|
Plagegeister aller Art und deren Bekämpfung: TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABYWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
16.02.2017, 21:10 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY Wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen, Infos folgen dann im Abschlussposting. Bitte JETZT nix mehr ohne Absprache installieren! 1. Schritt: Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers 2. Schritt: Kaspersky TDSS-Killer Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
16.02.2017, 22:04 | #17 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABYCode:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.02.16.12 rootkit: v2017.02.15.01 Windows 10 x64 NTFS Internet Explorer 11.576.14393.0 VerzehrendeSonne :: ROTEARMEE [administrator] 16.02.2017 21:46:53 mbar-log-2017-02-16 (21-46-53).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 306150 Time elapsed: 5 minute(s), 17 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter 21:59:58.0845 0x184c TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01 22:00:11.0721 0x184c ============================================================ 22:00:11.0721 0x184c Current date / time: 2017/02/16 22:00:11.0721 22:00:11.0721 0x184c SystemInfo: 22:00:11.0723 0x184c 22:00:11.0723 0x184c OS Version: 10.0.14393 ServicePack: 0.0 22:00:11.0723 0x184c Product type: Workstation 22:00:11.0723 0x184c ComputerName: ROTEARMEE 22:00:11.0723 0x184c UserName: VerzehrendeSonne 22:00:11.0723 0x184c Windows directory: C:\WINDOWS 22:00:11.0723 0x184c System windows directory: C:\WINDOWS 22:00:11.0723 0x184c Running under WOW64 22:00:11.0723 0x184c Processor architecture: Intel x64 22:00:11.0723 0x184c Number of processors: 4 22:00:11.0723 0x184c Page size: 0x1000 22:00:11.0723 0x184c Boot type: Normal boot 22:00:11.0723 0x184c CodeIntegrityOptions = 0x00000001 22:00:11.0723 0x184c ============================================================ 22:00:11.0815 0x184c KLMD registered as C:\WINDOWS\system32\drivers\43034010.sys 22:00:11.0815 0x184c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19 22:00:11.0930 0x184c System UUID: {527D9C31-4146-7AE4-A564-FC7B69B2CB19} 22:00:12.0337 0x184c Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:00:12.0338 0x184c Drive \Device\Harddisk1\DR1 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:00:12.0343 0x184c ============================================================ 22:00:12.0343 0x184c \Device\Harddisk0\DR0: 22:00:12.0343 0x184c MBR partitions: 22:00:12.0343 0x184c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1A13C000 22:00:12.0343 0x184c \Device\Harddisk1\DR1: 22:00:12.0343 0x184c GPT partitions: 22:00:12.0344 0x184c \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {8E8C9BC1-43D4-4A61-9C9B-49802601620D}, Name: Basic data partition, StartLBA 0x40800, BlocksNum 0xE8DC7800 22:00:12.0344 0x184c MBR partitions: 22:00:12.0344 0x184c ============================================================ 22:00:12.0345 0x184c C: <-> \Device\Harddisk0\DR0\Partition1 22:00:13.0005 0x184c D: <-> \Device\Harddisk1\DR1\Partition1 22:00:13.0005 0x184c ============================================================ 22:00:13.0005 0x184c Initialize success 22:00:13.0005 0x184c ============================================================ 22:01:14.0210 0x0730 ============================================================ 22:01:14.0210 0x0730 Scan started 22:01:14.0210 0x0730 Mode: Manual; SigCheck; TDLFS; 22:01:14.0210 0x0730 ============================================================ 22:01:14.0210 0x0730 KSN ping started 22:01:14.0525 0x0730 KSN ping finished: true 22:01:14.0942 0x0730 ================ Scan system memory ======================== 22:01:14.0942 0x0730 System memory - ok 22:01:14.0943 0x0730 ================ Scan services ============================= 22:01:14.0975 0x0730 [ A7901875F89D011C38CF52C98ACF5B29, 782141AB1DD7ACDE6EA08B5BAFDE8BADD05B81D38C18E097D6D9C46102056EB1 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys 22:01:15.0042 0x0730 1394ohci - ok 22:01:15.0050 0x0730 [ EE1CCC54F75C24727A218F98FC5349DA, 0B0D26640BFA0F551B7087027E572D0BF2C5EAF50A4187C5A7D839180B7FF589 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys 22:01:15.0066 0x0730 3ware - ok 22:01:15.0081 0x0730 [ 73C73E1AA0D4D727A04AAAB120B7F56A, 5D311F11022994410DF5C67914D38B1F0D813EFD181EA234750286A272D67A1A ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys 22:01:15.0106 0x0730 ACPI - ok 22:01:15.0109 0x0730 [ 0935496EF9624B46B935CB35ECE1F205, A22A2A29195505A65E8626D60B00C86C23E0CABC1EB8345EA5ED523516CC21C0 ] AcpiDev C:\WINDOWS\System32\drivers\AcpiDev.sys 22:01:15.0125 0x0730 AcpiDev - ok 22:01:15.0129 0x0730 [ D6794C31F4077B71433988787BAA926E, F16365C2F195AAE94D4740E6C3DF4C0CECEC6393CAD65425DCCD28CDBA6EC51A ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys 22:01:15.0143 0x0730 acpiex - ok 22:01:15.0146 0x0730 [ FE5F656D6B35089DA39112E74EC6A85A, 5D81EE63998232A5B36DE47FE15B9D04D5BD02234CA133A2462AECA8C60A22ED ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys 22:01:15.0161 0x0730 acpipagr - ok 22:01:15.0163 0x0730 [ 2F242941E4DFF69B883D77A16F039557, 45C388365317C720654A659A9326B2BC0E9D84929C704654985597D5D620101C ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys 22:01:15.0178 0x0730 AcpiPmi - ok 22:01:15.0180 0x0730 [ C247E35A21682DA8D0DC3AF9F025FCC5, 455415EE3166B3043AD8A4DD50B688DB74242267FB555642441251EFA823E971 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys 22:01:15.0194 0x0730 acpitime - ok 22:01:15.0199 0x0730 [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 22:01:15.0209 0x0730 AdobeARMservice - ok 22:01:15.0232 0x0730 [ 49B9DB97AFC85DCCBDACDAB2E90085B7, 2A6C2A09F74EA15044F442CCFB54A0F24F105ADB915E5C78F02F59652DC29152 ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS 22:01:15.0265 0x0730 ADP80XX - ok 22:01:15.0279 0x0730 [ 323AA1953ED9C01E23F740FA891FE064, 4CED6E3D61749316CDE28965C913E7ED462539DAAD637A29484F62AF47AD650D ] AFD C:\WINDOWS\system32\drivers\afd.sys 22:01:15.0303 0x0730 AFD - ok 22:01:15.0311 0x0730 [ 23522E5D581F7722B1B5B86737CAE39C, FB81ABD304376A1E87B65F5E1B34477B628CEDB2091C5D754DE97464B6050C5B ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys 22:01:15.0332 0x0730 ahcache - ok 22:01:15.0335 0x0730 [ D0905D4A945D01D4B28DB9E1BD5985F7, CF389CBCD3B99D1BAE34A42F723F1005C32213A394F691978076D3DF1727715C ] AJRouter C:\WINDOWS\System32\AJRouter.dll 22:01:15.0351 0x0730 AJRouter - ok 22:01:15.0355 0x0730 [ 8FD51B3B35707A66080D7C8CB05E792D, FE52F3DC280D208FDDC75F6E3294B8D601E0D86F9BD3DB1ACC8FC296AC74C23B ] ALG C:\WINDOWS\System32\alg.exe 22:01:15.0372 0x0730 ALG - ok 22:01:15.0377 0x0730 [ DF21E05E41E5AC3F13F304D91457649A, 7F48F2AD1DBE89A261113C76D7C23AD7D87D5599BCC31F8A558A8A10B81BF521 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys 22:01:15.0395 0x0730 AmdK8 - ok 22:01:15.0399 0x0730 [ 45D0AA4BB90B821DF92E8F19ABED0C5E, EA87A6E98DB3C5A88A844C04C6934E870B7004E783AA5211722115382A211B90 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys 22:01:15.0416 0x0730 AmdPPM - ok 22:01:15.0420 0x0730 [ 74FFBC43B4B899C9A8CA06A892F2CE73, 8D599363C7F3D373F1859BAA4D06DD0F40BE78B56BE52B74DE6EA6EF99452004 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys 22:01:15.0433 0x0730 amdsata - ok 22:01:15.0440 0x0730 [ AAB0F1D8D7E54761ABAB13AF161F1680, CF847990EFFA2828F5B1DB1A68F08A6C2C918E9612EDFFCF95C36BCABBBEA272 ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys 22:01:15.0457 0x0730 amdsbs - ok 22:01:15.0460 0x0730 [ F91BAAC4237C40352A807000F3B716F9, F7EFA08E5067C3D419C9D21EDB880BA08883A80DDF35F8B42EC3AB293FE5E03E ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys 22:01:15.0472 0x0730 amdxata - ok 22:01:15.0477 0x0730 [ BC121C099C6C659126AD2102AFDFF8CF, 42B5EE293BDD7ADCE48173A01B30D8452564B9DA225EAF25E9292FE77C0FCF3E ] AppID C:\WINDOWS\system32\drivers\appid.sys 22:01:15.0491 0x0730 AppID - ok 22:01:15.0496 0x0730 [ 74A24CF946279111D7F203B36569EC02, FD67D36804744B4FE3E20BA891852575E6C2DA6515643B2F4B4210118B0FCCDA ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll 22:01:15.0517 0x0730 AppIDSvc - ok 22:01:15.0521 0x0730 [ 73FAA5517CCD1332F00192A303CF2026, 75636222BFF381A3EECA010752DF7DC1603A395B91FF7FBF92127B5CA8EFFEE5 ] Appinfo C:\WINDOWS\System32\appinfo.dll 22:01:15.0540 0x0730 Appinfo - ok 22:01:15.0543 0x0730 [ 68190E2BADF23BD782344970E5B5DE9E, 95D30EC12C7FDF5822CED8BC2F17669A6687A2FB262B4F0D15C8DCFF4E9AB33D ] applockerfltr C:\WINDOWS\system32\drivers\applockerfltr.sys 22:01:15.0560 0x0730 applockerfltr - ok 22:01:15.0566 0x0730 [ 76A12AC673B0F8A607ACDD0583C247D4, CBC6C0EB82C7A8E3998344280BBB5A697AFA7206CA2BADFDA7ED6E7DD20E3DAC ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 22:01:15.0585 0x0730 AppMgmt - ok 22:01:15.0598 0x0730 [ A0746EF6C5AB7A17A67BC167167499C1, 1D2154D3AFC5219293EDD508C7726E7756FB72BF04F73861C575D1FE5C553411 ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll 22:01:15.0627 0x0730 AppReadiness - ok 22:01:15.0644 0x0730 [ 99CA3E622070FDBD7B75EB7E86B2DE40, 12BDD092667250EBC99B4D597897C1B2C83115CD83ECCDEAC36B2D9C9BEA77B6 ] AppVClient C:\WINDOWS\system32\AppVClient.exe 22:01:15.0672 0x0730 AppVClient - ok 22:01:15.0677 0x0730 [ B66ED2CB37F7E4696A51612AFBA08834, 70BA67AF7F1290E3145B873B53516F138E50D8AAC80CD00CBA66467ABC6643CB ] AppvStrm C:\WINDOWS\system32\drivers\AppvStrm.sys 22:01:15.0691 0x0730 AppvStrm - ok 22:01:15.0697 0x0730 [ 8DC924848E20F890BEFC6B31136D46BE, B7603425B4970F505B5A3EB0F6652A9CDD188059BDC945D6DF2BADC2DF8F4B5D ] AppvVemgr C:\WINDOWS\system32\drivers\AppvVemgr.sys 22:01:15.0711 0x0730 AppvVemgr - ok 22:01:15.0716 0x0730 [ 9ADC5A8BEE10E174F95349E9232D8E76, F322991323DCDC51199BB3AB0DA20F6C3CC7EE6E804400B473C610FDB895F0AE ] AppvVfs C:\WINDOWS\system32\drivers\AppvVfs.sys 22:01:15.0730 0x0730 AppvVfs - ok 22:01:15.0772 0x0730 [ D70B1453ADA82A92E76EAE72D936A0F6, 439DBC5818025887343D4B5B509C7D2C97ED0FFA4641A5178EA5719C50E5013F ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll 22:01:15.0846 0x0730 AppXSvc - ok 22:01:15.0853 0x0730 [ E6AB1F0B4C3D4E0D2A88332D76FECD03, 0D3003EB979DA4546DCDD055011E24F13E34F683F02C9801CAC564D1809F11D2 ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys 22:01:15.0867 0x0730 arcsas - ok 22:01:15.0870 0x0730 [ 61C5A480C43E7E8E49C42869F49D0D3E, E610F0E4315ABA1D90AD4A1D7A68ABA2ACBB7FCA89E9D1798470365D52592D55 ] AsyncMac C:\WINDOWS\System32\drivers\asyncmac.sys 22:01:15.0887 0x0730 AsyncMac - ok 22:01:15.0891 0x0730 [ A10F989A812B57B9695F6C305907C9C6, E2B292610079AA1A10696138DE8130905A8A834B75A8DED7EBF8B6732B77A0F4 ] atapi C:\WINDOWS\system32\drivers\atapi.sys 22:01:15.0902 0x0730 atapi - ok 22:01:15.0911 0x0730 [ 2DC3D53FFA0D10EB8C911AE2DB7BF4CF, 8E0A4B5D610D487A216E70396A99ACC1BEA12C46A6681B1A39CD0FD01EDD406A ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll 22:01:15.0935 0x0730 AudioEndpointBuilder - ok 22:01:15.0953 0x0730 [ 7B993290E7691C446C16A56A431669BA, 004551934E27E9FC1A939C9BD1DEB850A216CBED9B18CB3317920F5656D9F6BF ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll 22:01:15.0993 0x0730 Audiosrv - ok 22:01:15.0997 0x0730 avgsvc - ok 22:01:16.0002 0x0730 [ 6D90FDA2DC364B8EA1420F2F81585CC3, 10E6F23A213CFE49BE04BB7D366ADD4028D61D7114FEC67C30B5467DF6B36D4F ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll 22:01:16.0020 0x0730 AxInstSV - ok 22:01:16.0032 0x0730 [ 61BAC67048CA5C1D08C48FCC8012B613, 71B2A466FC38DA1029B471FBD2541D8FE359751A7B212AE0F420DB3645916450 ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys 22:01:16.0054 0x0730 b06bdrv - ok 22:01:16.0058 0x0730 [ 68F72B05EBC6D1779C0D60A147C7CA0B, AA1C857BEE34865C6B901157FC22570D4CF45D950708BAD7AA333F120F2B474C ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys 22:01:16.0075 0x0730 BasicDisplay - ok 22:01:16.0078 0x0730 [ 23156E7EDAF613D839E2839746B168D3, CAEF8F9C7D3A338BD747AC9D5BFBE730D77B911E87BCF532EBB75E1F80916AFA ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys 22:01:16.0093 0x0730 BasicRender - ok 22:01:16.0096 0x0730 [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn C:\WINDOWS\System32\drivers\bcmfn.sys 22:01:16.0111 0x0730 bcmfn - ok 22:01:16.0114 0x0730 [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys 22:01:16.0128 0x0730 bcmfn2 - ok 22:01:16.0137 0x0730 [ 2B4D3AEAAD02954F8C191BC2D67949AD, 8237C9AD556CFAF7442FF60F78608104BC17CE3134C89D986D49C38CC60B1518 ] BDESVC C:\WINDOWS\System32\bdesvc.dll 22:01:16.0161 0x0730 BDESVC - ok 22:01:16.0166 0x0730 [ 0A508274355745EEF01C6BE3198D02C4, E2DB08AEE2368FA95FDB357BB31EA4EBF31679C3E72E109DB3D7CD1B5F7B828E ] Beep C:\WINDOWS\system32\drivers\Beep.sys 22:01:16.0181 0x0730 Beep - ok 22:01:16.0197 0x0730 [ 5125CBB61AC81168366BEB290399CB8E, B2A3095D45E2114DE2BD0E5A3AE20B3CE95EE517A35B9E1EAD05E231F38DBDCF ] BFE C:\WINDOWS\System32\bfe.dll 22:01:16.0231 0x0730 BFE - ok 22:01:16.0253 0x0730 [ D876C567AB767258036F05E4766189FD, DE8BA67325CB64495BD454B8F9DDCAE82636253844FC68B360C7E1CF5D51DD0E ] BITS C:\WINDOWS\System32\qmgr.dll 22:01:16.0296 0x0730 BITS - ok 22:01:16.0301 0x0730 [ 9CD2A4821DE379305CACB2E99AD8953A, 89D700DFC3C59ACBBADB48954A28C0EBF8D6A11A9E63837689DD891868E43188 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys 22:01:16.0318 0x0730 bowser - ok 22:01:16.0334 0x0730 [ 2447BD15B41298622CC662249CD0F496, 013A326D2E3BF68D654BBABE2F1E5DF0FF0A153A4B95D570EE28F9BC0F5A78C3 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll 22:01:16.0369 0x0730 BrokerInfrastructure - ok 22:01:16.0374 0x0730 [ B3F32C630DD3F2F6A6091B89CFF13641, 7A9C53EF9AB9FF1DC392FD711B194A101DB36CA5BC799E817BEB446741089B76 ] Browser C:\WINDOWS\System32\browser.dll 22:01:16.0392 0x0730 Browser - ok 22:01:16.0396 0x0730 [ 722036C26D2C4E50EC2A2EC5FD678846, 999468038AE01F0FF6881F4B2A2CB67BC636641188E95F10729E08ADBC3CB3DE ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys 22:01:16.0411 0x0730 BthAvrcpTg - ok 22:01:16.0415 0x0730 [ C2E31BE025D46D189E38DD1EDF07837A, 656528DCAAAF485EC57EE5C3021E96736634DE3B9C39CBCD2728E055ABD4C0A5 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys 22:01:16.0431 0x0730 BthHFEnum - ok 22:01:16.0434 0x0730 [ F7CD605FC0B0B22F3F6F247595E3A655, 1CD9140DE5415DDBEACD8667E63E5C95FD64D693B56302A0474E693E578BEAB0 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys 22:01:16.0449 0x0730 bthhfhid - ok 22:01:16.0457 0x0730 [ B157D72BDA6A6DD6E9DC6BF338CD0CF8, B2AC26AE214151E5AD93DED78256BC0295DBF0133C854E7DEE4CD776D9C9A349 ] BthHFSrv C:\WINDOWS\System32\BthHFSrv.dll 22:01:16.0479 0x0730 BthHFSrv - ok 22:01:16.0483 0x0730 [ 535DC41A33630AE4C262406F9E981C03, 599332589AA28D04189E19B87A4AE6FEEB60B40A7BC6E3B11240DA363A981C29 ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys 22:01:16.0499 0x0730 BTHMODEM - ok 22:01:16.0505 0x0730 [ 96932F631F5CB9F5D1C8F99A71568EF3, 5E4C8955A2EE9DC76B4EBC383653EB753D76D6B017E1A5DD553AC16094D7F12A ] bthserv C:\WINDOWS\system32\bthserv.dll 22:01:16.0524 0x0730 bthserv - ok 22:01:16.0527 0x0730 [ 23F9EF739F685E07482116425E7879AA, 0EBDF96A49A319C0BCF6F51FB6C8C392C017E1738B950C19C91FF43E14D73143 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys 22:01:16.0543 0x0730 buttonconverter - ok 22:01:16.0547 0x0730 [ 60EB6A4CE3E21887D302350631C16F26, 4270EFA22285C1A9336CF1220761E416950D2DA9C6A40D1D8452686CD5040DAB ] CapImg C:\WINDOWS\System32\drivers\capimg.sys 22:01:16.0566 0x0730 CapImg - ok 22:01:16.0570 0x0730 [ F8FB51B9EF6372610E9B31A1D86B62FC, 7461584A8B39AC549AD7BAFFA509D4CD81EEE542808BC8EFC285863A0AE6432D ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys 22:01:16.0587 0x0730 cdfs - ok 22:01:16.0597 0x0730 [ 2E6612376D257F74781F2EF1F869D8C3, 908B0DECB9F098F7F11B029A03C06C67FB52E5E8BEA42033A2B579D3B3686AB8 ] CDPSvc C:\WINDOWS\System32\CDPSvc.dll 22:01:16.0622 0x0730 CDPSvc - ok 22:01:16.0631 0x0730 [ A93C9B9EBE2FDE5A536000D72CC17F7F, 9793CFAE8BE8C6B5B39A1D276577965FBB2CE131325A410B7C68BD23492ADAAF ] CDPUserSvc C:\WINDOWS\System32\CDPUserSvc.dll 22:01:16.0654 0x0730 CDPUserSvc - ok 22:01:16.0661 0x0730 [ 613D0137C269187FA298A157E3D14A18, 84BC268525F14BB27202CE242BF94D9E83BC91B50A0335908574F31B29A2F04D ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys 22:01:16.0679 0x0730 cdrom - ok 22:01:16.0685 0x0730 [ C1B5EE58E759C53F9939581709DC70BB, 85095ABC9459A766832373BC3839E573E9A73C967F8427D6B7CAB972551C3191 ] CertPropSvc C:\WINDOWS\System32\certprop.dll 22:01:16.0704 0x0730 CertPropSvc - ok 22:01:16.0713 0x0730 [ 0AED948DA8D5F08B3D6F12E4E2089736, 95E538E81DDBC83492C5F3820C82C78F050B4D74ACF12D7970EC84F93581AE29 ] cht4iscsi C:\WINDOWS\system32\drivers\cht4sx64.sys 22:01:16.0731 0x0730 cht4iscsi - ok 22:01:16.0770 0x0730 [ 0002A0FDE087C1657AB31CE73077539C, 4DD6210B67E9633AB3240371590869DC833A4C986C74FC12A5D4FFFFD361848A ] cht4vbd C:\WINDOWS\System32\drivers\cht4vx64.sys 22:01:16.0822 0x0730 cht4vbd - ok 22:01:16.0827 0x0730 [ 6B4F90A287D75CCD78694F6790C911B2, 73D7C31E9F475FA3FD568FCA9A953F968729AA114F63C06F38BF5198DAD67BD8 ] circlass C:\WINDOWS\System32\drivers\circlass.sys 22:01:16.0842 0x0730 circlass - ok 22:01:16.0851 0x0730 [ B72D26074E72A757D788FB1BEF8B2F2E, 36847C5315AFB9A5EC66AD3EF2A09C24C0FAF669FDF0831F78600F4609352CB4 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys 22:01:16.0869 0x0730 CLFS - ok 22:01:16.0885 0x0730 [ E133CFCBFABB3CB517BE9F42FEA5887C, DA699CDD5F3CC427354540C907BD24CCA7BAC3112C53918EB611CB4EEC7611DA ] ClipSVC C:\WINDOWS\System32\ClipSVC.dll 22:01:16.0910 0x0730 ClipSVC - ok 22:01:16.0914 0x0730 [ EEC3A4A98AE1A337E3CD1483AD6F2E15, 764DA329984A95E092F5C15116DA34FA7FC27216C0862365D4BF10ADC97EC5C5 ] clreg C:\WINDOWS\System32\drivers\registry.sys 22:01:16.0930 0x0730 clreg - ok 22:01:16.0936 0x0730 [ 429623E266EF067A44E8CF148E9DFB9B, A48AA85ACC52C7AD73DB2D6148B3F9FB5EAC33C8F8C5BB6D7D0A9D84B7C08E11 ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys 22:01:16.0950 0x0730 CmBatt - ok 22:01:16.0963 0x0730 [ 90C07EB909C42316982E753BDAA7860D, 438581FD3468FAF01D35529672201A920E8821EC80E30E59A43645DA57738F21 ] CNG C:\WINDOWS\system32\Drivers\cng.sys 22:01:16.0987 0x0730 CNG - ok 22:01:16.0990 0x0730 [ 3DB10C59405931E2C72EFB82C1AF97D1, 100B5450A70988DB1C1F8A5FDBB3553AF1A0D47B42A5AC71460DB92E26010CE6 ] cnghwassist C:\WINDOWS\system32\DRIVERS\cnghwassist.sys 22:01:17.0002 0x0730 cnghwassist - ok 22:01:17.0013 0x0730 [ 34C935AF2A414572B412B3556586D783, 912981B88B0796576ECCD5EBE0C4728EC02D5D6A96B039447DCBA59B2583F25E ] CompositeBus C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys 22:01:17.0028 0x0730 CompositeBus - ok 22:01:17.0031 0x0730 COMSysApp - ok 22:01:17.0035 0x0730 [ 44EEEB2382F566999287E13F2067693C, 53A4A0C85EAD38030FF2078C67465E3710ECD03A08FF34E1E67B2E3E1CC70043 ] condrv C:\WINDOWS\system32\drivers\condrv.sys 22:01:17.0046 0x0730 condrv - ok 22:01:17.0062 0x0730 [ 5DE2049D5F57C1D142F36FA9CE443693, E6C2807C0B1EF90C11EB39634693B76EACE6CC675777776112835212A334F328 ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll 22:01:17.0088 0x0730 CoreMessagingRegistrar - ok 22:01:17.0095 0x0730 [ 5F06CAC4B09250CDDDD0180A08162924, A2EB0A57225E65FC264CFC9FAD858D8B54A015CDAE3DC904B1C4E9AAB40B1F06 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll 22:01:17.0111 0x0730 CryptSvc - ok 22:01:17.0124 0x0730 [ 03214883D52FAD46573233852344C72C, 63DCCDD895EB804D205ABB8EA381B34FB0879D09E4D0EB0B28F9B2BB1024BAB7 ] CSC C:\WINDOWS\system32\drivers\csc.sys 22:01:17.0152 0x0730 CSC - ok 22:01:17.0168 0x0730 [ BE35D1BAC3F18C9EB1C1CFBA31ED95E3, 4255475D173868A0E5583E844A1884E819E229838C4DEACAC47F1A4DEF388C9D ] CscService C:\WINDOWS\System32\cscsvc.dll 22:01:17.0205 0x0730 CscService - ok 22:01:17.0209 0x0730 [ 039B5A8CBD5C75D1C46DF15F7C74D136, A5C8A41F2D406D37E147939F2058373ED091BFCC00CA7E829F887638CD3A2F64 ] dam C:\WINDOWS\system32\drivers\dam.sys 22:01:17.0221 0x0730 dam - ok 22:01:17.0240 0x0730 [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 22:01:17.0279 0x0730 DcomLaunch - ok 22:01:17.0286 0x0730 [ AE9F09F87755C18904656CB4F59F351D, B352A43B3B68B497D87B49C302AF3F37F36D56D49878AE3785C3D43597E5DC57 ] DcpSvc C:\WINDOWS\system32\dcpsvc.dll 22:01:17.0310 0x0730 DcpSvc - ok 22:01:17.0322 0x0730 [ ABBD3EE724117242E28D31F19FBCFF03, 68EA91A969DD80A5DE28B0A8EAEB308837183713559C2C2FAEF991858C971393 ] defragsvc C:\WINDOWS\System32\defragsvc.dll 22:01:17.0355 0x0730 defragsvc - ok 22:01:17.0366 0x0730 [ DD74F18227ACC837D9856E24282D446D, 6A760E44CD897952538CDFA8895FE11263D51AAA79CFF24C01F3862E919DA478 ] DeviceAssociationService C:\WINDOWS\system32\das.dll 22:01:17.0393 0x0730 DeviceAssociationService - ok 22:01:17.0398 0x0730 [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll 22:01:17.0421 0x0730 DeviceInstall - ok 22:01:17.0424 0x0730 [ CDF1B1B5C5951111791C236B2696C7F8, BF6C4BA545C8827B40DB69890DB4D2B2F9C583C5E3CFBDFD370B05891141458D ] DevQueryBroker C:\WINDOWS\system32\DevQueryBroker.dll 22:01:17.0440 0x0730 DevQueryBroker - ok 22:01:17.0445 0x0730 [ 0D1D392ED2597F295956D058D33BD7C3, 2F7FE5A06D880F9E2A46C9803DD249DC40C2898C04E946D14E7EECCCC9F2B24F ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys 22:01:17.0475 0x0730 Dfsc - ok 22:01:17.0483 0x0730 [ F0D4400BA0F08610D9A551B15BF10B76, 83EB8FB272FC2DD2CC0659C2FB90AD0DAE88A88AB3951E03BCD933A25B601E10 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll 22:01:17.0507 0x0730 Dhcp - ok 22:01:17.0512 0x0730 [ CA7FEDDFCF61EF15A09C54DA2C07C49F, 346EF7709BA9E6BD48592B86FA46F9D956C847EF91F4980EEAD98269D0F0EF67 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe 22:01:17.0529 0x0730 diagnosticshub.standardcollector.service - ok 22:01:17.0566 0x0730 [ CAD14E0AD1F03397E9B1C8733D76BEF4, 0035EF35F6520B1DF0E599C8A06D4163C52576BCE0976BF729B44DECDC506627 ] DiagTrack C:\WINDOWS\system32\diagtrack.dll 22:01:17.0632 0x0730 DiagTrack - ok 22:01:17.0638 0x0730 [ 35B9D46560339A5A7F0CAC6ED702C817, F70480B01533B7029F90E2DE297E9E829660300DDE7A7D009B0AC2684E7691A7 ] disk C:\WINDOWS\system32\drivers\disk.sys 22:01:17.0651 0x0730 disk - ok 22:01:17.0660 0x0730 [ 09CF47A74BFB480B8262FCEE222004B6, F5CD0ACA04BCB95984595CC2E17BC9E92865091A0A3BCAD4B06438A1570E7696 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll 22:01:17.0686 0x0730 DmEnrollmentSvc - ok 22:01:17.0689 0x0730 [ 815F45161A4571C2C44491564F3D5968, 32E7AE8414A178CE429C0CDFCF718E3C11C705FB3155EA5CA0EAD48AAE507B01 ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys 22:01:17.0704 0x0730 dmvsc - ok 22:01:17.0707 0x0730 [ 6E5EE6E420FECD64DE463C5F01CBFE71, F173C56895E80AA03D70CD78B3AB659C2EEAACFF43BE3B6EF3939D6F4AD4F62D ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll 22:01:17.0733 0x0730 dmwappushservice - ok 22:01:17.0740 0x0730 [ 7F8A3ABF7750326E18CE953CCE262670, 5DBD159E8A455A42764FC73CF7DCAC849B5896848C5589B00BD36697804C0A3B ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 22:01:17.0761 0x0730 Dnscache - ok 22:01:17.0770 0x0730 [ 8F46B4C3F9BA19C26A26D0A11137B20B, BA0A66DBA98D77FD85A7CD2D4593F2B2A1A3B4D32BBECBCFFBEB5A54DCB0D8ED ] dot3svc C:\WINDOWS\System32\dot3svc.dll 22:01:17.0791 0x0730 dot3svc - ok 22:01:17.0796 0x0730 [ CA09EAEE92C6FDDC6B05057F11A0372D, 14DB5C186B69644AA93C445BF31CC9670204F95A47B77B6EACB19B4A316378AD ] DPS C:\WINDOWS\system32\dps.dll 22:01:17.0815 0x0730 DPS - ok 22:01:17.0818 0x0730 [ AE6BD4C879A8C849E53947C92DF3B3A0, 8C29774CB2D30D901C54AAC0C8ACE709351EE40E5C8FB9951B2A18B4A03F28B7 ] drmkaud C:\WINDOWS\system32\DRIVERS\drmkaud.sys 22:01:17.0830 0x0730 drmkaud - ok 22:01:17.0836 0x0730 [ 7433474BE77F065D2FA628671FE31A3E, 063ADDC68F48036749E6EC7B2F66284DB29F90F62E9468D16B4EF5A0FDC45E35 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll 22:01:17.0859 0x0730 DsmSvc - ok 22:01:17.0865 0x0730 [ 5FCA45C24501DA7390065D3706A9FC3F, 093FD840F1502ECC6F05B9723CA523B3F15CF39A5D2B9106E1267739B3F2C52C ] DsSvc C:\WINDOWS\System32\DsSvc.dll 22:01:17.0884 0x0730 DsSvc - ok 22:01:17.0924 0x0730 [ 19F2B54EE8861D90579BD0E3AE5182F9, FDD4F091C61C8C20550C8F68375ABD7ED718A733F680F0F0367D4796C302BA14 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys 22:01:17.0978 0x0730 DXGKrnl - ok 22:01:17.0984 0x0730 [ 9FCE4EF7D5E274F862D9A2526B5F4779, 81D42D5475C2801C8E0C233A0BA827569D8A70590017C91C665C8B232D9BFAA9 ] EapHost C:\WINDOWS\System32\eapsvc.dll 22:01:18.0005 0x0730 EapHost - ok 22:01:18.0066 0x0730 [ 7EC6FC0266D74BD47ABB130A328B70EC, 3856790AF967AB03B1A89F97328DC4D5A6854ACDA6169681A9AFB03D7CF791F9 ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys 22:01:18.0143 0x0730 ebdrv - ok 22:01:18.0150 0x0730 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] EFS C:\WINDOWS\System32\lsass.exe 22:01:18.0163 0x0730 EFS - ok 22:01:18.0167 0x0730 [ 8D74B8B5D6F7C5BC4C525BAF2B083FF1, DA5656F745B3911F96871887FDFDC40F4D9C820622A0AA27EFE4BA93662833CA ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys 22:01:18.0179 0x0730 EhStorClass - ok 22:01:18.0184 0x0730 [ 2A9817B5A9260D8F60D52E36BEF10443, AC1A0203221AFAF584C71317FA07AA1B6E61BE619E918B3B1E4AD57CCED1CF03 ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys 22:01:18.0197 0x0730 EhStorTcgDrv - ok 22:01:18.0202 0x0730 [ 80A7999DE02CE678B865832E1CE78CD6, 2576EBB6E4D630A906DE724F125099E52A962B5B68B9F9BCA849A7B29D8C8689 ] embeddedmode C:\WINDOWS\System32\embeddedmodesvc.dll 22:01:18.0221 0x0730 embeddedmode - ok 22:01:18.0229 0x0730 [ 3CE2B6AECB9AF8BC159299EEC46A35CA, E933B28BB6E4D01FCCDF8FBBB134C244B28DA3ECBDFA13333F0D4C24B2551780 ] EntAppSvc C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 22:01:18.0250 0x0730 EntAppSvc - ok 22:01:18.0253 0x0730 [ 77B60DEC7DCB4233E4A69D3F52E5DB24, 3A5C905E37A93899051497C90E5BA8E1D003B56C6906CADFD2F1CDF52052D248 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys 22:01:18.0267 0x0730 ErrDev - ok 22:01:18.0272 0x0730 [ BE8117569CAA36E03683CC1BACEA1347, F4C55264838166EFC8A05ED1BA36F13B9BAD500CC17204D4C814050B8C18E107 ] ESProtectionDriver C:\Windows\system32\drivers\mbae64.sys 22:01:18.0288 0x0730 ESProtectionDriver - ok 22:01:18.0299 0x0730 [ F89083AB8B9F51C0031C1CBD0A9A7E35, 9EE973A25134960E62D1A6A1E34AD9B3F7690E71C1AD31A23FA2081A73438754 ] EventSystem C:\WINDOWS\system32\es.dll 22:01:18.0325 0x0730 EventSystem - ok 22:01:18.0334 0x0730 [ FCD2C63754C2E739A8EEAD9BC63F9DDC, C57A72ABA4C0BD71F914B9C8FF965DCFF585A205498F19A4584A4BAF7674839D ] exfat C:\WINDOWS\system32\drivers\exfat.sys 22:01:18.0358 0x0730 exfat - ok 22:01:18.0366 0x0730 [ FA918EC296EB410FF02867D008D02421, 23D164A24CB0D212778FA9592A046B6BA1F3628003E04181744A1F891B5B3E5A ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys 22:01:18.0385 0x0730 fastfat - ok 22:01:18.0399 0x0730 [ 77CE56471AF984800F318F3734D768C7, 72D540072374A56C2C497F0532A50705D3F0637F2C0C96B1D715F2EDFCA3AA2D ] Fax C:\WINDOWS\system32\fxssvc.exe 22:01:18.0431 0x0730 Fax - ok 22:01:18.0435 0x0730 [ 99598ECA5E41996E005D5B9D9FF1EFA2, 91345CD50EF02431B69093505C1C5F5DC6A1AA6BF192EE9392ED4D5626B60462 ] fdc C:\WINDOWS\System32\drivers\fdc.sys 22:01:18.0450 0x0730 fdc - ok 22:01:18.0453 0x0730 [ EF0DD43A4CBAB367BCA1AFBDC9971E4F, 73E161C45D63FDDE71EE2438137913724DC513860539D1E7F6BD861F5D1B33F3 ] fdPHost C:\WINDOWS\system32\fdPHost.dll 22:01:18.0470 0x0730 fdPHost - ok 22:01:18.0474 0x0730 [ 34DAC585994CD3B4E910DE11C584EF3D, A6C6A4CB5413EA61F1A54E2D3AD71A311CEA2C26218544D2D2D4A5CFEC52DE8C ] FDResPub C:\WINDOWS\system32\fdrespub.dll 22:01:18.0492 0x0730 FDResPub - ok 22:01:18.0496 0x0730 [ B68DA1FE3CA2311AFD38DD6905CA7F71, 4B395DFB1B47D2507CA4D9DC996A70D0A3BDB1A245CD6DA6C42B2A299AFCCF37 ] fhsvc C:\WINDOWS\system32\fhsvc.dll 22:01:18.0514 0x0730 fhsvc - ok 22:01:18.0519 0x0730 [ F44F666B0EACC3181544FFCF8CA0FFC7, 83F771CF9DAE1C504B30731EEC55355EA1253174252DA2192ADF1D228B3735C3 ] FileCrypt C:\WINDOWS\system32\drivers\filecrypt.sys 22:01:18.0535 0x0730 FileCrypt - ok 22:01:18.0539 0x0730 [ 78A210DDFDF2C9EC884631D2DAA573F0, 5D39C6EF4AC690A9749EEDBE2478FFF15A22877A2861EDA103C7BF1607B0C1BD ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys 22:01:18.0551 0x0730 FileInfo - ok 22:01:18.0554 0x0730 [ 1A97DB5E701A186989F3795223C3BE39, F7982220D4DF7E104955E63CACE352394E2577DEF49506EA126127F820EB62DF ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys 22:01:18.0571 0x0730 Filetrace - ok 22:01:18.0574 0x0730 [ 46626665F0E5906E45619B4EFD6186B8, 37FDD3B8AD49FD29E54DA5567EA77F28A53498AE56348F7A2628E5E5549D638B ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys 22:01:18.0588 0x0730 flpydisk - ok 22:01:18.0597 0x0730 [ FDA72ACA14D516D18C33AFCD0FD9260F, 6509612DEC82EA74614B5C9A7B432305A1A468C97B88BED9E141DF2929B621B1 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 22:01:18.0615 0x0730 FltMgr - ok 22:01:18.0650 0x0730 [ 49BF5C8182C3D2D6CD9F7EEDF1CFDB66, 0977EBE86B57FC370D27CA69D58122397D5D5369AF0C8DBCC492AE7AD55CBA2B ] FontCache C:\WINDOWS\system32\FntCache.dll 22:01:18.0712 0x0730 FontCache - ok 22:01:18.0730 0x0730 [ 8B52024D3A5C3A12F1C4D75D30A976C5, 982F1C783966C9A6D255AA7DBAB6D225EBE0050A36176B8DE85E8ADBFE17FDF1 ] FrameServer C:\WINDOWS\system32\FrameServer.dll 22:01:18.0765 0x0730 FrameServer - ok 22:01:18.0769 0x0730 [ D152CCBFC8251670BF0AAFE00D6BC782, 9DE82D8FC4E1DAF8FF23EE08C0B7CB5051A9224E64544D262CFA4996A41B04E1 ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys 22:01:18.0781 0x0730 FsDepends - ok 22:01:18.0784 0x0730 [ 6D6BB5C7363CD35FA715E826F3D029EE, C214F791EB39E8B25CE57ED9D6C1D56EE1AF6021BCB380980BD42A6338A6C9F7 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 22:01:18.0796 0x0730 Fs_Rec - ok 22:01:18.0809 0x0730 [ 8EEC4925C03E375C4EC496E45C44139A, 06C5C7BCC28D3E435675F0759A09CAB726E971DF4BFC1DC3DCF503EABCDCCCC6 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys 22:01:18.0833 0x0730 fvevol - ok 22:01:18.0837 0x0730 [ EF78034773CE506323655A868C949144, DF195BEEE6704FBCC6D2D9E1BF6723E52ED502A1459F495B7D18481E6A79B5BC ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys 22:01:18.0851 0x0730 gencounter - ok 22:01:18.0854 0x0730 [ B55FEBC6A00DAA1FE074F020B6907516, 67071FBAC2ABA47AB71358A5F08E92E034A55343878F00137E90B3B1F7362976 ] genericusbfn C:\WINDOWS\System32\drivers\genericusbfn.sys 22:01:18.0868 0x0730 genericusbfn - ok 22:01:18.0874 0x0730 [ DDD8A8CDDC7F13EF57D1DAAE71865936, 9D472A8689F72F24D40D5B94849690F53C67849FDF6162A94EF4FB330A3DA566 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys 22:01:18.0888 0x0730 GPIOClx0101 - ok 22:01:18.0911 0x0730 [ 713A176494CEC107E663CAD6C2B27F77, 76871D8CFBA8FCD8CFF96208AE84C658EBEC60270D978898B90EE9451AA1BCE1 ] gpsvc C:\WINDOWS\System32\gpsvc.dll 22:01:18.0958 0x0730 gpsvc - ok 22:01:18.0961 0x0730 [ 7ACD8F69B5D6EC97E6D2C006E19BED88, FC69214C9308EA64B88EF4C3C95800586DDBB44C8540846B79A161BAD8203B6E ] GpuEnergyDrv C:\WINDOWS\system32\drivers\gpuenergydrv.sys 22:01:18.0976 0x0730 GpuEnergyDrv - ok 22:01:18.0980 0x0730 [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:01:18.0991 0x0730 gupdate - ok 22:01:18.0995 0x0730 [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:01:19.0005 0x0730 gupdatem - ok 22:01:19.0015 0x0730 [ 217230B984AB2954E2FA5E36578D7B08, BB7B79EA7501A28EB2A0303FDF66FB9D59D567994C25A1523CD6D2081C403AF6 ] HdAudAddService C:\WINDOWS\system32\DRIVERS\HdAudio.sys 22:01:19.0040 0x0730 HdAudAddService - ok 22:01:19.0044 0x0730 [ 10E3515FE5DBA6656FA62C29342EC4A1, 2051F10F74ED712B1766EB61E87FADE25AB3D0970BABFD320600D1B0D6377F26 ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys 22:01:19.0060 0x0730 HDAudBus - ok 22:01:19.0063 0x0730 [ B90D284B97CD4CA9DE7430AAAD887A56, 2F14F985C39B7801ED64590979CF2114924E9547F5B11D2B37A74DBFFDD9E7C5 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys 22:01:19.0074 0x0730 HidBatt - ok 22:01:19.0078 0x0730 [ B2FE11643CC6ACDEE6C247DD36018FDB, 5796613C7DBF8B2A9E860E006FF1A245B6BE7D10E3F6685AD142B48E5C237B8C ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys 22:01:19.0095 0x0730 HidBth - ok 22:01:19.0098 0x0730 [ D24355488A2D4D2323518EC1AC7A6D9E, ED2176A2093726087EDDA25B86E9CDD4BA35F4E748E3A6DE0B15C4C97646B5C7 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys 22:01:19.0113 0x0730 hidi2c - ok 22:01:19.0116 0x0730 [ 0AF9ABBA4F3F55C6C803890D64BC3C29, D3DE6FA308F8E7CD4F16387F46AE4B2F7EC9BBA07BF87652B660A0D645710571 ] hidinterrupt C:\WINDOWS\System32\drivers\hidinterrupt.sys 22:01:19.0128 0x0730 hidinterrupt - ok 22:01:19.0131 0x0730 [ CDBCF8E9AB06D88A1E1191D32F320C5D, F76963AB7CF2BAB3A220013879AECD3976BFD851CFB66B5A69A9EA2541048861 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys 22:01:19.0146 0x0730 HidIr - ok 22:01:19.0149 0x0730 [ C900FE0DD6A1E2220084B8F1C427790C, 802194EBEDA1A50EDA300078B0888AAC1F17A42E67147B7B3B9C50AD8D4E5C89 ] hidserv C:\WINDOWS\system32\hidserv.dll 22:01:19.0164 0x0730 hidserv - ok 22:01:19.0167 0x0730 [ D8536CB438CC4CCDAE047B768EED22B2, 4F666BFA3554F9ACA6B9D436BFA64474D5F30FB3E78F4E66068CCDF283D9867F ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys 22:01:19.0182 0x0730 HidUsb - ok 22:01:19.0190 0x0730 [ 0AC1BD5A28FAA371EF34859FE703E515, 1DD1C33AF8D6EBE7C36FCD051F066E4039D2B47ABAECF7C68BC3933D567930B2 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll 22:01:19.0212 0x0730 HomeGroupListener - ok 22:01:19.0222 0x0730 [ 86161A89F16851728802590EC7C92608, 3A3B05BB4E115410D27063B30C0EF3F18295F542050F329F1E466C81A9E23A46 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll 22:01:19.0249 0x0730 HomeGroupProvider - ok 22:01:19.0253 0x0730 [ F5CA18197B4646E04DB9EB2D6642CC4D, 5BA3342DDF1BCB67E4156169FE9A33E7BC2641C729E9F1A80C0E80953C6AB114 ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys 22:01:19.0265 0x0730 HpSAMD - ok 22:01:19.0287 0x0730 [ A10C7C1E69FC90620C7BF2E51302A01F, D725AEAE38255CED73F4922A10F226215528706580B06D01C228488F93AC0397 ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys 22:01:19.0319 0x0730 HTTP - ok 22:01:19.0324 0x0730 [ 0C84C250F80EAEC2C9768464CC1A9626, 212E1003B78F9B98FEB084FD1FDB59B26A9DE4C9120F24D4361FBBF0F3C035E7 ] HvHost C:\WINDOWS\System32\hvhostsvc.dll 22:01:19.0340 0x0730 HvHost - ok 22:01:19.0344 0x0730 [ 74FC79C52395B10FFD0B55CF22CF88FC, 94D977DA2092EE8C2A598AC48758A84BB22CB6378BD114C2D3B4172A07A9CACC ] hvservice C:\WINDOWS\system32\drivers\hvservice.sys 22:01:19.0356 0x0730 hvservice - ok 22:01:19.0369 0x0730 [ EF558A02D734A1403583E95CCEEC2487, F0D052DAF48A62E4A90D067BFCB5EE9563804DE68D0EA82E0E11C8D16AD19D29 ] HWiNFO32 C:\WINDOWS\SysWoW64\drivers\HWiNFO64A.SYS 22:01:19.0378 0x0730 HWiNFO32 - ok 22:01:19.0381 0x0730 [ 771EDDA9830A3079F996F34D681FB6E5, F452AD656872A1C8B2D6DCE232CE01EBD456C46F4934A7601E78470F2A2CBF38 ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys 22:01:19.0392 0x0730 hwpolicy - ok 22:01:19.0395 0x0730 [ 3B9F315E7FA72CC25228EB097DD9C694, B26F1E494428EF197A0C97645C05BB3CA093827A005D35C987F1D6778BC4E52C ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys 22:01:19.0409 0x0730 hyperkbd - ok 22:01:19.0412 0x0730 [ 6A0B9F5662598D229F62CD317292E8F3, AF33D3FFACF72A15EEE37A4998DF0C1F9595B949D1AB4FAFA8AF278DB41E0455 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys 22:01:19.0426 0x0730 HyperVideo - ok 22:01:19.0430 0x0730 [ B54B30992620C97230013A74461C8517, CAF09BDCDD6DE2A39CB8AE2C65E6F8FE12D8E93D84BBEF6C6A98F872BF54A4E3 ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys 22:01:19.0448 0x0730 i8042prt - ok 22:01:19.0451 0x0730 [ C6B8743B213F06AA60943D8366FE968F, 758954F70B810063914B243115B2C753B2BCE40190F95C30ACBA0BF04EBD5B33 ] iagpio C:\WINDOWS\System32\drivers\iagpio.sys 22:01:19.0466 0x0730 iagpio - ok 22:01:19.0470 0x0730 [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c C:\WINDOWS\System32\drivers\iai2c.sys 22:01:19.0486 0x0730 iai2c - ok 22:01:19.0490 0x0730 [ 5A0E850F8CD17791A3E6A3CF81D0CA28, 10A965A49D53360DD250E0758B6BB142872298A21C732EB026ACB93492C5C6CF ] iaLPSS2i_GPIO2 C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys 22:01:19.0505 0x0730 iaLPSS2i_GPIO2 - ok 22:01:19.0511 0x0730 [ 7508F1096803385D6376BFD0BD473AC4, 1F32EC23CDC94DCB9710E6663B5C3BD83568545DDC2C741CFC13550A4E4DD2BE ] iaLPSS2i_I2C C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys 22:01:19.0523 0x0730 iaLPSS2i_I2C - ok 22:01:19.0526 0x0730 [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys 22:01:19.0535 0x0730 iaLPSSi_GPIO - ok 22:01:19.0540 0x0730 [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys 22:01:19.0556 0x0730 iaLPSSi_I2C - ok 22:01:19.0570 0x0730 [ 97E553D03219D3D51705C7235D9EAEBD, 5D4578C8804AF32D1DC0868E34D6538138DC15F9568CA7E21051B1C82C0D8D55 ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys 22:01:19.0595 0x0730 iaStorAV - ok 22:01:19.0605 0x0730 [ 8350FE3BCDE3428BC040877BB7E9EAEB, 77F9456351CA640C6B7862907C0580627E761EC807B551976A95657EB4D6CC20 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys 22:01:19.0624 0x0730 iaStorV - ok 22:01:19.0635 0x0730 [ 3BA03F7C7700DDF4C383DDE9252F5817, 3E90F69D0010E7764349D9AE865D577E431FEBC67DA554B400BC808DD286E203 ] ibbus C:\WINDOWS\System32\drivers\ibbus.sys 22:01:19.0657 0x0730 ibbus - ok 22:01:19.0663 0x0730 [ 937AC47F7356554DA05D9722C356EB55, 9EABC9F19B4E1193B669D2674967F5C6F03FAD348EDF0615E3F78554FF9A83CC ] icssvc C:\WINDOWS\System32\tetheringservice.dll 22:01:19.0684 0x0730 icssvc - ok 22:01:19.0703 0x0730 [ F2934208C0E50C0B971A7981AB90BED2, B936BFBBD71E731CC2CDB8B47D262F2EF09726FF921C2DA0841910CA2401423D ] IKEEXT C:\WINDOWS\System32\ikeext.dll 22:01:19.0742 0x0730 IKEEXT - ok 22:01:19.0745 0x0730 [ 2A01C96DF5802D3434634E55C91232D8, A3ABEF36E2FD2CF5C371ADBF92566A09669A1D990ABE4677370F57F2EEAF8121 ] IndirectKmd C:\WINDOWS\System32\drivers\IndirectKmd.sys 22:01:19.0760 0x0730 IndirectKmd - ok 22:01:19.0764 0x0730 [ 9F7E87F6595D065A8A200A291043045E, 6944F72F73EADC6C9B7691F2C1C6DF1898F22C88EFA78EC0BA8CB5FFD9CE057B ] intelide C:\WINDOWS\system32\drivers\intelide.sys 22:01:19.0776 0x0730 intelide - ok 22:01:19.0779 0x0730 [ A6BD2E20AE1BC5CB2776C87C28E4F4CA, BD8BE67CED9A4982D785CE9ECBEFE868C3A2E37DF7F9592B9F9049B807A1554B ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys 22:01:19.0791 0x0730 intelpep - ok 22:01:19.0796 0x0730 [ 2A48DA39542636DB0FA3BA915385D1B3, 6CA0916F5F4B1E81AE6A6233276320599BFA7C129267177703E3BB6468FB4683 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys 22:01:19.0813 0x0730 intelppm - ok 22:01:19.0816 0x0730 [ DB32758F3A7F6CCE81A5430080A2EA65, 36A26BAA884E96804F8EA0B12BB3E81BBE6D4EE704809904091445F36CAB5A29 ] iorate C:\WINDOWS\system32\drivers\iorate.sys 22:01:19.0828 0x0730 iorate - ok 22:01:19.0832 0x0730 [ FE85D0A86CA7A5A99CF8CD04DE7F80AE, 544C01FC01EE728EB5667158207E5F4418FE77A88BA318192A834722DB766F4E ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 22:01:19.0847 0x0730 IpFilterDriver - ok 22:01:19.0866 0x0730 [ EF1BB0EF8A12C32DD88C409706B8145E, 7AEDE717C258C29592CC8AEC40F61617E5382646E5141E1C0941882ACE5C5758 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll 22:01:19.0905 0x0730 iphlpsvc - ok 22:01:19.0910 0x0730 [ 450DBDD716C7911F83E05F78EE18BFA2, 43C0DA172F632131898F315A53DEDD1AE99FB0620AB32B3A5B99FEC498C9AAE5 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys 22:01:19.0923 0x0730 IPMIDRV - ok 22:01:19.0929 0x0730 [ F1DAECC3B3D6399875D4F10529D6A77C, 6533D2F858816BE6570C998510919FCA2904EC6EF806F61C1FD325E88133111B ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys 22:01:19.0947 0x0730 IPNAT - ok 22:01:19.0952 0x0730 [ 7475A2903BB704B446AA6309E34D3362, C94643A1626A9716015EBA7041A1224098501EB7DAA704CBFCAD3DC6F3CFC6AF ] irda C:\WINDOWS\system32\drivers\irda.sys 22:01:19.0970 0x0730 irda - ok 22:01:19.0972 0x0730 [ 9725E7F0C64CE9916A5CDABE8D6E13C3, 04AF9E48FEF208A2850DF28352E8FDCBF4018982C72C0F67EE12C048C4070116 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys 22:01:19.0987 0x0730 IRENUM - ok 22:01:19.0990 0x0730 [ 8C604213A2E73088BFFE6CD2E6F1AE53, B4C4FEE4D398A29F72EC27D5668071D7E68CD943FFFC38624DD5DF5BEBDF46D3 ] irmon C:\WINDOWS\System32\irmon.dll 22:01:20.0005 0x0730 irmon - ok 22:01:20.0008 0x0730 [ 58040898883A96160D41739C80328BBF, 7F85C91C905811416E266A263DDEFCDCB0B45376AAE51B551AB636C16577DB9F ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys 22:01:20.0019 0x0730 isapnp - ok 22:01:20.0026 0x0730 [ C9FD02D62E09337B67B0C61EC8CA38CC, DC77E935ECC8474BE9018F0937CB11C137073582B20A0EE107CE247FD9E1F9C1 ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys 22:01:20.0042 0x0730 iScsiPrt - ok 22:01:20.0046 0x0730 [ 210808437570BDDEE71A43535E3A2D30, EF5DE6EE4FF58F44CDE4D4E7F298ABBC9086EC05CC3AE4903060DA878115AC1E ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys 22:01:20.0058 0x0730 kbdclass - ok 22:01:20.0070 0x0730 [ 0B779E9FC426CA2268D28181FA6C222F, 83292023A688C3044D096F22242EB954B7F7511BE8341D45FF0AFBD9CB9BCB4E ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys 22:01:20.0085 0x0730 kbdhid - ok 22:01:20.0088 0x0730 [ 813BA3EB2CE038F2A5382DDD75CAD60B, 99FA444027CAC247B54317730D54AB0C4C000AE076B97E47470FDA9834594312 ] kdnic C:\WINDOWS\System32\drivers\kdnic.sys 22:01:20.0103 0x0730 kdnic - ok 22:01:20.0107 0x0730 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] KeyIso C:\WINDOWS\system32\lsass.exe 22:01:20.0120 0x0730 KeyIso - ok 22:01:20.0125 0x0730 [ 705C0F8BCCEF6E7CB704CCB454192D7E, FC608C708E2C3BF7A66E57B95E19E71E5F5C87EF359D8BC1A817500B45DF9338 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys 22:01:20.0138 0x0730 KSecDD - ok 22:01:20.0144 0x0730 [ 55AD13E2BAFC5AB53A10F8C271F5D242, 058BEF14DCB95574BCAB985F04737BA89483937E8D8A74F7B4CEAFB7400C2397 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys 22:01:20.0158 0x0730 KSecPkg - ok 22:01:20.0161 0x0730 [ 4ED115CD1A1099705F56B5E0FFF97CC6, 9CC49DF2CD6AAAE405BA661D13EFC1E05111D1DE3D1E50C39C425AF1F075610B ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys 22:01:20.0180 0x0730 ksthunk - ok 22:01:20.0189 0x0730 [ 8125BDF7ADC261F75EF0CAD92456E350, 184797AA1D58C4FF743BA60D48590B88B781EE7779205E45E0679DEC79F3E185 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll 22:01:20.0214 0x0730 KtmRm - ok 22:01:20.0222 0x0730 [ 8CCAB08815B50AD78B823DB3F96C8604, 265E6D582EB7207B5CC577D61CB7BC3646F613047F168CD69BB776C37780EBF5 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll 22:01:20.0246 0x0730 LanmanServer - ok 22:01:20.0254 0x0730 [ 33DBBCF71F68EA97D9FD34E4C9AB5AC6, 104F04A1560E75EB224A3825707CE51E8798ABD764F5CC3B854FFFC93A39AF60 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll 22:01:20.0276 0x0730 LanmanWorkstation - ok 22:01:20.0287 0x0730 [ 20EE2F2ADCF8DBD091E931593F5AC268, 5F053F8B7C8B340A0364CE37B25D68B6755C2CCDB050C02E9B4E0929DF587E0F ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe 22:01:20.0301 0x0730 LBTServ - ok 22:01:20.0306 0x0730 [ EAB70270BDDCFEF56FCC7425C2D9883D, 7B351EE3DA3DA4677DD8E4F91A5FFA6EBB3A15BF76F34EAC8879ECB16D01190F ] LEqdUsb C:\WINDOWS\system32\DRIVERS\LEqdUsb.Sys 22:01:20.0316 0x0730 LEqdUsb - ok 22:01:20.0320 0x0730 [ F8EBAA1FE6D3BF84752931DE1BFA0E2A, 2F3C512712BA709BBBBD779D9E792DBE324876C402CDCEF0345B8B7ABE1D232A ] lfsvc C:\WINDOWS\System32\lfsvc.dll 22:01:20.0335 0x0730 lfsvc - ok 22:01:20.0338 0x0730 [ 5EBB7C1FC685D45A1D3D8B2B9A656E48, 8C4D984D3566DE29D13A294ED927525A7D7A106887E809986EBDDA8CC0B98FFB ] LHidEqd C:\WINDOWS\system32\DRIVERS\LHidEqd.Sys 22:01:20.0346 0x0730 LHidEqd - ok 22:01:20.0350 0x0730 [ AFDFA4A6B0F7B15AA38E494FD4595741, 0D89CCEBC816F4A3F6DDB093B3F8BB8B85293E94559085961DA31F9330D43C21 ] LHidFilt C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys 22:01:20.0360 0x0730 LHidFilt - ok 22:01:20.0363 0x0730 [ 5A23E4BE0CCF49663C4CF7EB74C20278, 9DF91014B13B7CED1C3D409F90858FD03EFC5C4347C98901B4DF0AFF2B77845D ] LicenseManager C:\WINDOWS\system32\LicenseManagerSvc.dll 22:01:20.0378 0x0730 LicenseManager - ok 22:01:20.0382 0x0730 [ 5933A6673F00D8255C52957E40C2D601, 0AA1281F8B3F97E360592D1B35EE7D3D614F1AB46007F9884CFFB1C5E647575E ] lltdio C:\WINDOWS\system32\drivers\lltdio.sys 22:01:20.0397 0x0730 lltdio - ok 22:01:20.0405 0x0730 [ 88A3C935725FA6EA1A228DCC26CF9C6F, 9B1F70644EEFA1EE7CE151A8A970430087339B7A6345F2E0252370929D4AFAC6 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll 22:01:20.0426 0x0730 lltdsvc - ok 22:01:20.0429 0x0730 [ 3F858E28AEE6545FA1B64134DFD5C2CE, FFD7B4FB0A7B61BC6B76A172134673842F2CF00E96FA3ED4A8273DC525B6BB92 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll 22:01:20.0445 0x0730 lmhosts - ok 22:01:20.0448 0x0730 [ C3E82B320F34C97F32B8026F4C249BEF, CAF53CD4738D2C92E4764372F75B5D0D74EBA896E59E685ED15B915F4E7223A0 ] LMouFilt C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys 22:01:20.0457 0x0730 LMouFilt - ok 22:01:20.0463 0x0730 [ 8E1B0946948CCC0BC1FA3CB70374A795, 0B894C129A35E223FF9594725AC90916CBD597FAD2211A18FC2AE03EA8679597 ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys 22:01:20.0476 0x0730 LSI_SAS - ok 22:01:20.0480 0x0730 [ 4F68163FC04C973500DC4DA0946917B0, DF060C29109EB3978CEDFE781999B0C4C1E8C0FDB133428058D8400C53315EEC ] LSI_SAS2i C:\WINDOWS\system32\drivers\lsi_sas2i.sys 22:01:20.0493 0x0730 LSI_SAS2i - ok 22:01:20.0497 0x0730 [ E5AC5F2815938651CDCC27F425474673, 3AF0598982153C36A766506FA088F7B84333CC96FEBB050402547AFC613AF9F7 ] LSI_SAS3i C:\WINDOWS\system32\drivers\lsi_sas3i.sys 22:01:20.0510 0x0730 LSI_SAS3i - ok 22:01:20.0514 0x0730 [ CCF6EC9FB9B8F18E05B4253E81013E48, EBE8D77FEE8B99BD8C29702404774D554673C96DF3FDF3DCEA9C99E22C2709FC ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys 22:01:20.0526 0x0730 LSI_SSS - ok 22:01:20.0541 0x0730 [ D5EFC0BAEC21EDE6FE03D377D403B421, 41BE71AF7C896FD4C51EF7E3871AAB769164DFB8050DA43E48C7A100711414B4 ] LSM C:\WINDOWS\System32\lsm.dll 22:01:20.0574 0x0730 LSM - ok 22:01:20.0579 0x0730 [ C9579D32219E5B936AC3A48D470117EC, E61A77191B6BA25D29B1221FEBBE826BBC11F825C0E35A72B4CEFFF8B7FE59A8 ] luafv C:\WINDOWS\system32\drivers\luafv.sys 22:01:20.0598 0x0730 luafv - ok 22:01:20.0602 0x0730 [ CAAF0CD70FEE7C5110B1E62804E41B17, 48482A6C8D2296C4DC613304637C8DBB7DD1DB39326F27650EBCA6FD2793BCFD ] MapsBroker C:\WINDOWS\System32\moshost.dll 22:01:20.0618 0x0730 MapsBroker - ok 22:01:20.0624 0x0730 [ 0E4AD4D8C0A8048C00CAD9CFA082A26E, 77DE05486CA6A3DFAF7DDF249C27BE0CED7B678623D19419FE2B414BBA1E6F8E ] MBAMChameleon C:\WINDOWS\system32\drivers\MBAMChameleon.sys 22:01:20.0635 0x0730 MBAMChameleon - ok 22:01:20.0641 0x0730 [ E8922903632E78D9E60375E117089088, DE4E17E923AF1DAE0F42990BFBBD35CE9E0FD0483059FEDAA7B5F98034ED23AF ] MBAMFarflt C:\WINDOWS\system32\drivers\farflt.sys 22:01:20.0652 0x0730 MBAMFarflt - ok 22:01:20.0655 0x0730 [ 88BD122C3A35DE63D75D382DF75554CE, ABDF59543CAD186A6ED4E66257205D9CF5047732A5DA74A96A28B468B41BC396 ] MBAMProtection C:\Windows\system32\drivers\mbam.sys 22:01:20.0664 0x0730 MBAMProtection - ok 22:01:20.0742 0x0730 [ 804E3246E3E73D4A936F2F4BCDC53A2D, BF1F9B4AC292238FA6EE541E325B220F311977F9D87D5BC7F90AD058FBF0B35A ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe 22:01:20.0824 0x0730 MBAMService - ok 22:01:20.0835 0x0730 [ BDE2FC7213C0897524C1357BAAE30239, 1E1AB68145107429217E07A662477C86406E0188BE9F01CAC416AC13054D1A5E ] MBAMSwissArmy C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 22:01:20.0848 0x0730 MBAMSwissArmy - ok 22:01:20.0853 0x0730 [ D6067E2128F6AE309F9F39EE69DE85A0, 9D172FF4CA5AED9FB7CAE8E75151A25AC34251202C4ECF563535C0DD2500AC3A ] MBAMWebProtection C:\WINDOWS\system32\drivers\mwac.sys 22:01:20.0863 0x0730 MBAMWebProtection - ok 22:01:20.0866 0x0730 [ C3CDCCF07486BD2616A7B82946E07AC0, 1EF95DAB2DA856BC7D7573B2EB2D9006DF337F827F0B56A161D0C97F45DB755E ] megasas C:\WINDOWS\system32\drivers\megasas.sys 22:01:20.0878 0x0730 megasas - ok 22:01:20.0882 0x0730 [ 2CF0CB2A0ED68C5455371E84C16F9627, 1C9166B52140145F1968E83E52BFF041250811B23C770FE181A18A4BA060CA81 ] megasas2i C:\WINDOWS\system32\drivers\MegaSas2i.sys 22:01:20.0895 0x0730 megasas2i - ok 22:01:20.0907 0x0730 [ FADB2FE017E69EECE0E1BA78661C2E8C, BE99B49031D8B4B670B6F6B6E829E54406779CF6F1D8AFE8AB79A73E6764AB2F ] megasr C:\WINDOWS\system32\drivers\megasr.sys 22:01:20.0929 0x0730 megasr - ok 22:01:20.0934 0x0730 [ 55A417C3E41F2A98666CF929EC19108E, A38C262B2863C87E4151525BF26D6AC16E7982D370E2C6998EB15C88C4BC8254 ] MessagingService C:\WINDOWS\System32\MessagingService.dll 22:01:20.0950 0x0730 MessagingService - ok 22:01:20.0968 0x0730 [ FD60818B66B2E8A5415EA840E99A9D8F, 5D2F22909354534B821D958FBEF6A40EB4F642F53C7B509D00949096EF716F36 ] mlx4_bus C:\WINDOWS\System32\drivers\mlx4_bus.sys 22:01:20.0996 0x0730 mlx4_bus - ok 22:01:21.0000 0x0730 [ 68F6977F1CFBAAC770D940A8C0326FA1, 90EE1E7DAC680EAA5AD50E9B0B9FD8FCE8DD6A02D5EF941B5AA5084CBD40BB80 ] MMCSS C:\WINDOWS\system32\drivers\mmcss.sys 22:01:21.0015 0x0730 MMCSS - ok 22:01:21.0018 0x0730 [ 0D50B3F3AB32D416786B58D4553859CE, 9DA4D7A30982E8B31C45BDB721AEF5240EAD9DA6839CF34FDDBCF123BF104F2C ] Modem C:\WINDOWS\system32\drivers\modem.sys 22:01:21.0033 0x0730 Modem - ok 22:01:21.0037 0x0730 [ 9CCCB7FC3EDADEBA461D78615A6011A6, C120B58F25E8CCFD971EB78645C0682F367AD56DC15F2D8C1980CE75B04719DF ] monitor C:\WINDOWS\System32\drivers\monitor.sys 22:01:21.0052 0x0730 monitor - ok 22:01:21.0055 0x0730 [ 27A07B2FB2E3057DA8DAEA4F25D843C7, 09D2B39E6B9AAEC879E5871DD6BCFF2AEF0B894F3B44649665A685F8B3CA6F27 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys 22:01:21.0067 0x0730 mouclass - ok 22:01:21.0071 0x0730 [ 7BD6E7F7C9001AB21B8362CFFEE80B25, C470C3363EEF3A60409A5934988BFB9B72AE7C2BB63CC2C2D006D7EB1C797F6A ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys 22:01:21.0086 0x0730 mouhid - ok 22:01:21.0091 0x0730 [ F5BDAEE4B7D369D4C74668DCFBA3FF10, 100F39288E56AFE0D39D1CC235BDC9F3727C873CD3114E092DA7A08810BD3EB2 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys 22:01:21.0104 0x0730 mountmgr - ok 22:01:21.0109 0x0730 [ 17C3D8D5E65AE57B5E94B969433C0F99, 389F235A540CE1D55903F86C9045CAFC95B93E8EF0C3369D048D67B1106DE6E5 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 22:01:21.0120 0x0730 MozillaMaintenance - ok 22:01:21.0124 0x0730 [ 30844BD376F9D01E62C820BEF446F1F8, 910D672EDB544A20AEB4450B4D89830F46EDD28CE0021156176315C5D068A1B4 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys 22:01:21.0140 0x0730 mpsdrv - ok 22:01:21.0158 0x0730 [ 779CFDB17EA07A6D26FEBBAC95B65772, 74D9542E8DCCD07396A45A45D2F500AA6F9DCC1DB785A6153EB3067E42F576A4 ] MpsSvc C:\WINDOWS\system32\mpssvc.dll 22:01:21.0196 0x0730 MpsSvc - ok 22:01:21.0202 0x0730 [ 25D32BE04FE0A23FDF57FD5382757672, 64E39E3E21D9173FB1116B989D80C244C49DA827698A05AF5CC5CD1C6AE155DE ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys 22:01:21.0220 0x0730 MRxDAV - ok 22:01:21.0230 0x0730 [ E671EDAB0726E05ECEF4058B4CD73C4D, 9F4C50E635CE2204E3291C8D3D7F658A969E80722B8B6F0304228D9B434C20EA ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 22:01:21.0250 0x0730 mrxsmb - ok 22:01:21.0258 0x0730 [ D4D12BC29DE0F09280868FDCA65B3474, A6FE89ABD52087FEE52FDF31DDF4CB627ED400E94FDA86BEBF1D4763F1E42518 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys 22:01:21.0280 0x0730 mrxsmb10 - ok 22:01:21.0288 0x0730 [ 93A77008A8932FC84A173C4E97E52874, B7510CF7998C538D68BD2ECDC512A0BFC7CB7362F598EE4110F728427AFF0F5A ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys 22:01:21.0304 0x0730 mrxsmb20 - ok 22:01:21.0308 0x0730 [ 74C9D21523DAE0C18F413C196DF0058A, 3DB4B8CA368D9DD82FAE2C2BC828A21142C8D29780A7C8667188C447519FF702 ] MsBridge C:\WINDOWS\system32\drivers\bridge.sys 22:01:21.0326 0x0730 MsBridge - ok 22:01:21.0331 0x0730 [ 308F08347923DEEDE7BC03EC7D485841, 72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0 ] MSDTC C:\WINDOWS\System32\msdtc.exe 22:01:21.0349 0x0730 MSDTC - ok 22:01:21.0354 0x0730 [ F01B849D9D4A8CEAF32D4FDBD0B83C92, D2473AC4C6E6C03DEF13EA73EC78FB878BDC95C047651BF79A16C9DEA82AD046 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 22:01:21.0369 0x0730 Msfs - ok 22:01:21.0372 0x0730 [ 22ECD8F5D1DFADF2011BBB1700CB871D, 8F9EFF51137394EFA5471B8A29C541710063B65806B075B4925A84D5B6BC3BBB ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys 22:01:21.0384 0x0730 msgpiowin32 - ok 22:01:21.0387 0x0730 [ FD870F6968A145E4D2BA8A8842686B03, 34B8F601F3B5E42B4D0A41E2AF7DB4EB4E5B627DA8DA9A2A2D46B153AF23AEB1 ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys 22:01:21.0401 0x0730 mshidkmdf - ok 22:01:21.0404 0x0730 [ 30364757963A028CE5DF0FBAAC270173, C72588A6A52FF8E418A15D2C407A4DB7EA768585423720145F8253D5CA519DC2 ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys 22:01:21.0418 0x0730 mshidumdf - ok 22:01:21.0421 0x0730 [ 6BB0FEDDAE7135FA37FFAFF4D9E0E876, B41A3C0FFDFC493D6325ED493445AFCED04EC9DFF2B38125616FC5419AD1ACC4 ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys 22:01:21.0432 0x0730 msisadrv - ok 22:01:21.0438 0x0730 [ 07E3E54734B14F43A4A95A849C0A0DE2, 314AA02EA84D267B32DBAEBEA6C1AC1A266DED1E8D35A17B41D1D2AC75E8049E ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll 22:01:21.0456 0x0730 MSiSCSI - ok |
16.02.2017, 22:12 | #18 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABYCode:
ATTFilter 22:01:21.0459 0x0730 msiserver - ok 22:01:21.0462 0x0730 [ 13D614E6B51ECF36746C48CE829FA7F6, CAD63C0A4F7110093F84C58252C5803F14E3FC46584B79DA17EC86D49FEAEA64 ] MSKSSRV C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys 22:01:21.0481 0x0730 MSKSSRV - ok 22:01:21.0486 0x0730 [ 642CDE46351D5D2D90311E77072AB46D, B2D3033E607BA2F6E6B9CFB1CBF154CD0CE910EA473C56343EC81B9B94044CCA ] MsLldp C:\WINDOWS\system32\drivers\mslldp.sys 22:01:21.0502 0x0730 MsLldp - ok 22:01:21.0505 0x0730 [ F2302A5CE63CA7673200FAFCEEEDB6AF, B8C44FC2DC0332183DE325CDBF511101F3307225295EDD428CE575A8DE15C223 ] MSPCLOCK C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys 22:01:21.0523 0x0730 MSPCLOCK - ok 22:01:21.0526 0x0730 [ 6114512EA26E835BA522C63635429DB5, 0F91CE41B4555316A79AEF3047C152D538CC9C7C329987C9FD0E3D961AFC87C8 ] MSPQM C:\WINDOWS\system32\DRIVERS\MSPQM.sys 22:01:21.0545 0x0730 MSPQM - ok 22:01:21.0554 0x0730 [ AA538E16E644D00E3BA5349BBA9598EC, 64A68B06883FE7ED34E04AB119BA819753F1222923EDD4E802C35D402B89D075 ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys 22:01:21.0572 0x0730 MsRPC - ok 22:01:21.0579 0x0730 [ 7ACFE7435317E791FF9EED2F49B402F2, EAF2CE12403A9D975112A22EDBC313EE63B926C070B35E62D515403DD34BD88D ] MsSecFlt C:\WINDOWS\system32\drivers\mssecflt.sys 22:01:21.0594 0x0730 MsSecFlt - ok 22:01:21.0597 0x0730 [ 0543BEFD41EC4D25C7F7CF36409CEC7D, 631622CFEC49952C0470531B23FFFFF483DC0EFFEF7A97B1179A600392C05DDD ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys 22:01:21.0609 0x0730 mssmbios - ok 22:01:21.0612 0x0730 [ C1569E4DB8EFE3617847BF041A3C842F, 99ADE5E7F50E04CAEC737F7F90741CCA8EE628996BA5EB6C6BC62184884429B6 ] MSTEE C:\WINDOWS\system32\DRIVERS\MSTEE.sys 22:01:21.0631 0x0730 MSTEE - ok 22:01:21.0634 0x0730 [ 130B16970154BA9876B09E5C4BAC63BE, BE3AF8FC5A26AB9C9DBA9C015C2E1FD3C4CD9CB423A2BBDABA91428BF8620553 ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys 22:01:21.0648 0x0730 MTConfig - ok 22:01:21.0652 0x0730 [ 640617B6E682A150C36BE39D78547F6C, 784F712E9DC3EEE81F07946BBA08AA2BEAC7B3961E430B75043645EF7ECA715C ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys 22:01:21.0660 0x0730 MTsensor - ok 22:01:21.0665 0x0730 [ 15D987C8F6CCD4AC94E070C5986762CB, 452FB0C48B86C7F8F53794CC2DDBF2B900B03A0383B2DE8F6A830F8CB0AFBAD8 ] Mup C:\WINDOWS\system32\Drivers\mup.sys 22:01:21.0679 0x0730 Mup - ok 22:01:21.0683 0x0730 [ 3D2C5B4995CA0751D32DEA0DE9FDFE44, A26958785FD9E05E2CA97078C9BB277CD44222BF5F7D9E8DC2F3F6AAAFFC6483 ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys 22:01:21.0695 0x0730 mvumis - ok 22:01:21.0708 0x0730 [ DB31EBB04C871F422C36A0962DA7D38B, B1BC2344744F537FB2C7D07B415F860195B7795E185253F05C0817A3764FEC10 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys 22:01:21.0738 0x0730 NativeWifiP - ok 22:01:21.0744 0x0730 [ C3D9870E680D9D843B18F4626C3858FE, 43596CAC9FB488F810FBA954C52BC4D13F7D32028C40ACFE33DFD7EE36A65C17 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll 22:01:21.0763 0x0730 NcaSvc - ok 22:01:21.0772 0x0730 [ 04CE2C0F0759EACD886BA4B658B60D5D, E34D0976FC5936C8629800D826DB127072D1DFC3D350EFACA3AA1B8119551762 ] NcbService C:\WINDOWS\System32\ncbservice.dll 22:01:21.0795 0x0730 NcbService - ok 22:01:21.0800 0x0730 [ E6094065008FE423377294050E7CEA2D, 86E200227256407530E2C28243DEFBC3CB6E9497644404D9AD79DA242286DF7B ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll 22:01:21.0821 0x0730 NcdAutoSetup - ok 22:01:21.0826 0x0730 [ 629CB21AC49C8867E0F29DF1C16DB7B4, 20663E68C69D0A1A2FE99A0C2A9DEFABF49786A1DC8F7F4E1699458AF57D7E79 ] ndfltr C:\WINDOWS\System32\drivers\ndfltr.sys 22:01:21.0839 0x0730 ndfltr - ok 22:01:21.0862 0x0730 [ D5564FC81350458ED570528C4E3B1CCF, DD3C5012492EF9BCE3BE635BBB3AA40B3C5F5FDBD795A76B327D9C994102AC2B ] NDIS C:\WINDOWS\system32\drivers\ndis.sys 22:01:21.0896 0x0730 NDIS - ok 22:01:21.0901 0x0730 [ 6DD605338FAAF6BA17662AA874E0D162, 636607829F5D7C3B7A4683C0A2DD594360D72F2AA3F8710153BE32575AE34A15 ] NdisCap C:\WINDOWS\system32\drivers\ndiscap.sys 22:01:21.0916 0x0730 NdisCap - ok 22:01:21.0920 0x0730 [ E34196F285F8B8879E1FF36C31F7179E, 77A4F24F995D4C0689C43F9956E08DCEC62517E4F8B1B9EAA1852B5293DB5B9A ] NdisImPlatform C:\WINDOWS\system32\drivers\NdisImPlatform.sys 22:01:21.0938 0x0730 NdisImPlatform - ok 22:01:21.0941 0x0730 [ 1FAD2398673F30CEC616B89C46B7DCBA, 70302049E6AE2BC6B3A7A9DE54D3F940AD6A9771CC2EBCCEC65994E67A25ECB5 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 22:01:21.0959 0x0730 NdisTapi - ok 22:01:21.0962 0x0730 [ AEB8ECBE66CC46854066CB1F5623E179, 2F650A85A9DAE38887610C0B876621035616CEDB65D4BBBD7F1405616D218AAF ] Ndisuio C:\WINDOWS\system32\drivers\ndisuio.sys 22:01:21.0978 0x0730 Ndisuio - ok 22:01:21.0980 0x0730 [ 7340104C2BF2F126714F7CDE85E63610, 45B64EC6F3A4C43F7D74806789067658C6EF0D44D36B841F4D26E1EBC95AF66C ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys 22:01:21.0995 0x0730 NdisVirtualBus - ok 22:01:22.0001 0x0730 [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] NdisWan C:\WINDOWS\System32\drivers\ndiswan.sys 22:01:22.0024 0x0730 NdisWan - ok 22:01:22.0030 0x0730 [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] ndiswanlegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys 22:01:22.0052 0x0730 ndiswanlegacy - ok 22:01:22.0056 0x0730 [ 78A12E3DF035B5D054986949B19BE43C, AD9B34F89B9F27D473BD5FCE6694A40FCCB808B61ABEDD6F70F1AF6C7E73ABF8 ] ndproxy C:\WINDOWS\system32\DRIVERS\NDProxy.sys 22:01:22.0075 0x0730 ndproxy - ok 22:01:22.0079 0x0730 [ 04C8859355C1DC9C0FA198D1894D71C2, E7C67E73009341B5D402470C686781B3C7BBE2531CE26665E08E711B990B1A77 ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys 22:01:22.0100 0x0730 Ndu - ok 22:01:22.0105 0x0730 [ 6C76780A01FC2B885BD6E957B5C36B02, DB7834F03A765F65C773E772D8051AFADB22CA4B5074180AA397857A0C47A068 ] NetAdapterCx C:\WINDOWS\system32\drivers\NetAdapterCx.sys 22:01:22.0121 0x0730 NetAdapterCx - ok 22:01:22.0124 0x0730 [ 5D1513BD6430307C9DB86C6E351372ED, D2AB709CF7CFA5B857B084AFC821914A975B7DDDCE154229981F19448973BD6D ] NetBIOS C:\WINDOWS\system32\drivers\netbios.sys 22:01:22.0136 0x0730 NetBIOS - ok 22:01:22.0145 0x0730 [ 6FEBB0A847FFD5F057B9AC8889F1B9A7, 558BCC64C59079E6569F61CCE1219A124B3313FC4E6CB5CBCC94124D202FF19D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 22:01:22.0166 0x0730 NetBT - ok 22:01:22.0170 0x0730 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] Netlogon C:\WINDOWS\system32\lsass.exe 22:01:22.0182 0x0730 Netlogon - ok 22:01:22.0190 0x0730 [ D3BF2DA9216A4CF22A97820A50A67EFF, D00CBE0A7ECFB449D9B48967A01EE56141404EBE229893D5A1710781AD5F2551 ] Netman C:\WINDOWS\System32\netman.dll 22:01:22.0212 0x0730 Netman - ok 22:01:22.0224 0x0730 [ F2645D51DD8AABC8BC72358409410437, 8CB97628923D6CEA6EFAD7E666BE92C154060BD108C28D46287A520A14B18ADA ] netprofm C:\WINDOWS\System32\netprofmsvc.dll 22:01:22.0253 0x0730 netprofm - ok 22:01:22.0261 0x0730 [ D65F295A049473E6A39EA9A0EA76CA32, 274FC0BA044EB2D14093AB0E561F7FACEE06A3F433C81343C8B926FA2F9BD251 ] NetSetupSvc C:\WINDOWS\System32\NetSetupSvc.dll 22:01:22.0284 0x0730 NetSetupSvc - ok 22:01:22.0292 0x0730 [ EFA857E2B0CC7C9DFEF48A2187B910F7, 424475568CD70237F056838388A5F7BDCD1B09349085498644C75940B12E8EAF ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:01:22.0307 0x0730 NetTcpPortSharing - ok 22:01:22.0312 0x0730 [ 3613FDA8969255DB4D5B1AD753A6749A, D9B37C73E0EBB7298A51F44E278EAD1A2EF0C814EF82BA3B0729905FB07F0129 ] netvsc C:\WINDOWS\System32\drivers\netvsc.sys 22:01:22.0329 0x0730 netvsc - ok 22:01:22.0338 0x0730 [ B996DE26A2E16053C9485F5905B05320, 30EB2CEB466A4F05A44F7CBFCDFD8CC3C27B5FCF1269C1B9410C48AB362D2A75 ] NgcCtnrSvc C:\WINDOWS\System32\NgcCtnrSvc.dll 22:01:22.0362 0x0730 NgcCtnrSvc - ok 22:01:22.0381 0x0730 [ 54C31C2B815E2E26BB8158022F837C9C, CED660D1A58F635C6452F82FCB2EF8ACEEB7785E31617B2ADFD9EE69A2BDF2B8 ] NgcSvc C:\WINDOWS\system32\ngcsvc.dll 22:01:22.0423 0x0730 NgcSvc - ok 22:01:22.0432 0x0730 [ 9B9F520C72EE33EAEC857124BB800243, DFA9386B272F4D86F3E4BE861A2FC4617261E1AA40576DDA610FC24AB4961A63 ] NlaSvc C:\WINDOWS\System32\nlasvc.dll 22:01:22.0457 0x0730 NlaSvc - ok 22:01:22.0461 0x0730 [ 001CBD7A2CD45C4EB39C01C3C677EF73, F4AAF4D60DB1232921C7811A62287B55C7C098B7A1FF9A40D88AF58A5ABECBA2 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 22:01:22.0476 0x0730 Npfs - ok 22:01:22.0479 0x0730 [ 90F5DC9802AAA00CD0B6E2AD9E7FFADC, 71C0777829299DECA6ACD42F38802DBE3C29A42CFBD8A396F39DFA44D1F55B6C ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys 22:01:22.0494 0x0730 npsvctrig - ok 22:01:22.0497 0x0730 [ 1993C85962692EF7024501E7FE92D466, F5BCAA8308495EBF8BB061C2015E07C202A779668D171364D7E312975BC18B10 ] nsi C:\WINDOWS\system32\nsisvc.dll 22:01:22.0512 0x0730 nsi - ok 22:01:22.0516 0x0730 [ 0C6218321A09A7B51BA7FFAFBA4CCB21, 330B3FA793A78410B28DFC8250BBF24442E3BB80434A7938BB96F02337614E0D ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys 22:01:22.0530 0x0730 nsiproxy - ok 22:01:22.0573 0x0730 [ DB69C6DA8B3DDFDC547D455CA23A8250, AE495CEB18924C8B21F7F150FF17CD00880F2E222D7B5155661798E0535D63C4 ] NTFS C:\WINDOWS\system32\drivers\NTFS.sys 22:01:22.0629 0x0730 NTFS - ok 22:01:22.0633 0x0730 [ 6E6DD6F9DD2A034CF85E94047DBDB992, 63D0A0756F551B7668D1CBAB24B29FD462C706E8A81690BC248D6C92061FE215 ] Null C:\WINDOWS\system32\drivers\Null.sys 22:01:22.0648 0x0730 Null - ok 22:01:22.0656 0x0730 [ 207A78939B7BBA0EFE8BFA947A35E71C, BB7DDFED575F81CAB958DDC7CFF2D798EB14DAE633F49FA2229D98BDC489C0EE ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys 22:01:22.0668 0x0730 NVHDA - ok 22:01:22.0930 0x0730 [ B360CFC497FF8070E37AEEA92CEF14BC, 3172A296192640474E9B78A83C66079D916523F04D950AA56B65D570BED633FA ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_02838dee03d82b94\nvlddmkm.sys 22:01:23.0186 0x0730 nvlddmkm - ok 22:01:23.0203 0x0730 [ D261DF41F0840F734856A2B4F5E072C7, 2E703556D0C919375D0B7770513456844B13362190643D5524663EC8546E0FF5 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys 22:01:23.0216 0x0730 nvraid - ok 22:01:23.0222 0x0730 [ 23B702B555EB0436B9DAA0BC63DA65CE, D454F80D9657CFEC852F022C12D7B2C1A2D7D247ECC591EDB07B9369DFD8C99E ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys 22:01:23.0236 0x0730 nvstor - ok 22:01:23.0246 0x0730 [ 17997DC2441F7E29CDFC6458E0392764, 636CCE2DA1EF8195B33F8D6D5C8CC151D58EBF08DC9AD8ACCCE7ABD41A69639F ] OneSyncSvc C:\WINDOWS\System32\APHostService.dll 22:01:23.0270 0x0730 OneSyncSvc - ok 22:01:23.0280 0x0730 [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll 22:01:23.0304 0x0730 p2pimsvc - ok 22:01:23.0314 0x0730 [ 2BBCED66D7AFC968BDBB0E4D8524DF0A, 762D916390F9DE69B3EA1D31244224F910645F8E5CEF4C505B76B215BFDFCD9A ] p2psvc C:\WINDOWS\system32\p2psvc.dll 22:01:23.0340 0x0730 p2psvc - ok 22:01:23.0344 0x0730 [ 6B81BF7853D161DB8AC62CD8B9C2DE6B, B2DC06D135FD2501217DDA7349556EB873309E02188D4C3901807BA24FAB30C7 ] Parport C:\WINDOWS\System32\drivers\parport.sys 22:01:23.0361 0x0730 Parport - ok 22:01:23.0365 0x0730 [ CDBD029BAEC8D09F6FBD404632D9AF28, 71F4401150CD4C9C6BBF2DA854CF07EA2F8C9BBE900833858F49134DDAF14414 ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys 22:01:23.0379 0x0730 partmgr - ok 22:01:23.0390 0x0730 [ CDD8EDF4C35BE6D6137112F5CC7A70DA, 80EECA6BC2E668E5652A5CA9B119CCCE2A2E421F0EED1FD0EAC20C42E77C02ED ] PcaSvc C:\WINDOWS\System32\pcasvc.dll 22:01:23.0411 0x0730 PcaSvc - ok 22:01:23.0420 0x0730 [ 29AF16726F4DD84376ECA85AB6AFF2C6, BEF9EA10637065365ED343C4EBA51191B9BEADD8F1F3362D3EFE75F40BE9A027 ] pci C:\WINDOWS\system32\drivers\pci.sys 22:01:23.0437 0x0730 pci - ok 22:01:23.0440 0x0730 [ 214DCC87E3898F738075D1341252A552, E721FBBC3510DDB848A8CAEA3B6031EE988F42252DBC3BF7BDB6ABD9A0D9FABD ] pciide C:\WINDOWS\system32\drivers\pciide.sys 22:01:23.0451 0x0730 pciide - ok 22:01:23.0456 0x0730 [ AED76A3333B3A31536E430020E0226FC, EC255B79B0908E3C142D92E35B79D90A3F2594BA012CA2B1B04A6A8745153430 ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys 22:01:23.0469 0x0730 pcmcia - ok 22:01:23.0472 0x0730 [ E63FB38B6E75B39467492FBAD2CD512A, DB406C92BA2460C833A49B98EB5BD58348E868F643A0123B0C9B5315FFC6A124 ] pcw C:\WINDOWS\system32\drivers\pcw.sys 22:01:23.0484 0x0730 pcw - ok 22:01:23.0488 0x0730 [ 9EA203A07EFA6D74F07F32EF0DAB5CA6, D851F1CC748B4CD0E263931668FFF2FE20D5778267F4FF2237D565CFC171B5AF ] pdc C:\WINDOWS\system32\drivers\pdc.sys 22:01:23.0501 0x0730 pdc - ok 22:01:23.0516 0x0730 [ 1509A77F840AA9E72CF8247D0CF2FBDE, 2D47AD4D8F5C2D871E603FB6D72D25EFD0E63FA3A542DAADAB9D82ED074C0E0B ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys 22:01:23.0553 0x0730 PEAUTH - ok 22:01:23.0589 0x0730 [ 2B55ACB1727A8E5E7514D2D75AC4EBEB, 5E7449F3EE0B15E400E405DE561ED2D3932259107A9D9320AE42CA1A5C5AB992 ] PeerDistSvc C:\WINDOWS\system32\peerdistsvc.dll 22:01:23.0654 0x0730 PeerDistSvc - ok 22:01:23.0660 0x0730 [ 540116170E2135FCD5DDE77702166B67, CBEC51C2D47532F1781B3255040F303263420B204C2F8BB2B5D1EC342F57B285 ] percsas2i C:\WINDOWS\system32\drivers\percsas2i.sys 22:01:23.0672 0x0730 percsas2i - ok 22:01:23.0675 0x0730 [ 8356F87553BF49C703CF382033815898, 245EB941566D848F134629690BF271B1CBEAB6440771D3D8D7AED3756835354E ] percsas3i C:\WINDOWS\system32\drivers\percsas3i.sys 22:01:23.0687 0x0730 percsas3i - ok 22:01:23.0702 0x0730 [ CB5343FF52A702A9ACFAAE6BE972FE09, EAA5362D91D05D382DF4EBBAA3FD575456F23CAD531CC6F1270F8254892DBF02 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe 22:01:23.0718 0x0730 PerfHost - ok 22:01:23.0738 0x0730 [ D0D57322ABC7473E54472D8374169CC5, BD14A13D6908C8669E56EF9401FD8A3D7C618E8B6556B36E634864E733BCA4B2 ] PhoneSvc C:\WINDOWS\System32\PhoneService.dll 22:01:23.0773 0x0730 PhoneSvc - ok 22:01:23.0780 0x0730 [ B4AB2C0177715FFAED88A1223212043A, 1920792ADC78DD51EF98B6A9634D686EAED0848FB7EF74A0DCD3AEBA5AF41EC6 ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll 22:01:23.0800 0x0730 PimIndexMaintenanceSvc - ok 22:01:23.0829 0x0730 [ F931F21E4287FE3ECCF09B54A232BBA2, CEB7AB3236E5F30214027092B7B695ED35F7A1E007DF4046797D1E4DFEF49EC8 ] pla C:\WINDOWS\system32\pla.dll 22:01:23.0883 0x0730 pla - ok 22:01:23.0889 0x0730 [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll 22:01:23.0909 0x0730 PlugPlay - ok 22:01:23.0913 0x0730 [ 56D7A89423325121C4A9BD5C326414F3, 649048C23D1973C3504E26B35362AC99DFE9BF31FFE73F45B43306A212AEA34C ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll 22:01:23.0928 0x0730 PNRPAutoReg - ok 22:01:23.0936 0x0730 [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll 22:01:23.0959 0x0730 PNRPsvc - ok 22:01:23.0969 0x0730 [ F70CAC34B455D05EAA04B2F8FB58E1CB, 295BFFB3DA03C5CE5462C11D3240024B68AC06E8DEA9062A739BE2CCEE19EB5D ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll 22:01:23.0993 0x0730 PolicyAgent - ok 22:01:23.0999 0x0730 [ 60C8376B48BA96F07AEA536527433D44, EB988C119C3E71169B91ED2A744C71933DD35447DC4A8249E80EC24E9E7077D4 ] Power C:\WINDOWS\system32\umpo.dll 22:01:24.0018 0x0730 Power - ok 22:01:24.0022 0x0730 [ 5645B9D9788CCA2C88B9534996ED2D6D, 4988942DF163DB5B9B1A08CE6B628D2C47C2E2EAA30AEAE4EFE21C8CF4C8DC5D ] PptpMiniport C:\WINDOWS\System32\drivers\raspptp.sys 22:01:24.0042 0x0730 PptpMiniport - ok 22:01:24.0103 0x0730 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll 22:01:24.0204 0x0730 PrintNotify - ok 22:01:24.0211 0x0730 [ 372913E12677A8CBBBABDD8311894F9D, A5233D95A0D22D2A9DB214E7CB79A99D389B67189FF6A87D0AD4610A333A637F ] Processor C:\WINDOWS\System32\drivers\processr.sys 22:01:24.0228 0x0730 Processor - ok 22:01:24.0237 0x0730 [ 1F115AF75EFBAC28479B4F94A3F8D4A3, BE8D8C50D985F6AF9DDC0F13BDBE2D55D600E1F5E344982536538B14EC484AA6 ] ProfSvc C:\WINDOWS\system32\profsvc.dll 22:01:24.0261 0x0730 ProfSvc - ok 22:01:24.0267 0x0730 [ FC98407B85A31161851FDE245517574F, 2CCD706CF243934FCDA32B24CE0C385EA2E67F206E0306FA584496F583A20CD1 ] Psched C:\WINDOWS\system32\drivers\pacer.sys 22:01:24.0281 0x0730 Psched - ok 22:01:24.0289 0x0730 [ 7A68710BAC9B6809314B86C0CB1CBC4A, C02D97993D1F6FE6EFBA5B1366B3A4FE8CE1136A95F3A2DA07BA59554C163501 ] QWAVE C:\WINDOWS\system32\qwave.dll 22:01:24.0311 0x0730 QWAVE - ok 22:01:24.0314 0x0730 [ 819602BBBFDB0BD46DEA3715BF0DD452, D4007FF1E5296316B53436CA3598D6B1CF4F60AB77D5B02F3E595081EDD5D879 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys 22:01:24.0329 0x0730 QWAVEdrv - ok 22:01:24.0332 0x0730 [ CDF47037A0939F56D11F699629C276AD, A63F2A3FE80FB8084E3870E907505694B79EE1D9E56E292C01D481FEFD2534B0 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 22:01:24.0346 0x0730 RasAcd - ok 22:01:24.0350 0x0730 [ 28C2EA278070EE12701D0EDF8CB0EC36, F10288C1C6835840026DB30285345EF892DE989F43C948E7F4760B8895FF675F ] RasAgileVpn C:\WINDOWS\System32\drivers\AgileVpn.sys 22:01:24.0367 0x0730 RasAgileVpn - ok 22:01:24.0372 0x0730 [ 7B82197BF35CC3BE59AEF8B706AB8A16, AB0216164A548A48CD21F5F035E57E867584A96890B9887EC08F8DABDD89F990 ] RasAuto C:\WINDOWS\System32\rasauto.dll 22:01:24.0389 0x0730 RasAuto - ok 22:01:24.0393 0x0730 [ 17E565710172ED71B8531D8822E1C5D1, 0CA39ABD9E544DDAD9D9D7D1FC50444274C31E18F9BF73069051D9F62833698F ] Rasl2tp C:\WINDOWS\System32\drivers\rasl2tp.sys 22:01:24.0413 0x0730 Rasl2tp - ok 22:01:24.0428 0x0730 [ F79BFB5588B777C71734C1D1EC129D07, 9B9D70EC8978AAC19B2B94694EE1B9957C13DFDDFCBE8AA82C5F0D0EA04CDBDF ] RasMan C:\WINDOWS\System32\rasmans.dll 22:01:24.0459 0x0730 RasMan - ok 22:01:24.0464 0x0730 [ 9387DF155233D45D4E010F4F2FB52A57, CABC25DA4E512809AED0085767BDD94BF3C1DA792BFF8A009B5465D9110E7060 ] RasPppoe C:\WINDOWS\System32\drivers\raspppoe.sys 22:01:24.0480 0x0730 RasPppoe - ok 22:01:24.0484 0x0730 [ F0F4EEDEEBEE7A4244FAFB96A16B5712, F64717E601BD5EB674003009507B8CDD6F69F00E8670D6895EC64786166A0E8D ] RasSstp C:\WINDOWS\System32\drivers\rassstp.sys 22:01:24.0504 0x0730 RasSstp - ok 22:01:24.0514 0x0730 [ AF6963414B820B7C45578ED3300438A7, C00F60FD72608E6983D32642768AECE891DD816FADFA7B872BA88091C16B95D7 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 22:01:24.0533 0x0730 rdbss - ok 22:01:24.0538 0x0730 [ 79A415E6FA915EFC00297DAB16EC2635, 47BB49F6D756214193D38A4AB182B541AAC180381C3111FF7F9B0AD4C44D8733 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys 22:01:24.0552 0x0730 rdpbus - ok 22:01:24.0558 0x0730 [ 7135785C21CA79D270D11037C43D3F19, 654A3C65CF891ED8C82A740D10CF607FC7D709185E664DE03288CEB5B25F03A6 ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys 22:01:24.0576 0x0730 RDPDR - ok 22:01:24.0581 0x0730 [ 97A61A3CB2B5CB4FC32B3224EF333448, E4F2E8BCEE3639BE57BBC8A8E67FDE42C3A5158F1204684B0ECD216F4AA044A3 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys 22:01:24.0593 0x0730 RdpVideoMiniport - ok 22:01:24.0600 0x0730 [ 69BB204AE07EE84ECFAB1BF13C4BD04B, 1CA832CBF4AE4821EEA2A19F9519C2D1D00406B8CCE2A86FE3B33A5F293DB218 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys 22:01:24.0616 0x0730 rdyboost - ok 22:01:24.0635 0x0730 [ 940D6F5A2B0A61EE4170DF84F6C95C20, F8EE846DC8015EDFE7CB5BEEDC977EAA9C586BAC2216DE69D8ECCBDBC7408649 ] ReFSv1 C:\WINDOWS\system32\drivers\ReFSv1.sys 22:01:24.0664 0x0730 ReFSv1 - ok 22:01:24.0677 0x0730 [ 13F6B64235C60167052364BF7D99E4CA, BC12EE00775F7456FB922FBD684BF3F0CFABA5BEBB6E162C23B41DED5C20A978 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 22:01:24.0705 0x0730 RemoteAccess - ok 22:01:24.0711 0x0730 [ 3183B161B1F05333F6C325577FEF3596, D6A89B2A021377B6F371E5B9EFC36FF018822B28F0ED41F8CD2F00C5C8605707 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 22:01:24.0733 0x0730 RemoteRegistry - ok 22:01:24.0747 0x0730 [ 0660F4A14F9D2A2F59B26B1D74F1A6D0, A9443B6B7ED1ECA22AC960A2C6A2BE18C0BA58CD7BCF60E7AA617CD3662D122D ] RetailDemo C:\WINDOWS\system32\RDXService.dll 22:01:24.0778 0x0730 RetailDemo - ok 22:01:24.0784 0x0730 [ 5DAA644F17780FC4E3F4820A46D38FEC, 32C27FFA0A4608B164F4E709CD0D998AB73CA9713BE3E47F9DBC7B3D1B6C7453 ] RmSvc C:\WINDOWS\System32\RMapi.dll 22:01:24.0802 0x0730 RmSvc - ok 22:01:24.0806 0x0730 [ 672724C8B21B7DC56646045DE4D5B860, 79986E80A92C949C543959F1E35647A9788DAB2892AC20B6DEA5C0BBC0CEDE9E ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll 22:01:24.0823 0x0730 RpcEptMapper - ok 22:01:24.0826 0x0730 [ 109C1D609951E886D3643B15C1EDD1C2, 347D8E7C50EC7F96217C7421D9BC8A42C9DF50B94169CB58DCF857A63C33C2EA ] RpcLocator C:\WINDOWS\system32\locator.exe 22:01:24.0840 0x0730 RpcLocator - ok 22:01:24.0859 0x0730 [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] RpcSs C:\WINDOWS\system32\rpcss.dll 22:01:24.0898 0x0730 RpcSs - ok 22:01:24.0902 0x0730 [ 5FF28F097C9699097B473F8FC7C1AA7D, 695560F1DBD85073F3D6CB1FF16F16504CA044EA62E940E463A16BBA8B86E2FA ] rspndr C:\WINDOWS\system32\drivers\rspndr.sys 22:01:24.0918 0x0730 rspndr - ok 22:01:24.0938 0x0730 [ 3B32787A45586988A86CDFE954672F13, 8D013EB4FD6399ACD6F64DB117D9D35511D28CC47499F836E434BDCFAD914295 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys 22:01:24.0963 0x0730 rt640x64 - ok 22:01:24.0967 0x0730 [ B5DAEE69BACA64D2BB004568E22D8756, C0072CF6B438ED756435A182D55AC55F3AD356ACBD483DE06A94893D3CA8CCC5 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys 22:01:24.0981 0x0730 s3cap - ok 22:01:24.0985 0x0730 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] SamSs C:\WINDOWS\system32\lsass.exe 22:01:24.0997 0x0730 SamSs - ok 22:01:25.0002 0x0730 [ 5E73FB63E2DBC75FE0C17DEB0010CE0E, 9DAC47486262397D03BC01F7438CAB62CF33BD7B5283F5B9548C770A3D6D0ADC ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys 22:01:25.0015 0x0730 sbp2port - ok 22:01:25.0022 0x0730 [ 3CD0130FFDEAEACF0905B482F3934EA3, 1EC355B63135FD2563093EBB206741C0C4CCE0551A662F6DC86C875146A88B06 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll 22:01:25.0044 0x0730 SCardSvr - ok 22:01:25.0050 0x0730 [ 5E8ECCE130A72107B6DFDBE26185A7FB, 811E2CE485BC14161FF629069BCCF53B2B8C6F8B1E1A6B3A3C86DBE4F85A5577 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll 22:01:25.0070 0x0730 ScDeviceEnum - ok 22:01:25.0073 0x0730 [ 3D9A82B03C92D1FEC42CB171D6F57778, DC027F02F5EB5F1D10DB6F405FB0C15D4D5C922445F5F3C916624113278AF072 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys 22:01:25.0088 0x0730 scfilter - ok 22:01:25.0107 0x0730 [ D4DB6B318A0A0C74A90260725A228C0B, 57BA2EF9D880488C785C806ABF9EE753A48E589129442D72F815CD6EFFA07B22 ] Schedule C:\WINDOWS\system32\schedsvc.dll 22:01:25.0153 0x0730 Schedule - ok 22:01:25.0158 0x0730 [ 9055ADDFBA4C8B914C914CE693B55C0A, DB213AC36E14D856B81D2AFE46815402537A2ABEEA15032A9FF436F953129441 ] scmbus C:\WINDOWS\system32\drivers\scmbus.sys 22:01:25.0171 0x0730 scmbus - ok 22:01:25.0175 0x0730 [ B6F2363584E62960846F7C3F00124A4F, 252189FF9D623CF69BF415FF7C7FE74B0BBF756B632420578BFAFF6595616CF7 ] scmdisk0101 C:\WINDOWS\System32\drivers\scmdisk0101.sys 22:01:25.0196 0x0730 scmdisk0101 - ok 22:01:25.0214 0x0730 [ C1B5EE58E759C53F9939581709DC70BB, 85095ABC9459A766832373BC3839E573E9A73C967F8427D6B7CAB972551C3191 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll 22:01:25.0233 0x0730 SCPolicySvc - ok 22:01:25.0241 0x0730 [ 7C3D10BEC8B0DBA00A78C78EB10B3AE2, A671C9CB97977613576D70607E106C7A29B9EA9E875C7C5AF293EE5903D7AD0A ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys 22:01:25.0257 0x0730 sdbus - ok 22:01:25.0263 0x0730 [ F3714DBAA42C15F78FFCDFE4273214EB, 2D018970B92C5F0744FAE10A2FC298F3DCEA5C2EDEB760F4F0651337B9878ABF ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll 22:01:25.0281 0x0730 SDRSVC - ok 22:01:25.0284 0x0730 SDScannerService - ok 22:01:25.0288 0x0730 [ 120DFCB71D6C502613A9E2D50E16850C, 2C294010AD1C9C380CD5221A37720544178B7358C8C8553AF44055E4CEE5DAF5 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys 22:01:25.0301 0x0730 sdstor - ok 22:01:25.0303 0x0730 SDUpdateService - ok 22:01:25.0306 0x0730 SDWSCService - ok 22:01:25.0310 0x0730 [ EFD644DD091E1D94555FC3BBC95EA66D, FBDDA6680BEC378CCF12A32D9186020E884DA15A1E789D1531B1E687FC7B54B1 ] seclogon C:\WINDOWS\system32\seclogon.dll 22:01:25.0326 0x0730 seclogon - ok 22:01:25.0329 0x0730 [ F48535714BED7DD784853889B4594B26, 9B4AB7E7293E79A8F6CC46C84F23E62AD3BD6E958FCE078CDBB125A69FAC7E50 ] SENS C:\WINDOWS\System32\sens.dll 22:01:25.0346 0x0730 SENS - ok 22:01:25.0348 0x0730 Sense - ok 22:01:25.0374 0x0730 [ 2B4E090D06C60853C5C00CF255F9E02A, 4D4DBA7B04519622612BD4A4F28318CA2F5646C84CAFF8C5ACC9BF4C6031894E ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe 22:01:25.0423 0x0730 SensorDataService - ok 22:01:25.0434 0x0730 [ C09A42163878A082C3F0D0A3DFE95714, 8033DC38D0EDED3758DA6BF8C1955BE5FFE48863C079C589660B37D0E461300F ] SensorService C:\WINDOWS\system32\SensorService.dll 22:01:25.0460 0x0730 SensorService - ok 22:01:25.0466 0x0730 [ E6F00415DADCEEC860E7AB42BFD19A65, 274CAF22F93D43B6DB6953730E3DF8DA94776B24EEE74B80AB4CD780BC1366A9 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll 22:01:25.0486 0x0730 SensrSvc - ok 22:01:25.0489 0x0730 [ 401D706DDC0A7AF18C3DD228ADF74551, 27C0B38D7C2E3F6FF06201124E63483931F6071954B2B99EC0143C464238C0B7 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys 22:01:25.0502 0x0730 SerCx - ok 22:01:25.0507 0x0730 [ 7084D11083F0CDCA8B5C76F9846ABF5D, F639920882B0E784D8CFAF0D4C0F0C411937B6831E5DD99B0ABFBFE06BA4742F ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys 22:01:25.0521 0x0730 SerCx2 - ok 22:01:25.0524 0x0730 [ 3FF478A8ED32A83C36581425F6282B6C, 787646A17098EA7CF36064D0A950C1D470D4A280C8C5AC40023D566E53860EAE ] Serenum C:\WINDOWS\System32\drivers\serenum.sys 22:01:25.0538 0x0730 Serenum - ok 22:01:25.0542 0x0730 [ 92509187AA171A80521528B36F753E1D, FE0DA272B8A155ECC161E99586C4AE7EE17B1C84BC330DA1566C83B8E03FA825 ] Serial C:\WINDOWS\System32\drivers\serial.sys 22:01:25.0558 0x0730 Serial - ok 22:01:25.0561 0x0730 [ 433D38FF6D08B993847EA2A10EB8CB52, 29BA75DB6D1AC761BBDFB5AC8874FC7D763E1CD10D290E369063B34CE951270F ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys 22:01:25.0575 0x0730 sermouse - ok 22:01:25.0585 0x0730 [ 82CF273F0E8F243789683DEB40757569, 5433D93A41C4BF04494E6158931C6AC3154888F7CD3A417253EC02FF7EA6D00E ] SessionEnv C:\WINDOWS\system32\sessenv.dll 22:01:25.0610 0x0730 SessionEnv - ok 22:01:25.0613 0x0730 [ 697D3EE0740AEAB62B66ABCA1C83D13B, FCF54A0071ED04AD3FC8551C67FE5FD49089DC0510F753052CAC5972A65C9E3D ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys 22:01:25.0629 0x0730 sfloppy - ok 22:01:25.0641 0x0730 [ 832E933AA8DB9FD4733B96D8B6484D3F, 3A8E3D7ECA192EEE154CB568073B7211FDA06078EFC3BC7E961563A1BFDD0CAA ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 22:01:25.0669 0x0730 SharedAccess - ok 22:01:25.0683 0x0730 [ 482E6BE8A07832E824080D352075ACA1, 4123A76C8E805AF4FE229C53E9C174095C0937913BA81A63FE9B45C44AA5B15F ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 22:01:25.0719 0x0730 ShellHWDetection - ok 22:01:25.0725 0x0730 [ CF3BDF9EAD8D3EF671E9339B44B185BA, C17EC6D5B00F49D9C8B5B6C262A85F34ED71C58450659F006B3632AA84F68E23 ] shpamsvc C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 22:01:25.0744 0x0730 shpamsvc - ok 22:01:25.0748 0x0730 [ A34CE1830E45DA98932295FDE4B7908A, FC553ECF4D64B4B10B7FDE5352707785517A18D487A80665BAFC7261E3F35CDC ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys 22:01:25.0759 0x0730 SiSRaid2 - ok 22:01:25.0763 0x0730 [ A7B5C670770E908DA5FEF5BF1136E933, 8D3BB6FF65E631C34BE8EA766481B2FDB2E1E916A4FD67F86705A8975A136E6C ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys 22:01:25.0776 0x0730 SiSRaid4 - ok 22:01:25.0784 0x0730 [ B72B80E6FF423C5011E745CB76DA9A08, 18A6B9D46E91AD4D463EB5CB832702392D2E162577F90C328B515FCE69FABD15 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 22:01:25.0804 0x0730 SkypeUpdate - ok 22:01:25.0808 0x0730 [ B31A83EE76350323DAA92382151B1E3E, 316F0744CF53EA6E00F6B0827A210D65B5F4D8BCC75121D14FE3721AF6AA514B ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys 22:01:25.0816 0x0730 SmbDrvI - ok 22:01:25.0819 0x0730 [ D233EAE2A9D48485321816486ED635EF, 03AB49BE9CF15EB7EDC50C400E673B4DF0E5BFDA9A7811E157F2AF2F3CF38D49 ] smphost C:\WINDOWS\System32\smphost.dll 22:01:25.0835 0x0730 smphost - ok 22:01:25.0848 0x0730 [ 0B217141AC1283655402CDB356577735, 6EFA4CA46CFC8B7156CE7E5CA89B7F7073E16D66C2FC13F4DB95FEB78CCF698F ] SmsRouter C:\WINDOWS\system32\SmsRouterSvc.dll 22:01:25.0878 0x0730 SmsRouter - ok 22:01:25.0883 0x0730 [ 6F4CE07D420FB657B5936F71101ABD41, CEC52984C56E578E0FFE12BE1B8148335F788B7D1751F2D0E79B944A41113C20 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe 22:01:25.0899 0x0730 SNMPTRAP - ok 22:01:25.0911 0x0730 [ C994DF90427103CCB80F893FFD2B1CE8, 7E4B08095C77E68D337A3425EEA38F8FEC4D103CA7661E34FD96BF518DFB4BCB ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys 22:01:25.0933 0x0730 spaceport - ok 22:01:25.0937 0x0730 [ E03264C4C25B568F92ED1656AD541E64, D42942BFFBC7213D204FAF84F4FE015FC23A6ACB29B5E752834EDBC17A3AC20D ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys 22:01:25.0950 0x0730 SpbCx - ok 22:01:25.0966 0x0730 [ 79DCE27E8C4CF6701BFE49EC2446BBF6, F51CBB7A45C3C878F41653FD5FBDC93CC302712B7725DAAB4D3475A1F4771E3D ] Spooler C:\WINDOWS\System32\spoolsv.exe 22:01:26.0002 0x0730 Spooler - ok 22:01:26.0102 0x0730 [ 23529A00195CE71252FEBF647E56E27D, 8ADF7A1C96DAE005E9A974D90BE8954F88D49B6848252B88513C49E0A3BD9774 ] sppsvc C:\WINDOWS\system32\sppsvc.exe 22:01:26.0225 0x0730 sppsvc - ok 22:01:26.0240 0x0730 [ E83830BB74AE8CBECEA0ECD94DE436F9, 4A34569A34260324EBD629039E1BF45A3527FC75B22D9A3DB6360A6EB365483A ] srv C:\WINDOWS\system32\DRIVERS\srv.sys 22:01:26.0264 0x0730 srv - ok 22:01:26.0279 0x0730 [ 55CA5329D1ADEB8F8034045930147AE4, D4F31BC82700D166564C7F9CDCEA3ABAB4A37B55137C34572768DF46FDA9320A ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys 22:01:26.0312 0x0730 srv2 - ok 22:01:26.0319 0x0730 [ F13EE0DB1FB1D6946AC3228D7EFCFC8F, 109A809F0338FAB0F4045FA5EE33C6F0A994A9F586B2FBD8920A6AABA0E0EF66 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys 22:01:26.0339 0x0730 srvnet - ok 22:01:26.0346 0x0730 [ 44758105AB3EA34E815D4B6CA1153311, 7F223A20D2538C123BAC6F75BE0E126876A116F09502FD980C05B8916E26E1B7 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 22:01:26.0367 0x0730 SSDPSRV - ok 22:01:26.0374 0x0730 [ B97C7EC07218A8002323718202BF5E77, 39D3254383E3F49FD3E2DFF8212F4B5744D8D5E0A6BB320516C5EE525AD211EB ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll 22:01:26.0394 0x0730 SstpSvc - ok 22:01:26.0468 0x0730 [ 4E330AD1EED4A5D582EE415FD55953A2, 2C02E1F45F74D250110BA5117AA942495CB2EBAC7F2CCECC284B4FB8F47B13E1 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll 22:01:26.0591 0x0730 StateRepository - ok 22:01:26.0622 0x0730 [ 596DC69BB40A96FCA4B19D9D1E221E34, 3469D3B2E9A88E39C14AE2E3DD5EC3D91FBB88CA568D794555B397B50E64AB15 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe 22:01:26.0654 0x0730 Steam Client Service - ok 22:01:26.0658 0x0730 [ 29D26E1347AE1BBD4201014E19880B2C, 9E2153AD96CE4F189EEE43BB02515532C619FB1CA02D8F6DEF517AC3347AAA14 ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys 22:01:26.0670 0x0730 stexstor - ok 22:01:26.0684 0x0730 [ 91CB95B35481155BFE29C217CD237F27, CA66957DF1441D991453BEF02D768D44E5D9A484BC23C8874E8A7AC20904CB06 ] stisvc C:\WINDOWS\System32\wiaservc.dll 22:01:26.0717 0x0730 stisvc - ok 22:01:26.0722 0x0730 [ 53EB8CE34B55A1EE63424C8DB7388BFC, 5AB59117BA8A2844EB8693CCC19B217AE039B28C87519F96E1C845FE9BF456C2 ] storahci C:\WINDOWS\system32\drivers\storahci.sys 22:01:26.0735 0x0730 storahci - ok 22:01:26.0739 0x0730 [ C5E0ACE4771F5575D9D5B457ABF3AD03, 365880BC5AC313F25C313EFB7758301F98D9B2BF4C5FC9499F98C2B7F8407D96 ] storflt C:\WINDOWS\system32\drivers\vmstorfl.sys 22:01:26.0751 0x0730 storflt - ok 22:01:26.0755 0x0730 [ B66D8C75C9BC59D637177AB3B1C569A6, 76252A631F03EEBF5FDC7693F6B0A5E73838CDBE3157114CC96B8BBE88B476BF ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys 22:01:26.0767 0x0730 stornvme - ok 22:01:26.0771 0x0730 [ BEBF85EB4D90E6996047DA027D0ED26E, DF109CF0F07CDD1B9B702C2A076D4DD5366DAAD971CC9359AF0358E79981706F ] storqosflt C:\WINDOWS\system32\drivers\storqosflt.sys 22:01:26.0787 0x0730 storqosflt - ok 22:01:26.0797 0x0730 [ B91FBE7CB4633FEB32AFBD0B48576396, 9EFDD92E8096CE5555F8DC3C870864E5515469603C2373B99B3607234633CA66 ] StorSvc C:\WINDOWS\system32\storsvc.dll 22:01:26.0821 0x0730 StorSvc - ok 22:01:26.0825 0x0730 [ 8E73037A6F8938475692FFCC26EBF385, F78C5CD1A3CD17AA831EEC82426B14006B4DDBC9085A4814E04E8C37FD6B05F7 ] storufs C:\WINDOWS\system32\drivers\storufs.sys 22:01:26.0836 0x0730 storufs - ok 22:01:26.0839 0x0730 [ 9D9DED47DA10E845EFF2DD57C94C809B, 520D0CE7A867051B80C8141E351FE5A5BCE3C99776093F234DB77D3407B1F104 ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys 22:01:26.0851 0x0730 storvsc - ok 22:01:26.0854 0x0730 [ 224C92E442B1B8C20C274332F1ACF00D, CDE5DCFB7A21089464A6E2ABB29BBE08B184C3433C218756AA5902A8F67C0B2C ] svsvc C:\WINDOWS\system32\svsvc.dll 22:01:26.0871 0x0730 svsvc - ok 22:01:26.0874 0x0730 [ 505E0C40B5D0ADDCBB414640F59BD2E0, DF4B5E65FE6FF2224F298A2A2FAC9B648C082DFF8463148633647580A9FAD34D ] swenum C:\WINDOWS\System32\drivers\swenum.sys 22:01:26.0885 0x0730 swenum - ok 22:01:26.0895 0x0730 [ 2EE27411B5904C63D723BEA391819F58, C88C11D460E90398E16011B8A2CED5EE5626084F24790EA6115532F8F70060C6 ] swprv C:\WINDOWS\System32\swprv.dll 22:01:26.0924 0x0730 swprv - ok 22:01:26.0928 0x0730 [ 32F46FB0F290D16DAA452B289C985795, 73F88AAAA6026DB4C27F1D054145216DCC3F1960946FB2A7A90518DD1D5737CB ] Synth3dVsc C:\WINDOWS\System32\drivers\Synth3dVsc.sys 22:01:26.0944 0x0730 Synth3dVsc - ok 22:01:26.0963 0x0730 [ FED48B19D6F55D7A3AB498D85729D1BA, FA5E0E02BC2E2DE108C55991E3B063CC947072228B53539F42F922661510DE7C ] SysMain C:\WINDOWS\system32\sysmain.dll 22:01:27.0006 0x0730 SysMain - ok 22:01:27.0016 0x0730 [ D9FEA79BF6AF136F8E656AE045C2FEC8, E6F08A93348E035185F0F1C6B6277E636F4F25D1136E3ACCA63488DAEEC7114B ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll 22:01:27.0041 0x0730 SystemEventsBroker - ok 22:01:27.0046 0x0730 [ 86E7FD5C8DBEC1EB51C4368561402B75, 86EE61414CD5854E39E33F67BF5DA4377B569B3ED4D18882C470BC6784891DA1 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll 22:01:27.0065 0x0730 TabletInputService - ok 22:01:27.0073 0x0730 [ 3929C8FC134AC672C4F3F85160956257, CD3195CA58BA6F55EA0DDA2BE6AB58280AD1CA488D7AAA1539DD05FB99374F36 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 22:01:27.0096 0x0730 TapiSrv - ok 22:01:27.0143 0x0730 [ 4F25E481124059CC593B4C68BC485640, 2814D2BA4E83D3B0F7569E6C6EE0C763D9801BC505D8ED84675D19C8573834DB ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys 22:01:27.0203 0x0730 Tcpip - ok 22:01:27.0251 0x0730 [ 4F25E481124059CC593B4C68BC485640, 2814D2BA4E83D3B0F7569E6C6EE0C763D9801BC505D8ED84675D19C8573834DB ] Tcpip6 C:\WINDOWS\system32\drivers\tcpip.sys 22:01:27.0311 0x0730 Tcpip6 - ok 22:01:27.0318 0x0730 [ 8DBB1BE20C36E6D19BCC89EEA00B953C, 8B97A7E53E1D77363AFF6A5AAEAD89EBAE28DCB8D82753C804FD7CD5646500AF ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys 22:01:27.0333 0x0730 tcpipreg - ok 22:01:27.0339 0x0730 [ 9D2DD64A0B51C56285512DC9454340F6, ABB90CE6A55269F71AFB08E04969CF9A4EFD93F7A7189AF920EEE3E005214DDD ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys 22:01:27.0352 0x0730 tdx - ok 22:01:27.0356 0x0730 [ 06130AFFECEB94525FC2352936576B70, 10EBE2C8FDC087D29E2FFB328F0F7905A5374AB8CC9FAE8699E7676DBC8CBF91 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys 22:01:27.0367 0x0730 terminpt - ok 22:01:27.0387 0x0730 [ FB68E5F02316C42BE7282DA492351C6F, AC31D841FEA58B776127E138DB20F8D48E26FD8C00CE2FA9695EA14EBF159A0A ] TermService C:\WINDOWS\System32\termsrv.dll 22:01:27.0428 0x0730 TermService - ok 22:01:27.0432 0x0730 [ 2AF438EC0D361A7BBB70E604A686602C, 4BE6A0461EB2CB94288614434A1CEC81C2ED46241721FD5BBD8ABE0680F7C804 ] Themes C:\WINDOWS\system32\themeservice.dll 22:01:27.0453 0x0730 Themes - ok 22:01:27.0461 0x0730 [ 1482B8ED5CACA87992A882B853B83CEE, 613247F0E362A109090E8563D977DECC50C64D45D6962905FA84A2D59329045C ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe 22:01:27.0486 0x0730 TieringEngineService - ok 22:01:27.0499 0x0730 [ 3B3C607C3C62DFBEF61938DA2CAB94DF, E5EEA7F45A7BBFDF6F0003CD77E39958C451DD1B4B401876B5619A3C20F5C370 ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll 22:01:27.0529 0x0730 tiledatamodelsvc - ok 22:01:27.0535 0x0730 [ C1F8CBE2D4843E0CCC3EFEA2EC60D4AB, 9D07527D982066922318C77AECE99280DE55034C375ACE145E827A6BEB5C3B70 ] TimeBrokerSvc C:\WINDOWS\System32\TimeBrokerServer.dll 22:01:27.0554 0x0730 TimeBrokerSvc - ok 22:01:27.0561 0x0730 [ 46171262D0E806779DEEDFCAB2F830CC, 7F4A4658B8BA217D99E5B5C0E01600C20DC96ECBCA32A5BA7FBE17D2A7B8BFD8 ] TPM C:\WINDOWS\System32\drivers\tpm.sys 22:01:27.0576 0x0730 TPM - ok 22:01:27.0581 0x0730 [ 3B91F35089240F6187AD681A5EC28BDE, 3D035CB73BC8E7831DCD0FB7D9DAD91CE51D3D0F9D9C8B866A0009BD508B6702 ] TrkWks C:\WINDOWS\System32\trkwks.dll 22:01:27.0599 0x0730 TrkWks - ok 22:01:27.0603 0x0730 [ 09440FA30C020B4443391FAFCF4876E3, 208C7725F70C75D8C96CCAF5B22F83B8B1C66D8C9FFF48465B1C9F4A77425569 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe 22:01:27.0620 0x0730 TrustedInstaller - ok 22:01:27.0625 0x0730 [ A6F4025664C9D4BC2A9EDAB4092706D7, 89808A1679C0E716F86F06EE7701DCC289200894F0FA1F120DA2AC3A45FDB312 ] tsusbflt C:\WINDOWS\system32\drivers\TsUsbFlt.sys 22:01:27.0641 0x0730 tsusbflt - ok 22:01:27.0644 0x0730 [ 37A96AD493E110C0BF1EE0AC0F9E7DBD, F2A6894A4AEE18DF2B92222CDB0801A13AEEB7212071F0431430788339B30E23 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys 22:01:27.0658 0x0730 TsUsbGD - ok 22:01:27.0663 0x0730 [ 5A91FDBA4D3FCB56DAEB8C091B3EB8E1, 8AB91F4423125267FA8509A1C3A9AD1CBD642FA6A96D8789F9AB8CB75ABAD58C ] tsusbhub C:\WINDOWS\System32\drivers\tsusbhub.sys 22:01:27.0680 0x0730 tsusbhub - ok 22:01:27.0684 0x0730 TuneUp.UtilitiesSvc - ok 22:01:27.0686 0x0730 [ 9B5C98C9F9EF5E62806DCD58B0D8EACE, B4B8A3F943C2C401CA1ED05BDA0C6D631106B258FB40C433AC856DCA7E8D7F7A ] TuneUpUtilitiesDrv C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys 22:01:27.0695 0x0730 TuneUpUtilitiesDrv - ok 22:01:27.0701 0x0730 [ 79E264287F17D56D768440B0270466DE, ABF9DC95C5E939B30BFD9BF9EDFDB3BD78A9DFCB055B945965303B6A60E6D7A7 ] tunnel C:\WINDOWS\System32\drivers\tunnel.sys 22:01:27.0718 0x0730 tunnel - ok 22:01:27.0723 0x0730 [ F723552F65D44FE693DB1A383825B3A8, EF8C343C4EB5EEA4EC830378EF576CCD6CD4EEDEDD486C0F29697044E8C71F45 ] tzautoupdate C:\WINDOWS\system32\tzautoupdate.dll 22:01:27.0741 0x0730 tzautoupdate - ok 22:01:27.0745 0x0730 [ AA65954F512BA097DD190790876DD991, C1BB2B8F54F064D01190327B5E7949EBBDA21D6FC6F94D9FCD20F685C2F855FA ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys 22:01:27.0757 0x0730 UASPStor - ok 22:01:27.0761 0x0730 [ AB6268022C3A5B529075A39C33904DA6, 2717F1704640201F2681711543EA39A74C3E89C7DB232EC5DD89FD8AA6F07846 ] UcmCx0101 C:\WINDOWS\system32\Drivers\UcmCx.sys 22:01:27.0778 0x0730 UcmCx0101 - ok 22:01:27.0782 0x0730 [ 7ED2EDA43D21C7A5F589A7960E265C52, 7DB8A595236FBB8A264D7AB155201357212855050ABB5B1036EF32F1223FDCC2 ] UcmTcpciCx0101 C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys 22:01:27.0798 0x0730 UcmTcpciCx0101 - ok 22:01:27.0802 0x0730 [ 169351463039B45F5CDED9768879F712, 990C8C4AEF9ED7FF6BCEAE67F7BDAA037777B142B8D96A74F8715C941A5C63C6 ] UcmUcsi C:\WINDOWS\System32\drivers\UcmUcsi.sys 22:01:27.0816 0x0730 UcmUcsi - ok 22:01:27.0823 0x0730 [ 08A9E3AD29B215484FBB68CDC175DF3A, 3EFFF99C3BC4A1454E3D2B5177AE587ED3041AB4CE2A95BA7E28A2124E38E1E5 ] Ucx01000 C:\WINDOWS\system32\drivers\ucx01000.sys 22:01:27.0838 0x0730 Ucx01000 - ok 22:01:27.0841 0x0730 [ DA70AEE267491AA56BC63AA0C0C96CA2, 0A0AADB27607F9292BB3CE000CFDDB19BD4CA09EAAD926C4925CB43B17817AD9 ] UdeCx C:\WINDOWS\system32\drivers\udecx.sys 22:01:27.0856 0x0730 UdeCx - ok 22:01:27.0864 0x0730 [ FBC5ECF6D5A868D0B116C2DBB02B8168, 945AA76C60ABAD6075B5C8F9172C018F75BCF393A1CB8B329F5E68E664627775 ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys 22:01:27.0890 0x0730 udfs - ok 22:01:27.0893 0x0730 [ B918E40FAA9CD118CCA4AD388B748C98, 4B539B7B656F02C5E5BAEE52A677757B05CC11C5500D619850A564C28FAB8115 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys 22:01:27.0904 0x0730 UEFI - ok 22:01:27.0908 0x0730 [ 166B17AE1DD24D8BA8CA474C7C31148F, D34E786277093278F58EFAC957279DC4ED43A190538C875B80F5B1E0A0C30381 ] UevAgentDriver C:\WINDOWS\system32\drivers\UevAgentDriver.sys 22:01:27.0919 0x0730 UevAgentDriver - ok 22:01:27.0943 0x0730 [ FCA4D901FB9934DAB82ED31C4EE89A11, 8EDF8DD71C13DE77AC83D1086670E9E90C69DE379F1CF768C8B9C789254C04AA ] UevAgentService C:\WINDOWS\system32\AgentService.exe 22:01:27.0989 0x0730 UevAgentService - ok 22:01:27.0997 0x0730 [ 0FD75222C1AD2687AB365BEBEA400DD4, AD10DBCA59EB7D34FD8F963CE267F36774A9BC613F8D637903B12AC88C328E8A ] Ufx01000 C:\WINDOWS\system32\drivers\ufx01000.sys 22:01:28.0013 0x0730 Ufx01000 - ok 22:01:28.0018 0x0730 [ C1A78C53E01C641AE41BFA65797819F5, 0B9FE1BD724B3315199A1B1DA2F03255E4FE744DA3CE6CD0F77699A8E42E9359 ] UfxChipidea C:\WINDOWS\System32\drivers\UfxChipidea.sys 22:01:28.0031 0x0730 UfxChipidea - ok 22:01:28.0036 0x0730 [ 767307212110EBEFB93EC9A5BE9E85B9, 368797400FE54802CE74F34B773CE2AF09EB8DEA6C035B55419A52F0B5A6FAD0 ] ufxsynopsys C:\WINDOWS\System32\drivers\ufxsynopsys.sys 22:01:28.0050 0x0730 ufxsynopsys - ok 22:01:28.0057 0x0730 [ 8578F83EC5175920F2D8586FFF9DCE47, 049A16AC87F93E761150C8286633FFCA62EE85F5645DDE77D36BD0EB6481FF83 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe 22:01:28.0074 0x0730 UI0Detect - ok 22:01:28.0077 0x0730 [ DC460AAA18CA2342FBBFB2DF9B044472, 14D45E059C596AE97506D26705F248CA1C2269160B31A60341060E8A93146CBD ] umbus C:\WINDOWS\System32\drivers\umbus.sys 22:01:28.0092 0x0730 umbus - ok 22:01:28.0095 0x0730 [ C3CF0377917ECE6D65D7623E1E61568F, 4909695E04CBC86BFCFFBC15F332C367521054B7B4D3C141C7CA6B2E40E090B9 ] UmPass C:\WINDOWS\System32\drivers\umpass.sys 22:01:28.0108 0x0730 UmPass - ok 22:01:28.0116 0x0730 [ 640CF093C1CF16D5FD317616CA348F31, BEC34D1AACA83BF5A84CE01F6A668E3CA5A33C56A446DC42EFFF7C43D22E1AE6 ] UmRdpService C:\WINDOWS\System32\umrdp.dll 22:01:28.0138 0x0730 UmRdpService - ok 22:01:28.0161 0x0730 [ B8272BB8D4982C496FDC704809C38E02, F93855D932FB1DBBCC86E82C0FE0DC9ECF93BBD629D2CA9D0BE7E075E114B7FF ] UnistoreSvc C:\WINDOWS\System32\unistore.dll 22:01:28.0207 0x0730 UnistoreSvc - ok 22:01:28.0220 0x0730 [ 6CDA3536F6BAB7896A57EAB7DC07F379, 8FBE6457ECD1ABB518D9800EBA8A017774FFAA8EABD2EDC0825181A12FE9AEF6 ] upnphost C:\WINDOWS\System32\upnphost.dll 22:01:28.0250 0x0730 upnphost - ok 22:01:28.0254 0x0730 [ 6B46FC140C9AF68E6E7697D66D59CB4D, F018B4784D65F1A8140A6EA69C35D6A7ECE01738694052FD54AFD2B81A8F2FF8 ] UrsChipidea C:\WINDOWS\System32\drivers\urschipidea.sys 22:01:28.0265 0x0730 UrsChipidea - ok 22:01:28.0269 0x0730 [ B4402E7F0923F660270442CE76877ABE, 1C2DD26EAB71F75EA576E8DAABAF71FD7DC3DF807CF025617C774CEF33C0B718 ] UrsCx01000 C:\WINDOWS\system32\drivers\urscx01000.sys 22:01:28.0281 0x0730 UrsCx01000 - ok 22:01:28.0284 0x0730 [ 9DD431F1B94789CFB527E5D19261F124, 8F5A249A97C5B14B282E3147DD21951D2AD34B651E762814C12F4C26D74EC70C ] UrsSynopsys C:\WINDOWS\System32\drivers\urssynopsys.sys 22:01:28.0295 0x0730 UrsSynopsys - ok 22:01:28.0300 0x0730 [ 93F169DE94DBAC5DAF4755AFF10193DD, 381E6751EB97426B9BF30929E4B82A665D1ED985DA60BE18D3C17CF2BB41F848 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 22:01:28.0317 0x0730 usbaudio - ok 22:01:28.0323 0x0730 [ C87E32B90F085970D9637FBAD45EF6FE, C180EACD2EE479277DA5DBF39E43B428BD7945141B2451CB3946B0C1E495E76F ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys 22:01:28.0337 0x0730 usbccgp - ok 22:01:28.0342 0x0730 [ 0B663856474AC41924D9E9112203858F, 9E09F2A6279B48CAC09F8C7AA1F1BE02864D540C2ED1460CBA9FABCF0A546A1E ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys 22:01:28.0358 0x0730 usbcir - ok 22:01:28.0363 0x0730 [ F83D2250256203AC5DA5E8601C1AFDD7, AC0D90E2DB3051798B9D287CF3D0E92FED4000822E65A82775A29CF896B76F04 ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys 22:01:28.0375 0x0730 usbehci - ok 22:01:28.0387 0x0730 [ 7FFD26742321919590ED77FCA556D65F, F7FAB63C36F8519F5A7B9091C507F3CB580C390322FAF9155CCE7F66C965B968 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys 22:01:28.0407 0x0730 usbhub - ok 22:01:28.0419 0x0730 [ 7A749B2863B5561BE34B39E8E249AD8F, E5B67DFAF5407007FD0CC408D6B4BA19DF59584819FC715E9F9E0FBF3EA00AAB ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys 22:01:28.0441 0x0730 USBHUB3 - ok 22:01:28.0444 0x0730 [ D2109F1F4FEBF1DAC415CDC5DE876479, C8A871EBD0E5EF004BA622A73DAC36C03608CD317FDCD0A6A98608DF4CC10D55 ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys 22:01:28.0459 0x0730 usbohci - ok 22:01:28.0462 0x0730 [ 29C9572F2D061CFC3C0BD48A3163E343, 2527DCC9E6D421F5DC40051C787A5270EB077746785465C9AA2A2AEEF47307D5 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys 22:01:28.0476 0x0730 usbprint - ok 22:01:28.0480 0x0730 [ 429477D6DEF3321FF7D3EF23CAAADA00, BB7D2AFE99736AAFFA8B0B2DABF7D6A6D5CB9563B1DE6A7E86CE7DC9D27F31C0 ] usbser C:\WINDOWS\System32\drivers\usbser.sys 22:01:28.0495 0x0730 usbser - ok 22:01:28.0500 0x0730 [ 0CC16F7B91C57AE9A4E44425A295FDAA, 7CEE11955E5742DA390601F565412C14A7481B8747C495CCD246696C56B426DC ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS 22:01:28.0513 0x0730 USBSTOR - ok 22:01:28.0517 0x0730 [ C917D09064CDBD18F75ADC9B2C48F847, A7F6223346CCD7E84186CD0C0715014F8E3A4398298925A43290224678620D23 ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys 22:01:28.0531 0x0730 usbuhci - ok 22:01:28.0540 0x0730 [ 95BCCEFBC40D06484CF16144FE79B8A5, 8ABA73C5FFEDD319FB96B807AD08716698E557522478DF1A2C5D662675636AE0 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS 22:01:28.0558 0x0730 USBXHCI - ok 22:01:28.0588 0x0730 [ 4CC81AB9D380A6264FF4C0C1512CF965, 76C33053D1C9155B0F3F8392FF982AD4EABEE2BBBEE89EA41DBFE8E436973EB0 ] UserDataSvc C:\WINDOWS\System32\userdataservice.dll 22:01:28.0641 0x0730 UserDataSvc - ok 22:01:28.0665 0x0730 [ AA24C61D88E36BA1144072227922173D, 2EBBC827E740F72EA2E75745E585378189BC0DEE91CACD7FA31BDBC5EFCF8733 ] UserManager C:\WINDOWS\System32\usermgr.dll 22:01:28.0706 0x0730 UserManager - ok 22:01:28.0719 0x0730 [ EBF9E40845362DBE2AD0DB3077269488, A6363006350D097F95B03A2F44E1D3FBD3BC40048BE57C715CD7CBC22D1EE70B ] UsoSvc C:\WINDOWS\system32\usocore.dll 22:01:28.0749 0x0730 UsoSvc - ok 22:01:28.0753 0x0730 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] VaultSvc C:\WINDOWS\system32\lsass.exe 22:01:28.0766 0x0730 VaultSvc - ok 22:01:28.0769 0x0730 [ 0CBDE344FB48E42D78E29469F202ADBC, A1C3FBA5409DD3BBEAF1D3CE2583D6C8A621C0E4F534155EC540AFD67BC9E8CA ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys 22:01:28.0781 0x0730 vdrvroot - ok 22:01:28.0795 0x0730 [ 0783EDE1FA94649ED7F3CEF6A734041A, 1A13A613EF6B67459031C7994FFC6F32F73E02E0F123A171618E4F011C635684 ] vds C:\WINDOWS\System32\vds.exe 22:01:28.0829 0x0730 vds - ok 22:01:28.0836 0x0730 [ 723195568C8755CAD57F7933C5F2C5C2, 5C403799F67223605F825BC16D217C1EF5E1A0DDF00AC6380FE8976339B67D9B ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys 22:01:28.0851 0x0730 VerifierExt - ok 22:01:28.0866 0x0730 [ 3BB8D153A9A514EC9FFCB586251A1925, 5E4B46511F9791699826DC63B35528544347166BDE9981FB93F1F7F2A09599C7 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys 22:01:28.0891 0x0730 vhdmp - ok 22:01:28.0895 0x0730 [ 7929228F0E8B0C2FA0495A17A4FC27F6, 1F1667B10A96B1D85ED165F62A5C0EF28C37F828B8280EA08BFCC1BAC03F2C90 ] vhf C:\WINDOWS\System32\drivers\vhf.sys 22:01:28.0909 0x0730 vhf - ok 22:01:28.0925 0x0730 [ 1916D8565B95F93D696067C01280937E, 0DA15AE1729F2D0F37A00751871F68F07724B14B07AC3257B2636C7F171FF660 ] VIAHdAudAddService C:\WINDOWS\system32\drivers\viahduaa.sys 22:01:28.0945 0x0730 VIAHdAudAddService - ok 22:01:28.0951 0x0730 [ AEE432ED868831B1F068E373598F6D93, BAE91F47B0CB94B826CA010B490AD924D7B715911DF3FCE62F9165F3B571105C ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys 22:01:28.0964 0x0730 vmbus - ok 22:01:28.0967 0x0730 [ 9444B23FC694B5F90F21B0FC7F10D8DD, 86F92856F5C985DD8E5993B51E85E1F47EF8C9B2FB37468998C94266963BB4BD ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys 22:01:28.0981 0x0730 VMBusHID - ok 22:01:28.0984 0x0730 [ 4D0287F566B36536DD812A54C015FC4A, 01D6508CA59CF04A47902B1F7C202FD14A81240E0B447588D919DD1072B040CF ] vmgid C:\WINDOWS\System32\drivers\vmgid.sys 22:01:28.0998 0x0730 vmgid - ok 22:01:29.0006 0x0730 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll 22:01:29.0029 0x0730 vmicguestinterface - ok 22:01:29.0036 0x0730 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicheartbeat C:\WINDOWS\System32\icsvc.dll 22:01:29.0058 0x0730 vmicheartbeat - ok 22:01:29.0065 0x0730 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll 22:01:29.0087 0x0730 vmickvpexchange - ok 22:01:29.0096 0x0730 [ 0F621B52259D88A719AA20C6D04E3D72, 80B0528CCDE6E1B6F092787E1C0769C649698B196602859A5855134F0ECCBAE5 ] vmicrdv C:\WINDOWS\System32\icsvcext.dll 22:01:29.0119 0x0730 vmicrdv - ok 22:01:29.0127 0x0730 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicshutdown C:\WINDOWS\System32\icsvc.dll 22:01:29.0149 0x0730 vmicshutdown - ok 22:01:29.0157 0x0730 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmictimesync C:\WINDOWS\System32\icsvc.dll 22:01:29.0178 0x0730 vmictimesync - ok 22:01:29.0186 0x0730 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicvmsession C:\WINDOWS\System32\icsvc.dll 22:01:29.0207 0x0730 vmicvmsession - ok 22:01:29.0216 0x0730 [ 0F621B52259D88A719AA20C6D04E3D72, 80B0528CCDE6E1B6F092787E1C0769C649698B196602859A5855134F0ECCBAE5 ] vmicvss C:\WINDOWS\System32\icsvcext.dll 22:01:29.0239 0x0730 vmicvss - ok 22:01:29.0243 0x0730 [ 29075915F9BDC3437F8BED71C067D399, 2C7718080C11DFDD4C9A2085537F78F5633369B4A27D9C64168F0249594A4AA2 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys 22:01:29.0255 0x0730 volmgr - ok 22:01:29.0265 0x0730 [ 6BDB6CE6D2D9E3D3F28F1C97E12B62E2, 5E77D7AF858D7B90FF395F39B86D6F96413D1DDEA28BC9FB40C5524A4DF6DAD0 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys 22:01:29.0282 0x0730 volmgrx - ok 22:01:29.0292 0x0730 [ BF2546583BB75F01DDA60A7921DFB230, 579BD0BC55F4F03CD8D1FCDAC3975A1649C688820F2F7FC1AD354132D9E3BEE9 ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys 22:01:29.0311 0x0730 volsnap - ok 22:01:29.0314 0x0730 [ AC2E20A74D09D24485BE8396CE04F07B, 23FCE8BEE01B89E5CDCA536D75DBA6DCE3E92E13178A66836CEB7829310A89D1 ] volume C:\WINDOWS\system32\drivers\volume.sys 22:01:29.0325 0x0730 volume - ok 22:01:29.0330 0x0730 [ 92F6E3E6D3F1795263EB34B37F74AEF7, 33AB1ECCA1216AF1995E1DB4F11E48156FF62391D7C176C8A4CC1037B9CB3A27 ] vpci C:\WINDOWS\System32\drivers\vpci.sys 22:01:29.0342 0x0730 vpci - ok 22:01:29.0347 0x0730 [ FD9BCB8920973CEAD4D49DC7A6D8A618, 34AB4A485FB40DF737600006D8323BE927FB0BDA2BC170F4C123BE775EAE7CC8 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys 22:01:29.0361 0x0730 vsmraid - ok 22:01:29.0389 0x0730 [ 01FFD5AF533F2CFDF26DDDC9313731C1, BFF0F2E57CD2358AC8F519F6F5692A46D97EC4E9B763D47101CEF31712FD4738 ] VSS C:\WINDOWS\system32\vssvc.exe 22:01:29.0443 0x0730 VSS - ok 22:01:29.0453 0x0730 [ 0C111F220798CCE80484026E06822379, B98A5E44D3ABA67E6DE99E18BF3C2C606923E6269E262665C721F672ACBBED2A ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys 22:01:29.0469 0x0730 VSTXRAID - ok 22:01:29.0473 0x0730 [ 607639716E9DB1CEF4E18B5B229293B4, 1D997177093F907EFE8A04AD10443BB9C355C0D7657DBD449E7EE7FCABC3ECBC ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys 22:01:29.0488 0x0730 vwifibus - ok 22:01:29.0492 0x0730 [ B1ED64E628763148BF84FBE23F2AD711, 6182A39675E6049BC3DD353694720795A8E3D0331509AA8ABA4883D5C569AD5E ] vwififlt C:\WINDOWS\system32\drivers\vwififlt.sys 22:01:29.0507 0x0730 vwififlt - ok 22:01:29.0519 0x0730 [ 76C1CC611352499326001F25A3ED15F8, 228BFA8A01BB1B3868576D509A2EA6F3D37FEDC8F12D4DC4E0A84CE926C6D1B1 ] W32Time C:\WINDOWS\system32\w32time.dll 22:01:29.0547 0x0730 W32Time - ok 22:01:29.0551 0x0730 [ 55D00B785A7587F4263D125817871283, B92400B229099C1E243F2B149881A1423A2E9C8CA2D77D868B9B923BFDEC7FF2 ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys 22:01:29.0565 0x0730 WacomPen - ok 22:01:29.0576 0x0730 [ 1483BE4D0135C378CB61D3CD73AB3E03, B7309C9E4F370860C507BF52D17234CDF4A7FAE95D2D822714E07EF5DEC0249B ] WalletService C:\WINDOWS\system32\WalletService.dll 22:01:29.0602 0x0730 WalletService - ok 22:01:29.0607 0x0730 [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 22:01:29.0626 0x0730 wanarp - ok 22:01:29.0630 0x0730 [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarpv6 C:\WINDOWS\system32\DRIVERS\wanarp.sys 22:01:29.0649 0x0730 wanarpv6 - ok 22:01:29.0679 0x0730 [ 30B8286F8FE1AE90A583100D45E02247, 3C86A4A5E21F9A1267EA231B20914E0A162BA4C25FE8917AD3AB6D504DA5BE0C ] wbengine C:\WINDOWS\system32\wbengine.exe 22:01:29.0735 0x0730 wbengine - ok 22:01:29.0754 0x0730 [ 8C521D161445C3E1F38A494E7649E70D, F00990B2FE1FB52C74A2057E6480C5EBF2BDBC32955CC03C6B63360F20A49A18 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll 22:01:29.0790 0x0730 WbioSrvc - ok 22:01:29.0796 0x0730 [ E330144B97D493AA886000DCAAA8DAF5, ED86F46F5A76FD8F06CA98BD61B174ADB9AD4B065394356872708DF8B614E4F9 ] wcifs C:\WINDOWS\system32\drivers\wcifs.sys 22:01:29.0809 0x0730 wcifs - ok 22:01:29.0824 0x0730 [ 32960EA9CF836D7DD77767DCB68CE230, 679446A4FAB0331C181D2716CAEA225267C6164BB9867E360C5B3D6AB1083195 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll 22:01:29.0862 0x0730 Wcmsvc - ok 22:01:29.0874 0x0730 [ D50645235A507B0546B1B5CF7D0B8849, 19F5FE10C953B8EE8EEDA9A9F7F2E97AA193BB085E7FC364066686089ADD1C9F ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll 22:01:29.0900 0x0730 wcncsvc - ok 22:01:29.0905 0x0730 [ AEA1093B751339267D8C8C1EF3D669CF, 8F3325E7FB16BD856A0593C36F2E3E018909038C52CD5F92E116E0C1366F31CB ] wcnfs C:\WINDOWS\system32\drivers\wcnfs.sys 22:01:29.0920 0x0730 wcnfs - ok 22:01:29.0923 0x0730 [ D520B1B849B6D4D707AB31722B952C2D, 149BABB7BD63C1F212ADD9306C84FFB2A5CE6DC435BD3213EAB787E9B222C61F ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys 22:01:29.0936 0x0730 WdBoot - ok 22:01:29.0953 0x0730 [ 5030C76047D756263093A47B82970868, E772F15973F6DE36851DD230F1F4190746CD81CA1E7284DC074711C4BF45CAF0 ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys 22:01:29.0978 0x0730 Wdf01000 - ok 22:01:29.0987 0x0730 [ 29FF9199EDEB4F5470BB134D1A2563D2, 94713F98A6EA6042203D5DD0DE6758F5F0F331F7D4BB05E91EF20CEEEBD6780F ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys 22:01:30.0004 0x0730 WdFilter - ok 22:01:30.0008 0x0730 [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll 22:01:30.0028 0x0730 WdiServiceHost - ok 22:01:30.0032 0x0730 [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll 22:01:30.0051 0x0730 WdiSystemHost - ok 22:01:30.0066 0x0730 [ 8CB606A3057355FD5A9DBDD1A0AC94EF, 6DD0B4A2270633086EBB569A00B87430EE6EF173525E341404B15845B57BE86D ] wdiwifi C:\WINDOWS\system32\DRIVERS\wdiwifi.sys 22:01:30.0098 0x0730 wdiwifi - ok 22:01:30.0104 0x0730 [ 17CF416CFF408190F5A4CBD79AB12E55, E376C8865C7EA633AE20D2CF940E4C7584AC783BAAF7941780FB6C4C84802F33 ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys 22:01:30.0117 0x0730 WdNisDrv - ok 22:01:30.0120 0x0730 WdNisSvc - ok 22:01:30.0127 0x0730 [ 3570C4E14F85CE0B537D126727ACA91C, A474C9E6B6E4E5945C63367C1D3D24D4782C4A4FEB00FAE15DFED099D8283078 ] WebClient C:\WINDOWS\System32\webclnt.dll 22:01:30.0150 0x0730 WebClient - ok 22:01:30.0157 0x0730 [ 1785F9C96A0BDEC1F6E0C79EF412F342, D6D4EDA69457BEDDA69C2F60FC4C2FAC97D46CD8E9C1804CCD68F169383583E3 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll 22:01:30.0180 0x0730 Wecsvc - ok 22:01:30.0184 0x0730 [ B9175D63527B05131F2FA504CF0265F2, 1E43A17788F1B6A29E2889C81E0BE100D64BD3A9DEE7C154D9581F01D2D7D05F ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll 22:01:30.0200 0x0730 WEPHOSTSVC - ok 22:01:30.0215 0x0730 [ 5C58EC0C9D4DE04DCDE56F6DCEA62080, 8ED386EDF4C39C339CE0BB2AC7E199C38705E5A6B3F56A4987B9A8ABD19BB59F ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll 22:01:30.0237 0x0730 wercplsupport - ok 22:01:30.0243 0x0730 [ F899B355CC95AF26AB36E84E8A0DD685, C400F2F80FFF6473FEF066943C4A2AFF0FFE988A4F755757A2E5005C2A10DAD8 ] WerSvc C:\WINDOWS\System32\WerSvc.dll 22:01:30.0262 0x0730 WerSvc - ok 22:01:30.0268 0x0730 [ E1785942AC51FEE6826CDF02075C5AA9, 56FE7017684086F4F9C3A2C0D3AC00369BA0938BA3987EEBEE9A75B8E3CA0AE1 ] WFPLWFS C:\WINDOWS\system32\drivers\wfplwfs.sys 22:01:30.0282 0x0730 WFPLWFS - ok 22:01:30.0286 0x0730 [ B154618505A6A9026EFA6AB8C4123BF1, 713648D71AA027B4472E7E75B942630DBE7383687984B02A5E99C9E4192C95EB ] WiaRpc C:\WINDOWS\System32\wiarpc.dll 22:01:30.0305 0x0730 WiaRpc - ok 22:01:30.0308 0x0730 [ 0CF79A0EACFFBB75A50A469A27696D02, E112BF7B5A8D0B0AD2EA0E7B9FD4E8CFEC9371C8E94A60248292D688AFE715C4 ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys 22:01:30.0321 0x0730 WIMMount - ok 22:01:30.0323 0x0730 WinDefend - ok 22:01:30.0330 0x0730 [ 0DE131733317EB4BE67028366B0CAAC6, AC7DADBF03A3752B4D33CA19F03DBCEDD6F56893C2DA25C98B0AB07063D990E3 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys 22:01:30.0344 0x0730 WindowsTrustedRT - ok 22:01:30.0347 0x0730 [ 92EB5D38BDF10C790450F3E46BF93A0E, 0FC027398DBD43EDC1F7D703C0B6DB20294DF34E67C9288442039B1A5663CE1B ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys 22:01:30.0359 0x0730 WindowsTrustedRTProxy - ok 22:01:30.0376 0x0730 [ C2A3B07F0118D61086C99BDCBAB6A6A3, 04D646BEF1C6F427503C594F0ECBB33140C3991A3A7AFB66B2C9581E358F9FD2 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll 22:01:30.0413 0x0730 WinHttpAutoProxySvc - ok 22:01:30.0418 0x0730 [ F95DE20312ACCA7761446DE152BD1F7C, F6C5ACA500C2182437F4A7402BD81C3A2B77C0BBD78BA31FB574DC1997FCBFE6 ] WinMad C:\WINDOWS\System32\drivers\winmad.sys 22:01:30.0429 0x0730 WinMad - ok 22:01:30.0439 0x0730 [ CD49CA8E3280ACEEC5ECF431A59F5EFD, 75F48EFC6DEE9E06B490703EE47602AFDEA51505285B02D2CF884601E71857CC ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 22:01:30.0460 0x0730 Winmgmt - ok 22:01:30.0511 0x0730 [ B8C0D620219ECAA23A2AC841EAF454D1, FB527C4D36929D7FAE2A837727C557B7823A72069EBCAB7D16C49E8B21E8D952 ] WinRM C:\WINDOWS\system32\WsmSvc.dll 22:01:30.0599 0x0730 WinRM - ok 22:01:30.0607 0x0730 Winstep Xtreme Service - ok 22:01:30.0612 0x0730 [ 4EFB346BFDAEEB29316AA52BBB9852B1, 4BC5554F44BD9549D0A929D77BD410FA3EB502A7D0170303D369268672505494 ] WINUSB C:\WINDOWS\System32\drivers\WinUSB.SYS 22:01:30.0628 0x0730 WINUSB - ok 22:01:30.0632 0x0730 [ 8B9AFF5F08E66A6F1F1063DEC9457FB6, 98F2AF6988D125521FD34CAA48B9652922F0C8ECFAE9B0C1DF4B3CE6B9CF500F ] WinVerbs C:\WINDOWS\System32\drivers\winverbs.sys 22:01:30.0645 0x0730 WinVerbs - ok 22:01:30.0659 0x0730 [ ECD999D8412A3473C26B118F89DB9908, 5FB9B93E4B5482CCFF01D805DFA386FD8D3441BC81E7BD5DF89EE3078FD724F3 ] wisvc C:\WINDOWS\system32\flightsettings.dll 22:01:30.0692 0x0730 wisvc - ok 22:01:30.0737 0x0730 [ 7671078AEF4C0203B053A9642C401FF7, BBFADA89CD31F20ADDBFAFAD2E492C72D82BF2F8B823BB6773F04D229B62534C ] WlanSvc C:\WINDOWS\System32\wlansvc.dll 22:01:30.0814 0x0730 WlanSvc - ok 22:01:30.0855 0x0730 [ E15711970C5BE05E8D70B294D0AFF621, 30670CFC4DA57B4A3E0E895E4111100D847BB8041A258A303524CD96DC566482 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll 22:01:30.0925 0x0730 wlidsvc - ok 22:01:30.0930 0x0730 [ 6F4F4F5A007D1710BD76FB311DA97C07, FC0FEA4364F6BA4E31DBC82735D09D429CA3BE9AFCFF5D5E1263D8B27FC2CE3E ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys 22:01:30.0944 0x0730 WmiAcpi - ok 22:01:30.0952 0x0730 [ 3CDDFF6CAD962C5EF1C52FD667C358B6, F6F09145E9461EB17172988D26749FCF36920A1A683459334D04A6D072B31A92 ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe 22:01:30.0971 0x0730 wmiApSrv - ok 22:01:30.0973 0x0730 WMPNetworkSvc - ok 22:01:30.0980 0x0730 [ 43C8D087B31C592163B33A4BDA540E40, 3A6C4E5E56931B29321DCC723585F2F0E804EF4DCDEAB2A8687F30FC3AE70E43 ] Wof C:\WINDOWS\system32\drivers\Wof.sys 22:01:30.0995 0x0730 Wof - ok 22:01:31.0031 0x0730 [ 909CB4BBF7B08E78C363000E09E79A6F, 217205D1B5EE03274AFF9405AED6D2A5665CBA4C3876E84B53DA44920CDF9CB1 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll 22:01:31.0095 0x0730 workfolderssvc - ok 22:01:31.0101 0x0730 [ F02930EB91596042F2221397D60AFCE5, 10E2AB0993B67CBAA9E11C68280608965064EC9F7E0C570F5B453FACADB8AB5D ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll 22:01:31.0118 0x0730 WPDBusEnum - ok 22:01:31.0122 0x0730 [ 75A9284F01FE7CB1A7D5EAE5C1EB4F33, 390EF23AEA06D8711555F7979FF8BE0620B53C1A551638C4EC6FB7C6678965B3 ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys 22:01:31.0134 0x0730 WpdUpFltr - ok 22:01:31.0141 0x0730 [ 60E2EB3E7B7F15C25E02462159F90707, D8344B529EEC0D4922CAC3E6897CC9F191ACF1376017BE38ED6BF6019F1ED181 ] WpnService C:\WINDOWS\system32\WpnService.dll 22:01:31.0162 0x0730 WpnService - ok 22:01:31.0167 0x0730 [ C7C91FB86A3C6CD7619725A88ED1884C, 132C43C518F37BF303D768BD5FB0AB835F693C43FE693937D804A34E940D770F ] WpnUserService C:\WINDOWS\System32\WpnUserService.dll 22:01:31.0183 0x0730 WpnUserService - ok 22:01:31.0189 0x0730 [ 36D7B73ADC3E10607ED6EC874AFB5D1E, 1737B3E4D2CA76BB27903BF460E4960E6A0BC32D35069AC7C5E4B07F625F3282 ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys 22:01:31.0203 0x0730 ws2ifsl - ok 22:01:31.0210 0x0730 [ 9A0E0B836413EB0BC885532D2A5389D6, AFEE4A0578D5581E4D72999A33C0DEA6253BD891F611AFF9AFDE4160A60105F3 ] wscsvc C:\WINDOWS\System32\wscsvc.dll 22:01:31.0229 0x0730 wscsvc - ok 22:01:31.0233 0x0730 [ 696EC2EAA2A42A137CCBB9A84D6917C0, 424089F4F373962AF8357C5D4D43F35948989BE3F58EAD3690F565F4C1BBC66F ] WSDPrintDevice C:\WINDOWS\System32\drivers\WSDPrint.sys 22:01:31.0247 0x0730 WSDPrintDevice - ok 22:01:31.0251 0x0730 [ 46E4A69825A7554A5DB784A55F8AD203, 7F347054FCDD5DEF93083D420E56EBE5EEBBAE2BD2FED9B2E75E85149DE52780 ] WSDScan C:\WINDOWS\system32\DRIVERS\WSDScan.sys 22:01:31.0265 0x0730 WSDScan - ok 22:01:31.0270 0x0730 WSearch - ok 22:01:31.0314 0x0730 [ DDB7E452A99E0E5244105C6D2CF4BC9E, 1364B03AFFD20D339A2EBA303575BCCBC2D122D89810B1E3593CC55F93F9B79A ] wuauserv C:\WINDOWS\system32\wuaueng.dll 22:01:31.0390 0x0730 wuauserv - ok 22:01:31.0396 0x0730 [ AED7FE551E8672B824A56324076183EB, FFE543AAEFDEFFE6B20C244DB141A9425BDA88ED36F4870F0B70FEC433BDF0C1 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys 22:01:31.0413 0x0730 WudfPf - ok 22:01:31.0420 0x0730 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys 22:01:31.0439 0x0730 WUDFRd - ok 22:01:31.0444 0x0730 [ 47F6450F28BAA32B2AB0D6BE00996249, C8A47D6ADF89AD613AB685C6224B9099DCEFDCD8ABCF703542AFDC356404116E ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll 22:01:31.0461 0x0730 wudfsvc - ok 22:01:31.0468 0x0730 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys 22:01:31.0488 0x0730 WUDFWpdFs - ok 22:01:31.0512 0x0730 [ E231728BC515A4B85543AF74A1FEDFCB, 5D250D7D789B5BB56BFA2E7A109BCEB3686B7636C54D89F4E9804101D145C955 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll 22:01:31.0561 0x0730 WwanSvc - ok 22:01:31.0583 0x0730 [ F39D6915451D9226AC9A5E7AE70E2ABA, E05D678DC0423A4D0EB8B3BB5A942721BB4F3B0BED22748252DBD6053FE956F1 ] XblAuthManager C:\WINDOWS\System32\XblAuthManager.dll 22:01:31.0625 0x0730 XblAuthManager - ok 22:01:31.0649 0x0730 [ 765FF96467A26C4C03281ECA426EC2D9, 2526B03C518D72F429C29BA4D4F11707AF277BF71520A1A92238A932950AE161 ] XblGameSave C:\WINDOWS\System32\XblGameSave.dll 22:01:31.0696 0x0730 XblGameSave - ok 22:01:31.0704 0x0730 [ 9627BBAA50878F6833A6A7843EE3B1D9, 637566BB56501C4D11E3B6E6AC1C602D880C9D357CCE3DF1DF74EE672744F2B7 ] xboxgip C:\WINDOWS\System32\drivers\xboxgip.sys 22:01:31.0724 0x0730 xboxgip - ok 22:01:31.0745 0x0730 [ 335E6F2BE58523B295945C840C185B00, 94ED7E2CB212A3D55B8A2CB90CD1D02A6AF92DC0DDD487CB5B7CAC9883343460 ] XboxNetApiSvc C:\WINDOWS\system32\XboxNetApiSvc.dll 22:01:31.0791 0x0730 XboxNetApiSvc - ok 22:01:31.0796 0x0730 [ 63088A3361D9A308F328F11E9099DD87, E03FDB932FC57F199C8F8A8EADA338BDF7D2F9C6CB8FAB679A92B48B1E5AFE8A ] xinputhid C:\WINDOWS\System32\drivers\xinputhid.sys 22:01:31.0811 0x0730 xinputhid - ok 22:01:31.0813 0x0730 ================ Scan global =============================== 22:01:31.0816 0x0730 [ 0C710DB449712EE13ACE733695DB7780, BBC7875B38D318CE4E88979D083AC72E8993254A466A8A6882DDE9E0C3B687A3 ] C:\WINDOWS\system32\basesrv.dll 22:01:31.0822 0x0730 [ 4C08BF958476A137C78B62B22B5F90A4, 11DDD033896C96F8F7F1A1EDD0F4E0F07AFBB3202DC8A2E5E3ADB51C4D0700D4 ] C:\WINDOWS\system32\winsrv.dll 22:01:31.0828 0x0730 [ 1EE06E957B0B2CA52D26DA7861E160EF, 4B743A1C7010138F5F6684BBCF7CAD6FD05F49920BDD3FDB776347AA6B44AB94 ] C:\WINDOWS\system32\sxssrv.dll 22:01:31.0838 0x0730 [ 3C69CC28665854F1AAB4B4005005FA31, 2750F5ECCD448C07E3402AA64EA625D27C6BC1D000A3FFE57C03D62428BB46C4 ] C:\WINDOWS\system32\services.exe 22:01:31.0846 0x0730 [ Global ] - ok 22:01:31.0846 0x0730 ================ Scan MBR ================================== 22:01:31.0847 0x0730 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 22:01:31.0899 0x0730 \Device\Harddisk0\DR0 - ok 22:01:31.0901 0x0730 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1 22:01:32.0623 0x0730 \Device\Harddisk1\DR1 - ok 22:01:32.0623 0x0730 ================ Scan VBR ================================== 22:01:32.0625 0x0730 [ 546395F69F09BB7E245CFD3594AC592A ] \Device\Harddisk0\DR0\Partition1 22:01:32.0626 0x0730 \Device\Harddisk0\DR0\Partition1 - ok 22:01:32.0627 0x0730 [ D62BD9FA028F2BCABD93274DE5984CB8 ] \Device\Harddisk1\DR1\Partition1 22:01:32.0628 0x0730 \Device\Harddisk1\DR1\Partition1 - ok 22:01:32.0628 0x0730 ================ Scan generic autorun ====================== 22:01:32.0628 0x0730 WindowsDefender - ok 22:01:32.0632 0x0730 [ C7645D43451C6D94D87F4D07BDE59C89, 495BBA47FC43EE23054FCD419F2F00457162D1C04296900C6AEA551102A810F3 ] C:\Windows\system32\rundll32.exe 22:01:32.0653 0x0730 Logitech Download Assistant - ok 22:01:32.0704 0x0730 [ A6A21A7D544675E98C040DA18904CF50, AACB578C297C7AC9FEBDAB4AD20235E5CFF6E3F260E76E6AE18D43DC57D69672 ] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe 22:01:32.0758 0x0730 Malwarebytes TrayApp - ok 22:01:32.0815 0x0730 [ 948EB9C552C05DF39F79587E6979D9F5, 402B155395C32005A8D78C8B0F00F2391542CB41188AF944FF17ADE6BE97A62D ] C:\Program Files\Logitech\SetPointP\SetPoint.exe 22:01:32.0875 0x0730 EvtMgr6 - ok 22:01:32.0878 0x0730 AvgUi - ok 22:01:32.0894 0x0730 [ B985AD982BC0F187FA1EB9CDFAE2534B, 12759C9361B4675ED4D6B17D46A2E769603B510477E82EBD72EDB6E41ACBAB11 ] C:\Program Files (x86)\Winstep\winstep.exe 22:01:32.0922 0x0730 Winstep SpeedLaunch - detected UnsignedFile.Multi.Generic ( 1 ) 22:01:33.0340 0x0730 Detect skipped due to KSN trusted 22:01:33.0340 0x0730 Winstep SpeedLaunch - ok 22:01:33.0506 0x0730 [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe 22:01:33.0664 0x0730 OneDriveSetup - ok 22:01:33.0825 0x0730 [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe 22:01:33.0983 0x0730 OneDriveSetup - ok 22:01:34.0008 0x0730 [ F51BB12D8977D26C1A4CDA348770D9F1, DDA35CD8F8A6591B83821B5180D457740E0B820CCE000BC7FB1B78FB4AEAD3BA ] C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe 22:01:34.0039 0x0730 SpybotPostWindows10UpgradeReInstall - detected UnsignedFile.Multi.Generic ( 1 ) 22:01:34.0360 0x0730 Detect skipped due to KSN trusted 22:01:34.0360 0x0730 SpybotPostWindows10UpgradeReInstall - ok 22:01:34.0380 0x0730 [ C1DE156BD17A08A294C61C28981CCAD5, BCB8351A3F00126F0DD70C9FD72ED8CBEA692E76D1C377ECF8762E822DC31DDF ] C:\Users\VerzehrendeSonne\AppData\Local\FluxSoftware\Flux\flux.exe 22:01:34.0407 0x0730 f.lux - ok 22:01:34.0649 0x0730 [ 66F28A48A94BAC47C03FFD6F2EA2DED3, 9A2DD01315277DEC4C6EF9F25F08C4E6895D528B1DDD4CD5B784009EFBF506CE ] C:\Program Files (x86)\Winstep\Nexus.exe 22:01:35.0019 0x0730 Nexus - detected UnsignedFile.Multi.Generic ( 1 ) 22:01:35.0420 0x0730 Detect skipped due to KSN trusted 22:01:35.0420 0x0730 Nexus - ok 22:01:35.0428 0x0730 [ 88DBF6DF632CAD6B22186DA206829639, CB7FA8F321EDDFAA897E15C5ED212AFAD6469CAD88F966771FF2F824FDE50423 ] C:\Users\VerzehrendeSonne\AppData\Roaming\OpenOffice Updater\Updater.exe 22:01:35.0445 0x0730 OpenOffice Updater - ok 22:01:35.0446 0x0730 Waiting for KSN requests completion. In queue: 217 22:01:36.0460 0x0730 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated ) 22:01:36.0462 0x0730 AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.138 ), 0x61000 ( enabled : updated ) 22:01:36.0466 0x0730 Win FW state via NFP2: enabled ( trusted ) 22:01:36.0761 0x0730 ============================================================ 22:01:36.0761 0x0730 Scan finished 22:01:36.0761 0x0730 ============================================================ 22:01:36.0766 0x0a8c Detected object count: 0 22:01:36.0766 0x0a8c Actual detected object count: 0 22:01:58.0868 0x0af4 Deinitialize success Mir fällt gerade ein das ich unter MB, 4 Dateien in Quarantäne und 12 Echtzeiterkennung habe. Sry das ich es nicht vorher in Erwägung gezogen habe. Es sind in jedem Fall andere Erkennungen als mit AVAST. Könnte das hilfreich sein? |
16.02.2017, 22:32 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY Bitte das Log dazu posten. Ist im Verlauf zu sehen.
__________________ Logfiles bitte immer in CODE-Tags posten |
16.02.2017, 22:49 | #20 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY Ich habe die Premium Trial Version drauf 3.0.6, finde dort nicht den Reiter Verlauf. Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 11.02.17 Scan-Zeit: 19:56 Protokolldatei: Administrator: Ja -Softwaredaten- Version: 3.0.6.1469 Komponentenversion: 1.0.50 Version des Aktualisierungspakets: 1.0.1234 Lizenz: Testversion -Systemdaten- Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: ROTEARMEE\VerzehrendeSonne -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 382436 Abgelaufene Zeit: 2 Min., 29 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 2 RiskWare.IFEOHijack, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSASCUI.EXE, In Quarantäne, [876], [249452],1.0.1234 RiskWare.IFEOHijack, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSASCUI.EXE, In Quarantäne, [876], [249452],1.0.1234 Registrierungswert: 2 RiskWare.IFEOHijack, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSASCUI.EXE|DEBUGGER, In Quarantäne, [876], [249452],1.0.1234 RiskWare.IFEOHijack, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSASCUI.EXE|DEBUGGER, In Quarantäne, [876], [249452],1.0.1234 Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Datei: 0 (keine bösartigen Elemente erkannt) Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Datum des Schutzereignisses: 16.02.17 Uhrzeit des Schutzereignisses: 10:32 Protokolldatei: Administrator: Ja -Softwaredaten- Version: 3.0.6.1469 Komponentenversion: 1.0.50 Version des Aktualisierungspakets: 1.0.1274 Lizenz: Testversion -Systemdaten- Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: System -Einzelheiten zu blockierten Websites- Bösartige Website: 1 , , Blockiert, [-1], [-1],0.0.0 -Website-Daten- Domäne: download.fromdoctopdf.com IP-Adresse: 74.113.235.138 Port: [54081] Typ: Ausgehend Datei: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (end) |
16.02.2017, 22:50 | #21 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ --> TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY |
16.02.2017, 22:50 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Logfiles bitte immer in CODE-Tags posten |
16.02.2017, 23:14 | #23 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY welcher Virenscanner^^ ist das eine Mustervorlage?! Ansonsten fahre ich jetzt fort. Code:
ATTFilter # AdwCleaner v6.043 - Bericht erstellt am 16/02/2017 um 23:05:22 # Aktualisiert am 27/01/2017 von Malwarebytes # Datenbank : 2017-02-13.1 [Lokal] # Betriebssystem : Windows 10 Pro (X64) # Benutzername : VerzehrendeSonne - ROTEARMEE # Gestartet von : C:\Users\VerzehrendeSonne\Desktop\AdwCleaner_6.043.exe # Modus: Löschen # Unterstützung : https://www.malwarebytes.com/support ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner gelöscht: C:\Users\VerzehrendeSonne\AppData\Local\DriverToolkit [-] Ordner gelöscht: C:\Users\VerzehrendeSonne\AppData\Local\slimware utilities inc [#] Ordner mit Neustart gelöscht: C:\Users\VerzehrendeSonne\AppData\Local\SlimWare Utilities Inc [-] Ordner gelöscht: C:\Users\Public\Documents\Downloaded Installers [-] Ordner gelöscht: C:\Program Files (x86)\DriverToolkit ***** [ Dateien ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** [-] Aufgabe gelöscht: DRIVERTOOLKIT AUTORUN ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel gelöscht: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\Software\DriverToolkit [#] Schlüssel mit Neustart gelöscht: HKCU\Software\DriverToolkit [#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\DriverToolkit ***** [ Browser ] ***** ************************* :: "Tracing" Schlüssel gelöscht :: Winsock Einstellungen zurückgesetzt :: Proxy Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [1625 Bytes] - [16/02/2017 23:05:22] C:\AdwCleaner\AdwCleaner[S0].txt - [1813 Bytes] - [16/02/2017 22:58:24] C:\AdwCleaner\AdwCleaner[S1].txt - [1885 Bytes] - [16/02/2017 23:02:51] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1844 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.0 (12.05.2016) Operating System: Windows 10 Pro x64 Ran by VerzehrendeSonne (Administrator) on 16.02.2017 at 23:12:16,68 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 0 Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 16.02.2017 at 23:13:02,29 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
16.02.2017, 23:15 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY ja ist ne Mustervorlage damit ich nicht jedes Mal das Rad neu erfinden muss
__________________ Logfiles bitte immer in CODE-Tags posten |
16.02.2017, 23:15 | #25 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken
__________________ Logfiles bitte immer in CODE-Tags posten |
17.02.2017, 14:33 | #26 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABYCode:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-02-2017 02 durchgeführt von VerzehrendeSonne (17-02-2017 14:31:44) Gestartet von C:\Users\VerzehrendeSonne\Desktop Windows 10 Pro Version 1607 (X64) (2017-02-11 11:58:41) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2393573186-4192034997-1557151240-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2393573186-4192034997-1557151240-503 - Limited - Disabled) Gast (S-1-5-21-2393573186-4192034997-1557151240-501 - Limited - Disabled) VerzehrendeSonne (S-1-5-21-2393573186-4192034997-1557151240-1001 - Administrator - Enabled) => C:\Users\VerzehrendeSonne ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated) AIMP (HKLM-x32\...\AIMP) (Version: v4.12.1878, 25.12.2016 - AIMP DevTeam) Ansel (Version: 378.49 - NVIDIA Corporation) Hidden AVG Zen (Version: 1.113.1 - AVG Technologies) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.26 - Piriform) Driver Booster 4.2 (HKLM-x32\...\Driver Booster_is1) (Version: 4.2.0 - IObit) f.lux (HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Flux) (Version: - ) FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) Infestation New Z (HKLM-x32\...\Infestation New Z) (Version: v26.01.16 Beta - Fredaikis AB) Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech) Malwarebytes Version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.7.1 - Mozilla) Mozilla Thunderbird 45.7.1 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 45.7.1 (x86 de)) (Version: 45.7.1 - Mozilla) Mp3tag v2.80 (HKLM-x32\...\Mp3tag) (Version: v2.80 - Florian Heidenreich) Nexus 17.1 (HKLM-x32\...\Winstep Xtreme_is1) (Version: - ) NVIDIA Grafiktreiber 378.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.49 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.21 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation) OpenOffice Updater (HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\OpenOffice Updater) (Version: 1.1.10 - OpenOffice) paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.0.0.790 - Samsung Electronics) Skype™ 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.) WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\VerzehrendeSonne\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\amd64\FileSyncShell64.dl (Der Dateneintrag hat 16 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\VerzehrendeSonne\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\amd64\FileSyncShell64.dl (Der Dateneintrag hat 16 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\VerzehrendeSonne\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\amd64\FileSyncShell64.dl (Der Dateneintrag hat 16 mehr Zeichen). CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {082E84B9-1B9F-411B-A016-23649519DEEA} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung Magician\SamsungMagician.exe [2016-11-23] (Samsung Electronics Co. Ltd.) Task: {0D4358CF-69D3-43B4-AA07-A50AE34523E0} - System32\Tasks\{DDEA962C-F03C-470A-9C14-C5729111D64B} => pcalua.exe -a "C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -d "C:\Program Files (x86)\VIA\VIAudioi\VDeck" Task: {0E0530A7-931D-47C3-BD7D-202C859C2D46} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {273FAB31-F436-49D3-9AD0-3DC1594C9F63} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {29DBBDF9-1312-4119-A02D-CAF40CB8BA87} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {2BA21395-BED7-40A3-9CE6-A901A07BAFD8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {402F081F-5C2F-4B4F-A685-0ABA04AC54D2} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {5355325E-CAE5-4C11-89EC-D21438D316D4} - System32\Tasks\{20D290CE-79C9-457E-888D-E78C260D3D26} => pcalua.exe -a "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -d "C:\Program Files (x86)\Google\Chrome\Application" Task: {71679BB3-BE64-4B22-B474-7B5DC3F54AA5} - System32\Tasks\OneDrive Standalone Update Task v2 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {7E41757B-B86C-465D-875E-03981D981659} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-11] (Google Inc.) Task: {85284DF6-00AD-4135-83E2-78CDC5BC8B2B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-21] (Piriform Ltd) Task: {98DE7E9D-20AA-4B58-85BE-AA98A2EC6DAF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-11] (Google Inc.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-02-11 11:10 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-02-11 11:10 - 2017-01-20 07:47 - 02254800 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-02-11 11:10 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-11-20 22:06 - 2016-11-20 22:06 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-02-11 11:36 - 2017-02-01 10:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll 2017-02-11 11:36 - 2017-02-01 10:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\VerzehrendeSonne\Desktop\FRST64.exe:BDU [0] AlternateDataStreams: C:\Users\VerzehrendeSonne\Desktop\RevoUninstallerPortable_2.0.2.paf.exe:BDU [0] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\123simsen.com -> www.123simsen.com Da befinden sich 7865 mehr Seiten. ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2015-07-10 12:04 - 2017-02-11 11:03 - 00450709 ___RA C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com 127.0.0.1 www.123moviedownload.com Da befinden sich 15461 zusätzliche Einträge. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\VerzehrendeSonne\Pictures\HQpix\sun_and_rain_together-wallpaper-1920x1080.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "Logitech Download Assistant" HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall" HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\StartupApproved\Run: => "Nexus" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{C0328BDA-013F-476E-80AA-E3F6EEF4D5ED}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{77732940-A7EF-4C06-A425-52FBCC030854}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DriverBooster.exe FirewallRules: [{6034012A-B92D-4476-9B2D-710440F40639}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DriverBooster.exe FirewallRules: [{A54056AE-AC8B-4A82-A793-02B63A9397FF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DBDownloader.exe FirewallRules: [{E70B8F58-A8C4-4268-BC30-B5770D9E80E4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DBDownloader.exe FirewallRules: [{006B858F-F69D-46F3-889C-837ECE17B27B}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.2.0\AutoUpdate.exe FirewallRules: [{ED3D0EE8-398E-4839-8133-42DE486A0CD1}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\4.2.0\AutoUpdate.exe FirewallRules: [{9881D613-A75D-433D-A9CE-EA324969CFDF}] => (Allow) C:\Gamez\InfestationNewZ\TheNewZ.exe FirewallRules: [{DC62DF5E-1A91-4BF6-82FE-98F32C9085D9}] => (Allow) D:\Gamez\Steam\Steam.exe FirewallRules: [{C3CD3278-5785-4568-952D-425B4344A1AE}] => (Allow) D:\Gamez\Steam\Steam.exe FirewallRules: [{3E2D2330-DE83-430F-8241-02F10627F7D7}] => (Allow) D:\Gamez\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{E5050192-C1A8-497A-AB53-F88B624E51F6}] => (Allow) D:\Gamez\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{C06CFD4C-22C4-4FA9-8D92-BA5997266191}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe ==================== Wiederherstellungspunkte ========================= 11-02-2017 15:42:22 Installiert Samsung Data Migration 11-02-2017 20:19:32 O&O ShutUp10 11-02-2017 20:46:27 Driver Booster : DMI-Gerät 12-02-2017 19:55:24 O&O ShutUp10 16-02-2017 11:59:02 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 16-02-2017 16:37:56 Revo Uninstaller's restore point - AVG 16-02-2017 16:40:16 Revo Uninstaller's restore point - AVG Driver Updater 16-02-2017 16:40:29 Removed AVG Driver Updater 16-02-2017 16:41:19 Revo Uninstaller's restore point - AVG PC TuneUp 16-02-2017 16:43:41 Revo Uninstaller's restore point - Bitdefender Agent 16-02-2017 16:45:23 Revo Uninstaller's restore point - Bitdefender Agent 16-02-2017 16:46:19 Revo Uninstaller's restore point - Bitdefender Internet Security 2017 16-02-2017 16:48:14 Revo Uninstaller's restore point - Bitdefender Agent 16-02-2017 16:48:56 Revo Uninstaller's restore point - Spybot - Search & Destroy 16-02-2017 23:10:15 JRT Pre-Junkware Removal 16-02-2017 23:10:57 JRT Pre-Junkware Removal 16-02-2017 23:12:16 JRT Pre-Junkware Removal ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (02/17/2017 02:26:12 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "C:\$Recycle.Bin\S-1-5-21-2393573186-4192034997-1557151240-1001\$R1XIMGJ.exe". Fehler in Manifest- oder Richtliniendatei "C:\$Recycle.Bin\S-1-5-21-2393573186-4192034997-1557151240-1001\$R1XIMGJ.exe" in Zeile 2. Das Stammelement der Manifestdatei muss assembliert sein. Error: (02/16/2017 11:12:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 11:10:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 11:10:16 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 04:48:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 04:48:15 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 04:46:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 04:45:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 04:43:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/16/2017 04:41:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Systemfehler: ============= Error: (02/17/2017 12:59:22 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (02/16/2017 11:15:43 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Plattformdienst für verbundene Geräte" wurde mit folgendem Fehler beendet: Unbekannter Fehler Error: (02/16/2017 11:13:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SDWSCService" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (02/16/2017 11:13:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "avgsvc" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (02/16/2017 11:13:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SDUpdateService" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (02/16/2017 11:13:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp.UtilitiesSvc" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (02/16/2017 11:13:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SDScannerService" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. Error: (02/16/2017 11:13:12 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (02/16/2017 11:08:05 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Plattformdienst für verbundene Geräte" wurde mit folgendem Fehler beendet: Unbekannter Fehler Error: (02/16/2017 11:06:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SDWSCService" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. CodeIntegrity: =================================== Date: 2017-02-16 12:24:34.083 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-15 21:43:18.430 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-15 21:27:19.470 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-13 23:40:04.760 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-13 22:12:22.933 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-13 21:48:17.627 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume1\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz Prozentuale Nutzung des RAM: 24% Installierter physikalischer RAM: 8183.05 MB Verfügbarer physikalischer RAM: 6212.32 MB Summe virtueller Speicher: 10103.05 MB Verfügbarer virtueller Speicher: 8003.07 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:208.62 GB) (Free:140.2 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive d: () (Fixed) (Total:1862.89 GB) (Free:1852.68 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 7D47CE62) Partition 1: (Active) - (Size=208.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ==================== Ende von Addition.txt ============================ Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 02 durchgeführt von VerzehrendeSonne (Administrator) auf ROTEARMEE (17-02-2017 14:31:19) Gestartet von C:\Users\VerzehrendeSonne\Desktop Geladene Profile: VerzehrendeSonne (Verfügbare Profile: VerzehrendeSonne) Platform: Windows 10 Pro Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Flux Software LLC) C:\Users\VerzehrendeSonne\AppData\Local\FluxSoftware\Flux\flux.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-11-20] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.) HKLM-x32\...\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Run: [f.lux] => C:\Users\VerzehrendeSonne\AppData\Local\FluxSoftware\Flux\flux.exe [1024240 2016-12-06] (Flux Software LLC) HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Run: [Nexus] => C:\Program Files (x86)\Winstep\Nexus.exe [13910656 2017-01-27] (Winstep Software Technologies) HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Run: [OpenOffice Updater] => C:\Users\VerzehrendeSonne\AppData\Roaming\OpenOffice Updater\Updater.exe [388000 2017-01-17] () IFEO\ccleaner64.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\driverbooster.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\samsungmagician.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{67ec6da8-8c86-411d-ae6e-c0c961ee6abb}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.) FireFox: ======== FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2017-02-11] [ist nicht signiert] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-11] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-11] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxps://www.google.de/?gws_rd=ssl CHR Session Restore: Default -> ist aktiviert. CHR Profile: C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default [2017-02-17] CHR Extension: (Google Präsentationen) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-11] CHR Extension: (CookiesOK) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\afmkbjoakcacgljcdccofbffloabfbni [2017-02-15] CHR Extension: (Google Docs) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-11] CHR Extension: (Google Drive) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-11] CHR Extension: (Adguard Werbeblocker) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2017-02-11] CHR Extension: (YouTube) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-11] CHR Extension: (New Tab by Getty Images) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgkonfdhapldnkgkcfmihjjmedbbdaoc [2017-02-11] CHR Extension: (Adobe Acrobat) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-02-16] CHR Extension: (Google Tabellen) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-11] CHR Extension: (Deaktivierungs-Add-on von Google Analytics) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2017-02-11] CHR Extension: (IBA Opt-out (by Google)) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2017-02-11] CHR Extension: (Google Docs Offline) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-11] CHR Extension: (AdBlock) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-16] CHR Extension: (Carbon BlackOut) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ialnhggmaghopmhanfnjjneegopfpbdj [2017-02-11] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-11] CHR Extension: (Google Mail) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-11] CHR Extension: (Chrome Media Router) - C:\Users\VerzehrendeSonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-11] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-01-20] (NVIDIA Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-11-20] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X] S2 SDScannerService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" [X] S2 SDUpdateService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" [X] S2 SDWSCService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe" [X] S2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe" [X] S4 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2017-01-20] () R1 HWiNFO32; C:\WINDOWS\SysWoW64\drivers\HWiNFO64A.SYS [27552 2017-02-11] (REALiX(tm)) R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176584 2017-02-16] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [110536 2017-02-16] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-02-16] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251848 2017-02-16] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2017-02-16] (Malwarebytes) R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2017-02-11] () S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_02838dee03d82b94\nvlddmkm.sys [14427064 2017-01-21] (NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [955424 2017-02-11] (Realtek ) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [33960 2017-02-11] (Synaptics Incorporated) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-02-16 23:11 - 2017-02-16 23:13 - 00000557 _____ C:\Users\VerzehrendeSonne\Desktop\JRT.txt 2017-02-16 22:55 - 2017-02-16 23:05 - 00000000 ____D C:\AdwCleaner 2017-02-16 22:52 - 2017-02-16 23:10 - 01663040 _____ (Malwarebytes) C:\Users\VerzehrendeSonne\Desktop\JRT.exe 2017-02-16 22:51 - 2017-02-16 22:54 - 04015056 _____ C:\Users\VerzehrendeSonne\Desktop\AdwCleaner_6.043.exe 2017-02-16 21:59 - 2017-02-16 22:01 - 00255366 _____ C:\TDSSKiller.3.1.0.12_16.02.2017_21.59.58_log.txt 2017-02-16 21:46 - 2017-02-16 21:58 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-02-16 21:45 - 2017-02-16 21:59 - 04747704 _____ (AO Kaspersky Lab) C:\Users\VerzehrendeSonne\Desktop\tdsskiller.exe 2017-02-16 21:45 - 2017-02-16 21:58 - 00000000 ____D C:\Users\VerzehrendeSonne\Desktop\mbar 2017-02-16 21:45 - 2017-02-16 21:45 - 16563352 _____ (Malwarebytes Corp.) C:\Users\VerzehrendeSonne\Desktop\mbar-1.09.3.1001.exe 2017-02-16 19:21 - 2017-02-16 19:21 - 00032119 _____ C:\Users\VerzehrendeSonne\Desktop\Addition.txt 2017-02-16 19:20 - 2017-02-17 14:31 - 00012852 _____ C:\Users\VerzehrendeSonne\Desktop\FRST.txt 2017-02-16 16:48 - 2017-02-16 16:48 - 00029076 _____ C:\ProgramData\agent.1487260105.bdinstall.bin 2017-02-16 16:47 - 2017-02-16 16:47 - 00218764 _____ C:\ProgramData\cl.uninstall.1487259991.bdinstall.bin 2017-02-16 16:45 - 2017-02-16 16:45 - 00020463 _____ C:\ProgramData\agent.1487259935.bdinstall.bin 2017-02-16 16:44 - 2017-02-16 16:44 - 00020463 _____ C:\ProgramData\agent.1487259833.bdinstall.bin 2017-02-16 16:36 - 2017-02-16 16:37 - 00000000 ____D C:\Users\VerzehrendeSonne\Desktop\RevoUninstallerPortable 2017-02-16 16:35 - 2017-02-16 16:36 - 07056416 _____ (PortableApps.com) C:\Users\VerzehrendeSonne\Desktop\RevoUninstallerPortable_2.0.2.paf.exe 2017-02-16 12:01 - 2017-02-16 12:01 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\LocalLow\Adobe 2017-02-16 12:00 - 2017-02-16 12:00 - 00000000 ___SD C:\Users\VerzehrendeSonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3 2017-02-16 12:00 - 2017-02-16 12:00 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\OpenOffice 2017-02-16 11:59 - 2017-02-16 12:00 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2017-02-16 11:58 - 2017-02-16 12:24 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\OpenOffice Updater 2017-02-16 11:43 - 2017-02-16 12:38 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-02-16 11:42 - 2017-02-16 12:38 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-02-16 11:42 - 2017-02-16 12:37 - 00000000 ____D C:\ProgramData\Adobe 2017-02-16 11:42 - 2017-02-16 12:01 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Adobe 2017-02-16 11:42 - 2017-02-16 11:42 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-02-16 10:33 - 2017-02-17 14:31 - 00000000 ____D C:\FRST 2017-02-16 10:32 - 2017-02-16 10:33 - 02422272 _____ (Farbar) C:\Users\VerzehrendeSonne\Desktop\FRST64.exe 2017-02-15 22:19 - 2017-02-15 22:19 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\W10LogonChanger 2017-02-15 12:10 - 2017-02-15 12:10 - 00000000 ____D C:\Users\VerzehrendeSonne\Desktop\SHIFT 2 UNLEASHED 2017-02-15 12:09 - 2017-02-15 12:10 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Rockstar Games 2017-02-15 12:09 - 2017-02-15 12:09 - 00000000 ____D C:\Users\VerzehrendeSonne\Desktop\NFS SHIFT2 2017-02-15 12:08 - 2017-02-15 15:32 - 00003292 _____ C:\Users\VerzehrendeSonne\Desktop\SettingsPane.lnk 2017-02-15 12:08 - 2017-02-10 16:49 - 00106442 _____ C:\Users\VerzehrendeSonne\hier&jetzt.aimppl 2017-02-15 12:03 - 2017-02-16 10:48 - 00000000 ____D C:\Users\VerzehrendeSonne\Desktop\downpipe 2017-02-15 00:19 - 2017-02-15 00:19 - 00000000 ____D C:\Users\Default\AppData\Local\AVG 2017-02-15 00:19 - 2017-02-15 00:19 - 00000000 ____D C:\Users\Default User\AppData\Local\AVG 2017-02-13 22:13 - 2017-02-13 22:13 - 00001464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2017-02-13 22:13 - 2015-06-16 17:32 - 00020760 _____ (Safer-Networking Ltd.) C:\WINDOWS\system32\sdnclean64.exe 2017-02-13 21:53 - 2017-02-13 21:53 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Temp 2017-02-13 21:50 - 2017-02-16 16:47 - 00004721 _____ C:\bdlog.txt 2017-02-13 21:50 - 2017-02-13 21:50 - 00028767 _____ C:\ProgramData\agent.1487019056.bdinstall.bin 2017-02-13 21:48 - 2017-02-13 21:48 - 00382014 _____ C:\ProgramData\cl.1487018818.bdinstall.bin 2017-02-13 21:48 - 2017-02-13 21:48 - 00000385 _____ C:\WINDOWS\system32\user_gensett.xml 2017-02-13 21:48 - 2017-02-13 21:48 - 00000000 ____D C:\ProgramData\BDLogging 2017-02-13 21:48 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\capicom.dll 2017-02-13 21:46 - 2017-02-13 21:46 - 00026926 _____ C:\ProgramData\agent.1487018772.bdinstall.bin 2017-02-13 21:46 - 2017-02-13 21:46 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\QuickScan 2017-02-13 21:30 - 2017-02-13 21:30 - 00046287 _____ C:\ProgramData\agent.1487017829.bdinstall.bin 2017-02-12 21:40 - 2017-02-12 21:41 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\paint.net 2017-02-12 21:40 - 2017-02-12 21:40 - 00001160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2017-02-12 21:40 - 2017-02-12 21:40 - 00000000 ____D C:\Program Files\paint.net 2017-02-12 19:55 - 2017-02-12 19:55 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-02-12 19:55 - 2017-02-12 19:55 - 00000000 ____D C:\Users\VerzehrendeSonne\Tracing 2017-02-12 19:55 - 2017-02-12 19:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-02-12 19:54 - 2017-02-12 19:55 - 00000000 ____D C:\ProgramData\Skype 2017-02-12 19:18 - 2017-02-12 19:18 - 00496896 _____ C:\Program Files\flux-setup.exe 2017-02-12 17:37 - 2017-02-12 17:37 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Mp3tag 2017-02-12 17:37 - 2017-02-12 17:37 - 00000000 ____D C:\Program Files (x86)\Mp3tag 2017-02-12 17:22 - 2017-02-15 21:48 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\AIMP 2017-02-12 17:22 - 2017-02-12 17:22 - 00000000 ____D C:\Program Files (x86)\AIMP 2017-02-12 13:51 - 2017-02-12 13:51 - 00003400 _____ C:\WINDOWS\System32\Tasks\{20D290CE-79C9-457E-888D-E78C260D3D26} 2017-02-12 13:47 - 2017-02-12 13:47 - 00000000 ____D C:\WINDOWS\system32\ScanResults 2017-02-12 13:44 - 2017-02-12 13:44 - 00003370 _____ C:\WINDOWS\System32\Tasks\{DDEA962C-F03C-470A-9C14-C5729111D64B} 2017-02-12 10:54 - 2017-02-12 10:54 - 08974992 _____ (Sandboxie Holdings, LLC) C:\Users\VerzehrendeSonne\Sandboxie516Install.exe 2017-02-12 10:08 - 2017-02-12 20:04 - 00002280 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-02-12 10:08 - 2017-02-12 10:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-02-12 10:08 - 2017-02-12 10:08 - 00000000 ____D C:\Program Files\CCleaner 2017-02-12 09:59 - 2017-02-12 09:59 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Steam 2017-02-12 09:58 - 2017-02-12 09:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2017-02-11 23:35 - 2017-02-11 23:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm 2017-02-11 23:30 - 2017-02-12 12:59 - 00000000 ____D C:\Users\VerzehrendeSonne\Documents\Heroes of the Storm 2017-02-11 23:27 - 2017-02-12 13:24 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Battle.net 2017-02-11 23:27 - 2017-02-12 00:45 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Blizzard Entertainment 2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2017-02-11 23:26 - 2017-02-12 11:00 - 00000000 ____D C:\Program Files (x86)\Battle.net 2017-02-11 23:22 - 2017-02-11 23:27 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Battle.net 2017-02-11 23:22 - 2017-02-11 23:22 - 00000000 ____D C:\ProgramData\Battle.net 2017-02-11 22:59 - 2017-02-11 22:59 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Arktos Entertainment 2017-02-11 22:21 - 2017-02-11 23:56 - 00000000 ____D C:\icon 2017-02-11 22:01 - 2017-02-11 22:01 - 00000000 ____D C:\Users\VerzehrendeSonne\Documents\FredaikisAB 2017-02-11 22:01 - 2017-02-11 22:01 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\FredaikisAB 2017-02-11 21:21 - 2017-02-11 23:31 - 00000000 ____D C:\Users\Public\Documents\Winstep 2017-02-11 21:21 - 2017-02-11 21:22 - 00000000 ____D C:\Program Files (x86)\Winstep 2017-02-11 21:21 - 2017-02-11 21:21 - 00001135 _____ C:\Users\VerzehrendeSonne\Documents\Winstep.lnk 2017-02-11 21:21 - 2017-02-11 21:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winstep 2017-02-11 21:21 - 2008-02-05 14:36 - 00798208 _____ (Winstep Software Technologies) C:\WINDOWS\SysWOW64\NextControls.ocx 2017-02-11 21:21 - 2000-05-22 16:58 - 00608448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.ocx 2017-02-11 21:21 - 1997-07-19 15:55 - 01347344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvbvm50.dll 2017-02-11 21:19 - 2017-02-12 19:18 - 00002215 _____ C:\Users\VerzehrendeSonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk 2017-02-11 21:19 - 2017-02-11 21:19 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\FluxSoftware 2017-02-11 21:14 - 2017-02-11 21:14 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\WinRAR 2017-02-11 21:14 - 2017-02-11 21:14 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-02-11 21:14 - 2017-02-11 21:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-02-11 21:14 - 2017-02-11 21:14 - 00000000 ____D C:\Program Files\WinRAR 2017-02-11 21:08 - 2017-02-11 21:08 - 00000000 ____D C:\Gamez 2017-02-11 21:05 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll 2017-02-11 21:05 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll 2017-02-11 21:05 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll 2017-02-11 21:05 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll 2017-02-11 21:05 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll 2017-02-11 21:05 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll 2017-02-11 21:05 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll 2017-02-11 21:05 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll 2017-02-11 21:05 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll 2017-02-11 21:05 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll 2017-02-11 21:05 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll 2017-02-11 21:05 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll 2017-02-11 21:05 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll 2017-02-11 21:05 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll 2017-02-11 21:05 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll 2017-02-11 21:05 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll 2017-02-11 21:05 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll 2017-02-11 21:05 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll 2017-02-11 21:05 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll 2017-02-11 21:05 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll 2017-02-11 21:05 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll 2017-02-11 21:05 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll 2017-02-11 21:05 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll 2017-02-11 21:05 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll 2017-02-11 21:05 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll 2017-02-11 21:05 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll 2017-02-11 21:05 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll 2017-02-11 21:05 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll 2017-02-11 21:05 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll 2017-02-11 21:05 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll 2017-02-11 21:05 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll 2017-02-11 21:05 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll 2017-02-11 21:05 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll 2017-02-11 21:05 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll 2017-02-11 21:05 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll 2017-02-11 21:05 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll 2017-02-11 21:05 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll 2017-02-11 21:05 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll 2017-02-11 21:05 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll 2017-02-11 21:05 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll 2017-02-11 21:05 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2017-02-11 21:05 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll 2017-02-11 21:05 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2017-02-11 21:05 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll 2017-02-11 21:05 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2017-02-11 21:05 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll 2017-02-11 21:05 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll 2017-02-11 21:05 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll 2017-02-11 21:05 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll 2017-02-11 21:05 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll 2017-02-11 21:05 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll 2017-02-11 21:05 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll 2017-02-11 21:05 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll 2017-02-11 21:05 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll 2017-02-11 21:05 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll 2017-02-11 21:05 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll 2017-02-11 21:05 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll 2017-02-11 21:05 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll 2017-02-11 21:05 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll 2017-02-11 21:05 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll 2017-02-11 21:05 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll 2017-02-11 21:05 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll 2017-02-11 21:05 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll 2017-02-11 21:05 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll 2017-02-11 21:05 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll 2017-02-11 21:05 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll 2017-02-11 21:05 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll 2017-02-11 21:05 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll 2017-02-11 21:05 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll 2017-02-11 21:05 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll 2017-02-11 21:05 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll 2017-02-11 21:05 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll 2017-02-11 21:05 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll 2017-02-11 21:05 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll 2017-02-11 21:05 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll 2017-02-11 21:05 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll 2017-02-11 21:05 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll 2017-02-11 21:05 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll 2017-02-11 21:05 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll 2017-02-11 21:05 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll 2017-02-11 21:05 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll 2017-02-11 21:05 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll 2017-02-11 21:05 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll 2017-02-11 21:05 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll 2017-02-11 21:05 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll 2017-02-11 21:05 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll 2017-02-11 21:05 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll 2017-02-11 21:05 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll 2017-02-11 21:05 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll 2017-02-11 21:05 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll 2017-02-11 21:05 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll 2017-02-11 21:05 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll 2017-02-11 21:05 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll 2017-02-11 21:05 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll 2017-02-11 21:05 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll 2017-02-11 21:05 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll 2017-02-11 21:05 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll 2017-02-11 21:05 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll 2017-02-11 21:05 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll 2017-02-11 21:05 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll 2017-02-11 21:05 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll 2017-02-11 21:05 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll 2017-02-11 21:05 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll 2017-02-11 21:05 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll 2017-02-11 21:05 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll 2017-02-11 21:05 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll 2017-02-11 21:05 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll 2017-02-11 21:05 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll 2017-02-11 21:05 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll 2017-02-11 21:05 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll 2017-02-11 21:05 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll 2017-02-11 21:05 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll 2017-02-11 21:05 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll 2017-02-11 21:05 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll 2017-02-11 21:05 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll 2017-02-11 21:05 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll 2017-02-11 21:05 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll 2017-02-11 21:05 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll 2017-02-11 21:05 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll 2017-02-11 21:05 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll 2017-02-11 21:05 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll 2017-02-11 21:05 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll 2017-02-11 21:05 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll 2017-02-11 21:05 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll 2017-02-11 21:05 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll 2017-02-11 21:05 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll 2017-02-11 21:05 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll 2017-02-11 21:05 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll 2017-02-11 21:05 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll 2017-02-11 21:05 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll 2017-02-11 21:05 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll 2017-02-11 21:05 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll 2017-02-11 21:05 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll 2017-02-11 21:05 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll 2017-02-11 21:05 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll 2017-02-11 21:05 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll 2017-02-11 21:05 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll 2017-02-11 21:05 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll 2017-02-11 21:05 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll 2017-02-11 21:05 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll 2017-02-11 21:05 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll 2017-02-11 21:05 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll 2017-02-11 21:05 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll 2017-02-11 21:05 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll 2017-02-11 21:05 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll 2017-02-11 21:05 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll 2017-02-11 21:05 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll 2017-02-11 21:05 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll 2017-02-11 21:05 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll 2017-02-11 21:05 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll 2017-02-11 21:04 - 2017-02-11 21:08 - 00000000 ____D C:\WINDOWS\SysWOW64\directx |
17.02.2017, 14:35 | #27 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABYCode:
ATTFilter 2017-02-11 20:56 - 2017-02-16 11:37 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Thunderbird 2017-02-11 20:56 - 2017-02-15 12:11 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Thunderbird 2017-02-11 20:56 - 2017-02-11 20:56 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Mozilla 2017-02-11 20:56 - 2017-02-11 20:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2017-02-11 20:56 - 2017-02-11 20:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-02-11 20:48 - 2017-02-11 20:48 - 00955424 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys 2017-02-11 20:48 - 2017-02-11 20:48 - 00091272 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll 2017-02-11 20:46 - 2017-02-11 20:46 - 01795952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll 2017-02-11 20:46 - 2017-02-11 20:46 - 00033960 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_Intel.sys 2017-02-11 20:46 - 2017-02-11 20:46 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf 2017-02-11 20:46 - 2017-02-11 20:46 - 00000000 ____D C:\Program Files\Synaptics 2017-02-11 20:44 - 2017-02-15 22:20 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\CrashDumps 2017-02-11 20:44 - 2017-02-11 20:44 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS 2017-02-11 20:44 - 2017-02-11 20:44 - 00000000 ____D C:\WINDOWS\IObit 2017-02-11 20:44 - 2017-02-11 20:44 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\LocalLow\IObit 2017-02-11 20:44 - 2017-02-11 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4 2017-02-11 20:44 - 2017-02-11 20:44 - 00000000 ____D C:\ProgramData\IObit 2017-02-11 20:44 - 2017-02-11 20:44 - 00000000 ____D C:\Program Files (x86)\IObit 2017-02-11 20:43 - 2017-02-11 20:59 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\IObit 2017-02-11 20:26 - 2017-02-11 20:26 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-02-11 20:26 - 2017-01-20 17:38 - 00514616 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2017-02-11 20:26 - 2016-12-16 01:33 - 00273696 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2017-02-11 20:26 - 2016-12-16 01:33 - 00266528 _____ C:\WINDOWS\system32\vulkan-1.dll 2017-02-11 20:26 - 2016-12-16 01:33 - 00111392 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2017-02-11 20:26 - 2016-12-16 01:32 - 00125728 _____ C:\WINDOWS\system32\vulkaninfo.exe 2017-02-11 20:24 - 2017-02-11 21:05 - 00000000 ____D C:\ProgramData\Package Cache 2017-02-11 20:24 - 2017-01-24 01:00 - 00047664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 40192056 _____ C:\WINDOWS\system32\nvcompiler.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 35272760 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 34974656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 28239928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 19008576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 14677272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 11123936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 11019192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 09308896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 08990584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 03597640 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 03167288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 02715072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 01985080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437849.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 01591352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437849.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 01051584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00988608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00960568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00946456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00909760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00721952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00687224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00609216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00606776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00576192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00573120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00499136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00483384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00447800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2017-02-11 20:24 - 2017-01-20 17:38 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json 2017-02-11 20:24 - 2017-01-20 17:38 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json 2017-02-11 19:59 - 2017-02-11 20:49 - 00000000 ____D C:\WINDOWS\LastGood 2017-02-11 19:55 - 2017-02-11 19:55 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\570F660E.sys 2017-02-11 19:47 - 2009-04-02 13:30 - 00010296 _____ C:\WINDOWS\SysWOW64\Drivers\ASUSHWIO.SYS 2017-02-11 15:53 - 2017-02-12 13:45 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information 2017-02-11 15:53 - 2017-02-11 20:35 - 00000024 _____ C:\WINDOWS\SetupTemp.ini 2017-02-11 15:53 - 2017-02-11 15:53 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2017-02-11 15:52 - 2017-02-11 19:54 - 00000000 ____D C:\Program Files (x86)\VIA 2017-02-11 15:52 - 2017-02-11 15:03 - 00414632 ____N (Microsoft Corporation) C:\WINDOWS\difxapi.dll 2017-02-11 15:23 - 2017-02-11 15:23 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\PeerDistRepub 2017-02-11 15:17 - 2017-02-11 15:49 - 00002562 _____ C:\WINDOWS\System32\Tasks\SamsungMagician 2017-02-11 15:17 - 2017-02-11 15:18 - 00000000 ____D C:\Program Files (x86)\Samsung Magician 2017-02-11 15:17 - 2017-02-11 15:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2017-02-11 15:04 - 2017-02-11 15:17 - 00000000 ____D C:\ProgramData\Samsung 2017-02-11 14:54 - 2017-02-11 14:54 - 00000000 ____D C:\Users\Public\Documents\Logishrd 2017-02-11 14:54 - 2017-02-11 14:54 - 00000000 ____D C:\ProgramData\Logitech 2017-02-11 14:52 - 2017-02-11 20:49 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys 2017-02-11 14:52 - 2017-02-11 14:54 - 00000000 ____D C:\ProgramData\Logishrd 2017-02-11 14:52 - 2017-02-11 14:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2017-02-11 14:52 - 2017-02-11 14:52 - 00000000 ____D C:\Program Files\Logitech 2017-02-11 14:51 - 2017-02-11 14:54 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Logitech 2017-02-11 14:51 - 2017-02-11 14:52 - 00000000 ____D C:\Program Files\Common Files\LogiShrd 2017-02-11 14:51 - 2017-02-11 14:51 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Logishrd 2017-02-11 14:50 - 2017-02-11 14:50 - 00000000 ___HD C:\$SysReset 2017-02-11 14:49 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2017-02-11 14:49 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2017-02-11 14:41 - 2017-02-11 23:31 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\ConnectedDevicesPlatform 2017-02-11 14:41 - 2017-02-11 14:41 - 00000020 ___SH C:\Users\VerzehrendeSonne\ntuser.ini 2017-02-11 14:41 - 2017-02-11 14:41 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Comms 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Vorlagen 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Startmenü 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2017-02-11 12:58 - 2017-02-11 12:58 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2017-02-11 12:57 - 2017-02-16 10:04 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task 2017-02-11 12:57 - 2017-02-12 21:01 - 00003556 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-02-11 12:57 - 2017-02-12 21:01 - 00003332 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-02-11 12:57 - 2017-02-11 12:58 - 00007623 _____ C:\WINDOWS\diagwrn.xml 2017-02-11 12:57 - 2017-02-11 12:58 - 00007623 _____ C:\WINDOWS\diagerr.xml 2017-02-11 12:57 - 2017-02-11 12:57 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat 2017-02-11 12:57 - 2017-02-11 12:57 - 00002832 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-02-11 12:57 - 2017-02-11 12:57 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking 2017-02-11 12:54 - 2017-02-11 12:54 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-02-11 12:53 - 2017-02-15 21:51 - 00000000 ____D C:\Users\VerzehrendeSonne 2017-02-11 12:53 - 2017-02-11 12:54 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Vorlagen 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Startmenü 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Netzwerkumgebung 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Lokale Einstellungen 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Eigene Dateien 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Druckumgebung 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Documents\Eigene Videos 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Documents\Eigene Musik 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Documents\Eigene Bilder 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\AppData\Local\Verlauf 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\AppData\Local\Anwendungsdaten 2017-02-11 12:53 - 2017-02-11 12:53 - 00000000 _SHDL C:\Users\VerzehrendeSonne\Anwendungsdaten 2017-02-11 12:52 - 2017-02-11 20:26 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-02-11 12:52 - 2017-02-11 20:26 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-02-11 12:52 - 2017-02-11 20:24 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-02-11 12:52 - 2017-02-11 12:52 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2017-02-11 12:52 - 2017-02-11 12:52 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2017-02-11 12:52 - 2017-02-11 12:52 - 00000000 ____D C:\Program Files\VIA 2017-02-11 12:52 - 2017-01-20 16:13 - 06401984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 02479160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 00548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2017-02-11 12:52 - 2017-01-20 16:13 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2017-02-11 12:52 - 2017-01-18 13:57 - 07755067 _____ C:\WINDOWS\system32\nvcoproc.bin 2017-02-11 12:51 - 2017-02-12 10:13 - 00000000 ___DC C:\WINDOWS\Panther 2017-02-11 12:49 - 2017-02-11 12:49 - 00000000 ____D C:\Windows.old 2017-02-11 12:48 - 2017-02-11 12:48 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 17188864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 04130440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02169184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 01669984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01469792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01454504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01400160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2017-02-11 12:48 - 2017-02-11 12:48 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2017-02-11 12:48 - 2017-02-11 12:48 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2017-02-11 12:48 - 2017-02-11 12:48 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01054048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2017-02-11 12:48 - 2017-02-11 12:48 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00992096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2017-02-11 12:48 - 2017-02-11 12:48 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00822624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00813408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00779616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00752992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00571744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00513376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00406368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00319288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00190816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00089416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2017-02-11 12:48 - 2017-02-11 12:48 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll 2017-02-11 12:48 - 2017-02-11 12:48 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2017-02-11 12:48 - 2017-02-11 12:48 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2017-02-11 12:43 - 2017-02-11 12:43 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-02-11 12:40 - 2017-02-11 12:40 - 00000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER 2017-02-11 12:38 - 2017-02-11 12:53 - 00000000 ____D C:\Program Files\CMAK 2017-02-11 12:38 - 2017-02-11 12:38 - 00000000 ____D C:\Program Files (x86)\CMAK 2017-02-11 12:26 - 2016-12-03 15:16 - 00668736 _____ (O&O Software GmbH) C:\Users\VerzehrendeSonne\Desktop\OOSU10.exe 2017-02-11 12:19 - 2017-02-10 16:07 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\TURegOpt.exe 2017-02-11 12:18 - 2017-02-16 16:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen 2017-02-11 12:16 - 2017-02-11 12:16 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\CEF 2017-02-11 12:15 - 2017-02-16 16:38 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\AvgSetupLog 2017-02-11 12:15 - 2017-02-11 12:19 - 00000000 ____D C:\ProgramData\Avg 2017-02-11 12:14 - 2017-02-11 12:15 - 03312392 _____ (AVG Technologies CZ, s.r.o.) C:\Users\VerzehrendeSonne\Downloads\AVG_Performance_709.exe 2017-02-11 12:01 - 2017-02-11 12:02 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-02-11 12:01 - 2017-02-11 12:01 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-02-11 11:57 - 2016-09-30 04:28 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll 2017-02-11 11:56 - 2016-09-07 05:22 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll 2017-02-11 11:50 - 2017-02-16 23:13 - 00176584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys 2017-02-11 11:50 - 2017-02-16 23:13 - 00110536 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2017-02-11 11:50 - 2017-02-16 23:13 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2017-02-11 11:50 - 2017-02-16 23:13 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2017-02-11 11:39 - 2017-02-11 11:39 - 00017280 _____ () C:\WINDOWS\system32\Drivers\ASACPI.sys 2017-02-11 11:38 - 2017-02-15 21:48 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Skype 2017-02-11 11:36 - 2017-02-11 12:57 - 00002264 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-02-11 11:36 - 2017-02-11 12:20 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Google 2017-02-11 11:36 - 2017-02-11 11:36 - 27898680 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioVnA64.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 07235584 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEP64H.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 07235584 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEP64A.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 02130448 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 01031376 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00678176 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00446224 _____ (Dolby Laboratories) C:\WINDOWS\system32\EED64H.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00446224 _____ (Dolby Laboratories) C:\WINDOWS\system32\EED64A.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00260120 _____ (Windows (R) Codename Longhorn DDK provider) C:\WINDOWS\system32\Dts2APO.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00147224 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEL64A.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00147216 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEL64H.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00130144 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEA64H.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00130144 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEA64A.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00101016 _____ (VIA Technologies, Inc.) C:\WINDOWS\system32\Dts2PropPageExt.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00094720 _____ (QSound Labs, Inc.) C:\WINDOWS\system32\nQPropPageExt.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00093712 _____ (QSound Labs, Inc.) C:\WINDOWS\system32\nQAPO.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00084688 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEG64H.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00084688 _____ (Dolby Laboratories) C:\WINDOWS\system32\EEG64A.dll 2017-02-11 11:36 - 2017-02-11 11:36 - 00000000 ____D C:\Program Files (x86)\Google 2017-02-11 11:35 - 2017-02-16 23:13 - 00000000 ____D C:\ProgramData\NVIDIA 2017-02-11 11:35 - 2017-02-11 11:35 - 01964600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437653.dll 2017-02-11 11:35 - 2017-02-11 11:35 - 01600056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437653.dll 2017-02-11 11:35 - 2017-01-24 01:00 - 01600056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll 2017-02-11 11:35 - 2017-01-24 01:00 - 00217528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys 2017-02-11 11:35 - 2017-01-20 17:38 - 04079032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2017-02-11 11:35 - 2017-01-20 17:38 - 00043556 _____ C:\WINDOWS\system32\nvinfo.pb 2017-02-11 11:35 - 2017-01-20 15:04 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2017-02-11 11:33 - 2017-02-11 11:33 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Macromedia 2017-02-11 11:32 - 2017-02-11 11:32 - 03942864 _____ (Logitech, Inc.) C:\WINDOWS\system32\LogiLDA.DLL 2017-02-11 11:32 - 2017-02-11 11:32 - 02468304 _____ (Logitech, Inc.) C:\WINDOWS\system32\LdaCx2.dll 2017-02-11 11:32 - 2017-02-11 11:32 - 00838224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr110.dll 2017-02-11 11:32 - 2017-02-11 11:32 - 00670800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp110.dll 2017-02-11 11:32 - 2017-02-11 11:32 - 00363616 _____ (Microsoft Corporation) C:\WINDOWS\system32\vccorlib110.dll 2017-02-11 11:11 - 2017-02-11 11:30 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\MicrosoftEdge 2017-02-11 11:10 - 2017-02-16 23:13 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-02-11 11:10 - 2017-02-16 21:46 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-02-11 11:10 - 2017-02-11 11:10 - 00000000 ____D C:\Program Files\Malwarebytes 2017-02-11 11:10 - 2017-01-20 07:47 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-02-11 11:06 - 2017-02-13 21:45 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2017-02-11 11:04 - 2017-02-11 11:37 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2017-02-11 11:03 - 2017-02-11 11:03 - 00450709 ____R C:\WINDOWS\system32\Drivers\etc\hosts.20170211-110350.backup 2017-02-11 11:03 - 2015-07-10 12:02 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20170211-110321.backup 2017-02-11 10:20 - 2017-02-11 15:50 - 00000000 ___RD C:\Users\VerzehrendeSonne\OneDrive 2017-02-11 10:18 - 2017-02-16 12:01 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Roaming\Adobe 2017-02-11 10:18 - 2017-02-11 14:58 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Packages 2017-02-11 10:18 - 2017-02-11 10:18 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-R23SD8I_defaultuser0_HistoryPrediction.bin 2017-02-11 10:18 - 2017-02-11 10:18 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\VirtualStore 2017-02-11 10:18 - 2017-02-11 10:18 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\TileDataLayer 2017-02-11 10:18 - 2017-02-11 10:18 - 00000000 ____D C:\Users\VerzehrendeSonne\AppData\Local\Publishers 2017-02-11 10:17 - 2017-02-11 10:17 - 00000000 ____D C:\WINDOWS\CSC 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Videos 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Vorlagen 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Startmenü 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Netzwerkumgebung 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Lokale Einstellungen 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Eigene Dateien 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Druckumgebung 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Documents\Eigene Videos 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Documents\Eigene Musik 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Documents\Eigene Bilder 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\AppData\Local\Verlauf 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\AppData\Local\Anwendungsdaten 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Users\Default.migrated\Anwendungsdaten 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Programme 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\ProgramData\Vorlagen 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\ProgramData\Startmenü 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\ProgramData\Dokumente 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2017-02-11 10:15 - 2017-02-11 10:15 - 00000000 _SHDL C:\Dokumente und Einstellungen 2017-02-11 10:11 - 2017-02-11 12:33 - 00008192 __RSH C:\BOOTSECT.BAK ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-02-17 00:59 - 2016-11-20 13:36 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-02-16 23:17 - 2016-11-20 22:46 - 02018888 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-02-16 23:17 - 2016-11-20 22:00 - 00803808 _____ C:\WINDOWS\system32\perfh007.dat 2017-02-16 23:17 - 2016-11-20 22:00 - 00179902 _____ C:\WINDOWS\system32\perfc007.dat 2017-02-16 23:13 - 2016-11-20 22:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-02-16 23:13 - 2016-07-16 07:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI 2017-02-16 23:06 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ELAMBKUP 2017-02-16 19:19 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-02-16 16:47 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2017-02-16 12:23 - 2016-11-20 13:36 - 00232696 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-02-16 11:59 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-02-15 21:10 - 2016-11-20 22:50 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-02-13 21:44 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-02-13 21:43 - 2015-07-10 10:05 - 00000000 ____D C:\Users\Default.migrated 2017-02-12 10:13 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-02-12 09:35 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\appcompat 2017-02-11 14:58 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-02-11 14:49 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-02-11 13:31 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache 2017-02-11 12:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-02-11 12:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Registration 2017-02-11 12:58 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows NT 2017-02-11 12:57 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2017-02-11 12:56 - 2016-07-16 12:47 - 00000000 __RHD C:\Users\Public\Libraries 2017-02-11 12:54 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-02-11 12:53 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2017-02-11 12:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Help 2017-02-11 12:52 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-02-11 12:51 - 2016-07-16 12:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning 2017-02-11 12:49 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr 2017-02-11 12:49 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-02-11 12:49 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-02-11 12:49 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing 2017-02-11 12:47 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2017-02-11 12:30 - 2016-12-02 23:15 - 00000000 ___HD C:\$WINDOWS.~BT 2017-02-11 11:53 - 2015-07-10 12:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll 2017-02-11 11:53 - 2015-07-10 12:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll 2017-01-20 17:38 - 2016-11-20 22:27 - 00420408 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-02-12 19:18 - 2017-02-12 19:18 - 0496896 _____ () C:\Program Files\flux-setup.exe 2017-02-13 21:30 - 2017-02-13 21:30 - 0046287 _____ () C:\ProgramData\agent.1487017829.bdinstall.bin 2017-02-13 21:46 - 2017-02-13 21:46 - 0026926 _____ () C:\ProgramData\agent.1487018772.bdinstall.bin 2017-02-13 21:50 - 2017-02-13 21:50 - 0028767 _____ () C:\ProgramData\agent.1487019056.bdinstall.bin 2017-02-16 16:44 - 2017-02-16 16:44 - 0020463 _____ () C:\ProgramData\agent.1487259833.bdinstall.bin 2017-02-16 16:45 - 2017-02-16 16:45 - 0020463 _____ () C:\ProgramData\agent.1487259935.bdinstall.bin 2017-02-16 16:48 - 2017-02-16 16:48 - 0029076 _____ () C:\ProgramData\agent.1487260105.bdinstall.bin 2017-02-13 21:48 - 2017-02-13 21:48 - 0382014 _____ () C:\ProgramData\cl.1487018818.bdinstall.bin 2017-02-16 16:47 - 2017-02-16 16:47 - 0218764 _____ () C:\ProgramData\cl.uninstall.1487259991.bdinstall.bin Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\VerzehrendeSonne\Sandboxie516Install.exe Einige Dateien in TEMP: ==================== 2017-02-11 20:24 - 2016-12-29 13:43 - 0351680 _____ (NVIDIA Corporation) C:\Users\VerzehrendeSonne\AppData\Local\Temp\nvStInst.exe 2016-10-13 09:18 - 2016-10-13 09:18 - 171330228 _____ () C:\Users\VerzehrendeSonne\AppData\Local\Temp\OpenOffice_4.1.3_Win_x86_install_de.exe ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-02-11 13:07 ==================== Ende von FRST.txt ============================ |
18.02.2017, 18:33 | #28 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY COOSINUUS wo bisstee!! Hast du mich vergessen?? |
18.02.2017, 18:49 | #29 |
/// Winkelfunktion /// TB-Süch-Tiger™ | TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY sachte mein Junge (oder biste ein Mädl?) hab hier noch andere zu verarzten und nicht nur dich FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM-x32\...\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" IFEO\ccleaner64.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\driverbooster.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\samsungmagician.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" S2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe" [X] S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X] S2 SDScannerService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" [X] S2 SDUpdateService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" [X] S2 SDWSCService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe" [X] S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [X] C:\Program Files (x86)\AVG C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\Users\Default\AppData\Local\AVG C:\Users\Default User\AppData\Local\AVG C:\WINDOWS\system32\sdnclean64.exe hosts: emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
18.02.2017, 19:21 | #30 |
| TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY FRST hat leider kein Fixlog erstellt oder wo finde ich den log? Da wo die anderen logs auch sind nehme ich an FRST/Addition. Da zumindest ist es nicht. Nur ein FRST-OlderVersion Ordner wurde erstellt mit dem Inhalt FRST64.exe Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-02-2017 01 durchgeführt von VerzehrendeSonne (18-02-2017 19:13:09) Run:1 Gestartet von C:\Users\VerzehrendeSonne\Desktop Geladene Profile: VerzehrendeSonne (Verfügbare Profile: VerzehrendeSonne) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** HKLM-x32\...\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" IFEO\ccleaner64.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\driverbooster.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\samsungmagician.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" S2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe" [X] S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X] S2 SDScannerService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" [X] S2 SDUpdateService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" [X] S2 SDWSCService; "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe" [X] S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [X] C:\Program Files (x86)\AVG C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\Users\Default\AppData\Local\AVG C:\Users\Default User\AppData\Local\AVG C:\WINDOWS\system32\sdnclean64.exe hosts: emptytemp: ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AvgUi => Wert erfolgreich entfernt HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => Schlüssel erfolgreich entfernt HKU\S-1-5-21-2393573186-4192034997-1557151240-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotPostWindows10UpgradeReInstall => Wert erfolgreich entfernt HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ccleaner64.exe => Schlüssel erfolgreich entfernt HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\driverbooster.exe => Schlüssel erfolgreich entfernt HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\samsungmagician.exe => Schlüssel erfolgreich entfernt HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\unins000.exe => Schlüssel erfolgreich entfernt HKLM\System\CurrentControlSet\Services\TuneUp.UtilitiesSvc => Schlüssel erfolgreich entfernt TuneUp.UtilitiesSvc => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\avgsvc => Schlüssel erfolgreich entfernt avgsvc => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\SDScannerService => Schlüssel erfolgreich entfernt SDScannerService => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\SDUpdateService => Schlüssel erfolgreich entfernt SDUpdateService => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\SDWSCService => Schlüssel erfolgreich entfernt SDWSCService => Dienst erfolgreich entfernt HKLM\System\CurrentControlSet\Services\TuneUpUtilitiesDrv => Schlüssel erfolgreich entfernt TuneUpUtilitiesDrv => Dienst erfolgreich entfernt "C:\Program Files (x86)\AVG" => nicht gefunden. "C:\Program Files (x86)\Spybot - Search & Destroy 2" => nicht gefunden. C:\Users\Default\AppData\Local\AVG => erfolgreich verschoben "C:\Users\Default User\AppData\Local\AVG" => nicht gefunden. C:\WINDOWS\system32\sdnclean64.exe => erfolgreich verschoben C:\Windows\System32\Drivers\etc\hosts => erfolgreich verschoben Hosts erfolgreich wiederhergestellt. =========== EmptyTemp: ========== BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 208512416 B Java, Flash, Steam htmlcache => 6238266 B Windows/system/drivers => 11948135 B Edge => 11151 B Chrome => 411588664 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 6656 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 190532 B LocalService => 65362 B NetworkService => 0 B VerzehrendeSonne => 1387041237 B RecycleBin => 678678855 B EmptyTemp: => 2.5 GB temporäre Dateien entfernt. ================================ Das System musste neu gestartet werden. ==== Ende von Fixlog 19:13:18 ==== Der Ordner von FRST war unter Programme zufinden. Ich hatte meines wissens nach dort keinen Ornder angelegt, sondern immer brav die .exe vom Desktop aus gestartet. Naja habe es aber hinbekommen. LG Um deine Frage zu beantworten, bin ein männlein! |
Themen zu TROJANER auf USB-Stick...host.exe/copy.exe Win32:Hupigon-LCG, Win32:Agent-ILR, Win32:Small-ABY |
avast, erwischt, free, nicht, person, private, troja, trojaner, usb-stick, verwendet, win, win32, überspielen, ziemlich |