|
Plagegeister aller Art und deren Bekämpfung: Trojan.BitcoinMiner befall u. a. von svchost.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.11.2013, 13:45 | #16 |
| Trojan.BitcoinMiner befall u. a. von svchost.exe mbar hat nichts gefunden (juhu!) Das heißt die maleware ist entfernt oder? Das wäre ja super. Ich danke dir schon mal ganz herzlich! Kann man sich iwie erkenntlich zeigen? Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.11.06.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Carl :: CARL-PC [administrator] 06.11.2013 13:33:24 mbar-log-2013-11-06 (13-33-24).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged. Objects scanned: 273494 Time elapsed: 4 minute(s), 46 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
06.11.2013, 15:44 | #17 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exe Adware/Junkware/Toolbars entfernen
__________________1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
09.11.2013, 15:28 | #18 | ||
| Trojan.BitcoinMiner befall u. a. von svchost.exe Anscheinend ist die Malware doch noch nicht gelöscht denn ich kriege nun doch weiterhin
__________________Meldungen das meine svchost mit Malware infiziert ist und in Quarantäne gestellt wurde (wird von Malwarebytes Anti-Malware beim Systemstart per Pop-up aus der Taskleiste angezeigt). Ein Screenshot aus dem Quarantäne-Verzeichnis findest du im Anhang als Bilddatei. (Erstellt nachdem ich alle im folgenden aufgeführten Aktionen ausgeführt habe) Logdatein zu Schritt 1-3: Adwcleaner Code:
ATTFilter # AdwCleaner v3.011 - Bericht erstellt am 09/11/2013 um 14:38:43 # Updated 03/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Carl - CARL-PC # Gestartet von : C:\Users\Carl\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\boost_interprocess ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hamster-free-video-converter_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_hamster-free-video-converter_RASMANCS Schlüssel Gelöscht : HKLM\Software\InstallIQ ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v23.0.1 (de) [ Datei : C:\Users\Carl\AppData\Roaming\Mozilla\Firefox\Profiles\t8ainy9y.default\prefs.js ] -\\ Google Chrome v30.0.1599.101 [ Datei : C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1586 octets] - [09/11/2013 14:37:00] AdwCleaner[S0].txt - [1511 octets] - [09/11/2013 14:38:43] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1571 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by Carl on 09.11.2013 at 14:44:34,40 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3856524493-717638516-2450426649-1000\Software\sweetim ~~~ Files ~~~ Folders Failed to delete: [Folder] "C:\ProgramData\boost_interprocess" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 09.11.2013 at 14:49:32,01 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013 Ran by Carl (administrator) on CARL-PC on 09-11-2013 14:51:55 Running from C:\Users\Carl\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Arainia Solutions) D:\Programme\Gizmo\gservice.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Chicony) C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Spotify Ltd) C:\Users\Carl\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Logitech Inc.) D:\Logitech\SetPoint II\SetPointII.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe (Farbar) C:\Users\Carl\Downloads\FRST64 (1).exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2776360 2011-12-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [CECAPLF] - C:\Program Files (x86)\ChiconyCam\CECAPLF.exe [121456 2011-07-06] (Chicony) HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4123 2012-05-30] () HKLM\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [418240 2012-05-09] (Autodesk, Inc.) HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.Exe [134160 2007-07-17] (Logitech, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [33120 2010-08-20] (Alcohol Soft Development Team) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Carl\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-10-13] (Spotify Ltd) HKCU\...\Run: [GizmoDriveDelegate] - D:\Programme\Gizmo\gizmo.exe [223640 2012-10-27] (Arainia Solutions) HKCU\...\Policies\Explorer: [] HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-06-11] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\Updreg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-13] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [PowerDVD12DMREngine] - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe [506480 2012-12-28] (CyberLink) HKLM-x32\...\Run: [PowerDVD12Agent] - C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe [375168 2012-12-28] (CyberLink Corp.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\UpdatusUser\...\Run: [AdobeBridge] - [x] HKU\UpdatusUser\...\Run: [GizmoDriveDelegate] - D:\Programme\Gizmo\gizmo.exe [223640 2012-10-27] (Arainia Solutions) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-02] (NVIDIA Corporation) AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll [202600 2012-10-02] (NVIDIA Corporation) Startup: C:\Users\Carl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.6.lnk ShortcutTarget: Überwachungstool für die Intel® Turbo-Boost-Technik 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x875AB9ECA4B3CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: Hosts file not detected in the default directory Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Carl\AppData\Roaming\Mozilla\Firefox\Profiles\t8ainy9y.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Carl\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: client - C:\Users\Carl\AppData\Roaming\Mozilla\Firefox\Profiles\t8ainy9y.default\Extensions\client@anonymox.net.xpi FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HomePage: hxxp://www.faz.net/ CHR RestoreOnStartup: "hxxp://www.faz.net/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\plugin/npUrlAdvisor.dll (Kaspersky Lab ZAO) CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\plugin/content_blocker_npapi.dll (Kaspersky Lab ZAO) CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\plugin/npABPlugin.dll (Kaspersky Lab ZAO) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (YouTube) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Adblock Plus) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0 CHR Extension: (Google Search) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Kaspersky URL Advisor) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0 CHR Extension: (HTTPS Everywhere) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp\2013.10.16_0 CHR Extension: (Jon Klassen) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmgjhcokclngghkncjakaigpjhfhpoek\2_0 CHR Extension: (Safe Money) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0 CHR Extension: (Content Blocker) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0 CHR Extension: (Virtual Keyboard) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0 CHR Extension: (Disconnect) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo\5.10.0_0 CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe\1.0.8_0 CHR Extension: (Der Schn\u00E4ppchenfuchs Gutscheinfinder) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchofofdodfaibhigglfagnankbpglol\1.1_0 CHR Extension: (CnC TA Script Collection) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmhpmdclklpgfcpoiomjofgfagenmgeo\1.2.8.49_0 CHR Extension: (Google Wallet) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR Extension: (Anti-Banner) - C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0 CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx ==================== Services (Whitelisted) ================= R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-13] (Kaspersky Lab ZAO) R2 CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [91248 2012-12-28] (CyberLink Corp.) R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [78960 2012-12-28] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [296048 2012-12-28] (CyberLink) R2 Gizmo Central; D:\Programme\Gizmo\gservice.exe [34728 2012-10-27] (Arainia Solutions) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-16] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-16] (Intel Corporation) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-08] () R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2012-05-22] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-10-15] () R1 GizmoDrv; C:\Windows\System32\Drivers\GizmoDrv.sys [34704 2012-10-27] (Arainia Solutions LLC) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-13] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-13] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-13] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-13] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-24] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-10-15] () S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-09-10] (Cyberlink Corp.) S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2012-12-23] () S3 usbrndis6; C:\Windows\system32\drivers\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) R2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [130320 2012-12-28] (CyberLink Corp.) U3 a9js9f7j; C:\Windows\System32\Drivers\a9js9f7j.sys [0 ] (Intel Corporation) S3 cpuz130; \??\C:\Users\Carl\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-04-24] (Kaspersky Lab ZAO) S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-09 14:51 - 2013-11-09 14:51 - 01957098 _____ (Farbar) C:\Users\Carl\Downloads\FRST64 (1).exe 2013-11-09 14:49 - 2013-11-09 14:49 - 00000980 _____ C:\Users\Carl\Desktop\JRT.txt 2013-11-09 14:44 - 2013-11-09 14:44 - 01034531 _____ (Thisisu) C:\Users\Carl\Downloads\JRT.exe 2013-11-09 14:44 - 2013-11-09 14:44 - 00000000 ____D C:\Windows\ERUNT 2013-11-09 14:42 - 2013-11-09 14:42 - 00001651 _____ C:\Users\Carl\Desktop\AdwCleaner[S0].txt 2013-11-09 14:40 - 2013-11-09 14:40 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-11-09 14:36 - 2013-11-09 14:38 - 00000000 ____D C:\AdwCleaner 2013-11-09 14:34 - 2013-11-09 14:34 - 01073262 _____ C:\Users\Carl\Downloads\adwcleaner.exe 2013-11-06 13:32 - 2013-11-06 13:32 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Carl\Downloads\mbar-1.07.0.1007.exe 2013-11-05 20:38 - 2013-11-05 20:38 - 00029725 _____ C:\ComboFix.txt 2013-11-05 20:27 - 2013-11-05 20:38 - 00000000 ____D C:\Qoobox 2013-11-05 20:27 - 2013-11-05 20:36 - 00000000 ____D C:\Windows\erdnt 2013-11-05 20:27 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-11-05 20:27 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-11-05 20:27 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-11-05 20:27 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-11-05 20:27 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-11-05 20:27 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-11-05 20:27 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-11-05 20:27 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-11-05 20:25 - 2013-11-05 20:25 - 05144303 ____R (Swearware) C:\Users\Carl\Downloads\ComboFix.exe 2013-11-02 01:38 - 2013-11-02 01:38 - 00139100 _____ C:\Users\Carl\Downloads\OTL.Txt 2013-11-02 01:09 - 2013-11-02 01:09 - 00602112 _____ (OldTimer Tools) C:\Users\Carl\Downloads\OTL.exe 2013-11-02 01:09 - 2013-11-02 01:09 - 00000000 ____D C:\FRST 2013-10-30 15:04 - 2013-10-30 15:04 - 00000000 ____D C:\ProgramData\SystemRequirementsLab 2013-10-30 15:04 - 2013-10-30 15:04 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab 2013-10-29 21:38 - 2013-11-06 13:41 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-29 21:38 - 2013-11-06 13:32 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-10-29 21:37 - 2013-11-06 13:41 - 00000000 ____D C:\Users\Carl\Desktop\mbar 2013-10-29 21:16 - 2013-10-29 21:16 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-29 21:16 - 2013-10-29 21:16 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Malwarebytes 2013-10-29 21:16 - 2013-10-29 21:16 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-29 21:16 - 2013-10-29 21:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-29 21:16 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-26 10:09 - 2013-10-26 10:09 - 00262144 _____ C:\Windows\system32\config\elam 2013-10-26 02:24 - 2013-10-26 02:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-24 15:30 - 2013-10-24 15:30 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Unity 2013-10-24 15:26 - 2013-10-24 15:26 - 00000000 ____D C:\Users\Carl\AppData\Local\Unity 2013-10-22 23:40 - 2013-10-22 23:40 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 23:40 - 2013-10-22 23:40 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-22 23:40 - 2013-10-22 23:40 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-22 23:40 - 2013-10-22 23:40 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-22 23:40 - 2013-10-22 23:40 - 00000000 ____D C:\ProgramData\Oracle 2013-10-16 15:59 - 2013-10-16 15:59 - 00001233 _____ C:\Users\Public\Desktop\BIMx für ArchiCAD 17.lnk 2013-10-16 15:59 - 2013-10-16 15:59 - 00001058 _____ C:\Users\Public\Desktop\ArchiCAD 17.lnk 2013-10-16 15:59 - 2013-10-16 15:59 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-10-16 15:58 - 2013-10-16 15:58 - 00007861 _____ C:\Windows\vpd.properties 2013-10-16 15:57 - 2013-10-16 15:57 - 00000000 ____D C:\Program Files\GRAPHISOFT 2013-10-16 15:55 - 2013-10-16 15:55 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Install.GS 2013-10-15 15:23 - 2013-10-15 15:23 - 00000000 ____D C:\Users\Carl\Documents\Anno 1404 2013-10-15 14:44 - 2013-10-15 14:44 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Ubisoft 2013-10-15 14:43 - 2013-10-15 14:44 - 00000000 ____D C:\ProgramData\Tages 2013-10-15 14:19 - 2013-10-15 14:19 - 00314016 _____ C:\Windows\system32\Drivers\atksgt.sys 2013-10-15 14:19 - 2013-10-15 14:19 - 00043680 _____ C:\Windows\system32\Drivers\lirsgt.sys 2013-10-11 13:14 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-11 13:14 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-11 13:14 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-11 13:14 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 13:14 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 13:14 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-11 13:14 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 13:14 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-11 13:14 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 13:14 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-11 13:14 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-11 13:14 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-11 13:13 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-11 13:13 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 13:13 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-10 06:34 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-10 06:34 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-10 06:34 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-10 06:34 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-10 06:34 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-10 06:34 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-10 06:34 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-10 06:34 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-10 06:34 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-10 06:34 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-10 06:34 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-10 06:34 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-10 06:34 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-10 06:34 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-10 06:34 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-10 06:34 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-10 06:34 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-10 06:34 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-10 06:34 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-10 06:34 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-10 06:34 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-10 06:34 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-10 06:34 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 06:34 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 06:34 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-10 06:34 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-10 06:34 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-10 06:34 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-10 06:34 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-10 06:34 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-10 06:34 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-10 06:34 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-10 06:34 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-10 06:34 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-10 06:34 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-10 06:34 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-10 06:34 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-10 06:34 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-10 06:34 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-10 06:34 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-10 06:34 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-10 06:34 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-10 06:34 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-10 06:34 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-10 06:34 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-10 06:34 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-10 06:34 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll ==================== One Month Modified Files and Folders ======= 2013-11-09 14:51 - 2013-11-09 14:51 - 01957098 _____ (Farbar) C:\Users\Carl\Downloads\FRST64 (1).exe 2013-11-09 14:49 - 2013-11-09 14:49 - 00000980 _____ C:\Users\Carl\Desktop\JRT.txt 2013-11-09 14:47 - 2009-07-14 05:45 - 00022000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-09 14:47 - 2009-07-14 05:45 - 00022000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-09 14:44 - 2013-11-09 14:44 - 01034531 _____ (Thisisu) C:\Users\Carl\Downloads\JRT.exe 2013-11-09 14:44 - 2013-11-09 14:44 - 00000000 ____D C:\Windows\ERUNT 2013-11-09 14:44 - 2011-04-12 08:43 - 00696870 _____ C:\Windows\system32\perfh007.dat 2013-11-09 14:44 - 2011-04-12 08:43 - 00148134 _____ C:\Windows\system32\perfc007.dat 2013-11-09 14:44 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-09 14:42 - 2013-11-09 14:42 - 00001651 _____ C:\Users\Carl\Desktop\AdwCleaner[S0].txt 2013-11-09 14:40 - 2013-11-09 14:40 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-11-09 14:40 - 2012-12-02 01:46 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-11-09 14:40 - 2012-10-27 00:20 - 00017920 _____ C:\Windows\system32\rpcnetp.exe 2013-11-09 14:40 - 2012-10-26 19:15 - 00058288 _____ (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll 2013-11-09 14:40 - 2012-10-26 19:09 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-09 14:40 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-09 14:40 - 2009-07-14 05:51 - 00107633 _____ C:\Windows\setupact.log 2013-11-09 14:39 - 2012-10-27 00:31 - 02072121 _____ C:\Windows\WindowsUpdate.log 2013-11-09 14:38 - 2013-11-09 14:36 - 00000000 ____D C:\AdwCleaner 2013-11-09 14:34 - 2013-11-09 14:34 - 01073262 _____ C:\Users\Carl\Downloads\adwcleaner.exe 2013-11-09 14:32 - 2012-10-26 20:04 - 00000000 ____D C:\Users\Carl\AppData\Local\Windows Live 2013-11-09 14:31 - 2010-11-21 04:47 - 00040362 _____ C:\Windows\PFRO.log 2013-11-06 13:41 - 2013-10-29 21:38 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-06 13:41 - 2013-10-29 21:37 - 00000000 ____D C:\Users\Carl\Desktop\mbar 2013-11-06 13:32 - 2013-11-06 13:32 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Carl\Downloads\mbar-1.07.0.1007.exe 2013-11-06 13:32 - 2013-10-29 21:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-06 13:28 - 2013-02-01 15:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-06 13:28 - 2012-10-26 19:09 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-05 20:38 - 2013-11-05 20:38 - 00029725 _____ C:\ComboFix.txt 2013-11-05 20:38 - 2013-11-05 20:27 - 00000000 ____D C:\Qoobox 2013-11-05 20:38 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-11-05 20:36 - 2013-11-05 20:27 - 00000000 ____D C:\Windows\erdnt 2013-11-05 20:36 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-11-05 20:25 - 2013-11-05 20:25 - 05144303 ____R (Swearware) C:\Users\Carl\Downloads\ComboFix.exe 2013-11-02 22:11 - 2012-12-25 00:22 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Spotify 2013-11-02 21:54 - 2012-12-25 00:22 - 00000000 ____D C:\Users\Carl\AppData\Local\Spotify 2013-11-02 20:56 - 2013-05-07 18:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-02 11:21 - 2012-11-17 22:09 - 00000000 ____D C:\Users\Carl\AppData\Roaming\vlc 2013-11-02 01:38 - 2013-11-02 01:38 - 00139100 _____ C:\Users\Carl\Downloads\OTL.Txt 2013-11-02 01:31 - 2012-10-28 14:09 - 00000000 ____D C:\Program Files\Adobe 2013-11-02 01:31 - 2012-10-28 14:05 - 00000000 ____D C:\ProgramData\Adobe 2013-11-02 01:31 - 2012-10-26 22:13 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Adobe 2013-11-02 01:30 - 2012-10-28 14:09 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-11-02 01:29 - 2012-10-28 14:04 - 00000000 ____D C:\Users\Carl\AppData\Local\Adobe 2013-11-02 01:09 - 2013-11-02 01:09 - 00602112 _____ (OldTimer Tools) C:\Users\Carl\Downloads\OTL.exe 2013-11-02 01:09 - 2013-11-02 01:09 - 00000000 ____D C:\FRST 2013-10-30 15:04 - 2013-10-30 15:04 - 00000000 ____D C:\ProgramData\SystemRequirementsLab 2013-10-30 15:04 - 2013-10-30 15:04 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab 2013-10-30 14:19 - 2013-06-08 21:53 - 01125376 ___SH C:\Users\Carl\Downloads\Thumbs.db 2013-10-29 21:26 - 2012-10-28 14:48 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Dropbox 2013-10-29 21:26 - 2012-10-26 18:28 - 00000000 ___RD C:\Users\Carl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-29 21:16 - 2013-10-29 21:16 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-29 21:16 - 2013-10-29 21:16 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Malwarebytes 2013-10-29 21:16 - 2013-10-29 21:16 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-29 21:16 - 2013-10-29 21:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-28 11:39 - 2012-11-08 15:17 - 00000000 ____D C:\Users\Carl\AppData\Local\cache 2013-10-28 11:30 - 2012-10-26 18:39 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-26 10:09 - 2013-10-26 10:09 - 00262144 _____ C:\Windows\system32\config\elam 2013-10-26 02:24 - 2013-10-26 02:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-24 22:52 - 2013-03-09 15:26 - 00503808 ___SH C:\Users\Carl\Desktop\Thumbs.db 2013-10-24 15:30 - 2013-10-24 15:30 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Unity 2013-10-24 15:26 - 2013-10-24 15:26 - 00000000 ____D C:\Users\Carl\AppData\Local\Unity 2013-10-24 15:11 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-10-22 23:40 - 2013-10-22 23:40 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 23:40 - 2013-10-22 23:40 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-22 23:40 - 2013-10-22 23:40 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-22 23:40 - 2013-10-22 23:40 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-22 23:40 - 2013-10-22 23:40 - 00000000 ____D C:\ProgramData\Oracle 2013-10-17 21:19 - 2012-10-26 19:09 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-17 21:19 - 2012-10-26 19:09 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-16 15:59 - 2013-10-16 15:59 - 00001233 _____ C:\Users\Public\Desktop\BIMx für ArchiCAD 17.lnk 2013-10-16 15:59 - 2013-10-16 15:59 - 00001058 _____ C:\Users\Public\Desktop\ArchiCAD 17.lnk 2013-10-16 15:59 - 2013-10-16 15:59 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-10-16 15:58 - 2013-10-16 15:58 - 00007861 _____ C:\Windows\vpd.properties 2013-10-16 15:57 - 2013-10-16 15:57 - 00000000 ____D C:\Program Files\GRAPHISOFT 2013-10-16 15:55 - 2013-10-16 15:55 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Install.GS 2013-10-16 15:54 - 2012-10-26 18:28 - 00000000 ____D C:\Users\Carl 2013-10-16 15:53 - 2012-12-23 12:36 - 00000000 ____D C:\Users\Carl\Documents\My Games 2013-10-16 15:40 - 2013-01-28 14:13 - 00000000 ____D C:\Users\Carl\Privat 2013-10-16 14:27 - 2012-10-31 16:45 - 00000000 ____D C:\Users\Carl\UNI 2013-10-15 15:23 - 2013-10-15 15:23 - 00000000 ____D C:\Users\Carl\Documents\Anno 1404 2013-10-15 14:44 - 2013-10-15 14:44 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Ubisoft 2013-10-15 14:44 - 2013-10-15 14:43 - 00000000 ____D C:\ProgramData\Tages 2013-10-15 14:19 - 2013-10-15 14:19 - 00314016 _____ C:\Windows\system32\Drivers\atksgt.sys 2013-10-15 14:19 - 2013-10-15 14:19 - 00043680 _____ C:\Windows\system32\Drivers\lirsgt.sys 2013-10-15 14:19 - 2012-10-26 20:06 - 00259317 _____ C:\Windows\DirectX.log 2013-10-13 19:39 - 2012-10-27 08:29 - 00000000 ____D C:\Users\Carl\AppData\Roaming\Azureus 2013-10-13 16:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-13 08:33 - 2013-07-10 12:21 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-13 08:33 - 2013-07-10 12:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-13 08:33 - 2009-07-14 05:45 - 05015000 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-13 08:25 - 2012-12-02 01:46 - 00626272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-10-13 08:25 - 2012-10-25 12:42 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys 2013-10-13 08:25 - 2012-10-25 12:42 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2013-10-13 08:25 - 2012-06-19 17:28 - 07717984 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-10-11 13:11 - 2012-10-26 20:06 - 01590378 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-11 13:08 - 2013-08-14 07:28 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 13:07 - 2012-10-28 12:45 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-10 06:30 - 2012-11-01 19:50 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins Some content of TEMP: ==================== C:\Users\Carl\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-02 10:05 ==================== End Of Log ============================ Danach habe ich nochmal manuell einen Neustart gemacht und mbar ausgeführt, 5 Funde behandelt, neugestartet und erneut ausgeführt und die 5 Funde behandelt. Übrigens: Wenn ich mbar (also Malwarebytes Anti-Rootkit) starte kommt die Meldung Registry value "AppInit_Dlls" hast been found, which may caused by rootkit activity. (...) Do you want to remove this value and restart the tool? Es wird mir außerdem in der Meldung geraten, wenn ich mir nicht sicher bin die Frage mit Nein zu beantworten, was ich bisher auch immer so getan habe. (wollte das nur mal anmerken - vllt ist das ja wichtig) Dann hab ich mal in die Quarantäne von Anti-Malware und den oben genannten Screenshot gemacht. Hier die Logs von mbar Zitat:
Zitat:
|
09.11.2013, 17:06 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exe Bitte ein Log mit tdsskiller machen Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ Logfiles bitte immer in CODE-Tags posten |
09.11.2013, 20:25 | #20 |
| Trojan.BitcoinMiner befall u. a. von svchost.exe Der Scan ergab keine Funde Log dazu Code:
ATTFilter 20:21:59.0805 0x266c TDSS rootkit removing tool 3.0.0.16 Nov 1 2013 15:53:38 20:22:02.0500 0x266c ============================================================ 20:22:02.0500 0x266c Current date / time: 2013/11/09 20:22:02.0500 20:22:02.0500 0x266c SystemInfo: 20:22:02.0500 0x266c 20:22:02.0500 0x266c OS Version: 6.1.7601 ServicePack: 1.0 20:22:02.0500 0x266c Product type: Workstation 20:22:02.0500 0x266c ComputerName: CARL-PC 20:22:02.0500 0x266c UserName: Carl 20:22:02.0500 0x266c Windows directory: C:\Windows 20:22:02.0500 0x266c System windows directory: C:\Windows 20:22:02.0500 0x266c Running under WOW64 20:22:02.0501 0x266c Processor architecture: Intel x64 20:22:02.0501 0x266c Number of processors: 8 20:22:02.0501 0x266c Page size: 0x1000 20:22:02.0501 0x266c Boot type: Normal boot 20:22:02.0501 0x266c ============================================================ 20:22:02.0780 0x266c System UUID: {474B910E-F194-F90F-33CF-859CABBEE3FF} 20:22:03.0230 0x266c Drive \Device\Harddisk0\DR0 - Size: 0x1DCF856000 (119.24 Gb), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 20:22:03.0521 0x266c Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 20:22:03.0578 0x266c ============================================================ 20:22:03.0578 0x266c \Device\Harddisk0\DR0: 20:22:03.0579 0x266c MBR partitions: 20:22:03.0579 0x266c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 20:22:03.0579 0x266c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xEE49000 20:22:03.0579 0x266c \Device\Harddisk1\DR1: 20:22:03.0579 0x266c MBR partitions: 20:22:03.0579 0x266c \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x57545000 20:22:03.0579 0x266c ============================================================ 20:22:03.0581 0x266c C: <-> \Device\Harddisk0\DR0\Partition2 20:22:03.0601 0x266c D: <-> \Device\Harddisk1\DR1\Partition1 20:22:03.0601 0x266c ============================================================ 20:22:03.0601 0x266c Initialize success 20:22:03.0601 0x266c ============================================================ 20:22:31.0013 0x0cfc ============================================================ 20:22:31.0014 0x0cfc Scan started 20:22:31.0014 0x0cfc Mode: Manual; SigCheck; TDLFS; 20:22:31.0014 0x0cfc ============================================================ 20:22:31.0014 0x0cfc KSN ping started 20:22:33.0427 0x0cfc KSN ping finished: true 20:22:34.0072 0x0cfc ================ Scan system memory ======================== 20:22:34.0072 0x0cfc System memory - ok 20:22:34.0073 0x0cfc ================ Scan services ============================= 20:22:34.0111 0x0cfc [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 20:22:34.0211 0x0cfc 1394ohci - ok 20:22:34.0232 0x0cfc [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys 20:22:34.0261 0x0cfc ACPI - ok 20:22:34.0264 0x0cfc [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 20:22:34.0277 0x0cfc AcpiPmi - ok 20:22:34.0283 0x0cfc [ B1EA9681502EE57F87DB71D726288A5B, D17BD2CFAE72E92C77D183331D5CBA0FEA893BF54875920870E271940F40A8BB ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 20:22:34.0292 0x0cfc AdobeARMservice - ok 20:22:34.0310 0x0cfc [ A283108E14F3970432C21AF4C0CB1BCE, 1D3219EF916D54232838870EDE557296AACB714B456ED0AAE0DE3CE3822F4643 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 20:22:34.0321 0x0cfc AdobeFlashPlayerUpdateSvc - ok 20:22:34.0333 0x0cfc [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 20:22:34.0349 0x0cfc adp94xx - ok 20:22:34.0358 0x0cfc [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys 20:22:34.0371 0x0cfc adpahci - ok 20:22:34.0376 0x0cfc [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 20:22:34.0387 0x0cfc adpu320 - ok 20:22:34.0392 0x0cfc [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 20:22:34.0418 0x0cfc AeLookupSvc - ok 20:22:34.0429 0x0cfc [ 314C17917AC8523EC77A710215012A65, 725CF2D5F63C06F7704C24FE0CFA696215DADC6C0EC445D9671E82F8E23E56AD ] AFD C:\Windows\system32\drivers\afd.sys 20:22:34.0451 0x0cfc AFD - ok 20:22:34.0454 0x0cfc [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys 20:22:34.0463 0x0cfc agp440 - ok 20:22:34.0467 0x0cfc [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe 20:22:34.0479 0x0cfc ALG - ok 20:22:34.0482 0x0cfc [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys 20:22:34.0490 0x0cfc aliide - ok 20:22:34.0492 0x0cfc [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys 20:22:34.0500 0x0cfc amdide - ok 20:22:34.0504 0x0cfc [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 20:22:34.0516 0x0cfc AmdK8 - ok 20:22:34.0519 0x0cfc [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 20:22:34.0531 0x0cfc AmdPPM - ok 20:22:34.0535 0x0cfc [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys 20:22:34.0545 0x0cfc amdsata - ok 20:22:34.0550 0x0cfc [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 20:22:34.0562 0x0cfc amdsbs - ok 20:22:34.0565 0x0cfc [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys 20:22:34.0573 0x0cfc amdxata - ok 20:22:34.0579 0x0cfc [ 449D90F1FB6402773C2F1ECCEAE15F74, D432D3F9D9AD14C70324B13C0A82A5BADC0EA4927B2E49B8BC31A5DEE6440374 ] AMPPAL C:\Windows\system32\DRIVERS\AMPPAL.sys 20:22:34.0594 0x0cfc AMPPAL - ok 20:22:34.0600 0x0cfc [ 449D90F1FB6402773C2F1ECCEAE15F74, D432D3F9D9AD14C70324B13C0A82A5BADC0EA4927B2E49B8BC31A5DEE6440374 ] AMPPALP C:\Windows\system32\DRIVERS\amppal.sys 20:22:34.0612 0x0cfc AMPPALP - ok 20:22:34.0627 0x0cfc [ AB6E5B9333101E414D8F04BC570064F1, 4BB20C0ECE2C655B8E3A40E8C69A7B6974B73D3585AEDF47A0C52582D17BDAF6 ] AMPPALR3 C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe 20:22:34.0818 0x0cfc AMPPALR3 - ok 20:22:34.0823 0x0cfc [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID C:\Windows\system32\drivers\appid.sys 20:22:34.0849 0x0cfc AppID - ok 20:22:34.0853 0x0cfc [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc C:\Windows\System32\appidsvc.dll 20:22:34.0878 0x0cfc AppIDSvc - ok 20:22:34.0881 0x0cfc [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll 20:22:34.0894 0x0cfc Appinfo - ok 20:22:34.0898 0x0cfc [ 30E3850F303EAE5C364782EA78579CC9, 8C94E5A9052F6E794685194EEACB31A174A947D60246908B6A0DEFA081A747A3 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 20:22:34.0907 0x0cfc Apple Mobile Device - ok 20:22:34.0913 0x0cfc [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll 20:22:34.0929 0x0cfc AppMgmt - ok 20:22:34.0933 0x0cfc [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys 20:22:34.0942 0x0cfc arc - ok 20:22:34.0946 0x0cfc [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys 20:22:34.0955 0x0cfc arcsas - ok 20:22:34.0963 0x0cfc [ 9217D874131AE6FF8F642F124F00A555, BE2923D5AA7748FDAAED73AF567D015517B36F1C739C6E5637DD15112EFDF495 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 20:22:34.0971 0x0cfc aspnet_state - ok 20:22:34.0974 0x0cfc [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 20:22:34.0999 0x0cfc AsyncMac - ok 20:22:35.0002 0x0cfc [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys 20:22:35.0011 0x0cfc atapi - ok 20:22:35.0020 0x0cfc [ FC0E8778C000291CAF60EB88C011E931, 09BCCA3DE01021AEF76DFB46F01D21BA6FF409E816FA7547E5C3DFBF3A615ED2 ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys 20:22:35.0034 0x0cfc atksgt - ok 20:22:35.0048 0x0cfc [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 20:22:35.0086 0x0cfc AudioEndpointBuilder - ok 20:22:35.0099 0x0cfc [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv C:\Windows\System32\Audiosrv.dll 20:22:35.0135 0x0cfc AudioSrv - ok 20:22:35.0140 0x0cfc [ F431DC5D94F4B2FDBC927655D8A9B10E, FA16A95E5B83D08F0FD76FDAB03FC7CD4B6917BFE15F2F1D9F3B781F6A1888D8 ] Autodesk Content Service C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe 20:22:35.0149 0x0cfc Autodesk Content Service - ok 20:22:35.0162 0x0cfc [ 15D2DB9BFA8E833ED31FAB2BB088FDDA, 6198C0A5DA01DA146A9A054C3C882A1DBF9BA84466EBFDDA1C1062EF36F9B34B ] AVP C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe 20:22:35.0176 0x0cfc AVP - ok 20:22:35.0182 0x0cfc [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll 20:22:35.0198 0x0cfc AxInstSV - ok 20:22:35.0209 0x0cfc [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 20:22:35.0229 0x0cfc b06bdrv - ok 20:22:35.0236 0x0cfc [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 20:22:35.0252 0x0cfc b57nd60a - ok 20:22:35.0258 0x0cfc [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll 20:22:35.0270 0x0cfc BDESVC - ok 20:22:35.0273 0x0cfc [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys 20:22:35.0297 0x0cfc Beep - ok 20:22:35.0312 0x0cfc [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll 20:22:35.0351 0x0cfc BFE - ok 20:22:35.0369 0x0cfc [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\system32\qmgr.dll 20:22:35.0412 0x0cfc BITS - ok 20:22:35.0416 0x0cfc [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 20:22:35.0428 0x0cfc blbdrive - ok 20:22:35.0438 0x0cfc [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 20:22:35.0452 0x0cfc Bonjour Service - ok 20:22:35.0456 0x0cfc [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 20:22:35.0468 0x0cfc bowser - ok 20:22:35.0470 0x0cfc [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 20:22:35.0483 0x0cfc BrFiltLo - ok 20:22:35.0485 0x0cfc [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 20:22:35.0497 0x0cfc BrFiltUp - ok 20:22:35.0501 0x0cfc [ 5C2F352A4E961D72518261257AAE204B, 9EE1001E1D46A414A7A86FE1DBBE232203E26F54D9EF43ED31ED8EACD4D09853 ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 20:22:35.0527 0x0cfc BridgeMP - ok 20:22:35.0532 0x0cfc [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll 20:22:35.0546 0x0cfc Browser - ok 20:22:35.0553 0x0cfc [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys 20:22:35.0572 0x0cfc Brserid - ok 20:22:35.0575 0x0cfc [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 20:22:35.0587 0x0cfc BrSerWdm - ok 20:22:35.0589 0x0cfc [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 20:22:35.0601 0x0cfc BrUsbMdm - ok 20:22:35.0604 0x0cfc [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 20:22:35.0614 0x0cfc BrUsbSer - ok 20:22:35.0617 0x0cfc [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 20:22:35.0630 0x0cfc BTHMODEM - ok 20:22:35.0635 0x0cfc [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll 20:22:35.0661 0x0cfc bthserv - ok 20:22:35.0665 0x0cfc [ 588762F716C2B7A2054AFBC3D58E5C21, CD44B0200B2E0A81073563BE84ECF9C092F4B5E9DC166A8F0690D6272913CCB7 ] BTHSSecurityMgr C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe 20:22:35.0674 0x0cfc BTHSSecurityMgr - ok 20:22:35.0679 0x0cfc [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 20:22:35.0706 0x0cfc cdfs - ok 20:22:35.0711 0x0cfc [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 20:22:35.0724 0x0cfc cdrom - ok 20:22:35.0728 0x0cfc [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll 20:22:35.0753 0x0cfc CertPropSvc - ok 20:22:35.0756 0x0cfc [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys 20:22:35.0769 0x0cfc circlass - ok 20:22:35.0778 0x0cfc [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\Windows\system32\CLFS.sys 20:22:35.0793 0x0cfc CLFS - ok 20:22:35.0800 0x0cfc [ 525A4F2E6ED045A51CDA4DCD3A24C69F, F3A2C4E8D876A6AFAF7FB7F9B3221657595F7B161FC6BF1D3905C355A6F2C318 ] CLHNServiceForPowerDVD12 C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe 20:22:35.0810 0x0cfc CLHNServiceForPowerDVD12 - ok 20:22:35.0815 0x0cfc [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:22:35.0823 0x0cfc clr_optimization_v2.0.50727_32 - ok 20:22:35.0828 0x0cfc [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 20:22:35.0836 0x0cfc clr_optimization_v2.0.50727_64 - ok 20:22:35.0844 0x0cfc [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:22:35.0853 0x0cfc clr_optimization_v4.0.30319_32 - ok 20:22:35.0857 0x0cfc [ C6F9AF94DCD58122A4D7E89DB6BED29D, CB0E5AE60EC76323585FB86D89E8DB7ADB5EDF6EA3D0B27E9ECE75B8CAA8BFDE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 20:22:35.0867 0x0cfc clr_optimization_v4.0.30319_64 - ok 20:22:35.0870 0x0cfc [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 20:22:35.0883 0x0cfc CmBatt - ok 20:22:35.0886 0x0cfc [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys 20:22:35.0894 0x0cfc cmdide - ok 20:22:35.0904 0x0cfc [ 9AC4F97C2D3E93367E2148EA940CD2CD, 530E089E5CF868AECDB2B5548EBE76E0CA98FC74A72897292AB2485734402E3B ] CNG C:\Windows\system32\Drivers\cng.sys 20:22:35.0925 0x0cfc CNG - ok 20:22:35.0928 0x0cfc [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 20:22:35.0936 0x0cfc Compbatt - ok 20:22:35.0939 0x0cfc [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 20:22:35.0952 0x0cfc CompositeBus - ok 20:22:35.0954 0x0cfc COMSysApp - ok 20:22:35.0971 0x0cfc [ 236172C3A418B9A0F26B416A72F5A556, 315D8C8A002BE607A7AC011DA17C6CE305C49C6AF458669C3D2B649A06DBCDFB ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe 20:22:35.0984 0x0cfc cphs - ok 20:22:36.0011 0x0cfc cpuz130 - ok 20:22:36.0023 0x0cfc [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 20:22:36.0032 0x0cfc crcdisk - ok 20:22:36.0040 0x0cfc [ 6B400F211BEE880A37A1ED0368776BF4, 2F27C6FA96A1C8CBDA467846DA57E63949A7EA37DB094B13397DDD30114295BD ] CryptSvc C:\Windows\system32\cryptsvc.dll 20:22:36.0059 0x0cfc CryptSvc - ok 20:22:36.0071 0x0cfc [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys 20:22:36.0092 0x0cfc CSC - ok 20:22:36.0107 0x0cfc [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll 20:22:36.0141 0x0cfc CscService - ok 20:22:36.0148 0x0cfc [ 937337437A28D96DD107ABEEFEA4574F, 18C1185336595551FABA75E1034AF45170F8405BA621E85C38CD9BC4A0D97DF7 ] CyberLink PowerDVD 12 Media Server Monitor Service C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe 20:22:36.0157 0x0cfc CyberLink PowerDVD 12 Media Server Monitor Service - ok 20:22:36.0164 0x0cfc [ 9DBAD535C952276D780FF20D66A5A1C9, E475BB631DCACAF8759E5456A41AA59B9BC6FAB61438E8494EBCB8AB1C755FE7 ] CyberLink PowerDVD 12 Media Server Service C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe 20:22:36.0176 0x0cfc CyberLink PowerDVD 12 Media Server Service - ok 20:22:36.0189 0x0cfc [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll 20:22:36.0225 0x0cfc DcomLaunch - ok 20:22:36.0233 0x0cfc [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll 20:22:36.0263 0x0cfc defragsvc - ok 20:22:36.0267 0x0cfc [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys 20:22:36.0293 0x0cfc DfsC - ok 20:22:36.0301 0x0cfc [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll 20:22:36.0320 0x0cfc Dhcp - ok 20:22:36.0323 0x0cfc [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys 20:22:36.0349 0x0cfc discache - ok 20:22:36.0352 0x0cfc [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\drivers\disk.sys 20:22:36.0361 0x0cfc Disk - ok 20:22:36.0365 0x0cfc [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 20:22:36.0378 0x0cfc dmvsc - ok 20:22:36.0383 0x0cfc [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll 20:22:36.0398 0x0cfc Dnscache - ok 20:22:36.0406 0x0cfc [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll 20:22:36.0435 0x0cfc dot3svc - ok 20:22:36.0440 0x0cfc [ B42ED0320C6E41102FDE0005154849BB, 4DB872E23AD049C3C9FDC0759FC58BFA60DA91B18BC82B611BFA300D26DDFC7A ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 20:22:36.0456 0x0cfc Dot4 - ok 20:22:36.0458 0x0cfc [ E9F5969233C5D89F3C35E3A66A52A361, C4BD35795C78FB11E6022372CB25DEB570730EFDAD3DC1584368235FF622638C ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 20:22:36.0471 0x0cfc Dot4Print - ok 20:22:36.0474 0x0cfc [ FD05A02B0370BC3000F402E543CA5814, 089B1113E640F495F470E8F57060B89546270481B309DC8ED3C3D13A849076A3 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 20:22:36.0487 0x0cfc dot4usb - ok 20:22:36.0492 0x0cfc [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll 20:22:36.0520 0x0cfc DPS - ok 20:22:36.0522 0x0cfc [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 20:22:36.0534 0x0cfc drmkaud - ok 20:22:36.0553 0x0cfc [ 88612F1CE3BF42256913BF6E61C70D52, 7CF190F83FA8F15C33008EB381D3E345CEF37CBC046227DED26B36799EF4D9A7 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 20:22:36.0579 0x0cfc DXGKrnl - ok 20:22:36.0584 0x0cfc [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll 20:22:36.0611 0x0cfc EapHost - ok 20:22:36.0666 0x0cfc [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys 20:22:36.0744 0x0cfc ebdrv - ok 20:22:36.0750 0x0cfc [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] EFS C:\Windows\System32\lsass.exe 20:22:36.0761 0x0cfc EFS - ok 20:22:36.0776 0x0cfc [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 20:22:36.0803 0x0cfc ehRecvr - ok 20:22:36.0808 0x0cfc [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe 20:22:36.0821 0x0cfc ehSched - ok 20:22:36.0834 0x0cfc [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys 20:22:36.0851 0x0cfc elxstor - ok 20:22:36.0854 0x0cfc [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys 20:22:36.0864 0x0cfc ErrDev - ok 20:22:36.0871 0x0cfc [ 0B9BF3F5BC94E2D9CF565136145E1863, 5711B06FFC995230E9A0ECABD751668FE00EF7B7010D4A0C48C9570EA45EBCB1 ] ETD C:\Windows\system32\DRIVERS\ETD.sys 20:22:36.0882 0x0cfc ETD - ok 20:22:36.0892 0x0cfc [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll 20:22:36.0924 0x0cfc EventSystem - ok 20:22:36.0940 0x0cfc [ 64D25284A4E9D11CA0722AF3F30FD970, C7C40CA8AC444F7B0F88086396C17316348480EBA09109222897B5A42AD655DF ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 20:22:36.0957 0x0cfc EvtEng - ok 20:22:36.0963 0x0cfc [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys 20:22:36.0992 0x0cfc exfat - ok 20:22:36.0997 0x0cfc [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys 20:22:37.0026 0x0cfc fastfat - ok 20:22:37.0041 0x0cfc [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe 20:22:37.0068 0x0cfc Fax - ok 20:22:37.0072 0x0cfc [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys 20:22:37.0082 0x0cfc fdc - ok 20:22:37.0085 0x0cfc [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll 20:22:37.0111 0x0cfc fdPHost - ok 20:22:37.0114 0x0cfc [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll 20:22:37.0139 0x0cfc FDResPub - ok 20:22:37.0143 0x0cfc [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 20:22:37.0152 0x0cfc FileInfo - ok 20:22:37.0155 0x0cfc [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 20:22:37.0181 0x0cfc Filetrace - ok 20:22:37.0201 0x0cfc [ 8669BE94F63944E4F899C3950B520241, 9991E57B3C366D59BD186CEAA78D4590EDB2BC127250CF4D1522CBE413453E72 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 20:22:37.0228 0x0cfc FLEXnet Licensing Service - ok 20:22:37.0255 0x0cfc [ 64AB6F28047744B9B19C97459C2AB31B, B1F3FEE6DF1E72003DEAC8712C3E29D82DF67A095C4AC16A379BCD995C2F3833 ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe 20:22:37.0285 0x0cfc FLEXnet Licensing Service 64 - ok 20:22:37.0289 0x0cfc [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 20:22:37.0300 0x0cfc flpydisk - ok 20:22:37.0307 0x0cfc [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 20:22:37.0320 0x0cfc FltMgr - ok 20:22:37.0342 0x0cfc [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll 20:22:37.0378 0x0cfc FontCache - ok 20:22:37.0383 0x0cfc [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 20:22:37.0391 0x0cfc FontCache3.0.0.0 - ok 20:22:37.0394 0x0cfc [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 20:22:37.0402 0x0cfc FsDepends - ok 20:22:37.0405 0x0cfc [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 20:22:37.0413 0x0cfc Fs_Rec - ok 20:22:37.0419 0x0cfc [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 20:22:37.0433 0x0cfc fvevol - ok 20:22:37.0436 0x0cfc [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 20:22:37.0445 0x0cfc gagp30kx - ok 20:22:37.0448 0x0cfc [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 20:22:37.0456 0x0cfc GEARAspiWDM - ok 20:22:37.0533 0x0cfc [ B1C9B932F5A728800AB9C2C88C92594A, 74290A76EECB5B25C1F36DC9FD20EC80E9C60E569D42BA02F6568F75D0269EEA ] Gizmo Central D:\Programme\Gizmo\gservice.exe 20:22:37.0550 0x0cfc Gizmo Central - ok 20:22:37.0557 0x0cfc [ 4CF044DB46F79BFA47FBDFD35192D765, 8520DBAAB9BD148296B468D972BA51B3B2C829355E6109EE190CB7965873DF8D ] GizmoDrv C:\Windows\system32\drivers\GizmoDrv.sys 20:22:37.0567 0x0cfc GizmoDrv - ok 20:22:37.0583 0x0cfc [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll 20:22:37.0624 0x0cfc gpsvc - ok 20:22:37.0629 0x0cfc [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 20:22:37.0637 0x0cfc gupdate - ok 20:22:37.0640 0x0cfc [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 20:22:37.0647 0x0cfc gupdatem - ok 20:22:37.0651 0x0cfc [ 1E6438D4EA6E1174A3B3B1EDC4DE660B, F9995CFEC7BBFE10B06EEE04CA6B49658275C43096E57747BFF9C2C31A0F9011 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys 20:22:37.0660 0x0cfc hamachi - ok 20:22:37.0662 0x0cfc [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 20:22:37.0674 0x0cfc hcw85cir - ok 20:22:37.0682 0x0cfc [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 20:22:37.0701 0x0cfc HdAudAddService - ok 20:22:37.0706 0x0cfc [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 20:22:37.0720 0x0cfc HDAudBus - ok 20:22:37.0723 0x0cfc [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 20:22:37.0734 0x0cfc HidBatt - ok 20:22:37.0738 0x0cfc [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys 20:22:37.0752 0x0cfc HidBth - ok 20:22:37.0755 0x0cfc [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys 20:22:37.0768 0x0cfc HidIr - ok 20:22:37.0770 0x0cfc [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\System32\hidserv.dll 20:22:37.0795 0x0cfc hidserv - ok 20:22:37.0798 0x0cfc [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\drivers\hidusb.sys 20:22:37.0809 0x0cfc HidUsb - ok 20:22:37.0812 0x0cfc [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll 20:22:37.0839 0x0cfc hkmsvc - ok 20:22:37.0845 0x0cfc [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 20:22:37.0861 0x0cfc HomeGroupListener - ok 20:22:37.0867 0x0cfc [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 20:22:37.0882 0x0cfc HomeGroupProvider - ok 20:22:37.0892 0x0cfc [ 5DA42D24712E00728CEA2342A65009B2, 73EC5250DCFD556525B24B3CA66C64AC7747E77652A2AD6119936A59A9E8562A ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 20:22:38.0010 0x0cfc hpqcxs08 - ok 20:22:38.0021 0x0cfc [ D86A39BF100069444D026D22D9A6E555, 7B24D48D5BA67704C88697FADB64364E0E64D26259408E3C219820C5404C5EEC ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 20:22:38.0042 0x0cfc hpqddsvc - ok 20:22:38.0046 0x0cfc [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 20:22:38.0056 0x0cfc HpSAMD - ok 20:22:38.0076 0x0cfc [ F37882F128EFACEFE353E0BAE2766909, 2F9D21613500F092DFC0DB879180B549EE615D9B07408A5CC1A7F84663B2F47A ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL 20:22:38.0099 0x0cfc HPSLPSVC - detected UnsignedFile.Multi.Generic ( 1 ) 20:22:40.0456 0x0cfc Detect skipped due to KSN trusted 20:22:40.0456 0x0cfc HPSLPSVC - ok 20:22:40.0490 0x0cfc [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\Windows\system32\drivers\HTTP.sys 20:22:40.0536 0x0cfc HTTP - ok 20:22:40.0539 0x0cfc [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 20:22:40.0547 0x0cfc hwpolicy - ok 20:22:40.0551 0x0cfc [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 20:22:40.0563 0x0cfc i8042prt - ok 20:22:40.0577 0x0cfc [ C224331A54571C8C9162F7714400BBBD, C2CA4881ACD46071E67435BE5E3DB133D0743B026FD20D6D6E26B2FE7A03FCAA ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 20:22:40.0594 0x0cfc iaStor - ok 20:22:40.0598 0x0cfc [ 7D4B9A48430ED57ACA6373B71D5904CA, 6ED72DAA7A4951142F036364E8F237E74246EF3E9EA089448DEF15380DAB0DB3 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 20:22:40.0605 0x0cfc IAStorDataMgrSvc - ok 20:22:40.0615 0x0cfc [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 20:22:40.0630 0x0cfc iaStorV - ok 20:22:40.0635 0x0cfc [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 20:22:40.0641 0x0cfc IDriverT - detected UnsignedFile.Multi.Generic ( 1 ) 20:22:42.0994 0x0cfc Detect skipped due to KSN trusted 20:22:42.0994 0x0cfc IDriverT - ok 20:22:43.0028 0x0cfc [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 20:22:43.0059 0x0cfc idsvc - ok 20:22:43.0311 0x0cfc [ 3FB253E8059A1AAC3A8B83A31D094CC5, 4D4988BF7D81FB6D75CDB65E1E42AC72DA76D3F84712AA1A27428A6490E342D0 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 20:22:43.0624 0x0cfc igfx - ok 20:22:43.0638 0x0cfc [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys 20:22:43.0646 0x0cfc iirsp - ok 20:22:43.0664 0x0cfc [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE6D23797A36B406 ] IKEEXT C:\Windows\System32\ikeext.dll 20:22:43.0706 0x0cfc IKEEXT - ok 20:22:43.0774 0x0cfc [ 9CC645EB9697AA4F2D5A39835C80A0A2, 39861B19E9BF17F5250D571996167A178606150B62C876529D3699817FDDC42A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 20:22:43.0855 0x0cfc IntcAzAudAddService - ok 20:22:43.0866 0x0cfc [ 6C9FFFECA9FED31347D211C5D1FFBD2D, 36CF8B847FAED0D978B3169ED550CC958025902CAC1D7D304E2684B2483E72B8 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys 20:22:43.0883 0x0cfc IntcDAud - ok 20:22:43.0896 0x0cfc [ 0043EC20C06FD9FE339B5D37474B731E, E84A078BDBEC7EA29257D758030271B62F3ED2C954DC1EEECC5B24B39EDB2A59 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe 20:22:43.0913 0x0cfc Intel(R) Capability Licensing Service Interface - ok 20:22:43.0918 0x0cfc [ 50CA8F1A4B0AEC4EE583594F0A8EB719, D5CCADAA5510DDE82910C4782D2A4FF9419A832D5493BCD2DF5194D239763850 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 20:22:43.0926 0x0cfc Intel(R) ME Service - ok 20:22:43.0928 0x0cfc [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys 20:22:43.0936 0x0cfc intelide - ok 20:22:43.0939 0x0cfc [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 20:22:43.0951 0x0cfc intelppm - ok 20:22:43.0955 0x0cfc [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll 20:22:43.0982 0x0cfc IPBusEnum - ok 20:22:43.0985 0x0cfc [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:22:44.0010 0x0cfc IpFilterDriver - ok 20:22:44.0023 0x0cfc [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 20:22:44.0046 0x0cfc iphlpsvc - ok 20:22:44.0050 0x0cfc [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 20:22:44.0062 0x0cfc IPMIDRV - ok 20:22:44.0066 0x0cfc [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys 20:22:44.0093 0x0cfc IPNAT - ok 20:22:44.0108 0x0cfc [ 6660920D05A32DF2DC1260CEF0B6D172, 2C4361B59CD9F41519FDF14EC69F2E37E1B0635ACA476E4BEF2152C925E35F9F ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 20:22:44.0125 0x0cfc iPod Service - ok 20:22:44.0128 0x0cfc [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys 20:22:44.0142 0x0cfc IRENUM - ok 20:22:44.0144 0x0cfc [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys 20:22:44.0152 0x0cfc isapnp - ok 20:22:44.0159 0x0cfc [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 20:22:44.0172 0x0cfc iScsiPrt - ok 20:22:44.0175 0x0cfc [ D596D915CF091DA1F8CE4BD38BB5D509, 9B4D246B6886FFD9BE329F3543B819FC010661B0F70206F16ECBF25A7B12AA6F ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys 20:22:44.0182 0x0cfc iusb3hcs - ok 20:22:44.0191 0x0cfc [ 023896E23B61543A15A230EED996D911, 2F8D15B67AB2C1E87EA46F2CB9DBA564865D89DEA93A83B44A9B148883B96731 ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys 20:22:44.0204 0x0cfc iusb3hub - ok 20:22:44.0221 0x0cfc [ 7FAEC13F1ADD619F4B5B2D2CBF841E8E, E7ED64DD26FD4EA04C2C32C33BDA16FB985F3C6F1F8451480A0D24375B7F57AC ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys 20:22:44.0243 0x0cfc iusb3xhc - ok 20:22:44.0249 0x0cfc [ EF27B3B58E393E9F10FB6A6643BD8185, 8671AB0159CCACA39F6D072EFFDE984BAFE56137965AA0ADEC880D00893B8E8A ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe 20:22:44.0258 0x0cfc jhi_service - ok 20:22:44.0261 0x0cfc [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 20:22:44.0270 0x0cfc kbdclass - ok 20:22:44.0273 0x0cfc [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 20:22:44.0284 0x0cfc kbdhid - ok 20:22:44.0286 0x0cfc [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] KeyIso C:\Windows\system32\lsass.exe 20:22:44.0297 0x0cfc KeyIso - ok 20:22:44.0434 0x0cfc [ 1C6256096A341051509D36AD724830BE, 025F7E1E979DC8C4794FC7D3581D6BCF6E0F6DC327C6FCB925B6A8EDBE999A68 ] kl1 C:\Windows\system32\DRIVERS\kl1.sys 20:22:44.0566 0x0cfc kl1 - ok 20:22:44.0590 0x0cfc [ 788E5F92721849A17BD64883C49EB825, CEBCE3D9A84D31F597F8592F0E62C2E6ED8A492087F121B151E64903A86CAC52 ] KLIF C:\Windows\system32\DRIVERS\klif.sys 20:22:44.0608 0x0cfc KLIF - ok 20:22:44.0611 0x0cfc [ 9BD99E1AB3F664120AB95C35F9EC1EB0, B78738689B5006A3CC7AF17FC4A28B604411512A6CD74CC3CC5602602E5CBA00 ] KLIM6 C:\Windows\system32\DRIVERS\klim6.sys 20:22:44.0619 0x0cfc KLIM6 - ok 20:22:44.0622 0x0cfc [ AEB50941C6D67128B14F88DB9917C4E0, 2ACE46665DE298CC197660A442A3172B1FB460A40BD18AECEA786ACB011FDA43 ] klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys 20:22:44.0630 0x0cfc klkbdflt - ok 20:22:44.0632 0x0cfc [ 72CF64FBF38CD681FA7F37176047E967, BE5683C119DCEF7E678EE477D6CADF873E32D42372A253B7E86B8C335DF28E1C ] klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys 20:22:44.0640 0x0cfc klmouflt - ok 20:22:44.0643 0x0cfc [ 45ECF097BC6330C2054D7D43B7AD822B, 41684ED54E75FE6BEEA322E7CE888DFDD53EE1F45016E01CE10B84ABB02CBDA8 ] kltdi C:\Windows\system32\DRIVERS\kltdi.sys 20:22:44.0651 0x0cfc kltdi - ok 20:22:44.0657 0x0cfc [ 1FCB657B581CC4DF17FD6571F93602DE, D5D95773D19AA47BA619D149FD6068198E2AA05C219C3936E327B3DFFDE6B10C ] kneps C:\Windows\system32\DRIVERS\kneps.sys 20:22:44.0668 0x0cfc kneps - ok 20:22:44.0671 0x0cfc [ 97A7070AEA4C058B6418519E869A63B4, 15345C2D6CA159BD498002974A0BD21CAB611124D85E3320248B47652AEF23C8 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 20:22:44.0681 0x0cfc KSecDD - ok 20:22:44.0686 0x0cfc [ 26C43A7C2862447EC59DEDA188D1DA07, 5363BF87E650FE2010ACA9417D6920FF4ED752256FF47732882E9B2BA1ED154B ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 20:22:44.0697 0x0cfc KSecPkg - ok 20:22:44.0699 0x0cfc [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 20:22:44.0724 0x0cfc ksthunk - ok 20:22:44.0733 0x0cfc [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll 20:22:44.0766 0x0cfc KtmRm - ok 20:22:44.0773 0x0cfc [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\System32\srvsvc.dll 20:22:44.0802 0x0cfc LanmanServer - ok 20:22:44.0806 0x0cfc [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 20:22:44.0834 0x0cfc LanmanWorkstation - ok 20:22:44.0838 0x0cfc [ 5D00693E33A01690911572925BB89461, 4C5B03380DFAE6613F3CBFBA5F49D8FE02B6DEE4408FCD6B5A3B74F04B58F108 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys 20:22:44.0847 0x0cfc LHidFilt - ok 20:22:44.0850 0x0cfc [ 156AB2E56DC3CA0B582E3362E07CDED7, 7B03929273861690DC42E4C686E655BE5A1C60136AE5E739D7E62306AFD4AB9A ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys 20:22:44.0859 0x0cfc lirsgt - ok 20:22:44.0862 0x0cfc [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 20:22:44.0888 0x0cfc lltdio - ok 20:22:44.0896 0x0cfc [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll 20:22:44.0927 0x0cfc lltdsvc - ok 20:22:44.0930 0x0cfc [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll 20:22:44.0956 0x0cfc lmhosts - ok 20:22:44.0959 0x0cfc [ A0D8D290370F4B42C5A7284947EAFFEA, C1D5E4B3E87499945D8E3969988C5928513B8E9F2B39C2D560196601902DC794 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys 20:22:44.0967 0x0cfc LMouFilt - ok 20:22:44.0974 0x0cfc [ 2526FECED1625752EF4F8ABB367CAA7E, EB90022051D5A6AE5FC2C7B0AD05AEF15730160FD611F652E5E7AD00C774881A ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 20:22:44.0984 0x0cfc LMS - ok 20:22:44.0990 0x0cfc [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 20:22:44.0999 0x0cfc LSI_FC - ok 20:22:45.0004 0x0cfc [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 20:22:45.0013 0x0cfc LSI_SAS - ok 20:22:45.0017 0x0cfc [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 20:22:45.0026 0x0cfc LSI_SAS2 - ok 20:22:45.0030 0x0cfc [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 20:22:45.0039 0x0cfc LSI_SCSI - ok 20:22:45.0044 0x0cfc [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys 20:22:45.0070 0x0cfc luafv - ok 20:22:45.0073 0x0cfc [ 0147B82702D6A5413FB1AE03C243BF9B, 2D414DB40585A66BFE3FAB79E67DB63B1E99BF2E2844182645B81FD0843680E0 ] LUsbFilt C:\Windows\system32\Drivers\LUsbFilt.Sys 20:22:45.0081 0x0cfc LUsbFilt - ok 20:22:45.0085 0x0cfc [ C63BF488680F88B6A1D83302AA0ACD0E, B9DFE993C0FC605304D7DE91B5F90D9397AD8C2E6E1FCA3EF99614A8A535356B ] mbamchameleon C:\Windows\system32\drivers\mbamchameleon.sys 20:22:45.0103 0x0cfc mbamchameleon - ok 20:22:45.0107 0x0cfc [ 0BB97D43299910CBFBA59C461B99B910, 27C22D9D9EE8A410D7396960DA93E9E260D4DCDD38DCE06E85E45C5E24C067DE ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 20:22:45.0115 0x0cfc MBAMProtector - ok 20:22:45.0125 0x0cfc [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 20:22:45.0139 0x0cfc MBAMScheduler - ok 20:22:45.0154 0x0cfc [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 20:22:45.0172 0x0cfc MBAMService - ok 20:22:45.0178 0x0cfc [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 20:22:45.0191 0x0cfc Mcx2Svc - ok 20:22:45.0193 0x0cfc [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\drivers\megasas.sys 20:22:45.0202 0x0cfc megasas - ok 20:22:45.0209 0x0cfc [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 20:22:45.0222 0x0cfc MegaSR - ok 20:22:45.0225 0x0cfc [ 6B01B7414A105B9E51652089A03027CF, 9B113DC22F7D0D0B376E577C6D7083F9EDC09BBFE47726393E16D4FDAAAE21FE ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 20:22:45.0234 0x0cfc MEIx64 - ok 20:22:45.0237 0x0cfc [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll 20:22:45.0264 0x0cfc MMCSS - ok 20:22:45.0267 0x0cfc [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys 20:22:45.0291 0x0cfc Modem - ok 20:22:45.0294 0x0cfc [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 20:22:45.0307 0x0cfc monitor - ok 20:22:45.0310 0x0cfc [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 20:22:45.0319 0x0cfc mouclass - ok 20:22:45.0322 0x0cfc [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 20:22:45.0333 0x0cfc mouhid - ok 20:22:45.0337 0x0cfc [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 20:22:45.0346 0x0cfc mountmgr - ok 20:22:45.0352 0x0cfc [ A35576A433F4AEB0D48976A004657CB6, F820A759119785C3FB10B0EDCF8EF9985886A9B0767ABD45B2ACAC03498B321E ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 20:22:45.0362 0x0cfc MozillaMaintenance - ok 20:22:45.0367 0x0cfc [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys 20:22:45.0378 0x0cfc mpio - ok 20:22:45.0382 0x0cfc [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 20:22:45.0407 0x0cfc mpsdrv - ok 20:22:45.0425 0x0cfc [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll 20:22:45.0467 0x0cfc MpsSvc - ok 20:22:45.0473 0x0cfc [ 1A4F75E63C9FB84B85DFFC6B63FD5404, 01AFA6DBB4CDE55FE4EA05BBE8F753A4266F8D072EA1EE01DB79F5126780C21F ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 20:22:45.0486 0x0cfc MRxDAV - ok 20:22:45.0491 0x0cfc [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 20:22:45.0505 0x0cfc mrxsmb - ok 20:22:45.0512 0x0cfc [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:22:45.0527 0x0cfc mrxsmb10 - ok 20:22:45.0532 0x0cfc [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:22:45.0544 0x0cfc mrxsmb20 - ok 20:22:45.0546 0x0cfc [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys 20:22:45.0555 0x0cfc msahci - ok 20:22:45.0559 0x0cfc [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys 20:22:45.0570 0x0cfc msdsm - ok 20:22:45.0574 0x0cfc [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe 20:22:45.0588 0x0cfc MSDTC - ok 20:22:45.0592 0x0cfc [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys 20:22:45.0616 0x0cfc Msfs - ok 20:22:45.0619 0x0cfc [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 20:22:45.0644 0x0cfc mshidkmdf - ok 20:22:45.0646 0x0cfc [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 20:22:45.0655 0x0cfc msisadrv - ok 20:22:45.0660 0x0cfc [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 20:22:45.0688 0x0cfc MSiSCSI - ok 20:22:45.0690 0x0cfc msiserver - ok 20:22:45.0693 0x0cfc [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 20:22:45.0717 0x0cfc MSKSSRV - ok 20:22:45.0719 0x0cfc [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 20:22:45.0744 0x0cfc MSPCLOCK - ok 20:22:45.0746 0x0cfc [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 20:22:45.0770 0x0cfc MSPQM - ok 20:22:45.0779 0x0cfc [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 20:22:45.0793 0x0cfc MsRPC - ok 20:22:45.0797 0x0cfc [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 20:22:45.0805 0x0cfc mssmbios - ok 20:22:45.0807 0x0cfc [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 20:22:45.0832 0x0cfc MSTEE - ok 20:22:45.0834 0x0cfc [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 20:22:45.0845 0x0cfc MTConfig - ok 20:22:45.0848 0x0cfc [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys 20:22:45.0857 0x0cfc Mup - ok 20:22:45.0865 0x0cfc [ E3B58E3011B207C5289D11173B30E298, 68BDF7DE4FD5E38D33DBAD2A2E05E32BABA8BBD85DBC4364AF7CD62C54C6B539 ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 20:22:45.0876 0x0cfc MyWiFiDHCPDNS - ok 20:22:45.0887 0x0cfc [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll 20:22:45.0922 0x0cfc napagent - ok 20:22:45.0930 0x0cfc [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 20:22:45.0950 0x0cfc NativeWifiP - ok 20:22:45.0969 0x0cfc [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS C:\Windows\system32\drivers\ndis.sys 20:22:45.0994 0x0cfc NDIS - ok 20:22:45.0998 0x0cfc [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 20:22:46.0023 0x0cfc NdisCap - ok 20:22:46.0025 0x0cfc [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 20:22:46.0050 0x0cfc NdisTapi - ok 20:22:46.0053 0x0cfc [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 20:22:46.0077 0x0cfc Ndisuio - ok 20:22:46.0083 0x0cfc [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 20:22:46.0109 0x0cfc NdisWan - ok 20:22:46.0112 0x0cfc [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 20:22:46.0136 0x0cfc NDProxy - ok 20:22:46.0141 0x0cfc [ 2334DC48997BA203B794DF3EE70521DB, 832F4EC1586C9669F2D54AB3B212943E43B87A33B24DCC8CDAD6A0264291EE2F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 20:22:46.0147 0x0cfc Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 ) 20:22:48.0506 0x0cfc Detect skipped due to KSN trusted 20:22:48.0506 0x0cfc Net Driver HPZ12 - ok 20:22:48.0513 0x0cfc [ 6F4607E2333FE21E9E3FF8133A88B35B, F7B7B262D85D03552A8D0F3F91E795B31E3D09020DDA1E3D62A4A3209D916BB6 ] Netaapl C:\Windows\system32\DRIVERS\netaapl64.sys 20:22:48.0525 0x0cfc Netaapl - detected UnsignedFile.Multi.Generic ( 1 ) 20:22:50.0888 0x0cfc Detect skipped due to KSN trusted 20:22:50.0888 0x0cfc Netaapl - ok 20:22:50.0896 0x0cfc [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 20:22:50.0947 0x0cfc NetBIOS - ok 20:22:50.0954 0x0cfc [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 20:22:50.0983 0x0cfc NetBT - ok 20:22:50.0986 0x0cfc [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] Netlogon C:\Windows\system32\lsass.exe 20:22:50.0996 0x0cfc Netlogon - ok 20:22:51.0005 0x0cfc [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll 20:22:51.0038 0x0cfc Netman - ok 20:22:51.0044 0x0cfc [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:22:51.0054 0x0cfc NetMsmqActivator - ok 20:22:51.0057 0x0cfc [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:22:51.0066 0x0cfc NetPipeActivator - ok 20:22:51.0077 0x0cfc [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll 20:22:51.0111 0x0cfc netprofm - ok 20:22:51.0115 0x0cfc [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:22:51.0123 0x0cfc NetTcpActivator - ok 20:22:51.0126 0x0cfc [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:22:51.0134 0x0cfc NetTcpPortSharing - ok 20:22:51.0315 0x0cfc [ B51E9AD4F4E4F8DBE0AB882756BC5DAB, 74E975F3BF39B360C466A0CEEEF545D1B814EE1AEFF6B2FCDD81A33FA276FBF3 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys 20:22:51.0557 0x0cfc NETwNs64 - ok 20:22:51.0571 0x0cfc [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 20:22:51.0580 0x0cfc nfrd960 - ok 20:22:51.0587 0x0cfc [ 8AD77806D336673F270DB31645267293, E23F324913554A23CD043DD27D4305AF62F48C0561A0FC7B7811E55B74B1BE79 ] NlaSvc C:\Windows\System32\nlasvc.dll 20:22:51.0604 0x0cfc NlaSvc - ok 20:22:51.0607 0x0cfc [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys 20:22:51.0631 0x0cfc Npfs - ok 20:22:51.0634 0x0cfc [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll 20:22:51.0659 0x0cfc nsi - ok 20:22:51.0661 0x0cfc [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 20:22:51.0686 0x0cfc nsiproxy - ok 20:22:51.0716 0x0cfc [ B98F8C6E31CD07B2E6F71F7F648E38C0, 2FEA100B80680FBBF644CB6763738804155DF1E94A6542CAE2B2786D770D554E ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 20:22:51.0754 0x0cfc Ntfs - ok 20:22:51.0761 0x0cfc [ A773AA47341A1FD16C6A9BA3C11D7DAA, 55BA057FD11856BEB5F8C31CE3F422B53ABAACE565933B658882635A95231E6E ] ntk_PowerDVD12 C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys 20:22:51.0770 0x0cfc ntk_PowerDVD12 - ok 20:22:51.0772 0x0cfc [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys 20:22:51.0796 0x0cfc Null - ok 20:22:52.0026 0x0cfc [ 5104BAC2DA2A5BDD86AC6B0708B00F06, A02501514F8517CB5A6CFE4352A3D0F864153470015589428A6B14477E791514 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 20:22:52.0273 0x0cfc nvlddmkm - ok 20:22:52.0287 0x0cfc [ 918841B2454F4F2BD94479692079490B, 16667315DE4EB5543E176273362791B157223E775ED1CF285330CC8195E0F1BB ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys 20:22:52.0296 0x0cfc nvpciflt - ok 20:22:52.0301 0x0cfc [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys 20:22:52.0312 0x0cfc nvraid - ok 20:22:52.0317 0x0cfc [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys 20:22:52.0327 0x0cfc nvstor - ok 20:22:52.0345 0x0cfc [ DDFAFCE89A5C93D04712B86F94E9FCBA, 377303D4CAC9E3AD5B58894CF7AECDA4FCD3D721568BE8BACC0A897A0956919A ] nvsvc C:\Windows\system32\nvvsvc.exe 20:22:52.0367 0x0cfc nvsvc - ok 20:22:52.0391 0x0cfc [ 84E035225474E48CD3A6A3CE52332095, C90E1BC112EDED3035F2D440DDA6FC838D5D9B5F0D7CBE5E4672FEB1CC49F449 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 20:22:52.0422 0x0cfc nvUpdatusService - ok 20:22:52.0427 0x0cfc [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 20:22:52.0437 0x0cfc nv_agp - ok 20:22:52.0440 0x0cfc [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 20:22:52.0452 0x0cfc ohci1394 - ok 20:22:52.0460 0x0cfc [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 20:22:52.0478 0x0cfc p2pimsvc - ok 20:22:52.0488 0x0cfc [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll 20:22:52.0507 0x0cfc p2psvc - ok 20:22:52.0511 0x0cfc [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\drivers\parport.sys 20:22:52.0523 0x0cfc Parport - ok 20:22:52.0527 0x0cfc [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys 20:22:52.0536 0x0cfc partmgr - ok 20:22:52.0542 0x0cfc [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc C:\Windows\System32\pcasvc.dll 20:22:52.0559 0x0cfc PcaSvc - ok 20:22:52.0566 0x0cfc [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys 20:22:52.0577 0x0cfc pci - ok 20:22:52.0579 0x0cfc [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys 20:22:52.0588 0x0cfc pciide - ok 20:22:52.0594 0x0cfc [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 20:22:52.0606 0x0cfc pcmcia - ok 20:22:52.0609 0x0cfc [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys 20:22:52.0617 0x0cfc pcw - ok 20:22:52.0631 0x0cfc [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH C:\Windows\system32\drivers\peauth.sys 20:22:52.0668 0x0cfc PEAUTH - ok 20:22:52.0694 0x0cfc [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 20:22:52.0733 0x0cfc PeerDistSvc - ok 20:22:52.0747 0x0cfc [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe 20:22:52.0759 0x0cfc PerfHost - ok 20:22:52.0787 0x0cfc [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll 20:22:52.0840 0x0cfc pla - ok 20:22:52.0851 0x0cfc [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 20:22:52.0871 0x0cfc PlugPlay - ok 20:22:52.0876 0x0cfc [ AC78DF349F0E4CFB8B667C0CFFF83CCE, 7E635AA2E7350FCA0C954E697F1480A6204920AEFBCF06B90FFA02398DA82822 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 20:22:52.0882 0x0cfc Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 ) 20:22:55.0238 0x0cfc Detect skipped due to KSN trusted 20:22:55.0238 0x0cfc Pml Driver HPZ12 - ok 20:22:55.0246 0x0cfc PnkBstrA - ok 20:22:55.0252 0x0cfc [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 20:22:55.0280 0x0cfc PNRPAutoReg - ok 20:22:55.0295 0x0cfc [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 20:22:55.0318 0x0cfc PNRPsvc - ok 20:22:55.0330 0x0cfc [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 20:22:55.0364 0x0cfc PolicyAgent - ok 20:22:55.0371 0x0cfc [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll 20:22:55.0399 0x0cfc Power - ok 20:22:55.0403 0x0cfc [ CA1BA673AD28BA75D7EC2665EEC3206D, E99F9E2FC725CC4E9CA50D75B46012E5C6F05DDB43A919A5C0BE9B4F6AFBF1D6 ] PowerBiosServer C:\Program Files (x86)\Hotkey\PowerBiosServer.exe 20:22:55.0408 0x0cfc PowerBiosServer - detected UnsignedFile.Multi.Generic ( 1 ) 20:22:57.0765 0x0cfc Detect skipped due to KSN trusted 20:22:57.0765 0x0cfc PowerBiosServer - ok 20:22:57.0775 0x0cfc [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 20:22:57.0822 0x0cfc PptpMiniport - ok 20:22:57.0825 0x0cfc [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\drivers\processr.sys 20:22:57.0837 0x0cfc Processor - ok 20:22:57.0843 0x0cfc [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc C:\Windows\system32\profsvc.dll 20:22:57.0859 0x0cfc ProfSvc - ok 20:22:57.0861 0x0cfc [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] ProtectedStorage C:\Windows\system32\lsass.exe 20:22:57.0872 0x0cfc ProtectedStorage - ok 20:22:57.0877 0x0cfc [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 20:22:57.0903 0x0cfc Psched - ok 20:22:57.0931 0x0cfc [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 20:22:57.0967 0x0cfc ql2300 - ok 20:22:57.0972 0x0cfc [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 20:22:57.0982 0x0cfc ql40xx - ok 20:22:57.0989 0x0cfc [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll 20:22:58.0007 0x0cfc QWAVE - ok 20:22:58.0010 0x0cfc [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 20:22:58.0024 0x0cfc QWAVEdrv - ok 20:22:58.0027 0x0cfc [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 20:22:58.0051 0x0cfc RasAcd - ok 20:22:58.0055 0x0cfc [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 20:22:58.0080 0x0cfc RasAgileVpn - ok 20:22:58.0084 0x0cfc [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll 20:22:58.0112 0x0cfc RasAuto - ok 20:22:58.0117 0x0cfc [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 20:22:58.0144 0x0cfc Rasl2tp - ok 20:22:58.0152 0x0cfc [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll 20:22:58.0184 0x0cfc RasMan - ok 20:22:58.0188 0x0cfc [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 20:22:58.0216 0x0cfc RasPppoe - ok 20:22:58.0220 0x0cfc [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 20:22:58.0247 0x0cfc RasSstp - ok 20:22:58.0254 0x0cfc [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 20:22:58.0285 0x0cfc rdbss - ok 20:22:58.0288 0x0cfc [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 20:22:58.0301 0x0cfc rdpbus - ok 20:22:58.0304 0x0cfc [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 20:22:58.0328 0x0cfc RDPCDD - ok 20:22:58.0335 0x0cfc [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 20:22:58.0349 0x0cfc RDPDR - ok 20:22:58.0352 0x0cfc [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 20:22:58.0377 0x0cfc RDPENCDD - ok 20:22:58.0381 0x0cfc [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 20:22:58.0407 0x0cfc RDPREFMP - ok 20:22:58.0413 0x0cfc [ E61608AA35E98999AF9AAEEEA6114B0A, F754CDE89DC96786D2A3C4D19EE2AEF1008E634E4DE3C0CBF927436DE90C04A6 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 20:22:58.0428 0x0cfc RDPWD - ok 20:22:58.0434 0x0cfc [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 20:22:58.0446 0x0cfc rdyboost - ok 20:22:58.0452 0x0cfc [ F3AF2B43F35DBB3A0EB9FEEEC7D62217, 5BFB97BFE94F52CE02DFB2B7E8A9AD34AE489B77BA689F63D733EFB65548D734 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 20:22:58.0461 0x0cfc RegSrvc - ok 20:22:58.0466 0x0cfc [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll 20:22:58.0493 0x0cfc RemoteAccess - ok 20:22:58.0499 0x0cfc [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll 20:22:58.0528 0x0cfc RemoteRegistry - ok 20:22:58.0530 0x0cfc RimUsb - ok 20:22:58.0534 0x0cfc [ 4AAFFFA67AC4DFA3D9985D78573887E2, A2A4623A1DFA3C1BF0B09390F3731AFF5616BF9E9144F5DEEAA89B37E445D834 ] RimVSerPort C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys 20:22:58.0544 0x0cfc RimVSerPort - ok 20:22:58.0547 0x0cfc [ 388D3DD1A6457280F3BADBA9F3ACD6B1, 5C534EA15195B1301C917904627AF09FE2ABA3FEE1641B5C87E8F3191BC49058 ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys 20:22:58.0573 0x0cfc ROOTMODEM - ok 20:22:58.0577 0x0cfc [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 20:22:58.0603 0x0cfc RpcEptMapper - ok 20:22:58.0606 0x0cfc [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe 20:22:58.0617 0x0cfc RpcLocator - ok 20:22:58.0621 0x0cfc [ 6684437F3628EF237C354F77D33426D1, ABFCB62E688303373E3898ED479271F4F1133A64ED58868969CE314B7D871BC9 ] rpcnet C:\Windows\SysWOW64\rpcnet.exe 20:22:58.0629 0x0cfc rpcnet - ok 20:22:58.0640 0x0cfc [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\Windows\system32\rpcss.dll 20:22:58.0673 0x0cfc RpcSs - ok 20:22:58.0682 0x0cfc [ CED82FC17230CAE5AE7DE24A19D31361, 47FAA0184C4035A39E767E42EE43716A638BA3FDA13448C01DDCB2D66B6B8D5C ] RSBASTOR C:\Windows\system32\DRIVERS\RtsBaStor.sys 20:22:58.0696 0x0cfc RSBASTOR - ok 20:22:58.0700 0x0cfc [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 20:22:58.0726 0x0cfc rspndr - ok 20:22:58.0740 0x0cfc [ C5CD940EFFADE1F6246730BCA14E9FE6, 89DA870C50765D6E7344DCE56CDEB590BAC6927EA6C41B4F05B1C5C3D6ECA1FA ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 20:22:58.0760 0x0cfc RTL8167 - ok 20:22:58.0763 0x0cfc [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys 20:22:58.0774 0x0cfc s3cap - ok 20:22:58.0776 0x0cfc [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] SamSs C:\Windows\system32\lsass.exe 20:22:58.0787 0x0cfc SamSs - ok 20:22:58.0791 0x0cfc [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 20:22:58.0800 0x0cfc sbp2port - ok 20:22:58.0806 0x0cfc [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll 20:22:58.0835 0x0cfc SCardSvr - ok 20:22:58.0838 0x0cfc [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 20:22:58.0863 0x0cfc scfilter - ok 20:22:58.0883 0x0cfc [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\Windows\system32\schedsvc.dll 20:22:58.0930 0x0cfc Schedule - ok 20:22:58.0935 0x0cfc [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll 20:22:58.0959 0x0cfc SCPolicySvc - ok 20:22:58.0964 0x0cfc [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll 20:22:58.0979 0x0cfc SDRSVC - ok 20:22:58.0983 0x0cfc [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys 20:22:59.0007 0x0cfc secdrv - ok 20:22:59.0010 0x0cfc [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\Windows\system32\seclogon.dll 20:22:59.0035 0x0cfc seclogon - ok 20:22:59.0038 0x0cfc [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\system32\sens.dll 20:22:59.0066 0x0cfc SENS - ok 20:22:59.0069 0x0cfc [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll 20:22:59.0081 0x0cfc SensrSvc - ok 20:22:59.0084 0x0cfc [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\drivers\serenum.sys 20:22:59.0095 0x0cfc Serenum - ok 20:22:59.0098 0x0cfc [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\drivers\serial.sys 20:22:59.0111 0x0cfc Serial - ok 20:22:59.0114 0x0cfc [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\drivers\sermouse.sys 20:22:59.0125 0x0cfc sermouse - ok 20:22:59.0132 0x0cfc [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll 20:22:59.0159 0x0cfc SessionEnv - ok 20:22:59.0162 0x0cfc [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 20:22:59.0174 0x0cfc sffdisk - ok 20:22:59.0176 0x0cfc [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 20:22:59.0189 0x0cfc sffp_mmc - ok 20:22:59.0191 0x0cfc [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 20:22:59.0203 0x0cfc sffp_sd - ok 20:22:59.0206 0x0cfc [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 20:22:59.0216 0x0cfc sfloppy - ok 20:22:59.0226 0x0cfc [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll 20:22:59.0260 0x0cfc SharedAccess - ok 20:22:59.0270 0x0cfc [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 20:22:59.0302 0x0cfc ShellHWDetection - ok 20:22:59.0305 0x0cfc [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 20:22:59.0314 0x0cfc SiSRaid2 - ok 20:22:59.0318 0x0cfc [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 20:22:59.0327 0x0cfc SiSRaid4 - ok 20:22:59.0334 0x0cfc [ 3E587DBBDFF938DDE5D4CE4047BE9041, CA13B2C50FB09365362077AEC4B25120CF09F8C35702F645922D618FE57B5E05 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 20:22:59.0343 0x0cfc SkypeUpdate - ok 20:22:59.0348 0x0cfc [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys 20:22:59.0375 0x0cfc Smb - ok 20:22:59.0380 0x0cfc [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 20:22:59.0393 0x0cfc SNMPTRAP - ok 20:22:59.0395 0x0cfc [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys 20:22:59.0403 0x0cfc spldr - ok 20:22:59.0416 0x0cfc [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler C:\Windows\System32\spoolsv.exe 20:22:59.0438 0x0cfc Spooler - ok 20:22:59.0497 0x0cfc [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe 20:22:59.0587 0x0cfc sppsvc - ok 20:22:59.0593 0x0cfc [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll 20:22:59.0620 0x0cfc sppuinotify - ok 20:22:59.0633 0x0cfc [ 34F974F8B3C86DE03A30DCBE79091C97, 14E12E3A145F898CB8B89FB75E0100D47D04E3BFD3078C315FE1F3CBF30FEFEE ] sptd C:\Windows\system32\Drivers\sptd.sys 20:22:59.0633 0x0cfc Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\sptd.sys. md5: 34F974F8B3C86DE03A30DCBE79091C97, sha256: 14E12E3A145F898CB8B89FB75E0100D47D04E3BFD3078C315FE1F3CBF30FEFEE 20:22:59.0634 0x0cfc sptd - detected LockedFile.Multi.Generic ( 1 ) 20:23:01.0993 0x0cfc Detect skipped due to KSN trusted 20:23:01.0993 0x0cfc sptd - ok 20:23:02.0017 0x0cfc [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\Windows\system32\DRIVERS\srv.sys 20:23:02.0050 0x0cfc srv - ok 20:23:02.0060 0x0cfc [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 20:23:02.0079 0x0cfc srv2 - ok 20:23:02.0084 0x0cfc [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 20:23:02.0098 0x0cfc srvnet - ok 20:23:02.0104 0x0cfc [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 20:23:02.0134 0x0cfc SSDPSRV - ok 20:23:02.0138 0x0cfc [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll 20:23:02.0165 0x0cfc SstpSvc - ok 20:23:02.0167 0x0cfc Steam Client Service - ok 20:23:02.0170 0x0cfc [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\drivers\stexstor.sys 20:23:02.0179 0x0cfc stexstor - ok 20:23:02.0182 0x0cfc [ DECACB6921DED1A38642642685D77DAC, 1633711CE973F818EBCCCA28538772431167C33ECDD44D1E846A9436598B52DC ] StillCam C:\Windows\system32\drivers\serscan.sys 20:23:02.0193 0x0cfc StillCam - ok 20:23:02.0206 0x0cfc [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll 20:23:02.0231 0x0cfc stisvc - ok 20:23:02.0234 0x0cfc [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys 20:23:02.0243 0x0cfc storflt - ok 20:23:02.0246 0x0cfc [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc C:\Windows\system32\storsvc.dll 20:23:02.0258 0x0cfc StorSvc - ok 20:23:02.0261 0x0cfc [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys 20:23:02.0269 0x0cfc storvsc - ok 20:23:02.0272 0x0cfc [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 20:23:02.0280 0x0cfc swenum - ok 20:23:02.0292 0x0cfc [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll 20:23:02.0327 0x0cfc swprv - ok 20:23:02.0360 0x0cfc [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\Windows\system32\sysmain.dll 20:23:02.0410 0x0cfc SysMain - ok 20:23:02.0416 0x0cfc [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll 20:23:02.0432 0x0cfc TabletInputService - ok 20:23:02.0441 0x0cfc [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll 20:23:02.0471 0x0cfc TapiSrv - ok 20:23:02.0475 0x0cfc [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\Windows\System32\tbssvc.dll 20:23:02.0501 0x0cfc TBS - ok 20:23:02.0535 0x0cfc [ 40AF23633D197905F03AB5628C558C51, 644656A15236E964E4BE57B42225EAA5643C4CF1FFF6D306813A000716F9D72C ] Tcpip C:\Windows\system32\drivers\tcpip.sys 20:23:02.0577 0x0cfc Tcpip - ok 20:23:02.0611 0x0cfc [ 40AF23633D197905F03AB5628C558C51, 644656A15236E964E4BE57B42225EAA5643C4CF1FFF6D306813A000716F9D72C ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 20:23:02.0648 0x0cfc TCPIP6 - ok 20:23:02.0654 0x0cfc [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 20:23:02.0665 0x0cfc tcpipreg - ok 20:23:02.0669 0x0cfc [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 20:23:02.0679 0x0cfc TDPIPE - ok 20:23:02.0682 0x0cfc [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 20:23:02.0692 0x0cfc TDTCP - ok 20:23:02.0697 0x0cfc [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 20:23:02.0722 0x0cfc tdx - ok 20:23:02.0726 0x0cfc [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 20:23:02.0735 0x0cfc TermDD - ok 20:23:02.0750 0x0cfc [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC4EB052E6EBCBCD ] TermService C:\Windows\System32\termsrv.dll 20:23:02.0787 0x0cfc TermService - ok 20:23:02.0791 0x0cfc [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll 20:23:02.0805 0x0cfc Themes - ok 20:23:02.0809 0x0cfc [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll 20:23:02.0833 0x0cfc THREADORDER - ok 20:23:02.0838 0x0cfc [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll 20:23:02.0866 0x0cfc TrkWks - ok 20:23:02.0872 0x0cfc [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 20:23:02.0898 0x0cfc TrustedInstaller - ok 20:23:02.0902 0x0cfc [ 4CE278FC9671BA81A138D70823FCAA09, CBE501436696E32A3701B9F377B823AC36647B6626595F76CC63E2396AD7D300 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 20:23:02.0913 0x0cfc tssecsrv - ok 20:23:02.0917 0x0cfc [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 20:23:02.0928 0x0cfc TsUsbFlt - ok 20:23:02.0931 0x0cfc [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 20:23:02.0941 0x0cfc TsUsbGD - ok 20:23:02.0946 0x0cfc [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 20:23:02.0972 0x0cfc tunnel - ok 20:23:02.0976 0x0cfc [ 42350E49DA754D2D77362FDAE3491651, F29E8BA444ECB0484066B02C0A3DCE09B8417159EE37D7A2E05D4C06A98449C4 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys 20:23:02.0985 0x0cfc TurboB - ok 20:23:02.0991 0x0cfc [ 4F4B0AB2FB69C414CCBCEF7CF2E1C8D8, E1F197554369C97DBF61389346B4CB0233F40AAA2575F5D2FEC809AC9123FC69 ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe 20:23:03.0000 0x0cfc TurboBoost - ok 20:23:03.0004 0x0cfc [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 20:23:03.0013 0x0cfc uagp35 - ok 20:23:03.0021 0x0cfc [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 20:23:03.0051 0x0cfc udfs - ok 20:23:03.0057 0x0cfc [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe 20:23:03.0070 0x0cfc UI0Detect - ok 20:23:03.0073 0x0cfc [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 20:23:03.0082 0x0cfc uliagpkx - ok 20:23:03.0086 0x0cfc [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\DRIVERS\umbus.sys 20:23:03.0098 0x0cfc umbus - ok 20:23:03.0101 0x0cfc [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\drivers\umpass.sys 20:23:03.0111 0x0cfc UmPass - ok 20:23:03.0118 0x0cfc [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll 20:23:03.0133 0x0cfc UmRdpService - ok 20:23:03.0143 0x0cfc [ 5A5D20BD5BA50B8F671CDA78585729D5, 1B537183E883D64F8D6B6FC6CC01F62ED6EE744AB43124CB25EF55CA3A775558 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 20:23:03.0156 0x0cfc UNS - ok 20:23:03.0165 0x0cfc [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll 20:23:03.0198 0x0cfc upnphost - ok 20:23:03.0203 0x0cfc [ C9E9D59C0099A9FF51697E9306A44240, 78D9A7A5E5742962B6978F475BF06CB32262F1D214699D3D40538476A58012A1 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 20:23:03.0214 0x0cfc USBAAPL64 - ok 20:23:03.0219 0x0cfc [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68CCE47B1CFE5F12 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 20:23:03.0232 0x0cfc usbccgp - ok 20:23:03.0236 0x0cfc [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys 20:23:03.0249 0x0cfc usbcir - ok 20:23:03.0252 0x0cfc [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C36E6BB2045A3D9 ] usbehci C:\Windows\system32\drivers\usbehci.sys 20:23:03.0264 0x0cfc usbehci - ok 20:23:03.0273 0x0cfc [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B2109B05A4F462D4E ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 20:23:03.0290 0x0cfc usbhub - ok 20:23:03.0293 0x0cfc [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F110F296C377077B0 ] usbohci C:\Windows\system32\drivers\usbohci.sys 20:23:03.0303 0x0cfc usbohci - ok 20:23:03.0307 0x0cfc [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 20:23:03.0320 0x0cfc usbprint - ok 20:23:03.0323 0x0cfc [ 2C42E595E7E381596B9A14F88F5AE027, 948C2AD7FA0B01184312D1ABE43F2F3D85A934CF0658A8B2BDF9F0919568377B ] usbrndis6 C:\Windows\system32\drivers\usb80236.sys 20:23:03.0334 0x0cfc usbrndis6 - ok 20:23:03.0338 0x0cfc [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan C:\Windows\system32\drivers\usbscan.sys 20:23:03.0349 0x0cfc usbscan - ok 20:23:03.0353 0x0cfc [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:23:03.0366 0x0cfc USBSTOR - ok 20:23:03.0369 0x0cfc [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D10895EBA48D981E25 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 20:23:03.0380 0x0cfc usbuhci - ok 20:23:03.0386 0x0cfc [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 20:23:03.0400 0x0cfc usbvideo - ok 20:23:03.0403 0x0cfc [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll 20:23:03.0431 0x0cfc UxSms - ok 20:23:03.0434 0x0cfc [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] VaultSvc C:\Windows\system32\lsass.exe 20:23:03.0444 0x0cfc VaultSvc - ok 20:23:03.0447 0x0cfc [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 20:23:03.0456 0x0cfc vdrvroot - ok 20:23:03.0468 0x0cfc [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe 20:23:03.0505 0x0cfc vds - ok 20:23:03.0509 0x0cfc [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 20:23:03.0522 0x0cfc vga - ok 20:23:03.0525 0x0cfc [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys 20:23:03.0551 0x0cfc VgaSave - ok 20:23:03.0557 0x0cfc [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 20:23:03.0569 0x0cfc vhdmp - ok 20:23:03.0572 0x0cfc [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys 20:23:03.0581 0x0cfc viaide - ok 20:23:03.0587 0x0cfc [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys 20:23:03.0598 0x0cfc vmbus - ok 20:23:03.0601 0x0cfc [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 20:23:03.0611 0x0cfc VMBusHID - ok 20:23:03.0615 0x0cfc [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys 20:23:03.0624 0x0cfc volmgr - ok 20:23:03.0633 0x0cfc [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 20:23:03.0647 0x0cfc volmgrx - ok 20:23:03.0655 0x0cfc [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys 20:23:03.0668 0x0cfc volsnap - ok 20:23:03.0673 0x0cfc [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 20:23:03.0684 0x0cfc vsmraid - ok 20:23:03.0713 0x0cfc [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe 20:23:03.0767 0x0cfc VSS - ok 20:23:03.0771 0x0cfc [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 20:23:03.0783 0x0cfc vwifibus - ok 20:23:03.0787 0x0cfc [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 20:23:03.0801 0x0cfc vwififlt - ok 20:23:03.0804 0x0cfc [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 20:23:03.0817 0x0cfc vwifimp - ok 20:23:03.0827 0x0cfc [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll 20:23:03.0859 0x0cfc W32Time - ok 20:23:03.0863 0x0cfc [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 20:23:03.0874 0x0cfc WacomPen - ok 20:23:03.0878 0x0cfc [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 20:23:03.0903 0x0cfc WANARP - ok 20:23:03.0907 0x0cfc [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 20:23:03.0931 0x0cfc Wanarpv6 - ok 20:23:03.0961 0x0cfc [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe 20:23:04.0004 0x0cfc wbengine - ok 20:23:04.0012 0x0cfc [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 20:23:04.0030 0x0cfc WbioSrvc - ok 20:23:04.0038 0x0cfc [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll 20:23:04.0060 0x0cfc wcncsvc - ok 20:23:04.0063 0x0cfc [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 20:23:04.0076 0x0cfc WcsPlugInService - ok 20:23:04.0078 0x0cfc [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\drivers\wd.sys 20:23:04.0087 0x0cfc Wd - ok 20:23:04.0103 0x0cfc [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 20:23:04.0126 0x0cfc Wdf01000 - ok 20:23:04.0130 0x0cfc [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost C:\Windows\system32\wdi.dll 20:23:04.0146 0x0cfc WdiServiceHost - ok 20:23:04.0149 0x0cfc [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost C:\Windows\system32\wdi.dll 20:23:04.0164 0x0cfc WdiSystemHost - ok 20:23:04.0171 0x0cfc [ 0EB0E5D22B1760F2DBCE632F2DD7A54D, B8A4CC62F88768947FB0A161CF9564DB28FD9C1C037B5475DF192982DE035C22 ] WebClient C:\Windows\System32\webclnt.dll 20:23:04.0187 0x0cfc WebClient - ok 20:23:04.0194 0x0cfc [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll 20:23:04.0224 0x0cfc Wecsvc - ok 20:23:04.0228 0x0cfc [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll 20:23:04.0255 0x0cfc wercplsupport - ok 20:23:04.0259 0x0cfc [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll 20:23:04.0286 0x0cfc WerSvc - ok 20:23:04.0290 0x0cfc [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 20:23:04.0314 0x0cfc WfpLwf - ok 20:23:04.0317 0x0cfc [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 20:23:04.0327 0x0cfc WIMMount - ok 20:23:04.0329 0x0cfc WinDefend - ok 20:23:04.0334 0x0cfc WinHttpAutoProxySvc - ok 20:23:04.0343 0x0cfc [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 20:23:04.0374 0x0cfc Winmgmt - ok 20:23:04.0409 0x0cfc [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM C:\Windows\system32\WsmSvc.dll 20:23:04.0475 0x0cfc WinRM - ok 20:23:04.0483 0x0cfc [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 20:23:04.0495 0x0cfc WinUsb - ok 20:23:04.0514 0x0cfc [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll 20:23:04.0546 0x0cfc Wlansvc - ok 20:23:04.0587 0x0cfc [ 357CABBF155AFD1D3926E62539D2A3A7, C43CFF84E7D930B4999DC061AB0766B57AAD7540B3E6EE54605B10ECE90825F5 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 20:23:04.0631 0x0cfc wlidsvc - ok 20:23:04.0636 0x0cfc [ 680A7846370000D20D7E74917D5B7936, 55B77B358039672845D361CA4205F3482D1F30A4654B610FD785A1337EFDC316 ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys 20:23:04.0644 0x0cfc WmBEnum - ok 20:23:04.0648 0x0cfc [ 14C35BA8189C6F65D839163AA285E954, 8981AA488320C75E26E1ABDF884B721A4065F5D28F54782598B03F21B8CDC020 ] WmFilter C:\Windows\system32\drivers\WmFilter.sys 20:23:04.0656 0x0cfc WmFilter - ok 20:23:04.0659 0x0cfc [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 20:23:04.0670 0x0cfc WmiAcpi - ok 20:23:04.0678 0x0cfc [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 20:23:04.0693 0x0cfc wmiApSrv - ok 20:23:04.0696 0x0cfc WMPNetworkSvc - ok 20:23:04.0699 0x0cfc [ 8488DD91A3EE54A8E29F02AD7BB8201E, D428ED991D9E4A8765C240B21884A262854278698D60862117AC5949713231F9 ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys 20:23:04.0707 0x0cfc WmVirHid - ok 20:23:04.0710 0x0cfc [ 14802B3A30AA849C97CB968CCC813BF3, 330AD828ABD040ECDBF58F7162978CD61BFC093CAD404FD2BCAC74E3F2EC542A ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys 20:23:04.0719 0x0cfc WmXlCore - ok 20:23:04.0722 0x0cfc [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll 20:23:04.0734 0x0cfc WPCSvc - ok 20:23:04.0738 0x0cfc [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 20:23:04.0755 0x0cfc WPDBusEnum - ok 20:23:04.0758 0x0cfc [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 20:23:04.0782 0x0cfc ws2ifsl - ok 20:23:04.0787 0x0cfc [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\system32\wscsvc.dll 20:23:04.0803 0x0cfc wscsvc - ok 20:23:04.0805 0x0cfc WSearch - ok 20:23:04.0849 0x0cfc [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv C:\Windows\system32\wuaueng.dll 20:23:04.0900 0x0cfc wuauserv - ok 20:23:04.0906 0x0cfc [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 20:23:04.0918 0x0cfc WudfPf - ok 20:23:04.0925 0x0cfc [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 20:23:04.0938 0x0cfc WUDFRd - ok 20:23:04.0943 0x0cfc [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 20:23:04.0955 0x0cfc wudfsvc - ok 20:23:04.0962 0x0cfc [ FE90B750AB808FB9DD8FBB428B5FF83B, 3F8F592EC813BE292D305A87C5BA852F8BC3D7CE610612D9871F209A17326AA8 ] WwanSvc C:\Windows\System32\wwansvc.dll 20:23:04.0978 0x0cfc WwanSvc - ok 20:23:04.0993 0x0cfc [ 74713CB32792F9C7632DAA7DA22CA974, 1B1D907F8F18AE22E36F371EE6417D068C01FB4F9413571444AF3845A27F3C4D ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe 20:23:05.0009 0x0cfc ZeroConfigService - ok 20:23:05.0020 0x0cfc [ 6F58BD07113A38412A6AE6566A3B36A0, 1D1A6342F776C74D49D589548F5F00A549C4A32F35D08858D55D5EB8A55EED81 ] {73526619-C24F-470B-9BED-53D455FBB5C6} C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl 20:23:05.0030 0x0cfc {73526619-C24F-470B-9BED-53D455FBB5C6} - ok 20:23:05.0038 0x0cfc ================ Scan global =============================== 20:23:05.0040 0x0cfc [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll 20:23:05.0047 0x0cfc [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll 20:23:05.0056 0x0cfc [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll 20:23:05.0062 0x0cfc [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll 20:23:05.0071 0x0cfc [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe 20:23:05.0077 0x0cfc [ Global ] - ok 20:23:05.0077 0x0cfc ================ Scan MBR ================================== 20:23:05.0078 0x0cfc [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 20:23:05.0167 0x0cfc \Device\Harddisk0\DR0 - ok 20:23:05.0465 0x0cfc [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1 20:23:05.0634 0x0cfc \Device\Harddisk1\DR1 - ok 20:23:05.0635 0x0cfc ================ Scan VBR ================================== 20:23:05.0639 0x0cfc [ 58766EB62FB4F8FD7B0798CF7960A7A4 ] \Device\Harddisk0\DR0\Partition1 20:23:05.0641 0x0cfc \Device\Harddisk0\DR0\Partition1 - ok 20:23:05.0644 0x0cfc [ 873B7E6A5C81F51F07C9DB765ACD6AED ] \Device\Harddisk0\DR0\Partition2 20:23:05.0645 0x0cfc \Device\Harddisk0\DR0\Partition2 - ok 20:23:05.0678 0x0cfc [ 0D00C4B89D2F4F11ED19CDCD95B29682 ] \Device\Harddisk1\DR1\Partition1 20:23:05.0681 0x0cfc \Device\Harddisk1\DR1\Partition1 - ok 20:23:05.0682 0x0cfc Waiting for KSN requests completion. In queue: 218 20:23:06.0682 0x0cfc Waiting for KSN requests completion. In queue: 218 20:23:07.0682 0x0cfc Waiting for KSN requests completion. In queue: 218 20:23:08.0696 0x0cfc AV detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\wmiav.exe ( 13.0.1.4190 ), 0x41000 ( enabled : updated ) 20:23:08.0701 0x0cfc FW detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\wmifw.exe ( 13.0.1.4190 ), 0x41010 ( enabled ) 20:23:11.0121 0x0cfc ============================================================ 20:23:11.0121 0x0cfc Scan finished 20:23:11.0121 0x0cfc ============================================================ 20:23:11.0134 0x1990 Detected object count: 0 20:23:11.0134 0x1990 Actual detected object count: 0 Geändert von cosinus (09.11.2013 um 23:14 Uhr) Grund: CODE-Tags |
09.11.2013, 23:18 | #21 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exe Die Logs bitte in CODE-Tags und nicht in QUOTE- (zitat) oder anderen Tags posten. Habs für dich korrigiert. Bitte mal ein Kontrollscan mit ESET machen: ESET Online Scanner
__________________ --> Trojan.BitcoinMiner befall u. a. von svchost.exe |
11.11.2013, 11:29 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exe Hast du eigentlich noch den Orbit Downloader installiert? Lies mal bitte => Warnung vor Orbit Downloader | heise Security
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2013, 12:35 | #23 |
| Trojan.BitcoinMiner befall u. a. von svchost.exe Den Orbit Downloader? Ich glaube den hatte ich nie installiert oder hast du iwelche spuren in den Logs davon gefunden? Also ich bin mir sehr sicher das ich den nie installiert habe. Hab den Online-Scann gemacht. Es wurden 3 Funde gemeldet. Log dazu Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=b3f8676dd4d86e4c8be2b6d363ec3185 # engine=15844 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-12 12:49:58 # local_time=2013-11-12 01:49:58 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1286 16777213 100 98 8313 38983720 0 0 # compatibility_mode=5893 16776573 100 94 193929 135847248 0 0 # scanned=216974 # found=0 # cleaned=0 # scan_time=4509 ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=b3f8676dd4d86e4c8be2b6d363ec3185 # engine=15895 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-15 11:29:23 # local_time=2013-11-15 12:29:23 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1286 16777214 100 98 7482 39281285 0 0 # compatibility_mode=5893 16776573 100 94 140776 136144813 0 0 # scanned=297591 # found=3 # cleaned=0 # scan_time=3646 sh=849C55C1FF7DD35954AC0168217CB4156CF54416 ft=1 fh=d35aff3205e90d5e vn="Win32/AdWare.1ClickDownload.AP application" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-3856524493-717638516-2450426649-1000\$RBU8VRL.exe" sh=849C55C1FF7DD35954AC0168217CB4156CF54416 ft=1 fh=d35aff3205e90d5e vn="Win32/AdWare.1ClickDownload.AP application" ac=I fn="C:\Users\Carl\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000000" sh=9357AD524EC7D326F3FAEDB37BC88A2C99383120 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AD trojan" ac=I fn="C:\Users\Carl\AppData\Roaming\Origin\update.vbe" |
15.11.2013, 12:40 | #24 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exeZitat:
Wenn die Datei schon ausgewertet sein sollte, bitte eine weitere Auswertung starten.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.11.2013, 13:01 | #25 |
| Trojan.BitcoinMiner befall u. a. von svchost.exe https://www.virustotal.com/de/file/005a2c2e2e335afe5f77c6aeeae48dee65a9a17a7c1e036ffba769efe4893cd0/analysis/1384516818/ |
15.11.2013, 14:14 | #26 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exe Hm, sieht eher nach einem Fehlalarm aus. Wird BitCoinMiner denn noch gemeldet?
__________________ Logfiles bitte immer in CODE-Tags posten |
17.11.2013, 17:50 | #27 |
| Trojan.BitcoinMiner befall u. a. von svchost.exe Gerade den Pc hochgefahren und Malwarebytes Anti-Malware meldet sofort (wie bei jedem systemstart) das Trojan.Agent.cn und Trojan.BitCoinminer in Quarantäne verschoben wurden.. Was sind das denn eigntlich für Trojaner? Welche Gefahren gehen von so nem Ding grundsätzlich aus und was kann der auf dem pc anstellen? UND wie fängt man sich so ein teil ein? |
17.11.2013, 21:46 | #28 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exeZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
21.11.2013, 13:12 | #29 |
| Trojan.BitcoinMiner befall u. a. von svchost.exe Die Logs sind die gleichen wie vorher.. hilfreicher wäre mir mal die fragen zu beantworten. werde meine daten sichern und windows neu installieren das wird am schnellsten und effektivsten abhilfe schaffen. danke trotzdem das du dir die zeit genommen hast. |
21.11.2013, 14:08 | #30 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojan.BitcoinMiner befall u. a. von svchost.exeZitat:
Hast du das Kaspersky Log mit allen Funden noch? Du hast am Anfang nur den Name des Schädlings gepostet und selbst Kaspersky stuft den als not-a-virus ein. Ob der Kram eine echte Bedrohung ist weiß ich so nicht, hab mich mit Bitcoin und Bitcoinmining noch nicht auseinandergesetzt. Hast du überhaupt schon was mit Bitcoin gemacht? Ich hatte mr letztens erst einen ähnlichen Fall, sämltiches Fixen und löschen schlugen fehl, weil vor dem Einsatz von FRST bzw Malwarebytes der Virenscanner (in deinem Fall Kaspersky) nicht deaktiviert wurde und somit immer wieder das Löschen/Verschieben verhindert wurde.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Trojan.BitcoinMiner befall u. a. von svchost.exe |
administrator, anti-malware, appdata, bitcoinminer, coinminer, dateien, gelöscht, kaspersky, löschen, malwarebytes, mehrere trojaner, not-a-virus, pup.optional.adlyrics, pup.optional.babylon.a, pup.optional.delta, pup.optional.delta.a, pup.optional.installiq, pup.optional.somoto, super, svchost, svchost.exe, system, trojan.bitcoinminer |