|
Plagegeister aller Art und deren Bekämpfung: Antivirenprogramme werden ausgeschaltenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.08.2015, 12:28 | #1 |
| Antivirenprogramme werden ausgeschalten Guten Tag! Seit knapp 48 Stunden versuche ich die schädliche Software (die es ja scheinbar geben muss) von unserem Laptop zu werfen. Haben uns gestern GData gekauft und es durchlaufen lassen, weil McAfee keinen Scan mehr durchlaufen lassen konnte. GData hat folgendes Ergebnis erzielt: Virus: Win32.Trojan.Agent.GE8D27 (Engine B) Virus: Win32.Application.OpenCandy.O (Engine B) Virus: Win32.Application.OpenCandy.O Das Zeug ist aber mittlerweile verschwunden. Aber es wird immer noch McAfee ausgeschalten und weitere Scans mit GData führen zu nichts. Habe auch schon folgende Programme drüber laufen lassen: Security Task Manager, SUPERAntiSpyware Free, CCleaner, Trojan Remover. Ich habe den Laptop sogar vor zwei Tagen zurückgesetzt, weil er so unglaublich langsam lief und nun läuft er zwar recht schnell, aber er scheint schon wieder langsamer zu werden. Wäre nett, wenn uns also jemand helfen könnte! |
23.08.2015, 12:32 | #2 |
/// Selecta Jahrusso | Antivirenprogramme werden ausgeschalten Wäre es nicht am einfachsten, ihn erneut zurück zu setzen ?
__________________Alleine schon, dass du einfach blind irgendwelche Schrotttools über das System laufen hast lassen, wär für mich schon ein Grund dazu. Wenn du denkst, wir sollen uns ein 2 Tage altes System ansehen, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ |
23.08.2015, 12:59 | #3 |
| Antivirenprogramme werden ausgeschalten FRST.txt
__________________Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:21-08-2015 03 durchgeführt von Helmut (Administrator) auf KEVIN (23-08-2015 13:43:42) Gestartet von C:\Users\Helmut\Downloads Geladene Profile: Helmut (Verfügbare Profile: Helmut & Administrator) Platform: Windows 8 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 10 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe (Broadcom Corp.) C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Dritek System INC.) C:\Windows\RfBtnSvc64.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Daum Kakao Corp. ) C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe (Spotify Ltd) C:\Users\Helmut\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (G DATA Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (G DATA Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\GUI\GDSC.exe (Adobe Systems Incorporated) C:\Users\Helmut\Downloads\flashplayer18_ha_install.exe (Adobe Systems Incorporated) C:\Users\Helmut\Downloads\flashplayer18_ha_install.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3008824 2012-11-29] (Synaptics Incorporated) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1527896 2012-06-22] (McAfee, Inc.) HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2013-11-13] (Dritek System Inc.) HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe [1864312 2015-06-16] (G DATA Software AG) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G DATA\InternetSecurity\AVKTray\AVKTray.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4249919967-2187548655-1386870330-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd) HKU\S-1-5-21-4249919967-2187548655-1386870330-1001\...\Run: [KakaoTalk] => C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe [6331544 2015-08-20] (Daum Kakao Corp. ) HKU\S-1-5-21-4249919967-2187548655-1386870330-1001\...\Run: [Spotify Web Helper] => C:\Users\Helmut\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-08-21] (Spotify Ltd) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Keine Datei ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) HKU\S-1-5-21-4249919967-2187548655-1386870330-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006 HKU\S-1-5-21-4249919967-2187548655-1386870330-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKU\S-1-5-21-4249919967-2187548655-1386870330-1001 -> DefaultScope {F31A8A4A-DFA0-4B45-88C5-6A69F077EA01} URL = SearchScopes: HKU\S-1-5-21-4249919967-2187548655-1386870330-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKU\S-1-5-21-4249919967-2187548655-1386870330-1001 -> {F31A8A4A-DFA0-4B45-88C5-6A69F077EA01} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation) BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20150822115549.dll [2012-06-22] (McAfee, Inc.) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation) BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20150822115549.dll [2012-06-22] (McAfee, Inc.) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-08-04] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-08-04] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2012-05-14] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2012-05-14] (McAfee, Inc.) Tcpip\..\Interfaces\{0E925F35-3A68-4620-8551-FECD61EE61A3}: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-23] () FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2012-05-14] () FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-23] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\progra~2\mcafee\msc\npmcsn~1.dll [2012-05-14] () FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.169\npGoogleUpdate3.dll [2015-08-21] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.169\npGoogleUpdate3.dll [2015-08-21] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation) FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-02-02] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore [2013-02-02] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-02-02] Chrome: ======= CHR Profile: C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-21] CHR Extension: (Google Docs) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-21] CHR Extension: (Google Drive) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-21] CHR Extension: (YouTube) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-21] CHR Extension: (Google Search) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-21] CHR Extension: (Google Sheets) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-21] CHR Extension: (SiteAdvisor) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-08-21] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-21] CHR Extension: (Gmail) - C:\Users\Helmut\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-21] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-08-22] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-08-22] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2558072 2015-06-19] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe [966776 2015-06-16] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe [3711712 2015-06-16] (G Data Software AG) R2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.) [Datei ist nicht signiert] R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-19] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated) R3 GDFwSvc; C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe [3202368 2015-06-19] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [789624 2015-06-16] (G Data Software AG) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [155368 2015-08-04] (McAfee, Inc.) S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [332080 2012-01-27] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.) S2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.) S2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [383608 2012-05-22] (McAfee, Inc.) S2 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.) S4 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [237920 2012-06-22] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.) S2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.) R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2013-11-13] (Dritek System INC.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) S2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [158720 2015-08-22] (G Data Software AG) S0 GDElam; C:\Windows\System32\DRIVERS\GDElam.sys [117904 2015-01-08] (G Data Software AG) R3 GDKBB; C:\WINDOWS\system32\drivers\GDKBB64.sys [27648 2015-08-22] (G Data Software AG) R3 GDKBFlt; C:\WINDOWS\system32\drivers\GDKBFlt64.sys [20992 2015-08-22] (G Data Software AG) R1 GDMnIcpt; C:\WINDOWS\system32\drivers\MiniIcpt.sys [230912 2015-08-22] (G Data Software AG) R3 GDPkIcpt; C:\WINDOWS\system32\drivers\PktIcpt.sys [91648 2015-08-22] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [68608 2015-08-22] (G Data Software AG) R1 GRD; C:\WINDOWS\system32\drivers\GRD.sys [106272 2015-08-22] (G Data Software) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R1 HookCentre; C:\WINDOWS\system32\drivers\HookCentre.sys [125952 2015-08-22] (G Data Software AG) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.) U3 mfeavfk01; kein ImagePath S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.) S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106112 2012-06-22] (McAfee, Inc.) R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [37960 2015-08-04] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-11-13] (Dritek System Inc.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31032 2012-11-29] (Synaptics Incorporated) R4 ccSet_NARA; \SystemRoot\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-08-23 13:43 - 2015-08-23 13:44 - 00020808 _____ C:\Users\Helmut\Downloads\FRST.txt 2015-08-23 13:43 - 2015-08-23 13:43 - 00000000 ____D C:\FRST 2015-08-23 13:42 - 2015-08-23 13:43 - 04383777 _____ C:\Users\Helmut\Downloads\tdsskiller.zip 2015-08-23 13:42 - 2015-08-23 13:42 - 02173952 _____ (Farbar) C:\Users\Helmut\Downloads\FRST64.exe 2015-08-23 13:30 - 2015-08-23 13:30 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-08-23 13:30 - 2015-08-23 13:30 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-08-23 13:29 - 2015-08-23 13:29 - 00000000 ____D C:\Users\Helmut\AppData\Local\Adobe 2015-08-23 13:13 - 2015-08-23 13:13 - 01187032 _____ (Adobe Systems Incorporated) C:\Users\Helmut\Downloads\flashplayer18_ha_install.exe 2015-08-23 12:49 - 2015-08-23 13:07 - 00000000 ____D C:\ProgramData\SecTaskMan 2015-08-23 12:49 - 2015-08-23 12:49 - 00001166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk 2015-08-23 12:49 - 2015-08-23 12:49 - 00001155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk 2015-08-23 12:49 - 2015-08-23 12:49 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2015-08-23 12:46 - 2015-08-23 12:47 - 02816040 _____ C:\Users\Helmut\Downloads\SecurityTaskManager_Setup.exe 2015-08-23 12:42 - 2015-08-23 12:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2015-08-23 12:35 - 2015-08-23 12:35 - 00430040 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-08-23 12:00 - 2015-08-23 12:05 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-08-23 12:00 - 2015-07-28 10:59 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-08-23 11:48 - 2015-01-09 08:43 - 00951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2015-08-23 11:48 - 2015-01-09 07:03 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2015-08-23 11:48 - 2015-01-09 01:52 - 00478296 _____ C:\WINDOWS\SysWOW64\locale.nls 2015-08-23 11:48 - 2015-01-09 01:52 - 00478296 _____ C:\WINDOWS\system32\locale.nls 2015-08-23 11:09 - 2015-08-23 11:09 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2015-08-23 10:53 - 2015-08-23 10:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-08-23 09:35 - 2013-04-09 06:51 - 14267904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2015-08-23 09:35 - 2013-04-09 06:51 - 03552768 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2015-08-23 09:35 - 2013-04-09 06:50 - 02107904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2015-08-23 09:35 - 2013-04-08 23:52 - 11878912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2015-08-23 09:35 - 2013-04-08 23:51 - 02767360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2015-08-23 09:34 - 2013-04-09 07:33 - 00446792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-08-23 09:34 - 2013-04-09 07:20 - 00306952 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_10ec.dll 2015-08-23 09:34 - 2013-04-09 07:14 - 01455880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2015-08-23 09:34 - 2013-04-09 06:52 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2015-08-23 09:34 - 2013-04-09 06:52 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2015-08-23 09:34 - 2013-04-09 06:50 - 01285632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2015-08-23 09:34 - 2013-04-09 06:49 - 01444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll 2015-08-23 09:34 - 2013-04-09 04:33 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2015-08-23 09:34 - 2013-04-09 04:32 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys 2015-08-23 09:34 - 2013-04-08 23:52 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2015-08-23 09:34 - 2013-04-08 23:51 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2015-08-23 09:34 - 2013-04-08 23:51 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll 2015-08-23 09:34 - 2013-04-08 23:51 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2015-08-23 09:34 - 2013-03-16 00:05 - 00298456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll 2015-08-23 09:33 - 2013-04-09 07:33 - 00489576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-08-23 09:33 - 2013-04-09 07:33 - 00253544 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-08-23 09:33 - 2013-04-09 06:52 - 00804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2015-08-23 09:33 - 2013-04-09 06:51 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2015-08-23 09:33 - 2013-04-09 06:51 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 2015-08-23 09:33 - 2013-04-09 06:51 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2015-08-23 09:33 - 2013-04-09 06:51 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2015-08-23 09:33 - 2013-04-09 06:51 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe 2015-08-23 09:33 - 2013-04-09 06:50 - 00435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2015-08-23 09:33 - 2013-04-09 06:49 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2015-08-23 09:33 - 2013-04-09 06:49 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll 2015-08-23 09:33 - 2013-04-09 06:49 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2015-08-23 09:33 - 2013-04-09 04:31 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2015-08-23 09:33 - 2013-04-09 01:37 - 00426024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-08-23 09:33 - 2013-04-09 01:37 - 00324368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-08-23 09:33 - 2013-04-08 23:52 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2015-08-23 09:33 - 2013-04-08 23:51 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2015-08-23 09:33 - 2013-04-05 01:30 - 00503080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-08-23 09:33 - 2013-03-30 20:16 - 01403784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2015-08-23 09:33 - 2013-03-30 20:16 - 01267424 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2015-08-23 09:33 - 2013-03-29 00:09 - 01217328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2015-08-23 09:33 - 2013-03-29 00:09 - 01093880 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2015-08-23 09:33 - 2013-03-16 00:05 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll 2015-08-23 09:32 - 2013-04-09 07:18 - 00077960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdvm.dll 2015-08-23 09:32 - 2013-04-09 06:52 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2015-08-23 09:32 - 2013-04-09 06:52 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe 2015-08-23 09:32 - 2013-04-09 06:49 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll 2015-08-23 09:32 - 2013-04-09 06:49 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhengine.dll 2015-08-23 09:32 - 2013-04-09 06:49 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2015-08-23 09:32 - 2013-04-09 01:44 - 00123880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2015-08-23 09:32 - 2013-04-08 23:52 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2015-08-23 09:32 - 2013-04-08 23:52 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe 2015-08-23 09:32 - 2013-04-08 23:51 - 00659456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2015-08-23 09:32 - 2013-04-08 23:51 - 00361984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2015-08-23 09:32 - 2013-04-08 23:51 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2015-08-23 09:32 - 2013-04-08 23:51 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll 2015-08-23 09:32 - 2013-03-02 12:39 - 00069864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2015-08-23 09:32 - 2013-02-02 10:40 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsRasterService.dll 2015-08-23 09:32 - 2013-02-02 10:23 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsRasterService.dll 2015-08-23 09:31 - 2013-04-09 07:20 - 00086280 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll 2015-08-23 09:31 - 2013-04-09 06:51 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2015-08-23 09:31 - 2013-04-09 06:50 - 00745984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2015-08-23 09:31 - 2013-04-09 06:50 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenuineCenter.dll 2015-08-23 09:31 - 2013-04-09 06:50 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2015-08-23 09:31 - 2013-04-09 06:50 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2015-08-23 09:31 - 2013-04-09 06:50 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msshooks.dll 2015-08-23 09:31 - 2013-04-09 06:49 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\fmifs.dll 2015-08-23 09:31 - 2013-04-09 04:34 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys 2015-08-23 09:31 - 2013-04-09 04:33 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2015-08-23 09:31 - 2013-04-09 04:31 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2015-08-23 09:31 - 2013-04-08 23:52 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll 2015-08-23 09:31 - 2013-04-08 23:51 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll 2015-08-23 09:31 - 2013-04-08 23:51 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssphtb.dll 2015-08-23 09:31 - 2013-04-08 23:51 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fmifs.dll 2015-08-23 09:31 - 2013-04-08 23:51 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll 2015-08-23 09:31 - 2013-04-08 23:51 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msshooks.dll 2015-08-23 09:31 - 2013-01-10 03:40 - 00303848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2015-08-23 09:31 - 2012-12-13 06:00 - 00002048 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2015-08-23 09:31 - 2012-12-13 05:59 - 00002048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2015-08-23 09:14 - 2013-05-04 08:59 - 13644288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2015-08-23 09:14 - 2013-05-04 08:59 - 01483776 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 2015-08-23 09:14 - 2013-05-04 08:59 - 00760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-08-23 09:14 - 2013-05-04 08:58 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll 2015-08-23 09:14 - 2013-05-04 08:58 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2015-08-23 09:14 - 2013-05-04 08:58 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll 2015-08-23 09:14 - 2013-05-04 08:57 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2015-08-23 09:14 - 2013-05-04 08:57 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll 2015-08-23 09:14 - 2013-05-04 06:57 - 10788864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2015-08-23 09:14 - 2013-05-04 06:57 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ubpm.dll 2015-08-23 09:14 - 2013-05-04 06:56 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll 2015-08-23 09:14 - 2013-05-04 06:47 - 00427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2015-08-23 09:13 - 2013-05-04 09:34 - 00284416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2015-08-23 09:13 - 2013-05-04 08:59 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe 2015-08-23 09:13 - 2013-05-04 08:58 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2015-08-23 09:13 - 2013-05-04 08:58 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2015-08-23 09:13 - 2013-05-04 08:58 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2015-08-23 09:13 - 2013-05-04 08:57 - 00708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2015-08-23 09:13 - 2013-05-04 08:57 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2015-08-23 09:13 - 2013-05-04 06:58 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-08-23 09:13 - 2013-05-04 06:57 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2015-08-23 09:13 - 2013-05-04 06:57 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll 2015-08-23 09:13 - 2013-05-04 06:51 - 00014848 _____ (Microsoft) C:\WINDOWS\system32\rars.rs 2015-08-23 09:13 - 2013-05-04 06:10 - 00014848 _____ (Microsoft) C:\WINDOWS\SysWOW64\rars.rs 2015-08-23 09:13 - 2013-03-02 04:45 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhost.exe 2015-08-23 09:13 - 2013-03-02 04:45 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-08-23 09:12 - 2013-05-04 09:58 - 00120736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe 2015-08-23 09:12 - 2013-05-04 08:57 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2015-08-23 09:12 - 2013-05-04 08:57 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2015-08-23 09:12 - 2013-05-04 08:57 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll 2015-08-23 09:12 - 2013-05-04 08:56 - 00419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl 2015-08-23 09:12 - 2013-05-04 06:58 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe 2015-08-23 09:12 - 2013-05-04 06:57 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll 2015-08-23 09:12 - 2013-05-04 06:56 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2015-08-23 09:12 - 2013-05-04 06:56 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll 2015-08-23 09:12 - 2013-05-04 06:55 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl 2015-08-23 09:12 - 2013-05-04 06:48 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2015-08-23 09:12 - 2013-05-04 06:48 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys 2015-08-23 09:12 - 2013-03-02 04:45 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostex.exe 2015-08-23 09:11 - 2013-05-04 08:59 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2015-08-23 09:11 - 2013-05-04 08:59 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-08-23 09:11 - 2013-05-04 08:59 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2015-08-23 09:11 - 2013-05-04 08:57 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\muifontsetup.dll 2015-08-23 09:11 - 2013-05-04 06:58 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2015-08-23 09:11 - 2013-05-04 06:58 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-08-23 09:11 - 2013-05-04 06:58 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2015-08-23 09:11 - 2013-05-04 06:57 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\npmproxy.dll 2015-08-23 09:11 - 2013-05-04 06:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\muifontsetup.dll 2015-08-23 09:11 - 2013-05-04 06:56 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2015-08-23 09:11 - 2013-02-02 10:39 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmproxy.dll 2015-08-23 09:11 - 2013-02-02 10:39 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmsprep.dll 2015-08-23 09:07 - 2013-05-31 01:24 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2015-08-23 09:07 - 2013-05-31 01:08 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2015-08-23 09:07 - 2013-05-15 04:25 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe 2015-08-23 09:07 - 2013-05-15 04:25 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll 2015-08-23 09:07 - 2013-05-15 04:24 - 00793088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe 2015-08-23 09:07 - 2013-05-15 04:24 - 00482816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll 2015-08-23 08:13 - 2015-03-04 08:41 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe 2015-08-23 08:13 - 2015-03-04 08:39 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2015-08-23 08:13 - 2015-03-04 08:39 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\aelupsvc.dll 2015-08-23 08:13 - 2015-03-04 06:53 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe 2015-08-23 08:13 - 2015-03-04 06:52 - 00676864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll 2015-08-23 08:12 - 2015-02-18 09:39 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2015-08-23 08:12 - 2015-02-18 09:38 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssdisai.dll 2015-08-23 08:12 - 2012-11-10 06:23 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2015-08-23 08:12 - 2012-11-10 06:22 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDWebAI.dll 2015-08-23 08:12 - 2012-11-10 06:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmHostAI.dll 2015-08-23 08:12 - 2012-11-10 06:20 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\appserverai.dll 2015-08-23 08:06 - 2015-06-09 15:09 - 00411133 _____ C:\WINDOWS\system32\ApnDatabase.xml 2015-08-23 07:58 - 2013-02-02 12:54 - 01933544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2015-08-23 07:58 - 2013-02-02 12:28 - 00993512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2015-08-23 07:58 - 2013-02-02 10:39 - 05090816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2015-08-23 07:58 - 2013-02-02 10:38 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\duser.dll 2015-08-23 07:58 - 2013-02-02 10:23 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlroamextension.dll 2015-08-23 07:58 - 2013-02-02 10:23 - 00475136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll 2015-08-23 07:58 - 2013-02-02 10:23 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2015-08-23 07:58 - 2013-02-02 10:23 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll 2015-08-23 07:58 - 2013-02-02 10:22 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2015-08-23 07:58 - 2013-02-02 10:21 - 05977600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2015-08-23 07:58 - 2013-02-02 10:20 - 00729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll 2015-08-23 07:58 - 2013-02-02 10:20 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\system32\hotspotauth.dll 2015-08-23 07:58 - 2013-02-02 09:25 - 00037632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys 2015-08-23 07:57 - 2013-02-02 13:19 - 00329960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2015-08-23 07:57 - 2013-02-02 13:19 - 00061672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys 2015-08-23 07:57 - 2013-02-02 10:40 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlroamextension.dll 2015-08-23 07:57 - 2013-02-02 10:40 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll 2015-08-23 07:57 - 2013-02-02 10:40 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2015-08-23 07:57 - 2013-02-02 10:40 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2015-08-23 07:57 - 2013-02-02 10:40 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tasklist.exe 2015-08-23 07:57 - 2013-02-02 10:40 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskkill.exe 2015-08-23 07:57 - 2013-02-02 10:39 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll 2015-08-23 07:57 - 2013-02-02 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskkill.exe 2015-08-23 07:57 - 2013-02-02 10:24 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\tasklist.exe 2015-08-23 07:57 - 2013-02-02 10:23 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll 2015-08-23 07:57 - 2013-02-02 10:23 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll 2015-08-23 07:57 - 2013-02-02 10:21 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll 2015-08-23 07:57 - 2013-02-02 09:25 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys 2015-08-23 07:56 - 2015-03-12 07:31 - 02048000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2015-08-23 07:56 - 2015-03-12 07:31 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPDShServiceObj.dll 2015-08-23 07:56 - 2015-03-12 05:52 - 01933312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll 2015-08-23 07:56 - 2013-02-02 07:41 - 01437184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2015-08-23 07:56 - 2013-02-02 07:31 - 01690624 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2015-08-23 07:55 - 2014-12-18 10:51 - 00096576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 2015-08-23 07:55 - 2014-12-18 08:52 - 00889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2015-08-23 07:55 - 2014-12-18 08:51 - 01160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2015-08-23 07:55 - 2014-12-18 08:50 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2015-08-23 07:55 - 2014-12-18 08:20 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2015-08-23 07:55 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 2015-08-23 07:55 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2015-08-23 07:55 - 2013-04-03 01:37 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdlg.dll 2015-08-23 07:55 - 2013-04-03 01:12 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdlg.dll 2015-08-23 07:54 - 2013-03-06 08:31 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll 2015-08-23 07:53 - 2014-11-26 08:43 - 00778240 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2015-08-23 07:53 - 2014-11-26 06:50 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2015-08-23 07:53 - 2013-08-23 09:22 - 02062848 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2015-08-23 07:53 - 2013-08-23 03:44 - 01711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2015-08-23 07:53 - 2013-03-06 08:29 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll 2015-08-23 07:53 - 2013-03-06 07:03 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll 2015-08-23 07:52 - 2013-12-05 01:43 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll 2015-08-23 07:52 - 2013-12-05 01:37 - 00451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll 2015-08-23 07:48 - 2013-03-02 10:23 - 00375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2015-08-23 07:48 - 2013-03-02 04:44 - 01011200 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2015-08-23 07:47 - 2013-03-22 05:49 - 02382336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2015-08-23 07:47 - 2013-03-22 00:47 - 02851840 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2015-08-23 07:43 - 2014-10-11 09:44 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2015-08-23 07:43 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2015-08-23 07:31 - 2015-07-29 16:45 - 01412608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2015-08-23 07:31 - 2015-07-29 16:45 - 00035328 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2015-08-23 07:31 - 2015-07-29 15:52 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2015-08-23 07:31 - 2015-07-29 15:52 - 01280000 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2015-08-23 07:31 - 2015-07-29 15:52 - 00046080 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2015-08-23 07:31 - 2015-07-28 00:42 - 00304128 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2015-08-23 07:31 - 2015-07-28 00:40 - 04064768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-08-23 07:31 - 2015-07-28 00:40 - 00366592 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2015-08-23 07:27 - 2015-01-24 08:43 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll 2015-08-23 07:27 - 2015-01-24 07:00 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll 2015-08-23 07:26 - 2014-12-06 09:53 - 00458240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-08-23 07:26 - 2014-12-06 09:53 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2015-08-23 07:26 - 2014-12-06 09:51 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2015-08-23 07:26 - 2014-12-06 09:51 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-08-23 07:26 - 2014-12-06 09:50 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-08-23 07:26 - 2014-12-06 08:10 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2015-08-23 07:26 - 2014-12-06 08:10 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-08-23 07:26 - 2014-12-06 08:09 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2015-08-23 07:26 - 2014-10-03 03:21 - 00522728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-08-23 07:26 - 2014-10-03 00:29 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-08-23 07:26 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2015-08-23 07:26 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2015-08-23 07:21 - 2013-10-10 11:32 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe 2015-08-23 07:21 - 2013-10-10 11:30 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll 2015-08-23 07:21 - 2013-10-10 11:24 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx 2015-08-23 07:21 - 2013-10-10 11:23 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe 2015-08-23 07:21 - 2013-10-10 11:22 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll 2015-08-23 07:21 - 2013-10-10 11:22 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll 2015-08-23 07:20 - 2013-10-10 11:30 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll 2015-08-23 07:15 - 2014-12-19 06:35 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2015-08-23 07:14 - 2014-03-11 02:41 - 00559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll 2015-08-23 07:14 - 2014-03-11 02:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dimsroam.dll 2015-08-23 07:14 - 2014-03-11 02:38 - 00684032 _____ (Microsoft Corporation) C:\WINDOWS\system32\objsel.dll 2015-08-23 07:14 - 2014-03-11 02:38 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2015-08-23 07:14 - 2014-03-11 02:38 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dimsroam.dll 2015-08-23 06:52 - 2013-07-02 03:41 - 00447320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2015-08-23 06:52 - 2013-07-02 03:41 - 00337752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2015-08-23 06:52 - 2013-07-02 03:41 - 00213336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS 2015-08-23 06:49 - 2013-07-01 03:42 - 00623448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys 2015-08-23 06:49 - 2013-07-01 03:42 - 00498008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys 2015-08-23 06:49 - 2013-07-01 03:42 - 00079192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbehci.sys 2015-08-23 06:49 - 2013-07-01 03:42 - 00021848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys 2015-08-23 06:49 - 2013-06-29 05:07 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbuhci.sys 2015-08-23 06:48 - 2013-06-29 05:06 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2015-08-23 06:41 - 2015-05-09 01:39 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2015-08-23 06:41 - 2015-05-08 22:05 - 00668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2015-08-23 06:37 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL 2015-08-23 06:37 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL 2015-08-23 06:32 - 2015-06-11 22:29 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2015-08-23 06:32 - 2015-06-11 18:27 - 01024000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2015-08-23 06:31 - 2014-11-08 13:22 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll 2015-08-23 06:31 - 2014-11-08 08:57 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll 2015-08-23 06:30 - 2014-01-13 01:30 - 02238976 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2015-08-23 06:30 - 2014-01-13 01:30 - 02032640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2015-08-23 06:30 - 2013-11-20 02:15 - 03842560 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2015-08-23 06:30 - 2013-11-20 01:57 - 03288576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2015-08-23 06:24 - 2014-12-06 09:52 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-08-23 06:24 - 2014-12-06 09:52 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2015-08-23 06:24 - 2014-12-06 09:52 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2015-08-23 06:24 - 2014-12-06 08:09 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll 2015-08-23 06:24 - 2014-06-03 00:33 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll 2015-08-23 06:24 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2015-08-23 06:22 - 2015-07-15 18:09 - 06969688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-08-23 06:22 - 2015-07-15 18:09 - 00095064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys 2015-08-23 06:22 - 2015-07-15 18:06 - 01824296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2015-08-23 06:22 - 2015-07-15 15:49 - 01410000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2015-08-23 06:22 - 2015-07-15 15:29 - 01333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2015-08-23 06:22 - 2015-06-27 18:36 - 00171352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-08-23 06:22 - 2015-06-27 15:56 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2015-08-23 06:22 - 2015-06-27 15:55 - 00668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-08-23 06:22 - 2015-06-27 15:55 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2015-08-23 06:22 - 2015-06-27 15:46 - 00829952 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-08-23 06:22 - 2015-06-27 15:46 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2015-08-23 06:22 - 2015-06-27 15:46 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2015-08-23 06:22 - 2015-06-25 20:29 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2015-08-23 06:22 - 2015-06-25 20:27 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2015-08-23 06:22 - 2015-01-07 06:25 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2015-08-23 06:21 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2015-08-23 06:21 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2015-08-23 06:21 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll 2015-08-23 06:21 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2015-08-23 06:21 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2015-08-23 06:21 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2015-08-23 06:21 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2015-08-23 06:21 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2015-08-23 06:21 - 2013-03-02 11:59 - 00411880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2015-08-23 06:20 - 2015-06-15 17:22 - 08858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2015-08-23 06:20 - 2015-06-15 17:22 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2015-08-23 06:20 - 2015-06-15 17:20 - 10116608 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2015-08-23 06:20 - 2015-06-15 17:20 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2015-08-23 06:20 - 2014-06-13 01:34 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2015-08-23 06:20 - 2014-06-13 01:29 - 02146304 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-08-23 06:20 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2015-08-23 06:20 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2015-08-23 06:20 - 2013-09-28 05:35 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys 2015-08-23 06:20 - 2013-04-27 07:20 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2015-08-23 06:19 - 2015-06-15 17:22 - 02037760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2015-08-23 06:19 - 2015-06-15 17:22 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe 2015-08-23 06:19 - 2015-06-15 17:21 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe 2015-08-23 06:19 - 2015-06-15 17:19 - 02307072 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2015-08-23 06:19 - 2014-10-11 09:44 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll 2015-08-23 06:19 - 2014-10-11 07:57 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll 2015-08-23 06:19 - 2014-06-05 19:56 - 00112984 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe 2015-08-23 06:19 - 2013-02-12 02:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys 2015-08-23 06:17 - 2015-07-09 23:47 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe 2015-08-23 06:17 - 2015-07-09 23:47 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe 2015-08-23 06:17 - 2015-07-09 22:18 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe 2015-08-23 06:06 - 2015-05-02 08:28 - 00100184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys 2015-08-23 06:06 - 2015-05-02 05:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-08-23 06:06 - 2015-05-02 05:36 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-08-23 06:06 - 2015-04-14 00:09 - 00570248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-08-23 06:06 - 2015-01-15 13:44 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2015-08-23 06:06 - 2015-01-15 13:43 - 01282560 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-08-23 06:06 - 2015-01-15 12:00 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2015-08-23 06:06 - 2015-01-15 11:38 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2015-08-23 06:06 - 2015-01-15 11:09 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2015-08-23 06:06 - 2014-09-25 01:29 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll 2015-08-23 06:06 - 2014-09-25 01:01 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll 2015-08-23 06:06 - 2014-03-11 02:39 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe 2015-08-23 06:06 - 2014-03-11 02:38 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2015-08-23 06:06 - 2014-03-11 02:38 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll 2015-08-23 06:06 - 2014-03-10 03:27 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2015-08-23 01:16 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys 2015-08-22 23:37 - 2014-10-11 07:41 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll 2015-08-22 23:37 - 2014-10-11 07:05 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll 2015-08-22 23:37 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2015-08-22 23:37 - 2014-04-12 11:10 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2015-08-22 23:37 - 2014-04-12 11:09 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll 2015-08-22 23:37 - 2014-04-12 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll 2015-08-22 23:37 - 2014-04-12 11:07 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll 2015-08-22 23:37 - 2014-04-12 09:23 - 00178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdigest.dll 2015-08-22 23:37 - 2014-04-12 09:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll 2015-08-22 23:37 - 2014-04-12 09:22 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll 2015-08-22 23:37 - 2014-04-12 08:58 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\workerdd.dll 2015-08-22 23:35 - 2013-01-29 03:57 - 00035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 2015-08-22 23:35 - 2013-01-29 01:08 - 00230904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 2015-08-22 23:34 - 2015-04-25 05:41 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2015-08-22 23:34 - 2015-04-25 01:13 - 00652288 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2015-08-22 23:34 - 2014-10-23 14:47 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll 2015-08-22 23:34 - 2014-10-23 13:04 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll 2015-08-22 23:33 - 2015-04-06 07:36 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll 2015-08-22 23:33 - 2015-04-06 06:08 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll 2015-08-22 23:33 - 2015-02-17 08:54 - 19777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-08-22 23:33 - 2015-02-17 07:13 - 17561600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-08-22 23:32 - 2014-12-19 08:48 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-08-22 23:30 - 2014-06-11 00:44 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2015-08-22 23:30 - 2014-06-11 00:43 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2015-08-22 23:28 - 2013-11-01 07:38 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll 2015-08-22 23:28 - 2013-11-01 05:49 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll 2015-08-22 22:51 - 2015-08-22 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA INTERNET SECURITY 2015-08-22 22:40 - 2015-08-22 22:41 - 00285008 _____ C:\WINDOWS\Minidump\082215-34468-01.dmp 2015-08-22 22:40 - 2015-08-22 22:40 - 571852319 _____ C:\WINDOWS\MEMORY.DMP 2015-08-22 22:40 - 2015-08-22 22:40 - 00000000 ____D C:\WINDOWS\Minidump 2015-08-22 22:37 - 2014-10-30 09:20 - 01890816 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2015-08-22 22:37 - 2014-10-30 07:22 - 01569792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2015-08-22 18:26 - 2015-08-22 18:26 - 00106272 _____ (G Data Software) C:\WINDOWS\system32\Drivers\GRD.sys 2015-08-22 18:26 - 2015-08-22 18:26 - 00018160 _____ (G Data Software) C:\WINDOWS\system32\Drivers\GdPhyMem.sys 2015-08-22 18:18 - 2015-08-22 22:51 - 00091648 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\PktIcpt.sys 2015-08-22 18:17 - 2015-08-22 22:51 - 00001982 _____ C:\Users\Public\Desktop\G DATA INTERNET SECURITY.lnk 2015-08-22 18:17 - 2015-08-22 22:50 - 00230912 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\MiniIcpt.sys 2015-08-22 18:17 - 2015-08-22 22:50 - 00158720 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\GDBehave.sys 2015-08-22 18:17 - 2015-08-22 22:50 - 00125952 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\HookCentre.sys 2015-08-22 18:17 - 2015-08-22 22:50 - 00068608 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\gdwfpcd64.sys 2015-08-22 18:17 - 2015-08-22 18:17 - 00027648 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\GDKBB64.sys 2015-08-22 18:17 - 2015-08-22 18:17 - 00020992 _____ (G Data Software AG) C:\WINDOWS\system32\Drivers\GDKBFlt64.sys 2015-08-22 18:17 - 2015-08-22 18:17 - 00000779 _____ C:\Users\Helmut\AppData\Roaming\gdscan.log 2015-08-22 18:17 - 2015-08-22 18:17 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf 2015-08-22 18:17 - 2015-08-22 18:17 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_GDKBB64_01007.Wdf 2015-08-22 18:17 - 2015-08-22 18:17 - 00000000 _____ C:\Users\Helmut\AppData\Roaming\gdfw.log 2015-08-22 18:16 - 2015-08-22 22:50 - 00013972 _____ C:\WINDOWS\DPINST.LOG 2015-08-22 18:10 - 2015-08-22 18:10 - 00000000 ____D C:\Program Files (x86)\G DATA 2015-08-22 18:09 - 2015-08-22 22:51 - 00000000 ____D C:\ProgramData\G Data 2015-08-22 11:14 - 2014-05-15 03:02 - 00059424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-08-22 11:14 - 2014-05-15 00:43 - 03286528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-08-22 11:14 - 2014-05-15 00:43 - 01623040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2015-08-22 11:14 - 2014-05-15 00:43 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2015-08-22 11:14 - 2014-05-15 00:42 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2015-08-22 11:13 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-08-22 11:10 - 2015-08-23 01:30 - 00002759 _____ C:\WINDOWS\setupact.log 2015-08-22 11:10 - 2015-08-22 11:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2015-08-22 11:10 - 2015-08-22 11:10 - 00000000 _____ C:\WINDOWS\setuperr.log 2015-08-21 23:17 - 2015-08-21 23:20 - 119412110 _____ C:\Users\Helmut\Downloads\Nicht bestätigt 969614.crdownload 2015-08-21 23:14 - 2015-08-23 01:30 - 00000000 ____D C:\Users\Helmut\AppData\Local\Spotify 2015-08-21 23:14 - 2015-08-21 23:14 - 00001811 _____ C:\Users\Helmut\Desktop\Spotify.lnk 2015-08-21 23:14 - 2015-08-21 23:14 - 00001797 _____ C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2015-08-21 23:14 - 2015-08-21 23:14 - 00000000 ____D C:\Users\Helmut\AppData\Local\CEF 2015-08-21 23:13 - 2015-08-23 00:17 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\Spotify 2015-08-21 23:13 - 2015-08-21 23:13 - 00146080 _____ (Spotify Ltd) C:\Users\Helmut\Downloads\SpotifySetup.exe 2015-08-21 23:08 - 2015-08-21 23:08 - 00001139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\KakaoTalk.lnk 2015-08-21 23:08 - 2015-08-21 23:08 - 00001133 _____ C:\Users\Public\Desktop\KakaoTalk.lnk 2015-08-21 23:08 - 2015-08-21 23:08 - 00000000 ____D C:\Users\Helmut\AppData\Local\Kakao 2015-08-21 23:08 - 2015-08-21 23:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KakaoTalk 2015-08-21 23:07 - 2015-08-21 23:20 - 00141708 _____ (Daum Kakao Corp.) C:\Users\Helmut\Downloads\Nicht bestätigt 136496.crdownload 2015-08-21 23:07 - 2015-08-21 23:07 - 00000000 ____D C:\Program Files (x86)\Kakao 2015-08-21 23:05 - 2015-08-21 23:05 - 00000000 ____D C:\ProgramData\Licenses 2015-08-21 23:03 - 2015-08-21 23:07 - 28139840 _____ (Daum Kakao Corp.) C:\Users\Helmut\Downloads\KakaoTalk_Setup.exe 2015-08-21 23:00 - 2015-08-21 23:01 - 00000000 ____D C:\Users\Helmut\Desktop\idk idc 2015-08-21 22:58 - 2015-08-23 12:29 - 00614100 _____ C:\WINDOWS\PFRO.log 2015-08-21 22:46 - 2015-08-23 13:12 - 00000000 ____D C:\Users\Helmut\Desktop\important shit to upgrade the pc 2015-08-21 22:43 - 2015-08-22 23:50 - 00000000 ____D C:\Users\Helmut\AppData\Local\Deployment 2015-08-21 22:43 - 2015-08-21 22:43 - 00000000 ____D C:\Users\Helmut\AppData\Local\Apps\2.0 2015-08-21 22:38 - 2015-08-21 22:46 - 00000000 ____D C:\Users\Helmut\AppData\Local\clear.fi 2015-08-21 22:38 - 2015-08-21 22:38 - 00000000 ____D C:\ProgramData\SUPERSetup 2015-08-21 22:37 - 2015-08-21 22:37 - 01605632 _____ C:\Users\Helmut\Downloads\adwcleaner_5.003.exe 2015-08-21 22:37 - 2015-08-21 22:37 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2015-08-21 22:35 - 2015-08-23 12:19 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-08-21 22:34 - 2015-08-23 10:48 - 00000000 ____D C:\Windows.old 2015-08-21 22:34 - 2015-08-21 22:34 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2015-08-21 22:33 - 2015-08-21 22:33 - 00262144 _____ C:\WINDOWS\system32\config\userdiff 2015-08-21 22:33 - 2015-08-21 22:33 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2015-08-21 22:31 - 2015-08-23 13:40 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2015-08-21 22:31 - 2015-08-21 22:33 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2015-08-21 22:31 - 2015-08-21 22:31 - 00002786 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2015-08-21 22:31 - 2015-08-21 22:31 - 00000000 ____D C:\WINDOWS\PCHEALTH 2015-08-21 22:31 - 2015-08-21 22:31 - 00000000 ____D C:\ProgramData\Simply Super Software 2015-08-21 22:31 - 2015-08-21 22:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-08-21 22:31 - 2015-08-21 22:31 - 00000000 ____D C:\Program Files\CCleaner 2015-08-21 22:25 - 2015-08-21 22:31 - 00000000 ____D C:\Program Files\Microsoft Office 2015-08-21 22:25 - 2015-08-21 22:25 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2015-08-21 22:25 - 2015-08-21 22:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2015-08-21 22:17 - 2015-08-21 22:17 - 00000000 ____D C:\Users\Helmut\AppData\Local\Microsoft Help 2015-08-21 22:16 - 2015-08-23 12:18 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-08-21 22:13 - 2015-08-21 22:13 - 00000000 ____D C:\$WINDOWS.~BT 2015-08-21 22:12 - 2015-08-22 23:28 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4249919967-2187548655-1386870330-1001 2015-08-21 22:12 - 2012-06-22 17:35 - 00076736 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfenlfk.sys 2015-08-21 22:01 - 2015-08-21 22:02 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox 2015-08-21 22:01 - 2015-08-21 22:02 - 00000000 ____D C:\WINDOWS\system32\vbox 2015-08-21 22:00 - 2015-08-21 22:00 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-08-21 22:00 - 2015-08-21 22:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-08-21 21:59 - 2015-08-23 13:04 - 00001122 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-08-21 21:59 - 2015-08-23 12:44 - 00001118 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-08-21 21:59 - 2015-08-21 22:02 - 00000000 ____D C:\Users\Helmut\AppData\Local\Google 2015-08-21 21:59 - 2015-08-21 22:00 - 00000000 ____D C:\Program Files (x86)\Google 2015-08-21 21:59 - 2015-08-21 21:59 - 00004094 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-08-21 21:59 - 2015-08-21 21:59 - 00003858 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-08-21 21:51 - 2015-08-22 12:23 - 00000000 ____D C:\ProgramData\AVAST Software 2015-08-21 21:49 - 2015-08-21 21:49 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2015-08-21 21:49 - 2015-08-21 21:49 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\Synaptics 2015-08-21 21:48 - 2015-08-21 21:48 - 00001446 _____ C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-08-21 21:48 - 2015-08-21 21:48 - 00000000 ____D C:\ProgramData\OEM_YAHOO 2015-08-21 21:47 - 2015-08-21 21:47 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\lm 2015-08-21 21:41 - 2015-08-21 21:41 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\Macromedia 2015-08-21 21:41 - 2015-08-21 21:41 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\Adobe 2015-08-21 21:40 - 2015-08-21 22:02 - 00000000 ____D C:\Users\Helmut\AppData\Local\VirtualStore 2015-08-21 21:39 - 2015-08-21 21:48 - 00000000 ____D C:\Users\Helmut\AppData\Local\Packages 2015-08-21 21:39 - 2015-08-21 21:39 - 00000020 ___SH C:\Users\Helmut\ntuser.ini 2015-08-21 21:38 - 2015-08-23 12:58 - 01090119 _____ C:\WINDOWS\WindowsUpdate.log 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Vorlagen 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Startmenü 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\ProgramData\Vorlagen 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\ProgramData\Startmenü 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\ProgramData\Dokumente 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2015-08-21 21:37 - 2015-08-21 21:37 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2015-08-21 21:36 - 2015-08-21 21:48 - 00000000 ____D C:\Users\Helmut 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Vorlagen 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Startmenü 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Netzwerkumgebung 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Lokale Einstellungen 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Eigene Dateien 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Druckumgebung 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Documents\Eigene Musik 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Documents\Eigene Bilder 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\AppData\Local\Verlauf 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\AppData\Local\Anwendungsdaten 2015-08-21 21:36 - 2015-08-21 21:36 - 00000000 _SHDL C:\Users\Helmut\Anwendungsdaten 2015-08-21 21:36 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-08-21 21:36 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-21 21:36 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-08-21 21:36 - 2012-07-26 10:13 - 00000000 ____D C:\Users\Helmut\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-08-21 21:35 - 2015-08-21 21:36 - 00017148 _____ C:\WINDOWS\diagwrn.xml 2015-08-21 21:35 - 2015-08-21 21:36 - 00017148 _____ C:\WINDOWS\diagerr.xml 2015-08-21 21:06 - 2015-08-23 09:44 - 00000000 ___HD C:\$SysReset 2015-07-24 08:58 - 2015-08-21 22:33 - 00000000 ____D C:\Users\Helmut\Desktop\listen ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-08-23 13:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru 2015-08-23 12:58 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-08-23 12:42 - 2013-11-13 22:33 - 00753134 _____ C:\WINDOWS\system32\perfh007.dat 2015-08-23 12:42 - 2013-11-13 22:33 - 00155826 _____ C:\WINDOWS\system32\perfc007.dat 2015-08-23 12:42 - 2012-07-26 09:28 - 01745416 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-08-23 12:35 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-08-23 12:33 - 2012-07-26 07:37 - 00000000 ____D C:\WINDOWS\servicing 2015-08-23 12:26 - 2012-07-26 10:12 - 00000000 ___RD C:\WINDOWS\ToastData 2015-08-23 12:26 - 2012-07-26 09:52 - 00000000 ____D C:\Program Files\Windows Journal 2015-08-23 12:25 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-08-23 12:25 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2015-08-23 12:25 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2015-08-23 12:25 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2015-08-23 12:25 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\system32\Dism 2015-08-23 12:23 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-23 12:23 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\WinStore 2015-08-23 12:22 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-08-23 12:22 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender 2015-08-23 12:22 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2015-08-23 12:21 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\system32\oobe 2015-08-23 12:16 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Common Files\System 2015-08-23 12:16 - 2012-07-26 07:26 - 00000199 _____ C:\WINDOWS\win.ini 2015-08-23 12:11 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-08-23 11:48 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2015-08-23 11:41 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\rescache 2015-08-23 09:53 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent 2015-08-23 01:13 - 2013-02-02 03:06 - 00000000 ____D C:\Program Files\Common Files\mcafee 2015-08-22 23:35 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-08-22 22:49 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2015-08-22 12:24 - 2013-02-02 03:06 - 00000000 ____D C:\Program Files (x86)\McAfee 2015-08-22 12:23 - 2014-03-07 00:15 - 00000000 ____D C:\avast! sandbox 2015-08-22 12:22 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-08-21 23:05 - 2013-02-02 03:15 - 00000000 ____D C:\ProgramData\Temp 2015-08-21 22:39 - 2013-02-02 00:40 - 00000000 ___DC C:\WINDOWS\Panther 2015-08-21 22:34 - 2012-07-26 10:13 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template 2015-08-21 22:34 - 2012-07-26 09:52 - 00000000 ____D C:\WINDOWS\ShellNew 2015-08-21 22:18 - 2013-02-02 03:06 - 00000000 ____D C:\ProgramData\McAfee 2015-08-21 22:06 - 2015-05-03 21:29 - 00000000 ____D C:\Users\Helmut\Desktop\dont click just dont 2015-08-21 21:52 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\restore 2015-08-21 21:48 - 2013-02-02 00:12 - 00000000 ___HD C:\OEM 2015-08-21 21:39 - 2012-07-26 10:12 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2015-08-21 21:37 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows NT 2015-08-21 21:37 - 2012-07-26 07:37 - 00000000 __RHD C:\Users\Default 2015-08-21 21:36 - 2012-07-26 10:12 - 00000000 __RHD C:\Users\Public\Libraries 2015-08-21 21:36 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\Recovery 2015-08-21 20:49 - 2014-05-25 00:20 - 04482048 ___SH C:\Users\Helmut\Desktop\Thumbs.db 2015-08-21 20:27 - 2014-05-25 00:23 - 00000000 ___DO C:\Users\Helmut\OneDrive 2015-08-01 22:45 - 2013-12-06 13:26 - 00024576 ____H C:\Users\Helmut\Desktop\photothumb.db ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-08-22 18:17 - 2015-08-22 18:17 - 0000000 _____ () C:\Users\Helmut\AppData\Roaming\gdfw.log 2015-08-22 18:17 - 2015-08-22 18:17 - 0000779 _____ () C:\Users\Helmut\AppData\Roaming\gdscan.log Einige Dateien in TEMP: ==================== C:\Users\Helmut\AppData\Local\Temp\Quarantine.exe C:\Users\Helmut\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2013-02-02 00:40 ==================== Ende von Ergebnis ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:21-08-2015 03 durchgeführt von Helmut (2015-08-23 13:46:06) Gestartet von C:\Users\Helmut\Downloads Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-4249919967-2187548655-1386870330-500 - Administrator - Disabled) => C:\Users\Administrator Gast (S-1-5-21-4249919967-2187548655-1386870330-501 - Limited - Disabled) Helmut (S-1-5-21-4249919967-2187548655-1386870330-1001 - Administrator - Enabled) => C:\Users\Helmut HomeGroupUser$ (S-1-5-21-4249919967-2187548655-1386870330-1003 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AV: G DATA INTERNET SECURITY (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: G DATA INTERNET SECURITY (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: G*DATA Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3013 - Acer Incorporated) Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3016 - Acer Incorporated) AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.01.2008 - Acer Incorporated) AcerCloud Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.02.2021 - Acer Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Broadcom Card Reader Driver Installer (HKLM\...\{F0A7DF2F-0BE0-470F-B137-D7A19F977189}) (Version: 15.4.7.1 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform) clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.02.2012 - Acer Incorporated) clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.02.2016 - Acer Incorporated) clear.fi SDK - Video 2 (x32 Version: 2.1.2606 - CyberLink Corp.) Hidden clear.fi SDK- Movie 2 (x32 Version: 2.1.2606 - CyberLink Corp.) Hidden CyberLink MediaEspresso 6.5 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3729_45993 - CyberLink Corp.) Delicious: Emily's Childhood Memories Premium Edition (x32 Version: 3.0.2.32 - WildTangent) Hidden Dritek Radio Controller (HKLM-x32\...\RadioController) (Version: 2.02.2001.0803 - Dritek System Inc.) G DATA INTERNET SECURITY (HKLM-x32\...\{AC68D2FF-1674-4C16-A536-A69FC11BBD82}) (Version: 25.1.0.8 - G DATA Software AG) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3006 - Acer Incorporated) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2867 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.4.1001 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden KakaoTalk (HKLM-x32\...\KakaoTalk) (Version: 2.0.7.918 - Daum Kakao Corp) Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.10 - Acer Inc.) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3010 - Acer Incorporated) Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 11.6.385 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.124 - McAfee, Inc.) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}) (Version: 12.5.00500 - Nero AG) Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.02.2008 - Acer) Office Addin 2003 (HKLM-x32\...\{1FCC073B-CC01-4443-AD20-E559F66E6E83}) (Version: 2.02.2008 - Acer) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.39 - Qualcomm Atheros) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.) Security Task Manager 2.1 (HKLM-x32\...\Security Task Manager) (Version: 2.1 - Neuber Software) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Spotify (HKLM-x32\...\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.4.0 - Synaptics Incorporated) Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CBCC2FD8-7DFE-4752-95B5-2E447C226F45}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent) WildTangent Games App (x32 Version: 4.0.10.5 - WildTangent) Hidden ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Wiederherstellungspunkte ========================= 23-08-2015 09:47:07 Windows Update ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {37F1C7AB-78FD-4B6E-AFE9-E73E95846974} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {3D2177C1-EA8B-47DE-9FBC-59F5217C1A61} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {42894F4F-7D31-4611-AA3F-A2B31CD947ED} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-23] (Adobe Systems Incorporated) Task: {5F4DD87B-3B02-407E-BF3F-78E7A86D0D19} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd) Task: {9F9A5A16-2661-49FB-8BA8-504319AB49E1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-21] (Google Inc.) Task: {B570E562-BA5D-45DE-BD45-EB01D3B36538} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-03-13] () Task: {B5E44DFA-5A61-4F44-996D-C85B2EC44DC9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-21] (Google Inc.) Task: {C84369F6-DB6B-40E0-BBAF-7656CFEF0BC0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-28] (Microsoft Corporation) Task: {D5BCCF84-FA59-471E-A1A6-CB50D42385ED} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2013-01-23] (Acer Incorporated) Task: {DE8490F9-A2DC-47DE-A135-DB1D72A34954} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {E9E923F3-B15F-48A7-9D47-59C40E40A6B5} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2013-03-15] (Acer Incorporated) Task: {EC2F14FF-8290-4569-B236-11123E0326A5} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] () Task: {EED9D01B-D033-456A-B8D1-4084C9295A95} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2013-02-08] (CyberLink) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-06-16 11:17 - 2015-06-16 11:17 - 00382584 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll 2013-02-02 00:29 - 2012-10-23 20:37 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-05-04 21:25 - 2015-05-04 21:25 - 00055576 _____ () C:\Program Files\CCleaner\branding.dll 2015-07-17 19:34 - 2015-07-17 19:34 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2013-11-13 13:54 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-11-13 14:16 - 2013-02-20 23:58 - 00089672 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll 2015-08-21 22:00 - 2015-08-18 07:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll 2015-08-21 22:00 - 2015-08-18 07:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll 2015-08-21 22:00 - 2015-08-18 07:23 - 16393032 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\Helmut\OneDrive:ms-properties ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-4249919967-2187548655-1386870330-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Helmut\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\hintergrundbild der windows-fotoanzeige.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{98B39A5D-1800-48F1-B2F5-F03CFCBAB423}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{6CC9D4C2-17C4-436E-B12B-48718A3EBA1C}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{D0124BC6-4CFF-4BE1-9BE5-1D391C08BF0D}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe FirewallRules: [{D435E958-9516-4EC9-B343-F41DE2A76153}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe FirewallRules: [{C43AD416-472B-4018-93D6-0FA4E7D3890D}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe FirewallRules: [{4A96BB9E-6B0E-4F82-BD18-7CFC99AB2B46}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe FirewallRules: [{3243212E-E30D-4F1F-84A9-1F199CED35EC}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe FirewallRules: [{3FE02536-717C-4E1C-8948-F22F7246DF13}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe FirewallRules: [{60797D1D-032C-45D8-916F-B2F8460E6F9E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe FirewallRules: [{F754384B-D194-4614-9E35-1581FB8B013A}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe FirewallRules: [{C354894C-11FE-49FF-8F9A-CC82B539E4D7}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe FirewallRules: [{A16A2D8A-816E-4803-8FA5-EFC5D35064B5}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe FirewallRules: [{8A0F84E0-BFD3-4636-8A7F-F366E82B439E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\VideoPlayer.exe FirewallRules: [{3422FF14-7A8F-44E3-8B0D-B3CE1DC85DA5}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\MusicPlayer.exe FirewallRules: [{27114704-862C-40AE-A235-5EE646C90CDD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Movie\PlayMovie.exe FirewallRules: [{32C2CE52-10AE-460C-8DD9-FA6362D17F93}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe FirewallRules: [{1DA249CB-2CDC-464B-B108-7F5B2DB81932}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe FirewallRules: [{326D0B38-0455-4270-BC3E-C4D5BCD843A4}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe FirewallRules: [{3FDC6EEC-AA8D-493E-ACAE-B011F430C74C}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe FirewallRules: [{11B7E4D4-DE92-4D29-B429-9CA608F594F7}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe FirewallRules: [{69996C4E-C1FE-4C92-8AFE-737E4E2C8159}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe FirewallRules: [{8BBCD683-030D-492B-A1B3-F048B47EE52F}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\Sdd.exe FirewallRules: [{BDD70F33-5787-4C86-BAF5-CDEF7D479FF6}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\Sdd.exe FirewallRules: [{A018CD9E-197A-4CC9-BB41-27ED47886DD3}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\virtualdrive.exe FirewallRules: [{2B07B78C-A183-4855-80EE-0D5397492BD4}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\virtualdrive.exe FirewallRules: [{9E7B43A6-30F1-4D95-BBFE-5380386D1CD9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{1449BFAE-1786-4DDA-8D7E-0D15F85F6B21}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{79079929-961C-4FF6-99E2-E106D65E5B7A}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{4C5A000A-A1EA-48AC-BB0E-15DB1D66A2AC}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{724975CC-C784-4277-83F2-EE9ABBC4FFC7}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [TCP Query User{DE289DC3-AA14-4319-A610-560DD19C8BF3}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe FirewallRules: [UDP Query User{B55F0514-D258-4C14-AFEC-17924119E010}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe FirewallRules: [{BF0FC882-E8EF-4006-92CB-120AD00527F9}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{559FBFAC-6D1A-41A9-A655-646B20D593BF}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{2172023A-F1DE-4D62-85B9-24FAFA1A7568}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{BE88FF64-2AEA-4DE8-A51D-05FD5E80B9DB}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (08/23/2015 12:38:55 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: MCSCAN32 Engine Initialisation failed. Engine returned error : 1 Error: (08/23/2015 11:58:40 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x8007045B. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C} Error: (08/23/2015 09:49:45 AM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (08/23/2015 09:49:44 AM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (08/23/2015 09:49:42 AM) (Source: SideBySide) (EventID: 72) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "asmv2:clrClassInvocation1". Fehler in Manifest- oder Richtliniendatei "asmv2:clrClassInvocation2" in Zeile asmv2:clrClassInvocation3. Das asmv2:clrClassInvocation-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^entryPoint-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. Error: (08/23/2015 02:16:18 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (08/23/2015 01:43:05 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2310 Startzeit: 01d0dd340bac3d12 Endzeit: 16 Anwendungspfad: C:\WINDOWS\system32\wwahost.exe Berichts-ID: 7b495f60-4927-11e5-be79-208984545653 Vollständiger Name des fehlerhaften Pakets: Microsoft.ZuneMusic_1.1.139.0_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Microsoft.ZuneMusic Error: (08/22/2015 10:55:32 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: MCSCAN32 Engine Initialisation failed. Engine returned error : 1 Error: (08/22/2015 10:44:41 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: MCSCAN32 Engine Initialisation failed. Engine returned error : 1 Error: (08/22/2015 06:44:43 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: MCSCAN32 Engine Initialisation failed. Engine returned error : 1 Systemfehler: ============= Error: (08/23/2015 01:40:41 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Error: (08/23/2015 01:38:41 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Error: (08/23/2015 01:36:41 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {C90134D2-4AE9-407A-919A-4A2EF09C6C51} Error: (08/23/2015 01:34:41 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Error: (08/23/2015 01:32:41 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Error: (08/23/2015 01:30:41 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Error: (08/23/2015 01:28:40 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {395633B1-EED9-4DFC-B67F-9788B51C9F06} Error: (08/23/2015 01:26:40 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Error: (08/23/2015 01:24:40 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {395633B1-EED9-4DFC-B67F-9788B51C9F06} Error: (08/23/2015 01:22:40 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} Microsoft Office: ========================= Error: (08/23/2015 12:38:55 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: 1 Error: (08/23/2015 11:58:40 AM) (Source: MsiInstaller) (EventID: 11935) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1935.An error occurred during the installation of assembly 'Microsoft.VC90.ATL,version="9.0.30729.6161",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="amd64",type="win32"'. Please refer to Help and Support for more information. HRESULT: 0x8007045B. assembly interface: IAssemblyCacheItem, function: Commit, component: {74C57B6B-FF6E-3825-BED2-78E14E3E0E3C}(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/23/2015 09:49:45 AM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest4 Error: (08/23/2015 09:49:44 AM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest4 Error: (08/23/2015 09:49:42 AM) (Source: SideBySide) (EventID: 72) (User: ) Description: asmv2:clrClassInvocationurn:schemas-microsoft-com:asm.v1^entryPointC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.ManifestC:\Program Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest4 Error: (08/23/2015 02:16:18 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (08/23/2015 01:43:05 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.2.9200.16420231001d0dd340bac3d1216C:\WINDOWS\system32\wwahost.exe7b495f60-4927-11e5-be79-208984545653Microsoft.ZuneMusic_1.1.139.0_x64__8wekyb3d8bbweMicrosoft.ZuneMusic Error: (08/22/2015 10:55:32 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: 1 Error: (08/22/2015 10:44:41 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: 1 Error: (08/22/2015 06:44:43 PM) (Source: McLogEvent) (EventID: 5022) (User: NT-AUTORITÄT) Description: 1 ==================== Speicherinformationen =========================== Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz Prozentuale Nutzung des RAM: 62% Installierter physikalischer RAM: 3911.27 MB Verfügbarer physikalischer RAM: 1466.97 MB Summe virtueller Speicher: 7879.27 MB Verfügbarer virtueller Speicher: 4680.68 MB ==================== Laufwerke ================================ Drive c: (Acer) (Fixed) (Total:217.98 GB) (Free:24.93 GB) NTFS Drive d: (DATA) (Fixed) (Total:218.42 GB) (Free:217.98 GB) NTFS Drive e: (GDISWE) (CDROM) (Total:0.66 GB) (Free:0 GB) CDFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: AE936CCE) Partition: GPT. ==================== Ende von Ergebnis ============================ |
23.08.2015, 13:00 | #4 |
| Antivirenprogramme werden ausgeschalten TDSSkiller.exe Code:
ATTFilter 13:44:21.0533 0x1f54 TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57 13:44:21.0533 0x1f54 UEFI system 13:44:24.0505 0x1f54 ============================================================ 13:44:24.0505 0x1f54 Current date / time: 2015/08/23 13:44:24.0504 13:44:24.0505 0x1f54 SystemInfo: 13:44:24.0505 0x1f54 13:44:24.0505 0x1f54 OS Version: 6.2.9200 ServicePack: 0.0 13:44:24.0505 0x1f54 Product type: Workstation 13:44:24.0505 0x1f54 ComputerName: KEVIN 13:44:24.0505 0x1f54 UserName: Helmut 13:44:24.0505 0x1f54 Windows directory: C:\WINDOWS 13:44:24.0505 0x1f54 System windows directory: C:\WINDOWS 13:44:24.0505 0x1f54 Running under WOW64 13:44:24.0505 0x1f54 Processor architecture: Intel x64 13:44:24.0505 0x1f54 Number of processors: 4 13:44:24.0505 0x1f54 Page size: 0x1000 13:44:24.0505 0x1f54 Boot type: Normal boot 13:44:24.0505 0x1f54 ============================================================ 13:44:28.0091 0x1f54 KLMD registered as C:\WINDOWS\system32\drivers\59786086.sys 13:44:29.0428 0x1f54 System UUID: {A267E1FB-4F5B-123D-F1F1-199964B4708B} 13:44:31.0459 0x1f54 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 13:44:31.0502 0x1f54 ============================================================ 13:44:31.0502 0x1f54 \Device\Harddisk0\DR0: 13:44:31.0554 0x1f54 GPT partitions: 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {C2E62302-9A1D-439E-80A2-0E3FB7D0A143}, Name: , StartLBA 0x800, BlocksNum 0xC8000 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {80B8A6EC-04D7-4A21-8C01-311FCEF9D763}, Name: EFI system partition, StartLBA 0xC8800, BlocksNum 0x96000 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {B3FDEF14-EA65-4406-A79E-016E119FFFE4}, Name: Microsoft reserved partition, StartLBA 0x15E800, BlocksNum 0x40000 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {CD6937BC-6BCF-4555-819B-43AC722A8B15}, Name: Basic data partition, StartLBA 0x19E800, BlocksNum 0x1B3F8000 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {63273187-F362-4D04-A791-4EB914764839}, Name: , StartLBA 0x1B596800, BlocksNum 0xE1000 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {E5B41834-D53E-4AC1-B78C-87958C13BB91}, Name: Basic data partition, StartLBA 0x1B677800, BlocksNum 0x1B4D9000 13:44:31.0667 0x1f54 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {BA2542F5-B0CB-41EB-8E6C-285E9BE16E1C}, Name: , StartLBA 0x36B50800, BlocksNum 0x3835800 13:44:31.0668 0x1f54 MBR partitions: 13:44:31.0668 0x1f54 ============================================================ 13:44:31.0895 0x1f54 C: <-> \Device\Harddisk0\DR0\Partition4 13:44:32.0065 0x1f54 D: <-> \Device\Harddisk0\DR0\Partition6 13:44:32.0065 0x1f54 ============================================================ 13:44:32.0065 0x1f54 Initialize success 13:44:32.0065 0x1f54 ============================================================ 13:44:35.0905 0x1c74 ============================================================ 13:44:35.0905 0x1c74 Scan started 13:44:35.0905 0x1c74 Mode: Manual; 13:44:35.0905 0x1c74 ============================================================ 13:44:35.0905 0x1c74 KSN ping started 13:44:38.0446 0x1c74 KSN ping finished: true 13:44:41.0833 0x1c74 ================ Scan system memory ======================== 13:44:41.0833 0x1c74 System memory - ok 13:44:41.0834 0x1c74 ================ Scan services ============================= 13:44:47.0865 0x1c74 [ E890C46E4754F0DF51BAFCC8D2E07498, E620D03030F3B65442E0A5CB8B59016A6E8DB3BCA52741977B8897B34438E902 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys 13:44:47.0872 0x1c74 1394ohci - ok 13:44:48.0017 0x1c74 [ 4F18D4C7EA14F11A7211F60D553C03DB, 09AB6D2D8E9B7B6D6A97708551C0E4B34538947A15EA2A69C11764D7BC0BB7F6 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys 13:44:48.0020 0x1c74 3ware - ok 13:44:48.0136 0x1c74 [ 975AABEB243B800C23626D6B652C5A9C, FB02336F26AF10BA2A0D1B97C33CB1D78BB90CA51EF008A613A0274779798FAD ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys 13:44:48.0146 0x1c74 ACPI - ok 13:44:48.0189 0x1c74 [ DC968C37822117E576B933F34A2D130C, 4C94E00ADC242296D7CBBFC7346D5F9AE5FE1B0C616ECA3BDE10A7B34FD2040B ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys 13:44:48.0191 0x1c74 acpiex - ok 13:44:48.0205 0x1c74 [ 0CA9F7C3A78227C21A0A7854E245CFB2, D54147C9C1EE2F0098B863B0852E027DB89D6FA67F6B7FD54F609D9715A11442 ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys 13:44:48.0206 0x1c74 acpipagr - ok 13:44:48.0217 0x1c74 [ 8EB8DA03B142D3DD1EB9ED8107A76C43, 24B9B24F9A5BDF3AAD13C4EE0638497D9CA4A100096C6EAE403E0215EA89C439 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys 13:44:48.0218 0x1c74 AcpiPmi - ok 13:44:48.0229 0x1c74 [ CBCE725C5D86ABA7D2604E22951AA9B8, DE0440F0E943F057EBCD01DB4B1E12DBC241FBF03C42021306D322AB88FF8F21 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys 13:44:48.0230 0x1c74 acpitime - ok 13:44:55.0362 0x1c74 [ 368290D0A612D62DA6F3D798B1BB8FE7, D573BF8543F37BC51B88A2473EDFD28AFBCCC446E8CADD54A90FA48D8739D222 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 13:44:55.0368 0x1c74 AdobeFlashPlayerUpdateSvc - ok 13:44:55.0555 0x1c74 [ 93C6388592B99925C1D1576E465BC80F, 4C48BE5471DA4788357D71E90DFEA20FE320C7AAE1F4C55AFBE2E46FEA5CF8FB ] adp94xx C:\WINDOWS\system32\drivers\adp94xx.sys 13:44:56.0001 0x1c74 adp94xx - ok 13:44:56.0242 0x1c74 [ D27763E0247292654E7F7D16444C7C72, 0314C713D31E2B34F215B52F804F014D876E6ED92DC656CC3E27920CCD36CF0E ] adpahci C:\WINDOWS\system32\drivers\adpahci.sys 13:44:56.0253 0x1c74 adpahci - ok 13:44:56.0255 0x1c74 Scan was interrupted by user! 13:44:56.0256 0x1c74 Waiting for KSN requests completion. In queue: 3 13:44:57.0257 0x1c74 Waiting for KSN requests completion. In queue: 3 13:44:58.0257 0x1c74 Waiting for KSN requests completion. In queue: 3 13:44:59.0320 0x1c74 AV detected via SS2: McAfee Anti-Virus und Anti-Spyware, C:\Program Files\McAfee.com\Agent\mcupdate.exe ( 11.6.0.0 ), 0x52000 ( disabled : updated ) 13:44:59.0321 0x1c74 AV detected via SS2: G DATA INTERNET SECURITY, C:\Program Files (x86)\G DATA\InternetSecurity\AVK\avkwscpe.exe ( 25.1.0.0 ), 0x41000 ( enabled : updated ) 13:44:59.0427 0x1c74 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.2.223.0 ), 0x60100 ( disabled : updated ) 13:44:59.0429 0x1c74 FW detected via SS2: G*DATA Personal Firewall, C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe ( 22.0.0.1 ), 0x41010 ( enabled ) 13:44:59.0430 0x1c74 FW detected via SS2: McAfee Firewall, C:\Program Files\McAfee.com\Agent\mcupdate.exe ( 11.6.0.0 ), 0x51010 ( enabled ) 13:45:01.0824 0x1c74 ============================================================ 13:45:01.0824 0x1c74 Scan finished 13:45:01.0824 0x1c74 ============================================================ 13:45:01.0837 0x0a98 Detected object count: 0 13:45:01.0837 0x0a98 Actual detected object count: 0 13:45:37.0587 0x1140 ============================================================ 13:45:37.0587 0x1140 Scan started 13:45:37.0587 0x1140 Mode: Manual; SigCheck; TDLFS; 13:45:37.0587 0x1140 ============================================================ 13:45:37.0587 0x1140 KSN ping started 13:45:39.0911 0x1140 KSN ping finished: true 13:45:50.0636 0x1140 ================ Scan system memory ======================== 13:45:50.0636 0x1140 System memory - ok 13:45:50.0636 0x1140 ================ Scan services ============================= 13:45:54.0543 0x1140 [ E890C46E4754F0DF51BAFCC8D2E07498, E620D03030F3B65442E0A5CB8B59016A6E8DB3BCA52741977B8897B34438E902 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys 13:45:54.0627 0x1140 1394ohci - ok 13:45:54.0635 0x1140 [ 4F18D4C7EA14F11A7211F60D553C03DB, 09AB6D2D8E9B7B6D6A97708551C0E4B34538947A15EA2A69C11764D7BC0BB7F6 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys 13:45:54.0654 0x1140 3ware - ok 13:45:54.0669 0x1140 [ 975AABEB243B800C23626D6B652C5A9C, FB02336F26AF10BA2A0D1B97C33CB1D78BB90CA51EF008A613A0274779798FAD ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys 13:45:54.0694 0x1140 ACPI - ok 13:45:54.0707 0x1140 [ DC968C37822117E576B933F34A2D130C, 4C94E00ADC242296D7CBBFC7346D5F9AE5FE1B0C616ECA3BDE10A7B34FD2040B ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys 13:45:54.0719 0x1140 acpiex - ok 13:45:54.0723 0x1140 [ 0CA9F7C3A78227C21A0A7854E245CFB2, D54147C9C1EE2F0098B863B0852E027DB89D6FA67F6B7FD54F609D9715A11442 ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys 13:45:54.0739 0x1140 acpipagr - ok 13:45:54.0766 0x1140 [ 8EB8DA03B142D3DD1EB9ED8107A76C43, 24B9B24F9A5BDF3AAD13C4EE0638497D9CA4A100096C6EAE403E0215EA89C439 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys 13:45:54.0828 0x1140 AcpiPmi - ok 13:45:54.0841 0x1140 [ CBCE725C5D86ABA7D2604E22951AA9B8, DE0440F0E943F057EBCD01DB4B1E12DBC241FBF03C42021306D322AB88FF8F21 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys 13:45:54.0854 0x1140 acpitime - ok 13:45:55.0528 0x1140 [ 368290D0A612D62DA6F3D798B1BB8FE7, D573BF8543F37BC51B88A2473EDFD28AFBCCC446E8CADD54A90FA48D8739D222 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 13:45:55.0554 0x1140 AdobeFlashPlayerUpdateSvc - ok 13:45:55.0608 0x1140 [ 93C6388592B99925C1D1576E465BC80F, 4C48BE5471DA4788357D71E90DFEA20FE320C7AAE1F4C55AFBE2E46FEA5CF8FB ] adp94xx C:\WINDOWS\system32\drivers\adp94xx.sys 13:45:55.0631 0x1140 adp94xx - ok 13:45:55.0665 0x1140 [ D27763E0247292654E7F7D16444C7C72, 0314C713D31E2B34F215B52F804F014D876E6ED92DC656CC3E27920CCD36CF0E ] adpahci C:\WINDOWS\system32\drivers\adpahci.sys 13:45:55.0683 0x1140 adpahci - ok 13:45:55.0714 0x1140 [ 67B90070FF48F794AF19F9FCF0080D75, 5D0D352606D58D2CA0814F38EF7B1774C030BE44353DF5910CBFAAF4FDE64ED6 ] adpu320 C:\WINDOWS\system32\drivers\adpu320.sys 13:45:56.0365 0x1140 adpu320 - ok 13:45:56.0452 0x1140 [ 480C020D9B58E881A5349F5F1189A418, 8AE8ED9CD8F239DF47853FBCE45DB34652CE94E3FD296FDF3897AC6DD5F9B143 ] AeLookupSvc C:\WINDOWS\System32\aelupsvc.dll 13:45:56.0472 0x1140 AeLookupSvc - ok 13:45:56.0576 0x1140 [ FE7FB9612D354EB41DF4F0FF5D6FB259, 98D5BD9C1300195C49CB0717A831A06D99F7AE631D5EA065E10BFE7C2FA57A18 ] AFD C:\WINDOWS\system32\drivers\afd.sys 13:45:56.0611 0x1140 AFD - ok 13:45:56.0669 0x1140 [ 01590377A5AB19E792528C628A2A68F9, F3A4B6CA4E8D4436E44E36D7F7EEF3DC861D1EE50D41F4273226C4ED95674B84 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys 13:45:56.0684 0x1140 agp440 - ok 13:45:56.0730 0x1140 [ D1BE8E6E5B3AF23A4393AF1BF867977A, B3AE97D35A9304198715D76F6C3F0545AA176FDEBA6C2055782558B11DFA14EB ] ALG C:\WINDOWS\System32\alg.exe 13:45:56.0749 0x1140 ALG - ok 13:45:56.0816 0x1140 [ 025E8C755BE293E50854D26D1BBE5133, 4373639689306A3D8FE0F862072711BAD5DBAA45E105CD3129586439A90EE070 ] AllUserInstallAgent C:\WINDOWS\system32\AUInstallAgent.dll 13:45:56.0850 0x1140 AllUserInstallAgent - ok 13:45:56.0879 0x1140 [ 5A81054B824004B1ECC04F0034A1CDF9, 73A1986A4B346C425157216EBF16CC90EFFC642EDF6109E6364CF0552E3388FD ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys 13:45:56.0897 0x1140 AmdK8 - ok 13:45:56.0903 0x1140 [ B849D453E644FAB9BC8EF6DC8CA9C4C6, B803CDA478D3385937C44CBB05A0E65ABACEFEBA682975787C44E2904FB89D2D ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys 13:45:56.0921 0x1140 AmdPPM - ok 13:45:56.0945 0x1140 [ 35A0EB5AECB0FA3C41A2FB514A562304, 737783ABF348288471AC7051D4DC6CB336D686C94EC7B8938DCA74AFE9BECB1C ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys 13:45:56.0957 0x1140 amdsata - ok 13:45:56.0981 0x1140 [ 00452671904F5EE94B50BF0219C97164, 99F9B86D3DB3E10B014120A63CD43CBAAB22C8E38851090ABE37D89ABD61F7B6 ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys 13:45:57.0000 0x1140 amdsbs - ok 13:45:57.0005 0x1140 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7, DC0B8B798720F5F75F8AFD3383CF69194282AEEE84DCACB97382F4C86E1D3E49 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys 13:45:57.0016 0x1140 amdxata - ok 13:45:57.0025 0x1140 [ 83B3682CE922FB0F415734B26D9D6233, 9102E8B410BB1AE426770896B6AB584D1F02830337FBB2DEC182F3F19832F35F ] AppID C:\WINDOWS\system32\drivers\appid.sys 13:45:57.0041 0x1140 AppID - ok 13:45:57.0088 0x1140 [ CE2BEAD7F31816FF0AC490D048C969F9, 7D24C5A9E8F7C21CC6D8BF2CA29A8B79DDE7EEDE2F37D36B9071ECE1CF61371F ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll 13:45:57.0103 0x1140 AppIDSvc - ok 13:45:57.0149 0x1140 [ 4F750B7EFCB6520AE01E01D082D7D476, AD2A67D727A1D4DD0BBACC6B4BB432FA9A14D50D8BA292B95A4747CEC9F85728 ] Appinfo C:\WINDOWS\System32\appinfo.dll 13:45:57.0163 0x1140 Appinfo - ok 13:45:57.0168 0x1140 [ E933401B392387F4BE34DE8BAF1722A7, 57CC6DE31E2C82D2B12509F0A5EC9EC70DD2EF6A1F31A66ADF62DC6AE0A67323 ] arc C:\WINDOWS\system32\drivers\arc.sys 13:45:57.0182 0x1140 arc - ok 13:45:57.0207 0x1140 [ 07CA323EF2E8247A568AB0F3662AD644, 1224B41193F0E9B164732BA5BF707A13427C82C1D8C3EDC2AAE5C5C75454B9F6 ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys 13:45:57.0220 0x1140 arcsas - ok 13:45:57.0225 0x1140 [ 74DBAEC35366C4EE7670428808715A6A, 3B3A7A81CD8038C4750560B94A9247C4409410780B312BA71EDF2E393DCA7474 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 13:45:57.0240 0x1140 AsyncMac - ok 13:45:57.0246 0x1140 [ A721FF570C2387E383BDDEA9632863C9, 45DD7787F44A2C742560FEB03AB66910C2F0002D95BB02C55EEDE973AA92AD24 ] atapi C:\WINDOWS\system32\drivers\atapi.sys 13:45:57.0257 0x1140 atapi - ok 13:45:57.0503 0x1140 [ 667153FCB54CD80626A5AC5A2F49F068, B1FEE1D4A7B45C4DCC3A012E8837ADD6059E6E716862BDED3BBEB8282FA02CA8 ] athr C:\WINDOWS\system32\DRIVERS\athw8x.sys 13:45:57.0600 0x1140 athr - ok 13:45:57.0681 0x1140 [ 8FB10919E1283FD108334FDBFB173574, EAD11C6FA884AAC9E8534C267E9B1D2EAB1F2A396EACC900525465A2AEAB84D3 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll 13:45:57.0727 0x1140 AudioEndpointBuilder - ok 13:45:57.0769 0x1140 [ 463E7457227E970CB249031AEAE7902C, 2F627BC558E5764592B08269F3EE4C6ECD544904963312A60F5B0C0B9C8C5D32 ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll 13:45:57.0828 0x1140 Audiosrv - ok 13:45:58.0683 0x1140 [ 6FA423F957A966A53243F383D213B2B2, 98A8D304FDE16D6464A09A3CE823E1DB0CD3F7866C1FBDD5CE393E42FF60BF37 ] AVKProxy C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe 13:45:58.0738 0x1140 AVKProxy - ok 13:45:59.0240 0x1140 [ 57E9F462DE5ED77574116782BA05AB0F, 611987C8205E113DFA206F50EF4959AA5D6CE252A73EC1E74C043CBFD7172E3D ] AVKService C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe 13:45:59.0265 0x1140 AVKService - ok 13:46:00.0160 0x1140 [ E9F980D3646B85658D182A470D586E79, FE7CA31CD3D6CC6825F3228860DF8F2DFF09D82D3D84DF79C7F5C2484D8AB4FB ] AVKWCtl C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe 13:46:00.0259 0x1140 AVKWCtl - ok 13:46:00.0337 0x1140 [ 89491EF71D5EA011127832C588002853, 05620E4235956D8446FB9604F930738C8AA97E3A74C907E37F7CC08B8EDA0461 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll 13:46:00.0353 0x1140 AxInstSV - ok 13:46:00.0644 0x1140 [ 87AB5BB072A3F128541D5B815F82FFDD, 186AF33D3DE90638C3E165CAC3DA17295E8A80CDB523F9BE4AF7D38CA6954905 ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys 13:46:00.0703 0x1140 b06bdrv - ok 13:46:00.0759 0x1140 [ 0630C8915B747E88E825CE7F73B66A5D, E9B465EE23487B59B1C906B04F9235B0BFBF254C1760E2462A7D1D7FE1655088 ] b57xdbd C:\WINDOWS\System32\drivers\b57xdbd.sys 13:46:00.0771 0x1140 b57xdbd - ok 13:46:00.0791 0x1140 [ CA8457E528E13B38F8DC3B86B6BA4C6B, 532E48BBBA806608EBEFE10A94DCE2BFE8918D8DD6DEF6871F44FEEDA51238B8 ] b57xdmp C:\WINDOWS\System32\drivers\b57xdmp.sys 13:46:00.0799 0x1140 b57xdmp - ok 13:46:00.0819 0x1140 [ 81703BC5D68DEDBB086C2368FBE7B334, CFD4A55C8045C482F8D410514F3211AEFA00097AB395F5A04BFE983ED6254F6B ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys 13:46:00.0839 0x1140 BasicDisplay - ok 13:46:00.0844 0x1140 [ 5EC68164E14D25675C98BBB5F09E8606, 1D7EDB21C87039FC5F39F46460AD852BC4EC6B179B1C205D189DD3C397343435 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys 13:46:00.0860 0x1140 BasicRender - ok 13:46:00.0971 0x1140 [ 89143A7BA7850F5C7E61B43BB44B6418, 00BB781DF87D4FF1BAFD318AFE237296B4F5925023BA4486405EC0A384C88D8F ] BDESVC C:\WINDOWS\System32\bdesvc.dll 13:46:00.0991 0x1140 BDESVC - ok 13:46:00.0996 0x1140 [ 9E7AEA59776D904607985AFFE7E5E183, C3DB745A9F4DA7CB9628A7913DD52B2444B14FEB9D588FF6558CF52CEB8955EB ] Beep C:\WINDOWS\system32\drivers\Beep.sys 13:46:01.0028 0x1140 Beep - ok 13:46:01.0076 0x1140 [ C72AB32F7EFCA677AF079F4336BC1609, 90FF653027709ADB674B2D4240E398E7A64D2079CBF56E3983008D92FA12EA0D ] BFE C:\WINDOWS\System32\bfe.dll 13:46:01.0139 0x1140 BFE - ok 13:46:01.0221 0x1140 [ D598C44A7072D3108D8D8102EC5E07F7, D7472E9BAAB7B6E1D30F4E153412E2A16EE5C08DE2BF8BFF4D65089825226FE0 ] BITS C:\WINDOWS\System32\qmgr.dll 13:46:01.0299 0x1140 BITS - ok 13:46:01.0343 0x1140 [ B17AC10B47C7FCB44D22A1F06415840E, 990D6F629D93F4F913D218ACE5187A26DCB762BAFB2BB279CCE8CAF2755D85A5 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys 13:46:01.0364 0x1140 bowser - ok 13:46:01.0468 0x1140 [ 5C6ADD0111E1C6601B5911F7ACF85BB8, 1653E8725478C8118D2AF15399A1A44464AFDC6F66EB1A90BB268A0692831AEE ] BrcmCardReader C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe 13:46:01.0482 0x1140 BrcmCardReader - detected UnsignedFile.Multi.Generic ( 1 ) 13:46:03.0858 0x1140 Detect skipped due to KSN trusted 13:46:03.0858 0x1140 BrcmCardReader - ok 13:46:03.0984 0x1140 [ 038FA1B55531E7020DB705B42FCCE373, 023E87E3204D64890D6FEA78E762E5BC5BD0A59325EBC264834727779EEEDBC5 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll 13:46:04.0006 0x1140 BrokerInfrastructure - ok 13:46:04.0059 0x1140 [ 310068BDA80B1D55C36580FD8A873FAF, A75412FF1F483461F526E9A359DCEECA5E683441514464D5ED82D1A9740D583E ] Browser C:\WINDOWS\System32\browser.dll 13:46:04.0075 0x1140 Browser - ok 13:46:04.0109 0x1140 [ 0E9B28782D0E5DE7C25207432B791B33, FE33E3B27BEED03922DB2565DECC0E12F8CD586B5060EE4A1A87FF99EEC77B22 ] bScsiMSa C:\WINDOWS\System32\drivers\bScsiMSa.sys 13:46:04.0118 0x1140 bScsiMSa - ok 13:46:04.0140 0x1140 [ 8F62F985BDD2F333A3EE34D54894363D, 44755CEEE5B1823990547C1F22FFC833D7BD693E6C3DD056B0C41615ED61ED4C ] bScsiSDa C:\WINDOWS\System32\drivers\bScsiSDa.sys 13:46:04.0153 0x1140 bScsiSDa - ok 13:46:04.0181 0x1140 [ F17DEEAC7D51D44CF1BFF8DD4F0A2B6D, 2EA75F8D7D3BDDDE19B48D71D09C797BBACD40800BF557F6FD9047CA62FF2B9F ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys 13:46:04.0194 0x1140 BthAvrcpTg - ok 13:46:04.0231 0x1140 [ 616EB8748C988AEE98D93DA141C3D3B4, 15A055B0496BDB29CBCF6EEBF112D4BA1C7A2FF39124728830D0FD1FD7A404CB ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys 13:46:04.0265 0x1140 BthHFEnum - ok 13:46:04.0270 0x1140 [ DCB4EBD928A6FB368BE6CAE522412DE1, 9E1345F29467054689B9F48B5CCB567760D36610A4EA9AF41B829EAD60347269 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys 13:46:04.0285 0x1140 bthhfhid - ok 13:46:04.0290 0x1140 [ 033916CE8784A848B9A3D686B7F66D97, B4D0514D59646CF6B70D4FA488CF95C38EA38CC5C509329CC8753E897C640AFA ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys 13:46:04.0311 0x1140 BTHMODEM - ok 13:46:04.0337 0x1140 [ A4387C3D271959313E2577DB7BE8BA7A, C71474802102102EBE04DF036EEB2F5FB3380BE288E3842F19F234EFAE977D70 ] bthserv C:\WINDOWS\system32\bthserv.dll 13:46:04.0351 0x1140 bthserv - ok 13:46:04.0965 0x1140 [ 843F5EFF90A988617C5FFD8596A2B571, 69FF9731876E1CBA4BBF00557F0CBC73247165F8EB45F45A55CC0178A7B90D44 ] CCDMonitorService C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe 13:46:05.0052 0x1140 CCDMonitorService - ok 13:46:05.0059 0x1140 ccSet_NARA - ok 13:46:05.0101 0x1140 [ 990B1BABE6E81FB18E65A87EBEFB1772, 1820D4AC57E1D4B7FB5AA89C277B16910ED73712878D2B43FE542CE16DFE16C3 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys 13:46:05.0116 0x1140 cdfs - ok 13:46:05.0158 0x1140 [ 339BFF85D788268752DA8C9644B188EE, C2279F1A39AED39865A5027D2FD087F8E82F3ED8C94BA4D922855B98E792AFC5 ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys 13:46:05.0173 0x1140 cdrom - ok 13:46:05.0248 0x1140 [ BAF8F0F55BC300E5F882E521F054E345, FB228DB18F2FA55D8BA35A7E6778EE5D2EB0C29D384F1A0A868F90AE706188D7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll 13:46:05.0266 0x1140 CertPropSvc - ok 13:46:05.0305 0x1140 [ 27468DB367ABCFE855796775DB949AC1, F2DFC8CFBFCDC94798A5ADAAC96001927F9CE316751D42651C3AF1E52F1DC7EF ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys 13:46:05.0324 0x1140 cfwids - ok 13:46:05.0359 0x1140 [ F64B7D1A37CC1D5F421D5359EEC81E2E, 2B4879DD32B2C20B94847755E22B1BCBE2B567B3989C57A9BA2DD783307EFFDB ] circlass C:\WINDOWS\System32\drivers\circlass.sys 13:46:05.0391 0x1140 circlass - ok 13:46:05.0428 0x1140 [ 9905168708DB68849B879B5548F68AB3, B7A495E57B9398704988DC472126CBC5B8D76761A34F51732FBF6CC88E3AB79A ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys 13:46:05.0452 0x1140 CLFS - ok 13:46:05.0464 0x1140 [ 2DC8538A2260647484A6C921CA837313, 094059DD66B0C50A1CAE288F920107B0B6AD1AA5758284E35B92C131EDEA30EA ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys 13:46:05.0482 0x1140 CmBatt - ok 13:46:05.0615 0x1140 [ 45845AF69F92DEA0347168DFC6FA917B, AD31DFF99CA91A75F2636BBB4908103AE0C60727B3D1495E3EDF3A28EC7990EE ] CNG C:\WINDOWS\system32\Drivers\cng.sys 13:46:05.0665 0x1140 CNG - ok 13:46:05.0692 0x1140 [ 0E5B1E9E7122EDAAF1F6CE047965CA92, 803E585B92D1E2E5B6BF67BE511E88DC2629A12407C3E30F7AEFB544D390A9B8 ] CompositeBus C:\WINDOWS\System32\drivers\CompositeBus.sys 13:46:05.0714 0x1140 CompositeBus - ok 13:46:05.0718 0x1140 COMSysApp - ok 13:46:05.0724 0x1140 [ D9CB0782AF819548072AA45B70F8B22D, 04796F39ABB88759A534DE3D0C51F684BF2A8DE1F4028B657CCFDBDD39A6618C ] condrv C:\WINDOWS\system32\drivers\condrv.sys 13:46:05.0740 0x1140 condrv - ok 13:46:06.0188 0x1140 [ 78AF1C499BF02F9814DF959A04A4F9C9, 9D569A57551C7ACE032C3ECC7BEB8C7606D6BAF58AC1660B4E9FBE907F47E274 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe 13:46:06.0216 0x1140 cphs - ok 13:46:06.0279 0x1140 [ 5CE2742F063731EC10C1B2EE386A2C08, 309919BDDD4649AFB95A99DCF8AFC3BAE10F9BC1E2819C0794CFD0F80682C223 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll 13:46:06.0300 0x1140 CryptSvc - ok 13:46:06.0337 0x1140 [ C4D01BD86D6B207275FC143EEA951D75, D36F7BBE0DB3EAD0C74DE5E6622C89D4568760D8735B6E191AD30990EA8018DC ] dam C:\WINDOWS\system32\drivers\dam.sys 13:46:06.0354 0x1140 dam - ok 13:46:06.0421 0x1140 [ 1EC6E533C954BDDF2A37E7851A7E58FD, C25936A7465B6A2B3D05D2FCB09D91ACC07CFE038A5E968C99CFA9D9F2967DD4 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 13:46:06.0467 0x1140 DcomLaunch - ok 13:46:06.0512 0x1140 [ C8650D1F61149AA546BDBC99172EBBC1, D9592ED1B6F23B6EC76A0B93635B6E38702311B0A6982F0F9DEC37FCDAF1288B ] defragsvc C:\WINDOWS\System32\defragsvc.dll 13:46:06.0546 0x1140 defragsvc - ok 13:46:06.0614 0x1140 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16, ADAC7FD6AC12B50F4998C5EB0BD770DD4B80A94C4CC1B9376AD77648E48D012D ] DeviceAssociationService C:\WINDOWS\system32\das.dll 13:46:06.0645 0x1140 DeviceAssociationService - ok 13:46:06.0690 0x1140 [ 799BE46D45D486704CE0F37CA5385262, BB78DEE83B9DB613B1C083D55FAA458BE3E394AED80EB91B599185A7272F33B3 ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll 13:46:06.0706 0x1140 DeviceInstall - ok 13:46:06.0741 0x1140 [ 09D9EB9E7898F8E6561473A20CC808B9, 0F511593D36084843E5138AF6D55FE08D77803968AE12A236A02368DB364347E ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys 13:46:06.0760 0x1140 Dfsc - ok 13:46:06.0800 0x1140 [ 9E0E72222264745ADEB0E5AC680B0ED6, 576AFC8741695396A3B8E9DBDD3703E9D70370437D09D162262E47A140D101B4 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll 13:46:06.0847 0x1140 Dhcp - ok 13:46:06.0876 0x1140 [ 3C736FAE17BA6F91BA37594AAB139CD0, 34304A194105B19E7ADD80108DC85C3B7AA9E942C84A7EF93C475CE1D9AE4615 ] discache C:\WINDOWS\system32\drivers\discache.sys 13:46:06.0902 0x1140 discache - ok 13:46:06.0909 0x1140 [ 560495FF4CA22E1D9B1972FA18F43B6F, 41FFDD4C1097AA857A8177E34F101A1A9C1429A4E8DEC3D395C6135A9E112CD6 ] disk C:\WINDOWS\system32\drivers\disk.sys 13:46:06.0925 0x1140 disk - ok 13:46:06.0930 0x1140 [ 82A7C72593793FE1EADA7A305BD1567A, 75F432E4C75AE9EFF553BD860B3B250853BDDA85C17DBD9B7242D74593506A86 ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys 13:46:06.0947 0x1140 dmvsc - ok 13:46:07.0008 0x1140 [ 066B9710B36AB550E01EEFCA52155968, DCA9F3F4856A6866D3F5A2EEE34E96A83F40198DB0B5AC6381A7568DE1F56FAB ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 13:46:07.0029 0x1140 Dnscache - ok 13:46:07.0087 0x1140 [ 9949AD2ABA168A618D46C799D6CC898C, DFAC86A0AEE83C9EFE1BEE9EC15C8CAF1D619D55AF3ACC3986057A5AC985D06A ] dot3svc C:\WINDOWS\System32\dot3svc.dll 13:46:07.0447 0x1140 dot3svc - ok 13:46:07.0533 0x1140 [ 109FC3F80BF4F4DC5A071058074F13C1, F30736F45BA1811D59E9CB1C172D8D1EA9F5A7D36DCFFBFC9E7E02448C1CF851 ] DPS C:\WINDOWS\system32\dps.dll 13:46:07.0567 0x1140 DPS - ok 13:46:07.0645 0x1140 [ 9C7C183F937951AE17C5B8B3259CF3FF, 8ED607139F15D08B4835ACF864421BA4C08C88FE90B9AAF707F5D8514D7731B1 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 13:46:07.0662 0x1140 drmkaud - ok 13:46:07.0864 0x1140 [ D2BCDD6BBFCD068090C109854FCEE079, 6DC8C67713566ABD2CC7860359AC7ABDBA8B6949D8F7ED001730BB0D53010693 ] DsiWMIService C:\Program Files (x86)\Launch Manager\dsiwmis.exe 13:46:07.0881 0x1140 DsiWMIService - ok 13:46:07.0963 0x1140 [ BF48F32EE248C3D371DA5DC93BBEADA7, C8E9B685A8F2F99140382557F11E362D899E7EC6693ADEFE762F0A3850585C63 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll 13:46:07.0985 0x1140 DsmSvc - ok 13:46:08.0415 0x1140 [ AC47D05143E1E4D49D451E2A1784B2CB, A7104EC79B5B8ED1AB4E39159291C7D41D50C90E4698B1F59AC690EE5D27362C ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys 13:46:08.0514 0x1140 DXGKrnl - ok 13:46:08.0560 0x1140 [ CCED99682127E8582E5F716ECE775EF8, 3B0A51E1FC4D5BD3E7EC182799AD712AEEAF1DCD761D7E98BEC8A0A67F7334AF ] E1G60 C:\WINDOWS\system32\DRIVERS\E1G6032E.sys 13:46:08.0578 0x1140 E1G60 - ok 13:46:08.0627 0x1140 [ 58BA473DD88F5FC1932282BA683AA03E, B8A4407D3006D91BE88F9C5389AC1CACC73BEBF6F66433A1E5EB8E58E8836C12 ] Eaphost C:\WINDOWS\System32\eapsvc.dll 13:46:08.0645 0x1140 Eaphost - ok 13:46:08.0748 0x1140 [ 5AB97B3282D7D6114949D1EB5C8598E4, FB9449CC1CDC12C12AA0469BB6ACC770CB011250EDFD86E9600E754610608EFD ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys 13:46:08.0882 0x1140 ebdrv - ok 13:46:08.0958 0x1140 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] EFS C:\WINDOWS\System32\lsass.exe 13:46:08.0973 0x1140 EFS - ok 13:46:09.0015 0x1140 [ 66D60BD9A4C05616ABECA2A901475098, 8111550DB03FFD72F1822F47B16F075DA92874B64F19342D7CF60B0EE648AFEF ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys 13:46:09.0032 0x1140 EhStorClass - ok 13:46:09.0038 0x1140 [ A61D0F543024E458C0FE32352E1978E2, BDE6BC140300EAF790F16466C28897CE0BD7D94DCED13FDE20AA4AACA0F6A4FD ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys 13:46:09.0052 0x1140 EhStorTcgDrv - ok 13:46:09.0172 0x1140 [ 616E1B9130314EB0E331197940AA625B, A4736A31EFF6D35A27B0EC14A7C855B7577301500E20CE936B0F1C0013F0FDF0 ] ePowerSvc C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe 13:46:09.0192 0x1140 ePowerSvc - ok 13:46:09.0239 0x1140 [ D790D058D67582DB9C84C2D33695FE6B, A5763D7F6D191EA4B290B3E92D842AC36FD46DF598472E70B46E45D8CCD2F912 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys 13:46:09.0301 0x1140 ErrDev - ok 13:46:09.0579 0x1140 [ F9E01C2D9F8BC049E04CF5DC24A5F638, CB6CCB59C77D4A59DDA846608AABEF1DFEC24C8422712AB8D59E27C13D731D2E ] EventSystem C:\WINDOWS\system32\es.dll 13:46:09.0621 0x1140 EventSystem - ok 13:46:09.0650 0x1140 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03, 6B0146A4C9AD32DCDC2DEE8E8C5A29F687665458486449E0D37B151ED63B8ADC ] exfat C:\WINDOWS\system32\drivers\exfat.sys 13:46:09.0679 0x1140 exfat - ok 13:46:09.0692 0x1140 [ 60996602A7111FD2D086E803F33E4282, E62A91C90F8542990BEA4E6A5D9DD3D070F4EB23B4C13414C5DA2B0219509749 ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys 13:46:09.0707 0x1140 fastfat - ok 13:46:09.0818 0x1140 [ F0E7F8382ED5E138B0DFA4CB5058BCFE, 6247C7B75F975F5AB080FFB9881EF58A6F360219F7AF2DE871F38E80CAF3B62C ] Fax C:\WINDOWS\system32\fxssvc.exe 13:46:09.0922 0x1140 Fax - ok 13:46:09.0971 0x1140 [ 73B2D11DF0B6E03A0CB0323218ACB3E4, BA9256919BAA2E0760F6A658B557FDC389ACE8F9820D1A41FD995FC5613F5AA6 ] fdc C:\WINDOWS\System32\drivers\fdc.sys 13:46:09.0998 0x1140 fdc - ok 13:46:10.0041 0x1140 [ 0828E3E7BD77C89149EAD3232BFD38DB, A6A296647A4EDBFF59124E3A9C0AB48759AA1738615ACFA5A454FF6BD3C31BA2 ] fdPHost C:\WINDOWS\system32\fdPHost.dll 13:46:10.0071 0x1140 fdPHost - ok 13:46:10.0102 0x1140 [ 872506AAB591E8908DF4461475AF92DF, 772F2D08CB95775E438822B9EA005CBA92ED4071ADAB2C0101156A7D037D4704 ] FDResPub C:\WINDOWS\system32\fdrespub.dll 13:46:10.0126 0x1140 FDResPub - ok 13:46:10.0149 0x1140 [ 0588950D93A426F97C7AAADB1A9B0458, ABCB3619BD58CAC438FC032495AE45A7B6FFDD4BD33C1B3D1BC7F9F13FCB727A ] fhsvc C:\WINDOWS\system32\fhsvc.dll 13:46:10.0194 0x1140 fhsvc - ok 13:46:10.0227 0x1140 [ 88A9EBACD1058ABB237A6B4E96E7F397, 263D25D33B679EB01D97763701347C31B2F72E28CE2C7EC8013EA77756D98BE1 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys 13:46:10.0244 0x1140 FileInfo - ok 13:46:10.0257 0x1140 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02, 1D7BFB00D74A28AC13ECBA1E0036D50EE79266AC02CEDB2632466BF9DD46F211 ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys 13:46:10.0281 0x1140 Filetrace - ok 13:46:10.0335 0x1140 [ B1D4C168FF7B8579E3745888658FFB1D, 1A5C13E902A0C788A8B995ADD2FBC3303005911C0AA3F3F4497D3016AA0EF583 ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys 13:46:10.0364 0x1140 flpydisk - ok 13:46:10.0395 0x1140 [ B33EC133AE4E6C1881D2302D93D2467D, 77E3A16257EA3698B3FCD947D004144E8D1EEE48EF5C82DF49B1B9B2B3C61DB2 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 13:46:10.0438 0x1140 FltMgr - ok 13:46:10.0560 0x1140 [ AD61E8B66750B9C921F52FF6287C9B30, 6C284E7DC99D2A7DEE269FBCBF2FA97B035268F37633EE667DEEBAE627D51F83 ] FontCache C:\WINDOWS\system32\FntCache.dll 13:46:10.0660 0x1140 FontCache - ok 13:46:10.0804 0x1140 [ 0B56259F5611787222A04A8F254E51D4, F77AEC0ACBFAF9154E32223B84B613229DACCD953AEBC3E96C27570F9AB10FD0 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 13:46:10.0828 0x1140 FontCache3.0.0.0 - ok 13:46:10.0888 0x1140 [ A5F7873A39E4E9FAAAE59B7E9E36B705, 32036109F5A50E9F3BEF97C5B28AE8179B3A5E22517868A83CADE4671FF90DEC ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys 13:46:10.0907 0x1140 FsDepends - ok 13:46:10.0933 0x1140 [ A6DD7D491F587F4BC13FB972977DC8E8, B86F97F17F6F443EC16DEF67CCA4EF78AFE56078D2877838A982FECB19557C87 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 13:46:10.0942 0x1140 Fs_Rec - ok 13:46:11.0011 0x1140 [ FA228F4BB10DC7ED7E7D131C034E2331, 0463B1DB8BB2B5AF95EAD988EA9DEB5483D9E78C07E07BAC1E3CC46C086B3BB0 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys 13:46:11.0041 0x1140 fvevol - ok 13:46:11.0068 0x1140 [ A969D92973DFA895E7776B4BFE36DBB2, 7528E6983ECC59291A7A386E4E459B19D1593ABDDFFD276E2F01B0EA21693E20 ] FxPPM C:\WINDOWS\System32\drivers\fxppm.sys 13:46:11.0083 0x1140 FxPPM - ok 13:46:11.0093 0x1140 [ 52BC441E07A827EBAB70CDC7EAEDB28D, 8DECBD8E12EA52039742599CFBBF0D3B6610B57EF8D9DAEEEA33D202A478D286 ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys 13:46:11.0111 0x1140 gagp30kx - ok 13:46:11.0264 0x1140 [ C403C5DB49A0F9AAF4F2128EDC0106D8, 3C6948B63278022D8182F773C5FA15784514F76C1546118DDBADBA322B962D12 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe 13:46:11.0280 0x1140 GamesAppService - ok 13:46:11.0390 0x1140 [ 1B61BB65753CFBAF8448DA6E71E1D9F1, CB67917922357DF20BE06DF5C12276C10C7C6A1F672DF36C4CAE0D2A5B09A97F ] GDBehave C:\WINDOWS\system32\drivers\GDBehave.sys 13:46:11.0416 0x1140 GDBehave - ok 13:46:11.0487 0x1140 [ 1314062567B9ED86BFFDE5D8C48C52AE, 01DE02308E478F50DBFE4C6EAE9D0C052C1575283F2C182388E2028F3BF2E756 ] GDElam C:\WINDOWS\system32\DRIVERS\GDElam.sys 13:46:11.0522 0x1140 GDElam - ok 13:46:11.0835 0x1140 [ 96A9A12E11544EEF39375314176068CE, 7ED8BA4F2F151A97458BCB754B5BC6E4C346DB6E8E162D50D6E425C8102ED205 ] GDFwSvc C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe 13:46:11.0927 0x1140 GDFwSvc - ok 13:46:11.0967 0x1140 [ FF5543CDA6B06E3D29A5F312BE5C4919, 91E0BB934EFD01576C94FDA967340563BB92ECE7C5389978FBC9587A9D21B9CF ] GDKBB C:\WINDOWS\system32\drivers\GDKBB64.sys 13:46:11.0984 0x1140 GDKBB - ok 13:46:12.0015 0x1140 [ 1543775197DD1A27D16C0FA0FF73CAFB, B149282AFA5A60CEC797B643207F2541722C360989148FBC7A06DA0EB501ABED ] GDKBFlt C:\WINDOWS\system32\drivers\GDKBFlt64.sys 13:46:12.0036 0x1140 GDKBFlt - ok 13:46:12.0074 0x1140 [ 1A407BA6FAB577D7C198D9F10D26B2F6, 6CB266EB6D66F55D33DF2EB9474E6D9932288A03F411C1FEEEF48D8074E669D3 ] GDMnIcpt C:\WINDOWS\system32\drivers\MiniIcpt.sys 13:46:12.0094 0x1140 GDMnIcpt - ok 13:46:12.0183 0x1140 [ 2F9A187ABCB088EC78601857199C39FA, F6A64EAAF8FEF7AD98ECCE722C6FCE4FD3DFC6C99E71C70DF88260AFE5E51D29 ] GDPkIcpt C:\WINDOWS\system32\drivers\PktIcpt.sys 13:46:12.0195 0x1140 GDPkIcpt - ok 13:46:12.0424 0x1140 [ E9B7AF2C5C7B9AD739718AA7ED5F1911, 52C1B75B97DBCF343A6A7045E1F42C8BB35FF23CC2B463EA1B858FCD5B85678F ] GDScan C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe 13:46:12.0450 0x1140 GDScan - ok 13:46:12.0490 0x1140 [ EF57913C0078FC0263A564FB6581E32E, CAF281DA8635FDB9E2006F26A9B4DC93286F8F44E1EB6BE5A73113631A228E66 ] gdwfpcd C:\WINDOWS\system32\drivers\gdwfpcd64.sys 13:46:12.0501 0x1140 gdwfpcd - ok 13:46:12.0538 0x1140 [ 721F8EEF5E9747F32670DEFF7FB92541, E0A8EF70753E260C2C7D93D316B5EF9589DB086FDF829BDA2958C6A09CE471A6 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys 13:46:12.0552 0x1140 gencounter - ok 13:46:12.0606 0x1140 [ CA18ECFCFFDD638ECE80799A9056B238, FEA6778443253CBAA9FF43A980D576A3F449B036151F91495F04CE0C54F02254 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys 13:46:12.0620 0x1140 GPIOClx0101 - ok 13:46:13.0081 0x1140 [ 5358678C6370F2ADC5291849F6503262, 841633D7A936C3889690C67E189BAD4C6B294C196FFFE5B564FCECDFE46A9E52 ] gpsvc C:\WINDOWS\System32\gpsvc.dll 13:46:13.0310 0x1140 gpsvc - ok 13:46:13.0357 0x1140 [ CC708C622ECD93248158682AF088830E, C7FCF70E284F095E2D400BC0E7F807F772F385916C258E5F4F05C8CDACCF8754 ] GRD C:\WINDOWS\system32\drivers\GRD.sys 13:46:13.0368 0x1140 GRD - ok 13:46:13.0431 0x1140 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 13:46:13.0440 0x1140 gupdate - ok 13:46:13.0446 0x1140 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 13:46:13.0456 0x1140 gupdatem - ok 13:46:13.0574 0x1140 [ 9FC1F11D4D19F61DFE5CC878B4557D3A, 17A0EC253D04FBD25C2113FD96FBF9D822E8295623C1B1DDA712FB102D42E956 ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys 13:46:13.0623 0x1140 HdAudAddService - ok 13:46:13.0679 0x1140 [ 7D87B5B6C7188D553E11B59DC7F0B111, FC633DB71E1D72E8AD8F89BBB54324CC6ED17F5594EF55DD0BDB58EE1F601FF5 ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys 13:46:13.0695 0x1140 HDAudBus - ok 13:46:13.0700 0x1140 [ 3F76BBA53D65E85A7F53E7A71082082C, D1E18815BB19CD11007C4A66162C76F55D4FE6B09B34ED45969C7ECC29D394AD ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys 13:46:13.0714 0x1140 HidBatt - ok 13:46:13.0782 0x1140 [ 085F150D002B7F0153D3C06DDF33A143, 41847FD02608ECFE3A6B4B38CBDE8416B0EF17491868511FD704B0BCC280338E ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys 13:46:13.0824 0x1140 HidBth - ok 13:46:13.0873 0x1140 [ CC4A07E51D89575CAB6F4EB590D87CD4, DFB4EAF0923EF9FF6C42EDD1EA5E4025F243C9BE2D03D5423FE8A897DC01D657 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys 13:46:13.0932 0x1140 hidi2c - ok 13:46:13.0964 0x1140 [ DC96F7DACB777CDEAEF9958A50BFDA06, 7CE79F32D5EE65C0178CFF56523825D3EE01095B2CE8C67634A6604A821A9086 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys 13:46:13.0984 0x1140 HidIr - ok 13:46:14.0052 0x1140 [ FAC37D7B3D6354A5A5E19A45B50B4008, 2962B552A1DA545DFDEF0886582E82596FE8A3A19AAF989B025AFDA84D16D4EC ] hidserv C:\WINDOWS\system32\hidserv.dll 13:46:14.0066 0x1140 hidserv - ok 13:46:14.0098 0x1140 [ 012C354B4AB48E9A7A657DF39E3A2073, B15D0089CE509FF1CF73DFE095425C1C99FC3971622DCAAD9CAEB989A12A4FDB ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys 13:46:14.0189 0x1140 HidUsb - ok 13:46:14.0333 0x1140 [ 29F981739E50305128022CBE10B3659C, 25060937145B0DCA8CD088E78993BFEF1430CDDFF433E606AFC93993CBBF4B3E ] HipShieldK C:\WINDOWS\system32\drivers\HipShieldK.sys 13:46:14.0356 0x1140 HipShieldK - ok 13:46:14.0407 0x1140 [ 43F884B61A24377567CD0FEB35236334, B3BA36B527C8D6D83DE2FBCD8D503B87FD2611BF15B07A7BC138DC8BAE6A50C1 ] hkmsvc C:\WINDOWS\system32\kmsvc.dll 13:46:14.0429 0x1140 hkmsvc - ok 13:46:14.0538 0x1140 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF, E6967F3F465C6E903221BC0FCBAE7D05FD18C0BF110D929335F5935364B3C1BC ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll 13:46:14.0580 0x1140 HomeGroupListener - ok 13:46:14.0657 0x1140 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E, B965DCC72625188F3B896CB447B7696F22687266EAFC5AA270E2AD53DD9F324D ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll 13:46:14.0811 0x1140 HomeGroupProvider - ok 13:46:14.0837 0x1140 [ 82A3266E96EC3961872372EC9A7C131A, A57BD50800AB005C09FC77052EA7B62F1F6FAD11EB429F8F1AF2C5B977853137 ] HookCentre C:\WINDOWS\system32\drivers\HookCentre.sys 13:46:14.0849 0x1140 HookCentre - ok 13:46:14.0936 0x1140 [ 64DB7A8D97CA53DCCF93D0A1E08342CF, 02CAB7F28D3830C482683425C60044239C6F1562556688A274CA2C237C846E76 ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys 13:46:14.0966 0x1140 HpSAMD - ok 13:46:15.0116 0x1140 [ 29CB98187BB5711F7759540976D295FC, 75F98F2E2CA19B637DF1FC7C4E1FCCF0C50FCEDC69E07B2AD6AE139ED8E3AE99 ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys 13:46:15.0188 0x1140 HTTP - ok 13:46:15.0193 0x1140 [ 2A98301068801700906C06649860FE94, 664394A52326289DCA0828B0041A105653F4FEF3E3DCCC3787AAE0F6FDC73A14 ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys 13:46:15.0205 0x1140 hwpolicy - ok 13:46:15.0210 0x1140 [ DC76901D82097C9E297F20C287CB9A27, 01A412D0D8A65050BE4250A7C4B9F98A4C43FD891827761E0C830369A5F9F09C ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys 13:46:15.0222 0x1140 hyperkbd - ok 13:46:15.0227 0x1140 [ 716413AB3CA12DE0A7222D28C1C9352C, B82B586BD9DBD70DDA19A02504E8CB00DA53677703AB848B53387601C5BAD3D3 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys 13:46:15.0240 0x1140 HyperVideo - ok 13:46:15.0265 0x1140 [ C9E9CBF73AFFBFE3E801EFB516787BA3, 1A850D614BDA6AA4195CC657702BC6242BA51B90131717743182AA160F65E72C ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys 13:46:15.0282 0x1140 i8042prt - ok 13:46:15.0347 0x1140 [ 6C024B3AE192D72B216166802AF345DD, 67AEDBEF4A1C1EE1DA9B684BDEB3DB07715E12B766AA72B6684CC6C583A8DCC5 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys 13:46:15.0374 0x1140 iaStorA - ok 13:46:15.0388 0x1140 [ 5E394EBD26FD68AA9300332C46BEDD62, 56A5DA7CE08C07B519E55D0A46AA9D10B640349808EFE02B3278267B75B5F603 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys 13:46:15.0415 0x1140 iaStorV - ok 13:46:15.0872 0x1140 [ A1CF07D24EDCDC6870535471654D957C, FA0CD2ABA2C15E9FC4A1DEE58F365EC10D9597D521556DC2648B50CE0537926D ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys 13:46:16.0101 0x1140 igfx - ok 13:46:16.0163 0x1140 [ 24847A06B84339FEEDE5CABF3D27D320, 7727B1DAD0D4A1D474FBBEFCEBDF36A1F07D1AA300869AE57A24ED91BF84B6B4 ] iirsp C:\WINDOWS\system32\drivers\iirsp.sys 13:46:16.0176 0x1140 iirsp - ok 13:46:16.0303 0x1140 [ 644D7E4EAC8D5CE757435FA98A7BDA50, 7C91F6E75B148E69BF701F0152CDBF8FB94009935EE97F5208560E1E8FEDA4DB ] IKEEXT C:\WINDOWS\System32\ikeext.dll 13:46:16.0343 0x1140 IKEEXT - ok 13:46:16.0517 0x1140 [ 9CC645EB9697AA4F2D5A39835C80A0A2, 39861B19E9BF17F5250D571996167A178606150B62C876529D3699817FDDC42A ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys 13:46:16.0701 0x1140 IntcAzAudAddService - ok 13:46:16.0793 0x1140 [ F5495B38BFB9149925F54F65AB40EFBF, 7CBB72C41E2343DACBFB967A39CA04788561EDECB289C41BC2D6A06B80882AC4 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys 13:46:16.0819 0x1140 IntcDAud - ok 13:46:16.0964 0x1140 [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC, F791EE101EEF8B9F48102B6C63A89B78F7C0041C750C4F4C0D16D54B583B7B5C ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe 13:46:17.0000 0x1140 Intel(R) Capability Licensing Service Interface - ok 13:46:17.0029 0x1140 [ 4F37726CF764CA18A8A84F85EF3A7F24, 6212B23917526E127CE641A11A58DA93651FFE70829C4079FE465DBDC81CF470 ] intelide C:\WINDOWS\system32\drivers\intelide.sys 13:46:17.0042 0x1140 intelide - ok 13:46:17.0083 0x1140 [ E15CDF68DD73423F15D4AC404793AF0D, E2D0136AF68D1A73EB3A63C83284B4661222CB0A4AFACCF276CB57CBD4850287 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys 13:46:17.0100 0x1140 intelppm - ok 13:46:17.0107 0x1140 [ 8FCA66234A0933D796BB780B7953BAB9, 7DD677F5EE09A8D7A75C9E475B5E6B3DCA49D1E846C7D160B839D7029B1C5B6D ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 13:46:17.0125 0x1140 IpFilterDriver - ok 13:46:17.0324 0x1140 [ CAC5202757EF68C4849B0DFFA75F6D3C, D68EDCED68DB7755AA8BE5EC2784C124888BA4ED33B3E366FD83C3E64E42B770 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll 13:46:17.0388 0x1140 iphlpsvc - ok 13:46:17.0433 0x1140 [ 6E98A046A12AA113F8898AA5D612BD6E, 28816CC1F03F2BFBF099C087C0BB6949E959F44C888DD2D0528FF7ED5D665ECF ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys 13:46:17.0457 0x1140 IPMIDRV - ok 13:46:17.0474 0x1140 [ 3969B9C218DD3FAA9F4ED2FFC3651C02, 93447F124CC55FB17055126432194153E1BB8F0FD95A47608494B6834A5F7089 ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys 13:46:17.0492 0x1140 IPNAT - ok 13:46:17.0523 0x1140 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C, 4099BAA2DB4ADB93B878D71E241B7D9EB7E0EE7ED0FE2450CCB9E4718B3726EB ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys 13:46:17.0558 0x1140 IRENUM - ok 13:46:17.0564 0x1140 [ D940C5BB9DC92E588533C19ABCC3D2C2, D1442854CEDE86F2C187A35851E74C873D34B772C60BC118FA1577F79C03364D ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys 13:46:17.0578 0x1140 isapnp - ok 13:46:17.0612 0x1140 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF, 8FFF92828C3DC20F0F42C42E58A03B59A4E0187963F728DC618C9595FB2D0239 ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys 13:46:17.0631 0x1140 iScsiPrt - ok 13:46:17.0812 0x1140 [ 3C4002D339491AF73D663FFC7F6E5ECB, 0B53047989BDB781572253BC3AA757912FE54366870C1955E687972CE210C285 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe 13:46:17.0828 0x1140 jhi_service - ok 13:46:17.0935 0x1140 [ CB30BC4ECF8B96BC090EC5DA09E9B17D, 82F4A3B076F16EB8A321E97E0AD6DE6DEE10A4C8A8F158DCB961EEA841781F63 ] k57nd60a C:\WINDOWS\system32\DRIVERS\k57nd60a.sys 13:46:17.0968 0x1140 k57nd60a - ok 13:46:18.0050 0x1140 [ 8FBD94B69D6423E20ABCD59D86368B21, 218EF992095E365EC917413749856A64D55D8129D77098E24D670843233377F4 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys 13:46:18.0076 0x1140 kbdclass - ok 13:46:18.0082 0x1140 [ E88C932ABDF8185A62C8F2FC7B051FB6, 67F9AF58237A11F0BF3D15AA5B32E5CE66B7AA039B999D938F7F6E63DCEA7A6E ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys 13:46:18.0099 0x1140 kbdhid - ok 13:46:18.0121 0x1140 [ FB6C185092E18011EF49989425C2AA87, 043524409E0A764201DD221C48B7DEEA0D161945EB37D4B88313BAB2299949DF ] kdnic C:\WINDOWS\system32\DRIVERS\kdnic.sys 13:46:18.0139 0x1140 kdnic - ok 13:46:18.0212 0x1140 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] KeyIso C:\WINDOWS\system32\lsass.exe 13:46:18.0244 0x1140 KeyIso - ok 13:46:18.0305 0x1140 [ 559A933F5647A7A2783C8A0C6CB0514C, B4CF12D409F14E21DE081A5D7FC935719582FADA1505D03301B444B6B027F1EB ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys 13:46:18.0341 0x1140 KSecDD - ok 13:46:18.0427 0x1140 [ A01C9741FD25D87D9E2609A9B1C914C4, FA805767301C2EF1C451C86D0ED27C6A5D2417C3BAD66CB55F8F9682653AFD45 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys 13:46:18.0849 0x1140 KSecPkg - ok 13:46:19.0319 0x1140 [ 81492FEEBF2F26455B00EE8DBAE8A1B0, E33AA2DFB2D3BB30B02CDADA2EC290F86329DA3198327A653F39A843D86390B9 ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys 13:46:19.0350 0x1140 ksthunk - ok 13:46:19.0458 0x1140 [ 5825DBACEDC3812B5CF8D40B997BF210, 1C2997BCC707C1029B21876E093038CE3BBF6E6694B4CCF7EEDD47172ED9A541 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll 13:46:19.0494 0x1140 KtmRm - ok 13:46:19.0620 0x1140 [ 256EE31588257E8A555DBFAA13F1908E, B6817F632EDEA483E35BF26846DCDD4E95E860620959179B2A5D8AD7EEDDB126 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll 13:46:19.0665 0x1140 LanmanServer - ok 13:46:19.0735 0x1140 [ 16650912BE5A94B40E0B3B4C39652B56, 908C2C9367AE0AC9AECB5D91514BB33ACD746D99F19C1A8DD6A9550E9CAD9E00 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll 13:46:19.0761 0x1140 LanmanWorkstation - ok 13:46:19.0798 0x1140 [ CEEFD29FC551F289810B0B9381B321DC, 900F206B487B2190D9363F28AA4BA0CD7DCFE1D005BE05A48AF74B1B81194691 ] lltdio C:\WINDOWS\system32\DRIVERS\lltdio.sys 13:46:19.0822 0x1140 lltdio - ok 13:46:19.0875 0x1140 [ BCF53485E0A94722CDE3C4A93CD8EB8C, D24E1066EB102245A89A5D17D608DB9DF6B71C99F1C77E070B95EFD17D268141 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll 13:46:19.0896 0x1140 lltdsvc - ok 13:46:19.0903 0x1140 [ 5A2F7F1CBC2E631A497DAD16164E06D2, 35274FC6C386380B01B5E8F467E71A2C4E2FB2AD701554F9B1A9B036B0340142 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll 13:46:19.0931 0x1140 lmhosts - ok 13:46:20.0041 0x1140 [ 4269D44BB47A6DA5D80B11F4C8536458, 7A8FFC8F851DD9E5C43986BE0888831CB71D188138DF3CF7F787DADDA70915B0 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 13:46:20.0060 0x1140 LMS - ok 13:46:20.0111 0x1140 [ 022CDD12161B063D7852B1075BF3FFF2, E21267243AF2FC208D27E67827B1264A762C99AECEDB7AD2C48A04F421A6B2F0 ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys 13:46:20.0127 0x1140 LSI_SAS - ok 13:46:20.0157 0x1140 [ 07AD59D669B996F29F91817F0ECFA34F, 026F332F862D142BFFC9D169CCD17A35BFB6B301EEC72AA13E16369B3520919C ] LSI_SAS2 C:\WINDOWS\system32\drivers\lsi_sas2.sys 13:46:20.0174 0x1140 LSI_SAS2 - ok 13:46:20.0198 0x1140 [ 216FB796AA4E252ACCE93B1BCB80B5EC, 5B1E49B5F7B9C7A778198D27F8EE500FE35DC32D40B22A3D6ED67560BEB04212 ] LSI_SCSI C:\WINDOWS\system32\drivers\lsi_scsi.sys 13:46:20.0220 0x1140 LSI_SCSI - ok 13:46:20.0236 0x1140 [ 5E80530AF37102488EE980B4A92AF99F, 364E18EAD9AC22F8A306B24C6C43E58224F6BE2744EFEAA2484696B8D9880851 ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys 13:46:20.0257 0x1140 LSI_SSS - ok 13:46:20.0353 0x1140 [ 1DC9B701F8EB7D67774035AC9C3104F6, 77371267CDA605F78674BF8FA14B134B22299CD96EADA60A68762207595F0B46 ] LSM C:\WINDOWS\System32\lsm.dll 13:46:20.0379 0x1140 LSM - ok 13:46:20.0397 0x1140 [ 2BDC5D711FA61307CE6190D47C956368, 6BCDC6CBB9783F1ABE8957BDA94AF977DFB2A310BB6D19085EFC8609C97FD180 ] luafv C:\WINDOWS\system32\drivers\luafv.sys 13:46:20.0421 0x1140 luafv - ok 13:46:20.0588 0x1140 [ 37D933470CA4BA9CDA7238CCBAA21AEE, 38E2E0E937F00374B7ACD9C7258579724A16A0B33C438CEAE183A6B5C9DB1F3E ] McAfee SiteAdvisor Service C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe 13:46:20.0599 0x1140 McAfee SiteAdvisor Service - ok 13:46:20.0843 0x1140 [ 1E3AF124A3405EEE594BB9FFD4640F48, 7916D86433A6A305CC9699A8901795E74A22C99A2C6B091BAC951E30F7510FF7 ] McAWFwk c:\PROGRA~1\mcafee\msc\mcawfwk.exe 13:46:20.0865 0x1140 McAWFwk - ok 13:46:21.0098 0x1140 McMPFSvc - ok 13:46:21.0207 0x1140 [ C121367D21599367F2ADB9C11B7BABAA, 752993437AB2C797B5C0FFD397BC8FAC575886857C61BCCCCF169DA54BEE911C ] mcmscsvc C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe 13:46:21.0219 0x1140 mcmscsvc - ok 13:46:21.0267 0x1140 [ C121367D21599367F2ADB9C11B7BABAA, 752993437AB2C797B5C0FFD397BC8FAC575886857C61BCCCCF169DA54BEE911C ] McNaiAnn C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe 13:46:21.0288 0x1140 McNaiAnn - ok 13:46:21.0352 0x1140 [ C121367D21599367F2ADB9C11B7BABAA, 752993437AB2C797B5C0FFD397BC8FAC575886857C61BCCCCF169DA54BEE911C ] McNASvc C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe 13:46:21.0364 0x1140 McNASvc - ok 13:46:21.0597 0x1140 [ B26B99CE6218CC586B727CBA7C923233, DB5DD733BF81AB70F0EB9D1E8A6244531D22D96FA79FE4AC524E5C2B0564E639 ] McODS C:\Program Files\mcafee\VirusScan\mcods.exe 13:46:21.0624 0x1140 McODS - ok 13:46:21.0697 0x1140 [ C121367D21599367F2ADB9C11B7BABAA, 752993437AB2C797B5C0FFD397BC8FAC575886857C61BCCCCF169DA54BEE911C ] McOobeSv C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe 13:46:21.0720 0x1140 McOobeSv - ok 13:46:21.0805 0x1140 [ C121367D21599367F2ADB9C11B7BABAA, 752993437AB2C797B5C0FFD397BC8FAC575886857C61BCCCCF169DA54BEE911C ] McProxy C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe 13:46:21.0816 0x1140 McProxy - ok 13:46:22.0095 0x1140 [ 4DEC9B5BEDAA97B1FF6A3923E1C4F58A, F048949C6C2D7D4E6F667D6E9AF1574BD7F522A9505D92B7DAF956F105ADE2DF ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 13:46:22.0110 0x1140 McShield - ok 13:46:22.0231 0x1140 [ 9B0D829C3BE4E7472DB9DD2B79908E3C, ACED5806FFF39E84007B5A3DCB16315329DC53007F46B1BEEDC391CC659F7DD3 ] megasas C:\WINDOWS\system32\drivers\megasas.sys 13:46:22.0247 0x1140 megasas - ok 13:46:22.0333 0x1140 [ ECC3F54C7AFC318271C4F0B4606D8DB0, FD1ACB18B8C912C7A57DABCD5460800DD0721A82E09C8D79C47B3392D61CBEA6 ] MegaSR C:\WINDOWS\system32\drivers\MegaSR.sys 13:46:22.0365 0x1140 MegaSR - ok 13:46:22.0479 0x1140 [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys 13:46:22.0510 0x1140 MEIx64 - ok 13:46:22.0556 0x1140 [ D0574EF9490EBD32DFA14D3C16195DE2, 7F5623562E74BD09717103247CE9155F07092BC633B5647ED3C99A95283413B4 ] mfeapfk C:\WINDOWS\system32\drivers\mfeapfk.sys 13:46:22.0584 0x1140 mfeapfk - ok 13:46:22.0678 0x1140 [ 7B6A4509A2444F5F0689B2579E245177, 95A3A3560E253B7459F1B7C9E4E21008C725BA1A2C5F4E5FBAD1AB383058E2F6 ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys 13:46:22.0709 0x1140 mfeavfk - ok 13:46:22.0804 0x1140 mfeavfk01 - ok 13:46:23.0630 0x1140 [ C83EBEE66A2754CEE5B05699A42F728B, 1D739A505AEC1F40CC8CB86D01BDCEC0E29002A609FDA96CEF3531285E8261B9 ] mfecore C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe 13:46:23.0664 0x1140 mfecore - ok 13:46:23.0728 0x1140 [ DD19F44DE0F742B2E89FB6489A2F7197, B6BF5236181492B9996471469E18C3A11ECD6224BE740BA312771E1A7D4AD6BD ] mfeelamk C:\WINDOWS\system32\drivers\mfeelamk.sys 13:46:23.0752 0x1140 mfeelamk - ok 13:46:23.0853 0x1140 [ E7C6587AC8FB0BABEF6AB1733AFA8FEC, 1624B8D9C9431A2030B8C8CFAA90F56A9EE4039D2426A521C4102A68D2F8E3CD ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 13:46:23.0873 0x1140 mfefire - ok 13:46:23.0973 0x1140 [ 92AD9892D534CA58E020375C94E0307E, 3062625853C759852C5172040C69840315676A01A62EECFC53F55E6379DB190C ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys 13:46:24.0004 0x1140 mfefirek - ok 13:46:24.0059 0x1140 [ B6622A5B197D021647AE20E0D4C229B9, 15D64928FDB207C183A69E7CFB90BFFBF25F1AB14059EDEFDF021F323025F4E8 ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys 13:46:24.0115 0x1140 mfehidk - ok 13:46:24.0190 0x1140 [ 93712907DEE6FFBD8A4016ECBB250DCD, FB3673BA495EF1301C4BA75B457493D9B1D5AE52642A04473575CABC1EC6EDFD ] mfencbdc C:\WINDOWS\system32\DRIVERS\mfencbdc.sys 13:46:24.0220 0x1140 mfencbdc - ok 13:46:24.0254 0x1140 [ E97EE1F31F7E5349A06CE089658DA8A1, 8136155C734457E422331B3CBE67927C45FAB10B9B34789A612B58CF0E0E3BEC ] mfencrk C:\WINDOWS\system32\DRIVERS\mfencrk.sys 13:46:24.0273 0x1140 mfencrk - ok 13:46:24.0336 0x1140 [ D2A941C82A0A9227CD6F47AD40A40F69, CDB6BED989C45C3D15131AD43FB7A072117C327BAC5A691C2FE8B1F4A6FC2705 ] mferkdet C:\WINDOWS\system32\drivers\mferkdet.sys 13:46:24.0933 0x1140 mferkdet - ok 13:46:25.0343 0x1140 [ C4BF34A9C33832F9A23E849883D8D88D, 4DB4C025AE514A568E09943463E16B51C2A711C7567F3E7F34C8D266DACD87D4 ] mfesapsn C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys 13:46:25.0417 0x1140 mfesapsn - ok 13:46:25.0519 0x1140 [ 64BAFB4E5377056CDD71531097D69F6E, 28B434C1DB9AD930C5A32584C51FE1B3A4526952EBC953DAE775701E270C76C5 ] mfevtp C:\Windows\system32\mfevtps.exe 13:46:25.0548 0x1140 mfevtp - ok 13:46:25.0629 0x1140 [ A58F979117A424CDB33C21396887800F, E857E74BB08E49AEDC7EE21C9FDA36053113E04F8D29B9DBC3A2A3F0667915C6 ] mfewfpk C:\WINDOWS\system32\drivers\mfewfpk.sys 13:46:25.0708 0x1140 mfewfpk - ok 13:46:25.0798 0x1140 [ EEE908BE7143FCA48CF0CB87214E2AB8, 4F9BD299F559DD36DBD93489CFAA753F236FBB70946E034D2E2260059AE20962 ] MMCSS C:\WINDOWS\system32\mmcss.dll 13:46:25.0814 0x1140 MMCSS - ok 13:46:25.0911 0x1140 [ 780098AD5DA8A4822E2563984C85EF7B, 29312970774E944B5ED388316CF3D350DCABF721F9695737B0AC56BE878B0446 ] Modem C:\WINDOWS\system32\drivers\modem.sys 13:46:25.0982 0x1140 Modem - ok 13:46:26.0018 0x1140 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935, CC3F4E09F8834C7293B607446FECFE3CBB9B9151E65AAD38E2A4A8B30244DE14 ] monitor C:\WINDOWS\system32\DRIVERS\monitor.sys 13:46:26.0036 0x1140 monitor - ok 13:46:26.0104 0x1140 [ 618446B98C79776654340CE27C73485E, EFE7169FDD545933B5949DA2D09266971C0C3E6894E7BD8AFE29E41567C72B16 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys 13:46:26.0120 0x1140 mouclass - ok 13:46:26.0127 0x1140 [ CB2527B8B87D83E56FBF3944BBB6F606, F8DA5AF97B91099C58E14D1DACBCA02AF8F193E53A88DDC8CC4C0655A2E4F90B ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys 13:46:26.0142 0x1140 mouhid - ok 13:46:26.0181 0x1140 [ A1825437F11C4FD9778F293A08DE65F3, 8AD337363F6BDEB816770EFDA7C3F1AAFA88BA7E265ED168ACBC03001669B902 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys 13:46:26.0305 0x1140 mountmgr - ok 13:46:26.0361 0x1140 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C, BCBFF081FAFB822CE29D291FB329FC310D90F0EC0D1BB69CF8CB09ED5A2E84D1 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys 13:46:26.0378 0x1140 mpsdrv - ok 13:46:26.0564 0x1140 [ 3031573A739DBEE8923851929D0AF423, E9EA6C0D12A896AC745173B1F1A58192B52724AA424718B16B8D05E9AC091741 ] MpsSvc C:\WINDOWS\system32\mpssvc.dll 13:46:26.0661 0x1140 MpsSvc - ok 13:46:26.0726 0x1140 [ 25560C1656DC7F0723A0CC0B0E1C6BED, 17E8565B833ED58CCB6F85B90A42553464C4408C54006E019AA5641EDB682E31 ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys 13:46:26.0762 0x1140 MRxDAV - ok 13:46:26.0829 0x1140 [ 6BA2A5D1C74E7CB3AFAF301A7E5D9E44, 92CACD154D3D7E738C6D2492186270762B1888E89F505EE00C3CAE58F71650ED ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 13:46:26.0904 0x1140 mrxsmb - ok 13:46:26.0937 0x1140 [ 7E86B45D5F84E0F96AE18BEAC7A51EE4, 2B4DC0B017FD90D7D2F6A35342F5A17B20E79D077D3DFC4AD2455C0D814B7B5E ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys 13:46:26.0964 0x1140 mrxsmb10 - ok 13:46:26.0983 0x1140 [ 1BB4582396718EDEFF8A4493AEF67D66, 62AA83190CA041131E43B2031175D9F0F8ACD9A0EB0EC8B8F66C2951F15420E4 ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys 13:46:27.0001 0x1140 mrxsmb20 - ok 13:46:27.0031 0x1140 [ 98487487D6B3797CA927E9D7B030AE13, 05840AF0DD2E3CB596DA768DBD0728B52210EC05B55AB5921E697AD8956938DD ] MsBridge C:\WINDOWS\system32\DRIVERS\bridge.sys 13:46:27.0049 0x1140 MsBridge - ok 13:46:27.0065 0x1140 [ 4A07458EB4F17573BD39F22029A991C1, 74D7A1882EA4D19B8F090C2813489E5D3F759BF4AF2D88AE852EC6510C405B5E ] MSDTC C:\WINDOWS\System32\msdtc.exe 13:46:27.0084 0x1140 MSDTC - ok 13:46:27.0162 0x1140 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2, ECCA22985838A914EDC866C491DEB64B9FF5110EFA9BEE541F634AC5EC3081F9 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 13:46:27.0205 0x1140 Msfs - ok 13:46:27.0215 0x1140 [ C9BFB0353099B071E70299549C18C8AE, 5BEB200A6B824F63E2F39BA4F0693DBAC948BEA3B5A56AC9715716F1CE387566 ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys 13:46:27.0229 0x1140 msgpiowin32 - ok 13:46:27.0234 0x1140 [ D3857A767B91A061B408CCAB02DA4F40, A4D780772086AD8717EE6DC2B6189F796939FB5E5AA08FD9D1984101998FBECF ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys 13:46:27.0248 0x1140 mshidkmdf - ok 13:46:27.0252 0x1140 [ 839B48910FB1E887635C48F3EC11A05E, F8CFD99911500CC1B6A90C8E2A1697BD5A6E5776A62A62FE5B342FE204C936B1 ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys 13:46:27.0267 0x1140 mshidumdf - ok 13:46:27.0272 0x1140 [ 55C0DB741E3AB7463242B185B1C2997C, D2E2A5B48A64EA0EC2A6566C08E65A38D11CEA64BCA7B57793BA0D009E4D974A ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys 13:46:27.0284 0x1140 msisadrv - ok 13:46:27.0329 0x1140 [ 216C6B035A4BA5560E1255BD8E5BB89F, A14E038604B9A5506DB145A4D9F51E2751AC825240D2744924F39C332B5DE00B ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll 13:46:27.0345 0x1140 MSiSCSI - ok 13:46:27.0349 0x1140 msiserver - ok 13:46:27.0379 0x1140 [ C121367D21599367F2ADB9C11B7BABAA, 752993437AB2C797B5C0FFD397BC8FAC575886857C61BCCCCF169DA54BEE911C ] MSK80Service C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 13:46:27.0391 0x1140 MSK80Service - ok 13:46:27.0396 0x1140 [ 509809566E49F4411055864EA8D437CD, 70F37BF9C759E8BCA1C6AC8FB9805950925E1C648ED37E8561A0F7A407DFDC28 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 13:46:27.0410 0x1140 MSKSSRV - ok 13:46:27.0416 0x1140 [ 63145201D6458E4958E572E7D6FC2604, EDD4A8A3BBE94B983554B1117734E66A2647B867269C5F0567C47EDE6F3FACCB ] MsLldp C:\WINDOWS\system32\DRIVERS\mslldp.sys 13:46:27.0432 0x1140 MsLldp - ok 13:46:27.0439 0x1140 [ 99D526E803DB6D7FF290FD98B6204641, 4AFAA3B1186621AEAD19E12D3DBE104DD8FCD5C106F9EC3ADA4AD1BC7093E61F ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 13:46:27.0451 0x1140 MSPCLOCK - ok 13:46:27.0488 0x1140 [ 06FA77C3E2A491ADCD704C5E73006269, 465A7EE5387E6C11398A554F73437278F5BF110356E7F49F315905C1F2459278 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 13:46:27.0502 0x1140 MSPQM - ok 13:46:27.0572 0x1140 [ E134EC4DE11CF78CB01432D180710D84, BB111F97AEEFDCA5866B157E9957599CD7A4952B5BCCA0B0BCA9EDFCD17E61FE ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys 13:46:27.0592 0x1140 MsRPC - ok 13:46:27.0605 0x1140 [ B5AECF12F09DEE97C9FCAA5BA016CE1E, F5305C4CE6C93A3A3481BD13BE0C23FE26571E11029ACFFE75FB78913681FCFC ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys 13:46:27.0617 0x1140 mssmbios - ok 13:46:27.0636 0x1140 [ 72D66A05E0F99F2528F6C6204FD22AA1, B14D433BC5795F1DC4C672302285E665DC012693E75574F60664AAD8874DE562 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 13:46:27.0651 0x1140 MSTEE - ok 13:46:27.0657 0x1140 [ 8AAAE399FC255FA105D4158CBA289001, 2F55C02605B4A3406B289FF9D46C76260B9138E3DE96AFAEA0E0522E5A2A746C ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys 13:46:27.0671 0x1140 MTConfig - ok 13:46:27.0680 0x1140 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A, 00D33A4AB3E7C5F65F59C63F8E2FD27EF38D5484595F785D5632E9414E29352C ] Mup C:\WINDOWS\system32\Drivers\mup.sys 13:46:27.0693 0x1140 Mup - ok 13:46:27.0699 0x1140 [ 3A1E095277BBD406CEA8EA6B76950664, 47838F307A6354E77C19A7B1F3F3E22726EF60403B611F358AD6FFE81D7214E7 ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys 13:46:27.0715 0x1140 mvumis - ok 13:46:27.0769 0x1140 [ 4B18840511D720BA118D3017E8165875, 724458A69269A5AE57E8DAB74FF3C198A79B6F7A9602BF38A70B4A40543ED167 ] napagent C:\WINDOWS\system32\qagentRT.dll 13:46:27.0796 0x1140 napagent - ok 13:46:27.0868 0x1140 [ 43D7388A90A4C6EA346A4D6FF0377479, DFDCFA448B49C8A577056070AF516F08CD2E452706A3CF9173195ABA4256F35D ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys 13:46:27.0893 0x1140 NativeWifiP - ok 13:46:28.0073 0x1140 [ E0E4A1F81A7D69C595A8A9DDAD084C19, 8F55F3637AE8BFFB0ACE37AFC5122026525137E0B2923899B779C1BD08DF0E22 ] NAUpdate c:\Program Files (x86)\Nero\Update\NASvc.exe 13:46:28.0099 0x1140 NAUpdate - ok 13:46:28.0159 0x1140 [ 6A0C3996DA7DAE6D6939676D786EEEC4, 6E8A4C6234FD3040BC889E92016A4D5AC7BCAF5059521E50C733966163A546A0 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll 13:46:28.0179 0x1140 NcaSvc - ok 13:46:28.0216 0x1140 [ C982FE4CC91DECE2259F494FCEB4030F, 4C285407E6F9FBBA92180F4063AEFB736ED142D802F0151002F0CC20AB7BB4E5 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll 13:46:28.0235 0x1140 NcdAutoSetup - ok 13:46:28.0366 0x1140 [ 03CFE4108D1DE16D6C59455B5C73319C, 0816BAB06457F7ED53F658E53314A7A1D5A0398151186A47CE11A3017D002161 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys 13:46:28.0435 0x1140 NDIS - ok 13:46:28.0509 0x1140 [ 39C8A1D9D46F5E83A016BCAB72455284, 80DBED610E0818C2C7122FBC5BC8C15BCE981538AE48DC48F464A86389AF3F68 ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys 13:46:28.0524 0x1140 NdisCap - ok 13:46:28.0546 0x1140 [ 762941932B7E4C588E48A577BA9D6440, 71FA1870E398CB848D8294FEF6C60E0499CAB9A16EC3F487564C41072590E4F3 ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys 13:46:28.0583 0x1140 NdisImPlatform - ok 13:46:28.0622 0x1140 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7, D902AE15194A9F8A2198914FC76184FE7E2B589747275952A04A52853128FDB8 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 13:46:28.0642 0x1140 NdisTapi - ok 13:46:28.0657 0x1140 [ 79AB68BB3FFF974AD4F41FA559F4EC67, 1745EC6520B48E325C56D98A1F4DB9CE135FE3E097B3D66E6598791132CAD7BD ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 13:46:28.0687 0x1140 Ndisuio - ok 13:46:28.0749 0x1140 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8, D51FEF198F74FDF583826E259E4736F51CD49908194104677889FD135EEC2EBC ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 13:46:28.0768 0x1140 NdisWan - ok 13:46:28.0776 0x1140 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8, D51FEF198F74FDF583826E259E4736F51CD49908194104677889FD135EEC2EBC ] NDISWANLEGACY C:\WINDOWS\system32\DRIVERS\ndiswan.sys 13:46:28.0794 0x1140 NDISWANLEGACY - ok 13:46:28.0852 0x1140 [ 3730942D7DB2F8BB5F84542B7FF6F650, 89C9D7D7305205BDB304CE6DA7D1A57EDE86A9D77429698802A39D75EB78CAAB ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 13:46:28.0945 0x1140 NDProxy - ok 13:46:29.0008 0x1140 [ D3F60A4345FCA9C1BE68AD7D0D6DE770, 214AF09F4B021C2F8655FBC8AC8C801E89CD9115CDE690FAEBDA69D63D660EDD ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys 13:46:29.0024 0x1140 Ndu - ok 13:46:29.0030 0x1140 [ 7C203A76394F9AE68F69EEE5F9612C4A, 2222654915913BDC9367A2075714906A10CF22C047A7494CD59CB71834ED1B62 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 13:46:29.0046 0x1140 NetBIOS - ok 13:46:29.0084 0x1140 [ 7CEC25C682D319D484630B3952C31A11, 025C46B367E0570E9E3F9DF1564C3E47B1524E9E9A180BBDF0E9C684838F5E42 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 13:46:29.0125 0x1140 NetBT - ok 13:46:29.0162 0x1140 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] Netlogon C:\WINDOWS\system32\lsass.exe 13:46:29.0177 0x1140 Netlogon - ok 13:46:29.0252 0x1140 [ 89519D29CBEC2121CA65CC29C4D345E0, F3BA7BCAFEC8DD8B29837458D1B2B1DEE748AEAAAE0575FD3AAE65CFC72A04CD ] Netman C:\WINDOWS\System32\netman.dll 13:46:29.0298 0x1140 Netman - ok 13:46:29.0395 0x1140 [ 79FA9393C67EBBF92A56923592CF7A7C, A8AB8A6346B97B68810CC632F425085BE9E63ACAED0F119A7BFD03F2DA4AA5F6 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll 13:46:29.0437 0x1140 netprofm - ok 13:46:29.0799 0x1140 [ 5243CFC2E7161C91C2B355240035B9E4, CFD77485A9D7BC47F3A9C53D73B2AE2D5D04B90ED38628F3124EA569F4DE969E ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 13:46:29.0848 0x1140 NetTcpPortSharing - ok 13:46:29.0887 0x1140 [ 12DD2800E4EEA37DC9AE256AD62423B4, 34740469EEA8740CBACD881CB232C9ABB9AB180DE5F45336BC6DBE154259F29B ] nfrd960 C:\WINDOWS\system32\drivers\nfrd960.sys 13:46:29.0900 0x1140 nfrd960 - ok 13:46:30.0026 0x1140 [ 5177E35B186D2DED6F1EFF57BA61B975, B48C2E0FE2E95C37697107BDB8E0843D3E56200D2E242BF02E205C53978655D9 ] NlaSvc C:\WINDOWS\System32\nlasvc.dll 13:46:30.0494 0x1140 NlaSvc - ok 13:46:30.0518 0x1140 [ 17E19A742FB30C002F8B43575451DBE1, 59D226A4A5B5281C399BE96C694915E38EEAF335D31F346B0C65D8F469D7C9C3 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 13:46:30.0563 0x1140 Npfs - ok 13:46:30.0570 0x1140 [ 8ED299C30792544264E558BEA79F0947, 8A03FDA9AADB79ECBCBCDC988B7D8CF0672689C9DF673A2ECFE0D2D88A9C6A6B ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys 13:46:30.0589 0x1140 npsvctrig - ok 13:46:30.0647 0x1140 [ 832B5FDF0B5577713FD7F2465FCD0ACE, 4A551CDBACED47DD781EC59F8B59A13D66EFD85DCF636BCFCBACFE5972A78E93 ] nsi C:\WINDOWS\system32\nsisvc.dll 13:46:30.0661 0x1140 nsi - ok 13:46:30.0667 0x1140 [ 689B3B1E95C70ABF7AFF29F9406EF1E0, 8B62D8AE53E1B3218158FADC0075682AB06D18998CF5DE82C920A9CD91C0652F ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys 13:46:30.0686 0x1140 nsiproxy - ok 13:46:30.0824 0x1140 [ 76929F4A69E425911A63B407E26C2589, 17896DB6EDEF2637D159432DB61E8B5FA2F4F54B5F50BCD6215827C321ED2C2A ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 13:46:30.0943 0x1140 Ntfs - ok 13:46:31.0003 0x1140 [ 4163ADE07DB51843AE31F65B94F5398D, 4349E7EF1EE1E71E1F436BA42F5B58871D82B987D513BA2D6E1CEB8A21BD1B20 ] Null C:\WINDOWS\system32\drivers\Null.sys 13:46:31.0020 0x1140 Null - ok 13:46:31.0063 0x1140 [ D6D34118263412D3AAA8348A9572B7F2, 66106A25BC5A4CA7697A23ED67CEDB5C0BF678EA70FD967A405D2DF76F4CA3A4 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys 13:46:31.0085 0x1140 nvraid - ok 13:46:31.0100 0x1140 [ 27AFC428D1D32ABD04A86763A4EDDEA9, 0920866013A8C8CFEE00E6AECDD41736F5501C49837E2D785998734F087F6B98 ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys 13:46:31.0119 0x1140 nvstor - ok 13:46:31.0130 0x1140 [ 051CFB5107BAAE510419BDC41F8C4036, 9990906F17A3886EF301D2AA6556263B52A1C0554C6BD18331AF44ECECAEE4B5 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys 13:46:31.0147 0x1140 nv_agp - ok 13:46:31.0230 0x1140 [ 11E0B35479C895888BA3D7F619DCFFF3, 6ED82C19898101EC00BD64A9F90595C3D20AD2D2902AA8765B740FB3B9312DDF ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 13:46:31.0247 0x1140 ose64 - ok 13:46:31.0372 0x1140 [ AB76700D764A342D7475FB8F47CAB18C, ECDF705D3E69EF6E7044C98A462A7281D0E7D0D85769C0815555D934B0B69C8D ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll 13:46:31.0413 0x1140 p2pimsvc - ok 13:46:31.0489 0x1140 [ 4319FD931DCD796435ECB5DB4A04FBA5, 20185B2F359EEC202B37019A4E4F5B914ADCF78B97AF0CBD91EECED2259FC6DE ] p2psvc C:\WINDOWS\system32\p2psvc.dll 13:46:31.0517 0x1140 p2psvc - ok 13:46:31.0562 0x1140 [ 4563DAF8C6A740AD7F501E219BD10766, 7A1212DDAE2D66A9C2041262796904E36036CDC4C5B75C2F66B8DF9D89F7C25D ] Parport C:\WINDOWS\System32\drivers\parport.sys 13:46:31.0577 0x1140 Parport - ok 13:46:31.0584 0x1140 [ C1D7BA7F0DE487DFEEB51BF8D3EC5562, 72F38D6C6FD1ED6E1BC47B781A06FFBE29C99A70382D38759B53A184F61B6643 ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys 13:46:31.0598 0x1140 partmgr - ok 13:46:31.0614 0x1140 [ 4811D9EC53649105A5A8BEA661B0F936, C77907E03D0561500FCFEAFAC323E9679E66297329901A0CA2BD7E919419A8E8 ] PcaSvc C:\WINDOWS\System32\pcasvc.dll 13:46:31.0660 0x1140 PcaSvc - ok 13:46:31.0669 0x1140 [ 4A003E8F718C1E6A2050CA98CD53E3E2, BCC3BE1EC3FA4967353371D85094D096940A7B5944A6FFCA31E8FBE83D92CC6C ] pci C:\WINDOWS\system32\drivers\pci.sys 13:46:31.0693 0x1140 pci - ok 13:46:31.0723 0x1140 [ F9908D274D458220F91E89B54D78D837, 1E89ABFA6B375383E0297CEE5AF66E37F90E16DD21ABA5C91777A86CDF013B4D ] pciide C:\WINDOWS\system32\drivers\pciide.sys 13:46:31.0738 0x1140 pciide - ok 13:46:31.0779 0x1140 [ 84D19CB6102627932DCB5DFDF89FE269, 2F9C47E076645B35877D9ACA77968EFFCDA8794D76265CD9A4AAA239C4B33C5F ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys 13:46:31.0809 0x1140 pcmcia - ok 13:46:31.0825 0x1140 [ CEBBAD5391C2644560C55628A40BFD27, 8AAA6EBD8D89FC91AECCCF1452F53C5650A1A17027FF4E64D224371404CE4C8B ] pcw C:\WINDOWS\system32\drivers\pcw.sys 13:46:31.0843 0x1140 pcw - ok 13:46:31.0877 0x1140 [ 0698DEDEAD6A00AD0D468C687D830FBF, B9DCA1A61F2EF80DB26380F390F2E9A17114D33129D61CF465B949B6A7916CAA ] pdc C:\WINDOWS\system32\drivers\pdc.sys 13:46:31.0890 0x1140 pdc - ok 13:46:32.0056 0x1140 [ 61FE70659CD43E07F94DA4DC31DEC493, 3739B6670B440173FD81DE3D47B0B90FAF296802AD4F57C05BF5CF191BF16022 ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys 13:46:32.0094 0x1140 PEAUTH - ok 13:46:32.0704 0x1140 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A, 459CF99D5243C4ACAA38C7B426ADC52F1044C759D06A925D475DF6213AEB85CD ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe 13:46:32.0719 0x1140 PerfHost - ok 13:46:32.0903 0x1140 [ 6E84BFF58F7643499277F29DFA2F8C8D, 401CCF137F35D9690C7B56B2BFEDB2DB72709EBE38626D787904B67640EF6F14 ] pla C:\WINDOWS\system32\pla.dll 13:46:32.0975 0x1140 pla - ok 13:46:32.0997 0x1140 [ 799BE46D45D486704CE0F37CA5385262, BB78DEE83B9DB613B1C083D55FAA458BE3E394AED80EB91B599185A7272F33B3 ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll 13:46:33.0016 0x1140 PlugPlay - ok 13:46:33.0023 0x1140 [ 8E2414E818C26C4A9C70CB2B8567F04F, A16B22AE143BA070C562FBE5DEF32F7E228F50B302B66E46B46C44C0F50A4461 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll 13:46:33.0046 0x1140 PNRPAutoReg - ok 13:46:33.0071 0x1140 [ AB76700D764A342D7475FB8F47CAB18C, ECDF705D3E69EF6E7044C98A462A7281D0E7D0D85769C0815555D934B0B69C8D ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll 13:46:33.0096 0x1140 PNRPsvc - ok 13:46:33.0216 0x1140 [ 0108C8E5176D590F242701EF5A62CC26, 3A72F5D4402663B7445F6B3C55F01E83A619B6192F7D3CC2DE3C57F9F50D5A2D ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll 13:46:33.0247 0x1140 PolicyAgent - ok 13:46:33.0287 0x1140 [ F1E067F56373F11EA4B785CAE823740A, 69BD30E64DA17595FF29C9C9FF9AD4F2F4BE29B688FBAC9DABB2FA9D13A47FF0 ] Power C:\WINDOWS\system32\umpo.dll 13:46:33.0334 0x1140 Power - ok 13:46:33.0378 0x1140 [ 362D47E5B4D67270DE4B8606036F4ADD, 716E229C68D91AEA5B5629F60133D5CBDC0C95ABA54D9DC6264E923CAF4DC6C0 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 13:46:33.0402 0x1140 PptpMiniport - ok 13:46:33.0727 0x1140 [ C2D3B3D0060619D5E03E696BD56FF59F, 155954F16B6F9B51BA16F43F1AE6F977B1EC4DE77862C6F6C722293189BE0DD2 ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll 13:46:33.0842 0x1140 PrintNotify - ok 13:46:33.0881 0x1140 [ DD979EB6A7212F60E4AFBE96EDC7AE6D, BC681D64C5B8F08FD4613D71111853FCD5B05E4BD127D2C6258BAED7627105BE ] Processor C:\WINDOWS\System32\drivers\processr.sys 13:46:33.0896 0x1140 Processor - ok 13:46:33.0976 0x1140 [ 1D7127048413309629233B50BF2DD9A6, 918322AFDD576D9966961B111F5E38BDDB4278F9456E7AA1A3453EC8CAF4B8A8 ] ProfSvc C:\WINDOWS\system32\profsvc.dll 13:46:34.0012 0x1140 ProfSvc - ok 13:46:34.0051 0x1140 [ 138DBAE80F390B22297ACD861BDA996E, F0799F40266A11058710AD8ED5D8797A350DCB2A55D3DEF179C1D8C87AFB5208 ] Ps2Kb2Hid C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys 13:46:34.0069 0x1140 Ps2Kb2Hid - ok 13:46:34.0090 0x1140 [ EB8034147D4820CD31BFCB11A2A652DF, B10B5E16B7A05D2DB2D5D1945B6146DE15EEDE2C778772A59F104706B5145E46 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys 13:46:34.0150 0x1140 Psched - ok 13:46:34.0203 0x1140 [ 0AFBF333B6F87A2F598EAB379AF100B8, D11F3A4D7E4463B62E2DBDE5FC61425B1FDFB07DD1A19BC001D479CA1F554510 ] QWAVE C:\WINDOWS\system32\qwave.dll 13:46:34.0222 0x1140 QWAVE - ok 13:46:34.0292 0x1140 [ 13D47BB0CCA2FC51BD15F8E85C6A078E, EA832A9511007C9E8599C3066E1FA66BE869E8A27886D9A9AC590BD4DFBD1A15 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys 13:46:34.0352 0x1140 QWAVEdrv - ok 13:46:34.0370 0x1140 [ 873C60F8178100557740A832FCE10B5F, 400EF60CB2C98E2AFE122AF3D01CCE56A1548AF865345EE2194AB74DBCBF4C48 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 13:46:34.0385 0x1140 RasAcd - ok 13:46:34.0438 0x1140 [ 69B93F623B130976243ECA3D84CC99CA, F27617E651EADFAEE479619AAB01CDAA98111BA63E204D5C44A1256732CB0100 ] RasAgileVpn C:\WINDOWS\system32\DRIVERS\AgileVpn.sys 13:46:34.0454 0x1140 RasAgileVpn - ok 13:46:34.0474 0x1140 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0, 2F3C90A04964D4D906238BD557D90F7AC05DF86FE9729C4378B39431F54DDAE3 ] RasAuto C:\WINDOWS\System32\rasauto.dll 13:46:34.0492 0x1140 RasAuto - ok 13:46:34.0529 0x1140 [ A14D625C5AEE5FFE0F47D1A1D419FAAE, 1229B81C23340AD5B436B1FD227876EB41715CE6BD270BA367F18879D26B8F04 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 13:46:34.0548 0x1140 Rasl2tp - ok 13:46:34.0608 0x1140 [ C923C785A2DE0B396AD6D13ACAFF2DE9, 4F950DA776FBABEC7D546983D6F3018733F61268A4BF95C01D4836AD000BD073 ] RasMan C:\WINDOWS\System32\rasmans.dll 13:46:34.0651 0x1140 RasMan - ok 13:46:34.0674 0x1140 [ 00695B9C2DB6111064499C529E90C042, 3CD4DF4D8001C2BBF52EEEB1F0D587209878BEAC339D268892477AD840D490F1 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 13:46:34.0691 0x1140 RasPppoe - ok 13:46:34.0699 0x1140 [ A7F24D8CD1956B0A1FDCB86CC5114DE4, 30489D235362DF62B105378597168B13F4BAC74A8EDDBDA25237E3C017B69FEE ] RasSstp C:\WINDOWS\system32\DRIVERS\rassstp.sys 13:46:34.0716 0x1140 RasSstp - ok 13:46:34.0771 0x1140 [ CA03D642ACE58E1BA54E4B383F91CD69, 39BB942603801CF11FBEA28E24F8C8D1EF2AF615D1FABF951683A015D6A6EF37 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 13:46:34.0803 0x1140 rdbss - ok 13:46:34.0817 0x1140 [ CA7DF5EC95D8DE0DD24BE7FF97369F68, 153E6F716CA935DBCACB8FF1BB8DE5F5551CE3D18878225470E45893CA69BDB8 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys 13:46:34.0846 0x1140 rdpbus - ok 13:46:34.0879 0x1140 [ B2A3AD74FF2E2FFA73AF2567108231B3, DF8CEA6215F75C634D56F6B8AE11ECCEEB5F8CBC091AC3D6D9F7DE214B00A439 ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys 13:46:34.0897 0x1140 RDPDR - ok 13:46:34.0920 0x1140 [ 57F4787E4602A3FCA719C0A33137C6DA, D03AE59A184EB5D126F8EAB9D36EE406ABB8B9ED834F2D2496DDB1349FF56F89 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys 13:46:34.0931 0x1140 RdpVideoMiniport - ok 13:46:34.0958 0x1140 [ B3CB0721E81E30419CE7D837EF4EA151, EC9410818661BF77E4A19694E3A3030E1D983B36F49C72E27F92A1424E0729C2 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 13:46:34.0999 0x1140 RDPWD - ok 13:46:35.0017 0x1140 [ 62C1F8A0685FE07E998AA296C4F697C4, C636AB2D0F139003A6AD7A12E9DC13EE4485A62F30DA59AF842FF02FE07442EE ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys 13:46:35.0034 0x1140 rdyboost - ok 13:46:35.0104 0x1140 [ 3663CCF243EE0C04E9F6F91ED1737273, 31D06445996F99A7F6B32004D1BA63A21C61DE125373F860BA9A9DE5278E8293 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 13:46:35.0155 0x1140 RemoteAccess - ok 13:46:35.0235 0x1140 [ E80DD61E52EDFFF9DA1ED7260A68855B, 97909F42AE35E28B8F98C01A1D8BAD80A949CDCA0C88FB4ACF0A655DC7C10E45 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 13:46:35.0257 0x1140 RemoteRegistry - ok 13:46:35.0328 0x1140 [ F61333867216EDE1A09A7C55FEDCB6A8, 991FC810FB281F4E91B7D22A7C5AF5D11419ACE05BBB3F664812391069A336F0 ] RfButtonDriverService C:\Windows\RfBtnSvc64.exe 13:46:35.0338 0x1140 RfButtonDriverService - ok 13:46:35.0390 0x1140 [ 73F2E030B5C24E4E41401B5F0D59E6FD, FAA8B5E3159684E0836900C6EAF63857B445F7F180169B56D5790F097EDAA38B ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll 13:46:35.0435 0x1140 RpcEptMapper - ok 13:46:35.0511 0x1140 [ 10B21284B3D964AB3DC45490E57D422E, 12D5E3A7785F21C99C5EAD14A88EB7A86A058E26C091991339356D99D196CC13 ] RpcLocator C:\WINDOWS\system32\locator.exe 13:46:35.0524 0x1140 RpcLocator - ok 13:46:35.0748 0x1140 [ 1EC6E533C954BDDF2A37E7851A7E58FD, C25936A7465B6A2B3D05D2FCB09D91ACC07CFE038A5E968C99CFA9D9F2967DD4 ] RpcSs C:\WINDOWS\system32\rpcss.dll 13:46:36.0074 0x1140 RpcSs - ok 13:46:36.0182 0x1140 [ E04E770DD198B9399640717145E79EBF, 2F9BECB7E4B0A522C6370FD39CFD7DFD3FB5D0A779AECCED2EE855629FA3C952 ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys 13:46:36.0208 0x1140 rspndr - ok 13:46:36.0260 0x1140 [ 752EC7DCD2F96871A3857EEE6AFE965A, 1D0640966B9147A06ED0E733711773E6B4AB8AC6D962D5B369ECB04170D18AD8 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys 13:46:36.0276 0x1140 s3cap - ok 13:46:36.0354 0x1140 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] SamSs C:\WINDOWS\system32\lsass.exe 13:46:36.0385 0x1140 SamSs - ok 13:46:36.0407 0x1140 [ 9C7B28CE0D136DB226E24DB3BC817F92, E9DE55D6432ADD08EC75F99F2B5D2BD1F553F4EE55991B1767B1578351EE0BF2 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys 13:46:36.0421 0x1140 sbp2port - ok 13:46:36.0467 0x1140 [ 14316954FCE79C9DE5A0AFF9D42C83AA, B60FB1FAC0299F9560761411711E86EDFA2F8D27B58230E2E4BB37736FAB2287 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll 13:46:36.0486 0x1140 SCardSvr - ok 13:46:36.0506 0x1140 [ 5D7733A12756B267FCA021672B26BC9E, 01CE5B5F49914B9E099BD909A66296F3A40644AE47BA1D5EBFFB30CD33C70A4A ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys 13:46:36.0523 0x1140 scfilter - ok 13:46:36.0672 0x1140 [ ED40ED9A65F3E79A8C43DD50C5FDADBF, 2323BFAB1BC3D661A376650B7AC14C7780C92BA575DA048F3C7611CDB3F7F04A ] Schedule C:\WINDOWS\system32\schedsvc.dll 13:46:36.0738 0x1140 Schedule - ok 13:46:36.0817 0x1140 [ BAF8F0F55BC300E5F882E521F054E345, FB228DB18F2FA55D8BA35A7E6778EE5D2EB0C29D384F1A0A868F90AE706188D7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll 13:46:36.0852 0x1140 SCPolicySvc - ok 13:46:36.0935 0x1140 [ 66E29CADF9FF6C8325C356BDD617F7EA, D88A30DAD93470C5101136B781A1983495C01BFB9A0EC1625C5542DFC5BABFC0 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys 13:46:36.0955 0x1140 sdbus - ok 13:46:37.0014 0x1140 [ 92968277ED491E4B3DDA361E3952361E, 71C50853BB2126A34C7CD014EE44D4B8B39F589E2E8E8E8F4C982E07498E3899 ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll 13:46:37.0030 0x1140 SDRSVC - ok 13:46:37.0056 0x1140 [ BB107AA9980B0DA4E19A3A90C3BD4460, BCB4CF0FFF1FD57302557B68044A88C8EEAAE57C2FEAE8EAD1F410F960298B6D ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys 13:46:37.0070 0x1140 sdstor - ok 13:46:37.0100 0x1140 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys 13:46:37.0122 0x1140 secdrv - ok 13:46:37.0135 0x1140 [ CD282626738B6BC92B6E7CD0AAE95B63, 1A56567C781786C85C63E24E79186EE5C82D3EB2679061B21BA0571A3A6CB7F5 ] seclogon C:\WINDOWS\system32\seclogon.dll 13:46:37.0155 0x1140 seclogon - ok 13:46:37.0170 0x1140 [ 9C51620998F0763039DFA6BF68E475ED, 9E496ADE7CE9A446BE8A2C2FC61B462D966778A94A4C147AABBD25C4821C2BCE ] SENS C:\WINDOWS\System32\sens.dll 13:46:37.0203 0x1140 SENS - ok 13:46:37.0220 0x1140 [ 0D50B4B860DAB65241628D04CD33ACAE, 2AA897C3F9ED076AB9244A32745D18489B076F3ED28A35B868C472131C5B5B46 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll 13:46:37.0245 0x1140 SensrSvc - ok 13:46:37.0256 0x1140 [ 87C46B239A7EEF30FDFDD5E9BD46130C, F36FB5B20AC58FBD31F7E636059D2D865B751E178E51A03B94ABE0BBD1AB1EC9 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys 13:46:37.0276 0x1140 SerCx - ok 13:46:37.0295 0x1140 [ 7A1F9347C85FD55E39B8A76B3A25C5AD, 03AF3B23285278A38F4CBEAB7FD326A48FA1EC7F8D044C059CE5403C6D225639 ] Serenum C:\WINDOWS\System32\drivers\serenum.sys 13:46:37.0310 0x1140 Serenum - ok 13:46:37.0343 0x1140 [ F640A0A218BBF857F1D04A15D7D939F6, 948C13886281FE7947E10FB7B34D5CCFE512FB632F1132B6062AC85149F79950 ] Serial C:\WINDOWS\System32\drivers\serial.sys 13:46:37.0359 0x1140 Serial - ok 13:46:37.0364 0x1140 [ F1A5F56B2620B862CC28FF96A0A6DAAB, E5367212B2CADF3820D657CFC27CD961547E28DAB950C68E1380CF97FB68F3F4 ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys 13:46:37.0377 0x1140 sermouse - ok 13:46:37.0396 0x1140 [ CB60A60340788C8D6DE2A269D28086AB, 2D8948E59BB9B00E16D20E425F80E7B862957DBAC9A4D1484E5191FAF333B60D ] SessionEnv C:\WINDOWS\system32\sessenv.dll 13:46:37.0417 0x1140 SessionEnv - ok 13:46:37.0422 0x1140 [ 7EE65419B29302C795714FF8073969A1, E28D89A5423E3A5062030EB2418E9435DD5D8B9D16570046E782D3FCFDA2E79A ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys 13:46:37.0435 0x1140 sfloppy - ok 13:46:37.0569 0x1140 [ 090AE16F79C8EAD04E6031F863DA85F3, 3F27BE46DF602B53940414A6E9FEB23B36CFFB8E9A7F41440C3315B8E27D0029 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 13:46:37.0612 0x1140 SharedAccess - ok 13:46:37.0707 0x1140 [ A77F3ABE13FCC698511E5DEC7ACEBD5F, 78A43FDA9F770FD8BA107605DB44BC71D8B89D7E75560DA783AA6356C1873C15 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 13:46:37.0748 0x1140 ShellHWDetection - ok 13:46:37.0787 0x1140 [ 2560721D6F16D5B611C36A3A9D28C1B2, 15C30404902654ABA5DB5367FC5BD31343B12A3FC22B4BC5A26B09016447B5ED ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys 13:46:37.0800 0x1140 SiSRaid2 - ok 13:46:37.0838 0x1140 [ 3AA8FDE1DBF65BB8B88B053529554A0D, 8060D946344D043D336F4735363C23C37C91A6DB3F81E575C267B2EC2BECB0EC ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys 13:46:37.0851 0x1140 SiSRaid4 - ok 13:46:37.0881 0x1140 [ 5CDEF3A06AEA1B510F3F4B09340247D5, 5B57381BAD738E05BBBFC4B95F67611D879B31E248FE96104D0333A655AF9F13 ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys 13:46:37.0897 0x1140 SmbDrvI - ok 13:46:37.0927 0x1140 [ E660156A4588A84305CB772FD2C0DB21, 9492EB6578D4A689945E1FC2440EFA77D461049CDB2D00A645969A71B7DA68E1 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe 13:46:37.0952 0x1140 SNMPTRAP - ok 13:46:38.0026 0x1140 [ FD3AF5575B99871BADB94E7699DBCE08, 847A78C1388683984AFA7D00B7C7F8741BC1DFBF4999AAD1E2EFC22D3C316846 ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys 13:46:38.0050 0x1140 spaceport - ok 13:46:38.0058 0x1140 [ 3D8679C8DF52EB26EB7583A4E0A29202, DCD9B69299275857712AB200C014AE820C8A9F7E53C4A335A84518FBE4BB56BB ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys 13:46:38.0077 0x1140 SpbCx - ok 13:46:38.0191 0x1140 [ 3F215BF2D4D8D6756298B25B579772C2, 744192D1635E5D296BFD399E870B70592202CEAF95C31C2D2B226A868D33A3FD ] Spooler C:\WINDOWS\System32\spoolsv.exe 13:46:38.0228 0x1140 Spooler - ok 13:46:39.0087 0x1140 [ EC84D961501054F87A6878EC5D53388F, C69F3542B182BED4260EE1906361B72B9FFDE47FD92A161850E28BC6ED7505CC ] sppsvc C:\WINDOWS\system32\sppsvc.exe 13:46:39.0231 0x1140 sppsvc - ok 13:46:39.0365 0x1140 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6, 61EEB1349489CB85204F1B4E398BE24EDC01FB914120C9DD0487F8EE1EDA055E ] srv C:\WINDOWS\system32\DRIVERS\srv.sys 13:46:39.0406 0x1140 srv - ok 13:46:39.0654 0x1140 [ 56218A571ECF8D55E0CDFF8DF2546CF1, 44B34722108EDDC8757A0B7C939A854457BB7EBC92A83C4284DFFAECFC2E3619 ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys 13:46:39.0749 0x1140 srv2 - ok 13:46:39.0836 0x1140 [ 14FC338B80CFF7E04215133B568D15C4, 1F437BE0EC887097F0C3409D4198A20981FC325FDF915532AB85070D337DEF2B ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys 13:46:39.0862 0x1140 srvnet - ok 13:46:39.0940 0x1140 [ 7A20882D76D4A78240A5AC9F2C2EBA21, ACA05211EE542999A118BBD2CD051038A7DC8C40C4B8971DC6514BA90E90EC61 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 13:46:39.0968 0x1140 SSDPSRV - ok 13:46:39.0996 0x1140 [ D233B16999A8E626F6004BD7814C57EC, 5BBFE5DDF1269617ABD1BDBED85A79D99BB52EA29C2BB3A8F4A1827BFAA1A747 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll 13:46:40.0025 0x1140 SstpSvc - ok 13:46:40.0073 0x1140 [ 4E85355B94CFCB67C135F6521A4895A7, AC4FC65C1E62A54B3834E7FE0A2B1ECC48A2AA563AE5BD508326EE68FFFBBEEE ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys 13:46:40.0098 0x1140 stexstor - ok 13:46:40.0252 0x1140 [ BAC8A721736AECC55A4F71523AEAB65F, B52E1303B13A961A5FC190829E55B6F28ACA409A6EEF44B358D1D210558FE1D8 ] stisvc C:\WINDOWS\System32\wiaservc.dll 13:46:40.0332 0x1140 stisvc - ok 13:46:40.0408 0x1140 [ C588BBD37B432CE3204E5765B459E6B2, 6A30570C82390C4D6668137D05C7EFBE243CAC243CBE405D308E3F7B2BC5729D ] storahci C:\WINDOWS\system32\drivers\storahci.sys 13:46:40.0426 0x1140 storahci - ok 13:46:40.0457 0x1140 [ F74DBC95A57B1EE866D3732EB5F79BE2, E4FE9D5CD0A385ACB60D5D5E8D969F26C3A6BC0C08FF0838DBE9CA106229C8DE ] storflt C:\WINDOWS\system32\DRIVERS\vmstorfl.sys 13:46:40.0474 0x1140 storflt - ok 13:46:40.0526 0x1140 [ 5337E138B49ED1F44CCBA4073BC35C20, 2B296973215E3865A56C46DC3D27F1460D96BC321558CE7A911B05B0E7BF397F ] StorSvc C:\WINDOWS\system32\storsvc.dll 13:46:40.0541 0x1140 StorSvc - ok 13:46:40.0549 0x1140 [ 543CD3CC0E05B8D8815E0D4F040B6F59, 4B57C9534E94A0A67FC82DBD4FAECACA180BEC281FB477550A37C0A04777E09E ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys 13:46:40.0568 0x1140 storvsc - ok 13:46:40.0619 0x1140 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A, 82CC77030D23013572B4A64A64B6156789F253BF56268B790093CE3D345410A0 ] svsvc C:\WINDOWS\system32\svsvc.dll 13:46:40.0636 0x1140 svsvc - ok 13:46:40.0652 0x1140 [ 4AFD66AAE74FFB5986BC240744DC5FC9, 0C9347614E3FD3B4D3B29FA4A5DA23FF6EE4CD9A1FFC378B855B8DE61B2876CF ] swenum C:\WINDOWS\System32\drivers\swenum.sys 13:46:40.0668 0x1140 swenum - ok 13:46:40.0773 0x1140 [ 502F9488540051F3E6C39889ECFA76BB, 22ABD681BE4CF8A1F484C6363C1334B1EF7A6C074D837B0121DE1896887B84C6 ] swprv C:\WINDOWS\System32\swprv.dll 13:46:40.0892 0x1140 swprv - ok 13:46:41.0437 0x1140 [ 95FFE1C1C55B2E9CE45CCC7CFE25D2C3, 4F3F8A41A68076609FB5F334D8EC77423325C665FBE70404BB89371B5A3E1F22 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys 13:46:41.0524 0x1140 SynTP - ok 13:46:41.0872 0x1140 [ DC695DCF6C9A4A2B23C2FA284BBF19F8, 0D0357874CCC3AA9E76340ACFDB8FCF79DD79A3B333CC36A836B40ECFC61E4A1 ] SysMain C:\WINDOWS\system32\sysmain.dll 13:46:42.0368 0x1140 SysMain - ok 13:46:42.0442 0x1140 [ E219BF7BCCFE4881B0C053C7E0B47ECC, 38638803C4586B3583D6B935876EC59CA69A91A909734A864DC6F04D59D70C52 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll 13:46:42.0469 0x1140 SystemEventsBroker - ok 13:46:42.0517 0x1140 [ A6C06C45C44AD06C70AF8899AEC15BDC, AC2CCCDBA6B94BA85A6D41B47343193D175786D4ECF71AE9C7766ADD63A1273F ] TabletInputService C:\WINDOWS\System32\TabSvc.dll 13:46:42.0554 0x1140 TabletInputService - ok 13:46:42.0692 0x1140 [ 88B7721AB551C4325036B25A34A2BF7B, 2817CC6294542524EC373A674535F913440736BEBE81233CA91D5ECD93620B02 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 13:46:42.0715 0x1140 TapiSrv - ok 13:46:43.0093 0x1140 [ 0E0C16EE82E2F4EBC2FBCA24C8F00D9E, F8B2A0257442E00C5D7C5A15BBD84194D0F0C071424656CA4B8EC850B6898D10 ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys 13:46:43.0246 0x1140 Tcpip - ok 13:46:43.0350 0x1140 [ 0E0C16EE82E2F4EBC2FBCA24C8F00D9E, F8B2A0257442E00C5D7C5A15BBD84194D0F0C071424656CA4B8EC850B6898D10 ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys 13:46:43.0419 0x1140 TCPIP6 - ok 13:46:43.0475 0x1140 [ 8F2A13A5DF99D72FDDE87F502A66F989, 2228C62ACDB4CBBFDD2BE705E604E0B9A8AEA7146F65F2D8B9B2A2FB49ACFAE1 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys 13:46:43.0499 0x1140 tcpipreg - ok 13:46:43.0511 0x1140 [ 73DC722CE5DF26D7638CE2446F2655C7, 9B8E6F6DEA5E0C2AEAC24A31897D2E73F86EF44F1C25FEF82D2C860353793817 ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys 13:46:43.0536 0x1140 tdx - ok 13:46:43.0550 0x1140 [ F7C8AB5D8AFFAA318D6A21093D139BF4, 0A35052EF7DC8615783A23897358D8C579BE694363615C9563FF629E7B719991 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys 13:46:43.0562 0x1140 terminpt - ok 13:46:43.0696 0x1140 [ 541EE228D0DEF392F7B2DFD885DD021B, 594D6538FA4DB5EF4D130007D7C29051EC2EDCA39EBB119695B58E9CBB0EB728 ] TermService C:\WINDOWS\System32\termsrv.dll 13:46:43.0750 0x1140 TermService - ok 13:46:43.0790 0x1140 [ 519A6F672FFF56B7D8EE8C730CEC8ECD, 2B36F10C0AE16A261DC0887B1050808BA1F0568F3879E4ABC3D370F08C3FADB7 ] Themes C:\WINDOWS\system32\themeservice.dll 13:46:43.0811 0x1140 Themes - ok 13:46:43.0861 0x1140 [ EEE908BE7143FCA48CF0CB87214E2AB8, 4F9BD299F559DD36DBD93489CFAA753F236FBB70946E034D2E2260059AE20962 ] THREADORDER C:\WINDOWS\system32\mmcss.dll 13:46:43.0883 0x1140 THREADORDER - ok 13:46:43.0940 0x1140 [ FF4135424A79DCC2998276D8E39C9B4D, B61F57BC38B9C6E0576F1F555C41957D8F187D99D392967A8EBB66C73BFD3CBD ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll 13:46:43.0961 0x1140 TimeBroker - ok 13:46:44.0028 0x1140 [ B44EFE254C0B3719E4037088D24FE4B5, 5AC07658A599470C2BCB2813E644B132DDF886510470F5CC636113CEC48DC0F3 ] TPM C:\WINDOWS\system32\drivers\tpm.sys 13:46:44.0045 0x1140 TPM - ok 13:46:44.0126 0x1140 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA, A6846478B9E7B0A509E5A28C6C7B66ED39F0247F9AFF01E3C3CADC0DBEF3CA00 ] TrkWks C:\WINDOWS\System32\trkwks.dll 13:46:44.0145 0x1140 TrkWks - ok 13:46:44.0319 0x1140 [ 8ABBB5CE0C62E0A6D28F32F44B7F865C, 4C78FE2A4A25A758D5191C4EDB2A6FE691FF82E7C16C0F146DC96DAD87D4F64E ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe 13:46:44.0379 0x1140 TrustedInstaller - ok 13:46:44.0406 0x1140 [ 4E7C5FB10A50435523DE0CAA37DE2BD3, D6206DF61950F2541FB754E57C4D9EF9FA0CC1EDD6F6FA4E45F02B47958493F7 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys 13:46:44.0421 0x1140 TsUsbFlt - ok 13:46:44.0506 0x1140 [ 16D684A820872EE54F6370703AC0B513, 795E20484358424CE9FA766937DD99413025A8AF967D03490392E8E02A382D0B ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys 13:46:44.0530 0x1140 TsUsbGD - ok 13:46:44.0573 0x1140 [ 78C9EE193AC2B4CBDBC48B620314D740, 41523E47D321BFF5778F5E453545B928C0A469C3BBA51578E74D6721D7DF9273 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys 13:46:44.0596 0x1140 tunnel - ok 13:46:44.0624 0x1140 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A, AA7DA2207C0236F47859A4791F9D7301E7ADB50A59D831DC859ECC7CA70D3E1D ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys 13:46:44.0644 0x1140 uagp35 - ok 13:46:44.0682 0x1140 [ 6FD6D03B7752C78712E5CFF29A305026, F09C5188AAFCF4C77B05BA1E604F9912782A9F1371F72F959288EBC2725407ED ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys 13:46:44.0706 0x1140 UASPStor - ok 13:46:44.0797 0x1140 [ 061BA3EE0D2BE17944990544008CF190, C9236D368EC2281B545E8C008BC2801F21A9716ED3D4DAEDB0751A5008346E81 ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys 13:46:44.0813 0x1140 UCX01000 - ok 13:46:44.0904 0x1140 [ DC5A461591C71AF7F19DC048A81E3F88, C6689C70B6CDE5A5707C06ABDC9CABF87CCE549BD23B96969EF3AA177A889320 ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys 13:46:44.0947 0x1140 udfs - ok 13:46:45.0004 0x1140 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D, 16DE6E0894C356A58AF12BEC2FE9B188F147DD4B16CB2414DE600CE4127F929D ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe 13:46:45.0030 0x1140 UI0Detect - ok 13:46:45.0041 0x1140 [ 07FEBCDF24FABA0D47B635D85A0FFB7A, 452C04B14681EBCE8B1B25B75A1B7CC978722B7DDE54D624E17841B14ACCF65D ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys 13:46:45.0062 0x1140 uliagpkx - ok 13:46:45.0079 0x1140 [ 02CEB3FE6152668A7BA420B93B664860, 613F27540FD1EFE2442E326F507DACD5A25691C8481937022B7E1104F3E6E9E2 ] umbus C:\WINDOWS\System32\drivers\umbus.sys 13:46:45.0108 0x1140 umbus - ok 13:46:45.0116 0x1140 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09, 30AAD7D18FF5962CEC7180359D148EED5A1BF193DDB2B34508897FC3EBA692C3 ] UmPass C:\WINDOWS\System32\drivers\umpass.sys 13:46:45.0141 0x1140 UmPass - ok 13:46:45.0166 0x1140 [ 43FEFB040A0CC30F795FBF544169594D, F2A730C0F7C883321C378D4564120A40428D7F8E393F02C8D6A08934795A35C7 ] UmRdpService C:\WINDOWS\System32\umrdp.dll 13:46:45.0200 0x1140 UmRdpService - ok 13:46:45.0411 0x1140 [ DBE2E6388379D5CC78099650541E9566, 1914BC929F109A49FB18ED31F239A9813A010B0A3914BC8CD0D6A94A67A072D7 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 13:46:45.0429 0x1140 UNS - ok 13:46:45.0481 0x1140 [ 14D22C411854AA2560AFC94CD2D5E61F, BB376734733671C02319E6DB1800D41212694446FD65465498C92D4ECBFE7458 ] upnphost C:\WINDOWS\System32\upnphost.dll 13:46:45.0512 0x1140 upnphost - ok 13:46:45.0554 0x1140 [ C976C4306F9AE133D6BBD47FDFC3BF92, 820413D92D6A89055A7F26523BF5CC4B668610C4A06E8B0D163FBF929B1DFA9A ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys 13:46:45.0583 0x1140 usbccgp - ok 13:46:45.0617 0x1140 [ B395B62B62F28106218FA6FB17F4C797, 231CA3512B02BBE70E630A6304E899BCB741CE411FB10C2B3DE48E52034F24BB ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys 13:46:45.0648 0x1140 usbcir - ok 13:46:45.0671 0x1140 [ B24FDEB1B18496F1B463782235AA3AF1, 3F5036F36987C8007D03DAFC3EC30615515BE96D9A1DF879BCD4EB0E66CD50B1 ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys 13:46:45.0686 0x1140 usbehci - ok 13:46:45.0792 0x1140 [ F8C2A832DF9403F5EA8080CBDBDA95FB, 50E9455465672BC13EB945BEC132D2F30BA2EB25C68928D2B4C256F2DB292A83 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys 13:46:45.0841 0x1140 usbhub - ok 13:46:45.0901 0x1140 [ B1E910DDC08A8536116214326124903C, 8A1C69DD8ACC00A42CD86791397093342A86B2428DCBFC2CB21F0232D948B7B5 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys 13:46:45.0929 0x1140 USBHUB3 - ok 13:46:45.0969 0x1140 [ 325F6179009B5A7F6118951A5BA422AB, 756CB2893530485E8C3ACFF5A40F4C6EB446E72B2296E8772058E407A5E066DE ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys 13:46:46.0038 0x1140 usbohci - ok 13:46:46.0055 0x1140 [ BA3ABE0CD1C14B3295BAD0F076B84CAC, 19E0679D44A9BD9DDCC336C7DE784147D6CFC3DE4250D5CA31CE49867D51A414 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys 13:46:46.0075 0x1140 usbprint - ok 13:46:46.0084 0x1140 [ F77177F6C95B2116EE7AD23B5EF57007, 646E345DE5AFF26B338E17BC9D03D0EDA5608DF77D7685DE7AFF6E4113B9EB87 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS 13:46:46.0103 0x1140 USBSTOR - ok 13:46:46.0133 0x1140 [ 1ABF657259DB57F7E5558E4DF1357C0C, 34EAF5DEA3293CFA96BA81B036305FD90ABAE05B9CB73D4F54FB236448C1978C ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys 13:46:46.0148 0x1140 usbuhci - ok 13:46:46.0212 0x1140 [ 09799E701B4327097E9F63D3FE221083, CF2B97D5B3D434D8E5547B2A86771C69A6F7F4857CAD70865B50462A04A27A48 ] usbvideo C:\WINDOWS\System32\Drivers\usbvideo.sys 13:46:46.0245 0x1140 usbvideo - ok 13:46:46.0384 0x1140 [ 8DC398D7B8E02C929A2096E74A170970, 87B3CE84D05F50C33935B28F0AFF1CB15DAA4530768BA1FB25C311609CD4B0A5 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS 13:46:46.0424 0x1140 USBXHCI - ok 13:46:46.0483 0x1140 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] VaultSvc C:\WINDOWS\system32\lsass.exe 13:46:46.0515 0x1140 VaultSvc - ok 13:46:46.0564 0x1140 [ BACECBFF9C97F7627A60B0E0F1FE7EE8, DC82F767D066B93A48A090DC7146EBCCDC54B43C6CD9DF29A160E09E3A531DC8 ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys 13:46:46.0583 0x1140 vdrvroot - ok 13:46:46.0881 0x1140 [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71, 1B75B3BDA612FE1129B461A11A5C5333593E97CB79C8CBFD81E0E6AAD31ECF8B ] vds C:\WINDOWS\System32\vds.exe 13:46:47.0097 0x1140 vds - ok 13:46:47.0118 0x1140 [ 74FA2D4368DE6F6CE14393EDF1F342BE, C5CE4164B2C3D583A7FB8687ADEADCDB08D36A5AB1965E5FC6949AEED15881C8 ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys 13:46:47.0137 0x1140 VerifierExt - ok 13:46:47.0246 0x1140 [ 8628FA679F0EC4B709CCD1F6B6A3233B, E8A99795BB7956BFB9FDF6D24209280917FE6500E52F82F50C9FAD2EA6EDFA88 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys 13:46:47.0742 0x1140 vhdmp - ok 13:46:47.0764 0x1140 [ F5B4A14B00E89250C50982AC762DDD1D, 581CD97DD42E74A82F06BFB827DFC82618B4A8667ACA7E93C628BB0D056CE8F0 ] viaide C:\WINDOWS\system32\drivers\viaide.sys 13:46:47.0780 0x1140 viaide - ok 13:46:47.0843 0x1140 [ 78DB50F7329F6D1311658DABFFFC8BE0, 8CB0C831608033C4BC1D2DA7FAA7D429333A3654E76A989F7AF85BFC5F086BE9 ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys 13:46:47.0861 0x1140 vmbus - ok 13:46:47.0884 0x1140 [ ECFEE2F2BA3932C7880D1A8F67D68F91, 57DCD55A518A9FBDEF72B511C643B1062C3F7BD339F4B0FC19E9D84C615B968D ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys 13:46:47.0964 0x1140 VMBusHID - ok 13:46:48.0133 0x1140 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll 13:46:48.0160 0x1140 vmicheartbeat - ok 13:46:48.0170 0x1140 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll 13:46:48.0194 0x1140 vmickvpexchange - ok 13:46:48.0265 0x1140 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicrdv C:\WINDOWS\System32\ICSvc.dll 13:46:48.0289 0x1140 vmicrdv - ok 13:46:48.0313 0x1140 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll 13:46:48.0335 0x1140 vmicshutdown - ok 13:46:48.0347 0x1140 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmictimesync C:\WINDOWS\System32\ICSvc.dll 13:46:48.0369 0x1140 vmictimesync - ok 13:46:48.0420 0x1140 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicvss C:\WINDOWS\System32\ICSvc.dll 13:46:48.0441 0x1140 vmicvss - ok 13:46:48.0482 0x1140 [ CB60FAAED8B49B812EBBF77EB87D9B18, ADA7C68D4C4981555ED48981E8B7ACBEEF5C39F902EB98782FC3DFF495FE0C33 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys 13:46:48.0498 0x1140 volmgr - ok 13:46:48.0581 0x1140 [ A74101DA9809251BCD0E5A26BAE0F824, 15A3A7CC31A13C5882812C344D0937A8A4503D12DB07B9F7F2A8191B739CDBF7 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys 13:46:48.0602 0x1140 volmgrx - ok 13:46:48.0633 0x1140 [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE, 26FD9DBCFAEDE0F945D80B11769741A3A837F84461263217A43C458B674566EE ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys 13:46:48.0652 0x1140 volsnap - ok 13:46:48.0671 0x1140 [ A8DA1C1B52ECEA3726DEBED4FF1B700D, 75C024EC3858DF24FB82FE105BDD1E37900D53EFE9D72F42CDDFFD0742525586 ] vpci C:\WINDOWS\System32\drivers\vpci.sys 13:46:48.0687 0x1140 vpci - ok 13:46:48.0696 0x1140 [ 38A60CD9C009C55C6D3B5586F8E6A353, 7F7E2AE39F1A0A5245650911E310E0948BC22A18262A16FA76B44A042D66312D ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys 13:46:48.0715 0x1140 vsmraid - ok 13:46:48.0837 0x1140 [ D0C69E44BC1E1D4AD290FD84104623D8, 4C86760EA4BD2A64FFD42D89284EC3E5048CB2F0F6F3B80D017B41C0D2456A90 ] VSS C:\WINDOWS\system32\vssvc.exe 13:46:48.0957 0x1140 VSS - ok 13:46:48.0971 0x1140 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC, AC2F3C70EDCA0AFBB2606267DFE6D3E8E7B0772140153BAD6B0A9EDE6A1D2F29 ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys 13:46:48.0994 0x1140 VSTXRAID - ok 13:46:49.0000 0x1140 [ 62460A45435A26A334907E3F2EA45611, FEF86E05117CC0AAB8211CA1542776EB620BD4699BD590D91F16621ED35B9824 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys 13:46:49.0040 0x1140 vwifibus - ok 13:46:49.0046 0x1140 [ 095E943D27025E4D588AF0A72CC2318F, 3CE406A202F93EF8C4BC7317621A672670D734C69166393CA7256D5E5E667041 ] vwififlt C:\WINDOWS\system32\DRIVERS\vwififlt.sys 13:46:49.0061 0x1140 vwififlt - ok 13:46:49.0068 0x1140 [ 73FA1A41A97A5C34ADC03B3577FF1A86, CBA4BC0DA837C163587BBB4BF2AC1549C72440307C984D3CDF8995023718136C ] vwifimp C:\WINDOWS\system32\DRIVERS\vwifimp.sys 13:46:49.0118 0x1140 vwifimp - ok 13:46:49.0349 0x1140 [ F690B6EEAA94576727B24376D7ED3601, A61EE96024C8FC4058481DFB1E7F0AD746565368672FA3B6BA8F9E23D0F47E4C ] W32Time C:\WINDOWS\system32\w32time.dll 13:46:49.0381 0x1140 W32Time - ok 13:46:49.0462 0x1140 [ 6B806E893714019969E2B50D7EF6A4D9, 38FE2B01082DC4C2A0C11A292016A727F48C3DF1293DC3A0216B2254A452263F ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys 13:46:49.0476 0x1140 WacomPen - ok 13:46:49.0532 0x1140 [ 61F6972FF9AC9A8D0B4D62076DC30051, 5A028036461534CA53CB2D6C1D720783D408A9F17FD77AB1ECDD75FBAD9F2381 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 13:46:49.0552 0x1140 Wanarp - ok 13:46:49.0568 0x1140 [ 61F6972FF9AC9A8D0B4D62076DC30051, 5A028036461534CA53CB2D6C1D720783D408A9F17FD77AB1ECDD75FBAD9F2381 ] Wanarpv6 C:\WINDOWS\system32\DRIVERS\wanarp.sys 13:46:49.0582 0x1140 Wanarpv6 - ok 13:46:49.0810 0x1140 [ 42DF22F8C448E7CD219F6D63743505E2, 063F4280C7BD20CE1360436B76A17DFE17FF611F75337A47373D098CC6C263BF ] wbengine C:\WINDOWS\system32\wbengine.exe 13:46:49.0913 0x1140 wbengine - ok 13:46:49.0949 0x1140 [ 31D37B2F6069C631EF0557D322924812, 6E18A1060F3C8F4BF220E286C44327866A8F9109E74928AA2D8C2DA9C452038B ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll 13:46:49.0971 0x1140 WbioSrvc - ok 13:46:50.0074 0x1140 [ D9C1E82651BF19C6FF69CEC6FD400124, 93B96481A5B26F5617B16DD775AF0F8CE9001B30251FFF58D6EF9044D5EE91CD ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll 13:46:50.0095 0x1140 Wcmsvc - ok 13:46:50.0247 0x1140 [ 5B5FEAB51172F5513C2CF7B39CFA6A01, 4FDAC5168E00D44781C6F5D98ECD4977A12663C5CE6FFDFF9DBC89A28D6212D8 ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll 13:46:50.0272 0x1140 wcncsvc - ok 13:46:50.0342 0x1140 [ E19556D414332E2BEBA1F368229006B4, AB3454EC85D7B6E62D44C4510C1547AE7F736558588E54B0E265F7B3A5810E15 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll 13:46:50.0387 0x1140 WcsPlugInService - ok 13:46:50.0450 0x1140 [ B3A4D918DAB90505B6BC7B70632913CB, ECC19DCD7902C29D0682C70B9546CF8B82477A32147EE30EB6750D8499605B46 ] Wd C:\WINDOWS\system32\drivers\wd.sys 13:46:50.0496 0x1140 Wd - ok 13:46:50.0540 0x1140 [ 6F4B5DDDC3B86091E94BC47347A78AF7, C57697FAE297D832BE4EA4CEAB2F3F7A63682465FB448B6CEAB1A041A7434286 ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys 13:46:50.0569 0x1140 WdBoot - ok 13:46:50.0635 0x1140 [ 442783E2CB0DA19873B7A63833FF4CB4, 09254970265476214F3187CC22A4F9C7C2769D419600E83FBE302C3A103E527F ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys 13:46:50.0667 0x1140 Wdf01000 - ok 13:46:50.0696 0x1140 [ 99D404A9A0AFC4734E014EBEBAC13F8F, E8D4B4AFEC89D8AC707314C7086B1A981772FF3D64B5C2120D0809F1BBE9E62B ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys 13:46:50.0718 0x1140 WdFilter - ok 13:46:50.0756 0x1140 [ 240FC332484572227CD1DF82407F33E5, 5210549EC519DD3BCA6BBC995F01E1E3E0988580797E4BD1433F429E0CB30412 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll 13:46:50.0778 0x1140 WdiServiceHost - ok 13:46:50.0785 0x1140 [ 240FC332484572227CD1DF82407F33E5, 5210549EC519DD3BCA6BBC995F01E1E3E0988580797E4BD1433F429E0CB30412 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll 13:46:50.0808 0x1140 WdiSystemHost - ok 13:46:50.0875 0x1140 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6, 4281100271761521F75F4D5A3D2E9FF40A9C7D81CEDAFD2EDD95788534090CA6 ] WebClient C:\WINDOWS\System32\webclnt.dll 13:46:50.0895 0x1140 WebClient - ok 13:46:50.0964 0x1140 [ 35FD720943D4FCD75C3275BF062FF140, 9D8345E6DE1AE23F93AD0B52D27D1CCFD69EF7EE50654F92CA999BEC4570A773 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll 13:46:50.0988 0x1140 Wecsvc - ok 13:46:51.0024 0x1140 [ 4D2612E3C462B68F499D840B1133263E, 4DDAEB4480AEC31A8184838588E0D3DFA31CE6D2FA6E906926860C75F52DC7B7 ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll 13:46:51.0045 0x1140 wercplsupport - ok 13:46:51.0121 0x1140 [ 5F70EBFC1F75B487DE79501E3CCBDB54, 2FCA57BF60A43B03BB42FBF22BBFC19AD2266FBBD818494AD114125E6E433321 ] WerSvc C:\WINDOWS\System32\WerSvc.dll 13:46:51.0139 0x1140 WerSvc - ok 13:46:51.0170 0x1140 [ 8FDA12E934C7BB7CC317F90FC70DC4FC, AA0DA063BCE5692DFD46F0AAE07727B38D4AA87A9BAEBAFF137F9CAAF2808EC0 ] WFPLWFS C:\WINDOWS\system32\DRIVERS\wfplwfs.sys 13:46:51.0184 0x1140 WFPLWFS - ok 13:46:51.0207 0x1140 [ 60E0C220593DA4F7C289CB909D2DBAE0, 057CA7727F748600CC155043081AB9E3244763CF4913F317D13226A515F6FDB6 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll 13:46:51.0224 0x1140 WiaRpc - ok 13:46:51.0298 0x1140 [ A3C7624A42A3447EF5EDD1ED37FE4E60, BD8BDF0A571873FA8277878AF7AED11196CFF1B4DF1EA6BA13BD4887D7B63B94 ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys 13:46:51.0312 0x1140 WIMMount - ok 13:46:51.0339 0x1140 WinDefend - ok 13:46:51.0592 0x1140 [ 7911470B6018059A880469A63B65700A, 4B6131491A028FBCA54AC261112D183EFD42E98160545C8E8DFBDA01C87B3FB5 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll 13:46:51.0658 0x1140 WinHttpAutoProxySvc - ok 13:46:52.0044 0x1140 [ 3D6B518B71C75C8FA4115A33615C107A, ED7A266013D29D3B1A462464735C3632BEA121D1B32553907AEAA0B00595C3DF ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 13:46:52.0074 0x1140 Winmgmt - ok 13:46:52.0501 0x1140 [ 8E212A627F33F6FC3B5F3BB47212F66E, 9BBFE26ABFA14F346FE3711D13D959523EEA23608A33C16F3D750D66CA511911 ] WinRM C:\WINDOWS\system32\WsmSvc.dll 13:46:52.0834 0x1140 WinRM - ok 13:46:53.0045 0x1140 [ 6351724B8FA0255C2DBD970297F00B93, A02F274479F9F32E30C75A5BD991B008B3CCB47D380D5870563EF918DAC5730E ] WlanSvc C:\WINDOWS\System32\wlansvc.dll 13:46:53.0095 0x1140 WlanSvc - ok 13:46:53.0905 0x1140 [ 08EFA13A2234C8C3B8A99E4B88BE7E9B, 460ACD1687A2E5443A1B0E1786A517E67DB876403AC3498555848BD16DA08929 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll 13:46:54.0063 0x1140 wlidsvc - ok 13:46:54.0139 0x1140 [ E2A596CACFC6504306CDB7B593B90084, DF89CF57249553CE922C841F18B99A213185FA1099C053B9BB8C0F6E5BC3FEC0 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys 13:46:54.0154 0x1140 WmiAcpi - ok 13:46:54.0198 0x1140 [ D113499052C5E541906B727779F0F959, 05FB51086C0A0CE3812A7E6098C5A454ECCFE8553669CFA715153564F2226DB0 ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe 13:46:54.0221 0x1140 wmiApSrv - ok 13:46:54.0270 0x1140 WMPNetworkSvc - ok 13:46:54.0279 0x1140 [ C6FF953D5D6F2EAE3B8883474D5076B3, 001CBB7FBC30209C892869258E5ABD3F0932886E156ECB10DCA599F6D32648BE ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys 13:46:54.0306 0x1140 wpcfltr - ok 13:46:54.0337 0x1140 [ A6ED163169876BFD2437E872FE2F1509, C13E8676800EEEF690F51C4DEA660B36C8734AE2CCAAC48054E10D74B98949B8 ] WPCSvc C:\WINDOWS\System32\wpcsvc.dll 13:46:54.0351 0x1140 WPCSvc - ok 13:46:54.0404 0x1140 [ 39D8AB837F91B729D12D32ED81E2062F, 6CA51524A9CD70B122035B92E64A9BAAC1DBD62C047EAAD19515F54589A5BDB5 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll 13:46:54.0418 0x1140 WPDBusEnum - ok 13:46:54.0427 0x1140 [ 0346CAFC181C91C6E2330332EB332ED6, D46F44C339399CAAE13CD71C53A169E95065208E07E5420DE00A4509D6CB056F ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys 13:46:54.0446 0x1140 WpdUpFltr - ok 13:46:54.0452 0x1140 [ BC8B5CB336E63BB25EAD1CE8EDD34B81, A42759956EDCCC6D0688240AA4F833FB9CA132D42D2D901CDCBB24DCE1788C1D ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys 13:46:54.0488 0x1140 ws2ifsl - ok 13:46:54.0536 0x1140 [ 012CFE7F0F95266F554EE3B91EE2128A, 866312F6BF7369BE686F1BA9F01311C99E95E268C6E63BE37C841F54F5AA0DB8 ] wscsvc C:\WINDOWS\System32\wscsvc.dll 13:46:54.0580 0x1140 wscsvc - ok 13:46:54.0585 0x1140 WSearch - ok 13:46:54.0876 0x1140 [ C10BFFEE7E0D7A1366E84F251796C51D, E1FD1DF5F5C5934F9A8584D54F35720655AC4F5D4CFD69CD1E063C0BBEC4D33D ] WSService C:\WINDOWS\System32\WSService.dll 13:46:55.0011 0x1140 WSService - ok 13:46:55.0288 0x1140 [ D460D4F3D6B1D46DD5E8249D8340B15D, 2A694793226B68764920A8AF8F9E66CD3C6B819B77C8073F991019709166408F ] wuauserv C:\WINDOWS\system32\wuaueng.dll 13:46:55.0429 0x1140 wuauserv - ok 13:46:55.0452 0x1140 [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys 13:46:55.0466 0x1140 WudfPf - ok 13:46:55.0523 0x1140 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys 13:46:55.0548 0x1140 WUDFRd - ok 13:46:55.0584 0x1140 [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll 13:46:55.0608 0x1140 wudfsvc - ok 13:46:55.0621 0x1140 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys 13:46:55.0648 0x1140 WUDFWpdFs - ok 13:46:55.0719 0x1140 [ F9D8D2E6ECE08B278621D5BF3A7240A6, 99EEEE51EA6CE8909713CA81A2AFA5102774AE9C8554F422F4D9A1D8B0ABDB09 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll 13:46:55.0761 0x1140 WwanSvc - ok 13:46:55.0779 0x1140 ================ Scan global =============================== 13:46:55.0856 0x1140 [ DDC1AFBF9DDF880CE9BD3896114D8DED, E2406231EA4D2689A5EDFA9BD1A1BC064359D8D23B37F113A18B5EAE3E2D4050 ] C:\WINDOWS\system32\basesrv.dll 13:46:55.0900 0x1140 [ E9343076AE704D20BB0D01F3AF3EFFEF, FF2CE4146945976F9480690505CECD3C7C719BAF0F633E6192C8272C75EF295D ] C:\WINDOWS\system32\winsrv.dll 13:46:55.0922 0x1140 [ BD7C6949984D19AAA609896B675E7357, 5B46538B27BC70F5A3805AA63F6AACDC780C7168468FB535F2D35CF26B9DEE06 ] C:\WINDOWS\system32\sxssrv.dll 13:46:56.0050 0x1140 [ 8F226143046435C75C033B0C52E90FFE, 54FA316485B57D7B8104FE621F5F40DEC35E3D57C3DF46B5F7EACF57445FE7CA ] C:\WINDOWS\system32\services.exe 13:46:56.0326 0x1140 [ Global ] - ok 13:46:56.0327 0x1140 ================ Scan MBR ================================== 13:46:56.0347 0x1140 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0 13:46:56.0646 0x1140 \Device\Harddisk0\DR0 - ok 13:46:56.0647 0x1140 ================ Scan VBR ================================== 13:46:56.0721 0x1140 [ 93BC88435F954E2EB45CC614A591FCD4 ] \Device\Harddisk0\DR0\Partition1 13:46:56.0794 0x1140 \Device\Harddisk0\DR0\Partition1 - ok 13:46:56.0811 0x1140 [ 4D47C940DDF87DB28CAC6FC029AFEADE ] \Device\Harddisk0\DR0\Partition2 13:46:56.0828 0x1140 \Device\Harddisk0\DR0\Partition2 - ok 13:46:56.0838 0x1140 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3 13:46:56.0855 0x1140 \Device\Harddisk0\DR0\Partition3 - ok 13:46:56.0889 0x1140 [ AEA1867EE14AFA08CE69166C5B6812E3 ] \Device\Harddisk0\DR0\Partition4 13:46:56.0919 0x1140 \Device\Harddisk0\DR0\Partition4 - ok 13:46:56.0948 0x1140 [ 332E309161B51C7FCDA905F9F9201890 ] \Device\Harddisk0\DR0\Partition5 13:46:56.0997 0x1140 \Device\Harddisk0\DR0\Partition5 - ok 13:46:57.0025 0x1140 [ 2CAC2B63F1A533BFA44FD58944868960 ] \Device\Harddisk0\DR0\Partition6 13:46:57.0087 0x1140 \Device\Harddisk0\DR0\Partition6 - ok 13:46:57.0113 0x1140 [ 242C85077B67B3F515EFD814E388B01A ] \Device\Harddisk0\DR0\Partition7 13:46:57.0129 0x1140 \Device\Harddisk0\DR0\Partition7 - ok 13:46:57.0129 0x1140 ================ Scan generic autorun ====================== 13:46:57.0203 0x1140 [ 483BAA4246B80BDE1EA562C618BBA4A1, 0340A483F2F00A329ADC625940E5B2E951E1AA362CB088477EFC92D245207CEA ] C:\Windows\system32\igfxtray.exe 13:46:57.0215 0x1140 IgfxTray - ok 13:46:57.0304 0x1140 [ 40CAEC9DBC892ED1915704CC54CB382E, 38976A5EF1461027FF8F07397793A9BEFD0B3B47EB1B86F0F3FB88818E5917C9 ] C:\Windows\system32\hkcmd.exe 13:46:57.0321 0x1140 HotKeysCmds - ok 13:46:57.0448 0x1140 [ C88B01661694F2013F8DF1BD66B8B39E, 5BB40F448A85EE00FC090D61BFAB2D15874946E355F92B4FA40482153F0EB83E ] C:\Windows\system32\igfxpers.exe 13:46:57.0476 0x1140 Persistence - ok 13:46:58.0551 0x1140 [ 834A309C2FDF52FC09353F348CFE1235, FF8D5B0C4D8DEF3B313E11B01D6A2A29758E8721EF2EC0AAC2DB3C9AAF399276 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 13:46:58.0965 0x1140 RTHDVCPL - ok 13:46:58.0980 0x1140 SynTPEnh - ok 13:46:59.0322 0x1140 [ B6DEEB171382DEB54EA7D9F9F29F3DFB, DFADAFA02E1F1A49D0461CABF82ACA8FEEEF450370E4CB4D131D50F9C02826B5 ] C:\Program Files\McAfee.com\Agent\mcagent.exe 13:46:59.0358 0x1140 mcui_exe - ok 13:46:59.0468 0x1140 [ FF7CB5344094510654C240486B4B1B3F, 2A50A3BC366D5293C61FEDC5639C0EB2BB3176933599B6C1533F06F9B6C5D2DF ] C:\Program Files (x86)\RadioController\RfBtnHelper.exe 13:46:59.0491 0x1140 RadioController - ok 13:46:59.0799 0x1140 [ 0DB20318CEB155799880FEC174988933, 3840A7C9DF01F118048E806D71BDC5686A8FCF316FB35E65045988B0271532D8 ] C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe 13:46:59.0854 0x1140 GDFirewallTray - ok 13:47:01.0238 0x1140 [ 47DBCC66CF9A3DCEF2D42051431160D3, 5E99CB8333471E80590AED8CA139EF859AD617D1C7BD9406913A86016DCA08F6 ] C:\Program Files\CCleaner\CCleaner64.exe 13:47:02.0152 0x1140 CCleaner Monitoring - ok 13:47:04.0067 0x1140 [ 28E85C272234B2EC0607531D33F7ACE7, 5DC9C99061851549F56AD45F65C00886E27644A767CDF622F694B4F002461264 ] C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe 13:47:04.0200 0x1140 KakaoTalk - ok 13:47:04.0769 0x1140 [ 005B2B63719E6B3E8E2E1446A9278F8E, 0A34046B0205A2FEEE5E2867765D171D7BA420A1527E49472A35B484219BD377 ] C:\Users\Helmut\AppData\Roaming\Spotify\SpotifyWebHelper.exe 13:47:04.0856 0x1140 Spotify Web Helper - ok 13:47:04.0859 0x1140 Waiting for KSN requests completion. In queue: 157 13:47:05.0860 0x1140 Waiting for KSN requests completion. In queue: 157 13:47:06.0860 0x1140 Waiting for KSN requests completion. In queue: 157 13:47:07.0875 0x1140 AV detected via SS2: McAfee Anti-Virus und Anti-Spyware, C:\Program Files\McAfee.com\Agent\mcupdate.exe ( 11.6.0.0 ), 0x52000 ( disabled : updated ) 13:47:07.0876 0x1140 AV detected via SS2: G DATA INTERNET SECURITY, C:\Program Files (x86)\G DATA\InternetSecurity\AVK\avkwscpe.exe ( 25.1.0.0 ), 0x41000 ( enabled : updated ) 13:47:07.0878 0x1140 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.2.223.0 ), 0x60100 ( disabled : updated ) 13:47:07.0880 0x1140 FW detected via SS2: G*DATA Personal Firewall, C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe ( 22.0.0.1 ), 0x41010 ( enabled ) 13:47:07.0882 0x1140 FW detected via SS2: McAfee Firewall, C:\Program Files\McAfee.com\Agent\mcupdate.exe ( 11.6.0.0 ), 0x51010 ( enabled ) 13:47:10.0231 0x1140 ============================================================ 13:47:10.0231 0x1140 Scan finished 13:47:10.0231 0x1140 ============================================================ 13:47:10.0241 0x1da0 Detected object count: 0 13:47:10.0241 0x1da0 Actual detected object count: 0 13:51:36.0649 0x0a04 Deinitialize success |
23.08.2015, 20:39 | #5 |
/// Selecta Jahrusso | Antivirenprogramme werden ausgeschalten So sehe ich da jetzt nichts mehr an Malware, nur dass ein Treiber von McAfee aus der Registry gelöscht wurde. Dies könnte wohl der Grund sein, warum es sich nicht mehr starten lässt ( btw, empfehle ich McAfee niemanden. IMHO ist es schrott ) Kannst du bitte einmal all deine Anti Viren Programme deinstallieren und dann jenes installieren, welches du in Zukunft nutzen willst.
__________________ mfg, Daniel ASAP & UNITE Member Alliance of Security Analysis Professionals Unified Network of Instructors and Trusted Eliminators Lerne, zurück zu schlagen und unterstütze uns! TB Akademie |
26.08.2015, 18:40 | #6 |
/// Selecta Jahrusso | Antivirenprogramme werden ausgeschalten Dieses Thema wird aufgrund fehlender Rückmeldung aus meinen Abos gelöscht. Somit bekomme ich keine Benachrichtigung von neue Antworten. Solltest du dennoch weiter machen wollen, so schicke mir bitte eine PM.
__________________ --> Antivirenprogramme werden ausgeschalten |
Themen zu Antivirenprogramme werden ausgeschalten |
antivirenprogramme deaktiviert, ccleaner, ergebnis, folge, folgendes, free, gdata, gekauft, guten, knapp, langsam, langsamer, laptop, manager, mcafee, programme, recht, scan, schnell, security, software, superantispyware, task manager, trojaner, versuche, virus, win |