|
Log-Analyse und Auswertung: wssetup exeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.06.2013, 19:46 | #1 |
| wssetup exe seit ein paar tagen öffnet sich immer nach dem ich den rechner rauf gefahren habe ein fester ob ich wssetup exe zulassen möchte oder nich!!!kann mir jemand helfen |
16.06.2013, 19:59 | #2 |
/// Malware-holic | wssetup exe Hi,
__________________Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
16.06.2013, 22:07 | #3 |
| wssetup exe OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\chris\Desktop
__________________64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16614) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,98 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 59,72% Memory free 7,96 Gb Paging File | 6,04 Gb Available in Paging File | 75,80% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 582,18 Gb Total Space | 486,60 Gb Free Space | 83,58% Space Free | Partition Type: NTFS Computer Name: CHRIS-VAIO | User Name: chris | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\chris\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.) PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Microsoft Corporation.) PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe (Microsoft Corporation.) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros) PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) PRC - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) PRC - C:\Programme\Sony\VAIO Care\VCService.exe (Sony Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) PRC - C:\Programme\Sony\VAIO Care\listener.exe (Sony of America Corporation) PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) PRC - c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) PRC - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY) PRC - C:\Program Files (x86)\Lexmark 1200 Series\LXCZbmgr.exe (Lexmark International, Inc.) PRC - C:\Program Files (x86)\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.) PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe (SEIKO EPSON CORPORATION) ========== Modules (No Company Name) ========== MOD - C:\Users\chris\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\fbc70df7b07a2e9a7b59d26cb4e3b610\System.Runtime.Remoting.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b6eb138c3c9be780acb767c1bef572c1\System.Runtime.Remoting.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a9594959e951127f16eb49644ba92f79\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\7cfbbd029ef945fbcdaedd24b2b67a24\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\af18b8a8f56494da44cc448f3b9704a5\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ac9e3eca6c148504588e7c6d09fe83e3\System.Management.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\85a17526c326bfb377b5c2124dce39f2\IAStorCommon.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ceda881f46083cfb6356ed39e6bf9dcb\IAStorUtil.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\dfeff31ab1e7cd3480c8942290c92f5d\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll () MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll () MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll () ========== Services (SafeList) ========== SRV:64bit: - (EpsonScanSvc) -- C:\Windows\SysNative\escsvc64.exe (Seiko Epson Corporation) SRV:64bit: - (SampleCollector) -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation) SRV:64bit: - (lxcz_device) -- C:\Windows\SysNative\lxczcoms.exe ( ) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG) SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (VUAgent) -- C:\Programme\Sony\VAIO Update\VUAgent.exe (Sony Corporation) SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.) SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Microsoft Corporation.) SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe (Microsoft Corporation.) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (EPSON_PM_RPCV4_04) -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (SEIKO EPSON CORPORATION) SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) SRV - (VcmIAlzMgr) -- C:\Programme\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation) SRV - (Atheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros) SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Atheros Commnucations) SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.) SRV - (VAIO Event Service) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) SRV - (VSNService) -- C:\Programme\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) SRV - (uCamMonitor) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.) SRV - (SOHCImp) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation) SRV - (SOHDs) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation) SRV - (VcmXmlIfHelper) -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (Sony Corporation) SRV - (VcmINSMgr) -- C:\Programme\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe (Sony Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (VCService) -- C:\Programme\Sony\VAIO Care\VCService.exe (Sony Corporation) SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (SpfService) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation) SRV - (VCFw) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) SRV - (PMBDeviceInfoProvider) -- c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation) SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation) SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY) SRV - (lxcz_device) -- C:\Windows\SysWOW64\lxczcoms.exe ( ) SRV - (EpsonBidirectionalService) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe (SEIKO EPSON CORPORATION) ========== Driver Services (SafeList) ========== DRV:64bit: - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation) DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation) DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation) DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation) DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation) DRV:64bit: - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation) DRV:64bit: - (ssadmdfl) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation) DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros) DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros) DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros) DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros) DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros) DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros) DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros) DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (ApfiltrService) -- C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (SFEP) -- C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation) DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation) DRV:64bit: - (e1yexpress) -- C:\Windows\SysNative\drivers\e1y60x64.sys (Intel Corporation) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (ArcSoftKsUFilter) -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://sony.msn.com [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{44AAB85C-9C32-46F0-B32A-BFCBA426C780}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q311&_nkw={searchTerms} IE - HKCU\..\SearchScopes\{65717E9E-1E56-497D-BF3F-1398BC8D4414}: "URL" = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices IE - HKCU\..\SearchScopes\{9A25D1DC-860A-43EA-BA63-024A043C4C6D}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=cc3638fb-eca7-4f62-b49b-9a81fbcaa00c&apn_sauid=92419A59-671D-4ABD-9090-CBD15E2FC95D IE - HKCU\..\SearchScopes\{DCAF8E91-811B-4415-BB30-E11F8E3E0413}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 IE - HKCU\..\SearchScopes\8D35D3F2FF4B4B2298C4A3F53328EC96: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={43F33C3F-4BA5-11E2-BC7C-78843CF08728} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> ========== FireFox ========== FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\PROGRAM FILES\IB UPDATER\FIREFOX [2012.12.21 21:25:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions ========== Chrome ========== CHR - homepage: hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP&dt=061613 CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - default_search_provider: Bing (Enabled) CHR - default_search_provider: search_url = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=061613&q={searchTerms}&src=IE-SearchBox CHR - default_search_provider: suggest_url = hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language}&form=UP97DF&PC=UP97&dt=061613 CHR - Extension: Google Drive = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Google-Suche = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: Skype Click to Call = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.1.0.10441_0\ CHR - Extension: IncrediBar for Chrome\u2122 = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\ CHR - Extension: Google Mail = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ CHR - Extension: Google Drive = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Google-Suche = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: Skype Click to Call = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.1.0.10441_0\ CHR - Extension: IncrediBar for Chrome\u2122 = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\ CHR - Extension: Google Mail = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2013.06.16 21:02:22 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) O4:64bit: - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.) O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations) O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications) O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.) O4:64bit: - HKLM..\Run: [lxczbmgr.exe] C:\Program Files (x86)\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) O4 - HKLM..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-202 203 206 Series" File not found O4 - HKCU..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-202 203 206 Series" File not found O4 - HKCU..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\chris\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\chris\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O13 - gopher Prefix: missing O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16:64bit: - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A641BE5C-A94B-4023-9D65-A9B568B4035B}: DhcpNameServer = 192.168.0.1 O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013.06.15 01:24:38 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{3942788D-F1D2-4201-9BF0-003753DCCEB6} - RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2013.06.16 22:39:43 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro [2013.06.16 22:26:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2013.06.16 22:26:50 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2013.06.16 21:23:55 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Roaming\Malwarebytes [2013.06.16 21:23:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.06.16 21:23:50 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.06.16 21:23:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.06.16 21:23:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.06.16 21:22:47 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Local\Programs [2013.06.16 21:09:07 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2013.06.16 21:02:02 | 000,000,000 | ---D | C] -- C:\Windows\temp [2013.06.16 20:56:16 | 000,000,000 | ---D | C] -- C:\ComboFix [2013.06.16 20:55:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2013.06.16 20:55:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2013.06.16 20:55:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2013.06.16 20:55:08 | 000,000,000 | ---D | C] -- C:\Qoobox [2013.06.16 20:54:48 | 000,000,000 | ---D | C] -- C:\Windows\erdnt [2013.06.16 20:54:13 | 005,080,151 | R--- | C] (Swearware) -- C:\Users\chris\Desktop\ComboFix.exe [2013.06.16 20:27:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe [2013.06.16 19:11:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2013.06.16 19:11:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype [2013.06.15 01:24:22 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013.06.15 01:23:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2013.06.15 01:10:43 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\chris\Desktop\tdsskiller.exe [2013.05.30 12:16:09 | 000,000,000 | ---D | C] -- C:\ProgramData\tmp [2013.05.30 12:16:09 | 000,000,000 | ---D | C] -- C:\ProgramData\hps [2013.05.30 12:16:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Müller Foto [2013.05.30 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mueller Foto [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.06.16 22:52:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.06.16 22:44:57 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.06.16 22:44:57 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.06.16 22:36:52 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.06.16 22:36:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.06.16 22:36:34 | 3206,959,104 | -HS- | M] () -- C:\hiberfil.sys [2013.06.16 22:33:01 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.06.16 22:26:52 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.06.16 21:23:51 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.06.16 21:02:22 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2013.06.16 20:54:22 | 005,080,151 | R--- | M] (Swearware) -- C:\Users\chris\Desktop\ComboFix.exe [2013.06.16 20:27:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe [2013.06.16 19:11:36 | 000,002,517 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2013.06.15 01:24:38 | 000,000,000 | ---- | M] () -- C:\autoexec.bat [2013.06.15 01:10:43 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\chris\Desktop\tdsskiller.exe [2013.06.13 23:25:03 | 001,591,930 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013.06.13 23:25:03 | 000,697,322 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.06.13 23:25:03 | 000,652,600 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.06.13 23:25:03 | 000,148,328 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.06.13 23:25:03 | 000,121,274 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.06.13 23:24:55 | 001,591,930 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.05.31 21:38:01 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf [2013.05.31 21:38:01 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf [2013.05.30 12:16:07 | 000,001,224 | ---- | M] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk [2013.05.30 12:16:07 | 000,001,209 | ---- | M] () -- C:\Users\Public\Desktop\Müller Foto.lnk [2013.05.21 15:31:12 | 001,447,728 | ---- | M] () -- C:\Windows\SysNative\dmwu.exe [2013.05.21 15:30:18 | 000,033,792 | ---- | M] (IncrediMail, Ltd.) -- C:\Windows\SysNative\ImHttpComm.dll [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.06.16 22:26:52 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013.06.16 21:23:51 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.06.16 20:55:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013.06.16 20:55:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013.06.16 20:55:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013.06.16 20:55:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013.06.16 20:55:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013.06.16 19:11:36 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk [2013.06.15 01:24:38 | 000,000,000 | ---- | C] () -- C:\autoexec.bat [2013.05.31 21:38:01 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf [2013.05.31 21:38:01 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf [2013.05.30 12:16:07 | 000,001,224 | ---- | C] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk [2013.05.30 12:16:07 | 000,001,209 | ---- | C] () -- C:\Users\Public\Desktop\Müller Foto.lnk [2012.07.31 20:42:02 | 000,000,100 | ---- | C] () -- C:\Windows\Lexstat.ini [2012.07.31 20:11:23 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczpmui.dll [2012.07.31 20:11:23 | 000,413,696 | ---- | C] () -- C:\Windows\SysWow64\lxczutil.dll [2012.07.31 20:11:23 | 000,413,696 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczinpa.dll [2012.07.31 20:11:23 | 000,397,312 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcziesc.dll [2012.07.31 20:11:23 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\LXCZinst.dll [2012.07.31 20:11:22 | 001,224,704 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczserv.dll [2012.07.31 20:11:22 | 000,991,232 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczusb1.dll [2012.07.31 20:11:22 | 000,696,320 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczhbn3.dll [2012.07.31 20:11:22 | 000,684,032 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcomc.dll [2012.07.31 20:11:22 | 000,585,728 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczlmpm.dll [2012.07.31 20:11:22 | 000,537,520 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcoms.exe [2012.07.31 20:11:22 | 000,421,888 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcomm.dll [2012.07.31 20:11:22 | 000,385,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczih.exe [2012.07.31 20:11:22 | 000,381,872 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcfg.exe [2012.07.31 20:11:22 | 000,181,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczppls.exe [2012.07.31 20:11:22 | 000,163,840 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczprox.dll [2012.07.31 20:11:22 | 000,094,208 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczpplc.dll [2012.07.13 20:26:02 | 000,008,704 | ---- | C] () -- C:\Users\chris\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2012.08.05 12:26:15 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Ashampoo [2012.08.17 07:07:08 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\becker [2012.12.04 20:48:11 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\DVDVideoSoft [2013.02.08 21:18:46 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Elmu [2012.12.23 15:04:11 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\EPSON [2013.02.09 20:34:41 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Faol [2012.07.06 20:48:40 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Opera [2013.02.13 14:02:31 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Qoanix [2012.07.13 20:23:14 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Samsung [2013.05.20 09:54:28 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\SoftGrid Client [2013.01.20 21:03:43 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\TP [2012.12.04 20:48:47 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\TuneUp Software [2012.12.21 21:52:52 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\UseNeXT ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2013.06.16 21:04:57 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin [2013.06.16 21:06:10 | 000,000,000 | ---D | M] -- C:\ComboFix [2013.06.16 21:10:23 | 000,000,000 | -HSD | M] -- C:\Config.Msi [2012.07.01 21:54:21 | 000,000,000 | ---D | M] -- C:\Documentation [2009.07.14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2012.07.01 22:32:28 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2012.07.01 21:38:33 | 000,000,000 | ---D | M] -- C:\Intel [2012.07.31 20:11:05 | 000,000,000 | ---D | M] -- C:\lexmark [2013.01.20 21:10:15 | 000,000,000 | R--D | M] -- C:\MSOCache [2009.07.14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs [2013.06.16 22:34:48 | 000,000,000 | R--D | M] -- C:\Program Files [2013.06.16 22:34:48 | 000,000,000 | R--D | M] -- C:\Program Files (x86) [2012.07.31 20:11:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86) (x86) [2013.06.16 22:39:43 | 000,000,000 | ---D | M] -- C:\ProgramData [2012.07.01 22:32:28 | 000,000,000 | -HSD | M] -- C:\Programme [2013.06.16 20:55:35 | 000,000,000 | ---D | M] -- C:\Qoobox [2012.07.01 22:21:37 | 000,000,000 | ---D | M] -- C:\SPLASH.000 [2012.07.01 22:21:16 | 000,000,000 | ---D | M] -- C:\SPLASH.SYS [2013.06.16 22:54:40 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012.07.01 22:25:21 | 000,000,000 | ---D | M] -- C:\temp [2013.01.12 21:23:10 | 000,000,000 | ---D | M] -- C:\Update [2012.07.01 22:32:48 | 000,000,000 | R--D | M] -- C:\Users [2012.07.01 22:25:28 | 000,000,000 | ---D | M] -- C:\VAIO Sample Contents [2013.06.16 22:36:38 | 000,000,000 | ---D | M] -- C:\Windows [2012.07.01 21:54:21 | 000,000,000 | ---D | M] -- C:\_FS_SWRINFO < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < C:\Windows\system32\*.tsp > [2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp [2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp [2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp [2009.07.14 03:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp [2010.11.21 05:23:55 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] [2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2009.07.14 07:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2012.07.15 20:16:27 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job [2012.12.21 22:10:19 | 000,001,104 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2012.12.21 22:10:20 | 000,001,108 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job < MD5 for: AGP440.SYS > [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys [2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys < MD5 for: ATAPI.SYS > [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys [2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys < MD5 for: CNGAUDIT.DLL > [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll [2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll [2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll < MD5 for: EXPLORER.EXE > [2011.07.13 03:21:47 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe [2011.07.13 03:21:47 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe [2011.07.13 03:21:47 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe [2011.07.13 03:21:47 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe [2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe [2011.07.13 03:21:47 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe [2011.07.13 03:21:47 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe [2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe < MD5 for: IASTOR.SYS > [2011.02.22 17:27:05 | 000,437,272 | R--- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\drivers\iaStor.sys [2011.02.22 17:27:05 | 000,437,272 | R--- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_2b0c50dc63f09dae\iaStor.sys [2011.02.22 17:27:05 | 000,437,272 | R--- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_5b314ccea0aa569d\iaStor.sys < MD5 for: IASTORV.SYS > [2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys [2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys [2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys [2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys [2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys [2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys < MD5 for: NETLOGON.DLL > [2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll [2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll [2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll [2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll < MD5 for: NVSTOR.SYS > [2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys [2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys [2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys [2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys [2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys [2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys < MD5 for: SCECLI.DLL > [2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll [2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll [2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll [2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll < MD5 for: USER32.DLL > [2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll [2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll [2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll [2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll < MD5 for: USERINIT.EXE > [2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe [2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe [2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe < MD5 for: WINLOGON.EXE > [2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe [2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe < MD5 for: WS2IFSL.SYS > [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys [2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\*.dll /lockedfiles > [2013.05.17 03:25:26 | 013,760,512 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < %USERPROFILE%\*.* > [2013.06.16 23:04:13 | 001,835,008 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT [2013.06.16 23:04:13 | 000,262,144 | -HS- | M] () -- C:\Users\chris\ntuser.dat.LOG1 [2012.07.01 22:32:53 | 000,000,000 | -HS- | M] () -- C:\Users\chris\ntuser.dat.LOG2 [2012.07.01 22:39:17 | 000,065,536 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2012.07.01 22:39:17 | 000,524,288 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2012.07.01 22:39:17 | 000,524,288 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2012.07.01 22:32:53 | 000,000,020 | -HS- | M] () -- C:\Users\chris\ntuser.ini < %USERPROFILE%\Local Settings\Temp\*.exe > < %USERPROFILE%\Local Settings\Temp\*.dll > < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 < > < End of report > |
17.06.2013, 10:59 | #4 |
/// Malware-holic | wssetup exe Hi, Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
17.06.2013, 18:29 | #5 |
| wssetup exe Hi,hab ich gemacht hat nichts gefunden |
18.06.2013, 16:59 | #6 |
/// Malware-holic | wssetup exe log posten
__________________ --> wssetup exe |
18.06.2013, 19:10 | #7 |
| wssetup exe 19:56:44.0426 5924 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 19:56:44.0705 5924 ============================================================ 19:56:44.0706 5924 Current date / time: 2013/06/18 19:56:44.0705 19:56:44.0706 5924 SystemInfo: 19:56:44.0706 5924 19:56:44.0706 5924 OS Version: 6.1.7601 ServicePack: 1.0 19:56:44.0706 5924 Product type: Workstation 19:56:44.0706 5924 ComputerName: CHRIS-VAIO 19:56:44.0706 5924 UserName: chris 19:56:44.0707 5924 Windows directory: C:\Windows 19:56:44.0707 5924 System windows directory: C:\Windows 19:56:44.0707 5924 Running under WOW64 19:56:44.0707 5924 Processor architecture: Intel x64 19:56:44.0707 5924 Number of processors: 4 19:56:44.0707 5924 Page size: 0x1000 19:56:44.0707 5924 Boot type: Normal boot 19:56:44.0707 5924 ============================================================ 19:56:45.0183 5924 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 19:56:45.0188 5924 ============================================================ 19:56:45.0188 5924 \Device\Harddisk0\DR0: 19:56:45.0188 5924 MBR partitions: 19:56:45.0188 5924 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1BC9800, BlocksNum 0x32000 19:56:45.0188 5924 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1BFB800, BlocksNum 0x48C5C000 19:56:45.0188 5924 ============================================================ 19:56:45.0222 5924 C: <-> \Device\Harddisk0\DR0\Partition2 19:56:45.0222 5924 ============================================================ 19:56:45.0223 5924 Initialize success 19:56:45.0223 5924 ============================================================ 19:56:47.0351 7016 ============================================================ 19:56:47.0351 7016 Scan started 19:56:47.0351 7016 Mode: Manual; 19:56:47.0351 7016 ============================================================ 19:56:47.0512 7016 ================ Scan system memory ======================== 19:56:47.0512 7016 System memory - ok 19:56:47.0513 7016 ================ Scan services ============================= 19:56:47.0700 7016 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 19:56:47.0719 7016 1394ohci - ok 19:56:47.0829 7016 [ B33CF4DE909A5B30F526D82053A63C8E ] ABBYY.Licensing.FineReader.Sprint.9.0 C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe 19:56:47.0842 7016 ABBYY.Licensing.FineReader.Sprint.9.0 - ok 19:56:47.0924 7016 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 19:56:47.0927 7016 ACDaemon - ok 19:56:48.0000 7016 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 19:56:48.0007 7016 ACPI - ok 19:56:48.0039 7016 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 19:56:48.0046 7016 AcpiPmi - ok 19:56:48.0119 7016 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 19:56:48.0121 7016 AdobeARMservice - ok 19:56:48.0291 7016 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 19:56:48.0296 7016 AdobeFlashPlayerUpdateSvc - ok 19:56:48.0370 7016 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 19:56:48.0394 7016 adp94xx - ok 19:56:48.0441 7016 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 19:56:48.0462 7016 adpahci - ok 19:56:48.0489 7016 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 19:56:48.0498 7016 adpu320 - ok 19:56:48.0529 7016 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 19:56:48.0530 7016 AeLookupSvc - ok 19:56:48.0571 7016 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 19:56:48.0577 7016 AFD - ok 19:56:48.0614 7016 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 19:56:48.0621 7016 agp440 - ok 19:56:48.0647 7016 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 19:56:48.0654 7016 ALG - ok 19:56:48.0676 7016 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 19:56:48.0681 7016 aliide - ok 19:56:48.0687 7016 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 19:56:48.0692 7016 amdide - ok 19:56:48.0705 7016 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 19:56:48.0712 7016 AmdK8 - ok 19:56:48.0739 7016 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 19:56:48.0747 7016 AmdPPM - ok 19:56:48.0781 7016 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 19:56:48.0792 7016 amdsata - ok 19:56:48.0817 7016 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 19:56:48.0832 7016 amdsbs - ok 19:56:48.0847 7016 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 19:56:48.0853 7016 amdxata - ok 19:56:49.0030 7016 [ D9A92E6DD41C5ADC045AE485026AA40C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 19:56:49.0032 7016 AntiVirSchedulerService - ok 19:56:49.0102 7016 [ 66A7A38F7C439153B758548375EB9E5E ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 19:56:49.0106 7016 AntiVirService - ok 19:56:49.0151 7016 [ 9EDAE2D1CA368E8D01BEE8BFBC9488E4 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE 19:56:49.0181 7016 AntiVirWebService - ok 19:56:49.0237 7016 [ D80CB25D90474C731C0D1312A6DE3B13 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys 19:56:49.0253 7016 ApfiltrService - ok 19:56:49.0295 7016 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 19:56:49.0304 7016 AppID - ok 19:56:49.0333 7016 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 19:56:49.0342 7016 AppIDSvc - ok 19:56:49.0387 7016 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll 19:56:49.0390 7016 Appinfo - ok 19:56:49.0442 7016 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 19:56:49.0456 7016 arc - ok 19:56:49.0477 7016 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 19:56:49.0485 7016 arcsas - ok 19:56:49.0508 7016 [ C130BC4A51B1382B2BE8E44579EC4C0A ] ArcSoftKsUFilter C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys 19:56:49.0512 7016 ArcSoftKsUFilter - ok 19:56:49.0587 7016 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 19:56:49.0615 7016 aspnet_state - ok 19:56:49.0633 7016 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 19:56:49.0639 7016 AsyncMac - ok 19:56:49.0665 7016 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 19:56:49.0672 7016 atapi - ok 19:56:49.0707 7016 [ 50F257E19554421B6891E3F998EDCA90 ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys 19:56:49.0713 7016 AthBTPort - ok 19:56:49.0776 7016 [ 650F111D5CDA64C10AE4B9D1BA9D4FFF ] Atheros Bt&Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe 19:56:49.0780 7016 Atheros Bt&Wlan Coex Agent - ok 19:56:49.0811 7016 [ EBC3119394C9074A9CD87578A435050D ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe 19:56:49.0814 7016 AtherosSvc - ok 19:56:49.0897 7016 [ C8679A07267F030704168E45E27C3D43 ] athr C:\Windows\system32\DRIVERS\athrx.sys 19:56:49.0931 7016 athr - ok 19:56:49.0981 7016 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 19:56:49.0987 7016 AudioEndpointBuilder - ok 19:56:49.0998 7016 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 19:56:50.0003 7016 AudioSrv - ok 19:56:50.0052 7016 [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 19:56:50.0067 7016 avgntflt - ok 19:56:50.0129 7016 [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 19:56:50.0146 7016 avipbb - ok 19:56:50.0202 7016 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 19:56:50.0213 7016 avkmgr - ok 19:56:50.0270 7016 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 19:56:50.0286 7016 AxInstSV - ok 19:56:50.0337 7016 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 19:56:50.0359 7016 b06bdrv - ok 19:56:50.0406 7016 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 19:56:50.0425 7016 b57nd60a - ok 19:56:50.0537 7016 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe 19:56:50.0541 7016 BBSvc - ok 19:56:50.0623 7016 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe 19:56:50.0628 7016 BBUpdate - ok 19:56:50.0659 7016 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 19:56:50.0672 7016 BDESVC - ok 19:56:50.0707 7016 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 19:56:50.0713 7016 Beep - ok 19:56:50.0767 7016 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 19:56:50.0780 7016 BFE - ok 19:56:50.0837 7016 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 19:56:50.0856 7016 BITS - ok 19:56:50.0888 7016 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 19:56:50.0898 7016 blbdrive - ok 19:56:50.0920 7016 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 19:56:50.0933 7016 bowser - ok 19:56:50.0961 7016 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 19:56:50.0968 7016 BrFiltLo - ok 19:56:50.0977 7016 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 19:56:50.0980 7016 BrFiltUp - ok 19:56:51.0023 7016 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 19:56:51.0030 7016 BridgeMP - ok 19:56:51.0059 7016 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 19:56:51.0061 7016 Browser - ok 19:56:51.0098 7016 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 19:56:51.0119 7016 Brserid - ok 19:56:51.0126 7016 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 19:56:51.0131 7016 BrSerWdm - ok 19:56:51.0135 7016 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 19:56:51.0139 7016 BrUsbMdm - ok 19:56:51.0143 7016 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 19:56:51.0147 7016 BrUsbSer - ok 19:56:51.0209 7016 [ B3BCD755FA9A359D10208CC9F09847CC ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys 19:56:51.0226 7016 BTATH_A2DP - ok 19:56:51.0265 7016 [ 9BBBA9D6DBDEFC8A6542BC7A6EBAF710 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys 19:56:51.0278 7016 btath_avdt - ok 19:56:51.0313 7016 [ D838DD1BCB328EFCFAD7A52DE9E3CAFD ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys 19:56:51.0315 7016 BTATH_BUS - ok 19:56:51.0334 7016 [ A441B800E04CF8443FAF519207563ABB ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys 19:56:51.0349 7016 BTATH_HCRP - ok 19:56:51.0390 7016 [ B16F8429A35BBA2A8EF9DB2E08675B97 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys 19:56:51.0397 7016 BTATH_LWFLT - ok 19:56:51.0415 7016 [ C24231C6BDFE21735930084A22089AAB ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys 19:56:51.0426 7016 BTATH_RCP - ok 19:56:51.0494 7016 [ 3632FA4C6B3CE9EC827690DEAC266D8C ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys 19:56:51.0497 7016 BtFilter - ok 19:56:51.0551 7016 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 19:56:51.0561 7016 BthEnum - ok 19:56:51.0587 7016 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 19:56:51.0595 7016 BTHMODEM - ok 19:56:51.0617 7016 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 19:56:51.0626 7016 BthPan - ok 19:56:51.0671 7016 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 19:56:51.0679 7016 BTHPORT - ok 19:56:51.0713 7016 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 19:56:51.0722 7016 bthserv - ok 19:56:51.0747 7016 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 19:56:51.0749 7016 BTHUSB - ok 19:56:51.0866 7016 catchme - ok 19:56:51.0901 7016 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 19:56:51.0913 7016 cdfs - ok 19:56:51.0943 7016 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 19:56:51.0959 7016 cdrom - ok 19:56:51.0986 7016 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 19:56:51.0989 7016 CertPropSvc - ok 19:56:52.0029 7016 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 19:56:52.0035 7016 circlass - ok 19:56:52.0050 7016 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 19:56:52.0055 7016 CLFS - ok 19:56:52.0131 7016 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 19:56:52.0145 7016 clr_optimization_v2.0.50727_32 - ok 19:56:52.0185 7016 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 19:56:52.0195 7016 clr_optimization_v2.0.50727_64 - ok 19:56:52.0275 7016 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 19:56:52.0305 7016 clr_optimization_v4.0.30319_32 - ok 19:56:52.0350 7016 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 19:56:52.0364 7016 clr_optimization_v4.0.30319_64 - ok 19:56:52.0399 7016 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 19:56:52.0406 7016 CmBatt - ok 19:56:52.0432 7016 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 19:56:52.0440 7016 cmdide - ok 19:56:52.0527 7016 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 19:56:52.0553 7016 CNG - ok 19:56:52.0644 7016 [ 1F394DF3714ED4280047810790E6DF69 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys 19:56:52.0680 7016 CnxtHdAudService - ok 19:56:52.0732 7016 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 19:56:52.0738 7016 Compbatt - ok 19:56:52.0751 7016 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 19:56:52.0762 7016 CompositeBus - ok 19:56:52.0773 7016 COMSysApp - ok 19:56:52.0790 7016 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 19:56:52.0795 7016 crcdisk - ok 19:56:52.0858 7016 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll 19:56:52.0860 7016 CryptSvc - ok 19:56:52.0961 7016 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 19:56:52.0968 7016 cvhsvc - ok 19:56:53.0036 7016 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 19:56:53.0043 7016 DcomLaunch - ok 19:56:53.0093 7016 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 19:56:53.0104 7016 defragsvc - ok 19:56:53.0133 7016 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 19:56:53.0139 7016 DfsC - ok 19:56:53.0165 7016 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 19:56:53.0168 7016 Dhcp - ok 19:56:53.0172 7016 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 19:56:53.0173 7016 discache - ok 19:56:53.0204 7016 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 19:56:53.0211 7016 Disk - ok 19:56:53.0250 7016 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 19:56:53.0252 7016 Dnscache - ok 19:56:53.0258 7016 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 19:56:53.0269 7016 dot3svc - ok 19:56:53.0275 7016 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 19:56:53.0277 7016 DPS - ok 19:56:53.0311 7016 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 19:56:53.0313 7016 drmkaud - ok 19:56:53.0368 7016 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 19:56:53.0395 7016 DXGKrnl - ok 19:56:53.0436 7016 [ 50AD8FC1DC800FF36087994C8F7FDFF2 ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys 19:56:53.0455 7016 e1yexpress - ok 19:56:53.0486 7016 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 19:56:53.0490 7016 EapHost - ok 19:56:53.0601 7016 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 19:56:53.0644 7016 ebdrv - ok 19:56:53.0679 7016 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 19:56:53.0681 7016 EFS - ok 19:56:53.0753 7016 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 19:56:53.0775 7016 ehRecvr - ok 19:56:53.0791 7016 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 19:56:53.0801 7016 ehSched - ok 19:56:53.0836 7016 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 19:56:53.0850 7016 elxstor - ok 19:56:53.0887 7016 [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe 19:56:53.0889 7016 EpsonBidirectionalService - ok 19:56:53.0939 7016 [ 20ECD0A490A121CB34F553FAD1DBBD39 ] EpsonScanSvc C:\Windows\system32\EscSvc64.exe 19:56:53.0943 7016 EpsonScanSvc - ok 19:56:54.0026 7016 [ 194E8100D57FC13BEF88129BAAD07E46 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE 19:56:54.0029 7016 EPSON_PM_RPCV4_04 - ok 19:56:54.0044 7016 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 19:56:54.0052 7016 ErrDev - ok 19:56:54.0133 7016 esgiguard - ok 19:56:54.0185 7016 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 19:56:54.0194 7016 EventSystem - ok 19:56:54.0234 7016 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 19:56:54.0250 7016 exfat - ok 19:56:54.0277 7016 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 19:56:54.0292 7016 fastfat - ok 19:56:54.0345 7016 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 19:56:54.0359 7016 Fax - ok 19:56:54.0403 7016 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 19:56:54.0407 7016 fdc - ok 19:56:54.0444 7016 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 19:56:54.0445 7016 fdPHost - ok 19:56:54.0462 7016 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 19:56:54.0464 7016 FDResPub - ok 19:56:54.0487 7016 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 19:56:54.0493 7016 FileInfo - ok 19:56:54.0497 7016 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 19:56:54.0502 7016 Filetrace - ok 19:56:54.0538 7016 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 19:56:54.0543 7016 flpydisk - ok 19:56:54.0550 7016 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 19:56:54.0561 7016 FltMgr - ok 19:56:54.0627 7016 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 19:56:54.0643 7016 FontCache - ok 19:56:54.0687 7016 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 19:56:54.0689 7016 FontCache3.0.0.0 - ok 19:56:54.0714 7016 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 19:56:54.0721 7016 FsDepends - ok 19:56:54.0755 7016 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 19:56:54.0764 7016 Fs_Rec - ok 19:56:54.0804 7016 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 19:56:54.0809 7016 fvevol - ok 19:56:54.0848 7016 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 19:56:54.0860 7016 gagp30kx - ok 19:56:54.0917 7016 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 19:56:54.0932 7016 gpsvc - ok 19:56:55.0010 7016 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 19:56:55.0013 7016 gupdate - ok 19:56:55.0021 7016 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 19:56:55.0023 7016 gupdatem - ok 19:56:55.0092 7016 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 19:56:55.0098 7016 hcw85cir - ok 19:56:55.0161 7016 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 19:56:55.0175 7016 HdAudAddService - ok 19:56:55.0207 7016 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 19:56:55.0209 7016 HDAudBus - ok 19:56:55.0214 7016 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 19:56:55.0219 7016 HidBatt - ok 19:56:55.0225 7016 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 19:56:55.0232 7016 HidBth - ok 19:56:55.0254 7016 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 19:56:55.0259 7016 HidIr - ok 19:56:55.0275 7016 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 19:56:55.0280 7016 hidserv - ok 19:56:55.0320 7016 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys 19:56:55.0325 7016 HidUsb - ok 19:56:55.0355 7016 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 19:56:55.0359 7016 hkmsvc - ok 19:56:55.0377 7016 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 19:56:55.0384 7016 HomeGroupListener - ok 19:56:55.0414 7016 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 19:56:55.0417 7016 HomeGroupProvider - ok 19:56:55.0444 7016 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 19:56:55.0451 7016 HpSAMD - ok 19:56:55.0485 7016 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 19:56:55.0493 7016 HTTP - ok 19:56:55.0509 7016 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 19:56:55.0510 7016 hwpolicy - ok 19:56:55.0559 7016 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 19:56:55.0570 7016 i8042prt - ok 19:56:55.0602 7016 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\drivers\iaStor.sys 19:56:55.0609 7016 iaStor - ok 19:56:55.0667 7016 [ B25F192EA1F84A316EB7C19EFCCCF33D ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 19:56:55.0668 7016 IAStorDataMgrSvc - ok 19:56:55.0721 7016 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 19:56:55.0741 7016 iaStorV - ok 19:56:55.0840 7016 [ 6F3909A3D40CC9F4B28E03B027F918D8 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe 19:56:55.0867 7016 IconMan_R - ok 19:56:55.0916 7016 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 19:56:55.0940 7016 idsvc - ok 19:56:55.0977 7016 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 19:56:55.0982 7016 iirsp - ok 19:56:56.0031 7016 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 19:56:56.0046 7016 IKEEXT - ok 19:56:56.0053 7016 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 19:56:56.0058 7016 intelide - ok 19:56:56.0085 7016 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 19:56:56.0086 7016 intelppm - ok 19:56:56.0110 7016 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 19:56:56.0112 7016 IPBusEnum - ok 19:56:56.0124 7016 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:56:56.0129 7016 IpFilterDriver - ok 19:56:56.0177 7016 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 19:56:56.0189 7016 iphlpsvc - ok 19:56:56.0210 7016 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 19:56:56.0216 7016 IPMIDRV - ok 19:56:56.0220 7016 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 19:56:56.0226 7016 IPNAT - ok 19:56:56.0241 7016 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 19:56:56.0244 7016 IRENUM - ok 19:56:56.0249 7016 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 19:56:56.0253 7016 isapnp - ok 19:56:56.0275 7016 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 19:56:56.0285 7016 iScsiPrt - ok 19:56:56.0314 7016 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 19:56:56.0320 7016 kbdclass - ok 19:56:56.0343 7016 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 19:56:56.0347 7016 kbdhid - ok 19:56:56.0367 7016 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 19:56:56.0368 7016 KeyIso - ok 19:56:56.0401 7016 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 19:56:56.0412 7016 KSecDD - ok 19:56:56.0432 7016 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 19:56:56.0448 7016 KSecPkg - ok 19:56:56.0487 7016 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 19:56:56.0495 7016 ksthunk - ok 19:56:56.0533 7016 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 19:56:56.0557 7016 KtmRm - ok 19:56:56.0612 7016 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 19:56:56.0616 7016 LanmanServer - ok 19:56:56.0629 7016 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 19:56:56.0632 7016 LanmanWorkstation - ok 19:56:56.0670 7016 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 19:56:56.0679 7016 lltdio - ok 19:56:56.0705 7016 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 19:56:56.0724 7016 lltdsvc - ok 19:56:56.0765 7016 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 19:56:56.0769 7016 lmhosts - ok 19:56:56.0817 7016 [ 98B16E756243BEA9410E32025B19C06F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 19:56:56.0823 7016 LMS - ok 19:56:56.0871 7016 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 19:56:56.0884 7016 LSI_FC - ok 19:56:56.0893 7016 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 19:56:56.0906 7016 LSI_SAS - ok 19:56:56.0914 7016 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 19:56:56.0920 7016 LSI_SAS2 - ok 19:56:56.0926 7016 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 19:56:56.0932 7016 LSI_SCSI - ok 19:56:56.0951 7016 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 19:56:56.0961 7016 luafv - ok 19:56:56.0964 7016 lxcz_device - ok 19:56:57.0026 7016 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 19:56:57.0036 7016 MBAMProtector - ok 19:56:57.0113 7016 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 19:56:57.0120 7016 MBAMScheduler - ok 19:56:57.0200 7016 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 19:56:57.0214 7016 MBAMService - ok 19:56:57.0238 7016 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 19:56:57.0245 7016 Mcx2Svc - ok 19:56:57.0258 7016 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 19:56:57.0263 7016 megasas - ok 19:56:57.0298 7016 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 19:56:57.0309 7016 MegaSR - ok 19:56:57.0337 7016 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 19:56:57.0343 7016 MEIx64 - ok 19:56:57.0374 7016 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 19:56:57.0376 7016 MMCSS - ok 19:56:57.0395 7016 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 19:56:57.0400 7016 Modem - ok 19:56:57.0432 7016 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 19:56:57.0433 7016 monitor - ok 19:56:57.0448 7016 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 19:56:57.0455 7016 mouclass - ok 19:56:57.0488 7016 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\drivers\mouhid.sys 19:56:57.0493 7016 mouhid - ok 19:56:57.0521 7016 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 19:56:57.0523 7016 mountmgr - ok 19:56:57.0528 7016 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 19:56:57.0538 7016 mpio - ok 19:56:57.0542 7016 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 19:56:57.0548 7016 mpsdrv - ok 19:56:57.0591 7016 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 19:56:57.0601 7016 MpsSvc - ok 19:56:57.0621 7016 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 19:56:57.0630 7016 MRxDAV - ok 19:56:57.0652 7016 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 19:56:57.0661 7016 mrxsmb - ok 19:56:57.0680 7016 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:56:57.0691 7016 mrxsmb10 - ok 19:56:57.0702 7016 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:56:57.0710 7016 mrxsmb20 - ok 19:56:57.0730 7016 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 19:56:57.0735 7016 msahci - ok 19:56:57.0756 7016 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 19:56:57.0764 7016 msdsm - ok 19:56:57.0779 7016 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 19:56:57.0789 7016 MSDTC - ok 19:56:57.0815 7016 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 19:56:57.0819 7016 Msfs - ok 19:56:57.0833 7016 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 19:56:57.0837 7016 mshidkmdf - ok 19:56:57.0854 7016 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 19:56:57.0858 7016 msisadrv - ok 19:56:57.0884 7016 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 19:56:57.0892 7016 MSiSCSI - ok 19:56:57.0896 7016 msiserver - ok 19:56:57.0919 7016 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 19:56:57.0922 7016 MSKSSRV - ok 19:56:57.0932 7016 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 19:56:57.0936 7016 MSPCLOCK - ok 19:56:57.0950 7016 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 19:56:57.0950 7016 MSPQM - ok 19:56:57.0974 7016 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 19:56:57.0985 7016 MsRPC - ok 19:56:57.0996 7016 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 19:56:57.0997 7016 mssmbios - ok 19:56:58.0016 7016 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 19:56:58.0019 7016 MSTEE - ok 19:56:58.0023 7016 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 19:56:58.0027 7016 MTConfig - ok 19:56:58.0032 7016 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 19:56:58.0038 7016 Mup - ok 19:56:58.0073 7016 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 19:56:58.0080 7016 napagent - ok 19:56:58.0122 7016 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 19:56:58.0134 7016 NativeWifiP - ok 19:56:58.0194 7016 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 19:56:58.0209 7016 NDIS - ok 19:56:58.0229 7016 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 19:56:58.0235 7016 NdisCap - ok 19:56:58.0261 7016 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 19:56:58.0266 7016 NdisTapi - ok 19:56:58.0282 7016 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 19:56:58.0289 7016 Ndisuio - ok 19:56:58.0295 7016 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 19:56:58.0305 7016 NdisWan - ok 19:56:58.0314 7016 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 19:56:58.0321 7016 NDProxy - ok 19:56:58.0331 7016 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 19:56:58.0335 7016 NetBIOS - ok 19:56:58.0368 7016 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 19:56:58.0370 7016 NetBT - ok 19:56:58.0389 7016 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 19:56:58.0390 7016 Netlogon - ok 19:56:58.0416 7016 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 19:56:58.0420 7016 Netman - ok 19:56:58.0455 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:58.0472 7016 NetMsmqActivator - ok 19:56:58.0475 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:58.0476 7016 NetPipeActivator - ok 19:56:58.0484 7016 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 19:56:58.0488 7016 netprofm - ok 19:56:58.0492 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:58.0493 7016 NetTcpActivator - ok 19:56:58.0496 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:58.0497 7016 NetTcpPortSharing - ok 19:56:58.0530 7016 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 19:56:58.0534 7016 nfrd960 - ok 19:56:58.0560 7016 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 19:56:58.0563 7016 NlaSvc - ok 19:56:58.0578 7016 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 19:56:58.0582 7016 Npfs - ok 19:56:58.0611 7016 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 19:56:58.0612 7016 nsi - ok 19:56:58.0615 7016 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 19:56:58.0615 7016 nsiproxy - ok 19:56:58.0663 7016 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 19:56:58.0688 7016 Ntfs - ok 19:56:58.0707 7016 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 19:56:58.0709 7016 Null - ok 19:56:58.0741 7016 [ F12E3EA0386EBC284C893611107C6A96 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 19:56:58.0755 7016 NVHDA - ok 19:56:59.0049 7016 [ D5DEA2C1865CAB9EE6AA29CF9E79A2CE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 19:56:59.0398 7016 nvlddmkm - ok 19:56:59.0422 7016 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 19:56:59.0428 7016 nvraid - ok 19:56:59.0457 7016 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 19:56:59.0463 7016 nvstor - ok 19:56:59.0520 7016 [ 5A4AF8EA634B4FEEAF6F16BB1845715A ] NVSvc C:\Windows\system32\nvvsvc.exe 19:56:59.0539 7016 NVSvc - ok 19:56:59.0562 7016 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 19:56:59.0577 7016 nv_agp - ok 19:56:59.0601 7016 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 19:56:59.0614 7016 ohci1394 - ok 19:56:59.0681 7016 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 19:56:59.0698 7016 ose - ok 19:56:59.0867 7016 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 19:57:00.0005 7016 osppsvc - ok 19:57:00.0037 7016 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 19:57:00.0041 7016 p2pimsvc - ok 19:57:00.0067 7016 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 19:57:00.0072 7016 p2psvc - ok 19:57:00.0103 7016 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 19:57:00.0109 7016 Parport - ok 19:57:00.0140 7016 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 19:57:00.0146 7016 partmgr - ok 19:57:00.0183 7016 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 19:57:00.0189 7016 PcaSvc - ok 19:57:00.0206 7016 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 19:57:00.0222 7016 pci - ok 19:57:00.0243 7016 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 19:57:00.0250 7016 pciide - ok 19:57:00.0270 7016 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 19:57:00.0286 7016 pcmcia - ok 19:57:00.0300 7016 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 19:57:00.0307 7016 pcw - ok 19:57:00.0325 7016 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 19:57:00.0343 7016 PEAUTH - ok 19:57:00.0427 7016 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 19:57:00.0436 7016 PerfHost - ok 19:57:00.0512 7016 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 19:57:00.0542 7016 pla - ok 19:57:00.0577 7016 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 19:57:00.0583 7016 PlugPlay - ok 19:57:00.0782 7016 [ 63694C307273062A2167AE4CE80730EF ] PMBDeviceInfoProvider c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe 19:57:00.0808 7016 PMBDeviceInfoProvider - ok 19:57:00.0832 7016 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 19:57:00.0840 7016 PNRPAutoReg - ok 19:57:00.0860 7016 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 19:57:00.0865 7016 PNRPsvc - ok 19:57:00.0903 7016 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 19:57:00.0910 7016 PolicyAgent - ok 19:57:00.0957 7016 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 19:57:00.0961 7016 Power - ok 19:57:01.0010 7016 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 19:57:01.0024 7016 PptpMiniport - ok 19:57:01.0042 7016 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 19:57:01.0054 7016 Processor - ok 19:57:01.0081 7016 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 19:57:01.0085 7016 ProfSvc - ok 19:57:01.0100 7016 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 19:57:01.0102 7016 ProtectedStorage - ok 19:57:01.0133 7016 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 19:57:01.0135 7016 Psched - ok 19:57:01.0210 7016 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 19:57:01.0236 7016 ql2300 - ok 19:57:01.0240 7016 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 19:57:01.0247 7016 ql40xx - ok 19:57:01.0274 7016 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 19:57:01.0284 7016 QWAVE - ok 19:57:01.0287 7016 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 19:57:01.0291 7016 QWAVEdrv - ok 19:57:01.0300 7016 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 19:57:01.0303 7016 RasAcd - ok 19:57:01.0330 7016 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 19:57:01.0335 7016 RasAgileVpn - ok 19:57:01.0368 7016 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 19:57:01.0374 7016 RasAuto - ok 19:57:01.0386 7016 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 19:57:01.0391 7016 Rasl2tp - ok 19:57:01.0417 7016 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 19:57:01.0421 7016 RasMan - ok 19:57:01.0434 7016 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 19:57:01.0439 7016 RasPppoe - ok 19:57:01.0467 7016 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 19:57:01.0472 7016 RasSstp - ok 19:57:01.0478 7016 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 19:57:01.0487 7016 rdbss - ok 19:57:01.0497 7016 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 19:57:01.0501 7016 rdpbus - ok 19:57:01.0526 7016 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 19:57:01.0527 7016 RDPCDD - ok 19:57:01.0542 7016 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 19:57:01.0543 7016 RDPENCDD - ok 19:57:01.0557 7016 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 19:57:01.0557 7016 RDPREFMP - ok 19:57:01.0579 7016 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 19:57:01.0586 7016 RDPWD - ok 19:57:01.0619 7016 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 19:57:01.0628 7016 rdyboost - ok 19:57:01.0654 7016 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 19:57:01.0660 7016 RemoteAccess - ok 19:57:01.0695 7016 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 19:57:01.0704 7016 RemoteRegistry - ok 19:57:01.0739 7016 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 19:57:01.0746 7016 RFCOMM - ok 19:57:01.0769 7016 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 19:57:01.0772 7016 RpcEptMapper - ok 19:57:01.0802 7016 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 19:57:01.0809 7016 RpcLocator - ok 19:57:01.0849 7016 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 19:57:01.0858 7016 RpcSs - ok 19:57:01.0888 7016 [ 546D7F426776090B90EF5F195B6AE662 ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys 19:57:01.0892 7016 RSPCIESTOR - ok 19:57:01.0919 7016 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 19:57:01.0926 7016 rspndr - ok 19:57:01.0977 7016 [ EA5532868BA76923D75BCB2A1448D810 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 19:57:01.0988 7016 RTL8167 - ok 19:57:02.0022 7016 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 19:57:02.0024 7016 SamSs - ok 19:57:02.0043 7016 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 19:57:02.0051 7016 sbp2port - ok 19:57:02.0081 7016 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 19:57:02.0091 7016 SCardSvr - ok 19:57:02.0095 7016 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 19:57:02.0101 7016 scfilter - ok 19:57:02.0128 7016 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 19:57:02.0137 7016 Schedule - ok 19:57:02.0151 7016 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 19:57:02.0152 7016 SCPolicySvc - ok 19:57:02.0194 7016 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 19:57:02.0207 7016 sdbus - ok 19:57:02.0237 7016 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 19:57:02.0252 7016 SDRSVC - ok 19:57:02.0276 7016 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 19:57:02.0281 7016 secdrv - ok 19:57:02.0297 7016 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 19:57:02.0299 7016 seclogon - ok 19:57:02.0326 7016 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 19:57:02.0329 7016 SENS - ok 19:57:02.0353 7016 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 19:57:02.0360 7016 SensrSvc - ok 19:57:02.0383 7016 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 19:57:02.0388 7016 Serenum - ok 19:57:02.0412 7016 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 19:57:02.0420 7016 Serial - ok 19:57:02.0432 7016 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 19:57:02.0437 7016 sermouse - ok 19:57:02.0467 7016 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 19:57:02.0476 7016 SessionEnv - ok 19:57:02.0509 7016 [ 286D3889E6AB5589646FF8A63CB928AE ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys 19:57:02.0513 7016 SFEP - ok 19:57:02.0530 7016 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 19:57:02.0535 7016 sffdisk - ok 19:57:02.0539 7016 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 19:57:02.0545 7016 sffp_mmc - ok 19:57:02.0556 7016 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 19:57:02.0559 7016 sffp_sd - ok 19:57:02.0562 7016 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 19:57:02.0565 7016 sfloppy - ok 19:57:02.0630 7016 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 19:57:02.0653 7016 Sftfs - ok 19:57:02.0729 7016 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 19:57:02.0739 7016 sftlist - ok 19:57:02.0790 7016 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 19:57:02.0808 7016 Sftplay - ok 19:57:02.0835 7016 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 19:57:02.0844 7016 Sftredir - ok 19:57:02.0882 7016 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 19:57:02.0891 7016 Sftvol - ok 19:57:02.0925 7016 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 19:57:02.0930 7016 sftvsa - ok 19:57:02.0966 7016 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 19:57:02.0983 7016 SharedAccess - ok 19:57:03.0040 7016 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 19:57:03.0050 7016 ShellHWDetection - ok 19:57:03.0079 7016 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 19:57:03.0084 7016 SiSRaid2 - ok 19:57:03.0089 7016 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 19:57:03.0096 7016 SiSRaid4 - ok 19:57:03.0224 7016 [ 0F97E7A47A52F4A36969F0FC319654C2 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 19:57:03.0258 7016 Skype C2C Service - ok 19:57:03.0329 7016 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 19:57:03.0333 7016 SkypeUpdate - ok 19:57:03.0383 7016 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 19:57:03.0395 7016 Smb - ok 19:57:03.0442 7016 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 19:57:03.0453 7016 SNMPTRAP - ok 19:57:03.0557 7016 [ DDF2EC98AF6FC70608A4F9CE4DB52758 ] SOHCImp C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe 19:57:03.0575 7016 SOHCImp - ok 19:57:03.0583 7016 [ 5FA03F5EA6EFEF6D17B4A1A48C40A23C ] SOHDs C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe 19:57:03.0597 7016 SOHDs - ok 19:57:03.0640 7016 [ 65E5659E9C2A0762D05657C0E22A7CA2 ] SpfService C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe 19:57:03.0668 7016 SpfService - ok 19:57:03.0698 7016 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 19:57:03.0707 7016 spldr - ok 19:57:03.0762 7016 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 19:57:03.0776 7016 Spooler - ok 19:57:03.0905 7016 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 19:57:03.0937 7016 sppsvc - ok 19:57:03.0957 7016 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 19:57:03.0962 7016 sppuinotify - ok 19:57:03.0985 7016 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 19:57:03.0995 7016 srv - ok 19:57:04.0004 7016 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 19:57:04.0014 7016 srv2 - ok 19:57:04.0019 7016 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 19:57:04.0024 7016 srvnet - ok 19:57:04.0055 7016 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys 19:57:04.0067 7016 ssadbus - ok 19:57:04.0082 7016 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys 19:57:04.0089 7016 ssadmdfl - ok 19:57:04.0105 7016 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys 19:57:04.0116 7016 ssadmdm - ok 19:57:04.0146 7016 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 19:57:04.0149 7016 SSDPSRV - ok 19:57:04.0164 7016 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 19:57:04.0166 7016 SstpSvc - ok 19:57:04.0214 7016 [ 79969ACAEEBEDA7DC3673656AB9918FD ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 19:57:04.0217 7016 Stereo Service - ok 19:57:04.0250 7016 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 19:57:04.0254 7016 stexstor - ok 19:57:04.0289 7016 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 19:57:04.0296 7016 stisvc - ok 19:57:04.0313 7016 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 19:57:04.0317 7016 swenum - ok 19:57:04.0352 7016 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 19:57:04.0366 7016 swprv - ok 19:57:04.0414 7016 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 19:57:04.0431 7016 SysMain - ok 19:57:04.0447 7016 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 19:57:04.0454 7016 TabletInputService - ok 19:57:04.0487 7016 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 19:57:04.0491 7016 TapiSrv - ok 19:57:04.0503 7016 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 19:57:04.0506 7016 TBS - ok 19:57:04.0596 7016 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys 19:57:04.0636 7016 Tcpip - ok 19:57:04.0671 7016 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 19:57:04.0679 7016 TCPIP6 - ok 19:57:04.0698 7016 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 19:57:04.0702 7016 tcpipreg - ok 19:57:04.0730 7016 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 19:57:04.0733 7016 TDPIPE - ok 19:57:04.0766 7016 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 19:57:04.0773 7016 TDTCP - ok 19:57:04.0804 7016 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 19:57:04.0810 7016 tdx - ok 19:57:04.0814 7016 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 19:57:04.0820 7016 TermDD - ok 19:57:04.0859 7016 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 19:57:04.0867 7016 TermService - ok 19:57:04.0879 7016 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 19:57:04.0881 7016 Themes - ok 19:57:04.0907 7016 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 19:57:04.0909 7016 THREADORDER - ok 19:57:04.0927 7016 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 19:57:04.0930 7016 TrkWks - ok 19:57:04.0972 7016 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 19:57:04.0974 7016 TrustedInstaller - ok 19:57:05.0037 7016 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 19:57:05.0045 7016 tssecsrv - ok 19:57:05.0063 7016 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 19:57:05.0071 7016 TsUsbFlt - ok 19:57:05.0090 7016 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 19:57:05.0097 7016 TsUsbGD - ok 19:57:05.0129 7016 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 19:57:05.0132 7016 tunnel - ok 19:57:05.0138 7016 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 19:57:05.0145 7016 uagp35 - ok 19:57:05.0190 7016 [ 1FE69F3C1CA1CF4B7EC7E2E9090FFFDC ] uCamMonitor C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe 19:57:05.0192 7016 uCamMonitor - ok 19:57:05.0220 7016 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 19:57:05.0240 7016 udfs - ok 19:57:05.0271 7016 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 19:57:05.0281 7016 UI0Detect - ok 19:57:05.0301 7016 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 19:57:05.0309 7016 uliagpkx - ok 19:57:05.0318 7016 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 19:57:05.0323 7016 umbus - ok 19:57:05.0336 7016 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 19:57:05.0337 7016 UmPass - ok 19:57:05.0473 7016 [ 7A78ED1088890114DFDE2C4AB038D6B6 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 19:57:05.0495 7016 UNS - ok 19:57:05.0518 7016 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 19:57:05.0522 7016 upnphost - ok 19:57:05.0542 7016 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 19:57:05.0547 7016 usbccgp - ok 19:57:05.0568 7016 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 19:57:05.0575 7016 usbcir - ok 19:57:05.0578 7016 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 19:57:05.0583 7016 usbehci - ok 19:57:05.0605 7016 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 19:57:05.0616 7016 usbhub - ok 19:57:05.0625 7016 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 19:57:05.0630 7016 usbohci - ok 19:57:05.0661 7016 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 19:57:05.0664 7016 usbprint - ok 19:57:05.0716 7016 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 19:57:05.0726 7016 usbscan - ok 19:57:05.0758 7016 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:57:05.0771 7016 USBSTOR - ok 19:57:05.0778 7016 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 19:57:05.0788 7016 usbuhci - ok 19:57:05.0812 7016 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 19:57:05.0820 7016 usbvideo - ok 19:57:05.0851 7016 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 19:57:05.0854 7016 UxSms - ok 19:57:05.0889 7016 [ DCB1F83AD167D16D263CE57C94E9EEDF ] VAIO Event Service C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe 19:57:05.0891 7016 VAIO Event Service - ok 19:57:05.0911 7016 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 19:57:05.0915 7016 VaultSvc - ok 19:57:06.0027 7016 [ D00058C1FFF3F3DE990444A5734E9639 ] VCFw C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe 19:57:06.0134 7016 VCFw - ok 19:57:06.0258 7016 [ F19275655B42086C884ABCDAE2C659AE ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe 19:57:06.0308 7016 VcmIAlzMgr - ok 19:57:06.0324 7016 [ 2F06D134554BA84FE253DBC481DCFE6D ] VcmINSMgr C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe 19:57:06.0366 7016 VcmINSMgr - ok 19:57:06.0432 7016 [ 32A3735F6874B7783C6209ED5CA36D9D ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe 19:57:06.0449 7016 VcmXmlIfHelper - ok 19:57:06.0543 7016 [ D347D3ABE070AA09C22FC37121555D52 ] VCService C:\Program Files\Sony\VAIO Care\VCService.exe 19:57:06.0545 7016 VCService - ok 19:57:06.0579 7016 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 19:57:06.0590 7016 vdrvroot - ok 19:57:06.0633 7016 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 19:57:06.0645 7016 vds - ok 19:57:06.0662 7016 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 19:57:06.0668 7016 vga - ok 19:57:06.0673 7016 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 19:57:06.0678 7016 VgaSave - ok 19:57:06.0685 7016 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 19:57:06.0696 7016 vhdmp - ok 19:57:06.0699 7016 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 19:57:06.0703 7016 viaide - ok 19:57:06.0737 7016 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 19:57:06.0742 7016 volmgr - ok 19:57:06.0748 7016 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 19:57:06.0752 7016 volmgrx - ok 19:57:06.0759 7016 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 19:57:06.0768 7016 volsnap - ok 19:57:06.0794 7016 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 19:57:06.0800 7016 vsmraid - ok 19:57:06.0870 7016 [ 0ED394BFBA3EB4740F063E0BA5EC7104 ] VSNService C:\Program Files\Sony\VAIO Smart Network\VSNService.exe 19:57:06.0884 7016 VSNService - ok 19:57:06.0959 7016 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 19:57:06.0984 7016 VSS - ok 19:57:07.0111 7016 [ D2D646D4D686C6996BA1FF96E11BE570 ] VUAgent C:\Program Files\Sony\VAIO Update\VUAgent.exe 19:57:07.0124 7016 VUAgent - ok 19:57:07.0143 7016 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 19:57:07.0150 7016 vwifibus - ok 19:57:07.0190 7016 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 19:57:07.0197 7016 vwififlt - ok 19:57:07.0223 7016 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 19:57:07.0230 7016 W32Time - ok 19:57:07.0252 7016 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 19:57:07.0257 7016 WacomPen - ok 19:57:07.0262 7016 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 19:57:07.0268 7016 WANARP - ok 19:57:07.0271 7016 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 19:57:07.0273 7016 Wanarpv6 - ok 19:57:07.0325 7016 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 19:57:07.0351 7016 wbengine - ok 19:57:07.0363 7016 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 19:57:07.0373 7016 WbioSrvc - ok 19:57:07.0381 7016 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 19:57:07.0392 7016 wcncsvc - ok 19:57:07.0409 7016 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 19:57:07.0415 7016 WcsPlugInService - ok 19:57:07.0436 7016 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 19:57:07.0441 7016 Wd - ok 19:57:07.0474 7016 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 19:57:07.0493 7016 Wdf01000 - ok 19:57:07.0507 7016 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 19:57:07.0510 7016 WdiServiceHost - ok 19:57:07.0513 7016 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 19:57:07.0516 7016 WdiSystemHost - ok 19:57:07.0546 7016 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 19:57:07.0558 7016 WebClient - ok 19:57:07.0571 7016 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 19:57:07.0581 7016 Wecsvc - ok 19:57:07.0592 7016 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 19:57:07.0595 7016 wercplsupport - ok 19:57:07.0622 7016 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 19:57:07.0625 7016 WerSvc - ok 19:57:07.0643 7016 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 19:57:07.0646 7016 WfpLwf - ok 19:57:07.0666 7016 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 19:57:07.0670 7016 WIMMount - ok 19:57:07.0682 7016 WinDefend - ok 19:57:07.0699 7016 WinHttpAutoProxySvc - ok 19:57:07.0751 7016 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 19:57:07.0757 7016 Winmgmt - ok 19:57:07.0845 7016 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 19:57:07.0885 7016 WinRM - ok 19:57:07.0932 7016 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 19:57:07.0945 7016 WinUsb - ok 19:57:07.0996 7016 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 19:57:08.0008 7016 Wlansvc - ok 19:57:08.0053 7016 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 19:57:08.0067 7016 wlcrasvc - ok 19:57:08.0163 7016 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 19:57:08.0186 7016 wlidsvc - ok 19:57:08.0199 7016 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 19:57:08.0202 7016 WmiAcpi - ok 19:57:08.0225 7016 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 19:57:08.0232 7016 wmiApSrv - ok 19:57:08.0256 7016 WMPNetworkSvc - ok 19:57:08.0281 7016 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 19:57:08.0285 7016 WPCSvc - ok 19:57:08.0301 7016 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 19:57:08.0303 7016 WPDBusEnum - ok 19:57:08.0324 7016 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 19:57:08.0327 7016 ws2ifsl - ok 19:57:08.0346 7016 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 19:57:08.0351 7016 wscsvc - ok 19:57:08.0396 7016 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 19:57:08.0403 7016 WSDPrintDevice - ok 19:57:08.0421 7016 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys 19:57:08.0425 7016 WSDScan - ok 19:57:08.0428 7016 WSearch - ok 19:57:08.0519 7016 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 19:57:08.0548 7016 wuauserv - ok 19:57:08.0577 7016 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 19:57:08.0583 7016 WudfPf - ok 19:57:08.0633 7016 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 19:57:08.0649 7016 WUDFRd - ok 19:57:08.0699 7016 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 19:57:08.0714 7016 wudfsvc - ok 19:57:08.0754 7016 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll 19:57:08.0773 7016 WwanSvc - ok 19:57:08.0796 7016 ================ Scan global =============================== 19:57:08.0827 7016 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 19:57:08.0857 7016 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 19:57:08.0866 7016 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 19:57:08.0898 7016 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 19:57:08.0935 7016 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 19:57:08.0939 7016 [Global] - ok 19:57:08.0940 7016 ================ Scan MBR ================================== 19:57:08.0950 7016 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 19:57:09.0144 7016 \Device\Harddisk0\DR0 - ok 19:57:09.0145 7016 ================ Scan VBR ================================== 19:57:09.0149 7016 [ B66EC185B9DE52245CC45448CF4642D5 ] \Device\Harddisk0\DR0\Partition1 19:57:09.0153 7016 \Device\Harddisk0\DR0\Partition1 - ok 19:57:09.0167 7016 [ 25BFE8FE0C20C7A147DF3812DF9289A6 ] \Device\Harddisk0\DR0\Partition2 19:57:09.0169 7016 \Device\Harddisk0\DR0\Partition2 - ok 19:57:09.0170 7016 ============================================================ 19:57:09.0170 7016 Scan finished 19:57:09.0170 7016 ============================================================ 19:57:09.0181 6356 Detected object count: 0 19:57:09.0181 6356 Actual detected object count: 0 |
18.06.2013, 20:28 | #8 |
/// Malware-holic | wssetup exe bitte nach anleitung konfigurieren und scannen
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
18.06.2013, 21:40 | #9 |
| wssetup exe soory,22:32:42.0918 4908 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 22:32:43.0152 4908 ============================================================ 22:32:43.0152 4908 Current date / time: 2013/06/18 22:32:43.0152 22:32:43.0152 4908 SystemInfo: 22:32:43.0152 4908 22:32:43.0152 4908 OS Version: 6.1.7601 ServicePack: 1.0 22:32:43.0152 4908 Product type: Workstation 22:32:43.0152 4908 ComputerName: CHRIS-VAIO 22:32:43.0152 4908 UserName: chris 22:32:43.0152 4908 Windows directory: C:\Windows 22:32:43.0152 4908 System windows directory: C:\Windows 22:32:43.0152 4908 Running under WOW64 22:32:43.0152 4908 Processor architecture: Intel x64 22:32:43.0152 4908 Number of processors: 4 22:32:43.0152 4908 Page size: 0x1000 22:32:43.0152 4908 Boot type: Normal boot 22:32:43.0152 4908 ============================================================ 22:32:43.0932 4908 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:32:43.0948 4908 ============================================================ 22:32:43.0948 4908 \Device\Harddisk0\DR0: 22:32:43.0948 4908 MBR partitions: 22:32:43.0948 4908 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1BC9800, BlocksNum 0x32000 22:32:43.0948 4908 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1BFB800, BlocksNum 0x48C5C000 22:32:43.0948 4908 ============================================================ 22:32:43.0979 4908 C: <-> \Device\Harddisk0\DR0\Partition2 22:32:43.0979 4908 ============================================================ 22:32:43.0979 4908 Initialize success 22:32:43.0979 4908 ============================================================ 22:33:03.0701 2012 ============================================================ 22:33:03.0701 2012 Scan started 22:33:03.0701 2012 Mode: Manual; SigCheck; TDLFS; 22:33:03.0701 2012 ============================================================ 22:33:03.0966 2012 ================ Scan system memory ======================== 22:33:03.0966 2012 System memory - ok 22:33:03.0966 2012 ================ Scan services ============================= 22:33:04.0200 2012 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 22:33:04.0388 2012 1394ohci - ok 22:33:04.0512 2012 [ B33CF4DE909A5B30F526D82053A63C8E ] ABBYY.Licensing.FineReader.Sprint.9.0 C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe 22:33:04.0559 2012 ABBYY.Licensing.FineReader.Sprint.9.0 - ok 22:33:04.0637 2012 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 22:33:04.0684 2012 ACDaemon - ok 22:33:04.0731 2012 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 22:33:04.0778 2012 ACPI - ok 22:33:04.0793 2012 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 22:33:04.0902 2012 AcpiPmi - ok 22:33:04.0965 2012 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 22:33:04.0980 2012 AdobeARMservice - ok 22:33:05.0136 2012 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 22:33:05.0168 2012 AdobeFlashPlayerUpdateSvc - ok 22:33:05.0230 2012 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 22:33:05.0277 2012 adp94xx - ok 22:33:05.0308 2012 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 22:33:05.0324 2012 adpahci - ok 22:33:05.0339 2012 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 22:33:05.0355 2012 adpu320 - ok 22:33:05.0370 2012 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 22:33:05.0542 2012 AeLookupSvc - ok 22:33:05.0573 2012 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 22:33:05.0651 2012 AFD - ok 22:33:05.0698 2012 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 22:33:05.0729 2012 agp440 - ok 22:33:05.0760 2012 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 22:33:05.0823 2012 ALG - ok 22:33:05.0838 2012 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 22:33:05.0854 2012 aliide - ok 22:33:05.0870 2012 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 22:33:05.0885 2012 amdide - ok 22:33:05.0901 2012 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 22:33:05.0948 2012 AmdK8 - ok 22:33:05.0963 2012 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 22:33:06.0010 2012 AmdPPM - ok 22:33:06.0041 2012 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 22:33:06.0072 2012 amdsata - ok 22:33:06.0119 2012 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 22:33:06.0150 2012 amdsbs - ok 22:33:06.0166 2012 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 22:33:06.0197 2012 amdxata - ok 22:33:06.0400 2012 [ D9A92E6DD41C5ADC045AE485026AA40C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 22:33:06.0416 2012 AntiVirSchedulerService - ok 22:33:06.0494 2012 [ 66A7A38F7C439153B758548375EB9E5E ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 22:33:06.0509 2012 AntiVirService - ok 22:33:06.0556 2012 [ 9EDAE2D1CA368E8D01BEE8BFBC9488E4 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE 22:33:06.0618 2012 AntiVirWebService - ok 22:33:06.0665 2012 [ D80CB25D90474C731C0D1312A6DE3B13 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys 22:33:06.0712 2012 ApfiltrService - ok 22:33:06.0743 2012 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 22:33:06.0977 2012 AppID - ok 22:33:07.0008 2012 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 22:33:07.0086 2012 AppIDSvc - ok 22:33:07.0149 2012 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll 22:33:07.0227 2012 Appinfo - ok 22:33:07.0274 2012 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 22:33:07.0305 2012 arc - ok 22:33:07.0320 2012 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 22:33:07.0336 2012 arcsas - ok 22:33:07.0367 2012 [ C130BC4A51B1382B2BE8E44579EC4C0A ] ArcSoftKsUFilter C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys 22:33:07.0383 2012 ArcSoftKsUFilter - ok 22:33:07.0493 2012 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 22:33:07.0540 2012 aspnet_state - ok 22:33:07.0571 2012 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 22:33:07.0680 2012 AsyncMac - ok 22:33:07.0696 2012 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 22:33:07.0727 2012 atapi - ok 22:33:07.0758 2012 [ 50F257E19554421B6891E3F998EDCA90 ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys 22:33:07.0821 2012 AthBTPort - ok 22:33:07.0883 2012 [ 650F111D5CDA64C10AE4B9D1BA9D4FFF ] Atheros Bt&Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe 22:33:07.0914 2012 Atheros Bt&Wlan Coex Agent ( UnsignedFile.Multi.Generic ) - warning 22:33:07.0914 2012 Atheros Bt&Wlan Coex Agent - detected UnsignedFile.Multi.Generic (1) 22:33:07.0945 2012 [ EBC3119394C9074A9CD87578A435050D ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe 22:33:07.0961 2012 AtherosSvc ( UnsignedFile.Multi.Generic ) - warning 22:33:07.0961 2012 AtherosSvc - detected UnsignedFile.Multi.Generic (1) 22:33:08.0070 2012 [ C8679A07267F030704168E45E27C3D43 ] athr C:\Windows\system32\DRIVERS\athrx.sys 22:33:08.0195 2012 athr - ok 22:33:08.0257 2012 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 22:33:08.0335 2012 AudioEndpointBuilder - ok 22:33:08.0351 2012 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 22:33:08.0382 2012 AudioSrv - ok 22:33:08.0429 2012 [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 22:33:08.0460 2012 avgntflt - ok 22:33:08.0523 2012 [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 22:33:08.0569 2012 avipbb - ok 22:33:08.0632 2012 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 22:33:08.0663 2012 avkmgr - ok 22:33:08.0710 2012 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 22:33:08.0819 2012 AxInstSV - ok 22:33:08.0881 2012 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 22:33:08.0944 2012 b06bdrv - ok 22:33:08.0991 2012 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 22:33:09.0037 2012 b57nd60a - ok 22:33:09.0147 2012 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe 22:33:09.0178 2012 BBSvc - ok 22:33:09.0271 2012 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe 22:33:09.0303 2012 BBUpdate - ok 22:33:09.0334 2012 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 22:33:09.0381 2012 BDESVC - ok 22:33:09.0412 2012 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 22:33:09.0521 2012 Beep - ok 22:33:09.0583 2012 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 22:33:09.0677 2012 BFE - ok 22:33:09.0724 2012 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 22:33:09.0849 2012 BITS - ok 22:33:09.0880 2012 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 22:33:09.0911 2012 blbdrive - ok 22:33:09.0942 2012 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 22:33:10.0005 2012 bowser - ok 22:33:10.0020 2012 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 22:33:10.0083 2012 BrFiltLo - ok 22:33:10.0098 2012 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 22:33:10.0129 2012 BrFiltUp - ok 22:33:10.0176 2012 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 22:33:10.0254 2012 BridgeMP - ok 22:33:10.0285 2012 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 22:33:10.0348 2012 Browser - ok 22:33:10.0395 2012 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 22:33:10.0457 2012 Brserid - ok 22:33:10.0488 2012 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 22:33:10.0535 2012 BrSerWdm - ok 22:33:10.0566 2012 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 22:33:10.0597 2012 BrUsbMdm - ok 22:33:10.0613 2012 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 22:33:10.0629 2012 BrUsbSer - ok 22:33:10.0691 2012 [ B3BCD755FA9A359D10208CC9F09847CC ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys 22:33:10.0753 2012 BTATH_A2DP - ok 22:33:10.0800 2012 [ 9BBBA9D6DBDEFC8A6542BC7A6EBAF710 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys 22:33:10.0847 2012 btath_avdt - ok 22:33:10.0878 2012 [ D838DD1BCB328EFCFAD7A52DE9E3CAFD ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys 22:33:10.0941 2012 BTATH_BUS - ok 22:33:10.0956 2012 [ A441B800E04CF8443FAF519207563ABB ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys 22:33:11.0019 2012 BTATH_HCRP - ok 22:33:11.0081 2012 [ B16F8429A35BBA2A8EF9DB2E08675B97 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys 22:33:11.0143 2012 BTATH_LWFLT - ok 22:33:11.0175 2012 [ C24231C6BDFE21735930084A22089AAB ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys 22:33:11.0237 2012 BTATH_RCP - ok 22:33:11.0315 2012 [ 3632FA4C6B3CE9EC827690DEAC266D8C ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys 22:33:11.0393 2012 BtFilter - ok 22:33:11.0455 2012 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 22:33:11.0518 2012 BthEnum - ok 22:33:11.0549 2012 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 22:33:11.0596 2012 BTHMODEM - ok 22:33:11.0611 2012 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 22:33:11.0674 2012 BthPan - ok 22:33:11.0721 2012 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 22:33:11.0783 2012 BTHPORT - ok 22:33:11.0830 2012 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 22:33:11.0892 2012 bthserv - ok 22:33:11.0939 2012 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 22:33:11.0970 2012 BTHUSB - ok 22:33:12.0111 2012 catchme - ok 22:33:12.0142 2012 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 22:33:12.0251 2012 cdfs - ok 22:33:12.0282 2012 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 22:33:12.0329 2012 cdrom - ok 22:33:12.0360 2012 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 22:33:12.0438 2012 CertPropSvc - ok 22:33:12.0454 2012 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 22:33:12.0501 2012 circlass - ok 22:33:12.0517 2012 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 22:33:12.0548 2012 CLFS - ok 22:33:12.0626 2012 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 22:33:12.0642 2012 clr_optimization_v2.0.50727_32 - ok 22:33:12.0704 2012 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 22:33:12.0736 2012 clr_optimization_v2.0.50727_64 - ok 22:33:12.0798 2012 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 22:33:12.0845 2012 clr_optimization_v4.0.30319_32 - ok 22:33:12.0876 2012 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 22:33:12.0923 2012 clr_optimization_v4.0.30319_64 - ok 22:33:12.0970 2012 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 22:33:13.0001 2012 CmBatt - ok 22:33:13.0016 2012 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 22:33:13.0048 2012 cmdide - ok 22:33:13.0110 2012 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 22:33:13.0188 2012 CNG - ok 22:33:13.0282 2012 [ 1F394DF3714ED4280047810790E6DF69 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys 22:33:13.0375 2012 CnxtHdAudService - ok 22:33:13.0422 2012 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 22:33:13.0453 2012 Compbatt - ok 22:33:13.0469 2012 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 22:33:13.0516 2012 CompositeBus - ok 22:33:13.0547 2012 COMSysApp - ok 22:33:13.0562 2012 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 22:33:13.0578 2012 crcdisk - ok 22:33:13.0640 2012 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll 22:33:13.0703 2012 CryptSvc - ok 22:33:13.0828 2012 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 22:33:13.0874 2012 cvhsvc - ok 22:33:13.0921 2012 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 22:33:14.0015 2012 DcomLaunch - ok 22:33:14.0046 2012 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 22:33:14.0140 2012 defragsvc - ok 22:33:14.0171 2012 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 22:33:14.0280 2012 DfsC - ok 22:33:14.0327 2012 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 22:33:14.0405 2012 Dhcp - ok 22:33:14.0436 2012 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 22:33:14.0545 2012 discache - ok 22:33:14.0576 2012 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 22:33:14.0608 2012 Disk - ok 22:33:14.0623 2012 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 22:33:14.0670 2012 Dnscache - ok 22:33:14.0686 2012 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 22:33:14.0779 2012 dot3svc - ok 22:33:14.0795 2012 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 22:33:14.0857 2012 DPS - ok 22:33:14.0904 2012 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 22:33:14.0951 2012 drmkaud - ok 22:33:15.0013 2012 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 22:33:15.0091 2012 DXGKrnl - ok 22:33:15.0138 2012 [ 50AD8FC1DC800FF36087994C8F7FDFF2 ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys 22:33:15.0169 2012 e1yexpress - ok 22:33:15.0200 2012 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 22:33:15.0278 2012 EapHost - ok 22:33:15.0372 2012 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 22:33:15.0497 2012 ebdrv - ok 22:33:15.0528 2012 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 22:33:15.0575 2012 EFS - ok 22:33:15.0637 2012 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 22:33:15.0715 2012 ehRecvr - ok 22:33:15.0731 2012 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 22:33:15.0778 2012 ehSched - ok 22:33:15.0809 2012 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 22:33:15.0840 2012 elxstor - ok 22:33:15.0887 2012 [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe 22:33:15.0887 2012 EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - warning 22:33:15.0887 2012 EpsonBidirectionalService - detected UnsignedFile.Multi.Generic (1) 22:33:15.0965 2012 [ 20ECD0A490A121CB34F553FAD1DBBD39 ] EpsonScanSvc C:\Windows\system32\EscSvc64.exe 22:33:15.0996 2012 EpsonScanSvc - ok 22:33:16.0074 2012 [ 194E8100D57FC13BEF88129BAAD07E46 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE 22:33:16.0090 2012 EPSON_PM_RPCV4_04 - ok 22:33:16.0105 2012 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 22:33:16.0168 2012 ErrDev - ok 22:33:16.0246 2012 esgiguard - ok 22:33:16.0292 2012 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 22:33:16.0417 2012 EventSystem - ok 22:33:16.0448 2012 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 22:33:16.0542 2012 exfat - ok 22:33:16.0558 2012 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 22:33:16.0636 2012 fastfat - ok 22:33:16.0682 2012 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 22:33:16.0745 2012 Fax - ok 22:33:16.0776 2012 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 22:33:16.0807 2012 fdc - ok 22:33:16.0854 2012 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 22:33:16.0948 2012 fdPHost - ok 22:33:16.0963 2012 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 22:33:17.0057 2012 FDResPub - ok 22:33:17.0072 2012 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 22:33:17.0104 2012 FileInfo - ok 22:33:17.0119 2012 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 22:33:17.0182 2012 Filetrace - ok 22:33:17.0182 2012 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 22:33:17.0197 2012 flpydisk - ok 22:33:17.0197 2012 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 22:33:17.0228 2012 FltMgr - ok 22:33:17.0291 2012 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 22:33:17.0369 2012 FontCache - ok 22:33:17.0416 2012 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 22:33:17.0447 2012 FontCache3.0.0.0 - ok 22:33:17.0478 2012 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 22:33:17.0525 2012 FsDepends - ok 22:33:17.0556 2012 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 22:33:17.0588 2012 Fs_Rec - ok 22:33:17.0635 2012 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 22:33:17.0697 2012 fvevol - ok 22:33:17.0744 2012 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 22:33:17.0760 2012 gagp30kx - ok 22:33:17.0807 2012 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 22:33:17.0885 2012 gpsvc - ok 22:33:17.0963 2012 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:33:17.0978 2012 gupdate - ok 22:33:17.0994 2012 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:33:18.0009 2012 gupdatem - ok 22:33:18.0041 2012 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 22:33:18.0103 2012 hcw85cir - ok 22:33:18.0134 2012 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 22:33:18.0212 2012 HdAudAddService - ok 22:33:18.0259 2012 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 22:33:18.0306 2012 HDAudBus - ok 22:33:18.0337 2012 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 22:33:18.0384 2012 HidBatt - ok 22:33:18.0399 2012 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 22:33:18.0446 2012 HidBth - ok 22:33:18.0462 2012 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 22:33:18.0493 2012 HidIr - ok 22:33:18.0524 2012 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 22:33:18.0587 2012 hidserv - ok 22:33:18.0680 2012 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys 22:33:18.0711 2012 HidUsb - ok 22:33:18.0743 2012 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 22:33:18.0836 2012 hkmsvc - ok 22:33:18.0852 2012 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 22:33:18.0899 2012 HomeGroupListener - ok 22:33:18.0930 2012 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 22:33:18.0961 2012 HomeGroupProvider - ok 22:33:18.0992 2012 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 22:33:19.0008 2012 HpSAMD - ok 22:33:19.0039 2012 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 22:33:19.0133 2012 HTTP - ok 22:33:19.0148 2012 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 22:33:19.0164 2012 hwpolicy - ok 22:33:19.0195 2012 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 22:33:19.0226 2012 i8042prt - ok 22:33:19.0257 2012 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\drivers\iaStor.sys 22:33:19.0289 2012 iaStor - ok 22:33:19.0351 2012 [ B25F192EA1F84A316EB7C19EFCCCF33D ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 22:33:19.0367 2012 IAStorDataMgrSvc - ok 22:33:19.0413 2012 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 22:33:19.0445 2012 iaStorV - ok 22:33:19.0538 2012 [ 6F3909A3D40CC9F4B28E03B027F918D8 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe 22:33:19.0601 2012 IconMan_R ( UnsignedFile.Multi.Generic ) - warning 22:33:19.0601 2012 IconMan_R - detected UnsignedFile.Multi.Generic (1) 22:33:19.0679 2012 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 22:33:19.0725 2012 idsvc - ok 22:33:19.0757 2012 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 22:33:19.0772 2012 iirsp - ok 22:33:19.0819 2012 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 22:33:19.0897 2012 IKEEXT - ok 22:33:19.0897 2012 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 22:33:19.0913 2012 intelide - ok 22:33:19.0944 2012 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 22:33:19.0975 2012 intelppm - ok 22:33:20.0006 2012 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 22:33:20.0069 2012 IPBusEnum - ok 22:33:20.0084 2012 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:33:20.0131 2012 IpFilterDriver - ok 22:33:20.0178 2012 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 22:33:20.0240 2012 iphlpsvc - ok 22:33:20.0271 2012 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 22:33:20.0303 2012 IPMIDRV - ok 22:33:20.0318 2012 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 22:33:20.0381 2012 IPNAT - ok 22:33:20.0396 2012 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 22:33:20.0427 2012 IRENUM - ok 22:33:20.0443 2012 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 22:33:20.0459 2012 isapnp - ok 22:33:20.0474 2012 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 22:33:20.0505 2012 iScsiPrt - ok 22:33:20.0537 2012 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 22:33:20.0568 2012 kbdclass - ok 22:33:20.0599 2012 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 22:33:20.0646 2012 kbdhid - ok 22:33:20.0661 2012 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 22:33:20.0677 2012 KeyIso - ok 22:33:20.0708 2012 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 22:33:20.0755 2012 KSecDD - ok 22:33:20.0771 2012 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 22:33:20.0802 2012 KSecPkg - ok 22:33:20.0833 2012 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 22:33:20.0911 2012 ksthunk - ok 22:33:20.0942 2012 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 22:33:21.0005 2012 KtmRm - ok 22:33:21.0036 2012 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 22:33:21.0098 2012 LanmanServer - ok 22:33:21.0114 2012 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 22:33:21.0176 2012 LanmanWorkstation - ok 22:33:21.0223 2012 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 22:33:21.0301 2012 lltdio - ok 22:33:21.0332 2012 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 22:33:21.0395 2012 lltdsvc - ok 22:33:21.0426 2012 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 22:33:21.0504 2012 lmhosts - ok 22:33:21.0566 2012 [ 98B16E756243BEA9410E32025B19C06F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 22:33:21.0582 2012 LMS - ok 22:33:21.0629 2012 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 22:33:21.0660 2012 LSI_FC - ok 22:33:21.0660 2012 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 22:33:21.0691 2012 LSI_SAS - ok 22:33:21.0691 2012 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 22:33:21.0722 2012 LSI_SAS2 - ok 22:33:21.0722 2012 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 22:33:21.0753 2012 LSI_SCSI - ok 22:33:21.0769 2012 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 22:33:21.0863 2012 luafv - ok 22:33:21.0863 2012 lxcz_device - ok 22:33:21.0878 2012 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 22:33:21.0894 2012 MBAMProtector - ok 22:33:21.0987 2012 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 22:33:22.0034 2012 MBAMScheduler - ok 22:33:22.0112 2012 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 22:33:22.0143 2012 MBAMService - ok 22:33:22.0175 2012 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 22:33:22.0221 2012 Mcx2Svc - ok 22:33:22.0237 2012 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 22:33:22.0253 2012 megasas - ok 22:33:22.0284 2012 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 22:33:22.0315 2012 MegaSR - ok 22:33:22.0346 2012 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 22:33:22.0377 2012 MEIx64 - ok 22:33:22.0409 2012 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 22:33:22.0471 2012 MMCSS - ok 22:33:22.0487 2012 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 22:33:22.0533 2012 Modem - ok 22:33:22.0565 2012 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 22:33:22.0596 2012 monitor - ok 22:33:22.0596 2012 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 22:33:22.0611 2012 mouclass - ok 22:33:22.0627 2012 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\drivers\mouhid.sys 22:33:22.0674 2012 mouhid - ok 22:33:22.0705 2012 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 22:33:22.0736 2012 mountmgr - ok 22:33:22.0752 2012 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 22:33:22.0783 2012 mpio - ok 22:33:22.0799 2012 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 22:33:22.0877 2012 mpsdrv - ok 22:33:22.0923 2012 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 22:33:23.0001 2012 MpsSvc - ok 22:33:23.0017 2012 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 22:33:23.0048 2012 MRxDAV - ok 22:33:23.0079 2012 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 22:33:23.0142 2012 mrxsmb - ok 22:33:23.0157 2012 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:33:23.0204 2012 mrxsmb10 - ok 22:33:23.0220 2012 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:33:23.0267 2012 mrxsmb20 - ok 22:33:23.0298 2012 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 22:33:23.0329 2012 msahci - ok 22:33:23.0329 2012 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 22:33:23.0376 2012 msdsm - ok 22:33:23.0391 2012 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 22:33:23.0438 2012 MSDTC - ok 22:33:23.0469 2012 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 22:33:23.0579 2012 Msfs - ok 22:33:23.0625 2012 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 22:33:23.0719 2012 mshidkmdf - ok 22:33:23.0750 2012 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 22:33:23.0766 2012 msisadrv - ok 22:33:23.0797 2012 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 22:33:23.0875 2012 MSiSCSI - ok 22:33:23.0875 2012 msiserver - ok 22:33:23.0891 2012 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 22:33:23.0953 2012 MSKSSRV - ok 22:33:23.0969 2012 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 22:33:24.0015 2012 MSPCLOCK - ok 22:33:24.0031 2012 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 22:33:24.0078 2012 MSPQM - ok 22:33:24.0109 2012 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 22:33:24.0125 2012 MsRPC - ok 22:33:24.0156 2012 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 22:33:24.0187 2012 mssmbios - ok 22:33:24.0218 2012 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 22:33:24.0327 2012 MSTEE - ok 22:33:24.0327 2012 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 22:33:24.0343 2012 MTConfig - ok 22:33:24.0359 2012 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 22:33:24.0374 2012 Mup - ok 22:33:24.0405 2012 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 22:33:24.0499 2012 napagent - ok 22:33:24.0530 2012 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 22:33:24.0608 2012 NativeWifiP - ok 22:33:24.0655 2012 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 22:33:24.0717 2012 NDIS - ok 22:33:24.0733 2012 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 22:33:24.0795 2012 NdisCap - ok 22:33:24.0827 2012 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 22:33:24.0905 2012 NdisTapi - ok 22:33:24.0905 2012 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 22:33:24.0967 2012 Ndisuio - ok 22:33:24.0967 2012 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 22:33:25.0045 2012 NdisWan - ok 22:33:25.0061 2012 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 22:33:25.0107 2012 NDProxy - ok 22:33:25.0139 2012 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 22:33:25.0217 2012 NetBIOS - ok 22:33:25.0217 2012 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 22:33:25.0295 2012 NetBT - ok 22:33:25.0295 2012 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 22:33:25.0310 2012 Netlogon - ok 22:33:25.0341 2012 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 22:33:25.0388 2012 Netman - ok 22:33:25.0419 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:33:25.0466 2012 NetMsmqActivator - ok 22:33:25.0482 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:33:25.0497 2012 NetPipeActivator - ok 22:33:25.0497 2012 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 22:33:25.0575 2012 netprofm - ok 22:33:25.0591 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:33:25.0591 2012 NetTcpActivator - ok 22:33:25.0607 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:33:25.0607 2012 NetTcpPortSharing - ok 22:33:25.0638 2012 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 22:33:25.0669 2012 nfrd960 - ok 22:33:25.0700 2012 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 22:33:25.0731 2012 NlaSvc - ok 22:33:25.0763 2012 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 22:33:25.0841 2012 Npfs - ok 22:33:25.0872 2012 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 22:33:25.0919 2012 nsi - ok 22:33:25.0919 2012 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 22:33:25.0965 2012 nsiproxy - ok 22:33:26.0028 2012 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 22:33:26.0106 2012 Ntfs - ok 22:33:26.0137 2012 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 22:33:26.0184 2012 Null - ok 22:33:26.0215 2012 [ F12E3EA0386EBC284C893611107C6A96 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 22:33:26.0246 2012 NVHDA - ok 22:33:26.0527 2012 [ D5DEA2C1865CAB9EE6AA29CF9E79A2CE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 22:33:27.0057 2012 nvlddmkm - ok 22:33:27.0089 2012 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 22:33:27.0104 2012 nvraid - ok 22:33:27.0120 2012 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 22:33:27.0135 2012 nvstor - ok 22:33:27.0198 2012 [ 5A4AF8EA634B4FEEAF6F16BB1845715A ] NVSvc C:\Windows\system32\nvvsvc.exe 22:33:27.0245 2012 NVSvc - ok 22:33:27.0245 2012 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 22:33:27.0260 2012 nv_agp - ok 22:33:27.0276 2012 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 22:33:27.0307 2012 ohci1394 - ok 22:33:27.0354 2012 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 22:33:27.0401 2012 ose - ok 22:33:27.0557 2012 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 22:33:27.0635 2012 osppsvc - ok 22:33:27.0666 2012 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 22:33:27.0697 2012 p2pimsvc - ok 22:33:27.0728 2012 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 22:33:27.0744 2012 p2psvc - ok 22:33:27.0775 2012 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 22:33:27.0822 2012 Parport - ok 22:33:27.0869 2012 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 22:33:27.0900 2012 partmgr - ok 22:33:27.0947 2012 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 22:33:28.0009 2012 PcaSvc - ok 22:33:28.0040 2012 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 22:33:28.0087 2012 pci - ok 22:33:28.0103 2012 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 22:33:28.0134 2012 pciide - ok 22:33:28.0149 2012 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 22:33:28.0196 2012 pcmcia - ok 22:33:28.0196 2012 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 22:33:28.0227 2012 pcw - ok 22:33:28.0243 2012 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 22:33:28.0337 2012 PEAUTH - ok 22:33:28.0415 2012 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 22:33:28.0461 2012 PerfHost - ok 22:33:28.0539 2012 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 22:33:28.0695 2012 pla - ok 22:33:28.0727 2012 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 22:33:28.0805 2012 PlugPlay - ok 22:33:29.0054 2012 [ 63694C307273062A2167AE4CE80730EF ] PMBDeviceInfoProvider c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe 22:33:29.0101 2012 PMBDeviceInfoProvider - ok 22:33:29.0132 2012 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 22:33:29.0179 2012 PNRPAutoReg - ok 22:33:29.0195 2012 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 22:33:29.0241 2012 PNRPsvc - ok 22:33:29.0273 2012 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 22:33:29.0382 2012 PolicyAgent - ok 22:33:29.0429 2012 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 22:33:29.0507 2012 Power - ok 22:33:29.0538 2012 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 22:33:29.0585 2012 PptpMiniport - ok 22:33:29.0600 2012 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 22:33:29.0616 2012 Processor - ok 22:33:29.0647 2012 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 22:33:29.0694 2012 ProfSvc - ok 22:33:29.0709 2012 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 22:33:29.0741 2012 ProtectedStorage - ok 22:33:29.0772 2012 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 22:33:29.0865 2012 Psched - ok 22:33:29.0943 2012 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 22:33:30.0006 2012 ql2300 - ok 22:33:30.0006 2012 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 22:33:30.0037 2012 ql40xx - ok 22:33:30.0068 2012 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 22:33:30.0115 2012 QWAVE - ok 22:33:30.0131 2012 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 22:33:30.0177 2012 QWAVEdrv - ok 22:33:30.0193 2012 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 22:33:30.0255 2012 RasAcd - ok 22:33:30.0287 2012 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 22:33:30.0333 2012 RasAgileVpn - ok 22:33:30.0365 2012 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 22:33:30.0411 2012 RasAuto - ok 22:33:30.0443 2012 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 22:33:30.0521 2012 Rasl2tp - ok 22:33:30.0567 2012 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 22:33:30.0599 2012 RasMan - ok 22:33:30.0630 2012 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 22:33:30.0692 2012 RasPppoe - ok 22:33:30.0708 2012 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 22:33:30.0755 2012 RasSstp - ok 22:33:30.0770 2012 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 22:33:30.0817 2012 rdbss - ok 22:33:30.0817 2012 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 22:33:30.0848 2012 rdpbus - ok 22:33:30.0864 2012 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 22:33:30.0895 2012 RDPCDD - ok 22:33:30.0895 2012 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 22:33:30.0942 2012 RDPENCDD - ok 22:33:30.0973 2012 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 22:33:31.0004 2012 RDPREFMP - ok 22:33:31.0020 2012 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 22:33:31.0082 2012 RDPWD - ok 22:33:31.0098 2012 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 22:33:31.0129 2012 rdyboost - ok 22:33:31.0160 2012 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 22:33:31.0223 2012 RemoteAccess - ok 22:33:31.0269 2012 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 22:33:31.0347 2012 RemoteRegistry - ok 22:33:31.0379 2012 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 22:33:31.0425 2012 RFCOMM - ok 22:33:31.0441 2012 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 22:33:31.0535 2012 RpcEptMapper - ok 22:33:31.0566 2012 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 22:33:31.0597 2012 RpcLocator - ok 22:33:31.0628 2012 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 22:33:31.0691 2012 RpcSs - ok 22:33:31.0722 2012 [ 546D7F426776090B90EF5F195B6AE662 ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys 22:33:31.0753 2012 RSPCIESTOR - ok 22:33:31.0769 2012 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 22:33:31.0831 2012 rspndr - ok 22:33:31.0878 2012 [ EA5532868BA76923D75BCB2A1448D810 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 22:33:31.0925 2012 RTL8167 - ok 22:33:31.0956 2012 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 22:33:31.0987 2012 SamSs - ok 22:33:32.0018 2012 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 22:33:32.0034 2012 sbp2port - ok 22:33:32.0065 2012 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 22:33:32.0127 2012 SCardSvr - ok 22:33:32.0143 2012 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 22:33:32.0190 2012 scfilter - ok 22:33:32.0237 2012 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 22:33:32.0283 2012 Schedule - ok 22:33:32.0315 2012 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 22:33:32.0346 2012 SCPolicySvc - ok 22:33:32.0377 2012 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 22:33:32.0439 2012 sdbus - ok 22:33:32.0471 2012 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 22:33:32.0533 2012 SDRSVC - ok 22:33:32.0549 2012 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 22:33:32.0627 2012 secdrv - ok 22:33:32.0642 2012 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 22:33:32.0689 2012 seclogon - ok 22:33:32.0705 2012 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 22:33:32.0751 2012 SENS - ok 22:33:32.0783 2012 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 22:33:32.0829 2012 SensrSvc - ok 22:33:32.0845 2012 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 22:33:32.0892 2012 Serenum - ok 22:33:32.0907 2012 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 22:33:32.0954 2012 Serial - ok 22:33:32.0985 2012 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 22:33:33.0017 2012 sermouse - ok 22:33:33.0063 2012 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 22:33:33.0126 2012 SessionEnv - ok 22:33:33.0157 2012 [ 286D3889E6AB5589646FF8A63CB928AE ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys 22:33:33.0204 2012 SFEP - ok 22:33:33.0219 2012 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 22:33:33.0266 2012 sffdisk - ok 22:33:33.0282 2012 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 22:33:33.0344 2012 sffp_mmc - ok 22:33:33.0344 2012 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 22:33:33.0407 2012 sffp_sd - ok 22:33:33.0407 2012 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 22:33:33.0453 2012 sfloppy - ok 22:33:33.0516 2012 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 22:33:33.0563 2012 Sftfs - ok 22:33:33.0641 2012 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 22:33:33.0672 2012 sftlist - ok 22:33:33.0719 2012 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 22:33:33.0765 2012 Sftplay - ok 22:33:33.0797 2012 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 22:33:33.0828 2012 Sftredir - ok 22:33:33.0859 2012 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 22:33:33.0890 2012 Sftvol - ok 22:33:33.0921 2012 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 22:33:33.0921 2012 sftvsa - ok 22:33:33.0968 2012 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 22:33:34.0031 2012 SharedAccess - ok 22:33:34.0046 2012 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 22:33:34.0124 2012 ShellHWDetection - ok 22:33:34.0140 2012 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 22:33:34.0155 2012 SiSRaid2 - ok 22:33:34.0171 2012 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 22:33:34.0187 2012 SiSRaid4 - ok 22:33:34.0343 2012 [ 0F97E7A47A52F4A36969F0FC319654C2 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 22:33:34.0389 2012 Skype C2C Service - ok 22:33:34.0467 2012 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 22:33:34.0499 2012 SkypeUpdate - ok 22:33:34.0545 2012 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 22:33:34.0639 2012 Smb - ok 22:33:34.0686 2012 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 22:33:34.0717 2012 SNMPTRAP - ok 22:33:34.0826 2012 [ DDF2EC98AF6FC70608A4F9CE4DB52758 ] SOHCImp C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe 22:33:34.0857 2012 SOHCImp - ok 22:33:34.0873 2012 [ 5FA03F5EA6EFEF6D17B4A1A48C40A23C ] SOHDs C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe 22:33:34.0889 2012 SOHDs - ok 22:33:34.0967 2012 [ 65E5659E9C2A0762D05657C0E22A7CA2 ] SpfService C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe 22:33:35.0013 2012 SpfService - ok 22:33:35.0045 2012 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 22:33:35.0076 2012 spldr - ok 22:33:35.0123 2012 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 22:33:35.0201 2012 Spooler - ok 22:33:35.0310 2012 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 22:33:35.0435 2012 sppsvc - ok 22:33:35.0450 2012 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 22:33:35.0481 2012 sppuinotify - ok 22:33:35.0513 2012 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 22:33:35.0559 2012 srv - ok 22:33:35.0575 2012 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 22:33:35.0606 2012 srv2 - ok 22:33:35.0606 2012 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 22:33:35.0622 2012 srvnet - ok 22:33:35.0653 2012 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys 22:33:35.0715 2012 ssadbus - ok 22:33:35.0747 2012 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys 22:33:35.0793 2012 ssadmdfl - ok 22:33:35.0825 2012 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys 22:33:35.0871 2012 ssadmdm - ok 22:33:35.0903 2012 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 22:33:35.0981 2012 SSDPSRV - ok 22:33:35.0996 2012 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 22:33:36.0059 2012 SstpSvc - ok 22:33:36.0105 2012 [ 79969ACAEEBEDA7DC3673656AB9918FD ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 22:33:36.0137 2012 Stereo Service - ok 22:33:36.0168 2012 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 22:33:36.0199 2012 stexstor - ok 22:33:36.0246 2012 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 22:33:36.0308 2012 stisvc - ok 22:33:36.0324 2012 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 22:33:36.0355 2012 swenum - ok 22:33:36.0402 2012 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 22:33:36.0480 2012 swprv - ok 22:33:36.0542 2012 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 22:33:36.0605 2012 SysMain - ok 22:33:36.0636 2012 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 22:33:36.0683 2012 TabletInputService - ok 22:33:36.0698 2012 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 22:33:36.0761 2012 TapiSrv - ok 22:33:36.0776 2012 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 22:33:36.0807 2012 TBS - ok 22:33:36.0901 2012 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys 22:33:36.0995 2012 Tcpip - ok 22:33:37.0026 2012 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 22:33:37.0073 2012 TCPIP6 - ok 22:33:37.0088 2012 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 22:33:37.0104 2012 tcpipreg - ok 22:33:37.0135 2012 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 22:33:37.0182 2012 TDPIPE - ok 22:33:37.0229 2012 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 22:33:37.0260 2012 TDTCP - ok 22:33:37.0307 2012 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 22:33:37.0400 2012 tdx - ok 22:33:37.0400 2012 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 22:33:37.0416 2012 TermDD - ok 22:33:37.0463 2012 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 22:33:37.0556 2012 TermService - ok 22:33:37.0587 2012 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 22:33:37.0603 2012 Themes - ok 22:33:37.0634 2012 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 22:33:37.0665 2012 THREADORDER - ok 22:33:37.0712 2012 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 22:33:37.0806 2012 TrkWks - ok 22:33:37.0838 2012 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 22:33:37.0869 2012 TrustedInstaller - ok 22:33:37.0900 2012 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 22:33:37.0963 2012 tssecsrv - ok 22:33:37.0978 2012 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 22:33:38.0010 2012 TsUsbFlt - ok 22:33:38.0025 2012 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 22:33:38.0056 2012 TsUsbGD - ok 22:33:38.0088 2012 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 22:33:38.0150 2012 tunnel - ok 22:33:38.0150 2012 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 22:33:38.0166 2012 uagp35 - ok 22:33:38.0212 2012 [ 1FE69F3C1CA1CF4B7EC7E2E9090FFFDC ] uCamMonitor C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe 22:33:38.0244 2012 uCamMonitor - ok 22:33:38.0259 2012 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 22:33:38.0353 2012 udfs - ok 22:33:38.0368 2012 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 22:33:38.0415 2012 UI0Detect - ok 22:33:38.0431 2012 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 22:33:38.0446 2012 uliagpkx - ok 22:33:38.0462 2012 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 22:33:38.0509 2012 umbus - ok 22:33:38.0540 2012 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 22:33:38.0571 2012 UmPass - ok 22:33:38.0727 2012 [ 7A78ED1088890114DFDE2C4AB038D6B6 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 22:33:38.0805 2012 UNS - ok 22:33:38.0836 2012 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 22:33:38.0930 2012 upnphost - ok 22:33:38.0961 2012 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 22:33:38.0992 2012 usbccgp - ok 22:33:39.0024 2012 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 22:33:39.0055 2012 usbcir - ok 22:33:39.0055 2012 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 22:33:39.0102 2012 usbehci - ok 22:33:39.0148 2012 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 22:33:39.0211 2012 usbhub - ok 22:33:39.0226 2012 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 22:33:39.0273 2012 usbohci - ok 22:33:39.0320 2012 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 22:33:39.0367 2012 usbprint - ok 22:33:39.0429 2012 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 22:33:39.0476 2012 usbscan - ok 22:33:39.0507 2012 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 22:33:39.0554 2012 USBSTOR - ok 22:33:39.0585 2012 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 22:33:39.0616 2012 usbuhci - ok 22:33:39.0632 2012 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 22:33:39.0679 2012 usbvideo - ok 22:33:39.0710 2012 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 22:33:39.0772 2012 UxSms - ok 22:33:39.0819 2012 [ DCB1F83AD167D16D263CE57C94E9EEDF ] VAIO Event Service C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe 22:33:39.0835 2012 VAIO Event Service - ok 22:33:39.0850 2012 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 22:33:39.0882 2012 VaultSvc - ok 22:33:39.0991 2012 [ D00058C1FFF3F3DE990444A5734E9639 ] VCFw C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe 22:33:40.0053 2012 VCFw - ok 22:33:40.0178 2012 [ F19275655B42086C884ABCDAE2C659AE ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe 22:33:40.0240 2012 VcmIAlzMgr - ok 22:33:40.0272 2012 [ 2F06D134554BA84FE253DBC481DCFE6D ] VcmINSMgr C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe 22:33:40.0303 2012 VcmINSMgr - ok 22:33:40.0350 2012 [ 32A3735F6874B7783C6209ED5CA36D9D ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe 22:33:40.0381 2012 VcmXmlIfHelper - ok 22:33:40.0474 2012 [ D347D3ABE070AA09C22FC37121555D52 ] VCService C:\Program Files\Sony\VAIO Care\VCService.exe 22:33:40.0490 2012 VCService - ok 22:33:40.0521 2012 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 22:33:40.0552 2012 vdrvroot - ok 22:33:40.0584 2012 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 22:33:40.0677 2012 vds - ok 22:33:40.0708 2012 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 22:33:40.0724 2012 vga - ok 22:33:40.0786 2012 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 22:33:40.0880 2012 VgaSave - ok 22:33:40.0880 2012 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 22:33:40.0896 2012 vhdmp - ok 22:33:40.0896 2012 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 22:33:40.0911 2012 viaide - ok 22:33:40.0911 2012 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 22:33:40.0927 2012 volmgr - ok 22:33:40.0942 2012 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 22:33:40.0958 2012 volmgrx - ok 22:33:40.0974 2012 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 22:33:40.0989 2012 volsnap - ok 22:33:41.0005 2012 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 22:33:41.0020 2012 vsmraid - ok 22:33:41.0083 2012 [ 0ED394BFBA3EB4740F063E0BA5EC7104 ] VSNService C:\Program Files\Sony\VAIO Smart Network\VSNService.exe 22:33:41.0145 2012 VSNService - ok 22:33:41.0208 2012 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 22:33:41.0332 2012 VSS - ok 22:33:41.0442 2012 [ D2D646D4D686C6996BA1FF96E11BE570 ] VUAgent C:\Program Files\Sony\VAIO Update\VUAgent.exe 22:33:41.0488 2012 VUAgent - ok 22:33:41.0504 2012 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 22:33:41.0551 2012 vwifibus - ok 22:33:41.0582 2012 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 22:33:41.0613 2012 vwififlt - ok 22:33:41.0644 2012 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 22:33:41.0691 2012 W32Time - ok 22:33:41.0707 2012 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 22:33:41.0738 2012 WacomPen - ok 22:33:41.0754 2012 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 22:33:41.0832 2012 WANARP - ok 22:33:41.0847 2012 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 22:33:41.0910 2012 Wanarpv6 - ok 22:33:41.0972 2012 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 22:33:42.0034 2012 wbengine - ok 22:33:42.0050 2012 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 22:33:42.0097 2012 WbioSrvc - ok 22:33:42.0097 2012 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 22:33:42.0144 2012 wcncsvc - ok 22:33:42.0175 2012 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 22:33:42.0222 2012 WcsPlugInService - ok 22:33:42.0253 2012 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 22:33:42.0300 2012 Wd - ok 22:33:42.0331 2012 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 22:33:42.0424 2012 Wdf01000 - ok 22:33:42.0424 2012 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 22:33:42.0518 2012 WdiServiceHost - ok 22:33:42.0518 2012 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 22:33:42.0565 2012 WdiSystemHost - ok 22:33:42.0596 2012 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 22:33:42.0627 2012 WebClient - ok 22:33:42.0643 2012 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 22:33:42.0705 2012 Wecsvc - ok 22:33:42.0721 2012 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 22:33:42.0752 2012 wercplsupport - ok 22:33:42.0783 2012 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 22:33:42.0814 2012 WerSvc - ok 22:33:42.0830 2012 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 22:33:42.0861 2012 WfpLwf - ok 22:33:42.0877 2012 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 22:33:42.0892 2012 WIMMount - ok 22:33:42.0908 2012 WinDefend - ok 22:33:42.0970 2012 WinHttpAutoProxySvc - ok 22:33:43.0017 2012 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 22:33:43.0095 2012 Winmgmt - ok 22:33:43.0173 2012 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 22:33:43.0282 2012 WinRM - ok 22:33:43.0329 2012 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 22:33:43.0376 2012 WinUsb - ok 22:33:43.0423 2012 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 22:33:43.0470 2012 Wlansvc - ok 22:33:43.0516 2012 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 22:33:43.0516 2012 wlcrasvc - ok 22:33:43.0610 2012 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 22:33:43.0672 2012 wlidsvc - ok 22:33:43.0688 2012 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 22:33:43.0719 2012 WmiAcpi - ok 22:33:43.0735 2012 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 22:33:43.0782 2012 wmiApSrv - ok 22:33:43.0813 2012 WMPNetworkSvc - ok 22:33:43.0860 2012 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 22:33:43.0906 2012 WPCSvc - ok 22:33:43.0922 2012 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 22:33:43.0953 2012 WPDBusEnum - ok 22:33:43.0984 2012 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 22:33:44.0078 2012 ws2ifsl - ok 22:33:44.0094 2012 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 22:33:44.0125 2012 wscsvc - ok 22:33:44.0172 2012 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 22:33:44.0218 2012 WSDPrintDevice - ok 22:33:44.0250 2012 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys 22:33:44.0281 2012 WSDScan - ok 22:33:44.0296 2012 WSearch - ok 22:33:44.0374 2012 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 22:33:44.0452 2012 wuauserv - ok 22:33:44.0484 2012 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 22:33:44.0530 2012 WudfPf - ok 22:33:44.0562 2012 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 22:33:44.0640 2012 WUDFRd - ok 22:33:44.0686 2012 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 22:33:44.0749 2012 wudfsvc - ok 22:33:44.0796 2012 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll 22:33:44.0858 2012 WwanSvc - ok 22:33:44.0889 2012 ================ Scan global =============================== 22:33:44.0920 2012 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 22:33:44.0952 2012 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 22:33:44.0967 2012 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 22:33:44.0998 2012 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 22:33:45.0030 2012 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 22:33:45.0045 2012 [Global] - ok 22:33:45.0045 2012 ================ Scan MBR ================================== 22:33:45.0061 2012 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 22:33:46.0059 2012 \Device\Harddisk0\DR0 - ok 22:33:46.0059 2012 ================ Scan VBR ================================== 22:33:46.0090 2012 [ B66EC185B9DE52245CC45448CF4642D5 ] \Device\Harddisk0\DR0\Partition1 22:33:46.0090 2012 \Device\Harddisk0\DR0\Partition1 - ok 22:33:46.0106 2012 [ 25BFE8FE0C20C7A147DF3812DF9289A6 ] \Device\Harddisk0\DR0\Partition2 22:33:46.0122 2012 \Device\Harddisk0\DR0\Partition2 - ok 22:33:46.0122 2012 ============================================================ 22:33:46.0122 2012 Scan finished 22:33:46.0122 2012 ============================================================ 22:33:46.0137 2384 Detected object count: 4 22:33:46.0137 2384 Actual detected object count: 4 22:37:07.0445 2384 Atheros Bt&Wlan Coex Agent ( UnsignedFile.Multi.Generic ) - skipped by user 22:37:07.0445 2384 Atheros Bt&Wlan Coex Agent ( UnsignedFile.Multi.Generic ) - User select action: Skip 22:37:07.0445 2384 AtherosSvc ( UnsignedFile.Multi.Generic ) - skipped by user 22:37:07.0445 2384 AtherosSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 22:37:07.0445 2384 EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - skipped by user 22:37:07.0445 2384 EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - User select action: Skip 22:37:07.0445 2384 IconMan_R ( UnsignedFile.Multi.Generic ) - skipped by user 22:37:07.0445 2384 IconMan_R ( UnsignedFile.Multi.Generic ) - User select action: Skip |
18.06.2013, 22:17 | #10 |
/// Malware-holic | wssetup exe Hi, Scan mit Combofix
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
19.06.2013, 19:04 | #11 |
| wssetup exe Combofix Logfile: Code:
ATTFilter ComboFix 13-06-15.01 - chris 19.06.2013 19:41:35.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4078.2400 [GMT 2:00] ausgeführt von:: c:\users\chris\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\chris\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll . ---- Vorheriger Suchlauf ------- . c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarApp.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarEng.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarsrv.exe c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\inCRedibartlbr.dll c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\uninstall.exe c:\users\chris\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll c:\users\chris\AppData\Roaming\Microsoft\Windows\Recent\Search the Web.url c:\windows\SysWow64\muzapp.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-05-19 bis 2013-06-19 )))))))))))))))))))))))))))))) . . 2013-06-19 17:48 . 2013-06-19 17:48 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-06-18 16:39 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E00E2DFE-0858-4E2A-A4AE-8037B5559E8D}\mpengine.dll 2013-06-16 20:39 . 2013-06-16 20:46 -------- d-----w- c:\programdata\HitmanPro 2013-06-16 20:26 . 2013-06-16 20:26 -------- d-----w- c:\program files\CCleaner 2013-06-16 19:23 . 2013-06-16 19:23 -------- d-----w- c:\users\chris\AppData\Roaming\Malwarebytes 2013-06-16 19:23 . 2013-06-16 19:23 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-06-16 19:23 . 2013-06-16 19:23 -------- d-----w- c:\programdata\Malwarebytes 2013-06-16 19:23 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-06-16 19:22 . 2013-06-16 19:22 -------- d-----w- c:\users\chris\AppData\Local\Programs 2013-06-16 17:11 . 2013-06-16 17:11 -------- d-----w- c:\program files (x86)\Common Files\Skype 2013-06-14 23:24 . 2013-06-14 23:24 -------- d-----w- c:\program files\Enigma Software Group 2013-06-14 23:23 . 2013-06-16 19:09 -------- d-----w- c:\windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-06-14 23:23 . 2013-06-14 23:23 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2013-06-13 09:09 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-06-13 09:09 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll 2013-06-13 09:09 . 2013-04-26 04:55 492544 ----a-w- c:\windows\SysWow64\win32spl.dll 2013-06-13 09:09 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll 2013-06-13 09:09 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll 2013-06-13 09:09 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2013-06-13 09:09 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-06-13 09:08 . 2013-05-13 05:51 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-06-13 09:08 . 2013-05-13 05:51 1464320 ----a-w- c:\windows\system32\crypt32.dll 2013-06-13 09:08 . 2013-05-13 05:51 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-06-13 09:08 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll 2013-06-13 09:08 . 2013-05-13 04:45 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-06-13 09:08 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-06-13 09:08 . 2013-05-13 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-06-13 09:08 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe 2013-06-13 09:08 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe 2013-06-13 09:08 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll 2013-06-13 09:08 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll 2013-06-13 09:08 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-05-31 19:36 . 2013-05-31 19:36 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-30 10:16 . 2013-05-30 12:14 -------- d-----w- c:\programdata\tmp 2013-05-30 10:16 . 2013-05-30 11:17 -------- d-----w- c:\programdata\hps 2013-05-30 10:11 . 2013-05-30 10:11 -------- d-----w- c:\program files (x86)\Mueller Foto . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-13 21:26 . 2012-07-05 19:05 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-12 18:52 . 2012-07-15 18:16 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-12 18:52 . 2012-07-15 18:16 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-21 13:31 . 2012-12-21 19:25 1447728 ----a-w- c:\windows\system32\dmwu.exe 2013-05-21 13:30 . 2012-12-21 19:25 33792 ----a-w- c:\windows\system32\ImHttpComm.dll 2013-05-10 08:12 . 2010-06-24 09:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-06 10:22 . 2013-05-06 10:22 83160 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-05-02 00:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-04-13 05:49 . 2013-05-16 09:02 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-16 09:02 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-16 09:02 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-16 09:02 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-16 09:02 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-16 09:02 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-24 18:25 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 06:01 . 2013-05-16 09:03 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-04-10 06:01 . 2013-05-16 09:03 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-10 03:30 . 2013-05-16 09:02 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-03-31 17:03 . 2013-03-31 17:03 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-03-31 17:03 . 2013-03-31 17:03 130016 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-03-31 17:03 . 2013-03-31 17:03 100712 ----a-w- c:\windows\system32\drivers\avgntflt.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2011-03-17 909200] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2011-03-17 3373968] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-03-17 19872] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE" [2012-02-29 283232] "EPLTarget\P0000000000000001"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE" [2012-02-29 283232] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312] "PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-26 648032] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-05-06 345312] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x] R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x] R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x] R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x] R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x] R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x] R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x] S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x] S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe;c:\program files\Sony\VAIO Update\VUAgent.exe [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-06-05 18:33 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-06-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 18:52] . 2013-06-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-21 20:10] . 2013-06-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-21 20:10] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-04-29 790688] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-04-29 657568] "lxczbmgr.exe"="c:\program files (x86)\Lexmark 1200 Series\lxczbmgr.exe" [2009-04-27 74408] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: Free YouTube to MP3 Converter - c:\users\chris\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.0.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe AddRemove-Lexmark 1200 Series - c:\program files (x86) (x86)\Lexmark 1200 Series\Install\x64\Uninst.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector] "ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\"" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe c:\program files (x86)\Sony\VAIO Event Service\VESMgr.exe c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe c:\windows\SysWOW64\DllHost.exe c:\windows\SysWOW64\DllHost.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files\Sony\VAIO Care\listener.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-06-19 19:54:40 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-06-19 17:54 . Vor Suchlauf: 18 Verzeichnis(se), 522.266.624.000 Bytes frei Nach Suchlauf: 21 Verzeichnis(se), 521.742.581.760 Bytes frei . - - End Of File - - 2B106FD8948957031CBF924FC1190636 D41D8CD98F00B204E9800998ECF8427E |
19.06.2013, 19:33 | #12 |
/// Malware-holic | wssetup exe poste alle bisherigen Malwarebytes Logs mit funden http://www.trojaner-board.de/125889-...en-posten.html
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
19.06.2013, 19:48 | #13 |
| wssetup exe Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.06.16.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16614 chris :: CHRIS-VAIO [Administrator] Schutz: Aktiviert 16.06.2013 21:25:13 mbam-log-2013-06-16 (21-25-13).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 356147 Laufzeit: 57 Minute(n), 35 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 21:24:19 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh 2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection 2013/06/16 21:24:29 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully 2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully 2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 21:24:33 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 21:30:39 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily 2013/06/16 21:30:40 +0200 CHRIS-VAIO chris MESSAGE Database already up-to-date 2013/06/16 22:37:01 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 22:37:08 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting protection 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Protection started successfully 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting IP protection 2013/06/16 23:12:47 +0200 CHRIS-VAIO (null) MESSAGE IP Protection started successfully 2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50005, Process: opera.exe) 2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50006, Process: opera.exe) 2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50038, Process: opera.exe) 2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50039, Process: opera.exe) 2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe) 2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50166, Process: opera.exe) 2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51400, Process: opera.exe) 2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51401, Process: opera.exe) 2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51419, Process: opera.exe) 2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51420, Process: opera.exe) 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 21:24:19 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh 2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection 2013/06/16 21:24:29 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully 2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully 2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 21:24:33 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 21:30:39 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily 2013/06/16 21:30:40 +0200 CHRIS-VAIO chris MESSAGE Database already up-to-date 2013/06/16 22:37:01 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 22:37:08 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting protection 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Protection started successfully 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting IP protection 2013/06/16 23:12:47 +0200 CHRIS-VAIO (null) MESSAGE IP Protection started successfully 2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50005, Process: opera.exe) 2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50006, Process: opera.exe) 2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50038, Process: opera.exe) 2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50039, Process: opera.exe) 2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe) 2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50166, Process: opera.exe) 2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51400, Process: opera.exe) 2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51401, Process: opera.exe) 2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51419, Process: opera.exe) 2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51420, Process: opera.exe) 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 21:24:19 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh 2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection 2013/06/16 21:24:29 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully 2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully 2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 21:24:33 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 21:30:39 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily 2013/06/16 21:30:40 +0200 CHRIS-VAIO chris MESSAGE Database already up-to-date 2013/06/16 22:37:01 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/16 22:37:08 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting protection 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Protection started successfully 2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting IP protection 2013/06/16 23:12:47 +0200 CHRIS-VAIO (null) MESSAGE IP Protection started successfully 2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50005, Process: opera.exe) 2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50006, Process: opera.exe) 2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50038, Process: opera.exe) 2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50039, Process: opera.exe) 2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe) 2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50166, Process: opera.exe) 2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51400, Process: opera.exe) 2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51401, Process: opera.exe) 2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51419, Process: opera.exe) 2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51420, Process: opera.exe) 2013/06/19 06:38:57 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily 2013/06/19 06:38:57 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/19 06:38:58 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/19 06:38:58 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/19 06:39:00 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh 2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection 2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE Scheduled update executed successfully: database updated from version v2013.06.17.01 to version v2013.06.18.09 2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully 2013/06/19 06:39:41 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully 2013/06/19 06:39:41 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/19 06:39:43 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49405, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49406, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49407, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49408, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49409, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49410, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49414, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49415, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49416, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49417, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49418, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49419, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49425, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49426, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49427, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49428, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49429, Process: opera.exe) 2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49430, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49437, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49438, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49439, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49440, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49441, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49442, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49445, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49446, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49447, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49448, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49449, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49450, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49451, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49462, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49465, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49466, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49467, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49468, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49470, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49471, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49472, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49473, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49474, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49475, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49481, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49482, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49483, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49484, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49485, Process: opera.exe) 2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49486, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49515, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49516, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49517, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49518, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49519, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49520, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49563, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49564, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49565, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49566, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49567, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49568, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49569, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49570, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49571, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49572, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49573, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49574, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49575, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49576, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49577, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49578, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49579, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49580, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49581, Process: opera.exe) 2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49582, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49604, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49605, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49606, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49607, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49608, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49609, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49621, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49622, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49623, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49624, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49625, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49626, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49629, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49630, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49631, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49632, Process: opera.exe) 2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49633, Process: opera.exe) 2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50716, Process: opera.exe) 2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50717, Process: opera.exe) 2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50743, Process: opera.exe) 2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50744, Process: opera.exe) 2013/06/19 06:56:50 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51029, Process: opera.exe) 2013/06/19 06:56:50 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51032, Process: opera.exe) 2013/06/19 06:58:44 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51272, Process: opera.exe) 2013/06/19 06:58:44 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51273, Process: opera.exe) 2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51342, Process: opera.exe) 2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51343, Process: opera.exe) 2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51344, Process: opera.exe) 2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51345, Process: opera.exe) 2013/06/19 13:28:38 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/19 13:28:38 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/19 13:28:38 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/19 13:28:41 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/19 19:18:42 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/19 19:18:42 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/19 19:18:42 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/19 19:18:45 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49189, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49190, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49191, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49192, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49193, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49194, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49260, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49261, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49262, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49263, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49264, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49265, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49267, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49268, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49269, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49270, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49271, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49272, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49277, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49278, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49279, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49280, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49281, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49282, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49283, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49284, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49285, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49286, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49287, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49288, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49289, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49290, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49291, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49292, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49293, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49294, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49295, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49296, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49297, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49298, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49299, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49300, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49301, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49302, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49303, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49304, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49308, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49309, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49310, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49311, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49316, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49317, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49318, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49319, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49320, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49321, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49328, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49329, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49330, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49331, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49332, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49333, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49334, Process: opera.exe) 2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49335, Process: opera.exe) 2013/06/19 19:20:11 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49336, Process: opera.exe) 2013/06/19 19:20:11 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49337, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49345, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49346, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49347, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49348, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49349, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49350, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49356, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49357, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49358, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49359, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49360, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49361, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49384, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49385, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49386, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49387, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49388, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49389, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49390, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49391, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49392, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49393, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49394, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49395, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49396, Process: opera.exe) 2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49397, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50080, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50081, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50082, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50083, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50084, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50085, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50088, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50089, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50090, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50091, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50092, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50093, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50098, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50099, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50100, Process: opera.exe) 2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50101, Process: opera.exe) 2013/06/19 19:27:53 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50160, Process: opera.exe) 2013/06/19 19:27:53 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe) 2013/06/19 19:28:01 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50190, Process: opera.exe) 2013/06/19 19:28:01 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50191, Process: opera.exe) 2013/06/19 19:32:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50466, Process: opera.exe) 2013/06/19 19:32:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50467, Process: opera.exe) 2013/06/19 19:49:19 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/19 19:49:20 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/19 19:49:20 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/19 19:49:22 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully 2013/06/19 19:57:31 +0200 CHRIS-VAIO chris MESSAGE Starting protection 2013/06/19 19:57:32 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully 2013/06/19 19:57:32 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection 2013/06/19 19:57:34 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully |
21.06.2013, 10:02 | #14 |
/// the machine /// TB-Ausbilder | wssetup exe Hi, Markus ist im Urlaub. Gibt es noch irgendwelche Probleme mit dem System?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.06.2013, 17:49 | #15 |
| wssetup exe Hi, soweit ist eigentlich alles in ordnung,soweit ich das beurteilen kann |
Themen zu wssetup exe |
exe, fester, gefahren, rechner, tagen, zulassen, öffnet |