|
Log-Analyse und Auswertung: HEUR:Trojan.Script.Generic auf Chrome über FB-LinkWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.10.2017, 15:18 | #1 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link Werte Kollegen, nachdem ich mir selbst über den fb acc von meiner Freundin einen Link gesendet habe über ihren Laptop, und ich diesen geöffnet habe, hat mein Kaspersky los geschriehen. HEUR:Trojan.Script.Generic Dieser Trojaner befindet sich direkt auf der Website(natürlich quatsch, die Seite ist seriös gewesen), also muss es sich auf meinem Computer befinden. ich habe auch schon mehrfach versucht etwas aus anderen Themen aus meinem PC zu locken, hab Datein gelöscht und Einträge gelöscht, leider wird dieser Trojaner immer noch nicht kleiner. Bitte um Hilfe, poste alle nötigen dinge. Wenn möglich hätte ich gerne alle möglichen Infos, wie sowas möglich ist, wie sich der Trojaner im Hyperlink verstecken etc. bin begeisterter Informatik-interessierter mit zu wenig zeit und dem Flaschen Ausbildungsberuf. Vielen Dank im Vorraus Absylicus FRST.txt Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 23-10-2017 01 durchgeführt von Sam (Administrator) auf DESKTOP-8FDETOF (23-10-2017 22:52:40) Gestartet von C:\Users\Sam\Desktop Geladene Profile: Sam (Verfügbare Profile: Sam) Platform: Windows 10 Education Version 1703 15063.674 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe () C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe (Foxit Software Inc.) E:\Programme\Foxit Reader\FoxitConnectedPDFService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken_Driver\Drivers\SysAudio\KrakenHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avpui.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc.) HKLM-x32\...\Run: [FireStormStartUpAutoRun] => C:\Program Files (x86)\ZotacFireStorm\FireStorm.exe [33653248 2017-05-26] (PC Partner Co.Ltd) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596664 2017-08-30] (Razer Inc.) HKLM-x32\...\Run: [KrakenLauncher] => C:\Program Files (x86)\Razer\Razer_Kraken_Driver\Drivers\SysAudio\KrakenHelper.exe [1598920 2017-06-30] (Razer Inc) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation) HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Run: [Steam] => D:\Steam\steam.exe [3101984 2017-10-17] (Valve Corporation) HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Run: [GalaxyClient] => D:\GOG Galaxy\GOG Galaxy\GalaxyClient.exe [5161536 2017-09-28] (GOG.com) HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Run: [Discord] => C:\Users\Sam\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.) HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Run: [uTorrent] => C:\Users\Sam\AppData\Roaming\uTorrent\uTorrent.exe [2150336 2017-09-20] (BitTorrent Inc.) HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd) HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799376 2016-12-14] (Sandboxie Holdings, LLC) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{44ae14e7-f53b-418b-ad83-1a68a72889a7}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{71cb1e24-5870-4bb5-9074-ce19ca5af15f}: [DhcpNameServer] 172.18.12.1 Tcpip\..\Interfaces\{80127399-a795-429d-b693-c71a64c3c076}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-773800576-1985737239-35243653-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-09-05] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2017-10-22] (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-09-05] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-22] (Oracle Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Sam\AppData\Roaming\Mozilla\Firefox\Profiles\459svr9e.default [nicht gefunden] <==== ACHTUNG FF HKLM\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-10-13] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-22] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-22] (Oracle Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> E:\Programme\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> E:\Programme\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> E:\Programme\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> E:\Programme\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation) FF Plugin-x32: @google.com/zxwebplugin -> C:\Windows\system32\npzxwebplugin.dll [Keine Datei] FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2017-09-01] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-09-16] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-09-16] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-23] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-23] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) Chrome: ======= CHR HomePage: Default -> hxxps://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.de/","hxxp://www.google.com/","hxxp://www.sweet-page.com/?type=hp&ts=1406825202&from=cor&uid=HitachiXHDS723015BLA642_MN1120F100G7MD00G7MDX","hxxp://de.msn.com/?pc=U270&ocid=U270DHP","hxxp://www.mystartsearch.com/?type=hp&ts=1425744320&from=cor&uid=HitachiXHDS723015BLA642_MN1120F100G7MD00G7MDX","hxxp://binkiland.com/?f=7&a=bnk_ir_15_10&cd=2XzuyEtN2Y1L1QzutDtDtByDtBtB0D0EyEyD0AzzyCtA0FtDtN0D0Tzu0StCtCyCtCtN1L2XzutAtFzztFyEtFtAtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyB0ByB0CyE0F0AyBtGzzyBzzzztG0E0EtBzztGyB0A0A0BtGtA0D0C0EtD0E0A0E0B0CtCyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0EtB0FtBtD0F0AtGtC0EtAyCtGyEtC0DyDtG0B0DyByDtGzyyC0FtA0E0EtB0C0BtCzztA2QtN1B2Z1V1T1S1NzuyDyBtA&cr=1028375300&ir=","hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_29¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDzztDtDtByBtDtDtAyE0CyC0E0C0CtCtN0D0Tzu0StCtBzytDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StAyEzz0B0C0C0EtDtGtD0D0BtCtG0BtBzy0EtGyCtCyBzztGzzyEtA0DtBtCyB0E0C0FtAzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzz0DyEtC0E0EzytG0C0E0EtBtGyEyBzytDtG0BzzzzzztGyC0C0ByB0EtB0AtCtDtDtD0F2QtN0A0LzutD%26cr%3D566082629%26a%3Dwncy_ir_15_29%26os%3DWindows 8.1 Pro","hxxp://www.mystartsearch.com/?type=hp&ts=1436888125&z=673c09f64322f8521dc1aa7g6zfc6q3b3b3b9g8e9b&from=cor&uid=HitachiXHDS723015BLA642_MN1120F100G7MD00G7MDX" CHR DefaultSearchKeyword: Default -> hxxps://www.google.de/ CHR Profile: C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default [2017-10-23] CHR Extension: (Präsentationen) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-23] CHR Extension: (Nature Themes - Beach Ocean Galaxy Space Snow) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpcbdjjofgacpgojcennocojkdnaiei [2017-10-23] CHR Extension: (h264ify) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2017-10-23] CHR Extension: (Docs) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-23] CHR Extension: (Google Drive) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-23] CHR Extension: (YouTube) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-23] CHR Extension: (Adblock für Youtube™) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2017-10-23] CHR Extension: (Zombie Slayer) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpfnagalgcioakfhhpgakfgbljipmaa [2017-10-23] CHR Extension: (Free Rider 3) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\efgciaombdjbpmepfcndmfidlklafhcc [2017-10-23] CHR Extension: (Tabellen) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-23] CHR Extension: (Google Docs Offline) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-23] CHR Extension: (AdBlock) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-10-23] CHR Extension: (Crazy Chicken) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\hffidhkjaeimpicfoicgkhkokcbiaaka [2017-10-23] CHR Extension: (Creatures & Castles (Kreaturen & Burgen)) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfpeacgpdnhofhebmincihdelcemhagd [2017-10-23] CHR Extension: (TuneIn Radio) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhkolpgedpldcfmkgbdokgiljfbblpfj [2017-10-23] CHR Extension: (Material Dark - MKBHD) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\iiplegjeipnjdpgkeccfccnahofbckad [2017-10-23] CHR Extension: (Build with Chrome) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbbbhbjeecagnlfgggogfclkdjamoapf [2017-10-23] CHR Extension: (Audio EQ) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfafdlnjaliaghpjdajmlcnnblkgcefh [2017-10-23] CHR Extension: (Kaspersky Protection) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchjnmdbdlkdbfliogedbnpnanfjnolk [2017-10-23] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-23] CHR Extension: (Google Mail) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-23] CHR Extension: (Chrome Media Router) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-23] CHR HKLM\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk CHR HKLM-x32\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc.) R2 AVP18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe [354672 2017-01-24] (AO Kaspersky Lab) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1547200 2017-10-13] () S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-09-05] (BlueStack Systems, Inc.) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation) R2 FoxitReaderService; E:\Programme\Foxit Reader\FoxitConnectedPDFService.exe [1659456 2017-08-25] (Foxit Software Inc.) S3 GalaxyClientService; D:\GOG Galaxy\GOG Galaxy\GalaxyClientService.exe [532544 2017-09-28] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8242752 2017-08-25] (GOG.com) S3 klvssbridge64_18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe [426416 2017-09-01] (AO Kaspersky Lab) R2 KSDE2.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe [354672 2017-01-24] (AO Kaspersky Lab) S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation) R3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-09-16] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-10-11] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123104 2017-10-09] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3002720 2017-10-09] (Electronic Arts) R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2017-07-20] () R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [197776 2016-12-14] (Sandboxie Holdings, LLC) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-20] (Microsoft Corporation) R2 TunnelBearMaintenance; C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe [37248 2017-09-06] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 amdgpio2; C:\Windows\System32\drivers\amdgpio2.sys [34704 2016-08-13] (Advanced Micro Devices, Inc) R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [24424 2016-08-13] (Advanced Micro Devices, Inc) S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-16] (Advanced Micro Devices, Inc. ) R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [243048 2017-06-16] (Advanced Micro Devices, Inc. ) S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-06-21] (Bluestack System Inc. ) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [247008 2016-12-26] (AO Kaspersky Lab) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554408 2016-10-01] (AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [70872 2017-10-13] (AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [89952 2017-10-13] (AO Kaspersky Lab) R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29816 2016-10-14] (AO Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [207576 2017-10-13] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\drivers\klhk.sys [594144 2017-10-13] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1055448 2017-10-13] (AO Kaspersky Lab) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [57424 2016-10-12] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [57056 2016-12-23] (AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [58592 2016-12-07] (AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [50672 2017-06-22] (AO Kaspersky Lab) S3 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [44768 2017-01-20] (AO Kaspersky Lab) R3 kltap; C:\Windows\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project) R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [229288 2017-09-01] (AO Kaspersky Lab) R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [87584 2017-10-09] (AO Kaspersky Lab) S3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [251656 2017-09-01] (AO Kaspersky Lab) R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [112912 2017-09-01] (AO Kaspersky Lab) R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [173144 2017-09-01] (AO Kaspersky Lab) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [93920 2016-12-20] (AO Kaspersky Lab) R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [136176 2017-06-22] (AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [199360 2017-06-22] (AO Kaspersky Lab) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_63f40b686fe9309f\nvlddmkm.sys [15619320 2017-09-18] (NVIDIA Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-11] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57792 2017-10-11] (NVIDIA Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [946696 2016-11-21] (Realtek ) R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [52240 2016-10-30] (Razer Inc) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [45752 2017-07-19] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [139704 2017-08-19] (Razer, Inc.) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [205968 2016-12-14] (Sandboxie Holdings, LLC) S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 tap-tb-0901; C:\Windows\System32\drivers\tap-tb-0901.sys [38656 2017-09-06] (The OpenVPN Project) S3 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [196040 2017-09-13] (Oracle Corporation) R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [206976 2017-09-13] (Oracle Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-10-23 22:51 - 2017-10-23 22:51 - 011584088 _____ (SurfRight B.V.) C:\Users\Sam\Downloads\HitmanPro_x64.exe 2017-10-23 22:48 - 2017-10-23 22:48 - 004922400 _____ (AO Kaspersky Lab) C:\Users\Sam\Downloads\tdsskiller.exe 2017-10-23 22:48 - 2017-10-23 22:48 - 004922400 _____ (AO Kaspersky Lab) C:\Users\Sam\Desktop\tdsskiller.exe 2017-10-23 22:48 - 2017-10-23 22:48 - 000286176 _____ C:\Users\Sam\Desktop\TDSSKiller.3.1.0.15_23.10.2017_22.48.33_log.txt 2017-10-23 22:46 - 2017-10-23 22:46 - 000055401 _____ C:\Users\Sam\Desktop\Addition.txt 2017-10-23 22:45 - 2017-10-23 22:52 - 000024317 _____ C:\Users\Sam\Desktop\FRST.txt 2017-10-23 22:45 - 2017-10-23 22:52 - 000000000 ____D C:\FRST 2017-10-23 22:45 - 2017-10-23 22:45 - 002403328 _____ (Farbar) C:\Users\Sam\Downloads\FRST64.exe 2017-10-23 22:45 - 2017-10-23 22:45 - 002403328 _____ (Farbar) C:\Users\Sam\Desktop\FRST64.exe 2017-10-23 22:24 - 2017-10-23 22:25 - 000000000 ____D C:\Users\Sam\AppData\LocalLow\Mozilla 2017-10-23 22:24 - 2017-10-23 22:24 - 000245912 _____ (Mozilla) C:\Users\Sam\Downloads\Firefox Installer.exe 2017-10-23 22:24 - 2017-10-23 22:24 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-10-23 22:24 - 2017-10-23 22:24 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Mozilla 2017-10-23 22:24 - 2017-10-23 22:24 - 000000000 ____D C:\Users\Sam\AppData\Local\Mozilla 2017-10-23 22:24 - 2017-10-23 22:24 - 000000000 ____D C:\Program Files\Mozilla Firefox 2017-10-23 22:24 - 2017-10-23 22:24 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-10-23 22:20 - 2017-10-23 22:20 - 000000000 ___RD C:\Sandbox 2017-10-23 22:19 - 2017-10-23 22:29 - 000002062 _____ C:\Windows\Sandboxie.ini 2017-10-23 22:19 - 2017-10-23 22:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2017-10-23 22:19 - 2017-10-23 22:19 - 000000000 ____D C:\Program Files\Sandboxie 2017-10-23 22:18 - 2017-10-23 22:18 - 008974992 _____ (Sandboxie Holdings, LLC) C:\Users\Sam\Downloads\SandboxieInstall.exe 2017-10-23 22:12 - 2017-10-23 22:12 - 000003628 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-10-23 22:12 - 2017-10-23 22:12 - 000003504 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-10-23 22:12 - 2017-10-23 22:12 - 000002332 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-10-23 22:12 - 2017-10-23 22:12 - 000002320 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-10-23 21:42 - 2017-10-23 21:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-10-23 21:42 - 2017-10-23 21:42 - 000000000 ____D C:\ProgramData\MB2Migration 2017-10-23 21:42 - 2017-10-23 21:42 - 000000000 ____D C:\Program Files\Malwarebytes 2017-10-23 21:42 - 2017-10-04 13:15 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-10-23 21:40 - 2017-10-23 21:42 - 000000000 ____D C:\ProgramData\Malwarebytes 2017-10-23 21:40 - 2017-10-23 21:42 - 000000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2017-10-23 21:33 - 2017-10-23 22:02 - 000000000 ____D C:\AdwCleaner 2017-10-23 21:29 - 2017-10-23 21:29 - 000000000 ____D C:\Users\Sam\AppData\Local\RzStats 2017-10-23 21:22 - 2017-10-23 21:22 - 000002866 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2017-10-23 21:22 - 2017-10-23 21:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-10-23 21:22 - 2017-10-23 21:22 - 000000000 ____D C:\Program Files\CCleaner 2017-10-22 17:43 - 2017-10-22 17:43 - 000000000 ____D C:\Users\Sam\Documents\Thief 2017-10-22 12:45 - 2017-10-22 12:45 - 000000000 ____D C:\Users\Sam\Documents\DyingLight 2017-10-22 12:24 - 2017-10-22 12:24 - 000000000 ____D C:\Windows\LastGood.Tmp 2017-10-22 11:49 - 2017-10-22 11:51 - 000000000 ____D C:\Program Files (x86)\TunnelBear 2017-10-22 11:49 - 2017-10-22 11:49 - 000000000 ____D C:\Users\Sam\AppData\Roaming\TunnelBear 2017-10-22 11:49 - 2017-10-22 11:49 - 000000000 ____D C:\Users\Sam\AppData\Local\IsolatedStorage 2017-10-22 11:49 - 2017-10-22 11:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TunnelBear 2017-10-17 21:29 - 2017-10-17 21:31 - 000000000 ____D C:\Users\Sam\AppData\Roaming\.technic 2017-10-14 15:53 - 2017-10-14 15:54 - 000000000 ____D C:\Users\Sam\Desktop\Spielfelder 2017-10-14 15:44 - 2017-10-14 15:46 - 000000000 ____D C:\Users\Sam\AppData\Roaming\vlc 2017-10-14 15:43 - 2017-10-14 15:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-10-14 15:43 - 2017-10-14 15:43 - 000000000 ____D C:\Program Files (x86)\VideoLAN 2017-10-14 13:47 - 2017-10-14 13:47 - 000000000 ____D C:\Users\Sam\Documents\Banished 2017-10-11 09:01 - 2017-10-11 09:01 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-11 08:58 - 2017-09-30 07:52 - 001595152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll 2017-10-11 08:58 - 2017-09-30 07:51 - 001458320 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-11 08:58 - 2017-09-30 07:51 - 001147288 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2017-10-11 08:58 - 2017-09-30 07:51 - 000661224 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2017-10-11 08:58 - 2017-09-30 07:50 - 001346112 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2017-10-11 08:58 - 2017-09-30 07:50 - 001068208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll 2017-10-11 08:58 - 2017-09-30 07:50 - 001024920 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2017-10-11 08:58 - 2017-09-30 07:49 - 001004136 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-10-11 08:58 - 2017-09-30 07:49 - 000777400 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-10-11 08:58 - 2017-09-30 07:49 - 000135576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-11 08:58 - 2017-09-30 07:48 - 008319384 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-11 08:58 - 2017-09-30 07:48 - 002399728 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-10-11 08:58 - 2017-09-30 07:48 - 002327448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-11 08:58 - 2017-09-30 07:47 - 002969880 _____ (Microsoft Corporation) C:\Windows\system32\CoreUIComponents.dll 2017-10-11 08:58 - 2017-09-30 07:47 - 001194792 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-11 08:58 - 2017-09-30 07:45 - 000511896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2017-10-11 08:58 - 2017-09-30 07:44 - 000712600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2017-10-11 08:58 - 2017-09-30 07:44 - 000181912 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-11 08:58 - 2017-09-30 07:43 - 007318888 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll 2017-10-11 08:58 - 2017-09-30 07:43 - 002442136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-10-11 08:58 - 2017-09-30 07:42 - 004848952 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2017-10-11 08:58 - 2017-09-30 07:42 - 001506712 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll 2017-10-11 08:58 - 2017-09-30 07:42 - 000820120 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe 2017-10-11 08:58 - 2017-09-30 07:41 - 005477600 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll 2017-10-11 08:58 - 2017-09-30 07:41 - 005304496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll 2017-10-11 08:58 - 2017-09-30 07:41 - 000654976 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2017-10-11 08:58 - 2017-09-30 07:41 - 000651672 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2017-10-11 08:58 - 2017-09-30 07:41 - 000259400 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe 2017-10-11 08:58 - 2017-09-30 07:41 - 000257432 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2017-10-11 08:58 - 2017-09-30 07:41 - 000228248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-11 08:58 - 2017-09-30 07:40 - 000724704 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2017-10-11 08:58 - 2017-09-30 07:40 - 000558912 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll 2017-10-11 08:58 - 2017-09-30 07:40 - 000408984 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-11 08:58 - 2017-09-30 07:40 - 000336320 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe 2017-10-11 08:58 - 2017-09-30 07:40 - 000173976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2017-10-11 08:58 - 2017-09-30 07:39 - 021351760 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-10-11 08:58 - 2017-09-30 07:38 - 007910072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2017-10-11 08:58 - 2017-09-30 07:38 - 002239136 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll 2017-10-11 08:58 - 2017-09-30 07:37 - 002377112 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.AppAgent.dll 2017-10-11 08:58 - 2017-09-30 07:37 - 002229144 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll 2017-10-11 08:58 - 2017-09-30 07:36 - 002672024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-10-11 08:58 - 2017-09-30 07:36 - 000057976 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-11 08:58 - 2017-09-30 04:29 - 001408536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll 2017-10-11 08:58 - 2017-09-30 04:29 - 000804784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll 2017-10-11 08:58 - 2017-09-30 04:26 - 001333136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-10-11 08:58 - 2017-09-30 04:26 - 001292872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2017-10-11 08:58 - 2017-09-30 04:10 - 001839872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-10-11 08:58 - 2017-09-30 04:10 - 001150776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-10-11 08:58 - 2017-09-30 04:10 - 000606072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-10-11 08:58 - 2017-09-30 04:10 - 000508344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2017-10-11 08:58 - 2017-09-30 04:10 - 000480920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-10-11 08:58 - 2017-09-30 04:09 - 002259760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll 2017-10-11 08:58 - 2017-09-30 04:09 - 000787712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-10-11 08:58 - 2017-09-30 04:06 - 004471368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2017-10-11 08:58 - 2017-09-30 04:05 - 005827744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll 2017-10-11 08:58 - 2017-09-30 04:05 - 002603744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll 2017-10-11 08:58 - 2017-09-30 04:05 - 001266544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll 2017-10-11 08:58 - 2017-09-30 04:05 - 000750488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe 2017-10-11 08:58 - 2017-09-30 04:05 - 000559000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2017-10-11 08:58 - 2017-09-30 04:04 - 004215184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll 2017-10-11 08:58 - 2017-09-30 04:04 - 000612120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2017-10-11 08:58 - 2017-09-30 04:04 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2017-10-11 08:58 - 2017-09-30 04:04 - 000438096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll 2017-10-11 08:58 - 2017-09-30 04:04 - 000347544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-10-11 08:58 - 2017-09-30 04:04 - 000182680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll 2017-10-11 08:58 - 2017-09-30 04:03 - 020373408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-10-11 08:58 - 2017-09-30 04:03 - 006768288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-10-11 08:58 - 2017-09-30 04:03 - 001439032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll 2017-10-11 08:58 - 2017-09-30 04:02 - 001624096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.AppAgent.dll 2017-10-11 08:58 - 2017-09-30 04:02 - 001517464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll 2017-10-11 08:58 - 2017-09-30 04:02 - 000175512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll 2017-10-11 08:58 - 2017-09-30 04:01 - 000124544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-10-11 08:58 - 2017-09-29 09:46 - 023678976 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll 2017-10-11 08:58 - 2017-09-29 09:45 - 002953216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2017-10-11 08:58 - 2017-09-29 09:44 - 000133120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-10-11 08:58 - 2017-09-29 09:43 - 002199552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-10-11 08:58 - 2017-09-29 09:43 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\smartscreenps.dll 2017-10-11 08:58 - 2017-09-29 09:43 - 000060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll 2017-10-11 08:58 - 2017-09-29 09:42 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mgmtapi.dll 2017-10-11 08:58 - 2017-09-29 09:41 - 013844992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2017-10-11 08:58 - 2017-09-29 09:41 - 000110080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BitLockerCsp.dll 2017-10-11 08:58 - 2017-09-29 09:40 - 006728192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2017-10-11 08:58 - 2017-09-29 09:40 - 000371200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll 2017-10-11 08:58 - 2017-09-29 09:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll 2017-10-11 08:58 - 2017-09-29 09:39 - 020511232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2017-10-11 08:58 - 2017-09-29 09:39 - 011888640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-10-11 08:58 - 2017-09-29 09:39 - 000364032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 005721600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 002671616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 001135616 ____R (The ICU Project) C:\Windows\SysWOW64\icuuc.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 000498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 000471040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TpmCoreProvisioning.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 000370688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptngc.dll 2017-10-11 08:58 - 2017-09-29 09:38 - 000229376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll 2017-10-11 08:58 - 2017-09-29 09:37 - 000306688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll 2017-10-11 08:58 - 2017-09-29 09:37 - 000038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerUI.dll 2017-10-11 08:58 - 2017-09-29 09:36 - 019337216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-10-11 08:58 - 2017-09-29 09:36 - 000590336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll 2017-10-11 08:58 - 2017-09-29 09:35 - 003654656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-10-11 08:58 - 2017-09-29 09:34 - 017370624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2017-10-11 08:58 - 2017-09-29 09:34 - 006255616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2017-10-11 08:58 - 2017-09-29 09:34 - 003669504 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2017-10-11 08:58 - 2017-09-29 09:34 - 002859520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-10-11 08:58 - 2017-09-29 09:34 - 000798720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll 2017-10-11 08:58 - 2017-09-29 09:34 - 000787456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-10-11 08:58 - 2017-09-29 09:34 - 000434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll 2017-10-11 08:58 - 2017-09-29 09:33 - 007598080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2017-10-11 08:58 - 2017-09-29 09:33 - 004559360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll 2017-10-11 08:58 - 2017-09-29 09:33 - 001506816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-10-11 08:58 - 2017-09-29 09:33 - 000658944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 002782720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 002340864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 002199552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 001627136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 001244160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 000209920 _____ (Microsoft Corporation) C:\Windows\system32\smartscreenps.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys 2017-10-11 08:58 - 2017-09-29 09:32 - 000029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-11 08:58 - 2017-09-29 09:32 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\mgmtapi.dll 2017-10-11 08:58 - 2017-09-29 09:31 - 003107328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2017-10-11 08:58 - 2017-09-29 09:31 - 000306176 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2017-10-11 08:58 - 2017-09-29 09:31 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe 2017-10-11 08:58 - 2017-09-29 09:31 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll 2017-10-11 08:58 - 2017-09-29 09:31 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll 2017-10-11 08:58 - 2017-09-29 09:30 - 023686144 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-11 08:58 - 2017-09-29 09:30 - 007931392 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2017-10-11 08:58 - 2017-09-29 09:30 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-10-11 08:58 - 2017-09-29 09:30 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 008333312 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 001460736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 001318912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 000724992 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 000157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll 2017-10-11 08:58 - 2017-09-29 09:29 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000699904 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000681472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000556032 _____ (Microsoft Corporation) C:\Windows\system32\TpmCoreProvisioning.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000473088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000458752 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnr.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000297984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mcbuilder.exe 2017-10-11 08:58 - 2017-09-29 09:28 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll 2017-10-11 08:58 - 2017-09-29 09:28 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2017-10-11 08:58 - 2017-09-29 09:28 - 000040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cipher.exe 2017-10-11 08:58 - 2017-09-29 09:27 - 012803072 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-11 08:58 - 2017-09-29 09:27 - 000616960 _____ (Microsoft Corporation) C:\Windows\system32\WindowManagement.dll 2017-10-11 08:58 - 2017-09-29 09:27 - 000524800 _____ (Microsoft Corporation) C:\Windows\system32\TileDataRepository.dll 2017-10-11 08:58 - 2017-09-29 09:27 - 000412160 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll 2017-10-11 08:58 - 2017-09-29 09:27 - 000409600 _____ (Microsoft Corporation) C:\Windows\system32\cryptngc.dll 2017-10-11 08:58 - 2017-09-29 09:27 - 000350720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 008213504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 002809344 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 001468928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 001269760 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 001197568 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.CommonBridge.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 001141760 _____ (Microsoft Corporation) C:\Windows\system32\ApplySettingsTemplateCatalog.exe 2017-10-11 08:58 - 2017-09-29 09:26 - 000772096 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll 2017-10-11 08:58 - 2017-09-29 09:26 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerUI.dll 2017-10-11 08:58 - 2017-09-29 09:25 - 008199168 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2017-10-11 08:58 - 2017-09-29 09:25 - 004175872 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll 2017-10-11 08:58 - 2017-09-29 09:25 - 002760704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll 2017-10-11 08:58 - 2017-09-29 09:25 - 000586240 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 003377664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 003307008 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 002503680 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 001886208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 001628672 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll 2017-10-11 08:58 - 2017-09-29 09:24 - 001201664 _____ (Microsoft Corporation) C:\Windows\system32\AgentService.exe 2017-10-11 08:58 - 2017-09-29 09:24 - 000684032 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 005557760 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 004730368 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 003140096 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 002730496 _____ (Microsoft Corporation) C:\Windows\system32\smartscreen.exe 2017-10-11 08:58 - 2017-09-29 09:23 - 002446336 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 002195968 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.ModernAppAgent.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 002055680 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2017-10-11 08:58 - 2017-09-29 09:23 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 001605632 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 001460224 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 001398784 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 001052672 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 000986624 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 000972288 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 000756224 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-11 08:58 - 2017-09-29 09:23 - 000647168 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll 2017-10-11 08:58 - 2017-09-29 09:22 - 002829824 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-10-11 08:58 - 2017-09-29 09:22 - 001802240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-11 08:58 - 2017-09-29 09:22 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll 2017-10-11 08:58 - 2017-09-29 09:21 - 003304448 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2017-10-11 08:58 - 2017-09-29 09:21 - 000722944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-11 08:58 - 2017-09-29 09:21 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll 2017-10-11 08:58 - 2017-09-29 09:21 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-11 08:58 - 2017-09-29 09:21 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe 2017-10-11 08:58 - 2017-09-29 09:21 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\InputLocaleManager.dll 2017-10-11 08:58 - 2017-09-29 09:20 - 000804864 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll 2017-10-11 08:58 - 2017-09-29 09:20 - 000385536 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll 2017-10-11 08:58 - 2017-09-29 09:20 - 000286208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-11 08:58 - 2017-09-29 09:20 - 000194560 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-11 08:58 - 2017-09-29 09:19 - 000325120 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll 2017-10-11 08:58 - 2017-09-29 09:19 - 000306176 _____ (Microsoft Corporation) C:\Windows\system32\fveui.dll 2017-10-11 08:58 - 2017-09-29 09:19 - 000208896 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2017-10-11 08:58 - 2017-09-29 09:18 - 000364032 _____ (Microsoft Corporation) C:\Windows\system32\bdechangepin.exe 2017-10-11 08:58 - 2017-09-29 09:18 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe 2017-10-11 08:58 - 2017-09-29 09:18 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerDeviceEncryption.exe 2017-10-11 08:58 - 2017-09-29 07:40 - 000804312 _____ C:\Windows\SysWOW64\locale.nls 2017-10-11 08:58 - 2017-09-29 07:40 - 000804312 _____ C:\Windows\system32\locale.nls 2017-10-11 08:58 - 2017-09-20 17:08 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll 2017-10-11 08:58 - 2017-09-20 17:08 - 000345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-10-11 08:58 - 2017-09-20 17:08 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll 2017-10-11 08:58 - 2017-09-19 01:20 - 001065104 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-10-11 08:58 - 2017-09-19 01:20 - 000900376 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2017-10-11 08:58 - 2017-09-19 01:18 - 000965024 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi 2017-10-11 08:58 - 2017-09-19 01:17 - 001395664 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-10-11 08:58 - 2017-09-19 01:17 - 001186464 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2017-10-11 08:58 - 2017-09-19 01:17 - 000821664 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe 2017-10-11 08:58 - 2017-09-19 01:11 - 001018272 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi 2017-10-11 08:58 - 2017-09-19 01:09 - 000554400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2017-10-11 08:58 - 2017-09-19 00:25 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\eShims.dll 2017-10-11 08:58 - 2017-09-19 00:20 - 000831488 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll 2017-10-11 08:58 - 2017-09-19 00:20 - 000049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tetheringclient.dll 2017-10-11 08:58 - 2017-09-19 00:15 - 000648704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll 2017-10-11 08:57 - 2017-09-30 07:48 - 000644696 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-11 08:57 - 2017-09-30 07:41 - 002086808 _____ (Microsoft Corporation) C:\Windows\system32\UpdateAgent.dll 2017-10-11 08:57 - 2017-09-30 07:41 - 000961944 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll 2017-10-11 08:57 - 2017-09-30 07:40 - 000849816 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe 2017-10-11 08:57 - 2017-09-30 07:40 - 000701336 _____ (Microsoft Corporation) C:\Windows\system32\AppVCatalog.dll 2017-10-11 08:57 - 2017-09-30 07:40 - 000642680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2017-10-11 08:57 - 2017-09-30 07:40 - 000184728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-11 08:57 - 2017-09-30 07:40 - 000072944 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe 2017-10-11 08:57 - 2017-09-30 07:39 - 001694104 _____ (Microsoft Corporation) C:\Windows\system32\AppVIntegration.dll 2017-10-11 08:57 - 2017-09-30 07:39 - 000203672 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll 2017-10-11 08:57 - 2017-09-30 07:38 - 001854872 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntVirtualization.dll 2017-10-11 08:57 - 2017-09-30 07:37 - 001464728 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll 2017-10-11 08:57 - 2017-09-30 07:36 - 000855960 _____ (Microsoft Corporation) C:\Windows\system32\AppVOrchestration.dll 2017-10-11 08:57 - 2017-09-30 07:36 - 000675224 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll 2017-10-11 08:57 - 2017-09-29 09:33 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-11 08:57 - 2017-09-29 09:32 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll 2017-10-11 08:57 - 2017-09-29 09:31 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\efssvc.dll 2017-10-11 08:57 - 2017-09-29 09:30 - 000529408 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll 2017-10-11 08:57 - 2017-09-29 09:30 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerCsp.dll 2017-10-11 08:57 - 2017-09-29 09:29 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-11 08:57 - 2017-09-29 09:29 - 000461824 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-11 08:57 - 2017-09-29 09:29 - 000304640 _____ (Microsoft Corporation) C:\Windows\system32\dusmsvc.dll 2017-10-11 08:57 - 2017-09-29 09:29 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\ServiceWorkerHost.exe 2017-10-11 08:57 - 2017-09-29 09:28 - 000527360 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll 2017-10-11 08:57 - 2017-09-29 09:28 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll 2017-10-11 08:57 - 2017-09-29 09:27 - 001321984 ____R (The ICU Project) C:\Windows\system32\icuuc.dll 2017-10-11 08:57 - 2017-09-29 09:27 - 000565760 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2017-10-11 08:57 - 2017-09-29 09:27 - 000538624 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2017-10-11 08:57 - 2017-09-29 09:26 - 000356864 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll 2017-10-11 08:57 - 2017-09-29 09:23 - 000841216 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2017-10-11 08:57 - 2017-09-29 09:23 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll 2017-10-11 08:57 - 2017-09-29 09:22 - 001438208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Phone.dll 2017-10-11 08:57 - 2017-09-29 09:21 - 000154624 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll 2017-10-11 08:57 - 2017-09-29 09:21 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll 2017-10-11 08:57 - 2017-09-29 09:20 - 001811456 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll 2017-10-11 08:57 - 2017-09-29 09:20 - 000150016 _____ (Microsoft Corporation) C:\Windows\system32\iscsiexe.dll 2017-10-11 08:57 - 2017-09-29 09:19 - 002088448 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll 2017-10-11 08:57 - 2017-09-29 09:18 - 002438656 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll 2017-10-11 08:57 - 2017-09-29 09:18 - 001527296 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe 2017-10-11 08:57 - 2017-09-29 09:18 - 000893440 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll 2017-10-11 08:57 - 2017-09-29 09:18 - 000603136 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll 2017-10-11 08:57 - 2017-09-29 09:18 - 000347648 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe 2017-10-11 08:57 - 2017-09-29 09:18 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2017-10-11 08:57 - 2017-09-29 09:18 - 000046592 _____ (Microsoft Corporation) C:\Windows\system32\cipher.exe 2017-10-11 08:57 - 2017-09-19 00:26 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\tetheringclient.dll 2017-10-11 08:57 - 2017-09-19 00:23 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll 2017-10-09 15:08 - 2017-10-09 17:44 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Apple Computer 2017-10-09 15:08 - 2017-10-09 15:08 - 000000000 ____D C:\Users\Sam\AppData\Local\Apple Computer 2017-10-09 14:40 - 2017-10-09 14:40 - 000087584 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_kimul.sys 2017-10-09 14:29 - 2017-10-09 14:29 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\Windows\System32\Tasks\Apple 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\Users\Sam\AppData\Local\Apple 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\ProgramData\Apple Computer 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\ProgramData\Apple 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\Program Files\iTunes 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\Program Files\iPod 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\Program Files\Common Files\Apple 2017-10-09 14:29 - 2017-10-09 14:29 - 000000000 ____D C:\Program Files (x86)\Apple Software Update 2017-10-08 20:13 - 2017-10-08 20:13 - 000000000 ____D C:\Python27 2017-10-08 20:13 - 2017-10-08 20:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7 2017-10-08 20:12 - 2017-10-08 20:12 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.6 2017-10-08 20:12 - 2017-10-08 20:12 - 000000000 ____D C:\Users\Sam\AppData\Local\Package Cache 2017-10-08 12:40 - 2017-10-08 12:40 - 000000000 ____D C:\Program Files (x86)\VulkanRT 2017-10-08 12:40 - 2017-09-16 19:17 - 000135800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-10-08 12:38 - 2017-09-16 21:27 - 040240064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 035925440 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 035314112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 029020096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 023132720 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 018849784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 013782904 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 012241792 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 011692856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 010087504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 004145088 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 003575744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001988216 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438569.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001606592 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438569.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001291912 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001290024 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFThevc.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001067968 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001008816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001007280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFThevc.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 001005176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000972920 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000924280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000781728 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000725112 _____ (NVIDIA Corporation) C:\Windows\system32\nvDecMFTMjpeg.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000690504 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000618928 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000617232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000584128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvDecMFTMjpeg.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000578056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-10-08 12:38 - 2017-09-16 21:27 - 000499136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-10-08 12:34 - 2017-10-22 12:24 - 000004308 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-08 12:34 - 2017-10-22 12:24 - 000004000 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-08 12:34 - 2017-10-22 12:24 - 000003940 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-08 12:34 - 2017-10-11 03:05 - 001796032 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 001577920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 000918976 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 000186304 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 000152512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 000057792 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys 2017-10-08 12:34 - 2017-10-11 03:05 - 000050624 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2017-10-08 12:34 - 2017-09-19 09:20 - 001755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2017-10-08 12:34 - 2017-09-19 09:20 - 001317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2017-10-08 12:34 - 2017-09-18 08:55 - 000001951 _____ C:\Windows\NvContainerRecovery.bat 2017-10-06 16:31 - 2017-10-06 16:31 - 000000000 ____D C:\Users\Sam\AppData\Local\FortniteGame 2017-10-06 16:19 - 2017-10-06 16:19 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer 2017-10-06 16:19 - 2017-10-06 16:19 - 000000000 ____D C:\Program Files\Reference Assemblies 2017-10-06 16:19 - 2017-10-06 16:19 - 000000000 ____D C:\Program Files\MSBuild 2017-10-06 16:19 - 2017-10-06 16:19 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-10-06 16:19 - 2017-10-06 16:19 - 000000000 ____D C:\Program Files (x86)\MSBuild 2017-10-06 16:18 - 2017-02-10 11:26 - 001166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2017-10-06 16:18 - 2017-02-10 11:26 - 000124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2017-10-06 16:18 - 2017-02-10 11:26 - 000035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2017-10-06 16:18 - 2017-02-10 11:21 - 000778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll 2017-10-06 16:18 - 2017-02-10 11:21 - 000103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-10-06 16:18 - 2017-02-10 11:21 - 000035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2017-10-06 16:17 - 2017-10-06 16:18 - 000000000 ____D C:\ProgramData\Epic 2017-10-06 16:17 - 2017-10-06 16:17 - 000000909 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk 2017-10-06 16:17 - 2017-10-06 16:17 - 000000000 ____D C:\Users\Sam\AppData\Local\UnrealEngineLauncher 2017-10-06 16:17 - 2017-10-06 16:17 - 000000000 ____D C:\Users\Sam\AppData\Local\EpicGamesLauncher 2017-10-04 19:42 - 2017-10-04 19:42 - 000000000 ____D C:\Users\Sam\AppData\Local\PackageStaging 2017-10-03 17:27 - 2017-10-03 17:27 - 000890008 _____ (Python Software Foundation) C:\Windows\pyw.exe 2017-10-03 17:27 - 2017-10-03 17:27 - 000889496 _____ (Python Software Foundation) C:\Windows\py.exe 2017-10-02 17:34 - 2017-10-02 17:34 - 000000000 ____D C:\Users\Sam\AppData\Local\Notepad++ 2017-10-02 17:32 - 2017-10-02 17:34 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Notepad++ 2017-10-02 17:32 - 2017-10-02 17:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2017-10-02 17:32 - 2017-10-02 17:32 - 000000000 ____D C:\Program Files\Notepad++ 2017-10-01 13:29 - 2017-10-01 13:29 - 000000000 ____D C:\Users\Sam\Documents\NBGI 2017-10-01 13:29 - 2017-10-01 13:29 - 000000000 ____D C:\Users\Sam\AppData\Local\NBGI 2017-10-01 09:31 - 2017-10-01 09:31 - 000000000 ____D C:\Users\Sam\AppData\LocalLow\Spiderling Games 2017-09-30 15:20 - 2017-09-30 16:21 - 000000600 _____ C:\Users\Sam\AppData\Local\PUTTY.RND 2017-09-30 14:46 - 2017-09-30 14:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PuTTY (64-bit) 2017-09-30 14:46 - 2017-09-30 14:46 - 000000000 ____D C:\Program Files\PuTTY 2017-09-29 20:34 - 2017-09-29 20:34 - 000000000 ____D C:\Users\Sam\AppData\Roaming\WinRAR 2017-09-29 20:33 - 2017-09-29 20:33 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-09-29 20:33 - 2017-09-29 20:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-09-29 20:33 - 2017-09-29 20:33 - 000000000 ____D C:\Program Files\WinRAR 2017-09-29 12:45 - 2017-09-29 12:45 - 000000000 ____D C:\Users\Sam\AppData\LocalLow\Unity 2017-09-29 12:44 - 2017-09-29 12:44 - 000000000 ____D C:\Users\Sam\AppData\LocalLow\SKS 2017-09-28 16:59 - 2017-09-28 16:59 - 000000000 ____D C:\Users\Sam\Documents\ANNO 2070 2017-09-28 16:58 - 2017-09-28 16:58 - 000000000 ____D C:\ProgramData\Solidshield 2017-09-28 16:40 - 2017-09-28 16:40 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Ubisoft 2017-09-26 20:41 - 2017-10-04 19:42 - 000150528 ___SH C:\Users\Sam\Downloads\Thumbs.db 2017-09-26 20:38 - 2017-10-08 20:01 - 000036352 ___SH C:\Users\Sam\Desktop\Thumbs.db 2017-09-23 16:05 - 2017-09-05 07:12 - 000627080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe 2017-09-23 16:05 - 2017-09-05 06:45 - 002476712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2017-09-23 16:05 - 2017-09-05 06:23 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll 2017-09-23 16:05 - 2017-09-05 06:16 - 005961728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll 2017-09-23 16:05 - 2017-09-05 06:15 - 000657408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll 2017-09-23 16:05 - 2017-09-05 06:12 - 005225984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2017-09-23 16:05 - 2017-09-05 06:11 - 003667456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-09-23 16:05 - 2017-09-05 06:11 - 001355264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll 2017-09-23 16:05 - 2017-09-05 06:11 - 001060352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2017-09-23 16:05 - 2017-09-05 06:11 - 001019904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2017-09-23 16:05 - 2017-09-05 06:06 - 000089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll 2017-09-23 16:04 - 2017-09-05 07:31 - 000750560 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe 2017-09-23 16:04 - 2017-09-05 07:31 - 000115792 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll 2017-09-23 16:04 - 2017-09-05 07:30 - 000287648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2017-09-23 16:04 - 2017-09-05 07:26 - 001930840 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-09-23 16:04 - 2017-09-05 07:25 - 000159648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2017-09-23 16:04 - 2017-09-05 07:24 - 000923040 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll 2017-09-23 16:04 - 2017-09-05 07:24 - 000519584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2017-09-23 16:04 - 2017-09-05 07:23 - 004462120 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll 2017-09-23 16:04 - 2017-09-05 07:23 - 001242528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2017-09-23 16:04 - 2017-09-05 07:21 - 000189344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2017-09-23 16:04 - 2017-09-05 07:20 - 001057824 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2017-09-23 16:04 - 2017-09-05 07:18 - 002972552 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2017-09-23 16:04 - 2017-09-05 07:18 - 002647224 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-09-23 16:04 - 2017-09-05 07:18 - 001668344 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2017-09-23 16:04 - 2017-09-05 07:18 - 000685512 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2017-09-23 16:04 - 2017-09-05 07:18 - 000212384 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll 2017-09-23 16:04 - 2017-09-05 07:17 - 000316320 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2017-09-23 16:04 - 2017-09-05 07:16 - 001320344 _____ (Microsoft Corporation) C:\Windows\system32\wpx.dll 2017-09-23 16:04 - 2017-09-05 07:16 - 000872472 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll 2017-09-23 16:04 - 2017-09-05 07:16 - 000715168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2017-09-23 16:04 - 2017-09-05 07:16 - 000546208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2017-09-23 16:04 - 2017-09-05 07:16 - 000410168 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll 2017-09-23 16:04 - 2017-09-05 07:16 - 000182688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe 2017-09-23 16:04 - 2017-09-05 07:16 - 000049720 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll 2017-09-23 16:04 - 2017-09-05 07:15 - 003116184 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2017-09-23 16:04 - 2017-09-05 07:15 - 000871448 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2017-09-23 16:04 - 2017-09-05 07:15 - 000381824 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2017-09-23 16:04 - 2017-09-05 07:14 - 004708504 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2017-09-23 16:04 - 2017-09-05 07:14 - 001146176 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2017-09-23 16:04 - 2017-09-05 07:14 - 000958664 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll 2017-09-23 16:04 - 2017-09-05 07:14 - 000254176 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-09-23 16:04 - 2017-09-05 07:14 - 000094624 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2017-09-23 16:04 - 2017-09-05 07:13 - 001619816 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2017-09-23 16:04 - 2017-09-05 07:13 - 000078240 _____ (Microsoft Corporation) C:\Windows\system32\SyncAppvPublishingServer.exe 2017-09-23 16:04 - 2017-09-05 07:13 - 000064680 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-09-23 16:04 - 2017-09-05 07:12 - 000844704 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntStreamingManager.dll 2017-09-23 16:04 - 2017-09-05 07:12 - 000774560 _____ (Microsoft Corporation) C:\Windows\system32\AppVReporting.dll 2017-09-23 16:04 - 2017-09-05 07:12 - 000406944 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll 2017-09-23 16:04 - 2017-09-05 07:12 - 000235424 _____ (Microsoft Corporation) C:\Windows\system32\AppVShNotify.exe 2017-09-23 16:04 - 2017-09-05 07:12 - 000203680 _____ (Microsoft Corporation) C:\Windows\system32\AppVStreamingUX.dll 2017-09-23 16:04 - 2017-09-05 07:12 - 000081176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll 2017-09-23 16:04 - 2017-09-05 07:11 - 000610720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2017-09-23 16:04 - 2017-09-05 07:11 - 000387936 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll 2017-09-23 16:04 - 2017-09-05 06:53 - 001620880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-09-23 16:04 - 2017-09-05 06:50 - 004330920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll 2017-09-23 16:04 - 2017-09-05 06:45 - 002166808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-09-23 16:04 - 2017-09-05 06:45 - 000085784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialUIBroker.exe 2017-09-23 16:04 - 2017-09-05 06:44 - 000569264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2017-09-23 16:04 - 2017-09-05 06:43 - 000359560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll 2017-09-23 16:04 - 2017-09-05 06:43 - 000280480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe 2017-09-23 16:04 - 2017-09-05 06:43 - 000169376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe 2017-09-23 16:04 - 2017-09-05 06:43 - 000042456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll 2017-09-23 16:04 - 2017-09-05 06:42 - 002330520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2017-09-23 16:04 - 2017-09-05 06:42 - 000703056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2017-09-23 16:04 - 2017-09-05 06:42 - 000291904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtapi.dll 2017-09-23 16:04 - 2017-09-05 06:41 - 004671832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2017-09-23 16:04 - 2017-09-05 06:41 - 001106904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2017-09-23 16:04 - 2017-09-05 06:41 - 001013912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll 2017-09-23 16:04 - 2017-09-05 06:40 - 000052768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-09-23 16:04 - 2017-09-05 06:37 - 000583160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 001639936 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 001275904 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 000584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 000463360 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 000447488 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-09-23 16:04 - 2017-09-05 06:30 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE 2017-09-23 16:04 - 2017-09-05 06:30 - 000093184 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\winsrvext.dll 2017-09-23 16:04 - 2017-09-05 06:30 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe 2017-09-23 16:04 - 2017-09-05 06:29 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\SEMgrPS.dll 2017-09-23 16:04 - 2017-09-05 06:28 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys 2017-09-23 16:04 - 2017-09-05 06:28 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\buttonconverter.sys 2017-09-23 16:04 - 2017-09-05 06:27 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\CfgSPCellular.dll 2017-09-23 16:04 - 2017-09-05 06:27 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAPNCsp.dll 2017-09-23 16:04 - 2017-09-05 06:27 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UcmCx.sys 2017-09-23 16:04 - 2017-09-05 06:27 - 000095232 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-09-23 16:04 - 2017-09-05 06:27 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\datamarketsvc.dll 2017-09-23 16:04 - 2017-09-05 06:27 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll 2017-09-23 16:04 - 2017-09-05 06:26 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe 2017-09-23 16:04 - 2017-09-05 06:26 - 000404480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll 2017-09-23 16:04 - 2017-09-05 06:26 - 000156160 _____ (Microsoft Corporation) C:\Windows\system32\csplte.dll 2017-09-23 16:04 - 2017-09-05 06:26 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll 2017-09-23 16:04 - 2017-09-05 06:26 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll 2017-09-23 16:04 - 2017-09-05 06:26 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys 2017-09-23 16:04 - 2017-09-05 06:26 - 000084992 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-09-23 16:04 - 2017-09-05 06:26 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2017-09-23 16:04 - 2017-09-05 06:26 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2017-09-23 16:04 - 2017-09-05 06:25 - 001448960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2017-09-23 16:04 - 2017-09-05 06:25 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll 2017-09-23 16:04 - 2017-09-05 06:25 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys 2017-09-23 16:04 - 2017-09-05 06:25 - 000154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE 2017-09-23 16:04 - 2017-09-05 06:25 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys 2017-09-23 16:04 - 2017-09-05 06:24 - 000457728 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000385536 _____ (Microsoft Corporation) C:\Windows\system32\tpmvsc.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000353280 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000334336 _____ (Microsoft Corporation) C:\Windows\system32\wc_storage.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000274432 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\ngcrecovery.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\dinput.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000109056 _____ (Microsoft Corporation) C:\Windows\system32\dab.dll 2017-09-23 16:04 - 2017-09-05 06:24 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-09-23 16:04 - 2017-09-05 06:23 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\PhoneProviders.dll 2017-09-23 16:04 - 2017-09-05 06:23 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe 2017-09-23 16:04 - 2017-09-05 06:23 - 000305152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2017-09-23 16:04 - 2017-09-05 06:23 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2017-09-23 16:04 - 2017-09-05 06:23 - 000138752 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2017-09-23 16:04 - 2017-09-05 06:23 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\rasman.dll 2017-09-23 16:04 - 2017-09-05 06:23 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\ngcpopkeysrv.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000742912 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000640512 _____ (Microsoft Corporation) C:\Windows\system32\ngccredprov.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000477696 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000413184 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000388096 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000329728 _____ (Microsoft Corporation) C:\Windows\system32\RasMediaManager.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-09-23 16:04 - 2017-09-05 06:22 - 000213504 _____ (Microsoft Corporation) C:\Windows\system32\dinput8.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000173568 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000165888 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2017-09-23 16:04 - 2017-09-05 06:22 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 001178624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 001051136 _____ (Microsoft Corporation) C:\Windows\system32\nettrace.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000946688 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000773120 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000691712 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000422400 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\Phoneutil.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srpapi.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-09-23 16:04 - 2017-09-05 06:21 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2017-09-23 16:04 - 2017-09-05 06:20 - 007337472 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll 2017-09-23 16:04 - 2017-09-05 06:20 - 001878016 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll 2017-09-23 16:04 - 2017-09-05 06:20 - 000925696 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll 2017-09-23 16:04 - 2017-09-05 06:20 - 000805888 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll 2017-09-23 16:04 - 2017-09-05 06:20 - 000546816 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv 2017-09-23 16:04 - 2017-09-05 06:20 - 000412160 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll 2017-09-23 16:04 - 2017-09-05 06:20 - 000282112 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2017-09-23 16:04 - 2017-09-05 06:20 - 000229888 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe 2017-09-23 16:04 - 2017-09-05 06:19 - 001260544 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe 2017-09-23 16:04 - 2017-09-05 06:19 - 001085440 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 001028608 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000996864 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000772096 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000181760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dinput.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2017-09-23 16:04 - 2017-09-05 06:19 - 000080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 002078720 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-09-23 16:04 - 2017-09-05 06:18 - 000922112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000921600 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000874496 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000864256 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000832000 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe 2017-09-23 16:04 - 2017-09-05 06:18 - 000803328 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000752640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000564736 _____ (Microsoft Corporation) C:\Windows\system32\dsreg.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ngccredprov.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnrSvc.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasplap.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000266240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dinput8.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000100352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasman.dll 2017-09-23 16:04 - 2017-09-05 06:18 - 000056832 _____ (Microsoft Corporation) C:\Windows\system32\cldapi.dll 2017-09-23 16:04 - 2017-09-05 06:17 - 000918528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll 2017-09-23 16:04 - 2017-09-05 06:17 - 000852480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasgcw.dll 2017-09-23 16:04 - 2017-09-05 06:17 - 000757760 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2017-09-23 16:04 - 2017-09-05 06:17 - 000586240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 002680320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000844288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000563200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000440320 _____ (Microsoft Corporation) C:\Windows\system32\windows.immersiveshell.serviceprovider.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000397312 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll 2017-09-23 16:04 - 2017-09-05 06:16 - 000257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Phoneutil.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 004396032 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 003059200 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 001736704 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 001293824 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 001248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 001077248 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 000706560 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2017-09-23 16:04 - 2017-09-05 06:15 - 000664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 000636416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 000430592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv 2017-09-23 16:04 - 2017-09-05 06:15 - 000232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-09-23 16:04 - 2017-09-05 06:15 - 000223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 002516480 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 002177024 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 002006528 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 001657344 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 001583616 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 001046016 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 000810496 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 000754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-09-23 16:04 - 2017-09-05 06:14 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll 2017-09-23 16:04 - 2017-09-05 06:13 - 002009600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-09-23 16:04 - 2017-09-05 06:13 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cldapi.dll 2017-09-23 16:04 - 2017-09-05 06:12 - 002153984 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll 2017-09-23 16:04 - 2017-09-05 06:12 - 000899584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll 2017-09-23 16:04 - 2017-09-05 06:11 - 001463296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-09-23 16:04 - 2017-09-05 06:11 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-09-23 16:04 - 2017-09-05 06:10 - 000761344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll 2017-09-23 16:04 - 2017-09-05 06:10 - 000431616 _____ (Microsoft Corporation) C:\Windows\system32\BthHFSrv.dll 2017-09-23 16:04 - 2017-09-05 06:09 - 000268288 _____ (Microsoft Corporation) C:\Windows\system32\wisp.dll 2017-09-23 16:04 - 2017-09-05 06:07 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\RstrtMgr.dll 2017-09-23 16:04 - 2017-09-05 06:07 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll 2017-09-23 16:04 - 2017-09-05 06:06 - 000221696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wisp.dll 2017-09-23 16:04 - 2017-09-05 06:06 - 000078848 _____ (Microsoft Corporation) C:\Windows\system32\offreg.dll 2017-09-23 16:04 - 2017-09-05 06:04 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RstrtMgr.dll 2017-09-23 16:04 - 2017-09-05 06:04 - 000057856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offreg.dll 2017-09-23 16:04 - 2017-09-01 07:55 - 000031932 _____ C:\Windows\system32\edgehtmlpluginpolicy.bin ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-10-23 22:48 - 2017-09-01 19:58 - 000000000 ____D C:\Users\Sam\Desktop\Programme und Verknüpfungen 2017-10-23 22:39 - 2017-08-28 23:59 - 000000000 ____D C:\Users\Sam 2017-10-23 22:32 - 2017-09-20 17:20 - 000000000 ____D C:\Users\Sam\.VirtualBox 2017-10-23 22:31 - 2017-09-01 19:40 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2017-10-23 22:12 - 2017-09-01 19:31 - 000000000 ____D C:\Users\Sam\AppData\Local\Google 2017-10-23 22:12 - 2017-09-01 19:30 - 000000000 ____D C:\Program Files (x86)\Google 2017-10-23 22:10 - 2017-09-01 21:21 - 000000000 ____D C:\Users\Sam\AppData\Local\CrashDumps 2017-10-23 22:10 - 2017-08-29 00:15 - 002749414 _____ C:\Windows\system32\PerfStringBackup.INI 2017-10-23 22:10 - 2017-03-20 06:41 - 001285176 _____ C:\Windows\system32\perfh007.dat 2017-10-23 22:10 - 2017-03-20 06:41 - 000301276 _____ C:\Windows\system32\perfc007.dat 2017-10-23 22:05 - 2017-09-01 19:37 - 000000000 ____D C:\ProgramData\NVIDIA 2017-10-23 22:04 - 2017-08-28 23:56 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-10-23 22:03 - 2017-03-18 13:40 - 000524288 _____ C:\Windows\system32\config\BBI 2017-10-23 21:23 - 2017-09-20 17:22 - 000000000 ____D C:\Users\Sam\AppData\Roaming\uTorrent 2017-10-23 21:23 - 2017-09-19 18:09 - 000000000 ____D C:\Windows\Minidump 2017-10-23 21:23 - 2017-08-29 00:56 - 000000000 ____D C:\Windows\Panther 2017-10-23 21:23 - 2017-03-18 23:01 - 000000000 ____D C:\Windows\INF 2017-10-23 21:18 - 2017-09-19 18:11 - 000000000 ____D C:\Users\Sam\AppData\Local\MicrosoftEdge 2017-10-23 19:38 - 2017-08-28 23:56 - 000000000 ____D C:\Windows\system32\SleepStudy 2017-10-23 16:49 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps 2017-10-23 16:49 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\AppReadiness 2017-10-23 16:42 - 2017-09-01 19:37 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-10-22 14:28 - 2017-09-01 20:25 - 000000000 ____D C:\Users\Sam\Desktop\Spiele 2017-10-22 12:30 - 2017-09-01 19:37 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2017-10-22 12:25 - 2017-09-01 19:38 - 000000000 ____D C:\Users\Sam\AppData\Local\NVIDIA Corporation 2017-10-22 12:24 - 2017-09-01 19:38 - 000003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-22 12:24 - 2017-09-01 19:38 - 000003866 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-22 12:24 - 2017-09-01 19:38 - 000003858 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-22 12:24 - 2017-09-01 19:38 - 000003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-22 12:24 - 2017-09-01 19:38 - 000003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-10-22 12:24 - 2017-09-01 19:35 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2017-10-22 11:49 - 2017-09-01 19:20 - 000000000 ____D C:\ProgramData\Package Cache 2017-10-22 11:38 - 2017-09-01 20:31 - 000000000 ____D C:\Users\Sam\AppData\Roaming\Origin 2017-10-22 11:35 - 2017-09-01 21:43 - 000000700 _____ C:\Users\Public\Desktop\Battlefield 1.lnk 2017-10-22 11:29 - 2017-09-01 21:28 - 000000000 ____D C:\ProgramData\Oracle 2017-10-22 11:29 - 2017-09-01 20:25 - 000000000 ____D C:\ProgramData\Origin 2017-10-22 11:28 - 2017-09-20 16:11 - 000110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2017-10-22 11:28 - 2017-09-20 16:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit 2017-10-22 11:28 - 2017-09-20 16:11 - 000000000 ____D C:\Program Files\Java 2017-10-22 11:28 - 2017-09-19 16:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-10-22 11:20 - 2017-09-01 21:28 - 000000000 ____D C:\Users\Sam\AppData\Local\ftblauncher 2017-10-20 13:14 - 2017-09-01 20:58 - 000000000 ____D C:\Program Files\Microsoft Office 15 2017-10-20 13:14 - 2017-03-18 23:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-10-19 18:53 - 2017-09-01 20:30 - 000000000 ____D C:\Program Files (x86)\Origin 2017-10-17 21:32 - 2017-03-18 22:51 - 000000000 ____D C:\Windows\CbsTemp 2017-10-17 21:29 - 2017-09-01 20:47 - 000000000 ____D C:\Users\Sam\Desktop\Minecraft 2017-10-14 13:57 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\rescache 2017-10-14 13:41 - 2017-09-01 20:19 - 000000000 ____D C:\Users\Sam\AppData\Local\Ubisoft Game Launcher 2017-10-13 18:00 - 2017-09-01 19:40 - 001055448 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2017-10-13 18:00 - 2017-09-01 19:40 - 000207576 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2017-10-13 17:59 - 2017-09-01 19:40 - 000594144 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys 2017-10-13 17:59 - 2017-09-01 19:40 - 000149304 _____ (AO Kaspersky Lab) C:\Windows\system32\klhkum.dll 2017-10-13 17:59 - 2016-12-27 07:53 - 000089952 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klbackupflt.sys 2017-10-13 17:59 - 2016-12-22 07:13 - 000070872 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klbackupdisk.sys 2017-10-13 02:21 - 2017-03-18 23:06 - 000835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-10-13 02:21 - 2017-03-18 23:06 - 000177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-12 17:23 - 2017-08-28 23:59 - 000000000 __RHD C:\Users\Public\AccountPictures 2017-10-11 11:51 - 2017-03-18 23:03 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll 2017-10-11 11:51 - 2017-03-18 23:03 - 000207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll 2017-10-11 11:51 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\ShellExperiences 2017-10-11 11:51 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\Provisioning 2017-10-11 11:51 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\PolicyDefinitions 2017-10-11 09:03 - 2017-09-03 13:59 - 000000000 ____D C:\Windows\system32\MRT 2017-10-11 09:01 - 2017-09-03 13:59 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-11 01:26 - 2017-09-01 19:37 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2017-10-08 20:32 - 2017-09-19 19:14 - 000000000 ____D C:\ProgramData\BlueStacksSetup 2017-10-08 20:25 - 2017-09-19 16:35 - 000000000 ____D C:\Windows\hsperfdata_Sam 2017-10-08 20:25 - 2017-09-19 16:34 - 000000000 ____D C:\Users\Sam\Knuddels-Stapp 2017-10-08 12:40 - 2017-09-01 19:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-10-08 12:35 - 2017-09-01 19:38 - 000000000 ____D C:\Users\Sam\AppData\Local\NVIDIA 2017-10-06 16:31 - 2017-09-02 15:25 - 000000000 ____D C:\Users\Sam\AppData\Local\UnrealEngine 2017-10-06 16:19 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\SysWOW64\MUI 2017-10-06 16:19 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\MUI 2017-10-06 16:17 - 2017-09-01 20:48 - 000000000 ____D C:\Users\Sam\Desktop\Plattformen 2017-10-04 19:49 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\NDF 2017-10-04 19:42 - 2017-08-28 23:59 - 000000000 ____D C:\Users\Sam\AppData\Local\Packages 2017-10-03 13:13 - 2017-09-01 21:25 - 000000000 ____D C:\Users\Sam\Documents\My Games 2017-09-28 20:23 - 2017-09-01 20:49 - 000000000 ____D C:\Users\Sam\Documents\The Witcher 3 2017-09-26 18:53 - 2017-08-29 00:00 - 000000000 ___RD C:\Users\Sam\OneDrive 2017-09-26 17:29 - 2017-09-01 19:18 - 000003368 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-773800576-1985737239-35243653-1001 2017-09-26 17:29 - 2017-08-29 00:00 - 000002418 _____ C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-09-25 17:40 - 2017-03-20 06:41 - 000000000 ____D C:\Windows\system32\de 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ___SD C:\Windows\SysWOW64\F12 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ___SD C:\Windows\system32\F12 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\SysWOW64\setup 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\WinBioPlugIns 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ____D C:\Windows\system32\setup 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2017-09-25 17:40 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-09-24 13:12 - 2017-08-28 23:59 - 000000000 ____D C:\Users\Sam\AppData\Local\Publishers ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2017-09-30 15:20 - 2017-09-30 16:21 - 000000600 _____ () C:\Users\Sam\AppData\Local\PUTTY.RND 2017-09-08 17:54 - 2017-09-08 17:54 - 000007609 _____ () C:\Users\Sam\AppData\Local\Resmon.ResmonCfg ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-10-19 18:52 ==================== Ende von FRST.txt ============================ |
24.10.2017, 15:19 | #2 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link FRST Adiction.txt
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 23-10-2017 01 durchgeführt von Sam (23-10-2017 22:53:02) Gestartet von C:\Users\Sam\Desktop Windows 10 Education Version 1703 15063.674 (X64) (2017-08-28 21:58:10) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-773800576-1985737239-35243653-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-773800576-1985737239-35243653-503 - Limited - Disabled) Gast (S-1-5-21-773800576-1985737239-35243653-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-773800576-1985737239-35243653-1003 - Limited - Enabled) Sam (S-1-5-21-773800576-1985737239-35243653-1001 - Administrator - Enabled) => C:\Users\Sam ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Kaspersky Anti-Virus (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Kaspersky Anti-Virus (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) µTorrent (HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\uTorrent) (Version: 3.5.0.43916 - BitTorrent Inc.) 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov) Advanced IP Scanner 2.5 (HKLM-x32\...\{5384A10A-BFD0-491C-BD04-471025E807DE}) (Version: 2.5.3233 - Famatech) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.) Anno 2070 (HKLM-x32\...\Uplay Install 22) (Version: - Ubisoft) Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 385.69 - NVIDIA Corporation) Hidden Apple Application Support (32-Bit) (HKLM-x32\...\{3D1290E6-1F77-46D5-A715-A56679C8D4E3}) (Version: 6.0.2 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}) (Version: 6.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}) (Version: 11.0.0.30 - Apple Inc.) Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.51.22728 - Electronic Arts) BlueStacks 3 (HKLM-x32\...\BlueStacks) (Version: 3.7.44.1625 - BlueStack Systems, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.35 - Piriform) Discord (HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Discord) (Version: 0.0.298 - Discord Inc.) Epic Games Launcher (HKLM-x32\...\{0F9F6D3D-0EA8-4684-BB34-D5FA4AF721A5}) (Version: 1.1.125.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden FireStorm version V2.0.0.022 (HKLM-x32\...\FireStorm_is1) (Version: V2.0.0.022 - ) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 8.3.2.25013 - Foxit Software Inc.) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.62 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden iTunes (HKLM\...\{1441974B-BB94-41EC-AC0F-30D5F5AC54F7}) (Version: 12.7.0.166 - Apple Inc.) Java 8 Update 151 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180151F0}) (Version: 8.0.1510.12 - Oracle Corporation) Java SE Development Kit 8 Update 111 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180111}) (Version: 8.0.1110.14 - Oracle Corporation) Java SE Development Kit 8 Update 144 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180144}) (Version: 8.0.1440.1 - Oracle Corporation) Java-Editor 15.06, 2017.09.17 (HKLM-x32\...\{65FBA21B-7F80-4E4E-B275-0958D2648F94}_is1) (Version: - Gerhard Röhner) Kaspersky Anti-Virus (HKLM-x32\...\{5AAE61FF-858E-453E-B8F3-944618149975}) (Version: 18.0.0.405 - Kaspersky Lab) Hidden Kaspersky Anti-Virus (HKLM-x32\...\InstallWIX_{5AAE61FF-858E-453E-B8F3-944618149975}) (Version: 18.0.0.405 - Kaspersky Lab) Kaspersky Secure Connection (HKLM-x32\...\{F33C0717-8E04-4EB5-90C8-47221287DB4F}) (Version: 18.0.0.405 - Kaspersky Lab) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F33C0717-8E04-4EB5-90C8-47221287DB4F}) (Version: 18.0.0.405 - Kaspersky Lab) Knuddels Standalone App (HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\Knuddels App ) (Version: "2015.12.6.0" - "Knuddels App") Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Malwarebytes Version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes) Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4971.1002 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\OneDriveSetup.exe) (Version: 17.3.6998.0830 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 56.0.1 (x64 de) (HKLM\...\Mozilla Firefox 56.0.1 (x64 de)) (Version: 56.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.1 - Mozilla) NetBeans IDE 8.2 (HKLM\...\nbi-nb-base-8.2.0.0.201609300101) (Version: 8.2 - NetBeans.org) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.5.1 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 385.69 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 385.69 - NVIDIA Corporation) NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation) NVIDIA Grafiktreiber 385.69 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 385.69 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4971.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4971.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0407-0000-0000000FF1CE}) (Version: 15.0.4971.1002 - Microsoft Corporation) Hidden Oracle VM VirtualBox 5.1.28 (HKLM\...\{11BAF690-37C7-4A56-B518-3696BD15592F}) (Version: 5.1.28 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.5.4.63358 - Electronic Arts, Inc.) PuTTY release 0.70 (64-bit) (HKLM\...\{45B3032F-22CC-40CD-9E97-4DA7095FA5A2}) (Version: 0.70.0.0 - Simon Tatham) Python 2.7.14 (64-bit) (HKLM\...\{0398A685-FD8D-46B3-9816-C47319B0CF5f}) (Version: 2.7.14150 - Python Software Foundation) Python 3.6.3 (64-bit) (HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\{b3a11d5f-0d2d-4bc3-ad72-39f3fa14162c}) (Version: 3.6.3150.0 - Python Software Foundation) Python 3.6.3 Core Interpreter (64-bit) (HKLM\...\{5CAB3F9C-AC0C-4796-984C-292FF82FB112}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Development Libraries (64-bit) (HKLM\...\{B6B221CE-20AA-46D6-8156-911613216968}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Documentation (64-bit) (HKLM\...\{404A8C42-6B82-4B32-AC7F-0583644A04F2}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Executables (64-bit) (HKLM\...\{D3ABC2C4-85AF-4AFD-94D4-F2B84F49BFEA}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 pip Bootstrap (64-bit) (HKLM\...\{48EC8399-294B-40F5-8274-E2AFBF0CFCBE}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Standard Library (64-bit) (HKLM\...\{60B3332C-989F-4609-8D4F-7B1FD1DB0A5D}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Tcl/Tk Support (64-bit) (HKLM\...\{8FE3FFD1-2F7E-4EBB-A4B7-627E279DA70E}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Test Suite (64-bit) (HKLM\...\{2C6B5217-ACF4-4082-B19C-3463C9340E41}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python 3.6.3 Utility Scripts (64-bit) (HKLM\...\{E3F016B8-A524-4F97-9095-944C31A971E0}) (Version: 3.6.3150.0 - Python Software Foundation) Hidden Python Launcher (HKLM-x32\...\{C093353B-F9EE-4A06-923D-C1B340B82886}) (Version: 3.6.6119.0 - Python Software Foundation) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.00.830 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.12.1007.2016 - Realtek) Revo Uninstaller 2.0.3 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.3 - VS Revo Group, Ltd.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics) Sandboxie 5.16 (64-bit) (HKLM\...\Sandboxie) (Version: 5.16 - Sandboxie Holdings, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.6 - TeamSpeak Systems GmbH) The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.31.0.0 - GOG.com) The Witcher 3: Wild Hunt - Blood and Wine (HKLM-x32\...\Blood and Wine_is1) (Version: 1.24.0.0 - GOG.com) The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.24.0.0 - GOG.com) The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\...\Hearts of Stone_is1) (Version: 1.24.0.0 - GOG.com) Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Uplay Install 635) (Version: - Ubisoft Montreal) TunnelBear (HKLM-x32\...\{8092fbe5-9e59-4729-a5de-5bb6a64873cc}) (Version: 3.0.37.12 - TunnelBear) TunnelBear (HKLM-x32\...\{ABC9BE61-B890-4100-BCA4-5AC3BF1F3CB5}) (Version: 3.0.37.12 - TunnelBear) Hidden Uplay (HKLM-x32\...\Uplay) (Version: 39.1 - Ubisoft) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - LunarG, Inc.) Hidden web control version 3.0.5.1 (HKLM-x32\...\{F88ED86C-0010-4943-BA16-72E4184E31ED}_is1) (Version: 3.0.5.1 - ) WinRAR 5.50 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2017-08-29] () ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => E:\Programme\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-08-19] (Foxit Software Inc.) ContextMenuHandlers1: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2017-09-02] (AO Kaspersky Lab) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers2: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2017-09-02] (AO Kaspersky Lab) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers4: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2017-09-02] (AO Kaspersky Lab) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-09-16] (NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => E:\Programme\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-08-19] (Foxit Software Inc.) ContextMenuHandlers6: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2017-09-02] (AO Kaspersky Lab) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {04B0F0CE-B1C6-4686-8154-776493A7A6CF} - System32\Tasks\Microsoft\Windows\Display\Brightness\BrightnessReset Task: {0501CF85-3FEC-4BE5-998C-751C2A014561} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation) Task: {10BE2200-AB7C-4DB8-A414-49BCBFC05878} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.) Task: {1B2200F2-0FDA-4A0C-82E0-7442FE0DFB23} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11] (NVIDIA Corporation) Task: {2BF7AF84-C247-4C54-8059-79FC5D698535} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation) Task: {3F6CE8E8-C944-4C7D-BBDC-695536059A42} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation) Task: {44B367D5-F5BC-4EBC-98DD-EA83C47D8FA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-23] (Google Inc.) Task: {6819E097-A627-499E-9A4A-CEA08E28F7F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-23] (Google Inc.) Task: {8B1D4324-0E82-4A1D-8511-A095EDCECB1E} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.) Task: {9E1F8D76-49CB-4849-ADAB-D6C1DE0080BC} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation) Task: {A9CB9D46-7B98-4AB4-A5BF-CF5341EA3A70} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation) Task: {B1E6B285-5011-4CFC-8FF8-986500C8F779} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-11] (NVIDIA Corporation) Task: {D5F44AFF-9465-49D6-92E7-D7D817070577} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-10-11] (NVIDIA Corporation) Task: {F2F5D038-99C7-4086-B5C8-57D54D4769F5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-09-20] (Piriform Ltd) Task: {F3D79917-1011-4615-B8E2-72720D384F68} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation) Task: {F4D3D4F3-6E76-45FF-95B7-FC01483B82A1} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-10-11] (NVIDIA Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\Sam\Desktop\Programme und Verknüpfungen\Ark Server Ragnarok.lnk -> D:\Steam\steamapps\common\ARK Survival Evolved Dedicated Server\ShooterGame\Binaries\Win64\start.bat () ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2017-09-01 02:49 - 2017-09-01 02:49 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2017-09-01 02:49 - 2017-09-01 02:49 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-07-20 00:09 - 2017-07-20 00:09 - 000189264 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2017-09-06 16:48 - 2017-09-06 16:48 - 000037248 _____ () C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe 2017-03-18 22:58 - 2017-03-18 22:58 - 000138000 _____ () C:\Windows\SYSTEM32\inputhost.dll 2017-03-18 22:59 - 2017-03-20 06:43 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-09-02 18:58 - 2017-09-02 18:58 - 000074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-09-02 18:58 - 2017-09-02 18:58 - 000203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-09-02 18:58 - 2017-09-02 18:58 - 036162048 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-09-02 18:58 - 2017-09-02 18:58 - 002237952 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\skypert.dll 2017-09-11 14:45 - 2017-09-11 14:45 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll 2017-09-11 14:45 - 2017-09-11 14:45 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll 2017-09-07 18:12 - 2017-09-07 18:12 - 000069632 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2017-09-01 20:58 - 2017-01-17 04:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2017-10-23 22:12 - 2017-10-17 10:08 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.62\libglesv2.dll 2017-10-23 22:12 - 2017-10-17 10:08 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.62\libegl.dll 2017-09-01 19:40 - 2017-09-01 19:40 - 000836968 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\kpcengine.2.3.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-10-08 12:34 - 2017-10-11 03:05 - 070805952 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-07-11 12:23 - 2017-07-11 12:23 - 000143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2017-09-01 19:57 - 2014-09-28 17:59 - 000019872 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2017-03-18 23:03 - 2017-03-18 23:01 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-773800576-1985737239-35243653-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run32: => "FireStormStartUpAutoRun" HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\StartupApproved\Run: => "GalaxyClient" HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-773800576-1985737239-35243653-1001\...\StartupApproved\Run: => "uTorrent" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{F1B92658-900B-47BC-9989-F3550542389B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{AED5ECC4-E710-4667-9A03-B9711F013063}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{CA2CECAD-1C59-40E6-8A46-2519CB76FC67}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{F171CF78-84D6-4560-AA80-76D619488B58}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{70EDCF7F-FE8F-4E65-AF86-CFF9FC3E9581}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{55062BF3-1D07-46E4-B698-5A7D2FCE8FA4}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{20E51D00-6E0B-4586-AA7D-E962794156FB}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{9D81B87B-6676-43D4-89F7-47429320BF8A}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{26C4B9E1-189D-421E-9AB1-350947616060}] => (Allow) D:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe FirewallRules: [{6DB085FC-8E9B-4A2F-B96A-F2741D84F6E0}] => (Allow) D:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe FirewallRules: [{2D6F50C4-365B-413F-93FB-3531C709E0E0}] => (Allow) D:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe FirewallRules: [{21827CFC-AE86-4A16-B9A9-05F571BC41A8}] => (Allow) D:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe FirewallRules: [{29458AF6-4E87-4C9A-A6BB-1000E2B70000}] => (Allow) D:\Steam\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe FirewallRules: [{A7462A12-CE46-4255-AAD4-22D64FFD5067}] => (Allow) D:\Steam\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe FirewallRules: [{EAA5BD07-7955-4B7A-BE65-9067827593E8}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{FC1E1E41-4C05-4CCD-9046-D7FC6F0BAA5D}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{85164607-9C29-4D2C-B19E-1C79586814C4}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{89088FEE-88A1-48AB-A698-5B05075328E7}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{63D99534-72B9-4C6D-B7D3-DDBD64FC43B1}] => (Allow) D:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{BC9FC2B7-AEA4-4A23-AFFE-955D76D2ADFA}] => (Allow) D:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{39567111-9EF1-41FF-A268-619F55001D2C}] => (Allow) D:\Steam\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{0FA1C9C3-7063-4F60-966C-C954D109B65D}] => (Allow) D:\Steam\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{B419CE88-CB2F-4053-8CB3-8A5E05D3DE94}] => (Allow) D:\Steam\steamapps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe FirewallRules: [{F405F70B-2F0E-461F-AFAA-5A8F793972BC}] => (Allow) D:\Steam\steamapps\common\South Park - The Stick of Truth\South Park - The Stick of Truth.exe FirewallRules: [{EFD94FDC-38C1-43B9-8695-2168955A4699}] => (Allow) D:\Steam\steamapps\common\Prison Architect\Prison Architect.exe FirewallRules: [{8D61E076-9BE8-4373-BBD5-6D331C7BBE20}] => (Allow) D:\Steam\steamapps\common\Prison Architect\Prison Architect.exe FirewallRules: [{D4757A5A-91CC-4ABC-B0BD-9B8D871AD388}] => (Allow) D:\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{C6FEACFD-4DC1-4418-9395-585675E2FF7E}] => (Allow) D:\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe FirewallRules: [{7C6485F5-B479-4E20-BCA7-07D222A3090C}] => (Allow) D:\Steam\steamapps\common\Trials Fusion\datapack\trials_fusion.exe FirewallRules: [{0ED48327-2E3E-4C90-B601-7210FA35546C}] => (Allow) D:\Steam\steamapps\common\Trials Fusion\datapack\trials_fusion.exe FirewallRules: [{4DC29204-DA1E-483F-B139-801736043E62}] => (Allow) D:\Steam\steamapps\common\Cities_Skylines\Cities.exe FirewallRules: [{B158667C-E9E2-421A-9DA6-B856A2DFE191}] => (Allow) D:\Steam\steamapps\common\Cities_Skylines\Cities.exe FirewallRules: [TCP Query User{FB57CBFB-976E-46BF-AAE7-1AFBE69A57C5}D:\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) D:\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe FirewallRules: [UDP Query User{8035B445-8B89-4C23-B8E4-BB65BB8E0CBB}D:\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) D:\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe FirewallRules: [{E9965AAD-CCF7-41FC-99D2-D12B9572B780}] => (Allow) D:\Steam\steamapps\common\DOOM\DOOMx64.exe FirewallRules: [{7E12B98B-A715-4787-90AD-53123D4AD54B}] => (Allow) D:\Steam\steamapps\common\DOOM\DOOMx64.exe FirewallRules: [TCP Query User{DCF4AF63-6D7B-4515-8904-47C1245C79EE}D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{0DA425C1-78B6-4821-A734-37F83D878330}D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [{8A96FB7F-6D22-4013-9486-6035C4002A93}] => (Allow) D:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{20116AC3-2F0B-4A88-A71B-C375F3274304}] => (Allow) D:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{F100BBE6-3182-4BC0-805C-A55419E9EAA3}] => (Allow) D:\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{5FEA9A39-966B-45E9-A8AF-C4CB34B7DC12}] => (Allow) D:\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{CA1BD36E-6CB2-47DE-91B6-D80EA73D3700}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{FB04F9D8-54A5-4953-ABB9-AF06C1B80B64}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{0A631918-E712-443E-AB37-8354FAB65525}] => (Allow) D:\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe FirewallRules: [{25E932AB-4008-450E-893F-55AE9F9A8496}] => (Allow) D:\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe FirewallRules: [{7E36D7C3-8D80-401E-8F88-CEB203D52FE5}] => (Allow) C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe FirewallRules: [{04FF317B-7B9C-4355-B1C6-13FBC49C2384}] => (Allow) C:\Users\Sam\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{649303B6-FA25-45E9-B7F0-E65A20DE586D}] => (Allow) C:\Users\Sam\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C18DB43C-31FB-44B1-91D5-943603C54449}] => (Allow) D:\Ubisoft\Ubisoft Game Launcher\games\Anno 2070\Anno5.exe FirewallRules: [{045362E5-9FD5-4495-9C23-8B46E050F290}] => (Allow) D:\Ubisoft\Ubisoft Game Launcher\games\Anno 2070\Anno5.exe FirewallRules: [{CE3347D6-0C35-4A54-B933-3701FC1D14C5}] => (Allow) D:\Steam\steamapps\common\Banished\Application-steam-x64.exe FirewallRules: [{6153C76D-D0B4-4EA0-87C1-84ED299900D2}] => (Allow) D:\Steam\steamapps\common\Banished\Application-steam-x64.exe FirewallRules: [{B46C948B-E2E7-42FD-AB30-F3467B542AEE}] => (Allow) D:\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{14BA8E9B-AAFC-4EA4-8D1A-DC0112EF3A04}] => (Allow) D:\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{078C2C55-1B96-43D8-9F42-4E42709F1D33}] => (Allow) D:\Steam\steamapps\common\Thief\Binaries\Win64\Shipping-ThiefGame.exe FirewallRules: [{9C462613-5D20-4F0D-9560-3B9B0A8DB0FC}] => (Allow) D:\Steam\steamapps\common\Thief\Binaries\Win64\Shipping-ThiefGame.exe FirewallRules: [{FDAEC1DE-4D4D-493B-A83C-374E396D5982}] => (Allow) D:\Steam\steamapps\common\Wolfenstein.The.New.Order\WolfNewOrder_x64.exe FirewallRules: [{BCF16DD8-5D1C-4D50-9C84-A9CE228FD863}] => (Allow) D:\Steam\steamapps\common\Wolfenstein.The.New.Order\WolfNewOrder_x64.exe FirewallRules: [{816D78FE-3684-4253-B2AB-B99EE914EA4C}] => (Allow) D:\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{97C336C9-5F82-4944-ABD7-A904C5F287B9}] => (Allow) D:\Steam\steamapps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe FirewallRules: [{9805D460-0AA5-4137-BEB5-E53A24767801}] => (Allow) D:\Steam\steamapps\common\Besiege\Besiege.exe FirewallRules: [{40FF868A-E269-4EF4-80F1-4BE872A3A6A3}] => (Allow) D:\Steam\steamapps\common\Besiege\Besiege.exe FirewallRules: [TCP Query User{FF522400-8961-4B94-840F-F7E76E738D9C}D:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe] => (Allow) D:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe FirewallRules: [UDP Query User{F84E8D8A-0AD2-493B-BDDB-A5A99C28E75F}D:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe] => (Allow) D:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergameserver.exe FirewallRules: [{E1DC9F59-6DF6-4E61-A428-017D3884F21F}] => (Allow) D:\Steam\steamapps\common\ARK Survival Evolved Dedicated Server\ShooterGame\Binaries\Win64\ShooterGameServer.exe FirewallRules: [{138042D4-4290-4C4D-BD04-B63760874F29}] => (Allow) D:\Steam\steamapps\common\ARK Survival Evolved Dedicated Server\ShooterGame\Binaries\Win64\ShooterGameServer.exe FirewallRules: [{CEC929FE-E4D7-40C8-8CE8-5C1853A43F07}] => (Allow) D:\Steam\steamapps\common\Outlast\OutlastLauncher.exe FirewallRules: [{4BE6A1E9-4445-42D3-8EEE-A2DE9EBFA7A7}] => (Allow) D:\Steam\steamapps\common\Outlast\OutlastLauncher.exe FirewallRules: [TCP Query User{573FE7E5-0F4C-4196-9059-C42ECCDD20B4}D:\steam\steamapps\common\outlast\binaries\win64\olgame.exe] => (Allow) D:\steam\steamapps\common\outlast\binaries\win64\olgame.exe FirewallRules: [UDP Query User{176C5724-6A07-4EB2-A9D4-5B3F18D755F0}D:\steam\steamapps\common\outlast\binaries\win64\olgame.exe] => (Allow) D:\steam\steamapps\common\outlast\binaries\win64\olgame.exe FirewallRules: [{EE9B56EF-EF41-44E0-BC53-C2326B82973C}] => (Allow) D:\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe FirewallRules: [{ECCC9011-A172-4B5C-AEFA-DD234FD48A33}] => (Allow) D:\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe FirewallRules: [TCP Query User{F01E7E53-A670-4D0A-9D84-195C345E5432}D:\epic games\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) D:\epic games\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [UDP Query User{F0FAF0B1-EBFA-4F02-B518-CC4E16FE34F7}D:\epic games\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) D:\epic games\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{4D07105A-E80E-4BC0-B6BA-6E59C35A46C1}D:\epic games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\epic games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{935B9829-1A5C-4549-B94E-551C9EE37991}D:\epic games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\epic games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [{ED6ED168-5124-4032-AB84-42230EF29D9D}] => (Allow) D:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{CE2C7B5C-453D-4665-AA5B-F7EE34A21659}] => (Allow) D:\Steam\steamapps\common\Age Of Empires 3\bin\age3.exe FirewallRules: [{91A5C4AC-C106-404F-8AC5-4746B035BF47}] => (Allow) D:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{BA143BDD-E775-49A4-A832-24AF453C3F6E}] => (Allow) D:\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exe FirewallRules: [{ED70C45D-BD17-4D3A-B11A-973AE810C7D3}] => (Allow) D:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{B485BE35-5D41-470A-904D-4EF01BE979CE}] => (Allow) D:\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exe FirewallRules: [{3529075C-8A26-43B4-AF0B-2374D6039A22}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe FirewallRules: [{7FA9D4F0-D23E-484C-B827-91107A5EAA62}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe FirewallRules: [{E33FAE4B-AEA2-4CEC-A4D8-D4133DE14EE0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{426A2E67-9249-4D4C-8606-FF6362EB9C20}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{BE700DE9-1D5F-4D85-ADF1-927429BECE0F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{CB7BD0C9-E40B-4954-B48D-2A23661A18CC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{5B802A13-2C70-416A-B963-ADE86AAE7BF6}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{995ABE33-5A27-4C62-9400-DDFBE59A5318}] => (Allow) D:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{1338E10B-5F7B-4C33-917C-FB8849173973}] => (Allow) D:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{24E88C37-2F04-4FC4-AC24-A2FEE22A3220}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe FirewallRules: [{F6A24AE6-99A3-4128-A8A0-AFCD5E9CA25A}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe FirewallRules: [{DDE3164A-AC81-488A-BEAA-FBCA216E2B5E}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe FirewallRules: [{2EECC735-41D4-4F3B-9DC7-AE8BFBD6E383}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe FirewallRules: [{15139C0D-3606-4D62-99B3-A092BB81700C}] => (Allow) D:\Origin\Battlefield 1\bf1Trial.exe FirewallRules: [{D441812D-8EB5-4E02-BFF7-BC16404D245A}] => (Allow) D:\Origin\Battlefield 1\bf1Trial.exe FirewallRules: [{66FB2310-9EB3-4295-BEE1-D01D4CB0950A}] => (Allow) D:\Origin\Battlefield 1\bf1.exe FirewallRules: [{F51A4536-CABC-49B9-9DCF-A7BFD5D00DF6}] => (Allow) D:\Origin\Battlefield 1\bf1.exe FirewallRules: [{9499FFF3-8939-4294-A869-1B32BC65ED10}] => (Allow) D:\Steam\steamapps\common\Dying Light\DyingLightGame.exe FirewallRules: [{975E4C8A-7D1F-4625-AE6F-5DCBB5DCEBD7}] => (Allow) D:\Steam\steamapps\common\Dying Light\DyingLightGame.exe FirewallRules: [{CD87C94C-589E-4AE8-9BDB-EB99CEA1E85D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{B5C68E68-A6C6-4BBC-A3D9-5D1946A9792A}] => (Allow) D:\Steam\steamapps\common\Dead Island\DeadIslandGame.exe FirewallRules: [{339E53EB-3F84-4905-A5AE-5D2C9D23D95C}] => (Allow) D:\Steam\steamapps\common\Dead Island\DeadIslandGame.exe FirewallRules: [{07E89EFA-8A34-43A2-92D0-F051A5B159E9}] => (Allow) D:\Steam\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe FirewallRules: [{BE983F8D-BAC4-4260-846B-800C05F10F64}] => (Allow) D:\Steam\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe FirewallRules: [{569C3820-C02F-4542-BC62-98395E728F3A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{E1EC2207-7824-47BA-B83D-AEFFBD215F75}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{6141E322-CD05-4611-8769-2C7191CBDE01}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Wiederherstellungspunkte ========================= 08-10-2017 20:12:49 Installed Python 2.7.14 (64-bit) 17-10-2017 21:32:17 Windows Update 22-10-2017 11:35:35 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: VirtualBox Host-Only Ethernet Adapter Description: VirtualBox Host-Only Ethernet Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Oracle Corporation Service: VBoxNetAdp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: TunnelBear Adapter V9 Description: TunnelBear Adapter V9 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TunnelBear Provider V9 Service: tap-tb-0901 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (10/23/2017 10:06:21 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Fehler beim Aktualisieren des -Status auf SECURITY_PRODUCT_STATE_OFF. Error: (10/23/2017 10:05:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: wmiprvse.exe, Version: 10.0.15063.0, Zeitstempel: 0xeee35298 Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.15063.608, Zeitstempel: 0x8274fd8b Ausnahmecode: 0xc0000374 Fehleroffset: 0x00000000000f775f ID des fehlerhaften Prozesses: 0x12f4 Startzeit der fehlerhaften Anwendung: 0x01d34c3a1a014849 Pfad der fehlerhaften Anwendung: C:\Windows\system32\wbem\wmiprvse.exe Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll Berichtskennung: e919a758-bf97-4dd0-aeef-adbca01c66d1 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/23/2017 10:05:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RzStats.Manager.exe, Version: 1.2.16.0, Zeitstempel: 0x587327cf Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.15063.674, Zeitstempel: 0x6d16dd24 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000eb872 ID des fehlerhaften Prozesses: 0x3bd4 Startzeit der fehlerhaften Anwendung: 0x01d34c3a35f3869e Pfad der fehlerhaften Anwendung: C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe Pfad des fehlerhaften Moduls: C:\Windows\System32\KERNELBASE.dll Berichtskennung: 420fd3d6-2d3b-4e1a-ae3a-b6c1c4fab9b6 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/23/2017 10:05:04 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: RzStats.Manager.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.IO.IOException bei System.IO.__Error.WinIOError(Int32, System.String) bei System.IO.File.InternalCopy(System.String, System.String, Boolean, Boolean) bei System.IO.File.Copy(System.String, System.String, Boolean) bei Razer.DataTracking.Common.Utils.XDocumentSafe.SafeSave(System.Xml.Linq.XDocument, System.String) bei RzDataTrackingManager.DataHistoryManager.InitStatsHistory(System.String) bei RzDataTrackingManager.DataHistoryManager.GetStatsFromStorage() bei RzDataTrackingManager.Form1..ctor() bei RzDataTrackingManager.Program.Main() Error: (10/23/2017 09:46:45 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Fehler beim Aktualisieren des -Status auf SECURITY_PRODUCT_STATE_OFF. Error: (10/23/2017 09:45:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RzStats.Manager.exe, Version: 1.2.16.0, Zeitstempel: 0x587327cf Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.15063.674, Zeitstempel: 0x6d16dd24 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000eb872 ID des fehlerhaften Prozesses: 0x36a4 Startzeit der fehlerhaften Anwendung: 0x01d34c37821d23db Pfad der fehlerhaften Anwendung: C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe Pfad des fehlerhaften Moduls: C:\Windows\System32\KERNELBASE.dll Berichtskennung: d18b51a4-51bc-4d7e-aa75-d4a9ca14526a Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/23/2017 09:45:44 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: RzStats.Manager.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.IO.IOException bei System.IO.__Error.WinIOError(Int32, System.String) bei System.IO.File.InternalCopy(System.String, System.String, Boolean, Boolean) bei System.IO.File.Copy(System.String, System.String, Boolean) bei Razer.DataTracking.Common.Utils.XDocumentSafe.SafeSave(System.Xml.Linq.XDocument, System.String) bei RzDataTrackingManager.DataHistoryManager.InitStatsHistory(System.String) bei RzDataTrackingManager.DataHistoryManager.GetStatsFromStorage() bei RzDataTrackingManager.Form1..ctor() bei RzDataTrackingManager.Program.Main() Error: (10/23/2017 09:37:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: ksdeui.exe, Version: 18.0.0.405, Zeitstempel: 0x58876d8f Name des fehlerhaften Moduls: 0KrakenDevProps.dll, Version: 0.0.0.0, Zeitstempel: 0x59560099 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00004774 ID des fehlerhaften Prozesses: 0x1e78 Startzeit der fehlerhaften Anwendung: 0x01d34c364bf2eb4a Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe Pfad des fehlerhaften Moduls: C:\Users\Sam\AppData\Local\Temp\0KrakenDevProps.dll Berichtskennung: e40c03dc-2ba6-446f-b8fd-7b8ccafce59e Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/23/2017 09:36:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RzStats.Manager.exe, Version: 1.2.16.0, Zeitstempel: 0x587327cf Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.15063.674, Zeitstempel: 0x6d16dd24 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000eb872 ID des fehlerhaften Prozesses: 0x3dd8 Startzeit der fehlerhaften Anwendung: 0x01d34c364a24b294 Pfad der fehlerhaften Anwendung: C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe Pfad des fehlerhaften Moduls: C:\Windows\System32\KERNELBASE.dll Berichtskennung: f061fb07-7436-43be-b515-6e412391cc34 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/23/2017 09:36:59 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: RzStats.Manager.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.IO.IOException bei System.IO.__Error.WinIOError(Int32, System.String) bei System.IO.File.InternalCopy(System.String, System.String, Boolean, Boolean) bei System.IO.File.Copy(System.String, System.String, Boolean) bei Razer.DataTracking.Common.Utils.XDocumentSafe.SafeSave(System.Xml.Linq.XDocument, System.String) bei RzDataTrackingManager.DataHistoryManager.InitStatsHistory(System.String) bei RzDataTrackingManager.DataHistoryManager.GetStatsFromStorage() bei RzDataTrackingManager.Form1..ctor() bei RzDataTrackingManager.Program.Main() Systemfehler: ============= Error: (10/23/2017 10:04:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (10/23/2017 10:03:10 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-8FDETOF) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (10/23/2017 10:03:10 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-8FDETOF) Description: Der Server "{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (10/23/2017 10:03:10 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-8FDETOF) Description: Der Server "{4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (10/23/2017 10:03:10 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-8FDETOF) Description: Der Server "{4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (10/23/2017 10:00:15 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TunnelBear Maintenance" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/23/2017 09:44:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (10/23/2017 09:34:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet: Die Anforderung wird nicht unterstützt. Error: (10/23/2017 09:34:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kaspersky Secure Connection Service 2.0.0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (10/23/2017 09:34:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2017-10-23 21:52:22.194 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-10-23 21:52:21.916 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-10-23 21:51:44.902 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-10-23 21:51:44.655 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: AMD Ryzen 7 1700X Eight-Core Processor Prozentuale Nutzung des RAM: 22% Installierter physikalischer RAM: 16316.77 MB Verfügbarer physikalischer RAM: 12628.78 MB Summe virtueller Speicher: 19772.77 MB Verfügbarer virtueller Speicher: 15664.64 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:232.4 GB) (Free:121.79 GB) NTFS Drive d: (Volume) (Fixed) (Total:1863.01 GB) (Free:1229.78 GB) NTFS Drive e: (Volume) (Fixed) (Total:676.11 GB) (Free:662.43 GB) NTFS Drive g: (SamJule) (Fixed) (Total:931.51 GB) (Free:452.61 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 8152F8B2) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=232.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00B568C8) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 698.6 GB) (Disk ID: 26AC197A) Partition 1: (Not Active) - (Size=676.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=22.5 GB) - (Type=27) ======================================================== Disk: 3 (Size: 931.5 GB) (Disk ID: 218481D0) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
24.10.2017, 15:20 | #3 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link tdsskiller.txt Teil 1
__________________Code:
ATTFilter 22:48:33.0422 0x1f2c TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02 22:48:36.0397 0x1f2c ============================================================ 22:48:36.0397 0x1f2c Current date / time: 2017/10/23 22:48:36.0397 22:48:36.0397 0x1f2c SystemInfo: 22:48:36.0397 0x1f2c 22:48:36.0397 0x1f2c OS Version: 10.0.15063 ServicePack: 0.0 22:48:36.0397 0x1f2c Product type: Workstation 22:48:36.0397 0x1f2c ComputerName: DESKTOP-8FDETOF 22:48:36.0397 0x1f2c UserName: Sam 22:48:36.0397 0x1f2c Windows directory: C:\Windows 22:48:36.0397 0x1f2c System windows directory: C:\Windows 22:48:36.0397 0x1f2c Running under WOW64 22:48:36.0397 0x1f2c Processor architecture: Intel x64 22:48:36.0397 0x1f2c Number of processors: 16 22:48:36.0397 0x1f2c Page size: 0x1000 22:48:36.0397 0x1f2c Boot type: Normal boot 22:48:36.0397 0x1f2c CodeIntegrityOptions = 0x00000001 22:48:36.0397 0x1f2c ============================================================ 22:48:36.0497 0x1f2c KLMD registered as C:\Windows\system32\drivers\31681367.sys 22:48:36.0497 0x1f2c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 15063.0, osProperties = 0x19 22:48:36.0613 0x1f2c System UUID: {BC6654C7-6927-CA89-E09B-CAB2620AA84D} 22:48:36.0930 0x1f2c Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:48:36.0930 0x1f2c Drive \Device\Harddisk1\DR1 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:48:37.0674 0x1f2c Drive \Device\Harddisk2\DR2 - Size: 0xAEA8CDE000 ( 698.64 Gb ), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:48:37.0674 0x1f2c Drive \Device\Harddisk3\DR3 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 22:48:37.0674 0x1f2c ============================================================ 22:48:37.0674 0x1f2c \Device\Harddisk0\DR0: 22:48:37.0674 0x1f2c MBR partitions: 22:48:37.0674 0x1f2c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFA000 22:48:37.0674 0x1f2c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xFA800, BlocksNum 0x1D0CA800 22:48:37.0674 0x1f2c \Device\Harddisk1\DR1: 22:48:37.0674 0x1f2c MBR partitions: 22:48:37.0674 0x1f2c \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800 22:48:37.0674 0x1f2c \Device\Harddisk2\DR2: 22:48:37.0674 0x1f2c MBR partitions: 22:48:37.0674 0x1f2c \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x54838000 22:48:37.0674 0x1f2c \Device\Harddisk3\DR3: 22:48:37.0674 0x1f2c MBR partitions: 22:48:37.0674 0x1f2c \Device\Harddisk3\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x747051C1 22:48:37.0674 0x1f2c ============================================================ 22:48:37.0674 0x1f2c C: <-> \Device\Harddisk0\DR0\Partition2 22:48:37.0705 0x1f2c D: <-> \Device\Harddisk1\DR1\Partition1 22:48:37.0721 0x1f2c E: <-> \Device\Harddisk2\DR2\Partition1 22:48:38.0051 0x1f2c G: <-> \Device\Harddisk3\DR3\Partition1 22:48:38.0051 0x1f2c ============================================================ 22:48:38.0051 0x1f2c Initialize success 22:48:38.0051 0x1f2c ============================================================ 22:48:39.0836 0x3e08 ============================================================ 22:48:39.0836 0x3e08 Scan started 22:48:39.0836 0x3e08 Mode: Manual; 22:48:39.0836 0x3e08 ============================================================ 22:48:39.0836 0x3e08 KSN ping started 22:48:39.0953 0x3e08 KSN ping finished: true 22:48:40.0522 0x3e08 ================ Scan system memory ======================== 22:48:40.0522 0x3e08 System memory - ok 22:48:40.0522 0x3e08 ================ Scan services ============================= 22:48:40.0559 0x3e08 [ AAB860A5E606B9621E130D8C29D3F305, 93466620433B27F3BCFECDA26DD420AD1E5219034BA3B4E930EDED6D6728AE5C ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys 22:48:40.0560 0x3e08 1394ohci - ok 22:48:40.0560 0x3e08 [ 4140B14929C555E9513D59A2EEB5C471, 39A8400B3AA7FB1D8EBE87E65F89881AB23B6AE911BECAEC1FD86C7DADD4F1AA ] 3ware C:\Windows\system32\drivers\3ware.sys 22:48:40.0560 0x3e08 3ware - ok 22:48:40.0575 0x3e08 [ AC251B31370C1E00F577928260B8939F, D60946F1C43A8C2B9C989A1E259FDA44055F94766615F344CF8E28A7F104BC70 ] ACPI C:\Windows\system32\drivers\ACPI.sys 22:48:40.0591 0x3e08 ACPI - ok 22:48:40.0591 0x3e08 [ 3E5E5DAE5CAEC0209C93D3AD8128D8A0, 5CFA4D715AE8D928EA11F213C5A7B0B1C1705D2A8FF041E0A1988E645E669C54 ] AcpiDev C:\Windows\System32\drivers\AcpiDev.sys 22:48:40.0591 0x3e08 AcpiDev - ok 22:48:40.0591 0x3e08 [ F72D7CC7E7A97A09757313F3B4C7E17A, 36E3363380C51A2DB58D3177655A0A75DAA977C00C5A9C60A189068C0AFDC643 ] acpiex C:\Windows\system32\Drivers\acpiex.sys 22:48:40.0607 0x3e08 acpiex - ok 22:48:40.0607 0x3e08 [ F04B6F53FBDB2B6B0451AE53DE19F0C9, 41A8C314A46867BAA45CD9666AAF734AD45B74E2033A8E66D93E17CDDAD66578 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys 22:48:40.0607 0x3e08 acpipagr - ok 22:48:40.0607 0x3e08 [ C347A6095F3BE417D24F1E1349F4AF0F, 72C9D759BB132985AF55860658DC01F08590A2BD7E976FCF25E1314C5AA1D37B ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys 22:48:40.0607 0x3e08 AcpiPmi - ok 22:48:40.0607 0x3e08 [ 686BFFC47454DD2F58795C2EE891CA9F, 6CC4B6679914742D700A8373DED2DD9A821CA5284D4D73493BA0855DB8E6520A ] acpitime C:\Windows\System32\drivers\acpitime.sys 22:48:40.0607 0x3e08 acpitime - ok 22:48:40.0638 0x3e08 [ FBDA59118E59B3722248C66BAD89CAA9, 11AB83499757E3143834348DE39E85D56EC853071C96337C3ADD8A1E374C6CBC ] ADP80XX C:\Windows\system32\drivers\ADP80XX.SYS 22:48:40.0656 0x3e08 ADP80XX - ok 22:48:40.0660 0x3e08 [ 5A6D591D56791BA63CE73FCAD60D89A1, 7467E40EF0653A1A09CFD28A1EF8B75052D010E42C32F2E8B60B98ED87092CE1 ] AFD C:\Windows\system32\drivers\afd.sys 22:48:40.0675 0x3e08 AFD - ok 22:48:40.0675 0x3e08 [ 1D914C996F2C3134E2344BB74F79BCF6, D27AF01BA29784555AF7D2E89A3A65E81D6AFE1D3C7E8F9367F06D9DF5F88069 ] ahcache C:\Windows\system32\DRIVERS\ahcache.sys 22:48:40.0691 0x3e08 ahcache - ok 22:48:40.0691 0x3e08 [ 41856B40EE15F96DEC8755AB01FA3CF7, 33C3C899AF9CA15BE5A4CF097FF43DF3F0DBA0E48B6F1E28AE3E76AD76A1C361 ] AJRouter C:\Windows\System32\AJRouter.dll 22:48:40.0691 0x3e08 AJRouter - ok 22:48:40.0691 0x3e08 [ F485CA5559DB37A4882467A4F7D58BEA, A1C648EFE12A5A3356BC0949372ADD0FF0CA2F5A8F992EB71C87E9C0D5C92BB2 ] ALG C:\Windows\System32\alg.exe 22:48:40.0691 0x3e08 ALG - ok 22:48:40.0691 0x3e08 [ C2E0BA2229B895CC845E40B739EEDD7B, 63BC45E146FFE7B64A17179E27C72F300F448C2065708B77538BF8C8DBD899FB ] amdgpio2 C:\Windows\System32\drivers\amdgpio2.sys 22:48:40.0691 0x3e08 amdgpio2 - ok 22:48:40.0707 0x3e08 [ 765458AAF669D83323820E99D8BB1925, 07E4CD76AA7DC5BF416095ACB607500FF4D27ECF0EE9A3FF5AADABA58F36493B ] amdgpio3 C:\Windows\System32\drivers\amdgpio3.sys 22:48:40.0707 0x3e08 amdgpio3 - ok 22:48:40.0707 0x3e08 [ 9C39FBA94FFEF04561D13ED0D1B50DD0, 53FA118DEF37F0BA6030B9CB4C17019E6B5934941514756D66143B7BB66D7CA1 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys 22:48:40.0707 0x3e08 AmdK8 - ok 22:48:40.0707 0x3e08 [ 534D8A02188C2F78C90E6E79B1159259, 8AC06532D3DB4DE5074021966BE32D3F6AA39CEB755F0178021D9CC0483267B9 ] amdkmcsp C:\Windows\system32\DRIVERS\amdkmcsp.sys 22:48:40.0722 0x3e08 amdkmcsp - ok 22:48:40.0722 0x3e08 [ 395D56FA2E22A10AE4774440D086F559, 24D7CBE9B82DC8900D9A5E345347FEC330D47FDBD1517A2AC10218BA2A9DFAA9 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys 22:48:40.0722 0x3e08 AmdPPM - ok 22:48:40.0738 0x3e08 [ 9161CACD4C916953AE94943907D2EC81, 2D34A069387E9F8A053F8BAF241259B74926C459897BD817AB848253DCFFF903 ] amdpsp C:\Windows\system32\DRIVERS\amdpsp.sys 22:48:40.0738 0x3e08 amdpsp - ok 22:48:40.0738 0x3e08 [ EB729A9ADCB9F9C406B533F95E2F67D4, EDCB8E39C503FF30ECB82F368242179E2788C12B4FD9B557F38380A934E7D8E7 ] amdsata C:\Windows\system32\drivers\amdsata.sys 22:48:40.0738 0x3e08 amdsata - ok 22:48:40.0754 0x3e08 [ 3B5C5C696F33FE61F1922533B03B9316, C9BAAA9B02547C66A276A31958DFD2A289C5963A4EE3FF306535565240D816CC ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 22:48:40.0758 0x3e08 amdsbs - ok 22:48:40.0760 0x3e08 [ A7D45A303FF8A9493C96C4B804051E6E, 6074C264876A398039D3F89905A486ABA5BDACA038B79920A34323B38CFCB358 ] amdxata C:\Windows\system32\drivers\amdxata.sys 22:48:40.0760 0x3e08 amdxata - ok 22:48:40.0760 0x3e08 [ 2A5A93CAFF4320172897E9A366313962, 04ABF4DA27D80043BE1D5D3FFC843580A65A3CFEFCD5422005E9A2FD48D453B5 ] AppID C:\Windows\system32\drivers\appid.sys 22:48:40.0760 0x3e08 AppID - ok 22:48:40.0776 0x3e08 [ F7FEBF66A705F18DC063DFD259F15102, 394DA8A7355573C4D81C375450DF5C5B2FA6360E246B06FDE8E7F9ADF21360FA ] AppIDSvc C:\Windows\System32\appidsvc.dll 22:48:40.0776 0x3e08 AppIDSvc - ok 22:48:40.0776 0x3e08 [ 43116A8BCA28D336205D539EAAE200C6, AC4783D766949770FEBAA55BD38CA0DB703944D64A4AEC8754C023807002A72B ] Appinfo C:\Windows\System32\appinfo.dll 22:48:40.0776 0x3e08 Appinfo - ok 22:48:40.0791 0x3e08 [ 49D234989341C2D16419C1043A63CE68, B65D20145757B0585FDD3116D44931D915E47BFF29E3977222877CB2C47F3B99 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 22:48:40.0791 0x3e08 Apple Mobile Device Service - ok 22:48:40.0791 0x3e08 [ EAF36A714E16A69B8B4ED7591CBA77B6, 11FE2A5D991FB8AF78F4E78FB6DF02005EC5404DC298FE2D4E7774BB0011AB52 ] applockerfltr C:\Windows\system32\drivers\applockerfltr.sys 22:48:40.0791 0x3e08 applockerfltr - ok 22:48:40.0791 0x3e08 [ 290469FC9FDE400248DA3E528E729BC2, D9ABBEB76673D136698AA2F53C8EB1EAFBBDE365ACCA9AE348523B346143CA9C ] AppMgmt C:\Windows\System32\appmgmts.dll 22:48:40.0791 0x3e08 AppMgmt - ok 22:48:40.0807 0x3e08 [ E04FA981BC0168C66910C46633CEB4C4, E8268AB3F6C2E0FEF04F027C692D3A5F8944C82BB6B9AC2F15C858BAFC47C1AB ] AppReadiness C:\Windows\system32\AppReadiness.dll 22:48:40.0823 0x3e08 AppReadiness - ok 22:48:40.0838 0x3e08 [ EC2BD6103279C66BAAABBA15DE1718C5, 612F7045343524415BBCFFD0FAEDB81D80871021E18E0CAF376B8C48AF1B96D4 ] AppVClient C:\Windows\system32\AppVClient.exe 22:48:40.0858 0x3e08 AppVClient - ok 22:48:40.0860 0x3e08 [ 2D2DF2463FACFBF2FEE39DCCDF49D1B5, F083C1B5B2284AB818431ECC6C9A61EBAFA241840727B97DD0E3B4FF0CBD07C5 ] AppvStrm C:\Windows\system32\drivers\AppvStrm.sys 22:48:40.0860 0x3e08 AppvStrm - ok 22:48:40.0860 0x3e08 [ B86E646CE67FE9D75C0D762B19B465FC, B50C45A06AC6862DB4B183F567D55AE289EB05E6A1B32CC3AEBB6163C4296D79 ] AppvVemgr C:\Windows\system32\drivers\AppvVemgr.sys 22:48:40.0860 0x3e08 AppvVemgr - ok 22:48:40.0876 0x3e08 [ 2207D2A001A3C30B825F191CD2A76C91, A43EA8CB9E2D1A1FB2DDC738827514588BFFA420A2D618DBCA55614BE2E3B45D ] AppvVfs C:\Windows\system32\drivers\AppvVfs.sys 22:48:40.0876 0x3e08 AppvVfs - ok 22:48:40.0923 0x3e08 [ ECD9EF2663652D6770864257CF85A3CF, 44873C93537D01630860B37E85FE560E7B71A72028BA78FEDDE4FFFB8CF6E882 ] AppXSvc C:\Windows\system32\appxdeploymentserver.dll 22:48:40.0961 0x3e08 AppXSvc - ok 22:48:40.0961 0x3e08 [ 6E456A94B9BD7F6B4758729BCEDE40C3, 2F3146AC960992FA947A8E8C4D5497624A5BC69B7A3EECA117AD599C70DDE8E3 ] arcsas C:\Windows\system32\drivers\arcsas.sys 22:48:40.0961 0x3e08 arcsas - ok 22:48:40.0961 0x3e08 [ 766F3A7E42AFCF74265FAC78987D1665, 8FE82913DF5CF79B49B28B3CD782AF09FF30585A37473AE3E518A26C5D6453D0 ] AsyncMac C:\Windows\System32\drivers\asyncmac.sys 22:48:40.0976 0x3e08 AsyncMac - ok 22:48:40.0976 0x3e08 [ 01733BEEE02E51F712330D5909BD701C, A583B482DBE701A752EDFDEAE2EF16D7160DFEA6077E0C8EF013828E285D960A ] atapi C:\Windows\system32\drivers\atapi.sys 22:48:40.0976 0x3e08 atapi - ok 22:48:40.0992 0x3e08 [ 329F315D04B64BC185A59FE17A2AD6CE, B9721AD1641E3E96D1C07294884506EBED5D05921A9F9FC263711C28AD040693 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll 22:48:40.0992 0x3e08 AudioEndpointBuilder - ok 22:48:41.0023 0x3e08 [ 67ADB26CC1B504E9566B9106277DE92B, AF137C9FE9B3A231C7662F2E59EF12482396CFD8AC020DF6BDBFDD9A1209A98D ] Audiosrv C:\Windows\System32\Audiosrv.dll 22:48:41.0039 0x3e08 Audiosrv - ok 22:48:41.0058 0x3e08 [ 24B91DEBF94F19292C32DB76190036C9, 39C926526ADB06EA4C75AC3B0CD77C0CF10B8DA9FC0F44925541678E9F2CFF73 ] AVP18.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe 22:48:41.0061 0x3e08 AVP18.0.0 - ok 22:48:41.0061 0x3e08 [ 6086B5EE0DA4600B2EC2725D82DEB74E, C67CA7021D710CFDCF62B17A2B2890E61E4F1E3D956312688454FD85738C303F ] AxInstSV C:\Windows\System32\AxInstSV.dll 22:48:41.0061 0x3e08 AxInstSV - ok 22:48:41.0077 0x3e08 [ 0914A5E66C0775CE11960452A6434FEC, 978C1E20023841FBFEF0CEAFE09EDB679612C8E5986C6E40C1F6D0835112D13E ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 22:48:41.0077 0x3e08 b06bdrv - ok 22:48:41.0092 0x3e08 [ F8129321B1874D4386F7FEB754BC3380, 7264E7E2A339E456C0A1A40FDFAE0D202905467400B93FA0700498B86172337F ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys 22:48:41.0092 0x3e08 BasicDisplay - ok 22:48:41.0092 0x3e08 [ 21C85485F7675F74BC6212052033D553, 0678CA876479B3B31C62C572A61EB2B188233C053394B8316F2E2AD872D16FCD ] BasicRender C:\Windows\System32\drivers\BasicRender.sys 22:48:41.0092 0x3e08 BasicRender - ok 22:48:41.0092 0x3e08 [ 739D089777D2B66DBE7201E5EA4BA2D7, 9AD12E18A042C5B8EFB19297BC2E7BD1FEF75A138FEFB64C6BF0261FD3E53AB1 ] bcmfn2 C:\Windows\System32\drivers\bcmfn2.sys 22:48:41.0092 0x3e08 bcmfn2 - ok 22:48:41.0108 0x3e08 [ 01F529CF6AFB501324751848434AE246, 39AB2C0D3AF276946B9F020FC86F08FC7383A2B0C09768C319BB3BDC40DEF5F8 ] BDESVC C:\Windows\System32\bdesvc.dll 22:48:41.0108 0x3e08 BDESVC - ok 22:48:41.0108 0x3e08 [ ED03D2ACE378C9EB8BB957ABBD85B951, E9AE3025DC4956B736651B20AEA665909C2B468F9AE3E317F545DD4EEEA7D9E8 ] Beep C:\Windows\system32\drivers\Beep.sys 22:48:41.0108 0x3e08 Beep - ok 22:48:41.0139 0x3e08 [ 1BC518B7EC5CA53EAF44DE8213035F9D, AEE00B1C910DD806A89A3867A52F89787E1C2EA8BE0CFF82270AAAB470191A7C ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe 22:48:41.0161 0x3e08 BEService - ok 22:48:41.0176 0x3e08 [ 1FDC6CB56572203E6F4BF4E3FB30B886, 81D5C77C823DC078EEEB2DABEE5203D542C824E04FEDD96AA58F96037C065155 ] BFE C:\Windows\System32\bfe.dll 22:48:41.0192 0x3e08 BFE - ok 22:48:41.0208 0x3e08 [ 5C0D4DBACB90D9ECE77907F4F6CF9EF6, FC29F03FB7E58A9ED17A34BC2D8E39533070B8B23D1A110622C3A213BF48CD2D ] BITS C:\Windows\System32\qmgr.dll 22:48:41.0223 0x3e08 BITS - ok 22:48:41.0223 0x3e08 [ 2342B8619193B0D9FAC0D02C69DCE74A, 06A1512C9750ACD154DE8873DE6628355B7195759CE54FA96097EA6D56BE320E ] bowser C:\Windows\system32\DRIVERS\bowser.sys 22:48:41.0239 0x3e08 bowser - ok 22:48:41.0257 0x3e08 [ 06373FF017097FD40D60219980871FA0, 9366823AA3C248DD06FBFA237DCFDB2A9B7F93BA7115D235792DD81DDDA79C1F ] BrokerInfrastructure C:\Windows\System32\bisrv.dll 22:48:41.0261 0x3e08 BrokerInfrastructure - ok 22:48:41.0261 0x3e08 [ 9C7F445B018AB4744B6E0C657B5D1833, 83D04F5E3D4BA46BBD8A67764A60F5731F86B0BE3A85C2858E002ABCC362F592 ] Browser C:\Windows\System32\browser.dll 22:48:41.0261 0x3e08 Browser - ok 22:48:41.0276 0x3e08 [ 2EB2D533A0C94F05F1F511D3FA20D892, 77375EC0C1FB059D03FF2D23C975EB9A6EB00F9B59000A60A89582D4F6D1D4C4 ] BstHdLogRotatorSvc C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe 22:48:41.0276 0x3e08 BstHdLogRotatorSvc - ok 22:48:41.0292 0x3e08 [ 7DB8EE09821A6D81A19A6591C9B8AA3A, 0A9A826560884F95D64BDC8A2076AE33FB718A3A59C0BBEC48E48A5FB907ACA4 ] BstkDrv C:\Program Files (x86)\BlueStacks\BstkDrv.sys 22:48:41.0292 0x3e08 BstkDrv - ok 22:48:41.0292 0x3e08 [ AF57F0B0E284BE06860A7B701341324D, F94E44C777FDC049158B7BF73DAFCDB103D08493AC898D1C928771650F664412 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys 22:48:41.0292 0x3e08 BthAvrcpTg - ok 22:48:41.0308 0x3e08 [ E1E55BA45510B2B0309E2C77ABEB1BFE, EA7BDEC354190F1033B14847606220D414C1A52C938C9327A4765032D28B6960 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys 22:48:41.0308 0x3e08 BthHFEnum - ok 22:48:41.0308 0x3e08 [ 336A9C0254A0178ED50281B6EDF5B836, C9C454C6EC4FF5897B1873A7E90D1CE8122E43783E978A570CEA75E15F65DE97 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys 22:48:41.0308 0x3e08 bthhfhid - ok 22:48:41.0323 0x3e08 [ 47D2C4722BF3C7340B475B386AA8D78D, 045F63F8E2E222E192880EDDC4B54C3741F42ED9C13322678BE2AAF28BB240CD ] BthHFSrv C:\Windows\System32\BthHFSrv.dll 22:48:41.0323 0x3e08 BthHFSrv - ok 22:48:41.0323 0x3e08 [ 5428242193611BF91DDBF4F58900A55A, 91D59B0D0C7CA3DBBA8CA7CAD1E24845A224F451FC1880BE8CB7C1585AC79080 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys 22:48:41.0323 0x3e08 BTHMODEM - ok 22:48:41.0339 0x3e08 [ 6927D295017E9F1A5D655A8F3A122672, 4B686C93056924580390440B49C721BD9039D5C972994D8EA96CA848B786B693 ] bthserv C:\Windows\system32\bthserv.dll 22:48:41.0339 0x3e08 bthserv - ok 22:48:41.0339 0x3e08 [ FF4F46CEF5ED7FDE650CA1D73D9FB663, 42B1E911793D57D148ABCB5CEC5990A62E4C8FE17F9D71951AEA3921DC6B4DE3 ] buttonconverter C:\Windows\System32\drivers\buttonconverter.sys 22:48:41.0339 0x3e08 buttonconverter - ok 22:48:41.0355 0x3e08 [ 029434AC0A3935F9125ABBD08BF7C30B, 742338B882488CA83F502ACEBFEDC2783B8D9D6C391FE1088988276315A065F6 ] CAD C:\Windows\System32\drivers\CAD.sys 22:48:41.0356 0x3e08 CAD - ok 22:48:41.0360 0x3e08 [ 307AE8BC9B45772DA02FB952A1D86C35, 4983AC71C8E164D9E6669D345925B4FBEDD0A0A4566887E7ECC56C996B66DBD4 ] CapImg C:\Windows\System32\drivers\capimg.sys 22:48:41.0361 0x3e08 CapImg - ok 22:48:41.0361 0x3e08 [ B6E5AD7C83A5254DEE9D86023C0E5A81, 40F297406A025378A6273535475C1FF8C99BC6502B17C0E161131DA754D7974B ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 22:48:41.0361 0x3e08 cdfs - ok 22:48:41.0377 0x3e08 [ A0E5905465CBCCB63FE915F5B08752A8, 435B39A8B1684FFE9F2720A2CD11AF5A5F55E701709939756322C2CD6A22E0FA ] CDPSvc C:\Windows\System32\CDPSvc.dll 22:48:41.0392 0x3e08 CDPSvc - ok 22:48:41.0408 0x3e08 [ 618DA70D0D90DF3602259C1B121794DD, D2AF7967DE38F3B7C10824A1C900A145F45C57C0F179753A85989406600C4279 ] CDPUserSvc C:\Windows\System32\CDPUserSvc.dll 22:48:41.0408 0x3e08 CDPUserSvc - ok 22:48:41.0424 0x3e08 [ ABE77AD954BC3D72F559CF0C381E50BC, D0F24B023D7CADD4893AAF223A9BAC00B2C58D552E0C314B506C01767FB74133 ] cdrom C:\Windows\System32\drivers\cdrom.sys 22:48:41.0424 0x3e08 cdrom - ok 22:48:41.0424 0x3e08 [ 62E13528B9F900A5662E243D4315F10B, B3F4868E80A3A2EDEC19E5AA32C96FF90B08D6B9BD35B80EA01E6A098D46040B ] CertPropSvc C:\Windows\System32\certprop.dll 22:48:41.0424 0x3e08 CertPropSvc - ok 22:48:41.0439 0x3e08 [ 05EA22CFC40EDE05BF6E3BC782E5204C, F0C9C692FC31387E9D19426D3253317B6BA86D7118E3884C11E3287695006443 ] cht4iscsi C:\Windows\system32\drivers\cht4sx64.sys 22:48:41.0439 0x3e08 cht4iscsi - ok 22:48:41.0476 0x3e08 [ 863E1C9F6750446DFB9EDCAEC3531367, 88C5EE76FD85640EB1440DEFC7B6CB918E18DC09507BA91FAE285370B8C7D56A ] cht4vbd C:\Windows\System32\drivers\cht4vx64.sys 22:48:41.0508 0x3e08 cht4vbd - ok 22:48:41.0508 0x3e08 [ 3E416539352B007AD0610BF34AC15D31, E2041129770B24AE95C5EC4B507477C72DFE8CB08D412E2621BF67207F9DEB8C ] circlass C:\Windows\System32\drivers\circlass.sys 22:48:41.0508 0x3e08 circlass - ok 22:48:41.0508 0x3e08 [ 616E1ED94FA7F96D429D985FDB203D2E, EA681C442AA0F7D424C8DABD8D1C14653E61BDE740C0BC4C6C308B5FB4FE67AA ] CldFlt C:\Windows\system32\drivers\cldflt.sys 22:48:41.0508 0x3e08 CldFlt - ok 22:48:41.0523 0x3e08 [ AF0BF03C8574DD026FAF9A82A64C2D04, 363BF0C42181FA4CFBC3DB504F48496D62023F0E4A858DC8F739C08CC5AFA228 ] CLFS C:\Windows\system32\drivers\CLFS.sys 22:48:41.0523 0x3e08 CLFS - ok 22:48:41.0577 0x3e08 [ DC8A9E151BDDFF220B420F757D20DC28, E92AE93DFF3BEEE849218504514DF1AEDF7DAB32980546ABE5EAFFE25750AF6C ] ClickToRunSvc C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe 22:48:41.0608 0x3e08 ClickToRunSvc - ok 22:48:41.0641 0x3e08 [ 6EA702AD5307947122E5C726047F0B8E, 98F22573944A69CFEDAEB79D308B703385CDFDE9C4CFBC8CDA44D837489122FE ] ClipSVC C:\Windows\System32\ClipSVC.dll 22:48:41.0641 0x3e08 ClipSVC - ok 22:48:41.0660 0x3e08 [ 5118CFC33BBB51C7E3ED441B7085AD26, 8D33864FF750926C4B95827FFAD24C558DE8A90FC5B2663084DEAB5ADBBFAFD2 ] clreg C:\Windows\System32\drivers\registry.sys 22:48:41.0660 0x3e08 clreg - ok 22:48:41.0661 0x3e08 [ 232F3A3AC3A2FB32C5C46503A6517073, 9E0232E095471E6C8825E870F5842838F1AE515E56410F6A5CC3D58A9A4AF33A ] CmBatt C:\Windows\System32\drivers\CmBatt.sys 22:48:41.0661 0x3e08 CmBatt - ok 22:48:41.0676 0x3e08 [ F03BD81B9F81EE845D790B55417CD0AA, C8C5B83285BF70AC7A8585C06F46A66D746BA3CBE5E0D0CC743E4E01069E5029 ] cm_km C:\Windows\system32\DRIVERS\cm_km.sys 22:48:41.0676 0x3e08 cm_km - ok 22:48:41.0692 0x3e08 [ 1AB617F49EC6AC6CC45FD13E82F4A579, 4F4B37AACE534071C8D7A4B29FFF2EFD4071C5F4DE9554E3708C5BEEE58BFF8C ] CNG C:\Windows\system32\Drivers\cng.sys 22:48:41.0692 0x3e08 CNG - ok 22:48:41.0692 0x3e08 [ E1BFF774FF67CA951A5DFF0E104FB132, 68809C4B72C54CEDE3AD33F5634E15A0225A67B391F9012EC7CEBA8AFC6EC3D5 ] cnghwassist C:\Windows\system32\DRIVERS\cnghwassist.sys 22:48:41.0692 0x3e08 cnghwassist - ok 22:48:41.0707 0x3e08 [ DFDAEDB857BC18764F0D8ECDCC3C1499, AE12E908BAF53C605A17A9FB1AFD6BFBEC75EBE45D893541281473C197C71FED ] CompositeBus C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys 22:48:41.0707 0x3e08 CompositeBus - ok 22:48:41.0707 0x3e08 COMSysApp - ok 22:48:41.0723 0x3e08 [ 04532711732BE9DBC364E88E4A9EC18A, FCEB1F486E146A3FE7307397C1EB6760BFD8A327545F81C546F7134B08615B9E ] condrv C:\Windows\system32\drivers\condrv.sys 22:48:41.0723 0x3e08 condrv - ok 22:48:41.0739 0x3e08 [ 45E027357EB67E29DA732463FE0B6074, 5097151C35BD7E3B9381751AFFF01014624375A479044F761108267F6B8BFB06 ] CoreMessagingRegistrar C:\Windows\system32\coremessaging.dll 22:48:41.0759 0x3e08 CoreMessagingRegistrar - ok 22:48:41.0761 0x3e08 [ 1F7F1A15B807BC7B241BB2FEEA79BC92, D756E2247757C274F3470B46FCDBB63317C05E8E66FDA9DB7ABF3A6820933D4C ] CryptSvc C:\Windows\system32\cryptsvc.dll 22:48:41.0761 0x3e08 CryptSvc - ok 22:48:41.0777 0x3e08 [ EFB2A77F0CD1B8A79899C1D37B01CA86, 9FA32E0853FA93513ACA2CD4203DE8BC22268ABCA4BBDB366307C106F4FD5917 ] CSC C:\Windows\system32\drivers\csc.sys 22:48:41.0777 0x3e08 CSC - ok 22:48:41.0793 0x3e08 [ F010BDED808E86E1046F08865C11EDF2, 48FE0D176F7FA1F04685C0A1FD4FFB6464B6B88883D7D50E05C9C6C0636E895A ] CscService C:\Windows\System32\cscsvc.dll 22:48:41.0808 0x3e08 CscService - ok 22:48:41.0808 0x3e08 [ F51953EC4B9AACD92A3B3CE66E05CEF4, D39C9696213F53F89209000F245AC178B342A84E46EE766B634BB8DB86A26BB8 ] dam C:\Windows\system32\drivers\dam.sys 22:48:41.0808 0x3e08 dam - ok 22:48:41.0839 0x3e08 [ AA7F1C36F5BC779964CFA4F98D224D9F, 6DAF4FCE696B1D6A76E127A905C158724B13C20D2AA0F460F6C2E747E9525D98 ] DcomLaunch C:\Windows\system32\rpcss.dll 22:48:41.0861 0x3e08 DcomLaunch - ok 22:48:41.0861 0x3e08 [ 1175E107082287A58A756239F48E1A73, 0DB2017061D94FAC95CEBD7C4729E42018A92698D72CEE3EA412A9D14DB8D552 ] defragsvc C:\Windows\System32\defragsvc.dll 22:48:41.0877 0x3e08 defragsvc - ok 22:48:41.0893 0x3e08 [ BBCAC50027D030E07EC7E5C36469FAFF, FEF39659F21D2AE676E4882FBAF5A881C534BB7EA26E5EFF9F7B5F8B952D6532 ] DeviceAssociationService C:\Windows\system32\das.dll 22:48:41.0893 0x3e08 DeviceAssociationService - ok 22:48:41.0893 0x3e08 [ A2BACEBAC01BE7A6656B454E75C23262, C2C168718A341D48679AC4CA8005BD06E9F1F0D1F7C72D3C30A7A8CE1F665A43 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll 22:48:41.0893 0x3e08 DeviceInstall - ok 22:48:41.0908 0x3e08 [ 5B84093D490A6B060C8BE60BA52C876F, D34A854418A66529B18313A50E6D7EAB982611AD9AB0335245AE764FE0602C22 ] DevicesFlowUserSvc C:\Windows\System32\DevicesFlowBroker.dll 22:48:41.0924 0x3e08 DevicesFlowUserSvc - ok 22:48:41.0924 0x3e08 [ F08F70BBD833BAA3BF0D5E500CBEE6CC, 8BB99E6D96CB8B25036549030986EC267C26BF1FC66E4EB00A3E41FE3BB5DE70 ] DevQueryBroker C:\Windows\system32\DevQueryBroker.dll 22:48:41.0924 0x3e08 DevQueryBroker - ok 22:48:41.0939 0x3e08 [ 185A4519B7764F4DEF714D890A7A9FD2, 9805D9DB42D11582583EA3F0FFEE9EF2B0C536DA99A9A3D3863B2669B1CC34A7 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys 22:48:41.0939 0x3e08 Dfsc - ok 22:48:41.0939 0x3e08 [ BC5188B3F35BB8070888441A2A740465, 05C18A3DC1BD96C6751E76DBF57C47E526A1F9DF5E013B20B69EA0159CD6CE56 ] Dhcp C:\Windows\system32\dhcpcore.dll 22:48:41.0956 0x3e08 Dhcp - ok 22:48:41.0961 0x3e08 [ 5DF493C7954890EEC65CC2A21D479F76, 67087AAAC2AF93F265077AA392444E32DC299918A843A8AECFBE73636A5F2314 ] diagnosticshub.standardcollector.service C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe 22:48:41.0962 0x3e08 diagnosticshub.standardcollector.service - ok 22:48:41.0993 0x3e08 [ 9B844411D91C9BF616D2BCD91CC20723, 78C57216B4350E0AB4957423737FEE48B04A6D3C9F6BAF1A998D0FC1BD78ED17 ] DiagTrack C:\Windows\system32\diagtrack.dll 22:48:42.0024 0x3e08 DiagTrack - ok 22:48:42.0040 0x3e08 [ 1203EA16F36C5BEB2509FB7CC03DC178, 195209CB711E5BDE24A50C88AA62F32E8AE26F6A83B423374FCA41444F55D1CE ] Disk C:\Windows\system32\drivers\disk.sys 22:48:42.0040 0x3e08 Disk - ok 22:48:42.0056 0x3e08 [ 8BCFD0A4900E197DFA8679A13128EC79, DF09F3996F25F025E171DF3EF068BB9AC2DEC79BFCBCA5D58E9158CD7AD785B6 ] DmEnrollmentSvc C:\Windows\system32\Windows.Internal.Management.dll 22:48:42.0062 0x3e08 DmEnrollmentSvc - ok 22:48:42.0062 0x3e08 [ 038B8B76284BC291EC75B005BB3EB13F, FE7BD7CF833C4A96ABF4FD6EBAB829CC4D8096780A22A313035D7E49BBA12D36 ] dmvsc C:\Windows\System32\drivers\dmvsc.sys 22:48:42.0062 0x3e08 dmvsc - ok 22:48:42.0078 0x3e08 [ 32C76DFE2586EBECFFA4112E9196591C, 190C294F50B96B13D0B776F7C19DCB47EAACBEE999CBA50236CF8C856CF38B17 ] dmwappushservice C:\Windows\system32\dmwappushsvc.dll 22:48:42.0078 0x3e08 dmwappushservice - ok 22:48:42.0078 0x3e08 [ 8FD84F504BFD27FA9261B33F39737E5A, EE73EDA1314680C15C22A2EC65756677E805C7F2F7C5C01543CDD3D68F96F79F ] Dnscache C:\Windows\System32\dnsrslvr.dll 22:48:42.0093 0x3e08 Dnscache - ok 22:48:42.0093 0x3e08 [ F08CB37830A1F9950E8B2F7B1F78CC7E, E4E75645893597F6A02B98DC4F126A664F5DEF7B1CD4C2DEE5CA8ED18DB64C9C ] dot3svc C:\Windows\System32\dot3svc.dll 22:48:42.0109 0x3e08 dot3svc - ok 22:48:42.0109 0x3e08 [ 3425E26D0A7792F2EE7745C0336C2062, 54A3AFFC31C2641BCE1877F2CBA61D2CD7191BA39FD5B3659491E4E307570C1E ] DPS C:\Windows\system32\dps.dll 22:48:42.0109 0x3e08 DPS - ok 22:48:42.0125 0x3e08 [ 3D934A1C02EB6979CF45C70A71F580EC, 279B325E18ABF82FF523095D8D5958A3A48C7B7A4F64BD562DDED1D0662B608A ] drmkaud C:\Windows\System32\drivers\drmkaud.sys 22:48:42.0125 0x3e08 drmkaud - ok 22:48:42.0125 0x3e08 [ 5E92CB292D676634058E6C62653C9227, CE35C51B444664641306B4C2E21978B3418B58B2A973B19B908D86FE723FB4C4 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll 22:48:42.0125 0x3e08 DsmSvc - ok 22:48:42.0141 0x3e08 [ E479C2656A3A47F5D4FAD10AE6EAED52, B17D18D5440CF131EEADA385989A8ED0DB7728CAAC4E745720947DD1BC4F9EF6 ] DsSvc C:\Windows\System32\DsSvc.dll 22:48:42.0141 0x3e08 DsSvc - ok 22:48:42.0157 0x3e08 [ B8349B4988FD36D3885B877F822E1DF8, 7405A5D8A85BACD09EC2954019E8E171316605EE43544F63546821B6D104856E ] DusmSvc C:\Windows\System32\dusmsvc.dll 22:48:42.0162 0x3e08 DusmSvc - ok 22:48:42.0193 0x3e08 [ 0D459B3B6BC1318699992DCAA4BD76C6, 76AD8A3B18B447941489BE1D85FF39986CA49E25503F5D3EF0EE4B6789DF5110 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 22:48:42.0225 0x3e08 DXGKrnl - ok 22:48:42.0240 0x3e08 [ ECA1628436628362856ACF239E6AFD29, 19051DC348918B863E0A272CF56891B8CB49E7E705B8BAC7663D36C797A7B962 ] EapHost C:\Windows\System32\eapsvc.dll 22:48:42.0240 0x3e08 EapHost - ok 22:48:42.0295 0x3e08 [ D64CD3AE93125EDA383190C2AF607E70, 3D180B96C6A2318842FA03AE5F703320A93CF1F440FF7D0E6F6F9BAD98F2FA02 ] ebdrv C:\Windows\system32\drivers\evbda.sys 22:48:42.0342 0x3e08 ebdrv - ok 22:48:42.0342 0x3e08 [ BA909DA3D184EF80F9293AB9E12FF30F, 5C9BB19D447698F4EAE8D9A26548703C4B8B6FEB68D49E6F2516666E5226236A ] EFS C:\Windows\System32\lsass.exe 22:48:42.0358 0x3e08 EFS - ok 22:48:42.0362 0x3e08 [ FFBB37982E6D24AEC7A2E5459098EAC9, E89DD74540088ECAC9E802D7A059C0A6E3E5412BD42E5E9F26258724458EF8DB ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys 22:48:42.0362 0x3e08 EhStorClass - ok 22:48:42.0362 0x3e08 [ ABF38D02E01D6ED87AE1DF65FC5DF62D, 57D48609DA30F60016D2ADEB9A772942FB39A117247EB63FAE3FCF50D726B698 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys 22:48:42.0362 0x3e08 EhStorTcgDrv - ok 22:48:42.0362 0x3e08 [ 5E4AB60D50F368A09275F4055D621EDC, C840F5DF3C0813EC6CB9BA0C3C91F2C6410227A6255DEF5FA94C8AC1E43E36A0 ] embeddedmode C:\Windows\System32\embeddedmodesvc.dll 22:48:42.0362 0x3e08 embeddedmode - ok 22:48:42.0378 0x3e08 [ CA966CED8970A60FB00A3592564EF093, 4BD904032445235EE69DAA0024E0FB3D8B2325D897A683E334754EB3CA90AB39 ] EntAppSvc C:\Windows\system32\EnterpriseAppMgmtSvc.dll 22:48:42.0378 0x3e08 EntAppSvc - ok 22:48:42.0378 0x3e08 [ B9A59B4AD516E38C39FA416398B96CCB, 4630A9AD414476B47F634F2EB5659597797222A8938B68847B97FECCE1A1B5F8 ] ErrDev C:\Windows\System32\drivers\errdev.sys 22:48:42.0378 0x3e08 ErrDev - ok 22:48:42.0394 0x3e08 [ 1541374239F33512D7F4D24ED1E9238C, 8B1548D4052A72175EB6ADA9FD4286ACD5041E1CE071DCAC3760BB227FCD3621 ] EventSystem C:\Windows\system32\es.dll 22:48:42.0409 0x3e08 EventSystem - ok 22:48:42.0409 0x3e08 [ 9C4D88E8614487AD85A6F18A71A7298F, EE6F48C89D6379C7361484EAE7C7FAAA477D48032BFDD0D363E48642E62EADF4 ] exfat C:\Windows\system32\drivers\exfat.sys 22:48:42.0425 0x3e08 exfat - ok 22:48:42.0425 0x3e08 [ C61014A176ECAAF97589E6FC979CE786, FB913AC647B68DB9854367BB1E53A504A85833966211279C8D7171698F743B27 ] fastfat C:\Windows\system32\drivers\fastfat.sys 22:48:42.0425 0x3e08 fastfat - ok 22:48:42.0440 0x3e08 [ ECC5AEFEA31F1A078E954305B8CA6373, 15948D017E3B52D3B4BBEC047F963BD77247E24A59F0532B6A023B0C4159FC84 ] Fax C:\Windows\system32\fxssvc.exe 22:48:42.0461 0x3e08 Fax - ok 22:48:42.0462 0x3e08 [ 853081957BA148F38FD8DE4390CFCF4A, 37C92C7ABA55A5FF7094F77F8EBEEE1F4BEE161CEC6B01A50FC0D0C39E36C142 ] fdc C:\Windows\System32\drivers\fdc.sys 22:48:42.0462 0x3e08 fdc - ok 22:48:42.0462 0x3e08 [ 885C06C35CC8FAEDDE3CDA36B72CA2A9, FF6584E7AF2FB540B2183665C3E216BE98DE953CEA6A7E4C5F13514BE4AAC9D3 ] fdPHost C:\Windows\system32\fdPHost.dll 22:48:42.0462 0x3e08 fdPHost - ok 22:48:42.0462 0x3e08 [ 367E878C79D9F391E3D53B6BBC1B6386, 739D89F6954E17B73F53702CFF8EE985FB241255D962A83BAF1A20E783CAF466 ] FDResPub C:\Windows\system32\fdrespub.dll 22:48:42.0462 0x3e08 FDResPub - ok 22:48:42.0462 0x3e08 [ 514F6A0B83527DD6ACCC8B21A57B10E3, EA3D401E42D05BA39E5874513DFB895A086BECE4D69FC1AC12F85F326A435A4B ] fhsvc C:\Windows\system32\fhsvc.dll 22:48:42.0478 0x3e08 fhsvc - ok 22:48:42.0478 0x3e08 [ 27E764D6460504B7271AFECE7A59FB76, A32B08142068BF042B3E47C0CA7F4FCFD07A37807B1B8DAAE614F3A132475D52 ] FileCrypt C:\Windows\system32\drivers\filecrypt.sys 22:48:42.0478 0x3e08 FileCrypt - ok 22:48:42.0478 0x3e08 [ 3D6087F51110F3CC0DA89385354F8C5E, 49FF976C3391A257BCD4B048BF6D1273F8537005E32D65E5F272AF3294639F05 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 22:48:42.0478 0x3e08 FileInfo - ok 22:48:42.0478 0x3e08 [ 057E95E53C38260C4EF49B3A077770CD, 7008E71663046FF1D91D9DC3570094561C812067E1CA07715A1D2E4F787207AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys 22:48:42.0478 0x3e08 Filetrace - ok 22:48:42.0494 0x3e08 [ 90B2983D8495C26345A1DC5F0C3BB07B, 50D834D40C27EEF5023556A77B13D3335789333E302A73DF221CD86D156FDEE9 ] flpydisk C:\Windows\System32\drivers\flpydisk.sys 22:48:42.0494 0x3e08 flpydisk - ok 22:48:42.0494 0x3e08 [ A84261F75F490E45CFEDBA77EFE4F67E, 292BA04D8996140255E4B6105015C2A640890BEFB6C022E30E0D9CBF45D5F4DB ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 22:48:42.0509 0x3e08 FltMgr - ok 22:48:42.0541 0x3e08 [ CBCD52EFAA9777B7D23DC6AC66CA5BB5, 7CE23F50503CCD1AD8EB50EFF17294F7E281EF7167A6045445742960BC007FCA ] FontCache C:\Windows\system32\FntCache.dll 22:48:42.0562 0x3e08 FontCache - ok 22:48:42.0562 0x3e08 [ B282011D13BBEEA0273DF33C5E776D55, B4AF068BBB09D0F546F5590FCDD745250CFD58DD3A8ABF5DC26670FA32D181FB ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 22:48:42.0562 0x3e08 FontCache3.0.0.0 - ok 22:48:43.0360 0x3e08 [ A74399028A43A1FC93D960AB75A8371B, 8CB2551CB8C15C3D000DDB4A3E673DBAFB59E95DFD9F7879E5DD4FFE62F40946 ] FoxitReaderService E:\Programme\Foxit Reader\FoxitConnectedPDFService.exe 22:48:43.0380 0x3e08 FoxitReaderService - ok 22:48:43.0396 0x3e08 [ 58811D00A582A89B7839B4B2CE7302BE, D2B6C197BD257B462FC3E8E7A8E7C3F910282FDAA61DB00ADB64DA0698C203C7 ] FrameServer C:\Windows\system32\FrameServer.dll 22:48:43.0396 0x3e08 FrameServer - ok 22:48:43.0396 0x3e08 [ D2814848206DFC18EB8D3D069FAE703E, A62263CDF9261B692423473F4FF23B01AC864C05850BA5591EB9019906B4A08B ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 22:48:43.0396 0x3e08 FsDepends - ok 22:48:43.0411 0x3e08 [ AE7EDF845F41ACA3B74567C3CE20E987, 6159C227C85912B03D8C35A1EF91705AE6C1C23C7228D6FCC0A9529844798E1B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 22:48:43.0411 0x3e08 Fs_Rec - ok 22:48:43.0427 0x3e08 [ 7C14404ADEF7D6F1D4D5346CF1849DDC, B8B44F3630A9A63F3E80D1A28BFEECC2372D75B68E25749B858EAD612FB784A4 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 22:48:43.0427 0x3e08 fvevol - ok 22:48:43.0481 0x3e08 [ F8B426A185DD67689BAAFACA0076274A, B2DD0896FE2D7BE89456B562F087FC5141AA83E7D969F7576D6803BE87242564 ] GalaxyClientService D:\GOG Galaxy\GOG Galaxy\GalaxyClientService.exe 22:48:43.0481 0x3e08 GalaxyClientService - ok 22:48:43.0612 0x3e08 [ 7BBCFBA5CE2B7AC13BC5B3A44F1AC161, 21955A6234FF773A787DA8C3D6A5CC23231F8793AE124CA3010C43F84F649738 ] GalaxyCommunication C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe 22:48:43.0732 0x3e08 GalaxyCommunication - ok 22:48:43.0743 0x3e08 [ 4616F61E24B3AEA6E0E4EA7D69531EF4, 34CB16F68E4A4D19346C7FEC29BB5FE09BAAEC19EA730C9B93450F940D124D49 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys 22:48:43.0744 0x3e08 gencounter - ok 22:48:43.0747 0x3e08 [ 23174BB6937459B924BB8EF667FB28EF, 6675B87F4DE9CCA96B6BAB9F77C4E0B377828613D9FFB03F7D443AF11321F157 ] genericusbfn C:\Windows\System32\drivers\genericusbfn.sys 22:48:43.0748 0x3e08 genericusbfn - ok 22:48:43.0753 0x3e08 [ 4B11CFBE1D9B73A9D865F6AB26F800BA, BD76CB5AF0EE6DD404875A4C36622C6BC8CCF2975C47E28DD305EB041C6C0B91 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys 22:48:43.0755 0x3e08 GPIOClx0101 - ok 22:48:43.0771 0x3e08 [ CF22C0941409C772AA1568DC4F89A111, ED5895F024E64B672EB3FAE6C456FA0D30A068CF2B475A7EE988DEA4DCD6D8DE ] gpsvc C:\Windows\System32\gpsvc.dll 22:48:43.0786 0x3e08 gpsvc - ok 22:48:43.0786 0x3e08 [ 3FC3FCF557D0BE3D724EA10642E1F6FF, 744D0DDE748A1B681087668CB893F9A60A2BBE80A71098944E75B6A9AA934C82 ] GpuEnergyDrv C:\Windows\system32\drivers\gpuenergydrv.sys 22:48:43.0786 0x3e08 GpuEnergyDrv - ok 22:48:43.0802 0x3e08 [ 0545A3EB959CFA4790D267BFB8C1ACA4, 69061E33ACB7587D773D05000390F9101F71DFD6EED7973B551594EAF3F04193 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:48:43.0802 0x3e08 gupdate - ok 22:48:43.0802 0x3e08 [ 0545A3EB959CFA4790D267BFB8C1ACA4, 69061E33ACB7587D773D05000390F9101F71DFD6EED7973B551594EAF3F04193 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:48:43.0802 0x3e08 gupdatem - ok 22:48:43.0818 0x3e08 [ BF14976E8223D334B21792FB8B74D7FF, 0939B6605E9BCE2EC888AF3F3DA953351AB56E993B2C8BC6A6DC577D287811FD ] HdAudAddService C:\Windows\System32\drivers\HdAudio.sys 22:48:43.0818 0x3e08 HdAudAddService - ok 22:48:43.0833 0x3e08 [ 02B9639D9997E95CDF2F4C4F3BDCC73D, 612F472A72E44199E0B1ECEE6FF2836359039402212CBD26D1A1CDDAC61052A9 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys 22:48:43.0839 0x3e08 HDAudBus - ok 22:48:43.0843 0x3e08 [ 9F90819E301C70A3A042FC05D3E41B5F, D2175786775D08686264001ABAA4B61DC08A847666F6B9A2A64D10BFC022F646 ] HidBatt C:\Windows\System32\drivers\HidBatt.sys 22:48:43.0843 0x3e08 HidBatt - ok 22:48:43.0848 0x3e08 [ 1FE8E2676CD512181F84B27EE86CE29C, C694918ABD6533C04CF1F48A0ACB279391B020B3842AB47E7F1402DCC2DBA7BB ] HidBth C:\Windows\System32\drivers\hidbth.sys 22:48:43.0850 0x3e08 HidBth - ok 22:48:43.0853 0x3e08 [ 55DAF856F9633DD2519BA4E942870F02, 5283548CB93EB46C5FD3B08E45C97BBFB33D47F11F89560508775889FBF2F754 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys 22:48:43.0854 0x3e08 hidi2c - ok 22:48:43.0855 0x3e08 [ E34216A190D9BF8EAA666F6903BCD0EF, DA8529DAF903B447CC5FF2D112F670696549A4B66F54DF9A8C8C615D969CD477 ] hidinterrupt C:\Windows\System32\drivers\hidinterrupt.sys 22:48:43.0855 0x3e08 hidinterrupt - ok 22:48:43.0855 0x3e08 [ 852DBB5185996AD8C73872A43A453729, 8C20331AE99E280799407CC5FCF88F8F645C331604230876A2CD7C253B9BD633 ] HidIr C:\Windows\System32\drivers\hidir.sys 22:48:43.0855 0x3e08 HidIr - ok 22:48:43.0855 0x3e08 [ 6339CC87F0F610D1575C9A419940602A, B2A054ED0B669FA54E250EC2926955B1D944FA1FB2AF5B590C181CB2E9D297BA ] hidserv C:\Windows\system32\hidserv.dll 22:48:43.0855 0x3e08 hidserv - ok 22:48:43.0871 0x3e08 [ C1A608120DE0DF52E51B8BAF86AF19F9, F3529822E78CFCA2E323A75926A833529889E40BB9602B287CC343C496CB2062 ] HidUsb C:\Windows\System32\drivers\hidusb.sys 22:48:43.0871 0x3e08 HidUsb - ok 22:48:43.0871 0x3e08 [ BD1CF47172B97707DFC66ADA741AE2BE, 9607AB7074FC54D88FDF6E2A31506BCF8ECBF8FD651BB5CEA2421471C24BCED1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 22:48:43.0871 0x3e08 HomeGroupListener - ok 22:48:43.0886 0x3e08 [ A004895B838003BAE2281DAF193B6A09, 587FCDCEF769B2AED12551B6426477B764CB8A025E692D4EC8B24E1CBA1C06E3 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 22:48:43.0886 0x3e08 HomeGroupProvider - ok 22:48:43.0902 0x3e08 [ 8ADD9CA3E0F18CEA11EA6FAED794A228, B46BA885ED8253A253B1C87C331CA145F7F397AF49853038B3F1EDAF81B2C4BA ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 22:48:43.0902 0x3e08 HpSAMD - ok 22:48:43.0918 0x3e08 [ BB1AE72906564A6E81B79D73A05AE21F, 9BAC18FE0F99479E7B2AB804A0B4C286E55155A8C051CC7D20CE94798EEA0721 ] HTTP C:\Windows\system32\drivers\HTTP.sys 22:48:43.0933 0x3e08 HTTP - ok 22:48:43.0933 0x3e08 [ D3C45F1B5BB3EE772CDA416A4A3EEB9B, 97CD988CF307EBCC34F37F130F4F2C989DD17E70B2498DB1929B566A3387887B ] HvHost C:\Windows\System32\hvhostsvc.dll 22:48:43.0933 0x3e08 HvHost - ok 22:48:43.0951 0x3e08 [ F60F8390B635156593F7493AE898AFB0, AC5E58CDA12072C5FDBFEA0FA009CE2E251D143FC0878B2658ECCCF797B8B0EC ] hvservice C:\Windows\system32\drivers\hvservice.sys 22:48:43.0953 0x3e08 hvservice - ok 22:48:43.0955 0x3e08 [ 563F5FC3B46A70A91AB6C8822AC8BF25, 43E647A7752D7444BF306E38571130AB778AA2A6892782C6C1112E47FBEFBC87 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 22:48:43.0955 0x3e08 hwpolicy - ok 22:48:43.0955 0x3e08 [ C082249BC3E972C8A132D9EC6AD9EAD5, D69EEFD97CF5E0BD64D11DE1C331D02A9BE522BB93A40FF32ED434D960B85D39 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys 22:48:43.0955 0x3e08 hyperkbd - ok 22:48:43.0955 0x3e08 [ C6C8315E3262FAE460529C6DA2951682, 4ADBFA6601209BF6F5A9797721CBE2011905775CF4E266D7B42F89915D477E95 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys 22:48:43.0955 0x3e08 i8042prt - ok 22:48:43.0971 0x3e08 [ C6B8743B213F06AA60943D8366FE968F, 758954F70B810063914B243115B2C753B2BCE40190F95C30ACBA0BF04EBD5B33 ] iagpio C:\Windows\System32\drivers\iagpio.sys 22:48:43.0971 0x3e08 iagpio - ok 22:48:43.0971 0x3e08 [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c C:\Windows\System32\drivers\iai2c.sys 22:48:43.0971 0x3e08 iai2c - ok 22:48:43.0971 0x3e08 [ 42962355A7911407026E920E7252E3E5, 4A4016A53ED61354C81C594968339E6F3CCCFF4A64F8F28AD008ED8137E05AD2 ] iaLPSS2i_GPIO2 C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys 22:48:43.0971 0x3e08 iaLPSS2i_GPIO2 - ok 22:48:43.0971 0x3e08 [ BD47B2FEABFA48C6224D43EE9EA9BC06, 304628CA458AA7B1B8B1CFF12074AD75C1CE7BD41820B99607D7FA99A817D007 ] iaLPSS2i_GPIO2_BXT_P C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys 22:48:43.0986 0x3e08 iaLPSS2i_GPIO2_BXT_P - ok 22:48:43.0986 0x3e08 [ 2184CB3A65888F446FCD6DBA9F073F4C, 0B3D63EC7F61BFAD490C123084965A9F38DBFE587AC9DAE6F4E6B68AD8093DB2 ] iaLPSS2i_I2C C:\Windows\System32\drivers\iaLPSS2i_I2C.sys 22:48:43.0986 0x3e08 iaLPSS2i_I2C - ok 22:48:43.0986 0x3e08 [ 4126F8DA08CE7924A3AE6F7235F85D5F, 668DC1D09496A95F44C07C5C1F6ED7D3EFC6F89523B2744A86B460E5BECAEFB5 ] iaLPSS2i_I2C_BXT_P C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys 22:48:43.0986 0x3e08 iaLPSS2i_I2C_BXT_P - ok 22:48:44.0002 0x3e08 [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 22:48:44.0002 0x3e08 iaLPSSi_GPIO - ok 22:48:44.0002 0x3e08 [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C C:\Windows\System32\drivers\iaLPSSi_I2C.sys 22:48:44.0002 0x3e08 iaLPSSi_I2C - ok 22:48:44.0018 0x3e08 [ D820075D3395BED28FC57AEF8FBA666F, 7589CCCD355D2685C0E6D317AB39F0DB061153E6859A0F53834B001643CFDF57 ] iaStorAV C:\Windows\system32\drivers\iaStorAV.sys 22:48:44.0033 0x3e08 iaStorAV - ok 22:48:44.0045 0x3e08 [ A243E0CE8644378C9A9D015ABC3EDA27, 0C72F6D39DD64A16F54BCE185F4D8E670D386823F6364E9ED284F7F8DE11CBF5 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 22:48:44.0051 0x3e08 iaStorV - ok 22:48:44.0055 0x3e08 [ E16E4FC9F250E48CB2CAD93E59D010E2, EFF558EDD63DB0FD8BA240E94BD5999106233B95BF86BFB99EE9B897F41C542B ] ibbus C:\Windows\System32\drivers\ibbus.sys 22:48:44.0055 0x3e08 ibbus - ok 22:48:44.0071 0x3e08 [ 0AB34B5C5AE21C43E40F81EE7214DC71, 4D283E1264A52408195FD0D27DA8FE443C60784AF87E7C881D62F3568E5C1B5B ] icssvc C:\Windows\System32\tetheringservice.dll 22:48:44.0071 0x3e08 icssvc - ok 22:48:44.0086 0x3e08 [ E9E4BB312F6B544392F44D513FAA2243, 3E6917BCE9F1AF554D57FED9E76B33F36D92145B0090A5F8F64E2A53EB4C54A4 ] IKEEXT C:\Windows\System32\ikeext.dll 22:48:44.0102 0x3e08 IKEEXT - ok 22:48:44.0118 0x3e08 [ 0E33BC018502E7FDE77C343055D9C626, CD1C60E8EDAA044E03E5776962E091C1288204033A57A799D446F9B058D6AD59 ] IndirectKmd C:\Windows\System32\drivers\IndirectKmd.sys 22:48:44.0118 0x3e08 IndirectKmd - ok 22:48:44.0118 0x3e08 [ 4B7F8A1AAC7172DB6918A0E10E1D78A3, 1E9922AF9B5458F23A379EDCD61B615B6E53BAF8927237C1C7DCC04122CCF417 ] intelide C:\Windows\system32\drivers\intelide.sys 22:48:44.0118 0x3e08 intelide - ok 22:48:44.0118 0x3e08 [ 0A3DBE89C965FFB7C0D0E38834E77B90, 0166BE79228ED6B3D7AA1BACB4F1BB68357DBF70DF778B2F8A3776E374EE690C ] intelpep C:\Windows\system32\drivers\intelpep.sys 22:48:44.0118 0x3e08 intelpep - ok 22:48:44.0133 0x3e08 [ 64EC687A811DC4F69DF3816F073352AA, F70942B67448DF9848F32F88D37E1E0C548CE9FEFC4376628D7CBEF62494D8E1 ] intelppm C:\Windows\System32\drivers\intelppm.sys 22:48:44.0133 0x3e08 intelppm - ok 22:48:44.0133 0x3e08 [ 549C278119FF539C3B219C55B98B0E87, B4C15AB0C77EAB6C5ADEBD014F610BBFC537EAEB0E3960636624001C8A5DE56E ] iorate C:\Windows\system32\drivers\iorate.sys 22:48:44.0133 0x3e08 iorate - ok 22:48:44.0133 0x3e08 [ A0F9F2E87F0C751FE164D90EB44A9B63, BE816F17E43E5F80AC65E913AB7F9E77B8D6B70B90A784CB00C907D3DAFFD4DB ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:48:44.0133 0x3e08 IpFilterDriver - ok 22:48:44.0155 0x3e08 [ 16DBEB4BBB9A79490D772F136FF9696E, C4246BAD502D333B5E76520C9F2AD09CF00719341FD9C522FD76DDBD911AE125 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 22:48:44.0171 0x3e08 iphlpsvc - ok 22:48:44.0187 0x3e08 [ 656DDB34996A96539BA6E2843B5F2A77, EDC3F1A2BA38A9655361A20B6C8001984AEB1A530C5385CF6EC0AF595305DBC7 ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys 22:48:44.0187 0x3e08 IPMIDRV - ok 22:48:44.0187 0x3e08 [ DCC05E5EAA580C97F13B434FAFACED85, 5C6CFD3D9FAEB7274E05F3D19D3AA064624500C616650DE227B849B505662BB4 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 22:48:44.0187 0x3e08 IPNAT - ok 22:48:44.0202 0x3e08 [ 0D284906206F065D069939EB04184E29, 18607315138028D4F629CCD358CA50159BD573A6965574C3B5232FC4077C9293 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 22:48:44.0218 0x3e08 iPod Service - ok 22:48:44.0218 0x3e08 [ 9A6B993A95CCA15502DE3C980508DC44, 370A1A4531A72CFBF331ED274913925A269115A13E3A6B5E1821FB48DD7242AE ] IpxlatCfgSvc C:\Windows\System32\IpxlatCfg.dll 22:48:44.0218 0x3e08 IpxlatCfgSvc - ok 22:48:44.0233 0x3e08 [ 9035C10C7EB8CF7C87CEA82A62EBB43A, A0DA94E80E503DB3C2877CE1BCDC70B3FCC6861ADFBCCE66C6D2592BD63F27DC ] irda C:\Windows\system32\drivers\irda.sys 22:48:44.0233 0x3e08 irda - ok 22:48:44.0239 0x3e08 [ E7FD479E3298F3C8852A0D2F092BDB35, 07F2E779268EBBF4F32ED1C8423493B36BA823905E71B524C6AEBA0093193307 ] IRENUM C:\Windows\system32\drivers\irenum.sys 22:48:44.0240 0x3e08 IRENUM - ok 22:48:44.0243 0x3e08 [ 65B145143F6E5E1B5A213F0D9F4C4C44, 0E390BD8D7B4B9562E8FEE0D109DCE0D9EA823FD2D20B39FFACE3331F30FE5BC ] irmon C:\Windows\System32\irmon.dll 22:48:44.0244 0x3e08 irmon - ok 22:48:44.0248 0x3e08 [ 7FE3B3A30FA20F27AF7022A01C2266BA, 8AB924F08ABF1DCB154B6A3BDB7E3E5A863008B5AFF8E3DB9759848774E00E8A ] isapnp C:\Windows\system32\drivers\isapnp.sys 22:48:44.0249 0x3e08 isapnp - ok 22:48:44.0255 0x3e08 [ 618707F3F742BF67AB578808171F60EB, AC9322483A450856B60F61D0CC58380148C52451863364C6FF3A2FAB4173A7A5 ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys 22:48:44.0255 0x3e08 iScsiPrt - ok 22:48:44.0255 0x3e08 [ D36B404BF979297C6572AEF98B2594F2, CB2F4E6589936D35D59CA70B39A29D091540EA125BE4B937AF92CEA0C6D0AAEB ] kbdclass C:\Windows\System32\drivers\kbdclass.sys 22:48:44.0255 0x3e08 kbdclass - ok 22:48:44.0255 0x3e08 [ 7E2036A846789D6D6A2EE21915017EE1, 82AF85CA30B440E453F7694C7EDABB5D2DB213AD2FE8620B92667DFB492229A1 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys 22:48:44.0255 0x3e08 kbdhid - ok 22:48:44.0271 0x3e08 [ 4C054B8E901F41F5743DADE8A29FF256, 1009CC2503E08AFEA849BA83135C2D75C573FC4D6EFB5DBCDCC7ACB17AF83152 ] kdnic C:\Windows\System32\drivers\kdnic.sys 22:48:44.0271 0x3e08 kdnic - ok 22:48:44.0271 0x3e08 [ BA909DA3D184EF80F9293AB9E12FF30F, 5C9BB19D447698F4EAE8D9A26548703C4B8B6FEB68D49E6F2516666E5226236A ] KeyIso C:\Windows\system32\lsass.exe 22:48:44.0271 0x3e08 KeyIso - ok 22:48:44.0287 0x3e08 [ 025177EB96DDB40DBA3CD003AD54D90B, 68228990816781D79511FF72CBD47434980F979FB6A31742DB4000756E242333 ] kl1 C:\Windows\system32\DRIVERS\kl1.sys 22:48:44.0287 0x3e08 kl1 - ok 22:48:44.0302 0x3e08 [ 1C80741440DE1F956AF6FE444C608DF1, 8D4C4670C355CA1F80291E1A78770727C4FE02A94B3EB2FC6D0B787007B09E32 ] klbackupdisk C:\Windows\system32\DRIVERS\klbackupdisk.sys 22:48:44.0302 0x3e08 klbackupdisk - ok 22:48:44.0302 0x3e08 [ 2A53CC105B6869F19CB38D35360714BE, 5EE0F75C863C9FAA52D9CC6D7A83C3FC3A37F8371DD968079C57D4A0F48CF495 ] klbackupflt C:\Windows\system32\DRIVERS\klbackupflt.sys 22:48:44.0302 0x3e08 klbackupflt - ok 22:48:44.0302 0x3e08 [ 7DAA9047F50BF5A3F8C147719FC520AF, 0740387075AF46DB1E9AEE3B12C65A06EDFE58EADB8B562C36CB1FEFF9905C26 ] kldisk C:\Windows\system32\DRIVERS\kldisk.sys 22:48:44.0302 0x3e08 kldisk - ok 22:48:44.0302 0x3e08 [ 7AD0CCE09BEBE47E578BDD567AAB4051, 2F2B1EDBE66EC757E84A9EA69EE35AF247349693E172044B0A14B906F8837FC0 ] klelam C:\Windows\system32\DRIVERS\klelam.sys 22:48:44.0302 0x3e08 klelam - ok 22:48:44.0318 0x3e08 [ 44AAFFCBD506C15ED27BD2FA85BED2FE, A9C6854E4D88AFA6FEA75FF1A8EB29F2BDEFCB731CB460756C5BE869A1FDB1AB ] klflt C:\Windows\system32\DRIVERS\klflt.sys 22:48:44.0318 0x3e08 klflt - ok 22:48:44.0334 0x3e08 [ 2EBE042FF7CC4774D653D762CC02B395, 5CD0D814CA7464B79D6D6F839CE93A49BFCF840DE9F60D98C8346CE1A3753E18 ] klhk C:\Windows\System32\drivers\klhk.sys 22:48:44.0334 0x3e08 klhk - ok 22:48:44.0355 0x3e08 [ CBB5017BA716E0FD44E950E9A1EF6825, 51667B8BD1B8B5407A766F3EAFD8FE389C79408EC03A6330A5AA8B9B855219E5 ] KLIF C:\Windows\system32\DRIVERS\klif.sys 22:48:44.0371 0x3e08 KLIF - ok 22:48:44.0371 0x3e08 [ 6357C533C30650361110DBAF59A25DF8, FA8CF6292CCBC7E23527D968E54CD773706CF091E35563B0CF9F8A1DF0B724B9 ] KLIM6 C:\Windows\system32\DRIVERS\klim6.sys 22:48:44.0371 0x3e08 KLIM6 - ok 22:48:44.0387 0x3e08 [ BCD71B7987E6A5DCECCDABE4B5C5675C, 28C4A363F9384C57E3FE502FD9BC5DD068E21E9376DB7A7C8B577E31C7DBA100 ] klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys 22:48:44.0387 0x3e08 klkbdflt - ok 22:48:44.0387 0x3e08 [ C8DCC1339A3E5548B09F439F28F4DF1D, 938EFACB6B82FEB0CA25C04E88B281A00F5190ED00EC45F76DB0757C9393C8C6 ] klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys 22:48:44.0387 0x3e08 klmouflt - ok 22:48:44.0387 0x3e08 [ C334FBE82E1ADE139FFCD43517378A4B, 10E2A6D8CEECEDAF31FD61FD2E8EA5F11FB20BC8D4EE0DB3290BBA324087FB58 ] klpd C:\Windows\system32\DRIVERS\klpd.sys 22:48:44.0387 0x3e08 klpd - ok 22:48:44.0387 0x3e08 [ ED9BCB990982C7D9AD7E98C1406B1D6D, 854D6A93DED4382FF5CB9B3FBC24335828949791DD405CE16822E25D65CF6799 ] klpnpflt C:\Windows\system32\DRIVERS\klpnpflt.sys 22:48:44.0387 0x3e08 klpnpflt - ok 22:48:44.0402 0x3e08 [ 828B042A95F055648DA190DF6C7AB1B6, 0457B0EF03BCB4CC1297EB25A25C162937F456BF406EC7B1A5E9A0AA13A9BCD7 ] kltap C:\Windows\System32\drivers\kltap.sys 22:48:44.0402 0x3e08 kltap - ok 22:48:44.0402 0x3e08 [ 097D722294B9C1FA6E514A088F2E6B6E, FB0492CAF45FDF7F656CFF6662309435679C946269577ECF76A3077B7D7F940B ] klupd_klif_arkmon C:\Windows\system32\Drivers\klupd_klif_arkmon.sys 22:48:44.0402 0x3e08 klupd_klif_arkmon - ok 22:48:44.0418 0x3e08 [ A7E26109DE0E310EEE5CFEEA9E821DCA, D81C23CA254F9B96AF59A719BE8F7FB822D6272CF9A8DADACAC39C24008FDC00 ] klupd_klif_kimul C:\Windows\system32\Drivers\klupd_klif_kimul.sys 22:48:44.0418 0x3e08 klupd_klif_kimul - ok 22:48:44.0418 0x3e08 [ 6A80ECDC10138AC34E48A4BE684E06F9, DF8BD9139B82614614D9E1B5DAEA74E4DF4D5CE95F11ED503FD3B8E07722A1CA ] klupd_klif_klark C:\Windows\system32\Drivers\klupd_klif_klark.sys 22:48:44.0418 0x3e08 klupd_klif_klark - ok 22:48:44.0434 0x3e08 [ EBC5ACF5F373981161752650BC17DD4E, 892A6758F5C7589D38A6A01D08F7B3F6D144591E0D3337C0E4B2CA9B66C70C37 ] klupd_klif_klbg C:\Windows\system32\Drivers\klupd_klif_klbg.sys 22:48:44.0440 0x3e08 klupd_klif_klbg - ok 22:48:44.0446 0x3e08 [ D0B29808F37C6F6373AB16B716D9A1F8, 82E5760F0A313E43E3B9AF44E2A811021B84E7954CB5DC1462C7033AAEA8AF4B ] klupd_klif_mark C:\Windows\system32\Drivers\klupd_klif_mark.sys 22:48:44.0448 0x3e08 klupd_klif_mark - ok 22:48:44.0455 0x3e08 [ 33C55B05B758AAD633F6C882063D79E9, 5D540F87F9468FB4EF00642B42A802227F90A97597A33573DCBAC0E10D42F466 ] klvssbridge64_18.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe 22:48:44.0455 0x3e08 klvssbridge64_18.0.0 - ok 22:48:44.0471 0x3e08 [ 2EA26701413436BEE7E305E1648AE0A8, 40994F04F71970BCFFEAFBAE08DE97207493E0E169B41AA344A9E943094ABFA6 ] klwfp C:\Windows\system32\DRIVERS\klwfp.sys 22:48:44.0471 0x3e08 klwfp - ok 22:48:44.0471 0x3e08 [ 8B5BBF778E34573848917D8A4835D377, F3321F72896A34F88EFEA9C4815352A0042B9C7857F08FC4E44DBAC77BABD48F ] Klwtp C:\Windows\system32\DRIVERS\klwtp.sys 22:48:44.0471 0x3e08 Klwtp - ok 22:48:44.0487 0x3e08 [ 67DED6469DC6024517B5A4337F44745D, CE890E95DA9EB239987735EB82F84529556085DF8E0B8DA34964F9B3A9F14244 ] kneps C:\Windows\system32\DRIVERS\kneps.sys 22:48:44.0487 0x3e08 kneps - ok 22:48:44.0487 0x3e08 [ 4DCE20849E789DC24A867E7D7B15CE5B, 0F6236E0F99709FF628DB0568E673DA80292874D78AB89CA6C3BB07E4813786E ] KSDE2.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe 22:48:44.0502 0x3e08 KSDE2.0.0 - ok 22:48:44.0502 0x3e08 [ 2B9F287EF4AAB936D1B92DCE46626631, C216E1039FA9D7B6C93ADB7C4448E877F6ECDE1EF1EE018A492C17134F236D98 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 22:48:44.0502 0x3e08 KSecDD - ok 22:48:44.0518 0x3e08 [ 6629CAA1F157088B9EDD1EAD24C6D753, 3E5F3BCB34F4B52BE46B96F9F720FE5FB37A01D4E408875F6BB89F5B5C5A3900 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 22:48:44.0518 0x3e08 KSecPkg - ok 22:48:44.0518 0x3e08 [ 9778205F28DC4F2EFFCC146647FE5CF0, 6B7EFFB08C7757A2830745920A624F89DBD5B323E0A884932FECF06471894F9D ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 22:48:44.0518 0x3e08 ksthunk - ok 22:48:44.0534 0x3e08 [ 08F9C3F7FE3019BF53B1405B1820528F, E90940533F88A33C396E1DF9D186E945F030315FB2201E479F144E27387333CA ] KtmRm C:\Windows\system32\msdtckrm.dll 22:48:44.0534 0x3e08 KtmRm - ok 22:48:44.0551 0x3e08 [ ECFFCC67C47A86CA32D0953428699210, F5A06E82FDC092549623FD41C82B082092529808BA12339DE5B1D72B9B12072D ] LanmanServer C:\Windows\system32\srvsvc.dll 22:48:44.0555 0x3e08 LanmanServer - ok 22:48:44.0555 0x3e08 [ B82D6C634638534E41748FCEC909E55D, C286EB7B3E780549F77E75B4B9F053861D82EFDCD43B1308848A08D23EFADDCA ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 22:48:44.0555 0x3e08 LanmanWorkstation - ok 22:48:44.0571 0x3e08 [ AF1077E89AD4458EC9B1CABB35595346, 762AE3218B7B05032C4199F0AE9ABCC822C3DF88BBB09536202B6B26A7944024 ] lfsvc C:\Windows\System32\lfsvc.dll 22:48:44.0571 0x3e08 lfsvc - ok 22:48:44.0571 0x3e08 [ C0CB3B9F1F92C36B91309FDACCDF918B, 5D40C11388A48323D9D9AC18A950B09E2654092BC2F9DE45779A9354668BA18E ] LicenseManager C:\Windows\system32\LicenseManagerSvc.dll 22:48:44.0571 0x3e08 LicenseManager - ok 22:48:44.0571 0x3e08 [ FC37745959DFA4871759E4DCC836227A, 8B63F798440FD0A34E2F2940B2598238BC852EF3EFD22147A77AB4BA6FB9E704 ] lltdio C:\Windows\system32\drivers\lltdio.sys 22:48:44.0571 0x3e08 lltdio - ok 22:48:44.0587 0x3e08 [ 1797F544956D46966C67A2F7879403A9, D7820D2F8E936FF13D709BA1BD0541AABA8402F38698FE96DAE70B4E7A730835 ] lltdsvc C:\Windows\System32\lltdsvc.dll 22:48:44.0587 0x3e08 lltdsvc - ok 22:48:44.0587 0x3e08 [ AE561CB0813D4DFA7D3E4471B2B70F5F, 344EA5E02D04098F032353962C1B70B0F578BCCD2843C70D6330B3F967D2FDB5 ] lmhosts C:\Windows\System32\lmhsvc.dll 22:48:44.0587 0x3e08 lmhosts - ok 22:48:44.0603 0x3e08 [ 16C9D4D822CCA795A72DC88B25A577CC, AEF93AA4E815F90C1A42D574C6DE7EF31FE69AD7B78B8E1AC7C27304F3CD7959 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 22:48:44.0603 0x3e08 LSI_SAS - ok 22:48:44.0603 0x3e08 [ 920F0CFCED5F28A31B79F1C470649D11, 5A5F390F2FD7C26807E7896E9F8F94EE7E69FE3C4B247BEA515588EB076148EF ] LSI_SAS2i C:\Windows\system32\drivers\lsi_sas2i.sys 22:48:44.0603 0x3e08 LSI_SAS2i - ok 22:48:44.0603 0x3e08 [ 0FE63316F1C70A0F759A449FAC64C24B, CF99D62FDA862095BA1EB57DD58CEC070E0552E15B6F454B87D593707132636B ] LSI_SAS3i C:\Windows\system32\drivers\lsi_sas3i.sys 22:48:44.0603 0x3e08 LSI_SAS3i - ok 22:48:44.0618 0x3e08 [ 80E82C46B27A923A3744531069B63857, C73A200FC2A009D19F2C26FAC07489EA0F4329CD7A1D80EB3200B19DFC883F8D ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys 22:48:44.0618 0x3e08 LSI_SSS - ok 22:48:44.0634 0x3e08 [ A69A59CD52D26443FF728FD52283598C, E416481B23CDADBB9E608E49C9DC9A520D14935E92CA9B63E7763692DB382D7D ] LSM C:\Windows\System32\lsm.dll 22:48:44.0634 0x3e08 LSM - ok 22:48:44.0650 0x3e08 [ 88F5570C04766EE561FF129B2F93030C, A36F7FF563F813EC0F69E5BFB76C58A1C9824F54BA1729C4096E8B7B7C8D90EC ] luafv C:\Windows\system32\drivers\luafv.sys 22:48:44.0652 0x3e08 luafv - ok 22:48:44.0655 0x3e08 [ D365217A6D4528ABB41B40C8FBD227E8, 340129785A5788A8FFE0E1B339A616D290F7504F3658F63E1A3B169B38460FBF ] MapsBroker C:\Windows\System32\moshost.dll 22:48:44.0655 0x3e08 MapsBroker - ok 22:48:44.0655 0x3e08 [ C3EED732789052C98A2613A7E1C37CDA, D71735C8FB772EEB7F3F304CD79D8D774A9A285A94365DE0E635F61357EC9F0F ] mausbhost C:\Windows\System32\drivers\mausbhost.sys 22:48:44.0671 0x3e08 mausbhost - ok 22:48:44.0671 0x3e08 [ 4DCE65116A28488593FF5A6A18B03DB0, AAFA7E7C1C9A38B8CF5CE530F96028191F52B1FDD2790246E413B63CF7C5F02A ] mausbip C:\Windows\System32\drivers\mausbip.sys 22:48:44.0671 0x3e08 mausbip - ok 22:48:44.0771 0x3e08 [ FEAF4E98C93BC3512B8108D2F534A3BA, 6D93EF21DB9BFFACC1241E823F9BB7719B9395D64BBF952874CFF015B7930D92 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe 22:48:44.0854 0x3e08 MBAMService - ok 22:48:44.0856 0x3e08 [ 0609BF877A2F4DEECC62EEE220AB6242, 393268836EB055669997BD05866487497AFC396C9516DA4C4F143679B1DDCA6E ] megasas C:\Windows\system32\drivers\megasas.sys 22:48:44.0856 0x3e08 megasas - ok 22:48:44.0856 0x3e08 [ EEC64C8D498D121607C7615FDFBEE4D0, B605B9886C1A05C999B005AEA6D0677DF632E2F34F4FF03F09C2E6C05F554D50 ] megasas2i C:\Windows\system32\drivers\MegaSas2i.sys 22:48:44.0856 0x3e08 megasas2i - ok 22:48:44.0872 0x3e08 [ 2B7D3B206833D769218A1F4BE2D73B97, 25901A5E931DC3659993448E59ABC3601B7B0ED9AFEF0F5ECC139D0D0442F73B ] megasr C:\Windows\system32\drivers\megasr.sys 22:48:44.0887 0x3e08 megasr - ok 22:48:44.0887 0x3e08 [ 4F708DA590EDBCC124FB79066D44759B, B8DA803299AF5FDE1594CF958EA6B99D4B99E8163438A70A692CA33A96DBF8DE ] MessagingService C:\Windows\System32\MessagingService.dll 22:48:44.0887 0x3e08 MessagingService - ok 22:48:44.0903 0x3e08 [ 89257B8D3826B5629CF7F73F97DA44F9, F056D67EC82072BA209FF7942862862FDF562F8C038F3128861C387F8F63B494 ] mlx4_bus C:\Windows\System32\drivers\mlx4_bus.sys 22:48:44.0918 0x3e08 mlx4_bus - ok 22:48:44.0918 0x3e08 [ 9AE3C0CC0865B1618A3C97744A6A9E9B, BF72AEF0360AC278B36ED31E5BFC2E8F72136B0952490A105CB6929654C97F6C ] MMCSS C:\Windows\system32\drivers\mmcss.sys 22:48:44.0918 0x3e08 MMCSS - ok 22:48:44.0934 0x3e08 [ 0CD29540C32C2E2E0E3D7E9832752AF3, E64C3F5323C59D53409E33E88989FDD2A38B5B602336FC1D8C3702CA9B5EBFC7 ] Modem C:\Windows\system32\drivers\modem.sys 22:48:44.0934 0x3e08 Modem - ok 22:48:44.0934 0x3e08 [ 534477FCAFDFCA6B841BFA06BD26BCC5, 96404FDF0BA2127A3BD24319637EC0C8BE8C42618D9FEDF66F41C5F72840D427 ] monitor C:\Windows\System32\drivers\monitor.sys 22:48:44.0934 0x3e08 monitor - ok 22:48:44.0934 0x3e08 [ F5D4E18A70BA069D479154442CDEB60D, 96345E88BC6A50415E112A4B4CFDF3F4306EA049741C5B0A2BFFC142F15EB5CB ] mouclass C:\Windows\System32\drivers\mouclass.sys 22:48:44.0934 0x3e08 mouclass - ok 22:48:44.0934 0x3e08 [ 5C09868963B0C076AC3BC7759A46B7B1, 64CD200A8D90CDC31317009636A3BB6574ABF04BCAC903F93C47823C40CC03F6 ] mouhid C:\Windows\System32\drivers\mouhid.sys 22:48:44.0934 0x3e08 mouhid - ok 22:48:44.0953 0x3e08 [ 8BF7039787036529B98E50AE86A0E46B, 69C04D012D026A14E2D2A138EDA79227F9BE4BE1892D517DCDB797F2A5AEDB14 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 22:48:44.0955 0x3e08 mountmgr - ok 22:48:44.0956 0x3e08 [ DE077BA53BE5653E5FA7A6DB85FEFE0B, 437BF2801118AF01E7486D9E21A35E6D4BA758F2ADBFE533AE4EEAADD7214638 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 22:48:44.0956 0x3e08 MozillaMaintenance - ok 22:48:44.0956 0x3e08 [ AD118EC95E9EF4D5223D681D8F183567, 395B76626956F5B7992676B9CA57B2CA075F0CDA881E14B3ED07ABE2DC0EEDBC ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 22:48:44.0956 0x3e08 mpsdrv - ok 22:48:44.0987 0x3e08 [ 8498B51BB69E8151E9A0896318C346DD, 55F9C6BB365B482DEECC80E4361531E485FDCFBD01FAEB452F2159C79612D044 ] MpsSvc C:\Windows\system32\mpssvc.dll 22:48:44.0987 0x3e08 MpsSvc - ok 22:48:45.0003 0x3e08 [ D14C297933C82B8CB0B5CBBA4DDC830B, 2EF356F5373F16A7AE2421187FC5C150C09452C835229275B7403181D65C210F ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 22:48:45.0003 0x3e08 MRxDAV - ok 22:48:45.0018 0x3e08 [ F2AD1B72C5A6475FB5FF332E1980DF88, 41E24496FBD61C0A333F567DA7C4E38C5A792724FB56448189099F60114749D5 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 22:48:45.0018 0x3e08 mrxsmb - ok 22:48:45.0034 0x3e08 [ 3E76F1B33FDB39C524086CA6774CA2C6, 7749A976E6EDEE193D6EFD73AE715115FD0B96B47DE8C3E15FD4808DAB0BC0DB ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:48:45.0034 0x3e08 mrxsmb10 - ok 22:48:45.0034 0x3e08 [ 7EFDF47AA174D8CD8F6BAB40CC5D6D51, 0A9462A8F16FB451608BF70CE6099D9FEBDFF859CFD01AF7F8B6C4A5DA5967CD ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:48:45.0034 0x3e08 mrxsmb20 - ok 22:48:45.0054 0x3e08 [ 44A8A52763381E5DCAE122330191493C, 578630611F151C6D20D52145312F4A824C6FF80E27F282A2109BA6E54FDDC9BB ] MsBridge C:\Windows\system32\drivers\bridge.sys 22:48:45.0056 0x3e08 MsBridge - ok 22:48:45.0056 0x3e08 [ 41C5D9B52F4A1B30C3F7219D601CF12C, E1C1B1CED19D32FA1B765C7C380B9E749893B2018CF358F448E40DA60CB63166 ] MSDTC C:\Windows\System32\msdtc.exe 22:48:45.0056 0x3e08 MSDTC - ok 22:48:45.0056 0x3e08 [ 92C00BD9616F353CA59A755C33269757, E67F05A4A1C44137CCAC0C7292A7010B5920172ACAE32638600E231F28F33035 ] Msfs C:\Windows\system32\drivers\Msfs.sys 22:48:45.0056 0x3e08 Msfs - ok 22:48:45.0072 0x3e08 [ F27EC8F7A0A779276E5DA2E70C2B01EE, A450DB309F84CAFFCE2A720612BDB260D88E9C390D2BC60874D73A55D8567E04 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys 22:48:45.0072 0x3e08 msgpiowin32 - ok 22:48:45.0072 0x3e08 [ CBA955A54C9446CAAD28C76789D3B071, F6CA1BECA35B13B7CCC9FFB325FACF22713F6B81E8A6540C9967A462E425BBEC ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 22:48:45.0072 0x3e08 mshidkmdf - ok 22:48:45.0072 0x3e08 [ E8E568EF60677E4534F387C53EE1B35F, 2E250EE1A9AE8AFDCA5216BED87328B05713386BD7E61C66A74EF021F2AFE7D7 ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys 22:48:45.0072 0x3e08 mshidumdf - ok 22:48:45.0072 0x3e08 [ 16376B7B0730C04DD1A2C0CC8E09E420, 2F39D3254FD272E277B5496A8C93A7CBFBF80F6004AE0343BE9F09C538975910 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 22:48:45.0072 0x3e08 msisadrv - ok 22:48:45.0087 0x3e08 [ 03A2D6491BEA6FDEB0C9DD2C6132AEC6, BC16DA70D15E469EBE8B1B13F2B18A9C8B30BD80FAD93C8D4FBDA836FD5C0E48 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 22:48:45.0087 0x3e08 MSiSCSI - ok 22:48:45.0087 0x3e08 msiserver - ok 22:48:45.0087 0x3e08 [ C2939119A17E52D74191EFC1E4CDEE09, B5738A32B02CDD816F086BA84C733D9597A0193F42C068D7B90E386D1CA92EE1 ] MSKSSRV C:\Windows\system32\DRIVERS\MSKSSRV.sys 22:48:45.0087 0x3e08 MSKSSRV - ok 22:48:45.0087 0x3e08 [ E40B960078A15D4901265D32E071C42D, AC11B8221C8F529FE3CA6FEB99AF699664C86008A732C3A8E6B1CE31C2272454 ] MsLldp C:\Windows\system32\drivers\mslldp.sys 22:48:45.0087 0x3e08 MsLldp - ok 22:48:45.0103 0x3e08 [ B4860AB91DC4E73936F0FF504D6B4B07, 7371093D9EB62218D20F6B8B3C88CBF01932AEA2923ED119962A78BE46E5A939 ] MSPCLOCK C:\Windows\system32\DRIVERS\MSPCLOCK.sys 22:48:45.0103 0x3e08 MSPCLOCK - ok 22:48:45.0103 0x3e08 [ 8EDC45C3F7F64A51C98B59E24648F74B, 445731F32A37A99FAB3CD5D178A84FB4F835727826211FF18623409D29FF3A1A ] MSPQM C:\Windows\system32\DRIVERS\MSPQM.sys 22:48:45.0103 0x3e08 MSPQM - ok 22:48:45.0103 0x3e08 [ 7DA5FAC2A49D30CA5B7B96B8B26281AC, 168C3AA5C7318184D8F67EA832920FCE64E11D4CC418517D7BDACB9632F0BEA8 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 22:48:45.0119 0x3e08 MsRPC - ok 22:48:45.0119 0x3e08 [ 4369BBFCDDCCE61856DD862C8E5C4E19, 23BA06675997A3A46723D0FC9E3DFEBC17E4149FC67B9DCED3011BBB5B5DCFF9 ] MsSecFlt C:\Windows\system32\drivers\mssecflt.sys 22:48:45.0119 0x3e08 MsSecFlt - ok 22:48:45.0134 0x3e08 [ 7E3365C8BC83DCE88D6226BB5C7170C4, 69D741039CAAFCA93A4CC09CEC14F117527D732A6CF3077AA83E935B03EC3F9C ] mssmbios C:\Windows\System32\drivers\mssmbios.sys 22:48:45.0134 0x3e08 mssmbios - ok 22:48:45.0134 0x3e08 [ 09D51564E49181E9928910D6B91C920E, FB3C918820ACF4506AC49478709B4D4C6489BA0B5113E666C34B916CA5CD6DE7 ] MSTEE C:\Windows\system32\DRIVERS\MSTEE.sys 22:48:45.0134 0x3e08 MSTEE - ok 22:48:45.0134 0x3e08 [ 793AE56A3946EAD5F906C28D294FEFE6, BB563D088084026606C2FBD30A0850BA18363CC173CC6C77272D727CA6C1F9BD ] MTConfig C:\Windows\System32\drivers\MTConfig.sys 22:48:45.0134 0x3e08 MTConfig - ok 22:48:45.0134 0x3e08 [ E35F51C7474A26680627477462715206, 435490915CDD416D666B64C6B4526285EC946E6918CFA85585692B9ED43518B6 ] Mup C:\Windows\system32\Drivers\mup.sys 22:48:45.0134 0x3e08 Mup - ok 22:48:45.0153 0x3e08 [ 74BD1149BF50F1E24934042A3BD17C90, DC4626DC4D629CA7DF336EC7E6435F27D2E252D81945E57F4BF2C981DBCD9B45 ] mvumis C:\Windows\system32\drivers\mvumis.sys 22:48:45.0154 0x3e08 mvumis - ok 22:48:45.0156 0x3e08 [ 83397BCE9D176B74E80975647A295748, 5FFBC5195913297907C2F75412D674194301635C57826C34392682B5EE924A7C ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 22:48:45.0172 0x3e08 NativeWifiP - ok 22:48:45.0188 0x3e08 [ BC80F85C129F12A5F64D6741A120B539, AD410F13BCBDE54F98E353BD4DAF30CC5A0A9990FC4F1AB3623EF3175EEBCAF7 ] NaturalAuthentication C:\Windows\System32\NaturalAuth.dll 22:48:45.0188 0x3e08 NaturalAuthentication - ok 22:48:45.0203 0x3e08 [ F2EA6F3165E154C24C084AC35DD6C3F8, 4F8CB75770945F5A28CC308917A124109F7462CE933695B9CAA3FE2CAE76C445 ] NcaSvc C:\Windows\System32\ncasvc.dll 22:48:45.0203 0x3e08 NcaSvc - ok 22:48:45.0203 0x3e08 [ 9B3C6582CFB91BA2A04B1D06D8E2FB98, 431E6B075FD24002724E8A2ED9FB3221AD66D1F1D021B56466187D97E5B43A1F ] NcbService C:\Windows\System32\ncbservice.dll 22:48:45.0219 0x3e08 NcbService - ok 22:48:45.0219 0x3e08 [ 932E2E43078A3D786A46A5428F21B314, 17F1CC3388D80F1E1850063114C1EB72EEA149D9C8FA3501C0F9EB55C9E0C58D ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll 22:48:45.0219 0x3e08 NcdAutoSetup - ok 22:48:45.0219 0x3e08 [ 0FFE8AF1B94C5FD54E6ACC6DAE990D31, B67D3CA3460D4700D8B83EFE4B6A7AA940650E84D985484FBAA1EE80F3632133 ] ndfltr C:\Windows\System32\drivers\ndfltr.sys 22:48:45.0219 0x3e08 ndfltr - ok 22:48:45.0255 0x3e08 [ 64BB1D5A6A8711C980D2ABAB0ADFFF8E, 85061564E6684136D544A556896C9BDDC93146B94416F49DB8E9321E38DF46D0 ] NDIS C:\Windows\system32\drivers\ndis.sys 22:48:45.0257 0x3e08 NDIS - ok 22:48:45.0272 0x3e08 [ 4EA73CFDEE4A628D387D95464A131F29, 38A6E2389FA9B20A7AFDF3CFCD13B66489B92D853EE486BF81019F0A36A142E1 ] NdisCap C:\Windows\system32\drivers\ndiscap.sys 22:48:45.0272 0x3e08 NdisCap - ok 22:48:45.0272 0x3e08 [ EB127689AF6F24091AB73538A556257F, BC25067D355084D6893E9262750433044C28893BB27A67BF7AF5008742C6D359 ] NdisImPlatform C:\Windows\system32\drivers\NdisImPlatform.sys 22:48:45.0272 0x3e08 NdisImPlatform - ok 22:48:45.0272 0x3e08 [ 73B4C72FB6170A08C64BDA92DE93ECF7, 766BBE659232F0F5EAEE577EE88091FB76175BC52D65B9637126069C97E795D4 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 22:48:45.0272 0x3e08 NdisTapi - ok 22:48:45.0288 0x3e08 [ 6704F27EB15A5B30AA7FA5A4F4D1FD47, 841F99B3C751F4D4E23C0E7B5C275B4871C1D5EF937A93129DF64DF49F6B6736 ] Ndisuio C:\Windows\system32\drivers\ndisuio.sys 22:48:45.0288 0x3e08 Ndisuio - ok 22:48:45.0288 0x3e08 [ FE87CCAA89433FC306A80F15E848F4B2, 3269FDF53DA59057E066D582FCBB96B71C8063B8F488856A9DEA414B4797E43A ] NdisVirtualBus C:\Windows\System32\drivers\NdisVirtualBus.sys 22:48:45.0288 0x3e08 NdisVirtualBus - ok 22:48:45.0288 0x3e08 [ 94517BC9F29A1B73D377F1BF1C3DCA34, 45A34D7AAA851C643E80C0F61CBF8544B8A2E8E7DAB2D5AB6F3A34FDEE4AB0B3 ] NdisWan C:\Windows\System32\drivers\ndiswan.sys 22:48:45.0288 0x3e08 NdisWan - ok 22:48:45.0304 0x3e08 [ 94517BC9F29A1B73D377F1BF1C3DCA34, 45A34D7AAA851C643E80C0F61CBF8544B8A2E8E7DAB2D5AB6F3A34FDEE4AB0B3 ] ndiswanlegacy C:\Windows\system32\DRIVERS\ndiswan.sys 22:48:45.0304 0x3e08 ndiswanlegacy - ok 22:48:45.0304 0x3e08 [ AC6AC99075732F5C29DB0004DD5B1AC6, 684EC821EF5C60DA540CA36EC192B09E62440AAD5B13F0F4C23DDC4A9B96F28C ] ndproxy C:\Windows\system32\DRIVERS\NDProxy.sys 22:48:45.0304 0x3e08 ndproxy - ok 22:48:45.0304 0x3e08 [ 9AC090451D92E6081EB89CDA83D74189, D4D442412F112853AA8D88DFB5F695AE4E8E2C361905992537EE53BE675FECE8 ] Ndu C:\Windows\system32\drivers\Ndu.sys 22:48:45.0319 0x3e08 Ndu - ok 22:48:45.0319 0x3e08 [ EE00C544C025958AF50C7B199F3C8595, D774DB020D9C46D1AA0B2DB9FA2C36C4A9C38D904CC6929695321D32ACA0D4D1 ] Netaapl C:\Windows\System32\drivers\netaapl64.sys 22:48:45.0319 0x3e08 Netaapl - ok 22:48:45.0319 0x3e08 [ A115DDB2C7805C41EEC9A5276FF5764E, FC81D0BE2DAAC6E7161C0FC5C90050022A39AD50E28040D5357C0E1FD6C0B6B5 ] NetAdapterCx C:\Windows\system32\drivers\NetAdapterCx.sys 22:48:45.0319 0x3e08 NetAdapterCx - ok 22:48:45.0319 0x3e08 [ F420B6CAB5151A38E4DBBFFB500C11DA, 271F495B261461B8EA847BFDD87C155E6DC1B6236C161B8253A1F023706B1B1D ] NetBIOS C:\Windows\system32\drivers\netbios.sys 22:48:45.0319 0x3e08 NetBIOS - ok 22:48:45.0335 0x3e08 [ BAD3C424788BC071C3EC82CFCDA954D2, 7AA11C36C8365B476361FC4F05C612066C5159C7C1813314E881E1A3A4B75271 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 22:48:45.0335 0x3e08 NetBT - ok 22:48:45.0335 0x3e08 [ BA909DA3D184EF80F9293AB9E12FF30F, 5C9BB19D447698F4EAE8D9A26548703C4B8B6FEB68D49E6F2516666E5226236A ] Netlogon C:\Windows\system32\lsass.exe 22:48:45.0352 0x3e08 Netlogon - ok 22:48:45.0357 0x3e08 [ D9FF8CA42C3541F4840693F17143C595, B05FB0B6439B34BD93EE59DC48BBE3D712A7428EFBFE37A887CE8546E57EE68F ] Netman C:\Windows\System32\netman.dll 22:48:45.0357 0x3e08 Netman - ok 22:48:45.0372 0x3e08 [ 96173660A4DD4A56E4B8938A67DAD9B7, F1D8F94625C6461DB89F8D3BDC73748F8A7F3446694BD1F148AF9BE6F17E9543 ] netprofm C:\Windows\System32\netprofmsvc.dll 22:48:45.0372 0x3e08 netprofm - ok 22:48:45.0372 0x3e08 [ 79C810D49E6D2825F51B0D7CAA6E2FAD, 19B7FB87FC8CE8FEA456F06D32099ED5B69FE38D2954580D4CEC32998D206E9F ] NetSetupSvc C:\Windows\System32\NetSetupSvc.dll 22:48:45.0388 0x3e08 NetSetupSvc - ok 22:48:45.0388 0x3e08 [ 4D37150AB4D61598919AB70ACFD1369A, 9ABF73213988ED9AA72B2658F8B91967A24C7CC2049859D86CE9C51A4AB57A84 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 22:48:45.0388 0x3e08 NetTcpPortSharing - ok 22:48:45.0404 0x3e08 [ 8C03F2F5A9E93AEB08B3AEE51552394A, F95185FB8D5FDEAB39E593488BA6ABCFA9C081BFED05008E0CD95F29B894AFC8 ] netvsc C:\Windows\System32\drivers\netvsc.sys 22:48:45.0404 0x3e08 netvsc - ok 22:48:45.0404 0x3e08 [ 56CB676DC058995ED3AD61AF233B9975, 2658B1B5E0059D4C0CE8F82D327AFBBAD5CF6C5774C95039D39815092A74E4A1 ] NgcCtnrSvc C:\Windows\System32\NgcCtnrSvc.dll 22:48:45.0419 0x3e08 NgcCtnrSvc - ok 22:48:45.0435 0x3e08 [ 7D50141D1705AFB6BF2683201699FEC1, 1D333DD10BA6987A2787F2CF492E38029E2744BAA6B9354E8B2B8D22971B3D79 ] NgcSvc C:\Windows\system32\ngcsvc.dll 22:48:45.0457 0x3e08 NgcSvc - ok 22:48:45.0457 0x3e08 [ 50F98CD010326B58F09082BACF3123AE, 124446A2905E23BB3F5763E347842F3F511EC44C37C2F85E409F73EC8F53924E ] NlaSvc C:\Windows\System32\nlasvc.dll 22:48:45.0473 0x3e08 NlaSvc - ok 22:48:45.0473 0x3e08 [ 6D8F6A9C53CFB0C49E8251A442B7283F, C3E913E4997C35A9B4C2E613A499F01D15264EAB699B93269B690B2A74A70E9A ] Npfs C:\Windows\system32\drivers\Npfs.sys 22:48:45.0473 0x3e08 Npfs - ok 22:48:45.0473 0x3e08 [ BABF7E1757D6908941C9F9CBD66A5EF0, 323E743CB26583763A9C5DE64E7E08138CB8D3E2DE0A8BCE9F774E1C7426E7F8 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys 22:48:45.0473 0x3e08 npsvctrig - ok 22:48:45.0473 0x3e08 [ A85EB5721C7203AAAAAA04F551960CD9, E61ED728E154799346C749159BFE36FAEB2CE64FC5735F533B910017D66A7EE5 ] nsi C:\Windows\system32\nsisvc.dll 22:48:45.0488 0x3e08 nsi - ok 22:48:45.0488 0x3e08 [ 244C3E541E741C9D8F67E05D9D9AFBE7, 5848515910FD6FF01B94108E33BEBCA26D46DE54C6AC9CF9F5533180E16788AB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 22:48:45.0488 0x3e08 nsiproxy - ok 22:48:45.0520 0x3e08 [ CDB804F3EA333459FE3C21D61767CBB1, 7A0C3D4DEDEF6160FE9F4A0B87A84453B882D8727AE9ECAFE35CE45F2EDF91D5 ] NTFS C:\Windows\system32\drivers\NTFS.sys 22:48:45.0557 0x3e08 NTFS - ok 22:48:45.0557 0x3e08 [ 4FFB2D5655D10700D5B8E205C4DB86BD, 69078960669A373F9C2D47AF2ED841619831106B681EBAAEAAE5BD569A54CE6D ] Null C:\Windows\system32\drivers\Null.sys 22:48:45.0557 0x3e08 Null - ok 22:48:45.0573 0x3e08 [ 99EB6376EC2C03CE5F668577651E3454, A783FFBF89A9074E2074ACAF3F55862DF2F05CAFEAF6A2D509DDA665EB0D59CB ] nvdimmn C:\Windows\System32\drivers\nvdimmn.sys 22:48:45.0573 0x3e08 nvdimmn - ok 22:48:45.0573 0x3e08 [ 4938CCA6E12A7FDA5324FFF0DF5DB8EC, 053D4D21014020C0D39F7BFC480EAE1458E1ABA1C40E11190204C4A2CB0D46EF ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 22:48:45.0573 0x3e08 NVHDA - ok 22:48:45.0837 0x3e08 [ 145E2D832BDC4EEAD7A98AB4B85ABD54, 75AC01B0D206EE98CC1B286E577D5825CF690C27989AA95CB151FB6E7B4C29EB ] nvlddmkm C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_63f40b686fe9309f\nvlddmkm.sys 22:48:46.0043 0x3e08 nvlddmkm - ok 22:48:46.0061 0x3e08 [ 3DB2E9E207358BFBD09B77B5119ECA5B, 55FED85EFC06B7AB5031D9986E4E4D2FA8841C549081ABBA9F9D9BBAB7852B37 ] nvraid C:\Windows\system32\drivers\nvraid.sys 22:48:46.0064 0x3e08 nvraid - ok 22:48:46.0069 0x3e08 [ 4C04BFBD4DB2EECCC47F5FA39D65BB6E, 9312DC4F7000991946D92D87DD9D37D70E336629EDBA553BFC79804049E34B73 ] nvstor C:\Windows\system32\drivers\nvstor.sys 22:48:46.0069 0x3e08 nvstor - ok 22:48:46.0069 0x3e08 [ 23423E859CA253382D80D0321522A171, 79C914C0A421E0BE566B5FCD5868B1248D4F397C24F8C5E70A8EA6E260617845 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys 22:48:46.0069 0x3e08 NvStreamKms - ok 22:48:46.0069 0x3e08 [ 9DF8BBA81D0A44AA9D14B7ADE47D2200, 3F50BE14892D168032DA9AF22259A986F024E6AD43DAEEC3C1E777BFA9E5A157 ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe 22:48:46.0085 0x3e08 NvTelemetryContainer - ok 22:48:46.0085 0x3e08 [ E502016A185B5BB9DC341873F82CD49C, A1F7D3E4FA5B4C81966F0E1DE8039CDD0374A9FF86AB252483FC9D98360089A1 ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys 22:48:46.0085 0x3e08 nvvad_WaveExtensible - ok |
24.10.2017, 15:22 | #4 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link TDSSKILLER.txt Teil 2 Code:
ATTFilter 22:48:46.0085 0x3e08 [ E3BCAF332BC25574784D4B91EA8E0C57, 0C0FFEE1519D0E5BB0B04900860590777513B4B1315218406DFB8DEB15B2AF52 ] nvvhci C:\Windows\System32\drivers\nvvhci.sys 22:48:46.0085 0x3e08 nvvhci - ok 22:48:46.0101 0x3e08 [ 0D611DC17E48B6F8DD466A089170D118, E55A78E2CC6A0A5F7B8F0B75DFB2297FBC3B959C4FDEFBEA1C6C4E7706724AEB ] OneSyncSvc C:\Windows\System32\APHostService.dll 22:48:46.0101 0x3e08 OneSyncSvc - ok 22:48:46.0147 0x3e08 [ 97A6A05000332DA67DC8C93C9EA4871D, F62131D93B8EC4259A4E5514B5E56E776AE80C00E8387F0FFEBAC05DB47ED553 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe 22:48:46.0169 0x3e08 Origin Client Service - ok 22:48:46.0216 0x3e08 [ 3EDBD7B10EE51AB65F380338308CEE44, 9D6DA23AB79CAE77FD000D524F961D5E89AF2938313AA78879076D515B07D536 ] Origin Web Helper Service C:\Program Files (x86)\Origin\OriginWebHelperService.exe 22:48:46.0263 0x3e08 Origin Web Helper Service - ok 22:48:46.0269 0x3e08 [ 61537B02CEA00BE142B11384A7BBF04D, F4B8DE5A889C04CA4EEB82AD0A66D8828CA302ECAF9E91AAF288C8770EC97199 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 22:48:46.0269 0x3e08 ose - ok 22:48:46.0269 0x3e08 [ F5F10CE848CAF07A12A7B92290DBA38A, AC6AC13B692D07A6853B24A6396F1C3388586FD5D528F79FA3E373428D54D29A ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 22:48:46.0285 0x3e08 p2pimsvc - ok 22:48:46.0285 0x3e08 [ D1A9C22A98A10EB11A190B8FC7C07C6A, 1DE5F07E707DA9D833F105A8D948BBAEF0172DB2147D9A665EC7320F88D57B9E ] p2psvc C:\Windows\system32\p2psvc.dll 22:48:46.0301 0x3e08 p2psvc - ok 22:48:46.0301 0x3e08 [ 2CC6C325B271C7CA60F374F8F868CB45, 569391CA5DF003ED33CAA89FD38834641023C24F7FAE2261F6DA8ABC5CC9C3C9 ] Parport C:\Windows\System32\drivers\parport.sys 22:48:46.0301 0x3e08 Parport - ok 22:48:46.0301 0x3e08 [ ABE0711474C0518FD914F62AB4FB83E8, 17F38D28D0A2275A6A1E5BC2C60BF2459B0D642EDC42B59F4A1BCFC1100C8502 ] partmgr C:\Windows\system32\drivers\partmgr.sys 22:48:46.0301 0x3e08 partmgr - ok 22:48:46.0317 0x3e08 [ 72ABB842C15A6C3AC3D954308C6BF206, 8F2A69E3BE43BCD2C8A39153062216B5CCEC9FA62205EC8A23FAB209DFAE7062 ] PcaSvc C:\Windows\System32\pcasvc.dll 22:48:46.0332 0x3e08 PcaSvc - ok 22:48:46.0332 0x3e08 [ C5B74C6D87E77BC64DEBD1BF57DEB375, AEBC86E404D4E3985D9FBAD9913AC52127DDE7C79062830717CDFEEA4CD7CC0B ] pci C:\Windows\system32\drivers\pci.sys 22:48:46.0348 0x3e08 pci - ok 22:48:46.0348 0x3e08 [ CFB85CB7A6F6926EA0EB96EDFB3C8A91, 7B3A58C165DF231BB202D8A2036272932439864F8EBDC62811E2BEFA8B36FC01 ] pciide C:\Windows\system32\drivers\pciide.sys 22:48:46.0348 0x3e08 pciide - ok 22:48:46.0348 0x3e08 [ 13B7D84B397A90E82682C47A15C3A98D, 7F897DA83209381A8C26B34416899E276256AB587DC4E2B60B185CAC8D1877F0 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 22:48:46.0363 0x3e08 pcmcia - ok 22:48:46.0369 0x3e08 [ 76EA512FD9D4673CF7A57775EE8922E2, 6D2B90616A46BC4F9BB6BACBD78EB33C23834987365C87617AFC2E147871C984 ] pcw C:\Windows\system32\drivers\pcw.sys 22:48:46.0369 0x3e08 pcw - ok 22:48:46.0369 0x3e08 [ 10E48E45A03A7F4C2B7C11738BE87816, 44870E26C3B75D51F5035DE78E62F3EFF222D314DAACBD60AE40BF34BC706F2E ] pdc C:\Windows\system32\drivers\pdc.sys 22:48:46.0369 0x3e08 pdc - ok 22:48:46.0385 0x3e08 [ 4F190BA3C9BD2F0277BCBF480F396091, F09613C76350706992B39D7EA9B859D28F00790E5AC17CA7D49C3E270B9D8994 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 22:48:46.0401 0x3e08 PEAUTH - ok 22:48:46.0432 0x3e08 [ F5C8E47E2F7B72ACEA49F7AD2EA60D3B, 184B5C91BF36A03257A38E8FB5FDBEF96AE88F0F5FF2EEEAE7BFC6CA15CC1602 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 22:48:46.0470 0x3e08 PeerDistSvc - ok 22:48:46.0470 0x3e08 [ FE52FF97A094609429FEF098EDC6FB08, 6762ED340048AF61B756CB7B576BE2057768FDB677623D01F2A592727C0E5A00 ] percsas2i C:\Windows\system32\drivers\percsas2i.sys 22:48:46.0470 0x3e08 percsas2i - ok 22:48:46.0470 0x3e08 [ FCA143274792F12383C35902E801E83A, 87D93226E32153794993035553C9935D07242631E182460D8ED13650175C0F01 ] percsas3i C:\Windows\system32\drivers\percsas3i.sys 22:48:46.0485 0x3e08 percsas3i - ok 22:48:46.0485 0x3e08 [ 4DAD2C73778D41F951B33854936E7BDC, 1421FDA2D083D5923422A038C54603BF798C48DDB7244DBEDA46D537B8CE1534 ] PerfHost C:\Windows\SysWow64\perfhost.exe 22:48:46.0485 0x3e08 PerfHost - ok 22:48:46.0516 0x3e08 [ D4D4AFF22AEC7595EF24DB0FDCC06259, 4D3D7ECB724FE41924BA7699316D50566FE828B5B53616EC50DFBEE91C6464FA ] PhoneSvc C:\Windows\System32\PhoneService.dll 22:48:46.0532 0x3e08 PhoneSvc - ok 22:48:46.0541 0x3e08 [ 97D85602B8131C487EB08A36F7343F5E, BEDC106AF06358D40BB034390645A5BFF9C138CFD51B5997D32614741D3D2372 ] PimIndexMaintenanceSvc C:\Windows\System32\PimIndexMaintenance.dll 22:48:46.0541 0x3e08 PimIndexMaintenanceSvc - ok 22:48:46.0586 0x3e08 [ F9FB601621FF33376F3908C2C27C6EF4, 8689565D4FD1C68826EA0A9C2B44377A2AEC3CD812595F0D32904D8FA5809672 ] pla C:\Windows\system32\pla.dll 22:48:46.0601 0x3e08 pla - ok 22:48:46.0601 0x3e08 [ A2BACEBAC01BE7A6656B454E75C23262, C2C168718A341D48679AC4CA8005BD06E9F1F0D1F7C72D3C30A7A8CE1F665A43 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 22:48:46.0617 0x3e08 PlugPlay - ok 22:48:46.0617 0x3e08 [ 414CA4DCC31D795882B25ADC1DACE779, AFD8D9AA24C64DD9569FDCBE65171810FE27AF24B8DD2941FECE6245EABB6AAC ] pmem C:\Windows\System32\drivers\pmem.sys 22:48:46.0617 0x3e08 pmem - ok 22:48:46.0617 0x3e08 [ D54385DD5A39A5636D1587FC9ECFC337, DEEA5D433CB2DA55AE58C7C5431A1249C94B61606F0A75E4A44D516619060263 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 22:48:46.0617 0x3e08 PNRPAutoReg - ok 22:48:46.0633 0x3e08 [ F5F10CE848CAF07A12A7B92290DBA38A, AC6AC13B692D07A6853B24A6396F1C3388586FD5D528F79FA3E373428D54D29A ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 22:48:46.0648 0x3e08 PNRPsvc - ok 22:48:46.0664 0x3e08 [ 118E91AEE8F6DDAD088F955498CF2487, F4447C64CF1F36432E0FF09B6712DCE61BF28E3499F20C6C69E80D98B42D671E ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 22:48:46.0670 0x3e08 PolicyAgent - ok 22:48:46.0670 0x3e08 [ F6A0B848F75CF55E3980EA0FADCBA317, 11D8B12B4DE867B180965B0F2FD0F362265C518F76FE3351A2B7C9C2FFC5E137 ] Power C:\Windows\system32\umpo.dll 22:48:46.0670 0x3e08 Power - ok 22:48:46.0686 0x3e08 [ D292D7FADCEE481CC64A9DE8FE9C3347, BD870A375E33CD8434CA97FFE9C2F84E58C6CD0EAEEEE8922172CB01F9674B55 ] PptpMiniport C:\Windows\System32\drivers\raspptp.sys 22:48:46.0686 0x3e08 PptpMiniport - ok 22:48:46.0749 0x3e08 [ 5404E7A968A26DF03793B6F68536594D, BE5A85581E87EFE4DB43AD17B8D42D3F7F32364AEEC1416DBB94279C4A203FF2 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll 22:48:46.0786 0x3e08 PrintNotify - ok 22:48:46.0786 0x3e08 [ D57CF871B3977731A91FE9611A54C7C1, B6C7F685716A88D0978377B83C5320C88EED0CAA44A001849AAFF71E4E0682E7 ] Processor C:\Windows\System32\drivers\processr.sys 22:48:46.0786 0x3e08 Processor - ok 22:48:46.0802 0x3e08 [ EBBAEA19BB7BF5E7CF09BE1C294E2699, 4FAF59D5393A6979627A061216676106A3941F2FBAE8E1CD5485E49BB57A6297 ] ProfSvc C:\Windows\system32\profsvc.dll 22:48:46.0802 0x3e08 ProfSvc - ok 22:48:46.0818 0x3e08 [ B60431D2A046AD97F8427F6E568370F5, CD488E343585A5AC19D9AAF88BF0BB7EEA1BC48F6DA4A4FBF9BE5A04ECF5040B ] Psched C:\Windows\system32\drivers\pacer.sys 22:48:46.0818 0x3e08 Psched - ok 22:48:46.0818 0x3e08 [ E0DCCA2A78516D155A6485CCA99F0EA5, EAFD24F815ECD6373BEC8E75B24FB54694CB8E4FF430FB6886F9B5B1C1762BFC ] QWAVE C:\Windows\system32\qwave.dll 22:48:46.0833 0x3e08 QWAVE - ok 22:48:46.0833 0x3e08 [ A2B0F46FBA2521E7E732BDBDB1238515, 7F0FEFB09770BF5889D6C2219F68399C962A3F1071E70C4951B6FDAE196CF041 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 22:48:46.0833 0x3e08 QWAVEdrv - ok 22:48:46.0833 0x3e08 [ EA9EB06EFC325CD2ACF5DF2F26A4894E, 32AC7EDB42CDA736E2AD9AB67795735F16234D9BD80D56FDAE5B8B3C3C1CC26F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 22:48:46.0833 0x3e08 RasAcd - ok 22:48:46.0833 0x3e08 [ 4E9379389D0A851DD19D130C8FAEFBD0, 279A25EF8949A5BAF311CA75493A5F89F74A02711EF875F67D0A95849B409C00 ] RasAgileVpn C:\Windows\System32\drivers\AgileVpn.sys 22:48:46.0849 0x3e08 RasAgileVpn - ok 22:48:46.0849 0x3e08 [ 3E8CB44832FE3F96047187291523CDA1, 999A10D4D50CD2C39309FDC04A9F4CB0959BA061AE9305D4DF7F00F37F3813F9 ] RasAuto C:\Windows\System32\rasauto.dll 22:48:46.0849 0x3e08 RasAuto - ok 22:48:46.0849 0x3e08 [ 5279EC98F6218D29EADDFECCC0D80E9A, 6F376FC3BEFA9F521635192177962AF1F41173502EC067896B7C2A5FB71E7A3B ] Rasl2tp C:\Windows\System32\drivers\rasl2tp.sys 22:48:46.0849 0x3e08 Rasl2tp - ok 22:48:46.0871 0x3e08 [ FCC5824BCB4D12AFC40C61CADDC7175C, 2C2464849320B2E18B9A94574AA20218AF4EA50E9947C990068F086061400275 ] RasMan C:\Windows\System32\rasmans.dll 22:48:46.0886 0x3e08 RasMan - ok 22:48:46.0886 0x3e08 [ D7FF75ED7A48FD60A573C9E959CF4DB5, C67673E2D678527F8C07C9BCC487D385B92282D9D73396CFB01F14F5211CA991 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 22:48:46.0886 0x3e08 RasPppoe - ok 22:48:46.0902 0x3e08 [ 6A4E45A7F17FA0B4B1B48C550E311944, 1E84A559B7AA5F07E8156D223EFFB1B2B43D1E4E90E561D8DF2C257FFBCFDC0D ] RasSstp C:\Windows\System32\drivers\rassstp.sys 22:48:46.0902 0x3e08 RasSstp - ok 22:48:46.0902 0x3e08 [ 948DB267C109B3BF6A430198EF6C8D80, CCD3E369CE5D8E2912723F595FE2F18282A608163B8030100B81A16353A6B143 ] Razer Game Scanner Service C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 22:48:46.0902 0x3e08 Razer Game Scanner Service - ok 22:48:46.0918 0x3e08 [ F2C575A9657F7B2E027C6CE7BC8F1A2D, 5D002488CCEDCEBF0542F508FCE47DC9105C67D5685489970048437BD243AC0E ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 22:48:46.0918 0x3e08 rdbss - ok 22:48:46.0933 0x3e08 [ 9414B22E093243636D362BF8C8C12A67, 575CE91AFADD771CBF86377962EDFAF70150BBA575F8DF144FEE6CC1C0FF88E0 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys 22:48:46.0933 0x3e08 rdpbus - ok 22:48:46.0933 0x3e08 [ 53A01D3FDB701AC5D9DDE4140227E3D9, 833AF0BAAB49B58C71C684D2AA20B900C27E19DDCE5E15355C7ABAAB33BC7673 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 22:48:46.0933 0x3e08 RDPDR - ok 22:48:46.0933 0x3e08 [ DF32ED51DC0C3F6F3B1C4CEF71B8B426, DBEAD271B5DE6439E3106BDDB8B1E47D7BA47AE203CF3E1F8924CE02FDCA6E0B ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 22:48:46.0949 0x3e08 RdpVideoMiniport - ok 22:48:46.0949 0x3e08 [ 2369A5B651308E0C3458143976E9B03B, 0EDE99F7E2A7668E90C2FCA11D4BCE0676FBEA2CCFB57A004827CE5FE96D1584 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 22:48:46.0949 0x3e08 rdyboost - ok 22:48:46.0987 0x3e08 [ 3581FB9529035F8EC6DB681664CA70B1, 0C7BCD6A3B4248683C52B69F0B373D5929C2375F9BBF6CA80C480A8E7446A30C ] ReFS C:\Windows\system32\drivers\ReFS.sys 22:48:47.0002 0x3e08 ReFS - ok 22:48:47.0018 0x3e08 [ 79E1ADE19D8B7C56EF29D098EAF57AD0, 295D0F04359A00849759976710F6CB83DB96E5007946930EA19865620EA3EFE7 ] ReFSv1 C:\Windows\system32\drivers\ReFSv1.sys 22:48:47.0034 0x3e08 ReFSv1 - ok 22:48:47.0049 0x3e08 [ D91C597DE82E1500525945E1FFF24B0F, 3F5837A743715FB2CCBFC9458FBE010AED170B46515925D4C7C59BBAC792F695 ] RemoteAccess C:\Windows\System32\mprdim.dll 22:48:47.0049 0x3e08 RemoteAccess - ok 22:48:47.0068 0x3e08 [ E9BE20C3EB1AA268F64211AC9B4278B4, F2BAB6A77D534FB6302FD53E61F11CA5CACE4D422440B5BD67C73794A17F28A9 ] RemoteRegistry C:\Windows\system32\regsvc.dll 22:48:47.0071 0x3e08 RemoteRegistry - ok 22:48:47.0071 0x3e08 [ 4DA924DCC091A706E03AD3C9FFBEBAA3, 26D3CE64874BB67BBA3C629742CB366EE550BB90AD8C8A616622112A21931D52 ] RetailDemo C:\Windows\system32\RDXService.dll 22:48:47.0087 0x3e08 RetailDemo - ok 22:48:47.0087 0x3e08 [ D31B2CD9458D2E212A5F24D56D2FB8D5, D8EC0BDB9D143C050A48217C57AA1BA6D60EEFEF67A98441064BD8FD339987DD ] RmSvc C:\Windows\System32\RMapi.dll 22:48:47.0102 0x3e08 RmSvc - ok 22:48:47.0102 0x3e08 [ C79F1F7C8A5FCBE90E3C833299AA1F59, 7969E79B2095BDA144AA369DE21F49C9FAD272B5864B2F0FD28CB28D148F2AD6 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 22:48:47.0102 0x3e08 RpcEptMapper - ok 22:48:47.0102 0x3e08 [ 1CE6928C1587F9760F7C3A036786CAE8, 3E4F5371E0DDDBA612BF61891D17D691DCAFB2E1010BBD84737FBD98DA8C03DE ] RpcLocator C:\Windows\system32\locator.exe 22:48:47.0102 0x3e08 RpcLocator - ok 22:48:47.0134 0x3e08 [ AA7F1C36F5BC779964CFA4F98D224D9F, 6DAF4FCE696B1D6A76E127A905C158724B13C20D2AA0F460F6C2E747E9525D98 ] RpcSs C:\Windows\system32\rpcss.dll 22:48:47.0149 0x3e08 RpcSs - ok 22:48:47.0149 0x3e08 [ E87EECED9287C275B6CF30EB598B1D77, D0C5D4E37A3FAD422C0ECFFAB53904D9FD5385129DE2BC5AF75D91CD016EA6AC ] rspndr C:\Windows\system32\drivers\rspndr.sys 22:48:47.0149 0x3e08 rspndr - ok 22:48:47.0171 0x3e08 [ 39FC08BE0FBCBF40A67C22FFB671A96F, B9B942A0AEF03E4E9D4A61C9F042CDC97BAD98912369CD0E0D8B0FFC08D124A3 ] rt640x64 C:\Windows\System32\drivers\rt640x64.sys 22:48:47.0187 0x3e08 rt640x64 - ok 22:48:47.0187 0x3e08 [ E98661C24F2A1A0A0DD087DDB748C16A, D64EB4EEC88BF2DB99CCE6442C9EAA69120A8087020EB134A338E40AC74FC4DF ] rzendpt C:\Windows\System32\drivers\rzendpt.sys 22:48:47.0187 0x3e08 rzendpt - ok 22:48:47.0187 0x3e08 [ B34BEC622C63B0BD59004B0999E826C2, CAF2EAE8770E7377460E925FB0586D939D4683F3A95200C0FAE94A7E5DA4D372 ] rzpmgrk C:\Windows\system32\drivers\rzpmgrk.sys 22:48:47.0187 0x3e08 rzpmgrk - ok 22:48:47.0187 0x3e08 [ 935A7DF222F19AC532E831E6BF9E8E45, 567809308CFB72D59B89364A6475F34A912D03889AA50866803AC3D0BF2C3270 ] rzpnk C:\Windows\system32\drivers\rzpnk.sys 22:48:47.0202 0x3e08 rzpnk - ok 22:48:47.0202 0x3e08 [ A55C8B924448EE8ED93796A46363AD23, CB10941084749621033DDFD444D696B71F2ED0CEF0E46BB2737822B09FA732C2 ] rzudd C:\Windows\System32\drivers\rzudd.sys 22:48:47.0202 0x3e08 rzudd - ok 22:48:47.0202 0x3e08 [ 6308366D3CDEA5F427CFF4BCF0081B4E, ABB91A41C09A1607C66BD380FD0A3EECAAF9AD534856CCC78DE1A4E450ADB07F ] s3cap C:\Windows\System32\drivers\vms3cap.sys 22:48:47.0202 0x3e08 s3cap - ok 22:48:47.0218 0x3e08 [ BA909DA3D184EF80F9293AB9E12FF30F, 5C9BB19D447698F4EAE8D9A26548703C4B8B6FEB68D49E6F2516666E5226236A ] SamSs C:\Windows\system32\lsass.exe 22:48:47.0218 0x3e08 SamSs - ok 22:48:47.0218 0x3e08 [ 186151BC8CEE2CF3E942E81527AAFF1A, 33D68239D655054CE8822438E96D2648193419D8D94F979A4B67AF57BCEF6CBD ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys 22:48:47.0218 0x3e08 SbieDrv - ok 22:48:47.0234 0x3e08 [ 12820DA4BB0079BBC709C7028A22BA63, C15EDCC83CC4931C871D04F09A6FC6199C9DCD4332CDF4C80D1E6E5A2AFD4DE1 ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe 22:48:47.0234 0x3e08 SbieSvc - ok 22:48:47.0234 0x3e08 [ 33B2DC5C2F19DA89F862484E23D9833D, 1C3BD1804767D087BE1510EEDCE94FFAC096922C821A123DB1BACDA5777246A7 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 22:48:47.0234 0x3e08 sbp2port - ok 22:48:47.0249 0x3e08 [ 53F03A8A228D6C8016139A4B2583A2D8, 8EA046C7537B2D926D3AE1F058A9880F823EBEA6DC77F312082EDE1722F08236 ] SCardSvr C:\Windows\System32\SCardSvr.dll 22:48:47.0249 0x3e08 SCardSvr - ok 22:48:47.0249 0x3e08 [ CBCC25CDF5D30ACB253CC92ADC7D569C, 0DF0DE3B0F0007E4F3D663EB7CC503C38B5A99F5859A6BD8564F8153F1D925D5 ] ScDeviceEnum C:\Windows\System32\ScDeviceEnum.dll 22:48:47.0265 0x3e08 ScDeviceEnum - ok 22:48:47.0268 0x3e08 [ 5CFEEFCC6FAD1FD09ACCFBD652DDD85B, F90104CC42073ACD48A2FCCEDF58B57D8663223406ECB0A270140A053E9260B3 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 22:48:47.0269 0x3e08 scfilter - ok 22:48:47.0271 0x3e08 [ 5BBFA6CA63E8A5BB8FA2FA84A5562CE2, C74CD0A76473343A8620D26C96F7300026C295EDF61B8A336AB326DFE861678D ] Schedule C:\Windows\system32\schedsvc.dll 22:48:47.0287 0x3e08 Schedule - ok 22:48:47.0303 0x3e08 [ 5C8620FAC0E3C1658C8EF7AD7BB7EA5F, FEBE7FC79FCDF692167D82DE54031FD68BD2941544007EEB3D82C21E7F1C5C83 ] scmbus C:\Windows\system32\drivers\scmbus.sys 22:48:47.0303 0x3e08 scmbus - ok 22:48:47.0303 0x3e08 [ 62E13528B9F900A5662E243D4315F10B, B3F4868E80A3A2EDEC19E5AA32C96FF90B08D6B9BD35B80EA01E6A098D46040B ] SCPolicySvc C:\Windows\System32\certprop.dll 22:48:47.0303 0x3e08 SCPolicySvc - ok 22:48:47.0319 0x3e08 [ 134FB9DCA9244455917D80D33CA31ACA, 0B17BB514A14096C8F67D73F27E52C90E4BD343B131BD554D7DD3B424B4E070B ] sdbus C:\Windows\System32\drivers\sdbus.sys 22:48:47.0319 0x3e08 sdbus - ok 22:48:47.0319 0x3e08 [ 464B615872981015AC4FEEBDEA83A063, 5CF491352B267241CA11F08E72E6EA668A595662561892E0D02CCA5B71172E14 ] SDFRd C:\Windows\System32\drivers\SDFRd.sys 22:48:47.0319 0x3e08 SDFRd - ok 22:48:47.0334 0x3e08 [ 847F01FB8504425BB255856A14278A86, 41997D25D12779CA79551988C56FA0A302367076B09A82F620858EDDDBFCE3FF ] SDRSVC C:\Windows\System32\SDRSVC.dll 22:48:47.0334 0x3e08 SDRSVC - ok 22:48:47.0334 0x3e08 [ 6BC219F1D9CDE08CEB9084ADB41FBA01, DA8AC3B42A72515A1976961976203A52D4C8636586EB5EF6B466AAF967A6567E ] sdstor C:\Windows\System32\drivers\sdstor.sys 22:48:47.0334 0x3e08 sdstor - ok 22:48:47.0334 0x3e08 [ 2AE8505519C7E8A903DD7BE793A79846, 7044B1BC183E028BCFB544489B033F0968F033696F9816F354329ABD26C6EE7E ] seclogon C:\Windows\system32\seclogon.dll 22:48:47.0334 0x3e08 seclogon - ok 22:48:47.0350 0x3e08 [ 408B6A218D33CB08D132E0FA1B71FB06, 709F52F1898C1F79E1D6BC38923E56588FDBD9D1E4A592AA6D32A6DF112D090E ] SecurityHealthService C:\Windows\system32\SecurityHealthService.exe 22:48:47.0350 0x3e08 SecurityHealthService - ok 22:48:47.0371 0x3e08 [ 77FB9BE8EDDCC999D09F2B1A7878A2A9, 589774C006A339FCA9772C37C9103C73C8592E018553804B97F34E2A0069A3F7 ] SEMgrSvc C:\Windows\system32\SEMgrSvc.dll 22:48:47.0387 0x3e08 SEMgrSvc - ok 22:48:47.0402 0x3e08 [ 25456AF499A0C9C4A93CFAC70BDE9CC2, 885C1A9C8BFA73D9C9C454759DF871237F7C0F28D879E98B4BE0D0113C549B09 ] SENS C:\Windows\System32\sens.dll 22:48:47.0402 0x3e08 SENS - ok 22:48:47.0402 0x3e08 Sense - ok 22:48:47.0434 0x3e08 [ 892C955E1081412942F64679E0DD7A5D, 6A28012270FA1FB3BB279102C67FA5296564630181C887E1EA6EA1F952A30C37 ] SensorDataService C:\Windows\System32\SensorDataService.exe 22:48:47.0449 0x3e08 SensorDataService - ok 22:48:47.0465 0x3e08 [ AA4BA5CCB3B01E23605ACE13F4A94ECE, 7D8374FA03C33CFC7EA7CF680F81B0090AB22076E389EB6B6233F696FC63E1B0 ] SensorService C:\Windows\system32\SensorService.dll 22:48:47.0471 0x3e08 SensorService - ok 22:48:47.0471 0x3e08 [ 00897F867A525D2118DF98E2DCADA050, ADAEB414EE5F3EFE90AE8A56136FB0165CF68962661FE0B937150235DE1F4DE6 ] SensrSvc C:\Windows\system32\sensrsvc.dll 22:48:47.0471 0x3e08 SensrSvc - ok 22:48:47.0487 0x3e08 [ 585329F62195A4B7AAD0A95F6EC89751, E7ADED97ACA8E8E06C368E24702C22D4C2B0B9495DEA24A2DC2A30782099BDCE ] SerCx C:\Windows\system32\drivers\SerCx.sys 22:48:47.0487 0x3e08 SerCx - ok 22:48:47.0487 0x3e08 [ C8F4FDA8B3D039D7947344614FF5BFB2, 1A3B88EC59F2A820AFE4F3AC65F7149EAC68672D1F0D729CBB575694005A8911 ] SerCx2 C:\Windows\system32\drivers\SerCx2.sys 22:48:47.0487 0x3e08 SerCx2 - ok 22:48:47.0487 0x3e08 [ E5B450E4E0DC1591254BF9CCF6C57B40, 958E7378D9BDE1F2EBE736D8D9912D56835A606AABDD042443A35CA37EC70F11 ] Serenum C:\Windows\System32\drivers\serenum.sys 22:48:47.0487 0x3e08 Serenum - ok 22:48:47.0487 0x3e08 [ 628D8DD136F92316BFEB58FA005338B7, 0CDA673D31F40EBD07E9F67667DB6077F23DCADE2DD8376AB550575224625D44 ] Serial C:\Windows\System32\drivers\serial.sys 22:48:47.0502 0x3e08 Serial - ok 22:48:47.0502 0x3e08 [ E5BA0B7353ADC5C95AB466D2E4DC89B1, 98F2A22ED892B2610C85EAAAB51DF25939599955A27611FCE9E68C3701CFD4EA ] sermouse C:\Windows\System32\drivers\sermouse.sys 22:48:47.0502 0x3e08 sermouse - ok 22:48:47.0502 0x3e08 [ 043D7B39E693C610036BD56DF30EF440, 329D29CE1CB5F502B7DFCBE24878CA61EC56787A1B02195E19499701B194DE08 ] SessionEnv C:\Windows\system32\sessenv.dll 22:48:47.0518 0x3e08 SessionEnv - ok 22:48:47.0518 0x3e08 [ 15CFCC4692DA8887B977CE5FC5181084, 31D86E122E35AB9E7275F2B0573EE98770BBE517ED3B9CCED97F4969C9A619F9 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys 22:48:47.0518 0x3e08 sfloppy - ok 22:48:47.0534 0x3e08 [ 87B083252816171A17F833CBCB7AA85E, 200AB93CEF384791DC9B04D2AF17877CA10595B2CEDF4B9505E367A2382C4AB7 ] SharedAccess C:\Windows\System32\ipnathlp.dll 22:48:47.0534 0x3e08 SharedAccess - ok 22:48:47.0549 0x3e08 [ 490F6144273A85A3CFF3D416850E0611, F703D32580405B9CEF0E601222C2CE584B076B2E58710D66A15AFEA2A6907514 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 22:48:47.0568 0x3e08 ShellHWDetection - ok 22:48:47.0571 0x3e08 [ 7CA2E9B6EDC87FCCA9C49D3D9BE62B65, 3FE1A2DD8581BF8D29EA2000424EB992BCA8E00986F107C22489D006F729D2E3 ] shpamsvc C:\Windows\system32\Windows.SharedPC.AccountManager.dll 22:48:47.0571 0x3e08 shpamsvc - ok 22:48:47.0571 0x3e08 [ 2339F6B45E1D863B1D327F3AFD75A675, 03304ADC42EF6E8F671C8AA78A0D3E40408D870FBF2DA2B31A1727F86EF8F213 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 22:48:47.0571 0x3e08 SiSRaid2 - ok 22:48:47.0571 0x3e08 [ F520D50AD7266ED31D25DF4C8EA6BC2D, F68CF9EFB8319E59A8D9C24A36A198185DD79CBACD14510F5450F0024F0CD4D3 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 22:48:47.0587 0x3e08 SiSRaid4 - ok 22:48:47.0587 0x3e08 [ 70A2FD5F5B7B1A5E1146BE45E4DFB75D, 598824F06BBC2E37B9A6474411637C73233C8D2E13AE963C3229279A8519A9D3 ] smphost C:\Windows\System32\smphost.dll 22:48:47.0587 0x3e08 smphost - ok 22:48:47.0602 0x3e08 [ 15684D78C67B63475EABAB5A6ECF32A8, 46BA6830BC42839E22F600ED591E23611E092C2342702F403553BB0B9177E835 ] SmsRouter C:\Windows\system32\SmsRouterSvc.dll 22:48:47.0602 0x3e08 SmsRouter - ok 22:48:47.0602 0x3e08 [ 9977AFF389C0C32DE419226564886E09, 453ABAB020E3ACD04A45BD05B224C182A47534C23023C4E1AD1903E5377B3CCF ] SNMPTRAP C:\Windows\System32\snmptrap.exe 22:48:47.0618 0x3e08 SNMPTRAP - ok 22:48:47.0618 0x3e08 [ 2334ED0B61CAE7E7B1B454674206CDAC, 4EAA11805C2282E0306A381CF56E4B28D83C68BA1B401BFD512AE70C05C8A4CD ] spaceport C:\Windows\system32\drivers\spaceport.sys 22:48:47.0634 0x3e08 spaceport - ok 22:48:47.0634 0x3e08 [ 83E82B0E292DCDE4C75B9241BF0FB300, 494D2FD4CD082CC416CA5FF1ABE06BDC65A769F371CF0E18AD25C380B45AEE32 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys 22:48:47.0634 0x3e08 SpbCx - ok 22:48:47.0666 0x3e08 [ 10CD42898C9E4849193E78A87337B2E9, 7C4FCB36EE1AF92C6962F14AE6DEF2CB154468EC3963DCDB9BDF8398C98B475B ] spectrum C:\Windows\system32\spectrum.exe 22:48:47.0671 0x3e08 spectrum - ok 22:48:47.0687 0x3e08 [ 250B6272326FC54414231AC71176E6FA, DE531EEADD24F1866A5BD74411E91E0934B23DC508855D2B9AC88BC25EE7A4E0 ] Spooler C:\Windows\System32\spoolsv.exe 22:48:47.0702 0x3e08 Spooler - ok 22:48:47.0771 0x3e08 [ E910861720DE6EDFB5CC6158CE3C7E17, 526BA8EEB9EE5312FEC39753D728E05F49AD81132346A354C95D4D4938001E2B ] sppsvc C:\Windows\system32\sppsvc.exe 22:48:47.0834 0x3e08 sppsvc - ok 22:48:47.0849 0x3e08 [ 897A3A77543369BC4D97EB71A40E6111, A83534658E1FACAD81CA539319C441F0B0AE47DD8624A06E8F1E88178BD30169 ] srv C:\Windows\system32\DRIVERS\srv.sys 22:48:47.0865 0x3e08 srv - ok 22:48:47.0871 0x3e08 [ F729DC11C591228D474C0F4D6BC1F0F4, EAC266A3B673758A0433FD17C56ABB1010DA6AE9C229D5F3D21D9C1744F6749D ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 22:48:47.0887 0x3e08 srv2 - ok 22:48:47.0887 0x3e08 [ 62E6CF587C037E99F7450F5BAAF0CB87, 3EED46313FD5A9C942F447F531121395C31C1AE2DED0F7B2E4A974F6024E8330 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 22:48:47.0887 0x3e08 srvnet - ok 22:48:47.0902 0x3e08 [ E95A6C339AE68515897B2E4C6B0842CA, 29DD7E83CD68432EAE4A7ED92CDA40AA52028F5FBB52152F0A1C752B572C2684 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 22:48:47.0902 0x3e08 SSDPSRV - ok 22:48:47.0902 0x3e08 [ FBD45746B2EDEECA10CCA6A861F8049B, 34383B0A07A93E0FA89CA32CD45AC5061F73723B2A9E0BF4AF93A53F70F1678E ] SstpSvc C:\Windows\system32\sstpsvc.dll 22:48:47.0918 0x3e08 SstpSvc - ok 22:48:48.0002 0x3e08 [ 15DE978A9FE8AC2DAFFD2BAD186719EB, 7F2C2A700C405D91E6FB232A870342AD883B67B503DCD929CFA9AC80FBBED278 ] StateRepository C:\Windows\system32\windows.staterepository.dll 22:48:48.0078 0x3e08 StateRepository - ok 22:48:48.0111 0x3e08 [ 0DB06D60F4CA7E037304F8BB14779764, B9136AFE1881F6DE60E63F3A19D49908075A8EC250AB8C90286FC6EA0CF08B19 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe 22:48:48.0133 0x3e08 Steam Client Service - ok 22:48:48.0138 0x3e08 [ D40C589F80EB1C511263D0547C0259AE, A0236F6BB515AE006CC4C9F40FCCE250407888757A3646BB4BCB59EF8EEF1311 ] stexstor C:\Windows\system32\drivers\stexstor.sys 22:48:48.0139 0x3e08 stexstor - ok 22:48:48.0151 0x3e08 [ F83F43CD328E6CEEAAC27612F3EB1FF5, E3D35E5154CD228301806706E6EADCA36E9113EAF44BC06E3C43B2E902187326 ] stisvc C:\Windows\System32\wiaservc.dll 22:48:48.0152 0x3e08 stisvc - ok 22:48:48.0152 0x3e08 [ 576A818562069B1E091CC719C143AED2, 48880CF4D33033E9A6024C2A0AD673AFBCE400C74574913F8E24717BA6BADE7C ] storahci C:\Windows\system32\drivers\storahci.sys 22:48:48.0168 0x3e08 storahci - ok 22:48:48.0168 0x3e08 [ E5F703788DFA05411F1469E96838F438, A7E8D2DC23E23EA52B068C71D9387E69FF49798A27CE0243A994A2B1B09FA042 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 22:48:48.0168 0x3e08 storflt - ok 22:48:48.0168 0x3e08 [ 0D0128244FF55EAD3F878D3FE542DBA5, 4FCFA1B2113E07264A71A22298CA6E9FDC2AB722E0AE184A8F5656C18113A858 ] stornvme C:\Windows\system32\drivers\stornvme.sys 22:48:48.0168 0x3e08 stornvme - ok 22:48:48.0168 0x3e08 [ 3A62FF78619258E6126C5C4B4CC82C8E, C72CC295680B35E0EEE5A5310E0241E2FFE0E540BFAA49C35C06AA882229C1CD ] storqosflt C:\Windows\system32\drivers\storqosflt.sys 22:48:48.0168 0x3e08 storqosflt - ok 22:48:48.0183 0x3e08 [ 212CB512B785E218667CCA56C4BFD71D, 5FD4CFEE5AB2187D928632076E6AD5C2C53D66884479C4D34930DCFCA3CCEE34 ] StorSvc C:\Windows\system32\storsvc.dll 22:48:48.0199 0x3e08 StorSvc - ok 22:48:48.0199 0x3e08 [ C6097966F8EA3B288070CDF7C3C8C3E8, D12C4AF3E54DCE1E5DC9C8AA0E83420F481DC0165A7F7845083A85BABC102D37 ] storufs C:\Windows\system32\drivers\storufs.sys 22:48:48.0199 0x3e08 storufs - ok 22:48:48.0214 0x3e08 [ 3DC3B17E92DA02E36B4138733DF6C1AC, 398F20B6D6DAF6DA950C149F63F3B23864E1478119BFE53218C220CEADEC800D ] storvsc C:\Windows\system32\drivers\storvsc.sys 22:48:48.0214 0x3e08 storvsc - ok 22:48:48.0214 0x3e08 [ D284AB2CA6C30317D142D38CE1F848BE, 4C9EAE174F5C673CA550C9382E85CE7DAF5DC9965495BAB09078B634A4CDD4FB ] svsvc C:\Windows\system32\svsvc.dll 22:48:48.0214 0x3e08 svsvc - ok 22:48:48.0214 0x3e08 [ 2BC4D0EBC2467FE90302AE0AFAF23768, CF8BCC9CA1FBA8407FD044613A2497BEEC641DE463B076F0ED1FA7674C202ADE ] swenum C:\Windows\System32\drivers\swenum.sys 22:48:48.0214 0x3e08 swenum - ok 22:48:48.0230 0x3e08 [ 13985DA558FBCBFD9108A2CACB5FE494, DD457A73E82147AA90C36D695A47E862FF90D96FB1E22760FAB5780F7C332A46 ] swprv C:\Windows\System32\swprv.dll 22:48:48.0230 0x3e08 swprv - ok 22:48:48.0230 0x3e08 [ 572F81CF08972D53BAFFC2A110A2A586, D9AF8EBB31CE097849F93FC8C0F06178B2E1CA8C48D08BBDD85174CCD64A16D6 ] Synth3dVsc C:\Windows\System32\drivers\Synth3dVsc.sys 22:48:48.0230 0x3e08 Synth3dVsc - ok 22:48:48.0252 0x3e08 [ 7C29BBF63178BB6788AD1C2B231150A5, 5114AC1260C5447D3B21C7C56D825C1E77FCE388C5630D0200C8256F69EFA6B4 ] SysMain C:\Windows\system32\sysmain.dll 22:48:48.0268 0x3e08 SysMain - ok 22:48:48.0283 0x3e08 [ 97E0FD613D031EAA73E8AD259169AC22, E86E9B9C18AF2E79D7CF80B177A12D89418CDBD3CBB74307809DD0377408DB82 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll 22:48:48.0283 0x3e08 SystemEventsBroker - ok 22:48:48.0283 0x3e08 [ 7F285486F82AB978917EE8897C10CB42, F8895F0CAB3ACB96F3AD113D81013BD5B4DEACB561A1AF02B1C898755D34BBD0 ] TabletInputService C:\Windows\System32\TabSvc.dll 22:48:48.0283 0x3e08 TabletInputService - ok 22:48:48.0299 0x3e08 [ 5B4A09AB34D0205C616C4D247AD29F57, B1DBDD5E2149114E1DCC56DAB00876AAE1FBFC5D4063D3F5A59D8C66918EF693 ] tap-tb-0901 C:\Windows\System32\drivers\tap-tb-0901.sys 22:48:48.0299 0x3e08 tap-tb-0901 - ok 22:48:48.0299 0x3e08 [ C1C6A802C2A9A57029D4347E251F4D18, 9F75B7F003C829FFDB2CDC98231D32FE988754D23873048FA4F6EB82ED1DCED4 ] TapiSrv C:\Windows\System32\tapisrv.dll 22:48:48.0299 0x3e08 TapiSrv - ok 22:48:48.0352 0x3e08 [ 9360DA9E370C1E1483967351C0CB7245, 48D46564C2D762C919E2638C4E97FA6CC02FB2775EB9F0B9A99D38A40D823205 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 22:48:48.0383 0x3e08 Tcpip - ok 22:48:48.0430 0x3e08 [ 9360DA9E370C1E1483967351C0CB7245, 48D46564C2D762C919E2638C4E97FA6CC02FB2775EB9F0B9A99D38A40D823205 ] Tcpip6 C:\Windows\system32\drivers\tcpip.sys 22:48:48.0468 0x3e08 Tcpip6 - ok 22:48:48.0468 0x3e08 [ 1C35A5C62D110346379C55E39A3D547C, 5BDBD593AB51ECA5A6B703E86F300E3B2B153E128BEB9A006ABD827AE726BD62 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 22:48:48.0468 0x3e08 tcpipreg - ok 22:48:48.0484 0x3e08 [ D74756DD1518D28A09CDA99696273FA4, F01DDF8CDBBC70BB086970C324E60CF7A1828CA6DE5A4F5B1BA4686BC31C4058 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 22:48:48.0484 0x3e08 tdx - ok 22:48:48.0484 0x3e08 [ 96A35CDBA661D41C5A3914257CA1D200, 691ABBAA99C673E7D0B81D811BCC60976C3EC050F2B39B35B87A3BCC211F119A ] terminpt C:\Windows\System32\drivers\terminpt.sys 22:48:48.0484 0x3e08 terminpt - ok 22:48:48.0499 0x3e08 [ 0B5C6D1683CDE89B3488326C60EA6EF2, 3B822CF005FA3002F27FF9BF39E7E133987230DA3481CFCF99F3B2B6B373A718 ] TermService C:\Windows\System32\termsrv.dll 22:48:48.0515 0x3e08 TermService - ok 22:48:48.0531 0x3e08 [ 6568EF1B30101979107055B7E515EE58, A318082E5FDD79C9F85E8C00A78EBFA0EC44B1046976E85633DC7BD123DA38B9 ] Themes C:\Windows\system32\themeservice.dll 22:48:48.0531 0x3e08 Themes - ok 22:48:48.0531 0x3e08 [ 2ABC11CFC2F03A919AF78A6E3E29C570, 54D91F89993A0FF090E2213EED92DE3659DCB693FBDA5932E31C6D6D7CFC8E80 ] TieringEngineService C:\Windows\system32\TieringEngineService.exe 22:48:48.0549 0x3e08 TieringEngineService - ok 22:48:48.0552 0x3e08 [ 4F9A5CE9F3C75AF1EE4B00D5E69F7CF7, 5FEE41C10629E89BD372E5D6C05A78FC0F2C394F4DE7C70AACC8720C6C6590DA ] tiledatamodelsvc C:\Windows\system32\tileobjserver.dll 22:48:48.0568 0x3e08 tiledatamodelsvc - ok 22:48:48.0568 0x3e08 [ E59D4F92FE11B47AB727C6D192CC977F, 1DA06663889A20A1B22DDF90E5C99A5668023C0B89E252F3E820C0D1964B1948 ] TimeBrokerSvc C:\Windows\System32\TimeBrokerServer.dll 22:48:48.0568 0x3e08 TimeBrokerSvc - ok 22:48:48.0599 0x3e08 [ 199A7AEAB23122F74AB6A8FA87C5EC76, F45694C1DEC8A244FB924837C4377C19AE8D1DBBE808FB946E64FBBBE8EC8A6A ] TokenBroker C:\Windows\System32\TokenBroker.dll 22:48:48.0615 0x3e08 TokenBroker - ok 22:48:48.0615 0x3e08 [ F76A92975340DAA99939DA297D677EA8, 51DA87E921BBA21BF39D7D9B691CEF8B1D2BCE2BBB0BA5B3C12B7E98CB5C702E ] TPM C:\Windows\System32\drivers\tpm.sys 22:48:48.0615 0x3e08 TPM - ok 22:48:48.0630 0x3e08 [ 85E0D4431D61675A94EA99C9E1F56436, 9FA750703E04D20A62DBB0185CBDD70AFC4573FB65F86E61AAF7CF7A7D8E1E3E ] TrkWks C:\Windows\System32\trkwks.dll 22:48:48.0630 0x3e08 TrkWks - ok 22:48:48.0630 0x3e08 [ F21A69013A67B372675F523262AC1E33, C3F910E375C0F4B7FFA6F6D755622FF6B0CAE36DF691C938DE177C94815FE3C8 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 22:48:48.0630 0x3e08 TrustedInstaller - ok 22:48:48.0630 0x3e08 [ 9856BCCD1CD5DE4D17E8DBBA7CEFC688, F4B532DCE6F4728092848FE7B2FC05AB921EC7B3FDD7E62AB40EE0029C008398 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 22:48:48.0647 0x3e08 TsUsbFlt - ok 22:48:48.0651 0x3e08 [ 837AD2B941E721BCCEB7EF137E2DEE18, 84BE22616A50467B1957434C8BD19C8B0FC3B21CD77FFB8E16A09347CEAE0F4E ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys 22:48:48.0651 0x3e08 TsUsbGD - ok 22:48:48.0653 0x3e08 [ 5DED9E34D133F4A363652CDB595D83F3, E8CFE5DF737D7C2A576B2D6D508977E1F6961122D541DF82AA581C7B3B1C384B ] tsusbhub C:\Windows\system32\drivers\tsusbhub.sys 22:48:48.0653 0x3e08 tsusbhub - ok 22:48:48.0653 0x3e08 [ B3142C6118703E98EB0510CF7B43D0F2, 40FDCBAA2AD93026AD479BF8C1B4EE7A4E2E65590608B6B1C5DEB3C4716E5C03 ] tunnel C:\Windows\System32\drivers\tunnel.sys 22:48:48.0653 0x3e08 tunnel - ok 22:48:48.0669 0x3e08 [ B7324ABBA8BB65A26EC8D35FA88C7D8C, 1ED4F85A25BD9C0F9E58010F88198A43D67313C5176B24C04BD3A83F74EA56FE ] TunnelBearMaintenance C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe 22:48:48.0669 0x3e08 TunnelBearMaintenance - ok 22:48:48.0669 0x3e08 [ B097B77121A057AB6D70C647636978D4, 10F78A18AC898CDD0FA91D6FA29B8B45C6D8F6CE65B064C39256EB20FC6CD085 ] tzautoupdate C:\Windows\system32\tzautoupdate.dll 22:48:48.0669 0x3e08 tzautoupdate - ok 22:48:48.0669 0x3e08 [ B4C846ABD462558D45CA578C855759C3, E0F0DD39A6C101C2209CA46EF2B5A5F4559843C9EE37CC08ED78D9E124A566D2 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys 22:48:48.0684 0x3e08 UASPStor - ok 22:48:48.0684 0x3e08 [ 7B2B767C4DB23F87C698C139BEBEA400, 8E58AA7C05C183EC88423FA2CB72E082D0177120DAFE798EA04C5BB91ED52D89 ] UcmCx0101 C:\Windows\system32\Drivers\UcmCx.sys 22:48:48.0684 0x3e08 UcmCx0101 - ok 22:48:48.0684 0x3e08 [ 8BB64E04CD97AD8C68543181D93E2AFC, FBA2FB9A9906721BAD42CDFFCCE0234AF3F72B83E2571E526801F19173B7C9CE ] UcmTcpciCx0101 C:\Windows\system32\Drivers\UcmTcpciCx.sys 22:48:48.0684 0x3e08 UcmTcpciCx0101 - ok 22:48:48.0700 0x3e08 [ F083A400FB9CB8ADD1783848CB1C76F0, 7E543E5F81C04AF486ACC08B94F785B9702B743C96079241925C385BF8411EB9 ] UcmUcsi C:\Windows\System32\drivers\UcmUcsi.sys 22:48:48.0700 0x3e08 UcmUcsi - ok 22:48:48.0700 0x3e08 [ 5D4EAF3D0911338CB8FDB088386D6DCA, 1AC5B494C39570E66C4D4F867C6B8E37C174FB5D67C2865B07247122F60F8895 ] Ucx01000 C:\Windows\system32\drivers\ucx01000.sys 22:48:48.0700 0x3e08 Ucx01000 - ok 22:48:48.0716 0x3e08 [ 384E1F0D84B465820416338E52FE7C2B, 8F82778332EA1199987BA569536CBED8FEAF5E9D920321B0C9DFCBDDD91EEA35 ] UdeCx C:\Windows\system32\drivers\udecx.sys 22:48:48.0716 0x3e08 UdeCx - ok 22:48:48.0716 0x3e08 [ C82BE75239D412057C9E3DB1785680C6, AE712E40440F5725DA41C95C3E558B5E9ABB17C55B70297DD40D7D1BDA7CE45D ] udfs C:\Windows\system32\DRIVERS\udfs.sys 22:48:48.0716 0x3e08 udfs - ok 22:48:48.0731 0x3e08 [ CCDF6EFF952BF3BF34DC17600F479397, 2A2009B3C4BD1A44F1C6E334CB0A7DD02443BCE1EB48837C1C70A2A04CC7C54A ] UEFI C:\Windows\System32\drivers\UEFI.sys 22:48:48.0731 0x3e08 UEFI - ok 22:48:48.0731 0x3e08 [ 244A80A1A881E2B9303A0364AAB33F16, 3C58D5D5B1AF6AB598E6450817381E7D6B8700151B66DCDAD6002E73BD0EDF27 ] UevAgentDriver C:\Windows\system32\drivers\UevAgentDriver.sys 22:48:48.0731 0x3e08 UevAgentDriver - ok 22:48:48.0753 0x3e08 [ BDED7971CA7D1B8ACC6D93C2C1C9D4F8, 71350470C69277D35B90D4B2B2B1F1C9FC978BF7B604B837C0A6818E6352EB61 ] UevAgentService C:\Windows\system32\AgentService.exe 22:48:48.0769 0x3e08 UevAgentService - ok 22:48:48.0785 0x3e08 [ 00BEF71C45FD6B06E7525E7B31EFA88C, C0BDE8CB41BF9A34E395EA86756637E4CD6B88EF1C842364ECA639948D6CD59A ] Ufx01000 C:\Windows\system32\drivers\ufx01000.sys 22:48:48.0785 0x3e08 Ufx01000 - ok 22:48:48.0785 0x3e08 [ 9450AB15C30CF7D1F23C8A42E778C3A2, E62455008ED5B7220AEE62E0F459A67E26FB2878349ABA5AAF0164C2E7A8C0E9 ] UfxChipidea C:\Windows\System32\drivers\UfxChipidea.sys 22:48:48.0785 0x3e08 UfxChipidea - ok 22:48:48.0785 0x3e08 [ CEE12C7A689BDF448715024A7E0EB9C3, EC48E1469800E34A71C8A97A6F2F0B7C67385BCB8438844E6967DE0A82E39B94 ] ufxsynopsys C:\Windows\System32\drivers\ufxsynopsys.sys 22:48:48.0800 0x3e08 ufxsynopsys - ok 22:48:48.0800 0x3e08 [ 5A2F610B31CC3FD23D3E20C1D5F1EF52, D470B7C1CAE066C2DCDBA47001913FB1A7C9CC5B200FB8324DB896B641C1A132 ] UI0Detect C:\Windows\system32\UI0Detect.exe 22:48:48.0800 0x3e08 UI0Detect - ok 22:48:48.0800 0x3e08 [ F39ED750EDF5948FA8CD99D1F4EC9372, AE42AE50DE09F26D3CA4ACDCD5ECABD59D26926707030F0532A885266FE83EF9 ] umbus C:\Windows\System32\drivers\umbus.sys 22:48:48.0800 0x3e08 umbus - ok 22:48:48.0816 0x3e08 [ 55984D4E64C2F8E4223542CBCC15EDEB, ECBC832FBBA6AFCAEDEBB2728FA4A6DDCF52A6421929E72CA29B61CDBED840DF ] UmPass C:\Windows\System32\drivers\umpass.sys 22:48:48.0816 0x3e08 UmPass - ok 22:48:48.0816 0x3e08 [ FBEF4641E3E08A03CA84AF5C393CA86B, 9A14A0FB645AB6DD0B49F3A14FBF38FECC65796F2503324E93994113CC7AD52F ] UmRdpService C:\Windows\System32\umrdp.dll 22:48:48.0816 0x3e08 UmRdpService - ok 22:48:48.0852 0x3e08 [ 5B17D5E9FBF65ED93078DEB687357BAF, 00BC68F16E36681254E72D8D39006F695D38246EAB6ABC6F40E5305D5ACE26A1 ] UnistoreSvc C:\Windows\System32\unistore.dll 22:48:48.0869 0x3e08 UnistoreSvc - ok 22:48:48.0869 0x3e08 [ BBB6BDBE5ADCE6F87F70623D5A1EC5BC, E8BD5804FF82417890A9D1A44096B174E81A8C7AD3059B1F0C62740E0B39D137 ] upnphost C:\Windows\System32\upnphost.dll 22:48:48.0885 0x3e08 upnphost - ok 22:48:48.0885 0x3e08 [ 4D23214CB8B1C36B82061280EB8FDAB3, 387C01A7F9D8F89ED894EDF894AAAF8830DD7C90DF2F12A2CB4C4E9C7CB773BE ] UrsChipidea C:\Windows\System32\drivers\urschipidea.sys 22:48:48.0885 0x3e08 UrsChipidea - ok 22:48:48.0885 0x3e08 [ 4329D880DB96B504F0DDC991A7374CCD, 1486BEF2C03ED281B24A17D3C18FEA2360E37A6B46D1A67D4690CD871B0A13DA ] UrsCx01000 C:\Windows\system32\drivers\urscx01000.sys 22:48:48.0885 0x3e08 UrsCx01000 - ok 22:48:48.0901 0x3e08 [ 93FAD0AC5879F274FA248A49E3F3EA33, D936F408E23040B33F30AB3B43D8B8BB9F3CCF2549E821F4C47357987AFF386F ] UrsSynopsys C:\Windows\System32\drivers\urssynopsys.sys 22:48:48.0901 0x3e08 UrsSynopsys - ok 22:48:48.0901 0x3e08 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\Windows\System32\Drivers\usbaapl64.sys 22:48:48.0901 0x3e08 USBAAPL64 - ok 22:48:48.0901 0x3e08 [ FC318082D0793B76C766A8DFD4C247C5, F547C643A16D580BD96BC20DC901A8210875812EDABD57DD65F20A915A877CB3 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 22:48:48.0901 0x3e08 usbaudio - ok 22:48:48.0916 0x3e08 [ D3FE21B96DDFE97F50E8563FCF21C546, 098B550F10B70BD76BF29086425A9EC6F136A94EDFE67C506A0AC4F3C9398103 ] usbccgp C:\Windows\System32\drivers\usbccgp.sys 22:48:48.0916 0x3e08 usbccgp - ok 22:48:48.0916 0x3e08 [ ECE3AD18B4C22ED0C4AB1A2AD9AC32C8, 2062D400305075E886CF2C9D710A1C48B3F4AD48E7A75A77C66547357E96CB6E ] usbcir C:\Windows\System32\drivers\usbcir.sys 22:48:48.0916 0x3e08 usbcir - ok 22:48:48.0932 0x3e08 [ F8BCB536866474C6D8008F4C69B778A1, F86F4330DE2F50D48559C1ED46168ADB8F6AA7C8FE3834FFE00085C1783C5750 ] usbehci C:\Windows\System32\drivers\usbehci.sys 22:48:48.0932 0x3e08 usbehci - ok 22:48:48.0932 0x3e08 [ E9039631072644E0EF5488885F3925F9, CA5B306710DE7001014034F5C90D6EEF42CE24359702BB0A2FF90F8E9A87F3FB ] usbhub C:\Windows\System32\drivers\usbhub.sys 22:48:48.0953 0x3e08 usbhub - ok 22:48:48.0953 0x3e08 [ 62F77D1A95EC9CCF40648695FA910729, A877755E8D825DC1910C4C4ABFE690CA905A7B889603E880BA52EE76DD5214C1 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys 22:48:48.0969 0x3e08 USBHUB3 - ok 22:48:48.0969 0x3e08 [ BE6ED98FD0D3FE5FB11762AD7CCD6C96, 54C6C929CA55EA6770474F7E230190FC7574C1FA52437B564B3B5FA4D6106D8A ] usbohci C:\Windows\System32\drivers\usbohci.sys 22:48:48.0969 0x3e08 usbohci - ok 22:48:48.0969 0x3e08 [ CEE43CD5357DB8786CE6E2C430841AE4, 50F4629AE488A12D18EFFAD486D2F95545049AB1F6A3248BA44D2132EEC9A653 ] usbprint C:\Windows\System32\drivers\usbprint.sys 22:48:48.0969 0x3e08 usbprint - ok 22:48:48.0985 0x3e08 [ 8E6AE06A1CA4055340A49D73C9E0C21B, 82DC9F8A70FB1EB1F4A7B5697C72926C352FBA2DF06F539BDCDF0AE574D67CB9 ] usbser C:\Windows\System32\drivers\usbser.sys 22:48:48.0985 0x3e08 usbser - ok 22:48:48.0985 0x3e08 [ 67E26F56CF7EACCBD9C9F75343A3D7C2, 210FA280897CCCB2458E9E683A8B4CA8A5DF9606B54F8B9CE05CA4AA6FD810AB ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS 22:48:48.0985 0x3e08 USBSTOR - ok 22:48:48.0985 0x3e08 [ 7BA802C9F73A84B75BB22538ADA495BE, 7D97E6305168C4CA86AB9BD5B63300156DFE97032251CB83DB1D4C4DB9C28DC8 ] usbuhci C:\Windows\System32\drivers\usbuhci.sys 22:48:48.0985 0x3e08 usbuhci - ok 22:48:49.0000 0x3e08 [ 50E70B3A95138AA4A30B095270EE0DE6, 9B7072C36230102A089C4A6DFE1980CD9DB28E566EF02830600DEBAF3AAD31C7 ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS 22:48:49.0000 0x3e08 USBXHCI - ok 22:48:49.0032 0x3e08 [ 3EDFCC32481EDE3C98645754DB0965C4, 0EE181B27BA15932E734BB764B52EEC369790F763D46B317E1AE62761767EACB ] UserDataSvc C:\Windows\System32\userdataservice.dll 22:48:49.0054 0x3e08 UserDataSvc - ok 22:48:49.0069 0x3e08 [ C0E60CC6D48013728C7E4168D61A0B39, CA283312E9669BCC74A3B5E6332502D1CAA7148C049B94AF3996F3C7CD2676EF ] UserManager C:\Windows\System32\usermgr.dll 22:48:49.0085 0x3e08 UserManager - ok 22:48:49.0101 0x3e08 [ 34BB2D106F8757F662B4914013F625DE, 4E3706017BDF89F26163D92973E5E224EF24B420CB0F35D68EBAB285246E5014 ] UsoSvc C:\Windows\system32\usocore.dll 22:48:49.0116 0x3e08 UsoSvc - ok 22:48:49.0116 0x3e08 [ BA909DA3D184EF80F9293AB9E12FF30F, 5C9BB19D447698F4EAE8D9A26548703C4B8B6FEB68D49E6F2516666E5226236A ] VaultSvc C:\Windows\system32\lsass.exe 22:48:49.0116 0x3e08 VaultSvc - ok 22:48:49.0132 0x3e08 [ E0323496872FDCED10E64A49312BA448, 55915B71AC2D0ED105BDF00D96380A3D344E43D57EB6CEFE3BF9170FC5165FC6 ] VBoxDrv C:\Windows\system32\DRIVERS\VBoxDrv.sys 22:48:49.0154 0x3e08 VBoxDrv - ok 22:48:49.0154 0x3e08 [ E330CAD54160934D1FB0CC35A49C9CD1, 64EC0534A55DA80B8B3520FE3BB43F9BBEECCCA8F5C3CC3957FA84F40AACDAC3 ] VBoxNetAdp C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys 22:48:49.0154 0x3e08 VBoxNetAdp - ok 22:48:49.0154 0x3e08 [ B74B2FDA5BF4731515E564B71BBB0C15, F550A5730C58BEE36928731EE40B9FA8953E06D65CA2B96DDD118E524F38D250 ] VBoxNetLwf C:\Windows\system32\DRIVERS\VBoxNetLwf.sys 22:48:49.0169 0x3e08 VBoxNetLwf - ok 22:48:49.0169 0x3e08 [ B6D30F19832E3695B107BBA0F78DD3CB, 0D03154BB7C597B427A3738B89FD3747CC6CD31722E522CE008614EC77707A29 ] VBoxUSBMon C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 22:48:49.0169 0x3e08 VBoxUSBMon - ok 22:48:49.0169 0x3e08 [ C1EC9211C7759D2487FD30934AA3EE96, 6914BB8B44550DFE75E5A3772E93ADF8459EB621CA400BDD9B7E3185A09B6F9A ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 22:48:49.0169 0x3e08 vdrvroot - ok 22:48:49.0185 0x3e08 [ 374CD93271184F04988FDC1C25B3E855, 09727093C5F7B258867C16D41F7F9835BF549CC339288BFE01A8F34AC7E93E23 ] vds C:\Windows\System32\vds.exe 22:48:49.0201 0x3e08 vds - ok 22:48:49.0201 0x3e08 [ C83F3BC00651448DB127D497CF955089, 31B8838CEED08E7D5DD8635A805A8010798BD9B10A3775FAFDB576FBD7303D39 ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys 22:48:49.0201 0x3e08 VerifierExt - ok 22:48:49.0216 0x3e08 [ 0E12F5F6B1C813D17AFDA197C4394423, B0AFDFE0E12633C6D984DA366197BE09ED2649BAFF525FA0DE84701E5B335DB9 ] vhdmp C:\Windows\System32\drivers\vhdmp.sys 22:48:49.0232 0x3e08 vhdmp - ok 22:48:49.0232 0x3e08 [ 1AD096A5C00E522398D0092D875A8CB6, 6959FCD6DD2115CD293DBD4BCD6D1BA0AE4F7495A9BBB48F7388384EEABB38E9 ] vhf C:\Windows\System32\drivers\vhf.sys 22:48:49.0232 0x3e08 vhf - ok 22:48:49.0232 0x3e08 [ EE9A22CFD9AEDD7B52F98B0272494609, F668131BABD048857F011A471936B52EDF0F2A42CB6000ACB4E0E43F88782AAD ] vmbus C:\Windows\system32\drivers\vmbus.sys 22:48:49.0232 0x3e08 vmbus - ok 22:48:49.0250 0x3e08 [ BFBD0895926FD98A03AD6BB845B569B7, 5B7913ACD6CC132B2F36B079BC5F897C21884A7F21046B8996CC3D74C4B6DA4C ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys 22:48:49.0250 0x3e08 VMBusHID - ok 22:48:49.0253 0x3e08 [ C123C97D351C56C75FE5335AB18255EE, 67315E332E863E5C233BA113826A5DEEE08C1A0A3358E6AC21F25DC5EAC86D07 ] vmgid C:\Windows\System32\drivers\vmgid.sys 22:48:49.0253 0x3e08 vmgid - ok 22:48:49.0254 0x3e08 [ A9C889CFDDE704A15CDC639C3D6662B6, 9EE41886D9E8DFDB512B821EAFE1857E83A3C3318EB852A2C110DB8184346AA9 ] vmicguestinterface C:\Windows\System32\icsvc.dll 22:48:49.0254 0x3e08 vmicguestinterface - ok 22:48:49.0270 0x3e08 [ A9C889CFDDE704A15CDC639C3D6662B6, 9EE41886D9E8DFDB512B821EAFE1857E83A3C3318EB852A2C110DB8184346AA9 ] vmicheartbeat C:\Windows\System32\icsvc.dll 22:48:49.0270 0x3e08 vmicheartbeat - ok 22:48:49.0270 0x3e08 [ A9C889CFDDE704A15CDC639C3D6662B6, 9EE41886D9E8DFDB512B821EAFE1857E83A3C3318EB852A2C110DB8184346AA9 ] vmickvpexchange C:\Windows\System32\icsvc.dll 22:48:49.0270 0x3e08 vmickvpexchange - ok 22:48:49.0285 0x3e08 [ F8F380ABEAFBC589FF6D2D96267C1210, 0CFA3D9E88D984BAFED8E08102BF4DC4077856C6C8C1EBD8D4C4D0D49B673F44 ] vmicrdv C:\Windows\System32\icsvcext.dll 22:48:49.0285 0x3e08 vmicrdv - ok 22:48:49.0301 0x3e08 [ A9C889CFDDE704A15CDC639C3D6662B6, 9EE41886D9E8DFDB512B821EAFE1857E83A3C3318EB852A2C110DB8184346AA9 ] vmicshutdown C:\Windows\System32\icsvc.dll 22:48:49.0301 0x3e08 vmicshutdown - ok 22:48:49.0301 0x3e08 [ A9C889CFDDE704A15CDC639C3D6662B6, 9EE41886D9E8DFDB512B821EAFE1857E83A3C3318EB852A2C110DB8184346AA9 ] vmictimesync C:\Windows\System32\icsvc.dll 22:48:49.0317 0x3e08 vmictimesync - ok 22:48:49.0317 0x3e08 [ A9C889CFDDE704A15CDC639C3D6662B6, 9EE41886D9E8DFDB512B821EAFE1857E83A3C3318EB852A2C110DB8184346AA9 ] vmicvmsession C:\Windows\System32\icsvc.dll 22:48:49.0317 0x3e08 vmicvmsession - ok 22:48:49.0332 0x3e08 [ F8F380ABEAFBC589FF6D2D96267C1210, 0CFA3D9E88D984BAFED8E08102BF4DC4077856C6C8C1EBD8D4C4D0D49B673F44 ] vmicvss C:\Windows\System32\icsvcext.dll 22:48:49.0332 0x3e08 vmicvss - ok 22:48:49.0332 0x3e08 [ 0AB9C264F13E2A070A8CF10EDD099ED2, 2E7EB4EE8DCBBCA497CC0E7F4BE057627E9702B6FAF56A7DBCA1325236C880EC ] volmgr C:\Windows\system32\drivers\volmgr.sys 22:48:49.0332 0x3e08 volmgr - ok 22:48:49.0352 0x3e08 [ 6EE608257C1137A25B402EF8FC77E83A, 3AE684EBA32563468AD917155C93220F938460A699FBFC3DB8436F83C0C54209 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 22:48:49.0354 0x3e08 volmgrx - ok 22:48:49.0354 0x3e08 [ E3429DBBEA3965BB96E24B16EF4A2551, 0CEE2DEF75C6761DA67AFD3BBF8DEEB1331796719EB84D658B3E517DEC824B49 ] volsnap C:\Windows\system32\drivers\volsnap.sys 22:48:49.0370 0x3e08 volsnap - ok 22:48:49.0370 0x3e08 [ 86E790B503C771E674C7DF8FFCBFEFDB, 634B27C4FA363A2165D3D6929D3B22F41EE06198C579A70D446A48830924467B ] volume C:\Windows\system32\drivers\volume.sys 22:48:49.0370 0x3e08 volume - ok 22:48:49.0370 0x3e08 [ B25589A0892E6DF8CC07E5CB48BFC954, DA29974426EFD4472A3828FA0EF31AD3860AA8068AB66B5F4BE6A412BC3E73E9 ] vpci C:\Windows\System32\drivers\vpci.sys 22:48:49.0370 0x3e08 vpci - ok 22:48:49.0385 0x3e08 [ AA4466A47D2CA7ECE3DCF5256017DCC3, 83414BFBD3DF1CB7417F0F55709E8180D97FA20A74581C34EAAFF667FBEBFD93 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 22:48:49.0385 0x3e08 vsmraid - ok 22:48:49.0417 0x3e08 [ 0BB73BF6FDDD19DE3DE9377EA95E4C64, 74B6E612F9E009A5E43B603BCAD854F3711F6C8A7ED0328B1E3A9B2D4C9EA342 ] VSS C:\Windows\system32\vssvc.exe 22:48:49.0432 0x3e08 VSS - ok 22:48:49.0449 0x3e08 [ 98BB6C9AD39D8F2E883093F28282FAEC, 63F4036A1DB23C20AAEEC1CA8ABDE9B46FA09A55EA4E5DB0C0B5D6D58ABAD62F ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys 22:48:49.0454 0x3e08 VSTXRAID - ok 22:48:49.0454 0x3e08 [ B47026E109828102266CBE2F5F9AD113, 28C76B34C48BACEA267A208CC758BB55539323B16300E869AE71B6A99A849AB5 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 22:48:49.0454 0x3e08 vwifibus - ok 22:48:49.0454 0x3e08 [ 799ECD541A9B2764B36A22A095885365, E255E74682927D662294AA3F88FDA211EEE603466EB264E8941C3BACC6A0E530 ] vwififlt C:\Windows\system32\drivers\vwififlt.sys 22:48:49.0454 0x3e08 vwififlt - ok 22:48:49.0470 0x3e08 [ E75460AC4E936BFC0703021DB0BB17B8, D9985C3206B503659FD2F4EE7FD0B9AF8CB2DE821BFD68B13C9E3BD9CE5AEF6B ] W32Time C:\Windows\system32\w32time.dll 22:48:49.0470 0x3e08 W32Time - ok 22:48:49.0486 0x3e08 [ F0F477541F7AF67CC05DA1CF4921A500, F7DD2F49B61C484596DE3893683B1172A138386BD71F54BFCF37A31005C7368F ] WacomPen C:\Windows\System32\drivers\wacompen.sys 22:48:49.0486 0x3e08 WacomPen - ok 22:48:49.0486 0x3e08 [ A0957CBC1C054A87EE7A65A994102A96, CB6339F3F67D0E33C26E6756F88869574B84426B20C907E094F83B9DC5E36A3E ] WalletService C:\Windows\system32\WalletService.dll 22:48:49.0501 0x3e08 WalletService - ok 22:48:49.0501 0x3e08 [ FDD16EF9177A8A2EF08A7FA3D3EFAA13, 148F34CBEEF0CE87103C76294AE5BE318F990A5FE7A5EDE6F47D85361248582B ] wanarp C:\Windows\system32\DRIVERS\wanarp.sys 22:48:49.0501 0x3e08 wanarp - ok 22:48:49.0517 0x3e08 [ FDD16EF9177A8A2EF08A7FA3D3EFAA13, 148F34CBEEF0CE87103C76294AE5BE318F990A5FE7A5EDE6F47D85361248582B ] wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 22:48:49.0517 0x3e08 wanarpv6 - ok 22:48:49.0533 0x3e08 [ EA0524A2A01792796EC80AE2FE08307A, 68CC0F3451C6797222411C276376C7741C96C45E628DD77FB1FB17C10DC0EA8A ] wbengine C:\Windows\system32\wbengine.exe 22:48:49.0554 0x3e08 wbengine - ok 22:48:49.0586 0x3e08 [ 39A0B8DD517E3CBF0A6EED5A12BB182F, A25E7D3DC4DF9D0439627CFA0C4AD2292FDF29F4EFC832AEA5A2F774766F76D7 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 22:48:49.0601 0x3e08 WbioSrvc - ok 22:48:49.0601 0x3e08 [ 923200B78F5284D674A3712204D0FEFA, 4B00785D2E9D12052C2C8E80C568606E0148AA230285D4018A0A603E16224CEE ] wcifs C:\Windows\system32\drivers\wcifs.sys 22:48:49.0601 0x3e08 wcifs - ok 22:48:49.0617 0x3e08 [ 4CC7119E1527B0A34C50870002E6B7AC, 2C93CF62E01A208453A291A74E0392BA1CA1407CD76E506D7DD638386FE1DE99 ] Wcmsvc C:\Windows\System32\wcmsvc.dll 22:48:49.0633 0x3e08 Wcmsvc - ok 22:48:49.0650 0x3e08 [ 2C396871F724DDF871A2EF4CADE5151D, 8CAD8A393F0CC447432E1BED21A691E25356F7DBC06E3887138A6F86CB1D656D ] wcncsvc C:\Windows\System32\wcncsvc.dll 22:48:49.0655 0x3e08 wcncsvc - ok 22:48:49.0655 0x3e08 [ 1737BEF60CA384423CE4B32AF1C2BFFC, D61353D3B2EAEDFDCBB5DB3AD27E76396CC7755AFF01233307EAA1967493DE63 ] wcnfs C:\Windows\system32\drivers\wcnfs.sys 22:48:49.0655 0x3e08 wcnfs - ok 22:48:49.0655 0x3e08 [ 38130C1C5FE0E08820EE57E1B087B659, 3705AA4699D4C402C0BBC5BC4E1EE67CB4A4B9C27702E88952A76891C3A3F496 ] WdBoot C:\Windows\system32\drivers\WdBoot.sys 22:48:49.0655 0x3e08 WdBoot - ok 22:48:49.0670 0x3e08 [ 0C6CBF3490EE5F0D62B5820568CA30B8, 97EDEC84DA72A900D7740B8763DDDAB600628F3F1E1DDE1212383C2E60FDC77C ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 22:48:49.0686 0x3e08 Wdf01000 - ok 22:48:49.0702 0x3e08 [ F7B6CB0F9ECD28848E2BDACEAB0D9204, B64D91A36600AEBE656F0514AF8653C294DE88054FE6DBB7B1A6D0A23D2A5131 ] WdFilter C:\Windows\system32\drivers\WdFilter.sys 22:48:49.0702 0x3e08 WdFilter - ok 22:48:49.0702 0x3e08 [ 501CB5E6999B7336BE5D0D401013D251, D4581E4FD8BE65D611E763AE88D2982A785036B2A93F2A00D3A3A395AB2AD5B3 ] WdiServiceHost C:\Windows\system32\wdi.dll 22:48:49.0717 0x3e08 WdiServiceHost - ok 22:48:49.0717 0x3e08 [ 501CB5E6999B7336BE5D0D401013D251, D4581E4FD8BE65D611E763AE88D2982A785036B2A93F2A00D3A3A395AB2AD5B3 ] WdiSystemHost C:\Windows\system32\wdi.dll 22:48:49.0717 0x3e08 WdiSystemHost - ok 22:48:49.0733 0x3e08 [ BF45B43BA47D0FA769CE5AFBF7104F01, CBEEC0E915162BEBFCD2CA9EF72C02E82AFAB2A016F1750A7982975A94599CF6 ] wdiwifi C:\Windows\system32\DRIVERS\wdiwifi.sys 22:48:49.0750 0x3e08 wdiwifi - ok 22:48:49.0755 0x3e08 [ 82A4F22C884B4BAE8B531640859F9871, 1C662557F671FA680E7CC2FC565B198470E421778BD03749CD05B2928568C430 ] WdNisDrv C:\Windows\system32\Drivers\WdNisDrv.sys 22:48:49.0755 0x3e08 WdNisDrv - ok 22:48:49.0755 0x3e08 WdNisSvc - ok 22:48:49.0755 0x3e08 [ 9066FE8EAB91E15437CB3C43757F2A65, 1F8B3D8C90C7862CCAB91D170F49E7F1D58FABAFA1C8DDDE1796404D1DD98707 ] WebClient C:\Windows\System32\webclnt.dll 22:48:49.0755 0x3e08 WebClient - ok 22:48:49.0771 0x3e08 [ F322B8E6C5614E7975C8BF34B7A6710E, 299816001856E8C91BFBB9C48D87B7ACBD5A39F6A65147F5AE6EDB3065A893E9 ] Wecsvc C:\Windows\system32\wecsvc.dll 22:48:49.0771 0x3e08 Wecsvc - ok 22:48:49.0771 0x3e08 [ 04CA184EB5743DE5A2CCEEF2DB2DA8B3, E16921496F57B78A152A103F8D58601C9687360048A6CB51E76A96E3B64CC0FA ] WEPHOSTSVC C:\Windows\system32\wephostsvc.dll 22:48:49.0771 0x3e08 WEPHOSTSVC - ok 22:48:49.0786 0x3e08 [ A92AE9A042298E00BCC9BE877654DCA6, ACB2BE9F96CEF870043CFE69B98625779842518DB4F079F1E5C17E135A2EFAE3 ] wercplsupport C:\Windows\System32\wercplsupport.dll 22:48:49.0786 0x3e08 wercplsupport - ok 22:48:49.0786 0x3e08 [ EB3E11EC54371D840C9861EEFDAE1832, 568E3C63BE9A721001704967F57359A9243F50B620B77EC09BA4AB7F6AE324B0 ] WerSvc C:\Windows\System32\WerSvc.dll 22:48:49.0802 0x3e08 WerSvc - ok 22:48:49.0802 0x3e08 [ 4D64719B4819CA22A046EC32809BBD98, 0ABD6C7D039E57F5637E843388FA8D52072237061EB75C7CDEBC9E13A6C8F06E ] WFDSConMgrSvc C:\Windows\System32\wfdsconmgrsvc.dll 22:48:49.0818 0x3e08 WFDSConMgrSvc - ok 22:48:49.0818 0x3e08 [ 3C8F0ABD00E197101DCF43FEF8FB0D76, AF5C68B85EE1503ACD4AEA1D997F816C34293A77791D59A605DC18450B4906DE ] WFPLWFS C:\Windows\system32\drivers\wfplwfs.sys 22:48:49.0818 0x3e08 WFPLWFS - ok 22:48:49.0833 0x3e08 [ 2DEB40D6837956CE08A8F9EB3ECA5A01, B40D23E54CDF6BE05D6C5DA536BF6D998E79EDE9C391A42452F9F69EE206EA1E ] WiaRpc C:\Windows\System32\wiarpc.dll 22:48:49.0833 0x3e08 WiaRpc - ok 22:48:49.0833 0x3e08 [ 75014BF6510D4C6C69EEE5B7743A52AF, 11AEEF4D52C35E5A7006713836ECF1198A53CD02736E792B1C698144CA1363F0 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 22:48:49.0833 0x3e08 WIMMount - ok 22:48:49.0833 0x3e08 WinDefend - ok 22:48:49.0833 0x3e08 [ C8EBCFED8FD2CDF725E44AF93016621E, A0B76E55CC535A0F1D79C3C0EC59753086EAB669EC7ADA4F97656DCAD2A69448 ] WindowsTrustedRT C:\Windows\system32\drivers\WindowsTrustedRT.sys 22:48:49.0849 0x3e08 WindowsTrustedRT - ok 22:48:49.0852 0x3e08 [ D318557F9D7CA3836104F0B8ECB1F32E, 6850BBFB4F65167B052F3CA22FD72E9188A14FD2A9CC085861B4BC40CBA34249 ] WindowsTrustedRTProxy C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys 22:48:49.0852 0x3e08 WindowsTrustedRTProxy - ok 22:48:49.0855 0x3e08 [ F99F66FD660B1CD01EE410F6B4BB3C25, 4B6993791DF31DBB84722BD0BA01AF7952375D2E01F7B8D92AAB53C50AFB59A8 ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll 22:48:49.0871 0x3e08 WinHttpAutoProxySvc - ok 22:48:49.0871 0x3e08 [ 31DDF1D001336B2DCE7DF24E99EF1D04, A1FCABF4A263BFAE042FE7A9F6C15FD9B3D8E985278C32AE8975ECE79B341277 ] WinMad C:\Windows\System32\drivers\winmad.sys 22:48:49.0886 0x3e08 WinMad - ok 22:48:49.0886 0x3e08 [ 9A26F7834706A6D8C8824EB08FD7C362, 750F6A0759D70BE481C70FE4BB21D18E756A8F0C23A014C2CE1E7729A1E625FE ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 22:48:49.0886 0x3e08 Winmgmt - ok 22:48:49.0902 0x3e08 [ 2E1A614EFB0523E20860AE7978DDA0A4, E13564690F9977747CA676D3843B467506447F060A5FF6676835A9C7A30BA409 ] WinNat C:\Windows\system32\drivers\winnat.sys 22:48:49.0902 0x3e08 WinNat - ok 22:48:49.0951 0x3e08 [ 27DAA9AA3E03C1068678D5659461BB32, AFDED6D671C430F296C9EAA73590111D6A8A9FA93DFE0595B90467FFE28EFB35 ] WinRM C:\Windows\system32\WsmSvc.dll 22:48:49.0987 0x3e08 WinRM - ok 22:48:49.0987 0x3e08 [ 03858B18BB6DF6A400D9FC5153FD28A8, C7AD69B022AEFDDDAFB74CCCDF20AF9CCDBA0097634BBBD07A2EFBA5922560C1 ] WINUSB C:\Windows\System32\drivers\WinUsb.sys 22:48:49.0987 0x3e08 WINUSB - ok 22:48:49.0987 0x3e08 [ 0BF4A43CF1F3A4D50AFA4561C3B4628D, 2D0B4E7004C8AC8A9EE07E6D5241BF32395CA142BF3B03FA9CF00BC6720A6AC7 ] WinVerbs C:\Windows\System32\drivers\winverbs.sys 22:48:49.0987 0x3e08 WinVerbs - ok 22:48:50.0003 0x3e08 [ 5087CF1105D03114B3A9B04F56A181AE, 6E674BF49C4B6618332AFDE65665074A7E1E65B1660B05CFF177D42149B3F395 ] wisvc C:\Windows\system32\flightsettings.dll 22:48:50.0018 0x3e08 wisvc - ok 22:48:50.0056 0x3e08 [ E624376E7E7D9AC203113140D9E618A2, 3553D343665194492E38B8C437DE429CEAC135D69EC0CB951BA3E3A7549F673E ] WlanSvc C:\Windows\System32\wlansvc.dll 22:48:50.0087 0x3e08 WlanSvc - ok 22:48:50.0134 0x3e08 [ FFC5E4855C3EA1F3E65F0DC93A48D0EF, 82FADBDD8061764282FD31339B47B61CC0FB112ABE400C721535A66A39D0CD37 ] wlidsvc C:\Windows\system32\wlidsvc.dll 22:48:50.0156 0x3e08 wlidsvc - ok 22:48:50.0188 0x3e08 [ 24A624FC6DED20C3B7980BD71D6540D7, A1564B903E2B54106E6665B212E4F8E1A90B2B6CB966F5E965BA5602A801B7D3 ] wlpasvc C:\Windows\System32\lpasvc.dll 22:48:50.0203 0x3e08 wlpasvc - ok 22:48:50.0203 0x3e08 [ 0D6E1347A891607759340B1E55BA2A77, 033DF14920A581FE7E21C6930280AE159B5634F2FEAF79423E8D0B7D46500048 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys 22:48:50.0203 0x3e08 WmiAcpi - ok 22:48:50.0219 0x3e08 [ F7B122E8A238354DE344B77216E8D9AC, 3C4F864655CFF786B33333E643AA929B2D2B01ECD56EEEEADE7CEAB38249DA3B ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 22:48:50.0219 0x3e08 wmiApSrv - ok 22:48:50.0219 0x3e08 WMPNetworkSvc - ok 22:48:50.0219 0x3e08 [ 1AE1076034392218EE89D2744EC2A071, 695C28E2697B12BBD919687176CE082E94887A5D8B6229F163A26F6EDF401C4C ] Wof C:\Windows\system32\drivers\Wof.sys 22:48:50.0219 0x3e08 Wof - ok 22:48:50.0257 0x3e08 [ 5D9A8A2BB555B743334A096C5B1774E2, 660136C1E8D6CA1F7BD1AE0EC4E28B65527BFE69339589A8E3017EFE2BBDC41C ] workfolderssvc C:\Windows\system32\workfolderssvc.dll 22:48:50.0288 0x3e08 workfolderssvc - ok 22:48:50.0288 0x3e08 [ B16400BD585796C68DD11AD8BB3D2364, 017B0207C8CF2F8311B4E201F5C99AD758A64C9DFED3E05A58029699A6987150 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 22:48:50.0288 0x3e08 WPDBusEnum - ok 22:48:50.0288 0x3e08 [ 1FD80CBB192A20375F3664639DEB57B5, 7A4789D4B2F8E289726E1C723DC00D5AC1F8C5E00FB2879C9D0E6DDC97D2B1A6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys 22:48:50.0288 0x3e08 WpdUpFltr - ok 22:48:50.0303 0x3e08 [ 3369EF007E43B88EAC8F1789B43D4393, 347F9F7DF980BB739895EDFE72E2E595EF56634330DC63DAA36403AB232B5B5A ] WpnService C:\Windows\system32\WpnService.dll 22:48:50.0303 0x3e08 WpnService - ok 22:48:50.0303 0x3e08 [ 41403B9466EDA80FACD7713478A56DF8, A71BF9C7A2483FE1F660AC9688FCB38BA2310F16A69EB117C948458364953F34 ] WpnUserService C:\Windows\System32\WpnUserService.dll 22:48:50.0303 0x3e08 WpnUserService - ok 22:48:50.0319 0x3e08 [ DAF4451760B46CB383D287C4FAFFE97D, 658AFE31EF50E934FEDD2E7048257DBFE9E6DE5F1ACDC658B21737391CF1CC5A ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 22:48:50.0319 0x3e08 ws2ifsl - ok 22:48:50.0319 0x3e08 [ 4C370065B5BE595B17C9AD61793D2BEF, 2B15303204D3A71A0D89E2F15575BDE24F85D8F97FC55EFBD5DFF3703437A226 ] wscsvc C:\Windows\System32\wscsvc.dll 22:48:50.0319 0x3e08 wscsvc - ok 22:48:50.0335 0x3e08 [ F6E37A2C168A58F0172DA50018959228, C97305641F63BC84F5207A739F442ACB0A5FD9262331BB61C4B00CF2C6D94121 ] WSDPrintDevice C:\Windows\System32\drivers\WSDPrint.sys 22:48:50.0335 0x3e08 WSDPrintDevice - ok 22:48:50.0335 0x3e08 [ F454BF3F0D3F19057B8612CA523D22D5, 869EC91E7D709C15ADF9D53C82A87F2D5220ED3CA44CEBF34F4D601E78DA0481 ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys 22:48:50.0335 0x3e08 WSDScan - ok 22:48:50.0335 0x3e08 WSearch - ok 22:48:50.0373 0x3e08 [ EB90CBBEAA2CBC3353D8D7D1601A977D, 016B328D4F920DFD8DBDCEB07FD593DF26F3BD0AE5F240BAA943E630AD94B386 ] wuauserv C:\Windows\system32\wuaueng.dll 22:48:50.0404 0x3e08 wuauserv - ok 22:48:50.0419 0x3e08 [ 455609BF60DA3B57EEAB863DEFCCF14D, F55271C42B7AFD17D01275703719C1F52C21996DB82AC78A70A8A8B62370623B ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 22:48:50.0419 0x3e08 WudfPf - ok 22:48:50.0419 0x3e08 [ 5068DAA8F67A62E964C9C9F88B159EA9, 09FCB7A817280957D1AD365EF8B46F666C70957238BF9FBC87D51115E1B0FCB0 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys 22:48:50.0419 0x3e08 WUDFRd - ok 22:48:50.0435 0x3e08 [ 9EFE23CA208BF4B613FF4A6028DFAB10, 483D8D8DA578BF3EA5617EAB42457543EC6F97C1977BDD8ABFDF854AE3AAFD35 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 22:48:50.0435 0x3e08 wudfsvc - ok 22:48:50.0435 0x3e08 [ 5068DAA8F67A62E964C9C9F88B159EA9, 09FCB7A817280957D1AD365EF8B46F666C70957238BF9FBC87D51115E1B0FCB0 ] WUDFWpdFs C:\Windows\System32\drivers\WUDFRd.sys 22:48:50.0435 0x3e08 WUDFWpdFs - ok 22:48:50.0453 0x3e08 [ 5068DAA8F67A62E964C9C9F88B159EA9, 09FCB7A817280957D1AD365EF8B46F666C70957238BF9FBC87D51115E1B0FCB0 ] WUDFWpdMtp C:\Windows\System32\drivers\WUDFRd.sys 22:48:50.0456 0x3e08 WUDFWpdMtp - ok 22:48:50.0473 0x3e08 [ 86FBC0CD3F66309015BBD555EDBF2973, 82A18D57E82D42039BBD87E0B71EA89B093DA52823B3F231911115E88D16CFBB ] WwanSvc C:\Windows\System32\wwansvc.dll 22:48:50.0488 0x3e08 WwanSvc - ok 22:48:50.0504 0x3e08 [ FC0147AB34C7CDB2D8A1B29C207F2CD1, 737D40A4BE35AD13C091D8E320FAD3FD7C0C7E41C8B50E48D3C2151712A55718 ] xbgm C:\Windows\System32\xbgmsvc.dll 22:48:50.0504 0x3e08 xbgm - ok 22:48:50.0520 0x3e08 [ 7FE60B52DD841ED374285B7ED9210222, 0F7743A5A9289E47EE07477313083CE07B46F1C9C5CF83130303A7BAB2F3842B ] XblAuthManager C:\Windows\System32\XblAuthManager.dll 22:48:50.0535 0x3e08 XblAuthManager - ok 22:48:50.0557 0x3e08 [ A8BD191F46CC58E45637CB3E262CF0F2, CA65524427ECDB5E1138A5F8E885566064E507BA60FC31E0D9D17B9556CC9ADC ] XblGameSave C:\Windows\System32\XblGameSave.dll 22:48:50.0573 0x3e08 XblGameSave - ok 22:48:50.0588 0x3e08 [ B10655A4C2EFDC25483D670EF52A4854, 2D9DC81AE73FDFE7F4E395BEC8E806E6BAD8DE0470027EEEC256AC4A4B7C7AA4 ] xboxgip C:\Windows\System32\drivers\xboxgip.sys 22:48:50.0588 0x3e08 xboxgip - ok 22:48:50.0588 0x3e08 [ E099DED5C602AE4A7ECCF7CD4B1D2E33, 7FDAFFE13B87A8E6AA8721F8905FFF6EF04CAB93009F68EDA862B57EBB04514F ] XboxGipSvc C:\Windows\System32\XboxGipSvc.dll 22:48:50.0588 0x3e08 XboxGipSvc - ok 22:48:50.0620 0x3e08 [ EF83C2EF7F152DFDC6D9F1AEC6FBE66F, 21D4FCD12F9D40D066F05936131A4F7BAB301DD800C85921476EC182B9D27D0B ] XboxNetApiSvc C:\Windows\system32\XboxNetApiSvc.dll 22:48:50.0635 0x3e08 XboxNetApiSvc - ok 22:48:50.0635 0x3e08 [ 2E50A379A8E4F6C5D85E87C26C08D329, ADA0C344FE58A3772FFF7417268160E488741C5B2F08CA12ED587AB7F75756F6 ] xinputhid C:\Windows\System32\drivers\xinputhid.sys 22:48:50.0635 0x3e08 xinputhid - ok 22:48:50.0652 0x3e08 ================ Scan global =============================== 22:48:50.0656 0x3e08 [ EEA8447A2E39A39F66C74BA66C421F92, 7FFC5294E0D0438E7450ED36947AB04D0C84DF4E1C9F2D49340D3BA586FFFAB2 ] C:\Windows\system32\basesrv.dll 22:48:50.0657 0x3e08 [ F5774C1558D57112AA5388F6C1152F53, EE5E468BAA3C2605F011947EF2CBC24D0FEC5240D86F6A97DEE24F6D6E2E9289 ] C:\Windows\system32\winsrv.dll 22:48:50.0657 0x3e08 [ 7DD72CBE412C9567661F4B1CE9631FC1, 8D914805CBDAF448C8C132C4C3FEB1D90804F4F485180F7364A75EC5655A4DDB ] C:\Windows\system32\sxssrv.dll 22:48:50.0673 0x3e08 [ C81F9707DEA008EED4071B5A39B7C76E, 47FFEF27A479ED6B325B22296B6853D7E57B53E8E712824F3881E510D5C93667 ] C:\Windows\system32\services.exe 22:48:50.0673 0x3e08 [ Global ] - ok 22:48:50.0673 0x3e08 ================ Scan MBR ================================== 22:48:50.0673 0x3e08 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 22:48:50.0720 0x3e08 \Device\Harddisk0\DR0 - ok 22:48:50.0720 0x3e08 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1 22:48:50.0736 0x3e08 \Device\Harddisk1\DR1 - ok 22:48:51.0462 0x3e08 [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk2\DR2 22:48:51.0540 0x3e08 \Device\Harddisk2\DR2 - ok 22:48:51.0540 0x3e08 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk3\DR3 22:48:51.0540 0x3e08 \Device\Harddisk3\DR3 - ok 22:48:51.0540 0x3e08 ================ Scan VBR ================================== 22:48:51.0540 0x3e08 [ 08D42AEEC1407FFCEB81DBBAA84CDC23 ] \Device\Harddisk0\DR0\Partition1 22:48:51.0540 0x3e08 \Device\Harddisk0\DR0\Partition1 - ok 22:48:51.0540 0x3e08 [ 18002A8944E82CED124DEE1AE14B6902 ] \Device\Harddisk0\DR0\Partition2 22:48:51.0540 0x3e08 \Device\Harddisk0\DR0\Partition2 - ok 22:48:51.0540 0x3e08 [ 41A6840BA4B15EC5200C2CF5DF18E7D8 ] \Device\Harddisk1\DR1\Partition1 22:48:51.0540 0x3e08 \Device\Harddisk1\DR1\Partition1 - ok 22:48:51.0557 0x3e08 [ 78853E8100EB2129C11E55DD3D1F6F8E ] \Device\Harddisk2\DR2\Partition1 22:48:51.0558 0x3e08 \Device\Harddisk2\DR2\Partition1 - ok 22:48:51.0560 0x3e08 [ CEE9B5998CC95E02C1BE21AA94BA1ADF ] \Device\Harddisk3\DR3\Partition1 22:48:51.0561 0x3e08 \Device\Harddisk3\DR3\Partition1 - ok 22:48:51.0562 0x3e08 ================ Scan generic autorun ====================== 22:48:51.0562 0x3e08 SecurityHealth - ok 22:48:51.0563 0x3e08 [ 76FE2B9656AD81EBB9477E30B4A738FD, 6D44926D9B69D7F763F9B4D2E0DC14E9882605434796B44E2CB1F68A567EAEE0 ] C:\Program Files\iTunes\iTunesHelper.exe 22:48:51.0563 0x3e08 iTunesHelper - ok 22:48:51.0563 0x3e08 FireStormStartUpAutoRun - ok 22:48:51.0887 0x3e08 [ 450FDD861FD582026BDCE55FCB2162C4, 91166DBAEE6A0D97ABA5EED352D06078870A265E736ED491C666CB6A8559BEB2 ] C:\Windows\SysWOW64\OneDriveSetup.exe 22:48:52.0172 0x3e08 OneDriveSetup - ok 22:48:52.0496 0x3e08 [ 450FDD861FD582026BDCE55FCB2162C4, 91166DBAEE6A0D97ABA5EED352D06078870A265E736ED491C666CB6A8559BEB2 ] C:\Windows\SysWOW64\OneDriveSetup.exe 22:48:52.0757 0x3e08 OneDriveSetup - ok 22:48:52.0787 0x3e08 [ EE2826CAAF139688445D93C7C6613EE3, A343D94D748F8A2C06EA45566ECCCE1FCDC7660E0A2DBFF92E9741904FE0D559 ] C:\Users\Sam\AppData\Local\Microsoft\OneDrive\OneDrive.exe 22:48:52.0819 0x3e08 OneDrive - ok 22:48:52.0903 0x3e08 [ F75ABBE7B920011587F5B15F5C08AC6A, A2EF4160425438B8DFF28F83737E28930A647C5CA4183CE057C8A8BF1600D5C5 ] D:\Steam\steam.exe 22:48:52.0950 0x3e08 Steam - ok 22:48:53.0065 0x3e08 [ 5F7BB68AC917C4808B98C09996FD35AD, 456FFE335294983B2EC139BAB8B510182A0AD2850849139C294AC07E64D08824 ] D:\GOG Galaxy\GOG Galaxy\GalaxyClient.exe 22:48:53.0150 0x3e08 GalaxyClient - ok 22:48:53.0166 0x3e08 Discord - ok 22:48:53.0204 0x3e08 [ 353EE8267813CB630D84FF847E094DA0, 5B35C658221EAD9E675241FA10B10FFC0A650BF64E78DE6C0A69FCDE1EE89401 ] C:\Users\Sam\AppData\Roaming\uTorrent\uTorrent.exe 22:48:53.0235 0x3e08 uTorrent - ok 22:48:53.0394 0x3e08 [ E6F5AD3FD6D0F64EC88357FC481A71AB, 06B27F68366F8D25A599C3AD8B1D23F18158F4EDDDEE3174A22D3698089A8BC3 ] C:\Program Files\CCleaner\CCleaner64.exe 22:48:53.0518 0x3e08 CCleaner Monitoring - ok 22:48:53.0539 0x3e08 [ 1A2214CF882CE18EF513BF2A33907C51, C1E9349EA50A239F440F0353CEEE544322F2C7F731166B3256F68108F1448C1A ] C:\Program Files\Sandboxie\SbieCtrl.exe 22:48:53.0539 0x3e08 SandboxieControl - ok 22:48:53.0539 0x3e08 Waiting for KSN requests completion. In queue: 283 22:48:54.0555 0x3e08 AV detected via SS2: Kaspersky Anti-Virus, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\wmiav.exe ( 18.0.0.570 ), 0x41000 ( enabled : updated ) 22:48:54.0555 0x3e08 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.11.15063.332 ), 0x60100 ( disabled : updated ) 22:48:54.0555 0x3e08 AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.143 ), 0x60000 ( disabled : updated ) 22:48:54.0555 0x3e08 Win FW state via NFP2: enabled ( trusted ) 22:48:54.0687 0x3e08 ============================================================ 22:48:54.0687 0x3e08 Scan finished 22:48:54.0687 0x3e08 ============================================================ 22:48:54.0687 0x3090 Detected object count: 0 22:48:54.0687 0x3090 Actual detected object count: 0 22:48:58.0883 0x0204 Deinitialize success |
06.11.2017, 21:01 | #5 |
/// TB-Ausbilder | HEUR:Trojan.Script.Generic auf Chrome über FB-LinkMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Um die Bereinigung möchlichst effektiv und schnell gestalten zu können, bitte ich um Beachtung der folgenden Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Ich sehe jetzt nur etwas Adware in Chrome. Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop (Bebilderte Anleitung).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware 3 (Bebilderte Anleitung)
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
07.11.2017, 13:22 | #6 |
| Danke Sobald ich zuhause bin werde ich mich diesen dingen witmen. Vielen dank das du mir hilfst. |
07.11.2017, 17:07 | #7 |
/// TB-Ausbilder | HEUR:Trojan.Script.Generic auf Chrome über FB-Link Gern geschehen. |
08.11.2017, 21:17 | #8 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link Alks Anhang sende ich die Angeforderten txt datein der überprüfung. |
08.11.2017, 22:35 | #9 |
/// TB-Ausbilder | HEUR:Trojan.Script.Generic auf Chrome über FB-Link Servus, Schritt 1 Die Syncronisierung von Google Chrome verhindert, dass die Adware vollständig entfernt werden kann. Daher bitte die Syncronisation zurücksetzen, dann Google Chrome zurücksetzen. Schritt 2
Schritt 3
Bitte poste mit deiner nächsten Antwort
|
09.11.2017, 20:36 | #10 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link fixlog und search habe ich nicht finden könnnen, auch nicht unter gespeicherten pfad von FRST. Im anhang die beiden neuen log-datein. Chrome backup gelöscht und und chrome zurückgesetzt, dann deinstalliert. |
10.11.2017, 15:46 | #11 |
| HEUR:Trojan.Script.Generic auf Chrome über FB-Link Ich bin ab 19 uhr übers wochenende nicht mehr erreichbar und kann die nächste anforderung erst ab montag abend durchführen. |
10.11.2017, 21:30 | #12 |
/// TB-Ausbilder | HEUR:Trojan.Script.Generic auf Chrome über FB-Link Servus, wir entfernen noch ein bisschen was und kontrollieren nochmal alles. Hinweis: Der Suchlauf mit ESET kann länger dauern. Schritt 1
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 Downloade Dir bitte ESET Online Scanner (Bebilderte Anleitung)
Schritt 4
Gibt es jetzt noch Probleme mit dem PC oder mit deinen Internet Browsern? Wenn ja, welche? Bitte poste mit deiner nächsten Antwort
|
13.11.2017, 21:09 | #13 |
/// TB-Ausbilder | HEUR:Trojan.Script.Generic auf Chrome über FB-Link Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM inklusive Link zum Thema an mich falls du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu HEUR:Trojan.Script.Generic auf Chrome über FB-Link |
andere, anderen, befindet, computer, datei, datein, direkt, einträge, freundin, gelöscht, gesendet, heur, heur:trojan.script.generic, infos, kaspersky, laptop, link, msascuil.exe, mögliche, natürlich, node.js, seite, seriös, theme, themen, trojaner, versucht, website, windowsapps |