|
Plagegeister aller Art und deren Bekämpfung: Laptop Fujitsu Celsius H265 wird immer langsamerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
10.05.2015, 18:24 | #1 |
| Laptop Fujitsu Celsius H265 wird immer langsamer Hallo, mein Laptop Fujitsu Celsius H265 wird immer langsamer ... Was kann ich dagegen tun? Danke für Ratschläge .... |
10.05.2015, 18:40 | #2 |
/// the machine /// TB-Ausbilder | Laptop Fujitsu Celsius H265 wird immer langsamer hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
15.05.2015, 05:54 | #3 |
| Laptop Fujitsu Celsius H265 wird immer langsamer Hallo,
__________________vielen Dank für deine Hilfe ... weiß mir echt nicht mehr zu helfen ... ... hier die zwei txt-files ... FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2015 02 Ran by HN (administrator) on H265-W7P on 15-05-2015 06:22:32 Running from C:\Users\HN\Downloads Loaded Profiles: HN (Available profiles: HN & Administrator) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (charismathics) C:\Windows\System32\cmTCS64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Fujitsu Technology Solutions) C:\Program Files (x86)\Common Files\Fujitsu\Manageability\HaMDevMg.exe\1.01\HaMDevMg.exe (Aladdin Knowledge Systems Ltd.) C:\Windows\System32\hasplms.exe (Aladdin Knowledge Systems Ltd.) C:\Windows\SysWOW64\HLS32SVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe (iC ComPas GmbH & Co KG) C:\Program Files\SmartCase Logon+\System\logonuser.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe () C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe () C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseServer.exe (iC ComPas GmbH & Co KG) C:\Program Files\SmartCase Logon+\System\SmartyLog.exe (Fujitsu Technology Solutions) C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe (Fujitsu Technology Solutions) C:\Program Files (x86)\Fujitsu\DeskViewBasic\DeskViewBasicService.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe (Fujitsu Technologies Solutions) C:\Program Files\SmartCase Logon+\System\SclStart.exe (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (IT Solution GmbH) C:\Program Files (x86)\ITSolution\trustDesk basic\bin\SecurityLayer.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Fujitsu Technology Solutions) C:\Program Files (x86)\Fujitsu\Mobile Software Suite\Common\UiMdmTip\UIMdmTip.exe (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Fujitsu Technology Solutions) C:\Program Files (x86)\Common Files\Fujitsu\Manageability\CnMdKHkH.exe\1.01\CnMdKHkH.exe (Microsoft Corporation) C:\Windows\System32\CompatTel\wicainventory.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Program Files (x86)\Ask.com\UpdateTask.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-20] (Synaptics Incorporated) HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7940128 2009-07-06] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-07-06] (Realtek Semiconductor Corp.) HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [358936 2009-07-15] (Intel Corporation) HKLM\...\Run: [ConMgr] => C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe [535392 2009-07-28] (CSR, plc) HKLM\...\Run: [CSRSkype] => C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe [431456 2009-07-28] (CSR, plc) HKLM\...\Run: [BthSyncServ] => "C:\Program Files\CSR\Bluetooth Feature Pack 5.0\bthsyncserv.exe" HKLM\...\Run: [CSRFTP] => C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe [463216 2009-07-28] (CSR, plc) HKLM\...\Run: [SclStart.exe] => C:\Program Files\SmartCase Logon+\System\SclStart.exe [1074752 2009-08-06] (Fujitsu Technologies Solutions) HKLM\...\Run: [ATSwpNav] => "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM-x32\...\Run: [DeskViewBasic] => C:\Program Files (x86)\Fujitsu\DeskViewBasic\DeskViewBasic.exe [182784 2009-08-19] (Fujitsu Technology Solutions) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [COMImpersonater] => C:\Program Files (x86)\Fujitsu\Mobile Software Suite\Common\UiMdmTip\UiMdmTip.exe [176128 2009-05-20] (Fujitsu Technology Solutions) HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [85160 2009-06-17] (Elaborate Bytes AG) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-08-31] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [ApnUpdater] => C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1574176 2012-12-20] (Ask) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-09] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [SecurityLayer] => C:\Program Files (x86)\ITSolution\trustDesk basic\bin\SecurityLayer.exe [3128320 2010-03-20] (IT Solution GmbH) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [964024 2012-08-31] (Samsung) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [KiesPDLR] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-08-31] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 9.3 PE.lnk [2014-05-03] ShortcutTarget: PHOTOfunSTUDIO 9.3 PE.lnk -> C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe (Panasonic Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\LaunchCenter.lnk [2010-02-09] ShortcutTarget: LaunchCenter.lnk -> C:\Program Files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\LaunchCenter.lnk [2010-02-09] ShortcutTarget: LaunchCenter.lnk -> C:\Program Files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe (Fujitsu Technology Solutions) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE HKU\S-1-5-21-2065948893-2615235351-692522125-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ts.fujitsu.com/index2 URLSearchHook: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> DefaultScope {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQLNsybmA&i=26 SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> {5397299F-6097-463C-82BB-B9365934BB1E} URL = SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> {950C1FF7-D8A5-41A9-B2F7-AC4BDCED4F32} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=f2009b5b-d012-43c3-b27b-78864d6e92e4&apn_sauid=92312519-F6BD-4C03-9049-341E9D52FD7A SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> {9848AFE5-A709-4314-9AC6-73D65A8481C5} URL = SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQLNsybmA&i=26 BHO: SingleSignOn Class -> {37B109B0-E817-4072-8429-EDC6A987FCE3} -> C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseBho.dll [2009-09-25] () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-01] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-01] (Oracle Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated) BHO-x32: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04] (Skype Technologies S.A.) BHO-x32: SingleSignOn Class -> {37B109B0-E817-4072-8429-EDC6A987FCE3} -> C:\Program Files (x86)\SmartCase Logon+\Password Manager\SmartCaseBho.dll [2009-09-25] () BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-01] (Oracle Corporation) BHO-x32: Avira SearchFree Toolbar plus Web Protection -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2012-12-20] (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-01] (Oracle Corporation) Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2012-12-20] (Ask) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default FF NewTab: FF DefaultSearchEngine: Google FF SearchEngineOrder.1: Ask.com FF Homepage: hxxp://google.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-19] () FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-01] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-19] () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2009-03-03] (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @innoplus.de/ino3DViewer -> C:\Program Files (x86)\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll [2013-09-27] (INNOVA-engineering GmbH Dresden) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Windows\SysWOW64\npdeployJava1.dll [2015-02-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation) FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 -> C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll [2012-09-28] (Logitech Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-13] (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009-06-25] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-27] (Microsoft Corporation) FF SearchPlugin: C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default\searchplugins\askcom.xml [2013-02-16] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default\Extensions\toolbar@ask.com [2012-11-10] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-03-27] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-03-27] FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox Chrome: ======= CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2013-12-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-09] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-04-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-09] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-09] (Avira Operations GmbH & Co. KG) R2 cmTCS64 Service; C:\Windows\system32\cmTCS64.exe [284672 2008-05-16] (charismathics) [File not signed] R2 DeskViewBasicService; C:\Program Files (x86)\Fujitsu\DeskViewBasic\DeskViewBasicService.exe [34816 2009-08-19] (Fujitsu Technology Solutions) [File not signed] R2 HaMDevMg.1.01; C:\Program Files (x86)\Common Files\Fujitsu\Manageability\HaMDevMg.exe\1.01\HaMDevMg.exe [557056 2009-05-20] (Fujitsu Technology Solutions) [File not signed] R2 HLServer; C:\Windows\SysWOW64\HLS32SVC.EXE [327680 2004-02-06] (Aladdin Knowledge Systems Ltd.) [File not signed] R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-07-15] (Intel Corporation) R2 LogonUserService; C:\Program Files\SmartCase Logon+\System\logonuser.exe [280128 2009-07-24] (iC ComPas GmbH & Co KG) [File not signed] R2 NVIDIA Performance Driver Service; C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [4908576 2009-07-20] () R2 SmartCaseServer; C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseServer.exe [324672 2009-07-01] () [File not signed] R2 SmartyLogService; C:\Program Files\SmartCase Logon+\System\SmartyLog.exe [321600 2009-03-12] (iC ComPas GmbH & Co KG) [File not signed] R2 TestHandler; C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [341264 2009-02-19] (Fujitsu Technology Solutions) R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2009-07-15] (Intel Corporation) R2 VFPRadioSupportService; C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [145792 2009-07-28] (CSR, plc) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-10] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-03-10] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-30] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-10] (Avira Operations GmbH & Co. KG) R1 fcrimg4; C:\Windows\System32\DRIVERS\fcrimg4.sys [43584 2009-08-27] (iC ComPas GmbH & Co KG ) R3 FscBapi; C:\Windows\System32\DRIVERS\FscBapi.sys [18944 2009-05-05] (Fujitsu Technology Solutions) R3 FscGabi; C:\Windows\System32\DRIVERS\FscGabi.sys [19968 2009-05-05] (Fujitsu Technology Solutions) R3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [20992 2009-08-05] (Fujitsu) R3 guardian2; C:\Windows\System32\Drivers\oz776x64.sys [85280 2009-05-15] (O2Micro) R3 ITEIRDA; C:\Windows\System32\DRIVERS\ITEirda.sys [27904 2008-08-22] (ITE Tech. Inc.) S3 Si3531; C:\Windows\system32\DRIVERS\Si3531.sys [330544 2007-06-01] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22832 2007-04-04] (Silicon Image, Inc.) R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [17200 2007-04-04] (Silicon Image, Inc.) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-15 06:17 - 2015-05-15 06:21 - 00036992 _____ () C:\Users\HN\Downloads\Addition.txt 2015-05-15 06:07 - 2015-05-15 06:22 - 00020834 _____ () C:\Users\HN\Downloads\FRST.txt 2015-05-15 06:06 - 2015-05-15 06:23 - 00000000 ____D () C:\FRST 2015-05-15 06:04 - 2015-05-15 06:05 - 02106368 _____ (Farbar) C:\Users\HN\Downloads\FRST64.exe 2015-05-02 11:08 - 2015-05-02 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-19 18:48 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-19 18:48 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-19 18:48 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-19 18:48 - 2015-03-17 07:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-19 18:48 - 2015-03-17 07:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-19 18:48 - 2015-03-17 07:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-19 18:48 - 2015-03-17 07:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-19 18:48 - 2015-03-17 07:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-04-19 18:48 - 2015-03-17 07:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-04-19 18:48 - 2015-03-17 07:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-19 18:48 - 2015-03-17 07:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-19 18:48 - 2015-03-17 07:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-04-19 18:48 - 2015-03-17 07:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-04-19 18:48 - 2015-03-17 07:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-19 18:48 - 2015-03-17 07:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-19 18:48 - 2015-03-17 07:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-19 18:48 - 2015-03-17 07:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-04-19 18:48 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-04-19 18:48 - 2015-03-17 06:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-04-19 18:48 - 2015-03-17 06:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-04-19 18:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-04-19 18:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-04-19 18:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-04-19 18:48 - 2015-03-17 05:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-04-19 18:48 - 2015-03-17 05:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-04-19 10:08 - 2015-04-19 10:08 - 00408768 _____ () C:\Windows\Minidump\041915-27456-01.dmp 2015-04-19 09:40 - 2015-04-19 17:26 - 00000000 ____D () C:\Windows\Minidump 2015-04-19 09:06 - 2015-04-19 09:06 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-04-19 08:54 - 2015-04-19 09:07 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-15 06:24 - 2010-02-09 10:55 - 01087154 _____ () C:\Windows\WindowsUpdate.log 2015-05-15 06:08 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-15 06:08 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-15 06:02 - 2011-04-16 16:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-05-15 05:51 - 2010-02-14 20:11 - 00003918 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{FE69482A-A787-4E11-BB36-6B36DC5921D2} 2015-05-15 05:48 - 2010-03-04 22:16 - 00000000 ____D () C:\Users\HN\Documents\Bluetooth FTP Share 2015-05-15 05:47 - 2011-04-16 16:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-15 05:46 - 2013-10-05 15:18 - 00007810 _____ () C:\Windows\setupact.log 2015-05-15 05:46 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-10 21:50 - 2012-04-07 13:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-02 11:13 - 2014-12-29 10:05 - 00000000 ____D () C:\Windows\system32\appraiser 2015-05-02 11:13 - 2014-05-10 19:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-05-02 11:13 - 2009-08-21 11:14 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-05-02 11:11 - 2010-02-17 22:42 - 01607372 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-05-02 11:11 - 2009-08-10 22:20 - 00705086 _____ () C:\Windows\system32\perfh007.dat 2015-05-02 11:11 - 2009-08-10 22:20 - 00151454 _____ () C:\Windows\system32\perfc007.dat 2015-05-02 11:11 - 2009-07-14 07:13 - 01607372 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-02 11:08 - 2010-02-10 19:00 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-05-02 11:08 - 2010-02-10 19:00 - 00000000 ____D () C:\ProgramData\Skype 2015-05-02 11:07 - 2013-08-31 19:08 - 00000000 ____D () C:\Windows\system32\MRT 2015-05-02 10:58 - 2011-07-09 15:00 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-19 17:30 - 2010-02-09 11:07 - 00000000 ____D () C:\Users\HN 2015-04-19 17:27 - 2010-02-10 13:03 - 00000000 ____D () C:\Users\Administrator 2015-04-19 17:27 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-04-19 17:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-04-19 17:26 - 2010-02-09 11:07 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-19 17:26 - 2009-07-14 09:45 - 00000000 ___RD () C:\Users\Public\Recorded TV 2015-04-19 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2015-04-19 17:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2015-04-19 09:05 - 2012-07-29 19:30 - 00000000 ____D () C:\Temp 2015-04-19 08:10 - 2012-04-07 13:46 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-19 08:10 - 2012-04-07 13:46 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-19 08:10 - 2011-05-15 17:14 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Files in the root of some directories ======= 2010-07-13 10:18 - 2010-08-05 00:50 - 0007619 _____ () C:\Users\HN\AppData\Local\Resmon.ResmonCfg 2012-10-05 20:31 - 2012-10-05 20:31 - 0076359 _____ () C:\ProgramData\ezpyasyqxocngjn Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\GoogleToolbarInstaller.exe C:\Users\HN\AppData\Local\Temp\avgnt.exe C:\Users\HN\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\HN\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\HN\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe C:\Users\HN\AppData\Local\Temp\jre-8u31-windows-au.exe C:\Users\HN\AppData\Local\Temp\nvAppBar.exe C:\Users\HN\AppData\Local\Temp\nview.dll C:\Users\HN\AppData\Local\Temp\nView64.dll C:\Users\HN\AppData\Local\Temp\nViewSetup.exe C:\Users\HN\AppData\Local\Temp\nvShell.dll C:\Users\HN\AppData\Local\Temp\nvTaskBar.exe C:\Users\HN\AppData\Local\Temp\nvwdmcpl.dll C:\Users\HN\AppData\Local\Temp\nvwimg.dll C:\Users\HN\AppData\Local\Temp\nvwimg64.dll C:\Users\HN\AppData\Local\Temp\NVWRSAR.dll C:\Users\HN\AppData\Local\Temp\NVWRSCS.dll C:\Users\HN\AppData\Local\Temp\NVWRSDA.dll C:\Users\HN\AppData\Local\Temp\NVWRSDE.dll C:\Users\HN\AppData\Local\Temp\NVWRSEL.dll C:\Users\HN\AppData\Local\Temp\NVWRSENG.dll C:\Users\HN\AppData\Local\Temp\NVWRSENU.dll C:\Users\HN\AppData\Local\Temp\NVWRSES.dll C:\Users\HN\AppData\Local\Temp\NVWRSESM.dll C:\Users\HN\AppData\Local\Temp\NVWRSFI.dll C:\Users\HN\AppData\Local\Temp\NVWRSFR.dll C:\Users\HN\AppData\Local\Temp\NVWRSHE.dll C:\Users\HN\AppData\Local\Temp\NVWRSHU.dll C:\Users\HN\AppData\Local\Temp\NVWRSIT.dll C:\Users\HN\AppData\Local\Temp\NVWRSJA.dll C:\Users\HN\AppData\Local\Temp\NVWRSKO.dll C:\Users\HN\AppData\Local\Temp\NVWRSNL.dll C:\Users\HN\AppData\Local\Temp\NVWRSNO.dll C:\Users\HN\AppData\Local\Temp\NVWRSPL.dll C:\Users\HN\AppData\Local\Temp\NVWRSPT.dll C:\Users\HN\AppData\Local\Temp\NVWRSPTB.dll C:\Users\HN\AppData\Local\Temp\NVWRSRU.dll C:\Users\HN\AppData\Local\Temp\NVWRSSK.dll C:\Users\HN\AppData\Local\Temp\NVWRSSL.dll C:\Users\HN\AppData\Local\Temp\NVWRSSV.dll C:\Users\HN\AppData\Local\Temp\NVWRSTH.dll C:\Users\HN\AppData\Local\Temp\NVWRSTR.dll C:\Users\HN\AppData\Local\Temp\NVWRSZHC.dll C:\Users\HN\AppData\Local\Temp\NVWRSZHT.dll C:\Users\HN\AppData\Local\Temp\nwiz.exe C:\Users\HN\AppData\Local\Temp\SystemDiagnostics.exe C:\Users\HN\AppData\Local\Temp\ti2jyjec.dll C:\Users\HN\AppData\Local\Temp\_isDA40.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-01 13:26 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-05-2015 02 Ran by HN at 2015-05-15 06:31:55 Running from C:\Users\HN\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2065948893-2615235351-692522125-500 - Administrator - Enabled) => C:\Users\Administrator Gast (S-1-5-21-2065948893-2615235351-692522125-501 - Limited - Disabled) HN (S-1-5-21-2065948893-2615235351-692522125-1000 - Administrator - Enabled) => C:\Users\HN HomeGroupUser$ (S-1-5-21-2065948893-2615235351-692522125-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 2007 Microsoft Office system (HKLM-x32\...\PROHYBRIDR) (Version: 12.0.6612.1000 - Microsoft Corporation) 3D-Viewer-innoplus (HKLM-x32\...\{B96DB037-DBEA-4186-9081-9CBD537F82E8}) (Version: 14.00.231 - INNOVA-engineering GmbH) Accelerometer (HKLM-x32\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 1.06.08.11 - STMicroelectronics) Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Reader 9.1.3 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A91000000001}) (Version: 9.1.3 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Aladdin Monitor 1.4.2 (HKLM-x32\...\Aladdin Monitor 1.4.2) (Version: - ) Antivirus Pro (HKLM-x32\...\Avira AntiVir Desktop) (Version: 15.0.8.656 - Avira) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.13.0 - Ask.com) <==== ATTENTION AuthenTec Fingerprint Software (HKLM\...\{6B99AF03-2668-4572-BD3D-8C7A5D103065}) (Version: 8.5.1.28 - AuthenTec, Inc.) Avery Wizard 4.0 (HKLM-x32\...\{F5D84887-8A6F-4993-8560-B3AA44CB620D}) (Version: 4.0.201 - Avery) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.9.504 - Avira Operations GmbH & Co. KG) Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.3.33021 - Ask.com) <==== ATTENTION BitTorrent (HKLM-x32\...\BitTorrent) (Version: - BitTorrent, Inc) Bluetooth Feature Pack 5.0 (HKLM\...\{B2F4C332-2359-4ADE-AF0C-C631768BBB89}) (Version: 5.0.9 - CSR Plc.) Bullzip PDF Printer 7.1.0.1140 (HKLM\...\Bullzip PDF Printer_is1) (Version: - Bullzip) cmTSS64 (HKLM\...\{E28D2D28-4A78-4A5D-B626-E63030DDFF3D}) (Version: 1.2 - charismathics) Garmin City Navigator Europe NT 2008 (HKLM-x32\...\{EEC8205A-E3DE-4C00-B60C-48E3B9B58B13}) (Version: 10.0.0.0 - Garmin Ltd or its subsidiaries) Garmin TOPO Deutschland v3 (HKLM-x32\...\{AE255C55-E0CF-4591-AA86-CAA19AA32C53}) (Version: 3.0.0.0 - Garmin Ltd or its subsidiaries) Garmin TOPO Österreich v2 (HKLM-x32\...\{7AA38575-25A1-4C2F-B40B-2188EB73FF0E}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{07A8ED9E-B98E-437F-B750-241B412BE924}) (Version: 1.0.0.0 - Garmin Ltd or its subsidiaries) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden GPL Ghostscript Lite 8.70 (HKLM-x32\...\GPL Ghostscript Lite_is1) (Version: - ) Harmony Browser Plug-in (HKLM-x32\...\{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}) (Version: 2.0 - Logitech) Hartlauer Foto World (HKLM-x32\...\Hartlauer Foto World) (Version: 5.0.3 - CEWE COLOR AG u Co. OHG) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Management Engine Interface (HKLM\...\HECI) (Version: - Intel Corporation) Intel® Active-Management-Technologie (HKLM\...\MESOL) (Version: - Intel Corporation) Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) LoiLoScope Herunterladen (HKLM-x32\...\{C2A254F4-AC74-482F-8F09-DB2843AC2AAE}_is1) (Version: 2.0 - LoiLo inc) LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.1.94 - LSI Corporation) MapSource (HKLM-x32\...\MapSource) (Version: - ) Medion GoPal Assistant 4.03.006 (HKLM-x32\...\Medion GoPal Assistant) (Version: 4.3.6.0 - Medion) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MobileSoftwareSuite (HKLM\...\{B28D8FCA-1983-496F-A8FF-295A7D26CC48}) (Version: 1.10.0032 - Fujitsu Technology Solutions) Mozilla Firefox 36.0.4 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 9 Essentials (HKLM-x32\...\{74946408-f3a1-42d6-aab7-477f9ea2ece1}) (Version: - Nero AG) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10 - NVIDIA Corporation) NVIDIA nView Desktop Manager (HKLM\...\NVIDIA nView Desktop Manager) (Version: 121.20 - NVIDIA Corporation) NVIDIA Performance Drivers (HKLM\...\{4C0A8D65-4286-4B58-87FE-18AD24289285}) (Version: 2.0.0.19 - NVIDIA Corporation) OZ776 SCR Driver V2.1.4.204A (HKLM-x32\...\InstallShield_{890C7D7F-D482-44B3-9E15-4C3A18853E71}) (Version: 2.1.4.204A - O2Micro) OZ776 SCR Driver V2.1.4.204A (Version: 2.1.4.204A - O2Micro) Hidden PHOTOfunSTUDIO 9.3 PE (HKLM-x32\...\{E33B3B6C-5712-4A39-B30D-1391918D920D}) (Version: 9.03.703 - Panasonic Corporation) Pro/ENGINEER Release Wildfire 4.0 Datecode C000 (HKLM-x32\...\Pro/ENGINEER Release Wildfire 4.0 Datecode C000) (Version: Wildfire 4.0 - PTC) PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5888 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.3.2.12064_10 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.3.2.12064_10 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.) ScBios64 (HKLM\...\{9DD58519-340D-467E-9988-1E55472A3FC1}) (Version: 2.0.0 - Fujitsu Siemens Computers) Skype web features (HKLM-x32\...\{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}) (Version: 1.0.3971 - Skype Technologies S.A.) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SmartCase Logon+ (HKLM\...\{3D093918-3EA6-43FE-ADD5-32DE22EE9B5E}) (Version: 3.0.1 - iC Compas GmbH Co KG) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.6.1 - Synaptics Incorporated) SystemDiagnostics (HKLM-x32\...\{EF59DB7F-7426-426E-B862-7031F83ED304}) (Version: 2.04.0006 - Fujitsu Technology Solutions) trustDesk basic (HKLM-x32\...\trustDesk basic) (Version: - ) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Wer wird Millionär (HKLM-x32\...\{766FF098-68AB-48BE-BF41-05708D178198}) (Version: 1.0.0.0000 - Eidos Interactive) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0) (HKLM\...\45A7283175C62FAC673F913C1F532C5361F97841) (Version: 03/08/2007 2.2.1.0 - Garmin) Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16422 - Microsoft Corporation) Windows-Treiberpaket - iC Compas GmbH & Co KG fcrimg4 LegacyDriver (06/15/2009 2.4.0.0) (HKLM\...\0365BFF3019A5A8F602931AC51B181DF57EC0773) (Version: 06/15/2009 2.4.0.0 - iC Compas GmbH & Co KG) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 14-02-2015 08:44:08 Windows Update 01-03-2015 11:04:35 Windows Update 05-03-2015 19:40:02 Windows Update 15-03-2015 17:27:50 Windows Update 21-03-2015 08:20:01 Windows Update 19-04-2015 08:46:22 Windows Update 19-04-2015 17:13:15 Wiederherstellungsvorgang 02-05-2015 10:50:49 Windows Update 15-05-2015 05:53:10 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {16C5782E-EA59-4BD1-BD05-97EA02E4FD0C} - System32\Tasks\{6C4D9D7E-58BF-4D7C-8361-3CDB3CA6D088} => C:\Program Files (x86)\Cadmould\CMDB\6.0\Cmdb.exe Task: {213DAA10-0EA0-49F8-859E-0945ACAB9122} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-12-20] () <==== ATTENTION Task: {31511DF8-7E6C-4E0E-BFCC-98510BD705E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.) Task: {34505848-CAB9-4D96-BC4B-2FB00FC57B4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-19] (Adobe Systems Incorporated) Task: {3C59B076-1876-4C87-8B57-2A385EAA4162} - System32\Tasks\Cadmould_001 => C:\Windows\Tasks\Cadmould_001.bat [2012-12-15] () Task: {3F004500-D37E-40E9-BBD8-35D9EACCA30F} - System32\Tasks\{830834F3-F4D1-4E65-8FAF-79CC7A580C13} => C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\uiStub.exe Task: {69A7A05C-BEA0-47F8-9CC5-F7CEDBB8F2DE} - System32\Tasks\{B0448F5C-10D8-49A9-B16D-09B5D41174FB} => C:\Program Files (x86)\Cadmould\CMDB\6.0\Cmdb.exe Task: {7E0CB445-0D07-4183-BF77-4F6DB6662E0C} - System32\Tasks\{AC8C9665-45BA-48B9-84CC-7B24B1BC8A1F} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {83F7E319-A9CF-45C8-9C02-56CE3B50B4F0} - System32\Tasks\Microsoft\Windows\SyncCenter\S-1-5-21-2065948893-2615235351-692522125-1000\{750FDF10-2A26-11D1-A3EA-080036587F03}\Offlinedateien-Synchronisierungszeitplan 1 => C:\Windows\system32\mobsync.exe [2010-11-20] (Microsoft Corporation) Task: {8F692F5B-944E-4A7D-B419-63A46426CA0D} - System32\Tasks\{847E9D9E-46E5-4E33-B98D-25FDEE169C43} => C:\Program Files (x86)\Cadmould\CMDB\6.0\Cmdb.exe Task: {903D2E66-8ADF-4657-AFEF-964F67B96D6E} - System32\Tasks\Cadmould_000 => C:\Windows\Tasks\Cadmould_000.bat [2010-10-17] () Task: {C504E839-F0D3-4358-90C2-D49C777508DF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.) Task: {E30BC9F2-C942-4572-B2D1-22CD26689F76} - System32\Tasks\{EB051E5A-BF54-4054-AC72-EA78C1FFCD38} => C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\uiStub.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Cadmould_000.job => C:\Windows\Tasks\Cadmould_000.bat Task: C:\Windows\Tasks\Cadmould_001.job => C:\Windows\Tasks\Cadmould_001.bat Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2009-07-20 00:55 - 2009-07-20 00:55 - 04908576 _____ () C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe 2009-07-01 15:40 - 2009-07-01 15:40 - 00324672 _____ () C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseServer.exe 2012-07-16 13:24 - 2012-08-31 02:52 - 00021432 _____ () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe 2012-12-20 22:56 - 2012-12-20 22:56 - 00136992 _____ () C:\Program Files (x86)\Ask.com\UpdateTask.exe 2010-03-20 13:36 - 2010-03-20 13:36 - 00377856 _____ () C:\Program Files (x86)\ITSolution\trustDesk basic\bin\LIBEAY32.dll 2010-03-20 13:36 - 2010-03-20 13:36 - 00067584 _____ () C:\Program Files (x86)\ITSolution\trustDesk basic\bin\SSLEAY32.dll 2013-10-05 15:20 - 2013-10-05 15:20 - 00115137 _____ () C:\Users\HN\AppData\Local\Temp\fbe2808e-2380-4f14-a1fa-3fa9c3a364e8\CliSecureRT.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 10.0.0.138 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{F38BE193-F6E4-4855-B69E-A376B0D1D3AA}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{6E816377-3C78-4802-A17F-75AFDE7401ED}] => (Allow) C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe FirewallRules: [{00998C44-572F-4388-8CAA-52E50E1E8200}] => (Allow) C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe FirewallRules: [{4D4D48E7-4078-48A5-9840-76D52C76A583}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{B9873E22-0FE2-4C11-844D-D033050E3230}] => (Allow) C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe FirewallRules: [{48FD9569-C3DE-40D7-995B-2E7DE81793F8}] => (Allow) C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe FirewallRules: [{BFBA6C8D-94DE-411E-8E7E-8EA24D7BAC5C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{A3B61C0E-6CA4-4A86-B88F-CD354E57630A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [{D5943204-0814-483D-BC15-FCA1B8CAAC2F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{11E7BB02-0057-42F1-82D5-6C519B464F6B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{0CE5EB35-ECED-4309-A2F2-B63A39AD1F95}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [UDP Query User{7A90503E-4E1D-44B8-BC8A-37C8B7F53F15}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [TCP Query User{2FE0F6D7-3C2C-4018-B2F1-D63FD46688D7}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [UDP Query User{9A806442-C435-46B6-AD84-4CD74018138A}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [TCP Query User{57D20444-D8EC-4B28-B5A2-36818CFBC1B4}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [UDP Query User{0558A4B9-C3D1-4559-A5CD-EDD157ECA19D}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [{6466E33C-8EB9-4E59-B531-5AAB45A5806F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{E7D05F7B-CB2F-48AA-9FE5-3EAA0B4FA740}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{3DF98FD8-DF48-412C-BCC6-032086E12A23}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [UDP Query User{F2028681-9631-4BB5-AC3F-2E53188BF14D}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [TCP Query User{C1DD0FBA-ED50-4406-96DB-33BC8C69B457}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [UDP Query User{802C905D-EB5F-4926-A341-F4526F56C1C0}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [{0D6653F6-A82D-486A-AA1A-679E26B90503}] => (Allow) C:\Windows\System32\hasplms.exe FirewallRules: [{FBF3F50C-9A47-48D3-8258-1C7A022F7671}] => (Allow) C:\Windows\System32\hasplms.exe FirewallRules: [TCP Query User{F2BDD739-53AE-4827-96A8-882BB69FCCF3}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Allow) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [UDP Query User{765547BE-A25C-4844-A842-12443891594D}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Allow) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [TCP Query User{1B18C282-FC3F-470A-B4AE-BB2C58B116E4}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{1BE4A3B1-B4CF-46F0-8350-3D04E976151C}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [{3080844A-F7B5-4273-BFB5-606982E3B4C0}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{31237843-4E7E-42A9-B872-A249D7BB4716}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{5C62222F-0CBC-4DE2-9C28-17A123440E72}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{3D92D94C-5187-45AF-8EB6-C3195AB8B76F}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{35CAC9C2-F830-4A18-89E3-83842F7E37F7}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{2C596396-260F-4624-AD0C-98A4BBC11583}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{24DDE36C-7199-43E0-A307-F938908C0B2F}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{501CDE86-9B34-4804-A2A5-7E779EB64F53}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{EB79520D-336E-4224-9087-6D0A18289533}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{43712A23-02A6-4EEE-A5FC-968A8BCEFFF0}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [TCP Query User{C0FD6051-A04C-4DF6-B5EC-DF95BA547621}C:\users\hn\appdata\local\temp\teamviewer\version9\teamviewer.exe] => (Block) C:\users\hn\appdata\local\temp\teamviewer\version9\teamviewer.exe FirewallRules: [UDP Query User{147B77E7-40D0-43BE-BD86-B90FD5C3163E}C:\users\hn\appdata\local\temp\teamviewer\version9\teamviewer.exe] => (Block) C:\users\hn\appdata\local\temp\teamviewer\version9\teamviewer.exe FirewallRules: [{D4181E90-F22D-4137-AAA4-1BD1D8B74B60}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{EA7ABFEC-6EC8-4F59-8AA5-DC8D69296885}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/03/2015 06:54:28 PM) (Source: Microsoft Office 12) (EventID: 2000) (User: ) Description: Accepted Safe Mode action : Microsoft Office Outlook. Error: (04/09/2015 08:34:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000004e4e4 ID des fehlerhaften Prozesses: 0x520 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Error: (04/04/2015 08:26:44 AM) (Source: Windows Search Service) (EventID: 3084) (User: ) Description: Fehler beim Laden des Protokollhandlers Csc. Fehlerbeschreibung: Es wurde versucht, einen Registrierungsschlüssel einem unzulässigen Vorgang zu unterziehen, der zum Löschen markiert wurde. (HRESULT : 0x800703fa). Error: (02/07/2015 11:09:42 AM) (Source: Microsoft Office 12) (EventID: 2001) (User: ) Description: Rejected Safe Mode action : Microsoft Office Outlook. Error: (02/07/2015 10:54:47 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm AcroRd32.exe, Version 9.1.0.163 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a30 Startzeit: 01d042b21dc6f70d Endzeit: 6272 Anwendungspfad: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe Berichts-ID: de4bd900-aea6-11e4-86b7-00225feed621 Error: (02/01/2015 05:33:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm xtop.exe, Version 27.0.2007.170 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 16ec Startzeit: 01d03e33687e7ad8 Endzeit: 203 Anwendungspfad: C:\Program Files (x86)\proeWildfire 4.0\i486_nt\obj\xtop.exe Berichts-ID: 92f5a8bb-aa27-11e4-86b7-00225feed621 Error: (12/06/2014 06:30:27 PM) (Source: Application Error) (EventID: 1005) (User: ) Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder der Datenträger fehlt. Das Programm rescue-system.exe wurde wegen dieses Fehlers geschlossen. Programm: rescue-system.exe Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet. Benutzeraktion 1. Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE. 4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt. Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche Daten Fehlerwert: C0000013 Datenträgertyp: 0 Error: (12/06/2014 06:30:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: rescue-system.exe, Version: 0.0.0.0, Zeitstempel: 0x4bdad87d Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000006 Fehleroffset: 0x0003eaed ID des fehlerhaften Prozesses: 0x714 Startzeit der fehlerhaften Anwendung: 0xrescue-system.exe0 Pfad der fehlerhaften Anwendung: rescue-system.exe1 Pfad des fehlerhaften Moduls: rescue-system.exe2 Berichtskennung: rescue-system.exe3 Error: (12/06/2014 06:20:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: wwanapi.dll, Version: 6.1.7600.16385, Zeitstempel: 0x4a5be0a8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000333eb ID des fehlerhaften Prozesses: 0xdb8 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/30/2014 03:20:07 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Hartlauer Foto World.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c10 Startzeit: 01d00c9ff55659a4 Endzeit: 15 Anwendungspfad: C:\Program Files (x86)\Hartlauer Foto World\Hartlauer Foto World\Hartlauer Foto World.exe Berichts-ID: 8dcf41d9-7893-11e4-b161-00225feed621 System errors: ============= Error: (05/15/2015 06:19:14 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0902 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB2990214) Error: (05/15/2015 05:46:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%1058 Error: (05/10/2015 06:28:52 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (05/10/2015 06:21:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Bluetooth Device (Personal Area Network)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1058 Error: (05/10/2015 06:21:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%1058 Error: (05/10/2015 06:21:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Bluetooth Device (RFCOMM Protocol TDI)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1058 Error: (05/03/2015 07:08:40 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (05/03/2015 07:06:51 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (05/03/2015 06:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Bluetooth Device (Personal Area Network)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1058 Error: (05/03/2015 06:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%1058 Microsoft Office Sessions: ========================= Error: (11/16/2014 07:13:03 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6707.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 101 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/19/2010 10:17:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 256 seconds with 120 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T9600 @ 2.80GHz Percentage of memory in use: 95% Total physical RAM: 2026.68 MB Available physical RAM: 98.01 MB Total Pagefile: 4053.37 MB Available Pagefile: 652.19 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:296.08 GB) (Free:175.47 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 27987793) Partition 1: (Active) - (Size=2 GB) - (Type=27) Partition 2: (Not Active) - (Size=296.1 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
15.05.2015, 18:59 | #4 |
/// the machine /// TB-Ausbilder | Laptop Fujitsu Celsius H265 wird immer langsamer Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.05.2015, 08:25 | #5 |
| Laptop Fujitsu Celsius H265 wird immer langsamer ... na das nenn´ ich mal eine schnelle Hilfe ... ... bin froh, die "Ask"-Toolbar & Co losgeworden zu sein ... ... Malware scheint keine gefunden worden zu sein ... ... aber man weiß ja nie, wer oder was einem da und dort "dazwischen funzt" ... Jedenfalls nochmals ein herzliches Dankeschön ... Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.09.1.1004 www.malwarebytes.org Database version: main: v2015.05.16.06 rootkit: v2015.05.16.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.17728 HN :: H265-W7P [administrator] 17.05.2015 08:35:15 mbar-log-2015-05-17 (08-35-15).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged. Objects scanned: 413170 Time elapsed: 27 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter 09:07:07.0036 0x0424 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04 09:07:49.0609 0x0424 ============================================================ 09:07:49.0609 0x0424 Current date / time: 2015/05/17 09:07:49.0609 09:07:49.0609 0x0424 SystemInfo: 09:07:49.0609 0x0424 09:07:49.0609 0x0424 OS Version: 6.1.7601 ServicePack: 1.0 09:07:49.0609 0x0424 Product type: Workstation 09:07:49.0609 0x0424 ComputerName: H265-W7P 09:07:49.0609 0x0424 UserName: HN 09:07:49.0609 0x0424 Windows directory: C:\Windows 09:07:49.0609 0x0424 System windows directory: C:\Windows 09:07:49.0609 0x0424 Running under WOW64 09:07:49.0609 0x0424 Processor architecture: Intel x64 09:07:49.0609 0x0424 Number of processors: 2 09:07:49.0609 0x0424 Page size: 0x1000 09:07:49.0609 0x0424 Boot type: Normal boot 09:07:49.0609 0x0424 ============================================================ 09:07:50.0202 0x0424 KLMD registered as C:\Windows\system32\drivers\84415862.sys 09:07:50.0997 0x0424 System UUID: {740A05EC-070E-0329-9A5E-E9D0227232CA} 09:07:51.0793 0x0424 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 09:07:51.0793 0x0424 ============================================================ 09:07:51.0793 0x0424 \Device\Harddisk0\DR0: 09:07:51.0793 0x0424 MBR partitions: 09:07:51.0793 0x0424 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x40466C, BlocksNum 0x25029000 09:07:51.0793 0x0424 ============================================================ 09:07:51.0824 0x0424 C: <-> \Device\Harddisk0\DR0\Partition1 09:07:51.0887 0x0424 ============================================================ 09:07:51.0887 0x0424 Initialize success 09:07:51.0887 0x0424 ============================================================ 09:08:56.0845 0x0610 ============================================================ 09:08:56.0845 0x0610 Scan started 09:08:56.0845 0x0610 Mode: Manual; 09:08:56.0845 0x0610 ============================================================ 09:08:56.0845 0x0610 KSN ping started 09:09:06.0704 0x0610 KSN ping finished: true 09:09:07.0983 0x0610 ================ Scan system memory ======================== 09:09:07.0983 0x0610 System memory - ok 09:09:07.0983 0x0610 ================ Scan services ============================= 09:09:08.0217 0x0610 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 09:09:08.0233 0x0610 1394ohci - ok 09:09:08.0311 0x0610 [ 9FC242BE6F3A20C80C663EA5D51BE9E8, 981BF3540AFF7A769C25A5E19D3904B7A0739F052EC625B52B179BAE919BF972 ] Acceler C:\Windows\system32\DRIVERS\Acceler.sys 09:09:08.0311 0x0610 Acceler - ok 09:09:08.0342 0x0610 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys 09:09:08.0373 0x0610 ACPI - ok 09:09:08.0389 0x0610 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 09:09:08.0389 0x0610 AcpiPmi - ok 09:09:08.0529 0x0610 [ B04A4810C6CC205F9DC72DC22E4AB236, 547321F5C28C80D4818372D65E2A33D4BAC593015DD6613B24586FE4B4A95D5D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 09:09:08.0545 0x0610 AdobeFlashPlayerUpdateSvc - ok 09:09:08.0607 0x0610 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 09:09:08.0623 0x0610 adp94xx - ok 09:09:08.0670 0x0610 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 09:09:08.0685 0x0610 adpahci - ok 09:09:08.0701 0x0610 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 09:09:08.0701 0x0610 adpu320 - ok 09:09:08.0732 0x0610 [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 09:09:08.0732 0x0610 AeLookupSvc - ok 09:09:08.0810 0x0610 [ FA886682CFC5D36718D3E436AACF10B9, F80AB4F91AA6B5C7ECCB000D8E1BC2CF776DC3D69B3D9EBC2558C19035A6B3AB ] AFD C:\Windows\system32\drivers\afd.sys 09:09:08.0826 0x0610 AFD - ok 09:09:08.0888 0x0610 [ B65F8DBA54F251906BBE8611B5A0E7AB, 9ADE347CB4E7C33D668DAC79A316C97C78D94D296B158F481F3E32F9DA4D647E ] AgereModemAudio C:\Program Files\LSI SoftModem\agr64svc.exe 09:09:08.0888 0x0610 AgereModemAudio - ok 09:09:08.0982 0x0610 [ AF4748EF93416159459769A24A0053AF, AE1C4E67E7555066436112C5A090DC5B49B264E3BA3ECF4CE2F1E9B799089B7D ] AgereSoftModem C:\Windows\system32\DRIVERS\agrsm64.sys 09:09:09.0013 0x0610 AgereSoftModem - ok 09:09:09.0060 0x0610 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys 09:09:09.0060 0x0610 agp440 - ok 09:09:09.0107 0x0610 [ 89CD44C10D9B4D87725FF07F18A5702F, 6FB4CA3E8D9D65ED341F97DD7CF792CFACC5EAD4296DFC4E22D770B2383DFB91 ] aksdf C:\Windows\system32\drivers\aksdf.sys 09:09:09.0107 0x0610 aksdf - ok 09:09:09.0138 0x0610 [ BA0B6FD78AE88D39B9D3D984F295A137, 87185242D18C9BE6A763E7849F0F2968B7313BB81A4E44FC4E021A36284D0D0C ] aksfridge C:\Windows\system32\drivers\aksfridge.sys 09:09:09.0138 0x0610 aksfridge - ok 09:09:09.0169 0x0610 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe 09:09:09.0169 0x0610 ALG - ok 09:09:09.0216 0x0610 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys 09:09:09.0216 0x0610 aliide - ok 09:09:09.0231 0x0610 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys 09:09:09.0247 0x0610 amdide - ok 09:09:09.0263 0x0610 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 09:09:09.0263 0x0610 AmdK8 - ok 09:09:09.0278 0x0610 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 09:09:09.0278 0x0610 AmdPPM - ok 09:09:09.0325 0x0610 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys 09:09:09.0325 0x0610 amdsata - ok 09:09:09.0356 0x0610 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 09:09:09.0356 0x0610 amdsbs - ok 09:09:09.0356 0x0610 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys 09:09:09.0356 0x0610 amdxata - ok 09:09:09.0497 0x0610 [ 62A6B0A393591878A1E00224EA698AD7, 691B6E248D0682477543455B67E85C768A4A53A92139E153320ED4E4CED1E010 ] AntiVirMailService C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe 09:09:09.0512 0x0610 AntiVirMailService - ok 09:09:09.0606 0x0610 [ F36D18EF1E66F92094AD89D17BEF007C, A5C793B340311CB7A301B77316E1976E3CD7CA9470CE5F1062CB003BCD4C155C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 09:09:09.0653 0x0610 AntiVirSchedulerService - ok 09:09:09.0731 0x0610 [ F36D18EF1E66F92094AD89D17BEF007C, A5C793B340311CB7A301B77316E1976E3CD7CA9470CE5F1062CB003BCD4C155C ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 09:09:09.0762 0x0610 AntiVirService - ok 09:09:09.0871 0x0610 [ 5B7924A162A604B43FFBEE9384ABE77B, 1A1A836C145BAD330EDC778D4FD18CE737EB10E4B22AE8A39CDDBAAC36B0FF11 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe 09:09:09.0902 0x0610 AntiVirWebService - ok 09:09:09.0949 0x0610 [ 90C53BD47979FB8814F465A08B885102, 5EDFC1909FC1FF9133A534DFCC5408CF3A777AC41FB21FAD375436E3D86C02EC ] AppID C:\Windows\system32\drivers\appid.sys 09:09:09.0949 0x0610 AppID - ok 09:09:09.0965 0x0610 [ 72D4757510FDA69D729169C00AFC211E, FB9686D0D94EE7C19A3994C29E8331A6EC3020B2980B2CC75F72F3AB25512C15 ] AppIDSvc C:\Windows\System32\appidsvc.dll 09:09:09.0980 0x0610 AppIDSvc - ok 09:09:10.0027 0x0610 [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll 09:09:10.0027 0x0610 Appinfo - ok 09:09:10.0074 0x0610 [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll 09:09:10.0089 0x0610 AppMgmt - ok 09:09:10.0121 0x0610 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\DRIVERS\arc.sys 09:09:10.0136 0x0610 arc - ok 09:09:10.0167 0x0610 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 09:09:10.0167 0x0610 arcsas - ok 09:09:10.0277 0x0610 [ 9A262EDD17F8473B91B333D6B031A901, 05DFBD3A7D83FDE1D062EA719ACA9EC48CB7FD42D17DDD88B82E5D25469ADD23 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 09:09:10.0308 0x0610 aspnet_state - ok 09:09:10.0339 0x0610 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 09:09:10.0339 0x0610 AsyncMac - ok 09:09:10.0370 0x0610 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys 09:09:10.0370 0x0610 atapi - ok 09:09:10.0573 0x0610 [ 48486BE059400FC04B361A6B60F0FE78, 8EDDC71F07932E4635232C48F37CF6F57B3026CA751EF5E8B7CD7D8D503A733E ] ATService C:\Program Files\Fingerprint Sensor\ATService.exe 09:09:10.0604 0x0610 ATService - ok 09:09:10.0651 0x0610 [ F97F384B0361C0DF4266F59F456D2D3E, 7440F521CA1F28AC54DDCA2557AB8AD98768C273F5C3827B2AFF89101153F3A2 ] ATSwpWDF C:\Windows\system32\Drivers\ATSwpWDF.sys 09:09:10.0667 0x0610 ATSwpWDF - ok 09:09:10.0729 0x0610 [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 09:09:10.0745 0x0610 AudioEndpointBuilder - ok 09:09:10.0776 0x0610 [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioSrv C:\Windows\System32\Audiosrv.dll 09:09:10.0776 0x0610 AudioSrv - ok 09:09:10.0823 0x0610 [ 00BF66D168E1A7AA7E1C9F458BBA0B34, 3D3C42E87B3649819EED685D93417D61EB84FE39B3F4D4943721AE74026DE11B ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 09:09:10.0823 0x0610 avgntflt - ok 09:09:10.0885 0x0610 [ 055D318220DD4593F2A8C8FF83707D36, 93566931D019D4D4C35C3E2E4E9BAF87BEF863E1B40B2B03ED87EF5C28F908DE ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 09:09:10.0901 0x0610 avipbb - ok 09:09:10.0901 0x0610 [ 390184FAD8FCC1B6DA25AEBAE928C3B6, 537B0E0FAE080B55D70E990BBA0F7F22903CA340F6A42039BAD617A8ECF59119 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 09:09:10.0901 0x0610 avkmgr - ok 09:09:10.0932 0x0610 [ 13253E5E3B6BDF945B63B336A8C9489B, 671C716E43F89D4BDDAA2BE045CDEBBB569C85BC2BA334E1F550187B79A7740D ] avnetflt C:\Windows\system32\DRIVERS\avnetflt.sys 09:09:10.0947 0x0610 avnetflt - ok 09:09:10.0979 0x0610 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll 09:09:10.0994 0x0610 AxInstSV - ok 09:09:11.0025 0x0610 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 09:09:11.0041 0x0610 b06bdrv - ok 09:09:11.0088 0x0610 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 09:09:11.0103 0x0610 b57nd60a - ok 09:09:11.0135 0x0610 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll 09:09:11.0135 0x0610 BDESVC - ok 09:09:11.0150 0x0610 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys 09:09:11.0150 0x0610 Beep - ok 09:09:11.0228 0x0610 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll 09:09:11.0259 0x0610 BFE - ok 09:09:11.0322 0x0610 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll 09:09:11.0337 0x0610 BITS - ok 09:09:11.0353 0x0610 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 09:09:11.0369 0x0610 blbdrive - ok 09:09:11.0384 0x0610 [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 09:09:11.0400 0x0610 bowser - ok 09:09:11.0415 0x0610 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 09:09:11.0415 0x0610 BrFiltLo - ok 09:09:11.0447 0x0610 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 09:09:11.0447 0x0610 BrFiltUp - ok 09:09:11.0478 0x0610 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll 09:09:11.0478 0x0610 Browser - ok 09:09:11.0509 0x0610 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys 09:09:11.0509 0x0610 Brserid - ok 09:09:11.0525 0x0610 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 09:09:11.0525 0x0610 BrSerWdm - ok 09:09:11.0540 0x0610 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 09:09:11.0556 0x0610 BrUsbMdm - ok 09:09:11.0556 0x0610 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 09:09:11.0556 0x0610 BrUsbSer - ok 09:09:11.0603 0x0610 [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 09:09:11.0603 0x0610 BthEnum - ok 09:09:11.0634 0x0610 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 09:09:11.0634 0x0610 BTHMODEM - ok 09:09:11.0665 0x0610 [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 09:09:11.0681 0x0610 BthPan - ok 09:09:11.0712 0x0610 [ 738D0E9272F59EB7A1449C3EC118E6C4, FE3D32C2A5E4DC21376A0F89C0B2EE024ECF1A3FB99213CC9BBC986ADF7AF080 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 09:09:11.0743 0x0610 BTHPORT - ok 09:09:11.0774 0x0610 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll 09:09:11.0774 0x0610 bthserv - ok 09:09:11.0790 0x0610 [ F188B7394D81010767B6DF3178519A37, 576304E92FD94908F093A6AB5F4D328F25829BE32EC3CA0D29EBFDF5DE83539B ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 09:09:11.0790 0x0610 BTHUSB - ok 09:09:11.0805 0x0610 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 09:09:11.0821 0x0610 cdfs - ok 09:09:11.0868 0x0610 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\drivers\cdrom.sys 09:09:11.0883 0x0610 cdrom - ok 09:09:11.0930 0x0610 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll 09:09:11.0930 0x0610 CertPropSvc - ok 09:09:11.0961 0x0610 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\DRIVERS\circlass.sys 09:09:11.0961 0x0610 circlass - ok 09:09:12.0024 0x0610 [ 404B7DF9CA4D1CB675045AF220FF3285, 91FFADE2ABE5C48849E63134D5FFD20671FE0D1720F7D486F904391B3D142C96 ] CLFS C:\Windows\system32\CLFS.sys 09:09:12.0039 0x0610 CLFS - ok 09:09:12.0117 0x0610 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 09:09:12.0117 0x0610 clr_optimization_v2.0.50727_32 - ok 09:09:12.0180 0x0610 [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 09:09:12.0180 0x0610 clr_optimization_v2.0.50727_64 - ok 09:09:12.0305 0x0610 [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 09:09:12.0305 0x0610 clr_optimization_v4.0.30319_32 - ok 09:09:12.0351 0x0610 [ 4AEDAB50F83580D0B4D6CF78191F92AA, D113C47013B018B45161911B96E93AF96A2F3B34FA47061BF6E7A71FBA03194A ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 09:09:12.0367 0x0610 clr_optimization_v4.0.30319_64 - ok 09:09:12.0414 0x0610 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 09:09:12.0414 0x0610 CmBatt - ok 09:09:12.0429 0x0610 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys 09:09:12.0429 0x0610 cmdide - ok 09:09:12.0461 0x0610 [ 2F150150E2AC0ACB2966243AFD167755, 0BB1B5144834BAA7D8F0D8FBD1FD32635927EE4F48B99BBDC87365D17E02F590 ] cmTCS64 Service C:\Windows\system32\cmTCS64.exe 09:09:12.0476 0x0610 cmTCS64 Service - ok 09:09:12.0523 0x0610 [ 27667A788130A7F7A5858DE27572E6D7, 5501D80BCCB7A811ECCED3828DFD0A5D948BBED8504E9BCC4A3BFB840DD41CBC ] CNG C:\Windows\system32\Drivers\cng.sys 09:09:12.0523 0x0610 CNG - ok 09:09:12.0554 0x0610 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 09:09:12.0554 0x0610 Compbatt - ok 09:09:12.0601 0x0610 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 09:09:12.0601 0x0610 CompositeBus - ok 09:09:12.0617 0x0610 COMSysApp - ok 09:09:12.0632 0x0610 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 09:09:12.0632 0x0610 crcdisk - ok 09:09:12.0695 0x0610 [ 1CD76A83B9E8E9A5A3519B39E28354D9, F9931743B99820FFBFB13136DFFD92F86802D543F9D8478648CDC554FB38899D ] CryptSvc C:\Windows\system32\cryptsvc.dll 09:09:12.0710 0x0610 CryptSvc - ok 09:09:12.0773 0x0610 [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys 09:09:12.0788 0x0610 CSC - ok 09:09:12.0882 0x0610 [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll 09:09:12.0897 0x0610 CscService - ok 09:09:12.0975 0x0610 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll 09:09:13.0007 0x0610 DcomLaunch - ok 09:09:13.0038 0x0610 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll 09:09:13.0038 0x0610 defragsvc - ok 09:09:13.0100 0x0610 [ 1BC12D085CAC5B3F0DE394AC571F0E78, 5ADF5FFB8D2E9F99888064F7D10E1814BB4033BF21F329341B37296B466E22FF ] DeskViewBasicService C:\Program Files (x86)\Fujitsu\DeskViewBasic\DeskViewBasicService.exe 09:09:13.0100 0x0610 DeskViewBasicService - ok 09:09:13.0147 0x0610 [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys 09:09:13.0147 0x0610 DfsC - ok 09:09:13.0194 0x0610 [ B9430166FEB246F6070A62B3554932C9, 677DE435AA5C1FBFC0171384D4B7CED2EA6B0F8567540DB9DE454AC6D4A7C1D7 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys 09:09:13.0194 0x0610 dg_ssudbus - ok 09:09:13.0287 0x0610 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll 09:09:13.0303 0x0610 Dhcp - ok 09:09:13.0319 0x0610 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys 09:09:13.0319 0x0610 discache - ok 09:09:13.0334 0x0610 [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\DRIVERS\disk.sys 09:09:13.0334 0x0610 Disk - ok 09:09:13.0365 0x0610 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll 09:09:13.0365 0x0610 Dnscache - ok 09:09:13.0412 0x0610 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll 09:09:13.0428 0x0610 dot3svc - ok 09:09:13.0459 0x0610 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll 09:09:13.0459 0x0610 DPS - ok 09:09:13.0506 0x0610 [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 09:09:13.0506 0x0610 drmkaud - ok 09:09:13.0599 0x0610 [ 87CE5C8965E101CCCED1F4675557E868, 077D98F0F130B2FC710208BA34016EF2B2506EE2BD71740B228145E34A3046F1 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 09:09:13.0615 0x0610 DXGKrnl - ok 09:09:13.0677 0x0610 [ 50AD8FC1DC800FF36087994C8F7FDFF2, E3DA8DCE76599E0E1F0D80AA1483D6BECFE0F7242147D986A6AF3A4362FC2C80 ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys 09:09:13.0693 0x0610 e1yexpress - ok 09:09:13.0724 0x0610 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll 09:09:13.0724 0x0610 EapHost - ok 09:09:13.0880 0x0610 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 09:09:13.0943 0x0610 ebdrv - ok 09:09:13.0974 0x0610 [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] EFS C:\Windows\System32\lsass.exe 09:09:13.0974 0x0610 EFS - ok 09:09:14.0067 0x0610 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 09:09:14.0099 0x0610 ehRecvr - ok 09:09:14.0130 0x0610 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe 09:09:14.0130 0x0610 ehSched - ok 09:09:14.0161 0x0610 [ 9A47AC3DFCF81D30922CDAAF1C2D579F, 8CE5EC7C515D99928E701186DDDF80DC0BE6B98CE6E41509D2002ADA638609A5 ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys 09:09:14.0161 0x0610 ElbyCDIO - ok 09:09:14.0208 0x0610 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 09:09:14.0239 0x0610 elxstor - ok 09:09:14.0270 0x0610 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys 09:09:14.0270 0x0610 ErrDev - ok 09:09:14.0333 0x0610 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll 09:09:14.0333 0x0610 EventSystem - ok 09:09:14.0364 0x0610 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys 09:09:14.0379 0x0610 exfat - ok 09:09:14.0395 0x0610 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys 09:09:14.0395 0x0610 fastfat - ok 09:09:14.0473 0x0610 [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe 09:09:14.0504 0x0610 Fax - ok 09:09:14.0551 0x0610 [ 48C6EEF1742E9F573F81CAEF65C14835, 736703BD3806B79B0621FBAFF4B02D1CFC792014EEBE59E4ABEDB3B28F79D6CB ] fcrimg4 C:\Windows\system32\DRIVERS\fcrimg4.sys 09:09:14.0551 0x0610 fcrimg4 - ok 09:09:14.0567 0x0610 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\DRIVERS\fdc.sys 09:09:14.0567 0x0610 fdc - ok 09:09:14.0598 0x0610 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll 09:09:14.0598 0x0610 fdPHost - ok 09:09:14.0598 0x0610 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll 09:09:14.0598 0x0610 FDResPub - ok 09:09:14.0613 0x0610 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 09:09:14.0613 0x0610 FileInfo - ok 09:09:14.0629 0x0610 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 09:09:14.0629 0x0610 Filetrace - ok 09:09:14.0660 0x0610 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 09:09:14.0660 0x0610 flpydisk - ok 09:09:14.0691 0x0610 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 09:09:14.0723 0x0610 FltMgr - ok 09:09:14.0816 0x0610 [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll 09:09:14.0832 0x0610 FontCache - ok 09:09:14.0894 0x0610 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 09:09:14.0894 0x0610 FontCache3.0.0.0 - ok 09:09:14.0941 0x0610 [ E820D9AE86732C9A51A841C534CA9B1C, D00CF8F0AB77437BD68C5535E0009F6E7595A91213FBCD25214C2BFB465FF9D1 ] FscBapi C:\Windows\system32\DRIVERS\FscBapi.sys 09:09:14.0941 0x0610 FscBapi - ok 09:09:14.0972 0x0610 [ E0B778A647A780446D19873236CD3262, A49D89351780CCCC7FD9F6FB1B1CDE28FDAB6B785C22AFEE00D32B8E2BD23E74 ] FscGabi C:\Windows\system32\DRIVERS\FscGabi.sys 09:09:14.0972 0x0610 FscGabi - ok 09:09:15.0019 0x0610 [ 5B819EB9FCE3536777ACCAE1853AD906, 2729F9D7C140B11217F379BEFE5D64CE27DF945F4FEBB68257B06247D3718D3E ] FSCSLII C:\Windows\system32\DRIVERS\FSCSLII.sys 09:09:15.0019 0x0610 FSCSLII - ok 09:09:15.0035 0x0610 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 09:09:15.0050 0x0610 FsDepends - ok 09:09:15.0081 0x0610 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 09:09:15.0081 0x0610 Fs_Rec - ok 09:09:15.0128 0x0610 [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 09:09:15.0144 0x0610 fvevol - ok 09:09:15.0159 0x0610 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 09:09:15.0175 0x0610 gagp30kx - ok 09:09:15.0222 0x0610 [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll 09:09:15.0253 0x0610 gpsvc - ok 09:09:15.0284 0x0610 [ 2ED7FF3E1ADA4092632393781518B3A7, FDB82CF74BE31806A6BFFC9724E54A74F822DFB4E137EEA38209418BDBCDAAB6 ] grmnusb C:\Windows\system32\drivers\grmnusb.sys 09:09:15.0284 0x0610 grmnusb - ok 09:09:15.0331 0x0610 [ 8B4AFA00547BDA4FD4CAE4693BD7B783, 1C9DC7BD66ECF0AF40D5ADC024DC238EA25DEF68DB829850B166D0A7070DAA61 ] guardian2 C:\Windows\system32\Drivers\oz776x64.sys 09:09:15.0331 0x0610 guardian2 - ok 09:09:15.0440 0x0610 [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 09:09:15.0440 0x0610 gupdate - ok 09:09:15.0487 0x0610 [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 09:09:15.0487 0x0610 gupdatem - ok 09:09:15.0596 0x0610 [ 11B9BD6065CF5C699CB5E276554E62B4, F0ABA0691959217CCA8BE9162C868B62E9B7DA16D68EA691F3587E182CEF876D ] HaMDevMg.1.01 C:\Program Files (x86)\Common Files\Fujitsu\Manageability\HaMDevMg.exe\1.01\HaMDevMg.exe 09:09:15.0612 0x0610 HaMDevMg.1.01 - ok 09:09:15.0659 0x0610 [ 78FAD9117E4527F2CA82259DA10F40BD, 9CE5102C681B8147BFC189897C19852D2BF82A9B95DE6301EBBCD13A604A41F3 ] hardlock C:\Windows\system32\drivers\hardlock.sys 09:09:15.0659 0x0610 hardlock - ok 09:09:15.0674 0x0610 hasplms - ok 09:09:15.0690 0x0610 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 09:09:15.0690 0x0610 hcw85cir - ok 09:09:15.0752 0x0610 [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 09:09:15.0783 0x0610 HdAudAddService - ok 09:09:15.0815 0x0610 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 09:09:15.0830 0x0610 HDAudBus - ok 09:09:15.0861 0x0610 [ 15C9789470B8855AC2F54FDF96802D13, 5375BBA13219456DA87023F206732BF76F934DC04C8E298C7C5E94944CC268D4 ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 09:09:15.0861 0x0610 HECIx64 - ok 09:09:15.0893 0x0610 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 09:09:15.0893 0x0610 HidBatt - ok 09:09:15.0908 0x0610 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 09:09:15.0908 0x0610 HidBth - ok 09:09:15.0939 0x0610 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 09:09:15.0939 0x0610 HidIr - ok 09:09:15.0955 0x0610 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll 09:09:15.0955 0x0610 hidserv - ok 09:09:16.0002 0x0610 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 09:09:16.0002 0x0610 HidUsb - ok 09:09:16.0033 0x0610 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll 09:09:16.0049 0x0610 hkmsvc - ok 09:09:16.0064 0x0610 HLServer - ok 09:09:16.0111 0x0610 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 09:09:16.0111 0x0610 HomeGroupListener - ok 09:09:16.0142 0x0610 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 09:09:16.0158 0x0610 HomeGroupProvider - ok 09:09:16.0189 0x0610 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 09:09:16.0205 0x0610 HpSAMD - ok 09:09:16.0267 0x0610 [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP C:\Windows\system32\drivers\HTTP.sys 09:09:16.0283 0x0610 HTTP - ok 09:09:16.0329 0x0610 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 09:09:16.0329 0x0610 hwpolicy - ok 09:09:16.0392 0x0610 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 09:09:16.0392 0x0610 i8042prt - ok 09:09:16.0454 0x0610 [ 1D004CB1DA6323B1F55CAEF7F94B61D9, 8FFFB429BA46938724BBB87AB9B3EC77EA17C4B893BABDBDD38309F02963D405 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 09:09:16.0454 0x0610 iaStor - ok 09:09:16.0485 0x0610 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 09:09:16.0501 0x0610 iaStorV - ok 09:09:16.0595 0x0610 [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 09:09:16.0610 0x0610 idsvc - ok 09:09:16.0657 0x0610 IEEtwCollectorService - ok 09:09:16.0907 0x0610 [ A87261EF1546325B559374F5689CF5BC, 8DE48A8A13A32AAAC54CDDF58F3F61BE3E2802C1D9CA1CA98E57EB0D65FB6002 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 09:09:17.0031 0x0610 igfx - ok 09:09:17.0078 0x0610 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 09:09:17.0078 0x0610 iirsp - ok 09:09:17.0156 0x0610 [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll 09:09:17.0187 0x0610 IKEEXT - ok 09:09:17.0343 0x0610 [ D8BCE8176CB1084C6F5830C019D47166, FF8CBD68FE796216C2BD6CC11D05F0BEFF84B636D86C0132C99672A1BE151B7F ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 09:09:17.0375 0x0610 IntcAzAudAddService - ok 09:09:17.0406 0x0610 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys 09:09:17.0421 0x0610 intelide - ok 09:09:17.0453 0x0610 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 09:09:17.0453 0x0610 intelppm - ok 09:09:17.0484 0x0610 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll 09:09:17.0499 0x0610 IPBusEnum - ok 09:09:17.0531 0x0610 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 09:09:17.0546 0x0610 IpFilterDriver - ok 09:09:17.0609 0x0610 [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 09:09:17.0624 0x0610 iphlpsvc - ok 09:09:17.0671 0x0610 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 09:09:17.0671 0x0610 IPMIDRV - ok 09:09:17.0702 0x0610 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys 09:09:17.0702 0x0610 IPNAT - ok 09:09:17.0733 0x0610 [ 05360B1EA5A2ABF620D1D96EBD8BD8F1, 226185C9ED1F6367BE4937734FF528D1EAAC1F0F85E4735EE66B244C15FC8EAF ] irda C:\Windows\system32\DRIVERS\irda.sys 09:09:17.0733 0x0610 irda - ok 09:09:17.0749 0x0610 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys 09:09:17.0749 0x0610 IRENUM - ok 09:09:17.0780 0x0610 [ 3848384AB383F0A8F506C4370635C1F9, A18BAAAD42CFC5B33D8108875D1FC1A424351B6901798E7B2A5EB82C4C0F89AC ] Irmon C:\Windows\System32\irmon.dll 09:09:17.0780 0x0610 Irmon - ok 09:09:17.0796 0x0610 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys 09:09:17.0796 0x0610 isapnp - ok 09:09:17.0843 0x0610 [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 09:09:17.0858 0x0610 iScsiPrt - ok 09:09:17.0921 0x0610 [ B3AC709C77937A3E686CB767CC096A6C, 63D6C13235B79621E1F86366881338C7059F2D245EDA53BAA8AEBA256AE9B78D ] ITEIRDA C:\Windows\system32\DRIVERS\ITEirda.sys 09:09:17.0921 0x0610 ITEIRDA - ok 09:09:17.0952 0x0610 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 09:09:17.0952 0x0610 kbdclass - ok 09:09:17.0999 0x0610 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 09:09:17.0999 0x0610 kbdhid - ok 09:09:18.0014 0x0610 [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] KeyIso C:\Windows\system32\lsass.exe 09:09:18.0030 0x0610 KeyIso - ok 09:09:18.0061 0x0610 [ 063C09DB965E3DFD6F4F08416F6DB8F5, 0BE015C59288397536B3941BA55EFE0CF06714BC43FF3A33A1D844B4E0F16097 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 09:09:18.0077 0x0610 KSecDD - ok 09:09:18.0092 0x0610 [ 1FA627E63195BF3BF636BFEF0D7190D4, 794456605303F4916E81BE899E0B05CB070094E719ADA8BE8072A761E35CA8E9 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 09:09:18.0108 0x0610 KSecPkg - ok 09:09:18.0123 0x0610 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 09:09:18.0123 0x0610 ksthunk - ok 09:09:18.0170 0x0610 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll 09:09:18.0186 0x0610 KtmRm - ok 09:09:18.0264 0x0610 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll 09:09:18.0279 0x0610 LanmanServer - ok 09:09:18.0311 0x0610 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 09:09:18.0311 0x0610 LanmanWorkstation - ok 09:09:18.0357 0x0610 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 09:09:18.0357 0x0610 lltdio - ok 09:09:18.0389 0x0610 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll 09:09:18.0389 0x0610 lltdsvc - ok 09:09:18.0404 0x0610 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll 09:09:18.0404 0x0610 lmhosts - ok 09:09:18.0451 0x0610 [ 44CBF7F9E2FB9C36ACC892812F8750A0, B97D477494072D456D45046E66F341757A40B92390836D9C4AE24EB5D088D63A ] LMS C:\Program Files (x86)\Intel\AMT\LMS.exe 09:09:18.0467 0x0610 LMS - ok 09:09:18.0545 0x0610 [ A939B91C1DD17AB5B86182D3A052B0AC, 8BEF2F4C49DAB699D3FFBA81B6B41A26472916C52ED53009067BAD28E9D608DC ] LogonUserService C:\Program Files\SmartCase Logon+\System\logonuser.exe 09:09:18.0560 0x0610 LogonUserService - ok 09:09:18.0607 0x0610 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 09:09:18.0607 0x0610 LSI_FC - ok 09:09:18.0654 0x0610 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 09:09:18.0654 0x0610 LSI_SAS - ok 09:09:18.0685 0x0610 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 09:09:18.0685 0x0610 LSI_SAS2 - ok 09:09:18.0701 0x0610 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 09:09:18.0701 0x0610 LSI_SCSI - ok 09:09:18.0732 0x0610 [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys 09:09:18.0732 0x0610 luafv - ok 09:09:18.0763 0x0610 [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 09:09:18.0779 0x0610 Mcx2Svc - ok 09:09:18.0810 0x0610 [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 09:09:18.0810 0x0610 megasas - ok 09:09:18.0825 0x0610 [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 09:09:18.0841 0x0610 MegaSR - ok 09:09:18.0857 0x0610 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll 09:09:18.0872 0x0610 MMCSS - ok 09:09:18.0888 0x0610 [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys 09:09:18.0888 0x0610 Modem - ok 09:09:18.0935 0x0610 [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 09:09:18.0935 0x0610 monitor - ok 09:09:18.0981 0x0610 [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\drivers\mouclass.sys 09:09:18.0981 0x0610 mouclass - ok 09:09:19.0013 0x0610 [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 09:09:19.0028 0x0610 mouhid - ok 09:09:19.0059 0x0610 [ 87BCD1034CBF33537D4D4C251D39BA26, CB9DD235B62B79383F99873D75E26EEA5EE7914CA89E4B75992207F83420437F ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 09:09:19.0075 0x0610 mountmgr - ok 09:09:19.0184 0x0610 [ 0A68B3E37961CEC327EED518F6D62530, EDEB16545ECDDEA2ADFF73E4DF3E9FD87E4B7126C8CFB037ABAF883D157103DE ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 09:09:19.0184 0x0610 MozillaMaintenance - ok 09:09:19.0231 0x0610 [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys 09:09:19.0231 0x0610 mpio - ok 09:09:19.0262 0x0610 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 09:09:19.0262 0x0610 mpsdrv - ok 09:09:19.0418 0x0610 [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll 09:09:19.0449 0x0610 MpsSvc - ok 09:09:19.0481 0x0610 [ AE3334958D8F631FF14A0AEB3D7EFB3A, F5FD6B61F896104C20DFC43FEE2FCE6930B73F78DF876BD19A333EABB9139C6D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 09:09:19.0496 0x0610 MRxDAV - ok 09:09:19.0527 0x0610 [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 09:09:19.0543 0x0610 mrxsmb - ok 09:09:19.0574 0x0610 [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 09:09:19.0590 0x0610 mrxsmb10 - ok 09:09:19.0605 0x0610 [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 09:09:19.0605 0x0610 mrxsmb20 - ok 09:09:19.0637 0x0610 [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys 09:09:19.0637 0x0610 msahci - ok 09:09:19.0668 0x0610 [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys 09:09:19.0668 0x0610 msdsm - ok 09:09:19.0683 0x0610 [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe 09:09:19.0699 0x0610 MSDTC - ok 09:09:19.0715 0x0610 [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys 09:09:19.0715 0x0610 Msfs - ok 09:09:19.0730 0x0610 [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 09:09:19.0730 0x0610 mshidkmdf - ok 09:09:19.0746 0x0610 [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 09:09:19.0746 0x0610 msisadrv - ok 09:09:19.0777 0x0610 [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 09:09:19.0777 0x0610 MSiSCSI - ok 09:09:19.0793 0x0610 msiserver - ok 09:09:19.0808 0x0610 [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 09:09:19.0808 0x0610 MSKSSRV - ok 09:09:19.0808 0x0610 [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 09:09:19.0808 0x0610 MSPCLOCK - ok 09:09:19.0824 0x0610 [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 09:09:19.0824 0x0610 MSPQM - ok 09:09:19.0917 0x0610 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 09:09:19.0933 0x0610 MsRPC - ok 09:09:19.0949 0x0610 [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 09:09:19.0949 0x0610 mssmbios - ok 09:09:19.0949 0x0610 [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 09:09:19.0949 0x0610 MSTEE - ok 09:09:19.0964 0x0610 [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 09:09:19.0964 0x0610 MTConfig - ok 09:09:19.0980 0x0610 [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys 09:09:19.0980 0x0610 Mup - ok 09:09:20.0042 0x0610 [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll 09:09:20.0058 0x0610 napagent - ok 09:09:20.0105 0x0610 [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 09:09:20.0105 0x0610 NativeWifiP - ok 09:09:20.0198 0x0610 [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS C:\Windows\system32\drivers\ndis.sys 09:09:20.0229 0x0610 NDIS - ok 09:09:20.0229 0x0610 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 09:09:20.0245 0x0610 NdisCap - ok 09:09:20.0261 0x0610 [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 09:09:20.0261 0x0610 NdisTapi - ok 09:09:20.0292 0x0610 [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 09:09:20.0292 0x0610 Ndisuio - ok 09:09:20.0339 0x0610 [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 09:09:20.0339 0x0610 NdisWan - ok 09:09:20.0370 0x0610 [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 09:09:20.0385 0x0610 NDProxy - ok 09:09:20.0526 0x0610 [ B90E093E7A7250906F1054418B5339C0, F9A0BAC5B4B29F14B5CACA1047F8928A495EFD56E485492BF71C856B296476D6 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe 09:09:20.0541 0x0610 Nero BackItUp Scheduler 4.0 - ok 09:09:20.0573 0x0610 [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 09:09:20.0573 0x0610 NetBIOS - ok 09:09:20.0635 0x0610 [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 09:09:20.0651 0x0610 NetBT - ok 09:09:20.0682 0x0610 [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] Netlogon C:\Windows\system32\lsass.exe 09:09:20.0682 0x0610 Netlogon - ok 09:09:20.0729 0x0610 [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll 09:09:20.0729 0x0610 Netman - ok 09:09:20.0791 0x0610 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 09:09:20.0807 0x0610 NetMsmqActivator - ok 09:09:20.0822 0x0610 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 09:09:20.0822 0x0610 NetPipeActivator - ok 09:09:20.0869 0x0610 [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll 09:09:20.0885 0x0610 netprofm - ok 09:09:20.0900 0x0610 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 09:09:20.0900 0x0610 NetTcpActivator - ok 09:09:20.0900 0x0610 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 09:09:20.0900 0x0610 NetTcpPortSharing - ok 09:09:21.0134 0x0610 [ 705283C02177809CA9FA7CC58A4F1E77, EA723588AA706F3D1E6007B300119AF6A99D1E4FB6B454751F48519191DE26E5 ] NETw5v64 C:\Windows\system32\DRIVERS\NETw5v64.sys 09:09:21.0259 0x0610 NETw5v64 - ok 09:09:21.0306 0x0610 [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 09:09:21.0306 0x0610 nfrd960 - ok 09:09:21.0337 0x0610 [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc C:\Windows\System32\nlasvc.dll 09:09:21.0353 0x0610 NlaSvc - ok 09:09:21.0368 0x0610 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys 09:09:21.0368 0x0610 Npfs - ok 09:09:21.0384 0x0610 [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll 09:09:21.0384 0x0610 nsi - ok 09:09:21.0399 0x0610 [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 09:09:21.0399 0x0610 nsiproxy - ok 09:09:21.0509 0x0610 [ 1A29A59A4C5BA6F8C85062A613B7E2B2, CC137F499A12C724D4166C2D85E9F447413419A0683DAC6F1A802B7F210C77F1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 09:09:21.0540 0x0610 Ntfs - ok 09:09:21.0555 0x0610 [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys 09:09:21.0555 0x0610 Null - ok 09:09:21.0805 0x0610 [ 2E16ABA89D5C1CF925541CBBD0F2A5BC, D41BF22A07EF1986C41FEB90B5E9DC876C5D377DC4937DDEDBC0435EE312F4B8 ] NVIDIA Performance Driver Service C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe 09:09:21.0883 0x0610 NVIDIA Performance Driver Service - ok 09:09:22.0304 0x0610 [ ED5211F6788C0522AE8BAAA4EB5C72E1, 37397F78F1248CED93FD1C5E288CBCCB69BF624BE611223CA0FBD273FE90D721 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 09:09:22.0679 0x0610 nvlddmkm - ok 09:09:22.0725 0x0610 [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys 09:09:22.0725 0x0610 nvraid - ok 09:09:22.0757 0x0610 [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys 09:09:22.0772 0x0610 nvstor - ok 09:09:22.0819 0x0610 [ D31BB3EAD138641B4E9303A56A22894E, 0848E67163D77FF4C1002ACE2EBE52895BE2CC423BD1E7D86053A5363D6C1BE7 ] nvsvc C:\Windows\system32\nvvsvc.exe 09:09:22.0835 0x0610 nvsvc - ok 09:09:22.0866 0x0610 [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 09:09:22.0866 0x0610 nv_agp - ok 09:09:22.0944 0x0610 [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 09:09:22.0959 0x0610 odserv - ok 09:09:22.0991 0x0610 [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 09:09:22.0991 0x0610 ohci1394 - ok 09:09:23.0053 0x0610 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 09:09:23.0053 0x0610 ose - ok 09:09:23.0115 0x0610 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 09:09:23.0115 0x0610 p2pimsvc - ok 09:09:23.0162 0x0610 [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll 09:09:23.0178 0x0610 p2psvc - ok 09:09:23.0194 0x0610 [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\DRIVERS\parport.sys 09:09:23.0209 0x0610 Parport - ok 09:09:23.0225 0x0610 [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys 09:09:23.0225 0x0610 partmgr - ok 09:09:23.0256 0x0610 [ DB2D62AA2DF6B1F3D690A9EC9701AA2C, BEAC55E1AA0494565F1547DF5E6FE20FCEA66461764C016FCB68D8BFF0F0C375 ] PcaSvc C:\Windows\System32\pcasvc.dll 09:09:23.0256 0x0610 PcaSvc - ok 09:09:23.0287 0x0610 [ BC0018C2D29F655188A0ED3FA94FDB24, BCF7F2CA5E30F569AEB69049BA3C196982C72EA7264CFBA59D7123041BA96E5A ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys 09:09:23.0287 0x0610 pccsmcfd - ok 09:09:23.0303 0x0610 [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys 09:09:23.0318 0x0610 pci - ok 09:09:23.0350 0x0610 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys 09:09:23.0350 0x0610 pciide - ok 09:09:23.0396 0x0610 [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 09:09:23.0396 0x0610 pcmcia - ok 09:09:23.0412 0x0610 [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys 09:09:23.0412 0x0610 pcw - ok 09:09:23.0474 0x0610 [ ED6E75158D28D33A2E2A020AC5B2B59D, 0F364D9A88304C45F31318605C417A70A9D0E4CF087D73E949B42C12CC76CD6C ] PEAUTH C:\Windows\system32\drivers\peauth.sys 09:09:23.0506 0x0610 PEAUTH - ok 09:09:23.0615 0x0610 [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 09:09:23.0662 0x0610 PeerDistSvc - ok 09:09:23.0771 0x0610 [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe 09:09:23.0771 0x0610 PerfHost - ok 09:09:23.0880 0x0610 [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll 09:09:23.0911 0x0610 pla - ok 09:09:23.0958 0x0610 [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 09:09:23.0974 0x0610 PlugPlay - ok 09:09:23.0989 0x0610 [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 09:09:23.0989 0x0610 PNRPAutoReg - ok 09:09:24.0005 0x0610 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 09:09:24.0020 0x0610 PNRPsvc - ok 09:09:24.0052 0x0610 [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 09:09:24.0067 0x0610 PolicyAgent - ok 09:09:24.0083 0x0610 [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll 09:09:24.0098 0x0610 Power - ok 09:09:24.0130 0x0610 [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 09:09:24.0130 0x0610 PptpMiniport - ok 09:09:24.0145 0x0610 [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\DRIVERS\processr.sys 09:09:24.0161 0x0610 Processor - ok 09:09:24.0192 0x0610 [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc C:\Windows\system32\profsvc.dll 09:09:24.0192 0x0610 ProfSvc - ok 09:09:24.0208 0x0610 [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] ProtectedStorage C:\Windows\system32\lsass.exe 09:09:24.0208 0x0610 ProtectedStorage - ok 09:09:24.0254 0x0610 [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 09:09:24.0270 0x0610 Psched - ok 09:09:24.0317 0x0610 [ F2EECF8977BD3FE4E38743DDCFBECD20, 37AC3692C9159289C0675886930AA1999AE55196192F4EB22634D8DB46E4D9CC ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 09:09:24.0317 0x0610 PxHlpa64 - ok 09:09:24.0426 0x0610 [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 09:09:24.0473 0x0610 ql2300 - ok 09:09:24.0504 0x0610 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 09:09:24.0504 0x0610 ql40xx - ok 09:09:24.0551 0x0610 [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll 09:09:24.0566 0x0610 QWAVE - ok 09:09:24.0582 0x0610 [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 09:09:24.0582 0x0610 QWAVEdrv - ok 09:09:24.0660 0x0610 [ A55E7D0D873B2C97585B3B5926AC6ADE, 3BE3895DA7F0888E85B1941525878BA0846A8F215AD39ED8138BB39615468E32 ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll 09:09:24.0676 0x0610 RapiMgr - ok 09:09:24.0691 0x0610 [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 09:09:24.0691 0x0610 RasAcd - ok 09:09:24.0707 0x0610 [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 09:09:24.0707 0x0610 RasAgileVpn - ok 09:09:24.0722 0x0610 [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll 09:09:24.0722 0x0610 RasAuto - ok 09:09:24.0754 0x0610 [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 09:09:24.0769 0x0610 Rasl2tp - ok 09:09:24.0800 0x0610 [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll 09:09:24.0816 0x0610 RasMan - ok 09:09:24.0816 0x0610 [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 09:09:24.0832 0x0610 RasPppoe - ok 09:09:24.0832 0x0610 [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 09:09:24.0832 0x0610 RasSstp - ok 09:09:24.0894 0x0610 [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 09:09:24.0910 0x0610 rdbss - ok 09:09:24.0925 0x0610 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 09:09:24.0925 0x0610 rdpbus - ok 09:09:24.0941 0x0610 [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 09:09:24.0941 0x0610 RDPCDD - ok 09:09:24.0972 0x0610 [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 09:09:24.0972 0x0610 RDPDR - ok 09:09:25.0003 0x0610 [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 09:09:25.0003 0x0610 RDPENCDD - ok 09:09:25.0019 0x0610 [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 09:09:25.0019 0x0610 RDPREFMP - ok 09:09:25.0112 0x0610 [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 09:09:25.0112 0x0610 RdpVideoMiniport - ok 09:09:25.0175 0x0610 [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 09:09:25.0175 0x0610 RDPWD - ok 09:09:25.0253 0x0610 [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 09:09:25.0268 0x0610 rdyboost - ok 09:09:25.0284 0x0610 [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll 09:09:25.0300 0x0610 RemoteAccess - ok 09:09:25.0315 0x0610 [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll 09:09:25.0315 0x0610 RemoteRegistry - ok 09:09:25.0362 0x0610 [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 09:09:25.0362 0x0610 RFCOMM - ok 09:09:25.0393 0x0610 [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 09:09:25.0393 0x0610 RpcEptMapper - ok 09:09:25.0393 0x0610 [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe 09:09:25.0393 0x0610 RpcLocator - ok 09:09:25.0456 0x0610 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\Windows\system32\rpcss.dll 09:09:25.0456 0x0610 RpcSs - ok 09:09:25.0502 0x0610 [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 09:09:25.0502 0x0610 rspndr - ok 09:09:25.0549 0x0610 [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys 09:09:25.0549 0x0610 s3cap - ok 09:09:25.0565 0x0610 [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] SamSs C:\Windows\system32\lsass.exe 09:09:25.0565 0x0610 SamSs - ok 09:09:25.0596 0x0610 [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 09:09:25.0596 0x0610 sbp2port - ok 09:09:25.0627 0x0610 [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll 09:09:25.0627 0x0610 SCardSvr - ok 09:09:25.0658 0x0610 [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 09:09:25.0658 0x0610 scfilter - ok 09:09:25.0783 0x0610 [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\Windows\system32\schedsvc.dll 09:09:25.0814 0x0610 Schedule - ok 09:09:25.0846 0x0610 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll 09:09:25.0846 0x0610 SCPolicySvc - ok 09:09:25.0877 0x0610 [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll 09:09:25.0877 0x0610 SDRSVC - ok 09:09:25.0908 0x0610 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys 09:09:25.0908 0x0610 secdrv - ok 09:09:25.0924 0x0610 [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\Windows\system32\seclogon.dll 09:09:25.0924 0x0610 seclogon - ok 09:09:25.0955 0x0610 [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\System32\sens.dll 09:09:25.0955 0x0610 SENS - ok 09:09:25.0955 0x0610 [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll 09:09:25.0955 0x0610 SensrSvc - ok 09:09:25.0970 0x0610 [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 09:09:25.0970 0x0610 Serenum - ok 09:09:26.0002 0x0610 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\DRIVERS\serial.sys 09:09:26.0002 0x0610 Serial - ok 09:09:26.0033 0x0610 [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 09:09:26.0033 0x0610 sermouse - ok 09:09:26.0095 0x0610 [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll 09:09:26.0111 0x0610 SessionEnv - ok 09:09:26.0142 0x0610 [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 09:09:26.0142 0x0610 sffdisk - ok 09:09:26.0158 0x0610 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 09:09:26.0158 0x0610 sffp_mmc - ok 09:09:26.0173 0x0610 [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 09:09:26.0173 0x0610 sffp_sd - ok 09:09:26.0204 0x0610 [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 09:09:26.0204 0x0610 sfloppy - ok 09:09:26.0251 0x0610 [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll 09:09:26.0267 0x0610 SharedAccess - ok 09:09:26.0298 0x0610 [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 09:09:26.0314 0x0610 ShellHWDetection - ok 09:09:26.0360 0x0610 [ 904828D8FB78C353F8EF4E74C75E4534, 05BBD04D3A83F3B5198BDF101E5EB12D1041DEDCA9F4943F318CC7C736E70F01 ] Si3531 C:\Windows\system32\DRIVERS\Si3531.sys 09:09:26.0376 0x0610 Si3531 - ok 09:09:26.0392 0x0610 [ 2A6661A832482B99B529A73CC2C47A10, 4F2EF6120A305B49D771F50C0D95207D461EEF65E16071D19AB747A0701AFB16 ] SiFilter C:\Windows\system32\DRIVERS\SiWinAcc.sys 09:09:26.0392 0x0610 SiFilter - ok 09:09:26.0407 0x0610 [ 803AD7BBFB7F13E82AA4B874F7F8B249, BF792FFED018474E83C4EDE45775F7BD92998C8B62E9BC71A40A3A840BF13CF3 ] SiRemFil C:\Windows\system32\DRIVERS\SiRemFil.sys 09:09:26.0407 0x0610 SiRemFil - ok 09:09:26.0438 0x0610 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 09:09:26.0438 0x0610 SiSRaid2 - ok 09:09:26.0454 0x0610 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 09:09:26.0454 0x0610 SiSRaid4 - ok 09:09:26.0516 0x0610 [ F6EF225A23D336CA30001E5007644C24, B0A4B1256C1074F1B4F73E3BBA16FD4683D6EEA583DEEF8E11EFD29BA7541F2A ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 09:09:26.0532 0x0610 SkypeUpdate - ok 09:09:26.0610 0x0610 [ 346ADA7FCC14981CA529553AD1D3894B, C2F971F71748543556AFDEFE3CE4F81B7519E6CD2E93F8B5F0F3F61A83494C6F ] SmartCaseServer C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseServer.exe 09:09:26.0626 0x0610 SmartCaseServer - ok 09:09:26.0657 0x0610 [ 76377EB397B0BACCC7BE651A64BB440F, 42303D9424132CD9B89B29113D7F1646CEDC1CEC9D08A3DE5361027B3FCD49FC ] SmartyLogService C:\Program Files\SmartCase Logon+\System\SmartyLog.exe 09:09:26.0672 0x0610 SmartyLogService - ok 09:09:26.0735 0x0610 [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys 09:09:26.0735 0x0610 Smb - ok 09:09:26.0782 0x0610 [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 09:09:26.0782 0x0610 SNMPTRAP - ok 09:09:26.0782 0x0610 [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys 09:09:26.0782 0x0610 spldr - ok 09:09:26.0828 0x0610 [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler C:\Windows\System32\spoolsv.exe 09:09:26.0860 0x0610 Spooler - ok 09:09:27.0031 0x0610 [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe 09:09:27.0109 0x0610 sppsvc - ok 09:09:27.0125 0x0610 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll 09:09:27.0125 0x0610 sppuinotify - ok 09:09:27.0156 0x0610 [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\Windows\system32\DRIVERS\srv.sys 09:09:27.0172 0x0610 srv - ok 09:09:27.0203 0x0610 [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 09:09:27.0203 0x0610 srv2 - ok 09:09:27.0218 0x0610 [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 09:09:27.0218 0x0610 srvnet - ok 09:09:27.0234 0x0610 [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 09:09:27.0250 0x0610 SSDPSRV - ok 09:09:27.0265 0x0610 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll 09:09:27.0265 0x0610 SstpSvc - ok 09:09:27.0296 0x0610 [ C692C94FE55CAD0633440236022C27B3, 9A21E9B2EB96DC8C58DE060EEAFC2FD71AB9C539039DAAD5F7380556E2D1D69B ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys 09:09:27.0312 0x0610 ssudmdm - ok 09:09:27.0359 0x0610 [ A89312BF48D6B8C313680F5F4AA25D95, ECC10F16C53D937F90AA8A90CB86950561C5A9C616519B1FCAE2B847123B5F6B ] stdflt C:\Windows\system32\DRIVERS\stdflt.sys 09:09:27.0359 0x0610 stdflt - ok 09:09:27.0374 0x0610 [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 09:09:27.0374 0x0610 stexstor - ok 09:09:27.0437 0x0610 [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll 09:09:27.0452 0x0610 stisvc - ok 09:09:27.0484 0x0610 [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys 09:09:27.0484 0x0610 storflt - ok 09:09:27.0499 0x0610 [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc C:\Windows\system32\storsvc.dll 09:09:27.0515 0x0610 StorSvc - ok 09:09:27.0530 0x0610 [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys 09:09:27.0530 0x0610 storvsc - ok 09:09:27.0530 0x0610 [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\drivers\swenum.sys 09:09:27.0530 0x0610 swenum - ok 09:09:27.0562 0x0610 [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll 09:09:27.0577 0x0610 swprv - ok 09:09:27.0624 0x0610 [ BE7311DA9D6833FA69ED04B744A1C8F8, 19DD5E5DCB7F6B1584B5EEDDA8F7D05D1AB97E40E1B7C1AA29AA79B44EBCA964 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 09:09:27.0640 0x0610 SynTP - ok 09:09:27.0749 0x0610 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\Windows\system32\sysmain.dll 09:09:27.0796 0x0610 SysMain - ok 09:09:27.0827 0x0610 [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll 09:09:27.0827 0x0610 TabletInputService - ok 09:09:27.0889 0x0610 [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll 09:09:27.0905 0x0610 TapiSrv - ok 09:09:27.0920 0x0610 [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\Windows\System32\tbssvc.dll 09:09:27.0936 0x0610 TBS - ok 09:09:28.0045 0x0610 [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 09:09:28.0092 0x0610 Tcpip - ok 09:09:28.0139 0x0610 [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 09:09:28.0170 0x0610 TCPIP6 - ok 09:09:28.0217 0x0610 [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 09:09:28.0217 0x0610 tcpipreg - ok 09:09:28.0248 0x0610 [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 09:09:28.0248 0x0610 TDPIPE - ok 09:09:28.0264 0x0610 [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 09:09:28.0264 0x0610 TDTCP - ok 09:09:28.0310 0x0610 [ 70988118145F5F10EF24720B97F35F65, F80C806417A68047FFB3D63214BC4AE5445315219AC594E043293006B704A63D ] tdx C:\Windows\system32\DRIVERS\tdx.sys 09:09:28.0310 0x0610 tdx - ok 09:09:28.0357 0x0610 [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\drivers\termdd.sys 09:09:28.0373 0x0610 TermDD - ok 09:09:28.0451 0x0610 [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService C:\Windows\System32\termsrv.dll 09:09:28.0466 0x0610 TermService - ok 09:09:28.0576 0x0610 [ 76468DF7A7A92413A57C998DE5C39290, E2F2F2803FBB94443B5F0E8845348CFC8ECAC92FD188D3038B78FAEC14D34BC8 ] TestHandler C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe 09:09:28.0576 0x0610 TestHandler - ok 09:09:28.0591 0x0610 [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll 09:09:28.0607 0x0610 Themes - ok 09:09:28.0622 0x0610 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll 09:09:28.0622 0x0610 THREADORDER - ok 09:09:28.0669 0x0610 [ DBCC20C02E8A3E43B03C304A4E40A84F, BF5F3ACCB0342304A6870E94D2576644B08DBF307C853C7DBA4B82B0C7309DA4 ] TPM C:\Windows\system32\drivers\tpm.sys 09:09:28.0669 0x0610 TPM - ok 09:09:28.0685 0x0610 [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll 09:09:28.0685 0x0610 TrkWks - ok 09:09:28.0763 0x0610 [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 09:09:28.0778 0x0610 TrustedInstaller - ok 09:09:28.0825 0x0610 [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 09:09:28.0841 0x0610 tssecsrv - ok 09:09:28.0872 0x0610 [ 17C6B51CBCCDED95B3CC14E22791F85E, EE417C19E9B2C258D62A74F1F2421AFFBAC67ACD62481CAA08F5B6A3439C1D7C ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 09:09:28.0888 0x0610 TsUsbFlt - ok 09:09:28.0934 0x0610 [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 09:09:28.0950 0x0610 tunnel - ok 09:09:28.0966 0x0610 [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 09:09:28.0966 0x0610 uagp35 - ok 09:09:29.0012 0x0610 [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 09:09:29.0028 0x0610 udfs - ok 09:09:29.0059 0x0610 [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe 09:09:29.0059 0x0610 UI0Detect - ok 09:09:29.0106 0x0610 [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 09:09:29.0106 0x0610 uliagpkx - ok 09:09:29.0122 0x0610 [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\drivers\umbus.sys 09:09:29.0122 0x0610 umbus - ok 09:09:29.0153 0x0610 [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 09:09:29.0153 0x0610 UmPass - ok 09:09:29.0200 0x0610 [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll 09:09:29.0231 0x0610 UmRdpService - ok 09:09:29.0356 0x0610 [ C0AD6D5023060BB22CAC042A50B989D7, 828BF49AFF6DBD177E803C448C3C4B050D4BE1399E150830EB22C4EA2A641F5D ] UNS C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe 09:09:29.0387 0x0610 UNS - ok 09:09:29.0434 0x0610 [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll 09:09:29.0449 0x0610 upnphost - ok 09:09:29.0465 0x0610 [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 09:09:29.0480 0x0610 usbccgp - ok 09:09:29.0496 0x0610 [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys 09:09:29.0496 0x0610 usbcir - ok 09:09:29.0527 0x0610 [ 18A85013A3E0F7E1755365D287443965, 811C5EDF38C765BCF71BCE25CB6626FF6988C3699F5EF1846240EA0052F34C33 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 09:09:29.0527 0x0610 usbehci - ok 09:09:29.0543 0x0610 [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 09:09:29.0558 0x0610 usbhub - ok 09:09:29.0574 0x0610 [ 765A92D428A8DB88B960DA5A8D6089DC, 56DE8A2ED58E53B202C399CA7BACB1551136303C2EE0AB426BDBBF880E3C542C ] usbohci C:\Windows\system32\drivers\usbohci.sys 09:09:29.0574 0x0610 usbohci - ok 09:09:29.0605 0x0610 [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 09:09:29.0621 0x0610 usbprint - ok 09:09:29.0652 0x0610 [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 09:09:29.0668 0x0610 USBSTOR - ok 09:09:29.0683 0x0610 [ DD253AFC3BC6CBA412342DE60C3647F3, 146F8613F1057AC054DC3593E84BC52899DA27EA33B0E72ACFB78C3699ADCDE7 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 09:09:29.0683 0x0610 usbuhci - ok 09:09:29.0746 0x0610 [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 09:09:29.0761 0x0610 usbvideo - ok 09:09:29.0792 0x0610 [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll 09:09:29.0792 0x0610 UxSms - ok 09:09:29.0808 0x0610 [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] VaultSvc C:\Windows\system32\lsass.exe 09:09:29.0824 0x0610 VaultSvc - ok 09:09:29.0839 0x0610 [ 84BB306B7863883018D7F3EB0C453BD5, 0602C6987E42ADB3F98D200BA078363F80389941938E0611C3CCA6AD6A183DD0 ] VClone C:\Windows\system32\DRIVERS\VClone.sys 09:09:29.0839 0x0610 VClone - ok 09:09:29.0870 0x0610 [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 09:09:29.0870 0x0610 vdrvroot - ok 09:09:29.0933 0x0610 [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe 09:09:29.0948 0x0610 vds - ok 09:09:29.0995 0x0610 [ D7A4CEF1062F6B03C25F755D5306CD64, 694D6D40AECF50348CB279E08DCA6F99EA75D7E25660D3821D2D4636AE4531DC ] VFPRadioSupportService C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe 09:09:29.0995 0x0610 VFPRadioSupportService - ok 09:09:30.0011 0x0610 [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 09:09:30.0026 0x0610 vga - ok 09:09:30.0026 0x0610 [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys 09:09:30.0042 0x0610 VgaSave - ok 09:09:30.0089 0x0610 [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 09:09:30.0089 0x0610 vhdmp - ok 09:09:30.0136 0x0610 [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys 09:09:30.0136 0x0610 viaide - ok 09:09:30.0151 0x0610 [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys 09:09:30.0167 0x0610 vmbus - ok 09:09:30.0182 0x0610 [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 09:09:30.0182 0x0610 VMBusHID - ok 09:09:30.0198 0x0610 [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys 09:09:30.0198 0x0610 volmgr - ok 09:09:30.0245 0x0610 [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 09:09:30.0260 0x0610 volmgrx - ok 09:09:30.0292 0x0610 [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys 09:09:30.0307 0x0610 volsnap - ok 09:09:30.0354 0x0610 [ B4A73CA4EF9A02B9738CEA9AD5FE5917, B6A8086189FE2F1C3FE5B3F484FBA3DB2E5E1836F3154D30090F136C27D16166 ] vpcbus C:\Windows\system32\DRIVERS\vpchbus.sys 09:09:30.0370 0x0610 vpcbus - ok 09:09:30.0401 0x0610 [ E675FB2B48C54F09895482E2253B289C, 68BBFBF2356C849722E429CA753CC309A3CCE8CF00EBDBBD2695ECD292324DF2 ] vpcnfltr C:\Windows\system32\DRIVERS\vpcnfltr.sys 09:09:30.0401 0x0610 vpcnfltr - ok 09:09:30.0448 0x0610 [ 5FB42082B0D19A0268705F1DD343DF20, 62F8EEE6A507CE6A8BD638020118D71B78332F79BA82654AB702AE46B04767D9 ] vpcusb C:\Windows\system32\DRIVERS\vpcusb.sys 09:09:30.0463 0x0610 vpcusb - ok 09:09:30.0557 0x0610 [ 207B6539799CC1C112661A9B620DD233, 6B915CC7F77C867516D94865D7BF2E5C815402EF0A4488C3EB2FEF7CFA6C98F6 ] vpcvmm C:\Windows\system32\drivers\vpcvmm.sys 09:09:30.0572 0x0610 vpcvmm - ok 09:09:30.0604 0x0610 [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 09:09:30.0604 0x0610 vsmraid - ok 09:09:30.0713 0x0610 [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe 09:09:30.0760 0x0610 VSS - ok 09:09:30.0775 0x0610 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 09:09:30.0775 0x0610 vwifibus - ok 09:09:30.0838 0x0610 [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll 09:09:30.0853 0x0610 W32Time - ok 09:09:30.0869 0x0610 [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 09:09:30.0869 0x0610 WacomPen - ok 09:09:30.0916 0x0610 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 09:09:30.0931 0x0610 WANARP - ok 09:09:30.0931 0x0610 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 09:09:30.0947 0x0610 Wanarpv6 - ok 09:09:31.0056 0x0610 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 09:09:31.0103 0x0610 WatAdminSvc - ok 09:09:31.0212 0x0610 [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe 09:09:31.0259 0x0610 wbengine - ok 09:09:31.0274 0x0610 [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 09:09:31.0274 0x0610 WbioSrvc - ok 09:09:31.0352 0x0610 [ 8BDA6DB43AA54E8BB5E0794541DDC209, 8753C507BE77B019A3403AF5252434A01DB9F9332E58AC3783ABCE3D21AD9DD4 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll 09:09:31.0352 0x0610 WcesComm - ok 09:09:31.0399 0x0610 [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll 09:09:31.0415 0x0610 wcncsvc - ok 09:09:31.0415 0x0610 [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 09:09:31.0430 0x0610 WcsPlugInService - ok 09:09:31.0446 0x0610 [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\DRIVERS\wd.sys 09:09:31.0446 0x0610 Wd - ok 09:09:31.0493 0x0610 [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 09:09:31.0524 0x0610 Wdf01000 - ok 09:09:31.0555 0x0610 [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost C:\Windows\system32\wdi.dll 09:09:31.0555 0x0610 WdiServiceHost - ok 09:09:31.0555 0x0610 [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost C:\Windows\system32\wdi.dll 09:09:31.0571 0x0610 WdiSystemHost - ok 09:09:31.0586 0x0610 [ 0EB0E5D22B1760F2DBCE632F2DD7A54D, B8A4CC62F88768947FB0A161CF9564DB28FD9C1C037B5475DF192982DE035C22 ] WebClient C:\Windows\System32\webclnt.dll 09:09:31.0602 0x0610 WebClient - ok 09:09:31.0618 0x0610 [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll 09:09:31.0618 0x0610 Wecsvc - ok 09:09:31.0649 0x0610 [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll 09:09:31.0649 0x0610 wercplsupport - ok 09:09:31.0664 0x0610 [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll 09:09:31.0664 0x0610 WerSvc - ok 09:09:31.0742 0x0610 [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 09:09:31.0742 0x0610 WfpLwf - ok 09:09:31.0758 0x0610 [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 09:09:31.0758 0x0610 WIMMount - ok 09:09:31.0789 0x0610 WinDefend - ok 09:09:31.0805 0x0610 WinHttpAutoProxySvc - ok 09:09:31.0852 0x0610 [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 09:09:31.0852 0x0610 Winmgmt - ok 09:09:31.0976 0x0610 [ D929ABD465A2DED963DA8B30946A8D5C, DE8DBFB01C11D2AE903CBD6A974D6F995E9813CE2D6484B7DA06EAE4C545842A ] WinRM C:\Windows\system32\WsmSvc.dll 09:09:32.0023 0x0610 WinRM - ok 09:09:32.0070 0x0610 [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\drivers\WinUSB.sys 09:09:32.0070 0x0610 WinUsb - ok 09:09:32.0132 0x0610 [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll 09:09:32.0164 0x0610 Wlansvc - ok 09:09:32.0195 0x0610 [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 09:09:32.0195 0x0610 WmiAcpi - ok 09:09:32.0226 0x0610 [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 09:09:32.0242 0x0610 wmiApSrv - ok 09:09:32.0273 0x0610 WMPNetworkSvc - ok 09:09:32.0273 0x0610 [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll 09:09:32.0288 0x0610 WPCSvc - ok 09:09:32.0335 0x0610 [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 09:09:32.0335 0x0610 WPDBusEnum - ok 09:09:32.0382 0x0610 [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 09:09:32.0382 0x0610 ws2ifsl - ok 09:09:32.0429 0x0610 [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\System32\wscsvc.dll 09:09:32.0429 0x0610 wscsvc - ok 09:09:32.0444 0x0610 WSearch - ok 09:09:32.0585 0x0610 [ 61FF576450CCC80564B850BC3FB6713A, B2843BC9E2F62D27DCF6787D063378926748CE75002BADA1873DCB5039883705 ] wuauserv C:\Windows\system32\wuaueng.dll 09:09:32.0632 0x0610 wuauserv - ok 09:09:32.0678 0x0610 [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 09:09:32.0678 0x0610 WudfPf - ok 09:09:32.0710 0x0610 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\Windows\system32\drivers\WUDFRd.sys 09:09:32.0710 0x0610 WUDFRd - ok 09:09:32.0756 0x0610 [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 09:09:32.0756 0x0610 wudfsvc - ok 09:09:32.0772 0x0610 [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc C:\Windows\System32\wwansvc.dll 09:09:32.0788 0x0610 WwanSvc - ok 09:09:32.0803 0x0610 ================ Scan global =============================== 09:09:32.0834 0x0610 [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll 09:09:32.0881 0x0610 [ EA32F4EA3AE06EDD122FBCD5A489E457, C6E464170121D1714A367CFC80C5EA15D42AD34909039FDB114EAD3B878A47F6 ] C:\Windows\system32\winsrv.dll 09:09:32.0897 0x0610 [ EA32F4EA3AE06EDD122FBCD5A489E457, C6E464170121D1714A367CFC80C5EA15D42AD34909039FDB114EAD3B878A47F6 ] C:\Windows\system32\winsrv.dll 09:09:32.0928 0x0610 [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll 09:09:32.0959 0x0610 [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe 09:09:32.0959 0x0610 [ Global ] - ok 09:09:32.0959 0x0610 ================ Scan MBR ================================== 09:09:32.0975 0x0610 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 09:09:33.0224 0x0610 \Device\Harddisk0\DR0 - ok 09:09:33.0224 0x0610 ================ Scan VBR ================================== 09:09:33.0240 0x0610 [ 7A2896BFF3796EB39CB48E03C2A42C71 ] \Device\Harddisk0\DR0\Partition1 09:09:33.0240 0x0610 \Device\Harddisk0\DR0\Partition1 - ok 09:09:33.0240 0x0610 ================ Scan generic autorun ====================== 09:09:33.0240 0x0610 SynTPEnh - ok 09:09:33.0287 0x0610 FreeFallProtection - ok 09:09:33.0599 0x0610 [ 14F06BA8BCC5ED921962ADD86D8DB73A, 9CF00E242C589AF682B4F56DEC6A3EA6DD4F1F161C3A5DAE533DF6F73828DA56 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 09:09:33.0708 0x0610 RtHDVCpl - ok 09:09:33.0802 0x0610 [ E5ED3BFE95669305F6FF364C9107543C, 1D533A5677C59E37B9AB03DDA8D3FBB14C12EE0A7C53F81C141EFFE82C6AB81C ] C:\Program Files\Realtek\Audio\HDA\Skytel.exe 09:09:33.0848 0x0610 Skytel - ok 09:09:33.0880 0x0610 [ 71FC40DF690F7BF9F657616DEE9B3635, 0718AB8D42E0397CCD6BC612E26EC6AF01F84C6C6C081D429835C216CBBF7E29 ] C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe 09:09:33.0880 0x0610 picon - ok 09:09:33.0958 0x0610 [ B382EF12FF24AD633AAA34A08C744EAE, 96894BCA569C9D3F18B5E0EA54E40B6DBA9EE71B8EE38762E59FC502BDAFE347 ] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe 09:09:33.0973 0x0610 ConMgr - ok 09:09:34.0004 0x0610 [ CF804BCFC26C7FEEAB76CDDAB8A8C8BB, DCE26F9D61F48ACC7F442C33243BFB3B6774673B136A744900CB79FB630CA784 ] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe 09:09:34.0004 0x0610 CSRSkype - ok 09:09:34.0004 0x0610 BthSyncServ - ok 09:09:34.0036 0x0610 [ 28D77ACD3ACC877730BCC62D592CD958, AEC57603BF54A33866F8948C8B7AEEFB108B07A7EFD7EBE8093D6AE50A055110 ] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe 09:09:34.0036 0x0610 CSRFTP - ok 09:09:34.0114 0x0610 [ CFD9AECD0EADAD97851E99E35462AB8F, 865520E63EAC5261EE7BCECD1E11566CE8922DF3CAFF968548216898FA975FA2 ] C:\Program Files\SmartCase Logon+\System\SclStart.exe 09:09:34.0145 0x0610 SclStart.exe - ok 09:09:34.0160 0x0610 ATSwpNav - ok 09:09:34.0223 0x0610 [ 233A10D4B3F6897899112E4EC60F1906, 1F7E768E57064938114DF2EFC5B219EB0D30A7D9E574924E9CED054462505AF0 ] C:\Windows\WindowsMobile\wmdc.exe 09:09:34.0238 0x0610 Windows Mobile Device Center - ok 09:09:34.0254 0x0610 nwiz - ok 09:09:34.0254 0x0610 NvCplDaemon - ok 09:09:34.0285 0x0610 [ EE1F031384DB0856C363D77E45B16A62, 237236D8F7AE68882298370F2BF8AEF70F9588ED7B2F9E8E0222AD38A1FC6AE1 ] C:\Program Files (x86)\Fujitsu\DeskViewBasic\DeskViewBasic.exe 09:09:34.0301 0x0610 DeskViewBasic - ok 09:09:34.0363 0x0610 [ 452FA961163EF4AEE4815796A13AB2CF, 14DC422082F96F5C21C41A5E5F6E8445547CC4B02B18F0A86A34669CA2CE18A7 ] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe 09:09:34.0379 0x0610 Adobe Reader Speed Launcher - ok 09:09:34.0441 0x0610 [ F2739BC1BE8648FD7F49C00BC1F2E6F9, 312AFFD8643C1889F4E6E7E0FDE7F6026D7800E3F3E1DA4ACEDFA7069BD8A8BA ] C:\Program Files (x86)\Fujitsu\Mobile Software Suite\Common\UiMdmTip\UiMdmTip.exe 09:09:34.0441 0x0610 COMImpersonater - ok 09:09:34.0488 0x0610 [ F40E80C04475731C6ED5D19C48E45E3C, 40BB48DD37D6DFD61A68BA7891C4C453665561F7C74C5DA1BC7D7B36A0190DAA ] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe 09:09:34.0488 0x0610 VirtualCloneDrive - ok 09:09:34.0706 0x0610 [ 6B115CE521D96900373775ECAC975D59, 9E915F95AFBAABA418B30AAEEEEDA8A127AFD0C2EBD899AACF7AC9A8013F8413 ] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe 09:09:34.0753 0x0610 KiesTrayAgent - ok 09:09:34.0862 0x0610 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 09:09:34.0878 0x0610 Sidebar - ok 09:09:34.0909 0x0610 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 09:09:34.0909 0x0610 mctadmin - ok 09:09:34.0940 0x0610 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 09:09:34.0972 0x0610 Sidebar - ok 09:09:34.0972 0x0610 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 09:09:34.0972 0x0610 mctadmin - ok 09:09:35.0065 0x0610 [ E3BF29CED96790CDAAFA981FFDDF53A3, 76CB27EF7B27E5636EDA9D95229519B2A2870729A0BB694F1FD11CD602BAC4DC ] C:\Program Files\Windows Sidebar\sidebar.exe 09:09:35.0112 0x0610 Sidebar - ok 09:09:35.0299 0x0610 [ C01DC9DCF75D4F577A0C2368B2E98009, 63B3DA22DE21337EE0FD6DE2ABDF0939F1B093EF52AA39FF601BFA1504920AB1 ] C:\Program Files (x86)\ITSolution\trustDesk basic\bin\SecurityLayer.exe 09:09:35.0362 0x0610 SecurityLayer - ok 09:09:35.0440 0x0610 [ 70C305067B3D543870597C57F74D9EC3, CF25EB4D61A387E61B6C301AEEBD5B8EBF8AFC372A7001F53979521AA4758098 ] C:\Program Files (x86)\Samsung\Kies\Kies.exe 09:09:35.0455 0x0610 KiesPreload - ok 09:09:35.0471 0x0610 KiesAirMessage - ok 09:09:35.0486 0x0610 [ 8E689D83B243C229A683559FF98CF047, DC3D08CDD5EFF7EF81CB75AF4F354878CDC78CAE8FC8A2CFD143EE4F26DA1D3E ] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe 09:09:35.0486 0x0610 KiesPDLR - ok 09:09:35.0518 0x0610 Skype - ok 09:09:35.0658 0x0610 [ C01DC9DCF75D4F577A0C2368B2E98009, 63B3DA22DE21337EE0FD6DE2ABDF0939F1B093EF52AA39FF601BFA1504920AB1 ] C:\Program Files (x86)\ITSolution\trustDesk basic\bin\SecurityLayer.exe 09:09:35.0705 0x0610 SecurityLayer - ok 09:09:35.0705 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:36.0719 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:37.0733 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:38.0747 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:39.0761 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:40.0775 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:41.0789 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:42.0803 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:43.0817 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:44.0831 0x0610 Waiting for KSN requests completion. In queue: 280 09:09:46.0157 0x0610 AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe ( 15.0.9.460 ), 0x41000 ( enabled : updated ) 09:09:46.0204 0x0610 Win FW state via NFP2: enabled 09:09:56.0016 0x0610 ============================================================ 09:09:56.0016 0x0610 Scan finished 09:09:56.0016 0x0610 ============================================================ 09:09:56.0032 0x0ee8 Detected object count: 0 09:09:56.0032 0x0ee8 Actual detected object count: 0 |
17.05.2015, 11:51 | #6 |
/// the machine /// TB-Ausbilder | Laptop Fujitsu Celsius H265 wird immer langsamer hi, Scan mit Combofix
__________________ --> Laptop Fujitsu Celsius H265 wird immer langsamer |
17.05.2015, 15:06 | #7 |
| Laptop Fujitsu Celsius H265 wird immer langsamer hallo, hier die combofix.txt ... Code:
ATTFilter ComboFix 15-05-13.01 - HN 17.05.2015 15:31:21.1.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.43.1031.18.2027.967 [GMT 2:00] ausgeführt von:: c:\users\HN\Desktop\ComboFix.exe AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\HN\AppData\Roaming\.# c:\windows\IsUn0407.exe c:\windows\Tasks\Cadmould_000.bat c:\windows\Tasks\Cadmould_001.bat . . ((((((((((((((((((((((( Dateien erstellt von 2015-04-17 bis 2015-05-17 )))))))))))))))))))))))))))))) . . 2015-05-17 13:44 . 2015-05-17 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-05-17 13:44 . 2015-05-17 13:44 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2015-05-17 12:01 . 2013-12-10 17:43 38200 ----a-w- c:\windows\system32\uxtuneup.dll 2015-05-17 12:01 . 2013-12-10 17:43 30520 ----a-w- c:\windows\SysWow64\uxtuneup.dll 2015-05-17 11:57 . 2013-12-10 17:43 35640 ----a-w- c:\windows\system32\TURegOpt.exe 2015-05-17 11:56 . 2013-12-10 17:43 26936 ----a-w- c:\windows\system32\authuitu.dll 2015-05-17 11:56 . 2013-12-10 17:43 22328 ----a-w- c:\windows\SysWow64\authuitu.dll 2015-05-17 11:56 . 2015-05-17 11:56 -------- d-----w- c:\users\HN\AppData\Roaming\TuneUp Software 2015-05-17 11:55 . 2015-05-17 12:01 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2013 2015-05-17 11:54 . 2015-05-17 12:01 -------- d-----w- c:\programdata\TuneUp Software 2015-05-17 11:52 . 2015-05-17 12:26 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2015-05-17 11:52 . 2015-05-17 11:52 -------- d--h--w- c:\programdata\Common Files 2015-05-17 06:34 . 2015-05-17 07:03 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2015-05-17 06:34 . 2015-05-17 06:34 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-05-17 06:32 . 2015-05-17 06:32 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2015-05-17 05:42 . 2015-05-17 05:42 -------- d-----w- c:\program files (x86)\VS Revo Group 2015-05-17 05:22 . 2015-05-17 05:27 -------- d-s---w- c:\windows\system32\GWX 2015-05-17 05:22 . 2015-05-17 05:22 -------- d-s---w- c:\windows\SysWow64\GWX 2015-05-15 04:06 . 2015-05-15 04:40 -------- d-----w- C:\FRST 2015-05-10 16:39 . 2015-03-05 04:05 311808 ----a-w- c:\windows\SysWow64\gdi32.dll 2015-05-10 16:39 . 2015-03-05 05:12 404480 ----a-w- c:\windows\system32\gdi32.dll 2015-05-10 16:39 . 2015-03-10 03:08 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll 2015-05-10 16:39 . 2015-03-10 03:05 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2015-05-10 16:39 . 2015-03-10 03:25 1882624 ----a-w- c:\windows\system32\msxml3.dll 2015-05-10 16:39 . 2015-03-10 03:21 2048 ----a-w- c:\windows\system32\msxml3r.dll 2015-05-10 16:39 . 2015-02-25 03:18 754688 ----a-w- c:\windows\system32\drivers\http.sys 2015-05-10 16:37 . 2015-03-13 04:25 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2015-05-10 16:36 . 2015-03-04 04:10 58880 ----a-w- c:\windows\SysWow64\clfsw32.dll 2015-05-10 16:36 . 2015-03-04 04:55 367552 ----a-w- c:\windows\system32\clfs.sys 2015-05-10 16:36 . 2015-03-04 04:41 79360 ----a-w- c:\windows\system32\clfsw32.dll 2015-05-02 09:08 . 2015-05-02 09:08 -------- d-----w- c:\program files (x86)\Common Files\Skype 2015-04-19 07:06 . 2015-04-19 07:06 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2015-04-19 06:54 . 2015-04-19 07:07 -------- d-----w- c:\programdata\NVIDIA Corporation . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-05-17 10:08 . 2012-04-07 11:46 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-05-17 10:08 . 2011-05-15 15:14 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-05-02 08:58 . 2011-07-09 13:00 128913832 ----a-w- c:\windows\system32\MRT.exe 2015-03-17 04:56 . 2015-04-19 16:48 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2015-03-10 19:53 . 2013-05-07 17:12 44088 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2015-03-10 19:53 . 2013-03-29 22:37 132120 ----a-w- c:\windows\system32\drivers\avipbb.sys 2015-03-10 19:53 . 2013-03-29 22:37 128536 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2015-02-26 03:25 . 2015-03-14 10:12 3204096 ----a-w- c:\windows\system32\win32k.sys 2015-02-20 04:41 . 2015-03-14 10:16 41984 ----a-w- c:\windows\system32\lpk.dll 2015-02-20 04:40 . 2015-03-14 10:16 100864 ----a-w- c:\windows\system32\fontsub.dll 2015-02-20 04:40 . 2015-03-14 10:16 14336 ----a-w- c:\windows\system32\dciman32.dll 2015-02-20 04:40 . 2015-03-14 10:16 46080 ----a-w- c:\windows\system32\atmlib.dll 2015-02-20 04:13 . 2015-03-14 10:16 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2015-02-20 04:13 . 2015-03-14 10:16 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2015-02-20 04:13 . 2015-03-14 10:16 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2015-02-20 04:12 . 2015-03-14 10:16 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2015-02-20 03:29 . 2015-03-14 10:16 372224 ----a-w- c:\windows\system32\atmfd.dll 2015-02-20 03:09 . 2015-03-14 10:16 299008 ----a-w- c:\windows\SysWow64\atmfd.dll 2015-02-17 15:04 . 2015-02-17 15:04 1202848 ----a-w- c:\windows\SysWow64\FM20.DLL . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-12-20 1521952] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-12-20 20:56 1521952 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-12-20 1521952] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "SecurityLayer"="c:\program files (x86)\ITSolution\trustDesk basic\bin\SecurityLayer.exe" [2010-03-20 3128320] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-08-31 964024] "KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-08-31 21432] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "COMImpersonater"="c:\program files (x86)\Fujitsu\Mobile Software Suite\Common\UiMdmTip\UiMdmTip.exe" [2009-05-20 176128] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-08-31 3524536] "ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2012-12-20 1574176] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2015-04-09 726320] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ PHOTOfunSTUDIO 9.3 PE.lnk - c:\program files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe -e "c:\program files (x86)\Panasonic\PHOTOfunSTUDIO 9.3 PE\PHOTOfunSTUDIO.exe" [2014-5-3 160256] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LaunchCenter.lnk - c:\program files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe [2009-9-22 2351104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Si3531;Si3531;c:\windows\system32\DRIVERS\Si3531.sys;c:\windows\SYSNATIVE\DRIVERS\Si3531.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdflt.sys;c:\windows\SYSNATIVE\DRIVERS\stdflt.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 fcrimg4;SecureDrive;c:\windows\system32\DRIVERS\fcrimg4.sys;c:\windows\SYSNATIVE\DRIVERS\fcrimg4.sys [x] S2 aksdf;aksdf;c:\windows\system32\drivers\aksdf.sys;c:\windows\SYSNATIVE\drivers\aksdf.sys [x] S2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\ATService.exe;c:\program files\Fingerprint Sensor\ATService.exe [x] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x] S2 cmTCS64 Service;cmTCS64 Service;c:\windows\system32\cmTCS64.exe;c:\windows\SYSNATIVE\cmTCS64.exe [x] S2 DeskViewBasicService;DeskViewBasicService;c:\program files (x86)\Fujitsu\DeskViewBasic\DeskViewBasicService.exe;c:\program files (x86)\Fujitsu\DeskViewBasic\DeskViewBasicService.exe [x] S2 HaMDevMg.1.01;Fujitsu HaMDevMg.1.01;c:\program files (x86)\Common Files\Fujitsu\Manageability\HaMDevMg.exe\1.01\HaMDevMg.exe;c:\program files (x86)\Common Files\Fujitsu\Manageability\HaMDevMg.exe\1.01\HaMDevMg.exe [x] S2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run;c:\windows\SYSNATIVE\hasplms.exe -run [x] S2 HLServer;HL-Server;c:\windows\system32\HLS32SVC.EXE;c:\windows\SYSNATIVE\HLS32SVC.EXE [x] S2 LogonUserService;LogonUser Service;c:\program files\SmartCase Logon+\System\logonuser.exe;c:\program files\SmartCase Logon+\System\logonuser.exe [x] S2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [x] S2 SmartCaseServer;SmartCaseServer;c:\program files\SmartCase Logon+\Password Manager\SmartCaseServer.exe;c:\program files\SmartCase Logon+\Password Manager\SmartCaseServer.exe [x] S2 SmartyLogService;SmartyLogService;c:\program files\SmartCase Logon+\System\SmartyLog.exe;c:\program files\SmartCase Logon+\System\SmartyLog.exe [x] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe;c:\program files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [x] S2 VFPRadioSupportService;Unterstützung für Bluetooth-Funktionen;c:\program files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe;c:\program files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [x] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Acceler.sys;c:\windows\SYSNATIVE\DRIVERS\Acceler.sys [x] S3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys;c:\windows\SYSNATIVE\Drivers\ATSwpWDF.sys [x] S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x] S3 FscBapi;FscBapi;c:\windows\system32\DRIVERS\FscBapi.sys;c:\windows\SYSNATIVE\DRIVERS\FscBapi.sys [x] S3 FscGabi;FscGabi;c:\windows\system32\DRIVERS\FscGabi.sys;c:\windows\SYSNATIVE\DRIVERS\FscGabi.sys [x] S3 FSCSLII;FSCSLII;c:\windows\system32\DRIVERS\FSCSLII.sys;c:\windows\SYSNATIVE\DRIVERS\FSCSLII.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 ITEIRDA;ITE Infrared Device Driver;c:\windows\system32\DRIVERS\ITEirda.sys;c:\windows\SYSNATIVE\DRIVERS\ITEirda.sys [x] S3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5v64.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2015-05-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 10:08] . 2015-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-16 18:08] . 2015-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-16 18:08] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATSwpNav"="c:\program files\Fingerprint Sensor\ATSwpNav -run" [X] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-06 7940128] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504] "picon"="c:\program files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2009-07-15 358936] "ConMgr"="c:\program files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe" [2009-07-28 535392] "CSRSkype"="c:\program files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe" [2009-07-28 431456] "CSRFTP"="c:\program files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe" [2009-07-28 463216] "SclStart.exe"="c:\program files\SmartCase Logon+\System\SclStart.exe" [2009-08-06 1074752] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360] "nwiz"="nwiz.exe" [2009-08-26 1712672] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-31 16336488] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.138 FF - ProfilePath - c:\users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.at . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-DeskViewBasic - %ProgramFiles(x86)%\Fujitsu\DeskViewBasic\DeskViewBasic.exe Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Activation Assistant for the 2007 Microsoft Office suites - c:\programdata\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe AddRemove-Aladdin Monitor 1.4.2 - e:\progra~1\Aladdin\Monitor\UNWISE.EXE AddRemove-MapSource - c:\windows\IsUn0407.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-05-17 15:49:48 ComboFix-quarantined-files.txt 2015-05-17 13:49 . Vor Suchlauf: 13 Verzeichnis(se), 188.966.760.448 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 188.690.534.400 Bytes frei . - - End Of File - - 7CF40C762C23DD4E3F34DF6B18AFD22F A36C5E4F47E84449FF07ED3517B43A31 |
18.05.2015, 09:09 | #8 |
/// the machine /// TB-Ausbilder | Laptop Fujitsu Celsius H265 wird immer langsamer Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.05.2015, 21:19 | #9 |
| Laptop Fujitsu Celsius H265 wird immer langsamer Hallo, ... bin wirklich dankbar für die Hilfestellung ... ... hier die Dateien: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 19.05.2015 Suchlauf-Zeit: 20:29:31 Logdatei: mbam.txt Administrator: Ja Version: 2.01.6.1022 Malware Datenbank: v2015.05.19.04 Rootkit Datenbank: v2015.05.16.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: HN Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 423244 Verstrichene Zeit: 18 Min, 54 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 7 PUP.Optional.Incredibar.A, HKLM\SOFTWARE\IB Updater, In Quarantäne, [314f84117911c373300768ae4eb657a9], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [4a362471f298102677bf6da9e222ff01], Security.Hijack, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSIEXEC.EXE, In Quarantäne, [760a781d6a203df9ed112a7d30d4d42c], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\IB Updater, In Quarantäne, [2d53672eb4d60e287bbc7d99947049b7], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [4f31890c008aa5919d9911058e769b65], Security.Hijack, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSIEXEC.EXE, In Quarantäne, [17694550b1d91d198e70931443c10000], PUP.Optional.Incredibar.A, HKU\S-1-5-21-2065948893-2615235351-692522125-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}, In Quarantäne, [a9d7078e81097eb828eed59925e0fc04], Registrierungswerte: 7 PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [0080b9dc1b6f8da9a868490e847f6b95], PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [0080b9dc1b6f8da9a868490e847f6b95] PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [0080b9dc1b6f8da9a868490e847f6b95] PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [85fb93021674c076d937ec6bd72c728e], Security.Hijack, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSIEXEC.EXE|Debugger, "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe", In Quarantäne, [760a781d6a203df9ed112a7d30d4d42c] Security.Hijack, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSIEXEC.EXE|Debugger, "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe", In Quarantäne, [17694550b1d91d198e70931443c10000] PUP.Optional.Incredibar.A, HKU\S-1-5-21-2065948893-2615235351-692522125-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}|URL, hxxp://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQLNsybmA&i=26, In Quarantäne, [a9d7078e81097eb828eed59925e0fc04] Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 0 (Keine schädliche Elemente gefunden) Dateien: 0 (Keine schädliche Elemente gefunden) Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) Code:
ATTFilter # AdwCleaner v4.204 - Bericht erstellt 19/05/2015 um 21:35:49 # Aktualisiert 12/05/2015 von Xplode # Datenbank : 2015-05-12.2 [Server] # Betriebssystem : Windows 7 Professional Service Pack 1 (x64) # Benutzername : HN - H265-W7P # Gestarted von : C:\Users\HN\Downloads\AdwCleaner_4.204.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\Ask.com Ordner Gelöscht : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe} Ordner Gelöscht : C:\Users\HN\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default\Extensions\toolbar@ask.com Datei Gelöscht : C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default\searchplugins\Askcom.xml ***** [ Geplante Tasks ] ***** Task Gelöscht : Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{950C1FF7-D8A5-41A9-B2F7-AC4BDCED4F32} Schlüssel Gelöscht : HKCU\Software\APN Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\APN Schlüssel Gelöscht : HKU\.DEFAULT\Software\AskToolbar Schlüssel Gelöscht : HKU\.DEFAULT\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17728 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v36.0.4 (x86 de) [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Ask.com"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.FeaturePageVersion", "1"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.OOBEVersion", "1"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.apn_dbr", "ff_15.0.1"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.autofill-text-highlight-enabled", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.cbid", "^AGS"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.config-updated", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.crumb", "2012.11.10+03.32.49-toolbar019iad-DE-RnJhbmtmdXJ0IEFuIERlciBPZGVyLEdlcm1hbnk%3D"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://avira-int.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar&locale={locale}"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.domain", "avira-int.ask.com"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.domainName", "avira-int.ask.com"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.dtid", "^YYYYYY^YY^DE"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.fresh-install", false); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.guid", "f2009b5b-d012-43c3-b27b-78864d6e92e4"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.hpr", "YES"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...] [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.if", "first"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.keyword-toggled-in-session", false); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.l", "dis"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.last-config-req", "1361002120738"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.last-search-timestamp", "1356633678709"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.locale", "de_DE"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.localePref", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.location", "Frankfurt An Der Oder,Germany"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.nthp", "YES"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.nthp_prev", "1"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.o", "APN10261"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.qsrc", "2871"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.r", "19"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.sa", "YES"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.saguid", "92312519-F6BD-4C03-9049-341E9D52FD7A"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.search-history-queries", "hotmailchinesisches Jahreshoroskop 2013"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.silent-upgrade", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.socialmini-first", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.socialmini-interval", "1200000"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.socialmini-max-items", "30"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.socialmini-native-on", true); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.socialmini-speed", "5000"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.themeid", ""); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.timeinstalled", "10.11.2012 12:35:23"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.to", ""); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.v", "3.15.13.100015"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.version", "5.15.13.33021"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.enabledAddons", "toolbar%40ask.com:3.15.13.100015,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:36.0.4"); [s63t4uja.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"toolbar@ask.com\":{\"d\":\"C:\\\\Users\\\\HN\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\s63t4uja.default\\\\extensions\\\\toolbar@[...] ************************* AdwCleaner[R0].txt - [16665 Bytes] - [19/05/2015 21:24:56] AdwCleaner[S0].txt - [16405 Bytes] - [19/05/2015 21:35:49] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16465 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.7.4 (05.19.2015:1) OS: Windows 7 Professional x64 Ran by HN on 19.05.2015 at 21:51:20,05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\HN\AppData\Roaming\mozilla\firefox\profiles\s63t4uja.default\minidumps [79 files] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 19.05.2015 at 21:56:59,67 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015 Ran by HN (administrator) on H265-W7P on 19-05-2015 22:02:55 Running from C:\Users\HN\Desktop Loaded Profiles: HN (Available profiles: HN & Administrator) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Aladdin Knowledge Systems Ltd.) C:\Windows\System32\hasplms.exe (Aladdin Knowledge Systems Ltd.) C:\Windows\SysWOW64\HLS32SVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-20] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7940128 2009-07-06] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-07-06] (Realtek Semiconductor Corp.) HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [358936 2009-07-15] (Intel Corporation) HKLM\...\Run: [ConMgr] => C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe [535392 2009-07-28] (CSR, plc) HKLM\...\Run: [CSRSkype] => C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe [431456 2009-07-28] (CSR, plc) HKLM\...\Run: [CSRFTP] => C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe [463216 2009-07-28] (CSR, plc) HKLM\...\Run: [SclStart.exe] => C:\Program Files\SmartCase Logon+\System\SclStart.exe [1074752 2009-08-06] (Fujitsu Technologies Solutions) HKLM\...\Run: [ATSwpNav] => "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run (the data entry has 65 more characters). HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM-x32\...\Run: [COMImpersonater] => C:\Program Files (x86)\Fujitsu\Mobile Software Suite\Common\UiMdmTip\UiMdmTip.exe [176128 2009-05-20] (Fujitsu Technology Solutions) HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [85160 2009-06-17] (Elaborate Bytes AG) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3524536 2012-08-31] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [728312 2015-05-19] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [SecurityLayer] => C:\Program Files (x86)\ITSolution\trustDesk basic\bin\SecurityLayer.exe [3128320 2010-03-20] (IT Solution GmbH) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [964024 2012-08-31] (Samsung) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\...\Run: [KiesPDLR] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-08-31] () IFEO\applicationbuttonutility.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\autostartupservice.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\csrbippushinitiatorwizard.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\fancontrol.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\helplauncher.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\kies.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\launchcenter.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\photofunstudio.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\powersavingutility.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\sclstart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\securedrive.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\setup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\shocksensorutility.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\skype.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\smartcase.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\systemdiagnostics.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\vcd-uninst.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\vcdmount.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\vcdprefs.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\wirelessselector.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IFEO\wmdc.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 9.3 PE.lnk [2014-05-03] ShortcutTarget: PHOTOfunSTUDIO 9.3 PE.lnk -> C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe (Panasonic Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\LaunchCenter.lnk [2010-02-09] ShortcutTarget: LaunchCenter.lnk -> C:\Program Files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\LaunchCenter.lnk [2010-02-09] ShortcutTarget: LaunchCenter.lnk -> C:\Program Files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe (Fujitsu Technology Solutions) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2065948893-2615235351-692522125-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> {5397299F-6097-463C-82BB-B9365934BB1E} URL = SearchScopes: HKU\S-1-5-21-2065948893-2615235351-692522125-1000 -> {9848AFE5-A709-4314-9AC6-73D65A8481C5} URL = BHO: SingleSignOn Class -> {37B109B0-E817-4072-8429-EDC6A987FCE3} -> C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseBho.dll [2009-09-25] () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-01] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-01] (Oracle Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated) BHO-x32: SingleSignOn Class -> {37B109B0-E817-4072-8429-EDC6A987FCE3} -> C:\Program Files (x86)\SmartCase Logon+\Password Manager\SmartCaseBho.dll [2009-09-25] () BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-01] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-01] (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default FF NewTab: FF DefaultSearchEngine: Google FF Homepage: hxxp://google.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-17] () FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-01] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-17] () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2009-03-03] (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @innoplus.de/ino3DViewer -> C:\Program Files (x86)\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll [2013-09-27] (INNOVA-engineering GmbH Dresden) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Windows\SysWOW64\npdeployJava1.dll [2015-02-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-01] (Oracle Corporation) FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 -> C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll [2012-09-28] (Logitech Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll [2009-06-25] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-27] (Microsoft Corporation) FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-03-27] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-03-27] FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn FF Extension: No Name - C:\Users\HN\AppData\Roaming\Mozilla\Firefox\Profiles\s63t4uja.default\extensions\toolbar@ask.com [Not Found] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2013-12-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827640 2015-05-19] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-05-19] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-05-19] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1185584 2015-05-19] (Avira Operations GmbH & Co. KG) S2 cmTCS64 Service; C:\Windows\system32\cmTCS64.exe [284672 2008-05-16] (charismathics) [File not signed] S4 DeskViewBasicService; C:\Program Files (x86)\Fujitsu\DeskViewBasic\DeskViewBasicService.exe [34816 2009-08-19] (Fujitsu Technology Solutions) [File not signed] S4 HaMDevMg.1.01; C:\Program Files (x86)\Common Files\Fujitsu\Manageability\HaMDevMg.exe\1.01\HaMDevMg.exe [557056 2009-05-20] (Fujitsu Technology Solutions) [File not signed] R2 HLServer; C:\Windows\SysWOW64\HLS32SVC.EXE [327680 2004-02-06] (Aladdin Knowledge Systems Ltd.) [File not signed] R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-07-15] (Intel Corporation) S4 LogonUserService; C:\Program Files\SmartCase Logon+\System\logonuser.exe [280128 2009-07-24] (iC ComPas GmbH & Co KG) [File not signed] S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S2 NVIDIA Performance Driver Service; C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [4908576 2009-07-20] () S4 SmartCaseServer; C:\Program Files\SmartCase Logon+\Password Manager\SmartCaseServer.exe [324672 2009-07-01] () [File not signed] S4 SmartyLogService; C:\Program Files\SmartCase Logon+\System\SmartyLog.exe [321600 2009-03-12] (iC ComPas GmbH & Co KG) [File not signed] S4 TestHandler; C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [341264 2009-02-19] (Fujitsu Technology Solutions) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2409272 2013-12-10] (TuneUp Software) S2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2009-07-15] (Intel Corporation) S4 VFPRadioSupportService; C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [145792 2009-07-28] (CSR, plc) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S4 SkypeUpdate; "C:\Program Files (x86)\Skype\Updater\Updater.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [152744 2015-05-19] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-05-19] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-30] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-10] (Avira Operations GmbH & Co. KG) R1 fcrimg4; C:\Windows\System32\DRIVERS\fcrimg4.sys [43584 2009-08-27] (iC ComPas GmbH & Co KG ) R3 FscBapi; C:\Windows\System32\DRIVERS\FscBapi.sys [18944 2009-05-05] (Fujitsu Technology Solutions) R3 FscGabi; C:\Windows\System32\DRIVERS\FscGabi.sys [19968 2009-05-05] (Fujitsu Technology Solutions) R3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [20992 2009-08-05] (Fujitsu) R3 guardian2; C:\Windows\System32\Drivers\oz776x64.sys [85280 2009-05-15] (O2Micro) R3 ITEIRDA; C:\Windows\System32\DRIVERS\ITEirda.sys [27904 2008-08-22] (ITE Tech. Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-19] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation) S3 Si3531; C:\Windows\system32\DRIVERS\Si3531.sys [330544 2007-06-01] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22832 2007-04-04] (Silicon Image, Inc.) R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [17200 2007-04-04] (Silicon Image, Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-19 22:02 - 2015-05-19 22:05 - 00019085 _____ () C:\Users\HN\Desktop\FRST.txt 2015-05-19 22:02 - 2015-05-19 22:02 - 00000000 ____D () C:\Users\HN\Desktop\FRST-OlderVersion 2015-05-19 21:59 - 2015-05-19 21:59 - 00000887 _____ () C:\JRT.txt 2015-05-19 21:56 - 2015-05-19 21:56 - 00000887 _____ () C:\Users\HN\Desktop\JRT.txt 2015-05-19 21:52 - 2015-05-19 21:52 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-H265-W7P-Windows-7-Professional-(64-bit).dat 2015-05-19 21:51 - 2015-05-19 21:51 - 00000000 ____D () C:\RegBackup 2015-05-19 21:31 - 2015-05-19 21:31 - 00002042 _____ () C:\Users\Public\Desktop\Avira Antivirus.lnk 2015-05-19 21:31 - 2015-05-19 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-05-19 21:24 - 2015-05-19 21:36 - 00000000 ____D () C:\AdwCleaner 2015-05-19 21:21 - 2015-05-19 21:21 - 02720196 _____ (Thisisu) C:\Users\HN\Desktop\JRT.exe 2015-05-19 21:18 - 2015-05-19 21:18 - 02209792 _____ () C:\Users\HN\Desktop\AdwCleaner_4.204.exe 2015-05-19 20:52 - 2015-05-19 21:16 - 00003765 _____ () C:\mbam.txt 2015-05-19 20:48 - 2015-05-19 20:48 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2015-05-19 20:27 - 2015-05-19 20:27 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-05-19 20:27 - 2015-05-19 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-05-19 20:27 - 2015-05-19 20:27 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-05-19 20:27 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-05-19 20:27 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-05-19 20:26 - 2015-05-19 20:26 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\HN\Downloads\mbam-setup-2.1.6.1022.exe 2015-05-18 22:16 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-18 22:16 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-17 15:49 - 2015-05-17 15:49 - 00018681 _____ () C:\ComboFix.txt 2015-05-17 15:28 - 2015-05-17 15:49 - 00000000 ____D () C:\Qoobox 2015-05-17 15:28 - 2015-05-17 15:49 - 00000000 ____D () C:\ComboFix 2015-05-17 15:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-05-17 15:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-05-17 15:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-05-17 15:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-05-17 15:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-05-17 15:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2015-05-17 15:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2015-05-17 15:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2015-05-17 15:27 - 2015-05-17 15:46 - 00000000 ____D () C:\Windows\erdnt 2015-05-17 15:17 - 2015-05-17 15:18 - 05623645 ____R (Swearware) C:\Users\HN\Desktop\ComboFix.exe 2015-05-17 14:01 - 2013-12-10 19:43 - 00038200 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2015-05-17 14:01 - 2013-12-10 19:43 - 00030520 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll 2015-05-17 13:57 - 2013-12-10 19:43 - 00035640 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2015-05-17 13:56 - 2015-05-17 13:56 - 00002215 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk 2015-05-17 13:56 - 2015-05-17 13:56 - 00002207 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk 2015-05-17 13:56 - 2015-05-17 13:56 - 00002195 _____ () C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk 2015-05-17 13:56 - 2015-05-17 13:56 - 00000000 ____D () C:\Users\HN\AppData\Roaming\TuneUp Software 2015-05-17 13:56 - 2015-05-17 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013 2015-05-17 13:56 - 2013-12-10 19:43 - 00026936 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2015-05-17 13:56 - 2013-12-10 19:43 - 00022328 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2015-05-17 13:55 - 2015-05-17 14:01 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2013 2015-05-17 13:54 - 2015-05-17 14:01 - 00000000 ____D () C:\ProgramData\TuneUp Software 2015-05-17 13:52 - 2015-05-17 14:26 - 00000000 __SHD () C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2015-05-17 13:51 - 2015-05-17 13:52 - 28181408 _____ (TuneUp Software) C:\Users\HN\Downloads\TuneUpUtilities2013_de-DE.exe 2015-05-17 09:05 - 2015-05-17 09:05 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\HN\Desktop\tdsskiller.exe 2015-05-17 08:34 - 2015-05-19 21:44 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-17 08:34 - 2015-05-17 09:03 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-05-17 08:32 - 2015-05-17 09:02 - 00000000 ____D () C:\Users\HN\Desktop\mbar 2015-05-17 08:32 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-05-17 07:42 - 2015-05-17 07:42 - 00001270 _____ () C:\Users\HN\Desktop\Revo Uninstaller.lnk 2015-05-17 07:42 - 2015-05-17 07:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-05-17 07:22 - 2015-05-17 07:27 - 00000000 ___SD () C:\Windows\system32\GWX 2015-05-17 07:22 - 2015-05-17 07:22 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-05-15 07:29 - 2015-03-04 06:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-05-15 07:29 - 2015-03-04 06:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-05-15 07:29 - 2015-03-04 06:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-05-15 07:29 - 2015-03-04 06:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-05-15 07:29 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-05-15 07:29 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-05-15 07:29 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-05-15 07:29 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2015-05-15 07:29 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2015-05-15 07:29 - 2015-01-29 05:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll 2015-05-15 07:29 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll 2015-05-15 06:17 - 2015-05-15 06:40 - 00036991 _____ () C:\Users\HN\Downloads\Addition.txt 2015-05-15 06:07 - 2015-05-15 06:40 - 00043683 _____ () C:\Users\HN\Downloads\FRST.txt 2015-05-15 06:06 - 2015-05-19 22:03 - 00000000 ____D () C:\FRST 2015-05-15 06:04 - 2015-05-19 22:02 - 02107904 _____ (Farbar) C:\Users\HN\Desktop\FRST64.exe 2015-05-10 18:40 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-05-10 18:40 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-05-10 18:40 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-05-10 18:40 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-05-10 18:40 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-05-10 18:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-05-10 18:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-05-10 18:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-05-10 18:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-05-10 18:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-05-10 18:39 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-05-10 18:39 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-05-10 18:39 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2015-05-10 18:39 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2015-05-10 18:39 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-05-10 18:39 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-05-10 18:39 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-05-10 18:38 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-05-10 18:38 - 2015-03-13 06:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-05-10 18:38 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-05-10 18:38 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-05-10 18:38 - 2015-03-13 06:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-05-10 18:38 - 2015-03-13 05:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-05-10 18:38 - 2015-03-13 05:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-05-10 18:38 - 2015-03-13 05:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-05-10 18:38 - 2015-03-13 05:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-05-10 18:38 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-05-10 18:38 - 2015-03-13 05:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-05-10 18:38 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-05-10 18:38 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-05-10 18:38 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-05-10 18:38 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-05-10 18:38 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-05-10 18:38 - 2015-03-13 05:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-05-10 18:38 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-05-10 18:38 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-05-10 18:38 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-05-10 18:38 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-05-10 18:38 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-05-10 18:38 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-05-10 18:38 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-05-10 18:38 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-05-10 18:38 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-05-10 18:38 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-05-10 18:38 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-05-10 18:38 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-05-10 18:38 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-05-10 18:38 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-05-10 18:38 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-05-10 18:38 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-05-10 18:38 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-05-10 18:38 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-05-10 18:38 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-05-10 18:38 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-05-10 18:38 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-05-10 18:38 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-05-10 18:38 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-05-10 18:37 - 2015-04-02 02:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-05-10 18:37 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-05-10 18:37 - 2015-03-13 06:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-05-10 18:37 - 2015-03-13 06:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-05-10 18:37 - 2015-03-13 06:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-05-10 18:37 - 2015-03-13 06:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-05-10 18:37 - 2015-03-13 06:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-05-10 18:37 - 2015-03-13 05:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-05-10 18:37 - 2015-03-13 05:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-05-10 18:37 - 2015-03-13 05:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-05-10 18:37 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-05-10 18:37 - 2015-03-13 05:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-05-10 18:37 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-05-10 18:37 - 2015-03-13 05:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-05-10 18:37 - 2015-03-13 05:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-05-10 18:37 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-05-10 18:37 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-05-10 18:37 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-05-10 18:36 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-05-10 18:36 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-05-10 18:36 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-05-02 11:08 - 2015-05-19 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-19 18:48 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-19 18:48 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-19 18:48 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-19 18:48 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-19 18:48 - 2015-03-17 07:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-19 18:48 - 2015-03-17 07:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-19 18:48 - 2015-03-17 07:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-19 18:48 - 2015-03-17 07:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-19 18:48 - 2015-03-17 07:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-04-19 18:48 - 2015-03-17 07:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-04-19 18:48 - 2015-03-17 07:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-19 18:48 - 2015-03-17 07:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-19 18:48 - 2015-03-17 07:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-19 18:48 - 2015-03-17 07:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-04-19 18:48 - 2015-03-17 07:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-04-19 18:48 - 2015-03-17 07:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-19 18:48 - 2015-03-17 07:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-19 18:48 - 2015-03-17 07:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-19 18:48 - 2015-03-17 07:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-04-19 18:48 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-04-19 18:48 - 2015-03-17 06:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-04-19 18:48 - 2015-03-17 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-04-19 18:48 - 2015-03-17 06:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-04-19 18:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-04-19 18:48 - 2015-03-17 06:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-04-19 18:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-04-19 18:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-04-19 18:48 - 2015-03-17 05:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-04-19 18:48 - 2015-03-17 05:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-04-19 18:48 - 2015-03-17 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-04-19 10:08 - 2015-04-19 10:08 - 00408768 _____ () C:\Windows\Minidump\041915-27456-01.dmp 2015-04-19 09:40 - 2015-04-19 17:26 - 00000000 ____D () C:\Windows\Minidump 2015-04-19 09:06 - 2015-04-19 09:06 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-04-19 08:54 - 2015-04-19 09:07 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-19 22:03 - 2010-02-09 10:55 - 01720240 _____ () C:\Windows\WindowsUpdate.log 2015-05-19 21:50 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-19 21:50 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-19 21:45 - 2012-04-07 13:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-19 21:42 - 2011-04-16 16:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-19 21:39 - 2013-10-05 15:18 - 00008258 _____ () C:\Windows\setupact.log 2015-05-19 21:39 - 2010-02-09 19:45 - 00955300 _____ () C:\Windows\PFRO.log 2015-05-19 21:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-19 21:21 - 2013-03-30 00:37 - 00152744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-05-19 21:21 - 2013-03-30 00:37 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-05-19 21:20 - 2011-04-16 16:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-05-19 20:54 - 2010-02-10 13:03 - 00000000 ____D () C:\Users\Administrator 2015-05-19 20:27 - 2012-10-06 02:16 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-05-19 20:11 - 2009-08-10 22:20 - 00705086 _____ () C:\Windows\system32\perfh007.dat 2015-05-19 20:11 - 2009-08-10 22:20 - 00151454 _____ () C:\Windows\system32\perfc007.dat 2015-05-19 20:11 - 2009-07-14 07:13 - 01629348 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-19 19:33 - 2010-02-10 19:10 - 00002972 _____ () C:\Windows\System32\Tasks\{AC8C9665-45BA-48B9-84CC-7B24B1BC8A1F} 2015-05-19 19:19 - 2010-03-04 22:16 - 00000000 ____D () C:\Users\HN\Documents\Bluetooth FTP Share 2015-05-18 22:59 - 2010-02-14 20:11 - 00003918 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{FE69482A-A787-4E11-BB36-6B36DC5921D2} 2015-05-18 22:53 - 2010-02-09 11:07 - 00000000 ____D () C:\Users\HN 2015-05-18 22:32 - 2009-08-21 11:14 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-05-18 22:15 - 2013-12-20 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-05-18 22:14 - 2013-12-20 16:34 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2015-05-18 22:14 - 2013-12-20 16:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2015-05-17 18:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2015-05-17 15:49 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-05-17 15:44 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2015-05-17 14:26 - 2012-07-29 19:02 - 00000000 ____D () C:\Users\HN\AppData\Local\Downloaded Installations 2015-05-17 14:26 - 2010-07-29 20:32 - 00000000 ____D () C:\Users\HN\AppData\Roaming\Nero 2015-05-17 14:26 - 2010-02-09 11:08 - 00000000 ____D () C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1} 2015-05-17 14:26 - 2010-02-09 11:07 - 00000000 ____D () C:\Users\HN\AppData\Local\Microsoft Help 2015-05-17 13:32 - 2010-02-18 07:51 - 00000432 _____ () C:\Windows\BRWMARK.INI 2015-05-17 12:09 - 2012-04-07 13:46 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-05-17 12:09 - 2010-02-09 11:07 - 00000000 ____D () C:\Users\HN\AppData\Local\Adobe 2015-05-17 12:08 - 2012-04-07 13:46 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-05-17 12:08 - 2011-05-15 17:14 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-05-17 08:15 - 2011-04-16 16:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-05-17 08:14 - 2011-04-16 16:20 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-05-15 08:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2015-05-02 11:13 - 2014-12-29 10:05 - 00000000 ____D () C:\Windows\system32\appraiser 2015-05-02 11:13 - 2014-05-10 19:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-05-02 11:11 - 2010-02-17 22:42 - 01607372 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-05-02 11:08 - 2010-02-10 19:00 - 00000000 ____D () C:\ProgramData\Skype 2015-05-02 11:07 - 2013-08-31 19:08 - 00000000 ____D () C:\Windows\system32\MRT 2015-05-02 10:58 - 2011-07-09 15:00 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-19 17:27 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-04-19 17:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-04-19 17:26 - 2010-02-09 11:07 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-19 17:26 - 2009-07-14 09:45 - 00000000 ___RD () C:\Users\Public\Recorded TV 2015-04-19 17:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2015-04-19 17:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2015-04-19 09:05 - 2012-07-29 19:30 - 00000000 ____D () C:\Temp ==================== Files in the root of some directories ======= 2010-07-13 10:18 - 2010-08-05 00:50 - 0007619 _____ () C:\Users\HN\AppData\Local\Resmon.ResmonCfg 2012-10-05 20:31 - 2012-10-05 20:31 - 0076359 _____ () C:\ProgramData\ezpyasyqxocngjn Some content of TEMP: ==================== C:\Users\HN\AppData\Local\Temp\avgnt.exe C:\Users\HN\AppData\Local\Temp\Quarantine.exe C:\Users\HN\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-15 07:50 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-05-2015 Ran by HN at 2015-05-19 22:06:24 Running from C:\Users\HN\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2065948893-2615235351-692522125-500 - Administrator - Enabled) => C:\Users\Administrator Gast (S-1-5-21-2065948893-2615235351-692522125-501 - Limited - Disabled) HN (S-1-5-21-2065948893-2615235351-692522125-1000 - Administrator - Enabled) => C:\Users\HN HomeGroupUser$ (S-1-5-21-2065948893-2615235351-692522125-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 2007 Microsoft Office system (HKLM-x32\...\PROHYBRIDR) (Version: 12.0.6612.1000 - Microsoft Corporation) 3D-Viewer-innoplus (HKLM-x32\...\{B96DB037-DBEA-4186-9081-9CBD537F82E8}) (Version: 14.00.231 - INNOVA-engineering GmbH) Accelerometer (HKLM-x32\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 1.06.08.11 - STMicroelectronics) Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader 9.1.3 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A91000000001}) (Version: 9.1.3 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Aladdin Monitor 1.4.2 (HKLM-x32\...\Aladdin Monitor 1.4.2) (Version: - ) AuthenTec Fingerprint Software (HKLM\...\{6B99AF03-2668-4572-BD3D-8C7A5D103065}) (Version: 8.5.1.28 - AuthenTec, Inc.) Avery Wizard 4.0 (HKLM-x32\...\{F5D84887-8A6F-4993-8560-B3AA44CB620D}) (Version: 4.0.201 - Avery) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG) BitTorrent (HKLM-x32\...\BitTorrent) (Version: - BitTorrent, Inc) Bluetooth Feature Pack 5.0 (HKLM\...\{B2F4C332-2359-4ADE-AF0C-C631768BBB89}) (Version: 5.0.9 - CSR Plc.) Bullzip PDF Printer 7.1.0.1140 (HKLM\...\Bullzip PDF Printer_is1) (Version: - Bullzip) cmTSS64 (HKLM\...\{E28D2D28-4A78-4A5D-B626-E63030DDFF3D}) (Version: 1.2 - charismathics) Garmin City Navigator Europe NT 2008 (HKLM-x32\...\{EEC8205A-E3DE-4C00-B60C-48E3B9B58B13}) (Version: 10.0.0.0 - Garmin Ltd or its subsidiaries) Garmin TOPO Deutschland v3 (HKLM-x32\...\{AE255C55-E0CF-4591-AA86-CAA19AA32C53}) (Version: 3.0.0.0 - Garmin Ltd or its subsidiaries) Garmin TOPO Österreich v2 (HKLM-x32\...\{7AA38575-25A1-4C2F-B40B-2188EB73FF0E}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{07A8ED9E-B98E-437F-B750-241B412BE924}) (Version: 1.0.0.0 - Garmin Ltd or its subsidiaries) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GPL Ghostscript Lite 8.70 (HKLM-x32\...\GPL Ghostscript Lite_is1) (Version: - ) Harmony Browser Plug-in (HKLM-x32\...\{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}) (Version: 2.0 - Logitech) Hartlauer Foto World (HKLM-x32\...\Hartlauer Foto World) (Version: 5.0.3 - CEWE COLOR AG u Co. OHG) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Management Engine Interface (HKLM\...\HECI) (Version: - Intel Corporation) Intel® Active-Management-Technologie (HKLM\...\MESOL) (Version: - Intel Corporation) Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) LoiLoScope Herunterladen (HKLM-x32\...\{C2A254F4-AC74-482F-8F09-DB2843AC2AAE}_is1) (Version: 2.0 - LoiLo inc) LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.1.94 - LSI Corporation) Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) MapSource (HKLM-x32\...\MapSource) (Version: - ) Medion GoPal Assistant 4.03.006 (HKLM-x32\...\Medion GoPal Assistant) (Version: 4.3.6.0 - Medion) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MobileSoftwareSuite (HKLM\...\{B28D8FCA-1983-496F-A8FF-295A7D26CC48}) (Version: 1.10.0032 - Fujitsu Technology Solutions) Mozilla Firefox 36.0.4 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 9 Essentials (HKLM-x32\...\{74946408-f3a1-42d6-aab7-477f9ea2ece1}) (Version: - Nero AG) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10 - NVIDIA Corporation) NVIDIA nView Desktop Manager (HKLM\...\NVIDIA nView Desktop Manager) (Version: 121.20 - NVIDIA Corporation) NVIDIA Performance Drivers (HKLM\...\{4C0A8D65-4286-4B58-87FE-18AD24289285}) (Version: 2.0.0.19 - NVIDIA Corporation) OZ776 SCR Driver V2.1.4.204A (HKLM-x32\...\InstallShield_{890C7D7F-D482-44B3-9E15-4C3A18853E71}) (Version: 2.1.4.204A - O2Micro) OZ776 SCR Driver V2.1.4.204A (Version: 2.1.4.204A - O2Micro) Hidden PHOTOfunSTUDIO 9.3 PE (HKLM-x32\...\{E33B3B6C-5712-4A39-B30D-1391918D920D}) (Version: 9.03.703 - Panasonic Corporation) Pro/ENGINEER Release Wildfire 4.0 Datecode C000 (HKLM-x32\...\Pro/ENGINEER Release Wildfire 4.0 Datecode C000) (Version: Wildfire 4.0 - PTC) PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5888 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.3.2.12064_10 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.3.2.12064_10 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.9.0 - SAMSUNG Electronics Co., Ltd.) ScBios64 (HKLM\...\{9DD58519-340D-467E-9988-1E55472A3FC1}) (Version: 2.0.0 - Fujitsu Siemens Computers) SmartCase Logon+ (HKLM\...\{3D093918-3EA6-43FE-ADD5-32DE22EE9B5E}) (Version: 3.0.1 - iC Compas GmbH Co KG) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.6.1 - Synaptics Incorporated) SystemDiagnostics (HKLM-x32\...\{EF59DB7F-7426-426E-B862-7031F83ED304}) (Version: 2.04.0006 - Fujitsu Technology Solutions) trustDesk basic (HKLM-x32\...\trustDesk basic) (Version: - ) TuneUp Utilities 2013 (HKLM-x32\...\TuneUp Utilities 2013) (Version: 13.0.4000.179 - TuneUp Software) TuneUp Utilities 2013 (x32 Version: 13.0.4000.179 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.179 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Wer wird Millionär (HKLM-x32\...\{766FF098-68AB-48BE-BF41-05708D178198}) (Version: 1.0.0.0000 - Eidos Interactive) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0) (HKLM\...\45A7283175C62FAC673F913C1F532C5361F97841) (Version: 03/08/2007 2.2.1.0 - Garmin) Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16422 - Microsoft Corporation) Windows-Treiberpaket - iC Compas GmbH & Co KG fcrimg4 LegacyDriver (06/15/2009 2.4.0.0) (HKLM\...\0365BFF3019A5A8F602931AC51B181DF57EC0773) (Version: 06/15/2009 2.4.0.0 - iC Compas GmbH & Co KG) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 02-05-2015 10:50:49 Windows Update 15-05-2015 05:53:10 Windows Update 17-05-2015 07:48:34 Revo Uninstaller's restore point - Ask Toolbar 17-05-2015 08:23:34 Revo Uninstaller's restore point - Avira SearchFree Toolbar plus Web Protection Updater 17-05-2015 13:54:47 TuneUp Utilities 2013 wird installiert 18-05-2015 22:12:04 Windows Update 19-05-2015 20:18:24 Revo Uninstaller's restore point - Skype™ 7.0 19-05-2015 20:22:10 Revo Uninstaller's restore point - Skype web features ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2015-05-17 15:44 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {16C5782E-EA59-4BD1-BD05-97EA02E4FD0C} - System32\Tasks\{6C4D9D7E-58BF-4D7C-8361-3CDB3CA6D088} => C:\Program Files (x86)\Cadmould\CMDB\6.0\Cmdb.exe Task: {31511DF8-7E6C-4E0E-BFCC-98510BD705E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.) Task: {34505848-CAB9-4D96-BC4B-2FB00FC57B4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-17] (Adobe Systems Incorporated) Task: {3F004500-D37E-40E9-BBD8-35D9EACCA30F} - System32\Tasks\{830834F3-F4D1-4E65-8FAF-79CC7A580C13} => C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\uiStub.exe Task: {46C7D39A-72D4-4638-B6F4-DB529D9A34AE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {668661DD-7BA1-4C03-BBD1-CFEDC2C26775} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {69A7A05C-BEA0-47F8-9CC5-F7CEDBB8F2DE} - System32\Tasks\{B0448F5C-10D8-49A9-B16D-09B5D41174FB} => C:\Program Files (x86)\Cadmould\CMDB\6.0\Cmdb.exe Task: {7E0CB445-0D07-4183-BF77-4F6DB6662E0C} - System32\Tasks\{AC8C9665-45BA-48B9-84CC-7B24B1BC8A1F} => C:\Program Files (x86)\Skype\Phone\Skype.exe Task: {83F7E319-A9CF-45C8-9C02-56CE3B50B4F0} - System32\Tasks\Microsoft\Windows\SyncCenter\S-1-5-21-2065948893-2615235351-692522125-1000\{750FDF10-2A26-11D1-A3EA-080036587F03}\Offlinedateien-Synchronisierungszeitplan 1 => C:\Windows\system32\mobsync.exe [2010-11-20] (Microsoft Corporation) Task: {8F692F5B-944E-4A7D-B419-63A46426CA0D} - System32\Tasks\{847E9D9E-46E5-4E33-B98D-25FDEE169C43} => C:\Program Files (x86)\Cadmould\CMDB\6.0\Cmdb.exe Task: {BEA4DFB4-8A83-4498-BEF6-4942E59837BC} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {C504E839-F0D3-4358-90C2-D49C777508DF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.) Task: {E1E1E5F3-AB60-4D0B-AE08-58B5273C89E6} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {E30BC9F2-C942-4572-B2D1-22CD26689F76} - System32\Tasks\{EB051E5A-BF54-4054-AC72-EA78C1FFCD38} => C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\uiStub.exe Task: {F82E8AE6-0AF0-4CA9-9687-AD7E7B3C097B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2013-12-10] (TuneUp Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2013-12-10 19:45 - 2013-12-10 19:45 - 00753464 _____ () C:\Program Files (x86)\TuneUp Utilities 2013\avgrepliba.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2065948893-2615235351-692522125-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 10.0.0.138 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe FirewallRules: [TCP Query User{0CE5EB35-ECED-4309-A2F2-B63A39AD1F95}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [UDP Query User{7A90503E-4E1D-44B8-BC8A-37C8B7F53F15}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [TCP Query User{2FE0F6D7-3C2C-4018-B2F1-D63FD46688D7}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [UDP Query User{9A806442-C435-46B6-AD84-4CD74018138A}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [TCP Query User{57D20444-D8EC-4B28-B5A2-36818CFBC1B4}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [UDP Query User{0558A4B9-C3D1-4559-A5CD-EDD157ECA19D}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [TCP Query User{3DF98FD8-DF48-412C-BCC6-032086E12A23}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [UDP Query User{F2028681-9631-4BB5-AC3F-2E53188BF14D}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\xtop.exe FirewallRules: [TCP Query User{C1DD0FBA-ED50-4406-96DB-33BC8C69B457}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [UDP Query User{802C905D-EB5F-4926-A341-F4526F56C1C0}C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe] => (Block) C:\program files (x86)\proewildfire 4.0\i486_nt\obj\pro_comm_msg.exe FirewallRules: [{0D6653F6-A82D-486A-AA1A-679E26B90503}] => (Allow) C:\Windows\System32\hasplms.exe FirewallRules: [{FBF3F50C-9A47-48D3-8258-1C7A022F7671}] => (Allow) C:\Windows\System32\hasplms.exe FirewallRules: [TCP Query User{F2BDD739-53AE-4827-96A8-882BB69FCCF3}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Allow) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [UDP Query User{765547BE-A25C-4844-A842-12443891594D}C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe] => (Allow) C:\program files (x86)\proewildfire 4.0\i486_nt\nms\nmsd.exe FirewallRules: [TCP Query User{1B18C282-FC3F-470A-B4AE-BB2C58B116E4}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{1BE4A3B1-B4CF-46F0-8350-3D04E976151C}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [{3080844A-F7B5-4273-BFB5-606982E3B4C0}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{31237843-4E7E-42A9-B872-A249D7BB4716}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{5C62222F-0CBC-4DE2-9C28-17A123440E72}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{3D92D94C-5187-45AF-8EB6-C3195AB8B76F}] => (Allow) C:\Windows\System32\dmwu.exe FirewallRules: [{35CAC9C2-F830-4A18-89E3-83842F7E37F7}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{2C596396-260F-4624-AD0C-98A4BBC11583}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe FirewallRules: [{D4181E90-F22D-4137-AAA4-1BD1D8B74B60}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{EA7ABFEC-6EC8-4F59-8AA5-DC8D69296885}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/19/2015 00:10:27 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101). Error: (05/18/2015 10:42:54 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm AcroRd32.exe, Version 9.1.0.163 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 138c Startzeit: 01d091aa6c78be11 Endzeit: 2811 Anwendungspfad: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe Berichts-ID: 48699fa9-fd9e-11e4-895b-00225feed621 Error: (05/17/2015 02:01:16 PM) (Source: MsiInstaller) (EventID: 11321) (User: H265-W7P) Description: Produkt: TuneUp Utilities 2013 -- Fehler 1321. Das Installationsprogramm besitzt keine ausreichenden Berechtigungen, um diese Datei zu ändern: C:\Program Files (x86)\TuneUp Utilities 2013\Shredder.exe. Systemfehler 5. Error: (05/03/2015 06:54:28 PM) (Source: Microsoft Office 12) (EventID: 2000) (User: ) Description: Accepted Safe Mode action : Microsoft Office Outlook. Error: (04/09/2015 08:34:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000004e4e4 ID des fehlerhaften Prozesses: 0x520 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Error: (04/04/2015 08:26:44 AM) (Source: Windows Search Service) (EventID: 3084) (User: ) Description: Fehler beim Laden des Protokollhandlers Csc. Fehlerbeschreibung: Es wurde versucht, einen Registrierungsschlüssel einem unzulässigen Vorgang zu unterziehen, der zum Löschen markiert wurde. (HRESULT : 0x800703fa). Error: (02/07/2015 11:09:42 AM) (Source: Microsoft Office 12) (EventID: 2001) (User: ) Description: Rejected Safe Mode action : Microsoft Office Outlook. Error: (02/07/2015 10:54:47 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm AcroRd32.exe, Version 9.1.0.163 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a30 Startzeit: 01d042b21dc6f70d Endzeit: 6272 Anwendungspfad: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe Berichts-ID: de4bd900-aea6-11e4-86b7-00225feed621 Error: (02/01/2015 05:33:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm xtop.exe, Version 27.0.2007.170 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 16ec Startzeit: 01d03e33687e7ad8 Endzeit: 203 Anwendungspfad: C:\Program Files (x86)\proeWildfire 4.0\i486_nt\obj\xtop.exe Berichts-ID: 92f5a8bb-aa27-11e4-86b7-00225feed621 Error: (12/06/2014 06:30:27 PM) (Source: Application Error) (EventID: 1005) (User: ) Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder der Datenträger fehlt. Das Programm rescue-system.exe wurde wegen dieses Fehlers geschlossen. Programm: rescue-system.exe Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet. Benutzeraktion 1. Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE. 4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt. Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche Daten Fehlerwert: C0000013 Datenträgertyp: 0 System errors: ============= Error: (05/19/2015 09:53:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/19/2015 09:53:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Microsoft .NET Framework NGEN v4.0.30319_X86" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/19/2015 09:53:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Microsoft .NET Framework NGEN v4.0.30319_X64" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/19/2015 09:53:01 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/19/2015 09:52:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Email-Schutz" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/19/2015 09:52:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Intel(R) Management and Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/19/2015 09:52:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "NVIDIA Performance Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/19/2015 09:52:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/19/2015 09:52:33 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "MBAMScheduler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/19/2015 09:52:33 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Agere Modem Call Progress Audio" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Microsoft Office Sessions: ========================= Error: (11/16/2014 07:13:03 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6707.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 101 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/19/2010 10:17:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 256 seconds with 120 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-05-17 15:43:01.211 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-05-17 15:43:01.102 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T9600 @ 2.80GHz Percentage of memory in use: 64% Total physical RAM: 2026.68 MB Available physical RAM: 723.73 MB Total Pagefile: 4053.37 MB Available Pagefile: 2378.38 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:296.08 GB) (Free:174.42 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 27987793) Partition 1: (Active) - (Size=2 GB) - (Type=27) Partition 2: (Not Active) - (Size=296.1 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
20.05.2015, 12:28 | #10 |
/// the machine /// TB-Ausbilder | Laptop Fujitsu Celsius H265 wird immer langsamerESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Laptop Fujitsu Celsius H265 wird immer langsamer |
fujitsu, langsame, langsamer, laptop, ratschläge |