:\Windows\System32\klogon.dll (Kaspersky Lab ZAO) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/06/03 22:34:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2008/10/31 05:10:28 | 000,000,045 | R--- | M] () - F:\Autorun.inf -- [ CDFS ] O33 - MountPoints2\{6edeea0b-305b-11e2-ad7e-0019db617c90}\Shell - "" = AutoRun O33 - MountPoints2\{6edeea0b-305b-11e2-ad7e-0019db617c90}\Shell\AutoRun\command - "" = H:\pushinst.exe O33 - MountPoints2\{d25c0a88-304b-11e2-8b73-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{d25c0a88-304b-11e2-8b73-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe -- [2008/11/01 23:17:12 | 000,356,352 | R--- | M] () O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== File not found -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neue Funktion 1 [2013/01/16 16:25:29 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Malwarebytes [2013/01/16 16:25:17 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013/01/16 16:25:17 | 000,000,000 | ---D | C] -- D:\ProgramData\Malwarebytes [2013/01/16 16:25:16 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- D:\Windows\System32\drivers\mbam.sys [2013/01/16 16:25:16 | 000,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware [2013/01/16 16:25:05 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Local\Programs [2013/01/11 13:47:45 | 000,000,000 | ---D | C] -- D:\Users\Patrick\Desktop\RFT 2012 [2013/01/11 11:31:24 | 000,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox [2013/01/10 15:29:46 | 000,000,000 | ---D | C] -- D:\Program Files\icq [2013/01/10 15:29:23 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.6 [2013/01/10 15:28:09 | 000,000,000 | ---D | C] -- D:\Program Files\ICQ7.6 [2013/01/10 15:18:50 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\ICQ [2013/01/10 15:09:57 | 000,000,000 | ---D | C] -- D:\Users\Patrick\Documents\ICQ Dateien [2013/01/10 15:03:33 | 000,000,000 | ---D | C] -- D:\Program Files\ICQ6Toolbar [2013/01/10 15:03:32 | 000,000,000 | ---D | C] -- D:\ProgramData\ICQ [2013/01/10 15:02:49 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\ICQ-Profile [2013/01/09 22:57:23 | 000,000,000 | ---D | C] -- D:\Users\Patrick\Desktop\LMT 2010 Trackpack [2013/01/08 23:45:13 | 000,000,000 | -H-D | C] -- D:\Program Files\InstallShield Installation Information [2013/01/08 22:47:28 | 000,000,000 | ---D | C] -- D:\Program Files\League of Legends [2013/01/08 21:32:10 | 000,000,000 | ---D | C] -- D:\Program Files\Paint.NET [2013/01/08 21:31:51 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Local\Paint.NET [2013/01/08 20:02:23 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Local\ElevatedDiagnostics [2013/01/08 17:44:57 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KOREA CIRCUIT by macci DESIGN [2013/01/08 17:44:57 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\KOREA CIRCUIT by macci DESIGN [2013/01/08 17:26:01 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Korea International Circuit [2013/01/08 17:25:56 | 000,000,000 | ---D | C] -- D:\Windows\Korea International Circuit [2013/01/07 03:04:52 | 000,000,000 | ---D | C] -- D:\Users\Patrick\Desktop\Sandrox RFE Plugin [2013/01/06 02:47:44 | 000,000,000 | ---D | C] -- D:\Program Files\Incredibar.com [2013/01/06 02:47:28 | 000,000,000 | ---D | C] -- D:\Windows\System32\ARFC [2013/01/06 02:47:25 | 000,000,000 | ---D | C] -- D:\Windows\System32\WNLT [2013/01/06 02:47:11 | 000,000,000 | ---D | C] -- D:\Program Files\IB Updater [2013/01/06 02:46:46 | 000,000,000 | ---D | C] -- D:\Program Files\AddLyrics [2012/12/26 15:39:44 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien [2012/12/26 15:35:45 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts [2012/12/26 15:31:24 | 000,000,000 | ---D | C] -- D:\Program Files\Electronic Arts [2012/12/25 19:02:58 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games [2012/12/20 21:13:31 | 000,000,000 | -H-D | C] -- D:\Users\Patrick\AppData\Roaming\TempMods [2012/12/20 21:08:03 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Simraceway [2012/12/20 21:07:29 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Local\CrashRpt [2012/12/20 21:06:02 | 000,000,000 | ---D | C] -- D:\Program Files\SimracewayUpdater [2012/12/20 21:05:57 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Simraceway [2012/12/20 21:05:28 | 000,000,000 | ---D | C] -- D:\Program Files\Simraceway [2012/12/18 20:10:29 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\F1 1994 Season F1-S-R [2012/12/18 20:01:56 | 000,000,000 | ---D | C] -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\F1 1994 Season F1-S-R Track Pack [2012/12/18 19:41:54 | 000,000,000 | ---D | C] -- D:\Program Files\AGEIA Technologies ========== Files - Modified Within 30 Days ========== [2013/01/16 18:12:12 | 000,000,000 | ---- | M] () -- D:\Users\Patrick\defogger_reenable [2013/01/16 18:11:24 | 000,651,450 | ---- | M] () -- D:\Windows\System32\perfh009.dat [2013/01/16 18:11:24 | 000,120,382 | ---- | M] () -- D:\Windows\System32\perfc009.dat [2013/01/16 18:10:29 | 000,014,016 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/01/16 18:10:29 | 000,014,016 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/01/16 18:05:21 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat [2013/01/16 18:05:13 | 2415,407,104 | -HS- | M] () -- D:\hiberfil.sys [2013/01/16 17:39:02 | 000,000,884 | ---- | M] () -- D:\Windows\tasks\Adobe Flash Player Updater.job [2013/01/16 16:25:17 | 000,001,067 | ---- | M] () -- D:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/01/16 15:35:53 | 000,001,105 | ---- | M] () -- D:\Users\Public\Desktop\Mozilla Firefox.lnk [2013/01/10 15:29:23 | 000,001,770 | ---- | M] () -- D:\Users\Public\Desktop\ICQ7.6.lnk [2013/01/09 11:46:51 | 000,001,004 | ---- | M] () -- D:\Users\Patrick\Desktop\Mozilla Firefox.lnk [2013/01/08 23:52:28 | 000,001,722 | ---- | M] () -- D:\Users\Public\Desktop\League of Legends spielen .lnk [2013/01/08 21:33:02 | 000,001,288 | ---- | M] () -- D:\Users\Public\Desktop\Paint.NET.lnk [2013/01/06 02:47:48 | 000,000,684 | ---- | M] () -- D:\user.js [2012/12/31 19:17:07 | 000,007,602 | ---- | M] () -- D:\Users\Patrick\AppData\Local\Resmon.ResmonCfg [2012/12/29 22:47:03 | 000,139,328 | ---- | M] () -- D:\Windows\System32\drivers\PnkBstrK.sys [2012/12/29 22:46:39 | 000,281,520 | ---- | M] () -- D:\Windows\System32\PnkBstrB.xtr [2012/12/29 22:46:12 | 000,280,904 | ---- | M] () -- D:\Windows\System32\PnkBstrB.ex0 [2012/12/26 15:36:35 | 000,002,237 | ---- | M] () -- D:\Users\Public\Desktop\Die Schlacht um Mittelerde™ II.lnk [2012/12/24 14:30:27 | 291,962,654 | ---- | M] () -- D:\Windows\MEMORY.DMP [2012/12/20 21:05:57 | 000,001,891 | ---- | M] () -- D:\Users\Patrick\Desktop\Simraceway.lnk ========== Files Created - No Company Name ========== [2013/01/16 18:12:12 | 000,000,000 | ---- | C] () -- D:\Users\Patrick\defogger_reenable [2013/01/16 16:25:17 | 000,001,067 | ---- | C] () -- D:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013/01/16 15:35:53 | 000,001,117 | ---- | C] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013/01/16 15:35:53 | 000,001,105 | ---- | C] () -- D:\Users\Public\Desktop\Mozilla Firefox.lnk [2013/01/10 15:29:23 | 000,001,770 | ---- | C] () -- D:\Users\Public\Desktop\ICQ7.6.lnk [2013/01/09 11:46:51 | 000,001,034 | ---- | C] () -- D:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013/01/09 11:46:51 | 000,001,004 | ---- | C] () -- D:\Users\Patrick\Desktop\Mozilla Firefox.lnk [2013/01/08 23:52:28 | 000,001,722 | ---- | C] () -- D:\Users\Public\Desktop\League of Legends spielen .lnk [2013/01/08 21:33:02 | 000,001,300 | ---- | C] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk [2013/01/08 21:33:02 | 000,001,288 | ---- | C] () -- D:\Users\Public\Desktop\Paint.NET.lnk [2013/01/06 02:47:28 | 000,028,160 | ---- | C] () -- D:\Windows\System32\ImHttpComm.dll [2012/12/26 15:36:35 | 000,002,237 | ---- | C] () -- D:\Users\Public\Desktop\Die Schlacht um Mittelerde™ II.lnk [2012/12/20 21:05:57 | 000,001,891 | ---- | C] () -- D:\Users\Patrick\Desktop\Simraceway.lnk [2012/11/30 22:48:46 | 000,139,328 | ---- | C] () -- D:\Windows\System32\drivers\PnkBstrK.sys [2012/11/30 22:48:31 | 000,138,056 | ---- | C] () -- D:\Users\Patrick\AppData\Roaming\PnkBstrK.sys [2012/11/30 22:47:59 | 000,281,520 | ---- | C] () -- D:\Windows\System32\PnkBstrB.exe [2012/11/30 22:47:56 | 000,076,888 | ---- | C] () -- D:\Windows\System32\PnkBstrA.exe [2012/11/30 18:17:14 | 000,007,602 | ---- | C] () -- D:\Users\Patrick\AppData\Local\Resmon.ResmonCfg [2012/11/17 03:58:51 | 000,116,189 | ---- | C] () -- D:\Windows\System32\drivers\klin.dat [2012/11/17 03:58:51 | 000,098,168 | ---- | C] () -- D:\Windows\System32\drivers\klick.dat [2012/11/17 03:10:18 | 000,015,573 | ---- | C] () -- D:\Windows\System32\drivers\fwlanusbn.bin ========== ZeroAccess Check ========== [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- D:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both ========== LOP Check ========== [2012/11/30 18:47:49 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\Babylon [2013/01/14 08:18:16 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\ICQ [2013/01/10 15:06:35 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\ICQ-Profile [2012/11/25 20:58:08 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\Iminent [2012/11/18 09:04:15 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\LolClient [2013/01/10 18:08:39 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\Media Get LLC [2012/12/26 15:39:44 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien [2012/11/17 03:42:22 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\OpenCandy [2012/11/30 20:28:03 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\Origin [2012/12/20 21:40:03 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\Simraceway [2012/12/20 21:13:31 | 000,000,000 | -H-D | M] -- D:\Users\Patrick\AppData\Roaming\TempMods [2013/01/16 18:07:25 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\TS3Client [2012/11/30 18:47:44 | 000,000,000 | ---D | M] -- D:\Users\Patrick\AppData\Roaming\YourFileDownloader ========== Purity Check ========== < End of report > |
![]() | #5 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Access Restricted u. Adobeplugin Abstürze hi dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
![]() | #6 |
![]() | #7 |
| ![]() Access Restricted u. Adobeplugin Abstürze 21:30:52.0833 3884 TDSS rootkit removing tool Oct 31 2012 21:47:35 21:30:53.0052 3884 ============================================================ 21:30:53.0052 3884 Current date / time: 2013/01/16 21:30:53.0052 21:30:53.0052 3884 SystemInfo: 21:30:53.0052 3884 21:30:53.0052 3884 OS Version: 6.1.7600 ServicePack: 0.0 21:30:53.0052 3884 Product type: Workstation 21:30:53.0052 3884 ComputerName: PATRICK-PC 21:30:53.0052 3884 UserName: Patrick 21:30:53.0052 3884 Windows directory: D:\Windows 21:30:53.0052 3884 System windows directory: D:\Windows 21:30:53.0052 3884 Processor architecture: Intel x86 21:30:53.0052 3884 Number of processors: 2 21:30:53.0052 3884 Page size: 0x1000 21:30:53.0052 3884 Boot type: Normal boot 21:30:53.0052 3884 ============================================================ 21:30:54.0627 3884 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 21:30:54.0627 3884 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 21:30:54.0627 3884 ============================================================ 21:30:54.0627 3884 \Device\Harddisk0\DR0: 21:30:54.0627 3884 MBR partitions: 21:30:54.0627 3884 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2711637 21:30:54.0643 3884 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27116B5, BlocksNum 0x37C6F6CB 21:30:54.0643 3884 \Device\Harddisk1\DR1: 21:30:54.0643 3884 MBR partitions: 21:30:54.0643 3884 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x52474D54, BlocksNum 0x6D6F6B20 21:30:54.0643 3884 ============================================================ 21:30:54.0690 3884 C: <-> \Device\Harddisk0\DR0\Partition1 21:30:54.0705 3884 D: <-> \Device\Harddisk0\DR0\Partition2 21:30:54.0705 3884 ============================================================ 21:30:54.0705 3884 Initialize success 21:30:54.0705 3884 ============================================================ 21:33:47.0500 6112 ============================================================ 21:33:47.0500 6112 Scan started 21:33:47.0500 6112 Mode: Manual; SigCheck; TDLFS; 21:33:47.0500 6112 ============================================================ 21:33:48.0770 6112 ================ Scan system memory ======================== 21:33:48.0770 6112 System memory - ok 21:33:48.0770 6112 ================ Scan services ============================= 21:33:48.0980 6112 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci D:\Windows\system32\DRIVERS\1394ohci.sys 21:33:49.0100 6112 1394ohci - ok 21:33:49.0130 6112 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI D:\Windows\system32\DRIVERS\ACPI.sys 21:33:49.0150 6112 ACPI - ok 21:33:49.0170 6112 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi D:\Windows\system32\DRIVERS\acpipmi.sys 21:33:49.0230 6112 AcpiPmi - ok 21:33:49.0280 6112 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc D:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 21:33:49.0290 6112 AdobeFlashPlayerUpdateSvc - ok 21:33:49.0330 6112 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx D:\Windows\system32\DRIVERS\adp94xx.sys 21:33:49.0350 6112 adp94xx - ok 21:33:49.0360 6112 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci D:\Windows\system32\DRIVERS\adpahci.sys 21:33:49.0380 6112 adpahci - ok 21:33:49.0400 6112 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 D:\Windows\system32\DRIVERS\adpu320.sys 21:33:49.0410 6112 adpu320 - ok 21:33:49.0460 6112 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc D:\Windows\System32\aelupsvc.dll 21:33:49.0560 6112 AeLookupSvc - ok 21:33:49.0600 6112 [ DDC040FDB01EF1712A6B13E52AFB104C ] AFD D:\Windows\system32\drivers\afd.sys 21:33:49.0650 6112 AFD - ok 21:33:49.0670 6112 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 D:\Windows\system32\DRIVERS\agp440.sys 21:33:49.0680 6112 agp440 - ok 21:33:49.0710 6112 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx D:\Windows\system32\DRIVERS\djsvs.sys 21:33:49.0720 6112 aic78xx - ok 21:33:49.0750 6112 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG D:\Windows\System32\alg.exe 21:33:49.0810 6112 ALG - ok 21:33:49.0830 6112 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide D:\Windows\system32\DRIVERS\aliide.sys 21:33:49.0840 6112 aliide - ok 21:33:49.0860 6112 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp D:\Windows\system32\DRIVERS\amdagp.sys 21:33:49.0870 6112 amdagp - ok 21:33:49.0880 6112 [ CD5914170297126B6266860198D1D4F0 ] amdide D:\Windows\system32\DRIVERS\amdide.sys 21:33:49.0890 6112 amdide - ok 21:33:49.0920 6112 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 D:\Windows\system32\DRIVERS\amdk8.sys 21:33:49.0930 6112 AmdK8 - ok 21:33:49.0940 6112 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM D:\Windows\system32\DRIVERS\amdppm.sys 21:33:49.0960 6112 AmdPPM - ok 21:33:49.0970 6112 [ 2101A86C25C154F8314B24EF49D7FBC2 ] amdsata D:\Windows\system32\DRIVERS\amdsata.sys 21:33:49.0980 6112 amdsata - ok 21:33:50.0000 6112 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs D:\Windows\system32\DRIVERS\amdsbs.sys 21:33:50.0010 6112 amdsbs - ok 21:33:50.0030 6112 [ B81C2B5616F6420A9941EA093A92B150 ] amdxata D:\Windows\system32\DRIVERS\amdxata.sys 21:33:50.0040 6112 amdxata - ok 21:33:50.0060 6112 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID D:\Windows\system32\drivers\appid.sys 21:33:50.0130 6112 AppID - ok 21:33:50.0140 6112 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc D:\Windows\System32\appidsvc.dll 21:33:50.0160 6112 AppIDSvc - ok 21:33:50.0170 6112 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo D:\Windows\System32\appinfo.dll 21:33:50.0210 6112 Appinfo - ok 21:33:50.0270 6112 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt D:\Windows\System32\appmgmts.dll 21:33:50.0290 6112 AppMgmt - ok 21:33:50.0300 6112 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc D:\Windows\system32\DRIVERS\arc.sys 21:33:50.0320 6112 arc - ok 21:33:50.0330 6112 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas D:\Windows\system32\DRIVERS\arcsas.sys 21:33:50.0340 6112 arcsas - ok 21:33:50.0460 6112 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state D:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 21:33:50.0470 6112 aspnet_state - ok 21:33:50.0490 6112 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac D:\Windows\system32\DRIVERS\asyncmac.sys 21:33:50.0520 6112 AsyncMac - ok 21:33:50.0560 6112 [ 338C86357871C167A96AB976519BF59E ] atapi D:\Windows\system32\DRIVERS\atapi.sys 21:33:50.0570 6112 atapi - ok 21:33:50.0590 6112 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder D:\Windows\System32\Audiosrv.dll 21:33:50.0640 6112 AudioEndpointBuilder - ok 21:33:50.0650 6112 [ 510C873BFA135AA829F4180352772734 ] Audiosrv D:\Windows\System32\Audiosrv.dll 21:33:50.0690 6112 Audiosrv - ok 21:33:50.0800 6112 [ 06C3528E0686A58701367749B0145A4A ] AVM WLAN Connection Service D:\Program Files\avmwlanstick\WlanNetService.exe 21:33:50.0830 6112 AVM WLAN Connection Service ( UnsignedFile.Multi.Generic ) - warning 21:33:50.0830 6112 AVM WLAN Connection Service - detected UnsignedFile.Multi.Generic (1) 21:33:50.0850 6112 [ 263CF9D248FD5E020A1333ED4F7EAA88 ] avmeject D:\Windows\system32\drivers\avmeject.sys 21:33:50.0870 6112 avmeject ( UnsignedFile.Multi.Generic ) - warning 21:33:50.0870 6112 avmeject - detected UnsignedFile.Multi.Generic (1) 21:33:50.0930 6112 [ 3CE83DAAF178E2A8DBB5A1A7CB6892EA ] AVP D:\Program Files\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe 21:33:50.0960 6112 AVP - ok 21:33:51.0000 6112 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV D:\Windows\System32\AxInstSV.dll 21:33:51.0060 6112 AxInstSV - ok 21:33:51.0120 6112 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv D:\Windows\system32\DRIVERS\bxvbdx.sys 21:33:51.0150 6112 b06bdrv - ok 21:33:51.0210 6112 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x D:\Windows\system32\DRIVERS\b57nd60x.sys 21:33:51.0230 6112 b57nd60x - ok 21:33:51.0260 6112 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC D:\Windows\System32\bdesvc.dll 21:33:51.0310 6112 BDESVC - ok 21:33:51.0320 6112 [ 505506526A9D467307B3C393DEDAF858 ] Beep D:\Windows\system32\drivers\Beep.sys 21:33:51.0360 6112 Beep - ok 21:33:51.0390 6112 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE D:\Windows\System32\bfe.dll 21:33:51.0430 6112 BFE - ok 21:33:51.0500 6112 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS D:\Windows\System32\qmgr.dll 21:33:51.0540 6112 BITS - ok 21:33:51.0560 6112 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive D:\Windows\system32\DRIVERS\blbdrive.sys 21:33:51.0570 6112 blbdrive - ok 21:33:51.0590 6112 [ FCAFAEF6798D7B51FF029F99A9898961 ] bowser D:\Windows\system32\DRIVERS\bowser.sys 21:33:51.0630 6112 bowser - ok 21:33:51.0650 6112 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo D:\Windows\system32\DRIVERS\BrFiltLo.sys 21:33:51.0690 6112 BrFiltLo - ok 21:33:51.0710 6112 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp D:\Windows\system32\DRIVERS\BrFiltUp.sys 21:33:51.0720 6112 BrFiltUp - ok 21:33:51.0750 6112 [ 598E1280E7FF3744F4B8329366CC5635 ] Browser D:\Windows\System32\browser.dll 21:33:51.0770 6112 Browser - ok 21:33:51.0780 6112 [ 845B8CE732E67F3B4133164868C666EA ] Brserid D:\Windows\System32\Drivers\Brserid.sys 21:33:51.0820 6112 Brserid - ok 21:33:51.0830 6112 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm D:\Windows\System32\Drivers\BrSerWdm.sys 21:33:51.0870 6112 BrSerWdm - ok 21:33:51.0910 6112 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm D:\Windows\System32\Drivers\BrUsbMdm.sys 21:33:51.0920 6112 BrUsbMdm - ok 21:33:51.0920 6112 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer D:\Windows\System32\Drivers\BrUsbSer.sys 21:33:51.0950 6112 BrUsbSer - ok 21:33:51.0970 6112 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM D:\Windows\system32\DRIVERS\bthmodem.sys 21:33:52.0000 6112 BTHMODEM - ok 21:33:52.0040 6112 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv D:\Windows\system32\bthserv.dll 21:33:52.0080 6112 bthserv - ok 21:33:52.0100 6112 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs D:\Windows\system32\DRIVERS\cdfs.sys 21:33:52.0140 6112 cdfs - ok 21:33:52.0190 6112 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom D:\Windows\system32\DRIVERS\cdrom.sys 21:33:52.0210 6112 cdrom - ok 21:33:52.0230 6112 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc D:\Windows\System32\certprop.dll 21:33:52.0260 6112 CertPropSvc - ok 21:33:52.0280 6112 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass D:\Windows\system32\DRIVERS\circlass.sys 21:33:52.0290 6112 circlass - ok 21:33:52.0310 6112 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS D:\Windows\system32\CLFS.sys 21:33:52.0330 6112 CLFS - ok 21:33:52.0410 6112 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 21:33:52.0430 6112 clr_optimization_v2.0.50727_32 - ok 21:33:52.0460 6112 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 21:33:52.0470 6112 clr_optimization_v4.0.30319_32 - ok 21:33:52.0480 6112 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt D:\Windows\system32\DRIVERS\CmBatt.sys 21:33:52.0490 6112 CmBatt - ok 21:33:52.0500 6112 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide D:\Windows\system32\DRIVERS\cmdide.sys 21:33:52.0510 6112 cmdide - ok 21:33:52.0540 6112 [ 1B675691ED940766149C93E8F4488D68 ] CNG D:\Windows\system32\Drivers\cng.sys 21:33:52.0560 6112 CNG - ok 21:33:52.0580 6112 [ A6023D3823C37043986713F118A89BEE ] Compbatt D:\Windows\system32\DRIVERS\compbatt.sys 21:33:52.0590 6112 Compbatt - ok 21:33:52.0610 6112 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus D:\Windows\system32\DRIVERS\CompositeBus.sys 21:33:52.0630 6112 CompositeBus - ok 21:33:52.0630 6112 COMSysApp - ok 21:33:52.0650 6112 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk D:\Windows\system32\DRIVERS\crcdisk.sys 21:33:52.0660 6112 crcdisk - ok 21:33:52.0680 6112 [ 9C231178CE4FB385F4B54B0A9080B8A4 ] CryptSvc D:\Windows\system32\cryptsvc.dll 21:33:52.0700 6112 CryptSvc - ok 21:33:52.0750 6112 [ 27C9490BDD0AE48911AB8CF1932591ED ] CSC D:\Windows\system32\drivers\csc.sys 21:33:52.0800 6112 CSC - ok 21:33:52.0820 6112 [ 56FB5F222EA30D3D3FC459879772CB73 ] CscService D:\Windows\System32\cscsvc.dll 21:33:52.0860 6112 CscService - ok 21:33:52.0900 6112 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch D:\Windows\system32\rpcss.dll 21:33:52.0940 6112 DcomLaunch - ok 21:33:52.0990 6112 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc D:\Windows\System32\defragsvc.dll 21:33:53.0050 6112 defragsvc - ok 21:33:53.0070 6112 [ 8E09E52EE2E3CEB199EF3DD99CF9E3FB ] DfsC D:\Windows\system32\Drivers\dfsc.sys 21:33:53.0110 6112 DfsC - ok 21:33:53.0140 6112 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp D:\Windows\system32\dhcpcore.dll 21:33:53.0180 6112 Dhcp - ok 21:33:53.0190 6112 [ 1A050B0274BFB3890703D490F330C0DA ] discache D:\Windows\system32\drivers\discache.sys 21:33:53.0230 6112 discache - ok 21:33:53.0260 6112 [ 565003F326F99802E68CA78F2A68E9FF ] Disk D:\Windows\system32\DRIVERS\disk.sys 21:33:53.0270 6112 Disk - ok 21:33:53.0310 6112 [ D0722E963D3C6145446874241401B209 ] Dnscache D:\Windows\System32\dnsrslvr.dll 21:33:53.0360 6112 Dnscache - ok 21:33:53.0380 6112 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc D:\Windows\System32\dot3svc.dll 21:33:53.0410 6112 dot3svc - ok 21:33:53.0430 6112 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS D:\Windows\system32\dps.dll 21:33:53.0470 6112 DPS - ok 21:33:53.0520 6112 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud D:\Windows\system32\drivers\drmkaud.sys 21:33:53.0560 6112 drmkaud - ok 21:33:53.0590 6112 [ 39806CFEDDCC55E686A49BCCD2972F23 ] DXGKrnl D:\Windows\System32\drivers\dxgkrnl.sys 21:33:53.0640 6112 DXGKrnl - ok 21:33:53.0680 6112 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost D:\Windows\System32\eapsvc.dll 21:33:53.0720 6112 EapHost - ok 21:33:53.0810 6112 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv D:\Windows\system32\DRIVERS\evbdx.sys 21:33:53.0890 6112 ebdrv - ok 21:33:53.0920 6112 [ F42309C4191C506B71DB5D1126D26318 ] EFS D:\Windows\System32\lsass.exe 21:33:53.0940 6112 EFS - ok 21:33:54.0020 6112 [ 3A74A6E33685662B125A3269B1F2114F ] ehRecvr D:\Windows\ehome\ehRecvr.exe 21:33:54.0080 6112 ehRecvr - ok 21:33:54.0090 6112 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched D:\Windows\ehome\ehsched.exe 21:33:54.0120 6112 ehSched - ok 21:33:54.0140 6112 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor D:\Windows\system32\DRIVERS\elxstor.sys 21:33:54.0160 6112 elxstor - ok 21:33:54.0180 6112 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev D:\Windows\system32\DRIVERS\errdev.sys 21:33:54.0210 6112 ErrDev - ok 21:33:54.0280 6112 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem D:\Windows\system32\es.dll 21:33:54.0330 6112 EventSystem - ok 21:33:54.0350 6112 [ 2DC9108D74081149CC8B651D3A26207F ] exfat D:\Windows\system32\drivers\exfat.sys 21:33:54.0380 6112 exfat - ok 21:33:54.0390 6112 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat D:\Windows\system32\drivers\fastfat.sys 21:33:54.0430 6112 fastfat - ok 21:33:54.0500 6112 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax D:\Windows\system32\fxssvc.exe 21:33:54.0520 6112 Fax - ok 21:33:54.0540 6112 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc D:\Windows\system32\DRIVERS\fdc.sys 21:33:54.0560 6112 fdc - ok 21:33:54.0590 6112 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost D:\Windows\system32\fdPHost.dll 21:33:54.0650 6112 fdPHost - ok 21:33:54.0670 6112 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub D:\Windows\system32\fdrespub.dll 21:33:54.0690 6112 FDResPub - ok 21:33:54.0700 6112 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo D:\Windows\system32\drivers\fileinfo.sys 21:33:54.0720 6112 FileInfo - ok 21:33:54.0730 6112 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace D:\Windows\system32\drivers\filetrace.sys 21:33:54.0750 6112 Filetrace - ok 21:33:54.0760 6112 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk D:\Windows\system32\DRIVERS\flpydisk.sys 21:33:54.0790 6112 flpydisk - ok 21:33:54.0820 6112 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr D:\Windows\system32\drivers\fltmgr.sys 21:33:54.0830 6112 FltMgr - ok 21:33:54.0860 6112 [ B6512A85815FDC3D560C3705F5BDB93D ] FontCache D:\Windows\system32\FntCache.dll 21:33:54.0890 6112 FontCache - ok 21:33:54.0970 6112 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 D:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 21:33:54.0980 6112 FontCache3.0.0.0 - ok 21:33:55.0000 6112 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends D:\Windows\system32\drivers\FsDepends.sys 21:33:55.0010 6112 FsDepends - ok 21:33:55.0020 6112 [ A574B4360E438977038AAE4BF60D79A2 ] Fs_Rec D:\Windows\system32\drivers\Fs_Rec.sys 21:33:55.0030 6112 Fs_Rec - ok 21:33:55.0050 6112 [ 5592F5DBA26282D24D2B080EB438A4D7 ] fvevol D:\Windows\system32\DRIVERS\fvevol.sys 21:33:55.0060 6112 fvevol - ok 21:33:55.0100 6112 [ FC06A5BE1AB381CD47AF3D69006E88F0 ] fwlanusbn D:\Windows\system32\DRIVERS\fwlanusbn.sys 21:33:55.0150 6112 fwlanusbn - ok 21:33:55.0170 6112 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx D:\Windows\system32\DRIVERS\gagp30kx.sys 21:33:55.0180 6112 gagp30kx - ok 21:33:55.0200 6112 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc D:\Windows\System32\gpsvc.dll 21:33:55.0220 6112 gpsvc - ok 21:33:55.0250 6112 [ 833051C6C6C42117191935F734CFBD97 ] hamachi D:\Windows\system32\DRIVERS\hamachi.sys 21:33:55.0260 6112 hamachi - ok 21:33:55.0300 6112 [ 4F30AA406AC4C6FA1552C32DEE9539DF ] Hamachi2Svc D:\Program Files\LogMeIn Hamachi\hamachi-2.exe 21:33:55.0340 6112 Hamachi2Svc - ok 21:33:55.0360 6112 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir D:\Windows\system32\drivers\hcw85cir.sys 21:33:55.0410 6112 hcw85cir - ok 21:33:55.0460 6112 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService D:\Windows\system32\drivers\HdAudio.sys 21:33:55.0510 6112 HdAudAddService - ok 21:33:55.0540 6112 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus D:\Windows\system32\DRIVERS\HDAudBus.sys 21:33:55.0550 6112 HDAudBus - ok 21:33:55.0560 6112 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt D:\Windows\system32\DRIVERS\HidBatt.sys 21:33:55.0590 6112 HidBatt - ok 21:33:55.0610 6112 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth D:\Windows\system32\DRIVERS\hidbth.sys 21:33:55.0640 6112 HidBth - ok 21:33:55.0670 6112 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr D:\Windows\system32\DRIVERS\hidir.sys 21:33:55.0680 6112 HidIr - ok 21:33:55.0700 6112 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv D:\Windows\system32\hidserv.dll 21:33:55.0720 6112 hidserv - ok 21:33:55.0760 6112 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb D:\Windows\system32\DRIVERS\hidusb.sys 21:33:55.0780 6112 HidUsb - ok 21:33:55.0820 6112 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc D:\Windows\system32\kmsvc.dll 21:33:55.0860 6112 hkmsvc - ok 21:33:55.0880 6112 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener D:\Windows\system32\ListSvc.dll 21:33:55.0910 6112 HomeGroupListener - ok 21:33:55.0950 6112 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider D:\Windows\system32\provsvc.dll 21:33:55.0980 6112 HomeGroupProvider - ok 21:33:56.0050 6112 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD D:\Windows\system32\DRIVERS\HpSAMD.sys 21:33:56.0060 6112 HpSAMD - ok 21:33:56.0090 6112 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP D:\Windows\system32\drivers\HTTP.sys 21:33:56.0120 6112 HTTP - ok 21:33:56.0140 6112 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy D:\Windows\system32\drivers\hwpolicy.sys 21:33:56.0150 6112 hwpolicy - ok 21:33:56.0170 6112 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt D:\Windows\system32\DRIVERS\i8042prt.sys 21:33:56.0200 6112 i8042prt - ok 21:33:56.0230 6112 [ 934AF4D7C5F457B9F0743F4299B77B67 ] iaStorV D:\Windows\system32\DRIVERS\iaStorV.sys 21:33:56.0250 6112 iaStorV - ok 21:33:56.0320 6112 [ 8B672417438380704E6A39B2F9D78EE8 ] IB Updater D:\Program Files\IB Updater\ExtensionUpdaterService.exe 21:33:56.0330 6112 IB Updater - ok 21:33:56.0380 6112 [ 7A95A3AD931B97FEC5067E40636CE37F ] ICQ Service D:\Program Files\ICQ6Toolbar\ICQ Service.exe 21:33:56.0400 6112 ICQ Service - ok 21:33:56.0470 6112 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc D:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 21:33:56.0490 6112 idsvc - ok 21:33:56.0520 6112 [ 4173FF5708F3236CF25195FECD742915 ] iirsp D:\Windows\system32\DRIVERS\iirsp.sys 21:33:56.0530 6112 iirsp - ok 21:33:56.0580 6112 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT D:\Windows\System32\ikeext.dll 21:33:56.0610 6112 IKEEXT - ok 21:33:56.0620 6112 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide D:\Windows\system32\DRIVERS\intelide.sys 21:33:56.0630 6112 intelide - ok 21:33:56.0660 6112 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm D:\Windows\system32\DRIVERS\intelppm.sys 21:33:56.0690 6112 intelppm - ok 21:33:56.0690 6112 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum D:\Windows\system32\ipbusenum.dll 21:33:56.0720 6112 IPBusEnum - ok 21:33:56.0740 6112 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver D:\Windows\system32\DRIVERS\ipfltdrv.sys 21:33:56.0760 6112 IpFilterDriver - ok 21:33:56.0780 6112 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc D:\Windows\System32\iphlpsvc.dll 21:33:56.0830 6112 iphlpsvc - ok 21:33:56.0840 6112 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV D:\Windows\system32\DRIVERS\IPMIDrv.sys 21:33:56.0850 6112 IPMIDRV - ok 21:33:56.0850 6112 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT D:\Windows\system32\drivers\ipnat.sys 21:33:56.0880 6112 IPNAT - ok 21:33:56.0920 6112 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM D:\Windows\system32\drivers\irenum.sys 21:33:56.0930 6112 IRENUM - ok 21:33:56.0940 6112 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp D:\Windows\system32\DRIVERS\isapnp.sys 21:33:56.0950 6112 isapnp - ok 21:33:56.0990 6112 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt D:\Windows\system32\DRIVERS\msiscsi.sys 21:33:57.0010 6112 iScsiPrt - ok 21:33:57.0040 6112 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass D:\Windows\system32\DRIVERS\kbdclass.sys 21:33:57.0050 6112 kbdclass - ok 21:33:57.0080 6112 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid D:\Windows\system32\DRIVERS\kbdhid.sys 21:33:57.0110 6112 kbdhid - ok 21:33:57.0130 6112 [ F42309C4191C506B71DB5D1126D26318 ] KeyIso D:\Windows\system32\lsass.exe 21:33:57.0150 6112 KeyIso - ok 21:33:57.0190 6112 [ 94D67D49BD9503BB1D838405D80F2058 ] KL1 D:\Windows\system32\DRIVERS\kl1.sys 21:33:57.0200 6112 KL1 - ok 21:33:57.0220 6112 [ 713576569667AC9E0F8556076004A96B ] kl2 D:\Windows\system32\DRIVERS\kl2.sys 21:33:57.0230 6112 kl2 - ok 21:33:57.0270 6112 [ 39920D69EAEDB51757527AA54FE25216 ] KLIF D:\Windows\system32\DRIVERS\klif.sys 21:33:57.0290 6112 KLIF - ok 21:33:57.0320 6112 [ CF88B4985D957EEE45C9939092E87C92 ] KLIM6 D:\Windows\system32\DRIVERS\klim6.sys 21:33:57.0330 6112 KLIM6 - ok 21:33:57.0340 6112 [ 3DE1771C135328420315E21DDE229BBA ] klmouflt D:\Windows\system32\DRIVERS\klmouflt.sys 21:33:57.0340 6112 klmouflt - ok 21:33:57.0360 6112 [ E36A061EC11B373826905B21BE10948F ] KSecDD D:\Windows\system32\Drivers\ksecdd.sys 21:33:57.0370 6112 KSecDD - ok 21:33:57.0390 6112 [ 26C046977E85B95036453D7B88BA1820 ] KSecPkg D:\Windows\system32\Drivers\ksecpkg.sys 21:33:57.0400 6112 KSecPkg - ok 21:33:57.0450 6112 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm D:\Windows\system32\msdtckrm.dll 21:33:57.0500 6112 KtmRm - ok 21:33:57.0570 6112 [ BCA92CB047A4326925ECEF759DBAA233 ] LanmanServer D:\Windows\system32\srvsvc.dll 21:33:57.0630 6112 LanmanServer - ok 21:33:57.0710 6112 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation D:\Windows\System32\wkssvc.dll 21:33:57.0760 6112 LanmanWorkstation - ok 21:33:57.0790 6112 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio D:\Windows\system32\DRIVERS\lltdio.sys 21:33:57.0840 6112 lltdio - ok 21:33:57.0860 6112 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc D:\Windows\System32\lltdsvc.dll 21:33:57.0890 6112 lltdsvc - ok 21:33:57.0900 6112 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts D:\Windows\System32\lmhsvc.dll 21:33:57.0950 6112 lmhosts - ok 21:33:57.0970 6112 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC D:\Windows\system32\DRIVERS\lsi_fc.sys 21:33:57.0990 6112 LSI_FC - ok 21:33:58.0000 6112 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS D:\Windows\system32\DRIVERS\lsi_sas.sys 21:33:58.0010 6112 LSI_SAS - ok 21:33:58.0020 6112 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 D:\Windows\system32\DRIVERS\lsi_sas2.sys 21:33:58.0030 6112 LSI_SAS2 - ok 21:33:58.0050 6112 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI D:\Windows\system32\DRIVERS\lsi_scsi.sys 21:33:58.0060 6112 LSI_SCSI - ok 21:33:58.0070 6112 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv D:\Windows\system32\drivers\luafv.sys 21:33:58.0120 6112 luafv - ok 21:33:58.0170 6112 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector D:\Windows\system32\drivers\mbam.sys 21:33:58.0190 6112 MBAMProtector - ok 21:33:58.0240 6112 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 21:33:58.0260 6112 MBAMScheduler - ok 21:33:58.0290 6112 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 21:33:58.0310 6112 MBAMService - ok 21:33:58.0360 6112 [ 034606B82FA5BD3E73AB427B6D55F915 ] McComponentHostService D:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe 21:33:58.0370 6112 McComponentHostService - ok 21:33:58.0420 6112 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc D:\Windows\system32\Mcx2Svc.dll 21:33:58.0430 6112 Mcx2Svc - ok 21:33:58.0440 6112 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas D:\Windows\system32\DRIVERS\megasas.sys 21:33:58.0450 6112 megasas - ok 21:33:58.0470 6112 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR D:\Windows\system32\DRIVERS\MegaSR.sys 21:33:58.0480 6112 MegaSR - ok 21:33:58.0520 6112 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS D:\Windows\system32\mmcss.dll 21:33:58.0550 6112 MMCSS - ok 21:33:58.0560 6112 [ F001861E5700EE84E2D4E52C712F4964 ] Modem D:\Windows\system32\drivers\modem.sys 21:33:58.0600 6112 Modem - ok 21:33:58.0660 6112 [ 79D10964DE86B292320E9DFE02282A23 ] monitor D:\Windows\system32\DRIVERS\monitor.sys 21:33:58.0690 6112 monitor - ok 21:33:58.0720 6112 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass D:\Windows\system32\DRIVERS\mouclass.sys 21:33:58.0730 6112 mouclass - ok 21:33:58.0760 6112 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid D:\Windows\system32\DRIVERS\mouhid.sys 21:33:58.0790 6112 mouhid - ok 21:33:58.0810 6112 [ 921C18727C5920D6C0300736646931C2 ] mountmgr D:\Windows\system32\drivers\mountmgr.sys 21:33:58.0820 6112 mountmgr - ok 21:33:58.0870 6112 [ 730A519505621DF46BCBF9CDAC9FB6AD ] MozillaMaintenance D:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 21:33:58.0880 6112 MozillaMaintenance - ok 21:33:58.0900 6112 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio D:\Windows\system32\DRIVERS\mpio.sys 21:33:58.0920 6112 mpio - ok 21:33:58.0930 6112 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv D:\Windows\system32\drivers\mpsdrv.sys 21:33:58.0960 6112 mpsdrv - ok 21:33:59.0000 6112 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc D:\Windows\system32\mpssvc.dll 21:33:59.0030 6112 MpsSvc - ok 21:33:59.0040 6112 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV D:\Windows\system32\drivers\mrxdav.sys 21:33:59.0060 6112 MRxDAV - ok 21:33:59.0080 6112 [ F4A054BE78AF7F410129C4B64B07DC9B ] mrxsmb D:\Windows\system32\DRIVERS\mrxsmb.sys 21:33:59.0130 6112 mrxsmb - ok 21:33:59.0150 6112 [ DEFFA295BD1895C6ED8E3078412AC60B ] mrxsmb10 D:\Windows\system32\DRIVERS\mrxsmb10.sys 21:33:59.0190 6112 mrxsmb10 - ok 21:33:59.0220 6112 [ 24D76ABE5DCAD22F19D105F76FDF0CE1 ] mrxsmb20 D:\Windows\system32\DRIVERS\mrxsmb20.sys 21:33:59.0240 6112 mrxsmb20 - ok 21:33:59.0260 6112 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci D:\Windows\system32\DRIVERS\msahci.sys 21:33:59.0270 6112 msahci - ok 21:33:59.0290 6112 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm D:\Windows\system32\DRIVERS\msdsm.sys 21:33:59.0300 6112 msdsm - ok 21:33:59.0340 6112 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC D:\Windows\System32\msdtc.exe 21:33:59.0370 6112 MSDTC - ok 21:33:59.0430 6112 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs D:\Windows\system32\drivers\Msfs.sys 21:33:59.0450 6112 Msfs - ok 21:33:59.0460 6112 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf D:\Windows\System32\drivers\mshidkmdf.sys 21:33:59.0510 6112 mshidkmdf - ok 21:33:59.0530 6112 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv D:\Windows\system32\DRIVERS\msisadrv.sys 21:33:59.0540 6112 msisadrv - ok 21:33:59.0590 6112 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI D:\Windows\system32\iscsiexe.dll 21:33:59.0620 6112 MSiSCSI - ok 21:33:59.0620 6112 msiserver - ok 21:33:59.0640 6112 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV D:\Windows\system32\drivers\MSKSSRV.sys 21:33:59.0680 6112 MSKSSRV - ok 21:33:59.0700 6112 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK D:\Windows\system32\drivers\MSPCLOCK.sys 21:33:59.0730 6112 MSPCLOCK - ok 21:33:59.0740 6112 [ F456E973590D663B1073E9C463B40932 ] MSPQM D:\Windows\system32\drivers\MSPQM.sys 21:33:59.0780 6112 MSPQM - ok 21:33:59.0800 6112 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC D:\Windows\system32\drivers\MsRPC.sys 21:33:59.0810 6112 MsRPC - ok 21:33:59.0830 6112 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios D:\Windows\system32\DRIVERS\mssmbios.sys 21:33:59.0840 6112 mssmbios - ok 21:33:59.0860 6112 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE D:\Windows\system32\drivers\MSTEE.sys 21:33:59.0880 6112 MSTEE - ok 21:33:59.0890 6112 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig D:\Windows\system32\DRIVERS\MTConfig.sys 21:33:59.0920 6112 MTConfig - ok 21:33:59.0940 6112 [ 159FAD02F64E6381758C990F753BCC80 ] Mup D:\Windows\system32\Drivers\mup.sys 21:33:59.0950 6112 Mup - ok 21:33:59.0990 6112 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent D:\Windows\system32\qagentRT.dll 21:34:00.0020 6112 napagent - ok 21:34:00.0050 6112 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP D:\Windows\system32\DRIVERS\nwifi.sys 21:34:00.0080 6112 NativeWifiP - ok 21:34:00.0130 6112 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS D:\Windows\system32\drivers\ndis.sys 21:34:00.0150 6112 NDIS - ok 21:34:00.0150 6112 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap D:\Windows\system32\DRIVERS\ndiscap.sys 21:34:00.0180 6112 NdisCap - ok 21:34:00.0200 6112 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi D:\Windows\system32\DRIVERS\ndistapi.sys 21:34:00.0220 6112 NdisTapi - ok 21:34:00.0240 6112 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio D:\Windows\system32\DRIVERS\ndisuio.sys 21:34:00.0260 6112 Ndisuio - ok 21:34:00.0280 6112 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan D:\Windows\system32\DRIVERS\ndiswan.sys 21:34:00.0300 6112 NdisWan - ok 21:34:00.0320 6112 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy D:\Windows\system32\drivers\NDProxy.sys 21:34:00.0340 6112 NDProxy - ok 21:34:00.0350 6112 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS D:\Windows\system32\DRIVERS\netbios.sys 21:34:00.0370 6112 NetBIOS - ok 21:34:00.0380 6112 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT D:\Windows\system32\DRIVERS\netbt.sys 21:34:00.0410 6112 NetBT - ok 21:34:00.0420 6112 [ F42309C4191C506B71DB5D1126D26318 ] Netlogon D:\Windows\system32\lsass.exe 21:34:00.0430 6112 Netlogon - ok 21:34:00.0490 6112 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman D:\Windows\System32\netman.dll 21:34:00.0550 6112 Netman - ok 21:34:00.0580 6112 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator D:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 21:34:00.0600 6112 NetMsmqActivator - ok 21:34:00.0610 6112 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator D:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 21:34:00.0620 6112 NetPipeActivator - ok 21:34:00.0620 6112 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm D:\Windows\System32\netprofm.dll 21:34:00.0670 6112 netprofm - ok 21:34:00.0680 6112 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator D:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 21:34:00.0690 6112 NetTcpActivator - ok 21:34:00.0700 6112 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing D:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 21:34:00.0710 6112 NetTcpPortSharing - ok 21:34:00.0740 6112 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 D:\Windows\system32\DRIVERS\nfrd960.sys 21:34:00.0750 6112 nfrd960 - ok 21:34:00.0770 6112 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc D:\Windows\System32\nlasvc.dll 21:34:00.0790 6112 NlaSvc - ok 21:34:00.0810 6112 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs D:\Windows\system32\drivers\Npfs.sys 21:34:00.0830 6112 Npfs - ok 21:34:00.0870 6112 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi D:\Windows\system32\nsisvc.dll 21:34:00.0900 6112 nsi - ok 21:34:00.0910 6112 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy D:\Windows\system32\drivers\nsiproxy.sys 21:34:00.0950 6112 nsiproxy - ok 21:34:01.0000 6112 [ 3795DCD21F740EE799FB7223234215AF ] Ntfs D:\Windows\system32\drivers\Ntfs.sys 21:34:01.0030 6112 Ntfs - ok 21:34:01.0040 6112 [ F9756A98D69098DCA8945D62858A812C ] Null D:\Windows\system32\drivers\Null.sys 21:34:01.0070 6112 Null - ok 21:34:01.0140 6112 [ B5E37E31C053BC9950455A257526514B ] NVENETFD D:\Windows\system32\DRIVERS\nvm62x32.sys 21:34:01.0150 6112 NVENETFD - ok 21:34:01.0360 6112 [ C1E661888C719FC2E12C057F233FB238 ] nvlddmkm D:\Windows\system32\DRIVERS\nvlddmkm.sys 21:34:01.0540 6112 nvlddmkm - ok 21:34:01.0560 6112 [ 3F3D04B1D08D43C16EA7963954EC768D ] nvraid D:\Windows\system32\DRIVERS\nvraid.sys 21:34:01.0570 6112 nvraid - ok 21:34:01.0590 6112 [ C99F251A5DE63C6F129CF71933ACED0F ] nvstor D:\Windows\system32\DRIVERS\nvstor.sys 21:34:01.0600 6112 nvstor - ok 21:34:01.0640 6112 [ 31D7E63B62BC4680B5D1358F91DA104E ] nvsvc D:\Windows\system32\nvvsvc.exe 21:34:01.0660 6112 nvsvc - ok 21:34:01.0740 6112 [ 143B429F2D19A0F123ED8E4BCA8DB751 ] nvUpdatusService D:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 21:34:01.0770 6112 nvUpdatusService - ok 21:34:01.0780 6112 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp D:\Windows\system32\DRIVERS\nv_agp.sys 21:34:01.0790 6112 nv_agp - ok 21:34:01.0810 6112 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 D:\Windows\system32\DRIVERS\ohci1394.sys 21:34:01.0820 6112 ohci1394 - ok 21:34:01.0880 6112 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc D:\Windows\system32\pnrpsvc.dll 21:34:01.0910 6112 p2pimsvc - ok 21:34:01.0930 6112 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc D:\Windows\system32\p2psvc.dll 21:34:01.0970 6112 p2psvc - ok 21:34:02.0000 6112 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport D:\Windows\system32\DRIVERS\parport.sys 21:34:02.0010 6112 Parport - ok 21:34:02.0020 6112 [ FF4218952B51DE44FE910953A3E686B9 ] partmgr D:\Windows\system32\drivers\partmgr.sys 21:34:02.0040 6112 partmgr - ok 21:34:02.0040 6112 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm D:\Windows\system32\DRIVERS\parvdm.sys 21:34:02.0060 6112 Parvdm - ok 21:34:02.0070 6112 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc D:\Windows\System32\pcasvc.dll 21:34:02.0090 6112 PcaSvc - ok 21:34:02.0100 6112 [ C858CB77C577780ECC456A892E7E7D0F ] pci D:\Windows\system32\DRIVERS\pci.sys 21:34:02.0110 6112 pci - ok 21:34:02.0120 6112 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide D:\Windows\system32\DRIVERS\pciide.sys 21:34:02.0130 6112 pciide - ok 21:34:02.0140 6112 [ F396431B31693E71E8A80687EF523506 ] pcmcia D:\Windows\system32\DRIVERS\pcmcia.sys 21:34:02.0160 6112 pcmcia - ok 21:34:02.0170 6112 [ 250F6B43D2B613172035C6747AEEB19F ] pcw D:\Windows\system32\drivers\pcw.sys 21:34:02.0180 6112 pcw - ok 21:34:02.0220 6112 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH D:\Windows\system32\drivers\peauth.sys 21:34:02.0270 6112 PEAUTH - ok 21:34:02.0340 6112 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc D:\Windows\system32\peerdistsvc.dll 21:34:02.0400 6112 PeerDistSvc - ok 21:34:02.0440 6112 [ 9C1BFF7910C89A1D12E57343475840CB ] pla D:\Windows\system32\pla.dll 21:34:02.0490 6112 pla - ok 21:34:02.0540 6112 [ 2CC2008F1296968FBA162ED9F9AFE328 ] PlugPlay D:\Windows\system32\umpnpmgr.dll 21:34:02.0590 6112 PlugPlay - ok 21:34:02.0650 6112 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA D:\Windows\system32\PnkBstrA.exe 21:34:02.0660 6112 PnkBstrA - ok 21:34:02.0670 6112 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg D:\Windows\system32\pnrpauto.dll 21:34:02.0690 6112 PNRPAutoReg - ok 21:34:02.0700 6112 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc D:\Windows\system32\pnrpsvc.dll 21:34:02.0720 6112 PNRPsvc - ok 21:34:02.0770 6112 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent D:\Windows\System32\ipsecsvc.dll 21:34:02.0810 6112 PolicyAgent - ok 21:34:02.0840 6112 [ DBFF83F709A91049621C1D35DD45C92C ] Power D:\Windows\system32\umpo.dll 21:34:02.0860 6112 Power - ok 21:34:02.0910 6112 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport D:\Windows\system32\DRIVERS\raspptp.sys 21:34:02.0940 6112 PptpMiniport - ok 21:34:02.0950 6112 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor D:\Windows\system32\DRIVERS\processr.sys 21:34:02.0980 6112 Processor - ok 21:34:03.0020 6112 [ 630CF26F0227498B7D5A92B12548960F ] ProfSvc D:\Windows\system32\profsvc.dll 21:34:03.0040 6112 ProfSvc - ok 21:34:03.0050 6112 [ F42309C4191C506B71DB5D1126D26318 ] ProtectedStorage D:\Windows\system32\lsass.exe 21:34:03.0070 6112 ProtectedStorage - ok 21:34:03.0090 6112 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched D:\Windows\system32\DRIVERS\pacer.sys 21:34:03.0110 6112 Psched - ok 21:34:03.0150 6112 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 D:\Windows\system32\DRIVERS\ql2300.sys 21:34:03.0190 6112 ql2300 - ok 21:34:03.0220 6112 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx D:\Windows\system32\DRIVERS\ql40xx.sys 21:34:03.0230 6112 ql40xx - ok 21:34:03.0280 6112 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE D:\Windows\system32\qwave.dll 21:34:03.0310 6112 QWAVE - ok 21:34:03.0330 6112 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv D:\Windows\system32\drivers\qwavedrv.sys 21:34:03.0340 6112 QWAVEdrv - ok 21:34:03.0360 6112 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd D:\Windows\system32\DRIVERS\rasacd.sys 21:34:03.0380 6112 RasAcd - ok 21:34:03.0400 6112 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn D:\Windows\system32\DRIVERS\AgileVpn.sys 21:34:03.0440 6112 RasAgileVpn - ok 21:34:03.0470 6112 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto D:\Windows\System32\rasauto.dll 21:34:03.0490 6112 RasAuto - ok 21:34:03.0510 6112 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp D:\Windows\system32\DRIVERS\rasl2tp.sys 21:34:03.0550 6112 Rasl2tp - ok 21:34:03.0580 6112 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan D:\Windows\System32\rasmans.dll 21:34:03.0640 6112 RasMan - ok 21:34:03.0650 6112 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe D:\Windows\system32\DRIVERS\raspppoe.sys 21:34:03.0700 6112 RasPppoe - ok 21:34:03.0710 6112 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp D:\Windows\system32\DRIVERS\rassstp.sys 21:34:03.0760 6112 RasSstp - ok 21:34:03.0770 6112 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss D:\Windows\system32\DRIVERS\rdbss.sys 21:34:03.0810 6112 rdbss - ok 21:34:03.0830 6112 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus D:\Windows\system32\DRIVERS\rdpbus.sys 21:34:03.0870 6112 rdpbus - ok 21:34:03.0890 6112 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD D:\Windows\system32\DRIVERS\RDPCDD.sys 21:34:03.0910 6112 RDPCDD - ok 21:34:03.0970 6112 [ C5FF95883FFEF704D50C40D21CFB3AB5 ] RDPDR D:\Windows\system32\drivers\rdpdr.sys 21:34:04.0020 6112 RDPDR - ok 21:34:04.0050 6112 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD D:\Windows\system32\drivers\rdpencdd.sys 21:34:04.0070 6112 RDPENCDD - ok 21:34:04.0090 6112 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP D:\Windows\system32\drivers\rdprefmp.sys 21:34:04.0130 6112 RDPREFMP - ok 21:34:04.0150 6112 [ 801371BA9782282892D00AADB08EE367 ] RDPWD D:\Windows\system32\drivers\RDPWD.sys 21:34:04.0180 6112 RDPWD - ok 21:34:04.0200 6112 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost D:\Windows\system32\drivers\rdyboost.sys 21:34:04.0210 6112 rdyboost - ok 21:34:04.0260 6112 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess D:\Windows\System32\mprdim.dll 21:34:04.0300 6112 RemoteAccess - ok 21:34:04.0330 6112 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry D:\Windows\system32\regsvc.dll 21:34:04.0360 6112 RemoteRegistry - ok 21:34:04.0370 6112 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper D:\Windows\System32\RpcEpMap.dll 21:34:04.0410 6112 RpcEptMapper - ok 21:34:04.0440 6112 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator D:\Windows\system32\locator.exe 21:34:04.0460 6112 RpcLocator - ok 21:34:04.0490 6112 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs D:\Windows\system32\rpcss.dll 21:34:04.0520 6112 RpcSs - ok 21:34:04.0540 6112 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr D:\Windows\system32\DRIVERS\rspndr.sys 21:34:04.0580 6112 rspndr - ok 21:34:04.0610 6112 [ 5423D8437051E89DD34749F242C98648 ] s3cap D:\Windows\system32\DRIVERS\vms3cap.sys 21:34:04.0640 6112 s3cap - ok 21:34:04.0650 6112 [ F42309C4191C506B71DB5D1126D26318 ] SamSs D:\Windows\system32\lsass.exe 21:34:04.0670 6112 SamSs - ok 21:34:04.0700 6112 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port D:\Windows\system32\DRIVERS\sbp2port.sys 21:34:04.0710 6112 sbp2port - ok 21:34:04.0750 6112 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr D:\Windows\System32\SCardSvr.dll 21:34:04.0790 6112 SCardSvr - ok 21:34:04.0800 6112 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter D:\Windows\system32\DRIVERS\scfilter.sys 21:34:04.0850 6112 scfilter - ok 21:34:04.0880 6112 [ 3E8B0C453E25613A1F59762A5C42AA75 ] Schedule D:\Windows\system32\schedsvc.dll 21:34:04.0940 6112 Schedule - ok 21:34:04.0960 6112 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc D:\Windows\System32\certprop.dll 21:34:04.0980 6112 SCPolicySvc - ok 21:34:05.0000 6112 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC D:\Windows\System32\SDRSVC.dll 21:34:05.0060 6112 SDRSVC - ok 21:34:05.0080 6112 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv D:\Windows\system32\drivers\secdrv.sys 21:34:05.0120 6112 secdrv - ok 21:34:05.0140 6112 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon D:\Windows\system32\seclogon.dll 21:34:05.0180 6112 seclogon - ok 21:34:05.0210 6112 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS D:\Windows\System32\sens.dll 21:34:05.0250 6112 SENS - ok 21:34:05.0290 6112 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc D:\Windows\system32\sensrsvc.dll 21:34:05.0330 6112 SensrSvc - ok 21:34:05.0360 6112 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum D:\Windows\system32\DRIVERS\serenum.sys 21:34:05.0370 6112 Serenum - ok 21:34:05.0380 6112 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial D:\Windows\system32\DRIVERS\serial.sys 21:34:05.0400 6112 Serial - ok 21:34:05.0410 6112 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse D:\Windows\system32\DRIVERS\sermouse.sys 21:34:05.0430 6112 sermouse - ok 21:34:05.0500 6112 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv D:\Windows\system32\sessenv.dll 21:34:05.0540 6112 SessionEnv - ok 21:34:05.0560 6112 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk D:\Windows\system32\DRIVERS\sffdisk.sys 21:34:05.0570 6112 sffdisk - ok 21:34:05.0580 6112 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc D:\Windows\system32\DRIVERS\sffp_mmc.sys 21:34:05.0610 6112 sffp_mmc - ok 21:34:05.0630 6112 [ 4F1E5B0FE7C8050668DBFADE8999AEFB ] sffp_sd D:\Windows\system32\DRIVERS\sffp_sd.sys 21:34:05.0650 6112 sffp_sd - ok 21:34:05.0660 6112 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy D:\Windows\system32\DRIVERS\sfloppy.sys 21:34:05.0680 6112 sfloppy - ok 21:34:05.0710 6112 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess D:\Windows\System32\ipnathlp.dll 21:34:05.0730 6112 SharedAccess - ok 21:34:05.0750 6112 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection D:\Windows\System32\shsvcs.dll 21:34:05.0770 6112 ShellHWDetection - ok 21:34:05.0820 6112 [ 58E0E3E21227D6C1F7D0C149568759D8 ] Simraceway Update Service D:\Program Files\SimracewayUpdater\SRWUpdate.exe 21:34:05.0840 6112 Simraceway Update Service ( UnsignedFile.Multi.Generic ) - warning 21:34:05.0840 6112 Simraceway Update Service - detected UnsignedFile.Multi.Generic (1) 21:34:05.0850 6112 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp D:\Windows\system32\DRIVERS\sisagp.sys 21:34:05.0860 6112 sisagp - ok 21:34:05.0880 6112 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 D:\Windows\system32\DRIVERS\SiSRaid2.sys 21:34:05.0900 6112 SiSRaid2 - ok 21:34:05.0950 6112 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 D:\Windows\system32\DRIVERS\sisraid4.sys 21:34:05.0960 6112 SiSRaid4 - ok 21:34:05.0990 6112 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb D:\Windows\system32\DRIVERS\smb.sys 21:34:06.0010 6112 Smb - ok 21:34:06.0070 6112 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP D:\Windows\System32\snmptrap.exe 21:34:06.0090 6112 SNMPTRAP - ok 21:34:06.0100 6112 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr D:\Windows\system32\drivers\spldr.sys 21:34:06.0120 6112 spldr - ok 21:34:06.0150 6112 [ 49B6DD6AB3715B7A67965F17194E98A9 ] Spooler D:\Windows\System32\spoolsv.exe 21:34:06.0170 6112 Spooler - ok 21:34:06.0240 6112 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc D:\Windows\system32\sppsvc.exe 21:34:06.0300 6112 sppsvc - ok 21:34:06.0310 6112 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify D:\Windows\system32\sppuinotify.dll 21:34:06.0340 6112 sppuinotify - ok 21:34:06.0760 6112 [ 4EDA91FF8EEE2196229AACCCC9F6952C ] SProtection D:\Program Files\Common Files\Umbrella\Umbrella.exe 21:34:06.0890 6112 SProtection - ok 21:34:06.0990 6112 [ 2BA4EBC7DFBA845A1EDBE1F75913BE33 ] srv D:\Windows\system32\DRIVERS\srv.sys 21:34:07.0040 6112 srv - ok 21:34:07.0050 6112 [ DCE7E10FEAABD4CAE95948B3DE5340BB ] srv2 D:\Windows\system32\DRIVERS\srv2.sys 21:34:07.0080 6112 srv2 - ok 21:34:07.0090 6112 [ B5665BAA2120B8A54E22E9CD07C05106 ] srvnet D:\Windows\system32\DRIVERS\srvnet.sys 21:34:07.0120 6112 srvnet - ok 21:34:07.0160 6112 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV D:\Windows\System32\ssdpsrv.dll 21:34:07.0180 6112 SSDPSRV - ok 21:34:07.0200 6112 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc D:\Windows\system32\sstpsvc.dll 21:34:07.0220 6112 SstpSvc - ok 21:34:07.0270 6112 [ 0632004181860960CF6E10DE8DDEF78B ] Stereo Service D:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 21:34:07.0290 6112 Stereo Service - ok 21:34:07.0290 6112 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor D:\Windows\system32\DRIVERS\stexstor.sys 21:34:07.0300 6112 stexstor - ok 21:34:07.0360 6112 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc D:\Windows\System32\wiaservc.dll 21:34:07.0390 6112 StiSvc - ok 21:34:07.0430 6112 [ 957E346CA948668F2496A6CCF6FF82CC ] storflt D:\Windows\system32\DRIVERS\vmstorfl.sys 21:34:07.0450 6112 storflt - ok 21:34:07.0490 6112 [ D5751969DC3E4B88BF482AC8EC9FE019 ] storvsc D:\Windows\system32\DRIVERS\storvsc.sys 21:34:07.0500 6112 storvsc - ok 21:34:07.0500 6112 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum D:\Windows\system32\DRIVERS\swenum.sys 21:34:07.0510 6112 swenum - ok 21:34:07.0530 6112 [ A28BD92DF340E57B024BA433165D34D7 ] swprv D:\Windows\System32\swprv.dll 21:34:07.0580 6112 swprv - ok 21:34:07.0620 6112 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain D:\Windows\system32\sysmain.dll 21:34:07.0690 6112 SysMain - ok 21:34:07.0730 6112 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService D:\Windows\System32\TabSvc.dll 21:34:07.0750 6112 TabletInputService - ok 21:34:07.0770 6112 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv D:\Windows\System32\tapisrv.dll 21:34:07.0820 6112 TapiSrv - ok 21:34:07.0830 6112 [ B799D9FDB26111737F58288D8DC172D9 ] TBS D:\Windows\System32\tbssvc.dll 21:34:07.0860 6112 TBS - ok 21:34:07.0900 6112 [ 2CC3D75488ABD3EC628BBB9A4FC84EFC ] Tcpip D:\Windows\system32\drivers\tcpip.sys 21:34:07.0930 6112 Tcpip - ok 21:34:07.0950 6112 [ 2CC3D75488ABD3EC628BBB9A4FC84EFC ] TCPIP6 D:\Windows\system32\DRIVERS\tcpip.sys 21:34:07.0980 6112 TCPIP6 - ok 21:34:08.0000 6112 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg D:\Windows\system32\drivers\tcpipreg.sys 21:34:08.0040 6112 tcpipreg - ok 21:34:08.0060 6112 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE D:\Windows\system32\drivers\tdpipe.sys 21:34:08.0080 6112 TDPIPE - ok 21:34:08.0090 6112 [ 7551E91EA999EE9A8E9C331D5A9C31F3 ] TDTCP D:\Windows\system32\drivers\tdtcp.sys 21:34:08.0110 6112 TDTCP - ok 21:34:08.0130 6112 [ CB39E896A2A83702D1737BFD402B3542 ] tdx D:\Windows\system32\DRIVERS\tdx.sys 21:34:08.0150 6112 tdx - ok 21:34:08.0160 6112 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD D:\Windows\system32\DRIVERS\termdd.sys 21:34:08.0170 6112 TermDD - ok 21:34:08.0220 6112 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService D:\Windows\System32\termsrv.dll 21:34:08.0250 6112 TermService - ok 21:34:08.0270 6112 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes D:\Windows\system32\themeservice.dll 21:34:08.0280 6112 Themes - ok 21:34:08.0290 6112 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER D:\Windows\system32\mmcss.dll 21:34:08.0320 6112 THREADORDER - ok 21:34:08.0340 6112 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks D:\Windows\System32\trkwks.dll 21:34:08.0390 6112 TrkWks - ok 21:34:08.0460 6112 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller D:\Windows\servicing\TrustedInstaller.exe 21:34:08.0470 6112 TrustedInstaller - ok 21:34:08.0490 6112 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv D:\Windows\system32\DRIVERS\tssecsrv.sys 21:34:08.0510 6112 tssecsrv - ok 21:34:08.0540 6112 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel D:\Windows\system32\DRIVERS\tunnel.sys 21:34:08.0560 6112 tunnel - ok 21:34:08.0570 6112 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 D:\Windows\system32\DRIVERS\uagp35.sys 21:34:08.0590 6112 uagp35 - ok 21:34:08.0600 6112 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs D:\Windows\system32\DRIVERS\udfs.sys 21:34:08.0630 6112 udfs - ok 21:34:08.0680 6112 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect D:\Windows\system32\UI0Detect.exe 21:34:08.0720 6112 UI0Detect - ok 21:34:08.0760 6112 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx D:\Windows\system32\DRIVERS\uliagpkx.sys 21:34:08.0770 6112 uliagpkx - ok 21:34:08.0800 6112 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus D:\Windows\system32\DRIVERS\umbus.sys 21:34:08.0810 6112 umbus - ok 21:34:08.0840 6112 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass D:\Windows\system32\DRIVERS\umpass.sys 21:34:08.0850 6112 UmPass - ok 21:34:08.0910 6112 [ 8ECACA5454844F66386F7BE4AE0D7CD1 ] UmRdpService D:\Windows\System32\umrdp.dll 21:34:08.0920 6112 UmRdpService - ok 21:34:08.0970 6112 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost D:\Windows\System32\upnphost.dll 21:34:09.0000 6112 upnphost - ok 21:34:09.0020 6112 [ 8455C4ED038EFD09E99327F9D2D48FFA ] usbccgp D:\Windows\system32\DRIVERS\usbccgp.sys 21:34:09.0040 6112 usbccgp - ok 21:34:09.0050 6112 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir D:\Windows\system32\DRIVERS\usbcir.sys 21:34:09.0080 6112 usbcir - ok 21:34:09.0100 6112 [ 1C333BFD60F2FED2C7AD5DAF533CB742 ] usbehci D:\Windows\system32\DRIVERS\usbehci.sys 21:34:09.0130 6112 usbehci - ok 21:34:09.0160 6112 [ EE6EF93CCFA94FAE8C6AB298273D8AE2 ] usbhub D:\Windows\system32\DRIVERS\usbhub.sys 21:34:09.0180 6112 usbhub - ok 21:34:09.0200 6112 [ A6FB7957EA7AFB1165991E54CE934B74 ] usbohci D:\Windows\system32\DRIVERS\usbohci.sys 21:34:09.0210 6112 usbohci - ok 21:34:09.0230 6112 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint D:\Windows\system32\DRIVERS\usbprint.sys 21:34:09.0250 6112 usbprint - ok 21:34:09.0280 6112 [ D8889D56E0D27E57ED4591837FE71D27 ] USBSTOR D:\Windows\system32\DRIVERS\USBSTOR.SYS 21:34:09.0310 6112 USBSTOR - ok 21:34:09.0330 6112 [ 78780C3EBCE17405B1CCD07A3A8A7D72 ] usbuhci D:\Windows\system32\DRIVERS\usbuhci.sys 21:34:09.0360 6112 usbuhci - ok 21:34:09.0380 6112 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms D:\Windows\System32\uxsms.dll 21:34:09.0420 6112 UxSms - ok 21:34:09.0440 6112 [ F42309C4191C506B71DB5D1126D26318 ] VaultSvc D:\Windows\system32\lsass.exe 21:34:09.0450 6112 VaultSvc - ok 21:34:09.0470 6112 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot D:\Windows\system32\DRIVERS\vdrvroot.sys 21:34:09.0480 6112 vdrvroot - ok 21:34:09.0500 6112 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds D:\Windows\System32\vds.exe 21:34:09.0540 6112 vds - ok 21:34:09.0570 6112 [ 17C408214EA61696CEC9C66E388B14F3 ] vga D:\Windows\system32\DRIVERS\vgapnp.sys 21:34:09.0580 6112 vga - ok 21:34:09.0600 6112 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave D:\Windows\System32\drivers\vga.sys 21:34:09.0640 6112 VgaSave - ok 21:34:09.0670 6112 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp D:\Windows\system32\DRIVERS\vhdmp.sys 21:34:09.0690 6112 vhdmp - ok 21:34:09.0740 6112 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp D:\Windows\system32\DRIVERS\viaagp.sys 21:34:09.0760 6112 viaagp - ok 21:34:09.0770 6112 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 D:\Windows\system32\DRIVERS\viac7.sys 21:34:09.0800 6112 ViaC7 - ok 21:34:09.0820 6112 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide D:\Windows\system32\DRIVERS\viaide.sys 21:34:09.0840 6112 viaide - ok 21:34:09.0900 6112 [ 379B349F65F453D2A6E75EA6B7448E49 ] vmbus D:\Windows\system32\DRIVERS\vmbus.sys 21:34:09.0910 6112 vmbus - ok 21:34:09.0930 6112 [ EC2BBAB4B84D0738C6C83D2234DC36FE ] VMBusHID D:\Windows\system32\DRIVERS\VMBusHID.sys 21:34:09.0940 6112 VMBusHID - ok 21:34:09.0980 6112 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr D:\Windows\system32\DRIVERS\volmgr.sys 21:34:10.0000 6112 volmgr - ok 21:34:10.0010 6112 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx D:\Windows\system32\drivers\volmgrx.sys 21:34:10.0020 6112 volmgrx - ok 21:34:10.0040 6112 [ 58DF9D2481A56EDDE167E51B334D44FD ] volsnap D:\Windows\system32\DRIVERS\volsnap.sys 21:34:10.0050 6112 volsnap - ok 21:34:10.0090 6112 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid D:\Windows\system32\DRIVERS\vsmraid.sys 21:34:10.0100 6112 vsmraid - ok 21:34:10.0150 6112 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS D:\Windows\system32\vssvc.exe 21:34:10.0180 6112 VSS - ok 21:34:10.0200 6112 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus D:\Windows\System32\drivers\vwifibus.sys 21:34:10.0230 6112 vwifibus - ok 21:34:10.0260 6112 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time D:\Windows\system32\w32time.dll 21:34:10.0300 6112 W32Time - ok 21:34:10.0320 6112 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen D:\Windows\system32\DRIVERS\wacompen.sys 21:34:10.0330 6112 WacomPen - ok 21:34:10.0360 6112 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP D:\Windows\system32\DRIVERS\wanarp.sys 21:34:10.0380 6112 WANARP - ok 21:34:10.0390 6112 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 D:\Windows\system32\DRIVERS\wanarp.sys 21:34:10.0410 6112 Wanarpv6 - ok 21:34:10.0450 6112 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine D:\Windows\system32\wbengine.exe 21:34:10.0490 6112 wbengine - ok 21:34:10.0510 6112 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc D:\Windows\System32\wbiosrvc.dll 21:34:10.0530 6112 WbioSrvc - ok 21:34:10.0540 6112 [ D0F88AA11EE1A62BCC6D6A8A7783CA11 ] wcncsvc D:\Windows\System32\wcncsvc.dll 21:34:10.0580 6112 wcncsvc - ok 21:34:10.0600 6112 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService D:\Windows\System32\WcsPlugInService.dll 21:34:10.0620 6112 WcsPlugInService - ok 21:34:10.0640 6112 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd D:\Windows\system32\DRIVERS\wd.sys 21:34:10.0650 6112 Wd - ok 21:34:10.0700 6112 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 D:\Windows\system32\drivers\Wdf01000.sys 21:34:10.0720 6112 Wdf01000 - ok 21:34:10.0730 6112 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost D:\Windows\system32\wdi.dll 21:34:10.0770 6112 WdiServiceHost - ok 21:34:10.0770 6112 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost D:\Windows\system32\wdi.dll 21:34:10.0790 6112 WdiSystemHost - ok 21:34:10.0810 6112 [ D87C7D2C517F82A5AB7A73E203063D9E ] WebClient D:\Windows\System32\webclnt.dll 21:34:10.0830 6112 WebClient - ok 21:34:10.0850 6112 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc D:\Windows\system32\wecsvc.dll 21:34:10.0880 6112 Wecsvc - ok 21:34:10.0880 6112 [ AC804569BB2364FB6017370258A4091B ] wercplsupport D:\Windows\System32\wercplsupport.dll 21:34:10.0920 6112 wercplsupport - ok 21:34:10.0960 6112 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc D:\Windows\System32\WerSvc.dll 21:34:10.0990 6112 WerSvc - ok 21:34:11.0010 6112 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf D:\Windows\system32\DRIVERS\wfplwf.sys 21:34:11.0030 6112 WfpLwf - ok 21:34:11.0050 6112 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount D:\Windows\system32\drivers\wimmount.sys 21:34:11.0060 6112 WIMMount - ok 21:34:11.0150 6112 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend D:\Program Files\Windows Defender\mpsvc.dll 21:34:11.0170 6112 WinDefend - ok 21:34:11.0180 6112 WinHttpAutoProxySvc - ok 21:34:11.0260 6112 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt D:\Windows\system32\wbem\WMIsvc.dll 21:34:11.0290 6112 Winmgmt - ok 21:34:11.0360 6112 [ 845AF1BA23C8D5E64DEF61BCC441604C ] WinRing0_1_2_0 D:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys 21:34:11.0370 6112 WinRing0_1_2_0 - ok 21:34:11.0430 6112 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM D:\Windows\system32\WsmSvc.dll 21:34:11.0480 6112 WinRM - ok 21:34:11.0520 6112 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc D:\Windows\System32\wlansvc.dll 21:34:11.0560 6112 Wlansvc - ok 21:34:11.0600 6112 [ 5D410936831F7FB58EFF941EAC3F6D3D ] WmBEnum D:\Windows\system32\drivers\WmBEnum.sys 21:34:11.0600 6112 WmBEnum - ok 21:34:11.0630 6112 [ 7A13CFDE92956CA61A0927D766C5AD4F ] WmFilter D:\Windows\system32\drivers\WmFilter.sys 21:34:11.0640 6112 WmFilter - ok 21:34:11.0670 6112 [ 1F596392149CAC51F7C095AF7D533934 ] WmHidLo D:\Windows\system32\drivers\WmHidLo.sys 21:34:11.0670 6112 WmHidLo - ok 21:34:11.0680 6112 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi D:\Windows\system32\DRIVERS\wmiacpi.sys 21:34:11.0720 6112 WmiAcpi - ok 21:34:11.0740 6112 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv D:\Windows\system32\wbem\WmiApSrv.exe 21:34:11.0760 6112 wmiApSrv - ok 21:34:11.0850 6112 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc D:\Program Files\Windows Media Player\wmpnetwk.exe 21:34:11.0920 6112 WMPNetworkSvc - ok 21:34:11.0950 6112 [ 6F04646BC690F8BBFC344BE32A60796D ] WmVirHid D:\Windows\system32\drivers\WmVirHid.sys 21:34:11.0960 6112 WmVirHid - ok 21:34:11.0970 6112 [ 1D6CA43D562333F4DFB40BCEF2453F3A ] WmXlCore D:\Windows\system32\drivers\WmXlCore.sys 21:34:11.0980 6112 WmXlCore - ok 21:34:12.0030 6112 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc D:\Windows\System32\wpcsvc.dll 21:34:12.0080 6112 WPCSvc - ok 21:34:12.0100 6112 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum D:\Windows\system32\wpdbusenum.dll 21:34:12.0130 6112 WPDBusEnum - ok 21:34:12.0180 6112 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl D:\Windows\system32\drivers\ws2ifsl.sys 21:34:12.0210 6112 ws2ifsl - ok 21:34:12.0240 6112 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc D:\Windows\System32\wscsvc.dll 21:34:12.0270 6112 wscsvc - ok 21:34:12.0270 6112 WSearch - ok 21:34:12.0340 6112 [ A33408CC036F9C08142B11BE5E93F0A1 ] wuauserv D:\Windows\system32\wuaueng.dll 21:34:12.0390 6112 wuauserv - ok 21:34:12.0400 6112 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf D:\Windows\system32\drivers\WudfPf.sys 21:34:12.0420 6112 WudfPf - ok 21:34:12.0450 6112 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd D:\Windows\system32\DRIVERS\WUDFRd.sys 21:34:12.0470 6112 WUDFRd - ok 21:34:12.0500 6112 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] wudfsvc D:\Windows\System32\WUDFSvc.dll 21:34:12.0530 6112 wudfsvc - ok 21:34:12.0540 6112 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc D:\Windows\System32\wwansvc.dll 21:34:12.0580 6112 WwanSvc - ok 21:34:12.0620 6112 ================ Scan global =============================== 21:34:12.0700 6112 [ 9A595DF601070DA78C40481120DD2C06 ] D:\Windows\system32\basesrv.dll 21:34:12.0750 6112 [ 827E4F75901CA3F990B1487D3301841E ] D:\Windows\system32\winsrv.dll 21:34:12.0760 6112 [ 827E4F75901CA3F990B1487D3301841E ] D:\Windows\system32\winsrv.dll 21:34:12.0810 6112 [ 364455805E64882844EE9ACB72522830 ] D:\Windows\system32\sxssrv.dll 21:34:12.0820 6112 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] D:\Windows\system32\services.exe 21:34:12.0830 6112 [Global] - ok 21:34:12.0830 6112 ================ Scan MBR ================================== 21:34:12.0840 6112 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 21:34:13.0050 6112 \Device\Harddisk0\DR0 ( TDSS File System ) - warning 21:34:13.0050 6112 \Device\Harddisk0\DR0 - detected TDSS File System (1) 21:34:13.0050 6112 [ A53367A1F3D55E138DB3855873783664 ] \Device\Harddisk1\DR1 21:34:14.0050 6112 \Device\Harddisk1\DR1 - ok 21:34:14.0050 6112 ================ Scan VBR ================================== 21:34:14.0110 6112 [ 0C44E3D41EEB0F3400111D662EE32439 ] \Device\Harddisk0\DR0\Partition1 21:34:14.0110 6112 \Device\Harddisk0\DR0\Partition1 - ok 21:34:14.0130 6112 [ 75A22A53BE5267E21B7FCFF6F61002FC ] \Device\Harddisk0\DR0\Partition2 21:34:14.0130 6112 \Device\Harddisk0\DR0\Partition2 - ok 21:34:14.0130 6112 ============================================================ 21:34:14.0130 6112 Scan finished 21:34:14.0130 6112 ============================================================ 21:34:14.0140 4884 Detected object count: 4 21:34:14.0140 4884 Actual detected object count: 4 |
hi log ist unvollständig, bitte als txt anhängen.
![]() | #10 |
du hast ihn aber jetzt nicht so gestartet, wie oben beschrieben? oder hast du etwa alle 4 einträge gelöscht?
