|
Log-Analyse und Auswertung: Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.03.2015, 16:58 | #1 |
| Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert Erster Neustart nach der automatischen Installation der neuen Windows-7-Updates: zahlreiche Fehlermeldungen fehlender *.dll-Dateien, weder Firefox noch Chrome lassen sich starten (exe-Dateien fehlen). Aufrufe einiger anderer exe-Dateien werden mit der Fehlermeldung "Fehlender Parameter" quittiert. System auf den Zustand vor der Update-Installation wiederhergestellt. Unverändertes Problembild. Suche hier im Forum: vermutlich verwandtes Problem zu http://www.trojaner-board.de/164962-...arameter.html. Mit SCF dlls überprüft: einige Fehler (s. Log unten). Verdacht auf Malware. Weder Avira noch Panda lassen sich starten, Fehlermeldung zu avgnt.exe: "Die Anweisung in 0x00000000 verweist auf Speicher 0x000000000. Der Vorgang written konnte nicht im Speicher durchgeführt werden." Aufruf von rKill hängt sich in Endlosschleife auf. Ich bin für jede zielführende Hilfestellung sehr dankbar! Der FRST-Log: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by SYSTEM on MININT-RPE617U on 11-03-2015 15:48:01 Running from F:\ Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2821936 2012-03-07] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1020576 2012-02-20] (Atheros Communications) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2012-02-20] (Atheros Commnucations) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-29] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-23] (Dritek System Inc.) HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703280 2015-03-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [224128 2014-06-16] (Oracle Corporation) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191528 2014-07-04] (Geek Software GmbH) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-10-16] (Panda Security, S.L.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\admin\...\Run: [Akamai NetSession Interface] => C:\Users\admin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.) HKU\admin\...\RunOnce: [Adobe Speed Launcher] => 1419598591 HKU\ivana\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKU\ivana\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup HKU\ivana\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-04-23] (Samsung) ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-05] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-05] (Avira Operations GmbH & Co. KG) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG) S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) S2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-29] (Microsoft Corporation) S2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [142072 2014-10-13] (Panda Security, S.L.) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-29] (Microsoft Corporation) S2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [66808 2014-10-09] (Panda Security, S.L.) S2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-10-16] (Panda Security, S.L.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S2 DsiWMIService; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [X] S2 Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [X] S2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-05] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-03-05] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-27] (Avira Operations GmbH & Co. KG) S2 IntelHaxm; C:\Windows\System32\DRIVERS\IntelHaxm.sys [91392 2014-03-14] () S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) S1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.) S1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.) S1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.) S1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.) S1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [46336 2014-01-16] (Panda Security, S.L.) S1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.) S1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.) S1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.) S1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.) S1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.) S1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.) S1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.) S1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.) S2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [163088 2014-10-13] (Panda Security, S.L.) S2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [121616 2014-10-13] (Panda Security, S.L.) S1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.) S2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.) S2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.) S2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [107792 2014-10-13] (Panda Security, S.L.) S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.) S0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-07-14] (Duplex Secure Ltd.) S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [203672 2013-04-02] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 stdriver; C:\Windows\System32\DRIVERS\stdriverx64.sys [33488 2014-07-10] () ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys FA886682CFC5D36718D3E436AACF10B9 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\btath_flt.sys BCC09E0B0362741D0C084828A1B950F3 C:\Windows\System32\DRIVERS\athrx.sys 947AEA92989FFA16426725F9B94B99CD C:\Windows\System32\DRIVERS\avgntflt.sys 00BF66D168E1A7AA7E1C9F458BBA0B34 C:\Windows\System32\DRIVERS\avipbb.sys 055D318220DD4593F2A8C8FF83707D36 C:\Windows\System32\DRIVERS\avkmgr.sys 390184FAD8FCC1B6DA25AEBAE928C3B6 C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57xdbd.sys F9EB252CD589EBB2F77744450F123F60 C:\Windows\System32\DRIVERS\b57xdmp.sys FFA28D0356212A2DCF304C58E2369494 C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\system32\drivers\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bScsiMSa.sys 45218A053209DA867A9B334CCAD0AD01 C:\Windows\System32\DRIVERS\bScsiSDa.sys FDC00A0F0E37E11DB3DC82990998C4B0 C:\Windows\System32\drivers\btath_a2dp.sys C05ED3246C06EC56F10D85B0304CD09E C:\Windows\System32\drivers\btath_avdt.sys 2D27F7A831657D63AFC78E5E78DCA83F C:\Windows\System32\DRIVERS\btath_bus.sys E6B734A37ADE36FE1A77035F4E484C8C C:\Windows\System32\DRIVERS\btath_hcrp.sys FB3833E63FF602B69C2FF085846DCF43 C:\Windows\System32\DRIVERS\btath_lwflt.sys 371A11C1333BA526263A987A93ACDE3D C:\Windows\System32\DRIVERS\btath_rcp.sys ABCD3C16CA850A7594CEB9AD5D966810 C:\Windows\System32\DRIVERS\btfilter.sys 13BDB661991ACF40ADCB09BD64A8CBEF C:\Windows\System32\DRIVERS\BthEnum.sys CF98190A94F62E405C8CB255018B2315 C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bthpan.sys 02DD601B708DD0667E1331FA8518E9FF C:\Windows\System32\Drivers\BTHport.sys 738D0E9272F59EB7A1449C3EC118E6C4 C:\Windows\System32\Drivers\BTHUSB.sys F188B7394D81010767B6DF3178519A37 C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys E45CDE1C8340DFEDF1D6724263F39E5B C:\Windows\System32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\drivers\csc.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ssudbus.sys 421D371E96480DD3A14EA37D0D2757D1 C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\dmvsc.sys 5DB085A8A6600BE6401F2B24EECB5415 C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 87CE5C8965E101CCCED1F4675557E868 C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Windows\System32\Drivers\ElbyCDIO.sys A05FC7ECA0966EBB70E4D17B855A853B C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ETD.sys 9FD76E7BA1D2A534B7BCF5BD5755E24B C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\iaStor.sys D1753C06EE17E29352B065EACF3F10D0 C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\System32\DRIVERS\igdkmd64.sys 3FB253E8059A1AAC3A8B83A31D094CC5 C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHD64.sys D830262519DDCDFC8BE34EB7047C22DC C:\Windows\System32\DRIVERS\IntcDAud.sys 6C9FFFECA9FED31347D211C5D1FFBD2D C:\Windows\System32\DRIVERS\IntelHaxm.sys 524762664384737EB02F62AC03054ECF C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6 C:\Windows\System32\DRIVERS\k57nd60a.sys E610C2ADF44FFAB91BBA5CA6FC085640 C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys C60C6B9A2E50B0404F6789C62B428C03 C:\Windows\System32\Drivers\ksecpkg.sys 78D152A9FD5747FF6AA89C79F0346F62 C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85 C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\MpFilter.sys FBA4CDA6B3B00D7A116DCC2B5C7E9790 C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys AE3334958D8F631FF14A0AEB3D7EFB3A C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163 C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\NisDrvWFP.sys E10B84385C3FEEF4BDE8E6A980535522 C:\Windows\System32\DRIVERS\NNSAlpc.sys ACC47D60E202EBA0A8A80768EC5D3C97 C:\Windows\System32\DRIVERS\NNSHttp.sys 4C7EAD79B914ADE44D68171AFEEF2AB3 C:\Windows\System32\DRIVERS\NNSHttps.sys B40C57451477334E8A66F4823BE04AE3 C:\Windows\System32\DRIVERS\NNSIds.sys 222CF23D6FCEB616CA48BBA55FC4D5C0 C:\Windows\System32\DRIVERS\NNSNAHSL.sys 735143727C4438A72490A2432E7D5CEA C:\Windows\System32\DRIVERS\NNSPicc.sys C5332A1FB751B8D5FD9D424D330BC91B C:\Windows\System32\DRIVERS\NNSPihsw.sys AA1A311C019288FFCCF3661B5EA27A99 C:\Windows\System32\DRIVERS\NNSPop3.sys EB153B4FA5200D1D3352D6C3FB7C9C38 C:\Windows\System32\DRIVERS\NNSProt.sys 425356A7A3657174C206AA3FDB3DDD35 C:\Windows\System32\DRIVERS\NNSPrv.sys FFDF3257F83A094941005EE607B8A905 C:\Windows\System32\DRIVERS\NNSSmtp.sys DE87A11CB1767ABDDE223D4CC0F7C221 C:\Windows\System32\DRIVERS\NNSStrm.sys 537FB2F711E65475562FE29877F108E1 C:\Windows\System32\DRIVERS\NNSTlsc.sys 4F37DC4420A00BC6E9D22E3590806BFC C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys 1A29A59A4C5BA6F8C85062A613B7E2B2 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\PSINAflt.sys ABF42AF66C50E3FBAD2280020360920E C:\Windows\System32\DRIVERS\PSINFile.sys 54C28488E5F038B29E2D80DBFC910666 C:\Windows\System32\DRIVERS\psinknc.sys 305FCF2F725B806BC5E69AC95340A271 C:\Windows\System32\DRIVERS\PSINProc.sys ED6B1CDE5B178B057F64B2AF682EB45A C:\Windows\System32\DRIVERS\PSINProt.sys 171F1C6F49142F2D1C174B817F46EC0F C:\Windows\System32\DRIVERS\PSINReg.sys 6A19A5665FBE15D63046B20BB0BFD7AB C:\Windows\System32\DRIVERS\PSKMAD.sys 105ACC469DF34C8BD0D5E68A70C774E5 C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41 C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rfcomm.sys 3DD798846E2C28102B922C56E71B7932 C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\sdbus.sys 111E0EBC0AD79CB0FA014B907B231CF0 C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\Drivers\sptd.sys 74D30C2EF66C2EB19F17ED5423AA8038 C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\System32\DRIVERS\ssudmdm.sys A97BFF59B3B983FDBDCD8AE6CF3C1E2D C:\Windows\System32\DRIVERS\ssudobex.sys 2F9F058CD56B2535B5A8787936DB6D1C C:\Windows\System32\DRIVERS\stdriverx64.sys 30D7CE5C0B812BAF4F2FB5F47820C76A C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys 70988118145F5F10EF24720B97F35F65 C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tssecsrv.sys E232A3B43A894BB327FC161529BD9ED1 C:\Windows\System32\drivers\tsusbflt.sys E9981ECE8D894CEF7038FD1D040EB426 C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2 C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965 C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\system32\drivers\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24 C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3 C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7 C:\Windows\System32\DRIVERS\VClone.sys FD911873C0BB6945FA38C16E9A2B58F9 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\system32\drivers\vmbus.sys ==> MD5 is legit C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vpchbus.sys ABD9B4A7E2D0AE51A3B8DF1AF3152D61 C:\Windows\System32\DRIVERS\vpcnfltr.sys 8ACDA395841538CE9713A67FE8B2A3EB C:\Windows\System32\DRIVERS\vpcusb.sys 31924E31BC315773E6D149B157DB46D5 C:\Windows\System32\drivers\vpcvmm.sys 510D250A08C09850F5C78CA2011B3B62 C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== Three Months Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-11 15:47 - 2015-03-11 15:48 - 00000000 ____D () C:\FRST 2015-03-11 06:34 - 2015-03-11 06:34 - 00070541 _____ () C:\Users\ivana\Desktop\scfdetais.txt 2015-03-11 06:17 - 2015-03-11 06:14 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\ivana\Downloads\avira_de_av_5902429157__ws.exe 2015-03-11 06:05 - 2015-03-11 06:05 - 00000062 _____ () C:\Windows\wininit.ini 2015-03-10 03:51 - 2015-03-11 06:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-09 06:29 - 2015-03-09 06:29 - 00000193 _____ () C:\Windows\WORDPAD.INI 2015-03-05 13:58 - 2015-03-05 13:58 - 00000000 ____D () C:\Users\Public\Documents\CrashDump 2015-03-05 12:10 - 2015-03-05 12:10 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log 2015-03-05 12:10 - 2015-03-05 12:10 - 00000000 ____D () C:\Users\ivana\AppData\Roaming\Samsung 2015-03-05 12:10 - 2015-03-05 12:10 - 00000000 ____D () C:\Users\ivana\AppData\Local\Samsung 2015-03-05 12:09 - 2015-03-05 12:09 - 00000000 ____D () C:\Users\ivana\Documents\samsung 2015-03-05 12:08 - 2015-03-05 12:08 - 00000000 ____H () C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2015-03-05 12:08 - 2013-04-02 23:58 - 01490656 _____ (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01007.dll 2015-03-05 12:08 - 2013-04-02 23:58 - 00708168 _____ (Microsoft Corporation) C:\Windows\System32\WinUSBCoInstaller.dll 2015-03-05 12:08 - 2013-04-02 23:58 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudobex.sys 2015-03-05 12:08 - 2013-04-02 23:58 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys 2015-03-05 12:08 - 2013-04-02 23:58 - 00103064 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys 2015-03-05 12:05 - 2013-04-18 10:08 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2015-03-05 12:04 - 2013-04-18 10:06 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2015-03-05 12:03 - 2015-03-05 12:08 - 00000000 ____D () C:\Program Files (x86)\Samsung 2015-03-05 12:03 - 2015-03-05 12:07 - 00000000 ____D () C:\ProgramData\Samsung 2015-03-05 12:01 - 2015-03-05 12:01 - 00000000 ____D () C:\Users\ivana\AppData\Local\Downloaded Installations 2015-03-05 09:53 - 2015-03-05 09:53 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-02-26 05:06 - 2015-02-26 05:06 - 00000000 ____D () C:\Users\ivana\Documents\Vermischtes 2015-02-25 10:39 - 2015-01-08 15:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls 2015-02-25 10:39 - 2015-01-08 15:43 - 00419936 _____ () C:\Windows\System32\locale.nls 2015-02-24 04:03 - 2014-12-11 09:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe 2015-02-24 04:03 - 2014-09-04 18:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2015-02-24 04:03 - 2014-09-04 17:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-02-23 03:51 - 2013-10-01 17:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll 2015-02-23 03:50 - 2013-10-01 18:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys 2015-02-23 03:50 - 2013-10-01 18:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2015-02-23 03:50 - 2013-10-01 18:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2015-02-23 03:50 - 2013-10-01 17:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll 2015-02-23 03:50 - 2013-10-01 17:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll 2015-02-23 03:50 - 2013-10-01 17:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2015-02-23 03:50 - 2013-10-01 16:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\System32\rdvidcrl.dll 2015-02-23 03:50 - 2013-10-01 16:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2015-02-23 03:50 - 2013-10-01 16:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2015-02-23 03:50 - 2013-10-01 16:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\wksprt.exe 2015-02-23 03:50 - 2013-10-01 15:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2015-02-23 03:50 - 2013-10-01 15:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe 2015-02-23 03:50 - 2013-10-01 15:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2015-02-23 03:50 - 2013-10-01 14:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2015-02-23 03:26 - 2015-01-22 20:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2015-02-23 03:26 - 2015-01-22 20:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2015-02-23 03:26 - 2015-01-22 19:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-02-23 03:26 - 2015-01-22 19:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-11 06:43 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-11 06:43 - 2009-07-13 20:51 - 00094159 _____ () C:\Windows\setupact.log 2015-03-11 06:40 - 2010-11-20 19:47 - 00291428 _____ () C:\Windows\PFRO.log 2015-03-11 06:39 - 2013-06-24 03:36 - 00000000 ____D () C:\Program Files (x86)\Launch Manager 2015-03-11 06:39 - 2013-06-24 03:19 - 01254126 _____ () C:\Windows\WindowsUpdate.log 2015-03-11 06:22 - 2013-06-24 13:11 - 00701334 _____ () C:\Windows\System32\perfh007.dat 2015-03-11 06:22 - 2013-06-24 13:11 - 00150202 _____ () C:\Windows\System32\perfc007.dat 2015-03-11 06:22 - 2009-07-13 21:13 - 01619700 _____ () C:\Windows\System32\PerfStringBackup.INI 2015-03-11 06:17 - 2013-06-24 03:50 - 00000000 ____D () C:\Program Files (x86)\Qualcomm Atheros 2015-03-11 06:08 - 2009-07-13 20:45 - 00016976 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-11 06:08 - 2009-07-13 20:45 - 00016976 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-11 06:05 - 2013-12-23 12:55 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-11 05:57 - 2013-10-04 04:11 - 00000000 ___RD () C:\Users\ivana\Virtual Machines 2015-03-11 05:57 - 2013-10-04 04:11 - 00000000 ____D () C:\users\ivana 2015-03-11 05:57 - 2013-09-28 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-11 05:57 - 2013-09-26 22:10 - 00000000 ____D () C:\users\admin 2015-03-11 05:57 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\registration 2015-03-11 05:57 - 2009-07-13 19:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-03-11 05:18 - 2013-10-01 23:56 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-11 05:03 - 2013-09-26 23:22 - 00000000 ____D () C:\Windows\System32\MRT 2015-03-11 03:53 - 2013-12-23 12:55 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-10 10:05 - 2014-07-17 11:15 - 00000000 ____D () C:\Users\ivana\AppData\Roaming\Audacity 2015-03-07 11:09 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\System32\NDF 2015-03-06 04:40 - 2014-06-26 06:33 - 00000000 ____D () C:\Users\ivana\AppData\Local\CrashDumps 2015-03-05 12:04 - 2013-03-04 20:18 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-03-05 09:53 - 2014-06-23 09:51 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-05 09:52 - 2014-06-23 09:51 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-03-05 02:26 - 2014-06-23 10:06 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys 2015-03-05 02:26 - 2014-06-23 10:00 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys 2015-03-05 02:26 - 2014-06-23 10:00 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys 2015-03-03 05:17 - 2010-11-20 19:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2015-02-26 05:06 - 2013-03-04 20:57 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-26 05:06 - 2013-03-04 20:57 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-23 03:13 - 2009-07-13 20:45 - 00573576 _____ () C:\Windows\System32\FNTCACHE.DAT 2015-02-22 14:43 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\tracing 2015-02-22 14:43 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-02-22 03:40 - 2013-12-23 12:57 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-19 03:22 - 2013-10-01 08:45 - 00001912 _____ () C:\Windows\epplauncher.mif 2015-02-19 03:21 - 2013-10-01 08:39 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2015-02-19 03:21 - 2013-10-01 08:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2015-02-19 03:20 - 2009-07-13 18:34 - 00000510 _____ () C:\Windows\win.ini 2015-02-19 03:07 - 2013-09-26 23:22 - 116773704 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe Some content of TEMP: ==================== C:\Users\admin\AppData\Local\Temp\avgnt.exe C:\Users\admin\AppData\Local\Temp\ose00000.exe C:\Users\admin\AppData\Local\Temp\{6159E8B5-DE19-40E3-B52A-1DBEB7791350}.exe C:\Users\ivana\AppData\Local\Temp\avgnt.exe C:\Users\ivana\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\ivana\AppData\Local\Temp\ppadsetup.exe C:\Users\ivana\AppData\Local\Temp\stsetup.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2015-03-02 06:16:18 Restore point made on: 2015-03-05 12:02:27 Restore point made on: 2015-03-05 14:10:59 Restore point made on: 2015-03-09 03:37:14 Restore point made on: 2015-03-11 04:51:54 Restore point made on: 2015-03-11 05:53:54 ==================== BCD ================================ Start-Manager fr Firmware -------------------------- Bezeichner {fwbootmgr} displayorder {54c4a911-dd11-11e2-b5e1-208984775221} {54c4a912-dd11-11e2-b5e1-208984775221} {54c4a910-dd11-11e2-b5e1-208984775221} {95b04355-c7fc-11e4-8143-806e6f6e6963} timeout 2 Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=\Device\HarddiskVolume2 path \EFI\Microsoft\Boot\bootmgfw.efi description Windows Boot Manager locale de-DE inherit {globalsettings} default {default} resumeobject {54c4a915-dd11-11e2-b5e1-208984775221} displayorder {default} toolsdisplayorder {memdiag} timeout 30 Firmwareanwendung (101fffff) ---------------------------- Bezeichner {54c4a910-dd11-11e2-b5e1-208984775221} description BRCM MBA Slot 0200 v15.0.11 Firmwareanwendung (101fffff) ---------------------------- Bezeichner {54c4a911-dd11-11e2-b5e1-208984775221} description WDC WD5000LPVX-22V0TT0 Firmwareanwendung (101fffff) ---------------------------- Bezeichner {54c4a912-dd11-11e2-b5e1-208984775221} description MATSHITA DVD-RAM UJ8E1 Firmwareanwendung (101fffff) ---------------------------- Bezeichner {95b04355-c7fc-11e4-8143-806e6f6e6963} description USB DISK 2.0 Windows-Startladeprogramm ------------------------- Bezeichner {default} device partition=C: path \Windows\system32\winload.efi description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {current} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {54c4a915-dd11-11e2-b5e1-208984775221} nx OptIn Windows-Startladeprogramm ------------------------- Bezeichner {current} device ramdisk=[C:]\Recovery\54c4a917-dd11-11e2-b5e1-208984775221\Winre.wim,{54c4a918-dd11-11e2-b5e1-208984775221} path \windows\system32\winload.efi description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\54c4a917-dd11-11e2-b5e1-208984775221\Winre.wim,{54c4a918-dd11-11e2-b5e1-208984775221} systemroot \windows nx OptIn winpe Yes Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {54c4a915-dd11-11e2-b5e1-208984775221} device partition=C: path \Windows\system32\winresume.efi description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=\Device\HarddiskVolume2 path \EFI\Microsoft\Boot\memtest.efi description Windows-Speicherdiagnose locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems Yes Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger„teoptionen -------------- Bezeichner {54c4a918-dd11-11e2-b5e1-208984775221} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\54c4a917-dd11-11e2-b5e1-208984775221\boot.sdi ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 3911.28 MB Available physical RAM: 3221.11 MB Total Pagefile: 3909.48 MB Available Pagefile: 3217.1 MB Total Virtual: 8192 MB Available Virtual: 8191.89 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:216.6 GB) (Free:111.71 GB) NTFS Drive d: (DATA) (Fixed) (Total:216.6 GB) (Free:114.6 GB) NTFS Drive f: (USB DISK) (Removable) (Total:1.86 GB) (Free:0.67 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 68DA96F1) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 1.9 GB) (Disk ID: C3072E18) Partition 1: (Not Active) - (Size=1.9 GB) - (Type=06) LastRegBack: 2015-03-06 06:45 ==================== End Of Log ============================ Code:
ATTFilter 2015-03-11 15:19:59, Info CSI 000001a7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:19:59, Info CSI 000001a8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:00, Info CSI 000001aa [SR] Verify complete 2015-03-11 15:20:00, Info CSI 000001ab [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:00, Info CSI 000001ac [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:02, Info CSI 000001ae [SR] Verify complete 2015-03-11 15:20:02, Info CSI 000001af [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:02, Info CSI 000001b0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:04, Info CSI 000001b2 [SR] Verify complete 2015-03-11 15:20:04, Info CSI 000001b3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:04, Info CSI 000001b4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:05, Info CSI 000001b6 [SR] Verify complete 2015-03-11 15:20:05, Info CSI 000001b7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:05, Info CSI 000001b8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:07, Info CSI 000001ba [SR] Verify complete 2015-03-11 15:20:07, Info CSI 000001bb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:07, Info CSI 000001bc [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:08, Info CSI 000001be [SR] Verify complete 2015-03-11 15:20:09, Info CSI 000001bf [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:09, Info CSI 000001c0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:10, Info CSI 000001c2 [SR] Verify complete 2015-03-11 15:20:10, Info CSI 000001c3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:10, Info CSI 000001c4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:12, Info CSI 000001c6 [SR] Verify complete 2015-03-11 15:20:12, Info CSI 000001c7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:12, Info CSI 000001c8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:14, Info CSI 000001ca [SR] Verify complete 2015-03-11 15:20:14, Info CSI 000001cb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:14, Info CSI 000001cc [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:16, Info CSI 000001ce [SR] Verify complete 2015-03-11 15:20:16, Info CSI 000001cf [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:16, Info CSI 000001d0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:17, Info CSI 000001d2 [SR] Verify complete 2015-03-11 15:20:17, Info CSI 000001d3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:17, Info CSI 000001d4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:19, Info CSI 000001d6 [SR] Verify complete 2015-03-11 15:20:19, Info CSI 000001d7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:19, Info CSI 000001d8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:21, Info CSI 000001da [SR] Verify complete 2015-03-11 15:20:21, Info CSI 000001db [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:21, Info CSI 000001dc [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:23, Info CSI 000001de [SR] Verify complete 2015-03-11 15:20:23, Info CSI 000001df [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:23, Info CSI 000001e0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:25, Info CSI 000001e2 [SR] Verify complete 2015-03-11 15:20:26, Info CSI 000001e3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:26, Info CSI 000001e4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:28, Info CSI 000001e6 [SR] Verify complete 2015-03-11 15:20:28, Info CSI 000001e7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:28, Info CSI 000001e8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:30, Info CSI 000001ea [SR] Verify complete 2015-03-11 15:20:30, Info CSI 000001eb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:30, Info CSI 000001ec [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:32, Info CSI 000001ee [SR] Verify complete 2015-03-11 15:20:32, Info CSI 000001ef [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:32, Info CSI 000001f0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:34, Info CSI 000001f2 [SR] Verify complete 2015-03-11 15:20:34, Info CSI 000001f3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:34, Info CSI 000001f4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:36, Info CSI 000001f6 [SR] Verify complete 2015-03-11 15:20:36, Info CSI 000001f7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:36, Info CSI 000001f8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:37, Info CSI 000001fa [SR] Verify complete 2015-03-11 15:20:38, Info CSI 000001fb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:38, Info CSI 000001fc [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:40, Info CSI 000001fe [SR] Verify complete 2015-03-11 15:20:40, Info CSI 000001ff [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:40, Info CSI 00000200 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:44, Info CSI 00000202 [SR] Verify complete 2015-03-11 15:20:44, Info CSI 00000203 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:44, Info CSI 00000204 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:47, Info CSI 00000206 [SR] Verify complete 2015-03-11 15:20:47, Info CSI 00000207 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:47, Info CSI 00000208 [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:50, Info CSI 0000020a [SR] Verify complete 2015-03-11 15:20:50, Info CSI 0000020b [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:50, Info CSI 0000020c [SR] Beginning Verify and Repair transaction 2015-03-11 15:20:55, Info CSI 0000020f [SR] Verify complete 2015-03-11 15:20:55, Info CSI 00000210 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:20:55, Info CSI 00000211 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:01, Info CSI 00000214 [SR] Verify complete 2015-03-11 15:21:01, Info CSI 00000215 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:01, Info CSI 00000216 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:04, Info CSI 00000219 [SR] Verify complete 2015-03-11 15:21:04, Info CSI 0000021a [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:04, Info CSI 0000021b [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:08, Info CSI 0000021f [SR] Verify complete 2015-03-11 15:21:08, Info CSI 00000220 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:08, Info CSI 00000221 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:12, Info CSI 00000223 [SR] Verify complete 2015-03-11 15:21:12, Info CSI 00000224 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:12, Info CSI 00000225 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:18, Info CSI 00000247 [SR] Verify complete 2015-03-11 15:21:18, Info CSI 00000248 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:18, Info CSI 00000249 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:22, Info CSI 0000024e [SR] Verify complete 2015-03-11 15:21:22, Info CSI 0000024f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:22, Info CSI 00000250 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:26, Info CSI 00000252 [SR] Verify complete 2015-03-11 15:21:26, Info CSI 00000253 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:26, Info CSI 00000254 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:31, Info CSI 00000256 [SR] Verify complete 2015-03-11 15:21:31, Info CSI 00000257 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:31, Info CSI 00000258 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:35, Info CSI 0000025a [SR] Verify complete 2015-03-11 15:21:35, Info CSI 0000025b [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:35, Info CSI 0000025c [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:38, Info CSI 0000025e [SR] Verify complete 2015-03-11 15:21:39, Info CSI 0000025f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:39, Info CSI 00000260 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:43, Info CSI 00000262 [SR] Verify complete 2015-03-11 15:21:43, Info CSI 00000263 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:43, Info CSI 00000264 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:49, Info CSI 00000272 [SR] Verify complete 2015-03-11 15:21:50, Info CSI 00000273 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:50, Info CSI 00000274 [SR] Beginning Verify and Repair transaction 2015-03-11 15:21:56, Info CSI 00000295 [SR] Verify complete 2015-03-11 15:21:56, Info CSI 00000296 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:21:56, Info CSI 00000297 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:02, Info CSI 00000299 [SR] Verify complete 2015-03-11 15:22:03, Info CSI 0000029a [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:03, Info CSI 0000029b [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:12, Info CSI 0000029f [SR] Verify complete 2015-03-11 15:22:12, Info CSI 000002a0 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:12, Info CSI 000002a1 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:15, Info CSI 000002a3 [SR] Verify complete 2015-03-11 15:22:15, Info CSI 000002a4 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:15, Info CSI 000002a5 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:18, Info CSI 000002a7 [SR] Verify complete 2015-03-11 15:22:18, Info CSI 000002a8 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:18, Info CSI 000002a9 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:20, Info CSI 000002ab [SR] Verify complete 2015-03-11 15:22:20, Info CSI 000002ac [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:20, Info CSI 000002ad [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:25, Info CSI 000002b3 [SR] Verify complete 2015-03-11 15:22:25, Info CSI 000002b4 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:25, Info CSI 000002b5 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:29, Info CSI 000002c4 [SR] Verify complete 2015-03-11 15:22:29, Info CSI 000002c5 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:29, Info CSI 000002c6 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:31, Info CSI 000002c8 [SR] Verify complete 2015-03-11 15:22:31, Info CSI 000002c9 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:31, Info CSI 000002ca [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:34, Info CSI 000002cc [SR] Verify complete 2015-03-11 15:22:34, Info CSI 000002cd [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:34, Info CSI 000002ce [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:36, Info CSI 000002d0 [SR] Verify complete 2015-03-11 15:22:36, Info CSI 000002d1 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:36, Info CSI 000002d2 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:41, Info CSI 000002d5 [SR] Verify complete 2015-03-11 15:22:41, Info CSI 000002d6 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:41, Info CSI 000002d7 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:50, Info CSI 000002da [SR] Verify complete 2015-03-11 15:22:50, Info CSI 000002db [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:50, Info CSI 000002dc [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:54, Info CSI 000002de [SR] Verify complete 2015-03-11 15:22:54, Info CSI 000002df [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:54, Info CSI 000002e0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:22:56, Info CSI 000002e2 [SR] Verify complete 2015-03-11 15:22:57, Info CSI 000002e3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:22:57, Info CSI 000002e4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:02, Info CSI 000002e6 [SR] Verify complete 2015-03-11 15:23:02, Info CSI 000002e7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:02, Info CSI 000002e8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:06, Info CSI 000002ea [SR] Verify complete 2015-03-11 15:23:06, Info CSI 000002eb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:06, Info CSI 000002ec [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:09, Info CSI 000002ee [SR] Verify complete 2015-03-11 15:23:09, Info CSI 000002ef [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:09, Info CSI 000002f0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:19, Info CSI 000002f2 [SR] Verify complete 2015-03-11 15:23:19, Info CSI 000002f3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:19, Info CSI 000002f4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:26, Info CSI 0000030c [SR] Verify complete 2015-03-11 15:23:26, Info CSI 0000030d [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:26, Info CSI 0000030e [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:32, Info CSI 00000310 [SR] Verify complete 2015-03-11 15:23:32, Info CSI 00000311 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:32, Info CSI 00000312 [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:45, Info CSI 00000314 [SR] Verify complete 2015-03-11 15:23:45, Info CSI 00000315 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:45, Info CSI 00000316 [SR] Beginning Verify and Repair transaction 2015-03-11 15:23:57, Info CSI 00000318 [SR] Verify complete 2015-03-11 15:23:57, Info CSI 00000319 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:23:57, Info CSI 0000031a [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:02, Info CSI 0000031c [SR] Verify complete 2015-03-11 15:24:03, Info CSI 0000031d [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:03, Info CSI 0000031e [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:09, Info CSI 00000320 [SR] Verify complete 2015-03-11 15:24:09, Info CSI 00000321 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:09, Info CSI 00000322 [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:13, Info CSI 00000324 [SR] Verify complete 2015-03-11 15:24:13, Info CSI 00000325 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:13, Info CSI 00000326 [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:18, Info CSI 00000328 [SR] Verify complete 2015-03-11 15:24:18, Info CSI 00000329 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:18, Info CSI 0000032a [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:22, Info CSI 0000032e [SR] Verify complete 2015-03-11 15:24:23, Info CSI 0000032f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:23, Info CSI 00000330 [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:27, Info CSI 00000332 [SR] Verify complete 2015-03-11 15:24:27, Info CSI 00000333 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:27, Info CSI 00000334 [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:34, Info CSI 00000337 [SR] Verify complete 2015-03-11 15:24:34, Info CSI 00000338 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:34, Info CSI 00000339 [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:40, Info CSI 0000033b [SR] Verify complete 2015-03-11 15:24:40, Info CSI 0000033c [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:40, Info CSI 0000033d [SR] Beginning Verify and Repair transaction 2015-03-11 15:24:50, Info CSI 00000340 [SR] Verify complete 2015-03-11 15:24:50, Info CSI 00000341 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:24:50, Info CSI 00000342 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:08, Info CSI 00000345 [SR] Verify complete 2015-03-11 15:25:08, Info CSI 00000346 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:08, Info CSI 00000347 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:14, Info CSI 00000349 [SR] Verify complete 2015-03-11 15:25:14, Info CSI 0000034a [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:14, Info CSI 0000034b [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:17, Info CSI 0000034d [SR] Verify complete 2015-03-11 15:25:18, Info CSI 0000034e [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:18, Info CSI 0000034f [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:23, Info CSI 00000351 [SR] Verify complete 2015-03-11 15:25:23, Info CSI 00000352 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:23, Info CSI 00000353 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:28, Info CSI 00000356 [SR] Verify complete 2015-03-11 15:25:28, Info CSI 00000357 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:28, Info CSI 00000358 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:34, Info CSI 0000035a [SR] Verify complete 2015-03-11 15:25:35, Info CSI 0000035b [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:35, Info CSI 0000035c [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:37, Info CSI 0000035e [SR] Verify complete 2015-03-11 15:25:38, Info CSI 0000035f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:38, Info CSI 00000360 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:42, Info CSI 00000362 [SR] Verify complete 2015-03-11 15:25:42, Info CSI 00000363 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:42, Info CSI 00000364 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:44, Info CSI 00000366 [SR] Verify complete 2015-03-11 15:25:45, Info CSI 00000367 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:45, Info CSI 00000368 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:46, Info CSI 0000036a [SR] Verify complete 2015-03-11 15:25:46, Info CSI 0000036b [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:46, Info CSI 0000036c [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:49, Info CSI 0000036f [SR] Verify complete 2015-03-11 15:25:49, Info CSI 00000370 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:49, Info CSI 00000371 [SR] Beginning Verify and Repair transaction 2015-03-11 15:25:55, Info CSI 00000374 [SR] Verify complete 2015-03-11 15:25:55, Info CSI 00000375 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:25:55, Info CSI 00000376 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:01, Info CSI 00000379 [SR] Verify complete 2015-03-11 15:26:01, Info CSI 0000037a [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:01, Info CSI 0000037b [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:07, Info CSI 0000037d [SR] Verify complete 2015-03-11 15:26:07, Info CSI 0000037e [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:07, Info CSI 0000037f [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:13, Info CSI 00000382 [SR] Verify complete 2015-03-11 15:26:13, Info CSI 00000383 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:13, Info CSI 00000384 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:18, Info CSI 00000386 [SR] Verify complete 2015-03-11 15:26:18, Info CSI 00000387 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:18, Info CSI 00000388 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:20, Info CSI 0000038a [SR] Verify complete 2015-03-11 15:26:20, Info CSI 0000038b [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:20, Info CSI 0000038c [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:24, Info CSI 0000038e [SR] Verify complete 2015-03-11 15:26:24, Info CSI 0000038f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:24, Info CSI 00000390 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:29, Info CSI 00000392 [SR] Verify complete 2015-03-11 15:26:29, Info CSI 00000393 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:29, Info CSI 00000394 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:35, Info CSI 00000396 [SR] Verify complete 2015-03-11 15:26:35, Info CSI 00000397 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:35, Info CSI 00000398 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:39, Info CSI 0000039a [SR] Verify complete 2015-03-11 15:26:39, Info CSI 0000039b [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:39, Info CSI 0000039c [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:42, Info CSI 0000039e [SR] Verify complete 2015-03-11 15:26:42, Info CSI 0000039f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:42, Info CSI 000003a0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:26:50, Info CSI 000003a2 [SR] Verify complete 2015-03-11 15:26:50, Info CSI 000003a3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:26:50, Info CSI 000003a4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:07, Info CSI 000003a6 [SR] Verify complete 2015-03-11 15:27:07, Info CSI 000003a7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:07, Info CSI 000003a8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:13, Info CSI 000003aa [SR] Verify complete 2015-03-11 15:27:13, Info CSI 000003ab [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:13, Info CSI 000003ac [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:19, Info CSI 000003ae [SR] Verify complete 2015-03-11 15:27:19, Info CSI 000003af [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:19, Info CSI 000003b0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:22, Info CSI 000003b2 [SR] Verify complete 2015-03-11 15:27:22, Info CSI 000003b3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:22, Info CSI 000003b4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:26, Info CSI 000003b6 [SR] Verify complete 2015-03-11 15:27:26, Info CSI 000003b7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:26, Info CSI 000003b8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:27, Info CSI 000003ba [SR] Verify complete 2015-03-11 15:27:27, Info CSI 000003bb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:27, Info CSI 000003bc [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:31, Info CSI 000003be [SR] Verify complete 2015-03-11 15:27:31, Info CSI 000003bf [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:31, Info CSI 000003c0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:35, Info CSI 000003c2 [SR] Verify complete 2015-03-11 15:27:35, Info CSI 000003c3 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:35, Info CSI 000003c4 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:37, Info CSI 000003c6 [SR] Verify complete 2015-03-11 15:27:37, Info CSI 000003c7 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:37, Info CSI 000003c8 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:39, Info CSI 000003ca [SR] Verify complete 2015-03-11 15:27:39, Info CSI 000003cb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:39, Info CSI 000003cc [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:44, Info CSI 000003d4 [SR] Verify complete 2015-03-11 15:27:44, Info CSI 000003d5 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:44, Info CSI 000003d6 [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:47, Info CSI 000003d8 [SR] Verify complete 2015-03-11 15:27:47, Info CSI 000003d9 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:47, Info CSI 000003da [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:51, Info CSI 000003dc [SR] Verify complete 2015-03-11 15:27:51, Info CSI 000003dd [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:51, Info CSI 000003de [SR] Beginning Verify and Repair transaction 2015-03-11 15:27:56, Info CSI 000003e0 [SR] Verify complete 2015-03-11 15:27:56, Info CSI 000003e1 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:27:56, Info CSI 000003e2 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:01, Info CSI 000003e4 [SR] Verify complete 2015-03-11 15:28:01, Info CSI 000003e5 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:01, Info CSI 000003e6 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:06, Info CSI 000003e9 [SR] Verify complete 2015-03-11 15:28:06, Info CSI 000003ea [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:06, Info CSI 000003eb [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:08, Info CSI 000003ec [SR] Cannot repair member file [l:20{10}]"hhctrl.ocx" of Microsoft-Windows-HtmlHelp, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:14, Info CSI 000003ed [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[ml:22{11},l:20{10}]"hhctrl.ocx" by copying from backup 2015-03-11 15:28:15, Info CSI 000003ef [SR] Verify complete 2015-03-11 15:28:16, Info CSI 000003f0 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:16, Info CSI 000003f1 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:16, Info CSI 000003f3 [SR] Verify complete 2015-03-11 15:28:17, Info CSI 000003f4 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:17, Info CSI 000003f5 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:18, Info CSI 000003f6 [SR] Cannot repair member file [l:14{7}]"tdc.ocx" of Microsoft-Windows-IE-DataControl, Version = 11.2.9600.16428, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:21, Info CSI 000003f7 [SR] Cannot repair member file [l:14{7}]"tdc.ocx" of Microsoft-Windows-IE-DataControl, Version = 11.2.9600.16428, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:21, Info CSI 000003f8 [SR] This component was referenced by [l:230{115}]"Microsoft-Windows-InternetExplorer-VistaPlus-Update~31bf3856ad364e35~amd64~~11.2.9600.16428.Internet-Explorer-amd64" 2015-03-11 15:28:21, Info CSI 000003fa [SR] Verify complete 2015-03-11 15:28:21, Info CSI 000003fb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:21, Info CSI 000003fc [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:24, Info CSI 000003fd [SR] Cannot repair member file [l:18{9}]"msdxm.ocx" of Microsoft-Windows-MediaPlayer-Core, Version = 6.1.7601.18150, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:30, Info CSI 000003ff [SR] Cannot repair member file [l:18{9}]"msdxm.ocx" of Microsoft-Windows-MediaPlayer-Core, Version = 6.1.7601.18150, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:30, Info CSI 00000400 [SR] This component was referenced by [l:154{77}]"Package_1_for_KB2847077~31bf3856ad364e35~amd64~~6.1.1.1.2847077-2_neutral_GDR" 2015-03-11 15:28:34, Info CSI 00000404 [SR] Verify complete 2015-03-11 15:28:34, Info CSI 00000405 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:34, Info CSI 00000406 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:38, Info CSI 00000407 [SR] Cannot repair member file [l:20{10}]"sysmon.ocx" of Microsoft-Windows-PerformanceToolsGui, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:38, Info CSI 00000408 [SR] Cannot repair member file [l:20{10}]"sysmon.ocx" of Microsoft-Windows-PerformanceToolsGui, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:38, Info CSI 00000409 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:28:40, Info CSI 0000040e [SR] Verify complete 2015-03-11 15:28:40, Info CSI 0000040f [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:40, Info CSI 00000410 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:41, Info CSI 00000411 [SR] Cannot repair member file [l:18{9}]"wshom.ocx" of Microsoft-Windows-Scripting, Version = 6.1.7601.18283, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:44, Info CSI 00000412 [SR] Cannot repair member file [l:18{9}]"wshom.ocx" of Microsoft-Windows-Scripting, Version = 6.1.7601.18283, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:28:44, Info CSI 00000413 [SR] This component was referenced by [l:154{77}]"Package_2_for_KB2892074~31bf3856ad364e35~amd64~~6.1.1.0.2892074-4_neutral_GDR" 2015-03-11 15:28:46, Info CSI 00000416 [SR] Verify complete 2015-03-11 15:28:46, Info CSI 00000417 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:46, Info CSI 00000418 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:50, Info CSI 00000422 [SR] Verify complete 2015-03-11 15:28:50, Info CSI 00000423 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:50, Info CSI 00000424 [SR] Beginning Verify and Repair transaction 2015-03-11 15:28:56, Info CSI 0000042b [SR] Verify complete 2015-03-11 15:28:56, Info CSI 0000042c [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:28:56, Info CSI 0000042d [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:00, Info CSI 0000042f [SR] Verify complete 2015-03-11 15:29:00, Info CSI 00000430 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:00, Info CSI 00000431 [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:02, Info CSI 00000432 [SR] Cannot repair member file [l:22{11}]"Bubbles.scr" of Microsoft-Windows-Bubbles, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:29:03, Info CSI 00000435 [SR] Cannot repair member file [l:22{11}]"Bubbles.scr" of Microsoft-Windows-Bubbles, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:29:03, Info CSI 00000436 [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:29:03, Info CSI 00000438 [SR] Verify complete 2015-03-11 15:29:04, Info CSI 00000439 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:04, Info CSI 0000043a [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:07, Info CSI 0000043c [SR] Verify complete 2015-03-11 15:29:08, Info CSI 0000043d [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:08, Info CSI 0000043e [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:12, Info CSI 00000463 [SR] Verify complete 2015-03-11 15:29:12, Info CSI 00000464 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:12, Info CSI 00000465 [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:16, Info CSI 00000467 [SR] Verify complete 2015-03-11 15:29:16, Info CSI 00000468 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:16, Info CSI 00000469 [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:20, Info CSI 0000046b [SR] Verify complete 2015-03-11 15:29:20, Info CSI 0000046c [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:20, Info CSI 0000046d [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:22, Info CSI 0000046e [SR] Cannot repair member file [l:20{10}]"dmview.ocx" of Microsoft-Windows-DiskManagement, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:29:24, Info CSI 0000046f [SR] Cannot repair member file [l:20{10}]"dmview.ocx" of Microsoft-Windows-DiskManagement, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:29:24, Info CSI 00000470 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:29:24, Info CSI 00000472 [SR] Verify complete 2015-03-11 15:29:24, Info CSI 00000473 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:24, Info CSI 00000474 [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:28, Info CSI 00000478 [SR] Verify complete 2015-03-11 15:29:28, Info CSI 00000479 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:28, Info CSI 0000047a [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:35, Info CSI 0000047c [SR] Verify complete 2015-03-11 15:29:35, Info CSI 0000047d [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:35, Info CSI 0000047e [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:39, Info CSI 00000488 [SR] Verify complete 2015-03-11 15:29:39, Info CSI 00000489 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:39, Info CSI 0000048a [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:42, Info CSI 00000490 [SR] Verify complete 2015-03-11 15:29:42, Info CSI 00000491 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:42, Info CSI 00000492 [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:45, Info CSI 00000494 [SR] Verify complete 2015-03-11 15:29:46, Info CSI 00000495 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:46, Info CSI 00000496 [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:52, Info CSI 00000499 [SR] Verify complete 2015-03-11 15:29:52, Info CSI 0000049a [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:52, Info CSI 0000049b [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:55, Info CSI 0000049d [SR] Verify complete 2015-03-11 15:29:55, Info CSI 0000049e [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:55, Info CSI 0000049f [SR] Beginning Verify and Repair transaction 2015-03-11 15:29:57, Info CSI 000004a1 [SR] Verify complete 2015-03-11 15:29:57, Info CSI 000004a2 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:29:57, Info CSI 000004a3 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:03, Info CSI 000004a5 [SR] Verify complete 2015-03-11 15:30:03, Info CSI 000004a6 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:03, Info CSI 000004a7 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:06, Info CSI 000004a9 [SR] Verify complete 2015-03-11 15:30:06, Info CSI 000004aa [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:06, Info CSI 000004ab [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:14, Info CSI 000004c5 [SR] Verify complete 2015-03-11 15:30:14, Info CSI 000004c6 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:14, Info CSI 000004c7 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:17, Info CSI 000004c8 [SR] Cannot repair member file [l:22{11}]"Mystify.scr" of Microsoft-Windows-Mystify, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:20, Info CSI 000004c9 [SR] Cannot repair member file [l:22{11}]"Mystify.scr" of Microsoft-Windows-Mystify, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:30:20, Info CSI 000004ca [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:30:20, Info CSI 000004cc [SR] Verify complete 2015-03-11 15:30:20, Info CSI 000004cd [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:20, Info CSI 000004ce [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:32, Info CSI 000004d0 [SR] Verify complete 2015-03-11 15:30:33, Info CSI 000004d1 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:33, Info CSI 000004d2 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:36, Info CSI 000004d4 [SR] Verify complete 2015-03-11 15:30:36, Info CSI 000004d5 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:36, Info CSI 000004d6 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:37, Info CSI 000004d7 [SR] Cannot repair member file [l:40{20}]"PhotoScreensaver.scr" of Microsoft-Windows-PhotoScreensaver, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:39, Info CSI 000004d9 [SR] Cannot repair member file [l:40{20}]"PhotoScreensaver.scr" of Microsoft-Windows-PhotoScreensaver, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:30:39, Info CSI 000004da [SR] This component was referenced by [l:182{91}]"Microsoft-Windows-PhotoBasicPackage~31bf3856ad364e35~amd64~~6.1.7601.17514.PhotoBasicUpdate" 2015-03-11 15:30:40, Info CSI 000004dd [SR] Verify complete 2015-03-11 15:30:40, Info CSI 000004de [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:40, Info CSI 000004df [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:40, Info CSI 000004e0 [SR] Cannot repair member file [l:22{11}]"Ribbons.scr" of Microsoft-Windows-Ribbons, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:43, Info CSI 000004e1 [SR] Cannot repair member file [l:22{11}]"Ribbons.scr" of Microsoft-Windows-Ribbons, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:30:43, Info CSI 000004e2 [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:30:43, Info CSI 000004e4 [SR] Verify complete 2015-03-11 15:30:43, Info CSI 000004e5 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:43, Info CSI 000004e6 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:45, Info CSI 000004e7 [SR] Cannot repair member file [l:24{12}]"msscript.ocx" of Microsoft-Windows-Scripting-MSScript, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:45, Info CSI 000004e8 [SR] Cannot repair member file [l:24{12}]"scrnsave.scr" of Microsoft-Windows-scrnsave, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:47, Info CSI 000004e9 [SR] Cannot repair member file [l:24{12}]"scrnsave.scr" of Microsoft-Windows-scrnsave, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:47, Info CSI 000004ea [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:30:47, Info CSI 000004eb [SR] Cannot repair member file [l:24{12}]"msscript.ocx" of Microsoft-Windows-Scripting-MSScript, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:30:47, Info CSI 000004ec [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:30:48, Info CSI 000004ee [SR] Verify complete 2015-03-11 15:30:48, Info CSI 000004ef [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:48, Info CSI 000004f0 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:49, Info CSI 000004f1 [SR] Cannot repair member file [l:24{12}]"ssText3d.scr" of Microsoft-Windows-ssText3d, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:50, Info CSI 000004f2 [SR] Cannot repair member file [l:24{12}]"ssText3d.scr" of Microsoft-Windows-ssText3d, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file cannot be checked 2015-03-11 15:30:50, Info CSI 000004f3 [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:30:50, Info CSI 000004f5 [SR] Verify complete 2015-03-11 15:30:50, Info CSI 000004f6 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:50, Info CSI 000004f7 [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:54, Info CSI 000004fa [SR] Verify complete 2015-03-11 15:30:54, Info CSI 000004fb [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:54, Info CSI 000004fc [SR] Beginning Verify and Repair transaction 2015-03-11 15:30:57, Info CSI 000004fe [SR] Verify complete 2015-03-11 15:30:57, Info CSI 000004ff [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:30:57, Info CSI 00000500 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:00, Info CSI 00000502 [SR] Verify complete 2015-03-11 15:31:00, Info CSI 00000503 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:31:00, Info CSI 00000504 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:04, Info CSI 00000506 [SR] Verify complete 2015-03-11 15:31:04, Info CSI 00000507 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:31:04, Info CSI 00000508 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:09, Info CSI 0000050b [SR] Verify complete 2015-03-11 15:31:09, Info CSI 0000050c [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:31:09, Info CSI 0000050d [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:12, Info CSI 0000050f [SR] Verify complete 2015-03-11 15:31:12, Info CSI 00000510 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:31:12, Info CSI 00000511 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:17, Info CSI 00000513 [SR] Verify complete 2015-03-11 15:31:17, Info CSI 00000514 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:31:17, Info CSI 00000515 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:22, Info CSI 00000517 [SR] Verify complete 2015-03-11 15:31:22, Info CSI 00000518 [SR] Verifying 100 (0x0000000000000064) components 2015-03-11 15:31:22, Info CSI 00000519 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:25, Info CSI 0000051b [SR] Verify complete 2015-03-11 15:31:25, Info CSI 0000051c [SR] Verifying 51 (0x0000000000000033) components 2015-03-11 15:31:25, Info CSI 0000051d [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:27, Info CSI 0000051f [SR] Verify complete 2015-03-11 15:31:27, Info CSI 00000520 [SR] Repairing 13 (0x000000000000000d) components 2015-03-11 15:31:27, Info CSI 00000521 [SR] Beginning Verify and Repair transaction 2015-03-11 15:31:27, Info CSI 00000522 [SR] Cannot repair member file [l:20{10}]"hhctrl.ocx" of Microsoft-Windows-HtmlHelp, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000523 [SR] Cannot repair member file [l:14{7}]"tdc.ocx" of Microsoft-Windows-IE-DataControl, Version = 11.2.9600.16428, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000524 [SR] Cannot repair member file [l:18{9}]"msdxm.ocx" of Microsoft-Windows-MediaPlayer-Core, Version = 6.1.7601.18150, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000525 [SR] Cannot repair member file [l:20{10}]"sysmon.ocx" of Microsoft-Windows-PerformanceToolsGui, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000526 [SR] Cannot repair member file [l:18{9}]"wshom.ocx" of Microsoft-Windows-Scripting, Version = 6.1.7601.18283, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000527 [SR] Cannot repair member file [l:22{11}]"Bubbles.scr" of Microsoft-Windows-Bubbles, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000528 [SR] Cannot repair member file [l:20{10}]"dmview.ocx" of Microsoft-Windows-DiskManagement, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000529 [SR] Cannot repair member file [l:22{11}]"Mystify.scr" of Microsoft-Windows-Mystify, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000052a [SR] Cannot repair member file [l:40{20}]"PhotoScreensaver.scr" of Microsoft-Windows-PhotoScreensaver, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000052b [SR] Cannot repair member file [l:22{11}]"Ribbons.scr" of Microsoft-Windows-Ribbons, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000052c [SR] Cannot repair member file [l:24{12}]"scrnsave.scr" of Microsoft-Windows-scrnsave, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000052d [SR] Cannot repair member file [l:24{12}]"msscript.ocx" of Microsoft-Windows-Scripting-MSScript, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000052e [SR] Cannot repair member file [l:24{12}]"ssText3d.scr" of Microsoft-Windows-ssText3d, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000052f [SR] Cannot repair member file [l:18{9}]"wshom.ocx" of Microsoft-Windows-Scripting, Version = 6.1.7601.18283, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000530 [SR] This component was referenced by [l:154{77}]"Package_2_for_KB2892074~31bf3856ad364e35~amd64~~6.1.1.0.2892074-4_neutral_GDR" 2015-03-11 15:31:27, Info CSI 00000531 [SR] Cannot repair member file [l:22{11}]"Ribbons.scr" of Microsoft-Windows-Ribbons, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000532 [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:31:27, Info CSI 00000533 [SR] Cannot repair member file [l:24{12}]"ssText3d.scr" of Microsoft-Windows-ssText3d, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000534 [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:31:27, Info CSI 00000535 [SR] Cannot repair member file [l:24{12}]"scrnsave.scr" of Microsoft-Windows-scrnsave, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000536 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:31:27, Info CSI 00000537 [SR] Cannot repair member file [l:24{12}]"msscript.ocx" of Microsoft-Windows-Scripting-MSScript, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 00000538 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:31:27, Info CSI 00000539 [SR] Cannot repair member file [l:20{10}]"dmview.ocx" of Microsoft-Windows-DiskManagement, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:27, Info CSI 0000053a [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:31:28, Info CSI 0000053b [SR] Repaired file \SystemRoot\WinSxS\Manifests\\[ml:22{11},l:20{10}]"hhctrl.ocx" by copying from backup 2015-03-11 15:31:28, Info CSI 0000053c [SR] Cannot repair member file [l:20{10}]"sysmon.ocx" of Microsoft-Windows-PerformanceToolsGui, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:28, Info CSI 0000053d [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery" 2015-03-11 15:31:28, Info CSI 0000053e [SR] Cannot repair member file [l:22{11}]"Bubbles.scr" of Microsoft-Windows-Bubbles, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:28, Info CSI 0000053f [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:31:28, Info CSI 00000540 [SR] Cannot repair member file [l:14{7}]"tdc.ocx" of Microsoft-Windows-IE-DataControl, Version = 11.2.9600.16428, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:28, Info CSI 00000541 [SR] This component was referenced by [l:230{115}]"Microsoft-Windows-InternetExplorer-VistaPlus-Update~31bf3856ad364e35~amd64~~11.2.9600.16428.Internet-Explorer-amd64" 2015-03-11 15:31:28, Info CSI 00000542 [SR] Cannot repair member file [l:18{9}]"msdxm.ocx" of Microsoft-Windows-MediaPlayer-Core, Version = 6.1.7601.18150, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:28, Info CSI 00000543 [SR] This component was referenced by [l:154{77}]"Package_1_for_KB2847077~31bf3856ad364e35~amd64~~6.1.1.1.2847077-2_neutral_GDR" 2015-03-11 15:31:29, Info CSI 00000544 [SR] Cannot repair member file [l:22{11}]"Mystify.scr" of Microsoft-Windows-Mystify, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:29, Info CSI 00000545 [SR] This component was referenced by [l:242{121}]"Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.Microsoft-Windows-Client-Features-Update" 2015-03-11 15:31:29, Info CSI 00000546 [SR] Cannot repair member file [l:40{20}]"PhotoScreensaver.scr" of Microsoft-Windows-PhotoScreensaver, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing 2015-03-11 15:31:29, Info CSI 00000547 [SR] This component was referenced by [l:182{91}]"Microsoft-Windows-PhotoBasicPackage~31bf3856ad364e35~amd64~~6.1.7601.17514.PhotoBasicUpdate" 2015-03-11 15:31:29, Info CSI 00000549 [SR] Repair complete 2015-03-11 15:31:29, Info CSI 0000054a [SR] Committing transaction 2015-03-11 15:31:29, Info CSI 0000054e [SR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction have been successfully repaired |
11.03.2015, 17:00 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert hi,
__________________Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter LastRegBack: 2015-03-06 06:45
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ |
11.03.2015, 17:22 | #3 |
| Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert Hallo Schrauber,
__________________hier ist fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by SYSTEM at 2015-03-11 17:20:02 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** LastRegBack: 2015-03-06 06:45 ***************** DEFAULT hive was successfully copied to System32\config\HiveBackup DEFAULT hive was successfully restored from registry back up. SAM hive was successfully copied to System32\config\HiveBackup SAM hive was successfully restored from registry back up. SECURITY hive was successfully copied to System32\config\HiveBackup SECURITY hive was successfully restored from registry back up. SOFTWARE hive was successfully copied to System32\config\HiveBackup SOFTWARE hive was successfully restored from registry back up. SYSTEM hive was successfully copied to System32\config\HiveBackup SYSTEM hive was successfully restored from registry back up. ==== End of Fixlog 17:20:08 ==== |
12.03.2015, 08:59 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert Kannste normal booten? Achtung: Panda-Virenscanner zerschießt Windows, nicht Neustarten! | heise online
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.03.2015, 19:37 | #5 |
| fehlende dll-Dateien verhindern recovery-Lösung Hallo schrauber, vielen Dank für die schnelle Hilfestellung! Das Panda-Problem scheint eine heiße Spur zu sein! Windows hat sich nach einigen Starts im abgesichterten Modus wieder so weit repariert, daß es nun im normalen Modus zumindest wieder hochfährt. Leider funktioniert auch da noch nicht sehr viel - z.B. kann ich die von Panda vorgeschlagene Lösung nicht umsetzen, weil das ps-security-Programm wegen fehlender COMCTL32.dll-Datei nicht startet. Panda hat darauf gerade mit einem erweiterten Lösungsvorschlag reagiert: hxxp://www.pandasecurity.com/uk/homeusers/support/card?id=100046. Leider scheitert dieser Vorschlag bei mir am Entpacken der Datei: "Fehler 0x80004005". Das ist wahrscheinlich auch nur die Spitze des Eisbergs. Wie kann ich hier weiter vorgehen? Mit bestem Dank und Gruß! Glücklicherweise konnte ich den Computer mit einem früheren Wiederherstellungspunkt wieder reanimieren. Das Thema kann daher geschlossen werden. Mit bestem Dank! theGardener Geändert von theGardener (12.03.2015 um 12:59 Uhr) |
13.03.2015, 10:17 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert ok
__________________ --> Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert |
Themen zu Windows 7: Verdacht auf Virus - fehlende .dll-Dateien, Programmaufrufe blockiert |
.exe und .dll-dateien fehlerhaft, adobe, akamai, antivir, avg, avira, blockiert, defender, desktop, exe-dateien, firefox, hängt, installation, launch, malware, mozilla, psuamain.exe, realtek, registry, scan, security, services.exe, software, starten, svchost.exe, usbvideo.sys, virus, windows, windows 7, windows xp, wlan |