Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Schadsoftware versendet E-Mails

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 11.11.2015, 20:09   #1
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Guten Abend.

Mein computer-unkundiger Nachbar hat mich gebeten, ihn bei einem Problem zu helfen, und auch wenn ich computerkundig bin, bin ich hier ratlos. Es handelt sich offenbar um eine Schadsoftware, die er sich eingefangen hat. Diese verschickt alle 2-3 Wochen automatisch E-Mails an all seine Kontakte. Diese Mails enthalten nur einen Link, auf den ich gleich noch zu sprechn komme.

Das Versenden der Mails geschah einmal zu einem Zeitpunkt, wo der Rechner bestimmt nicht an war, also nehm ich an, dass diese Versende-Software nicht auf dem Rechner liegt. Aber: Mein Nachbar hat sich nun schon 2 mal von der Telekom neue Konto-Zugangsdaten geben lassen, und trotzdem gabs nach 2 Wochen erneut eine solche E-Mail-Welle.
Das lässt mich glauben, dass auf dem Rechner eine Spyware ist, die die jeweils aktuellen Kontodaten stiehlt und an einen Server schickt, welcher wiederum die E-Mails verschickt.

Weitere Fakten:
G-Data-Virusscanner findet nichts.
Ein von der Telekom installierter Malwarebytes-Scanner findet auch nichts.

In der versendeten E-Mail stehrt ein Link etwa wie "Mark360.com/xx/yyy.php"
Mark360.com ist eine zum Kauf angebotene domain, also eigentlich ohne Inhalt. Wenn man die Adresse eingibt, erhält man eine Standard-Seite, die diese Domain zum Kauf anbietet.
Gab man im Browser (bis letzte Woche jedenfalls war es so), die Adresse Mark360.com/xx an (xx: weiß nicht mehr genau auswendig wie das hieß), dann gabs eine G-Data-Warning, die Seite enthielte einen Virus "Script.Trojan.Agent.IT (Engine B)".
Im Internet hab ich nichts darüber gefunden.

Meine Fragen:
Sind meine Annahmen bezüglich der Funktionsweise der Schadsoftware richtig?
Kennt jemand diese Sch... adsoftware und weiß, wie man das abstellen kann?
Wie kann ich das, was noch auf diesem Rechner ist finden und vernichten?

Vielen Dank für eure Aufmerksamkeit.

Alt 11.11.2015, 22:52   #2
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails





Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
  • Bitte arbeite alle Schritte der Reihe nach ab.
  • Lies die Anleitungen sorgfältig durch bevor Du beginnst. Wenn es Probleme gibt oder Du etwas nicht verstehst, dann stoppe mit Deiner Ausführung und beschreibe mir das Problem.
  • Führe bitte nur Scans durch, zu denen Du von mir aufgefordert wurdest.
  • Bitte kein Crossposting (posten in mehreren Foren).
  • Installiere oder deinstalliere während der Bereinigung keine Software, außer Du wurdest dazu aufgefordert.
  • Speichere alle unsere Tools auf dem Desktop ab. Link: So ladet Ihr unsere Tools richtig
  • Poste die Logfiles direkt in Deinen Thread in Code-Tags.
  • Bedenke, dass wir hier alle während unserer Freizeit tätig sind, wenn du innerhalb von 24 Stunden nichts von mir liest, dann schreibe mir bitte eine PM.

Hinweis:
Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden.
Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert.
Adware & Co. können wir sehr gut entfernen.
Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst.



Los geht's:

Schritt 1


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)




Lesestoff
Posten in CODE-Tags: So gehts...
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert uns massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 13.11.2015, 15:14   #3
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Hallo Jürgen,
vielen Dank für Deine Initiative. Ich bin jetzt auf dem Rechner meines Nachbarn und habe den FRST-Scan durchgeführt. Hier sind die entsprechenden Files:
FRST.TXT:

FRST Logfile:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
durchgeführt von Silence (Administrator) auf SILENCE-PC (13-11-2015 15:02:00)
Gestartet von C:\Users\Silence\Desktop
Geladene Profile: Silence (Verfügbare Profile: Silence)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(G Data Software AG) C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(G Data Software AG) C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(HP) C:\Program Files\Hp\HPLaserJetService\HPLaserJetService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(G Data Software AG) C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(G Data Software AG) C:\Program Files\G DATA\InternetSecurity\AVKTray\AVKTray.exe
(G Data Software AG) C:\Program Files\Common Files\G Data\AVKProxy\GDKBFltExe32.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Hewlett-Packard) C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) C:\Program Files\Hp\StatusAlerts\bin\HPStatusAlerts.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(G DATA Software AG) C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\reader_sl.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12111576 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM\...\Run: [GDFirewallTray] => C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe [1864312 2015-06-16] (G DATA Software AG)
HKLM\...\Run: [HP Color LaserJet CM1312 MFP Series Fax] => C:\Program Files\HP\HP Color LaserJet CM1312 MFP Series\hppfaxprintersrv.exe [2453504 2009-09-22] (Hewlett-Packard Company)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [StatusAlerts] => C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe [330176 2014-08-19] (Hewlett-Packard Company)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-10-16] (Apple Inc.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files\G DATA\InternetSecurity\AVKTray\AVKTray.exe,c:\program files\g data\internetsecurity\avkkid\avkcks.exe
HKU\S-1-5-21-3906192273-1234835177-2734361635-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3906192273-1234835177-2734361635-1000\...\MountPoints2: {e0d70709-cb52-11e3-9ee3-806e6f6e6963} - D:\Autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2015-07-15]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2015-06-12]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{84630ACD-562D-48CF-8C9E-379588CC0E2F}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKU\S-1-5-21-3906192273-1234835177-2734361635-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
SearchScopes: HKU\S-1-5-21-3906192273-1234835177-2734361635-1000 -> {118EB0EA-5186-43B5-892C-7DF7EDE41461} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-25] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-25] (Oracle Corporation)
BHO: Kein Name -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> Keine Datei

FireFox:
========
FF ProfilePath: C:\Users\Silence\AppData\Roaming\Mozilla\Firefox\Profiles\qwr33p97.default
FF DefaultSearchEngine: Yahoo Web
FF Homepage: hxxps://de.yahoo.com/?type=orcl_hpset
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-03] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-03] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-25] (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Silence\AppData\Roaming\Mozilla\Firefox\Profiles\qwr33p97.default\searchplugins\yahoo-ysp.xml [2015-10-25]
FF Extension: New Tab by Yahoo - C:\Users\Silence\AppData\Roaming\Mozilla\Firefox\Profiles\qwr33p97.default\Extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2015-10-08] [ist nicht signiert]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-10-09]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AVKProxy; C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe [2738296 2015-09-16] (G Data Software AG)
R2 AVKService; C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe [966776 2015-06-16] (G Data Software AG)
R2 AVKWCtl; C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe [3036544 2015-09-16] (G Data Software AG)
S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [279024 2013-09-12] (Intel Corporation)
R3 GDFwSvc; C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe [2551408 2015-09-15] (G Data Software AG)
R3 GDScan; C:\Program Files\Common Files\G Data\GDScan\GDScan.exe [789624 2015-06-16] (G Data Software AG)
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [Datei ist nicht signiert]
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [Datei ist nicht signiert]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [Datei ist nicht signiert]
R3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [169752 2012-04-24] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [586240 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [637912 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [Datei ist nicht signiert]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [Datei ist nicht signiert]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5491984 2015-05-20] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2014-01-15] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [112640 2015-10-16] (G Data Software AG)
R1 GDKBB; C:\Windows\system32\drivers\GDKBB32.sys [25088 2015-10-16] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt32.sys [20352 2015-10-16] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [161792 2015-10-16] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [73216 2015-10-16] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd32.sys [54272 2015-10-16] (G DATA Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [29528 2015-09-11] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [87552 2015-10-16] (G Data Software AG)
S3 HPEWSFXBULK; C:\Windows\System32\drivers\hpfxbulk.sys [17432 2009-02-26] (Hewlett Packard)
S3 HPFXBULK; C:\Windows\System32\drivers\hpfxbulk.sys [17432 2009-02-26] (Hewlett Packard)
S3 HPFXFAX; C:\Windows\System32\drivers\hpfxfax.sys [20504 2007-07-16] (Hewlett Packard)
S3 iaStorA; C:\Windows\system32\drivers\iaStorA.sys [489968 2013-07-02] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24048 2013-07-02] (Intel Corporation)
S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [583664 2013-07-02] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\TeeDriver.sys [85464 2013-09-03] (Intel Corporation)
S4 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x32.sys [X]
S4 gdrv; \??\C:\Windows\gdrv.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-13 15:02 - 2015-11-13 15:02 - 00013993 _____ C:\Users\Silence\Desktop\FRST.txt
2015-11-13 15:00 - 2015-11-13 15:02 - 00000000 ____D C:\FRST
2015-11-13 14:59 - 2015-11-13 14:59 - 01702400 _____ (Farbar) C:\Users\Silence\Desktop\FRST.exe
2015-11-13 14:42 - 2015-11-13 14:42 - 00000056 _____ C:\Windows\setupact.log
2015-11-13 14:42 - 2015-11-13 14:42 - 00000000 _____ C:\Windows\setuperr.log
2015-11-13 06:39 - 2015-11-03 18:46 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 06:10 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-11 06:10 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-11 06:10 - 2015-10-29 18:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-11 06:10 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-11 06:09 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-11 06:09 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-11 06:09 - 2015-10-30 23:58 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 06:09 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 06:09 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 06:09 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-11 06:09 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-11 06:09 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-11 06:09 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-11 06:09 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 06:09 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-11 06:09 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-11 06:09 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-11 06:09 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 06:09 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-11 06:09 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-11 06:09 - 2015-10-30 23:36 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-11 06:09 - 2015-10-30 23:31 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 06:09 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-11 06:09 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 06:09 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-11 06:09 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-11 06:09 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-11 06:09 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-11 06:09 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-11 06:09 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-11 06:09 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 06:09 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 06:09 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-11 06:09 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-11 06:09 - 2015-10-30 23:09 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 06:09 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 06:09 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 06:09 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-11 06:09 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-11-11 06:09 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 06:09 - 2015-10-20 01:52 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-11 06:09 - 2015-10-20 01:52 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-11 06:09 - 2015-10-20 01:48 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-11 06:09 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-11 06:09 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-11 06:09 - 2015-10-20 01:45 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-11 06:09 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-11 06:09 - 2015-10-20 01:44 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-11 06:09 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-11 06:09 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-11 06:09 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-11 06:09 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-11 06:09 - 2015-10-20 00:29 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-11 06:09 - 2015-10-20 00:28 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-11 06:09 - 2015-10-20 00:28 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-11 06:09 - 2015-10-13 17:31 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 06:09 - 2015-10-13 17:31 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 06:09 - 2015-10-13 05:50 - 00712640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-11 06:09 - 2015-09-23 14:09 - 00371920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-11 06:09 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 02955776 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-11 06:08 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-11 06:08 - 2015-10-20 18:45 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-11 06:08 - 2015-10-20 18:45 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-11 06:08 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-11 06:08 - 2015-10-20 18:45 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 06:08 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-11 06:08 - 2015-10-01 18:50 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-07 07:30 - 2015-11-07 09:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-11-05 10:40 - 2015-11-13 08:01 - 00023040 _____ C:\Users\Silence\Desktop\3. Wochenplan .xls
2015-11-03 06:31 - 2015-11-03 06:31 - 00001791 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-11-03 06:31 - 2015-11-03 06:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-11-03 06:30 - 2015-11-03 06:31 - 00000000 ____D C:\Program Files\iTunes
2015-11-03 06:30 - 2015-11-03 06:30 - 00000000 ____D C:\Program Files\iPod
2015-11-03 06:27 - 2015-11-03 06:27 - 00000000 ____D C:\Program Files\Bonjour
2015-11-03 06:26 - 2015-11-03 06:26 - 00000000 ____D C:\Program Files\Apple Software Update
2015-11-03 06:15 - 2015-11-13 14:49 - 01297778 _____ C:\Windows\WindowsUpdate.log
2015-11-02 15:34 - 2015-11-02 15:34 - 00000000 ____D C:\Users\Silence\AppData\Local\CEF
2015-11-02 15:33 - 2015-11-06 06:34 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-02 15:33 - 2015-11-02 15:33 - 00002055 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-11-02 15:33 - 2015-11-02 15:33 - 00000000 ____D C:\Program Files\Adobe
2015-10-30 16:25 - 2015-10-30 17:00 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2015-10-27 13:31 - 2015-10-27 13:34 - 00000000 ____D C:\Users\Silence\Desktop\SERVIGAS
2015-10-25 07:04 - 2015-10-25 07:04 - 00000000 ____D C:\Users\Silence\AppData\Local\YSearchUtil
2015-10-25 07:04 - 2015-10-25 07:04 - 00000000 ____D C:\Program Files\Yahoo!
2015-10-25 07:02 - 2015-10-25 07:02 - 00000000 ____D C:\Program Files\Common Files\Java
2015-10-16 05:42 - 2015-10-16 05:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA INTERNET SECURITY
2015-10-15 13:27 - 2015-09-18 18:47 - 00023384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-10-15 13:27 - 2015-09-18 18:44 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-10-15 13:27 - 2015-09-18 18:44 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-10-15 13:27 - 2015-09-18 18:44 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-10-15 13:27 - 2015-09-18 18:44 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-10-15 13:27 - 2015-09-18 18:44 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-10-15 13:27 - 2015-09-18 18:35 - 00999936 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-10-14 14:33 - 2015-10-01 18:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-10-14 14:33 - 2015-10-01 18:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-10-14 14:33 - 2015-10-01 18:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-10-14 14:33 - 2015-10-01 18:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-10-14 14:33 - 2015-10-01 18:50 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-10-14 14:33 - 2015-10-01 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-10-14 14:33 - 2015-08-06 18:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 14:33 - 2015-08-06 18:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 14:33 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-13 14:57 - 2009-07-14 05:34 - 00053776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-13 14:57 - 2009-07-14 05:34 - 00053776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-13 14:50 - 2015-06-12 17:56 - 00000000 ____D C:\Users\Silence\AppData\Roaming\FileAdvisor
2015-11-13 14:47 - 2010-11-20 22:01 - 01628560 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-13 14:42 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-13 14:42 - 2009-07-14 05:33 - 00369264 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-13 08:11 - 2015-06-12 16:07 - 00064000 _____ C:\Users\Silence\Desktop\2.Wochenplan.xls
2015-11-13 07:16 - 2014-11-05 12:31 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-11 19:16 - 2014-11-05 12:31 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-11 19:16 - 2014-11-05 12:31 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-11 17:30 - 2015-06-12 16:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor
2015-11-11 17:30 - 2015-06-12 16:30 - 00000000 ____D C:\Program Files\File Type Advisor
2015-11-11 17:27 - 2015-06-13 10:12 - 00050688 _____ C:\Users\Silence\Desktop\Koch.xls
2015-11-11 17:08 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-11-11 15:15 - 2011-04-12 02:39 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 15:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-11-11 07:48 - 2014-02-22 10:59 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 07:36 - 2014-02-22 10:59 - 143250520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-10 17:17 - 2015-06-13 10:21 - 00000000 ____D C:\Users\Silence\Desktop\Pest - Angebot
2015-11-09 18:03 - 2015-06-13 09:16 - 00000000 ____D C:\Users\Silence\Desktop\Robert Terbeck AL
2015-11-08 07:37 - 2015-10-08 16:38 - 00000000 ____D C:\Users\Silence\AppData\Roaming\HpUpdate
2015-11-07 09:06 - 2015-06-12 14:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-11-06 17:13 - 2015-06-13 10:22 - 00000000 ____D C:\Users\Silence\Desktop\Bestellung
2015-11-04 16:14 - 2014-04-23 20:07 - 00000862 _____ C:\Users\Silence\AppData\Roaming\burnaware.ini
2015-11-03 06:30 - 2015-06-12 16:27 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-11-03 06:26 - 2015-06-12 16:27 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-11-02 15:34 - 2015-06-12 15:28 - 00000000 ____D C:\Users\Silence\AppData\Local\Adobe
2015-11-02 15:33 - 2014-02-22 10:38 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-11-02 15:33 - 2014-02-22 10:37 - 00000000 ____D C:\ProgramData\Adobe
2015-11-02 15:25 - 2015-06-12 16:07 - 00024576 _____ C:\Users\Silence\Desktop\1. Wochenplan.xls
2015-10-27 14:18 - 2015-09-11 15:49 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-10-27 13:34 - 2015-06-13 09:16 - 00000000 ____D C:\Users\Silence\Desktop\Kunde
2015-10-25 09:44 - 2015-06-13 10:21 - 00000000 ____D C:\Users\Silence\Desktop\Privat
2015-10-25 07:02 - 2015-06-01 11:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-25 07:02 - 2014-02-22 10:47 - 00000000 ____D C:\ProgramData\Oracle
2015-10-25 07:01 - 2015-09-11 16:24 - 00000000 ____D C:\Users\Silence\.oracle_jre_usage
2015-10-25 07:01 - 2015-06-01 11:43 - 00097888 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-10-25 07:01 - 2015-06-01 11:43 - 00000000 ____D C:\Program Files\Java
2015-10-22 14:54 - 2015-06-12 16:07 - 02605568 _____ C:\Users\Silence\Desktop\Angebot Koch .xls
2015-10-20 11:57 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2015-10-18 10:15 - 2015-06-13 09:15 - 00000000 ____D C:\Users\Silence\Desktop\AL - SERVIGAS
2015-10-17 13:30 - 2015-06-13 09:15 - 00000000 ____D C:\Users\Silence\Desktop\Andreas
2015-10-16 05:42 - 2015-07-03 11:58 - 00025088 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBB32.sys
2015-10-16 05:42 - 2015-06-12 15:20 - 00073216 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2015-10-16 05:42 - 2015-06-12 15:20 - 00001974 _____ C:\Users\Public\Desktop\G DATA INTERNET SECURITY.lnk
2015-10-16 05:42 - 2015-06-12 15:19 - 00020352 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt32.sys
2015-10-16 05:41 - 2015-06-12 15:19 - 00161792 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2015-10-16 05:41 - 2015-06-12 15:19 - 00112640 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2015-10-16 05:41 - 2015-06-12 15:19 - 00087552 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2015-10-16 05:41 - 2015-06-12 15:19 - 00054272 _____ (G DATA Software AG) C:\Windows\system32\Drivers\gdwfpcd32.sys
2015-10-15 14:36 - 2015-02-19 18:31 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-15 14:36 - 2014-04-23 21:18 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-10-14 17:59 - 2015-06-12 16:07 - 00029696 _____ C:\Users\Silence\Desktop\ANGEBOTE .xls
2015-10-14 08:29 - 2015-07-13 17:04 - 00022290 _____ C:\Users\Silence\Desktop\Koch.ods
2015-10-14 07:57 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\system32\FxsTmp

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-04-23 20:07 - 2015-11-04 16:14 - 0000862 _____ () C:\Users\Silence\AppData\Roaming\burnaware.ini
2015-06-12 15:19 - 2015-06-12 15:19 - 0000000 _____ () C:\Users\Silence\AppData\Roaming\gdfw.log
2015-06-12 15:19 - 2015-06-12 15:19 - 0000779 _____ () C:\Users\Silence\AppData\Roaming\gdscan.log
2015-07-22 16:33 - 2015-08-09 12:28 - 0000031 _____ () C:\Users\Silence\AppData\Local\burnaware.ini
2015-06-15 15:56 - 2015-07-15 16:50 - 0006973 _____ () C:\ProgramData\hpzinstall.log

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-11-13 07:46

==================== Ende vom FRST.txt ============================
         
--- --- ---


und Addition.TXT
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version:07-11-2015
durchgeführt von Silence (2015-11-13 15:03:23)
Gestartet von C:\Users\Silence\Desktop
Microsoft Windows 7 Professional  Service Pack 1 (X86) (2014-02-22 09:17:47)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3906192273-1234835177-2734361635-500 - Administrator - Disabled)
Gast (S-1-5-21-3906192273-1234835177-2734361635-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3906192273-1234835177-2734361635-1002 - Limited - Enabled)
Silence (S-1-5-21-3906192273-1234835177-2734361635-1000 - Administrator - Enabled) => C:\Users\Silence

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: G DATA INTERNET SECURITY (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G DATA INTERNET SECURITY (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: G*DATA Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

32 Bit HP CIO Components Installer (Version: 4.1.1 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe Acrobat Reader DC - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.009.20077 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Apple Application Support (32-Bit) (HKLM\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{9A629DCB-415D-4A50-85B9-5C2E4F8F74A8}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Bonjour (HKLM\...\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.)
BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden
BurnAware Free 8.0 (HKLM\...\BurnAware Free_is1) (Version:  - Burnaware)
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
CDex - Open Source Digital Audio CD Extractor (HKLM\...\CDex) (Version: 1.78.0.2015 - Georgy Berdyshev)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CopyCd personal (HKU\S-1-5-21-3906192273-1234835177-2734361635-1000\...\ReuschtoolsCopyCd) (Version: CopyCd_1.3_english - Arndt Reusch eK, Germany)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
File Type Advisor 1.6 (HKLM\...\File Type Advisor_is1) (Version:  - )
Fotogalerie (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
G DATA INTERNET SECURITY (HKLM\...\{AC68D2FF-1674-4C16-A536-A69FC11BBD82}) (Version: 25.1.0.9 - G DATA Software AG)
HP Color LaserJet CM1312 MFP Series 5.1 (HKLM\...\{8EEDB90E-6ABC-42bb-AD4C-39DEE05E3EEA}) (Version: 5.1 - HP)
HP Color LaserJet Pro MFP M277 (HKLM\...\{7ac49734-541c-48e7-99be-02f41e43e79d}) (Version: 14.0.14309.409 - Hewlett-Packard)
HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPCLJProM277 (Version: 1.00.0000 - Hewlett-Packard) Hidden
hppCLJCM1312 (Version: 005.001.00142 - Hewlett-Packard) Hidden
hppFaxDrvCM1312 (Version: 005.000.00001 - Hewlett-Packard) Hidden
hppFaxUtilityCM1312 (Version: 005.001.00137 - Ihr Firmenname) Hidden
hppFonts (Version: 001.001.00061 - Hewlett-Packard) Hidden
hppLaserJetService (Version: 009.033.00926 - Hewlett-Packard) Hidden
hppM277LaserJetService (Version: 001.034.00686 - Hewlett-Packard) Hidden
hppManualsCM1312 (Version: 005.001.00145 - Ihr Firmenname) Hidden
hppQFolderCM1312 (Version: 1.00.0000 - Hewlett-Packard) Hidden
hppScanToCM1312 (Version: 005.001.00140 - Ihr Firmenname) Hidden
hppSendFaxCM1312 (Version: 005.000.00001 - Ihr Firmenname) Hidden
HPScanPlugin (HKLM\...\{0D118BA9-4706-49DE-8E2F-1A12317EDBF6}) (Version: 28.11.0.0 - Hewlett-Packard Co.)
hpStatusAlerts (Version: 140.040.00231 - Hewlett Packard) Hidden
hpStatusAlertsM277 (Version: 140.046.00129 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM\...\{F20A04CF-5BE6-404A-9295-D59046238245}) (Version: 12.3.6.6 - HP)
Intel(R) Control Center (HKLM\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
iTunes (HKLM\...\{8862F11A-A9A0-4899-9F50-B5A79F12F3C2}) (Version: 12.3.1.23 - Apple Inc.)
Java 8 Update 65 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.52213 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.52213 - Microsoft Corporation)
Microsoft Office 2000 Professional (HKLM\...\{00010407-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2816 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Movie Maker (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 42.0 (x86 de) (HKLM\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 de) (HKLM\...\Mozilla Thunderbird 38.2.0 (x86 de)) (Version: 38.2.0 - Mozilla)
Mozilla Thunderbird 38.3.0 (x86 de) (HKU\S-1-5-21-3906192273-1234835177-2734361635-1000\...\Mozilla Thunderbird 38.3.0 (x86 de)) (Version: 38.3.0 - Mozilla)
OpenOffice 4.1.1 (HKLM\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
PhotoScape (HKLM\...\PhotoScape) (Version:  - )
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.42849 - TeamViewer)
TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Yahoo Search Set (HKLM\...\Yahoo! SearchSet) (Version:  - Yahoo Inc.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-3906192273-1234835177-2734361635-1000_Classes\CLSID\{02504641-039b-4746-9c4b-0f04428bb28b}\InprocServer32 -> C:\Users\Silence\AppData\Local\CopyCd\RClick.dll (Arndt Reusch eK)
CustomCLSID: HKU\S-1-5-21-3906192273-1234835177-2734361635-1000_Classes\CLSID\{53B5243F-8302-4DAD-BE8F-1D0665E8225E}\InprocServer32 -> C:\Program Files\HP\Common\FWUpdateEDO3.dll (Hewlett-Packard Company)

==================== Wiederherstellungspunkte =========================

28-10-2015 05:57:49 Windows Update
31-10-2015 06:08:24 Windows Update
04-11-2015 05:50:23 Windows Update
07-11-2015 06:55:23 Windows Update
11-11-2015 07:30:53 Windows Update
13-11-2015 08:13:39 Windows Update

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:04 - 2015-10-09 15:16 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {2DDCC192-E1B6-47FC-AAEB-0FBFF878D81A} - System32\Tasks\{F519B736-CC2E-468C-8A29-B06710FC5BB2} => D:\Setup.exe
Task: {43511DAB-E374-4453-9007-0C97DE37A831} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {6B1222A3-31E1-4C58-A9B6-6BFBE60A9A5A} - System32\Tasks\{FAB0B38C-5AD3-4E57-8B39-88641C0543F4} => Iexplore.exe hxxp://ui.skype.com/ui/0/7.0.0.102/de/abandoninstall?page=tsMain
Task: {787D7D26-1308-4D60-8E53-8E44CB20CDF3} - System32\Tasks\{77C15785-9718-48E1-870B-A5F3FA3BC74E} => D:\Setup.exe
Task: {82AE311C-1B0D-44CF-8A0C-211CCEDFF87D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd)
Task: {9CE591CE-E161-4391-92FA-9BB12D104FE4} - System32\Tasks\{E7933C5A-59B7-48D6-AA1E-9215F8EB7AC9} => C:\Users\Silence\Downloads\CM1312series_full_solution_v5.0_AM-EMEA.exe [2015-07-13] ()
Task: {C7142019-CDB6-4E68-9E57-5B9B64306C9B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)
Task: {C756455C-46EF-46F5-9455-AFB07B996031} - System32\Tasks\{272D9193-1746-4A6C-86A3-6D22333DB69F} => pcalua.exe -a C:\Users\Silence\AppData\Local\Temp\7zS4C17\Setup.exe -d C:\Users\Silence\AppData\Local\Temp\7zS4C17 -c /webpack
Task: {E74920EC-A2B9-4596-8F28-69065F7FF067} - System32\Tasks\FileAdvisorCheck => C:\Program Files\File Type Advisor\file-type-advisor.exe [2014-02-24] (                                                            )
Task: {EB4C1E8A-5F47-47A0-88AB-2F755153C84D} - System32\Tasks\{CC6D2EF3-E4E8-4D8C-95B2-DCA9E5FE0DBE} => D:\Setup.exe
Task: {F791A882-58C7-44C4-86B7-22D2C81E20C0} - System32\Tasks\FileAdvisorUpdate => C:\Program Files\File Type Advisor\fileadvisor.exe [2014-02-24] (File Type Advisor)
Task: {F92A09A3-39AA-4A2B-B293-D77DEB52ED8E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-03-20 17:12 - 2015-03-20 17:12 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 05:46 - 2015-10-13 05:46 - 01040144 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-09-22 03:43 - 2015-09-22 03:43 - 00323704 ____N () C:\Program Files\Common Files\G Data\AVKProxy\PktIcpt2.dll
2015-02-19 18:23 - 2015-02-19 18:23 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\1eeea3ab8d69ec722bdcb28b8eb8dd75\IsdiInterop.ni.dll
2014-02-22 10:33 - 2012-02-01 16:25 - 00059904 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-02-22 10:28 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-02-22 10:29 - 2013-09-03 20:45 - 00094208 _____ () C:\Windows\System32\IccLibDll.dll
2015-05-08 19:50 - 2015-05-08 19:50 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3906192273-1234835177-2734361635-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist deaktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)


==================== FirewallRules (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{EA2E281C-4BCE-4391-ABCB-983DA77213F4}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{F9109597-0FF1-40D9-A5D9-13C6FBA49A13}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1FB5AD86-EA5C-4A35-BE2D-301F8B6FF128}] => (Allow) LPort=2869
FirewallRules: [{D4C2D57B-718E-4197-B945-1832A21EE785}] => (Allow) LPort=1900
FirewallRules: [{BE49F75D-2CBC-4910-A8A6-9B8D70168241}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B93F12A6-8A87-4056-BCC6-00A9393A76B3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{46829076-B717-4D16-96A4-F7302D08CBFF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6C256535-36C7-4068-B025-DC1A1ED5863C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{FB0E5E66-AAE8-4007-B0B7-3F581EE2D86B}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe
FirewallRules: [{FBF23556-0A40-4E38-A016-65E21460491D}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe
FirewallRules: [{AC0EB7C3-A11C-4960-B3A2-CA929F038305}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7C883B1A-A932-4D8B-BADB-ECBAF43501B0}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{51766988-50F7-4D55-9D6D-A43919E80601}] => (Allow) C:\Program Files\HP\HP Color LaserJet Pro MFP M277\bin\SendAFax.exe
FirewallRules: [{60398A49-8E8C-4CC1-9979-6E7D588E33DB}] => (Allow) C:\Program Files\HP\HP Color LaserJet Pro MFP M277\bin\FaxPrinterUtility.exe
FirewallRules: [{B7E3559C-3BCC-4FB5-9CCA-E93D3CC890EF}] => (Allow) C:\Program Files\HP\HP Color LaserJet Pro MFP M277\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{4CD40002-B255-4060-8F21-E12AE88F9B9E}] => (Allow) C:\Program Files\HP\HP Color LaserJet Pro MFP M277\bin\DigitalWizards.exe
FirewallRules: [{FD976641-A767-4BFC-A923-6177B31A0407}] => (Allow) C:\Program Files\HP\HP Color LaserJet Pro MFP M277\bin\FaxApplications.exe
FirewallRules: [{526C7B1B-5B82-47F9-836C-8068E5DE6132}] => (Allow) C:\Program Files\HP\HP Color LaserJet Pro MFP M277\bin\EWSProxy.exe
FirewallRules: [{F485B379-D5DE-49F9-B488-BCBA5E35127B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2A235BAF-1CCE-47AE-B7D7-8B0D84131E95}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5E980995-748D-4544-8A66-7F8655E06032}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{F4AF9647-920C-4C86-A966-62BEDDBDF9FE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6D5E4755-C86C-4329-87E7-F133E529525F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/10/2015 03:29:09 PM) (Source: YSearchUtilSvc) (EventID: 0) (User: )
Description: YSearchUtilSvc error: Der Vorgang wurde erfolgreich beendet. (0x0)Could not stop service (1061)

Error: (11/09/2015 05:59:51 PM) (Source: YSearchUtilSvc) (EventID: 0) (User: )
Description: YSearchUtilSvc error: Der Vorgang wurde erfolgreich beendet. (0x0)Could not stop service (1061)

Error: (11/09/2015 05:26:39 PM) (Source: YSearchUtilSvc) (EventID: 0) (User: )
Description: YSearchUtilSvc error: Der Vorgang wurde erfolgreich beendet. (0x0)Could not stop service (1061)

Error: (11/07/2015 10:33:45 AM) (Source: YSearchUtilSvc) (EventID: 0) (User: )
Description: YSearchUtilSvc error: Der Vorgang wurde erfolgreich beendet. (0x0)Could not stop service (1061)

Error: (11/06/2015 06:33:38 AM) (Source: MsiInstaller) (EventID: 1024) (User: Silence-PC)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F094E6D00}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (11/05/2015 10:37:20 AM) (Source: YSearchUtilSvc) (EventID: 0) (User: )
Description: YSearchUtilSvc error: Der Vorgang wurde erfolgreich beendet. (0x0)Could not stop service (1061)

Error: (11/02/2015 09:30:44 AM) (Source: YSearchUtilSvc) (EventID: 0) (User: )
Description: YSearchUtilSvc error: Der Vorgang wurde erfolgreich beendet. (0x0)Could not stop service (1061)

Error: (10/26/2015 06:03:36 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Der Index kann nicht initialisiert werden.

Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (10/26/2015 06:03:36 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung

Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (10/26/2015 06:03:36 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)


Systemfehler:
=============
Error: (11/13/2015 02:43:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/13/2015 06:18:22 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/12/2015 04:41:20 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/12/2015 05:35:17 AM) (Source: Microsoft-Windows-Application-Experience) (EventID: 205) (User: NT-AUTORITÄT)
Description: Der Dienst "Programmkompatibilitäts-Assistent" konnte Phase 2 nicht initialisieren.

Error: (11/12/2015 05:35:00 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/11/2015 07:09:53 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/11/2015 03:18:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/11/2015 05:47:07 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/10/2015 03:30:04 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.

Error: (11/10/2015 06:37:42 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet.


==================== Memory info =========================== 

Processor: Intel(R) Celeron(R) CPU 1037U @ 1.80GHz
Prozentuale Nutzung des RAM: 41%
Installierter physikalischer RAM: 3485.57 MB
Verfügbarer physikalischer RAM: 2033.68 MB
Summe virtueller Speicher: 6969.45 MB
Verfügbarer virtueller Speicher: 4894.3 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:879.54 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1B161442)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== Ende vom Addition.txt ============================
         
Ich hoffe, die sagen Dir etwas.

Gruß

Wolfgang
__________________

Alt 13.11.2015, 17:56   #4
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Hallo Wolfgang,
untersuchen wir mal den PC.

Schritt 1
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
__________________
Gruß
deeprybka

Lob, Kritik, Wünsche?

Spende fürs trojaner-board?
_______________________________________________
„Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer

Alt 13.11.2015, 20:16   #5
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Hallo Jürgen,

ok, werde ich machen. Es geht allerdings erst morgen Nachmittag weiter. Hab jetzt keinen Zugang mehr zu dem Rechner.

Hatte ich Recht mit meiner Vermutung über die Arbeitsweise des Virus? Dass ein Spion an Bord ist, der die jeweilig aktuellen Zugangsdaten ausliest und sie an einen Client weiterleitet, der dann die Mails irgendwann verschickt?

Ist übrigens gestern wieder passiert. Ähnliche Mails, diesmal mit ner anderen Adresse, die wieder auf ein dubioses php-Script verweisen.

Wolfgang


Alt 13.11.2015, 20:48   #6
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Ich spekuliere nur mit Aktien.
Wenn alle entsprechenden Diagnose-Logs vorliegen, kann man vermutlich mehr sagen.

Zitat:
Das Versenden der Mails geschah einmal zu einem Zeitpunkt, wo der Rechner bestimmt nicht an war, also nehm ich an, dass diese Versende-Software nicht auf dem Rechner liegt. Aber: Mein Nachbar hat sich nun schon 2 mal von der Telekom neue Konto-Zugangsdaten geben lassen, und trotzdem gabs nach 2 Wochen erneut eine solche E-Mail-Welle.
Wenn man einmal die Kontakt-Adressen hat, dann kann man problemlos unter jedem Absender-Namen Emails versenden.
__________________
--> Schadsoftware versendet E-Mails

Alt 14.11.2015, 13:37   #7
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Soll das heißen, dass - auch wenn wir den Rechner hier erfolgreich entwanzen - der Spuk trotzdem noch weitergehen kann? Ich dachte Mails mit einem bestimmten Absender können nur über ebendieses Konto verschickt werden.

So, und hier ist das Log vom TDSSKiller - der keine Bedrohung gefunden hat. Sagt er.

Code:
ATTFilter
13:32:03.0937 0x1530  TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57
13:32:14.0459 0x1530  ============================================================
13:32:14.0459 0x1530  Current date / time: 2015/11/14 13:32:14.0459
13:32:14.0459 0x1530  SystemInfo:
13:32:14.0459 0x1530  
13:32:14.0459 0x1530  OS Version: 6.1.7601 ServicePack: 1.0
13:32:14.0459 0x1530  Product type: Workstation
13:32:14.0460 0x1530  ComputerName: SILENCE-PC
13:32:14.0460 0x1530  UserName: Silence
13:32:14.0460 0x1530  Windows directory: C:\Windows
13:32:14.0460 0x1530  System windows directory: C:\Windows
13:32:14.0460 0x1530  Processor architecture: Intel x86
13:32:14.0460 0x1530  Number of processors: 2
13:32:14.0460 0x1530  Page size: 0x1000
13:32:14.0460 0x1530  Boot type: Normal boot
13:32:14.0461 0x1530  ============================================================
13:32:16.0798 0x1530  KLMD registered as C:\Windows\system32\drivers\73030119.sys
13:32:17.0535 0x1530  System UUID: {57202954-29A7-1650-8D37-1C3181B11FB3}
13:32:18.0292 0x1530  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:32:18.0297 0x1530  ============================================================
13:32:18.0297 0x1530  \Device\Harddisk0\DR0:
13:32:18.0297 0x1530  MBR partitions:
13:32:18.0297 0x1530  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:32:18.0297 0x1530  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D4000
13:32:18.0297 0x1530  ============================================================
13:32:18.0312 0x1530  C: <-> \Device\Harddisk0\DR0\Partition2
13:32:18.0313 0x1530  ============================================================
13:32:18.0313 0x1530  Initialize success
13:32:18.0313 0x1530  ============================================================
13:33:00.0220 0x1514  ============================================================
13:33:00.0220 0x1514  Scan started
13:33:00.0220 0x1514  Mode: Manual; 
13:33:00.0220 0x1514  ============================================================
13:33:00.0220 0x1514  KSN ping started
13:33:03.0370 0x1514  KSN ping finished: true
13:33:05.0424 0x1514  ================ Scan system memory ========================
13:33:05.0424 0x1514  System memory - ok
13:33:05.0425 0x1514  ================ Scan services =============================
13:33:05.0563 0x1514  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
13:33:05.0577 0x1514  1394ohci - ok
13:33:05.0629 0x1514  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
13:33:05.0638 0x1514  ACPI - ok
13:33:05.0662 0x1514  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
13:33:05.0664 0x1514  AcpiPmi - ok
13:33:05.0741 0x1514  [ 5DB2C6B908C50767E2EDAA294A7566B5, 13AE4879D679BB0C6B2A5A5B13910359815A9D2E569BC1DE740B5A387A78CF33 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
13:33:05.0747 0x1514  AdobeARMservice - ok
13:33:05.0794 0x1514  [ 280A526E8111AC6A5BCC1A059E1E0340, FB92DDAE29A097D148AB23D8A0BD2B9E662EC1DBF0DA8B716374D6919B4C646F ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:33:05.0803 0x1514  AdobeFlashPlayerUpdateSvc - ok
13:33:05.0847 0x1514  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
13:33:05.0864 0x1514  adp94xx - ok
13:33:05.0887 0x1514  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci         C:\Windows\system32\drivers\adpahci.sys
13:33:05.0897 0x1514  adpahci - ok
13:33:05.0923 0x1514  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320         C:\Windows\system32\drivers\adpu320.sys
13:33:05.0929 0x1514  adpu320 - ok
13:33:05.0962 0x1514  [ 39AEAECE9F42407F176FE130D790BFBE, 19010DF87BDC1884268098CC04B4B15ECB710C94054A57157C0F9B7A795BDB28 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
13:33:05.0964 0x1514  AeLookupSvc - ok
13:33:06.0004 0x1514  [ 93B49FA857F7036A4EFF32371F6E7391, B9B2867D9A80E7F028E9D7C6ABCB9EC5198ACE28CEE101C5A846666B356B2843 ] AFD             C:\Windows\system32\drivers\afd.sys
13:33:06.0043 0x1514  AFD - ok
13:33:06.0087 0x1514  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
13:33:06.0094 0x1514  agp440 - ok
13:33:06.0137 0x1514  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx         C:\Windows\system32\drivers\djsvs.sys
13:33:06.0146 0x1514  aic78xx - ok
13:33:06.0183 0x1514  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG             C:\Windows\System32\alg.exe
13:33:06.0189 0x1514  ALG - ok
13:33:06.0222 0x1514  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
13:33:06.0228 0x1514  aliide - ok
13:33:06.0279 0x1514  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
13:33:06.0286 0x1514  amdagp - ok
13:33:06.0308 0x1514  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
13:33:06.0315 0x1514  amdide - ok
13:33:06.0365 0x1514  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
13:33:06.0372 0x1514  AmdK8 - ok
13:33:06.0421 0x1514  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
13:33:06.0428 0x1514  AmdPPM - ok
13:33:06.0469 0x1514  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
13:33:06.0478 0x1514  amdsata - ok
13:33:06.0538 0x1514  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
13:33:06.0551 0x1514  amdsbs - ok
13:33:06.0582 0x1514  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
13:33:06.0585 0x1514  amdxata - ok
13:33:06.0619 0x1514  [ FE4F2ADE5DBB3B888E9EB0A1FBA1F152, B17053A912C73835A2E80176D79885B530E15240B988125114B6B877C903D61C ] AppID           C:\Windows\system32\drivers\appid.sys
13:33:06.0623 0x1514  AppID - ok
13:33:06.0650 0x1514  [ A4DA304773AC1396792C5DE1D1EB601A, ECD23FF67FB1C4B94DBE23F6724E2DA0917CE0E479DE9C9F790A8635A2234950 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
13:33:06.0652 0x1514  AppIDSvc - ok
13:33:06.0680 0x1514  [ 133A7896E643D139443B47FDBFA327C7, 371FC602B531DF1EFDCEEC3A2F5497A0D0BE7F558B0583F572862C69A65BD454 ] Appinfo         C:\Windows\System32\appinfo.dll
13:33:06.0682 0x1514  Appinfo - ok
13:33:06.0737 0x1514  [ BB6093AD659360CB350F4E84B445F36D, 16E16AD8E58C3777E2C858C8223BEB3CC9999E6FDCD23A0013C39AAADC54193C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:33:06.0740 0x1514  Apple Mobile Device - ok
13:33:06.0775 0x1514  [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt         C:\Windows\System32\appmgmts.dll
13:33:06.0781 0x1514  AppMgmt - ok
13:33:06.0804 0x1514  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc             C:\Windows\system32\drivers\arc.sys
13:33:06.0809 0x1514  arc - ok
13:33:06.0823 0x1514  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\drivers\arcsas.sys
13:33:06.0828 0x1514  arcsas - ok
13:33:06.0906 0x1514  [ 8489551F063218E6693F2EAAA6CE01E4, 742D1BF2538037AD591D34C82F72A17CE49F8535F611E2D2B77A6E29409444E5 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:33:06.0912 0x1514  aspnet_state - ok
13:33:06.0936 0x1514  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
13:33:06.0938 0x1514  AsyncMac - ok
13:33:06.0980 0x1514  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi           C:\Windows\system32\drivers\atapi.sys
13:33:06.0991 0x1514  atapi - ok
13:33:07.0040 0x1514  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:33:07.0051 0x1514  AudioEndpointBuilder - ok
13:33:07.0065 0x1514  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
13:33:07.0077 0x1514  Audiosrv - ok
13:33:07.0203 0x1514  [ BC949A3706983328D8034D061E3F99B9, 2EAEE4F664B355C9E381B239F3E83EABBBC39A4FEA891D30F11B85D1057A652E ] AVKProxy        C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
13:33:07.0263 0x1514  AVKProxy - ok
13:33:07.0324 0x1514  [ 57E9F462DE5ED77574116782BA05AB0F, 611987C8205E113DFA206F50EF4959AA5D6CE252A73EC1E74C043CBFD7172E3D ] AVKService      C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
13:33:07.0351 0x1514  AVKService - ok
13:33:07.0446 0x1514  [ 26B9C28D738D91832A5F0011CB2288D0, 7EA287DA55C10D333F56CA7C73B60E2728A56D3974C8504354E0895BE03AC82C ] AVKWCtl         C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
13:33:07.0514 0x1514  AVKWCtl - ok
13:33:07.0544 0x1514  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
13:33:07.0548 0x1514  AxInstSV - ok
13:33:07.0586 0x1514  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv         C:\Windows\system32\drivers\bxvbdx.sys
13:33:07.0599 0x1514  b06bdrv - ok
13:33:07.0628 0x1514  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
13:33:07.0636 0x1514  b57nd60x - ok
13:33:07.0670 0x1514  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
13:33:07.0673 0x1514  BDESVC - ok
13:33:07.0686 0x1514  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
13:33:07.0688 0x1514  Beep - ok
13:33:07.0722 0x1514  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE             C:\Windows\System32\bfe.dll
13:33:07.0734 0x1514  BFE - ok
13:33:07.0771 0x1514  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\System32\qmgr.dll
13:33:07.0786 0x1514  BITS - ok
13:33:07.0795 0x1514  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
13:33:07.0797 0x1514  blbdrive - ok
13:33:07.0872 0x1514  [ 5EA9C80F18CBC393EA7D9A2991DED4B5, 7E5EB1CE44FEBE93686174058D51581FA00BDFF0EBB84BD74BC08F6386019253 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:33:07.0886 0x1514  Bonjour Service - ok
13:33:07.0940 0x1514  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
13:33:07.0946 0x1514  bowser - ok
13:33:07.0970 0x1514  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
13:33:07.0974 0x1514  BrFiltLo - ok
13:33:08.0004 0x1514  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
13:33:08.0006 0x1514  BrFiltUp - ok
13:33:08.0030 0x1514  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser         C:\Windows\System32\browser.dll
13:33:08.0033 0x1514  Browser - ok
13:33:08.0053 0x1514  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
13:33:08.0063 0x1514  Brserid - ok
13:33:08.0080 0x1514  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
13:33:08.0084 0x1514  BrSerWdm - ok
13:33:08.0099 0x1514  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
13:33:08.0102 0x1514  BrUsbMdm - ok
13:33:08.0107 0x1514  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
13:33:08.0110 0x1514  BrUsbSer - ok
13:33:08.0122 0x1514  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
13:33:08.0125 0x1514  BTHMODEM - ok
13:33:08.0154 0x1514  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv         C:\Windows\system32\bthserv.dll
13:33:08.0157 0x1514  bthserv - ok
13:33:08.0173 0x1514  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
13:33:08.0177 0x1514  cdfs - ok
13:33:08.0212 0x1514  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
13:33:08.0216 0x1514  cdrom - ok
13:33:08.0232 0x1514  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc     C:\Windows\System32\certprop.dll
13:33:08.0234 0x1514  CertPropSvc - ok
13:33:08.0249 0x1514  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\drivers\circlass.sys
13:33:08.0252 0x1514  circlass - ok
13:33:08.0287 0x1514  [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS            C:\Windows\system32\CLFS.sys
13:33:08.0296 0x1514  CLFS - ok
13:33:08.0349 0x1514  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:33:08.0357 0x1514  clr_optimization_v2.0.50727_32 - ok
13:33:08.0400 0x1514  [ F3C5A948079B128E70AFB38FFBD20533, 5FDD012AF3F2D59B3BB549062E140FE2AD3D2E4E89B06CDC7FACED339E0D71AA ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:33:08.0406 0x1514  clr_optimization_v4.0.30319_32 - ok
13:33:08.0459 0x1514  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
13:33:08.0464 0x1514  CmBatt - ok
13:33:08.0491 0x1514  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
13:33:08.0496 0x1514  cmdide - ok
13:33:08.0541 0x1514  [ 780FFC005741C9316576086155E55F56, D863E5657F1468410BBDD657D5EA8A2FDDB70FED459CDE3178CB8FDB910058EC ] CNG             C:\Windows\system32\Drivers\cng.sys
13:33:08.0570 0x1514  CNG - ok
13:33:08.0599 0x1514  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
13:33:08.0606 0x1514  Compbatt - ok
13:33:08.0642 0x1514  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
13:33:08.0644 0x1514  CompositeBus - ok
13:33:08.0656 0x1514  COMSysApp - ok
13:33:08.0686 0x1514  [ 2D95DFA349D8DA1C89DF7E67924B5B64, D3E6A9B285F7D22B20C59BA62DDB677079DC18E3E0152C8049AE979F9D2FE7A6 ] cphs            C:\Windows\system32\IntelCpHeciSvc.exe
13:33:08.0696 0x1514  cphs - ok
13:33:08.0756 0x1514  cpuz136 - ok
13:33:08.0769 0x1514  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
13:33:08.0772 0x1514  crcdisk - ok
13:33:08.0819 0x1514  [ 33F67BBCC3C0499D3F3382473114CFA8, FDDCC41CE005B7C1BEBB6F4ACA9A3F10E5972792ADFD7D294E70A0B781460981 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
13:33:08.0823 0x1514  CryptSvc - ok
13:33:08.0854 0x1514  [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC             C:\Windows\system32\drivers\csc.sys
13:33:08.0866 0x1514  CSC - ok
13:33:08.0891 0x1514  [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService      C:\Windows\System32\cscsvc.dll
13:33:08.0905 0x1514  CscService - ok
13:33:08.0937 0x1514  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
13:33:08.0948 0x1514  DcomLaunch - ok
13:33:08.0971 0x1514  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc       C:\Windows\System32\defragsvc.dll
13:33:08.0978 0x1514  defragsvc - ok
13:33:09.0000 0x1514  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
13:33:09.0003 0x1514  DfsC - ok
13:33:09.0024 0x1514  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
13:33:09.0031 0x1514  Dhcp - ok
13:33:09.0119 0x1514  [ 0A3386E3CF9C5D089D695AC5A35F4C6F, D610071493EB95FCE39E24C457A0B5BBA131193159E43FDC1E8EDABB9C7AB81A ] DiagTrack       C:\Windows\system32\diagtrack.dll
13:33:09.0146 0x1514  DiagTrack - ok
13:33:09.0164 0x1514  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
13:33:09.0166 0x1514  discache - ok
13:33:09.0193 0x1514  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\drivers\disk.sys
13:33:09.0196 0x1514  Disk - ok
13:33:09.0231 0x1514  [ 2A958EF85DB1B61FFCA65044FA4BCE9E, C83511685EE1CE85A5ADF9B5BE96C375A521601F66024BDC3EE044C0B6E85D69 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
13:33:09.0235 0x1514  dmvsc - ok
13:33:09.0261 0x1514  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
13:33:09.0265 0x1514  Dnscache - ok
13:33:09.0288 0x1514  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc         C:\Windows\System32\dot3svc.dll
13:33:09.0295 0x1514  dot3svc - ok
13:33:09.0311 0x1514  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS             C:\Windows\system32\dps.dll
13:33:09.0316 0x1514  DPS - ok
13:33:09.0343 0x1514  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
13:33:09.0345 0x1514  drmkaud - ok
13:33:09.0385 0x1514  [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
13:33:09.0407 0x1514  DXGKrnl - ok
13:33:09.0421 0x1514  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost         C:\Windows\System32\eapsvc.dll
13:33:09.0425 0x1514  EapHost - ok
13:33:09.0560 0x1514  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv           C:\Windows\system32\drivers\evbdx.sys
13:33:09.0643 0x1514  ebdrv - ok
13:33:09.0685 0x1514  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] EFS             C:\Windows\System32\lsass.exe
13:33:09.0690 0x1514  EFS - ok
13:33:09.0766 0x1514  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
13:33:09.0783 0x1514  ehRecvr - ok
13:33:09.0807 0x1514  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched         C:\Windows\ehome\ehsched.exe
13:33:09.0811 0x1514  ehSched - ok
13:33:09.0856 0x1514  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
13:33:09.0870 0x1514  elxstor - ok
13:33:09.0883 0x1514  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
13:33:09.0886 0x1514  ErrDev - ok
13:33:09.0945 0x1514  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem     C:\Windows\system32\es.dll
13:33:09.0952 0x1514  EventSystem - ok
13:33:09.0970 0x1514  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat           C:\Windows\system32\drivers\exfat.sys
13:33:09.0976 0x1514  exfat - ok
13:33:09.0993 0x1514  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
13:33:10.0000 0x1514  fastfat - ok
13:33:10.0029 0x1514  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax             C:\Windows\system32\fxssvc.exe
13:33:10.0042 0x1514  Fax - ok
13:33:10.0061 0x1514  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc             C:\Windows\system32\drivers\fdc.sys
13:33:10.0064 0x1514  fdc - ok
13:33:10.0087 0x1514  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost         C:\Windows\system32\fdPHost.dll
13:33:10.0088 0x1514  fdPHost - ok
13:33:10.0096 0x1514  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
13:33:10.0097 0x1514  FDResPub - ok
13:33:10.0104 0x1514  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
13:33:10.0107 0x1514  FileInfo - ok
13:33:10.0122 0x1514  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
13:33:10.0125 0x1514  Filetrace - ok
13:33:10.0137 0x1514  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
13:33:10.0140 0x1514  flpydisk - ok
13:33:10.0161 0x1514  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
13:33:10.0167 0x1514  FltMgr - ok
13:33:10.0222 0x1514  [ 37DE123FE4276D8EC7F3C5B10C236238, 93CA47B9A96D904DD177FC0E04DECDF13756C8FA3C7613913DB4BF29A70ECE96 ] FontCache       C:\Windows\system32\FntCache.dll
13:33:10.0244 0x1514  FontCache - ok
13:33:10.0296 0x1514  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:33:10.0300 0x1514  FontCache3.0.0.0 - ok
13:33:10.0321 0x1514  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
13:33:10.0325 0x1514  FsDepends - ok
13:33:10.0348 0x1514  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
13:33:10.0351 0x1514  Fs_Rec - ok
13:33:10.0371 0x1514  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
13:33:10.0379 0x1514  fvevol - ok
13:33:10.0404 0x1514  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
13:33:10.0409 0x1514  gagp30kx - ok
13:33:10.0448 0x1514  [ 8145A7A9D571B129689CFDAB425CA575, E83778E68C9C45D6ED288838F3D81531B5BC878130CE877E3F4DDA1B223E4D8B ] GDBehave        C:\Windows\system32\drivers\GDBehave.sys
13:33:10.0452 0x1514  GDBehave - ok
13:33:10.0568 0x1514  [ 83FBEF575A31D7CE6D7823E415D3791D, D60FAD209C019CC918D840C650DCE98FB313365336ADB0F124CE811E5A61B822 ] GDFwSvc         C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
13:33:10.0626 0x1514  GDFwSvc - ok
13:33:10.0695 0x1514  [ 70D3B79D77D9DD0AE404330AB4BED823, F2AC2185759612A5F9907193DF2E7046D945688DBE1DA42FBD16CE4E8B7DE539 ] GDKBB           C:\Windows\system32\drivers\GDKBB32.sys
13:33:10.0698 0x1514  GDKBB - ok
13:33:10.0718 0x1514  [ 1C38F4732FEAA90F50185696900FC3D0, 60F74372C4971AD81CE083D6A340E7ADBA5D55697D8B2F9ACCB02B9ED291CFCB ] GDKBFlt         C:\Windows\system32\drivers\GDKBFlt32.sys
13:33:10.0721 0x1514  GDKBFlt - ok
13:33:10.0733 0x1514  [ 05DC9DDD93A2050B1407CEB36AE717A7, 16650CB56B5393D56423C778C580CA24D45428CF2B178F8D4B380FC10D4814FE ] GDMnIcpt        C:\Windows\system32\drivers\MiniIcpt.sys
13:33:10.0738 0x1514  GDMnIcpt - ok
13:33:10.0765 0x1514  [ 735E1EBE420F12C1012045968CEDCBF7, 7667E5C9F3E3C5CD944708900C86E0749A7F0AB6A6877F3807430863126C82D3 ] GDPkIcpt        C:\Windows\system32\drivers\PktIcpt.sys
13:33:10.0769 0x1514  GDPkIcpt - ok
13:33:10.0787 0x1514  gdrv - ok
13:33:10.0828 0x1514  [ E9B7AF2C5C7B9AD739718AA7ED5F1911, 52C1B75B97DBCF343A6A7045E1F42C8BB35FF23CC2B463EA1B858FCD5B85678F ] GDScan          C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
13:33:10.0851 0x1514  GDScan - ok
13:33:10.0862 0x1514  [ F908F4A3EA6EC721264D20FEDAD1FFD2, E8888A5BAF33653DDE9F2937E29DD0DE028B78B554FDBAC076604B9DD615BD8B ] gdwfpcd         C:\Windows\system32\drivers\gdwfpcd32.sys
13:33:10.0865 0x1514  gdwfpcd - ok
13:33:10.0905 0x1514  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:33:10.0908 0x1514  GEARAspiWDM - ok
13:33:10.0939 0x1514  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc           C:\Windows\System32\gpsvc.dll
13:33:10.0955 0x1514  gpsvc - ok
13:33:10.0990 0x1514  [ DE640BC12C11DE49CE3392161AD4E64D, CD291205D8997DABD7154A5170B1D1A15E2B243270AD018F01864090DFFFBE24 ] GRD             C:\Windows\system32\drivers\GRD.sys
13:33:10.0993 0x1514  GRD - ok
13:33:11.0015 0x1514  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
13:33:11.0017 0x1514  hcw85cir - ok
13:33:11.0057 0x1514  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:33:11.0067 0x1514  HdAudAddService - ok
13:33:11.0084 0x1514  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
13:33:11.0089 0x1514  HDAudBus - ok
13:33:11.0103 0x1514  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
13:33:11.0106 0x1514  HidBatt - ok
13:33:11.0118 0x1514  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\drivers\hidbth.sys
13:33:11.0122 0x1514  HidBth - ok
13:33:11.0140 0x1514  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr           C:\Windows\system32\drivers\hidir.sys
13:33:11.0143 0x1514  HidIr - ok
13:33:11.0160 0x1514  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv         C:\Windows\system32\hidserv.dll
13:33:11.0162 0x1514  hidserv - ok
13:33:11.0191 0x1514  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
13:33:11.0193 0x1514  HidUsb - ok
13:33:11.0204 0x1514  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
13:33:11.0207 0x1514  hkmsvc - ok
13:33:11.0221 0x1514  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:33:11.0228 0x1514  HomeGroupListener - ok
13:33:11.0253 0x1514  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:33:11.0259 0x1514  HomeGroupProvider - ok
13:33:11.0273 0x1514  [ A39F5EFD8D65DA4E67C5EB14CAE60F15, 10558A3AB55BF431E1146C062C12EE5C71EB063A195CD4284412824350C867B2 ] HookCentre      C:\Windows\system32\drivers\HookCentre.sys
13:33:11.0277 0x1514  HookCentre - ok
13:33:11.0342 0x1514  [ CE1DD06F2A2AFD6D5DACAA6D58FD25C0, 4A3BA099323953BBAE06313FDB5A3C6855B009537FA491FFCA8779ACD6ED5E65 ] HP LaserJet Service C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
13:33:11.0355 0x1514  HP LaserJet Service - ok
13:33:11.0372 0x1514  [ 299683D4C8AAA3F6F5D5D226A1782A6E, A2ECF52DBDC442F3C9514EC80CE614A9D3F45698E5B0992CF009C66B770E9027 ] HPEWSFXBULK     C:\Windows\system32\drivers\hpfxbulk.sys
13:33:11.0376 0x1514  HPEWSFXBULK - ok
13:33:11.0402 0x1514  [ 299683D4C8AAA3F6F5D5D226A1782A6E, A2ECF52DBDC442F3C9514EC80CE614A9D3F45698E5B0992CF009C66B770E9027 ] HPFXBULK        C:\Windows\system32\drivers\hpfxbulk.sys
13:33:11.0403 0x1514  HPFXBULK - ok
13:33:11.0422 0x1514  [ F728DB73A87231E27B6BA34D71CE2EDB, 0C3BDF6017BF494990CD121A7948090639AE2371C0E070B079386DCD4B99FA16 ] HPFXFAX         C:\Windows\system32\drivers\hpfxfax.sys
13:33:11.0427 0x1514  HPFXFAX - ok
13:33:11.0513 0x1514  [ F50F7984FDD151EDD8A70A8DBD9E2A44, 45E7ECA40298B233D124993D6C9D4FBBF05E9A843F4DE089317342B3D8A83696 ] hpqcxs08        C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
13:33:11.0525 0x1514  hpqcxs08 - ok
13:33:11.0544 0x1514  [ DF446BA625CC441617843E87798CE048, B45C11EEA7EA792DE82E9BB283B9DCF30F891AAB8366075856BD84D10BCBCCD3 ] hpqddsvc        C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
13:33:11.0548 0x1514  hpqddsvc - ok
13:33:11.0577 0x1514  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
13:33:11.0582 0x1514  HpSAMD - ok
13:33:11.0620 0x1514  [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP            C:\Windows\system32\drivers\HTTP.sys
13:33:11.0637 0x1514  HTTP - ok
13:33:11.0647 0x1514  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
13:33:11.0649 0x1514  hwpolicy - ok
13:33:11.0674 0x1514  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
13:33:11.0678 0x1514  i8042prt - ok
13:33:11.0733 0x1514  [ 76C3966183BD5382E14CEB6DF97D9709, 52A2676FED3A73182D7BA3AC4EA954BC2DC8879CE71DB973E37720B2F0A7392A ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
13:33:11.0744 0x1514  iaStor - ok
13:33:11.0785 0x1514  [ 95E0895DC40A6DAA8D0A92D12993DE79, D35AAD7674D450D4D09161435C52E5C2B5B2BCF28F3DC9E7BCBD4437A57B2C48 ] iaStorA         C:\Windows\system32\drivers\iaStorA.sys
13:33:11.0800 0x1514  iaStorA - ok
13:33:11.0878 0x1514  [ 545462D0DBE24AF379BA869B7C185CCD, 056F9D0D5FD4FEF37665A35A4029722FF60D02A69854E952DC361CC0E5CD26F9 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
13:33:11.0880 0x1514  IAStorDataMgrSvc - ok
13:33:11.0902 0x1514  [ C10DFBB841657DE0032B0CA29AC2A041, 90390E709FE6B35F07D0C915E17C758A4EFB7AFF96D8B3370AA35F534FAB109B ] iaStorF         C:\Windows\system32\drivers\iaStorF.sys
13:33:11.0916 0x1514  iaStorF - ok
13:33:11.0962 0x1514  [ 64EC5FC35D38F1EE71650E8384ECCA44, 3E0573D06448737D3024DDC3DA892014D9C4D5CDFFC7F2B520EC76992051FA78 ] iaStorS         C:\Windows\system32\drivers\iaStorS.sys
13:33:11.0979 0x1514  iaStorS - ok
13:33:12.0003 0x1514  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
13:33:12.0014 0x1514  iaStorV - ok
13:33:12.0068 0x1514  [ 83FF82FE209E7997067B375DAD6CF23D, E312DD068E51DBF96A8232D7D1C9F158652FDA23649655F1102928B320795091 ] ICCS            C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
13:33:12.0078 0x1514  ICCS - ok
13:33:12.0141 0x1514  [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:33:12.0167 0x1514  idsvc - ok
13:33:12.0171 0x1514  IEEtwCollectorService - ok
13:33:12.0295 0x1514  [ 543E9429115BC70BD796E412EC8BB82E, 89EB80A7901EC906CC2D8E57501E6652339C7C7EB03761BF277E84752AB9CC7D ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
13:33:12.0384 0x1514  igfx - ok
13:33:12.0429 0x1514  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp           C:\Windows\system32\drivers\iirsp.sys
13:33:12.0432 0x1514  iirsp - ok
13:33:12.0469 0x1514  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
13:33:12.0487 0x1514  IKEEXT - ok
13:33:12.0651 0x1514  [ DAA00AE67B4F8B083442BEAB684A387B, 8770DE3B80F8F192E333311A90BB0AD8E2CA0959B2CF363589C54E15F3D37569 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:33:12.0743 0x1514  IntcAzAudAddService - ok
13:33:12.0778 0x1514  [ 5C65EC99D43E7F2BAD08F96FE2771E89, 750A8B9C304F45B3FE6D5156B734AAFD7FD5C1D85F53D8205EC36E49C437874E ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
13:33:12.0789 0x1514  IntcDAud - ok
13:33:12.0818 0x1514  [ 5BD12A81869923C8A690A315363D17A2, 81B41ED432A02D3C013FD2103FA78B56BB953E2442FE54B830F08EDBFA174870 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
13:33:12.0836 0x1514  Intel(R) Capability Licensing Service Interface - ok
13:33:12.0866 0x1514  [ 4D6A4F5A96881D15A016C7D930FB97F1, 080633E6ECD4CD244ECDC36C2009E7B454B7454C968BBB3A2CE68DF0A6B04283 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
13:33:12.0885 0x1514  Intel(R) Capability Licensing Service TCP IP Interface - ok
13:33:12.0893 0x1514  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
13:33:12.0896 0x1514  intelide - ok
13:33:12.0910 0x1514  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
13:33:12.0913 0x1514  intelppm - ok
13:33:12.0939 0x1514  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
13:33:12.0943 0x1514  IPBusEnum - ok
13:33:12.0967 0x1514  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:33:12.0971 0x1514  IpFilterDriver - ok
13:33:13.0017 0x1514  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
13:33:13.0031 0x1514  iphlpsvc - ok
13:33:13.0047 0x1514  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
13:33:13.0051 0x1514  IPMIDRV - ok
13:33:13.0069 0x1514  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
13:33:13.0073 0x1514  IPNAT - ok
13:33:13.0114 0x1514  [ 3EBDA8B348A231CF1E98D4BCA31731D7, E7D8A87DEFD9531421671F5A8CCB9C52CC33CCB235C88788B4566284F506A6D7 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
13:33:13.0127 0x1514  iPod Service - ok
13:33:13.0143 0x1514  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
13:33:13.0146 0x1514  IRENUM - ok
13:33:13.0168 0x1514  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
13:33:13.0171 0x1514  isapnp - ok
13:33:13.0198 0x1514  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
13:33:13.0206 0x1514  iScsiPrt - ok
13:33:13.0260 0x1514  [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service     C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
13:33:13.0269 0x1514  jhi_service - ok
13:33:13.0296 0x1514  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
13:33:13.0300 0x1514  kbdclass - ok
13:33:13.0332 0x1514  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
13:33:13.0335 0x1514  kbdhid - ok
13:33:13.0360 0x1514  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] KeyIso          C:\Windows\system32\lsass.exe
13:33:13.0363 0x1514  KeyIso - ok
13:33:13.0399 0x1514  [ A061E519ACDE34843DFA3F1C7358DAA2, 457417DF5BDC267EA4649A2E65D72FC8308899C1E4F0D26113D31F42767E618E ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
13:33:13.0436 0x1514  KSecDD - ok
13:33:13.0454 0x1514  [ 523091605C05F5DE880426A2FBA0F87C, 96884B50032B70F455D519934671940ED2493CA62CAACF68E89CCC2E5B0D3F01 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
13:33:13.0475 0x1514  KSecPkg - ok
13:33:13.0502 0x1514  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm           C:\Windows\system32\msdtckrm.dll
13:33:13.0513 0x1514  KtmRm - ok
13:33:13.0536 0x1514  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\system32\srvsvc.dll
13:33:13.0543 0x1514  LanmanServer - ok
13:33:13.0562 0x1514  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:33:13.0566 0x1514  LanmanWorkstation - ok
13:33:13.0601 0x1514  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
13:33:13.0604 0x1514  lltdio - ok
13:33:13.0619 0x1514  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
13:33:13.0626 0x1514  lltdsvc - ok
13:33:13.0643 0x1514  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts         C:\Windows\System32\lmhsvc.dll
13:33:13.0645 0x1514  lmhosts - ok
13:33:13.0694 0x1514  [ 6A35B295812CE7064CFBCD9F254169CF, 561DD131FED6F90686D8C031B45B87B6D065C7E0C8804AEFCDE239725AAEE43E ] LMS             C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
13:33:13.0703 0x1514  LMS - ok
13:33:13.0732 0x1514  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
13:33:13.0737 0x1514  LSI_FC - ok
13:33:13.0750 0x1514  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
13:33:13.0754 0x1514  LSI_SAS - ok
13:33:13.0764 0x1514  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
13:33:13.0767 0x1514  LSI_SAS2 - ok
13:33:13.0776 0x1514  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
13:33:13.0781 0x1514  LSI_SCSI - ok
13:33:13.0799 0x1514  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv           C:\Windows\system32\drivers\luafv.sys
13:33:13.0803 0x1514  luafv - ok
13:33:13.0850 0x1514  [ B4CD87E78A01562E3DA67FE1C2779204, 536AC01C53A18E7B43F02F345FC3088C189A2D01F5E060714C0534FE7ECA2356 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
13:33:13.0852 0x1514  MBAMProtector - ok
13:33:13.0951 0x1514  [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService     C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe
13:33:13.0977 0x1514  MBAMService - ok
13:33:14.0022 0x1514  [ 490F0F3ED8A970E2BAA38F719242B8F7, 03F902365372639424AB654AEBF6EB2B6B73363275435ADC2D086EAA7112AC3D ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
13:33:14.0025 0x1514  MBAMWebAccessControl - ok
13:33:14.0054 0x1514  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
13:33:14.0058 0x1514  Mcx2Svc - ok
13:33:14.0081 0x1514  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas         C:\Windows\system32\drivers\megasas.sys
13:33:14.0084 0x1514  megasas - ok
13:33:14.0111 0x1514  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
13:33:14.0120 0x1514  MegaSR - ok
13:33:14.0155 0x1514  [ 97AEFCC50287E647876CF19F5F9A367F, 316EC1A1E9C56F56292413C2BCA647FC2F0D88694F7423BFEA703DE0BB54F3ED ] MEI             C:\Windows\system32\DRIVERS\TeeDriver.sys
13:33:14.0160 0x1514  MEI - ok
13:33:14.0184 0x1514  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS           C:\Windows\system32\mmcss.dll
13:33:14.0187 0x1514  MMCSS - ok
13:33:14.0214 0x1514  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem           C:\Windows\system32\drivers\modem.sys
13:33:14.0222 0x1514  Modem - ok
13:33:14.0306 0x1514  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
13:33:14.0310 0x1514  monitor - ok
13:33:14.0367 0x1514  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
13:33:14.0374 0x1514  mouclass - ok
13:33:14.0401 0x1514  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
13:33:14.0403 0x1514  mouhid - ok
13:33:14.0452 0x1514  [ BAD9C0366134BA181514E9263C8CE606, 7976B2D3DC283ACDBC21C7D197C0E2A650E6555F6569283302766B17D736BDB8 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
13:33:14.0460 0x1514  mountmgr - ok
13:33:14.0595 0x1514  [ 0DE2474F316C515482ABAD3B697F8714, 62862AE7432F5350068E96AD466093359C6CF444EB517AE6D09134FAF78C49F5 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:33:14.0603 0x1514  MozillaMaintenance - ok
13:33:14.0641 0x1514  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
13:33:14.0652 0x1514  mpio - ok
13:33:14.0674 0x1514  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
13:33:14.0677 0x1514  mpsdrv - ok
13:33:14.0716 0x1514  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
13:33:14.0732 0x1514  MpsSvc - ok
13:33:14.0782 0x1514  [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
13:33:14.0798 0x1514  MRxDAV - ok
13:33:14.0889 0x1514  [ C7492026F6691A92C4508DDDB041CE4E, 98B05C6B7EE5FE4F4BFCFDB807612897E692B4C07524506EB84B318535076ADD ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
13:33:14.0942 0x1514  mrxsmb - ok
13:33:14.0982 0x1514  [ 34779EBCFEAB87A236B33C365A637144, B2091C423A4767CC0616B4385FF3B8AC2CBDBCC9BF82F2C79670CC1BC1E49A02 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:33:15.0010 0x1514  mrxsmb10 - ok
13:33:15.0040 0x1514  [ C34DE43FDAD9C32383BB4A5EE60126D4, 5F82D803ABB2817D9384D87435849A5EEE946B1C431348F26FA0220262DB1798 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:33:15.0059 0x1514  mrxsmb20 - ok
13:33:15.0089 0x1514  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
13:33:15.0092 0x1514  msahci - ok
13:33:15.0109 0x1514  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
13:33:15.0115 0x1514  msdsm - ok
13:33:15.0154 0x1514  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC           C:\Windows\System32\msdtc.exe
13:33:15.0161 0x1514  MSDTC - ok
13:33:15.0190 0x1514  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
13:33:15.0192 0x1514  Msfs - ok
13:33:15.0203 0x1514  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
13:33:15.0206 0x1514  mshidkmdf - ok
13:33:15.0221 0x1514  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
13:33:15.0224 0x1514  msisadrv - ok
13:33:15.0254 0x1514  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
13:33:15.0259 0x1514  MSiSCSI - ok
13:33:15.0263 0x1514  msiserver - ok
13:33:15.0289 0x1514  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
13:33:15.0292 0x1514  MSKSSRV - ok
13:33:15.0315 0x1514  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
13:33:15.0317 0x1514  MSPCLOCK - ok
13:33:15.0321 0x1514  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
13:33:15.0323 0x1514  MSPQM - ok
13:33:15.0350 0x1514  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
13:33:15.0356 0x1514  MsRPC - ok
13:33:15.0376 0x1514  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
13:33:15.0378 0x1514  mssmbios - ok
13:33:15.0410 0x1514  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
13:33:15.0413 0x1514  MSTEE - ok
13:33:15.0459 0x1514  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
13:33:15.0464 0x1514  MTConfig - ok
13:33:15.0496 0x1514  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup             C:\Windows\system32\Drivers\mup.sys
13:33:15.0502 0x1514  Mup - ok
13:33:15.0555 0x1514  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
13:33:15.0576 0x1514  napagent - ok
13:33:15.0622 0x1514  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
13:33:15.0631 0x1514  NativeWifiP - ok
13:33:15.0720 0x1514  [ 9804FB2E46077F2977552347DFCA7E05, A34B703462C6998AB2B3EA6389F4B89616CDC257D44C400C92663E6FB4A8F196 ] NDIS            C:\Windows\system32\drivers\ndis.sys
13:33:15.0744 0x1514  NDIS - ok
13:33:15.0781 0x1514  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
13:33:15.0784 0x1514  NdisCap - ok
13:33:15.0799 0x1514  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
13:33:15.0802 0x1514  NdisTapi - ok
13:33:15.0825 0x1514  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
13:33:15.0829 0x1514  Ndisuio - ok
13:33:15.0841 0x1514  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
13:33:15.0846 0x1514  NdisWan - ok
13:33:15.0863 0x1514  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
13:33:15.0865 0x1514  NDProxy - ok
13:33:15.0901 0x1514  [ 69C503C004F49AEE8B8E3067CC047BA7, 0E7A2FB0CC7669E6400EDA4D2220BBB1A85CF3D3529739DA5AE2C073FFA08313 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
13:33:15.0904 0x1514  Net Driver HPZ12 - ok
13:33:15.0924 0x1514  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
13:33:15.0927 0x1514  NetBIOS - ok
13:33:15.0971 0x1514  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
13:33:15.0978 0x1514  NetBT - ok
13:33:16.0002 0x1514  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] Netlogon        C:\Windows\system32\lsass.exe
13:33:16.0004 0x1514  Netlogon - ok
13:33:16.0064 0x1514  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
13:33:16.0078 0x1514  Netman - ok
13:33:16.0123 0x1514  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:33:16.0131 0x1514  NetMsmqActivator - ok
13:33:16.0138 0x1514  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:33:16.0143 0x1514  NetPipeActivator - ok
13:33:16.0171 0x1514  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
13:33:16.0184 0x1514  netprofm - ok
13:33:16.0191 0x1514  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:33:16.0195 0x1514  NetTcpActivator - ok
13:33:16.0201 0x1514  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:33:16.0205 0x1514  NetTcpPortSharing - ok
13:33:16.0244 0x1514  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
13:33:16.0247 0x1514  nfrd960 - ok
13:33:16.0296 0x1514  [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc          C:\Windows\System32\nlasvc.dll
13:33:16.0312 0x1514  NlaSvc - ok
13:33:16.0336 0x1514  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
13:33:16.0338 0x1514  Npfs - ok
13:33:16.0379 0x1514  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi             C:\Windows\system32\nsisvc.dll
13:33:16.0385 0x1514  nsi - ok
13:33:16.0412 0x1514  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
13:33:16.0414 0x1514  nsiproxy - ok
13:33:16.0472 0x1514  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
13:33:16.0506 0x1514  Ntfs - ok
13:33:16.0528 0x1514  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
13:33:16.0530 0x1514  Null - ok
13:33:16.0568 0x1514  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
13:33:16.0573 0x1514  nvraid - ok
13:33:16.0602 0x1514  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
13:33:16.0608 0x1514  nvstor - ok
13:33:16.0634 0x1514  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
13:33:16.0639 0x1514  nv_agp - ok
13:33:16.0650 0x1514  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
13:33:16.0653 0x1514  ohci1394 - ok
13:33:16.0692 0x1514  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
13:33:16.0700 0x1514  p2pimsvc - ok
13:33:16.0730 0x1514  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
13:33:16.0739 0x1514  p2psvc - ok
13:33:16.0776 0x1514  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport         C:\Windows\system32\DRIVERS\parport.sys
13:33:16.0780 0x1514  Parport - ok
13:33:16.0795 0x1514  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
13:33:16.0798 0x1514  partmgr - ok
13:33:16.0807 0x1514  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
13:33:16.0808 0x1514  Parvdm - ok
13:33:16.0843 0x1514  [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc          C:\Windows\System32\pcasvc.dll
13:33:16.0849 0x1514  PcaSvc - ok
13:33:16.0856 0x1514  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci             C:\Windows\system32\drivers\pci.sys
13:33:16.0862 0x1514  pci - ok
13:33:16.0869 0x1514  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
13:33:16.0871 0x1514  pciide - ok
13:33:16.0887 0x1514  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
13:33:16.0894 0x1514  pcmcia - ok
13:33:16.0904 0x1514  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw             C:\Windows\system32\drivers\pcw.sys
13:33:16.0907 0x1514  pcw - ok
13:33:16.0935 0x1514  [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
13:33:16.0953 0x1514  PEAUTH - ok
13:33:17.0000 0x1514  [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
13:33:17.0030 0x1514  PeerDistSvc - ok
13:33:17.0109 0x1514  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla             C:\Windows\system32\pla.dll
13:33:17.0152 0x1514  pla - ok
13:33:17.0188 0x1514  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
13:33:17.0197 0x1514  PlugPlay - ok
13:33:17.0206 0x1514  [ 12B4549D515CB26BB8D375038017CA65, B09ED2BED994D2B04862BBF62EF56F110235D3489D3B1762432F22A3A8F97BB8 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
13:33:17.0209 0x1514  Pml Driver HPZ12 - ok
13:33:17.0239 0x1514  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
13:33:17.0243 0x1514  PNRPAutoReg - ok
13:33:17.0258 0x1514  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
13:33:17.0267 0x1514  PNRPsvc - ok
13:33:17.0301 0x1514  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
13:33:17.0310 0x1514  PolicyAgent - ok
13:33:17.0325 0x1514  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power           C:\Windows\system32\umpo.dll
13:33:17.0331 0x1514  Power - ok
13:33:17.0345 0x1514  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
13:33:17.0349 0x1514  PptpMiniport - ok
13:33:17.0364 0x1514  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor       C:\Windows\system32\drivers\processr.sys
13:33:17.0367 0x1514  Processor - ok
13:33:17.0395 0x1514  [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc         C:\Windows\system32\profsvc.dll
13:33:17.0401 0x1514  ProfSvc - ok
13:33:17.0426 0x1514  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:33:17.0429 0x1514  ProtectedStorage - ok
13:33:17.0464 0x1514  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
13:33:17.0468 0x1514  Psched - ok
13:33:17.0518 0x1514  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\drivers\ql2300.sys
13:33:17.0558 0x1514  ql2300 - ok
13:33:17.0594 0x1514  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
13:33:17.0599 0x1514  ql40xx - ok
13:33:17.0629 0x1514  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE           C:\Windows\system32\qwave.dll
13:33:17.0638 0x1514  QWAVE - ok
13:33:17.0651 0x1514  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
13:33:17.0654 0x1514  QWAVEdrv - ok
13:33:17.0667 0x1514  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
13:33:17.0669 0x1514  RasAcd - ok
13:33:17.0686 0x1514  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
13:33:17.0689 0x1514  RasAgileVpn - ok
13:33:17.0705 0x1514  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto         C:\Windows\System32\rasauto.dll
13:33:17.0711 0x1514  RasAuto - ok
13:33:17.0722 0x1514  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
13:33:17.0726 0x1514  Rasl2tp - ok
13:33:17.0771 0x1514  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
13:33:17.0782 0x1514  RasMan - ok
13:33:17.0796 0x1514  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
13:33:17.0799 0x1514  RasPppoe - ok
13:33:17.0805 0x1514  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
13:33:17.0808 0x1514  RasSstp - ok
13:33:17.0841 0x1514  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
13:33:17.0850 0x1514  rdbss - ok
13:33:17.0860 0x1514  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
13:33:17.0862 0x1514  rdpbus - ok
13:33:17.0871 0x1514  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
13:33:17.0873 0x1514  RDPCDD - ok
13:33:17.0907 0x1514  [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
13:33:17.0913 0x1514  RDPDR - ok
13:33:17.0926 0x1514  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
13:33:17.0928 0x1514  RDPENCDD - ok
13:33:17.0933 0x1514  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
13:33:17.0935 0x1514  RDPREFMP - ok
13:33:18.0009 0x1514  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:33:18.0019 0x1514  RdpVideoMiniport - ok
13:33:18.0043 0x1514  [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
13:33:18.0053 0x1514  RDPWD - ok
13:33:18.0084 0x1514  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
13:33:18.0090 0x1514  rdyboost - ok
13:33:18.0123 0x1514  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
13:33:18.0128 0x1514  RemoteAccess - ok
13:33:18.0154 0x1514  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
13:33:18.0160 0x1514  RemoteRegistry - ok
13:33:18.0171 0x1514  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
13:33:18.0175 0x1514  RpcEptMapper - ok
13:33:18.0186 0x1514  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
13:33:18.0189 0x1514  RpcLocator - ok
13:33:18.0212 0x1514  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs           C:\Windows\system32\rpcss.dll
13:33:18.0223 0x1514  RpcSs - ok
13:33:18.0259 0x1514  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
13:33:18.0262 0x1514  rspndr - ok
13:33:18.0312 0x1514  [ 6A2586DCB5B04A52404699EB325DF1DB, 07EA046410E23C3CCBCA20EBD187D4B5C1E1480359654FEB756EDFAAA8FFEAFD ] RTL8167         C:\Windows\system32\DRIVERS\Rt86win7.sys
13:33:18.0327 0x1514  RTL8167 - ok
13:33:18.0354 0x1514  [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
13:33:18.0356 0x1514  s3cap - ok
13:33:18.0385 0x1514  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] SamSs           C:\Windows\system32\lsass.exe
13:33:18.0387 0x1514  SamSs - ok
13:33:18.0419 0x1514  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
13:33:18.0423 0x1514  sbp2port - ok
13:33:18.0447 0x1514  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
13:33:18.0453 0x1514  SCardSvr - ok
13:33:18.0464 0x1514  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
13:33:18.0467 0x1514  scfilter - ok
13:33:18.0535 0x1514  [ 9060B8D5BCD5F2B019249F85E3D811F3, 7FB32AB7FE118462988321B9230074DAA960B587417EB463187539C3215445AE ] Schedule        C:\Windows\system32\schedsvc.dll
13:33:18.0556 0x1514  Schedule - ok
13:33:18.0572 0x1514  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc     C:\Windows\System32\certprop.dll
13:33:18.0574 0x1514  SCPolicySvc - ok
13:33:18.0587 0x1514  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
13:33:18.0594 0x1514  SDRSVC - ok
13:33:18.0619 0x1514  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
13:33:18.0621 0x1514  secdrv - ok
13:33:18.0638 0x1514  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
13:33:18.0641 0x1514  seclogon - ok
13:33:18.0666 0x1514  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\System32\sens.dll
13:33:18.0670 0x1514  SENS - ok
13:33:18.0689 0x1514  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
13:33:18.0693 0x1514  SensrSvc - ok
13:33:18.0705 0x1514  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
13:33:18.0707 0x1514  Serenum - ok
13:33:18.0722 0x1514  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
13:33:18.0725 0x1514  Serial - ok
13:33:18.0748 0x1514  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\drivers\sermouse.sys
13:33:18.0751 0x1514  sermouse - ok
13:33:18.0774 0x1514  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
13:33:18.0780 0x1514  SessionEnv - ok
13:33:18.0792 0x1514  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
13:33:18.0795 0x1514  sffdisk - ok
13:33:18.0811 0x1514  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
13:33:18.0814 0x1514  sffp_mmc - ok
13:33:18.0822 0x1514  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
13:33:18.0825 0x1514  sffp_sd - ok
13:33:18.0838 0x1514  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
13:33:18.0841 0x1514  sfloppy - ok
13:33:18.0863 0x1514  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
13:33:18.0873 0x1514  SharedAccess - ok
13:33:18.0896 0x1514  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:33:18.0907 0x1514  ShellHWDetection - ok
13:33:18.0926 0x1514  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
13:33:18.0929 0x1514  sisagp - ok
13:33:18.0953 0x1514  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
13:33:18.0957 0x1514  SiSRaid2 - ok
13:33:18.0972 0x1514  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
13:33:18.0976 0x1514  SiSRaid4 - ok
13:33:19.0004 0x1514  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
13:33:19.0008 0x1514  Smb - ok
13:33:19.0037 0x1514  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
13:33:19.0039 0x1514  SNMPTRAP - ok
13:33:19.0060 0x1514  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr           C:\Windows\system32\drivers\spldr.sys
13:33:19.0062 0x1514  spldr - ok
13:33:19.0095 0x1514  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler         C:\Windows\System32\spoolsv.exe
13:33:19.0106 0x1514  Spooler - ok
13:33:19.0214 0x1514  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
13:33:19.0287 0x1514  sppsvc - ok
13:33:19.0309 0x1514  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify     C:\Windows\system32\sppuinotify.dll
13:33:19.0314 0x1514  sppuinotify - ok
13:33:19.0346 0x1514  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv             C:\Windows\system32\DRIVERS\srv.sys
13:33:19.0356 0x1514  srv - ok
13:33:19.0377 0x1514  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
13:33:19.0387 0x1514  srv2 - ok
13:33:19.0397 0x1514  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
13:33:19.0401 0x1514  srvnet - ok
13:33:19.0420 0x1514  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
13:33:19.0426 0x1514  SSDPSRV - ok
13:33:19.0437 0x1514  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
13:33:19.0441 0x1514  SstpSvc - ok
13:33:19.0464 0x1514  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\drivers\stexstor.sys
13:33:19.0467 0x1514  stexstor - ok
13:33:19.0491 0x1514  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
13:33:19.0505 0x1514  StiSvc - ok
13:33:19.0537 0x1514  [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
13:33:19.0540 0x1514  storflt - ok
13:33:19.0560 0x1514  [ 0BF669F0A910BEDA4A32258D363AF2A5, 83EEBACDE4F69A2866B69CAA633F5C8B3CB01D88CEDB01B6EA5988E0A25CEE47 ] StorSvc         C:\Windows\system32\storsvc.dll
13:33:19.0564 0x1514  StorSvc - ok
13:33:19.0580 0x1514  [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
13:33:19.0583 0x1514  storvsc - ok
13:33:19.0595 0x1514  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
13:33:19.0597 0x1514  swenum - ok
13:33:19.0621 0x1514  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv           C:\Windows\System32\swprv.dll
13:33:19.0633 0x1514  swprv - ok
13:33:19.0714 0x1514  [ 4EE25AC85AFC3FD67D9F57ECDF566FF2, F1BFF1FB655F31B97FA9C6A49D433EFD33D8A35F6B28B4D83E45C27A05A86228 ] SysMain         C:\Windows\system32\sysmain.dll
13:33:19.0750 0x1514  SysMain - ok
13:33:19.0767 0x1514  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
13:33:19.0772 0x1514  TabletInputService - ok
13:33:19.0784 0x1514  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv         C:\Windows\System32\tapisrv.dll
13:33:19.0794 0x1514  TapiSrv - ok
13:33:19.0805 0x1514  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS             C:\Windows\System32\tbssvc.dll
13:33:19.0810 0x1514  TBS - ok
13:33:19.0870 0x1514  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
13:33:19.0907 0x1514  Tcpip - ok
13:33:19.0953 0x1514  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
13:33:19.0982 0x1514  TCPIP6 - ok
13:33:20.0004 0x1514  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
13:33:20.0007 0x1514  tcpipreg - ok
13:33:20.0034 0x1514  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
13:33:20.0037 0x1514  TDPIPE - ok
13:33:20.0049 0x1514  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
13:33:20.0052 0x1514  TDTCP - ok
13:33:20.0075 0x1514  [ BB8817D0508DD5EA69C770C8DEF5AB67, C55671524EEF6E16BBCC92556E83FD1D6457E707EA9330FC1CDD28FB11D99B77 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
13:33:20.0093 0x1514  tdx - ok
13:33:20.0290 0x1514  [ FC8DC5DB5F707C96FEBC526AA4CE562A, AB97B53EA9E8C55A18733A6A3DE42E6EBC8BA9150796338DF04AB2DDA5124E1A ] TeamViewer      C:\Program Files\TeamViewer\TeamViewer_Service.exe
13:33:20.0412 0x1514  TeamViewer - ok
13:33:20.0449 0x1514  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
13:33:20.0452 0x1514  TermDD - ok
13:33:20.0506 0x1514  [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService     C:\Windows\System32\termsrv.dll
13:33:20.0526 0x1514  TermService - ok
13:33:20.0551 0x1514  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
13:33:20.0554 0x1514  Themes - ok
13:33:20.0567 0x1514  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER     C:\Windows\system32\mmcss.dll
13:33:20.0570 0x1514  THREADORDER - ok
13:33:20.0584 0x1514  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
13:33:20.0589 0x1514  TrkWks - ok
13:33:20.0624 0x1514  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:33:20.0631 0x1514  TrustedInstaller - ok
13:33:20.0660 0x1514  [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
13:33:20.0664 0x1514  tssecsrv - ok
13:33:20.0689 0x1514  [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
13:33:20.0692 0x1514  TsUsbFlt - ok
13:33:20.0707 0x1514  [ 7E6E0797EB91F1D63641058416044313, 3A681A337DFCE9108B73CC4707462114E8D534C52BF8C8E226C0B31326FF24D5 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
13:33:20.0710 0x1514  TsUsbGD - ok
13:33:20.0768 0x1514  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
13:33:20.0777 0x1514  tunnel - ok
13:33:20.0796 0x1514  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
13:33:20.0801 0x1514  uagp35 - ok
13:33:20.0819 0x1514  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
13:33:20.0827 0x1514  udfs - ok
13:33:20.0847 0x1514  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect       C:\Windows\system32\UI0Detect.exe
13:33:20.0852 0x1514  UI0Detect - ok
13:33:20.0870 0x1514  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
13:33:20.0874 0x1514  uliagpkx - ok
13:33:20.0892 0x1514  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
13:33:20.0894 0x1514  umbus - ok
13:33:20.0907 0x1514  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\drivers\umpass.sys
13:33:20.0915 0x1514  UmPass - ok
13:33:20.0932 0x1514  [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService    C:\Windows\System32\umrdp.dll
13:33:20.0940 0x1514  UmRdpService - ok
13:33:20.0961 0x1514  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
13:33:20.0972 0x1514  upnphost - ok
13:33:20.0998 0x1514  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
13:33:21.0001 0x1514  usbccgp - ok
13:33:21.0020 0x1514  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
13:33:21.0024 0x1514  usbcir - ok
13:33:21.0036 0x1514  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
13:33:21.0038 0x1514  usbehci - ok
13:33:21.0060 0x1514  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
13:33:21.0069 0x1514  usbhub - ok
13:33:21.0082 0x1514  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
13:33:21.0085 0x1514  usbohci - ok
13:33:21.0111 0x1514  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
13:33:21.0113 0x1514  usbprint - ok
13:33:21.0146 0x1514  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
13:33:21.0149 0x1514  usbscan - ok
13:33:21.0170 0x1514  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:33:21.0174 0x1514  USBSTOR - ok
13:33:21.0178 0x1514  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
13:33:21.0181 0x1514  usbuhci - ok
13:33:21.0204 0x1514  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms           C:\Windows\System32\uxsms.dll
13:33:21.0207 0x1514  UxSms - ok
13:33:21.0234 0x1514  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] VaultSvc        C:\Windows\system32\lsass.exe
13:33:21.0236 0x1514  VaultSvc - ok
13:33:21.0267 0x1514  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
13:33:21.0270 0x1514  vdrvroot - ok
13:33:21.0296 0x1514  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds             C:\Windows\System32\vds.exe
13:33:21.0312 0x1514  vds - ok
13:33:21.0326 0x1514  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
13:33:21.0329 0x1514  vga - ok
13:33:21.0333 0x1514  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave         C:\Windows\System32\drivers\vga.sys
13:33:21.0335 0x1514  VgaSave - ok
13:33:21.0349 0x1514  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
13:33:21.0355 0x1514  vhdmp - ok
13:33:21.0381 0x1514  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
13:33:21.0385 0x1514  viaagp - ok
13:33:21.0405 0x1514  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7           C:\Windows\system32\drivers\viac7.sys
13:33:21.0409 0x1514  ViaC7 - ok
13:33:21.0421 0x1514  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
13:33:21.0424 0x1514  viaide - ok
13:33:21.0450 0x1514  [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus           C:\Windows\system32\drivers\vmbus.sys
13:33:21.0457 0x1514  vmbus - ok
13:33:21.0469 0x1514  [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
13:33:21.0471 0x1514  VMBusHID - ok
13:33:21.0484 0x1514  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
13:33:21.0488 0x1514  volmgr - ok
13:33:21.0502 0x1514  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
13:33:21.0511 0x1514  volmgrx - ok
13:33:21.0521 0x1514  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
13:33:21.0529 0x1514  volsnap - ok
13:33:21.0557 0x1514  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
13:33:21.0563 0x1514  vsmraid - ok
13:33:21.0615 0x1514  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS             C:\Windows\system32\vssvc.exe
13:33:21.0646 0x1514  VSS - ok
13:33:21.0660 0x1514  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
13:33:21.0663 0x1514  vwifibus - ok
13:33:21.0683 0x1514  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time         C:\Windows\system32\w32time.dll
13:33:21.0693 0x1514  W32Time - ok
13:33:21.0722 0x1514  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
13:33:21.0725 0x1514  WacomPen - ok
13:33:21.0747 0x1514  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
13:33:21.0750 0x1514  WANARP - ok
13:33:21.0754 0x1514  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
13:33:21.0756 0x1514  Wanarpv6 - ok
13:33:21.0805 0x1514  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
13:33:21.0841 0x1514  wbengine - ok
13:33:21.0866 0x1514  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
13:33:21.0873 0x1514  WbioSrvc - ok
13:33:21.0896 0x1514  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc         C:\Windows\System32\wcncsvc.dll
13:33:21.0908 0x1514  wcncsvc - ok
13:33:21.0937 0x1514  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:33:21.0942 0x1514  WcsPlugInService - ok
13:33:21.0965 0x1514  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\drivers\wd.sys
13:33:21.0968 0x1514  Wd - ok
13:33:21.0997 0x1514  [ CF68C54937BACCC0DA9A056FFA2A3988, 4D1FD6CEDA7A00D8F496916F6EE127B41C8875585C9AECAEBB0FC1B6F5E1312F ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
13:33:22.0013 0x1514  Wdf01000 - ok
13:33:22.0068 0x1514  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost  C:\Windows\system32\wdi.dll
13:33:22.0073 0x1514  WdiServiceHost - ok
13:33:22.0077 0x1514  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost   C:\Windows\system32\wdi.dll
13:33:22.0082 0x1514  WdiSystemHost - ok
13:33:22.0106 0x1514  [ 55C70654420DBF429604FD567E6F3CD3, 22191B049BCA76EF13AEDF8078E452E6B35E998A75AD63F14C542B541EA9F67D ] WebClient       C:\Windows\System32\webclnt.dll
13:33:22.0115 0x1514  WebClient - ok
13:33:22.0140 0x1514  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
13:33:22.0148 0x1514  Wecsvc - ok
13:33:22.0157 0x1514  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
13:33:22.0161 0x1514  wercplsupport - ok
13:33:22.0188 0x1514  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
13:33:22.0193 0x1514  WerSvc - ok
13:33:22.0213 0x1514  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
13:33:22.0215 0x1514  WfpLwf - ok
13:33:22.0232 0x1514  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
13:33:22.0234 0x1514  WIMMount - ok
13:33:22.0277 0x1514  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
13:33:22.0293 0x1514  WinDefend - ok
13:33:22.0300 0x1514  WinHttpAutoProxySvc - ok
13:33:22.0339 0x1514  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
13:33:22.0344 0x1514  Winmgmt - ok
13:33:22.0401 0x1514  [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM           C:\Windows\system32\WsmSvc.dll
13:33:22.0436 0x1514  WinRM - ok
13:33:22.0476 0x1514  [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
13:33:22.0478 0x1514  WinUsb - ok
13:33:22.0525 0x1514  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc         C:\Windows\System32\wlansvc.dll
13:33:22.0548 0x1514  Wlansvc - ok
13:33:22.0634 0x1514  [ 5E7C103F8475C4289847D15E129C20F7, C6325D3557545FA1DA26B0B1EA9A1C95AED1FA84A93BE29A771DAD9ECB00768B ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:33:22.0673 0x1514  wlidsvc - ok
13:33:22.0701 0x1514  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
13:33:22.0704 0x1514  WmiAcpi - ok
13:33:22.0732 0x1514  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
13:33:22.0737 0x1514  wmiApSrv - ok
13:33:22.0799 0x1514  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
13:33:22.0831 0x1514  WMPNetworkSvc - ok
13:33:22.0851 0x1514  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
13:33:22.0855 0x1514  WPCSvc - ok
13:33:22.0860 0x1514  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
13:33:22.0866 0x1514  WPDBusEnum - ok
13:33:22.0883 0x1514  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
13:33:22.0886 0x1514  ws2ifsl - ok
13:33:22.0900 0x1514  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\System32\wscsvc.dll
13:33:22.0905 0x1514  wscsvc - ok
13:33:22.0908 0x1514  WSearch - ok
13:33:22.0998 0x1514  [ 621DEDFB22B3F6F8CD3B2BBA54901A13, 80792978B1BDB89DB83265BF7224AC4B93510054F5914CBD733D221C8540A17D ] wuauserv        C:\Windows\system32\wuaueng.dll
13:33:23.0047 0x1514  wuauserv - ok
13:33:23.0082 0x1514  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
13:33:23.0085 0x1514  WudfPf - ok
13:33:23.0112 0x1514  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
13:33:23.0117 0x1514  WUDFRd - ok
13:33:23.0138 0x1514  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
13:33:23.0144 0x1514  wudfsvc - ok
13:33:23.0167 0x1514  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc         C:\Windows\System32\wwansvc.dll
13:33:23.0176 0x1514  WwanSvc - ok
13:33:23.0191 0x1514  ================ Scan global ===============================
13:33:23.0217 0x1514  [ 5E7C5DE85AF978495C3A9A0B720B9811, 142CDEBED78E3BAEE8D2DBF6A97CE26313932024010548EC2E570CAE480AF7C3 ] C:\Windows\system32\basesrv.dll
13:33:23.0252 0x1514  [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll
13:33:23.0298 0x1514  [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll
13:33:23.0325 0x1514  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
13:33:23.0353 0x1514  [ 0780A42DBD7D9969F9BF4A19AA4285B5, 8EA41124A4E97732C5DAA616457FBA7111CB38986F3427FA776ED00BC1407171 ] C:\Windows\system32\services.exe
13:33:23.0362 0x1514  [ Global ] - ok
13:33:23.0363 0x1514  ================ Scan MBR ==================================
13:33:23.0371 0x1514  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:33:23.0578 0x1514  \Device\Harddisk0\DR0 - ok
13:33:23.0578 0x1514  ================ Scan VBR ==================================
13:33:23.0579 0x1514  [ 213A3DF601CB3B3C582A07A259C6ACF8 ] \Device\Harddisk0\DR0\Partition1
13:33:23.0637 0x1514  \Device\Harddisk0\DR0\Partition1 - ok
13:33:23.0639 0x1514  [ 046E1F73AB2B18E72E12AF8743673AD1 ] \Device\Harddisk0\DR0\Partition2
13:33:23.0687 0x1514  \Device\Harddisk0\DR0\Partition2 - ok
13:33:23.0687 0x1514  ================ Scan generic autorun ======================
13:33:23.0751 0x1514  [ 7E7194AFFA4A6D1DE2FD8EED5537BCA0, 3669F88C63DAFA39DBDDE26029E3E7D84EDA2E2A7A8E216C424A5DD0934E29EA ] C:\Windows\system32\igfxtray.exe
13:33:23.0760 0x1514  IgfxTray - ok
13:33:23.0772 0x1514  [ C7BAB79AF0C5F2DB086B20E6E75D02CA, 76F8242AC01B4A9B209C930E9B1537C297E7C63EA4018E3992CF417A0D8B4ACF ] C:\Windows\system32\hkcmd.exe
13:33:23.0781 0x1514  HotKeysCmds - ok
13:33:23.0792 0x1514  [ 91841850DF96658EA287F9705A0211F1, D5E7850DE9912DBBA71A9A5C33046D9D4F8F97337BFA8315DB3DE0FE627D3E1D ] C:\Windows\system32\igfxpers.exe
13:33:23.0800 0x1514  Persistence - ok
13:33:24.0188 0x1514  [ D72ABA21ABB9314DA878FB9760E7A4C2, 90E3892B4070A6265CE8AB33115EEBED7D61F6FDB836B5EB1972BE7DD30E21F0 ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
13:33:24.0584 0x1514  RtHDVCpl - ok
13:33:24.0609 0x1514  [ 5514B64F7F2D25E09E2FDAF5D62B688C, 43263715ADC49250762A01E41DB2832C6A8B63CE4F66CDD8FC0B51DCA031DF27 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
13:33:24.0611 0x1514  IAStorIcon - ok
13:33:24.0696 0x1514  [ 0DB20318CEB155799880FEC174988933, 3840A7C9DF01F118048E806D71BDC5686A8FCF316FB35E65045988B0271532D8 ] C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
13:33:24.0737 0x1514  GDFirewallTray - ok
13:33:24.0894 0x1514  [ 2110F60508EA102B5B4B85A9307C34E5, A4DC5AAA01B066ACF0AB61CC20F77030EE6B494247A1C0653CDE987D46B97C9E ] C:\Program Files\HP\HP Color LaserJet CM1312 MFP Series\hppfaxprintersrv.exe
13:33:24.0948 0x1514  HP Color LaserJet CM1312 MFP Series Fax - ok
13:33:24.0978 0x1514  [ 34D296AFC913E302953C70463EF09A48, BC413307CBC56C039EE8A05B51A56E14EF59678FBB33815AEB320078056C8CE7 ] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
13:33:24.0980 0x1514  HP Software Update - ok
13:33:25.0054 0x1514  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
13:33:25.0083 0x1514  Sidebar - ok
13:33:25.0104 0x1514  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
13:33:25.0109 0x1514  mctadmin - ok
13:33:25.0141 0x1514  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
13:33:25.0167 0x1514  Sidebar - ok
13:33:25.0173 0x1514  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
13:33:25.0177 0x1514  mctadmin - ok
13:33:25.0389 0x1514  [ EE526B0428581B57FFC571FF57309E28, 1CF4DD251E78F2B67C4B1973E3378D6B87C5698EEC398CA4043621842ACC426C ] C:\Program Files\CCleaner\CCleaner.exe
13:33:25.0559 0x1514  CCleaner Monitoring - ok
13:33:25.0566 0x1514  Waiting for KSN requests completion. In queue: 83
13:33:26.0566 0x1514  Waiting for KSN requests completion. In queue: 83
13:33:27.0566 0x1514  Waiting for KSN requests completion. In queue: 83
13:33:28.0630 0x1514  AV detected via SS2: G DATA INTERNET SECURITY, C:\Program Files\G DATA\InternetSecurity\AVK\avkwscpe.exe ( 25.1.0.0 ), 0x41000 ( enabled : updated )
13:33:28.0633 0x1514  FW detected via SS2: G*DATA Personal Firewall, C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe ( 22.0.0.1 ), 0x41010 ( enabled )
13:33:31.0104 0x1514  ============================================================
13:33:31.0104 0x1514  Scan finished
13:33:31.0104 0x1514  ============================================================
13:33:31.0124 0x14e8  Detected object count: 0
13:33:31.0124 0x14e8  Actual detected object count: 0
13:34:43.0832 0x0714  Deinitialize success
         

Alt 14.11.2015, 13:53   #8
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Zitat:
Zitat von WoF Beitrag anzeigen
Soll das heißen, dass - auch wenn wir den Rechner hier erfolgreich entwanzen - der Spuk trotzdem noch weitergehen kann? Ich dachte Mails mit einem bestimmten Absender können nur über ebendieses Konto verschickt werden.


Da liegst Du falsch. Man kann jede Absender-Email-Adresse faken. Kannst Du mir mal eine Email die an andere verschickt wurde weiterleiten?

Bitte TDSS-Killer nach Anleitung ausführen! Da fehlen Parameter.
__________________
Gruß
deeprybka

Lob, Kritik, Wünsche?

Spende fürs trojaner-board?
_______________________________________________
„Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer

Alt 14.11.2015, 14:35   #9
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Sorry, hab ich übersehen.

Die E-Mail sieht so aus:
Code:
ATTFilter
Hello!

 

New message, please read hxxp://mark360.com.mx/its.php

(Absender Adresse)
         
Wenn ich sie Dir zumailen soll, musst Du mir eine Adresse schicken. Ich kann Dir per PM meine E-Mail_Adresse geben, wenn Du willst.

Hier der wiederholte Scan:
Code:
ATTFilter
14:30:10.0220 0x13c0  TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57
14:30:16.0834 0x13c0  ============================================================
14:30:16.0850 0x13c0  Current date / time: 2015/11/14 14:30:16.0834
14:30:16.0850 0x13c0  SystemInfo:
14:30:16.0850 0x13c0  
14:30:16.0850 0x13c0  OS Version: 6.1.7601 ServicePack: 1.0
14:30:16.0850 0x13c0  Product type: Workstation
14:30:16.0850 0x13c0  ComputerName: SILENCE-PC
14:30:16.0850 0x13c0  UserName: Silence
14:30:16.0850 0x13c0  Windows directory: C:\Windows
14:30:16.0850 0x13c0  System windows directory: C:\Windows
14:30:16.0850 0x13c0  Processor architecture: Intel x86
14:30:16.0850 0x13c0  Number of processors: 2
14:30:16.0850 0x13c0  Page size: 0x1000
14:30:16.0850 0x13c0  Boot type: Normal boot
14:30:16.0850 0x13c0  ============================================================
14:30:17.0006 0x13c0  KLMD registered as C:\Windows\system32\drivers\42487509.sys
14:30:17.0333 0x13c0  System UUID: {57202954-29A7-1650-8D37-1C3181B11FB3}
14:30:17.0864 0x13c0  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:30:17.0879 0x13c0  ============================================================
14:30:17.0879 0x13c0  \Device\Harddisk0\DR0:
14:30:17.0879 0x13c0  MBR partitions:
14:30:17.0879 0x13c0  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
14:30:17.0879 0x13c0  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D4000
14:30:17.0879 0x13c0  ============================================================
14:30:17.0879 0x13c0  C: <-> \Device\Harddisk0\DR0\Partition2
14:30:17.0879 0x13c0  ============================================================
14:30:17.0895 0x13c0  Initialize success
14:30:17.0895 0x13c0  ============================================================
14:32:45.0615 0x0ccc  ============================================================
14:32:45.0615 0x0ccc  Scan started
14:32:45.0615 0x0ccc  Mode: Manual; SigCheck; TDLFS; 
14:32:45.0615 0x0ccc  ============================================================
14:32:45.0615 0x0ccc  KSN ping started
14:32:48.0393 0x0ccc  KSN ping finished: true
14:32:49.0147 0x0ccc  ================ Scan system memory ========================
14:32:49.0148 0x0ccc  System memory - ok
14:32:49.0149 0x0ccc  ================ Scan services =============================
14:32:49.0277 0x0ccc  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
14:32:49.0417 0x0ccc  1394ohci - ok
14:32:49.0460 0x0ccc  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
14:32:49.0483 0x0ccc  ACPI - ok
14:32:49.0522 0x0ccc  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
14:32:49.0561 0x0ccc  AcpiPmi - ok
14:32:49.0647 0x0ccc  [ 5DB2C6B908C50767E2EDAA294A7566B5, 13AE4879D679BB0C6B2A5A5B13910359815A9D2E569BC1DE740B5A387A78CF33 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
14:32:49.0677 0x0ccc  AdobeARMservice - ok
14:32:49.0711 0x0ccc  [ 280A526E8111AC6A5BCC1A059E1E0340, FB92DDAE29A097D148AB23D8A0BD2B9E662EC1DBF0DA8B716374D6919B4C646F ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:32:49.0731 0x0ccc  AdobeFlashPlayerUpdateSvc - ok
14:32:49.0765 0x0ccc  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
14:32:49.0791 0x0ccc  adp94xx - ok
14:32:49.0815 0x0ccc  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci         C:\Windows\system32\drivers\adpahci.sys
14:32:49.0838 0x0ccc  adpahci - ok
14:32:49.0851 0x0ccc  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320         C:\Windows\system32\drivers\adpu320.sys
14:32:49.0870 0x0ccc  adpu320 - ok
14:32:49.0893 0x0ccc  [ 39AEAECE9F42407F176FE130D790BFBE, 19010DF87BDC1884268098CC04B4B15ECB710C94054A57157C0F9B7A795BDB28 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
14:32:49.0949 0x0ccc  AeLookupSvc - ok
14:32:49.0998 0x0ccc  [ 93B49FA857F7036A4EFF32371F6E7391, B9B2867D9A80E7F028E9D7C6ABCB9EC5198ACE28CEE101C5A846666B356B2843 ] AFD             C:\Windows\system32\drivers\afd.sys
14:32:50.0053 0x0ccc  AFD - ok
14:32:50.0089 0x0ccc  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
14:32:50.0120 0x0ccc  agp440 - ok
14:32:50.0143 0x0ccc  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx         C:\Windows\system32\drivers\djsvs.sys
14:32:50.0160 0x0ccc  aic78xx - ok
14:32:50.0193 0x0ccc  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG             C:\Windows\System32\alg.exe
14:32:50.0214 0x0ccc  ALG - ok
14:32:50.0231 0x0ccc  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
14:32:50.0246 0x0ccc  aliide - ok
14:32:50.0289 0x0ccc  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
14:32:50.0305 0x0ccc  amdagp - ok
14:32:50.0319 0x0ccc  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
14:32:50.0341 0x0ccc  amdide - ok
14:32:50.0357 0x0ccc  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
14:32:50.0376 0x0ccc  AmdK8 - ok
14:32:50.0391 0x0ccc  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
14:32:50.0408 0x0ccc  AmdPPM - ok
14:32:50.0472 0x0ccc  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
14:32:50.0508 0x0ccc  amdsata - ok
14:32:50.0520 0x0ccc  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
14:32:50.0539 0x0ccc  amdsbs - ok
14:32:50.0546 0x0ccc  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
14:32:50.0560 0x0ccc  amdxata - ok
14:32:50.0605 0x0ccc  [ FE4F2ADE5DBB3B888E9EB0A1FBA1F152, B17053A912C73835A2E80176D79885B530E15240B988125114B6B877C903D61C ] AppID           C:\Windows\system32\drivers\appid.sys
14:32:50.0645 0x0ccc  AppID - ok
14:32:50.0663 0x0ccc  [ A4DA304773AC1396792C5DE1D1EB601A, ECD23FF67FB1C4B94DBE23F6724E2DA0917CE0E479DE9C9F790A8635A2234950 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
14:32:50.0685 0x0ccc  AppIDSvc - ok
14:32:50.0711 0x0ccc  [ 133A7896E643D139443B47FDBFA327C7, 371FC602B531DF1EFDCEEC3A2F5497A0D0BE7F558B0583F572862C69A65BD454 ] Appinfo         C:\Windows\System32\appinfo.dll
14:32:50.0734 0x0ccc  Appinfo - ok
14:32:50.0776 0x0ccc  [ BB6093AD659360CB350F4E84B445F36D, 16E16AD8E58C3777E2C858C8223BEB3CC9999E6FDCD23A0013C39AAADC54193C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
14:32:50.0790 0x0ccc  Apple Mobile Device - ok
14:32:50.0817 0x0ccc  [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt         C:\Windows\System32\appmgmts.dll
14:32:50.0846 0x0ccc  AppMgmt - ok
14:32:50.0872 0x0ccc  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc             C:\Windows\system32\drivers\arc.sys
14:32:50.0887 0x0ccc  arc - ok
14:32:50.0896 0x0ccc  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\drivers\arcsas.sys
14:32:50.0912 0x0ccc  arcsas - ok
14:32:50.0995 0x0ccc  [ 8489551F063218E6693F2EAAA6CE01E4, 742D1BF2538037AD591D34C82F72A17CE49F8535F611E2D2B77A6E29409444E5 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
14:32:51.0058 0x0ccc  aspnet_state - ok
14:32:51.0075 0x0ccc  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
14:32:51.0158 0x0ccc  AsyncMac - ok
14:32:51.0186 0x0ccc  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi           C:\Windows\system32\drivers\atapi.sys
14:32:51.0200 0x0ccc  atapi - ok
14:32:51.0258 0x0ccc  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:32:51.0293 0x0ccc  AudioEndpointBuilder - ok
14:32:51.0307 0x0ccc  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
14:32:51.0341 0x0ccc  Audiosrv - ok
14:32:51.0475 0x0ccc  [ BC949A3706983328D8034D061E3F99B9, 2EAEE4F664B355C9E381B239F3E83EABBBC39A4FEA891D30F11B85D1057A652E ] AVKProxy        C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
14:32:51.0569 0x0ccc  AVKProxy - ok
14:32:51.0668 0x0ccc  [ 57E9F462DE5ED77574116782BA05AB0F, 611987C8205E113DFA206F50EF4959AA5D6CE252A73EC1E74C043CBFD7172E3D ] AVKService      C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
14:32:51.0718 0x0ccc  AVKService - ok
14:32:51.0819 0x0ccc  [ 26B9C28D738D91832A5F0011CB2288D0, 7EA287DA55C10D333F56CA7C73B60E2728A56D3974C8504354E0895BE03AC82C ] AVKWCtl         C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
14:32:51.0934 0x0ccc  AVKWCtl - ok
14:32:51.0953 0x0ccc  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
14:32:51.0974 0x0ccc  AxInstSV - ok
14:32:52.0016 0x0ccc  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv         C:\Windows\system32\drivers\bxvbdx.sys
14:32:52.0050 0x0ccc  b06bdrv - ok
14:32:52.0074 0x0ccc  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
14:32:52.0096 0x0ccc  b57nd60x - ok
14:32:52.0122 0x0ccc  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
14:32:52.0146 0x0ccc  BDESVC - ok
14:32:52.0159 0x0ccc  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
14:32:52.0189 0x0ccc  Beep - ok
14:32:52.0220 0x0ccc  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE             C:\Windows\System32\bfe.dll
14:32:52.0252 0x0ccc  BFE - ok
14:32:52.0285 0x0ccc  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\System32\qmgr.dll
14:32:52.0371 0x0ccc  BITS - ok
14:32:52.0392 0x0ccc  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
14:32:52.0409 0x0ccc  blbdrive - ok
14:32:52.0477 0x0ccc  [ 5EA9C80F18CBC393EA7D9A2991DED4B5, 7E5EB1CE44FEBE93686174058D51581FA00BDFF0EBB84BD74BC08F6386019253 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
14:32:52.0510 0x0ccc  Bonjour Service - ok
14:32:52.0537 0x0ccc  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
14:32:52.0565 0x0ccc  bowser - ok
14:32:52.0582 0x0ccc  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
14:32:52.0601 0x0ccc  BrFiltLo - ok
14:32:52.0611 0x0ccc  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
14:32:52.0628 0x0ccc  BrFiltUp - ok
14:32:52.0653 0x0ccc  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser         C:\Windows\System32\browser.dll
14:32:52.0675 0x0ccc  Browser - ok
14:32:52.0693 0x0ccc  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
14:32:52.0720 0x0ccc  Brserid - ok
14:32:52.0732 0x0ccc  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
14:32:52.0751 0x0ccc  BrSerWdm - ok
14:32:52.0775 0x0ccc  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
14:32:52.0793 0x0ccc  BrUsbMdm - ok
14:32:52.0796 0x0ccc  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
14:32:52.0813 0x0ccc  BrUsbSer - ok
14:32:52.0820 0x0ccc  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
14:32:52.0839 0x0ccc  BTHMODEM - ok
14:32:52.0866 0x0ccc  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv         C:\Windows\system32\bthserv.dll
14:32:52.0900 0x0ccc  bthserv - ok
14:32:52.0920 0x0ccc  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
14:32:52.0952 0x0ccc  cdfs - ok
14:32:52.0984 0x0ccc  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
14:32:53.0002 0x0ccc  cdrom - ok
14:32:53.0021 0x0ccc  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc     C:\Windows\System32\certprop.dll
14:32:53.0051 0x0ccc  CertPropSvc - ok
14:32:53.0062 0x0ccc  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\drivers\circlass.sys
14:32:53.0080 0x0ccc  circlass - ok
14:32:53.0101 0x0ccc  [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS            C:\Windows\system32\CLFS.sys
14:32:53.0123 0x0ccc  CLFS - ok
14:32:53.0169 0x0ccc  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:32:53.0184 0x0ccc  clr_optimization_v2.0.50727_32 - ok
14:32:53.0211 0x0ccc  [ F3C5A948079B128E70AFB38FFBD20533, 5FDD012AF3F2D59B3BB549062E140FE2AD3D2E4E89B06CDC7FACED339E0D71AA ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:32:53.0260 0x0ccc  clr_optimization_v4.0.30319_32 - ok
14:32:53.0269 0x0ccc  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
14:32:53.0284 0x0ccc  CmBatt - ok
14:32:53.0301 0x0ccc  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
14:32:53.0315 0x0ccc  cmdide - ok
14:32:53.0344 0x0ccc  [ 780FFC005741C9316576086155E55F56, D863E5657F1468410BBDD657D5EA8A2FDDB70FED459CDE3178CB8FDB910058EC ] CNG             C:\Windows\system32\Drivers\cng.sys
14:32:53.0374 0x0ccc  CNG - ok
14:32:53.0381 0x0ccc  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
14:32:53.0394 0x0ccc  Compbatt - ok
14:32:53.0423 0x0ccc  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
14:32:53.0440 0x0ccc  CompositeBus - ok
14:32:53.0454 0x0ccc  COMSysApp - ok
14:32:53.0488 0x0ccc  [ 2D95DFA349D8DA1C89DF7E67924B5B64, D3E6A9B285F7D22B20C59BA62DDB677079DC18E3E0152C8049AE979F9D2FE7A6 ] cphs            C:\Windows\system32\IntelCpHeciSvc.exe
14:32:53.0511 0x0ccc  cphs - ok
14:32:53.0553 0x0ccc  cpuz136 - ok
14:32:53.0566 0x0ccc  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
14:32:53.0581 0x0ccc  crcdisk - ok
14:32:53.0624 0x0ccc  [ 33F67BBCC3C0499D3F3382473114CFA8, FDDCC41CE005B7C1BEBB6F4ACA9A3F10E5972792ADFD7D294E70A0B781460981 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
14:32:53.0648 0x0ccc  CryptSvc - ok
14:32:53.0676 0x0ccc  [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC             C:\Windows\system32\drivers\csc.sys
14:32:53.0713 0x0ccc  CSC - ok
14:32:53.0747 0x0ccc  [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService      C:\Windows\System32\cscsvc.dll
14:32:53.0780 0x0ccc  CscService - ok
14:32:53.0818 0x0ccc  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
14:32:53.0860 0x0ccc  DcomLaunch - ok
14:32:53.0885 0x0ccc  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc       C:\Windows\System32\defragsvc.dll
14:32:53.0923 0x0ccc  defragsvc - ok
14:32:53.0938 0x0ccc  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
14:32:53.0968 0x0ccc  DfsC - ok
14:32:53.0996 0x0ccc  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
14:32:54.0023 0x0ccc  Dhcp - ok
14:32:54.0086 0x0ccc  [ 0A3386E3CF9C5D089D695AC5A35F4C6F, D610071493EB95FCE39E24C457A0B5BBA131193159E43FDC1E8EDABB9C7AB81A ] DiagTrack       C:\Windows\system32\diagtrack.dll
14:32:54.0259 0x0ccc  DiagTrack - ok
14:32:54.0286 0x0ccc  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
14:32:54.0323 0x0ccc  discache - ok
14:32:54.0348 0x0ccc  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\drivers\disk.sys
14:32:54.0364 0x0ccc  Disk - ok
14:32:54.0384 0x0ccc  [ 2A958EF85DB1B61FFCA65044FA4BCE9E, C83511685EE1CE85A5ADF9B5BE96C375A521601F66024BDC3EE044C0B6E85D69 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
14:32:54.0408 0x0ccc  dmvsc - ok
14:32:54.0425 0x0ccc  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
14:32:54.0445 0x0ccc  Dnscache - ok
14:32:54.0468 0x0ccc  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc         C:\Windows\System32\dot3svc.dll
14:32:54.0503 0x0ccc  dot3svc - ok
14:32:54.0516 0x0ccc  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS             C:\Windows\system32\dps.dll
14:32:54.0549 0x0ccc  DPS - ok
14:32:54.0573 0x0ccc  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
14:32:54.0593 0x0ccc  drmkaud - ok
14:32:54.0641 0x0ccc  [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
14:32:54.0677 0x0ccc  DXGKrnl - ok
14:32:54.0694 0x0ccc  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost         C:\Windows\System32\eapsvc.dll
14:32:54.0728 0x0ccc  EapHost - ok
14:32:54.0837 0x0ccc  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv           C:\Windows\system32\drivers\evbdx.sys
14:32:54.0948 0x0ccc  ebdrv - ok
14:32:54.0972 0x0ccc  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] EFS             C:\Windows\System32\lsass.exe
14:32:55.0130 0x0ccc  EFS - ok
14:32:55.0182 0x0ccc  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
14:32:55.0227 0x0ccc  ehRecvr - ok
14:32:55.0235 0x0ccc  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched         C:\Windows\ehome\ehsched.exe
14:32:55.0255 0x0ccc  ehSched - ok
14:32:55.0286 0x0ccc  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
14:32:55.0312 0x0ccc  elxstor - ok
14:32:55.0323 0x0ccc  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
14:32:55.0338 0x0ccc  ErrDev - ok
14:32:55.0367 0x0ccc  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem     C:\Windows\system32\es.dll
14:32:55.0407 0x0ccc  EventSystem - ok
14:32:55.0424 0x0ccc  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat           C:\Windows\system32\drivers\exfat.sys
14:32:55.0459 0x0ccc  exfat - ok
14:32:55.0466 0x0ccc  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
14:32:55.0500 0x0ccc  fastfat - ok
14:32:55.0527 0x0ccc  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax             C:\Windows\system32\fxssvc.exe
14:32:55.0567 0x0ccc  Fax - ok
14:32:55.0593 0x0ccc  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc             C:\Windows\system32\drivers\fdc.sys
14:32:55.0610 0x0ccc  fdc - ok
14:32:55.0626 0x0ccc  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost         C:\Windows\system32\fdPHost.dll
14:32:55.0658 0x0ccc  fdPHost - ok
14:32:55.0668 0x0ccc  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
14:32:55.0699 0x0ccc  FDResPub - ok
14:32:55.0710 0x0ccc  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
14:32:55.0725 0x0ccc  FileInfo - ok
14:32:55.0729 0x0ccc  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
14:32:55.0761 0x0ccc  Filetrace - ok
14:32:55.0770 0x0ccc  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
14:32:55.0785 0x0ccc  flpydisk - ok
14:32:55.0808 0x0ccc  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
14:32:55.0827 0x0ccc  FltMgr - ok
14:32:55.0878 0x0ccc  [ 37DE123FE4276D8EC7F3C5B10C236238, 93CA47B9A96D904DD177FC0E04DECDF13756C8FA3C7613913DB4BF29A70ECE96 ] FontCache       C:\Windows\system32\FntCache.dll
14:32:55.0928 0x0ccc  FontCache - ok
14:32:55.0967 0x0ccc  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:32:55.0995 0x0ccc  FontCache3.0.0.0 - ok
14:32:56.0028 0x0ccc  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
14:32:56.0046 0x0ccc  FsDepends - ok
14:32:56.0070 0x0ccc  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
14:32:56.0088 0x0ccc  Fs_Rec - ok
14:32:56.0111 0x0ccc  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
14:32:56.0135 0x0ccc  fvevol - ok
14:32:56.0156 0x0ccc  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
14:32:56.0172 0x0ccc  gagp30kx - ok
14:32:56.0204 0x0ccc  [ 8145A7A9D571B129689CFDAB425CA575, E83778E68C9C45D6ED288838F3D81531B5BC878130CE877E3F4DDA1B223E4D8B ] GDBehave        C:\Windows\system32\drivers\GDBehave.sys
14:32:56.0220 0x0ccc  GDBehave - ok
14:32:56.0317 0x0ccc  [ 83FBEF575A31D7CE6D7823E415D3791D, D60FAD209C019CC918D840C650DCE98FB313365336ADB0F124CE811E5A61B822 ] GDFwSvc         C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
14:32:56.0409 0x0ccc  GDFwSvc - ok
14:32:56.0477 0x0ccc  [ 70D3B79D77D9DD0AE404330AB4BED823, F2AC2185759612A5F9907193DF2E7046D945688DBE1DA42FBD16CE4E8B7DE539 ] GDKBB           C:\Windows\system32\drivers\GDKBB32.sys
14:32:56.0506 0x0ccc  GDKBB - ok
14:32:56.0533 0x0ccc  [ 1C38F4732FEAA90F50185696900FC3D0, 60F74372C4971AD81CE083D6A340E7ADBA5D55697D8B2F9ACCB02B9ED291CFCB ] GDKBFlt         C:\Windows\system32\drivers\GDKBFlt32.sys
14:32:56.0546 0x0ccc  GDKBFlt - ok
14:32:56.0556 0x0ccc  [ 05DC9DDD93A2050B1407CEB36AE717A7, 16650CB56B5393D56423C778C580CA24D45428CF2B178F8D4B380FC10D4814FE ] GDMnIcpt        C:\Windows\system32\drivers\MiniIcpt.sys
14:32:56.0573 0x0ccc  GDMnIcpt - ok
14:32:56.0605 0x0ccc  [ 735E1EBE420F12C1012045968CEDCBF7, 7667E5C9F3E3C5CD944708900C86E0749A7F0AB6A6877F3807430863126C82D3 ] GDPkIcpt        C:\Windows\system32\drivers\PktIcpt.sys
14:32:56.0620 0x0ccc  GDPkIcpt - ok
14:32:56.0636 0x0ccc  gdrv - ok
14:32:56.0677 0x0ccc  [ E9B7AF2C5C7B9AD739718AA7ED5F1911, 52C1B75B97DBCF343A6A7045E1F42C8BB35FF23CC2B463EA1B858FCD5B85678F ] GDScan          C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
14:32:56.0711 0x0ccc  GDScan - ok
14:32:56.0744 0x0ccc  [ F908F4A3EA6EC721264D20FEDAD1FFD2, E8888A5BAF33653DDE9F2937E29DD0DE028B78B554FDBAC076604B9DD615BD8B ] gdwfpcd         C:\Windows\system32\drivers\gdwfpcd32.sys
14:32:56.0757 0x0ccc  gdwfpcd - ok
14:32:56.0787 0x0ccc  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
14:32:56.0800 0x0ccc  GEARAspiWDM - ok
14:32:56.0828 0x0ccc  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc           C:\Windows\System32\gpsvc.dll
14:32:56.0876 0x0ccc  gpsvc - ok
14:32:56.0914 0x0ccc  [ DE640BC12C11DE49CE3392161AD4E64D, CD291205D8997DABD7154A5170B1D1A15E2B243270AD018F01864090DFFFBE24 ] GRD             C:\Windows\system32\drivers\GRD.sys
14:32:56.0927 0x0ccc  GRD - ok
14:32:56.0941 0x0ccc  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
14:32:56.0964 0x0ccc  hcw85cir - ok
14:32:57.0003 0x0ccc  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:32:57.0029 0x0ccc  HdAudAddService - ok
14:32:57.0041 0x0ccc  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
14:32:57.0061 0x0ccc  HDAudBus - ok
14:32:57.0071 0x0ccc  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
14:32:57.0087 0x0ccc  HidBatt - ok
14:32:57.0099 0x0ccc  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\drivers\hidbth.sys
14:32:57.0118 0x0ccc  HidBth - ok
14:32:57.0137 0x0ccc  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr           C:\Windows\system32\drivers\hidir.sys
14:32:57.0156 0x0ccc  HidIr - ok
14:32:57.0175 0x0ccc  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv         C:\Windows\system32\hidserv.dll
14:32:57.0208 0x0ccc  hidserv - ok
14:32:57.0239 0x0ccc  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
14:32:57.0265 0x0ccc  HidUsb - ok
14:32:57.0277 0x0ccc  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
14:32:57.0309 0x0ccc  hkmsvc - ok
14:32:57.0328 0x0ccc  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
14:32:57.0357 0x0ccc  HomeGroupListener - ok
14:32:57.0385 0x0ccc  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
14:32:57.0407 0x0ccc  HomeGroupProvider - ok
14:32:57.0421 0x0ccc  [ A39F5EFD8D65DA4E67C5EB14CAE60F15, 10558A3AB55BF431E1146C062C12EE5C71EB063A195CD4284412824350C867B2 ] HookCentre      C:\Windows\system32\drivers\HookCentre.sys
14:32:57.0436 0x0ccc  HookCentre - ok
14:32:57.0515 0x0ccc  [ CE1DD06F2A2AFD6D5DACAA6D58FD25C0, 4A3BA099323953BBAE06313FDB5A3C6855B009537FA491FFCA8779ACD6ED5E65 ] HP LaserJet Service C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
14:32:57.0538 0x0ccc  HP LaserJet Service - detected UnsignedFile.Multi.Generic ( 1 )
14:33:00.0138 0x0ccc  Detect skipped due to KSN trusted
14:33:00.0139 0x0ccc  HP LaserJet Service - ok
14:33:00.0178 0x0ccc  [ 299683D4C8AAA3F6F5D5D226A1782A6E, A2ECF52DBDC442F3C9514EC80CE614A9D3F45698E5B0992CF009C66B770E9027 ] HPEWSFXBULK     C:\Windows\system32\drivers\hpfxbulk.sys
14:33:00.0206 0x0ccc  HPEWSFXBULK - ok
14:33:00.0227 0x0ccc  [ 299683D4C8AAA3F6F5D5D226A1782A6E, A2ECF52DBDC442F3C9514EC80CE614A9D3F45698E5B0992CF009C66B770E9027 ] HPFXBULK        C:\Windows\system32\drivers\hpfxbulk.sys
14:33:00.0244 0x0ccc  HPFXBULK - ok
14:33:00.0259 0x0ccc  [ F728DB73A87231E27B6BA34D71CE2EDB, 0C3BDF6017BF494990CD121A7948090639AE2371C0E070B079386DCD4B99FA16 ] HPFXFAX         C:\Windows\system32\drivers\hpfxfax.sys
14:33:00.0272 0x0ccc  HPFXFAX - ok
14:33:00.0361 0x0ccc  [ F50F7984FDD151EDD8A70A8DBD9E2A44, 45E7ECA40298B233D124993D6C9D4FBBF05E9A843F4DE089317342B3D8A83696 ] hpqcxs08        C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
14:33:00.0387 0x0ccc  hpqcxs08 - detected UnsignedFile.Multi.Generic ( 1 )
14:33:04.0129 0x0ccc  Detect skipped due to KSN trusted
14:33:04.0129 0x0ccc  hpqcxs08 - ok
14:33:04.0160 0x0ccc  [ DF446BA625CC441617843E87798CE048, B45C11EEA7EA792DE82E9BB283B9DCF30F891AAB8366075856BD84D10BCBCCD3 ] hpqddsvc        C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
14:33:04.0172 0x0ccc  hpqddsvc - detected UnsignedFile.Multi.Generic ( 1 )
14:33:06.0587 0x0ccc  Detect skipped due to KSN trusted
14:33:06.0587 0x0ccc  hpqddsvc - ok
14:33:06.0622 0x0ccc  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
14:33:06.0639 0x0ccc  HpSAMD - ok
14:33:06.0673 0x0ccc  [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP            C:\Windows\system32\drivers\HTTP.sys
14:33:06.0721 0x0ccc  HTTP - ok
14:33:06.0744 0x0ccc  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
14:33:06.0760 0x0ccc  hwpolicy - ok
14:33:06.0780 0x0ccc  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
14:33:06.0808 0x0ccc  i8042prt - ok
14:33:06.0855 0x0ccc  [ 76C3966183BD5382E14CEB6DF97D9709, 52A2676FED3A73182D7BA3AC4EA954BC2DC8879CE71DB973E37720B2F0A7392A ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
14:33:06.0883 0x0ccc  iaStor - ok
14:33:06.0924 0x0ccc  [ 95E0895DC40A6DAA8D0A92D12993DE79, D35AAD7674D450D4D09161435C52E5C2B5B2BCF28F3DC9E7BCBD4437A57B2C48 ] iaStorA         C:\Windows\system32\drivers\iaStorA.sys
14:33:06.0952 0x0ccc  iaStorA - ok
14:33:06.0991 0x0ccc  [ 545462D0DBE24AF379BA869B7C185CCD, 056F9D0D5FD4FEF37665A35A4029722FF60D02A69854E952DC361CC0E5CD26F9 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
14:33:07.0004 0x0ccc  IAStorDataMgrSvc - ok
14:33:07.0015 0x0ccc  [ C10DFBB841657DE0032B0CA29AC2A041, 90390E709FE6B35F07D0C915E17C758A4EFB7AFF96D8B3370AA35F534FAB109B ] iaStorF         C:\Windows\system32\drivers\iaStorF.sys
14:33:07.0029 0x0ccc  iaStorF - ok
14:33:07.0060 0x0ccc  [ 64EC5FC35D38F1EE71650E8384ECCA44, 3E0573D06448737D3024DDC3DA892014D9C4D5CDFFC7F2B520EC76992051FA78 ] iaStorS         C:\Windows\system32\drivers\iaStorS.sys
14:33:07.0091 0x0ccc  iaStorS - ok
14:33:07.0112 0x0ccc  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
14:33:07.0136 0x0ccc  iaStorV - ok
14:33:07.0161 0x0ccc  [ 83FF82FE209E7997067B375DAD6CF23D, E312DD068E51DBF96A8232D7D1C9F158652FDA23649655F1102928B320795091 ] ICCS            C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
14:33:07.0178 0x0ccc  ICCS - ok
14:33:07.0233 0x0ccc  [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:33:07.0274 0x0ccc  idsvc - ok
14:33:07.0279 0x0ccc  IEEtwCollectorService - ok
14:33:07.0402 0x0ccc  [ 543E9429115BC70BD796E412EC8BB82E, 89EB80A7901EC906CC2D8E57501E6652339C7C7EB03761BF277E84752AB9CC7D ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
14:33:07.0631 0x0ccc  igfx - ok
14:33:07.0707 0x0ccc  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp           C:\Windows\system32\drivers\iirsp.sys
14:33:07.0724 0x0ccc  iirsp - ok
14:33:07.0800 0x0ccc  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
14:33:07.0839 0x0ccc  IKEEXT - ok
14:33:07.0988 0x0ccc  [ DAA00AE67B4F8B083442BEAB684A387B, 8770DE3B80F8F192E333311A90BB0AD8E2CA0959B2CF363589C54E15F3D37569 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
14:33:08.0116 0x0ccc  IntcAzAudAddService - ok
14:33:08.0150 0x0ccc  [ 5C65EC99D43E7F2BAD08F96FE2771E89, 750A8B9C304F45B3FE6D5156B734AAFD7FD5C1D85F53D8205EC36E49C437874E ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
14:33:08.0178 0x0ccc  IntcDAud - ok
14:33:08.0207 0x0ccc  [ 5BD12A81869923C8A690A315363D17A2, 81B41ED432A02D3C013FD2103FA78B56BB953E2442FE54B830F08EDBFA174870 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
14:33:08.0233 0x0ccc  Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
14:33:10.0664 0x0ccc  Detect skipped due to KSN trusted
14:33:10.0664 0x0ccc  Intel(R) Capability Licensing Service Interface - ok
14:33:10.0705 0x0ccc  [ 4D6A4F5A96881D15A016C7D930FB97F1, 080633E6ECD4CD244ECDC36C2009E7B454B7454C968BBB3A2CE68DF0A6B04283 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
14:33:10.0739 0x0ccc  Intel(R) Capability Licensing Service TCP IP Interface - ok
14:33:10.0755 0x0ccc  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
14:33:10.0768 0x0ccc  intelide - ok
14:33:10.0790 0x0ccc  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
14:33:10.0806 0x0ccc  intelppm - ok
14:33:10.0828 0x0ccc  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
14:33:10.0861 0x0ccc  IPBusEnum - ok
14:33:10.0875 0x0ccc  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:33:10.0906 0x0ccc  IpFilterDriver - ok
14:33:10.0947 0x0ccc  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
14:33:10.0990 0x0ccc  iphlpsvc - ok
14:33:11.0005 0x0ccc  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
14:33:11.0022 0x0ccc  IPMIDRV - ok
14:33:11.0043 0x0ccc  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
14:33:11.0077 0x0ccc  IPNAT - ok
14:33:11.0119 0x0ccc  [ 3EBDA8B348A231CF1E98D4BCA31731D7, E7D8A87DEFD9531421671F5A8CCB9C52CC33CCB235C88788B4566284F506A6D7 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
14:33:11.0148 0x0ccc  iPod Service - ok
14:33:11.0166 0x0ccc  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
14:33:11.0186 0x0ccc  IRENUM - ok
14:33:11.0200 0x0ccc  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
14:33:11.0215 0x0ccc  isapnp - ok
14:33:11.0244 0x0ccc  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
14:33:11.0264 0x0ccc  iScsiPrt - ok
14:33:11.0301 0x0ccc  [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service     C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
14:33:11.0318 0x0ccc  jhi_service - ok
14:33:11.0341 0x0ccc  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
14:33:11.0356 0x0ccc  kbdclass - ok
14:33:11.0386 0x0ccc  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
14:33:11.0403 0x0ccc  kbdhid - ok
14:33:11.0445 0x0ccc  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] KeyIso          C:\Windows\system32\lsass.exe
14:33:11.0462 0x0ccc  KeyIso - ok
14:33:11.0489 0x0ccc  [ A061E519ACDE34843DFA3F1C7358DAA2, 457417DF5BDC267EA4649A2E65D72FC8308899C1E4F0D26113D31F42767E618E ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
14:33:11.0505 0x0ccc  KSecDD - ok
14:33:11.0519 0x0ccc  [ 523091605C05F5DE880426A2FBA0F87C, 96884B50032B70F455D519934671940ED2493CA62CAACF68E89CCC2E5B0D3F01 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
14:33:11.0536 0x0ccc  KSecPkg - ok
14:33:11.0565 0x0ccc  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm           C:\Windows\system32\msdtckrm.dll
14:33:11.0607 0x0ccc  KtmRm - ok
14:33:11.0632 0x0ccc  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\system32\srvsvc.dll
14:33:11.0669 0x0ccc  LanmanServer - ok
14:33:11.0682 0x0ccc  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:33:11.0716 0x0ccc  LanmanWorkstation - ok
14:33:11.0739 0x0ccc  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
14:33:11.0774 0x0ccc  lltdio - ok
14:33:11.0790 0x0ccc  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
14:33:11.0827 0x0ccc  lltdsvc - ok
14:33:11.0838 0x0ccc  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts         C:\Windows\System32\lmhsvc.dll
14:33:11.0868 0x0ccc  lmhosts - ok
14:33:11.0915 0x0ccc  [ 6A35B295812CE7064CFBCD9F254169CF, 561DD131FED6F90686D8C031B45B87B6D065C7E0C8804AEFCDE239725AAEE43E ] LMS             C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
14:33:11.0940 0x0ccc  LMS - ok
14:33:11.0969 0x0ccc  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
14:33:11.0985 0x0ccc  LSI_FC - ok
14:33:11.0994 0x0ccc  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
14:33:12.0010 0x0ccc  LSI_SAS - ok
14:33:12.0015 0x0ccc  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
14:33:12.0030 0x0ccc  LSI_SAS2 - ok
14:33:12.0040 0x0ccc  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
14:33:12.0056 0x0ccc  LSI_SCSI - ok
14:33:12.0070 0x0ccc  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv           C:\Windows\system32\drivers\luafv.sys
14:33:12.0103 0x0ccc  luafv - ok
14:33:12.0145 0x0ccc  [ B4CD87E78A01562E3DA67FE1C2779204, 536AC01C53A18E7B43F02F345FC3088C189A2D01F5E060714C0534FE7ECA2356 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
14:33:12.0158 0x0ccc  MBAMProtector - ok
14:33:12.0222 0x0ccc  [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService     C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe
14:33:12.0274 0x0ccc  MBAMService - ok
14:33:12.0295 0x0ccc  [ 490F0F3ED8A970E2BAA38F719242B8F7, 03F902365372639424AB654AEBF6EB2B6B73363275435ADC2D086EAA7112AC3D ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
14:33:12.0309 0x0ccc  MBAMWebAccessControl - ok
14:33:12.0341 0x0ccc  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
14:33:12.0361 0x0ccc  Mcx2Svc - ok
14:33:12.0385 0x0ccc  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas         C:\Windows\system32\drivers\megasas.sys
14:33:12.0400 0x0ccc  megasas - ok
14:33:12.0426 0x0ccc  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
14:33:12.0447 0x0ccc  MegaSR - ok
14:33:12.0476 0x0ccc  [ 97AEFCC50287E647876CF19F5F9A367F, 316EC1A1E9C56F56292413C2BCA647FC2F0D88694F7423BFEA703DE0BB54F3ED ] MEI             C:\Windows\system32\DRIVERS\TeeDriver.sys
14:33:12.0490 0x0ccc  MEI - ok
14:33:12.0505 0x0ccc  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS           C:\Windows\system32\mmcss.dll
14:33:12.0538 0x0ccc  MMCSS - ok
14:33:12.0553 0x0ccc  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem           C:\Windows\system32\drivers\modem.sys
14:33:12.0585 0x0ccc  Modem - ok
14:33:12.0609 0x0ccc  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
14:33:12.0626 0x0ccc  monitor - ok
14:33:12.0653 0x0ccc  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
14:33:12.0668 0x0ccc  mouclass - ok
14:33:12.0679 0x0ccc  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
14:33:12.0696 0x0ccc  mouhid - ok
14:33:12.0731 0x0ccc  [ BAD9C0366134BA181514E9263C8CE606, 7976B2D3DC283ACDBC21C7D197C0E2A650E6555F6569283302766B17D736BDB8 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
14:33:12.0746 0x0ccc  mountmgr - ok
14:33:12.0806 0x0ccc  [ 0DE2474F316C515482ABAD3B697F8714, 62862AE7432F5350068E96AD466093359C6CF444EB517AE6D09134FAF78C49F5 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:33:12.0840 0x0ccc  MozillaMaintenance - ok
14:33:12.0859 0x0ccc  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
14:33:12.0877 0x0ccc  mpio - ok
14:33:12.0886 0x0ccc  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
14:33:12.0923 0x0ccc  mpsdrv - ok
14:33:12.0961 0x0ccc  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
14:33:13.0026 0x0ccc  MpsSvc - ok
14:33:13.0062 0x0ccc  [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
14:33:13.0084 0x0ccc  MRxDAV - ok
14:33:13.0116 0x0ccc  [ C7492026F6691A92C4508DDDB041CE4E, 98B05C6B7EE5FE4F4BFCFDB807612897E692B4C07524506EB84B318535076ADD ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
14:33:13.0174 0x0ccc  mrxsmb - ok
14:33:13.0207 0x0ccc  [ 34779EBCFEAB87A236B33C365A637144, B2091C423A4767CC0616B4385FF3B8AC2CBDBCC9BF82F2C79670CC1BC1E49A02 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:33:13.0229 0x0ccc  mrxsmb10 - ok
14:33:13.0244 0x0ccc  [ C34DE43FDAD9C32383BB4A5EE60126D4, 5F82D803ABB2817D9384D87435849A5EEE946B1C431348F26FA0220262DB1798 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:33:13.0283 0x0ccc  mrxsmb20 - ok
14:33:13.0335 0x0ccc  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
14:33:13.0373 0x0ccc  msahci - ok
14:33:13.0385 0x0ccc  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
14:33:13.0406 0x0ccc  msdsm - ok
14:33:13.0430 0x0ccc  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC           C:\Windows\System32\msdtc.exe
14:33:13.0474 0x0ccc  MSDTC - ok
14:33:13.0494 0x0ccc  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
14:33:13.0548 0x0ccc  Msfs - ok
14:33:13.0557 0x0ccc  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
14:33:13.0598 0x0ccc  mshidkmdf - ok
14:33:13.0610 0x0ccc  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
14:33:13.0627 0x0ccc  msisadrv - ok
14:33:13.0690 0x0ccc  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
14:33:13.0734 0x0ccc  MSiSCSI - ok
14:33:13.0742 0x0ccc  msiserver - ok
14:33:13.0780 0x0ccc  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
14:33:13.0832 0x0ccc  MSKSSRV - ok
14:33:13.0852 0x0ccc  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
14:33:13.0920 0x0ccc  MSPCLOCK - ok
14:33:13.0931 0x0ccc  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
14:33:13.0968 0x0ccc  MSPQM - ok
14:33:13.0988 0x0ccc  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
14:33:14.0006 0x0ccc  MsRPC - ok
14:33:14.0014 0x0ccc  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
14:33:14.0028 0x0ccc  mssmbios - ok
14:33:14.0043 0x0ccc  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
14:33:14.0074 0x0ccc  MSTEE - ok
14:33:14.0087 0x0ccc  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
14:33:14.0130 0x0ccc  MTConfig - ok
14:33:14.0149 0x0ccc  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup             C:\Windows\system32\Drivers\mup.sys
14:33:14.0168 0x0ccc  Mup - ok
14:33:14.0218 0x0ccc  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
14:33:14.0283 0x0ccc  napagent - ok
14:33:14.0384 0x0ccc  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
14:33:14.0413 0x0ccc  NativeWifiP - ok
14:33:14.0473 0x0ccc  [ 9804FB2E46077F2977552347DFCA7E05, A34B703462C6998AB2B3EA6389F4B89616CDC257D44C400C92663E6FB4A8F196 ] NDIS            C:\Windows\system32\drivers\ndis.sys
14:33:14.0511 0x0ccc  NDIS - ok
14:33:14.0521 0x0ccc  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
14:33:14.0552 0x0ccc  NdisCap - ok
14:33:14.0571 0x0ccc  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
14:33:14.0599 0x0ccc  NdisTapi - ok
14:33:14.0612 0x0ccc  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
14:33:14.0643 0x0ccc  Ndisuio - ok
14:33:14.0655 0x0ccc  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
14:33:14.0691 0x0ccc  NdisWan - ok
14:33:14.0701 0x0ccc  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
14:33:14.0733 0x0ccc  NDProxy - ok
14:33:14.0772 0x0ccc  [ 69C503C004F49AEE8B8E3067CC047BA7, 0E7A2FB0CC7669E6400EDA4D2220BBB1A85CF3D3529739DA5AE2C073FFA08313 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
14:33:14.0781 0x0ccc  Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
14:33:17.0168 0x0ccc  Detect skipped due to KSN trusted
14:33:17.0168 0x0ccc  Net Driver HPZ12 - ok
14:33:17.0188 0x0ccc  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
14:33:17.0227 0x0ccc  NetBIOS - ok
14:33:17.0243 0x0ccc  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
14:33:17.0278 0x0ccc  NetBT - ok
14:33:17.0287 0x0ccc  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] Netlogon        C:\Windows\system32\lsass.exe
14:33:17.0304 0x0ccc  Netlogon - ok
14:33:17.0344 0x0ccc  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
14:33:17.0385 0x0ccc  Netman - ok
14:33:17.0411 0x0ccc  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:33:17.0445 0x0ccc  NetMsmqActivator - ok
14:33:17.0452 0x0ccc  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:33:17.0472 0x0ccc  NetPipeActivator - ok
14:33:17.0492 0x0ccc  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
14:33:17.0538 0x0ccc  netprofm - ok
14:33:17.0550 0x0ccc  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:33:17.0570 0x0ccc  NetTcpActivator - ok
14:33:17.0580 0x0ccc  [ 6EEEA0E79B5BD1163740B53B96A1F1E4, A1218ED6F92A65F69F4A1E4ED96D61D27DA2992A72F675C51457BE4205D5C0DC ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:33:17.0599 0x0ccc  NetTcpPortSharing - ok
14:33:17.0629 0x0ccc  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
14:33:17.0645 0x0ccc  nfrd960 - ok
14:33:17.0678 0x0ccc  [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc          C:\Windows\System32\nlasvc.dll
14:33:17.0707 0x0ccc  NlaSvc - ok
14:33:17.0723 0x0ccc  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
14:33:17.0755 0x0ccc  Npfs - ok
14:33:17.0766 0x0ccc  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi             C:\Windows\system32\nsisvc.dll
14:33:17.0798 0x0ccc  nsi - ok
14:33:17.0808 0x0ccc  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
14:33:17.0839 0x0ccc  nsiproxy - ok
14:33:17.0914 0x0ccc  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
14:33:17.0967 0x0ccc  Ntfs - ok
14:33:17.0982 0x0ccc  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
14:33:18.0015 0x0ccc  Null - ok
14:33:18.0045 0x0ccc  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
14:33:18.0062 0x0ccc  nvraid - ok
14:33:18.0069 0x0ccc  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
14:33:18.0087 0x0ccc  nvstor - ok
14:33:18.0111 0x0ccc  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
14:33:18.0127 0x0ccc  nv_agp - ok
14:33:18.0147 0x0ccc  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
14:33:18.0166 0x0ccc  ohci1394 - ok
14:33:18.0196 0x0ccc  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
14:33:18.0230 0x0ccc  p2pimsvc - ok
14:33:18.0250 0x0ccc  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
14:33:18.0331 0x0ccc  p2psvc - ok
14:33:18.0355 0x0ccc  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport         C:\Windows\system32\DRIVERS\parport.sys
14:33:18.0374 0x0ccc  Parport - ok
14:33:18.0382 0x0ccc  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
14:33:18.0399 0x0ccc  partmgr - ok
14:33:18.0411 0x0ccc  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
14:33:18.0427 0x0ccc  Parvdm - ok
14:33:18.0464 0x0ccc  [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc          C:\Windows\System32\pcasvc.dll
14:33:18.0489 0x0ccc  PcaSvc - ok
14:33:18.0496 0x0ccc  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci             C:\Windows\system32\drivers\pci.sys
14:33:18.0515 0x0ccc  pci - ok
14:33:18.0523 0x0ccc  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
14:33:18.0538 0x0ccc  pciide - ok
14:33:18.0554 0x0ccc  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
14:33:18.0573 0x0ccc  pcmcia - ok
14:33:18.0583 0x0ccc  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw             C:\Windows\system32\drivers\pcw.sys
14:33:18.0598 0x0ccc  pcw - ok
14:33:18.0634 0x0ccc  [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
14:33:18.0670 0x0ccc  PEAUTH - ok
14:33:18.0738 0x0ccc  [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
14:33:18.0805 0x0ccc  PeerDistSvc - ok
14:33:18.0890 0x0ccc  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla             C:\Windows\system32\pla.dll
14:33:18.0978 0x0ccc  pla - ok
14:33:19.0017 0x0ccc  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
14:33:19.0055 0x0ccc  PlugPlay - ok
14:33:19.0069 0x0ccc  [ 12B4549D515CB26BB8D375038017CA65, B09ED2BED994D2B04862BBF62EF56F110235D3489D3B1762432F22A3A8F97BB8 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
14:33:19.0078 0x0ccc  Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
14:33:21.0541 0x0ccc  Detect skipped due to KSN trusted
14:33:21.0541 0x0ccc  Pml Driver HPZ12 - ok
14:33:21.0568 0x0ccc  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
14:33:21.0587 0x0ccc  PNRPAutoReg - ok
14:33:21.0613 0x0ccc  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
14:33:21.0639 0x0ccc  PNRPsvc - ok
14:33:21.0672 0x0ccc  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
14:33:21.0713 0x0ccc  PolicyAgent - ok
14:33:21.0729 0x0ccc  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power           C:\Windows\system32\umpo.dll
14:33:21.0765 0x0ccc  Power - ok
14:33:21.0783 0x0ccc  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
14:33:21.0815 0x0ccc  PptpMiniport - ok
14:33:21.0838 0x0ccc  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor       C:\Windows\system32\drivers\processr.sys
14:33:21.0855 0x0ccc  Processor - ok
14:33:21.0882 0x0ccc  [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc         C:\Windows\system32\profsvc.dll
14:33:21.0913 0x0ccc  ProfSvc - ok
14:33:21.0920 0x0ccc  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] ProtectedStorage C:\Windows\system32\lsass.exe
14:33:21.0937 0x0ccc  ProtectedStorage - ok
14:33:21.0951 0x0ccc  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
14:33:21.0987 0x0ccc  Psched - ok
14:33:22.0043 0x0ccc  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\drivers\ql2300.sys
14:33:22.0099 0x0ccc  ql2300 - ok
14:33:22.0122 0x0ccc  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
14:33:22.0139 0x0ccc  ql40xx - ok
14:33:22.0166 0x0ccc  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE           C:\Windows\system32\qwave.dll
14:33:22.0201 0x0ccc  QWAVE - ok
14:33:22.0215 0x0ccc  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
14:33:22.0236 0x0ccc  QWAVEdrv - ok
14:33:22.0253 0x0ccc  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
14:33:22.0283 0x0ccc  RasAcd - ok
14:33:22.0307 0x0ccc  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
14:33:22.0339 0x0ccc  RasAgileVpn - ok
14:33:22.0351 0x0ccc  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto         C:\Windows\System32\rasauto.dll
14:33:22.0388 0x0ccc  RasAuto - ok
14:33:22.0401 0x0ccc  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
14:33:22.0438 0x0ccc  Rasl2tp - ok
14:33:22.0467 0x0ccc  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
14:33:22.0506 0x0ccc  RasMan - ok
14:33:22.0525 0x0ccc  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
14:33:22.0558 0x0ccc  RasPppoe - ok
14:33:22.0564 0x0ccc  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
14:33:22.0594 0x0ccc  RasSstp - ok
14:33:22.0612 0x0ccc  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
14:33:22.0651 0x0ccc  rdbss - ok
14:33:22.0664 0x0ccc  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
14:33:22.0682 0x0ccc  rdpbus - ok
14:33:22.0692 0x0ccc  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
14:33:22.0721 0x0ccc  RDPCDD - ok
14:33:22.0744 0x0ccc  [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
14:33:22.0771 0x0ccc  RDPDR - ok
14:33:22.0780 0x0ccc  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
14:33:22.0811 0x0ccc  RDPENCDD - ok
14:33:22.0816 0x0ccc  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
14:33:22.0848 0x0ccc  RDPREFMP - ok
14:33:22.0905 0x0ccc  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
14:33:22.0947 0x0ccc  RdpVideoMiniport - ok
14:33:22.0965 0x0ccc  [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
14:33:22.0992 0x0ccc  RDPWD - ok
14:33:23.0013 0x0ccc  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
14:33:23.0032 0x0ccc  rdyboost - ok
14:33:23.0060 0x0ccc  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
14:33:23.0095 0x0ccc  RemoteAccess - ok
14:33:23.0116 0x0ccc  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
14:33:23.0154 0x0ccc  RemoteRegistry - ok
14:33:23.0175 0x0ccc  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
14:33:23.0210 0x0ccc  RpcEptMapper - ok
14:33:23.0224 0x0ccc  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
14:33:23.0242 0x0ccc  RpcLocator - ok
14:33:23.0266 0x0ccc  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs           C:\Windows\system32\rpcss.dll
14:33:23.0308 0x0ccc  RpcSs - ok
14:33:23.0338 0x0ccc  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
14:33:23.0371 0x0ccc  rspndr - ok
14:33:23.0399 0x0ccc  [ 6A2586DCB5B04A52404699EB325DF1DB, 07EA046410E23C3CCBCA20EBD187D4B5C1E1480359654FEB756EDFAAA8FFEAFD ] RTL8167         C:\Windows\system32\DRIVERS\Rt86win7.sys
14:33:23.0427 0x0ccc  RTL8167 - ok
14:33:23.0445 0x0ccc  [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
14:33:23.0460 0x0ccc  s3cap - ok
14:33:23.0470 0x0ccc  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] SamSs           C:\Windows\system32\lsass.exe
14:33:23.0488 0x0ccc  SamSs - ok
14:33:23.0515 0x0ccc  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
14:33:23.0533 0x0ccc  sbp2port - ok
14:33:23.0551 0x0ccc  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
14:33:23.0587 0x0ccc  SCardSvr - ok
14:33:23.0598 0x0ccc  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
14:33:23.0630 0x0ccc  scfilter - ok
14:33:23.0673 0x0ccc  [ 9060B8D5BCD5F2B019249F85E3D811F3, 7FB32AB7FE118462988321B9230074DAA960B587417EB463187539C3215445AE ] Schedule        C:\Windows\system32\schedsvc.dll
14:33:23.0732 0x0ccc  Schedule - ok
14:33:23.0769 0x0ccc  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc     C:\Windows\System32\certprop.dll
14:33:23.0805 0x0ccc  SCPolicySvc - ok
14:33:23.0823 0x0ccc  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
14:33:23.0859 0x0ccc  SDRSVC - ok
14:33:23.0882 0x0ccc  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
14:33:23.0905 0x0ccc  secdrv - ok
14:33:23.0925 0x0ccc  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
14:33:23.0960 0x0ccc  seclogon - ok
14:33:23.0987 0x0ccc  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\System32\sens.dll
14:33:24.0021 0x0ccc  SENS - ok
14:33:24.0035 0x0ccc  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
14:33:24.0063 0x0ccc  SensrSvc - ok
14:33:24.0084 0x0ccc  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
14:33:24.0099 0x0ccc  Serenum - ok
14:33:24.0109 0x0ccc  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
14:33:24.0127 0x0ccc  Serial - ok
14:33:24.0137 0x0ccc  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\drivers\sermouse.sys
14:33:24.0153 0x0ccc  sermouse - ok
14:33:24.0177 0x0ccc  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
14:33:24.0213 0x0ccc  SessionEnv - ok
14:33:24.0228 0x0ccc  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
14:33:24.0246 0x0ccc  sffdisk - ok
14:33:24.0254 0x0ccc  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
14:33:24.0272 0x0ccc  sffp_mmc - ok
14:33:24.0284 0x0ccc  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
14:33:24.0300 0x0ccc  sffp_sd - ok
14:33:24.0327 0x0ccc  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
14:33:24.0344 0x0ccc  sfloppy - ok
14:33:24.0366 0x0ccc  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
14:33:24.0409 0x0ccc  SharedAccess - ok
14:33:24.0433 0x0ccc  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:33:24.0476 0x0ccc  ShellHWDetection - ok
14:33:24.0501 0x0ccc  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
14:33:24.0517 0x0ccc  sisagp - ok
14:33:24.0531 0x0ccc  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
14:33:24.0546 0x0ccc  SiSRaid2 - ok
14:33:24.0557 0x0ccc  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
14:33:24.0573 0x0ccc  SiSRaid4 - ok
14:33:24.0587 0x0ccc  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
14:33:24.0621 0x0ccc  Smb - ok
14:33:24.0649 0x0ccc  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
14:33:24.0668 0x0ccc  SNMPTRAP - ok
14:33:24.0689 0x0ccc  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr           C:\Windows\system32\drivers\spldr.sys
14:33:24.0702 0x0ccc  spldr - ok
14:33:24.0732 0x0ccc  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler         C:\Windows\System32\spoolsv.exe
14:33:24.0768 0x0ccc  Spooler - ok
14:33:24.0871 0x0ccc  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
14:33:25.0008 0x0ccc  sppsvc - ok
14:33:25.0030 0x0ccc  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify     C:\Windows\system32\sppuinotify.dll
14:33:25.0064 0x0ccc  sppuinotify - ok
14:33:25.0093 0x0ccc  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv             C:\Windows\system32\DRIVERS\srv.sys
14:33:25.0124 0x0ccc  srv - ok
14:33:25.0147 0x0ccc  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
14:33:25.0174 0x0ccc  srv2 - ok
14:33:25.0184 0x0ccc  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
14:33:25.0202 0x0ccc  srvnet - ok
14:33:25.0232 0x0ccc  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
14:33:25.0270 0x0ccc  SSDPSRV - ok
14:33:25.0282 0x0ccc  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
14:33:25.0316 0x0ccc  SstpSvc - ok
14:33:25.0337 0x0ccc  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\drivers\stexstor.sys
14:33:25.0351 0x0ccc  stexstor - ok
14:33:25.0379 0x0ccc  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
14:33:25.0418 0x0ccc  StiSvc - ok
14:33:25.0449 0x0ccc  [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
14:33:25.0464 0x0ccc  storflt - ok
14:33:25.0489 0x0ccc  [ 0BF669F0A910BEDA4A32258D363AF2A5, 83EEBACDE4F69A2866B69CAA633F5C8B3CB01D88CEDB01B6EA5988E0A25CEE47 ] StorSvc         C:\Windows\system32\storsvc.dll
14:33:25.0520 0x0ccc  StorSvc - ok
14:33:25.0536 0x0ccc  [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
14:33:25.0550 0x0ccc  storvsc - ok
14:33:25.0574 0x0ccc  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
14:33:25.0589 0x0ccc  swenum - ok
14:33:25.0617 0x0ccc  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv           C:\Windows\System32\swprv.dll
14:33:25.0662 0x0ccc  swprv - ok
14:33:25.0717 0x0ccc  [ 4EE25AC85AFC3FD67D9F57ECDF566FF2, F1BFF1FB655F31B97FA9C6A49D433EFD33D8A35F6B28B4D83E45C27A05A86228 ] SysMain         C:\Windows\system32\sysmain.dll
14:33:25.0790 0x0ccc  SysMain - ok
14:33:25.0804 0x0ccc  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
14:33:25.0829 0x0ccc  TabletInputService - ok
14:33:25.0846 0x0ccc  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv         C:\Windows\System32\tapisrv.dll
14:33:25.0886 0x0ccc  TapiSrv - ok
14:33:25.0909 0x0ccc  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS             C:\Windows\System32\tbssvc.dll
14:33:25.0945 0x0ccc  TBS - ok
14:33:26.0002 0x0ccc  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
14:33:26.0059 0x0ccc  Tcpip - ok
14:33:26.0101 0x0ccc  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
14:33:26.0156 0x0ccc  TCPIP6 - ok
14:33:26.0167 0x0ccc  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
14:33:26.0183 0x0ccc  tcpipreg - ok
14:33:26.0199 0x0ccc  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
14:33:26.0227 0x0ccc  TDPIPE - ok
14:33:26.0234 0x0ccc  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
14:33:26.0251 0x0ccc  TDTCP - ok
14:33:26.0288 0x0ccc  [ BB8817D0508DD5EA69C770C8DEF5AB67, C55671524EEF6E16BBCC92556E83FD1D6457E707EA9330FC1CDD28FB11D99B77 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
14:33:26.0305 0x0ccc  tdx - ok
14:33:26.0548 0x0ccc  [ 2AA61246A5B813C1B12BCCFAA6F23DD8, 74EE3DB839A0F4BC781294803281DB2248D013B8808FF05F2EE9597C14C6FEED ] TeamViewer      C:\Program Files\TeamViewer\TeamViewer_Service.exe
14:33:26.0743 0x0ccc  TeamViewer - ok
14:33:26.0778 0x0ccc  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
14:33:26.0793 0x0ccc  TermDD - ok
14:33:26.0837 0x0ccc  [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService     C:\Windows\System32\termsrv.dll
14:33:26.0883 0x0ccc  TermService - ok
14:33:26.0905 0x0ccc  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
14:33:26.0927 0x0ccc  Themes - ok
14:33:26.0954 0x0ccc  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER     C:\Windows\system32\mmcss.dll
14:33:26.0987 0x0ccc  THREADORDER - ok
14:33:27.0013 0x0ccc  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
14:33:27.0049 0x0ccc  TrkWks - ok
14:33:27.0095 0x0ccc  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:33:27.0130 0x0ccc  TrustedInstaller - ok
14:33:27.0172 0x0ccc  [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
14:33:27.0188 0x0ccc  tssecsrv - ok
14:33:27.0243 0x0ccc  [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
14:33:27.0282 0x0ccc  TsUsbFlt - ok
14:33:27.0303 0x0ccc  [ 7E6E0797EB91F1D63641058416044313, 3A681A337DFCE9108B73CC4707462114E8D534C52BF8C8E226C0B31326FF24D5 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
14:33:27.0320 0x0ccc  TsUsbGD - ok
14:33:27.0402 0x0ccc  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
14:33:27.0437 0x0ccc  tunnel - ok
14:33:27.0458 0x0ccc  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
14:33:27.0473 0x0ccc  uagp35 - ok
14:33:27.0507 0x0ccc  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
14:33:27.0544 0x0ccc  udfs - ok
14:33:27.0576 0x0ccc  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect       C:\Windows\system32\UI0Detect.exe
14:33:27.0595 0x0ccc  UI0Detect - ok
14:33:27.0633 0x0ccc  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
14:33:27.0648 0x0ccc  uliagpkx - ok
14:33:27.0670 0x0ccc  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
14:33:27.0688 0x0ccc  umbus - ok
14:33:27.0703 0x0ccc  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\drivers\umpass.sys
14:33:27.0720 0x0ccc  UmPass - ok
14:33:27.0753 0x0ccc  [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService    C:\Windows\System32\umrdp.dll
14:33:27.0775 0x0ccc  UmRdpService - ok
14:33:27.0798 0x0ccc  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
14:33:27.0840 0x0ccc  upnphost - ok
14:33:27.0868 0x0ccc  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
14:33:27.0896 0x0ccc  usbccgp - ok
14:33:27.0915 0x0ccc  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
14:33:27.0946 0x0ccc  usbcir - ok
14:33:27.0956 0x0ccc  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
14:33:27.0972 0x0ccc  usbehci - ok
14:33:27.0990 0x0ccc  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
14:33:28.0014 0x0ccc  usbhub - ok
14:33:28.0028 0x0ccc  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
14:33:28.0043 0x0ccc  usbohci - ok
14:33:28.0073 0x0ccc  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
14:33:28.0091 0x0ccc  usbprint - ok
14:33:28.0125 0x0ccc  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
14:33:28.0153 0x0ccc  usbscan - ok
14:33:28.0165 0x0ccc  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:33:28.0192 0x0ccc  USBSTOR - ok
14:33:28.0197 0x0ccc  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
14:33:28.0213 0x0ccc  usbuhci - ok
14:33:28.0232 0x0ccc  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms           C:\Windows\System32\uxsms.dll
14:33:28.0266 0x0ccc  UxSms - ok
14:33:28.0278 0x0ccc  [ 5111FA6EC341BACC07FA69AA9764B6D2, ACF4095EE673AFAF9FDDE9E8EFA191A4A72BAA0371A3AD26925EA267E0E40E61 ] VaultSvc        C:\Windows\system32\lsass.exe
14:33:28.0294 0x0ccc  VaultSvc - ok
14:33:28.0321 0x0ccc  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
14:33:28.0335 0x0ccc  vdrvroot - ok
14:33:28.0366 0x0ccc  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds             C:\Windows\System32\vds.exe
14:33:28.0415 0x0ccc  vds - ok
14:33:28.0429 0x0ccc  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
14:33:28.0448 0x0ccc  vga - ok
14:33:28.0454 0x0ccc  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave         C:\Windows\System32\drivers\vga.sys
14:33:28.0485 0x0ccc  VgaSave - ok
14:33:28.0502 0x0ccc  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
14:33:28.0522 0x0ccc  vhdmp - ok
14:33:28.0552 0x0ccc  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
14:33:28.0567 0x0ccc  viaagp - ok
14:33:28.0584 0x0ccc  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7           C:\Windows\system32\drivers\viac7.sys
14:33:28.0602 0x0ccc  ViaC7 - ok
14:33:28.0617 0x0ccc  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
14:33:28.0632 0x0ccc  viaide - ok
14:33:28.0662 0x0ccc  [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus           C:\Windows\system32\drivers\vmbus.sys
14:33:28.0682 0x0ccc  vmbus - ok
14:33:28.0687 0x0ccc  [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
14:33:28.0705 0x0ccc  VMBusHID - ok
14:33:28.0730 0x0ccc  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
14:33:28.0745 0x0ccc  volmgr - ok
14:33:28.0764 0x0ccc  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
14:33:28.0787 0x0ccc  volmgrx - ok
14:33:28.0799 0x0ccc  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
14:33:28.0822 0x0ccc  volsnap - ok
14:33:28.0842 0x0ccc  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
14:33:28.0860 0x0ccc  vsmraid - ok
14:33:28.0912 0x0ccc  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS             C:\Windows\system32\vssvc.exe
14:33:28.0977 0x0ccc  VSS - ok
14:33:28.0989 0x0ccc  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
14:33:29.0007 0x0ccc  vwifibus - ok
14:33:29.0047 0x0ccc  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time         C:\Windows\system32\w32time.dll
14:33:29.0090 0x0ccc  W32Time - ok
14:33:29.0098 0x0ccc  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
14:33:29.0115 0x0ccc  WacomPen - ok
14:33:29.0143 0x0ccc  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
14:33:29.0174 0x0ccc  WANARP - ok
14:33:29.0178 0x0ccc  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
14:33:29.0209 0x0ccc  Wanarpv6 - ok
14:33:29.0259 0x0ccc  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
14:33:29.0336 0x0ccc  wbengine - ok
14:33:29.0361 0x0ccc  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
14:33:29.0389 0x0ccc  WbioSrvc - ok
14:33:29.0416 0x0ccc  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc         C:\Windows\System32\wcncsvc.dll
14:33:29.0447 0x0ccc  wcncsvc - ok
14:33:29.0458 0x0ccc  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:33:29.0488 0x0ccc  WcsPlugInService - ok
14:33:29.0511 0x0ccc  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\drivers\wd.sys
14:33:29.0526 0x0ccc  Wd - ok
14:33:29.0560 0x0ccc  [ CF68C54937BACCC0DA9A056FFA2A3988, 4D1FD6CEDA7A00D8F496916F6EE127B41C8875585C9AECAEBB0FC1B6F5E1312F ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
14:33:29.0594 0x0ccc  Wdf01000 - ok
14:33:29.0621 0x0ccc  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost  C:\Windows\system32\wdi.dll
14:33:29.0645 0x0ccc  WdiServiceHost - ok
14:33:29.0650 0x0ccc  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost   C:\Windows\system32\wdi.dll
14:33:29.0671 0x0ccc  WdiSystemHost - ok
14:33:29.0701 0x0ccc  [ 55C70654420DBF429604FD567E6F3CD3, 22191B049BCA76EF13AEDF8078E452E6B35E998A75AD63F14C542B541EA9F67D ] WebClient       C:\Windows\System32\webclnt.dll
14:33:29.0736 0x0ccc  WebClient - ok
14:33:29.0770 0x0ccc  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
14:33:29.0808 0x0ccc  Wecsvc - ok
14:33:29.0819 0x0ccc  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
14:33:29.0853 0x0ccc  wercplsupport - ok
14:33:29.0870 0x0ccc  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
14:33:29.0906 0x0ccc  WerSvc - ok
14:33:29.0933 0x0ccc  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
14:33:29.0966 0x0ccc  WfpLwf - ok
14:33:29.0977 0x0ccc  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
14:33:29.0991 0x0ccc  WIMMount - ok
14:33:30.0039 0x0ccc  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
14:33:30.0082 0x0ccc  WinDefend - ok
14:33:30.0094 0x0ccc  WinHttpAutoProxySvc - ok
14:33:30.0134 0x0ccc  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
14:33:30.0169 0x0ccc  Winmgmt - ok
14:33:30.0230 0x0ccc  [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM           C:\Windows\system32\WsmSvc.dll
14:33:30.0303 0x0ccc  WinRM - ok
14:33:30.0348 0x0ccc  [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
14:33:30.0370 0x0ccc  WinUsb - ok
14:33:30.0412 0x0ccc  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc         C:\Windows\System32\wlansvc.dll
14:33:30.0463 0x0ccc  Wlansvc - ok
14:33:30.0563 0x0ccc  [ 5E7C103F8475C4289847D15E129C20F7, C6325D3557545FA1DA26B0B1EA9A1C95AED1FA84A93BE29A771DAD9ECB00768B ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
14:33:30.0630 0x0ccc  wlidsvc - ok
14:33:30.0655 0x0ccc  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
14:33:30.0672 0x0ccc  WmiAcpi - ok
14:33:30.0698 0x0ccc  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
14:33:30.0720 0x0ccc  wmiApSrv - ok
14:33:30.0788 0x0ccc  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
14:33:30.0851 0x0ccc  WMPNetworkSvc - ok
14:33:30.0881 0x0ccc  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
14:33:30.0902 0x0ccc  WPCSvc - ok
14:33:30.0913 0x0ccc  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
14:33:30.0949 0x0ccc  WPDBusEnum - ok
14:33:30.0996 0x0ccc  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
14:33:31.0028 0x0ccc  ws2ifsl - ok
14:33:31.0038 0x0ccc  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\System32\wscsvc.dll
14:33:31.0061 0x0ccc  wscsvc - ok
14:33:31.0066 0x0ccc  WSearch - ok
14:33:31.0159 0x0ccc  [ 621DEDFB22B3F6F8CD3B2BBA54901A13, 80792978B1BDB89DB83265BF7224AC4B93510054F5914CBD733D221C8540A17D ] wuauserv        C:\Windows\system32\wuaueng.dll
14:33:31.0301 0x0ccc  wuauserv - ok
14:33:31.0322 0x0ccc  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
14:33:31.0346 0x0ccc  WudfPf - ok
14:33:31.0374 0x0ccc  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
14:33:31.0394 0x0ccc  WUDFRd - ok
14:33:31.0426 0x0ccc  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
14:33:31.0447 0x0ccc  wudfsvc - ok
14:33:31.0475 0x0ccc  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc         C:\Windows\System32\wwansvc.dll
14:33:31.0503 0x0ccc  WwanSvc - ok
14:33:31.0525 0x0ccc  ================ Scan global ===============================
14:33:31.0555 0x0ccc  [ 5E7C5DE85AF978495C3A9A0B720B9811, 142CDEBED78E3BAEE8D2DBF6A97CE26313932024010548EC2E570CAE480AF7C3 ] C:\Windows\system32\basesrv.dll
14:33:31.0585 0x0ccc  [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll
14:33:31.0599 0x0ccc  [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll
14:33:31.0621 0x0ccc  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
14:33:31.0650 0x0ccc  [ 0780A42DBD7D9969F9BF4A19AA4285B5, 8EA41124A4E97732C5DAA616457FBA7111CB38986F3427FA776ED00BC1407171 ] C:\Windows\system32\services.exe
14:33:31.0659 0x0ccc  [ Global ] - ok
14:33:31.0660 0x0ccc  ================ Scan MBR ==================================
14:33:31.0667 0x0ccc  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
14:33:31.0874 0x0ccc  \Device\Harddisk0\DR0 - ok
14:33:31.0874 0x0ccc  ================ Scan VBR ==================================
14:33:31.0876 0x0ccc  [ 213A3DF601CB3B3C582A07A259C6ACF8 ] \Device\Harddisk0\DR0\Partition1
14:33:31.0907 0x0ccc  \Device\Harddisk0\DR0\Partition1 - ok
14:33:31.0912 0x0ccc  [ 046E1F73AB2B18E72E12AF8743673AD1 ] \Device\Harddisk0\DR0\Partition2
14:33:31.0965 0x0ccc  \Device\Harddisk0\DR0\Partition2 - ok
14:33:31.0966 0x0ccc  ================ Scan generic autorun ======================
14:33:32.0014 0x0ccc  [ 7E7194AFFA4A6D1DE2FD8EED5537BCA0, 3669F88C63DAFA39DBDDE26029E3E7D84EDA2E2A7A8E216C424A5DD0934E29EA ] C:\Windows\system32\igfxtray.exe
14:33:32.0040 0x0ccc  IgfxTray - ok
14:33:32.0054 0x0ccc  [ C7BAB79AF0C5F2DB086B20E6E75D02CA, 76F8242AC01B4A9B209C930E9B1537C297E7C63EA4018E3992CF417A0D8B4ACF ] C:\Windows\system32\hkcmd.exe
14:33:32.0077 0x0ccc  HotKeysCmds - ok
14:33:32.0088 0x0ccc  [ 91841850DF96658EA287F9705A0211F1, D5E7850DE9912DBBA71A9A5C33046D9D4F8F97337BFA8315DB3DE0FE627D3E1D ] C:\Windows\system32\igfxpers.exe
14:33:32.0120 0x0ccc  Persistence - ok
14:33:32.0511 0x0ccc  [ D72ABA21ABB9314DA878FB9760E7A4C2, 90E3892B4070A6265CE8AB33115EEBED7D61F6FDB836B5EB1972BE7DD30E21F0 ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
14:33:32.0970 0x0ccc  RtHDVCpl - ok
14:33:33.0022 0x0ccc  [ 5514B64F7F2D25E09E2FDAF5D62B688C, 43263715ADC49250762A01E41DB2832C6A8B63CE4F66CDD8FC0B51DCA031DF27 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
14:33:33.0035 0x0ccc  IAStorIcon - ok
14:33:33.0152 0x0ccc  [ 0DB20318CEB155799880FEC174988933, 3840A7C9DF01F118048E806D71BDC5686A8FCF316FB35E65045988B0271532D8 ] C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
14:33:33.0243 0x0ccc  GDFirewallTray - ok
14:33:33.0377 0x0ccc  [ 2110F60508EA102B5B4B85A9307C34E5, A4DC5AAA01B066ACF0AB61CC20F77030EE6B494247A1C0653CDE987D46B97C9E ] C:\Program Files\HP\HP Color LaserJet CM1312 MFP Series\hppfaxprintersrv.exe
14:33:33.0469 0x0ccc  HP Color LaserJet CM1312 MFP Series Fax - detected UnsignedFile.Multi.Generic ( 1 )
14:33:35.0859 0x0ccc  Detect skipped due to KSN trusted
14:33:35.0859 0x0ccc  HP Color LaserJet CM1312 MFP Series Fax - ok
14:33:35.0910 0x0ccc  [ 34D296AFC913E302953C70463EF09A48, BC413307CBC56C039EE8A05B51A56E14EF59678FBB33815AEB320078056C8CE7 ] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
14:33:35.0939 0x0ccc  HP Software Update - ok
14:33:36.0004 0x0ccc  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
14:33:36.0067 0x0ccc  Sidebar - ok
14:33:36.0092 0x0ccc  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
14:33:36.0132 0x0ccc  mctadmin - ok
14:33:36.0186 0x0ccc  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
14:33:36.0240 0x0ccc  Sidebar - ok
14:33:36.0247 0x0ccc  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
14:33:36.0272 0x0ccc  mctadmin - ok
14:33:36.0480 0x0ccc  [ EE526B0428581B57FFC571FF57309E28, 1CF4DD251E78F2B67C4B1973E3378D6B87C5698EEC398CA4043621842ACC426C ] C:\Program Files\CCleaner\CCleaner.exe
14:33:36.0710 0x0ccc  CCleaner Monitoring - ok
14:33:36.0718 0x0ccc  Waiting for KSN requests completion. In queue: 176
14:33:37.0718 0x0ccc  Waiting for KSN requests completion. In queue: 176
14:33:38.0718 0x0ccc  Waiting for KSN requests completion. In queue: 6
14:33:39.0750 0x0ccc  AV detected via SS2: G DATA INTERNET SECURITY, C:\Program Files\G DATA\InternetSecurity\AVK\avkwscpe.exe ( 25.1.0.0 ), 0x41000 ( enabled : updated )
14:33:39.0752 0x0ccc  FW detected via SS2: G*DATA Personal Firewall, C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe ( 22.0.0.1 ), 0x41010 ( enabled )
14:33:42.0195 0x0ccc  ============================================================
14:33:42.0195 0x0ccc  Scan finished
14:33:42.0195 0x0ccc  ============================================================
14:33:42.0205 0x13c4  Detected object count: 0
14:33:42.0205 0x13c4  Actual detected object count: 0
         

Alt 14.11.2015, 14:42   #10
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Ich brauche die Original-Email. Schreib mir mal Deine via PM bitte.
__________________
Gruß
deeprybka

Lob, Kritik, Wünsche?

Spende fürs trojaner-board?
_______________________________________________
„Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer

Alt 14.11.2015, 15:05   #11
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



So, ist geschehen.

Um E-Mails unter einem gefaketen Absender zu verschicken, muss man wohl irgendwie verschiedene Mechanismen außer Kraft setzen können.
Ich habe (bin Programmierer) mal einen Client für eine Maschine programmiert, der Mails an den Benutzer sendet, wenn ein Job erledigt ist. Mails konnten jedoch, auch per Programmierung, nur abgeschickt werden, wenn die Absenderaddresse gültig war.

Alt 14.11.2015, 15:07   #12
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Zitat:
Zitat von WoF Beitrag anzeigen
Um E-Mails unter einem gefaketen Absender zu verschicken, muss man wohl irgendwie verschiedene Mechanismen außer Kraft setzen können.
Nein.
__________________
Gruß
deeprybka

Lob, Kritik, Wünsche?

Spende fürs trojaner-board?
_______________________________________________
„Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer

Alt 14.11.2015, 15:18   #13
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Hm. Wills gar nicht wissen, aber mit den Mitteln, die ich hatte (eine SMTP-Control) ging es nicht.

Alt 14.11.2015, 15:20   #14
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Bitte schick mir von seinem Account mal ne neue Email an die beiden angegeben Adressen.
__________________
Gruß
deeprybka

Lob, Kritik, Wünsche?

Spende fürs trojaner-board?
_______________________________________________
„Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer

Alt 14.11.2015, 15:33   #15
WoF
 
Schadsoftware versendet E-Mails - Standard

Schadsoftware versendet E-Mails



Ist geschehen.
Und nein, im "Gesendet"-Ordner kann ich die Mails nicht finden.

Antwort

Themen zu Schadsoftware versendet E-Mails
adresse, aktuelle, automatisch, bezüglich, browser, e-mail, eingefangen, erneut, frage, fragen, gen, guten, internet, link, neue, nicht mehr, problem, rechner, server, spyware, telekom, trojaner, verschickt, verschickt e-mails, versenden, woche, wochen




Ähnliche Themen: Schadsoftware versendet E-Mails


  1. PC versendet Spam Mails
    Log-Analyse und Auswertung - 05.11.2015 (9)
  2. Outlook versendet automatisch Mails
    Plagegeister aller Art und deren Bekämpfung - 22.10.2015 (18)
  3. Mails werden automatisch versendet
    Plagegeister aller Art und deren Bekämpfung - 15.10.2015 (9)
  4. Mails werden automatisch versendet
    Log-Analyse und Auswertung - 29.09.2015 (7)
  5. WIN 7 pro: PC versendet eigenständig mails
    Plagegeister aller Art und deren Bekämpfung - 25.09.2015 (3)
  6. Mail Acc versendet Spam Mails
    Plagegeister aller Art und deren Bekämpfung - 09.04.2014 (11)
  7. Mail Account versendet lt. Provider, Schadsoftware, wie z.B Viren oder Trojaner
    Log-Analyse und Auswertung - 09.02.2014 (1)
  8. von meinem Internet-Anschluss wird Schadsoftware versendet
    Log-Analyse und Auswertung - 06.10.2013 (9)
  9. E-Mails vom Mailaccount versendet worden
    Plagegeister aller Art und deren Bekämpfung - 12.09.2013 (5)
  10. Spam Mails - Mail delivery failed obwohl ich keine E-Mails versendet habe
    Plagegeister aller Art und deren Bekämpfung - 16.06.2013 (11)
  11. Outlook versendet selbstständig Mails
    Plagegeister aller Art und deren Bekämpfung - 04.01.2013 (35)
  12. Outlook versendet ungewollt e-Mails
    Plagegeister aller Art und deren Bekämpfung - 23.11.2012 (4)
  13. Virus? Yahoo versendet Mails
    Plagegeister aller Art und deren Bekämpfung - 21.10.2012 (11)
  14. PC versendet SPAM mails im hintergrund
    Log-Analyse und Auswertung - 16.07.2012 (15)
  15. web.de versendet selbständig Mails; evt. Trojaner eingefangen?
    Log-Analyse und Auswertung - 07.09.2011 (10)
  16. MSN hat selbstständig E-Mails an Kontakte versendet.
    Überwachung, Datenschutz und Spam - 28.03.2011 (22)
  17. Rechner versendet E-mails
    Log-Analyse und Auswertung - 13.02.2011 (13)

Zum Thema Schadsoftware versendet E-Mails - Guten Abend. Mein computer-unkundiger Nachbar hat mich gebeten, ihn bei einem Problem zu helfen, und auch wenn ich computerkundig bin, bin ich hier ratlos. Es handelt sich offenbar um eine - Schadsoftware versendet E-Mails...
Archiv
Du betrachtest: Schadsoftware versendet E-Mails auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.