|
Plagegeister aller Art und deren Bekämpfung: DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöschtWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.05.2015, 14:31 | #1 |
| DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Hallo liebes Trojaner Board, ich habe, wie viele andere auch diese vorgebliche DHL-Mail bekommen und da ich auf eine Lieferung gewartet habe, habe ich im Affekt auf den link geklickt. Als dann die ZIP Datei in den Downloadordner wanderte, hatte ich meinen Fehler gleich bemerkt und die Datei gelöscht. Anschließend habe ich einen Scan mit Antivir und Spybot - Search and Destroy 2.2 gemacht und bin dann auf euer Forum gestoßen. Dummerweise habe ich mich nicht an die Regeln gehalten bzw. diese gelesen , sondern ich habe der Reihenfolge nach Kaspersky TDSSKiller, Malwarebyte (Korrekturen ausgeführt! - siehe log file), Adw Cleaner (Korrekturen ausgeführt! - siehe log file) und Junkware Removal Tool (siehe log file) benutzt. Danach habe ich auch den Eset online scanner laufen lassen (leider vergessen die log-file zu speichern und deinstallieren lassen). Es wurde nirgendwo etwas gefunden! Dennoch bin ich etwas paranoid geworden und habe den Kaspersky noch mal mit dem Häckchen bei "Verify digital signature" gemacht und dann findet er zumindest einen "suspicious file": Service:WUDFRd...!? Kann den ein ZIP-file Schaden anrichten wenn man ihn nicht mal angeklickt bzw. entpackt hat? Sollte ich noch irgendwas tun? Vielen Dank und Beste Grüße, Stefan Aktueller FRST File: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015 01 Ran by Labrat (administrator) on MAX_POWERS on 08-05-2015 15:17:46 Running from C:\Users\Labrat\Downloads Loaded Profiles: Labrat (Available profiles: Labrat & Labrat_Adm) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Opera) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (AMD) C:\Windows\System32\atieclxx.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\Windows\runservice.exe ( ) C:\Windows\System32\lxbxcoms.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Micro-Star International) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe () C:\Program Files (x86)\Vidalia Bridge Bundle\Tor\tor.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe () C:\Program Files (x86)\Opera\29.0.1795.47\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe (Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12480616 2012-04-24] (Realtek Semiconductor) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [728312 2015-05-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2014-10-16] (Cisco Systems, Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Run: [Vidalia] => C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe [6239727 2014-01-18] () HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.) HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Run: [OscarEditor] => "C:\Program Files (x86)\MOUSE Editor\\MouseEditor.exe" Minimum HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\MountPoints2: {1e62b01c-2ad6-11df-95af-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\MountPoints2: {e5b8d7e1-ded8-11e4-acb4-806e6f6e6963} - E:\SETUP.EXE HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\MountPoints2: {f25e9aa2-4740-11e0-b2ef-0024211056dd} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Autorun.exe HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-11-10] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-11-10] (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Labrat\AppData\Roaming\Mozilla\Firefox\Profiles\d5h5b9mo.default-1412722597851 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.104.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.118.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.138.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-25] (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-10] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-11-10] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-01-14] (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=1.1.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1690515653-3619170862-1892073707-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2014-12-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Extension: NoScript - C:\Users\Labrat\AppData\Roaming\Mozilla\Firefox\Profiles\d5h5b9mo.default-1412722597851\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-01-23] FF Extension: Adblock Plus - C:\Users\Labrat\AppData\Roaming\Mozilla\Firefox\Profiles\d5h5b9mo.default-1412722597851\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-23] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-04-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2015-04-24] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-04] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-11-14] FF HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.95\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.95\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.95\pdf.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL No File CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Wolfram Mathematica) - C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.4.2609412\npmathplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 6 U39) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.390.4) - C:\Windows\SysWOW64\npdeployJava1.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Profile: C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-15] CHR Extension: (Google Search) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-15] CHR Extension: (Skype Click to Call) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-02-15] CHR Extension: (Gmail) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-15] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17] Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Labrat\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2013-11-19] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeActiveFileMonitor5.0; C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe [102400 2006-09-14] () [File not signed] R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [File not signed] S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827640 2015-05-05] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1185584 2015-05-05] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation) R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 LicCtrlService; C:\Windows\runservice.exe [16384 2010-09-28] () [File not signed] R2 lxbx_device; C:\Windows\system32\lxbxcoms.exe [566704 2007-03-22] ( ) R2 lxbx_device; C:\Windows\SysWOW64\lxbxcoms.exe [537520 2007-03-22] ( ) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [84432 2014-07-01] (Micro-Star International) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [162800 2014-03-17] (MSI) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) S2 SuperRAIDSvc; C:\MSI\Smart Utilities\SuperRAIDSvc.exe [27632 2014-04-30] (Micro-Star International) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11944 2012-12-03] (Advanced Micro Devices Inc.) S0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices) S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () [File not signed] R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-03-16] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [152744 2015-05-05] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-05-05] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-10] (Avira Operations GmbH & Co. KG) S3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdpt.sys [32768 2013-02-18] (Juniper Networks) [File not signed] S3 johci; C:\Windows\System32\DRIVERS\johci.sys [26200 2011-11-30] (JMicron Technology Corp.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-03-16] () R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [31024 2012-08-02] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-08] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation) R0 MxEFUF; C:\Windows\System32\DRIVERS\MxEFUF64.sys [157696 2011-10-20] (Matrox Graphics Inc.) S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI) S3 NTIOLib_MSI_RAID; C:\MSI\Smart Utilities\NTIOLib_X64.sys [13808 2014-03-17] (MSI) R3 pikbd; C:\Windows\System32\DRIVERS\pikbd.sys [22880 2013-11-30] (Christian Gulden) S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [402024 2012-02-23] (Realtek Semiconductor Corporation ) S3 SliceDisk5; C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [31824 2011-02-25] (Atola) [File not signed] R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider) S3 StarOpen; No ImagePath R3 ubohci; C:\Windows\System32\DRIVERS\ubohci.sys [132608 2012-10-05] (Unibrain) R2 ubsbm; C:\Windows\System32\DRIVERS\ubsbm.sys [24064 2012-10-05] (Unibrain) R2 ubumapi; C:\Windows\System32\DRIVERS\ubumapi.sys [92160 2012-10-05] (Unibrain) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [51712 2011-02-18] (Apple, Inc.) [File not signed] S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-10-16] (Cisco Systems, Inc.) S3 WUDFRd; C:\Windows\system32\drivers\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) [File not signed] R3 ZCLDRV; C:\Windows\System32\DRIVERS\ZclDrv64.sys [71680 2013-06-27] (TechnoScope Co., Ltd.) S3 FLASHSYS; \??\C:\Program Files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP1\WNt500x64\Sandra.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-08 15:14 - 2015-05-08 15:14 - 00000000 ____D () C:\Users\Labrat\Downloads\FRST-OlderVersion 2015-05-08 08:49 - 2015-05-08 08:49 - 00000000 ____D () C:\TDSSKiller_Quarantine 2015-05-06 20:23 - 2015-05-06 20:38 - 00000000 ____D () C:\Users\Labrat\Desktop\FIgures_PDF 2015-05-06 13:14 - 2015-05-06 13:14 - 02347384 _____ (ESET) C:\Users\Labrat\Downloads\esetsmartinstaller_deu.exe 2015-05-06 13:09 - 2015-05-06 13:09 - 00090375 _____ () C:\Users\Labrat\Downloads\Addition.txt 2015-05-06 13:08 - 2015-05-08 15:17 - 00029428 _____ () C:\Users\Labrat\Downloads\FRST.txt 2015-05-06 13:08 - 2015-05-08 15:17 - 00000000 ____D () C:\FRST 2015-05-06 13:07 - 2015-05-08 15:14 - 02102272 _____ (Farbar) C:\Users\Labrat\Downloads\FRST64.exe 2015-05-06 13:06 - 2015-05-06 13:06 - 00001082 _____ () C:\Users\Labrat\Desktop\JRT.txt 2015-05-06 12:26 - 2015-05-06 12:26 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-MAX_POWERS-Windows-7-Professional-(64-bit).dat 2015-05-06 12:26 - 2015-05-06 12:26 - 00000000 ____D () C:\RegBackup 2015-05-06 12:18 - 2015-05-06 12:52 - 00000000 ____D () C:\AdwCleaner 2015-05-06 12:16 - 2015-05-06 13:10 - 00000000 ____D () C:\Users\Labrat\Desktop\Virensuchlauf 2015-05-06 11:53 - 2015-05-08 15:15 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-06 11:53 - 2015-05-06 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-05-06 11:53 - 2015-05-06 11:53 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-05-06 11:53 - 2015-05-06 11:53 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-05-06 11:53 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-05-06 11:53 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-05-06 11:53 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-05-06 11:51 - 2015-05-06 11:52 - 02716306 _____ (Thisisu) C:\Users\Labrat\Downloads\JRT.exe 2015-05-06 11:51 - 2015-05-06 11:51 - 02204160 _____ () C:\Users\Labrat\Downloads\AdwCleaner_4.203.exe 2015-05-06 11:50 - 2015-05-06 11:52 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Labrat\Downloads\mbam-setup-2.1.6.1022.exe 2015-05-06 11:39 - 2015-05-06 12:54 - 00003980 _____ () C:\Windows\PFRO.log 2015-05-06 01:05 - 2015-03-14 05:21 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-05-06 01:05 - 2015-03-14 05:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-05-06 01:05 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-05-06 01:05 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll 2015-05-06 01:05 - 2015-03-04 06:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-05-06 01:05 - 2015-03-04 06:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-05-06 01:05 - 2015-03-04 06:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-05-06 01:05 - 2015-03-04 06:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-05-06 01:05 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-05-06 01:05 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-05-06 01:05 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-05-06 01:05 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2015-05-06 01:05 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2015-05-06 01:05 - 2015-01-29 05:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll 2015-05-06 01:05 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll 2015-05-03 12:23 - 2015-05-03 12:25 - 00000000 ____D () C:\Users\Labrat\Desktop\Tickets_u_Buchungsbestätigungen 2015-04-29 14:35 - 2015-05-03 12:38 - 00021331 _____ () C:\Users\Labrat\Desktop\Adressen_SJ.xlsx 2015-04-24 00:52 - 2015-04-24 00:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-04-22 20:46 - 2015-05-08 14:22 - 00004999 _____ () C:\Windows\setupact.log 2015-04-22 20:46 - 2015-04-22 20:46 - 00000000 _____ () C:\Windows\setuperr.log 2015-04-22 09:28 - 2015-04-22 09:45 - 00074103 _____ () C:\Users\Labrat\Desktop\TEST_BIPLOT.xlsx 2015-04-15 15:40 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-15 15:40 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-15 15:40 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-15 15:40 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-15 15:40 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-15 15:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-04-15 15:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-04-15 15:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-04-15 15:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-04-15 15:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-04-15 15:40 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-15 15:40 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-15 15:40 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-15 15:40 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-15 15:40 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-15 15:40 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-15 15:40 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-15 15:40 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-15 15:40 - 2015-03-17 07:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-15 15:40 - 2015-03-17 07:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-15 15:40 - 2015-03-17 07:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-15 15:40 - 2015-03-17 07:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-15 15:40 - 2015-03-17 07:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-04-15 15:40 - 2015-03-17 07:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-04-15 15:40 - 2015-03-17 07:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-15 15:40 - 2015-03-17 07:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-15 15:40 - 2015-03-17 07:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-15 15:40 - 2015-03-17 07:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-04-15 15:40 - 2015-03-17 07:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-04-15 15:40 - 2015-03-17 07:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-15 15:40 - 2015-03-17 07:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-15 15:40 - 2015-03-17 07:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-15 15:40 - 2015-03-17 07:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-04-15 15:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-04-15 15:40 - 2015-03-17 06:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-04-15 15:40 - 2015-03-17 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-04-15 15:40 - 2015-03-17 06:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-04-15 15:40 - 2015-03-17 06:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-04-15 15:40 - 2015-03-17 06:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-04-15 15:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-04-15 15:40 - 2015-03-17 06:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-04-15 15:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-04-15 15:40 - 2015-03-17 06:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-04-15 15:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-04-15 15:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 05:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-04-15 15:40 - 2015-03-17 05:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-04-15 15:40 - 2015-03-17 05:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-04-15 15:40 - 2015-03-17 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-04-15 15:40 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-15 15:40 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-15 15:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2015-04-15 15:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2015-04-15 15:40 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-15 15:40 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-04-15 15:39 - 2015-04-02 02:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-04-15 15:39 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-04-15 15:39 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-04-15 15:39 - 2015-03-13 06:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-04-15 15:39 - 2015-03-13 06:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-04-15 15:39 - 2015-03-13 06:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-04-15 15:39 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-04-15 15:39 - 2015-03-13 06:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-04-15 15:39 - 2015-03-13 06:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-04-15 15:39 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-04-15 15:39 - 2015-03-13 06:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-04-15 15:39 - 2015-03-13 06:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-04-15 15:39 - 2015-03-13 05:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-04-15 15:39 - 2015-03-13 05:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-04-15 15:39 - 2015-03-13 05:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-04-15 15:39 - 2015-03-13 05:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-04-15 15:39 - 2015-03-13 05:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-04-15 15:39 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-04-15 15:39 - 2015-03-13 05:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-04-15 15:39 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-04-15 15:39 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-04-15 15:39 - 2015-03-13 05:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-04-15 15:39 - 2015-03-13 05:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-04-15 15:39 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-04-15 15:39 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-04-15 15:39 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-04-15 15:39 - 2015-03-13 05:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-04-15 15:39 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-04-15 15:39 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-04-15 15:39 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-04-15 15:39 - 2015-03-13 05:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-04-15 15:39 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-04-15 15:39 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-04-15 15:39 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-04-15 15:39 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-04-15 15:39 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-04-15 15:39 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-04-15 15:39 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-04-15 15:39 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-04-15 15:39 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-04-15 15:39 - 2015-03-13 05:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-04-15 15:39 - 2015-03-13 05:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-04-15 15:39 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-04-15 15:39 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-04-15 15:39 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-04-15 15:39 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-04-15 15:39 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-04-15 15:39 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-04-15 15:39 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-04-15 15:39 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-04-15 15:39 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-04-15 15:39 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-04-15 15:39 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-04-15 15:39 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-04-15 15:39 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-04-15 15:39 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-04-15 15:39 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-04-15 15:39 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-04-15 15:39 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-15 15:37 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-15 15:37 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-15 15:37 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-04-14 23:22 - 2015-04-14 23:22 - 00000000 ____D () C:\Users\Labrat\AppData\Local\openvr 2015-04-09 19:22 - 2015-04-09 19:22 - 00000202 _____ () C:\Users\Labrat\Desktop\Pillars of Eternity.url 2015-04-08 19:53 - 2015-04-11 11:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2015-04-08 01:46 - 2015-04-08 01:46 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-08 01:46 - 2015-04-08 01:46 - 00000000 ___SD () C:\Windows\system32\GWX ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-08 14:40 - 2014-11-04 12:46 - 00000306 _____ () C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job 2015-05-08 14:40 - 2014-01-30 11:51 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\tor 2015-05-08 14:40 - 2014-01-30 11:51 - 00000000 ____D () C:\Users\Labrat\AppData\Local\Vidalia 2015-05-08 14:32 - 2012-04-02 10:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-08 14:31 - 2009-07-14 06:45 - 00025552 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-08 14:31 - 2009-07-14 06:45 - 00025552 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-08 14:22 - 2010-09-28 19:26 - 00000049 ___SH () C:\Windows\SysWOW64\mmf.sys 2015-05-08 14:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-08 08:49 - 2013-10-12 14:35 - 01398715 _____ () C:\Windows\WindowsUpdate.log 2015-05-06 22:48 - 2010-10-17 17:57 - 00000000 ____D () C:\Users\Labrat\Desktop\Programme 2015-05-06 21:32 - 2013-09-09 00:13 - 01594028 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-05-06 21:32 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2015-05-06 21:32 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2015-05-06 21:32 - 2009-07-14 07:13 - 01594028 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-06 11:40 - 2014-11-04 12:46 - 00002582 _____ () C:\Windows\System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c 2015-05-06 11:11 - 2010-03-09 11:30 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\Skype 2015-05-06 10:12 - 2015-01-14 00:31 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2015-05-06 01:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-05-05 11:06 - 2013-04-12 08:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-05-05 11:03 - 2013-04-12 08:56 - 00152744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-05-05 11:03 - 2013-04-12 08:56 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-05-04 08:35 - 2014-02-16 19:33 - 00000000 ____D () C:\Users\Labrat\Desktop\SlowFood 2015-04-28 18:43 - 2013-08-29 07:59 - 00000000 ____D () C:\Users\Labrat\Desktop\Zeug 2015-04-28 14:19 - 2014-06-03 13:54 - 00003856 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1379505506 2015-04-28 14:19 - 2010-03-09 11:29 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-04-28 14:11 - 2012-09-03 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-04-26 23:14 - 2014-06-10 09:56 - 00530966 _____ () C:\Users\Labrat\Desktop\Master_Lib.enl 2015-04-24 23:37 - 2014-07-07 18:07 - 00000000 ____D () C:\Users\Labrat\Desktop\Manuscript 2015-04-24 14:37 - 2011-07-17 15:13 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\vlc 2015-04-22 21:40 - 2014-02-28 19:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2015-04-22 21:38 - 2014-02-28 19:38 - 00000000 ____D () C:\Users\Labrat\AppData\Local\Battle.net 2015-04-22 10:49 - 2012-09-04 10:56 - 00001023 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-04-22 10:49 - 2010-03-09 11:35 - 00000000 ____D () C:\Program Files (x86)\CCleaner 2015-04-22 09:55 - 2015-01-14 16:05 - 00000000 ____D () C:\Users\Labrat\Desktop\LITERATUR_Dissertation 2015-04-22 08:57 - 2014-01-30 12:00 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2015-04-16 22:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2015-04-16 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2015-04-16 20:01 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-04-15 20:39 - 2012-04-02 10:28 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-15 20:39 - 2012-04-02 10:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-15 20:39 - 2011-05-14 11:31 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-15 16:07 - 2014-12-11 00:30 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-15 16:07 - 2014-05-06 13:34 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-15 16:02 - 2013-07-30 17:11 - 00000000 ____D () C:\Windows\system32\MRT 2015-04-15 15:58 - 2010-03-08 19:44 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-09 16:04 - 2013-01-05 19:18 - 00000000 ____D () C:\Users\Labrat\Desktop\Rezepte 2015-04-09 15:58 - 2014-09-23 10:31 - 00000000 ____D () C:\Users\Labrat\Desktop\Doktorand 2015-04-09 15:56 - 2014-08-14 09:21 - 00001143 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-04-09 15:56 - 2014-08-14 09:20 - 00000000 ____D () C:\ProgramData\Package Cache 2015-04-09 15:56 - 2013-04-12 08:56 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-04-08 19:36 - 2015-01-14 01:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote 2015-04-08 19:36 - 2015-01-14 01:47 - 00000000 ____D () C:\Program Files (x86)\EndNote X7 2015-04-08 19:36 - 2010-07-09 12:57 - 00000000 ____D () C:\ProgramData\Thomson.ResearchSoft.Installers 2015-04-08 19:36 - 2010-03-08 19:37 - 00000000 ____D () C:\Users\Labrat 2015-04-08 01:09 - 2013-04-12 09:02 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\Avira 2015-04-08 01:08 - 2013-04-12 08:56 - 00000000 ____D () C:\ProgramData\Avira ==================== Files in the root of some directories ======= 2012-05-08 15:15 - 2012-05-08 15:15 - 0000005 _____ () C:\Program Files (x86)\basis-link 2012-08-13 11:57 - 2012-08-13 11:57 - 0012927 _____ () C:\Program Files (x86)\readme.html 2012-08-13 11:57 - 2012-08-13 11:57 - 0012558 _____ () C:\Program Files (x86)\readme.txt 2011-08-14 13:29 - 2011-08-14 13:29 - 0007605 _____ () C:\Users\Labrat\AppData\Local\Resmon.ResmonCfg 2010-03-09 11:31 - 2010-03-09 11:31 - 0000056 ____H () C:\ProgramData\ezsidmv.dat 2013-11-14 17:36 - 2014-03-13 09:44 - 0002345 _____ () C:\ProgramData\hpzinstall.log 2012-04-09 15:18 - 2012-04-09 21:04 - 0000040 _____ () C:\ProgramData\ra3.ini Files to move or delete: ==================== C:\Users\Labrat\cc_20140526_224255.reg C:\Users\Labrat\cc_20140602_191308.reg Some content of TEMP: ==================== C:\Users\Labrat\AppData\Local\Temp\avgnt.exe C:\Users\Labrat\AppData\Local\Temp\Quarantine.exe C:\Users\Labrat\AppData\Local\Temp\sqlite3.dll C:\Users\Labrat_Adm\AppData\Local\Temp\AskSLib.dll C:\Users\Labrat_Adm\AppData\Local\Temp\avgnt.exe C:\Users\Labrat_Adm\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Labrat_Adm\AppData\Local\Temp\nvStereoApiI64.dll C:\Users\Labrat_Adm\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-05 20:51 ==================== End Of Log ============================ --- --- --- Geändert von Labrat (08.05.2015 um 14:39 Uhr) |
08.05.2015, 14:35 | #2 |
| DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht FRST Addition:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-05-2015 01 Ran by Labrat at 2015-05-08 15:18:16 Running from C:\Users\Labrat\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1690515653-3619170862-1892073707-500 - Administrator - Disabled) Gast (S-1-5-21-1690515653-3619170862-1892073707-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1690515653-3619170862-1892073707-1002 - Limited - Enabled) Labrat (S-1-5-21-1690515653-3619170862-1892073707-1001 - Administrator - Enabled) => C:\Users\Labrat Labrat_Adm (S-1-5-21-1690515653-3619170862-1892073707-1005 - Administrator - Enabled) => C:\Users\Labrat_Adm ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 4.65 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0465-000001000000}) (Version: 4.65.00.0 - Igor Pavlov) Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Photoshop Elements 5.0 (HKLM-x32\...\Adobe Photoshop Elements 5) (Version: 5.0 - Adobe Systems Inc.) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.03.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Apple Application Support (32-bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ATI AVIVO64 Codecs (Version: 11.6.0.50730 - ATI Technologies Inc.) Hidden ATI Catalyst Registration (x32 Version: 3.00.0000 - ATI Technologies Inc.) Hidden Avira (HKLM-x32\...\{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}) (Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG) Baldur's Gate II: Enhanced Edition (HKLM-x32\...\Steam App 257350) (Version: - Beamdog) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.4.0.0 - Electronic Arts) Battlefield 3™ (HKLM-x32\...\{77033683-0816-4D7D-8BF1-3949B4E9823D}) (Version: 1.0.0.0 - Electronic Arts) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden Bulletstorm (HKLM-x32\...\GFWL_{45410935-3E72-472B-8C35-AB1000008200}) (Version: 1.0.0000.130 - EA) Bulletstorm (x32 Version: 1.0.0000.130 - EA) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05187 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05187 - Cisco Systems, Inc.) Hidden Command & Conquer™ Alarmstufe Rot 3 - Englisches Sprachpaket (HKLM-x32\...\Red Alert 3 English Language Pack) (Version: 1.0 - Thundermods.net) Command & Conquer™ Alarmstufe Rot 3 (HKLM-x32\...\{296D8550-CB06-48E4-9A8B-E5034FB64715}) (Version: 1.0.1.0 - Electronic Arts) Command and Conquer 3: Tiberium Wars (HKLM-x32\...\Steam App 24790) (Version: - EA Los Angeles) Company of Heroes 2 (HKLM-x32\...\Steam App 231430) (Version: - Relic Entertainment) D7200 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden D7200_Help (x32 Version: 100.0.206.000 - Hewlett-Packard) Hidden DarthMod Empire (HKLM-x32\...\DarthMod Empire8.0 Platinum) (Version: 8.0 Platinum - ) Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform) Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version: - Eidos Montreal) DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Dragon Age Awakening Redesigned (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Awakening Redesigned) (Version: - ) Dragon Age Awakening Velanna Redesigned© (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Awakening Velanna Redesigned©) (Version: - ) Dragon Age Redesigned © Morrigan (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned © Morrigan) (Version: - ) Dragon Age Redesigned Oghren© (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned Oghren©) (Version: - ) Dragon Age Redesigned© Zevran (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Zevran) (Version: - ) Dragon Age Redesigned© (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned©) (Version: - ) Dragon Age Redesigned© Leliana (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Leliana) (Version: - ) Dragon Age Redesigned© Sten (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Sten) (Version: - ) Dragon Age Redesigned© Wynne (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Wynne) (Version: - ) DriverMax 7 (HKLM-x32\...\DMX5_is1) (Version: 7.44.0.738 - Innovative Solutions) Dropbox (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 13.3.0.9066 - Landesfinanzdirektion Thüringen) Empire: Total War (HKLM-x32\...\Steam App 10500) (Version: - The Creative Assembly) EndNote X7 (HKLM-x32\...\{86B3F2D6-AC2B-0017-8AE1-F2F77F781B0C}) (Version: 17.3.0.8536 - Thomson Reuters) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) FAKEFACTORY Cinematic Mod V10 (HKLM-x32\...\FAKEFACTORY CM10V10.40) (Version: V10.40 - FAKEFACTORY) Fallout 3 (HKLM-x32\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks) Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version: - Bethesda Softworks) Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai) Find and Mount 2.32 (HKLM\...\Find and Mount_is1) (Version: 2.32 - A-FF Data Recovery) GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games) Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve) Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve) Half-Life: Source (HKLM-x32\...\Steam App 280) (Version: - Valve) HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software) HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP) HP Photosmart Printer Driver Software 13.0 Rel. 2 (HKLM\...\{F69E48F2-94B0-4272-845C-5F21F2A9815F}) (Version: 13.0 - HP) HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM-x32\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard) HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HydraVision (x32 Version: 4.2.174.0 - ATI Technologies Inc.) Hidden IBM SPSS Statistics 22 (HKLM\...\{104875A1-D083-4A34-BC4F-3F635B7F8EF7}) (Version: 22.0.0.0 - IBM Corp) iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.) Japanese Fonts Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5760-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated) Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Lexmark 7100 Series (HKLM\...\Lexmark 7100 Series) (Version: - Lexmark International, Inc.) Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden Medieval II Total War (HKLM-x32\...\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}) (Version: 1.03.000 - SEGA) Medieval II Total War : Kingdoms : Americas (HKLM-x32\...\{75983B66-804C-40D1-BA13-64DAF652A6F1}) (Version: 1.03.000 - SEGA) Medieval II Total War : Kingdoms : Britannia (HKLM-x32\...\{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}) (Version: 1.03.000 - SEGA) Medieval II Total War : Kingdoms : Crusades (HKLM-x32\...\{02A10468-2F1C-447C-AD8E-4DEDDEA25AE2}) (Version: 1.03.000 - SEGA) Medieval II Total War : Kingdoms : Teutonic (HKLM-x32\...\{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}) (Version: 1.03.000 - SEGA) Mendeley Desktop 1.12.3 (HKLM-x32\...\Mendeley Desktop) (Version: 1.12.3 - Mendeley Ltd.) Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - THQ) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4711.1003 - Microsoft Corporation) Microsoft Office Proofing Tools 2013 - English (HKLM-x32\...\{90150000-001F-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM-x32\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mozilla Thunderbird 31.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.6.0 (x86 de)) (Version: 31.6.0 - Mozilla) MSI Live Update (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.0.006 - MSI) MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.025 - MSI) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.16.4 - Black Tree Gaming) NVIDIA Grafiktreiber 344.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.75 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4711.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice.org 3.4.1 (HKLM-x32\...\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation) Opera Stable 29.0.1795.47 (HKLM-x32\...\Opera 29.0.1795.47) (Version: 29.0.1795.47 - Opera Software ASA) Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PDF Architect (HKLM-x32\...\{30B41B7A-3C9D-44DE-A7A1-949011F33CC3}) (Version: 1.0.41.8362 - pdfforge) Pillars of Eternity (HKLM-x32\...\Steam App 291650) (Version: - Obsidian Entertainment) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) PS_SF_02_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden PS_SF_02_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden PS_SF_02_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden R for Windows 2.15.3 (HKLM\...\R for Windows 2.15.3_is1) (Version: 2.15.3 - R Core Team) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7111 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version: - Thomson Reuters) RStudio (HKLM-x32\...\RStudio) (Version: 0.97.332 - RStudio) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Source SDK (HKLM-x32\...\Steam App 211) (Version: - Valve) Source SDK Base 2006 (HKLM-x32\...\Steam App 215) (Version: - Valve) Source SDK Base 2007 (HKLM-x32\...\Steam App 218) (Version: - Valve) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Lord of the Rings FREE Trial (x32 Version: 1.00.0000 - ATI Technologies Inc.) Hidden The Witcher 2: Assassins of Kings Enhanced Edition (HKLM-x32\...\Steam App 20920) (Version: - CD Projekt RED) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden Tor 0.2.4.20 (HKLM-x32\...\Tor) (Version: - ) Total War: ROME II (HKLM-x32\...\Steam App 214950) (Version: - Creative Assembly) TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft) Vidalia 0.2.21 (HKLM-x32\...\Vidalia) (Version: - ) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 26-04-2015 21:59:43 Windows-Sicherung 28-04-2015 15:25:14 Windows Update 05-05-2015 18:24:11 Windows Update 06-05-2015 01:05:37 Windows Update 06-05-2015 11:15:04 Windows Update 06-05-2015 21:29:55 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2014-05-29 11:50 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {07FE1F6F-50EE-4A67-A1BB-3DAB9405320A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {083BE7DA-05BF-4D16-BB76-380E5CCD0058} - System32\Tasks\{780A4746-ECD4-4336-9DC8-AA267CD256EF} => c:\program files (x86)\opera\launcher.exe [2015-04-17] (Opera Software) Task: {17B28221-18C3-4FE9-A371-F4E7A284E36E} - System32\Tasks\{A9F80C0C-CE31-44A0-A326-1DA3C01652E7} => pcalua.exe -a "C:\Program Files (x86)\MSI\Live Update 4\LU4\DL_FILE\Realtek 8111 LAN Driver_6.241.0721.2010.exe" -d "C:\Program Files (x86)\MSI\Live Update 4\LU4\DL_FILE" Task: {1DFACC64-0A3D-49BE-A05E-BD14F2937860} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation) Task: {223FE3EB-059F-4B11-BD86-09B30AAA372C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {299F765B-D608-46CA-BB73-EEC726B5D903} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {2CCC2C4A-18C0-49E0-9DF7-8D052C0E86EA} - System32\Tasks\{7CEB5D3C-7692-4F24-A522-3A6259D427EB} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {360FA1DC-92DB-4648-ACAA-CF0E842C74FB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd) Task: {4131AB68-C733-46F4-87BD-2D9CB1C4EF27} - System32\Tasks\{AF70E2D3-D93E-4A06-B1CD-261DA03EF3D2} => pcalua.exe -a C:\Users\Labrat\Downloads\jxpiinstall(1).exe -d C:\Windows\system32 Task: {468A3E8E-E82E-4A5C-B843-D7775C3350E8} - System32\Tasks\{5A303460-D157-4261-9868-6A7ECD4CF561} => pcalua.exe -a "C:\Program Files (x86)\program\\swriter.exe" -c -o "C:\Users\Labrat\Desktop\Personalfragebogen_neu.doc" Task: {520BEA77-A0C8-49DF-9413-0E55EFD2C836} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated) Task: {5B26E8BC-52FF-4A04-86D0-7163C91344FE} - System32\Tasks\{DED81D3D-8C1F-4EE9-B023-F6E8FBBEDAB6} => pcalua.exe -a "C:\Users\Labrat\Desktop\Adobe Creative Suit\PSE_5.0_WIN_ESD1_ENG.exe" -d "C:\Users\Labrat\Desktop\Adobe Creative Suit" Task: {5D705D4F-AE60-49D5-8596-4DD8C7115457} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {63C8506B-CC70-48A6-A94E-C2EFE3CFF7D1} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {6458E1DD-975B-4D5E-AB5B-C99A2AD35405} - System32\Tasks\{1F46AE61-F0DD-428A-9B86-17F3C8F82001} => pcalua.exe -a "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008\vcredist_x64.exe" -d "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008" Task: {6864F499-29DB-4518-9F53-DDFED77E63CA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {71601CED-3FB1-42AC-B33C-E92D068FFFFC} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {72BC9135-7984-40DA-8066-9C9A6D668CAF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {77EAFF06-B042-4BAA-8B58-81741EFB2DA1} - System32\Tasks\{DE7694B1-A656-48E9-B942-A5AD001BD27D} => pcalua.exe -a "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008\vcredist_x86.exe" -d "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008" Task: {7C33F6E8-0264-40CD-ABE0-01E43C88115C} - System32\Tasks\{9A259AC2-61E9-43AF-A042-DB4D0E14263F} => pcalua.exe -a "D:\Spiele\MoH_beta\Support\Medal of Honor MP Beta_uninst.exe" -d D:\Spiele\MoH_beta\Support Task: {9D82C999-660D-48B7-9C78-4EE914AB68DC} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2013-09-20] (Safer-Networking Ltd.) Task: {A40A5266-8E9C-42CD-9A67-A105A15EB524} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {AC53B5DA-D300-4E7E-AA04-886ABDCBEBC7} - System32\Tasks\{261F7702-DAB9-4FC7-9014-B1F1A9745CF7} => pcalua.exe -a "D:\Steam\SteamApps\common\empire total war\Uninstall DarthMod Empire Enforced.exe" -d "D:\Steam\SteamApps\common\empire total war" Task: {B45E68E1-0A06-45B6-A1FF-45A1254E6E7A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2013-09-20] (Safer-Networking Ltd.) Task: {C9C1D77D-C196-4D49-ABA7-6AEE39627045} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2013-09-20] (Safer-Networking Ltd.) Task: {D0143E59-8C4E-41D1-B6E1-877EF1CA6951} - System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c => C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe Task: {D5938137-9D76-4D2D-9E17-2B894A186005} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {DB537226-1B45-4B2C-B6AE-2D5A73085D41} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {E173DBAE-934E-4AF1-A1F8-886025EDCED8} - System32\Tasks\{F21B8802-1E91-441D-92EB-4EA2A6765F00} => pcalua.exe -a C:\Users\Labrat\Desktop\Netfx2setup.exe -d C:\Users\Labrat\Desktop Task: {E1E4DAAF-032E-4CCA-AD85-FDE0A78AC090} - System32\Tasks\{9B9BC100-4D97-4CA6-91CA-D53B74868084} => pcalua.exe -a C:\Users\Labrat\Desktop\avira_free_antivirus_de.exe -d C:\Users\Labrat\Desktop Task: {E3ECC742-1491-405F-A761-7966349AB235} - System32\Tasks\{EE428E84-3D33-40C4-BE50-E19901A94EA4} => pcalua.exe -a E:\SETUP.EXE -d E:\ Task: {F1D13230-23F5-48C6-8BAC-22637090A9AD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation) Task: {F7DE0614-1ECA-4EFD-A39D-903235B9A448} - System32\Tasks\Opera scheduled Autoupdate 1379505506 => C:\Program Files (x86)\Opera\launcher.exe [2015-04-17] (Opera Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job => C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe ==================== Loaded Modules (whitelisted) ============== 2013-09-26 17:19 - 2014-11-12 23:56 - 00118080 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2006-09-14 08:56 - 2006-09-14 08:56 - 00102400 _____ () C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe 2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-02-13 05:20 - 2015-02-13 05:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-01-14 00:31 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2010-09-28 19:26 - 2010-09-28 19:26 - 00016384 _____ () C:\Windows\runservice.exe 2014-01-18 11:42 - 2014-01-18 11:42 - 06239727 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe 2014-01-18 12:37 - 2014-01-18 12:37 - 03610126 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Tor\tor.exe 2015-04-28 14:19 - 2015-04-28 14:18 - 00479352 _____ () C:\Program Files (x86)\Opera\29.0.1795.47\opera_crashreporter.exe 2014-10-16 02:48 - 2014-10-16 02:48 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2010-09-28 19:26 - 2010-09-28 19:26 - 00048640 _____ () C:\Windows\mmfs.dll 2014-01-30 12:00 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-01-30 12:00 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-01-30 12:00 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2014-01-30 12:00 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2014-01-30 12:00 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2009-06-23 04:42 - 2009-06-23 04:42 - 00043008 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\libgcc_s_dw2-1.dll 2011-08-24 00:59 - 2011-08-24 00:59 - 00047972 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\mingwm10.dll 2015-04-08 19:53 - 2015-04-08 19:53 - 03348592 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2015-04-08 19:53 - 2015-04-08 19:53 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2015-04-08 19:53 - 2015-04-08 19:53 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2015-04-28 14:19 - 2015-04-28 14:18 - 01576568 _____ () C:\Program Files (x86)\Opera\29.0.1795.47\libglesv2.dll 2015-04-28 14:19 - 2015-04-28 14:18 - 00081016 _____ () C:\Program Files (x86)\Opera\29.0.1795.47\libegl.dll 2015-04-15 20:39 - 2015-04-15 20:39 - 14980272 _____ () C:\Windows\SysWOW64\Macromed\Flash\pepflashplayer32_17_0_0_169.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\com -> hxxp://www.msi.com IE trusted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\com.tw -> hxxp://asia.msi.com.tw IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123simsen.com -> www.123simsen.com There are 7867 more restricted sites. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Labrat\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Labrat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup MSCONFIG\startupfolder: C:^Users^Labrat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: Adobe Photo Downloader => "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ATICustomerCare => "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" MSCONFIG\startupreg: DriverMax => "C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -agent MSCONFIG\startupreg: DriverMax_RESTART => "C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -RESTART MSCONFIG\startupreg: EADM => "D:\Spiele\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Live Update => C:\Program Files (x86)\MSI\Live Update\StartLiveUpdate.exe /REMINDER MSCONFIG\startupreg: NokiaMServer => C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: Steam => "d:\steam\steam.exe" -silent MSCONFIG\startupreg: Super Charger => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe ==================== FirewallRules (whitelisted) =============== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{291E905E-EE00-4B3B-A66B-F471C9244C63}] => (Allow) C:\Program Files (x86)\Opera\opera.exe FirewallRules: [{B2A53BC9-ACA4-481E-A652-29B34C096B74}] => (Allow) C:\Program Files (x86)\Opera\opera.exe FirewallRules: [{A812A72F-79B8-4B59-9800-2C5D5D442C3D}] => (Allow) D:\Steam\steam.exe FirewallRules: [{BFD6D713-C240-4E72-A3AC-D510DC6E4E09}] => (Allow) D:\Steam\steam.exe FirewallRules: [{B2BB8029-D0F7-4F84-9031-0F8507C9CF7C}] => (Allow) D:\Spiele\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe FirewallRules: [{A003797F-474F-495C-B06E-66B6BC2EE233}] => (Allow) D:\Spiele\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe FirewallRules: [TCP Query User{0812C55C-9AEA-4BE1-ACBB-5F701F60AEB4}D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe FirewallRules: [UDP Query User{3E8691B6-643C-43D4-B70A-F4ECC3ABC184}D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe FirewallRules: [{ADB93B0C-F423-4707-94D1-D36A61281953}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\Anno4.exe FirewallRules: [{D2427430-04F2-4EA4-AA99-F7D269DD0E4A}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\Anno4.exe FirewallRules: [{D41162C9-38A8-4307-AD8B-4D32F88D86E2}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\tools\Anno4Web.exe FirewallRules: [{3D2E0030-3800-453E-A3DB-4C8853F3D2EE}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\tools\Anno4Web.exe FirewallRules: [TCP Query User{28C9ABE4-A536-462C-B329-6BFC1DBCA648}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{CE95AB74-6CF4-4766-916A-F39C35758C00}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [TCP Query User{02767BA0-D74A-49E2-AEF7-DBAAF2D3DAFD}C:\program files (x86)\opera\opera.exe] => (Allow) C:\program files (x86)\opera\opera.exe FirewallRules: [UDP Query User{CC40C61C-C1EB-4366-AC6E-DF5C793AD9A2}C:\program files (x86)\opera\opera.exe] => (Allow) C:\program files (x86)\opera\opera.exe FirewallRules: [{D0F1A911-E170-449A-BDF3-C080D6BABE56}] => (Allow) C:\Users\Labrat\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{598319BA-B0A9-4149-B070-739230CE1EEB}] => (Allow) C:\Users\Labrat\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{440A0224-6199-4E96-89ED-B7C9697929D0}] => (Allow) D:\Spiele\Bulletstorm\Binaries\Win32\ShippingPC-StormGame.exe FirewallRules: [{ABC3E749-9D58-42C7-AE63-D78197F917F5}] => (Allow) D:\Spiele\Bulletstorm\Binaries\Win32\ShippingPC-StormGame.exe FirewallRules: [{B21D7192-45D6-4BC5-802F-0D9796E3F69B}] => (Allow) D:\Steam\SteamApps\labrat69\half-life source\hl2.exe FirewallRules: [{85A1063A-0D43-4621-83F4-D20818E41023}] => (Allow) D:\Steam\SteamApps\labrat69\half-life source\hl2.exe FirewallRules: [{5D521022-484D-46F8-A4BF-97A0BB2EA8C7}] => (Block) D:\Spiele\Origin\Origin.exe FirewallRules: [{89178815-2738-4649-934D-DC5817C03A48}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\CNC3.exe FirewallRules: [{37C999DB-0831-4F70-A286-F4EABF03DC3A}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\CNC3.exe FirewallRules: [{E10ED662-969E-472D-915E-8E0B5960A3BC}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\Support\EA Help\Electronic_Arts_Technical_Support.htm FirewallRules: [{4FCDEDE6-F460-4182-889D-DB65A8DCA30D}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\Support\EA Help\Electronic_Arts_Technical_Support.htm FirewallRules: [{E307EF1D-D2BB-466B-95FC-FB57239BFD64}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{B09E73A7-A707-4C1A-A037-74F7B65544C1}] => (Allow) C:\Windows\SysWOW64\lxbxcoms.exe FirewallRules: [{895C1824-D6BA-4BBA-A188-754A881BA45B}] => (Allow) C:\Windows\SysWOW64\lxbxcoms.exe FirewallRules: [{63FA5365-9E12-48C1-BDFB-B42D3201A04E}] => (Allow) D:\Spiele\Diablo III\Diablo III.exe FirewallRules: [{5A74735D-64E8-44E4-907E-C6A3B8E887D2}] => (Allow) D:\Spiele\Diablo III\Diablo III.exe FirewallRules: [{A0FA0445-EFCF-4589-A385-5ADDEC4BE285}] => (Allow) D:\Spiele\Battlefield 3\Battlefield 3\bf3.exe FirewallRules: [{78F5A3A7-773B-4A48-9DAD-FCAECF928456}] => (Allow) D:\Spiele\Battlefield 3\Battlefield 3\bf3.exe FirewallRules: [{D4703311-1015-4807-AC7E-0B5995BA0D82}] => (Allow) D:\Steam\SteamApps\common\deus ex - human revolution\dxhr.exe FirewallRules: [{A02B2BFD-5FED-4515-AC4F-0EE5DCC97281}] => (Allow) D:\Steam\SteamApps\common\deus ex - human revolution\dxhr.exe FirewallRules: [{89683748-D859-4B5C-B798-54F91994DDB7}] => (Allow) D:\Steam\SteamApps\common\Metro 2033\metro2033.exe FirewallRules: [{2BADB2E2-E9A1-4A44-B4B2-BC948EE68496}] => (Allow) D:\Steam\SteamApps\common\Metro 2033\metro2033.exe FirewallRules: [{D33032EB-C9E4-4A51-87C0-AFC51861001F}] => (Allow) C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe FirewallRules: [{26ADDD14-9ED7-491C-87FF-10EBB81A27DE}] => (Allow) C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe FirewallRules: [{9F5C64E7-2E82-447D-920A-87B8B39A87B4}] => (Allow) C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{ECC55AE8-39CD-45A3-A75A-C9B353AFF6BF}] => (Allow) D:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe FirewallRules: [{D1AD6B48-B833-45B6-8338-6A93997E6580}] => (Allow) D:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe FirewallRules: [TCP Query User{2140A85B-474B-448B-B0BA-F001F5C2771B}D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Allow) D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe FirewallRules: [UDP Query User{4B2530F3-1474-4B3F-AD4E-B53D11CA9E7A}D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Allow) D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe FirewallRules: [{7597E5E9-88B6-4545-A928-C439AED8A320}] => (Allow) D:\Steam\SteamApps\common\empire total war\Empire.exe FirewallRules: [{3BF6963C-554F-46E0-8D15-5D73B50ABD6F}] => (Allow) D:\Steam\SteamApps\common\empire total war\Empire.exe FirewallRules: [{2EB08BCB-C794-4089-A078-CBD343B17ECC}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe FirewallRules: [{4FF19DA1-C94E-49EA-B0E6-6365BFC4A393}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe FirewallRules: [{D9BA9A78-F11F-4FC8-A201-1C2961E56EDB}] => (Allow) D:\Steam\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [{65698631-0608-479C-A101-A7B4C19FE62B}] => (Allow) D:\Steam\SteamApps\common\the witcher 2\Launcher.exe FirewallRules: [TCP Query User{69D9A361-F300-4DDF-9FED-9BA439BD4B3D}D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe FirewallRules: [UDP Query User{8848E9EE-30EC-4BD5-AAEE-E58EBE023C69}D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe FirewallRules: [{BB612E1E-76BE-4843-B40B-73E6AB383C69}] => (Allow) D:\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe FirewallRules: [{7D73DA38-2248-4804-94B3-5BFBD60168A5}] => (Allow) D:\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe FirewallRules: [{C509595F-AC55-41AE-9479-88A4B873A69B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{A15E07EE-A643-4078-9C0F-89C01588ED1A}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{940CEF92-C3E2-4C65-A9A6-1361AD20861D}] => (Allow) D:\Steam\SteamApps\common\Anno 2070\Anno5.exe FirewallRules: [{FFD4659C-9469-430A-A21A-2684BD3279DD}] => (Allow) D:\Steam\SteamApps\common\Anno 2070\Anno5.exe FirewallRules: [TCP Query User{FBD85B1D-9BEE-4B0D-BB9F-6D78BCE461D1}D:\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) D:\steam\steamapps\common\total war rome ii\rome2.exe FirewallRules: [UDP Query User{B686D8B7-9937-4237-AFBC-B77D3BC7B6A4}D:\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) D:\steam\steamapps\common\total war rome ii\rome2.exe FirewallRules: [{1B8658A6-884D-4999-B4FC-45F4551CFB2F}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{8E03D2ED-FA73-4C29-8764-A32F6CB0E3E2}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{0BF89F08-A2E3-4A10-B375-2A8858128828}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.com FirewallRules: [{20C821A9-CE43-47C0-BEAE-071C5F6AC58F}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.exe FirewallRules: [{62231418-B861-42BB-8F52-1BA288D103F3}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\WinWrapIDE.exe FirewallRules: [{5DB254A6-2ADD-416A-A628-0325A91F737A}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.com FirewallRules: [{DE43F1E5-A15C-4D00-9788-355F131EA554}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.exe FirewallRules: [{8849F072-7E49-4BCB-A7F4-20D6A89F2018}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\WinWrapIDE.exe FirewallRules: [TCP Query User{F5E7AB23-E173-4B6C-A22D-801C876A6A7E}C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe] => (Allow) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe FirewallRules: [UDP Query User{F10331A3-46C3-4146-8131-D263F07FF058}C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe] => (Allow) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe FirewallRules: [{6BD068B2-9A97-4246-9E7E-CBC406A27074}] => (Block) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe FirewallRules: [{CB2A68C4-332B-4538-A019-C9FC04671933}] => (Block) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe FirewallRules: [{051AD11F-C7BE-4136-ACCB-E554DFFEA9A8}] => (Allow) D:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{ABD71F08-17F0-4AF5-9A1B-C3D3FBFC91B2}] => (Allow) D:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{0CF197B8-CA2A-4560-B915-4DCD44E58DFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{B8D13929-B6D3-4A00-B238-1E770C2FD2A8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{4914840A-7208-426B-9434-FE38C4163807}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{A302C88F-CD1B-4A2D-8A40-75D6D6A1F5E4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{6B2B461C-423F-4FF9-AD7C-7F958ABE1FBC}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{D6FECA2A-28D7-4E13-9EFA-F73A7B3D753B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{F338572E-8190-411B-BEC4-E32D6EC8DEE8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{61E3BF50-F810-44A0-A866-1BA35A5CA11F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{4C2505F2-012D-4FE1-BCBD-57B0507DB7BB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{5F1B4480-B0DA-430F-87A4-054B3B0BE968}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{3710E862-E4E5-4E72-B7FA-4D8FA6C175A8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{193B9EC0-3CF3-4267-A56E-97B03CE13E05}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{839012CD-F482-4D89-BCCA-29998C20D493}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{8DF18A5E-E5B7-4183-A8CD-6ACF46D46532}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{497F0BCD-8999-44F0-BB33-9155CE56E8EF}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe FirewallRules: [{BFA4CAFD-735B-45DC-BDD3-0921CAA31B75}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe FirewallRules: [{1D8C62EF-DD0F-45DA-A729-47EC42B48D2E}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe FirewallRules: [{8BEA3B47-67CF-4CA3-9995-6D4EAB4EEA54}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe FirewallRules: [{EEA9EE5A-745A-4AD7-9F87-CE7B14E58BB8}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html FirewallRules: [{C1CE430A-9528-4BAC-BEC1-7D8D5B395FFE}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html FirewallRules: [{628836D8-22CA-42C1-997F-E13E12AEC003}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{3316DE6E-A589-4E13-B0B7-227B275B1208}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{2A22422E-E424-45A6-BEEE-DE85E403BE2C}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{5B41C1CC-515E-450B-B1B6-1A60DFD1F1C2}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{ADBF29DB-7F30-49B3-822A-F7F4B24F3792}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat FirewallRules: [{276FDF3F-EE62-4B04-A256-F5188483A507}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat FirewallRules: [{DAC5D431-883F-489E-8D85-961BB2B091C8}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{DAABBEFE-29F6-4106-8FA0-C76C28A8C708}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{C25C4FC3-B032-454E-A1D5-99AFF73852D1}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{AC4D0620-85D3-415C-9B0E-CB7BA3136EE9}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{F26E54F4-AE74-48F3-B7F3-CF08B766B2A9}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe FirewallRules: [{9FE55117-C929-4559-B464-8E64EB857130}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe FirewallRules: [{C0ECDE46-1475-4F4B-989D-0D9866EFD4EB}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html FirewallRules: [{326BD206-0B38-40B9-A2F7-A3569D096DB0}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html FirewallRules: [{6B2A40C6-0963-405D-8170-B3CFB8BDA486}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{AE594FF8-3CD9-4669-B71A-67CE9EFB3A9B}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{796A3A4B-980D-4552-9E28-0BB0E1F7A09F}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{63CDB837-5F5E-4129-9120-D0442730D07D}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{2420C9AC-2D2E-48B3-B950-01236B4B7178}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat FirewallRules: [{771018AC-71E0-499A-8C1D-5B9BE9026220}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat FirewallRules: [{F11076A6-8853-4870-A7F4-9AFEDF28300C}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{C2F17E39-2912-4F8D-9EFE-C56EEC17068D}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{569D74D5-71AA-48B1-A825-F927C6F346EB}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{F90A15D2-9505-4E6B-99EB-972974DDFF0A}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat FirewallRules: [{BC7A86E7-3D4F-492F-AB7A-44F5089098F0}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe FirewallRules: [{ECA8E002-53EA-4F50-9BEC-11ADF2E6662B}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe FirewallRules: [TCP Query User{E2050DFC-7C90-46B3-AA5F-CA2D6A57C945}D:\steam\steam.exe] => (Block) D:\steam\steam.exe FirewallRules: [UDP Query User{77F341AF-2704-496F-96CD-41E4F8CB07E3}D:\steam\steam.exe] => (Block) D:\steam\steam.exe FirewallRules: [{D7566D8F-04B7-464A-991F-B6FC8E6E55B5}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP1\WNt500x64\RpcSandraSrv.exe FirewallRules: [{706579DA-6066-46AC-93CA-D477E58627E4}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{07BBEAF9-4842-4F7A-9A9C-A856F27546DE}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{563813B6-9B88-40DA-B6EB-A4703892566A}] => (Allow) C:\Windows\System32\lxbxcoms.exe FirewallRules: [{C0B6DAC1-67F2-4B72-8FCB-43273DE532F9}] => (Allow) C:\Windows\System32\lxbxcoms.exe FirewallRules: [{E908E21B-C6DC-4E37-81FD-6DD6D921C257}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{CCADD611-D51A-48D1-9BD7-A045405CF576}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{0F0F3420-1D30-4F36-899C-02DD20E53DDF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{D0B948E8-B62F-432A-ABC6-3EFDCFBCCDA7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [TCP Query User{F791548F-FD52-4135-AFB5-39991521FF61}D:\spiele\diablo iii\diablo iii.exe] => (Allow) D:\spiele\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{FD8776A8-DE52-4E42-8F02-4FDADE2ECF2E}D:\spiele\diablo iii\diablo iii.exe] => (Allow) D:\spiele\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{AA892CE1-EF61-4F68-9F1E-D91F1B7E43F3}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe] => (Allow) C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe FirewallRules: [UDP Query User{0CFF3757-BC86-4C11-954E-CDB1101B157B}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe] => (Allow) C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe FirewallRules: [{7C1143C5-6392-431A-80AB-436E188C4FAA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{A3F06CD0-05A7-41BB-8A6D-039F092D265F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{A3C85FBE-EE0B-4761-8B43-4BBAD87B6E5B}] => (Allow) D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\Baldur.exe FirewallRules: [{615125E0-8145-4C71-AAE0-D9438169636E}] => (Allow) D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\Baldur.exe FirewallRules: [{3B0F2D15-274E-4B18-8962-81AA97277C4D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{46C4B002-0843-4D7A-8228-16E63C6B2E44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{FF8C746D-27AF-4788-B3E5-B7C4976BE2B3}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{008B3B0F-87FC-4B71-8CE8-342CDCC2D841}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{62803D62-B42E-4C55-AAA6-B667CBE3718C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe FirewallRules: [{54F2096B-F1CC-49AB-B0CD-D6428CED22CC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe FirewallRules: [{9C4F032B-4A4F-40AA-AAFC-1C86C623CD6E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3322\Agent.exe FirewallRules: [{0833C379-BA4B-4071-8192-5609359AED29}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3322\Agent.exe FirewallRules: [{9E0F3323-8886-4FC2-92D2-FD9E2BE48DAA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3323\Agent.exe FirewallRules: [{58D9CFE9-8209-488B-914B-4A96C852557E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3323\Agent.exe FirewallRules: [{77D32B21-6B34-4E67-95D6-701ABBA3D0FA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3332\Agent.exe FirewallRules: [{D943169B-019D-45C4-BF40-63255F77F75B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3332\Agent.exe FirewallRules: [{E872EACA-9FA3-48E5-8B5E-07D30C5F3038}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe FirewallRules: [{5A50DE21-090C-4871-9476-2659EB7AF6C2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe FirewallRules: [TCP Query User{C72F3FD4-ED57-49B2-9421-62D44F9AB1E8}C:\programdata\battle.net\agent\agent.3346\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3346\agent.exe FirewallRules: [UDP Query User{94E56DCF-A785-4DE8-B7D8-C913CD5E2D26}C:\programdata\battle.net\agent\agent.3346\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3346\agent.exe FirewallRules: [{99B59D30-55ED-4913-9498-F2BA56C471D8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7C28DA0A-889C-432E-998E-37B9254F3625}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{2262B5AD-66DF-46CB-AF37-668982D3C491}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{23E62406-0337-47A1-9037-528C70D5487B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{ADEBC4B7-0702-40A4-A1BE-4EEEC4E99F18}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{70006993-4B02-413E-8993-2830A1E100D5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{C2370EA4-859F-4B02-ABC3-5549BCEC37C5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{26114F00-FD61-451E-8896-521B83E87F42}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{A0D6A84E-BCD2-4145-8D24-3FB4A1E45C7A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe FirewallRules: [{227D122C-C461-4320-95E1-378A7357E0F9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe FirewallRules: [{E607223B-3A47-4DA5-BD00-14E0B3B4546E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe FirewallRules: [{4FA81B24-E4EA-4C41-BCE1-952BF0473A52}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe FirewallRules: [{FC8CD3EB-3027-45EB-AB22-D1C7CE89BF09}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe FirewallRules: [{B20398C4-682A-43FF-9D2E-1C4F40126FEA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe FirewallRules: [{593B72B5-96EC-485B-910B-87995F2E04A9}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{EE34EA22-F787-493A-AFEF-533C94C02128}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{38C3088C-D62F-45A1-922D-56869C203FEF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{7DD5EBDB-3C70-48E6-9364-E184F0FE818F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{62CDC4E1-D810-42CE-8F61-19CA616DDB7B}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe FirewallRules: [{940846B8-B541-4A75-B30A-6E8E00F07B9A}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe FirewallRules: [{2265DD61-5539-4146-B843-BFCEB7F18368}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe FirewallRules: [{0D561DD6-E0BC-4401-A404-E010F6BAD927}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe FirewallRules: [{22150C4B-5363-410F-8F75-68591CF74C97}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe FirewallRules: [{8042C260-98F8-4663-A4CD-864D3F857455}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe FirewallRules: [TCP Query User{37FC6185-2132-4D36-8B17-DDC4DEF6E68D}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Allow) D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe FirewallRules: [UDP Query User{D7A28ABB-6B54-409B-B318-DECF70E536A9}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Allow) D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe FirewallRules: [{1F4C1C6B-16AA-4F89-A616-77F7CC21A650}] => (Allow) D:\Steam\SteamApps\common\SourceSDK\bin\SDKLauncher.exe FirewallRules: [{4EAD0E61-AFCA-42F0-A850-22AF49B4CF77}] => (Allow) D:\Steam\SteamApps\common\SourceSDK\bin\SDKLauncher.exe FirewallRules: [{E9BB4652-16C4-4058-925A-D7C6D18D82CF}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe FirewallRules: [{488917D1-77F7-4097-A4BA-FAE2946F14DC}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe FirewallRules: [{030A0317-1CC5-42E2-93AA-CF14EE9B32FD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{B44E02C5-BE95-4575-9196-ED7AE5F6E03C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{E27B94E2-DE92-468B-8B17-6C23A3863D3A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5A21C0E9-AA9E-44A2-86FE-A3E5FC3C825F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{7F17D424-810D-41E5-B806-F8E1C6F65513}] => (Allow) D:\Steam\SteamApps\common\Company of Heroes 2\RelicCoH2.exe FirewallRules: [{8E5881E6-A47F-4C5F-B816-8655DB279542}] => (Allow) D:\Steam\SteamApps\common\Company of Heroes 2\RelicCoH2.exe FirewallRules: [{27253C9F-E037-4F00-AC4C-3F83DC87C743}] => (Allow) D:\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe FirewallRules: [{F7307748-B817-48BA-ABB5-5BE7AEA30C5D}] => (Allow) D:\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe FirewallRules: [{874E307C-8D1B-4920-9CBA-00CCB7B54B00}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [TCP Query User{2CA58D27-BB1F-42C5-A216-9A4ACE2BF73E}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{D01A4E9D-F15B-4A81-A7E2-615B4C99C587}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{BBCFD502-3B9E-4CCA-A310-6F16078AE11C}] => (Allow) D:\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe FirewallRules: [{8C3D5C0B-B6DE-4B52-8EE1-1EA40D79DB99}] => (Allow) D:\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D 2 Tray Icon StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (05/08/2015 03:17:07 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (05/08/2015 02:23:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: SuperRAIDSvc.exe, Version: 2.0.0.6, Zeitstempel: 0x53605b30 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18798, Zeitstempel: 0x5507b485 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000c42d ID des fehlerhaften Prozesses: 0xbec Startzeit der fehlerhaften Anwendung: 0xSuperRAIDSvc.exe0 Pfad der fehlerhaften Anwendung: SuperRAIDSvc.exe1 Pfad des fehlerhaften Moduls: SuperRAIDSvc.exe2 Berichtskennung: SuperRAIDSvc.exe3 Error: (05/08/2015 02:23:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: SuperRAIDSvc.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Reflection.TargetInvocationException Stapel: bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance() bei SuperRAID.Common.SyncObject..ctor() bei SuperRAIDSvc.MainService.<OnStart>b__0() bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() Error: (05/08/2015 08:32:43 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (05/08/2015 08:09:53 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: spoolsv.exe, Version: 6.1.7601.17777, Zeitstempel: 0x4f35fc1d Name des fehlerhaften Moduls: msvcrt.dll, Version: 7.0.7601.17744, Zeitstempel: 0x4eeb033f Ausnahmecode: 0x40000015 Fehleroffset: 0x000000000002a84e ID des fehlerhaften Prozesses: 0x618 Startzeit der fehlerhaften Anwendung: 0xspoolsv.exe0 Pfad der fehlerhaften Anwendung: spoolsv.exe1 Pfad des fehlerhaften Moduls: spoolsv.exe2 Berichtskennung: spoolsv.exe3 Error: (05/08/2015 08:09:36 AM) (Source: ATIeRecord) (EventID: 16386) (User: ) Description: ATI EEU Client has failed to start Error: (05/08/2015 07:53:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: SuperRAIDSvc.exe, Version: 2.0.0.6, Zeitstempel: 0x53605b30 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18798, Zeitstempel: 0x5507b485 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000c42d ID des fehlerhaften Prozesses: 0xfe0 Startzeit der fehlerhaften Anwendung: 0xSuperRAIDSvc.exe0 Pfad der fehlerhaften Anwendung: SuperRAIDSvc.exe1 Pfad des fehlerhaften Moduls: SuperRAIDSvc.exe2 Berichtskennung: SuperRAIDSvc.exe3 Error: (05/08/2015 07:53:19 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: SuperRAIDSvc.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Reflection.TargetInvocationException Stapel: bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance() bei SuperRAID.Common.SyncObject..ctor() bei SuperRAIDSvc.MainService.<OnStart>b__0() bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() Error: (05/07/2015 11:23:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: SuperRAIDSvc.exe, Version: 2.0.0.6, Zeitstempel: 0x53605b30 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18798, Zeitstempel: 0x5507b485 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000c42d ID des fehlerhaften Prozesses: 0xcc4 Startzeit der fehlerhaften Anwendung: 0xSuperRAIDSvc.exe0 Pfad der fehlerhaften Anwendung: SuperRAIDSvc.exe1 Pfad des fehlerhaften Moduls: SuperRAIDSvc.exe2 Berichtskennung: SuperRAIDSvc.exe3 Error: (05/07/2015 11:23:13 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: SuperRAIDSvc.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Reflection.TargetInvocationException Stapel: bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance() bei SuperRAID.Common.SyncObject..ctor() bei SuperRAIDSvc.MainService.<OnStart>b__0() bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() System errors: ============= Error: (05/08/2015 03:18:28 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:17:27 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:15:33 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:15:30 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:15:26 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:15:22 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:15:19 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:14:57 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:14:42 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Error: (05/08/2015 03:14:36 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden. Microsoft Office Sessions: ========================= Error: (05/08/2015 03:17:07 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Labrat\Downloads\esetsmartinstaller_deu.exe Error: (05/08/2015 02:23:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: SuperRAIDSvc.exe2.0.0.653605b30KERNELBASE.dll6.1.7601.187985507b485e04343520000c42dbec01d08989c5c7bedeC:\MSI\Smart Utilities\SuperRAIDSvc.exeC:\Windows\syswow64\KERNELBASE.dll1097c21f-f57d-11e4-9d2f-0024211056dd Error: (05/08/2015 02:23:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: SuperRAIDSvc.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Reflection.TargetInvocationException Stapel: bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance() bei SuperRAID.Common.SyncObject..ctor() bei SuperRAIDSvc.MainService.<OnStart>b__0() bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() Error: (05/08/2015 08:32:43 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: assemblyIdentityprocessorArchitecturex64c:\program files\R\r-2.15.3\Tcl\bin64\tk85.dllc:\program files\R\r-2.15.3\Tcl\bin64\tk85.dll9 Error: (05/08/2015 08:09:53 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: spoolsv.exe6.1.7601.177774f35fc1dmsvcrt.dll7.0.7601.177444eeb033f40000015000000000002a84e61801d089532780ee9bC:\Windows\System32\spoolsv.exeC:\Windows\system32\msvcrt.dlld7309a3c-f548-11e4-a775-0024211056dd Error: (05/08/2015 08:09:36 AM) (Source: ATIeRecord) (EventID: 16386) (User: ) Description: Error: (05/08/2015 07:53:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: SuperRAIDSvc.exe2.0.0.653605b30KERNELBASE.dll6.1.7601.187985507b485e04343520000c42dfe001d0895348b3e20cC:\MSI\Smart Utilities\SuperRAIDSvc.exeC:\Windows\syswow64\KERNELBASE.dll9480372a-f546-11e4-a775-0024211056dd Error: (05/08/2015 07:53:19 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: SuperRAIDSvc.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Reflection.TargetInvocationException Stapel: bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance() bei SuperRAID.Common.SyncObject..ctor() bei SuperRAIDSvc.MainService.<OnStart>b__0() bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() Error: (05/07/2015 11:23:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: SuperRAIDSvc.exe2.0.0.653605b30KERNELBASE.dll6.1.7601.187985507b485e04343520000c42dcc401d0890c059ae101C:\MSI\Smart Utilities\SuperRAIDSvc.exeC:\Windows\syswow64\KERNELBASE.dll515275a7-f4ff-11e4-8972-0024211056dd Error: (05/07/2015 11:23:13 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: SuperRAIDSvc.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet. Ausnahmeinformationen: System.Reflection.TargetInvocationException Stapel: bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean) bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance() bei SuperRAID.Common.SyncObject..ctor() bei SuperRAIDSvc.MainService.<OnStart>b__0() bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Threading.ThreadHelper.ThreadStart() CodeIntegrity Errors: =================================== Date: 2015-05-07 23:17:08.193 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\nvlddmkm.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-05-07 23:17:08.006 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\nvlddmkm.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-24 14:33:28.057 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-24 14:33:27.952 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-24 14:33:23.892 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-24 14:33:23.782 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-22 20:50:00.729 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-22 20:50:00.636 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-22 10:44:57.233 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-04-22 10:44:57.130 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: AMD Phenom(tm) II X4 940 Processor Percentage of memory in use: 62% Total physical RAM: 6143.18 MB Available physical RAM: 2273.74 MB Total Pagefile: 12284.55 MB Available Pagefile: 7161.74 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:13.49 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:400.86 GB) (Free:60.68 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: D91548F4) Partition 1: (Active) - (Size=195.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=400.9 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 06-May-15 Suchlauf-Zeit: 11:54:12 AM Logdatei: Malwarebyte.txt Administrator: Ja Version: 2.01.6.1022 Malware Datenbank: v2015.05.06.01 Rootkit Datenbank: v2015.04.21.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Labrat Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 425010 Verstrichene Zeit: 20 Min, 41 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 1 PUP.Optional.PriceGong.A, HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [acbdbed26624181e6e75b72d986b956b], Registrierungswerte: 0 (Keine schädliche Elemente gefunden) Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 2 PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data, , [96d3fe927218ea4c2a65ff9ea95ac33d], Dateien: 29 PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\1.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\7031.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\a.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\b.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\c.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\d.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\e.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\f.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\g.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\h.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\i.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\j.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\k.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\l.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\m.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\n.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\o.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\p.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\q.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\r.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\s.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\t.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\u.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\v.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\w.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\wlu.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\x.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\y.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\z.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v4.203 - Bericht erstellt 06/05/2015 um 12:19:32 # Aktualisiert 30/04/2015 von Xplode # Datenbank : 2015-05-05.1 [Server] # Betriebssystem : Windows 7 Professional Service Pack 1 (x64) # Benutzername : Labrat - MAX_POWERS # Gestarted von : C:\Users\Labrat\Downloads\AdwCleaner_4.203.exe # Option : Suchlauf ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gefunden : C:\Program Files (x86)\Conduit Ordner Gefunden : C:\Program Files (x86)\Innovative Solutions Ordner Gefunden : C:\ProgramData\Ask Ordner Gefunden : C:\ProgramData\Innovative Solutions Ordner Gefunden : C:\ProgramData\Yahoo! Companion Ordner Gefunden : C:\Users\Labrat\AppData\Local\Innovative Solutions Ordner Gefunden : C:\Users\Labrat\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Labrat\AppData\LocalLow\HPAppData Ordner Gefunden : C:\Users\Labrat\AppData\Roaming\dvdvideosoftiehelpers Ordner Gefunden : C:\Users\Labrat\AppData\Roaming\Innovative Solutions Ordner Gefunden : C:\Users\Labrat_Adm\AppData\Local\Innovative Solutions Ordner Gefunden : C:\Users\Labrat_Adm\AppData\Roaming\Innovative Solutions ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Daten Gefunden : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\IGearSettings Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} Schlüssel Gefunden : HKCU\Software\YahooPartnerToolbar Schlüssel Gefunden : [x64] HKCU\Software\IGearSettings Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gefunden : [x64] HKCU\Software\YahooPartnerToolbar Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gefunden : HKLM\SOFTWARE\Conduit Schlüssel Gefunden : HKLM\SOFTWARE\dt soft\daemon tools toolbar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47 Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856 Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494 Schlüssel Gefunden : HKU\.DEFAULT\Software\AVG Secure Search Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17728 -\\ Mozilla Firefox v37.0.2 (x86 de) [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("avira.safe_search.installed", "[\"safesearch\"]"); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"147d364d9f3122-0b5875d98fc388-42504136-0-147d364d9f4158\""); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_expires_at", "1430947836"); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"f3f3b3797c8e8c1b9c24f28568cfd789761483c1\""); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_userid", "5717590696"); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_utoken", "\"e41a95ebf9142febd7b8a86a06660135877cddba\""); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.install", "1418741824383"); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.search_offer_disabled", "true"); [d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.xpiState", "{\"app-profile\":{\"safesearch@avira.com\":{\"d\":\"C:\\\\Users\\\\Labrat\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\d5h5b9mo.default-1412722597851\\\[...] -\\ Google Chrome v -\\ Chromium v -\\ Opera v29.0.1795.47 ************************* AdwCleaner[R0].txt - [7049 Bytes] - [06/05/2015 12:19:32] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [7108 Bytes] ########## [/CODE] JRT JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.6.7 (04.30.2015:1) OS: Windows 7 Professional x64 Ran by Labrat on 06-May-15 at 12:26:38.45 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3A2D5EBA-F86D-4BD3-A177-019765996711} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711} ~~~ Files ~~~ Folders Successfully deleted: [Folder] C:\Program Files (x86)\conduit Successfully deleted: [Folder] C:\Users\Labrat\appdata\locallow\conduit Successfully deleted: [Folder] C:\Users\Labrat\AppData\Roaming\dvdvideosoftiehelpers ~~~ FireFox Successfully deleted: [File] C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\searchplugins\avira-safesearch.xml Successfully deleted: [Folder] C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\extensions\safesearch@avira.com Successfully deleted the following from C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\prefs.js user_pref(avira.safe_search.installed, [\safesearch\]); user_pref(avira.safe_search.search_was_active, false); user_pref(browser.uiCustomization.state, {\placements\:{\PanelUI-contents\:[\edit-controls\,\zoom-controls\,\new-window-button\,\privatebrowsing-button\,\save- user_pref(extensions.bootstrappedAddons, {\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\:{\version\:\2.6.9\,\type\:\extension\,\descriptor\:\C:\\\\Users\\\\Labrat\\\ user_pref(extensions.safesearch.MP_DISTINCT_ID, \147d364d9f3122-0b5875d98fc388-42504136-0-147d364d9f4158\); user_pref(extensions.safesearch.SAUTH_expires_at, 1430947836); user_pref(extensions.safesearch.SAUTH_rndsnr, \f3f3b3797c8e8c1b9c24f28568cfd789761483c1\); user_pref(extensions.safesearch.SAUTH_userid, 5717590696); user_pref(extensions.safesearch.SAUTH_utoken, \e41a95ebf9142febd7b8a86a06660135877cddba\); user_pref(extensions.safesearch.install, 1418741824383); user_pref(extensions.safesearch.search_offer_disabled, true); user_pref(extensions.xpiState, {\app-profile\:{\safesearch@avira.com\:{\d\:\C:\\\\Users\\\\Labrat\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\d5h5b9mo Emptied folder: C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\minidumps [45 files] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06-May-15 at 12:29:10.77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
08.05.2015, 15:54 | #3 |
/// the machine /// TB-Ausbilder | DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Hi,
__________________die ZIP muss entpackt und ausgeführt werden, erst dann passiert was
__________________ |
08.05.2015, 18:23 | #4 |
| DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Hallo schrauber, verzeih mir meine Paranoia! Danke fürs Beruhigen Eine Frage noch: Was hat der zweite Kapersky Scan da gefunden? Im Internet habe ich erfahren das es sich um eine Windows Treiberdatei handelt. Es ist ja nur als "medium risk" eingeordnet worden. Pax, Stefan |
09.05.2015, 16:26 | #5 |
/// the machine /// TB-Ausbilder | DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Ich sehe kein Log von Kaspersky. Was wurde denn genau gefunden?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.05.2015, 11:37 | #6 |
| DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Der "normale" Kaspersky-Scan hatte nichts gefunden erst nachdem ich das Häckchen bei "Verify digital signature" gemacht und dann findet er zumindest einen "suspicious file": Service:WUDFRd...!? Code:
ATTFilter 12:34:23.0917 0x1f3c TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04 12:34:28.0251 0x1f3c ============================================================ 12:34:28.0251 0x1f3c Current date / time: 2015/05/10 12:34:28.0251 12:34:28.0252 0x1f3c SystemInfo: 12:34:28.0252 0x1f3c 12:34:28.0252 0x1f3c OS Version: 6.1.7601 ServicePack: 1.0 12:34:28.0252 0x1f3c Product type: Workstation 12:34:28.0252 0x1f3c ComputerName: MAX_POWERS 12:34:28.0252 0x1f3c UserName: Labrat 12:34:28.0252 0x1f3c Windows directory: C:\Windows 12:34:28.0253 0x1f3c System windows directory: C:\Windows 12:34:28.0253 0x1f3c Running under WOW64 12:34:28.0253 0x1f3c Processor architecture: Intel x64 12:34:28.0253 0x1f3c Number of processors: 4 12:34:28.0253 0x1f3c Page size: 0x1000 12:34:28.0253 0x1f3c Boot type: Normal boot 12:34:28.0253 0x1f3c ============================================================ 12:34:32.0891 0x1f3c KLMD registered as C:\Windows\system32\drivers\04246906.sys 12:34:33.0364 0x1f3c System UUID: {4552459F-87A3-1086-4CE0-A18B4A2CB915} 12:34:34.0368 0x1f3c Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 ( 596.17 Gb ), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 12:34:34.0387 0x1f3c ============================================================ 12:34:34.0387 0x1f3c \Device\Harddisk0\DR0: 12:34:34.0393 0x1f3c MBR partitions: 12:34:34.0393 0x1f3c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x186A0000 12:34:34.0393 0x1f3c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x186A0800, BlocksNum 0x321B7000 12:34:34.0393 0x1f3c ============================================================ 12:34:34.0415 0x1f3c C: <-> \Device\Harddisk0\DR0\Partition1 12:34:34.0475 0x1f3c D: <-> \Device\Harddisk0\DR0\Partition2 12:34:34.0476 0x1f3c ============================================================ 12:34:34.0476 0x1f3c Initialize success 12:34:34.0476 0x1f3c ============================================================ 12:34:40.0107 0x0ddc ============================================================ 12:34:40.0107 0x0ddc Scan started 12:34:40.0107 0x0ddc Mode: Manual; SigCheck; 12:34:40.0107 0x0ddc ============================================================ 12:34:40.0107 0x0ddc KSN ping started 12:34:43.0430 0x0ddc KSN ping finished: true 12:34:48.0129 0x0ddc ================ Scan system memory ======================== 12:34:48.0129 0x0ddc System memory - ok 12:34:48.0130 0x0ddc ================ Scan services ============================= 12:34:48.0432 0x0ddc [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 12:34:49.0000 0x0ddc 1394ohci - ok 12:34:49.0266 0x0ddc [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys 12:34:49.0409 0x0ddc ACPI - ok 12:34:49.0480 0x0ddc [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 12:34:50.0327 0x0ddc AcpiPmi - ok 12:34:50.0673 0x0ddc [ D0B11E40EA74A98A5E133DF1F5276240, BAD5885CD8CC271D59DFA95159EFC3AC36D2BA11B6DA593AAED0C45F1C2F280F ] acsock C:\Windows\system32\DRIVERS\acsock64.sys 12:34:51.0402 0x0ddc acsock - ok 12:34:52.0190 0x0ddc [ 177FF6608B48638D4066726F3A3F8444, D0D7B7EAEFDF30210CE4D31E9C7AB349CEB862A452D5925E698B60204AAE8A49 ] AdobeActiveFileMonitor5.0 C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe 12:34:52.0594 0x0ddc AdobeActiveFileMonitor5.0 - detected UnsignedFile.Multi.Generic ( 1 ) 12:34:55.0014 0x0ddc Detect skipped due to KSN trusted 12:34:55.0014 0x0ddc AdobeActiveFileMonitor5.0 - ok 12:34:55.0295 0x0ddc [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 12:34:55.0343 0x0ddc AdobeARMservice - ok 12:34:55.0619 0x0ddc [ AAF87A1B230B1E5585EA742C633A5414, 181E3E8EB91BF411C527C07F67AE47938740CBC2DADFC22053A25FEB842D5EFA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 12:34:55.0633 0x0ddc AdobeFlashPlayerUpdateSvc - ok 12:34:55.0756 0x0ddc [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 12:34:55.0826 0x0ddc adp94xx - ok 12:34:55.0894 0x0ddc [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 12:34:55.0965 0x0ddc adpahci - ok 12:34:55.0988 0x0ddc [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 12:34:56.0023 0x0ddc adpu320 - ok 12:34:56.0054 0x0ddc [ 83BFCCAC53795E8A5055A93672D0C46C, B2B03473D950A5BA9DE59D81E7B14C1FAFF17B2A4D8A5808588F5CC21D63B291 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 12:34:56.0162 0x0ddc AeLookupSvc - ok 12:34:56.0305 0x0ddc [ FA886682CFC5D36718D3E436AACF10B9, F80AB4F91AA6B5C7ECCB000D8E1BC2CF776DC3D69B3D9EBC2558C19035A6B3AB ] AFD C:\Windows\system32\drivers\afd.sys 12:34:56.0510 0x0ddc AFD - ok 12:34:56.0574 0x0ddc [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys 12:34:56.0676 0x0ddc agp440 - ok 12:34:56.0715 0x0ddc [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe 12:34:56.0857 0x0ddc ALG - ok 12:34:56.0892 0x0ddc [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys 12:34:56.0918 0x0ddc aliide - ok 12:34:56.0966 0x0ddc [ 5C8C9AAB596582AFFD94939917D8FB13, 3F9BC512E41D14AC35F7035D5E2B4ADDA1948488DA2822C692E612CF3FF3DAEA ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 12:34:57.0096 0x0ddc AMD External Events Utility - ok 12:34:57.0171 0x0ddc AMD FUEL Service - ok 12:34:57.0194 0x0ddc [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys 12:34:57.0233 0x0ddc amdide - ok 12:34:57.0307 0x0ddc [ 35D34AD337A1AC46F74C3377B4CCA88E, 046695BDF540EDCA87C36EDC725615ACA99DA57558A54CAC1B49F245D702B406 ] amdide64 C:\Windows\system32\DRIVERS\amdide64.sys 12:34:57.0329 0x0ddc amdide64 - ok 12:34:57.0493 0x0ddc [ 6A2EEB0C4133B20773BB3DD0B7B377B4, E4CB35C6937C70A145A13E5AE5B34A271B49101DA623171ACBFDA8601E5A70EA ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys 12:34:57.0558 0x0ddc amdiox64 - ok 12:34:57.0625 0x0ddc [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 12:34:57.0774 0x0ddc AmdK8 - ok 12:34:57.0904 0x0ddc [ F2FF8C1B41B3784EDBD5C6D5397F403C, 104873700D2BDF4812DC48200B4609F46A63E7A50594A0599100EF1438863708 ] amdkmafd C:\Windows\system32\DRIVERS\amdkmafd.sys 12:34:57.0966 0x0ddc amdkmafd - ok 12:34:59.0335 0x0ddc [ 538B0A6E89ACA1929668F9EB95D3C0BC, 1447EA64848F7B90F0963E8B7016687E93CCF19E2DE912B4ED71AF96C0BEA45A ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys 12:35:00.0045 0x0ddc amdkmdag - ok 12:35:00.0183 0x0ddc [ 977286B382FE0920F379A69C351A7AF4, 0EB260640825A3F04D2A0B687CF0D3BC54CB36BDD8BA23057AF99984ADE1AAF3 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 12:35:00.0493 0x0ddc amdkmdap - ok 12:35:00.0589 0x0ddc [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 12:35:00.0639 0x0ddc AmdPPM - ok 12:35:00.0743 0x0ddc [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys 12:35:00.0798 0x0ddc amdsata - ok 12:35:00.0964 0x0ddc [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 12:35:01.0053 0x0ddc amdsbs - ok 12:35:01.0083 0x0ddc [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys 12:35:01.0139 0x0ddc amdxata - ok 12:35:01.0711 0x0ddc [ D908096B873B940BB438CE63BA35BD1E, F1C79C907E6CDBC2770C16AFFAE0D6F9B9B7DA21F5074D602AC5FE1597975748 ] AntiVirMailService C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe 12:35:01.0770 0x0ddc AntiVirMailService - ok 12:35:02.0041 0x0ddc [ EC705D6ED3A7F3D9AE42F6239707D9FE, B50F6BB0FC308E7403B1807DF2AAF87BEDE0B044128C580970A26801CCABC43F ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 12:35:02.0076 0x0ddc AntiVirSchedulerService - ok 12:35:02.0478 0x0ddc [ EC705D6ED3A7F3D9AE42F6239707D9FE, B50F6BB0FC308E7403B1807DF2AAF87BEDE0B044128C580970A26801CCABC43F ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 12:35:02.0502 0x0ddc AntiVirService - ok 12:35:02.0854 0x0ddc [ 0F3D12E5FAE0082DB3F306095CA6B027, 726D054357031F45B43C87D798E84FA93439ECA6C691EB8C76FE524B50C25B32 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe 12:35:02.0981 0x0ddc AntiVirWebService - ok 12:35:03.0092 0x0ddc [ D7253A1A7A49FA40EF0BA1955AAFB346, 0C84A844F06D414F1A6793C9330B7B1474641B569EFEB5F64F29C0D11E59E631 ] AODDriver4.1 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys 12:35:03.0119 0x0ddc AODDriver4.1 - ok 12:35:03.0196 0x0ddc [ 90C53BD47979FB8814F465A08B885102, 5EDFC1909FC1FF9133A534DFCC5408CF3A777AC41FB21FAD375436E3D86C02EC ] AppID C:\Windows\system32\drivers\appid.sys 12:35:03.0303 0x0ddc AppID - ok 12:35:03.0326 0x0ddc [ 72D4757510FDA69D729169C00AFC211E, FB9686D0D94EE7C19A3994C29E8331A6EC3020B2980B2CC75F72F3AB25512C15 ] AppIDSvc C:\Windows\System32\appidsvc.dll 12:35:03.0365 0x0ddc AppIDSvc - ok 12:35:03.0407 0x0ddc [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll 12:35:03.0509 0x0ddc Appinfo - ok 12:35:03.0693 0x0ddc [ 612CB66D93ED0F2F21BB109840C7D813, 75484123DA27B8942B13148FCF061C75A08A50386A095143736B593E9C772173 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 12:35:03.0726 0x0ddc Apple Mobile Device Service - ok 12:35:03.0816 0x0ddc [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll 12:35:03.0982 0x0ddc AppMgmt - ok 12:35:04.0036 0x0ddc [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\DRIVERS\arc.sys 12:35:04.0067 0x0ddc arc - ok 12:35:04.0084 0x0ddc [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 12:35:04.0111 0x0ddc arcsas - ok 12:35:04.0872 0x0ddc [ F15AB80B867D3332D5DDFB0A05B9CE04, 5A16577106246AB5DCC04FE0A0B00B7C5702557B75F958721E4C00383AB99809 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 12:35:04.0985 0x0ddc aspnet_state - ok 12:35:05.0056 0x0ddc [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 12:35:07.0019 0x0ddc AsyncMac - ok 12:35:07.0067 0x0ddc [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys 12:35:07.0081 0x0ddc atapi - ok 12:35:07.0194 0x0ddc [ CBE5F8B3E54198F5DFE403A55A95DE08, A0A67A277CAEE39E401BFBE5EA51643EB67A0B5B742B30F24EFC1558BE8999E8 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys 12:35:07.0224 0x0ddc AtiHDAudioService - ok 12:35:07.0305 0x0ddc [ 77C149E6D702737B2E372DEE166FAEF8, D18FEAE9D915D5F25B787B755F9C6321A9C9506D4F563DD637E3586401E36053 ] AtiHdmiService C:\Windows\system32\drivers\AtiHdmi.sys 12:35:07.0401 0x0ddc AtiHdmiService - ok 12:35:08.0547 0x0ddc [ 538B0A6E89ACA1929668F9EB95D3C0BC, 1447EA64848F7B90F0963E8B7016687E93CCF19E2DE912B4ED71AF96C0BEA45A ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys 12:35:08.0723 0x0ddc atikmdag - ok 12:35:08.0850 0x0ddc [ E82E61F46D1336447F4DEFF8C074F13E, 9FC152B33F1D9F5684B687743E943AA26AC17A1093F4C31A43C7012E70BC302E ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie64.sys 12:35:08.0899 0x0ddc AtiPcie - ok 12:35:08.0977 0x0ddc [ B07E6681D303A612680223C729B021E2, DEF063A2A45B5FAF3B676AD5025417B9437A073D9BB2A47F57A0FCCBC78C2FEE ] ATITool C:\Windows\system32\DRIVERS\ATITool64.sys 12:35:09.0041 0x0ddc ATITool - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:11.0444 0x0ddc Detect skipped due to KSN trusted 12:35:11.0444 0x0ddc ATITool - ok 12:35:11.0496 0x0ddc [ FC0E8778C000291CAF60EB88C011E931, 09BCCA3DE01021AEF76DFB46F01D21BA6FF409E816FA7547E5C3DFBF3A615ED2 ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys 12:35:11.0520 0x0ddc atksgt - ok 12:35:11.0569 0x0ddc [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 12:35:11.0623 0x0ddc AudioEndpointBuilder - ok 12:35:11.0640 0x0ddc [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioSrv C:\Windows\System32\Audiosrv.dll 12:35:11.0664 0x0ddc AudioSrv - ok 12:35:11.0718 0x0ddc [ 43B6D229C7DBA9F0FC0FC0C318DB5350, F5A525DBD71FC4A323E92839C6D27F323FB304B7E9FFA35E89E9B419570AA4C8 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 12:35:11.0737 0x0ddc avgntflt - ok 12:35:11.0799 0x0ddc [ 626D1BAD7A1975A8FEE8876A8AD0EEA7, 59772746A2DF3B7E8D021756B8A64569AC8468CA1C802EB594494224354F1E60 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 12:35:11.0817 0x0ddc avipbb - ok 12:35:11.0875 0x0ddc [ 0D32033DCB359FD98B4C3513EF849FE6, 5870D67526BC29D888DAF8DBAB04B1E97ED5C7C51484ED400A5E65D0EB61576A ] Avira.OE.ServiceHost C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe 12:35:11.0931 0x0ddc Avira.OE.ServiceHost - ok 12:35:11.0970 0x0ddc [ 390184FAD8FCC1B6DA25AEBAE928C3B6, 537B0E0FAE080B55D70E990BBA0F7F22903CA340F6A42039BAD617A8ECF59119 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 12:35:11.0986 0x0ddc avkmgr - ok 12:35:12.0029 0x0ddc [ 13253E5E3B6BDF945B63B336A8C9489B, 671C716E43F89D4BDDAA2BE045CDEBBB569C85BC2BA334E1F550187B79A7740D ] avnetflt C:\Windows\system32\DRIVERS\avnetflt.sys 12:35:12.0072 0x0ddc avnetflt - ok 12:35:12.0106 0x0ddc [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll 12:35:12.0185 0x0ddc AxInstSV - ok 12:35:12.0229 0x0ddc [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 12:35:12.0301 0x0ddc b06bdrv - ok 12:35:12.0334 0x0ddc [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 12:35:12.0376 0x0ddc b57nd60a - ok 12:35:12.0421 0x0ddc [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll 12:35:12.0519 0x0ddc BDESVC - ok 12:35:12.0543 0x0ddc [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys 12:35:12.0618 0x0ddc Beep - ok 12:35:12.0692 0x0ddc [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll 12:35:12.0779 0x0ddc BFE - ok 12:35:12.0846 0x0ddc [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll 12:35:12.0987 0x0ddc BITS - ok 12:35:13.0024 0x0ddc [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 12:35:13.0050 0x0ddc blbdrive - ok 12:35:13.0134 0x0ddc [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 12:35:13.0177 0x0ddc Bonjour Service - ok 12:35:13.0210 0x0ddc [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 12:35:13.0251 0x0ddc bowser - ok 12:35:13.0274 0x0ddc [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 12:35:13.0330 0x0ddc BrFiltLo - ok 12:35:13.0343 0x0ddc [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 12:35:13.0357 0x0ddc BrFiltUp - ok 12:35:13.0379 0x0ddc [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll 12:35:13.0423 0x0ddc Browser - ok 12:35:13.0438 0x0ddc [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys 12:35:13.0508 0x0ddc Brserid - ok 12:35:13.0522 0x0ddc [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 12:35:13.0550 0x0ddc BrSerWdm - ok 12:35:13.0568 0x0ddc [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 12:35:13.0593 0x0ddc BrUsbMdm - ok 12:35:13.0609 0x0ddc [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 12:35:13.0638 0x0ddc BrUsbSer - ok 12:35:13.0653 0x0ddc [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 12:35:13.0705 0x0ddc BTHMODEM - ok 12:35:13.0731 0x0ddc [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll 12:35:13.0800 0x0ddc bthserv - ok 12:35:13.0829 0x0ddc [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 12:35:13.0872 0x0ddc cdfs - ok 12:35:13.0906 0x0ddc [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 12:35:13.0971 0x0ddc cdrom - ok 12:35:14.0008 0x0ddc [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll 12:35:14.0061 0x0ddc CertPropSvc - ok 12:35:14.0098 0x0ddc [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\DRIVERS\circlass.sys 12:35:14.0151 0x0ddc circlass - ok 12:35:14.0224 0x0ddc [ 404B7DF9CA4D1CB675045AF220FF3285, 91FFADE2ABE5C48849E63134D5FFD20671FE0D1720F7D486F904391B3D142C96 ] CLFS C:\Windows\system32\CLFS.sys 12:35:14.0281 0x0ddc CLFS - ok 12:35:14.0881 0x0ddc [ 1352A95AD8150440E0A5DD9745154D74, CF78A6267A246F747844FFA255783B5867B0A7232C65AF6224B25B2FBB893313 ] ClickToRunSvc C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe 12:35:15.0046 0x0ddc ClickToRunSvc - ok 12:35:15.0108 0x0ddc [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 12:35:15.0126 0x0ddc clr_optimization_v2.0.50727_32 - ok 12:35:15.0169 0x0ddc [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 12:35:15.0220 0x0ddc clr_optimization_v2.0.50727_64 - ok 12:35:15.0294 0x0ddc [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 12:35:15.0336 0x0ddc clr_optimization_v4.0.30319_32 - ok 12:35:15.0365 0x0ddc [ 9ACBE5EC13C2CC95833BFB7636CA8B1A, 6224DA9FB335D2A8374C60B8DEA539DD3A0E43230DB888B137B71A56EC57D6AF ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 12:35:15.0395 0x0ddc clr_optimization_v4.0.30319_64 - ok 12:35:15.0429 0x0ddc [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 12:35:15.0459 0x0ddc CmBatt - ok 12:35:15.0493 0x0ddc [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys 12:35:15.0551 0x0ddc cmdide - ok 12:35:15.0584 0x0ddc [ 27667A788130A7F7A5858DE27572E6D7, 5501D80BCCB7A811ECCED3828DFD0A5D948BBED8504E9BCC4A3BFB840DD41CBC ] CNG C:\Windows\system32\Drivers\cng.sys 12:35:15.0618 0x0ddc CNG - ok 12:35:15.0628 0x0ddc [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 12:35:15.0642 0x0ddc Compbatt - ok 12:35:15.0692 0x0ddc [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 12:35:15.0739 0x0ddc CompositeBus - ok 12:35:15.0757 0x0ddc COMSysApp - ok 12:35:15.0769 0x0ddc [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 12:35:15.0783 0x0ddc crcdisk - ok 12:35:15.0831 0x0ddc [ 1CD76A83B9E8E9A5A3519B39E28354D9, F9931743B99820FFBFB13136DFFD92F86802D543F9D8478648CDC554FB38899D ] CryptSvc C:\Windows\system32\cryptsvc.dll 12:35:15.0892 0x0ddc CryptSvc - ok 12:35:15.0927 0x0ddc [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys 12:35:15.0989 0x0ddc CSC - ok 12:35:16.0048 0x0ddc [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll 12:35:16.0092 0x0ddc CscService - ok 12:35:16.0133 0x0ddc [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll 12:35:16.0186 0x0ddc DcomLaunch - ok 12:35:16.0226 0x0ddc [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll 12:35:16.0320 0x0ddc defragsvc - ok 12:35:16.0381 0x0ddc [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys 12:35:16.0489 0x0ddc DfsC - ok 12:35:16.0517 0x0ddc [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll 12:35:16.0557 0x0ddc Dhcp - ok 12:35:16.0577 0x0ddc [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys 12:35:16.0613 0x0ddc discache - ok 12:35:16.0654 0x0ddc [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\DRIVERS\disk.sys 12:35:16.0702 0x0ddc Disk - ok 12:35:16.0749 0x0ddc [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll 12:35:16.0832 0x0ddc Dnscache - ok 12:35:16.0856 0x0ddc [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll 12:35:16.0899 0x0ddc dot3svc - ok 12:35:17.0014 0x0ddc [ B42ED0320C6E41102FDE0005154849BB, 4DB872E23AD049C3C9FDC0759FC58BFA60DA91B18BC82B611BFA300D26DDFC7A ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 12:35:17.0039 0x0ddc Dot4 - ok 12:35:17.0148 0x0ddc [ E9F5969233C5D89F3C35E3A66A52A361, C4BD35795C78FB11E6022372CB25DEB570730EFDAD3DC1584368235FF622638C ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 12:35:17.0188 0x0ddc Dot4Print - ok 12:35:17.0211 0x0ddc [ FD05A02B0370BC3000F402E543CA5814, 089B1113E640F495F470E8F57060B89546270481B309DC8ED3C3D13A849076A3 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 12:35:17.0241 0x0ddc dot4usb - ok 12:35:17.0290 0x0ddc [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll 12:35:17.0377 0x0ddc DPS - ok 12:35:17.0422 0x0ddc [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 12:35:17.0477 0x0ddc drmkaud - ok 12:35:17.0506 0x0ddc [ 0040A0132AAC1004E50055F8FBB14C08, A336CA41DA09AC749242852827C1F2FB645E8E81A707217C360C5E4ACD1760BA ] dsNcAdpt C:\Windows\system32\DRIVERS\dsNcAdpt.sys 12:35:17.0527 0x0ddc dsNcAdpt - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:19.0923 0x0ddc Detect skipped due to KSN trusted 12:35:19.0924 0x0ddc dsNcAdpt - ok 12:35:20.0018 0x0ddc [ 87CE5C8965E101CCCED1F4675557E868, 077D98F0F130B2FC710208BA34016EF2B2506EE2BD71740B228145E34A3046F1 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 12:35:20.0095 0x0ddc DXGKrnl - ok 12:35:20.0137 0x0ddc [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll 12:35:20.0208 0x0ddc EapHost - ok 12:35:20.0479 0x0ddc [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 12:35:20.0640 0x0ddc ebdrv - ok 12:35:20.0713 0x0ddc [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] EFS C:\Windows\System32\lsass.exe 12:35:20.0929 0x0ddc EFS - ok 12:35:21.0085 0x0ddc [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 12:35:21.0161 0x0ddc ehRecvr - ok 12:35:21.0183 0x0ddc [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe 12:35:21.0261 0x0ddc ehSched - ok 12:35:21.0358 0x0ddc [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 12:35:21.0409 0x0ddc elxstor - ok 12:35:21.0436 0x0ddc [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys 12:35:21.0487 0x0ddc ErrDev - ok 12:35:21.0539 0x0ddc [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll 12:35:21.0587 0x0ddc EventSystem - ok 12:35:21.0602 0x0ddc [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys 12:35:21.0648 0x0ddc exfat - ok 12:35:21.0671 0x0ddc [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys 12:35:21.0785 0x0ddc fastfat - ok 12:35:21.0830 0x0ddc [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe 12:35:21.0879 0x0ddc Fax - ok 12:35:21.0890 0x0ddc [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\DRIVERS\fdc.sys 12:35:21.0920 0x0ddc fdc - ok 12:35:21.0934 0x0ddc [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll 12:35:21.0961 0x0ddc fdPHost - ok 12:35:21.0969 0x0ddc [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll 12:35:22.0013 0x0ddc FDResPub - ok 12:35:22.0033 0x0ddc [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 12:35:22.0095 0x0ddc FileInfo - ok 12:35:22.0121 0x0ddc [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 12:35:22.0192 0x0ddc Filetrace - ok 12:35:22.0267 0x0ddc FLASHSYS - ok 12:35:22.0290 0x0ddc [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 12:35:22.0335 0x0ddc flpydisk - ok 12:35:22.0396 0x0ddc [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 12:35:22.0433 0x0ddc FltMgr - ok 12:35:22.0496 0x0ddc [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll 12:35:22.0653 0x0ddc FontCache - ok 12:35:22.0702 0x0ddc [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 12:35:22.0718 0x0ddc FontCache3.0.0.0 - ok 12:35:22.0736 0x0ddc [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 12:35:22.0752 0x0ddc FsDepends - ok 12:35:22.0790 0x0ddc [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 12:35:22.0892 0x0ddc Fs_Rec - ok 12:35:23.0068 0x0ddc [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 12:35:23.0164 0x0ddc fvevol - ok 12:35:23.0180 0x0ddc [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 12:35:23.0209 0x0ddc gagp30kx - ok 12:35:23.0235 0x0ddc [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 12:35:23.0246 0x0ddc GEARAspiWDM - ok 12:35:23.0308 0x0ddc [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll 12:35:23.0398 0x0ddc gpsvc - ok 12:35:23.0407 0x0ddc [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 12:35:23.0469 0x0ddc hcw85cir - ok 12:35:23.0593 0x0ddc [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 12:35:23.0643 0x0ddc HdAudAddService - ok 12:35:23.0677 0x0ddc [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 12:35:23.0707 0x0ddc HDAudBus - ok 12:35:23.0724 0x0ddc [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 12:35:23.0750 0x0ddc HidBatt - ok 12:35:23.0770 0x0ddc [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 12:35:23.0805 0x0ddc HidBth - ok 12:35:23.0819 0x0ddc [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 12:35:23.0849 0x0ddc HidIr - ok 12:35:23.0872 0x0ddc [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll 12:35:23.0920 0x0ddc hidserv - ok 12:35:23.0956 0x0ddc [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 12:35:23.0998 0x0ddc HidUsb - ok 12:35:24.0042 0x0ddc [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll 12:35:24.0158 0x0ddc hkmsvc - ok 12:35:24.0185 0x0ddc [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 12:35:24.0208 0x0ddc HomeGroupListener - ok 12:35:24.0227 0x0ddc [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 12:35:24.0256 0x0ddc HomeGroupProvider - ok 12:35:24.0354 0x0ddc [ 1DAE5C46D42B02A6D5862E1482EFB390, 90B14E0A8376AE51872D89C141E88AE144B742805F94B4F7948E295322C78B9D ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 12:35:24.0363 0x0ddc hpqcxs08 - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:26.0767 0x0ddc Detect skipped due to KSN trusted 12:35:26.0767 0x0ddc hpqcxs08 - ok 12:35:26.0853 0x0ddc [ 99E8EEF42FE2F4AF29B08C3355DD7685, D57BC2148653DA5596FB49F1086D165B11C9F6C644608202C08305D3C8499CFE ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 12:35:26.0890 0x0ddc hpqddsvc - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:29.0291 0x0ddc Detect skipped due to KSN trusted 12:35:29.0294 0x0ddc hpqddsvc - ok 12:35:29.0322 0x0ddc [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 12:35:29.0347 0x0ddc HpSAMD - ok 12:35:29.0442 0x0ddc [ F37882F128EFACEFE353E0BAE2766909, 2F9D21613500F092DFC0DB879180B549EE615D9B07408A5CC1A7F84663B2F47A ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL 12:35:29.0482 0x0ddc HPSLPSVC - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:31.0896 0x0ddc Detect skipped due to KSN trusted 12:35:31.0897 0x0ddc HPSLPSVC - ok 12:35:31.0982 0x0ddc [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP C:\Windows\system32\drivers\HTTP.sys 12:35:32.0054 0x0ddc HTTP - ok 12:35:32.0077 0x0ddc [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 12:35:32.0089 0x0ddc hwpolicy - ok 12:35:32.0109 0x0ddc [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 12:35:32.0127 0x0ddc i8042prt - ok 12:35:32.0164 0x0ddc [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 12:35:32.0190 0x0ddc iaStorV - ok 12:35:32.0275 0x0ddc [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 12:35:32.0321 0x0ddc IDriverT - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:34.0734 0x0ddc Detect skipped due to KSN trusted 12:35:34.0734 0x0ddc IDriverT - ok 12:35:34.0826 0x0ddc [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 12:35:34.0874 0x0ddc idsvc - ok 12:35:34.0913 0x0ddc IEEtwCollectorService - ok 12:35:34.0935 0x0ddc [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 12:35:34.0975 0x0ddc iirsp - ok 12:35:35.0024 0x0ddc [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll 12:35:35.0080 0x0ddc IKEEXT - ok 12:35:35.0253 0x0ddc [ 02674201AD9FE19AC3376705077882C6, 9AA800AA77EBA488FA537FF47D361F6B09E8063A99CCBF5AE2F754A6A648DF84 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 12:35:35.0378 0x0ddc IntcAzAudAddService - ok 12:35:35.0400 0x0ddc [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys 12:35:35.0413 0x0ddc intelide - ok 12:35:35.0432 0x0ddc [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 12:35:35.0448 0x0ddc intelppm - ok 12:35:35.0471 0x0ddc [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll 12:35:35.0524 0x0ddc IPBusEnum - ok 12:35:35.0553 0x0ddc [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 12:35:35.0597 0x0ddc IpFilterDriver - ok 12:35:35.0636 0x0ddc [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 12:35:35.0718 0x0ddc iphlpsvc - ok 12:35:35.0750 0x0ddc [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 12:35:35.0782 0x0ddc IPMIDRV - ok 12:35:35.0803 0x0ddc [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys 12:35:35.0836 0x0ddc IPNAT - ok 12:35:35.0937 0x0ddc [ A4857E8B1DEB9740FB5ADEDF05ED69E0, 24FC7A188D32B08CE4F10EEEF17F37C45DB5433158A7A97A07D43F6BEE58DFFC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 12:35:35.0966 0x0ddc iPod Service - ok 12:35:35.0988 0x0ddc [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys 12:35:36.0046 0x0ddc IRENUM - ok 12:35:36.0057 0x0ddc [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys 12:35:36.0070 0x0ddc isapnp - ok 12:35:36.0093 0x0ddc [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 12:35:36.0116 0x0ddc iScsiPrt - ok 12:35:36.0170 0x0ddc [ 6B37B542157C2EFA3BDA5F87428FE588, 61BD79573B4764F8CAC1BA5224EF0B82E9D2916AC32B62A1DC880641128A25F3 ] johci C:\Windows\system32\DRIVERS\johci.sys 12:35:36.0204 0x0ddc johci - ok 12:35:36.0235 0x0ddc [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 12:35:36.0271 0x0ddc kbdclass - ok 12:35:36.0289 0x0ddc [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 12:35:36.0331 0x0ddc kbdhid - ok 12:35:36.0363 0x0ddc [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] KeyIso C:\Windows\system32\lsass.exe 12:35:36.0377 0x0ddc KeyIso - ok 12:35:36.0406 0x0ddc [ 063C09DB965E3DFD6F4F08416F6DB8F5, 0BE015C59288397536B3941BA55EFE0CF06714BC43FF3A33A1D844B4E0F16097 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 12:35:36.0424 0x0ddc KSecDD - ok 12:35:36.0437 0x0ddc [ 1FA627E63195BF3BF636BFEF0D7190D4, 794456605303F4916E81BE899E0B05CB070094E719ADA8BE8072A761E35CA8E9 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 12:35:36.0455 0x0ddc KSecPkg - ok 12:35:36.0472 0x0ddc [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 12:35:36.0501 0x0ddc ksthunk - ok 12:35:36.0525 0x0ddc [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll 12:35:36.0582 0x0ddc KtmRm - ok 12:35:36.0610 0x0ddc [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll 12:35:36.0648 0x0ddc LanmanServer - ok 12:35:36.0672 0x0ddc [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 12:35:36.0707 0x0ddc LanmanWorkstation - ok 12:35:36.0752 0x0ddc [ 47901EADCA0971A997ED926F0EC316C4, 727654BDCD2D2911CEF14C9C1BA161309A2E3D260BF58C77A406E218BE886E26 ] LicCtrlService C:\Windows\runservice.exe 12:35:36.0775 0x0ddc LicCtrlService - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:39.0196 0x0ddc Detect skipped due to KSN trusted 12:35:39.0196 0x0ddc LicCtrlService - ok 12:35:39.0231 0x0ddc [ 156AB2E56DC3CA0B582E3362E07CDED7, 7B03929273861690DC42E4C686E655BE5A1C60136AE5E739D7E62306AFD4AB9A ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys 12:35:39.0266 0x0ddc lirsgt - ok 12:35:39.0290 0x0ddc [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 12:35:39.0354 0x0ddc lltdio - ok 12:35:39.0390 0x0ddc [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll 12:35:39.0477 0x0ddc lltdsvc - ok 12:35:39.0494 0x0ddc [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll 12:35:39.0536 0x0ddc lmhosts - ok 12:35:39.0569 0x0ddc [ 81C0817E8D4FEF2EC38300B31070D67F, 249AD6731161B9BDFD57D0267ED9206AD24CF7EA688B54685ED5EF54511E6BD7 ] LPCFilter C:\Windows\system32\DRIVERS\LPCFilter.sys 12:35:39.0582 0x0ddc LPCFilter - ok 12:35:39.0609 0x0ddc [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 12:35:39.0626 0x0ddc LSI_FC - ok 12:35:39.0641 0x0ddc [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 12:35:39.0657 0x0ddc LSI_SAS - ok 12:35:39.0670 0x0ddc [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 12:35:39.0685 0x0ddc LSI_SAS2 - ok 12:35:39.0700 0x0ddc [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 12:35:39.0716 0x0ddc LSI_SCSI - ok 12:35:39.0743 0x0ddc [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys 12:35:39.0796 0x0ddc luafv - ok 12:35:39.0816 0x0ddc lxbx_device - ok 12:35:39.0881 0x0ddc [ 1E9E32AEC3E1EB1B31B8169F33168B56, 39114585E1FDBBA31E1F781C6A627281907183F94626EB347B08D1F78992ED2A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 12:35:39.0919 0x0ddc MBAMProtector - ok 12:35:40.0040 0x0ddc [ 516E29AD03BDF610CC36A95AE692FE42, 09F913B169AD775FF587AE59AEC5DD2A2D8646803F48BF616C74EEC0DE3BE7A2 ] MBAMScheduler C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe 12:35:40.0105 0x0ddc MBAMScheduler - ok 12:35:40.0152 0x0ddc [ 2B983F067AEE3F9EB4DF5E97F45D21D1, 0B9ED0E91FF01A5445927650113E320C3C0EA16F1401AA55A509DDBF704DF22F ] MBAMService C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe 12:35:40.0200 0x0ddc MBAMService - ok 12:35:40.0261 0x0ddc [ E9CD058C79EA15B4AA93E259FA713B07, 2B09F65188D8782F9C797545F2F791EC7EAB85D8914B2C0B30BD869C412E3980 ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys 12:35:40.0287 0x0ddc MBAMSwissArmy - ok 12:35:40.0308 0x0ddc [ F49FB3C88E263AE9A246593B0BB29294, FB53D6FA4A98B98334DCFF81E40712265256D31A9E9FF36022887BABD50F39EB ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys 12:35:40.0320 0x0ddc MBAMWebAccessControl - ok 12:35:40.0338 0x0ddc [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 12:35:40.0363 0x0ddc Mcx2Svc - ok 12:35:40.0377 0x0ddc [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 12:35:40.0394 0x0ddc megasas - ok 12:35:40.0450 0x0ddc [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 12:35:40.0504 0x0ddc MegaSR - ok 12:35:40.0528 0x0ddc [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll 12:35:40.0576 0x0ddc MMCSS - ok 12:35:40.0595 0x0ddc [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys 12:35:40.0669 0x0ddc Modem - ok 12:35:40.0698 0x0ddc [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 12:35:40.0719 0x0ddc monitor - ok 12:35:40.0767 0x0ddc [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 12:35:40.0813 0x0ddc mouclass - ok 12:35:40.0831 0x0ddc [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 12:35:40.0864 0x0ddc mouhid - ok 12:35:40.0892 0x0ddc [ 87BCD1034CBF33537D4D4C251D39BA26, CB9DD235B62B79383F99873D75E26EEA5EE7914CA89E4B75992207F83420437F ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 12:35:40.0916 0x0ddc mountmgr - ok 12:35:40.0985 0x0ddc [ 03D14BF1DC59130002F6B8BA3AD89DB9, 1729CCD8AAF51CDB86ED67569974D0B6B1CFFA5F90EF6E6004B0D8A305D88C27 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 12:35:41.0024 0x0ddc MozillaMaintenance - ok 12:35:41.0036 0x0ddc [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys 12:35:41.0047 0x0ddc mpio - ok 12:35:41.0072 0x0ddc [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 12:35:41.0106 0x0ddc mpsdrv - ok 12:35:41.0146 0x0ddc [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll 12:35:41.0196 0x0ddc MpsSvc - ok 12:35:41.0216 0x0ddc [ AE3334958D8F631FF14A0AEB3D7EFB3A, F5FD6B61F896104C20DFC43FEE2FCE6930B73F78DF876BD19A333EABB9139C6D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 12:35:41.0268 0x0ddc MRxDAV - ok 12:35:41.0304 0x0ddc [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 12:35:41.0358 0x0ddc mrxsmb - ok 12:35:41.0398 0x0ddc [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 12:35:41.0499 0x0ddc mrxsmb10 - ok 12:35:41.0608 0x0ddc [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 12:35:41.0697 0x0ddc mrxsmb20 - ok 12:35:41.0736 0x0ddc [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys 12:35:41.0778 0x0ddc msahci - ok 12:35:41.0804 0x0ddc [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys 12:35:41.0832 0x0ddc msdsm - ok 12:35:41.0845 0x0ddc [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe 12:35:41.0885 0x0ddc MSDTC - ok 12:35:41.0914 0x0ddc [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys 12:35:41.0961 0x0ddc Msfs - ok 12:35:41.0977 0x0ddc [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 12:35:42.0048 0x0ddc mshidkmdf - ok 12:35:42.0069 0x0ddc [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 12:35:42.0082 0x0ddc msisadrv - ok 12:35:42.0103 0x0ddc [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 12:35:42.0143 0x0ddc MSiSCSI - ok 12:35:42.0145 0x0ddc msiserver - ok 12:35:42.0219 0x0ddc [ 2C7CCCAF8630827EFB8F1939F61EA508, ABA53947A08BFFDF02C2383666E9E9CF7A45030513BE64AF955D84BEE590777C ] MSI_LiveUpdate_Service C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe 12:35:42.0265 0x0ddc MSI_LiveUpdate_Service - ok 12:35:42.0320 0x0ddc [ 6AFCD25B843D0C731B6987E39995AE72, FD0F2E15B0CEB1E558BD8A02D59B9002706A003049678281A446BC4398862B70 ] MSI_SuperCharger C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe 12:35:42.0354 0x0ddc MSI_SuperCharger - ok 12:35:42.0372 0x0ddc [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 12:35:42.0426 0x0ddc MSKSSRV - ok 12:35:42.0447 0x0ddc [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 12:35:42.0491 0x0ddc MSPCLOCK - ok 12:35:42.0502 0x0ddc [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 12:35:42.0598 0x0ddc MSPQM - ok 12:35:42.0626 0x0ddc [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 12:35:42.0654 0x0ddc MsRPC - ok 12:35:42.0666 0x0ddc [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 12:35:42.0675 0x0ddc mssmbios - ok 12:35:42.0685 0x0ddc [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 12:35:42.0729 0x0ddc MSTEE - ok 12:35:42.0742 0x0ddc [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 12:35:42.0767 0x0ddc MTConfig - ok 12:35:42.0786 0x0ddc [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys 12:35:42.0801 0x0ddc Mup - ok 12:35:42.0864 0x0ddc [ 08835780CC6A5CFF5275101B5A9D17A4, 0D07860EAB6C26BF13D7FDB53A8A663D6F2C8C139D7B3B3AD36210A650C43826 ] MxEFUF C:\Windows\system32\DRIVERS\MxEFUF64.sys 12:35:42.0949 0x0ddc MxEFUF - ok 12:35:43.0007 0x0ddc [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll 12:35:43.0053 0x0ddc napagent - ok 12:35:43.0085 0x0ddc [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 12:35:43.0120 0x0ddc NativeWifiP - ok 12:35:43.0167 0x0ddc [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS C:\Windows\system32\drivers\ndis.sys 12:35:43.0195 0x0ddc NDIS - ok 12:35:43.0209 0x0ddc [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 12:35:43.0251 0x0ddc NdisCap - ok 12:35:43.0278 0x0ddc [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 12:35:43.0345 0x0ddc NdisTapi - ok 12:35:43.0374 0x0ddc [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 12:35:43.0418 0x0ddc Ndisuio - ok 12:35:43.0476 0x0ddc [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 12:35:43.0549 0x0ddc NdisWan - ok 12:35:43.0581 0x0ddc [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 12:35:43.0643 0x0ddc NDProxy - ok 12:35:43.0692 0x0ddc [ 2334DC48997BA203B794DF3EE70521DB, 832F4EC1586C9669F2D54AB3B212943E43B87A33B24DCC8CDAD6A0264291EE2F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 12:35:43.0726 0x0ddc Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:46.0134 0x0ddc Detect skipped due to KSN trusted 12:35:46.0134 0x0ddc Net Driver HPZ12 - ok 12:35:46.0164 0x0ddc [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 12:35:46.0223 0x0ddc NetBIOS - ok 12:35:46.0257 0x0ddc [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 12:35:46.0306 0x0ddc NetBT - ok 12:35:46.0330 0x0ddc [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] Netlogon C:\Windows\system32\lsass.exe 12:35:46.0340 0x0ddc Netlogon - ok 12:35:46.0372 0x0ddc [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll 12:35:46.0413 0x0ddc Netman - ok 12:35:46.0447 0x0ddc [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 12:35:46.0487 0x0ddc NetMsmqActivator - ok 12:35:46.0492 0x0ddc [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 12:35:46.0506 0x0ddc NetPipeActivator - ok 12:35:46.0531 0x0ddc [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll 12:35:46.0585 0x0ddc netprofm - ok 12:35:46.0604 0x0ddc [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 12:35:46.0616 0x0ddc NetTcpActivator - ok 12:35:46.0620 0x0ddc [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 12:35:46.0633 0x0ddc NetTcpPortSharing - ok 12:35:46.0654 0x0ddc [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 12:35:46.0699 0x0ddc nfrd960 - ok 12:35:46.0783 0x0ddc [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc C:\Windows\System32\nlasvc.dll 12:35:46.0872 0x0ddc NlaSvc - ok 12:35:46.0904 0x0ddc [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys 12:35:46.0990 0x0ddc Npfs - ok 12:35:47.0012 0x0ddc [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll 12:35:47.0079 0x0ddc nsi - ok 12:35:47.0082 0x0ddc [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 12:35:47.0130 0x0ddc nsiproxy - ok 12:35:47.0202 0x0ddc [ 1A29A59A4C5BA6F8C85062A613B7E2B2, CC137F499A12C724D4166C2D85E9F447413419A0683DAC6F1A802B7F210C77F1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 12:35:47.0266 0x0ddc Ntfs - ok 12:35:47.0308 0x0ddc [ 23CF3DA010497EB2BF39A5C5A57E437C, 39CFDE7D401EFCE4F550E0A9461F5FC4D71FA07235E1336E4F0B4882BD76550E ] NTIOLib_1_0_3 C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys 12:35:47.0316 0x0ddc NTIOLib_1_0_3 - ok 12:35:47.0350 0x0ddc [ 1B32C54B95121AB1683C7B83B2DB4B96, 99F4994A0E5BD1BF6E3F637D3225C69FF4CD620557E23637533E7F18D7D6CBA1 ] NTIOLib_1_0_4 C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys 12:35:47.0362 0x0ddc NTIOLib_1_0_4 - ok 12:35:47.0407 0x0ddc [ C6F8983DD3D75640C072A8459B8FA55A, 101402D4F5D1AE413DED499C78A5FCBBC7E3BAE9B000D64C1DD64E3C48C37558 ] NTIOLib_MSI_RAID C:\MSI\Smart Utilities\NTIOLib_X64.sys 12:35:47.0441 0x0ddc NTIOLib_MSI_RAID - ok 12:35:47.0462 0x0ddc [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys 12:35:47.0540 0x0ddc Null - ok 12:35:47.0601 0x0ddc [ C87B11EB78428853F9E8495C47E53C10, FAE479DB0812967B3FF968773BA998591B4F50BE4329B8349BCA7E6EAB1B0474 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 12:35:47.0646 0x0ddc NVHDA - ok 12:35:48.0052 0x0ddc [ 185B4FFECD886A424B57B58AE173FBBE, 7CFD51694091035639B900EC64FAD62CC1E5F3DC520F59CC27540B170A957C60 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 12:35:48.0507 0x0ddc nvlddmkm - ok 12:35:48.0553 0x0ddc [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys 12:35:48.0585 0x0ddc nvraid - ok 12:35:48.0616 0x0ddc [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys 12:35:48.0631 0x0ddc nvstor - ok 12:35:48.0725 0x0ddc [ E1CE82592245B9E9621F17FBF457DB4E, 98B021623B10EBF7ED370BC2516D8377C09E9E2BB49BD96F492F55006B1B8CC4 ] nvsvc C:\Windows\system32\nvvsvc.exe 12:35:48.0756 0x0ddc nvsvc - ok 12:35:48.0772 0x0ddc nvvad_WaveExtensible - ok 12:35:48.0787 0x0ddc [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 12:35:48.0850 0x0ddc nv_agp - ok 12:35:48.0881 0x0ddc [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 12:35:48.0928 0x0ddc ohci1394 - ok 12:35:48.0975 0x0ddc [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 12:35:49.0021 0x0ddc ose - ok 12:35:49.0271 0x0ddc [ FE9C0029E1AF26350D9985D00520E5C8, 967079CCF7B2CBD4B48C9F076675C26AF93A1CEC26C96811F279414E34004EE6 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 12:35:49.0427 0x0ddc osppsvc - ok 12:35:49.0458 0x0ddc [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 12:35:49.0505 0x0ddc p2pimsvc - ok 12:35:49.0552 0x0ddc [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll 12:35:49.0583 0x0ddc p2psvc - ok 12:35:49.0614 0x0ddc [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\DRIVERS\parport.sys 12:35:49.0645 0x0ddc Parport - ok 12:35:49.0661 0x0ddc [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys 12:35:49.0677 0x0ddc partmgr - ok 12:35:49.0708 0x0ddc [ DB2D62AA2DF6B1F3D690A9EC9701AA2C, BEAC55E1AA0494565F1547DF5E6FE20FCEA66461764C016FCB68D8BFF0F0C375 ] PcaSvc C:\Windows\System32\pcasvc.dll 12:35:49.0786 0x0ddc PcaSvc - ok 12:35:49.0833 0x0ddc [ 3FDE033DFB0D07F8B7D5C9A3044AA121, 2C23B4FA34BA3060884B0168A830DD395A3853855CD6DF4065FBB303DFB4A87E ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys 12:35:49.0911 0x0ddc pccsmcfd - ok 12:35:49.0942 0x0ddc [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys 12:35:49.0973 0x0ddc pci - ok 12:35:50.0004 0x0ddc [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys 12:35:50.0020 0x0ddc pciide - ok 12:35:50.0035 0x0ddc [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 12:35:50.0051 0x0ddc pcmcia - ok 12:35:50.0067 0x0ddc [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys 12:35:50.0067 0x0ddc pcw - ok 12:35:50.0160 0x0ddc [ 98655F862BB07CFB1CCC9262DA621AE1, 6903FA802D73A2450DE29BBA9283EC9C256C4C08D848201952D51DBBD9630A9A ] PDF Architect Helper Service C:\Program Files (x86)\PDF Architect\HelperService.exe 12:35:50.0223 0x0ddc PDF Architect Helper Service - ok 12:35:50.0254 0x0ddc [ 73406F96E946F2B38615375269EF286F, 28170FF1F3B641B013DDB57582F8D9E6ED4205D8C63C89EA685FEC1E42833309 ] PDF Architect Service C:\Program Files (x86)\PDF Architect\ConversionService.exe 12:35:50.0301 0x0ddc PDF Architect Service - ok 12:35:50.0379 0x0ddc [ ED6E75158D28D33A2E2A020AC5B2B59D, 0F364D9A88304C45F31318605C417A70A9D0E4CF087D73E949B42C12CC76CD6C ] PEAUTH C:\Windows\system32\drivers\peauth.sys 12:35:50.0457 0x0ddc PEAUTH - ok 12:35:50.0535 0x0ddc [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 12:35:50.0628 0x0ddc PeerDistSvc - ok 12:35:50.0722 0x0ddc [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe 12:35:50.0769 0x0ddc PerfHost - ok 12:35:50.0817 0x0ddc [ 096E2BE69F61CFA7AC47EA4F4637BEA6, 369DBE623897AF65AC1605883B37556F152EB5021FAE0C2512DB617D3629B0F1 ] pikbd C:\Windows\system32\DRIVERS\pikbd.sys 12:35:50.0849 0x0ddc pikbd - ok 12:35:50.0942 0x0ddc [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll 12:35:51.0036 0x0ddc pla - ok 12:35:51.0083 0x0ddc [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 12:35:51.0129 0x0ddc PlugPlay - ok 12:35:51.0192 0x0ddc [ AC78DF349F0E4CFB8B667C0CFFF83CCE, 7E635AA2E7350FCA0C954E697F1480A6204920AEFBCF06B90FFA02398DA82822 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 12:35:51.0223 0x0ddc Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 ) 12:35:53.0688 0x0ddc Detect skipped due to KSN trusted 12:35:53.0688 0x0ddc Pml Driver HPZ12 - ok 12:35:53.0703 0x0ddc [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 12:35:53.0750 0x0ddc PNRPAutoReg - ok 12:35:53.0781 0x0ddc [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 12:35:53.0813 0x0ddc PNRPsvc - ok 12:35:53.0828 0x0ddc [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 12:35:53.0891 0x0ddc PolicyAgent - ok 12:35:53.0937 0x0ddc [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll 12:35:54.0000 0x0ddc Power - ok 12:35:54.0015 0x0ddc [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 12:35:54.0062 0x0ddc PptpMiniport - ok 12:35:54.0093 0x0ddc [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\DRIVERS\processr.sys 12:35:54.0125 0x0ddc Processor - ok 12:35:54.0156 0x0ddc [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc C:\Windows\system32\profsvc.dll 12:35:54.0218 0x0ddc ProfSvc - ok 12:35:54.0234 0x0ddc [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] ProtectedStorage C:\Windows\system32\lsass.exe 12:35:54.0265 0x0ddc ProtectedStorage - ok 12:35:54.0296 0x0ddc [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 12:35:54.0327 0x0ddc Psched - ok 12:35:54.0390 0x0ddc [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 12:35:54.0437 0x0ddc ql2300 - ok 12:35:54.0452 0x0ddc [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 12:35:54.0468 0x0ddc ql40xx - ok 12:35:54.0499 0x0ddc [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll 12:35:54.0530 0x0ddc QWAVE - ok 12:35:54.0546 0x0ddc [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 12:35:54.0561 0x0ddc QWAVEdrv - ok 12:35:54.0561 0x0ddc [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 12:35:54.0639 0x0ddc RasAcd - ok 12:35:54.0671 0x0ddc [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 12:35:54.0733 0x0ddc RasAgileVpn - ok 12:35:54.0749 0x0ddc [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll 12:35:54.0795 0x0ddc RasAuto - ok 12:35:54.0827 0x0ddc [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 12:35:54.0905 0x0ddc Rasl2tp - ok 12:35:54.0936 0x0ddc [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll 12:35:54.0983 0x0ddc RasMan - ok 12:35:54.0998 0x0ddc [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 12:35:55.0029 0x0ddc RasPppoe - ok 12:35:55.0045 0x0ddc [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 12:35:55.0076 0x0ddc RasSstp - ok 12:35:55.0107 0x0ddc [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 12:35:55.0170 0x0ddc rdbss - ok 12:35:55.0185 0x0ddc [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 12:35:55.0217 0x0ddc rdpbus - ok 12:35:55.0232 0x0ddc [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 12:35:55.0310 0x0ddc RDPCDD - ok 12:35:55.0326 0x0ddc [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 12:35:55.0357 0x0ddc RDPDR - ok 12:35:55.0373 0x0ddc [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 12:35:55.0451 0x0ddc RDPENCDD - ok 12:35:55.0451 0x0ddc [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 12:35:55.0482 0x0ddc RDPREFMP - ok 12:35:55.0529 0x0ddc [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 12:35:55.0607 0x0ddc RdpVideoMiniport - ok 12:35:55.0653 0x0ddc [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 12:35:55.0716 0x0ddc RDPWD - ok 12:35:55.0747 0x0ddc [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 12:35:55.0778 0x0ddc rdyboost - ok 12:35:55.0794 0x0ddc [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll 12:35:55.0841 0x0ddc RemoteAccess - ok 12:35:55.0872 0x0ddc [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll 12:35:55.0919 0x0ddc RemoteRegistry - ok 12:35:55.0950 0x0ddc [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 12:35:56.0012 0x0ddc RpcEptMapper - ok 12:35:56.0028 0x0ddc [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe 12:35:56.0059 0x0ddc RpcLocator - ok 12:35:56.0106 0x0ddc [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\Windows\system32\rpcss.dll 12:35:56.0137 0x0ddc RpcSs - ok 12:35:56.0168 0x0ddc [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 12:35:56.0215 0x0ddc rspndr - ok 12:35:56.0262 0x0ddc [ AC0E048F44BB30B96B81075A2455F0F7, D2BE8A9303AEDD9DC4F407A69C52F906F1A29EEC809E6A40F1A36873E3C276D6 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys 12:35:56.0277 0x0ddc RTHDMIAzAudService - ok 12:35:56.0324 0x0ddc [ D2D055E7ED70A5EE885D17D35DF97E80, 51781E55EEE111140A261822D3F78D76AD288E9DDF8578E236358E0AEB872C2F ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 12:35:56.0371 0x0ddc RTL8167 - ok 12:35:56.0402 0x0ddc [ B263B3AEBCDE2210D1CC25756601B8EA, 85395F55555BC846397BB5F4FE5DE90EC7A12B629B339758F969B5B4AE6C8ADA ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh64.sys 12:35:56.0418 0x0ddc RTL8169 - ok 12:35:56.0480 0x0ddc [ 496043BAD6FBFAAF5280C9EB41920684, E9ECFE2527A020FED1E6BDBE7D82BA977F7A03968A3F2A9897321CB0472F6087 ] RTLE8023x64 C:\Windows\system32\DRIVERS\Rtenic64.sys 12:35:56.0527 0x0ddc RTLE8023x64 - ok 12:35:56.0558 0x0ddc [ 2B38C905492F36FE42B59DA52D6B4EB7, 966AA4E15A4BB079E91C1900AB2B565DC0BEFCDCBFD49CDD480CE9348BFCB73B ] RtNdPt60 C:\Windows\system32\DRIVERS\RtNdPt60.sys 12:35:56.0636 0x0ddc RtNdPt60 - ok 12:35:56.0652 0x0ddc [ F3F166CA4283FF6F5F2C0D883D475CF8, 1F0DE9C082D5BB817557DB99827D0E912FBF2BCA53BDB6C64438A48214F92FC0 ] RTTEAMPT C:\Windows\system32\DRIVERS\RtTeam60.sys 12:35:56.0667 0x0ddc RTTEAMPT - ok 12:35:56.0683 0x0ddc [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys 12:35:56.0714 0x0ddc s3cap - ok 12:35:56.0730 0x0ddc [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] SamSs C:\Windows\system32\lsass.exe 12:35:56.0730 0x0ddc SamSs - ok 12:35:56.0745 0x0ddc SANDRA - ok 12:35:56.0761 0x0ddc [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 12:35:56.0777 0x0ddc sbp2port - ok 12:35:56.0808 0x0ddc [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll 12:35:56.0839 0x0ddc SCardSvr - ok 12:35:56.0870 0x0ddc [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 12:35:56.0948 0x0ddc scfilter - ok 12:35:57.0073 0x0ddc [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\Windows\system32\schedsvc.dll 12:35:57.0151 0x0ddc Schedule - ok 12:35:57.0182 0x0ddc [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll 12:35:57.0245 0x0ddc SCPolicySvc - ok 12:35:57.0276 0x0ddc [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll 12:35:57.0338 0x0ddc SDRSVC - ok 12:35:57.0557 0x0ddc [ 98EF79CC2B07398AC525F9EA1AE0366F, D0D5D69696ED339F363024AF3271867F4C55572C67FD0F2AA27D24B37982E39A ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe 12:35:57.0666 0x0ddc SDScannerService - ok 12:35:57.0759 0x0ddc [ 14BF6B3AB327D519ED007CDDC56F6900, 4E5DC4AF45347C885E0E87F205EE1F95BB4713A0B581CD7317FBEEE2A9628982 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe 12:35:57.0822 0x0ddc SDUpdateService - ok 12:35:57.0837 0x0ddc [ 820EBE67AB99F033FDE25B2692157991, A9E86FE6EFD3CFD4EA1A26121C706335A6791CC6F81EE98AE2BE7EA566ECFEBB ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe 12:35:57.0853 0x0ddc SDWSCService - ok 12:35:57.0900 0x0ddc [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys 12:35:57.0978 0x0ddc secdrv - ok 12:35:58.0009 0x0ddc [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\Windows\system32\seclogon.dll 12:35:58.0071 0x0ddc seclogon - ok 12:35:58.0087 0x0ddc [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\System32\sens.dll 12:35:58.0134 0x0ddc SENS - ok 12:35:58.0165 0x0ddc [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll 12:35:58.0227 0x0ddc SensrSvc - ok 12:35:58.0227 0x0ddc [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 12:35:58.0243 0x0ddc Serenum - ok 12:35:58.0259 0x0ddc [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\DRIVERS\serial.sys 12:35:58.0305 0x0ddc Serial - ok 12:35:58.0321 0x0ddc [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 12:35:58.0461 0x0ddc sermouse - ok 12:35:58.0586 0x0ddc [ 78F7BB9F4924BE164294C59B8C3FC096, 75051A6A8B0DBB16CD70855A408134270EEAF0C127BAAE5B592DB53BB87C085B ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe 12:35:58.0617 0x0ddc ServiceLayer - ok 12:35:58.0649 0x0ddc [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll 12:35:58.0695 0x0ddc SessionEnv - ok 12:35:58.0727 0x0ddc [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 12:35:58.0773 0x0ddc sffdisk - ok 12:35:58.0789 0x0ddc [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 12:35:58.0851 0x0ddc sffp_mmc - ok 12:35:58.0851 0x0ddc [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 12:35:58.0898 0x0ddc sffp_sd - ok 12:35:58.0914 0x0ddc [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 12:35:58.0929 0x0ddc sfloppy - ok 12:35:58.0992 0x0ddc [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll 12:35:59.0070 0x0ddc SharedAccess - ok 12:35:59.0085 0x0ddc [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 12:35:59.0132 0x0ddc ShellHWDetection - ok 12:35:59.0163 0x0ddc [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 12:35:59.0179 0x0ddc SiSRaid2 - ok 12:35:59.0195 0x0ddc [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 12:35:59.0210 0x0ddc SiSRaid4 - ok 12:35:59.0273 0x0ddc [ F6EF225A23D336CA30001E5007644C24, B0A4B1256C1074F1B4F73E3BBA16FD4683D6EEA583DEEF8E11EFD29BA7541F2A ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 12:35:59.0319 0x0ddc SkypeUpdate - ok 12:35:59.0382 0x0ddc [ BA8B51F09A17A14D11A26289AE2858B6, 9006E47EABDA122C0401DFCFA764524FB58BDD484DF713C387D64D9558CE19D3 ] SliceDisk5 C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys 12:35:59.0429 0x0ddc SliceDisk5 - detected UnsignedFile.Multi.Generic ( 1 ) 12:36:01.0893 0x0ddc Detect skipped due to KSN trusted 12:36:01.0893 0x0ddc SliceDisk5 - ok 12:36:01.0925 0x0ddc [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys 12:36:02.0003 0x0ddc Smb - ok 12:36:02.0034 0x0ddc [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 12:36:02.0065 0x0ddc SNMPTRAP - ok 12:36:02.0096 0x0ddc [ 5F9785E7535F8F602CB294A54962C9E7, 22BE050955347661685A4343C51F11C7811674E030386D2264CD12ECBF544B7C ] speedfan C:\Windows\syswow64\speedfan.sys 12:36:02.0112 0x0ddc speedfan - ok 12:36:02.0127 0x0ddc [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys 12:36:02.0159 0x0ddc spldr - ok 12:36:02.0190 0x0ddc [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler C:\Windows\System32\spoolsv.exe 12:36:02.0237 0x0ddc Spooler - ok 12:36:02.0377 0x0ddc [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe 12:36:02.0471 0x0ddc sppsvc - ok 12:36:02.0486 0x0ddc [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll 12:36:02.0517 0x0ddc sppuinotify - ok 12:36:02.0549 0x0ddc [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\Windows\system32\DRIVERS\srv.sys 12:36:02.0627 0x0ddc srv - ok 12:36:02.0673 0x0ddc [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 12:36:02.0720 0x0ddc srv2 - ok 12:36:02.0736 0x0ddc [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 12:36:02.0783 0x0ddc srvnet - ok 12:36:02.0829 0x0ddc [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 12:36:02.0876 0x0ddc SSDPSRV - ok 12:36:02.0907 0x0ddc [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll 12:36:02.0954 0x0ddc SstpSvc - ok 12:36:02.0985 0x0ddc StarOpen - ok 12:36:03.0063 0x0ddc [ EBAA82F7C9B97C0E450449178E007340, D470927CC216C4E3EA23236E6C6464187CD3A49C3A4A456F488FEC8E713EA31B ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe 12:36:03.0173 0x0ddc Steam Client Service - ok 12:36:03.0188 0x0ddc [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 12:36:03.0219 0x0ddc stexstor - ok 12:36:03.0251 0x0ddc [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll 12:36:03.0297 0x0ddc stisvc - ok 12:36:03.0313 0x0ddc [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys 12:36:03.0329 0x0ddc storflt - ok 12:36:03.0344 0x0ddc [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc C:\Windows\system32\storsvc.dll 12:36:03.0407 0x0ddc StorSvc - ok 12:36:03.0422 0x0ddc [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys 12:36:03.0453 0x0ddc storvsc - ok 12:36:03.0500 0x0ddc [ 1DA090D603EBAC2658CC895B1C6AC399, E803ED08C0531CCFCF6454E96F1F96146D8894D09D51AEE42AF9542C2C3DF01C ] SuperRAIDSvc C:\MSI\Smart Utilities\SuperRAIDSvc.exe 12:36:03.0531 0x0ddc SuperRAIDSvc - ok 12:36:03.0563 0x0ddc [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\drivers\swenum.sys 12:36:03.0594 0x0ddc swenum - ok 12:36:03.0656 0x0ddc [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll 12:36:03.0719 0x0ddc swprv - ok 12:36:03.0797 0x0ddc [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\Windows\system32\sysmain.dll 12:36:03.0859 0x0ddc SysMain - ok 12:36:03.0890 0x0ddc [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll 12:36:03.0921 0x0ddc TabletInputService - ok 12:36:03.0953 0x0ddc [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll 12:36:03.0999 0x0ddc TapiSrv - ok 12:36:04.0015 0x0ddc [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\Windows\System32\tbssvc.dll 12:36:04.0046 0x0ddc TBS - ok 12:36:04.0124 0x0ddc [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 12:36:04.0202 0x0ddc Tcpip - ok 12:36:04.0249 0x0ddc [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 12:36:04.0296 0x0ddc TCPIP6 - ok 12:36:04.0327 0x0ddc [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 12:36:04.0358 0x0ddc tcpipreg - ok 12:36:04.0389 0x0ddc [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 12:36:04.0436 0x0ddc TDPIPE - ok 12:36:04.0467 0x0ddc [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 12:36:04.0514 0x0ddc TDTCP - ok 12:36:04.0561 0x0ddc [ 70988118145F5F10EF24720B97F35F65, F80C806417A68047FFB3D63214BC4AE5445315219AC594E043293006B704A63D ] tdx C:\Windows\system32\DRIVERS\tdx.sys 12:36:04.0655 0x0ddc tdx - ok 12:36:04.0670 0x0ddc [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\drivers\termdd.sys 12:36:04.0717 0x0ddc TermDD - ok 12:36:04.0795 0x0ddc [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService C:\Windows\System32\termsrv.dll 12:36:04.0842 0x0ddc TermService - ok 12:36:04.0857 0x0ddc [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll 12:36:04.0889 0x0ddc Themes - ok 12:36:04.0904 0x0ddc [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll 12:36:04.0935 0x0ddc THREADORDER - ok 12:36:04.0951 0x0ddc [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll 12:36:05.0013 0x0ddc TrkWks - ok 12:36:05.0060 0x0ddc [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 12:36:05.0123 0x0ddc TrustedInstaller - ok 12:36:05.0169 0x0ddc [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 12:36:05.0169 0x0ddc tssecsrv - ok 12:36:05.0216 0x0ddc [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 12:36:05.0263 0x0ddc TsUsbFlt - ok 12:36:05.0310 0x0ddc [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 12:36:05.0372 0x0ddc tunnel - ok 12:36:05.0403 0x0ddc [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 12:36:05.0419 0x0ddc uagp35 - ok 12:36:05.0450 0x0ddc [ 632AA439691CF71F544567C3D6458A2A, 69CA9C5BB7D6FA3F361318985DB5DEF832B6151A43E99D344585291675ED4EF9 ] ubohci C:\Windows\system32\DRIVERS\ubohci.sys 12:36:05.0528 0x0ddc ubohci - ok 12:36:05.0559 0x0ddc [ E1AFED5E72113D552B2E2ADEFC8A7CE9, FD471B256ED6A505957EB12E3E3B04869831E2F52F596922D999392669A562BC ] ubsbm C:\Windows\system32\DRIVERS\ubsbm.sys 12:36:05.0575 0x0ddc ubsbm - ok 12:36:05.0606 0x0ddc [ F188ECC28D9685F32A0286D66B94B01A, 50DC4A621DDC347497E3C4181D5E2A2648A019B9EE294A28AE9814DDE7869675 ] ubumapi C:\Windows\system32\DRIVERS\ubumapi.sys 12:36:05.0622 0x0ddc ubumapi - ok 12:36:05.0669 0x0ddc [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 12:36:05.0715 0x0ddc udfs - ok 12:36:05.0731 0x0ddc [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe 12:36:05.0778 0x0ddc UI0Detect - ok 12:36:05.0809 0x0ddc [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 12:36:05.0856 0x0ddc uliagpkx - ok 12:36:05.0887 0x0ddc [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\drivers\umbus.sys 12:36:05.0949 0x0ddc umbus - ok 12:36:05.0965 0x0ddc [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 12:36:05.0996 0x0ddc UmPass - ok 12:36:06.0027 0x0ddc [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll 12:36:06.0074 0x0ddc UmRdpService - ok 12:36:06.0090 0x0ddc [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll 12:36:06.0152 0x0ddc upnphost - ok 12:36:06.0199 0x0ddc [ 54D4B48D443E7228BF64CF7CDC3118AC, 4C953166EAECFD217218E386B411A4BDDA86AE65DCF352D271DF8E3D7DECC85F ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 12:36:06.0246 0x0ddc USBAAPL64 - detected UnsignedFile.Multi.Generic ( 1 ) 12:36:08.0711 0x0ddc Detect skipped due to KSN trusted 12:36:08.0711 0x0ddc USBAAPL64 - ok 12:36:08.0789 0x0ddc [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 12:36:08.0867 0x0ddc usbaudio - ok 12:36:08.0898 0x0ddc [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 12:36:08.0976 0x0ddc usbccgp - ok 12:36:09.0007 0x0ddc [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys 12:36:09.0038 0x0ddc usbcir - ok 12:36:09.0054 0x0ddc [ 18A85013A3E0F7E1755365D287443965, 811C5EDF38C765BCF71BCE25CB6626FF6988C3699F5EF1846240EA0052F34C33 ] usbehci C:\Windows\system32\drivers\usbehci.sys 12:36:09.0069 0x0ddc usbehci - ok 12:36:09.0101 0x0ddc [ 76E2FFAD301490BA27B947C6507752FB, A4C6FC5C3BF428C624D0792873CB01C8F16F49B0E8B36422025A1094F0AAE231 ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys 12:36:09.0116 0x0ddc usbfilter - ok 12:36:09.0163 0x0ddc [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 12:36:09.0241 0x0ddc usbhub - ok 12:36:09.0257 0x0ddc [ 765A92D428A8DB88B960DA5A8D6089DC, 56DE8A2ED58E53B202C399CA7BACB1551136303C2EE0AB426BDBBF880E3C542C ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 12:36:09.0272 0x0ddc usbohci - ok 12:36:09.0303 0x0ddc [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 12:36:09.0335 0x0ddc usbprint - ok 12:36:09.0366 0x0ddc [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 12:36:09.0413 0x0ddc usbscan - ok 12:36:09.0444 0x0ddc [ B57B4F0BEC4270A281B9F8537EB2FA04, 554273482EE85F010DC62E412C9933E65BD63AA09911BD25D86F86D2618EF382 ] usbser C:\Windows\system32\DRIVERS\usbser.sys 12:36:09.0506 0x0ddc usbser - ok 12:36:09.0537 0x0ddc [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 12:36:09.0600 0x0ddc USBSTOR - ok 12:36:09.0615 0x0ddc [ DD253AFC3BC6CBA412342DE60C3647F3, 146F8613F1057AC054DC3593E84BC52899DA27EA33B0E72ACFB78C3699ADCDE7 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 12:36:09.0662 0x0ddc usbuhci - ok 12:36:09.0709 0x0ddc [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 12:36:09.0756 0x0ddc usbvideo - ok 12:36:09.0771 0x0ddc [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll 12:36:09.0834 0x0ddc UxSms - ok 12:36:09.0849 0x0ddc [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] VaultSvc C:\Windows\system32\lsass.exe 12:36:09.0865 0x0ddc VaultSvc - ok 12:36:09.0881 0x0ddc [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 12:36:09.0927 0x0ddc vdrvroot - ok 12:36:09.0974 0x0ddc [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe 12:36:10.0021 0x0ddc vds - ok 12:36:10.0052 0x0ddc [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 12:36:10.0068 0x0ddc vga - ok 12:36:10.0083 0x0ddc [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys 12:36:10.0130 0x0ddc VgaSave - ok 12:36:10.0146 0x0ddc [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 12:36:10.0161 0x0ddc vhdmp - ok 12:36:10.0193 0x0ddc [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys 12:36:10.0208 0x0ddc viaide - ok 12:36:10.0224 0x0ddc [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys 12:36:10.0239 0x0ddc vmbus - ok 12:36:10.0255 0x0ddc [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 12:36:10.0271 0x0ddc VMBusHID - ok 12:36:10.0286 0x0ddc [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys 12:36:10.0302 0x0ddc volmgr - ok 12:36:10.0333 0x0ddc [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 12:36:10.0364 0x0ddc volmgrx - ok 12:36:10.0380 0x0ddc [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys 12:36:10.0395 0x0ddc volsnap - ok 12:36:10.0473 0x0ddc [ 6C60B5B5E6510BBC0CC3BA78722E8C80, F9E445566C314FF2F22382C051A090083741E86986729E905F07767DD9B84ABE ] vpnagent C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe 12:36:10.0520 0x0ddc vpnagent - ok 12:36:10.0551 0x0ddc [ 0F42C39016F82F345C0F2DB2D5B90EB4, 2E957E72BB8D0293F61FA7385BA9400DF7759E1E3D35FE24F3877A6460988F4D ] vpnva C:\Windows\system32\DRIVERS\vpnva64-6.sys 12:36:10.0598 0x0ddc vpnva - ok 12:36:10.0614 0x0ddc [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 12:36:10.0629 0x0ddc vsmraid - ok 12:36:10.0739 0x0ddc [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe 12:36:10.0848 0x0ddc VSS - ok 12:36:10.0863 0x0ddc [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 12:36:10.0879 0x0ddc vwifibus - ok 12:36:10.0910 0x0ddc [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll 12:36:10.0941 0x0ddc W32Time - ok 12:36:10.0957 0x0ddc [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 12:36:10.0973 0x0ddc WacomPen - ok 12:36:11.0019 0x0ddc [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 12:36:11.0051 0x0ddc WANARP - ok 12:36:11.0051 0x0ddc [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 12:36:11.0082 0x0ddc Wanarpv6 - ok 12:36:11.0175 0x0ddc [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 12:36:11.0238 0x0ddc WatAdminSvc - ok 12:36:11.0331 0x0ddc [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe 12:36:11.0409 0x0ddc wbengine - ok 12:36:11.0425 0x0ddc [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 12:36:11.0472 0x0ddc WbioSrvc - ok 12:36:11.0503 0x0ddc [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll 12:36:11.0534 0x0ddc wcncsvc - ok 12:36:11.0534 0x0ddc [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 12:36:11.0612 0x0ddc WcsPlugInService - ok 12:36:11.0643 0x0ddc [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\DRIVERS\wd.sys 12:36:11.0675 0x0ddc Wd - ok 12:36:11.0721 0x0ddc [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 12:36:11.0753 0x0ddc Wdf01000 - ok 12:36:11.0784 0x0ddc [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost C:\Windows\system32\wdi.dll 12:36:11.0815 0x0ddc WdiServiceHost - ok 12:36:11.0815 0x0ddc [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost C:\Windows\system32\wdi.dll 12:36:11.0831 0x0ddc WdiSystemHost - ok 12:36:11.0862 0x0ddc [ 0EB0E5D22B1760F2DBCE632F2DD7A54D, B8A4CC62F88768947FB0A161CF9564DB28FD9C1C037B5475DF192982DE035C22 ] WebClient C:\Windows\System32\webclnt.dll 12:36:11.0893 0x0ddc WebClient - ok 12:36:11.0909 0x0ddc [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll 12:36:11.0971 0x0ddc Wecsvc - ok 12:36:11.0987 0x0ddc [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll 12:36:12.0033 0x0ddc wercplsupport - ok 12:36:12.0065 0x0ddc [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll 12:36:12.0096 0x0ddc WerSvc - ok 12:36:12.0127 0x0ddc [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 12:36:12.0158 0x0ddc WfpLwf - ok 12:36:12.0158 0x0ddc [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 12:36:12.0174 0x0ddc WIMMount - ok 12:36:12.0205 0x0ddc WinDefend - ok 12:36:12.0205 0x0ddc WinHttpAutoProxySvc - ok 12:36:12.0283 0x0ddc [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 12:36:12.0361 0x0ddc Winmgmt - ok 12:36:12.0486 0x0ddc [ D929ABD465A2DED963DA8B30946A8D5C, DE8DBFB01C11D2AE903CBD6A974D6F995E9813CE2D6484B7DA06EAE4C545842A ] WinRM C:\Windows\system32\WsmSvc.dll 12:36:12.0611 0x0ddc WinRM - ok 12:36:12.0673 0x0ddc [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\drivers\WinUsb.sys 12:36:12.0720 0x0ddc WinUsb - ok 12:36:12.0782 0x0ddc [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll 12:36:12.0829 0x0ddc Wlansvc - ok 12:36:13.0032 0x0ddc [ 98F138897EF4246381D197CB81846D62, A9FA88475AFBB8883297708608EC7C1AC29F229C3299A84D557172604813A18C ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 12:36:13.0125 0x0ddc wlidsvc - ok 12:36:13.0157 0x0ddc [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 12:36:13.0203 0x0ddc WmiAcpi - ok 12:36:13.0250 0x0ddc [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 12:36:13.0297 0x0ddc wmiApSrv - ok 12:36:13.0330 0x0ddc WMPNetworkSvc - ok 12:36:13.0330 0x0ddc [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll 12:36:13.0393 0x0ddc WPCSvc - ok 12:36:13.0426 0x0ddc [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 12:36:13.0490 0x0ddc WPDBusEnum - ok 12:36:13.0521 0x0ddc [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 12:36:13.0599 0x0ddc ws2ifsl - ok 12:36:13.0631 0x0ddc [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\System32\wscsvc.dll 12:36:13.0655 0x0ddc wscsvc - ok 12:36:13.0658 0x0ddc WSearch - ok 12:36:13.0791 0x0ddc [ 0814A74C853F50B354F08F83DDA9F7FB, 0A63BAA8DE451B8C2C71FEF961718E769B9BAC305C76D24048C664CB27D0DF28 ] wuauserv C:\Windows\system32\wuaueng.dll 12:36:13.0918 0x0ddc wuauserv - ok 12:36:13.0949 0x0ddc [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 12:36:14.0000 0x0ddc WudfPf - ok 12:36:14.0016 0x0ddc [ 834469525EE22EFF3F411014E31B3E7B, 923499AFFAC47857EE7DADA747A6008C5ADE81C4B04A13E00A1879728ABE957E ] WUDFRd C:\Windows\system32\drivers\WUDFRd.sys 12:36:14.0031 0x0ddc WUDFRd - detected UnsignedFile.Multi.Generic ( 1 ) 12:36:16.0559 0x0ddc Object is SCO, delete is not allowed 12:36:16.0559 0x0ddc WUDFRd ( UnsignedFile.Multi.Generic ) - warning 12:36:19.0051 0x0ddc [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 12:36:19.0088 0x0ddc wudfsvc - ok 12:36:19.0126 0x0ddc [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc C:\Windows\System32\wwansvc.dll 12:36:19.0238 0x0ddc WwanSvc - ok 12:36:19.0272 0x0ddc [ D0352B3BD81565F97978128A308ED541, 330565435F7C7149EFEF17112FAF54B2F155736904F32D18A41EAA907AD4EF0D ] ZCLDRV C:\Windows\system32\DRIVERS\ZclDrv64.sys 12:36:19.0438 0x0ddc ZCLDRV - ok 12:36:19.0508 0x0ddc ================ Scan global =============================== 12:36:19.0559 0x0ddc [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll 12:36:19.0688 0x0ddc [ EA32F4EA3AE06EDD122FBCD5A489E457, C6E464170121D1714A367CFC80C5EA15D42AD34909039FDB114EAD3B878A47F6 ] C:\Windows\system32\winsrv.dll 12:36:19.0783 0x0ddc [ EA32F4EA3AE06EDD122FBCD5A489E457, C6E464170121D1714A367CFC80C5EA15D42AD34909039FDB114EAD3B878A47F6 ] C:\Windows\system32\winsrv.dll 12:36:19.0820 0x0ddc [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll 12:36:19.0926 0x0ddc [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe 12:36:19.0974 0x0ddc [ Global ] - ok 12:36:19.0974 0x0ddc ================ Scan MBR ================================== 12:36:19.0991 0x0ddc [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 12:36:23.0268 0x0ddc \Device\Harddisk0\DR0 - ok 12:36:23.0269 0x0ddc ================ Scan VBR ================================== 12:36:23.0282 0x0ddc [ 6C14845D90610B9AF624B26F6D8FB3E8 ] \Device\Harddisk0\DR0\Partition1 12:36:23.0290 0x0ddc \Device\Harddisk0\DR0\Partition1 - ok 12:36:23.0309 0x0ddc [ 1E26BF6F68737874C1D4231B149B3BF9 ] \Device\Harddisk0\DR0\Partition2 12:36:23.0321 0x0ddc \Device\Harddisk0\DR0\Partition2 - ok 12:36:23.0322 0x0ddc ================ Scan generic autorun ====================== 12:36:25.0801 0x0ddc [ BF5ECAC9B15AF1424EC4E7B3280537EB, B39FD921978EB1929F016B81498DA962BB3D597A593B2E5D992490A74CCBF62D ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 12:36:26.0145 0x0ddc RtHDVCpl - ok 12:36:26.0223 0x0ddc [ D0B542256A968DFCB8896C140FCE6047, 3F92A9871B521BCCCDFE6D9BFF88930B26C5DB86F6F6578554A3F2ECC5C5EBA0 ] C:\Program Files\iTunes\iTunesHelper.exe 12:36:26.0254 0x0ddc iTunesHelper - ok 12:36:26.0394 0x0ddc [ 66177D4C99FD8B578C7C56DE445E4D5D, 003D0254D7C693A72DE84CB76858F8D67D9FD62206F1B56DF7F5D0FA834C3BA7 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe 12:36:26.0410 0x0ddc avgnt - ok 12:36:26.0644 0x0ddc [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 12:36:26.0815 0x0ddc Sidebar - ok 12:36:26.0862 0x0ddc [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 12:36:26.0925 0x0ddc mctadmin - ok 12:36:26.0971 0x0ddc [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 12:36:27.0003 0x0ddc Sidebar - ok 12:36:27.0018 0x0ddc [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 12:36:27.0018 0x0ddc mctadmin - ok 12:36:27.0424 0x0ddc [ 5D566601E0F94B70946C15B66DE1CE9A, DD3006EC080B62A8FD943916CB451A55C9BFD7D9DBCA2956078EEC7D167052CF ] C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe 12:36:27.0658 0x0ddc Vidalia - detected UnsignedFile.Multi.Generic ( 1 ) 12:36:30.0123 0x0ddc Detect skipped due to KSN trusted 12:36:30.0123 0x0ddc Vidalia - ok 12:36:31.0137 0x0ddc [ 771293BC7EACB6FB7A78F8B7A954F019, DF06F0D0C8E38F17AD155CAB009A5A2969E7638B88AFBC2A75450EB1239ECAB4 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe 12:36:31.0324 0x0ddc Spybot-S&D Cleaning - ok 12:36:31.0355 0x0ddc OscarEditor - ok 12:36:31.0605 0x0ddc [ 5D566601E0F94B70946C15B66DE1CE9A, DD3006EC080B62A8FD943916CB451A55C9BFD7D9DBCA2956078EEC7D167052CF ] C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe 12:36:31.0745 0x0ddc Vidalia - detected UnsignedFile.Multi.Generic ( 1 ) 12:36:31.0745 0x0ddc Detect skipped due to KSN trusted 12:36:31.0745 0x0ddc Vidalia - ok 12:36:31.0995 0x0ddc [ 771293BC7EACB6FB7A78F8B7A954F019, DF06F0D0C8E38F17AD155CAB009A5A2969E7638B88AFBC2A75450EB1239ECAB4 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe 12:36:32.0085 0x0ddc Spybot-S&D Cleaning - ok 12:36:32.0092 0x0ddc Adobe Speed Launcher - ok 12:36:32.0093 0x0ddc Waiting for KSN requests completion. In queue: 2 12:36:33.0093 0x0ddc Waiting for KSN requests completion. In queue: 2 12:36:34.0096 0x0ddc Waiting for KSN requests completion. In queue: 2 12:36:35.0208 0x0ddc AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe ( 15.0.10.414 ), 0x41000 ( enabled : updated ) 12:36:35.0288 0x0ddc Win FW state via NFP2: enabled 12:36:37.0673 0x0ddc ============================================================ 12:36:37.0673 0x0ddc Scan finished 12:36:37.0673 0x0ddc ============================================================ 12:36:37.0676 0x10d0 Detected object count: 1 12:36:37.0676 0x10d0 Actual detected object count: 1 12:36:45.0173 0x10d0 WUDFRd ( UnsignedFile.Multi.Generic ) - skipped by user 12:36:45.0173 0x10d0 WUDFRd ( UnsignedFile.Multi.Generic ) - User select action: Skip |
11.05.2015, 06:06 | #7 |
/// the machine /// TB-Ausbilder | DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht ist legitim
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.05.2015, 09:04 | #8 |
| DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Vielen dank! Toll das ihr dieses Forum betreibt! |
11.05.2015, 13:23 | #9 |
/// the machine /// TB-Ausbilder | DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht |
adobe, antivir, avira, beste grüße, bonjour, browser, chromium, converter, defender, desktop, fehler, flash player, google, kaspersky, launch, log file, mozilla, phishing, realtek, registry, rundll, scan, services.exe, software, super, system, trojaner, trojaner board, windows |