Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: wssetup exe

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 16.06.2013, 19:46   #1
xibor
 
wssetup exe - Standard

wssetup exe



seit ein paar tagen öffnet sich immer nach dem ich den rechner rauf gefahren habe ein fester ob ich wssetup exe zulassen möchte oder nich!!!kann mir jemand helfen

Alt 16.06.2013, 19:59   #2
markusg
/// Malware-holic
 
wssetup exe - Standard

wssetup exe



Hi,

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die
    OTL.exe
    .
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die
    Textbox.
Code:
ATTFilter
activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread
__________________

__________________

Alt 16.06.2013, 22:07   #3
xibor
 
wssetup exe - Standard

wssetup exe



OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\chris\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

3,98 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 59,72% Memory free
7,96 Gb Paging File | 6,04 Gb Available in Paging File | 75,80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 582,18 Gb Total Space | 486,60 Gb Free Space | 83,58% Space Free | Partition Type: NTFS

Computer Name: CHRIS-VAIO | User Name: chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\chris\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Programme\Sony\VAIO Care\VCService.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Programme\Sony\VAIO Care\listener.exe (Sony of America Corporation)
PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
PRC - C:\Program Files (x86)\Lexmark 1200 Series\LXCZbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files (x86)\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe (SEIKO EPSON CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\Users\chris\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\fbc70df7b07a2e9a7b59d26cb4e3b610\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b6eb138c3c9be780acb767c1bef572c1\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a9594959e951127f16eb49644ba92f79\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\7cfbbd029ef945fbcdaedd24b2b67a24\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\af18b8a8f56494da44cc448f3b9704a5\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ac9e3eca6c148504588e7c6d09fe83e3\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\85a17526c326bfb377b5c2124dce39f2\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ceda881f46083cfb6356ed39e6bf9dcb\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\dfeff31ab1e7cd3480c8942290c92f5d\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (EpsonScanSvc) -- C:\Windows\SysNative\escsvc64.exe (Seiko Epson Corporation)
SRV:64bit: - (SampleCollector) -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation)
SRV:64bit: - (lxcz_device) -- C:\Windows\SysNative\lxczcoms.exe ( )
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (VUAgent) -- C:\Programme\Sony\VAIO Update\VUAgent.exe (Sony Corporation)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Microsoft Corporation.)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe (Microsoft Corporation.)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (EPSON_PM_RPCV4_04) -- C:\Programme\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (SEIKO EPSON CORPORATION)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (VcmIAlzMgr) -- C:\Programme\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
SRV - (Atheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Atheros Commnucations)
SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (VAIO Event Service) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VSNService) -- C:\Programme\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation)
SRV - (uCamMonitor) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (SOHCImp) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation)
SRV - (SOHDs) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation)
SRV - (VcmXmlIfHelper) -- C:\Programme\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (Sony Corporation)
SRV - (VcmINSMgr) -- C:\Programme\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe (Sony Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (VCService) -- C:\Programme\Sony\VAIO Care\VCService.exe (Sony Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (SpfService) -- C:\Programme\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation)
SRV - (VCFw) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
SRV - (PMBDeviceInfoProvider) -- c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
SRV - (lxcz_device) -- C:\Windows\SysWOW64\lxczcoms.exe ( )
SRV - (EpsonBidirectionalService) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadmdfl) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ApfiltrService) -- C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (SFEP) -- C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (e1yexpress) -- C:\Windows\SysNative\drivers\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ArcSoftKsUFilter) -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://sony.msn.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{44AAB85C-9C32-46F0-B32A-BFCBA426C780}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q311&_nkw={searchTerms}
IE - HKCU\..\SearchScopes\{65717E9E-1E56-497D-BF3F-1398BC8D4414}: "URL" = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
IE - HKCU\..\SearchScopes\{9A25D1DC-860A-43EA-BA63-024A043C4C6D}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=cc3638fb-eca7-4f62-b49b-9a81fbcaa00c&apn_sauid=92419A59-671D-4ABD-9090-CBD15E2FC95D
IE - HKCU\..\SearchScopes\{DCAF8E91-811B-4415-BB30-E11F8E3E0413}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848
IE - HKCU\..\SearchScopes\8D35D3F2FF4B4B2298C4A3F53328EC96: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={43F33C3F-4BA5-11E2-BC7C-78843CF08728}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\PROGRAM FILES\IB UPDATER\FIREFOX

[2012.12.21 21:25:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions

========== Chrome ==========

CHR - homepage: hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP&dt=061613
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - default_search_provider: Bing (Enabled)
CHR - default_search_provider: search_url = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=061613&q={searchTerms}&src=IE-SearchBox
CHR - default_search_provider: suggest_url = hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language}&form=UP97DF&PC=UP97&dt=061613
CHR - Extension: Google Drive = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Skype Click to Call = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.1.0.10441_0\
CHR - Extension: IncrediBar for Chrome\u2122 = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\
CHR - Extension: Google Mail = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Google Drive = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Skype Click to Call = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.1.0.10441_0\
CHR - Extension: IncrediBar for Chrome\u2122 = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\
CHR - Extension: Google Mail = C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013.06.16 21:02:22 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O4:64bit: - HKLM..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [lxczbmgr.exe] C:\Program Files (x86)\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-202 203 206 Series" File not found
O4 - HKCU..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-202 203 206 Series" File not found
O4 - HKCU..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\chris\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\chris\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A641BE5C-A94B-4023-9D65-A9B568B4035B}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.06.15 01:24:38 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{3942788D-F1D2-4201-9BF0-003753DCCEB6} - RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP


MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013.06.16 22:39:43 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.06.16 22:26:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013.06.16 22:26:50 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.06.16 21:23:55 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Roaming\Malwarebytes
[2013.06.16 21:23:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.06.16 21:23:50 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.06.16 21:23:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.06.16 21:23:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.06.16 21:22:47 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Local\Programs
[2013.06.16 21:09:07 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.06.16 21:02:02 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.06.16 20:56:16 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.06.16 20:55:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.06.16 20:55:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.06.16 20:55:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.06.16 20:55:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.06.16 20:54:48 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.06.16 20:54:13 | 005,080,151 | R--- | C] (Swearware) -- C:\Users\chris\Desktop\ComboFix.exe
[2013.06.16 20:27:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe
[2013.06.16 19:11:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.06.16 19:11:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013.06.15 01:24:22 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2013.06.15 01:23:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013.06.15 01:10:43 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\chris\Desktop\tdsskiller.exe
[2013.05.30 12:16:09 | 000,000,000 | ---D | C] -- C:\ProgramData\tmp
[2013.05.30 12:16:09 | 000,000,000 | ---D | C] -- C:\ProgramData\hps
[2013.05.30 12:16:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Müller Foto
[2013.05.30 12:11:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mueller Foto
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013.06.16 22:52:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.16 22:44:57 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.16 22:44:57 | 000,020,992 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.16 22:36:52 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.16 22:36:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.16 22:36:34 | 3206,959,104 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.16 22:33:01 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.16 22:26:52 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.06.16 21:23:51 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013.06.16 21:02:22 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.06.16 20:54:22 | 005,080,151 | R--- | M] (Swearware) -- C:\Users\chris\Desktop\ComboFix.exe
[2013.06.16 20:27:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe
[2013.06.16 19:11:36 | 000,002,517 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.06.15 01:24:38 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2013.06.15 01:10:43 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\chris\Desktop\tdsskiller.exe
[2013.06.13 23:25:03 | 001,591,930 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.06.13 23:25:03 | 000,697,322 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.06.13 23:25:03 | 000,652,600 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.06.13 23:25:03 | 000,148,328 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.06.13 23:25:03 | 000,121,274 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.06.13 23:24:55 | 001,591,930 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.31 21:38:01 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.05.31 21:38:01 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013.05.30 12:16:07 | 000,001,224 | ---- | M] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
[2013.05.30 12:16:07 | 000,001,209 | ---- | M] () -- C:\Users\Public\Desktop\Müller Foto.lnk
[2013.05.21 15:31:12 | 001,447,728 | ---- | M] () -- C:\Windows\SysNative\dmwu.exe
[2013.05.21 15:30:18 | 000,033,792 | ---- | M] (IncrediMail, Ltd.) -- C:\Windows\SysNative\ImHttpComm.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.06.16 22:26:52 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.06.16 21:23:51 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013.06.16 20:55:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.06.16 20:55:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.06.16 20:55:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.06.16 20:55:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.06.16 20:55:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.06.16 19:11:36 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2013.06.15 01:24:38 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2013.05.31 21:38:01 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.05.31 21:38:01 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013.05.30 12:16:07 | 000,001,224 | ---- | C] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
[2013.05.30 12:16:07 | 000,001,209 | ---- | C] () -- C:\Users\Public\Desktop\Müller Foto.lnk
[2012.07.31 20:42:02 | 000,000,100 | ---- | C] () -- C:\Windows\Lexstat.ini
[2012.07.31 20:11:23 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczpmui.dll
[2012.07.31 20:11:23 | 000,413,696 | ---- | C] () -- C:\Windows\SysWow64\lxczutil.dll
[2012.07.31 20:11:23 | 000,413,696 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczinpa.dll
[2012.07.31 20:11:23 | 000,397,312 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcziesc.dll
[2012.07.31 20:11:23 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\LXCZinst.dll
[2012.07.31 20:11:22 | 001,224,704 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczserv.dll
[2012.07.31 20:11:22 | 000,991,232 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczusb1.dll
[2012.07.31 20:11:22 | 000,696,320 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczhbn3.dll
[2012.07.31 20:11:22 | 000,684,032 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcomc.dll
[2012.07.31 20:11:22 | 000,585,728 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczlmpm.dll
[2012.07.31 20:11:22 | 000,537,520 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcoms.exe
[2012.07.31 20:11:22 | 000,421,888 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcomm.dll
[2012.07.31 20:11:22 | 000,385,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczih.exe
[2012.07.31 20:11:22 | 000,381,872 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczcfg.exe
[2012.07.31 20:11:22 | 000,181,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczppls.exe
[2012.07.31 20:11:22 | 000,163,840 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczprox.dll
[2012.07.31 20:11:22 | 000,094,208 | ---- | C] ( ) -- C:\Windows\SysWow64\lxczpplc.dll
[2012.07.13 20:26:02 | 000,008,704 | ---- | C] () -- C:\Users\chris\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012.08.05 12:26:15 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Ashampoo
[2012.08.17 07:07:08 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\becker
[2012.12.04 20:48:11 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\DVDVideoSoft
[2013.02.08 21:18:46 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Elmu
[2012.12.23 15:04:11 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\EPSON
[2013.02.09 20:34:41 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Faol
[2012.07.06 20:48:40 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Opera
[2013.02.13 14:02:31 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Qoanix
[2012.07.13 20:23:14 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Samsung
[2013.05.20 09:54:28 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\SoftGrid Client
[2013.01.20 21:03:43 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\TP
[2012.12.04 20:48:47 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\TuneUp Software
[2012.12.21 21:52:52 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\UseNeXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*. >
[2013.06.16 21:04:57 | 000,000,000 | ---D | M] -- C:\$Recycle.Bin
[2013.06.16 21:06:10 | 000,000,000 | ---D | M] -- C:\ComboFix
[2013.06.16 21:10:23 | 000,000,000 | -HSD | M] -- C:\Config.Msi
[2012.07.01 21:54:21 | 000,000,000 | ---D | M] -- C:\Documentation
[2009.07.14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2012.07.01 22:32:28 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.07.01 21:38:33 | 000,000,000 | ---D | M] -- C:\Intel
[2012.07.31 20:11:05 | 000,000,000 | ---D | M] -- C:\lexmark
[2013.01.20 21:10:15 | 000,000,000 | R--D | M] -- C:\MSOCache
[2009.07.14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2013.06.16 22:34:48 | 000,000,000 | R--D | M] -- C:\Program Files
[2013.06.16 22:34:48 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012.07.31 20:11:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86) (x86)
[2013.06.16 22:39:43 | 000,000,000 | ---D | M] -- C:\ProgramData
[2012.07.01 22:32:28 | 000,000,000 | -HSD | M] -- C:\Programme
[2013.06.16 20:55:35 | 000,000,000 | ---D | M] -- C:\Qoobox
[2012.07.01 22:21:37 | 000,000,000 | ---D | M] -- C:\SPLASH.000
[2012.07.01 22:21:16 | 000,000,000 | ---D | M] -- C:\SPLASH.SYS
[2013.06.16 22:54:40 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.07.01 22:25:21 | 000,000,000 | ---D | M] -- C:\temp
[2013.01.12 21:23:10 | 000,000,000 | ---D | M] -- C:\Update
[2012.07.01 22:32:48 | 000,000,000 | R--D | M] -- C:\Users
[2012.07.01 22:25:28 | 000,000,000 | ---D | M] -- C:\VAIO Sample Contents
[2013.06.16 22:36:38 | 000,000,000 | ---D | M] -- C:\Windows
[2012.07.01 21:54:21 | 000,000,000 | ---D | M] -- C:\_FS_SWRINFO

< %PROGRAMFILES%\*.exe >

< %LOCALAPPDATA%\*.exe >

< %systemroot%\*. /mp /s >

< C:\Windows\system32\*.tsp >
[2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 03:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.21 05:23:55 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.07.15 20:16:27 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.12.21 22:10:19 | 000,001,104 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.12.21 22:10:20 | 000,001,108 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< MD5 for: AGP440.SYS >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: EXPLORER.EXE >
[2011.07.13 03:21:47 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.07.13 03:21:47 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.07.13 03:21:47 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.07.13 03:21:47 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.07.13 03:21:47 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.07.13 03:21:47 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: IASTOR.SYS >
[2011.02.22 17:27:05 | 000,437,272 | R--- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.02.22 17:27:05 | 000,437,272 | R--- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_2b0c50dc63f09dae\iaStor.sys
[2011.02.22 17:27:05 | 000,437,272 | R--- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F -- C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_5b314ccea0aa569d\iaStor.sys

< MD5 for: IASTORV.SYS >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: USER32.DLL >
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll

< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WS2IFSL.SYS >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >
[2013.05.17 03:25:26 | 013,760,512 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %USERPROFILE%\*.* >
[2013.06.16 23:04:13 | 001,835,008 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT
[2013.06.16 23:04:13 | 000,262,144 | -HS- | M] () -- C:\Users\chris\ntuser.dat.LOG1
[2012.07.01 22:32:53 | 000,000,000 | -HS- | M] () -- C:\Users\chris\ntuser.dat.LOG2
[2012.07.01 22:39:17 | 000,065,536 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2012.07.01 22:39:17 | 000,524,288 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2012.07.01 22:39:17 | 000,524,288 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2012.07.01 22:32:53 | 000,000,020 | -HS- | M] () -- C:\Users\chris\ntuser.ini

< %USERPROFILE%\Local Settings\Temp\*.exe >

< %USERPROFILE%\Local Settings\Temp\*.dll >

< %USERPROFILE%\Application Data\*.exe >

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

< >

< End of report >
__________________

Alt 17.06.2013, 10:59   #4
markusg
/// Malware-holic
 
wssetup exe - Standard

wssetup exe



Hi,
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 17.06.2013, 18:29   #5
xibor
 
wssetup exe - Standard

wssetup exe



Hi,hab ich gemacht hat nichts gefunden


Alt 18.06.2013, 16:59   #6
markusg
/// Malware-holic
 
wssetup exe - Standard

wssetup exe



log posten
__________________
--> wssetup exe

Alt 18.06.2013, 19:10   #7
xibor
 
wssetup exe - Standard

wssetup exe



19:56:44.0426 5924 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
19:56:44.0705 5924 ============================================================
19:56:44.0706 5924 Current date / time: 2013/06/18 19:56:44.0705
19:56:44.0706 5924 SystemInfo:
19:56:44.0706 5924
19:56:44.0706 5924 OS Version: 6.1.7601 ServicePack: 1.0
19:56:44.0706 5924 Product type: Workstation
19:56:44.0706 5924 ComputerName: CHRIS-VAIO
19:56:44.0706 5924 UserName: chris
19:56:44.0707 5924 Windows directory: C:\Windows
19:56:44.0707 5924 System windows directory: C:\Windows
19:56:44.0707 5924 Running under WOW64
19:56:44.0707 5924 Processor architecture: Intel x64
19:56:44.0707 5924 Number of processors: 4
19:56:44.0707 5924 Page size: 0x1000
19:56:44.0707 5924 Boot type: Normal boot
19:56:44.0707 5924 ============================================================
19:56:45.0183 5924 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:56:45.0188 5924 ============================================================
19:56:45.0188 5924 \Device\Harddisk0\DR0:
19:56:45.0188 5924 MBR partitions:
19:56:45.0188 5924 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1BC9800, BlocksNum 0x32000
19:56:45.0188 5924 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1BFB800, BlocksNum 0x48C5C000
19:56:45.0188 5924 ============================================================
19:56:45.0222 5924 C: <-> \Device\Harddisk0\DR0\Partition2
19:56:45.0222 5924 ============================================================
19:56:45.0223 5924 Initialize success
19:56:45.0223 5924 ============================================================
19:56:47.0351 7016 ============================================================
19:56:47.0351 7016 Scan started
19:56:47.0351 7016 Mode: Manual;
19:56:47.0351 7016 ============================================================
19:56:47.0512 7016 ================ Scan system memory ========================
19:56:47.0512 7016 System memory - ok
19:56:47.0513 7016 ================ Scan services =============================
19:56:47.0700 7016 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
19:56:47.0719 7016 1394ohci - ok
19:56:47.0829 7016 [ B33CF4DE909A5B30F526D82053A63C8E ] ABBYY.Licensing.FineReader.Sprint.9.0 C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
19:56:47.0842 7016 ABBYY.Licensing.FineReader.Sprint.9.0 - ok
19:56:47.0924 7016 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
19:56:47.0927 7016 ACDaemon - ok
19:56:48.0000 7016 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
19:56:48.0007 7016 ACPI - ok
19:56:48.0039 7016 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
19:56:48.0046 7016 AcpiPmi - ok
19:56:48.0119 7016 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:56:48.0121 7016 AdobeARMservice - ok
19:56:48.0291 7016 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:56:48.0296 7016 AdobeFlashPlayerUpdateSvc - ok
19:56:48.0370 7016 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
19:56:48.0394 7016 adp94xx - ok
19:56:48.0441 7016 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
19:56:48.0462 7016 adpahci - ok
19:56:48.0489 7016 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
19:56:48.0498 7016 adpu320 - ok
19:56:48.0529 7016 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:56:48.0530 7016 AeLookupSvc - ok
19:56:48.0571 7016 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
19:56:48.0577 7016 AFD - ok
19:56:48.0614 7016 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
19:56:48.0621 7016 agp440 - ok
19:56:48.0647 7016 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
19:56:48.0654 7016 ALG - ok
19:56:48.0676 7016 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
19:56:48.0681 7016 aliide - ok
19:56:48.0687 7016 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
19:56:48.0692 7016 amdide - ok
19:56:48.0705 7016 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
19:56:48.0712 7016 AmdK8 - ok
19:56:48.0739 7016 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
19:56:48.0747 7016 AmdPPM - ok
19:56:48.0781 7016 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
19:56:48.0792 7016 amdsata - ok
19:56:48.0817 7016 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
19:56:48.0832 7016 amdsbs - ok
19:56:48.0847 7016 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
19:56:48.0853 7016 amdxata - ok
19:56:49.0030 7016 [ D9A92E6DD41C5ADC045AE485026AA40C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
19:56:49.0032 7016 AntiVirSchedulerService - ok
19:56:49.0102 7016 [ 66A7A38F7C439153B758548375EB9E5E ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
19:56:49.0106 7016 AntiVirService - ok
19:56:49.0151 7016 [ 9EDAE2D1CA368E8D01BEE8BFBC9488E4 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
19:56:49.0181 7016 AntiVirWebService - ok
19:56:49.0237 7016 [ D80CB25D90474C731C0D1312A6DE3B13 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
19:56:49.0253 7016 ApfiltrService - ok
19:56:49.0295 7016 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
19:56:49.0304 7016 AppID - ok
19:56:49.0333 7016 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
19:56:49.0342 7016 AppIDSvc - ok
19:56:49.0387 7016 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
19:56:49.0390 7016 Appinfo - ok
19:56:49.0442 7016 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
19:56:49.0456 7016 arc - ok
19:56:49.0477 7016 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
19:56:49.0485 7016 arcsas - ok
19:56:49.0508 7016 [ C130BC4A51B1382B2BE8E44579EC4C0A ] ArcSoftKsUFilter C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
19:56:49.0512 7016 ArcSoftKsUFilter - ok
19:56:49.0587 7016 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
19:56:49.0615 7016 aspnet_state - ok
19:56:49.0633 7016 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:56:49.0639 7016 AsyncMac - ok
19:56:49.0665 7016 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
19:56:49.0672 7016 atapi - ok
19:56:49.0707 7016 [ 50F257E19554421B6891E3F998EDCA90 ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys
19:56:49.0713 7016 AthBTPort - ok
19:56:49.0776 7016 [ 650F111D5CDA64C10AE4B9D1BA9D4FFF ] Atheros Bt&Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
19:56:49.0780 7016 Atheros Bt&Wlan Coex Agent - ok
19:56:49.0811 7016 [ EBC3119394C9074A9CD87578A435050D ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
19:56:49.0814 7016 AtherosSvc - ok
19:56:49.0897 7016 [ C8679A07267F030704168E45E27C3D43 ] athr C:\Windows\system32\DRIVERS\athrx.sys
19:56:49.0931 7016 athr - ok
19:56:49.0981 7016 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:56:49.0987 7016 AudioEndpointBuilder - ok
19:56:49.0998 7016 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
19:56:50.0003 7016 AudioSrv - ok
19:56:50.0052 7016 [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
19:56:50.0067 7016 avgntflt - ok
19:56:50.0129 7016 [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
19:56:50.0146 7016 avipbb - ok
19:56:50.0202 7016 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
19:56:50.0213 7016 avkmgr - ok
19:56:50.0270 7016 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
19:56:50.0286 7016 AxInstSV - ok
19:56:50.0337 7016 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
19:56:50.0359 7016 b06bdrv - ok
19:56:50.0406 7016 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
19:56:50.0425 7016 b57nd60a - ok
19:56:50.0537 7016 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe
19:56:50.0541 7016 BBSvc - ok
19:56:50.0623 7016 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
19:56:50.0628 7016 BBUpdate - ok
19:56:50.0659 7016 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
19:56:50.0672 7016 BDESVC - ok
19:56:50.0707 7016 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
19:56:50.0713 7016 Beep - ok
19:56:50.0767 7016 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
19:56:50.0780 7016 BFE - ok
19:56:50.0837 7016 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
19:56:50.0856 7016 BITS - ok
19:56:50.0888 7016 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
19:56:50.0898 7016 blbdrive - ok
19:56:50.0920 7016 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:56:50.0933 7016 bowser - ok
19:56:50.0961 7016 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
19:56:50.0968 7016 BrFiltLo - ok
19:56:50.0977 7016 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
19:56:50.0980 7016 BrFiltUp - ok
19:56:51.0023 7016 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
19:56:51.0030 7016 BridgeMP - ok
19:56:51.0059 7016 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
19:56:51.0061 7016 Browser - ok
19:56:51.0098 7016 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
19:56:51.0119 7016 Brserid - ok
19:56:51.0126 7016 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
19:56:51.0131 7016 BrSerWdm - ok
19:56:51.0135 7016 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
19:56:51.0139 7016 BrUsbMdm - ok
19:56:51.0143 7016 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
19:56:51.0147 7016 BrUsbSer - ok
19:56:51.0209 7016 [ B3BCD755FA9A359D10208CC9F09847CC ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys
19:56:51.0226 7016 BTATH_A2DP - ok
19:56:51.0265 7016 [ 9BBBA9D6DBDEFC8A6542BC7A6EBAF710 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys
19:56:51.0278 7016 btath_avdt - ok
19:56:51.0313 7016 [ D838DD1BCB328EFCFAD7A52DE9E3CAFD ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys
19:56:51.0315 7016 BTATH_BUS - ok
19:56:51.0334 7016 [ A441B800E04CF8443FAF519207563ABB ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys
19:56:51.0349 7016 BTATH_HCRP - ok
19:56:51.0390 7016 [ B16F8429A35BBA2A8EF9DB2E08675B97 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys
19:56:51.0397 7016 BTATH_LWFLT - ok
19:56:51.0415 7016 [ C24231C6BDFE21735930084A22089AAB ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys
19:56:51.0426 7016 BTATH_RCP - ok
19:56:51.0494 7016 [ 3632FA4C6B3CE9EC827690DEAC266D8C ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys
19:56:51.0497 7016 BtFilter - ok
19:56:51.0551 7016 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
19:56:51.0561 7016 BthEnum - ok
19:56:51.0587 7016 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
19:56:51.0595 7016 BTHMODEM - ok
19:56:51.0617 7016 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
19:56:51.0626 7016 BthPan - ok
19:56:51.0671 7016 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
19:56:51.0679 7016 BTHPORT - ok
19:56:51.0713 7016 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
19:56:51.0722 7016 bthserv - ok
19:56:51.0747 7016 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
19:56:51.0749 7016 BTHUSB - ok
19:56:51.0866 7016 catchme - ok
19:56:51.0901 7016 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:56:51.0913 7016 cdfs - ok
19:56:51.0943 7016 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:56:51.0959 7016 cdrom - ok
19:56:51.0986 7016 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
19:56:51.0989 7016 CertPropSvc - ok
19:56:52.0029 7016 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
19:56:52.0035 7016 circlass - ok
19:56:52.0050 7016 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
19:56:52.0055 7016 CLFS - ok
19:56:52.0131 7016 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:56:52.0145 7016 clr_optimization_v2.0.50727_32 - ok
19:56:52.0185 7016 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:56:52.0195 7016 clr_optimization_v2.0.50727_64 - ok
19:56:52.0275 7016 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:56:52.0305 7016 clr_optimization_v4.0.30319_32 - ok
19:56:52.0350 7016 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:56:52.0364 7016 clr_optimization_v4.0.30319_64 - ok
19:56:52.0399 7016 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
19:56:52.0406 7016 CmBatt - ok
19:56:52.0432 7016 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:56:52.0440 7016 cmdide - ok
19:56:52.0527 7016 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
19:56:52.0553 7016 CNG - ok
19:56:52.0644 7016 [ 1F394DF3714ED4280047810790E6DF69 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys
19:56:52.0680 7016 CnxtHdAudService - ok
19:56:52.0732 7016 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
19:56:52.0738 7016 Compbatt - ok
19:56:52.0751 7016 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
19:56:52.0762 7016 CompositeBus - ok
19:56:52.0773 7016 COMSysApp - ok
19:56:52.0790 7016 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
19:56:52.0795 7016 crcdisk - ok
19:56:52.0858 7016 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:56:52.0860 7016 CryptSvc - ok
19:56:52.0961 7016 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
19:56:52.0968 7016 cvhsvc - ok
19:56:53.0036 7016 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
19:56:53.0043 7016 DcomLaunch - ok
19:56:53.0093 7016 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
19:56:53.0104 7016 defragsvc - ok
19:56:53.0133 7016 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:56:53.0139 7016 DfsC - ok
19:56:53.0165 7016 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
19:56:53.0168 7016 Dhcp - ok
19:56:53.0172 7016 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
19:56:53.0173 7016 discache - ok
19:56:53.0204 7016 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
19:56:53.0211 7016 Disk - ok
19:56:53.0250 7016 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:56:53.0252 7016 Dnscache - ok
19:56:53.0258 7016 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
19:56:53.0269 7016 dot3svc - ok
19:56:53.0275 7016 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
19:56:53.0277 7016 DPS - ok
19:56:53.0311 7016 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:56:53.0313 7016 drmkaud - ok
19:56:53.0368 7016 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:56:53.0395 7016 DXGKrnl - ok
19:56:53.0436 7016 [ 50AD8FC1DC800FF36087994C8F7FDFF2 ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys
19:56:53.0455 7016 e1yexpress - ok
19:56:53.0486 7016 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
19:56:53.0490 7016 EapHost - ok
19:56:53.0601 7016 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
19:56:53.0644 7016 ebdrv - ok
19:56:53.0679 7016 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
19:56:53.0681 7016 EFS - ok
19:56:53.0753 7016 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:56:53.0775 7016 ehRecvr - ok
19:56:53.0791 7016 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
19:56:53.0801 7016 ehSched - ok
19:56:53.0836 7016 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
19:56:53.0850 7016 elxstor - ok
19:56:53.0887 7016 [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
19:56:53.0889 7016 EpsonBidirectionalService - ok
19:56:53.0939 7016 [ 20ECD0A490A121CB34F553FAD1DBBD39 ] EpsonScanSvc C:\Windows\system32\EscSvc64.exe
19:56:53.0943 7016 EpsonScanSvc - ok
19:56:54.0026 7016 [ 194E8100D57FC13BEF88129BAAD07E46 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
19:56:54.0029 7016 EPSON_PM_RPCV4_04 - ok
19:56:54.0044 7016 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:56:54.0052 7016 ErrDev - ok
19:56:54.0133 7016 esgiguard - ok
19:56:54.0185 7016 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
19:56:54.0194 7016 EventSystem - ok
19:56:54.0234 7016 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
19:56:54.0250 7016 exfat - ok
19:56:54.0277 7016 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:56:54.0292 7016 fastfat - ok
19:56:54.0345 7016 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
19:56:54.0359 7016 Fax - ok
19:56:54.0403 7016 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
19:56:54.0407 7016 fdc - ok
19:56:54.0444 7016 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
19:56:54.0445 7016 fdPHost - ok
19:56:54.0462 7016 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
19:56:54.0464 7016 FDResPub - ok
19:56:54.0487 7016 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:56:54.0493 7016 FileInfo - ok
19:56:54.0497 7016 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:56:54.0502 7016 Filetrace - ok
19:56:54.0538 7016 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
19:56:54.0543 7016 flpydisk - ok
19:56:54.0550 7016 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:56:54.0561 7016 FltMgr - ok
19:56:54.0627 7016 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
19:56:54.0643 7016 FontCache - ok
19:56:54.0687 7016 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:56:54.0689 7016 FontCache3.0.0.0 - ok
19:56:54.0714 7016 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
19:56:54.0721 7016 FsDepends - ok
19:56:54.0755 7016 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:56:54.0764 7016 Fs_Rec - ok
19:56:54.0804 7016 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
19:56:54.0809 7016 fvevol - ok
19:56:54.0848 7016 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
19:56:54.0860 7016 gagp30kx - ok
19:56:54.0917 7016 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
19:56:54.0932 7016 gpsvc - ok
19:56:55.0010 7016 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:56:55.0013 7016 gupdate - ok
19:56:55.0021 7016 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:56:55.0023 7016 gupdatem - ok
19:56:55.0092 7016 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
19:56:55.0098 7016 hcw85cir - ok
19:56:55.0161 7016 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:56:55.0175 7016 HdAudAddService - ok
19:56:55.0207 7016 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
19:56:55.0209 7016 HDAudBus - ok
19:56:55.0214 7016 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
19:56:55.0219 7016 HidBatt - ok
19:56:55.0225 7016 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
19:56:55.0232 7016 HidBth - ok
19:56:55.0254 7016 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
19:56:55.0259 7016 HidIr - ok
19:56:55.0275 7016 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
19:56:55.0280 7016 hidserv - ok
19:56:55.0320 7016 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
19:56:55.0325 7016 HidUsb - ok
19:56:55.0355 7016 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:56:55.0359 7016 hkmsvc - ok
19:56:55.0377 7016 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:56:55.0384 7016 HomeGroupListener - ok
19:56:55.0414 7016 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:56:55.0417 7016 HomeGroupProvider - ok
19:56:55.0444 7016 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
19:56:55.0451 7016 HpSAMD - ok
19:56:55.0485 7016 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:56:55.0493 7016 HTTP - ok
19:56:55.0509 7016 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
19:56:55.0510 7016 hwpolicy - ok
19:56:55.0559 7016 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:56:55.0570 7016 i8042prt - ok
19:56:55.0602 7016 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\drivers\iaStor.sys
19:56:55.0609 7016 iaStor - ok
19:56:55.0667 7016 [ B25F192EA1F84A316EB7C19EFCCCF33D ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
19:56:55.0668 7016 IAStorDataMgrSvc - ok
19:56:55.0721 7016 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
19:56:55.0741 7016 iaStorV - ok
19:56:55.0840 7016 [ 6F3909A3D40CC9F4B28E03B027F918D8 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
19:56:55.0867 7016 IconMan_R - ok
19:56:55.0916 7016 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:56:55.0940 7016 idsvc - ok
19:56:55.0977 7016 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
19:56:55.0982 7016 iirsp - ok
19:56:56.0031 7016 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
19:56:56.0046 7016 IKEEXT - ok
19:56:56.0053 7016 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
19:56:56.0058 7016 intelide - ok
19:56:56.0085 7016 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:56:56.0086 7016 intelppm - ok
19:56:56.0110 7016 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:56:56.0112 7016 IPBusEnum - ok
19:56:56.0124 7016 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:56:56.0129 7016 IpFilterDriver - ok
19:56:56.0177 7016 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:56:56.0189 7016 iphlpsvc - ok
19:56:56.0210 7016 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
19:56:56.0216 7016 IPMIDRV - ok
19:56:56.0220 7016 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
19:56:56.0226 7016 IPNAT - ok
19:56:56.0241 7016 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:56:56.0244 7016 IRENUM - ok
19:56:56.0249 7016 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:56:56.0253 7016 isapnp - ok
19:56:56.0275 7016 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
19:56:56.0285 7016 iScsiPrt - ok
19:56:56.0314 7016 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:56:56.0320 7016 kbdclass - ok
19:56:56.0343 7016 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
19:56:56.0347 7016 kbdhid - ok
19:56:56.0367 7016 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
19:56:56.0368 7016 KeyIso - ok
19:56:56.0401 7016 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:56:56.0412 7016 KSecDD - ok
19:56:56.0432 7016 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
19:56:56.0448 7016 KSecPkg - ok
19:56:56.0487 7016 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
19:56:56.0495 7016 ksthunk - ok
19:56:56.0533 7016 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
19:56:56.0557 7016 KtmRm - ok
19:56:56.0612 7016 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
19:56:56.0616 7016 LanmanServer - ok
19:56:56.0629 7016 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:56:56.0632 7016 LanmanWorkstation - ok
19:56:56.0670 7016 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:56:56.0679 7016 lltdio - ok
19:56:56.0705 7016 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:56:56.0724 7016 lltdsvc - ok
19:56:56.0765 7016 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
19:56:56.0769 7016 lmhosts - ok
19:56:56.0817 7016 [ 98B16E756243BEA9410E32025B19C06F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:56:56.0823 7016 LMS - ok
19:56:56.0871 7016 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
19:56:56.0884 7016 LSI_FC - ok
19:56:56.0893 7016 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
19:56:56.0906 7016 LSI_SAS - ok
19:56:56.0914 7016 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
19:56:56.0920 7016 LSI_SAS2 - ok
19:56:56.0926 7016 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
19:56:56.0932 7016 LSI_SCSI - ok
19:56:56.0951 7016 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
19:56:56.0961 7016 luafv - ok
19:56:56.0964 7016 lxcz_device - ok
19:56:57.0026 7016 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
19:56:57.0036 7016 MBAMProtector - ok
19:56:57.0113 7016 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
19:56:57.0120 7016 MBAMScheduler - ok
19:56:57.0200 7016 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
19:56:57.0214 7016 MBAMService - ok
19:56:57.0238 7016 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:56:57.0245 7016 Mcx2Svc - ok
19:56:57.0258 7016 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
19:56:57.0263 7016 megasas - ok
19:56:57.0298 7016 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
19:56:57.0309 7016 MegaSR - ok
19:56:57.0337 7016 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
19:56:57.0343 7016 MEIx64 - ok
19:56:57.0374 7016 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
19:56:57.0376 7016 MMCSS - ok
19:56:57.0395 7016 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
19:56:57.0400 7016 Modem - ok
19:56:57.0432 7016 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:56:57.0433 7016 monitor - ok
19:56:57.0448 7016 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:56:57.0455 7016 mouclass - ok
19:56:57.0488 7016 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\drivers\mouhid.sys
19:56:57.0493 7016 mouhid - ok
19:56:57.0521 7016 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
19:56:57.0523 7016 mountmgr - ok
19:56:57.0528 7016 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
19:56:57.0538 7016 mpio - ok
19:56:57.0542 7016 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:56:57.0548 7016 mpsdrv - ok
19:56:57.0591 7016 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
19:56:57.0601 7016 MpsSvc - ok
19:56:57.0621 7016 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:56:57.0630 7016 MRxDAV - ok
19:56:57.0652 7016 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:56:57.0661 7016 mrxsmb - ok
19:56:57.0680 7016 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:56:57.0691 7016 mrxsmb10 - ok
19:56:57.0702 7016 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:56:57.0710 7016 mrxsmb20 - ok
19:56:57.0730 7016 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
19:56:57.0735 7016 msahci - ok
19:56:57.0756 7016 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:56:57.0764 7016 msdsm - ok
19:56:57.0779 7016 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
19:56:57.0789 7016 MSDTC - ok
19:56:57.0815 7016 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:56:57.0819 7016 Msfs - ok
19:56:57.0833 7016 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
19:56:57.0837 7016 mshidkmdf - ok
19:56:57.0854 7016 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:56:57.0858 7016 msisadrv - ok
19:56:57.0884 7016 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:56:57.0892 7016 MSiSCSI - ok
19:56:57.0896 7016 msiserver - ok
19:56:57.0919 7016 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:56:57.0922 7016 MSKSSRV - ok
19:56:57.0932 7016 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:56:57.0936 7016 MSPCLOCK - ok
19:56:57.0950 7016 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:56:57.0950 7016 MSPQM - ok
19:56:57.0974 7016 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:56:57.0985 7016 MsRPC - ok
19:56:57.0996 7016 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
19:56:57.0997 7016 mssmbios - ok
19:56:58.0016 7016 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:56:58.0019 7016 MSTEE - ok
19:56:58.0023 7016 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
19:56:58.0027 7016 MTConfig - ok
19:56:58.0032 7016 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
19:56:58.0038 7016 Mup - ok
19:56:58.0073 7016 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
19:56:58.0080 7016 napagent - ok
19:56:58.0122 7016 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:56:58.0134 7016 NativeWifiP - ok
19:56:58.0194 7016 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:56:58.0209 7016 NDIS - ok
19:56:58.0229 7016 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
19:56:58.0235 7016 NdisCap - ok
19:56:58.0261 7016 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:56:58.0266 7016 NdisTapi - ok
19:56:58.0282 7016 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:56:58.0289 7016 Ndisuio - ok
19:56:58.0295 7016 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:56:58.0305 7016 NdisWan - ok
19:56:58.0314 7016 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:56:58.0321 7016 NDProxy - ok
19:56:58.0331 7016 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:56:58.0335 7016 NetBIOS - ok
19:56:58.0368 7016 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
19:56:58.0370 7016 NetBT - ok
19:56:58.0389 7016 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
19:56:58.0390 7016 Netlogon - ok
19:56:58.0416 7016 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
19:56:58.0420 7016 Netman - ok
19:56:58.0455 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:56:58.0472 7016 NetMsmqActivator - ok
19:56:58.0475 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:56:58.0476 7016 NetPipeActivator - ok
19:56:58.0484 7016 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
19:56:58.0488 7016 netprofm - ok
19:56:58.0492 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:56:58.0493 7016 NetTcpActivator - ok
19:56:58.0496 7016 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:56:58.0497 7016 NetTcpPortSharing - ok
19:56:58.0530 7016 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
19:56:58.0534 7016 nfrd960 - ok
19:56:58.0560 7016 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
19:56:58.0563 7016 NlaSvc - ok
19:56:58.0578 7016 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:56:58.0582 7016 Npfs - ok
19:56:58.0611 7016 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
19:56:58.0612 7016 nsi - ok
19:56:58.0615 7016 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:56:58.0615 7016 nsiproxy - ok
19:56:58.0663 7016 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:56:58.0688 7016 Ntfs - ok
19:56:58.0707 7016 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
19:56:58.0709 7016 Null - ok
19:56:58.0741 7016 [ F12E3EA0386EBC284C893611107C6A96 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
19:56:58.0755 7016 NVHDA - ok
19:56:59.0049 7016 [ D5DEA2C1865CAB9EE6AA29CF9E79A2CE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:56:59.0398 7016 nvlddmkm - ok
19:56:59.0422 7016 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:56:59.0428 7016 nvraid - ok
19:56:59.0457 7016 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:56:59.0463 7016 nvstor - ok
19:56:59.0520 7016 [ 5A4AF8EA634B4FEEAF6F16BB1845715A ] NVSvc C:\Windows\system32\nvvsvc.exe
19:56:59.0539 7016 NVSvc - ok
19:56:59.0562 7016 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:56:59.0577 7016 nv_agp - ok
19:56:59.0601 7016 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
19:56:59.0614 7016 ohci1394 - ok
19:56:59.0681 7016 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:56:59.0698 7016 ose - ok
19:56:59.0867 7016 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:57:00.0005 7016 osppsvc - ok
19:57:00.0037 7016 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
19:57:00.0041 7016 p2pimsvc - ok
19:57:00.0067 7016 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
19:57:00.0072 7016 p2psvc - ok
19:57:00.0103 7016 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
19:57:00.0109 7016 Parport - ok
19:57:00.0140 7016 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:57:00.0146 7016 partmgr - ok
19:57:00.0183 7016 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
19:57:00.0189 7016 PcaSvc - ok
19:57:00.0206 7016 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
19:57:00.0222 7016 pci - ok
19:57:00.0243 7016 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
19:57:00.0250 7016 pciide - ok
19:57:00.0270 7016 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
19:57:00.0286 7016 pcmcia - ok
19:57:00.0300 7016 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
19:57:00.0307 7016 pcw - ok
19:57:00.0325 7016 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:57:00.0343 7016 PEAUTH - ok
19:57:00.0427 7016 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
19:57:00.0436 7016 PerfHost - ok
19:57:00.0512 7016 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
19:57:00.0542 7016 pla - ok
19:57:00.0577 7016 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:57:00.0583 7016 PlugPlay - ok
19:57:00.0782 7016 [ 63694C307273062A2167AE4CE80730EF ] PMBDeviceInfoProvider c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
19:57:00.0808 7016 PMBDeviceInfoProvider - ok
19:57:00.0832 7016 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
19:57:00.0840 7016 PNRPAutoReg - ok
19:57:00.0860 7016 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
19:57:00.0865 7016 PNRPsvc - ok
19:57:00.0903 7016 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:57:00.0910 7016 PolicyAgent - ok
19:57:00.0957 7016 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
19:57:00.0961 7016 Power - ok
19:57:01.0010 7016 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:57:01.0024 7016 PptpMiniport - ok
19:57:01.0042 7016 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
19:57:01.0054 7016 Processor - ok
19:57:01.0081 7016 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
19:57:01.0085 7016 ProfSvc - ok
19:57:01.0100 7016 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:57:01.0102 7016 ProtectedStorage - ok
19:57:01.0133 7016 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
19:57:01.0135 7016 Psched - ok
19:57:01.0210 7016 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
19:57:01.0236 7016 ql2300 - ok
19:57:01.0240 7016 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
19:57:01.0247 7016 ql40xx - ok
19:57:01.0274 7016 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
19:57:01.0284 7016 QWAVE - ok
19:57:01.0287 7016 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:57:01.0291 7016 QWAVEdrv - ok
19:57:01.0300 7016 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:57:01.0303 7016 RasAcd - ok
19:57:01.0330 7016 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
19:57:01.0335 7016 RasAgileVpn - ok
19:57:01.0368 7016 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
19:57:01.0374 7016 RasAuto - ok
19:57:01.0386 7016 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:57:01.0391 7016 Rasl2tp - ok
19:57:01.0417 7016 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
19:57:01.0421 7016 RasMan - ok
19:57:01.0434 7016 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:57:01.0439 7016 RasPppoe - ok
19:57:01.0467 7016 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:57:01.0472 7016 RasSstp - ok
19:57:01.0478 7016 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:57:01.0487 7016 rdbss - ok
19:57:01.0497 7016 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
19:57:01.0501 7016 rdpbus - ok
19:57:01.0526 7016 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:57:01.0527 7016 RDPCDD - ok
19:57:01.0542 7016 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:57:01.0543 7016 RDPENCDD - ok
19:57:01.0557 7016 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
19:57:01.0557 7016 RDPREFMP - ok
19:57:01.0579 7016 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:57:01.0586 7016 RDPWD - ok
19:57:01.0619 7016 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
19:57:01.0628 7016 rdyboost - ok
19:57:01.0654 7016 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
19:57:01.0660 7016 RemoteAccess - ok
19:57:01.0695 7016 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:57:01.0704 7016 RemoteRegistry - ok
19:57:01.0739 7016 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
19:57:01.0746 7016 RFCOMM - ok
19:57:01.0769 7016 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
19:57:01.0772 7016 RpcEptMapper - ok
19:57:01.0802 7016 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
19:57:01.0809 7016 RpcLocator - ok
19:57:01.0849 7016 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
19:57:01.0858 7016 RpcSs - ok
19:57:01.0888 7016 [ 546D7F426776090B90EF5F195B6AE662 ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys
19:57:01.0892 7016 RSPCIESTOR - ok
19:57:01.0919 7016 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:57:01.0926 7016 rspndr - ok
19:57:01.0977 7016 [ EA5532868BA76923D75BCB2A1448D810 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
19:57:01.0988 7016 RTL8167 - ok
19:57:02.0022 7016 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
19:57:02.0024 7016 SamSs - ok
19:57:02.0043 7016 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:57:02.0051 7016 sbp2port - ok
19:57:02.0081 7016 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:57:02.0091 7016 SCardSvr - ok
19:57:02.0095 7016 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
19:57:02.0101 7016 scfilter - ok
19:57:02.0128 7016 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
19:57:02.0137 7016 Schedule - ok
19:57:02.0151 7016 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
19:57:02.0152 7016 SCPolicySvc - ok
19:57:02.0194 7016 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
19:57:02.0207 7016 sdbus - ok
19:57:02.0237 7016 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:57:02.0252 7016 SDRSVC - ok
19:57:02.0276 7016 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:57:02.0281 7016 secdrv - ok
19:57:02.0297 7016 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
19:57:02.0299 7016 seclogon - ok
19:57:02.0326 7016 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
19:57:02.0329 7016 SENS - ok
19:57:02.0353 7016 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
19:57:02.0360 7016 SensrSvc - ok
19:57:02.0383 7016 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
19:57:02.0388 7016 Serenum - ok
19:57:02.0412 7016 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
19:57:02.0420 7016 Serial - ok
19:57:02.0432 7016 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
19:57:02.0437 7016 sermouse - ok
19:57:02.0467 7016 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
19:57:02.0476 7016 SessionEnv - ok
19:57:02.0509 7016 [ 286D3889E6AB5589646FF8A63CB928AE ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys
19:57:02.0513 7016 SFEP - ok
19:57:02.0530 7016 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:57:02.0535 7016 sffdisk - ok
19:57:02.0539 7016 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:57:02.0545 7016 sffp_mmc - ok
19:57:02.0556 7016 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:57:02.0559 7016 sffp_sd - ok
19:57:02.0562 7016 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
19:57:02.0565 7016 sfloppy - ok
19:57:02.0630 7016 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
19:57:02.0653 7016 Sftfs - ok
19:57:02.0729 7016 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
19:57:02.0739 7016 sftlist - ok
19:57:02.0790 7016 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
19:57:02.0808 7016 Sftplay - ok
19:57:02.0835 7016 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
19:57:02.0844 7016 Sftredir - ok
19:57:02.0882 7016 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
19:57:02.0891 7016 Sftvol - ok
19:57:02.0925 7016 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
19:57:02.0930 7016 sftvsa - ok
19:57:02.0966 7016 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:57:02.0983 7016 SharedAccess - ok
19:57:03.0040 7016 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:57:03.0050 7016 ShellHWDetection - ok
19:57:03.0079 7016 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
19:57:03.0084 7016 SiSRaid2 - ok
19:57:03.0089 7016 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
19:57:03.0096 7016 SiSRaid4 - ok
19:57:03.0224 7016 [ 0F97E7A47A52F4A36969F0FC319654C2 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
19:57:03.0258 7016 Skype C2C Service - ok
19:57:03.0329 7016 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
19:57:03.0333 7016 SkypeUpdate - ok
19:57:03.0383 7016 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:57:03.0395 7016 Smb - ok
19:57:03.0442 7016 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:57:03.0453 7016 SNMPTRAP - ok
19:57:03.0557 7016 [ DDF2EC98AF6FC70608A4F9CE4DB52758 ] SOHCImp C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
19:57:03.0575 7016 SOHCImp - ok
19:57:03.0583 7016 [ 5FA03F5EA6EFEF6D17B4A1A48C40A23C ] SOHDs C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
19:57:03.0597 7016 SOHDs - ok
19:57:03.0640 7016 [ 65E5659E9C2A0762D05657C0E22A7CA2 ] SpfService C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
19:57:03.0668 7016 SpfService - ok
19:57:03.0698 7016 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
19:57:03.0707 7016 spldr - ok
19:57:03.0762 7016 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
19:57:03.0776 7016 Spooler - ok
19:57:03.0905 7016 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
19:57:03.0937 7016 sppsvc - ok
19:57:03.0957 7016 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
19:57:03.0962 7016 sppuinotify - ok
19:57:03.0985 7016 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
19:57:03.0995 7016 srv - ok
19:57:04.0004 7016 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:57:04.0014 7016 srv2 - ok
19:57:04.0019 7016 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:57:04.0024 7016 srvnet - ok
19:57:04.0055 7016 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
19:57:04.0067 7016 ssadbus - ok
19:57:04.0082 7016 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
19:57:04.0089 7016 ssadmdfl - ok
19:57:04.0105 7016 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
19:57:04.0116 7016 ssadmdm - ok
19:57:04.0146 7016 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:57:04.0149 7016 SSDPSRV - ok
19:57:04.0164 7016 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:57:04.0166 7016 SstpSvc - ok
19:57:04.0214 7016 [ 79969ACAEEBEDA7DC3673656AB9918FD ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
19:57:04.0217 7016 Stereo Service - ok
19:57:04.0250 7016 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
19:57:04.0254 7016 stexstor - ok
19:57:04.0289 7016 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
19:57:04.0296 7016 stisvc - ok
19:57:04.0313 7016 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
19:57:04.0317 7016 swenum - ok
19:57:04.0352 7016 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
19:57:04.0366 7016 swprv - ok
19:57:04.0414 7016 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
19:57:04.0431 7016 SysMain - ok
19:57:04.0447 7016 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:57:04.0454 7016 TabletInputService - ok
19:57:04.0487 7016 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
19:57:04.0491 7016 TapiSrv - ok
19:57:04.0503 7016 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
19:57:04.0506 7016 TBS - ok
19:57:04.0596 7016 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:57:04.0636 7016 Tcpip - ok
19:57:04.0671 7016 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
19:57:04.0679 7016 TCPIP6 - ok
19:57:04.0698 7016 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:57:04.0702 7016 tcpipreg - ok
19:57:04.0730 7016 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:57:04.0733 7016 TDPIPE - ok
19:57:04.0766 7016 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:57:04.0773 7016 TDTCP - ok
19:57:04.0804 7016 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:57:04.0810 7016 tdx - ok
19:57:04.0814 7016 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
19:57:04.0820 7016 TermDD - ok
19:57:04.0859 7016 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
19:57:04.0867 7016 TermService - ok
19:57:04.0879 7016 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
19:57:04.0881 7016 Themes - ok
19:57:04.0907 7016 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
19:57:04.0909 7016 THREADORDER - ok
19:57:04.0927 7016 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
19:57:04.0930 7016 TrkWks - ok
19:57:04.0972 7016 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:57:04.0974 7016 TrustedInstaller - ok
19:57:05.0037 7016 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:57:05.0045 7016 tssecsrv - ok
19:57:05.0063 7016 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
19:57:05.0071 7016 TsUsbFlt - ok
19:57:05.0090 7016 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
19:57:05.0097 7016 TsUsbGD - ok
19:57:05.0129 7016 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:57:05.0132 7016 tunnel - ok
19:57:05.0138 7016 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
19:57:05.0145 7016 uagp35 - ok
19:57:05.0190 7016 [ 1FE69F3C1CA1CF4B7EC7E2E9090FFFDC ] uCamMonitor C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
19:57:05.0192 7016 uCamMonitor - ok
19:57:05.0220 7016 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:57:05.0240 7016 udfs - ok
19:57:05.0271 7016 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:57:05.0281 7016 UI0Detect - ok
19:57:05.0301 7016 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:57:05.0309 7016 uliagpkx - ok
19:57:05.0318 7016 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:57:05.0323 7016 umbus - ok
19:57:05.0336 7016 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
19:57:05.0337 7016 UmPass - ok
19:57:05.0473 7016 [ 7A78ED1088890114DFDE2C4AB038D6B6 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
19:57:05.0495 7016 UNS - ok
19:57:05.0518 7016 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
19:57:05.0522 7016 upnphost - ok
19:57:05.0542 7016 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:57:05.0547 7016 usbccgp - ok
19:57:05.0568 7016 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:57:05.0575 7016 usbcir - ok
19:57:05.0578 7016 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
19:57:05.0583 7016 usbehci - ok
19:57:05.0605 7016 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:57:05.0616 7016 usbhub - ok
19:57:05.0625 7016 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:57:05.0630 7016 usbohci - ok
19:57:05.0661 7016 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:57:05.0664 7016 usbprint - ok
19:57:05.0716 7016 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
19:57:05.0726 7016 usbscan - ok
19:57:05.0758 7016 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:57:05.0771 7016 USBSTOR - ok
19:57:05.0778 7016 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
19:57:05.0788 7016 usbuhci - ok
19:57:05.0812 7016 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
19:57:05.0820 7016 usbvideo - ok
19:57:05.0851 7016 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
19:57:05.0854 7016 UxSms - ok
19:57:05.0889 7016 [ DCB1F83AD167D16D263CE57C94E9EEDF ] VAIO Event Service C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
19:57:05.0891 7016 VAIO Event Service - ok
19:57:05.0911 7016 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
19:57:05.0915 7016 VaultSvc - ok
19:57:06.0027 7016 [ D00058C1FFF3F3DE990444A5734E9639 ] VCFw C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
19:57:06.0134 7016 VCFw - ok
19:57:06.0258 7016 [ F19275655B42086C884ABCDAE2C659AE ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
19:57:06.0308 7016 VcmIAlzMgr - ok
19:57:06.0324 7016 [ 2F06D134554BA84FE253DBC481DCFE6D ] VcmINSMgr C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
19:57:06.0366 7016 VcmINSMgr - ok
19:57:06.0432 7016 [ 32A3735F6874B7783C6209ED5CA36D9D ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
19:57:06.0449 7016 VcmXmlIfHelper - ok
19:57:06.0543 7016 [ D347D3ABE070AA09C22FC37121555D52 ] VCService C:\Program Files\Sony\VAIO Care\VCService.exe
19:57:06.0545 7016 VCService - ok
19:57:06.0579 7016 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
19:57:06.0590 7016 vdrvroot - ok
19:57:06.0633 7016 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
19:57:06.0645 7016 vds - ok
19:57:06.0662 7016 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:57:06.0668 7016 vga - ok
19:57:06.0673 7016 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
19:57:06.0678 7016 VgaSave - ok
19:57:06.0685 7016 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
19:57:06.0696 7016 vhdmp - ok
19:57:06.0699 7016 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
19:57:06.0703 7016 viaide - ok
19:57:06.0737 7016 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:57:06.0742 7016 volmgr - ok
19:57:06.0748 7016 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:57:06.0752 7016 volmgrx - ok
19:57:06.0759 7016 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:57:06.0768 7016 volsnap - ok
19:57:06.0794 7016 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
19:57:06.0800 7016 vsmraid - ok
19:57:06.0870 7016 [ 0ED394BFBA3EB4740F063E0BA5EC7104 ] VSNService C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
19:57:06.0884 7016 VSNService - ok
19:57:06.0959 7016 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
19:57:06.0984 7016 VSS - ok
19:57:07.0111 7016 [ D2D646D4D686C6996BA1FF96E11BE570 ] VUAgent C:\Program Files\Sony\VAIO Update\VUAgent.exe
19:57:07.0124 7016 VUAgent - ok
19:57:07.0143 7016 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
19:57:07.0150 7016 vwifibus - ok
19:57:07.0190 7016 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
19:57:07.0197 7016 vwififlt - ok
19:57:07.0223 7016 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
19:57:07.0230 7016 W32Time - ok
19:57:07.0252 7016 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
19:57:07.0257 7016 WacomPen - ok
19:57:07.0262 7016 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:57:07.0268 7016 WANARP - ok
19:57:07.0271 7016 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:57:07.0273 7016 Wanarpv6 - ok
19:57:07.0325 7016 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
19:57:07.0351 7016 wbengine - ok
19:57:07.0363 7016 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:57:07.0373 7016 WbioSrvc - ok
19:57:07.0381 7016 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:57:07.0392 7016 wcncsvc - ok
19:57:07.0409 7016 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:57:07.0415 7016 WcsPlugInService - ok
19:57:07.0436 7016 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
19:57:07.0441 7016 Wd - ok
19:57:07.0474 7016 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:57:07.0493 7016 Wdf01000 - ok
19:57:07.0507 7016 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:57:07.0510 7016 WdiServiceHost - ok
19:57:07.0513 7016 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:57:07.0516 7016 WdiSystemHost - ok
19:57:07.0546 7016 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
19:57:07.0558 7016 WebClient - ok
19:57:07.0571 7016 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:57:07.0581 7016 Wecsvc - ok
19:57:07.0592 7016 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:57:07.0595 7016 wercplsupport - ok
19:57:07.0622 7016 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
19:57:07.0625 7016 WerSvc - ok
19:57:07.0643 7016 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:57:07.0646 7016 WfpLwf - ok
19:57:07.0666 7016 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:57:07.0670 7016 WIMMount - ok
19:57:07.0682 7016 WinDefend - ok
19:57:07.0699 7016 WinHttpAutoProxySvc - ok
19:57:07.0751 7016 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:57:07.0757 7016 Winmgmt - ok
19:57:07.0845 7016 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
19:57:07.0885 7016 WinRM - ok
19:57:07.0932 7016 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
19:57:07.0945 7016 WinUsb - ok
19:57:07.0996 7016 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
19:57:08.0008 7016 Wlansvc - ok
19:57:08.0053 7016 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
19:57:08.0067 7016 wlcrasvc - ok
19:57:08.0163 7016 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:57:08.0186 7016 wlidsvc - ok
19:57:08.0199 7016 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
19:57:08.0202 7016 WmiAcpi - ok
19:57:08.0225 7016 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:57:08.0232 7016 wmiApSrv - ok
19:57:08.0256 7016 WMPNetworkSvc - ok
19:57:08.0281 7016 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:57:08.0285 7016 WPCSvc - ok
19:57:08.0301 7016 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:57:08.0303 7016 WPDBusEnum - ok
19:57:08.0324 7016 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:57:08.0327 7016 ws2ifsl - ok
19:57:08.0346 7016 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
19:57:08.0351 7016 wscsvc - ok
19:57:08.0396 7016 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
19:57:08.0403 7016 WSDPrintDevice - ok
19:57:08.0421 7016 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys
19:57:08.0425 7016 WSDScan - ok
19:57:08.0428 7016 WSearch - ok
19:57:08.0519 7016 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
19:57:08.0548 7016 wuauserv - ok
19:57:08.0577 7016 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:57:08.0583 7016 WudfPf - ok
19:57:08.0633 7016 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:57:08.0649 7016 WUDFRd - ok
19:57:08.0699 7016 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:57:08.0714 7016 wudfsvc - ok
19:57:08.0754 7016 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
19:57:08.0773 7016 WwanSvc - ok
19:57:08.0796 7016 ================ Scan global ===============================
19:57:08.0827 7016 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
19:57:08.0857 7016 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
19:57:08.0866 7016 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
19:57:08.0898 7016 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
19:57:08.0935 7016 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
19:57:08.0939 7016 [Global] - ok
19:57:08.0940 7016 ================ Scan MBR ==================================
19:57:08.0950 7016 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
19:57:09.0144 7016 \Device\Harddisk0\DR0 - ok
19:57:09.0145 7016 ================ Scan VBR ==================================
19:57:09.0149 7016 [ B66EC185B9DE52245CC45448CF4642D5 ] \Device\Harddisk0\DR0\Partition1
19:57:09.0153 7016 \Device\Harddisk0\DR0\Partition1 - ok
19:57:09.0167 7016 [ 25BFE8FE0C20C7A147DF3812DF9289A6 ] \Device\Harddisk0\DR0\Partition2
19:57:09.0169 7016 \Device\Harddisk0\DR0\Partition2 - ok
19:57:09.0170 7016 ============================================================
19:57:09.0170 7016 Scan finished
19:57:09.0170 7016 ============================================================
19:57:09.0181 6356 Detected object count: 0
19:57:09.0181 6356 Actual detected object count: 0

Alt 18.06.2013, 20:28   #8
markusg
/// Malware-holic
 
wssetup exe - Standard

wssetup exe



bitte nach anleitung konfigurieren und scannen
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 18.06.2013, 21:40   #9
xibor
 
wssetup exe - Standard

wssetup exe



soory,22:32:42.0918 4908 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:32:43.0152 4908 ============================================================
22:32:43.0152 4908 Current date / time: 2013/06/18 22:32:43.0152
22:32:43.0152 4908 SystemInfo:
22:32:43.0152 4908
22:32:43.0152 4908 OS Version: 6.1.7601 ServicePack: 1.0
22:32:43.0152 4908 Product type: Workstation
22:32:43.0152 4908 ComputerName: CHRIS-VAIO
22:32:43.0152 4908 UserName: chris
22:32:43.0152 4908 Windows directory: C:\Windows
22:32:43.0152 4908 System windows directory: C:\Windows
22:32:43.0152 4908 Running under WOW64
22:32:43.0152 4908 Processor architecture: Intel x64
22:32:43.0152 4908 Number of processors: 4
22:32:43.0152 4908 Page size: 0x1000
22:32:43.0152 4908 Boot type: Normal boot
22:32:43.0152 4908 ============================================================
22:32:43.0932 4908 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:32:43.0948 4908 ============================================================
22:32:43.0948 4908 \Device\Harddisk0\DR0:
22:32:43.0948 4908 MBR partitions:
22:32:43.0948 4908 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1BC9800, BlocksNum 0x32000
22:32:43.0948 4908 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1BFB800, BlocksNum 0x48C5C000
22:32:43.0948 4908 ============================================================
22:32:43.0979 4908 C: <-> \Device\Harddisk0\DR0\Partition2
22:32:43.0979 4908 ============================================================
22:32:43.0979 4908 Initialize success
22:32:43.0979 4908 ============================================================
22:33:03.0701 2012 ============================================================
22:33:03.0701 2012 Scan started
22:33:03.0701 2012 Mode: Manual; SigCheck; TDLFS;
22:33:03.0701 2012 ============================================================
22:33:03.0966 2012 ================ Scan system memory ========================
22:33:03.0966 2012 System memory - ok
22:33:03.0966 2012 ================ Scan services =============================
22:33:04.0200 2012 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
22:33:04.0388 2012 1394ohci - ok
22:33:04.0512 2012 [ B33CF4DE909A5B30F526D82053A63C8E ] ABBYY.Licensing.FineReader.Sprint.9.0 C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
22:33:04.0559 2012 ABBYY.Licensing.FineReader.Sprint.9.0 - ok
22:33:04.0637 2012 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
22:33:04.0684 2012 ACDaemon - ok
22:33:04.0731 2012 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
22:33:04.0778 2012 ACPI - ok
22:33:04.0793 2012 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
22:33:04.0902 2012 AcpiPmi - ok
22:33:04.0965 2012 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:33:04.0980 2012 AdobeARMservice - ok
22:33:05.0136 2012 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:33:05.0168 2012 AdobeFlashPlayerUpdateSvc - ok
22:33:05.0230 2012 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
22:33:05.0277 2012 adp94xx - ok
22:33:05.0308 2012 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
22:33:05.0324 2012 adpahci - ok
22:33:05.0339 2012 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
22:33:05.0355 2012 adpu320 - ok
22:33:05.0370 2012 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:33:05.0542 2012 AeLookupSvc - ok
22:33:05.0573 2012 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
22:33:05.0651 2012 AFD - ok
22:33:05.0698 2012 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
22:33:05.0729 2012 agp440 - ok
22:33:05.0760 2012 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
22:33:05.0823 2012 ALG - ok
22:33:05.0838 2012 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
22:33:05.0854 2012 aliide - ok
22:33:05.0870 2012 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
22:33:05.0885 2012 amdide - ok
22:33:05.0901 2012 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
22:33:05.0948 2012 AmdK8 - ok
22:33:05.0963 2012 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
22:33:06.0010 2012 AmdPPM - ok
22:33:06.0041 2012 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
22:33:06.0072 2012 amdsata - ok
22:33:06.0119 2012 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
22:33:06.0150 2012 amdsbs - ok
22:33:06.0166 2012 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
22:33:06.0197 2012 amdxata - ok
22:33:06.0400 2012 [ D9A92E6DD41C5ADC045AE485026AA40C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:33:06.0416 2012 AntiVirSchedulerService - ok
22:33:06.0494 2012 [ 66A7A38F7C439153B758548375EB9E5E ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:33:06.0509 2012 AntiVirService - ok
22:33:06.0556 2012 [ 9EDAE2D1CA368E8D01BEE8BFBC9488E4 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
22:33:06.0618 2012 AntiVirWebService - ok
22:33:06.0665 2012 [ D80CB25D90474C731C0D1312A6DE3B13 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
22:33:06.0712 2012 ApfiltrService - ok
22:33:06.0743 2012 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
22:33:06.0977 2012 AppID - ok
22:33:07.0008 2012 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:33:07.0086 2012 AppIDSvc - ok
22:33:07.0149 2012 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
22:33:07.0227 2012 Appinfo - ok
22:33:07.0274 2012 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
22:33:07.0305 2012 arc - ok
22:33:07.0320 2012 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
22:33:07.0336 2012 arcsas - ok
22:33:07.0367 2012 [ C130BC4A51B1382B2BE8E44579EC4C0A ] ArcSoftKsUFilter C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
22:33:07.0383 2012 ArcSoftKsUFilter - ok
22:33:07.0493 2012 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:33:07.0540 2012 aspnet_state - ok
22:33:07.0571 2012 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:33:07.0680 2012 AsyncMac - ok
22:33:07.0696 2012 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
22:33:07.0727 2012 atapi - ok
22:33:07.0758 2012 [ 50F257E19554421B6891E3F998EDCA90 ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys
22:33:07.0821 2012 AthBTPort - ok
22:33:07.0883 2012 [ 650F111D5CDA64C10AE4B9D1BA9D4FFF ] Atheros Bt&Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
22:33:07.0914 2012 Atheros Bt&Wlan Coex Agent ( UnsignedFile.Multi.Generic ) - warning
22:33:07.0914 2012 Atheros Bt&Wlan Coex Agent - detected UnsignedFile.Multi.Generic (1)
22:33:07.0945 2012 [ EBC3119394C9074A9CD87578A435050D ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
22:33:07.0961 2012 AtherosSvc ( UnsignedFile.Multi.Generic ) - warning
22:33:07.0961 2012 AtherosSvc - detected UnsignedFile.Multi.Generic (1)
22:33:08.0070 2012 [ C8679A07267F030704168E45E27C3D43 ] athr C:\Windows\system32\DRIVERS\athrx.sys
22:33:08.0195 2012 athr - ok
22:33:08.0257 2012 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:33:08.0335 2012 AudioEndpointBuilder - ok
22:33:08.0351 2012 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
22:33:08.0382 2012 AudioSrv - ok
22:33:08.0429 2012 [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
22:33:08.0460 2012 avgntflt - ok
22:33:08.0523 2012 [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
22:33:08.0569 2012 avipbb - ok
22:33:08.0632 2012 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
22:33:08.0663 2012 avkmgr - ok
22:33:08.0710 2012 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:33:08.0819 2012 AxInstSV - ok
22:33:08.0881 2012 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
22:33:08.0944 2012 b06bdrv - ok
22:33:08.0991 2012 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
22:33:09.0037 2012 b57nd60a - ok
22:33:09.0147 2012 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe
22:33:09.0178 2012 BBSvc - ok
22:33:09.0271 2012 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
22:33:09.0303 2012 BBUpdate - ok
22:33:09.0334 2012 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
22:33:09.0381 2012 BDESVC - ok
22:33:09.0412 2012 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
22:33:09.0521 2012 Beep - ok
22:33:09.0583 2012 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
22:33:09.0677 2012 BFE - ok
22:33:09.0724 2012 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
22:33:09.0849 2012 BITS - ok
22:33:09.0880 2012 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:33:09.0911 2012 blbdrive - ok
22:33:09.0942 2012 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:33:10.0005 2012 bowser - ok
22:33:10.0020 2012 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
22:33:10.0083 2012 BrFiltLo - ok
22:33:10.0098 2012 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
22:33:10.0129 2012 BrFiltUp - ok
22:33:10.0176 2012 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
22:33:10.0254 2012 BridgeMP - ok
22:33:10.0285 2012 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
22:33:10.0348 2012 Browser - ok
22:33:10.0395 2012 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:33:10.0457 2012 Brserid - ok
22:33:10.0488 2012 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:33:10.0535 2012 BrSerWdm - ok
22:33:10.0566 2012 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:33:10.0597 2012 BrUsbMdm - ok
22:33:10.0613 2012 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:33:10.0629 2012 BrUsbSer - ok
22:33:10.0691 2012 [ B3BCD755FA9A359D10208CC9F09847CC ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys
22:33:10.0753 2012 BTATH_A2DP - ok
22:33:10.0800 2012 [ 9BBBA9D6DBDEFC8A6542BC7A6EBAF710 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys
22:33:10.0847 2012 btath_avdt - ok
22:33:10.0878 2012 [ D838DD1BCB328EFCFAD7A52DE9E3CAFD ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys
22:33:10.0941 2012 BTATH_BUS - ok
22:33:10.0956 2012 [ A441B800E04CF8443FAF519207563ABB ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys
22:33:11.0019 2012 BTATH_HCRP - ok
22:33:11.0081 2012 [ B16F8429A35BBA2A8EF9DB2E08675B97 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys
22:33:11.0143 2012 BTATH_LWFLT - ok
22:33:11.0175 2012 [ C24231C6BDFE21735930084A22089AAB ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys
22:33:11.0237 2012 BTATH_RCP - ok
22:33:11.0315 2012 [ 3632FA4C6B3CE9EC827690DEAC266D8C ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys
22:33:11.0393 2012 BtFilter - ok
22:33:11.0455 2012 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
22:33:11.0518 2012 BthEnum - ok
22:33:11.0549 2012 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
22:33:11.0596 2012 BTHMODEM - ok
22:33:11.0611 2012 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
22:33:11.0674 2012 BthPan - ok
22:33:11.0721 2012 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
22:33:11.0783 2012 BTHPORT - ok
22:33:11.0830 2012 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
22:33:11.0892 2012 bthserv - ok
22:33:11.0939 2012 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
22:33:11.0970 2012 BTHUSB - ok
22:33:12.0111 2012 catchme - ok
22:33:12.0142 2012 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:33:12.0251 2012 cdfs - ok
22:33:12.0282 2012 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:33:12.0329 2012 cdrom - ok
22:33:12.0360 2012 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
22:33:12.0438 2012 CertPropSvc - ok
22:33:12.0454 2012 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
22:33:12.0501 2012 circlass - ok
22:33:12.0517 2012 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
22:33:12.0548 2012 CLFS - ok
22:33:12.0626 2012 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:33:12.0642 2012 clr_optimization_v2.0.50727_32 - ok
22:33:12.0704 2012 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:33:12.0736 2012 clr_optimization_v2.0.50727_64 - ok
22:33:12.0798 2012 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:33:12.0845 2012 clr_optimization_v4.0.30319_32 - ok
22:33:12.0876 2012 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:33:12.0923 2012 clr_optimization_v4.0.30319_64 - ok
22:33:12.0970 2012 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:33:13.0001 2012 CmBatt - ok
22:33:13.0016 2012 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:33:13.0048 2012 cmdide - ok
22:33:13.0110 2012 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
22:33:13.0188 2012 CNG - ok
22:33:13.0282 2012 [ 1F394DF3714ED4280047810790E6DF69 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys
22:33:13.0375 2012 CnxtHdAudService - ok
22:33:13.0422 2012 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:33:13.0453 2012 Compbatt - ok
22:33:13.0469 2012 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
22:33:13.0516 2012 CompositeBus - ok
22:33:13.0547 2012 COMSysApp - ok
22:33:13.0562 2012 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
22:33:13.0578 2012 crcdisk - ok
22:33:13.0640 2012 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:33:13.0703 2012 CryptSvc - ok
22:33:13.0828 2012 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
22:33:13.0874 2012 cvhsvc - ok
22:33:13.0921 2012 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
22:33:14.0015 2012 DcomLaunch - ok
22:33:14.0046 2012 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
22:33:14.0140 2012 defragsvc - ok
22:33:14.0171 2012 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:33:14.0280 2012 DfsC - ok
22:33:14.0327 2012 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
22:33:14.0405 2012 Dhcp - ok
22:33:14.0436 2012 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
22:33:14.0545 2012 discache - ok
22:33:14.0576 2012 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
22:33:14.0608 2012 Disk - ok
22:33:14.0623 2012 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:33:14.0670 2012 Dnscache - ok
22:33:14.0686 2012 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
22:33:14.0779 2012 dot3svc - ok
22:33:14.0795 2012 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
22:33:14.0857 2012 DPS - ok
22:33:14.0904 2012 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:33:14.0951 2012 drmkaud - ok
22:33:15.0013 2012 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:33:15.0091 2012 DXGKrnl - ok
22:33:15.0138 2012 [ 50AD8FC1DC800FF36087994C8F7FDFF2 ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys
22:33:15.0169 2012 e1yexpress - ok
22:33:15.0200 2012 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
22:33:15.0278 2012 EapHost - ok
22:33:15.0372 2012 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
22:33:15.0497 2012 ebdrv - ok
22:33:15.0528 2012 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
22:33:15.0575 2012 EFS - ok
22:33:15.0637 2012 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:33:15.0715 2012 ehRecvr - ok
22:33:15.0731 2012 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
22:33:15.0778 2012 ehSched - ok
22:33:15.0809 2012 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
22:33:15.0840 2012 elxstor - ok
22:33:15.0887 2012 [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
22:33:15.0887 2012 EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - warning
22:33:15.0887 2012 EpsonBidirectionalService - detected UnsignedFile.Multi.Generic (1)
22:33:15.0965 2012 [ 20ECD0A490A121CB34F553FAD1DBBD39 ] EpsonScanSvc C:\Windows\system32\EscSvc64.exe
22:33:15.0996 2012 EpsonScanSvc - ok
22:33:16.0074 2012 [ 194E8100D57FC13BEF88129BAAD07E46 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
22:33:16.0090 2012 EPSON_PM_RPCV4_04 - ok
22:33:16.0105 2012 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:33:16.0168 2012 ErrDev - ok
22:33:16.0246 2012 esgiguard - ok
22:33:16.0292 2012 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
22:33:16.0417 2012 EventSystem - ok
22:33:16.0448 2012 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
22:33:16.0542 2012 exfat - ok
22:33:16.0558 2012 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:33:16.0636 2012 fastfat - ok
22:33:16.0682 2012 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
22:33:16.0745 2012 Fax - ok
22:33:16.0776 2012 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
22:33:16.0807 2012 fdc - ok
22:33:16.0854 2012 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
22:33:16.0948 2012 fdPHost - ok
22:33:16.0963 2012 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
22:33:17.0057 2012 FDResPub - ok
22:33:17.0072 2012 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:33:17.0104 2012 FileInfo - ok
22:33:17.0119 2012 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:33:17.0182 2012 Filetrace - ok
22:33:17.0182 2012 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
22:33:17.0197 2012 flpydisk - ok
22:33:17.0197 2012 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:33:17.0228 2012 FltMgr - ok
22:33:17.0291 2012 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
22:33:17.0369 2012 FontCache - ok
22:33:17.0416 2012 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:33:17.0447 2012 FontCache3.0.0.0 - ok
22:33:17.0478 2012 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:33:17.0525 2012 FsDepends - ok
22:33:17.0556 2012 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:33:17.0588 2012 Fs_Rec - ok
22:33:17.0635 2012 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:33:17.0697 2012 fvevol - ok
22:33:17.0744 2012 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
22:33:17.0760 2012 gagp30kx - ok
22:33:17.0807 2012 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
22:33:17.0885 2012 gpsvc - ok
22:33:17.0963 2012 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:33:17.0978 2012 gupdate - ok
22:33:17.0994 2012 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:33:18.0009 2012 gupdatem - ok
22:33:18.0041 2012 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:33:18.0103 2012 hcw85cir - ok
22:33:18.0134 2012 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:33:18.0212 2012 HdAudAddService - ok
22:33:18.0259 2012 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
22:33:18.0306 2012 HDAudBus - ok
22:33:18.0337 2012 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
22:33:18.0384 2012 HidBatt - ok
22:33:18.0399 2012 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
22:33:18.0446 2012 HidBth - ok
22:33:18.0462 2012 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
22:33:18.0493 2012 HidIr - ok
22:33:18.0524 2012 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
22:33:18.0587 2012 hidserv - ok
22:33:18.0680 2012 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
22:33:18.0711 2012 HidUsb - ok
22:33:18.0743 2012 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
22:33:18.0836 2012 hkmsvc - ok
22:33:18.0852 2012 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:33:18.0899 2012 HomeGroupListener - ok
22:33:18.0930 2012 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:33:18.0961 2012 HomeGroupProvider - ok
22:33:18.0992 2012 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
22:33:19.0008 2012 HpSAMD - ok
22:33:19.0039 2012 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:33:19.0133 2012 HTTP - ok
22:33:19.0148 2012 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:33:19.0164 2012 hwpolicy - ok
22:33:19.0195 2012 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
22:33:19.0226 2012 i8042prt - ok
22:33:19.0257 2012 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\drivers\iaStor.sys
22:33:19.0289 2012 iaStor - ok
22:33:19.0351 2012 [ B25F192EA1F84A316EB7C19EFCCCF33D ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
22:33:19.0367 2012 IAStorDataMgrSvc - ok
22:33:19.0413 2012 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
22:33:19.0445 2012 iaStorV - ok
22:33:19.0538 2012 [ 6F3909A3D40CC9F4B28E03B027F918D8 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
22:33:19.0601 2012 IconMan_R ( UnsignedFile.Multi.Generic ) - warning
22:33:19.0601 2012 IconMan_R - detected UnsignedFile.Multi.Generic (1)
22:33:19.0679 2012 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:33:19.0725 2012 idsvc - ok
22:33:19.0757 2012 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
22:33:19.0772 2012 iirsp - ok
22:33:19.0819 2012 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
22:33:19.0897 2012 IKEEXT - ok
22:33:19.0897 2012 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
22:33:19.0913 2012 intelide - ok
22:33:19.0944 2012 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:33:19.0975 2012 intelppm - ok
22:33:20.0006 2012 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:33:20.0069 2012 IPBusEnum - ok
22:33:20.0084 2012 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:33:20.0131 2012 IpFilterDriver - ok
22:33:20.0178 2012 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:33:20.0240 2012 iphlpsvc - ok
22:33:20.0271 2012 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
22:33:20.0303 2012 IPMIDRV - ok
22:33:20.0318 2012 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:33:20.0381 2012 IPNAT - ok
22:33:20.0396 2012 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:33:20.0427 2012 IRENUM - ok
22:33:20.0443 2012 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:33:20.0459 2012 isapnp - ok
22:33:20.0474 2012 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
22:33:20.0505 2012 iScsiPrt - ok
22:33:20.0537 2012 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:33:20.0568 2012 kbdclass - ok
22:33:20.0599 2012 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
22:33:20.0646 2012 kbdhid - ok
22:33:20.0661 2012 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
22:33:20.0677 2012 KeyIso - ok
22:33:20.0708 2012 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:33:20.0755 2012 KSecDD - ok
22:33:20.0771 2012 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:33:20.0802 2012 KSecPkg - ok
22:33:20.0833 2012 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
22:33:20.0911 2012 ksthunk - ok
22:33:20.0942 2012 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
22:33:21.0005 2012 KtmRm - ok
22:33:21.0036 2012 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
22:33:21.0098 2012 LanmanServer - ok
22:33:21.0114 2012 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:33:21.0176 2012 LanmanWorkstation - ok
22:33:21.0223 2012 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:33:21.0301 2012 lltdio - ok
22:33:21.0332 2012 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:33:21.0395 2012 lltdsvc - ok
22:33:21.0426 2012 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:33:21.0504 2012 lmhosts - ok
22:33:21.0566 2012 [ 98B16E756243BEA9410E32025B19C06F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:33:21.0582 2012 LMS - ok
22:33:21.0629 2012 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
22:33:21.0660 2012 LSI_FC - ok
22:33:21.0660 2012 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
22:33:21.0691 2012 LSI_SAS - ok
22:33:21.0691 2012 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
22:33:21.0722 2012 LSI_SAS2 - ok
22:33:21.0722 2012 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
22:33:21.0753 2012 LSI_SCSI - ok
22:33:21.0769 2012 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
22:33:21.0863 2012 luafv - ok
22:33:21.0863 2012 lxcz_device - ok
22:33:21.0878 2012 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
22:33:21.0894 2012 MBAMProtector - ok
22:33:21.0987 2012 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
22:33:22.0034 2012 MBAMScheduler - ok
22:33:22.0112 2012 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:33:22.0143 2012 MBAMService - ok
22:33:22.0175 2012 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:33:22.0221 2012 Mcx2Svc - ok
22:33:22.0237 2012 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
22:33:22.0253 2012 megasas - ok
22:33:22.0284 2012 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
22:33:22.0315 2012 MegaSR - ok
22:33:22.0346 2012 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
22:33:22.0377 2012 MEIx64 - ok
22:33:22.0409 2012 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
22:33:22.0471 2012 MMCSS - ok
22:33:22.0487 2012 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
22:33:22.0533 2012 Modem - ok
22:33:22.0565 2012 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:33:22.0596 2012 monitor - ok
22:33:22.0596 2012 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:33:22.0611 2012 mouclass - ok
22:33:22.0627 2012 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\drivers\mouhid.sys
22:33:22.0674 2012 mouhid - ok
22:33:22.0705 2012 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:33:22.0736 2012 mountmgr - ok
22:33:22.0752 2012 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
22:33:22.0783 2012 mpio - ok
22:33:22.0799 2012 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:33:22.0877 2012 mpsdrv - ok
22:33:22.0923 2012 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:33:23.0001 2012 MpsSvc - ok
22:33:23.0017 2012 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:33:23.0048 2012 MRxDAV - ok
22:33:23.0079 2012 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:33:23.0142 2012 mrxsmb - ok
22:33:23.0157 2012 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:33:23.0204 2012 mrxsmb10 - ok
22:33:23.0220 2012 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:33:23.0267 2012 mrxsmb20 - ok
22:33:23.0298 2012 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
22:33:23.0329 2012 msahci - ok
22:33:23.0329 2012 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:33:23.0376 2012 msdsm - ok
22:33:23.0391 2012 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
22:33:23.0438 2012 MSDTC - ok
22:33:23.0469 2012 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:33:23.0579 2012 Msfs - ok
22:33:23.0625 2012 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:33:23.0719 2012 mshidkmdf - ok
22:33:23.0750 2012 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:33:23.0766 2012 msisadrv - ok
22:33:23.0797 2012 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:33:23.0875 2012 MSiSCSI - ok
22:33:23.0875 2012 msiserver - ok
22:33:23.0891 2012 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:33:23.0953 2012 MSKSSRV - ok
22:33:23.0969 2012 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:33:24.0015 2012 MSPCLOCK - ok
22:33:24.0031 2012 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:33:24.0078 2012 MSPQM - ok
22:33:24.0109 2012 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:33:24.0125 2012 MsRPC - ok
22:33:24.0156 2012 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
22:33:24.0187 2012 mssmbios - ok
22:33:24.0218 2012 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:33:24.0327 2012 MSTEE - ok
22:33:24.0327 2012 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
22:33:24.0343 2012 MTConfig - ok
22:33:24.0359 2012 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
22:33:24.0374 2012 Mup - ok
22:33:24.0405 2012 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
22:33:24.0499 2012 napagent - ok
22:33:24.0530 2012 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:33:24.0608 2012 NativeWifiP - ok
22:33:24.0655 2012 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:33:24.0717 2012 NDIS - ok
22:33:24.0733 2012 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:33:24.0795 2012 NdisCap - ok
22:33:24.0827 2012 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:33:24.0905 2012 NdisTapi - ok
22:33:24.0905 2012 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:33:24.0967 2012 Ndisuio - ok
22:33:24.0967 2012 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:33:25.0045 2012 NdisWan - ok
22:33:25.0061 2012 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:33:25.0107 2012 NDProxy - ok
22:33:25.0139 2012 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:33:25.0217 2012 NetBIOS - ok
22:33:25.0217 2012 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:33:25.0295 2012 NetBT - ok
22:33:25.0295 2012 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
22:33:25.0310 2012 Netlogon - ok
22:33:25.0341 2012 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
22:33:25.0388 2012 Netman - ok
22:33:25.0419 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:33:25.0466 2012 NetMsmqActivator - ok
22:33:25.0482 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:33:25.0497 2012 NetPipeActivator - ok
22:33:25.0497 2012 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
22:33:25.0575 2012 netprofm - ok
22:33:25.0591 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:33:25.0591 2012 NetTcpActivator - ok
22:33:25.0607 2012 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:33:25.0607 2012 NetTcpPortSharing - ok
22:33:25.0638 2012 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
22:33:25.0669 2012 nfrd960 - ok
22:33:25.0700 2012 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:33:25.0731 2012 NlaSvc - ok
22:33:25.0763 2012 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:33:25.0841 2012 Npfs - ok
22:33:25.0872 2012 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
22:33:25.0919 2012 nsi - ok
22:33:25.0919 2012 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:33:25.0965 2012 nsiproxy - ok
22:33:26.0028 2012 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:33:26.0106 2012 Ntfs - ok
22:33:26.0137 2012 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
22:33:26.0184 2012 Null - ok
22:33:26.0215 2012 [ F12E3EA0386EBC284C893611107C6A96 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
22:33:26.0246 2012 NVHDA - ok
22:33:26.0527 2012 [ D5DEA2C1865CAB9EE6AA29CF9E79A2CE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:33:27.0057 2012 nvlddmkm - ok
22:33:27.0089 2012 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:33:27.0104 2012 nvraid - ok
22:33:27.0120 2012 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:33:27.0135 2012 nvstor - ok
22:33:27.0198 2012 [ 5A4AF8EA634B4FEEAF6F16BB1845715A ] NVSvc C:\Windows\system32\nvvsvc.exe
22:33:27.0245 2012 NVSvc - ok
22:33:27.0245 2012 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:33:27.0260 2012 nv_agp - ok
22:33:27.0276 2012 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
22:33:27.0307 2012 ohci1394 - ok
22:33:27.0354 2012 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:33:27.0401 2012 ose - ok
22:33:27.0557 2012 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:33:27.0635 2012 osppsvc - ok
22:33:27.0666 2012 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
22:33:27.0697 2012 p2pimsvc - ok
22:33:27.0728 2012 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
22:33:27.0744 2012 p2psvc - ok
22:33:27.0775 2012 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
22:33:27.0822 2012 Parport - ok
22:33:27.0869 2012 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:33:27.0900 2012 partmgr - ok
22:33:27.0947 2012 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
22:33:28.0009 2012 PcaSvc - ok
22:33:28.0040 2012 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
22:33:28.0087 2012 pci - ok
22:33:28.0103 2012 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
22:33:28.0134 2012 pciide - ok
22:33:28.0149 2012 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
22:33:28.0196 2012 pcmcia - ok
22:33:28.0196 2012 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
22:33:28.0227 2012 pcw - ok
22:33:28.0243 2012 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:33:28.0337 2012 PEAUTH - ok
22:33:28.0415 2012 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
22:33:28.0461 2012 PerfHost - ok
22:33:28.0539 2012 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
22:33:28.0695 2012 pla - ok
22:33:28.0727 2012 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:33:28.0805 2012 PlugPlay - ok
22:33:29.0054 2012 [ 63694C307273062A2167AE4CE80730EF ] PMBDeviceInfoProvider c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
22:33:29.0101 2012 PMBDeviceInfoProvider - ok
22:33:29.0132 2012 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
22:33:29.0179 2012 PNRPAutoReg - ok
22:33:29.0195 2012 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
22:33:29.0241 2012 PNRPsvc - ok
22:33:29.0273 2012 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:33:29.0382 2012 PolicyAgent - ok
22:33:29.0429 2012 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
22:33:29.0507 2012 Power - ok
22:33:29.0538 2012 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:33:29.0585 2012 PptpMiniport - ok
22:33:29.0600 2012 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
22:33:29.0616 2012 Processor - ok
22:33:29.0647 2012 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
22:33:29.0694 2012 ProfSvc - ok
22:33:29.0709 2012 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
22:33:29.0741 2012 ProtectedStorage - ok
22:33:29.0772 2012 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
22:33:29.0865 2012 Psched - ok
22:33:29.0943 2012 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
22:33:30.0006 2012 ql2300 - ok
22:33:30.0006 2012 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
22:33:30.0037 2012 ql40xx - ok
22:33:30.0068 2012 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
22:33:30.0115 2012 QWAVE - ok
22:33:30.0131 2012 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:33:30.0177 2012 QWAVEdrv - ok
22:33:30.0193 2012 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:33:30.0255 2012 RasAcd - ok
22:33:30.0287 2012 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
22:33:30.0333 2012 RasAgileVpn - ok
22:33:30.0365 2012 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
22:33:30.0411 2012 RasAuto - ok
22:33:30.0443 2012 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:33:30.0521 2012 Rasl2tp - ok
22:33:30.0567 2012 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
22:33:30.0599 2012 RasMan - ok
22:33:30.0630 2012 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:33:30.0692 2012 RasPppoe - ok
22:33:30.0708 2012 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:33:30.0755 2012 RasSstp - ok
22:33:30.0770 2012 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:33:30.0817 2012 rdbss - ok
22:33:30.0817 2012 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
22:33:30.0848 2012 rdpbus - ok
22:33:30.0864 2012 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:33:30.0895 2012 RDPCDD - ok
22:33:30.0895 2012 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:33:30.0942 2012 RDPENCDD - ok
22:33:30.0973 2012 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
22:33:31.0004 2012 RDPREFMP - ok
22:33:31.0020 2012 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:33:31.0082 2012 RDPWD - ok
22:33:31.0098 2012 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
22:33:31.0129 2012 rdyboost - ok
22:33:31.0160 2012 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
22:33:31.0223 2012 RemoteAccess - ok
22:33:31.0269 2012 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:33:31.0347 2012 RemoteRegistry - ok
22:33:31.0379 2012 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
22:33:31.0425 2012 RFCOMM - ok
22:33:31.0441 2012 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
22:33:31.0535 2012 RpcEptMapper - ok
22:33:31.0566 2012 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
22:33:31.0597 2012 RpcLocator - ok
22:33:31.0628 2012 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
22:33:31.0691 2012 RpcSs - ok
22:33:31.0722 2012 [ 546D7F426776090B90EF5F195B6AE662 ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys
22:33:31.0753 2012 RSPCIESTOR - ok
22:33:31.0769 2012 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:33:31.0831 2012 rspndr - ok
22:33:31.0878 2012 [ EA5532868BA76923D75BCB2A1448D810 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
22:33:31.0925 2012 RTL8167 - ok
22:33:31.0956 2012 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
22:33:31.0987 2012 SamSs - ok
22:33:32.0018 2012 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:33:32.0034 2012 sbp2port - ok
22:33:32.0065 2012 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:33:32.0127 2012 SCardSvr - ok
22:33:32.0143 2012 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
22:33:32.0190 2012 scfilter - ok
22:33:32.0237 2012 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
22:33:32.0283 2012 Schedule - ok
22:33:32.0315 2012 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
22:33:32.0346 2012 SCPolicySvc - ok
22:33:32.0377 2012 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
22:33:32.0439 2012 sdbus - ok
22:33:32.0471 2012 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:33:32.0533 2012 SDRSVC - ok
22:33:32.0549 2012 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:33:32.0627 2012 secdrv - ok
22:33:32.0642 2012 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
22:33:32.0689 2012 seclogon - ok
22:33:32.0705 2012 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
22:33:32.0751 2012 SENS - ok
22:33:32.0783 2012 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
22:33:32.0829 2012 SensrSvc - ok
22:33:32.0845 2012 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
22:33:32.0892 2012 Serenum - ok
22:33:32.0907 2012 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
22:33:32.0954 2012 Serial - ok
22:33:32.0985 2012 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
22:33:33.0017 2012 sermouse - ok
22:33:33.0063 2012 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
22:33:33.0126 2012 SessionEnv - ok
22:33:33.0157 2012 [ 286D3889E6AB5589646FF8A63CB928AE ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys
22:33:33.0204 2012 SFEP - ok
22:33:33.0219 2012 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
22:33:33.0266 2012 sffdisk - ok
22:33:33.0282 2012 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:33:33.0344 2012 sffp_mmc - ok
22:33:33.0344 2012 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
22:33:33.0407 2012 sffp_sd - ok
22:33:33.0407 2012 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
22:33:33.0453 2012 sfloppy - ok
22:33:33.0516 2012 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
22:33:33.0563 2012 Sftfs - ok
22:33:33.0641 2012 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
22:33:33.0672 2012 sftlist - ok
22:33:33.0719 2012 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
22:33:33.0765 2012 Sftplay - ok
22:33:33.0797 2012 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
22:33:33.0828 2012 Sftredir - ok
22:33:33.0859 2012 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
22:33:33.0890 2012 Sftvol - ok
22:33:33.0921 2012 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
22:33:33.0921 2012 sftvsa - ok
22:33:33.0968 2012 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:33:34.0031 2012 SharedAccess - ok
22:33:34.0046 2012 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:33:34.0124 2012 ShellHWDetection - ok
22:33:34.0140 2012 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
22:33:34.0155 2012 SiSRaid2 - ok
22:33:34.0171 2012 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
22:33:34.0187 2012 SiSRaid4 - ok
22:33:34.0343 2012 [ 0F97E7A47A52F4A36969F0FC319654C2 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:33:34.0389 2012 Skype C2C Service - ok
22:33:34.0467 2012 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
22:33:34.0499 2012 SkypeUpdate - ok
22:33:34.0545 2012 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:33:34.0639 2012 Smb - ok
22:33:34.0686 2012 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:33:34.0717 2012 SNMPTRAP - ok
22:33:34.0826 2012 [ DDF2EC98AF6FC70608A4F9CE4DB52758 ] SOHCImp C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
22:33:34.0857 2012 SOHCImp - ok
22:33:34.0873 2012 [ 5FA03F5EA6EFEF6D17B4A1A48C40A23C ] SOHDs C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
22:33:34.0889 2012 SOHDs - ok
22:33:34.0967 2012 [ 65E5659E9C2A0762D05657C0E22A7CA2 ] SpfService C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
22:33:35.0013 2012 SpfService - ok
22:33:35.0045 2012 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
22:33:35.0076 2012 spldr - ok
22:33:35.0123 2012 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
22:33:35.0201 2012 Spooler - ok
22:33:35.0310 2012 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
22:33:35.0435 2012 sppsvc - ok
22:33:35.0450 2012 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
22:33:35.0481 2012 sppuinotify - ok
22:33:35.0513 2012 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
22:33:35.0559 2012 srv - ok
22:33:35.0575 2012 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:33:35.0606 2012 srv2 - ok
22:33:35.0606 2012 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:33:35.0622 2012 srvnet - ok
22:33:35.0653 2012 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
22:33:35.0715 2012 ssadbus - ok
22:33:35.0747 2012 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
22:33:35.0793 2012 ssadmdfl - ok
22:33:35.0825 2012 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
22:33:35.0871 2012 ssadmdm - ok
22:33:35.0903 2012 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:33:35.0981 2012 SSDPSRV - ok
22:33:35.0996 2012 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:33:36.0059 2012 SstpSvc - ok
22:33:36.0105 2012 [ 79969ACAEEBEDA7DC3673656AB9918FD ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
22:33:36.0137 2012 Stereo Service - ok
22:33:36.0168 2012 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
22:33:36.0199 2012 stexstor - ok
22:33:36.0246 2012 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
22:33:36.0308 2012 stisvc - ok
22:33:36.0324 2012 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
22:33:36.0355 2012 swenum - ok
22:33:36.0402 2012 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
22:33:36.0480 2012 swprv - ok
22:33:36.0542 2012 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
22:33:36.0605 2012 SysMain - ok
22:33:36.0636 2012 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:33:36.0683 2012 TabletInputService - ok
22:33:36.0698 2012 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
22:33:36.0761 2012 TapiSrv - ok
22:33:36.0776 2012 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
22:33:36.0807 2012 TBS - ok
22:33:36.0901 2012 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:33:36.0995 2012 Tcpip - ok
22:33:37.0026 2012 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
22:33:37.0073 2012 TCPIP6 - ok
22:33:37.0088 2012 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:33:37.0104 2012 tcpipreg - ok
22:33:37.0135 2012 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:33:37.0182 2012 TDPIPE - ok
22:33:37.0229 2012 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:33:37.0260 2012 TDTCP - ok
22:33:37.0307 2012 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:33:37.0400 2012 tdx - ok
22:33:37.0400 2012 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
22:33:37.0416 2012 TermDD - ok
22:33:37.0463 2012 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
22:33:37.0556 2012 TermService - ok
22:33:37.0587 2012 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
22:33:37.0603 2012 Themes - ok
22:33:37.0634 2012 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
22:33:37.0665 2012 THREADORDER - ok
22:33:37.0712 2012 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
22:33:37.0806 2012 TrkWks - ok
22:33:37.0838 2012 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:33:37.0869 2012 TrustedInstaller - ok
22:33:37.0900 2012 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:33:37.0963 2012 tssecsrv - ok
22:33:37.0978 2012 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
22:33:38.0010 2012 TsUsbFlt - ok
22:33:38.0025 2012 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
22:33:38.0056 2012 TsUsbGD - ok
22:33:38.0088 2012 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:33:38.0150 2012 tunnel - ok
22:33:38.0150 2012 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
22:33:38.0166 2012 uagp35 - ok
22:33:38.0212 2012 [ 1FE69F3C1CA1CF4B7EC7E2E9090FFFDC ] uCamMonitor C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
22:33:38.0244 2012 uCamMonitor - ok
22:33:38.0259 2012 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:33:38.0353 2012 udfs - ok
22:33:38.0368 2012 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:33:38.0415 2012 UI0Detect - ok
22:33:38.0431 2012 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:33:38.0446 2012 uliagpkx - ok
22:33:38.0462 2012 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
22:33:38.0509 2012 umbus - ok
22:33:38.0540 2012 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
22:33:38.0571 2012 UmPass - ok
22:33:38.0727 2012 [ 7A78ED1088890114DFDE2C4AB038D6B6 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:33:38.0805 2012 UNS - ok
22:33:38.0836 2012 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
22:33:38.0930 2012 upnphost - ok
22:33:38.0961 2012 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:33:38.0992 2012 usbccgp - ok
22:33:39.0024 2012 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:33:39.0055 2012 usbcir - ok
22:33:39.0055 2012 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:33:39.0102 2012 usbehci - ok
22:33:39.0148 2012 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:33:39.0211 2012 usbhub - ok
22:33:39.0226 2012 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
22:33:39.0273 2012 usbohci - ok
22:33:39.0320 2012 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:33:39.0367 2012 usbprint - ok
22:33:39.0429 2012 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
22:33:39.0476 2012 usbscan - ok
22:33:39.0507 2012 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:33:39.0554 2012 USBSTOR - ok
22:33:39.0585 2012 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
22:33:39.0616 2012 usbuhci - ok
22:33:39.0632 2012 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
22:33:39.0679 2012 usbvideo - ok
22:33:39.0710 2012 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
22:33:39.0772 2012 UxSms - ok
22:33:39.0819 2012 [ DCB1F83AD167D16D263CE57C94E9EEDF ] VAIO Event Service C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
22:33:39.0835 2012 VAIO Event Service - ok
22:33:39.0850 2012 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
22:33:39.0882 2012 VaultSvc - ok
22:33:39.0991 2012 [ D00058C1FFF3F3DE990444A5734E9639 ] VCFw C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
22:33:40.0053 2012 VCFw - ok
22:33:40.0178 2012 [ F19275655B42086C884ABCDAE2C659AE ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
22:33:40.0240 2012 VcmIAlzMgr - ok
22:33:40.0272 2012 [ 2F06D134554BA84FE253DBC481DCFE6D ] VcmINSMgr C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
22:33:40.0303 2012 VcmINSMgr - ok
22:33:40.0350 2012 [ 32A3735F6874B7783C6209ED5CA36D9D ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
22:33:40.0381 2012 VcmXmlIfHelper - ok
22:33:40.0474 2012 [ D347D3ABE070AA09C22FC37121555D52 ] VCService C:\Program Files\Sony\VAIO Care\VCService.exe
22:33:40.0490 2012 VCService - ok
22:33:40.0521 2012 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
22:33:40.0552 2012 vdrvroot - ok
22:33:40.0584 2012 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
22:33:40.0677 2012 vds - ok
22:33:40.0708 2012 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:33:40.0724 2012 vga - ok
22:33:40.0786 2012 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
22:33:40.0880 2012 VgaSave - ok
22:33:40.0880 2012 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
22:33:40.0896 2012 vhdmp - ok
22:33:40.0896 2012 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
22:33:40.0911 2012 viaide - ok
22:33:40.0911 2012 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:33:40.0927 2012 volmgr - ok
22:33:40.0942 2012 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:33:40.0958 2012 volmgrx - ok
22:33:40.0974 2012 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:33:40.0989 2012 volsnap - ok
22:33:41.0005 2012 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
22:33:41.0020 2012 vsmraid - ok
22:33:41.0083 2012 [ 0ED394BFBA3EB4740F063E0BA5EC7104 ] VSNService C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
22:33:41.0145 2012 VSNService - ok
22:33:41.0208 2012 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
22:33:41.0332 2012 VSS - ok
22:33:41.0442 2012 [ D2D646D4D686C6996BA1FF96E11BE570 ] VUAgent C:\Program Files\Sony\VAIO Update\VUAgent.exe
22:33:41.0488 2012 VUAgent - ok
22:33:41.0504 2012 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
22:33:41.0551 2012 vwifibus - ok
22:33:41.0582 2012 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
22:33:41.0613 2012 vwififlt - ok
22:33:41.0644 2012 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
22:33:41.0691 2012 W32Time - ok
22:33:41.0707 2012 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
22:33:41.0738 2012 WacomPen - ok
22:33:41.0754 2012 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
22:33:41.0832 2012 WANARP - ok
22:33:41.0847 2012 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:33:41.0910 2012 Wanarpv6 - ok
22:33:41.0972 2012 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
22:33:42.0034 2012 wbengine - ok
22:33:42.0050 2012 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
22:33:42.0097 2012 WbioSrvc - ok
22:33:42.0097 2012 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:33:42.0144 2012 wcncsvc - ok
22:33:42.0175 2012 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:33:42.0222 2012 WcsPlugInService - ok
22:33:42.0253 2012 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
22:33:42.0300 2012 Wd - ok
22:33:42.0331 2012 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:33:42.0424 2012 Wdf01000 - ok
22:33:42.0424 2012 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:33:42.0518 2012 WdiServiceHost - ok
22:33:42.0518 2012 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:33:42.0565 2012 WdiSystemHost - ok
22:33:42.0596 2012 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
22:33:42.0627 2012 WebClient - ok
22:33:42.0643 2012 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:33:42.0705 2012 Wecsvc - ok
22:33:42.0721 2012 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:33:42.0752 2012 wercplsupport - ok
22:33:42.0783 2012 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
22:33:42.0814 2012 WerSvc - ok
22:33:42.0830 2012 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
22:33:42.0861 2012 WfpLwf - ok
22:33:42.0877 2012 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
22:33:42.0892 2012 WIMMount - ok
22:33:42.0908 2012 WinDefend - ok
22:33:42.0970 2012 WinHttpAutoProxySvc - ok
22:33:43.0017 2012 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:33:43.0095 2012 Winmgmt - ok
22:33:43.0173 2012 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
22:33:43.0282 2012 WinRM - ok
22:33:43.0329 2012 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
22:33:43.0376 2012 WinUsb - ok
22:33:43.0423 2012 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
22:33:43.0470 2012 Wlansvc - ok
22:33:43.0516 2012 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
22:33:43.0516 2012 wlcrasvc - ok
22:33:43.0610 2012 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:33:43.0672 2012 wlidsvc - ok
22:33:43.0688 2012 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
22:33:43.0719 2012 WmiAcpi - ok
22:33:43.0735 2012 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:33:43.0782 2012 wmiApSrv - ok
22:33:43.0813 2012 WMPNetworkSvc - ok
22:33:43.0860 2012 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:33:43.0906 2012 WPCSvc - ok
22:33:43.0922 2012 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:33:43.0953 2012 WPDBusEnum - ok
22:33:43.0984 2012 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:33:44.0078 2012 ws2ifsl - ok
22:33:44.0094 2012 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
22:33:44.0125 2012 wscsvc - ok
22:33:44.0172 2012 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
22:33:44.0218 2012 WSDPrintDevice - ok
22:33:44.0250 2012 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys
22:33:44.0281 2012 WSDScan - ok
22:33:44.0296 2012 WSearch - ok
22:33:44.0374 2012 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
22:33:44.0452 2012 wuauserv - ok
22:33:44.0484 2012 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:33:44.0530 2012 WudfPf - ok
22:33:44.0562 2012 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:33:44.0640 2012 WUDFRd - ok
22:33:44.0686 2012 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:33:44.0749 2012 wudfsvc - ok
22:33:44.0796 2012 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
22:33:44.0858 2012 WwanSvc - ok
22:33:44.0889 2012 ================ Scan global ===============================
22:33:44.0920 2012 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
22:33:44.0952 2012 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
22:33:44.0967 2012 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
22:33:44.0998 2012 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
22:33:45.0030 2012 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
22:33:45.0045 2012 [Global] - ok
22:33:45.0045 2012 ================ Scan MBR ==================================
22:33:45.0061 2012 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:33:46.0059 2012 \Device\Harddisk0\DR0 - ok
22:33:46.0059 2012 ================ Scan VBR ==================================
22:33:46.0090 2012 [ B66EC185B9DE52245CC45448CF4642D5 ] \Device\Harddisk0\DR0\Partition1
22:33:46.0090 2012 \Device\Harddisk0\DR0\Partition1 - ok
22:33:46.0106 2012 [ 25BFE8FE0C20C7A147DF3812DF9289A6 ] \Device\Harddisk0\DR0\Partition2
22:33:46.0122 2012 \Device\Harddisk0\DR0\Partition2 - ok
22:33:46.0122 2012 ============================================================
22:33:46.0122 2012 Scan finished
22:33:46.0122 2012 ============================================================
22:33:46.0137 2384 Detected object count: 4
22:33:46.0137 2384 Actual detected object count: 4
22:37:07.0445 2384 Atheros Bt&Wlan Coex Agent ( UnsignedFile.Multi.Generic ) - skipped by user
22:37:07.0445 2384 Atheros Bt&Wlan Coex Agent ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:37:07.0445 2384 AtherosSvc ( UnsignedFile.Multi.Generic ) - skipped by user
22:37:07.0445 2384 AtherosSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:37:07.0445 2384 EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - skipped by user
22:37:07.0445 2384 EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:37:07.0445 2384 IconMan_R ( UnsignedFile.Multi.Generic ) - skipped by user
22:37:07.0445 2384 IconMan_R ( UnsignedFile.Multi.Generic ) - User select action: Skip

Alt 18.06.2013, 22:17   #10
markusg
/// Malware-holic
 
wssetup exe - Standard

wssetup exe



Hi,
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 19.06.2013, 19:04   #11
xibor
 
wssetup exe - Standard

wssetup exe



Combofix Logfile:
Code:
ATTFilter
ComboFix 13-06-15.01 - chris 19.06.2013  19:41:35.2.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.4078.2400 [GMT 2:00]
ausgeführt von:: c:\users\chris\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\chris\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll
.
---- Vorheriger Suchlauf -------
.
c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarApp.dll
c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarEng.dll
c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarsrv.exe
c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\inCRedibartlbr.dll
c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\uninstall.exe
c:\users\chris\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll
c:\users\chris\AppData\Roaming\Microsoft\Windows\Recent\Search the Web.url
c:\windows\SysWow64\muzapp.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-05-19 bis 2013-06-19  ))))))))))))))))))))))))))))))
.
.
2013-06-19 17:48 . 2013-06-19 17:48	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-06-18 16:39 . 2013-06-12 03:08	9552976	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{E00E2DFE-0858-4E2A-A4AE-8037B5559E8D}\mpengine.dll
2013-06-16 20:39 . 2013-06-16 20:46	--------	d-----w-	c:\programdata\HitmanPro
2013-06-16 20:26 . 2013-06-16 20:26	--------	d-----w-	c:\program files\CCleaner
2013-06-16 19:23 . 2013-06-16 19:23	--------	d-----w-	c:\users\chris\AppData\Roaming\Malwarebytes
2013-06-16 19:23 . 2013-06-16 19:23	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2013-06-16 19:23 . 2013-06-16 19:23	--------	d-----w-	c:\programdata\Malwarebytes
2013-06-16 19:23 . 2013-04-04 12:50	25928	----a-w-	c:\windows\system32\drivers\mbam.sys
2013-06-16 19:22 . 2013-06-16 19:22	--------	d-----w-	c:\users\chris\AppData\Local\Programs
2013-06-16 17:11 . 2013-06-16 17:11	--------	d-----w-	c:\program files (x86)\Common Files\Skype
2013-06-14 23:24 . 2013-06-14 23:24	--------	d-----w-	c:\program files\Enigma Software Group
2013-06-14 23:23 . 2013-06-16 19:09	--------	d-----w-	c:\windows\BCD5545077AC4347B24F654B1189F8D4.TMP
2013-06-14 23:23 . 2013-06-14 23:23	--------	d-----w-	c:\program files (x86)\Common Files\Wise Installation Wizard
2013-06-13 09:09 . 2013-05-08 06:39	1910632	----a-w-	c:\windows\system32\drivers\tcpip.sys
2013-06-13 09:09 . 2013-04-26 05:51	751104	----a-w-	c:\windows\system32\win32spl.dll
2013-06-13 09:09 . 2013-04-26 04:55	492544	----a-w-	c:\windows\SysWow64\win32spl.dll
2013-06-13 09:09 . 2013-05-10 05:49	30720	----a-w-	c:\windows\system32\cryptdlg.dll
2013-06-13 09:09 . 2013-05-10 03:20	24576	----a-w-	c:\windows\SysWow64\cryptdlg.dll
2013-06-13 09:09 . 2013-04-17 07:02	1230336	----a-w-	c:\windows\SysWow64\WindowsCodecs.dll
2013-06-13 09:09 . 2013-04-17 06:24	1424384	----a-w-	c:\windows\system32\WindowsCodecs.dll
2013-06-13 09:08 . 2013-05-13 05:51	184320	----a-w-	c:\windows\system32\cryptsvc.dll
2013-06-13 09:08 . 2013-05-13 05:51	1464320	----a-w-	c:\windows\system32\crypt32.dll
2013-06-13 09:08 . 2013-05-13 05:51	139776	----a-w-	c:\windows\system32\cryptnet.dll
2013-06-13 09:08 . 2013-05-13 05:50	52224	----a-w-	c:\windows\system32\certenc.dll
2013-06-13 09:08 . 2013-05-13 04:45	140288	----a-w-	c:\windows\SysWow64\cryptsvc.dll
2013-06-13 09:08 . 2013-05-13 04:45	1160192	----a-w-	c:\windows\SysWow64\crypt32.dll
2013-06-13 09:08 . 2013-05-13 04:45	103936	----a-w-	c:\windows\SysWow64\cryptnet.dll
2013-06-13 09:08 . 2013-05-13 03:43	1192448	----a-w-	c:\windows\system32\certutil.exe
2013-06-13 09:08 . 2013-05-13 03:08	903168	----a-w-	c:\windows\SysWow64\certutil.exe
2013-06-13 09:08 . 2013-05-13 03:08	43008	----a-w-	c:\windows\SysWow64\certenc.dll
2013-06-13 09:08 . 2013-04-25 23:30	1505280	----a-w-	c:\windows\SysWow64\d3d11.dll
2013-06-13 09:08 . 2013-03-31 22:52	1887232	----a-w-	c:\windows\system32\d3d11.dll
2013-05-31 19:36 . 2013-05-31 19:36	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 10:16 . 2013-05-30 12:14	--------	d-----w-	c:\programdata\tmp
2013-05-30 10:16 . 2013-05-30 11:17	--------	d-----w-	c:\programdata\hps
2013-05-30 10:11 . 2013-05-30 10:11	--------	d-----w-	c:\program files (x86)\Mueller Foto
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-13 21:26 . 2012-07-05 19:05	75825640	----a-w-	c:\windows\system32\MRT.exe
2013-06-12 18:52 . 2012-07-15 18:16	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 18:52 . 2012-07-15 18:16	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-21 13:31 . 2012-12-21 19:25	1447728	----a-w-	c:\windows\system32\dmwu.exe
2013-05-21 13:30 . 2012-12-21 19:25	33792	----a-w-	c:\windows\system32\ImHttpComm.dll
2013-05-10 08:12 . 2010-06-24 09:33	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-06 10:22 . 2013-05-06 10:22	83160	----a-w-	c:\windows\system32\drivers\avnetflt.sys
2013-05-02 00:06 . 2010-11-21 03:27	278800	------w-	c:\windows\system32\MpSigStub.exe
2013-04-13 05:49 . 2013-05-16 09:02	135168	----a-w-	c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-16 09:02	350208	----a-w-	c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-16 09:02	308736	----a-w-	c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-16 09:02	111104	----a-w-	c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-16 09:02	474624	----a-w-	c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-16 09:02	2176512	----a-w-	c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 18:25	1656680	----a-w-	c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-16 09:03	265064	----a-w-	c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-16 09:03	983400	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-16 09:02	3153920	----a-w-	c:\windows\system32\win32k.sys
2013-03-31 17:03 . 2013-03-31 17:03	28600	----a-w-	c:\windows\system32\drivers\avkmgr.sys
2013-03-31 17:03 . 2013-03-31 17:03	130016	----a-w-	c:\windows\system32\drivers\avipbb.sys
2013-03-31 17:03 . 2013-03-31 17:03	100712	----a-w-	c:\windows\system32\drivers\avgntflt.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2011-03-17 909200]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2011-03-17 3373968]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-03-17 19872]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE" [2012-02-29 283232]
"EPLTarget\P0000000000000001"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIIME.EXE" [2012-02-29 283232]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-26 648032]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-05-06 345312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x]
R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x]
R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x]
R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x]
R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe;c:\program files\Sony\VAIO Update\VUAgent.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-05 18:33	1165776	----a-w-	c:\program files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 18:52]
.
2013-06-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-21 20:10]
.
2013-06-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-21 20:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-04-29 790688]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-04-29 657568]
"lxczbmgr.exe"="c:\program files (x86)\Lexmark 1200 Series\lxczbmgr.exe" [2009-04-27 74408]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: Free YouTube to MP3 Converter - c:\users\chris\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
AddRemove-Lexmark 1200 Series - c:\program files (x86) (x86)\Lexmark 1200 Series\Install\x64\Uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgr.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\SysWOW64\DllHost.exe
c:\windows\SysWOW64\DllHost.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files\Sony\VAIO Care\listener.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-06-19  19:54:40 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-06-19 17:54
.
Vor Suchlauf: 18 Verzeichnis(se), 522.266.624.000 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 521.742.581.760 Bytes frei
.
- - End Of File - - 2B106FD8948957031CBF924FC1190636
         
--- --- ---
D41D8CD98F00B204E9800998ECF8427E

Alt 19.06.2013, 19:33   #12
markusg
/// Malware-holic
 
wssetup exe - Standard

wssetup exe



poste alle bisherigen Malwarebytes Logs mit funden
http://www.trojaner-board.de/125889-...en-posten.html
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 19.06.2013, 19:48   #13
xibor
 
wssetup exe - Standard

wssetup exe



Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.06.16.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16614
chris :: CHRIS-VAIO [Administrator]

Schutz: Aktiviert

16.06.2013 21:25:13
mbam-log-2013-06-16 (21-25-13).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|Q:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 356147
Laufzeit: 57 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 21:24:19 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh
2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection
2013/06/16 21:24:29 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully
2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully
2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 21:24:33 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 21:30:39 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily
2013/06/16 21:30:40 +0200 CHRIS-VAIO chris MESSAGE Database already up-to-date
2013/06/16 22:37:01 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 22:37:08 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting protection
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Protection started successfully
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting IP protection
2013/06/16 23:12:47 +0200 CHRIS-VAIO (null) MESSAGE IP Protection started successfully
2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50005, Process: opera.exe)
2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50006, Process: opera.exe)
2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50038, Process: opera.exe)
2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50039, Process: opera.exe)
2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe)
2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50166, Process: opera.exe)
2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51400, Process: opera.exe)
2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51401, Process: opera.exe)
2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51419, Process: opera.exe)
2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51420, Process: opera.exe)

2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 21:24:19 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh
2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection
2013/06/16 21:24:29 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully
2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully
2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 21:24:33 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 21:30:39 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily
2013/06/16 21:30:40 +0200 CHRIS-VAIO chris MESSAGE Database already up-to-date
2013/06/16 22:37:01 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 22:37:08 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting protection
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Protection started successfully
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting IP protection
2013/06/16 23:12:47 +0200 CHRIS-VAIO (null) MESSAGE IP Protection started successfully
2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50005, Process: opera.exe)
2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50006, Process: opera.exe)
2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50038, Process: opera.exe)
2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50039, Process: opera.exe)
2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe)
2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50166, Process: opera.exe)
2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51400, Process: opera.exe)
2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51401, Process: opera.exe)
2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51419, Process: opera.exe)
2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51420, Process: opera.exe)

2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/16 21:24:03 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 21:24:19 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh
2013/06/16 21:24:26 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection
2013/06/16 21:24:29 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully
2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully
2013/06/16 21:24:31 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 21:24:33 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 21:30:39 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily
2013/06/16 21:30:40 +0200 CHRIS-VAIO chris MESSAGE Database already up-to-date
2013/06/16 22:37:01 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/16 22:37:05 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/16 22:37:08 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting protection
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Protection started successfully
2013/06/16 23:12:44 +0200 CHRIS-VAIO (null) MESSAGE Starting IP protection
2013/06/16 23:12:47 +0200 CHRIS-VAIO (null) MESSAGE IP Protection started successfully
2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50005, Process: opera.exe)
2013/06/16 23:25:00 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50006, Process: opera.exe)
2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50038, Process: opera.exe)
2013/06/16 23:25:08 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50039, Process: opera.exe)
2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe)
2013/06/16 23:26:05 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50166, Process: opera.exe)
2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51400, Process: opera.exe)
2013/06/16 23:41:12 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51401, Process: opera.exe)
2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51419, Process: opera.exe)
2013/06/16 23:41:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51420, Process: opera.exe)

2013/06/19 06:38:57 +0200 CHRIS-VAIO chris MESSAGE Executing scheduled update: Daily
2013/06/19 06:38:57 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/19 06:38:58 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/19 06:38:58 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/19 06:39:00 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE Starting database refresh
2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE Stopping IP protection
2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE Scheduled update executed successfully: database updated from version v2013.06.17.01 to version v2013.06.18.09
2013/06/19 06:39:38 +0200 CHRIS-VAIO chris MESSAGE IP Protection stopped successfully
2013/06/19 06:39:41 +0200 CHRIS-VAIO chris MESSAGE Database refreshed successfully
2013/06/19 06:39:41 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/19 06:39:43 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49405, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49406, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49407, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49408, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49409, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49410, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49414, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49415, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49416, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49417, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49418, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49419, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49425, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49426, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49427, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49428, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49429, Process: opera.exe)
2013/06/19 06:45:04 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49430, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49437, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49438, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49439, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49440, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49441, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49442, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49445, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49446, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49447, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49448, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49449, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49450, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49451, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49462, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49465, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49466, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49467, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49468, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49470, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49471, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49472, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49473, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49474, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49475, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49481, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49482, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49483, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49484, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49485, Process: opera.exe)
2013/06/19 06:45:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49486, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49515, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49516, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49517, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49518, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49519, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49520, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49563, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49564, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49565, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49566, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49567, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49568, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49569, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49570, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49571, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49572, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49573, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49574, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49575, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49576, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49577, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49578, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49579, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49580, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49581, Process: opera.exe)
2013/06/19 06:46:17 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49582, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49604, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49605, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49606, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49607, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49608, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49609, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49621, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49622, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49623, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49624, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49625, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49626, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49629, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49630, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49631, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49632, Process: opera.exe)
2013/06/19 06:46:49 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49633, Process: opera.exe)
2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50716, Process: opera.exe)
2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50717, Process: opera.exe)
2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50743, Process: opera.exe)
2013/06/19 06:54:40 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50744, Process: opera.exe)
2013/06/19 06:56:50 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51029, Process: opera.exe)
2013/06/19 06:56:50 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51032, Process: opera.exe)
2013/06/19 06:58:44 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51272, Process: opera.exe)
2013/06/19 06:58:44 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 51273, Process: opera.exe)
2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51342, Process: opera.exe)
2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51343, Process: opera.exe)
2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51344, Process: opera.exe)
2013/06/19 06:59:32 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 51345, Process: opera.exe)
2013/06/19 13:28:38 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/19 13:28:38 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/19 13:28:38 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/19 13:28:41 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/19 19:18:42 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/19 19:18:42 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/19 19:18:42 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/19 19:18:45 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49189, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49190, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49191, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49192, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49193, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49194, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49260, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49261, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49262, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49263, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49264, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49265, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49267, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49268, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49269, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49270, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49271, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49272, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49277, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49278, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49279, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49280, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49281, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49282, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49283, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49284, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49285, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49286, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49287, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49288, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49289, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49290, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49291, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49292, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49293, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49294, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49295, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49296, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49297, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49298, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49299, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49300, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49301, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49302, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49303, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49304, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49308, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49309, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49310, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49311, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49316, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49317, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49318, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49319, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49320, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49321, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49328, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49329, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49330, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49331, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49332, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49333, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49334, Process: opera.exe)
2013/06/19 19:20:10 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49335, Process: opera.exe)
2013/06/19 19:20:11 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49336, Process: opera.exe)
2013/06/19 19:20:11 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49337, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49345, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49346, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49347, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49348, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49349, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49350, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49356, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49357, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49358, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49359, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49360, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49361, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49384, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49385, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49386, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49387, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49388, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49389, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49390, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49391, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49392, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49393, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49394, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49395, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49396, Process: opera.exe)
2013/06/19 19:20:35 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 49397, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50080, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50081, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50082, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50083, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50084, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50085, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50088, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50089, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50090, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50091, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50092, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50093, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50098, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50099, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50100, Process: opera.exe)
2013/06/19 19:27:20 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50101, Process: opera.exe)
2013/06/19 19:27:53 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50160, Process: opera.exe)
2013/06/19 19:27:53 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50165, Process: opera.exe)
2013/06/19 19:28:01 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50190, Process: opera.exe)
2013/06/19 19:28:01 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.1.5 (Type: outgoing, Port: 50191, Process: opera.exe)
2013/06/19 19:32:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50466, Process: opera.exe)
2013/06/19 19:32:36 +0200 CHRIS-VAIO chris IP-BLOCK 88.208.33.4 (Type: outgoing, Port: 50467, Process: opera.exe)
2013/06/19 19:49:19 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/19 19:49:20 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/19 19:49:20 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/19 19:49:22 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully
2013/06/19 19:57:31 +0200 CHRIS-VAIO chris MESSAGE Starting protection
2013/06/19 19:57:32 +0200 CHRIS-VAIO chris MESSAGE Protection started successfully
2013/06/19 19:57:32 +0200 CHRIS-VAIO chris MESSAGE Starting IP protection
2013/06/19 19:57:34 +0200 CHRIS-VAIO chris MESSAGE IP Protection started successfully

Alt 21.06.2013, 10:02   #14
schrauber
/// the machine
/// TB-Ausbilder
 

wssetup exe - Standard

wssetup exe



Hi,

Markus ist im Urlaub. Gibt es noch irgendwelche Probleme mit dem System?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 21.06.2013, 17:49   #15
xibor
 
wssetup exe - Standard

wssetup exe



Hi, soweit ist eigentlich alles in ordnung,soweit ich das beurteilen kann

Antwort

Themen zu wssetup exe
exe, fester, gefahren, rechner, tagen, zulassen, öffnet




Ähnliche Themen: wssetup exe


  1. WSSETUP.EXE eingefangen
    Log-Analyse und Auswertung - 22.09.2014 (8)
  2. Problem durch wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 30.09.2013 (8)
  3. wssetup.exe eingefangen
    Log-Analyse und Auswertung - 22.07.2013 (22)
  4. wssetup.exe von Perion Network Ltd.
    Log-Analyse und Auswertung - 03.07.2013 (12)
  5. wssetup.exe eingefangen
    Plagegeister aller Art und deren Bekämpfung - 27.06.2013 (11)
  6. wssetup
    Plagegeister aller Art und deren Bekämpfung - 25.06.2013 (7)
  7. wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 24.06.2013 (15)
  8. wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 23.06.2013 (18)
  9. wssetup.exe will installiert werden
    Plagegeister aller Art und deren Bekämpfung - 22.06.2013 (7)
  10. wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 19.06.2013 (8)
  11. WSsetup.exe Problem
    Log-Analyse und Auswertung - 18.06.2013 (8)
  12. Problem mit wssetup.exe !
    Plagegeister aller Art und deren Bekämpfung - 18.06.2013 (12)
  13. wssetup.exe - Virus ja/ nein?
    Plagegeister aller Art und deren Bekämpfung - 16.06.2013 (29)
  14. wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 16.06.2013 (7)
  15. wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 14.06.2013 (13)
  16. wssetup.exe
    Log-Analyse und Auswertung - 11.06.2013 (3)
  17. wssetup.exe
    Plagegeister aller Art und deren Bekämpfung - 10.06.2013 (7)

Zum Thema wssetup exe - seit ein paar tagen öffnet sich immer nach dem ich den rechner rauf gefahren habe ein fester ob ich wssetup exe zulassen möchte oder nich!!!kann mir jemand helfen - wssetup exe...
Archiv
Du betrachtest: wssetup exe auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.