Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Trojaner qv06 wie werd ich den wieder los ? (https://www.trojaner-board.de/139730-trojaner-qv06-werd-los.html)

girli 12.08.2013 19:16

Trojaner qv06 wie werd ich den wieder los ?
 
Hey,
Ich hab ein das Problem das wenn ich mein Browser immer als startseite qv06. Ich weiß das ich es ausversehen mal mit runtergeladen hab und hab es wieder deinstalliert. aber es geht die einstellung immer wieder rein. Das dies die startseite sein soll. ich kann es so oft umändern wie ich will. ich hoffe es kann mir einer Helfen. ich hab windows 7 starter.

markusg 12.08.2013 19:18

Hi,
gleich wird eine Anleitung für das Programm FRST folgen, beachte bitte das du die Liste der instalierten Programme bearbeiten sollst.

Empfehlungen fürs Deinstallieren
Bitte kopiere die Liste der installierten Programme aus der additions.txt hier in deinen Thread. Notiere mir bitte
hinter jede Zeile, ob folgendes Kategorie zutrifft: Unbekannt, Nötig, Unnötig

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


girli 12.08.2013 19:39

wie meinst du das mit additions.txt?
& wie mach ich das ?

markusg 12.08.2013 20:13

Hi,
FRST wie beschrieben ausführen, du bekommst 2 Logs unteranderem die Additions.txt welche du dann bearbeitest wie angegeben

girli 12.08.2013 20:46

der sagt ich soll das löschen & die Ausführung nicht durch führen

markusg 12.08.2013 20:52

Wer ist "er" und was steht da genau.b
einfach das Programm nach anleitung nutzen und die Additions.txt bearbeiten.

girli 12.08.2013 20:57

okii mach ich :)

schon okii hab das hinbekommen

hier die FRST.text


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-08-2013
Ran by Mandy (administrator) on 12-08-2013 21:49:59
Running from C:\Users\Mandy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F66BE1FR
Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(Iminent) C:\Program Files\Common Files\Umbrella\umbrella.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Iminent) C:\Program Files\Iminent\Iminent.exe
(Iminent) C:\Program Files\Iminent\Iminent.Messengers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\windows\system32\hkcmd.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Intel Corporation) C:\windows\system32\igfxpers.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SFB\SmartRestarter.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
() C:\PROGRA~1\samsung\SAMSUN~3\SUPNOT~1.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems, Inc.) C:\windows\system32\Macromed\Flash\FlashUtil10d.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [YouCam Service] - "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s [x]
HKLM\...\Run: [Iminent] - C:\Program Files\Iminent\Iminent.exe [1074736 2013-07-02] (Iminent)
HKLM\...\Run: [IminentMessenger] - C:\Program Files\Iminent\Iminent.Messengers.exe [884784 2013-07-02] (Iminent)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
MountPoints2: {a1fb7148-b864-11e1-badf-e8113246b51e} - F:\AutoRun.exe
MountPoints2: {a1fb7156-b864-11e1-badf-e8113246b51e} - E:\Startme.exe
HKU\blaablaa\...\Winlogon: [Shell] explorer.exe, "C:\Users\blaablaa\AppData\Roaming\Microsoft\Windows\msshell.exe" <==== ATTENTION
BootExecute: autocheck autochk * ⹁䯎谀[BdFirewallPath]* x⹋䯎踀[InstallPath]..\ex⹵䯎踀[BdFirewallPath]

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
URLSearchHook: (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} -  No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153893
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153893
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153893
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=FC1690A4DE22AF7F&affID=124247&tsp=4967
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153893
SearchScopes: HKCU - {63422161-A942-4143-AD73-A02CD29DD70D} URL = hxxp://www.bing.com/search?FORM=SMSTDF&PC=MASM&q={searchTerms}&src=IE-SearchBox
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent)
BHO: Windows 7 Starter Helper - {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - C:\Program Files\Oceanis\SystemSetting\StarterHelper.dll (Oceanis)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} -  No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Mandy\AppData\Roaming\Mozilla\Firefox\Profiles\l80t3m2l.default
FF user.js: detected! => C:\Users\Mandy\AppData\Roaming\Mozilla\Firefox\Profiles\l80t3m2l.default\user.js
FF Homepage: about:home
FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1428909&SearchSource=2&CUI=UN29133404102847052&UM=1&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Mandy\AppData\Roaming\Mozilla\Firefox\Profiles\l80t3m2l.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\qvo6.xml
FF Extension: No Name - C:\Users\Mandy\AppData\Roaming\Mozilla\Firefox\Profiles\l80t3m2l.default\Extensions\staged
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892

========================== Services (Whitelisted) =================

R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2864448 2013-08-07] (Iminent)

==================== Drivers (Whitelisted) ====================

S3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [297000 2010-07-14] (Broadcom Corporation.)
R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [109056 2010-04-01] (ELAN Microelectronics Corp.)
R1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2010-10-07] (SAMSUNG ELECTRONICS)
S3 clwvd; system32\DRIVERS\clwvd.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
U4 vsserv;
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-12 21:49 - 2013-08-12 21:49 - 00000000 ____D C:\FRST
2013-08-12 21:48 - 2013-08-12 21:48 - 01575296 _____ (Farbar) C:\Users\Mandy\Downloads\FRST64.exe
2013-08-12 18:55 - 2013-08-12 18:56 - 00082348 _____ C:\ProgramData\1376325072.3768.bin
2013-08-12 18:40 - 2013-08-12 18:40 - 00001700 _____ C:\ProgramData\1376325072.2868.bin
2013-08-12 18:35 - 2013-08-12 18:37 - 00001545 _____ C:\ProgramData\1376325072.5368.bin
2013-08-12 18:35 - 2013-08-12 18:35 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\QuickScan
2013-08-12 18:33 - 2013-08-12 18:55 - 00118675 _____ C:\ProgramData\1376325072.784.bin
2013-08-12 18:33 - 2013-08-12 18:41 - 00016869 _____ C:\ProgramData\1376325072.5044.bin
2013-08-12 18:33 - 2013-08-12 18:40 - 00000000 ____D C:\ProgramData\Bitdefender
2013-08-12 18:33 - 2013-08-12 18:36 - 00001090 _____ C:\ProgramData\1376325072.3532.bin
2013-08-12 18:33 - 2013-08-12 18:34 - 00001090 _____ C:\ProgramData\1376325072.2668.bin
2013-08-12 18:33 - 2013-08-12 18:33 - 00016449 _____ C:\ProgramData\1376325072.4340.bin
2013-08-12 18:33 - 2013-08-12 18:33 - 00006705 _____ C:\ProgramData\1376325072.1136.bin
2013-08-12 18:32 - 2013-08-12 18:32 - 00002969 _____ C:\ProgramData\1376325072.1632.bin
2013-08-12 18:31 - 2013-08-12 19:01 - 00251068 _____ C:\ProgramData\1376325072.2580.bin
2013-08-12 18:31 - 2013-08-12 19:01 - 00032557 _____ C:\ProgramData\1376325072.1376.bin
2013-08-12 18:31 - 2013-08-12 18:55 - 00181853 _____ C:\ProgramData\1376325072.4364.bin
2013-08-12 17:56 - 2013-08-12 17:56 - 00057253 _____ C:\ProgramData\1376322871.bdinstall.bin
2013-08-12 17:52 - 2013-08-12 17:52 - 00247923 _____ C:\ProgramData\1376322694.bdinstall.bin
2013-08-12 17:40 - 2013-08-12 18:56 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-08-12 16:51 - 2013-08-12 16:51 - 00005130 _____ C:\windows\ykinstutil.log
2013-08-12 16:51 - 2013-08-12 16:51 - 00000000 ____H C:\windows\nslB87E.tmp
2013-08-12 16:50 - 2013-08-12 16:51 - 00000336 ____R C:\YukonInstall.log
2013-08-12 16:37 - 2013-08-12 16:37 - 00288696 _____ C:\Users\Mandy\Downloads\CyberLink%20YouCam.exe
2013-08-12 16:03 - 2013-08-12 16:45 - 00000000 ____D C:\Users\Mandy\Downloads\musik download
2013-08-12 15:44 - 2013-08-12 15:44 - 00001356 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-08-12 15:42 - 2013-08-12 15:44 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-08-12 15:38 - 2013-08-12 15:38 - 01211376 _____ (DVDVideoSoft Ltd.                                          ) C:\Users\Mandy\Downloads\FreeYouTubeToMP3Converter-3.12.9.725.exe
2013-08-10 23:33 - 2013-08-10 23:33 - 00000000 ____D C:\Program Files\Tracker Software
2013-08-10 23:28 - 2013-08-10 23:28 - 16523960 _____ (Tracker Software Products Ltd                              ) C:\Users\Mandy\Downloads\PDFXVwer_2.5.211.exe
2013-08-10 20:24 - 2013-08-10 20:24 - 00000055 _____ C:\Users\Mandy\AppData\Roaming\WB.CFG
2013-08-10 20:24 - 2013-08-10 20:24 - 00000005 _____ C:\Users\Mandy\AppData\Roaming\WBPU-TTL.DAT
2013-08-10 18:58 - 2013-08-10 20:28 - 00000000 ____D C:\ProgramData\eSafe
2013-08-10 18:58 - 2013-08-10 20:24 - 00000286 _____ C:\windows\Tasks\DSite.job
2013-08-10 18:58 - 2013-08-10 20:24 - 00000000 ____D C:\Program Files\DealPlyLive
2013-08-10 18:58 - 2013-08-10 19:19 - 00000000 ____D C:\Program Files\DealPly
2013-08-10 18:58 - 2013-08-10 18:58 - 00000290 _____ C:\windows\Tasks\Dealply.job
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\DSite
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Dealply
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\Users\Mandy\AppData\Local\DealPlyLive
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-08-10 18:57 - 2013-08-10 18:57 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\eIntaller
2013-08-10 18:57 - 2013-08-10 18:57 - 00000000 ____D C:\Program Files\Image Converter
2013-08-10 17:30 - 2013-08-10 17:30 - 00392040 _____ (Softonic                                        ) C:\Users\Mandy\Downloads\SoftonicDownloader_fuer_computer-repair-free.exe
2013-08-10 17:04 - 2013-08-10 17:05 - 04328856 _____ (Systweak Inc                                                ) C:\Users\Mandy\Downloads\rcpsetup_25752.exe
2013-08-10 13:02 - 2013-08-12 13:18 - 00000000 ____D C:\Users\Mandy\Desktop\Bewerbungen Sophie
2013-08-10 11:17 - 2013-08-10 11:19 - 00000000 ____D C:\ProgramData\Avira
2013-08-09 09:23 - 2013-08-09 09:24 - 01094056 _____ (Conduit) C:\Users\Mandy\Downloads\tb_iminent.exe
2013-08-08 23:11 - 2013-08-08 23:18 - 00000000 ____D C:\windows\system32\MRT
2013-08-08 16:25 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2013-08-08 15:02 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2013-08-08 14:17 - 2012-12-16 16:13 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2013-08-08 14:17 - 2012-12-16 16:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2013-08-08 14:13 - 2013-08-11 13:22 - 00001890 _____ C:\windows\system32\ASOROSet.bin
2013-08-08 14:13 - 2013-08-10 17:36 - 00000000 ____D C:\windows\system32\config\RCCBakup
2013-08-08 12:58 - 2013-08-10 20:26 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Systweak
2013-08-08 12:58 - 2013-01-29 18:17 - 00018800 _____ (Systweak Inc., (www.systweak.com)) C:\windows\system32\roboot.exe
2013-08-08 12:54 - 2013-08-08 12:54 - 04365864 _____ (Systweak Inc                                                ) C:\Users\Mandy\Downloads\rcpsetup_matomy_my30679.exe
2013-08-08 12:29 - 2013-08-08 12:29 - 00000000 ____D C:\f77ac4d2369eda7f3983c157b73a6e4b
2013-08-08 01:17 - 2013-08-08 01:17 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-08 01:17 - 2013-08-08 01:17 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 01441280 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-08-08 01:17 - 2013-08-08 01:17 - 01400416 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2013-08-08 01:17 - 2013-08-08 01:17 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00745472 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00719360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00629248 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00523264 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00361984 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2013-08-08 01:17 - 2013-08-08 01:17 - 00357888 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00242200 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00232960 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00204800 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00158720 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00138752 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00137216 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00125440 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00117248 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00073728 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2013-08-08 01:17 - 2013-08-08 01:17 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2013-08-08 01:16 - 2013-08-08 01:16 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2013-08-08 01:15 - 2013-08-08 01:15 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 02284544 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 01988096 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 01158144 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 01080832 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00906240 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00604160 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00364544 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00207872 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-08 01:11 - 2013-08-08 01:27 - 00011265 _____ C:\windows\IE10_main.log
2013-08-08 00:56 - 2013-08-08 00:56 - 00000000 ____D C:\windows\system32\searchplugins
2013-08-08 00:56 - 2013-08-08 00:56 - 00000000 ____D C:\windows\system32\Extensions
2013-08-08 00:12 - 2013-08-08 00:12 - 00001992 _____ C:\Users\Public\Desktop\Oceanis Change Background W7.lnk
2013-08-08 00:12 - 2013-08-08 00:12 - 00000000 ____D C:\Program Files\Oceanis
2013-08-07 23:55 - 2013-08-07 23:55 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Iminent
2013-08-07 23:54 - 2013-08-07 23:54 - 00000611 _____ C:\windows\system32\InstallUtil.InstallLog
2013-08-07 23:54 - 2013-08-07 23:54 - 00000000 ____D C:\ProgramData\Iminent
2013-08-07 23:53 - 2013-08-08 00:38 - 00000000 ____D C:\Program Files\Common Files\Umbrella
2013-08-07 23:53 - 2013-08-07 23:55 - 00000000 ____D C:\Program Files\Iminent
2013-08-07 23:47 - 2013-08-07 23:48 - 00392048 _____ (Softonic                                        ) C:\Users\Mandy\Downloads\SoftonicDownloader_fuer_oceanis-change-background.exe
2013-08-07 23:47 - 2013-08-07 23:47 - 00003053 _____ C:\Users\Mandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Logon Background Changer.lnk
2013-08-07 23:47 - 2013-08-07 23:47 - 00000000 ____D C:\Program Files\Julien MANICI
2013-08-07 23:44 - 2013-08-08 00:02 - 00000000 ____D C:\Users\Mandy\AppData\Local\http___www.julien-manici
2013-08-07 23:33 - 2013-04-12 15:45 - 01211752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2013-08-07 23:33 - 2013-02-12 05:32 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023x.sys
2013-08-07 23:33 - 2013-02-12 05:32 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2013-08-07 23:33 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2013-08-07 23:32 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2013-08-07 23:32 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2013-08-07 23:31 - 2013-05-06 07:06 - 03968872 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-08-07 23:31 - 2013-05-06 07:06 - 03913576 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-07 23:31 - 2013-03-19 06:53 - 00186368 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2013-08-07 23:31 - 2013-03-19 06:48 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2013-08-07 23:31 - 2013-03-19 05:33 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2013-08-07 23:31 - 2013-03-19 04:49 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2013-08-07 23:31 - 2013-01-24 06:47 - 00196328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2013-08-07 23:30 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2013-08-07 23:29 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-07 23:29 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-07 23:29 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-07 23:29 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2013-08-07 23:29 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2013-08-07 23:29 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-07 23:29 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2013-08-07 23:29 - 2013-02-15 06:37 - 03217408 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2013-08-07 23:29 - 2013-02-15 06:34 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll
2013-08-07 23:29 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2013-08-07 23:29 - 2012-11-01 06:47 - 01389568 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2013-08-07 23:28 - 2012-11-30 06:47 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2013-08-07 23:28 - 2012-11-30 06:47 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 04:55 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2013-08-07 23:28 - 2012-11-30 04:38 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 04:38 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 04:38 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 04:38 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-08-07 23:28 - 2012-11-30 01:17 - 00420064 _____ C:\windows\system32\locale.nls
2013-08-07 23:27 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-08-07 23:27 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2013-08-07 23:12 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2013-08-07 23:12 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2013-08-07 23:12 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2013-08-07 23:12 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2013-08-07 23:11 - 2013-05-08 07:38 - 01293672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-07 23:11 - 2013-04-10 07:18 - 00728424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2013-08-07 23:11 - 2013-04-10 07:18 - 00218984 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2013-08-07 23:11 - 2013-01-03 07:04 - 00187752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2013-08-07 23:11 - 2012-11-20 06:51 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2013-08-07 22:58 - 2013-08-07 23:57 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-07 22:58 - 2013-08-07 22:58 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-07 22:57 - 2012-11-09 06:42 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-07 22:56 - 2013-02-27 07:05 - 00101720 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2013-08-07 22:56 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2013-08-07 22:56 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2013-08-07 22:56 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-08-07 22:56 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2013-08-07 22:56 - 2013-01-04 06:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2013-08-07 22:22 - 2013-08-07 22:22 - 00003416 ____N C:\bootsqm.dat
2013-08-07 22:19 - 2013-08-07 22:19 - 00000000 __SHD C:\found.000

==================== One Month Modified Files and Folders =======

2013-08-12 21:50 - 2012-06-29 20:40 - 00000000 ____D C:\Users\blaablaa
2013-08-12 21:49 - 2013-08-12 21:49 - 00000000 ____D C:\FRST
2013-08-12 21:48 - 2013-08-12 21:48 - 01575296 _____ (Farbar) C:\Users\Mandy\Downloads\FRST64.exe
2013-08-12 21:35 - 2012-04-27 22:33 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-12 20:50 - 2009-07-14 06:34 - 00010272 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-12 20:50 - 2009-07-14 06:34 - 00010272 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-12 20:31 - 2010-11-13 01:48 - 02053247 _____ C:\windows\WindowsUpdate.log
2013-08-12 19:26 - 2012-10-12 12:11 - 00020676 _____ C:\windows\PFRO.log
2013-08-12 19:26 - 2012-07-02 22:28 - 00019955 _____ C:\windows\setupact.log
2013-08-12 19:26 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-12 19:01 - 2013-08-12 18:31 - 00251068 _____ C:\ProgramData\1376325072.2580.bin
2013-08-12 19:01 - 2013-08-12 18:31 - 00032557 _____ C:\ProgramData\1376325072.1376.bin
2013-08-12 18:56 - 2013-08-12 18:55 - 00082348 _____ C:\ProgramData\1376325072.3768.bin
2013-08-12 18:56 - 2013-08-12 18:33 - 00000000 ____D C:\ProgramData\Bitdefender
2013-08-12 18:56 - 2013-08-12 17:40 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-08-12 18:55 - 2013-08-12 18:33 - 00118675 _____ C:\ProgramData\1376325072.784.bin
2013-08-12 18:55 - 2013-08-12 18:31 - 00181853 _____ C:\ProgramData\1376325072.4364.bin
2013-08-12 18:41 - 2013-08-12 18:33 - 00016869 _____ C:\ProgramData\1376325072.5044.bin
2013-08-12 18:40 - 2013-08-12 18:40 - 00001700 _____ C:\ProgramData\1376325072.2868.bin
2013-08-12 18:37 - 2013-08-12 18:35 - 00001545 _____ C:\ProgramData\1376325072.5368.bin
2013-08-12 18:36 - 2013-08-12 18:33 - 00001090 _____ C:\ProgramData\1376325072.3532.bin
2013-08-12 18:35 - 2013-08-12 18:35 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\QuickScan
2013-08-12 18:34 - 2013-08-12 18:33 - 00001090 _____ C:\ProgramData\1376325072.2668.bin
2013-08-12 18:33 - 2013-08-12 18:33 - 00016449 _____ C:\ProgramData\1376325072.4340.bin
2013-08-12 18:33 - 2013-08-12 18:33 - 00006705 _____ C:\ProgramData\1376325072.1136.bin
2013-08-12 18:32 - 2013-08-12 18:32 - 00002969 _____ C:\ProgramData\1376325072.1632.bin
2013-08-12 17:56 - 2013-08-12 17:56 - 00057253 _____ C:\ProgramData\1376322871.bdinstall.bin
2013-08-12 17:54 - 2009-07-26 22:06 - 01395984 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-12 17:52 - 2013-08-12 17:52 - 00247923 _____ C:\ProgramData\1376322694.bdinstall.bin
2013-08-12 17:46 - 2013-08-10 11:17 - 00000000 ____D C:\ProgramData\Avira
2013-08-12 17:45 - 2012-05-09 18:51 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\SoftGrid Client
2013-08-12 17:32 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\NDF
2013-08-12 16:51 - 2013-08-12 16:51 - 00005130 _____ C:\windows\ykinstutil.log
2013-08-12 16:51 - 2013-08-12 16:51 - 00000000 ____H C:\windows\nslB87E.tmp
2013-08-12 16:51 - 2013-08-12 16:50 - 00000336 ____R C:\YukonInstall.log
2013-08-12 16:48 - 2012-04-03 21:20 - 00000000 ____D C:\Users\Mandy
2013-08-12 16:47 - 2012-04-05 12:31 - 00000000 ____D C:\Users\Mandy\AppData\Local\CrashDumps
2013-08-12 16:45 - 2013-08-12 16:03 - 00000000 ____D C:\Users\Mandy\Downloads\musik download
2013-08-12 16:41 - 2012-06-05 07:40 - 00000000 ____D C:\ProgramData\CyberLink
2013-08-12 16:37 - 2013-08-12 16:37 - 00288696 _____ C:\Users\Mandy\Downloads\CyberLink%20YouCam.exe
2013-08-12 15:44 - 2013-08-12 15:44 - 00001356 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-08-12 15:44 - 2013-08-12 15:42 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-08-12 15:44 - 2012-04-25 19:40 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-08-12 15:42 - 2012-10-09 17:03 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\OpenCandy
2013-08-12 15:42 - 2012-04-25 19:45 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\DVDVideoSoft
2013-08-12 15:38 - 2013-08-12 15:38 - 01211376 _____ (DVDVideoSoft Ltd.                                          ) C:\Users\Mandy\Downloads\FreeYouTubeToMP3Converter-3.12.9.725.exe
2013-08-12 13:18 - 2013-08-10 13:02 - 00000000 ____D C:\Users\Mandy\Desktop\Bewerbungen Sophie
2013-08-11 13:22 - 2013-08-08 14:13 - 00001890 _____ C:\windows\system32\ASOROSet.bin
2013-08-11 13:22 - 2009-07-14 04:03 - 39583744 _____ C:\windows\system32\config\software.bak
2013-08-11 13:22 - 2009-07-14 04:03 - 16515072 _____ C:\windows\system32\config\system.bak
2013-08-11 13:22 - 2009-07-14 04:03 - 00262144 _____ C:\windows\system32\config\security.bak
2013-08-11 01:40 - 2009-07-14 04:03 - 00262144 _____ C:\windows\system32\config\sam.bak
2013-08-10 23:33 - 2013-08-10 23:33 - 00000000 ____D C:\Program Files\Tracker Software
2013-08-10 23:28 - 2013-08-10 23:28 - 16523960 _____ (Tracker Software Products Ltd                              ) C:\Users\Mandy\Downloads\PDFXVwer_2.5.211.exe
2013-08-10 20:28 - 2013-08-10 18:58 - 00000000 ____D C:\ProgramData\eSafe
2013-08-10 20:26 - 2013-08-08 12:58 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Systweak
2013-08-10 20:24 - 2013-08-10 20:24 - 00000055 _____ C:\Users\Mandy\AppData\Roaming\WB.CFG
2013-08-10 20:24 - 2013-08-10 20:24 - 00000005 _____ C:\Users\Mandy\AppData\Roaming\WBPU-TTL.DAT
2013-08-10 20:24 - 2013-08-10 18:58 - 00000286 _____ C:\windows\Tasks\DSite.job
2013-08-10 20:24 - 2013-08-10 18:58 - 00000000 ____D C:\Program Files\DealPlyLive
2013-08-10 19:19 - 2013-08-10 18:58 - 00000000 ____D C:\Program Files\DealPly
2013-08-10 18:58 - 2013-08-10 18:58 - 00000290 _____ C:\windows\Tasks\Dealply.job
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\DSite
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Dealply
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\Users\Mandy\AppData\Local\DealPlyLive
2013-08-10 18:58 - 2013-08-10 18:58 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-08-10 18:58 - 2012-04-04 01:44 - 00000000 ____D C:\Users\Mandy\AppData\Local\Google
2013-08-10 18:58 - 2012-04-03 21:34 - 00001649 _____ C:\Users\Mandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-08-10 18:57 - 2013-08-10 18:57 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\eIntaller
2013-08-10 18:57 - 2013-08-10 18:57 - 00000000 ____D C:\Program Files\Image Converter
2013-08-10 17:36 - 2013-08-08 14:13 - 00000000 ____D C:\windows\system32\config\RCCBakup
2013-08-10 17:32 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2013-08-10 17:30 - 2013-08-10 17:30 - 00392040 _____ (Softonic                                        ) C:\Users\Mandy\Downloads\SoftonicDownloader_fuer_computer-repair-free.exe
2013-08-10 17:05 - 2013-08-10 17:04 - 04328856 _____ (Systweak Inc                                                ) C:\Users\Mandy\Downloads\rcpsetup_25752.exe
2013-08-10 12:40 - 2012-04-03 21:26 - 00000000 ____D C:\Users\Mandy\AppData\Local\Adobe
2013-08-10 12:12 - 2012-04-03 21:25 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-08-10 12:11 - 2012-04-03 21:25 - 00000000 ____D C:\Program Files\Adobe
2013-08-10 12:07 - 2012-04-03 21:25 - 00000000 ____D C:\ProgramData\Adobe
2013-08-09 13:48 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-08-09 09:24 - 2013-08-09 09:23 - 01094056 _____ (Conduit) C:\Users\Mandy\Downloads\tb_iminent.exe
2013-08-08 23:18 - 2013-08-08 23:11 - 00000000 ____D C:\windows\system32\MRT
2013-08-08 16:46 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-08-08 14:44 - 2009-07-14 06:33 - 00261968 _____ C:\windows\system32\FNTCACHE.DAT
2013-08-08 14:40 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE
2013-08-08 14:10 - 2010-11-12 08:52 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-08-08 12:54 - 2013-08-08 12:54 - 04365864 _____ (Systweak Inc                                                ) C:\Users\Mandy\Downloads\rcpsetup_matomy_my30679.exe
2013-08-08 12:35 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\zh-TW
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\zh-HK
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\zh-CN
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\tr-TR
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\sv-SE
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\ru-RU
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\pt-PT
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\pt-BR
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\pl-PL
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\nl-NL
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\nb-NO
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\ko-KR
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\ja-JP
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\it-IT
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\hu-HU
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\fr-FR
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\fi-FI
2013-08-08 12:35 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\el-GR
2013-08-08 12:29 - 2013-08-08 12:29 - 00000000 ____D C:\f77ac4d2369eda7f3983c157b73a6e4b
2013-08-08 12:25 - 2010-11-12 10:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-08-08 01:27 - 2013-08-08 01:11 - 00011265 _____ C:\windows\IE10_main.log
2013-08-08 01:17 - 2013-08-08 01:17 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-08 01:17 - 2013-08-08 01:17 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 01441280 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-08-08 01:17 - 2013-08-08 01:17 - 01400416 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2013-08-08 01:17 - 2013-08-08 01:17 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00745472 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00719360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00629248 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00523264 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00361984 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2013-08-08 01:17 - 2013-08-08 01:17 - 00357888 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00242200 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00232960 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00204800 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00158720 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00138752 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00137216 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00125440 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00117248 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00073728 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2013-08-08 01:17 - 2013-08-08 01:17 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2013-08-08 01:17 - 2013-08-08 01:17 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2013-08-08 01:17 - 2013-08-08 01:17 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2013-08-08 01:16 - 2013-08-08 01:16 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2013-08-08 01:15 - 2013-08-08 01:15 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 02284544 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 01988096 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 01158144 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 01080832 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00906240 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00604160 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00364544 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00207872 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-08 01:15 - 2013-08-08 01:15 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-08 00:56 - 2013-08-08 00:56 - 00000000 ____D C:\windows\system32\searchplugins
2013-08-08 00:56 - 2013-08-08 00:56 - 00000000 ____D C:\windows\system32\Extensions
2013-08-08 00:38 - 2013-08-07 23:53 - 00000000 ____D C:\Program Files\Common Files\Umbrella
2013-08-08 00:12 - 2013-08-08 00:12 - 00001992 _____ C:\Users\Public\Desktop\Oceanis Change Background W7.lnk
2013-08-08 00:12 - 2013-08-08 00:12 - 00000000 ____D C:\Program Files\Oceanis
2013-08-08 00:02 - 2013-08-07 23:44 - 00000000 ____D C:\Users\Mandy\AppData\Local\http___www.julien-manici
2013-08-07 23:57 - 2013-08-07 22:58 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-08-07 23:55 - 2013-08-07 23:55 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Iminent
2013-08-07 23:55 - 2013-08-07 23:53 - 00000000 ____D C:\Program Files\Iminent
2013-08-07 23:54 - 2013-08-07 23:54 - 00000611 _____ C:\windows\system32\InstallUtil.InstallLog
2013-08-07 23:54 - 2013-08-07 23:54 - 00000000 ____D C:\ProgramData\Iminent
2013-08-07 23:54 - 2012-11-17 20:23 - 00000000 ____D C:\Users\Mandy\Desktop\marie
2013-08-07 23:48 - 2013-08-07 23:47 - 00392048 _____ (Softonic                                        ) C:\Users\Mandy\Downloads\SoftonicDownloader_fuer_oceanis-change-background.exe
2013-08-07 23:47 - 2013-08-07 23:47 - 00003053 _____ C:\Users\Mandy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Logon Background Changer.lnk
2013-08-07 23:47 - 2013-08-07 23:47 - 00000000 ____D C:\Program Files\Julien MANICI
2013-08-07 23:02 - 2012-04-09 20:43 - 00000000 ____D C:\Users\Mandy\AppData\Roaming\Mozilla
2013-08-07 22:58 - 2013-08-07 22:58 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-08-07 22:36 - 2012-04-27 22:33 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-08-07 22:36 - 2012-04-27 22:33 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-07 22:22 - 2013-08-07 22:22 - 00003416 ____N C:\bootsqm.dat
2013-08-07 22:19 - 2013-08-07 22:19 - 00000000 __SHD C:\found.000

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-12 12:05

==================== End Of Log ============================

--- --- ---

--- --- ---

markusg 12.08.2013 21:02

Das ist 1 von 2 Logs, bitte Logs immer gleichzeitig posten

girli 12.08.2013 21:36

hier der Addition.txt

Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-08-2013
Ran by Mandy at 2013-08-12 21:52:41
Running from C:\Users\Mandy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F66BE1FR
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

„Messenger“ pagalbinė priemonė (Version: 15.4.3502.0922)  unnötig
„Windows Live Essentials“ (Version: 15.4.3502.0922)          unnötig
„Windows Live Mail“ (Version: 15.4.3502.0922)              unnötig
„Windows Live Messenger“ (Version: 15.4.3502.0922)        unnötig
„Windows Live“ fotogalerija (Version: 15.4.3502.0922)      unnötig
Adobe Flash Player 10 ActiveX (Version: 10.0.42.34)        nötig
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)      nötig
Adobe Reader XI (11.0.03) - Deutsch (Version: 11.0.03)    nötig
BatteryLifeExtender (Version: 1.0.10)                      nötig
Broadcom 802.11 Network Adapter (Version: 5.60.48.44)      nötig
ChargeableUSB (Version: 1.0.0.0)                          nötig
Complément Messenger (Version: 15.4.3502.0922)            unbekannt
Complemento Messenger (Version: 15.4.3502.0922)            unbekannt
D3DX10 (Version: 15.4.2368.0902)                          unbekannt
Doplnok programu Messenger (Version: 15.4.3502.0922)      unbekannt
Easy Content Share (Version: 1.0)                          nötig
Easy Display Manager (Version: 3.2)                        nötig
Easy Network Manager (Version: 4.3.3)                      nötig
Easy Resolution Manager (Version: 1.0.9)                  nötig
Easy SpeedUp Manager (Version: 2.1.0.15)                  nötig
EasyBatteryManager (Version: 4.0.0.4)                      nötig
EasyFileShare (Version: 1.0.11)                            nötig
ETDWare PS/2-x86 7.0.7.0_WHQL (Version: 7.0.7.0)          nötig
Fast Booting SW (Version: 1.8.0.0)                        nötig
Fotogalerija Windows Live (Version: 15.4.3502.0922)        unnötig
Free YouTube to MP3 Converter version 3.12.9.725 (Version: 3.12.9.725)    nötig
Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922)          unnötig
Galería fotográfica de Windows Live (Version: 15.4.3502.0922)              unnötig
Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922)          unnötig
Galerie de photos Windows Live (Version: 15.4.3502.0922)                  unnötig
Galerie foto Windows Live (Version: 15.4.3502.0922)                        unnötig
Google Update Helper (Version: 1.3.23.0)                                  unnötig
Iminent (Version: 6.27.21.0)                                              unbekannt
Intel(R) Graphics Media Accelerator Driver (Version: 8.14.10.2117)        nötig
Intel® Matrix Storage Manager                                              nötig
Java 7 Update 7 (Version: 7.0.70)                                          unnötig
Java Auto Updater (Version: 2.1.9.0)                                      unnötig
Junk Mail filter update (Version: 15.4.3502.0922)                          unbekannt
Mesh Runtime (Version: 15.4.5722.2)                                        unnötig
Messenger Assistent (Version: 15.4.3502.0922)                              unnötig
Messenger Companion (Version: 15.4.3502.0922)                              unnötig
Messenger kísérő (Version: 15.4.3502.0922)                                unnötig
Messenger Pratilac (Version: 15.4.3502.0922)                              unnötig
Messenger Suradnik (Version: 15.4.3502.0922)                              unnötig
Messenger 사이트 공유 (Version: 15.4.3502.0922)                                unnötig
Messenger 分享元件 (Version: 15.4.3502.0922)                                  unnötig
Messenger 浏览器插件 (Version: 15.4.3502.0922)                                unnötig
Messenger-kumppani (Version: 15.4.3502.0922)                              unnötig
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)            nötig
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)  nötig
Microsoft Application Error Reporting (Version: 12.0.6012.5000)                    nötig
Microsoft Office 2010 (Version: 14.0.4763.1000)                                    nötig
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)                      nötig
Microsoft Office Starter 2010 - Deutsch (Version: 14.0.4763.1000)                  nötig
Microsoft Silverlight (Version: 5.1.20513.0)                                      nötig
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)                nötig
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)                    nötig
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)                    nötig
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)  nötig
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)  nötig
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)        nötig
Mozilla Firefox 23.0 (x86 de) (Version: 23.0)                              nötig
Mozilla Maintenance Service (Version: 23.0)                                nötig
MSVCRT (Version: 15.4.2862.0708)                                          unbekannt
Oceanis Change Background Windows 7 (Version: 1.0)                        unnötig
PDF-Viewer (Version: 2.5.211.0)                                            nötig
PhotoScape                                                                nötig
Poczta usługi Windows Live (Version: 15.4.3502.0922)                      unnötig
Podstawowe programy Windows Live (Version: 15.4.3502.0922)                unnötig
Pomocnik Messenger (Version: 15.4.3502.0922)                              unnötig
Pošta Windows Live (Version: 15.4.3502.0922)                              unnötig
Raccolta foto di Windows Live (Version: 15.4.3502.0922)                    unnötig
Realtek High Definition Audio Driver (Version: 6.0.1.6083)                nötig
REALTEK PCIE Wireless LAN Software (Version: 0136.10.0325)                nötig
Samsung Recovery Solution 4 (Version: 4.0.0.6)                            nötig
Samsung Support Center (Version: 1.0.2)                                    nötig
Samsung Update Plus (Version: 2.0)                                        nötig
Skype™ 6.0 (Version: 6.0.126)                                              unnötig
Spremljevalec Messenger (Version: 15.4.3502.0922)                          unnötig
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)        nötig
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)        nötig
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)        nötig
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)        nötig
User Guide (Version: 1.0)                                                  nötig
VirtualDJ Home FREE (Version: 7.0.5)                                      nötig
WIDCOMM Bluetooth Software (Version: 6.3.0.6200)                          nötig
Windows 7 Logon Background Changer (Version: 1.5.2)                        unnötig
Windows Live Communications Platform (Version: 15.4.3502.0922)            unnötig
Windows Live Essentials (Version: 15.4.3502.0922)                          unnötig
Windows Live fotoattēlu galerija (Version: 15.4.3502.0922)                unnötig
Windows Live Fotogaléria (Version: 15.4.3502.0922)                        unnötig
Windows Live Fotogalerie (Version: 15.4.3502.0922)                        unnötig
Windows Live Foto-galerija (Version: 15.4.3502.0922)                      unnötig
Windows Live Fotogalleri (Version: 15.4.3502.0922)                        unnötig
Windows Live Fotoğraf Galerisi (Version: 15.4.3502.0922)                  unnötig
Windows Live Fotótár (Version: 15.4.3502.0922)                            unnötig
Windows Live Galeria de Fotos (Version: 15.4.3502.0922)                    unnötig
Windows Live Galerija fotografija (Version: 15.4.3502.0922)                unnötig
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)                  unnötig
Windows Live Installer (Version: 15.4.3502.0922)                          unnötig
Windows Live Mail (Version: 15.4.3502.0922)                                unnötig
Windows Live Mesh (Version: 15.4.3502.0922)                                unnötig
Windows Live Messenger (Version: 15.4.3502.0922)                          unnötig
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)            unnötig
Windows Live MIME IFilter (Version: 15.4.3502.0922)                        unnötig
Windows Live Movie Maker (Version: 15.4.3502.0922)                        nötig
Windows Live Photo Common (Version: 15.4.3502.0922)                        nötig
Windows Live Photo Gallery (Version: 15.4.3502.0922)                      nötig
Windows Live PIMT Platform (Version: 15.4.3502.0922)                      nötig
Windows Live Pošta (Version: 15.4.3502.0922)                              nötig
Windows Live Remote Client (Version: 15.4.5722.2)                          unnötig
Windows Live Remote Client Resources (Version: 15.4.5722.2)                unnötig
Windows Live Remote Service (Version: 15.4.5722.2)                        unnötig
Windows Live Remote Service Resources (Version: 15.4.5722.2)              unnötig
Windows Live SOXE (Version: 15.4.3502.0922)                                unnötig
Windows Live SOXE Definitions (Version: 15.4.3502.0922)                    unnötig
Windows Live Temel Parçalar (Version: 15.4.3502.0922)                      unnötig
Windows Live UX Platform (Version: 15.4.3502.0922)                        unnötig
Windows Live UX Platform Language Pack (Version: 15.4.3502.0922)          unnötig
Windows Live Writer (Version: 15.4.3502.0922)                              unnötig
Windows Live Writer Resources (Version: 15.4.3502.0922)                    unnötig
Windows Live 메일 (Version: 15.4.3502.0922)                                  unnötig
Windows Live 사진 갤러리 (Version: 15.4.3502.0922)                            unnötig
Windows Live 필수 패키지 (Version: 15.4.3502.0922)                            unnötig
Windows Live 影像中心 (Version: 15.4.3502.0922)                              unnötig
Windows Live 照片库 (Version: 15.4.3502.0922)                                unnötig
Windows Live 程式集 (Version: 15.4.3502.0922)                                unnötig
Windows Live 软件包 (Version: 15.4.3502.0922)                                unnötig
Windows Liven asennustyökalu (Version: 15.4.3502.0922)                    unnötig
Windows Liven sähköposti (Version: 15.4.3502.0922)                        unnötig
Windows Liven valokuvavalikoima (Version: 15.4.3502.0922)                  unnötig
WinRAR 4.01 (32-Bit) (Version: 4.01.0)                                    unnötig 
Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922)            unnötig
Компаньон Messenger (Version: 15.4.3502.0922)                              unnötig
Основные компоненты Windows Live (Version: 15.4.3502.0922)                unnötig
Помощник на Messenger (Version: 15.4.3502.0922)                            unnötig
Почта Windows Live (Version: 15.4.3502.0922)                              unnötig
Фотоальбом Windows Live (Version: 15.4.3502.0922)                          unnötig
Фотогалерия на Windows Live (Version: 15.4.3502.0922)                      unnötig
גלריית התמונות של Windows Live (Version: 15.4.3502.0922)                        unnötig
מסייע Messenger (Version: 15.4.3502.0922)                                    unnötig
بريد Windows Live (Version: 15.4.3502.0922)                                  unnötig
معرض صور Windows Live (Version: 15.4.3502.0922)                              unnötig
 

==================== Restore Points  =========================

08-08-2013 21:05:07 Windows Update
10-08-2013 15:34:20 RegClean Pro Sa, Aug 10, 13  17:34
12-08-2013 14:43:48 Removed Facebook Video Calling 1.2.0.287
12-08-2013 17:02:01 Removed Java 7 Update 7
12-08-2013 17:09:58 JavaFX 2.1.1 wird entfernt
12-08-2013 17:20:23 TuneUp Utilities 2011 wird entfernt
12-08-2013 17:23:14 TuneUp Utilities Language Pack (de-DE) wird entfernt

==================== Hosts content: ==========================

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {0014F513-353E-4EC8-A27C-C7A995E72E13} - System32\Tasks\advSRS4 => C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
Task: {19249A48-3F29-4D56-B5FC-A6C4D15DA2E1} - System32\Tasks\DSite => C:\Users\Mandy\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File
Task: {32046335-5DA6-406A-852B-B5BF24BA6C47} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-05-06] (SAMSUNG Electronics)
Task: {3EB81B0D-BEB6-486A-B2EB-B28BF5F6E89A} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2010-02-10] (Samsung Electronics Co., Ltd.)
Task: {4962BD89-DE05-452F-ADA2-125EFE6797D0} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SFB\SmartRestarter.exe [2010-06-03] (Samsung Electronics Co., Ltd.)
Task: {500FE000-48F2-43E2-B8F9-D78C137E0E51} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-07] (Adobe Systems Incorporated)
Task: {60B921A1-1AFE-411D-9655-B0B132F41AA8} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3101594506-4248310904-250478768-1000
Task: {7C3C4890-3C81-4FDE-B7A9-5E20EB9292D8} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-06-08] (Samsung Electronics Co., Ltd.)
Task: {8C0F3205-C19F-4932-A657-C02B1FE04817} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation)
Task: {97712973-BEFD-4B0B-81E8-993477721B31} - System32\Tasks\Dealply => C:\Users\Mandy\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE No File
Task: {A0C74355-C27D-45B8-8304-F9E2BCA66517} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-10-14] (Samsung Electronics. Co. Ltd.)
Task: {A7B937E3-1865-4173-9C20-2B6908BF8884} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-04-20] ()
Task: {BD60167B-5A7F-4F9E-A520-AC5B5ED4E43F} - System32\Tasks\Google Updater and Installer => C:\Users\Mandy\AppData\Local\Google\Update\GoogleUpdate.exe No File
Task: {C6FC8306-2B59-419B-A23C-FBB8DC1CC06C} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-03-29] (SAMSUNG Electronics co., LTD.)
Task: {D65AF7A8-5649-4216-A870-857DC9FA45AD} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {D806704B-AE64-4668-AE5D-0842653C5FCB} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {E94BBB68-A366-4C8F-B386-EEFDBA3F3BAC} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {FEC183B4-ABFA-4111-B41A-CEC38E970D36} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\Dealply.job => C:\Users\Mandy\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE
Task: C:\windows\Tasks\DSite.job => C:\Users\Mandy\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE

==================== Faulty Device Manager Devices =============

Name: Broadcom BCM2070 Bluetooth 3.0 + HS USB Device
Description: Broadcom BCM2070 Bluetooth 3.0 + HS USB Device
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/12/2013 07:23:16 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (08/12/2013 07:22:12 PM) (Source: Microsoft-Windows-RestartManager) (User: Mandy-PC)
Description: Die Anwendung oder der Dienst "Windows-Explorer" konnte nicht heruntergefahren werden.

Error: (08/12/2013 07:20:26 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (08/12/2013 07:10:02 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (08/12/2013 07:02:14 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (08/12/2013 05:33:06 PM) (Source: Application Hang) (User: )
Description: Programm CyberLink_YouCam_Downloader.exe, Version 2.9.0.2925 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1bb4

Startzeit: 01ce97712c6ad2e1

Endzeit: 15

Anwendungspfad: C:\Users\Mandy\Desktop\CyberLink_YouCam_Downloader.exe

Berichts-ID: 71d63807-0364-11e3-be79-e8113246b51e

Error: (08/12/2013 05:32:32 PM) (Source: Application Hang) (User: )
Description: Programm avscan.exe, Version 13.6.0.1722 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: e94

Startzeit: 01ce976d79f5051f

Endzeit: 60000

Anwendungspfad: C:\Program Files\Avira\AntiVir Desktop\avscan.exe

Berichts-ID: 342b91ee-0364-11e3-be79-e8113246b51e

Error: (08/12/2013 04:47:45 PM) (Source: Application Hang) (User: )
Description: Programm wmplayer.exe, Version 12.0.7601.17514 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 14ec

Startzeit: 01ce976a8b8db017

Endzeit: 88

Anwendungspfad: C:\Program Files\Windows Media Player\wmplayer.exe

Berichts-ID: 1e0094ac-035e-11e3-be79-e8113246b51e

Error: (08/12/2013 04:46:41 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: notification.exe, Version: 0.0.0.0, Zeitstempel: 0x51cda4f4
Name des fehlerhaften Moduls: notification.exe, Version: 0.0.0.0, Zeitstempel: 0x51cda4f4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000030e2
ID des fehlerhaften Prozesses: 0x1c00
Startzeit der fehlerhaften Anwendung: 0xnotification.exe0
Pfad der fehlerhaften Anwendung: notification.exe1
Pfad des fehlerhaften Moduls: notification.exe2
Berichtskennung: notification.exe3

Error: (08/12/2013 04:43:21 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "Error calling CreateFile on volume '\\?\Volume{54573372-999f-11e1-a767-e8113246b51e}\'" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.


Vorgang:
  Überprüfen, ob das Volume vom Anbieter unterstützt wird
  Volume einem Schattenkopiesatz hinzufügen

Kontext:
  Ausführungskontext: Coordinator
  Anbieter-ID: {00000000-0000-0000-0000-000000000000}
  Volumename: Q:\
  Ausführungskontext: Coordinator


System errors:
=============
Error: (08/12/2013 09:28:31 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht.

Error: (08/12/2013 08:31:45 PM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (08/12/2013 08:31:40 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht.

Error: (08/12/2013 07:26:56 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom

Error: (08/12/2013 05:57:58 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom

Error: (08/12/2013 05:48:04 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom

Error: (08/12/2013 11:13:54 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005

Error: (08/12/2013 11:13:49 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.

Error: (08/12/2013 11:11:01 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom

Error: (08/11/2013 10:35:02 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht.


Microsoft Office Sessions:
=========================
Error: (08/12/2013 07:23:16 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (08/12/2013 07:22:12 PM) (Source: Microsoft-Windows-RestartManager)(User: Mandy-PC)
Description: 1C:\Windows\explorer.exeWindows-Explorer0411724800

Error: (08/12/2013 07:20:26 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (08/12/2013 07:10:02 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (08/12/2013 07:02:14 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary bdselfpr.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (08/12/2013 05:33:06 PM) (Source: Application Hang)(User: )
Description: CyberLink_YouCam_Downloader.exe2.9.0.29251bb401ce97712c6ad2e115C:\Users\Mandy\Desktop\CyberLink_YouCam_Downloader.exe71d63807-0364-11e3-be79-e8113246b51e

Error: (08/12/2013 05:32:32 PM) (Source: Application Hang)(User: )
Description: avscan.exe13.6.0.1722e9401ce976d79f5051f60000C:\Program Files\Avira\AntiVir Desktop\avscan.exe342b91ee-0364-11e3-be79-e8113246b51e

Error: (08/12/2013 04:47:45 PM) (Source: Application Hang)(User: )
Description: wmplayer.exe12.0.7601.1751414ec01ce976a8b8db01788C:\Program Files\Windows Media Player\wmplayer.exe1e0094ac-035e-11e3-be79-e8113246b51e

Error: (08/12/2013 04:46:41 PM) (Source: Application Error)(User: )
Description: notification.exe0.0.0.051cda4f4notification.exe0.0.0.051cda4f4c0000005000030e21c0001ce976aafc12f0fC:\Users\Mandy\Qtrax\Player\notification.exeC:\Users\Mandy\Qtrax\Player\notification.exeffc88ae5-035d-11e3-be79-e8113246b51e

Error: (08/12/2013 04:43:21 PM) (Source: VSS)(User: )
Description: Error calling CreateFile on volume '\\?\Volume{54573372-999f-11e1-a767-e8113246b51e}\'0x80070005, Zugriff verweigert


Vorgang:
  Überprüfen, ob das Volume vom Anbieter unterstützt wird
  Volume einem Schattenkopiesatz hinzufügen

Kontext:
  Ausführungskontext: Coordinator
  Anbieter-ID: {00000000-0000-0000-0000-000000000000}
  Volumename: Q:\
  Ausführungskontext: Coordinator


==================== Memory info ===========================

Percentage of memory in use: 77%
Total physical RAM: 1013.3 MB
Available physical RAM: 225.65 MB
Total Pagefile: 2037.3 MB
Available Pagefile: 1100.5 MB
Total Virtual: 2047.88 MB
Available Virtual: 1904.91 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:85 GB) (Free:49.02 GB) NTFS
Drive d: () (Fixed) (Total:127.79 GB) (Free:15.9 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 233 GB) (Disk ID: C9AF158C)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=85 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=128 GB) - (Type=OF Extended)

==================== End Of Log ============================


markusg 13.08.2013 17:02

Hi,
es sind 2 Logs zu erstellen, möglichst gleichzeitig posten.
wenn eine der Deinstalationen nicht klappt, nutze Revo:
Revo Uninstaller - Download - Filepony

1.
deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
Sicherheit (erweitert)
Erweiterte Sicherheit anhaken
und alle Dateien auswählen.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok

deinstaliere:

Iminent
Java 7
downloade Java jre:
Java-Downloads für alle Betriebssysteme
klicke:
Download der Java-Software für Windows Offline
laden, und instalieren
deinstaliere:
Messenger : alle
Oceanis
neustarten.
2.
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


3.
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

girli 13.08.2013 19:31

iminent hab ich deinstalliert aber es ist immernoch da & ich hab es aber nicht mehr bei meiner liste mit installierten programmen , es nicht mehr zustehen. auc nicht bei den programm.

markusg 13.08.2013 19:42

Hi
weiter mit dem Rest.

girli 19.08.2013 20:13

soll ich den combofix nochmal durchlaufen lassen, wenn ich nebenbei doch am pc was gemacht hab.

das ist wo ich was gemacht habe nebenbei
Combofix :
Code:

ComboFix 13-08-13.02 - Mandy 19.08.2013  19:25:37.1.2 - x86
Microsoft Windows 7 Starter  6.1.7601.1.1252.49.1031.18.1013.304 [GMT 2:00]
ausgeführt von:: c:\users\Mandy\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DealPly
c:\program files\DealPly\uninst.exe
c:\program files\Windows Live\Messenger\msacm32.dll
c:\programdata\1376322694.bdinstall.bin
c:\programdata\1376322871.bdinstall.bin
c:\programdata\1376325072.1136.bin
c:\programdata\1376325072.1376.bin
c:\programdata\1376325072.1632.bin
c:\programdata\1376325072.2580.bin
c:\programdata\1376325072.2668.bin
c:\programdata\1376325072.2868.bin
c:\programdata\1376325072.3532.bin
c:\programdata\1376325072.3768.bin
c:\programdata\1376325072.4340.bin
c:\programdata\1376325072.4364.bin
c:\programdata\1376325072.5044.bin
c:\programdata\1376325072.5368.bin
c:\programdata\1376325072.784.bin
c:\users\blaablaa\AppData\Roaming\Microsoft\Windows\.data
c:\users\blaablaa\AppData\Roaming\Microsoft\Windows\unicode2.nls
c:\windows\system32\roboot.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-07-19 bis 2013-08-19  ))))))))))))))))))))))))))))))
.
.
2013-08-19 17:49 . 2013-08-19 17:49        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-08-19 17:49 . 2013-08-19 17:49        --------        d-----w-        c:\users\blaablaa\AppData\Local\temp
2013-08-19 17:33 . 2013-08-19 17:33        60872        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2268201-9EC7-4AAC-B6FF-F9F7ADA78FD7}\offreg.dll
2013-08-16 07:54 . 2013-07-15 01:34        7143960        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2268201-9EC7-4AAC-B6FF-F9F7ADA78FD7}\mpengine.dll
2013-08-14 21:15 . 2013-08-14 21:15        --------        d-----w-        c:\users\Mandy\AppData\Roaming\SoftMaker
2013-08-14 21:14 . 2013-08-14 21:14        --------        d-----w-        c:\program files\SoftMaker Viewer
2013-08-14 21:13 . 2010-09-23 11:15        98344        ----a-w-        c:\windows\unTMV.exe
2013-08-14 08:04 . 2013-07-09 04:50        652800        ----a-w-        c:\windows\system32\rpcrt4.dll
2013-08-14 08:04 . 2013-07-09 04:52        175104        ----a-w-        c:\windows\system32\wintrust.dll
2013-08-14 08:04 . 2013-07-09 04:46        1166848        ----a-w-        c:\windows\system32\crypt32.dll
2013-08-14 08:04 . 2013-07-09 04:46        140288        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-08-14 08:04 . 2013-07-09 04:46        103936        ----a-w-        c:\windows\system32\cryptnet.dll
2013-08-14 08:04 . 2013-07-09 05:03        3913664        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-08-14 08:04 . 2013-07-09 05:03        3968960        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2013-08-14 08:04 . 2013-07-09 04:53        1289096        ----a-w-        c:\windows\system32\ntdll.dll
2013-08-14 08:04 . 2013-07-06 05:05        1293760        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-08-14 08:04 . 2013-07-25 08:57        1620992        ----a-w-        c:\windows\system32\WMVDECOD.DLL
2013-08-14 08:04 . 2013-07-19 01:41        2048        ----a-w-        c:\windows\system32\tzres.dll
2013-08-14 08:03 . 2013-06-15 03:38        31232        ----a-w-        c:\windows\system32\drivers\tssecsrv.sys
2013-08-13 19:49 . 2013-08-13 19:49        94632        ----a-w-        c:\windows\system32\WindowsAccessBridge.dll
2013-08-13 19:48 . 2013-08-13 19:48        --------        d-----w-        c:\program files\Java
2013-08-13 18:11 . 2013-08-13 18:11        --------        d-----w-        c:\program files\VS Revo Group
2013-08-13 18:06 . 2013-08-13 18:06        71048        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-13 18:06 . 2013-08-13 18:06        692104        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2013-08-12 19:49 . 2013-08-12 19:49        --------        d-----w-        C:\FRST
2013-08-12 16:35 . 2013-08-12 16:35        --------        d-----w-        c:\users\Mandy\AppData\Roaming\QuickScan
2013-08-12 16:33 . 2013-08-12 16:56        --------        d-----w-        c:\programdata\Bitdefender
2013-08-12 15:40 . 2013-08-12 16:56        --------        d-----w-        c:\program files\Common Files\Bitdefender
2013-08-12 14:51 . 2013-08-12 14:51        0        ---h--w-        c:\windows\nslB87E.tmp
2013-08-12 13:42 . 2013-08-12 13:44        --------        d-----w-        c:\program files\Common Files\DVDVideoSoft
2013-08-10 21:33 . 2013-08-10 21:33        --------        d-----w-        c:\program files\Tracker Software
2013-08-10 16:58 . 2013-08-10 18:28        --------        d-----w-        c:\programdata\eSafe
2013-08-10 16:58 . 2013-08-10 18:24        --------        d-----w-        c:\program files\DealPlyLive
2013-08-10 16:58 . 2013-08-10 16:58        --------        d-----w-        c:\users\Mandy\AppData\Local\DealPlyLive
2013-08-10 16:58 . 2013-08-10 16:58        --------        d-----w-        c:\programdata\DealPlyLive
2013-08-10 16:58 . 2013-08-10 16:58        --------        d-----w-        c:\users\Mandy\AppData\Roaming\Dealply
2013-08-10 16:58 . 2013-08-10 16:58        --------        d-----w-        c:\users\Mandy\AppData\Roaming\DSite
2013-08-10 16:57 . 2013-08-10 16:57        --------        d-----w-        c:\users\Mandy\AppData\Roaming\eIntaller
2013-08-10 16:57 . 2013-08-10 16:57        --------        d-----w-        c:\program files\Image Converter
2013-08-10 09:17 . 2013-08-12 15:46        --------        d-----w-        c:\programdata\Avira
2013-08-08 21:11 . 2013-08-15 21:12        --------        d-----w-        c:\windows\system32\MRT
2013-08-08 14:25 . 2013-04-17 07:02        1230336        ----a-w-        c:\windows\system32\WindowsCodecs.dll
2013-08-08 13:36 . 2013-08-08 13:36        --------        d-----w-        c:\users\Mandy\AppData\Local\ElevatedDiagnostics
2013-08-08 13:02 . 2013-04-09 23:34        1247744        ----a-w-        c:\windows\system32\DWrite.dll
2013-08-08 12:17 . 2012-12-16 14:13        295424        ----a-w-        c:\windows\system32\atmfd.dll
2013-08-08 12:17 . 2012-12-16 14:13        34304        ----a-w-        c:\windows\system32\atmlib.dll
2013-08-08 12:13 . 2013-08-11 11:22        1890        ----a-w-        c:\windows\system32\ASOROSet.bin
2013-08-08 10:58 . 2013-08-10 18:26        --------        d-----w-        c:\users\Mandy\AppData\Roaming\Systweak
2013-08-08 10:55 . 2013-08-08 10:55        --------        d-----w-        c:\users\Mandy\AppData\Local\Programs
2013-08-08 10:29 . 2013-08-08 10:29        --------        d-----w-        C:\f77ac4d2369eda7f3983c157b73a6e4b
2013-08-07 23:16 . 2013-08-07 23:16        49152        ----a-w-        c:\windows\system32\taskhost.exe
2013-08-07 22:56 . 2013-08-07 22:56        --------        d-----w-        c:\windows\system32\searchplugins
2013-08-07 22:56 . 2013-08-07 22:56        --------        d-----w-        c:\windows\system32\Extensions
2013-08-07 21:55 . 2013-08-07 21:55        --------        d-----w-        c:\users\Mandy\AppData\Roaming\Iminent
2013-08-07 21:54 . 2013-08-07 21:54        --------        d-----w-        c:\programdata\Iminent
2013-08-07 21:53 . 2013-08-08 10:35        --------        d-----w-        c:\program files\Common Files\Umbrella
2013-08-07 21:53 . 2013-08-07 21:55        --------        d-----w-        c:\program files\Iminent
2013-08-07 21:47 . 2013-08-07 21:47        --------        d-----w-        c:\program files\Julien MANICI
2013-08-07 21:44 . 2013-08-07 22:02        --------        d-----w-        c:\users\Mandy\AppData\Local\http___www.julien-manici
2013-08-07 21:33 . 2013-04-12 13:45        1211752        ----a-w-        c:\windows\system32\drivers\ntfs.sys
2013-08-07 21:33 . 2012-11-22 04:45        626688        ----a-w-        c:\windows\system32\usp10.dll
2013-08-07 21:33 . 2013-02-12 03:32        15872        ----a-w-        c:\windows\system32\drivers\usb8023x.sys
2013-08-07 21:33 . 2013-02-12 03:32        15872        ----a-w-        c:\windows\system32\drivers\usb8023.sys
2013-08-07 21:32 . 2012-11-02 05:11        376832        ----a-w-        c:\windows\system32\dpnet.dll
2013-08-07 21:32 . 2013-04-25 23:30        1505280        ----a-w-        c:\windows\system32\d3d11.dll
2013-08-07 21:31 . 2013-01-24 04:47        196328        ----a-w-        c:\windows\system32\drivers\fvevol.sys
2013-08-07 21:31 . 2013-03-19 04:53        186368        ----a-w-        c:\windows\system32\wwansvc.dll
2013-08-07 21:31 . 2013-03-19 03:33        40960        ----a-w-        c:\windows\system32\wwanprotdim.dll
2013-08-07 21:31 . 2013-03-19 02:49        69632        ----a-w-        c:\windows\system32\smss.exe
2013-08-07 21:31 . 2013-03-19 04:48        38912        ----a-w-        c:\windows\system32\csrsrv.dll
2013-08-07 21:31 . 2013-04-10 05:03        936448        ----a-w-        c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-07 21:30 . 2013-05-10 03:20        24576        ----a-w-        c:\windows\system32\cryptdlg.dll
2013-08-07 21:29 . 2013-02-15 04:37        3217408        ----a-w-        c:\windows\system32\mstscax.dll
2013-08-07 21:29 . 2013-02-15 04:34        131584        ----a-w-        c:\windows\system32\aaclient.dll
2013-08-07 21:29 . 2013-02-15 03:25        36864        ----a-w-        c:\windows\system32\tsgqec.dll
2013-08-07 21:29 . 2013-04-26 04:55        492544        ----a-w-        c:\windows\system32\win32spl.dll
2013-08-07 21:29 . 2012-11-01 04:47        1389568        ----a-w-        c:\windows\system32\msxml6.dll
2013-08-07 21:29 . 2013-05-13 03:08        903168        ----a-w-        c:\windows\system32\certutil.exe
2013-08-07 21:29 . 2013-05-13 03:08        43008        ----a-w-        c:\windows\system32\certenc.dll
2013-08-07 21:27 . 2013-06-04 04:53        509440        ----a-w-        c:\windows\system32\qedit.dll
2013-08-07 21:27 . 2013-06-05 03:05        2347520        ----a-w-        c:\windows\system32\win32k.sys
2013-08-07 21:11 . 2012-11-20 04:51        220160        ----a-w-        c:\windows\system32\ncrypt.dll
2013-08-07 21:11 . 2013-04-10 05:18        728424        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys
2013-08-07 21:11 . 2013-04-10 05:18        218984        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys
2013-08-07 21:11 . 2013-01-03 05:04        187752        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2013-08-07 21:10 . 2013-05-27 04:57        680960        ----a-w-        c:\program files\Windows Defender\MpSvc.dll
2013-08-07 21:10 . 2013-05-27 04:57        392704        ----a-w-        c:\program files\Windows Defender\MpClient.dll
2013-08-07 21:10 . 2013-05-27 04:57        224768        ----a-w-        c:\program files\Windows Defender\MpCommu.dll
2013-08-07 20:58 . 2013-08-07 20:58        --------        d-----w-        c:\program files\Mozilla Maintenance Service
2013-08-07 20:56 . 2013-01-04 04:50        169984        ----a-w-        c:\windows\system32\winsrv.dll
2013-08-07 20:56 . 2013-02-27 05:05        101720        ----a-w-        c:\windows\system32\consent.exe
2013-08-07 20:56 . 2013-02-27 04:49        1796096        ----a-w-        c:\windows\system32\authui.dll
2013-08-07 20:56 . 2013-02-27 04:49        47104        ----a-w-        c:\windows\system32\appinfo.dll
2013-08-07 20:19 . 2013-08-07 20:19        --------        d-----w-        C:\found.000
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-13 19:49 . 2012-07-30 15:47        867240        ----a-w-        c:\windows\system32\npDeployJava1.dll
2013-08-13 19:49 . 2012-07-30 15:47        789416        ----a-w-        c:\windows\system32\deployJava1.dll
2013-08-07 20:36 . 2010-06-24 02:33        22240        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-07 8555040]
"Iminent"="c:\program files\Iminent\Iminent.exe" [2013-07-02 1074736]
"IminentMessenger"="c:\program files\Iminent\Iminent.Messengers.exe" [2013-07-02 884784]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0??\0?[BdFirewallPath]*\0x\0??\0?[InstallPath]..\\0ex\0??\0?[BdFirewallPath]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Mandy\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"Facebook Update"="c:\users\Mandy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"YouCam Service"="c:\program files\CyberLink\YouCam\YouCamService.exe" /s
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-07-13 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-02 33320]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2010-10-07 10752]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 SProtection;SProtection;c:\program files\Common Files\Umbrella\umbrella.exe [2013-08-07 2864448]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-01 109056]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 579944]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 194408]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 yukonw7;NDIS6.2-Miniporttreiber für Marvell Yukon-Ethernet-Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc
.
Inhalt des "geplante Tasks" Ordners
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube to MP3 Converter - c:\program files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Mandy\AppData\Roaming\Mozilla\Firefox\Profiles\l80t3m2l.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1428909&SearchSource=2&CUI=UN29133404102847052&UM=1&q=
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - fc16653100000000000090a4de22af7f
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15924
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.023:57
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=124247&tsp=4967
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
HKLM-Run-YouCam Service - c:\program files\CyberLink\YouCam\YouCamService.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-19  19:56:38
ComboFix-quarantined-files.txt  2013-08-19 17:56
.
Vor Suchlauf: 10 Verzeichnis(se), 53.026.693.120 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 53.726.908.416 Bytes frei
.
- - End Of File - - 828D4AD3723C1D03C3E6FB04D099631C
2E5DEBB2116B3417023E0D6562D7ED07


markusg 21.08.2013 13:20

Sorry für die Wartezeit, warte momentan auf das TDSS Killer log

girli 29.08.2013 15:01

mach ich jetzt nochmal beim letzten mal hab ich ja was falsch gemacht

also den TDSS Killer kann ich nicht benutzen der ist zu größ für mein Netbook ich brauch da 32-bit.

markusg 29.08.2013 15:18

hi schau mal direkt hier:
Wie werden Schadprogramme der Familie Rootkit.Win32.TDSS bekämpft?
müsst auch auf 32 bit Systemen laufen

girli 29.08.2013 22:18

Der sagt er findet nichts .

TDSSKiller:
Code:

23:11:16.0579 0x1598  TDSS rootkit removing tool 2.9.2.0 Aug 15 2013 16:44:29
23:11:17.0716 0x1598  ============================================================
23:11:17.0716 0x1598  Current date / time: 2013/08/29 23:11:17.0716
23:11:17.0717 0x1598  SystemInfo:
23:11:17.0717 0x1598 
23:11:17.0717 0x1598  OS Version: 6.1.7601 ServicePack: 1.0
23:11:17.0717 0x1598  Product type: Workstation
23:11:17.0717 0x1598  ComputerName: MANDY-PC
23:11:17.0718 0x1598  UserName: Mandy
23:11:17.0718 0x1598  Windows directory: C:\windows
23:11:17.0718 0x1598  System windows directory: C:\windows
23:11:17.0718 0x1598  Processor architecture: Intel x86
23:11:17.0718 0x1598  Number of processors: 2
23:11:17.0718 0x1598  Page size: 0x1000
23:11:17.0718 0x1598  Boot type: Normal boot
23:11:17.0718 0x1598  ============================================================
23:11:20.0050 0x1598  Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
23:11:20.0128 0x1598  ============================================================
23:11:20.0128 0x1598  \Device\Harddisk0\DR0:
23:11:20.0128 0x1598  MBR partitions:
23:11:20.0128 0x1598  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2800800, BlocksNum 0x32000
23:11:20.0128 0x1598  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2832800, BlocksNum 0xAA00000
23:11:20.0152 0x1598  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xD233000, BlocksNum 0xFF92000
23:11:20.0152 0x1598  ============================================================
23:11:20.0225 0x1598  C: <-> \Device\Harddisk0\DR0\Partition2
23:11:20.0347 0x1598  D: <-> \Device\Harddisk0\DR0\Partition3
23:11:20.0370 0x1598  ============================================================
23:11:20.0370 0x1598  Initialize success
23:11:20.0370 0x1598  ============================================================
23:15:22.0222 0x0ea8  ============================================================
23:15:22.0222 0x0ea8  Scan started
23:15:22.0222 0x0ea8  Mode: Manual;
23:15:22.0222 0x0ea8  ============================================================
23:15:24.0249 0x0ea8  ================ Scan system memory ========================
23:15:24.0249 0x0ea8  System memory - ok
23:15:24.0251 0x0ea8  ================ Scan services =============================
23:15:24.0552 0x0ea8  [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci        C:\windows\system32\drivers\1394ohci.sys
23:15:24.0560 0x0ea8  1394ohci - ok
23:15:24.0601 0x0ea8  [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI            C:\windows\system32\drivers\ACPI.sys
23:15:24.0607 0x0ea8  ACPI - ok
23:15:24.0644 0x0ea8  [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi        C:\windows\system32\drivers\acpipmi.sys
23:15:24.0647 0x0ea8  AcpiPmi - ok
23:15:24.0735 0x0ea8  [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
23:15:24.0738 0x0ea8  AdobeARMservice - ok
23:15:24.0794 0x0ea8  [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx        C:\windows\system32\DRIVERS\adp94xx.sys
23:15:24.0804 0x0ea8  adp94xx - ok
23:15:24.0826 0x0ea8  [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci        C:\windows\system32\DRIVERS\adpahci.sys
23:15:24.0833 0x0ea8  adpahci - ok
23:15:24.0881 0x0ea8  [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320        C:\windows\system32\DRIVERS\adpu320.sys
23:15:24.0887 0x0ea8  adpu320 - ok
23:15:24.0961 0x0ea8  [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc    C:\windows\System32\aelupsvc.dll
23:15:24.0964 0x0ea8  AeLookupSvc - ok
23:15:25.0013 0x0ea8  [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD            C:\windows\system32\drivers\afd.sys
23:15:25.0020 0x0ea8  AFD - ok
23:15:25.0059 0x0ea8  [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440          C:\windows\system32\drivers\agp440.sys
23:15:25.0063 0x0ea8  agp440 - ok
23:15:25.0116 0x0ea8  [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx        C:\windows\system32\DRIVERS\djsvs.sys
23:15:25.0137 0x0ea8  aic78xx - ok
23:15:25.0189 0x0ea8  [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG            C:\windows\System32\alg.exe
23:15:25.0193 0x0ea8  ALG - ok
23:15:25.0248 0x0ea8  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide          C:\windows\system32\drivers\aliide.sys
23:15:25.0253 0x0ea8  aliide - ok
23:15:25.0304 0x0ea8  [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp          C:\windows\system32\drivers\amdagp.sys
23:15:25.0308 0x0ea8  amdagp - ok
23:15:25.0352 0x0ea8  [ CD5914170297126B6266860198D1D4F0 ] amdide          C:\windows\system32\drivers\amdide.sys
23:15:25.0355 0x0ea8  amdide - ok
23:15:25.0381 0x0ea8  [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8          C:\windows\system32\DRIVERS\amdk8.sys
23:15:25.0385 0x0ea8  AmdK8 - ok
23:15:25.0401 0x0ea8  [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM          C:\windows\system32\DRIVERS\amdppm.sys
23:15:25.0405 0x0ea8  AmdPPM - ok
23:15:25.0453 0x0ea8  [ D320BF87125326F996D4904FE24300FC ] amdsata        C:\windows\system32\drivers\amdsata.sys
23:15:25.0458 0x0ea8  amdsata - ok
23:15:25.0511 0x0ea8  [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs          C:\windows\system32\DRIVERS\amdsbs.sys
23:15:25.0517 0x0ea8  amdsbs - ok
23:15:25.0555 0x0ea8  [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata        C:\windows\system32\drivers\amdxata.sys
23:15:25.0558 0x0ea8  amdxata - ok
23:15:25.0600 0x0ea8  [ AEA177F783E20150ACE5383EE368DA19 ] AppID          C:\windows\system32\drivers\appid.sys
23:15:25.0604 0x0ea8  AppID - ok
23:15:25.0674 0x0ea8  [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc        C:\windows\System32\appidsvc.dll
23:15:25.0679 0x0ea8  AppIDSvc - ok
23:15:25.0741 0x0ea8  [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo        C:\windows\System32\appinfo.dll
23:15:25.0745 0x0ea8  Appinfo - ok
23:15:25.0807 0x0ea8  [ 2932004F49677BD84DBC72EDB754FFB3 ] arc            C:\windows\system32\DRIVERS\arc.sys
23:15:25.0813 0x0ea8  arc - ok
23:15:25.0844 0x0ea8  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas          C:\windows\system32\DRIVERS\arcsas.sys
23:15:25.0850 0x0ea8  arcsas - ok
23:15:25.0875 0x0ea8  [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac        C:\windows\system32\DRIVERS\asyncmac.sys
23:15:25.0879 0x0ea8  AsyncMac - ok
23:15:25.0910 0x0ea8  [ 338C86357871C167A96AB976519BF59E ] atapi          C:\windows\system32\drivers\atapi.sys
23:15:25.0914 0x0ea8  atapi - ok
23:15:25.0962 0x0ea8  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
23:15:25.0971 0x0ea8  AudioEndpointBuilder - ok
23:15:26.0006 0x0ea8  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv        C:\windows\System32\Audiosrv.dll
23:15:26.0013 0x0ea8  Audiosrv - ok
23:15:26.0060 0x0ea8  [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV        C:\windows\System32\AxInstSV.dll
23:15:26.0065 0x0ea8  AxInstSV - ok
23:15:26.0116 0x0ea8  [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv        C:\windows\system32\DRIVERS\bxvbdx.sys
23:15:26.0131 0x0ea8  b06bdrv - ok
23:15:26.0186 0x0ea8  [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x        C:\windows\system32\DRIVERS\b57nd60x.sys
23:15:26.0193 0x0ea8  b57nd60x - ok
23:15:26.0351 0x0ea8  [ 9E209171C51B1D750F53777253B80E81 ] BCM43XX        C:\windows\system32\DRIVERS\bcmwl6.sys
23:15:26.0482 0x0ea8  BCM43XX - ok
23:15:26.0534 0x0ea8  [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC          C:\windows\System32\bdesvc.dll
23:15:26.0540 0x0ea8  BDESVC - ok
23:15:26.0571 0x0ea8  [ 505506526A9D467307B3C393DEDAF858 ] Beep            C:\windows\system32\drivers\Beep.sys
23:15:26.0573 0x0ea8  Beep - ok
23:15:26.0628 0x0ea8  [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE            C:\windows\System32\bfe.dll
23:15:26.0638 0x0ea8  BFE - ok
23:15:26.0673 0x0ea8  [ E585445D5021971FAE10393F0F1C3961 ] BITS            C:\windows\system32\qmgr.dll
23:15:26.0702 0x0ea8  BITS - ok
23:15:26.0741 0x0ea8  [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive        C:\windows\system32\DRIVERS\blbdrive.sys
23:15:26.0745 0x0ea8  blbdrive - ok
23:15:26.0783 0x0ea8  [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser          C:\windows\system32\DRIVERS\bowser.sys
23:15:26.0788 0x0ea8  bowser - ok
23:15:26.0809 0x0ea8  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\windows\system32\DRIVERS\BrFiltLo.sys
23:15:26.0811 0x0ea8  BrFiltLo - ok
23:15:26.0826 0x0ea8  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\windows\system32\DRIVERS\BrFiltUp.sys
23:15:26.0830 0x0ea8  BrFiltUp - ok
23:15:26.0860 0x0ea8  [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP        C:\windows\system32\DRIVERS\bridge.sys
23:15:26.0865 0x0ea8  BridgeMP - ok
23:15:26.0927 0x0ea8  [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser        C:\windows\System32\browser.dll
23:15:26.0932 0x0ea8  Browser - ok
23:15:26.0959 0x0ea8  [ 845B8CE732E67F3B4133164868C666EA ] Brserid        C:\windows\System32\Drivers\Brserid.sys
23:15:26.0967 0x0ea8  Brserid - ok
23:15:26.0984 0x0ea8  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\windows\System32\Drivers\BrSerWdm.sys
23:15:26.0988 0x0ea8  BrSerWdm - ok
23:15:27.0005 0x0ea8  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\windows\System32\Drivers\BrUsbMdm.sys
23:15:27.0010 0x0ea8  BrUsbMdm - ok
23:15:27.0029 0x0ea8  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\windows\System32\Drivers\BrUsbSer.sys
23:15:27.0033 0x0ea8  BrUsbSer - ok
23:15:27.0061 0x0ea8  [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum        C:\windows\system32\drivers\BthEnum.sys
23:15:27.0064 0x0ea8  BthEnum - ok
23:15:27.0089 0x0ea8  [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM        C:\windows\system32\DRIVERS\bthmodem.sys
23:15:27.0093 0x0ea8  BTHMODEM - ok
23:15:27.0135 0x0ea8  [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan          C:\windows\system32\DRIVERS\bthpan.sys
23:15:27.0139 0x0ea8  BthPan - ok
23:15:27.0174 0x0ea8  [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT        C:\windows\System32\Drivers\BTHport.sys
23:15:27.0185 0x0ea8  BTHPORT - ok
23:15:27.0218 0x0ea8  [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv        C:\windows\system32\bthserv.dll
23:15:27.0223 0x0ea8  bthserv - ok
23:15:27.0253 0x0ea8  [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB          C:\windows\System32\Drivers\BTHUSB.sys
23:15:27.0257 0x0ea8  BTHUSB - ok
23:15:27.0306 0x0ea8  [ 525432CFD6D8C004860AF7ECD0A84234 ] btwampfl        C:\windows\system32\drivers\btwampfl.sys
23:15:27.0314 0x0ea8  btwampfl - ok
23:15:27.0341 0x0ea8  [ CF8799A563F734984D4E053CACEC1426 ] btwaudio        C:\windows\system32\drivers\btwaudio.sys
23:15:27.0347 0x0ea8  btwaudio - ok
23:15:27.0396 0x0ea8  [ 9ED9932043D599AEA04F6EA2D86964A1 ] btwavdt        C:\windows\system32\drivers\btwavdt.sys
23:15:27.0401 0x0ea8  btwavdt - ok
23:15:27.0485 0x0ea8  [ 7778C6BCAFF58C0E876B307514923A48 ] btwdins        C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
23:15:27.0521 0x0ea8  btwdins - ok
23:15:27.0555 0x0ea8  [ DE53089F0678CB5F0AFEB867ACB0FB05 ] btwl2cap        C:\windows\system32\DRIVERS\btwl2cap.sys
23:15:27.0558 0x0ea8  btwl2cap - ok
23:15:27.0580 0x0ea8  [ 373D1BB0F7DC8F1931F9B7E0DE3E9A30 ] btwrchid        C:\windows\system32\DRIVERS\btwrchid.sys
23:15:27.0583 0x0ea8  btwrchid - ok
23:15:27.0702 0x0ea8  catchme - ok
23:15:27.0740 0x0ea8  [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs            C:\windows\system32\DRIVERS\cdfs.sys
23:15:27.0744 0x0ea8  cdfs - ok
23:15:27.0791 0x0ea8  [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom          C:\windows\system32\DRIVERS\cdrom.sys
23:15:27.0796 0x0ea8  cdrom - ok
23:15:27.0828 0x0ea8  [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc    C:\windows\System32\certprop.dll
23:15:27.0833 0x0ea8  CertPropSvc - ok
23:15:27.0863 0x0ea8  [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass        C:\windows\system32\DRIVERS\circlass.sys
23:15:27.0868 0x0ea8  circlass - ok
23:15:27.0929 0x0ea8  [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS            C:\windows\system32\CLFS.sys
23:15:27.0935 0x0ea8  CLFS - ok
23:15:28.0013 0x0ea8  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:15:28.0028 0x0ea8  clr_optimization_v2.0.50727_32 - ok
23:15:28.0088 0x0ea8  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:15:28.0118 0x0ea8  clr_optimization_v4.0.30319_32 - ok
23:15:28.0133 0x0ea8  clwvd - ok
23:15:28.0180 0x0ea8  [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt          C:\windows\system32\DRIVERS\CmBatt.sys
23:15:28.0183 0x0ea8  CmBatt - ok
23:15:28.0226 0x0ea8  [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide          C:\windows\system32\drivers\cmdide.sys
23:15:28.0229 0x0ea8  cmdide - ok
23:15:28.0270 0x0ea8  [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG            C:\windows\system32\Drivers\cng.sys
23:15:28.0289 0x0ea8  CNG - ok
23:15:28.0309 0x0ea8  [ A6023D3823C37043986713F118A89BEE ] Compbatt        C:\windows\system32\DRIVERS\compbatt.sys
23:15:28.0313 0x0ea8  Compbatt - ok
23:15:28.0351 0x0ea8  [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus    C:\windows\system32\drivers\CompositeBus.sys
23:15:28.0356 0x0ea8  CompositeBus - ok
23:15:28.0379 0x0ea8  COMSysApp - ok
23:15:28.0412 0x0ea8  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk        C:\windows\system32\DRIVERS\crcdisk.sys
23:15:28.0416 0x0ea8  crcdisk - ok
23:15:28.0463 0x0ea8  [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc        C:\windows\system32\cryptsvc.dll
23:15:28.0468 0x0ea8  CryptSvc - ok
23:15:28.0568 0x0ea8  [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc          C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
23:15:28.0601 0x0ea8  cvhsvc - ok
23:15:28.0656 0x0ea8  [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch      C:\windows\system32\rpcss.dll
23:15:28.0669 0x0ea8  DcomLaunch - ok
23:15:28.0708 0x0ea8  [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc      C:\windows\System32\defragsvc.dll
23:15:28.0716 0x0ea8  defragsvc - ok
23:15:28.0757 0x0ea8  [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC            C:\windows\system32\Drivers\dfsc.sys
23:15:28.0761 0x0ea8  DfsC - ok
23:15:28.0804 0x0ea8  [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp            C:\windows\system32\dhcpcore.dll
23:15:28.0811 0x0ea8  Dhcp - ok
23:15:28.0851 0x0ea8  [ 1A050B0274BFB3890703D490F330C0DA ] discache        C:\windows\system32\drivers\discache.sys
23:15:28.0853 0x0ea8  discache - ok
23:15:28.0869 0x0ea8  [ 565003F326F99802E68CA78F2A68E9FF ] Disk            C:\windows\system32\DRIVERS\disk.sys
23:15:28.0874 0x0ea8  Disk - ok
23:15:28.0921 0x0ea8  [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache        C:\windows\System32\dnsrslvr.dll
23:15:28.0927 0x0ea8  Dnscache - ok
23:15:28.0965 0x0ea8  [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc        C:\windows\System32\dot3svc.dll
23:15:28.0972 0x0ea8  dot3svc - ok
23:15:29.0017 0x0ea8  [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS            C:\windows\system32\dps.dll
23:15:29.0023 0x0ea8  DPS - ok
23:15:29.0065 0x0ea8  [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud        C:\windows\system32\drivers\drmkaud.sys
23:15:29.0069 0x0ea8  drmkaud - ok
23:15:29.0124 0x0ea8  [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl        C:\windows\System32\drivers\dxgkrnl.sys
23:15:29.0159 0x0ea8  DXGKrnl - ok
23:15:29.0202 0x0ea8  [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost        C:\windows\System32\eapsvc.dll
23:15:29.0207 0x0ea8  EapHost - ok
23:15:29.0351 0x0ea8  [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv          C:\windows\system32\DRIVERS\evbdx.sys
23:15:29.0459 0x0ea8  ebdrv - ok
23:15:29.0500 0x0ea8  [ 81951F51E318AECC2D68559E47485CC4 ] EFS            C:\windows\System32\lsass.exe
23:15:29.0505 0x0ea8  EFS - ok
23:15:29.0569 0x0ea8  [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor        C:\windows\system32\DRIVERS\elxstor.sys
23:15:29.0579 0x0ea8  elxstor - ok
23:15:29.0606 0x0ea8  [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev          C:\windows\system32\drivers\errdev.sys
23:15:29.0609 0x0ea8  ErrDev - ok
23:15:29.0662 0x0ea8  [ DF4F000CFC05DEC947D928A8F3ADCD7A ] ETD            C:\windows\system32\DRIVERS\ETD.sys
23:15:29.0666 0x0ea8  ETD - ok
23:15:29.0735 0x0ea8  [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem    C:\windows\system32\es.dll
23:15:29.0743 0x0ea8  EventSystem - ok
23:15:29.0775 0x0ea8  [ 2DC9108D74081149CC8B651D3A26207F ] exfat          C:\windows\system32\drivers\exfat.sys
23:15:29.0781 0x0ea8  exfat - ok
23:15:29.0810 0x0ea8  [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat        C:\windows\system32\drivers\fastfat.sys
23:15:29.0816 0x0ea8  fastfat - ok
23:15:29.0859 0x0ea8  [ 967EA5B213E9984CBE270205DF37755B ] Fax            C:\windows\system32\fxssvc.exe
23:15:29.0878 0x0ea8  Fax - ok
23:15:29.0894 0x0ea8  [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc            C:\windows\system32\DRIVERS\fdc.sys
23:15:29.0900 0x0ea8  fdc - ok
23:15:29.0948 0x0ea8  [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost        C:\windows\system32\fdPHost.dll
23:15:29.0952 0x0ea8  fdPHost - ok
23:15:29.0974 0x0ea8  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub        C:\windows\system32\fdrespub.dll
23:15:29.0978 0x0ea8  FDResPub - ok
23:15:29.0998 0x0ea8  [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo        C:\windows\system32\drivers\fileinfo.sys
23:15:30.0002 0x0ea8  FileInfo - ok
23:15:30.0022 0x0ea8  [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace      C:\windows\system32\drivers\filetrace.sys
23:15:30.0026 0x0ea8  Filetrace - ok
23:15:30.0057 0x0ea8  [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk        C:\windows\system32\DRIVERS\flpydisk.sys
23:15:30.0061 0x0ea8  flpydisk - ok
23:15:30.0094 0x0ea8  [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr          C:\windows\system32\drivers\fltmgr.sys
23:15:30.0100 0x0ea8  FltMgr - ok
23:15:30.0186 0x0ea8  [ E12C4928B32ACE04610259647F072635 ] FontCache      C:\windows\system32\FntCache.dll
23:15:30.0216 0x0ea8  FontCache - ok
23:15:30.0290 0x0ea8  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
23:15:30.0300 0x0ea8  FontCache3.0.0.0 - ok
23:15:30.0344 0x0ea8  [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends      C:\windows\system32\drivers\FsDepends.sys
23:15:30.0349 0x0ea8  FsDepends - ok
23:15:30.0379 0x0ea8  [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec          C:\windows\system32\drivers\Fs_Rec.sys
23:15:30.0383 0x0ea8  Fs_Rec - ok
23:15:30.0439 0x0ea8  [ E306A24D9694C724FA2491278BF50FDB ] fvevol          C:\windows\system32\DRIVERS\fvevol.sys
23:15:30.0445 0x0ea8  fvevol - ok
23:15:30.0476 0x0ea8  [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx        C:\windows\system32\DRIVERS\gagp30kx.sys
23:15:30.0480 0x0ea8  gagp30kx - ok
23:15:30.0528 0x0ea8  [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc          C:\windows\System32\gpsvc.dll
23:15:30.0544 0x0ea8  gpsvc - ok
23:15:30.0573 0x0ea8  [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir        C:\windows\system32\drivers\hcw85cir.sys
23:15:30.0578 0x0ea8  hcw85cir - ok
23:15:30.0629 0x0ea8  [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
23:15:30.0637 0x0ea8  HdAudAddService - ok
23:15:30.0660 0x0ea8  [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus        C:\windows\system32\drivers\HDAudBus.sys
23:15:30.0664 0x0ea8  HDAudBus - ok
23:15:30.0691 0x0ea8  [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt        C:\windows\system32\DRIVERS\HidBatt.sys
23:15:30.0695 0x0ea8  HidBatt - ok
23:15:30.0712 0x0ea8  [ 89448F40E6DF260C206A193A4683BA78 ] HidBth          C:\windows\system32\DRIVERS\hidbth.sys
23:15:30.0717 0x0ea8  HidBth - ok
23:15:30.0733 0x0ea8  [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr          C:\windows\system32\DRIVERS\hidir.sys
23:15:30.0738 0x0ea8  HidIr - ok
23:15:30.0776 0x0ea8  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv        C:\windows\System32\hidserv.dll
23:15:30.0781 0x0ea8  hidserv - ok
23:15:30.0816 0x0ea8  [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb          C:\windows\system32\DRIVERS\hidusb.sys
23:15:30.0820 0x0ea8  HidUsb - ok
23:15:30.0856 0x0ea8  [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc          C:\windows\system32\kmsvc.dll
23:15:30.0863 0x0ea8  hkmsvc - ok
23:15:30.0896 0x0ea8  [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\windows\system32\ListSvc.dll
23:15:30.0905 0x0ea8  HomeGroupListener - ok
23:15:30.0943 0x0ea8  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\windows\system32\provsvc.dll
23:15:30.0953 0x0ea8  HomeGroupProvider - ok
23:15:30.0990 0x0ea8  [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD          C:\windows\system32\drivers\HpSAMD.sys
23:15:30.0995 0x0ea8  HpSAMD - ok
23:15:31.0051 0x0ea8  [ 871917B07A141BFF43D76D8844D48106 ] HTTP            C:\windows\system32\drivers\HTTP.sys
23:15:31.0063 0x0ea8  HTTP - ok
23:15:31.0113 0x0ea8  [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy        C:\windows\system32\drivers\hwpolicy.sys
23:15:31.0114 0x0ea8  hwpolicy - ok
23:15:31.0138 0x0ea8  [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt        C:\windows\system32\drivers\i8042prt.sys
23:15:31.0143 0x0ea8  i8042prt - ok
23:15:31.0182 0x0ea8  [ D483687EACE0C065EE772481A96E05F5 ] iaStor          C:\windows\system32\DRIVERS\iaStor.sys
23:15:31.0188 0x0ea8  iaStor - ok
23:15:31.0227 0x0ea8  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV        C:\windows\system32\drivers\iaStorV.sys
23:15:31.0235 0x0ea8  iaStorV - ok
23:15:31.0306 0x0ea8  [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc          C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:15:31.0326 0x0ea8  idsvc - ok
23:15:31.0537 0x0ea8  [ D0074897C6BC132F3980EA4654BF7FB9 ] igfx            C:\windows\system32\DRIVERS\igdkmd32.sys
23:15:31.0682 0x0ea8  igfx - ok
23:15:31.0717 0x0ea8  [ 4173FF5708F3236CF25195FECD742915 ] iirsp          C:\windows\system32\DRIVERS\iirsp.sys
23:15:31.0722 0x0ea8  iirsp - ok
23:15:31.0781 0x0ea8  [ F95622F161474511B8D80D6B093AA610 ] IKEEXT          C:\windows\System32\ikeext.dll
23:15:31.0813 0x0ea8  IKEEXT - ok
23:15:31.0962 0x0ea8  [ F4427E5DF32CDE359B2E2E5512D18001 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHDA.sys
23:15:32.0062 0x0ea8  IntcAzAudAddService - ok
23:15:32.0085 0x0ea8  [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide        C:\windows\system32\drivers\intelide.sys
23:15:32.0088 0x0ea8  intelide - ok
23:15:32.0118 0x0ea8  [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm        C:\windows\system32\DRIVERS\intelppm.sys
23:15:32.0121 0x0ea8  intelppm - ok
23:15:32.0166 0x0ea8  [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum      C:\windows\system32\ipbusenum.dll
23:15:32.0173 0x0ea8  IPBusEnum - ok
23:15:32.0198 0x0ea8  [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver  C:\windows\system32\DRIVERS\ipfltdrv.sys
23:15:32.0201 0x0ea8  IpFilterDriver - ok
23:15:32.0241 0x0ea8  [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc        C:\windows\System32\iphlpsvc.dll
23:15:32.0253 0x0ea8  iphlpsvc - ok
23:15:32.0303 0x0ea8  [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV        C:\windows\system32\drivers\IPMIDrv.sys
23:15:32.0307 0x0ea8  IPMIDRV - ok
23:15:32.0334 0x0ea8  [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT          C:\windows\system32\drivers\ipnat.sys
23:15:32.0340 0x0ea8  IPNAT - ok
23:15:32.0370 0x0ea8  [ 42996CFF20A3084A56017B7902307E9F ] IRENUM          C:\windows\system32\drivers\irenum.sys
23:15:32.0373 0x0ea8  IRENUM - ok
23:15:32.0415 0x0ea8  [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp          C:\windows\system32\drivers\isapnp.sys
23:15:32.0420 0x0ea8  isapnp - ok
23:15:32.0475 0x0ea8  [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt        C:\windows\system32\drivers\msiscsi.sys
23:15:32.0482 0x0ea8  iScsiPrt - ok
23:15:32.0505 0x0ea8  [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass        C:\windows\system32\DRIVERS\kbdclass.sys
23:15:32.0508 0x0ea8  kbdclass - ok
23:15:32.0547 0x0ea8  [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid          C:\windows\system32\DRIVERS\kbdhid.sys
23:15:32.0551 0x0ea8  kbdhid - ok
23:15:32.0577 0x0ea8  [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso          C:\windows\system32\lsass.exe
23:15:32.0584 0x0ea8  KeyIso - ok
23:15:32.0639 0x0ea8  [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD          C:\windows\system32\Drivers\ksecdd.sys
23:15:32.0644 0x0ea8  KSecDD - ok
23:15:32.0693 0x0ea8  [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg        C:\windows\system32\Drivers\ksecpkg.sys
23:15:32.0698 0x0ea8  KSecPkg - ok
23:15:32.0746 0x0ea8  [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm          C:\windows\system32\msdtckrm.dll
23:15:32.0758 0x0ea8  KtmRm - ok
23:15:32.0807 0x0ea8  [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer    C:\windows\System32\srvsvc.dll
23:15:32.0829 0x0ea8  LanmanServer - ok
23:15:32.0857 0x0ea8  [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
23:15:32.0867 0x0ea8  LanmanWorkstation - ok
23:15:32.0909 0x0ea8  [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio          C:\windows\system32\DRIVERS\lltdio.sys
23:15:32.0914 0x0ea8  lltdio - ok
23:15:32.0958 0x0ea8  [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc        C:\windows\System32\lltdsvc.dll
23:15:32.0967 0x0ea8  lltdsvc - ok
23:15:33.0010 0x0ea8  [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts        C:\windows\System32\lmhsvc.dll
23:15:33.0016 0x0ea8  lmhosts - ok
23:15:33.0048 0x0ea8  [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC          C:\windows\system32\DRIVERS\lsi_fc.sys
23:15:33.0052 0x0ea8  LSI_FC - ok
23:15:33.0078 0x0ea8  [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS        C:\windows\system32\DRIVERS\lsi_sas.sys
23:15:33.0083 0x0ea8  LSI_SAS - ok
23:15:33.0112 0x0ea8  [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2        C:\windows\system32\DRIVERS\lsi_sas2.sys
23:15:33.0115 0x0ea8  LSI_SAS2 - ok
23:15:33.0148 0x0ea8  [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI        C:\windows\system32\DRIVERS\lsi_scsi.sys
23:15:33.0153 0x0ea8  LSI_SCSI - ok
23:15:33.0175 0x0ea8  [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv          C:\windows\system32\drivers\luafv.sys
23:15:33.0179 0x0ea8  luafv - ok
23:15:33.0192 0x0ea8  massfilter - ok
23:15:33.0228 0x0ea8  [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas        C:\windows\system32\DRIVERS\megasas.sys
23:15:33.0232 0x0ea8  megasas - ok
23:15:33.0263 0x0ea8  [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR          C:\windows\system32\DRIVERS\MegaSR.sys
23:15:33.0271 0x0ea8  MegaSR - ok
23:15:33.0322 0x0ea8  [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS          C:\windows\system32\mmcss.dll
23:15:33.0328 0x0ea8  MMCSS - ok
23:15:33.0373 0x0ea8  [ F001861E5700EE84E2D4E52C712F4964 ] Modem          C:\windows\system32\drivers\modem.sys
23:15:33.0376 0x0ea8  Modem - ok
23:15:33.0402 0x0ea8  [ 79D10964DE86B292320E9DFE02282A23 ] monitor        C:\windows\system32\DRIVERS\monitor.sys
23:15:33.0405 0x0ea8  monitor - ok
23:15:33.0451 0x0ea8  [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass        C:\windows\system32\drivers\mouclass.sys
23:15:33.0456 0x0ea8  mouclass - ok
23:15:33.0495 0x0ea8  [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid          C:\windows\system32\DRIVERS\mouhid.sys
23:15:33.0499 0x0ea8  mouhid - ok
23:15:33.0565 0x0ea8  [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr        C:\windows\system32\drivers\mountmgr.sys
23:15:33.0570 0x0ea8  mountmgr - ok
23:15:33.0629 0x0ea8  [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
23:15:33.0636 0x0ea8  MozillaMaintenance - ok
23:15:33.0666 0x0ea8  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio            C:\windows\system32\drivers\mpio.sys
23:15:33.0672 0x0ea8  mpio - ok
23:15:33.0708 0x0ea8  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv          C:\windows\system32\drivers\mpsdrv.sys
23:15:33.0712 0x0ea8  mpsdrv - ok
23:15:33.0770 0x0ea8  [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc          C:\windows\system32\mpssvc.dll
23:15:33.0803 0x0ea8  MpsSvc - ok
23:15:33.0849 0x0ea8  [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV          C:\windows\system32\drivers\mrxdav.sys
23:15:33.0856 0x0ea8  MRxDAV - ok
23:15:33.0900 0x0ea8  [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb          C:\windows\system32\DRIVERS\mrxsmb.sys
23:15:33.0905 0x0ea8  mrxsmb - ok
23:15:33.0932 0x0ea8  [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10        C:\windows\system32\DRIVERS\mrxsmb10.sys
23:15:33.0939 0x0ea8  mrxsmb10 - ok
23:15:33.0972 0x0ea8  [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20        C:\windows\system32\DRIVERS\mrxsmb20.sys
23:15:33.0977 0x0ea8  mrxsmb20 - ok
23:15:34.0000 0x0ea8  [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci          C:\windows\system32\drivers\msahci.sys
23:15:34.0004 0x0ea8  msahci - ok
23:15:34.0038 0x0ea8  [ 55055F8AD8BE27A64C831322A780A228 ] msdsm          C:\windows\system32\drivers\msdsm.sys
23:15:34.0043 0x0ea8  msdsm - ok
23:15:34.0075 0x0ea8  [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC          C:\windows\System32\msdtc.exe
23:15:34.0084 0x0ea8  MSDTC - ok
23:15:34.0122 0x0ea8  [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs            C:\windows\system32\drivers\Msfs.sys
23:15:34.0126 0x0ea8  Msfs - ok
23:15:34.0153 0x0ea8  [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf      C:\windows\System32\drivers\mshidkmdf.sys
23:15:34.0155 0x0ea8  mshidkmdf - ok
23:15:34.0177 0x0ea8  [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv        C:\windows\system32\drivers\msisadrv.sys
23:15:34.0181 0x0ea8  msisadrv - ok
23:15:34.0218 0x0ea8  [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI        C:\windows\system32\iscsiexe.dll
23:15:34.0226 0x0ea8  MSiSCSI - ok
23:15:34.0239 0x0ea8  msiserver - ok
23:15:34.0275 0x0ea8  [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV        C:\windows\system32\drivers\MSKSSRV.sys
23:15:34.0278 0x0ea8  MSKSSRV - ok
23:15:34.0301 0x0ea8  [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK        C:\windows\system32\drivers\MSPCLOCK.sys
23:15:34.0304 0x0ea8  MSPCLOCK - ok
23:15:34.0331 0x0ea8  [ F456E973590D663B1073E9C463B40932 ] MSPQM          C:\windows\system32\drivers\MSPQM.sys
23:15:34.0334 0x0ea8  MSPQM - ok
23:15:34.0361 0x0ea8  [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC          C:\windows\system32\drivers\MsRPC.sys
23:15:34.0367 0x0ea8  MsRPC - ok
23:15:34.0428 0x0ea8  [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios        C:\windows\system32\drivers\mssmbios.sys
23:15:34.0433 0x0ea8  mssmbios - ok
23:15:34.0467 0x0ea8  [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE          C:\windows\system32\drivers\MSTEE.sys
23:15:34.0471 0x0ea8  MSTEE - ok
23:15:34.0498 0x0ea8  [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig        C:\windows\system32\DRIVERS\MTConfig.sys
23:15:34.0502 0x0ea8  MTConfig - ok
23:15:34.0523 0x0ea8  [ 159FAD02F64E6381758C990F753BCC80 ] Mup            C:\windows\system32\Drivers\mup.sys
23:15:34.0527 0x0ea8  Mup - ok
23:15:34.0580 0x0ea8  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent        C:\windows\system32\qagentRT.dll
23:15:34.0592 0x0ea8  napagent - ok
23:15:34.0638 0x0ea8  [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP    C:\windows\system32\DRIVERS\nwifi.sys
23:15:34.0646 0x0ea8  NativeWifiP - ok
23:15:34.0715 0x0ea8  [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS            C:\windows\system32\drivers\ndis.sys
23:15:34.0748 0x0ea8  NDIS - ok
23:15:34.0786 0x0ea8  [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap        C:\windows\system32\DRIVERS\ndiscap.sys
23:15:34.0791 0x0ea8  NdisCap - ok
23:15:34.0822 0x0ea8  [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi        C:\windows\system32\DRIVERS\ndistapi.sys
23:15:34.0825 0x0ea8  NdisTapi - ok
23:15:34.0862 0x0ea8  [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio        C:\windows\system32\DRIVERS\ndisuio.sys
23:15:34.0865 0x0ea8  Ndisuio - ok
23:15:34.0897 0x0ea8  [ 38FBE267E7E6983311179230FACB1017 ] NdisWan        C:\windows\system32\DRIVERS\ndiswan.sys
23:15:34.0902 0x0ea8  NdisWan - ok
23:15:34.0917 0x0ea8  [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy        C:\windows\system32\drivers\NDProxy.sys
23:15:34.0926 0x0ea8  NDProxy - ok
23:15:34.0956 0x0ea8  [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS        C:\windows\system32\DRIVERS\netbios.sys
23:15:34.0961 0x0ea8  NetBIOS - ok
23:15:35.0013 0x0ea8  [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT          C:\windows\system32\DRIVERS\netbt.sys
23:15:35.0018 0x0ea8  NetBT - ok
23:15:35.0044 0x0ea8  [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon        C:\windows\system32\lsass.exe
23:15:35.0049 0x0ea8  Netlogon - ok
23:15:35.0093 0x0ea8  [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman          C:\windows\System32\netman.dll
23:15:35.0103 0x0ea8  Netman - ok
23:15:35.0135 0x0ea8  [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm        C:\windows\System32\netprofm.dll
23:15:35.0148 0x0ea8  netprofm - ok
23:15:35.0183 0x0ea8  [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
23:15:35.0188 0x0ea8  NetTcpPortSharing - ok
23:15:35.0221 0x0ea8  [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960        C:\windows\system32\DRIVERS\nfrd960.sys
23:15:35.0226 0x0ea8  nfrd960 - ok
23:15:35.0276 0x0ea8  [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc          C:\windows\System32\nlasvc.dll
23:15:35.0288 0x0ea8  NlaSvc - ok
23:15:35.0345 0x0ea8  [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs            C:\windows\system32\drivers\Npfs.sys
23:15:35.0348 0x0ea8  Npfs - ok
23:15:35.0380 0x0ea8  [ BA387E955E890C8A88306D9B8D06BF17 ] nsi            C:\windows\system32\nsisvc.dll
23:15:35.0389 0x0ea8  nsi - ok
23:15:35.0417 0x0ea8  [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy        C:\windows\system32\drivers\nsiproxy.sys
23:15:35.0418 0x0ea8  nsiproxy - ok
23:15:35.0509 0x0ea8  [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs            C:\windows\system32\drivers\Ntfs.sys
23:15:35.0555 0x0ea8  Ntfs - ok
23:15:35.0579 0x0ea8  [ F9756A98D69098DCA8945D62858A812C ] Null            C:\windows\system32\drivers\Null.sys
23:15:35.0583 0x0ea8  Null - ok
23:15:35.0629 0x0ea8  [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid          C:\windows\system32\drivers\nvraid.sys
23:15:35.0636 0x0ea8  nvraid - ok
23:15:35.0665 0x0ea8  [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor          C:\windows\system32\drivers\nvstor.sys
23:15:35.0671 0x0ea8  nvstor - ok
23:15:35.0712 0x0ea8  [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp          C:\windows\system32\drivers\nv_agp.sys
23:15:35.0717 0x0ea8  nv_agp - ok
23:15:35.0747 0x0ea8  [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394        C:\windows\system32\drivers\ohci1394.sys
23:15:35.0752 0x0ea8  ohci1394 - ok
23:15:35.0790 0x0ea8  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:15:35.0797 0x0ea8  ose - ok
23:15:35.0966 0x0ea8  [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
23:15:36.0116 0x0ea8  osppsvc - ok
23:15:36.0170 0x0ea8  [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc        C:\windows\system32\pnrpsvc.dll
23:15:36.0182 0x0ea8  p2pimsvc - ok
23:15:36.0202 0x0ea8  [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc          C:\windows\system32\p2psvc.dll
23:15:36.0216 0x0ea8  p2psvc - ok
23:15:36.0262 0x0ea8  [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport        C:\windows\system32\DRIVERS\parport.sys
23:15:36.0267 0x0ea8  Parport - ok
23:15:36.0307 0x0ea8  [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr        C:\windows\system32\drivers\partmgr.sys
23:15:36.0312 0x0ea8  partmgr - ok
23:15:36.0340 0x0ea8  [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm          C:\windows\system32\DRIVERS\parvdm.sys
23:15:36.0344 0x0ea8  Parvdm - ok
23:15:36.0385 0x0ea8  [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc          C:\windows\System32\pcasvc.dll
23:15:36.0396 0x0ea8  PcaSvc - ok
23:15:36.0424 0x0ea8  [ 673E55C3498EB970088E812EA820AA8F ] pci            C:\windows\system32\drivers\pci.sys
23:15:36.0430 0x0ea8  pci - ok
23:15:36.0458 0x0ea8  [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide          C:\windows\system32\drivers\pciide.sys
23:15:36.0461 0x0ea8  pciide - ok
23:15:36.0498 0x0ea8  [ F396431B31693E71E8A80687EF523506 ] pcmcia          C:\windows\system32\DRIVERS\pcmcia.sys
23:15:36.0504 0x0ea8  pcmcia - ok
23:15:36.0519 0x0ea8  [ 250F6B43D2B613172035C6747AEEB19F ] pcw            C:\windows\system32\drivers\pcw.sys
23:15:36.0524 0x0ea8  pcw - ok
23:15:36.0570 0x0ea8  [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH          C:\windows\system32\drivers\peauth.sys
23:15:36.0587 0x0ea8  PEAUTH - ok
23:15:36.0698 0x0ea8  [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla            C:\windows\system32\pla.dll
23:15:36.0759 0x0ea8  pla - ok
23:15:36.0808 0x0ea8  [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay        C:\windows\system32\umpnpmgr.dll
23:15:36.0827 0x0ea8  PlugPlay - ok
23:15:36.0874 0x0ea8  [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg    C:\windows\system32\pnrpauto.dll
23:15:36.0883 0x0ea8  PNRPAutoReg - ok
23:15:36.0915 0x0ea8  [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc        C:\windows\system32\pnrpsvc.dll
23:15:36.0923 0x0ea8  PNRPsvc - ok
23:15:36.0967 0x0ea8  [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent    C:\windows\System32\ipsecsvc.dll
23:15:36.0977 0x0ea8  PolicyAgent - ok
23:15:37.0026 0x0ea8  [ F87D30E72E03D579A5199CCB3831D6EA ] Power          C:\windows\system32\umpo.dll
23:15:37.0036 0x0ea8  Power - ok
23:15:37.0081 0x0ea8  [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport    C:\windows\system32\DRIVERS\raspptp.sys
23:15:37.0086 0x0ea8  PptpMiniport - ok
23:15:37.0113 0x0ea8  [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor      C:\windows\system32\DRIVERS\processr.sys
23:15:37.0117 0x0ea8  Processor - ok
23:15:37.0158 0x0ea8  [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc        C:\windows\system32\profsvc.dll
23:15:37.0168 0x0ea8  ProfSvc - ok
23:15:37.0188 0x0ea8  [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\windows\system32\lsass.exe
23:15:37.0193 0x0ea8  ProtectedStorage - ok
23:15:37.0214 0x0ea8  [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched          C:\windows\system32\DRIVERS\pacer.sys
23:15:37.0217 0x0ea8  Psched - ok
23:15:37.0295 0x0ea8  [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300          C:\windows\system32\DRIVERS\ql2300.sys
23:15:37.0357 0x0ea8  ql2300 - ok
23:15:37.0401 0x0ea8  [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx          C:\windows\system32\DRIVERS\ql40xx.sys
23:15:37.0407 0x0ea8  ql40xx - ok
23:15:37.0460 0x0ea8  [ 31AC809E7707EB580B2BDB760390765A ] QWAVE          C:\windows\system32\qwave.dll
23:15:37.0472 0x0ea8  QWAVE - ok
23:15:37.0498 0x0ea8  [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv        C:\windows\system32\drivers\qwavedrv.sys
23:15:37.0499 0x0ea8  QWAVEdrv - ok
23:15:37.0530 0x0ea8  [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd          C:\windows\system32\DRIVERS\rasacd.sys
23:15:37.0533 0x0ea8  RasAcd - ok
23:15:37.0554 0x0ea8  [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn    C:\windows\system32\DRIVERS\AgileVpn.sys
23:15:37.0557 0x0ea8  RasAgileVpn - ok
23:15:37.0585 0x0ea8  [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto        C:\windows\System32\rasauto.dll
23:15:37.0595 0x0ea8  RasAuto - ok
23:15:37.0623 0x0ea8  [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp        C:\windows\system32\DRIVERS\rasl2tp.sys
23:15:37.0628 0x0ea8  Rasl2tp - ok
23:15:37.0668 0x0ea8  [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan          C:\windows\System32\rasmans.dll
23:15:37.0680 0x0ea8  RasMan - ok
23:15:37.0696 0x0ea8  [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe        C:\windows\system32\DRIVERS\raspppoe.sys
23:15:37.0701 0x0ea8  RasPppoe - ok
23:15:37.0717 0x0ea8  [ 44101F495A83EA6401D886E7FD70096B ] RasSstp        C:\windows\system32\DRIVERS\rassstp.sys
23:15:37.0723 0x0ea8  RasSstp - ok
23:15:37.0749 0x0ea8  [ D528BC58A489409BA40334EBF96A311B ] rdbss          C:\windows\system32\DRIVERS\rdbss.sys
23:15:37.0757 0x0ea8  rdbss - ok
23:15:37.0780 0x0ea8  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus          C:\windows\system32\DRIVERS\rdpbus.sys
23:15:37.0785 0x0ea8  rdpbus - ok
23:15:37.0812 0x0ea8  [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD          C:\windows\system32\DRIVERS\RDPCDD.sys
23:15:37.0813 0x0ea8  RDPCDD - ok
23:15:37.0843 0x0ea8  [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD        C:\windows\system32\drivers\rdpencdd.sys
23:15:37.0844 0x0ea8  RDPENCDD - ok
23:15:37.0870 0x0ea8  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP        C:\windows\system32\drivers\rdprefmp.sys
23:15:37.0872 0x0ea8  RDPREFMP - ok
23:15:37.0918 0x0ea8  [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD          C:\windows\system32\drivers\RDPWD.sys
23:15:37.0925 0x0ea8  RDPWD - ok
23:15:37.0957 0x0ea8  [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost        C:\windows\system32\drivers\rdyboost.sys
23:15:37.0965 0x0ea8  rdyboost - ok
23:15:38.0011 0x0ea8  [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess    C:\windows\System32\mprdim.dll
23:15:38.0019 0x0ea8  RemoteAccess - ok
23:15:38.0060 0x0ea8  [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry  C:\windows\system32\regsvc.dll
23:15:38.0070 0x0ea8  RemoteRegistry - ok
23:15:38.0100 0x0ea8  [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM          C:\windows\system32\DRIVERS\rfcomm.sys
23:15:38.0106 0x0ea8  RFCOMM - ok
23:15:38.0131 0x0ea8  [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper    C:\windows\System32\RpcEpMap.dll
23:15:38.0140 0x0ea8  RpcEptMapper - ok
23:15:38.0178 0x0ea8  [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator      C:\windows\system32\locator.exe
23:15:38.0186 0x0ea8  RpcLocator - ok
23:15:38.0221 0x0ea8  [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs          C:\windows\system32\rpcss.dll
23:15:38.0232 0x0ea8  RpcSs - ok
23:15:38.0267 0x0ea8  [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr          C:\windows\system32\DRIVERS\rspndr.sys
23:15:38.0272 0x0ea8  rspndr - ok
23:15:38.0307 0x0ea8  [ 7DFD48E24479B68B258D8770121155A0 ] RTL8167        C:\windows\system32\DRIVERS\Rt86win7.sys
23:15:38.0313 0x0ea8  RTL8167 - ok
23:15:38.0350 0x0ea8  [ 6E5FBB7CBAEC47038B945D5E9B144A64 ] SABI            C:\windows\system32\Drivers\SABI.sys
23:15:38.0354 0x0ea8  SABI - ok
23:15:38.0377 0x0ea8  [ 81951F51E318AECC2D68559E47485CC4 ] SamSs          C:\windows\system32\lsass.exe
23:15:38.0381 0x0ea8  SamSs - ok
23:15:38.0404 0x0ea8  [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port        C:\windows\system32\drivers\sbp2port.sys
23:15:38.0408 0x0ea8  sbp2port - ok
23:15:38.0458 0x0ea8  [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr        C:\windows\System32\SCardSvr.dll
23:15:38.0469 0x0ea8  SCardSvr - ok
23:15:38.0508 0x0ea8  [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter        C:\windows\system32\DRIVERS\scfilter.sys
23:15:38.0512 0x0ea8  scfilter - ok
23:15:38.0565 0x0ea8  [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule        C:\windows\system32\schedsvc.dll
23:15:38.0599 0x0ea8  Schedule - ok
23:15:38.0627 0x0ea8  [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc    C:\windows\System32\certprop.dll
23:15:38.0630 0x0ea8  SCPolicySvc - ok
23:15:38.0671 0x0ea8  [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC          C:\windows\System32\SDRSVC.dll
23:15:38.0681 0x0ea8  SDRSVC - ok
23:15:38.0724 0x0ea8  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\windows\system32\drivers\secdrv.sys
23:15:38.0728 0x0ea8  secdrv - ok
23:15:38.0778 0x0ea8  [ A59B3A4442C52060CC7A85293AA3546F ] seclogon        C:\windows\system32\seclogon.dll
23:15:38.0790 0x0ea8  seclogon - ok
23:15:38.0816 0x0ea8  [ DCB7FCDCC97F87360F75D77425B81737 ] SENS            C:\windows\system32\sens.dll
23:15:38.0825 0x0ea8  SENS - ok
23:15:38.0846 0x0ea8  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum        C:\windows\system32\DRIVERS\serenum.sys
23:15:38.0849 0x0ea8  Serenum - ok
23:15:38.0866 0x0ea8  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial          C:\windows\system32\DRIVERS\serial.sys
23:15:38.0872 0x0ea8  Serial - ok
23:15:38.0894 0x0ea8  [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse        C:\windows\system32\DRIVERS\sermouse.sys
23:15:38.0897 0x0ea8  sermouse - ok
23:15:38.0964 0x0ea8  [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv      C:\windows\system32\sessenv.dll
23:15:38.0975 0x0ea8  SessionEnv - ok
23:15:39.0019 0x0ea8  [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk        C:\windows\system32\drivers\sffdisk.sys
23:15:39.0023 0x0ea8  sffdisk - ok
23:15:39.0053 0x0ea8  [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc        C:\windows\system32\drivers\sffp_mmc.sys
23:15:39.0056 0x0ea8  sffp_mmc - ok
23:15:39.0077 0x0ea8  [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd        C:\windows\system32\drivers\sffp_sd.sys
23:15:39.0080 0x0ea8  sffp_sd - ok
23:15:39.0118 0x0ea8  [ DB96666CC8312EBC45032F30B007A547 ] sfloppy        C:\windows\system32\DRIVERS\sfloppy.sys
23:15:39.0122 0x0ea8  sfloppy - ok
23:15:39.0169 0x0ea8  [ D9B734638DD8DBA9D59AAD3189CD0FAD ] Sftfs          C:\windows\system32\DRIVERS\Sftfslh.sys
23:15:39.0187 0x0ea8  Sftfs - ok
23:15:39.0243 0x0ea8  [ CB73BC422C07FB611F194DA18D1E7F36 ] sftlist        C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
23:15:39.0254 0x0ea8  sftlist - ok
23:15:39.0286 0x0ea8  [ 2F61BD46C0BFF4EB36E1E359CA17BFC5 ] Sftplay        C:\windows\system32\DRIVERS\Sftplaylh.sys
23:15:39.0293 0x0ea8  Sftplay - ok
23:15:39.0333 0x0ea8  [ 518BAC0179F94304F422696B47C0EC12 ] Sftredir        C:\windows\system32\DRIVERS\Sftredirlh.sys
23:15:39.0337 0x0ea8  Sftredir - ok
23:15:39.0360 0x0ea8  [ 747325236D88B3F05FFD27FF9EC711C5 ] Sftvol          C:\windows\system32\DRIVERS\Sftvollh.sys
23:15:39.0363 0x0ea8  Sftvol - ok
23:15:39.0390 0x0ea8  [ A5812F0281CA5081BF696626F9BF324D ] sftvsa          C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
23:15:39.0396 0x0ea8  sftvsa - ok
23:15:39.0456 0x0ea8  [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess    C:\windows\System32\ipnathlp.dll
23:15:39.0467 0x0ea8  SharedAccess - ok
23:15:39.0518 0x0ea8  [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\windows\System32\shsvcs.dll
23:15:39.0531 0x0ea8  ShellHWDetection - ok
23:15:39.0569 0x0ea8  [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp          C:\windows\system32\drivers\sisagp.sys
23:15:39.0574 0x0ea8  sisagp - ok
23:15:39.0608 0x0ea8  [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2        C:\windows\system32\DRIVERS\SiSRaid2.sys
23:15:39.0612 0x0ea8  SiSRaid2 - ok
23:15:39.0644 0x0ea8  [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4        C:\windows\system32\DRIVERS\sisraid4.sys
23:15:39.0649 0x0ea8  SiSRaid4 - ok
23:15:39.0680 0x0ea8  [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb            C:\windows\system32\DRIVERS\smb.sys
23:15:39.0687 0x0ea8  Smb - ok
23:15:39.0735 0x0ea8  [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP        C:\windows\System32\snmptrap.exe
23:15:39.0744 0x0ea8  SNMPTRAP - ok
23:15:39.0767 0x0ea8  [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr          C:\windows\system32\drivers\spldr.sys
23:15:39.0771 0x0ea8  spldr - ok
23:15:39.0820 0x0ea8  [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler        C:\windows\System32\spoolsv.exe
23:15:39.0833 0x0ea8  Spooler - ok
23:15:39.0964 0x0ea8  [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc          C:\windows\system32\sppsvc.exe
23:15:40.0057 0x0ea8  sppsvc - ok
23:15:40.0110 0x0ea8  [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify    C:\windows\system32\sppuinotify.dll
23:15:40.0120 0x0ea8  sppuinotify - ok
23:15:40.0255 0x0ea8  [ BE5C0E39BE31233770C92BD54492F856 ] SProtection    C:\Program Files\Common Files\Umbrella\umbrella.exe
23:15:40.0346 0x0ea8  SProtection - ok
23:15:40.0395 0x0ea8  [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv            C:\windows\system32\DRIVERS\srv.sys
23:15:40.0404 0x0ea8  srv - ok
23:15:40.0425 0x0ea8  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2            C:\windows\system32\DRIVERS\srv2.sys
23:15:40.0433 0x0ea8  srv2 - ok
23:15:40.0450 0x0ea8  [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet          C:\windows\system32\DRIVERS\srvnet.sys
23:15:40.0456 0x0ea8  srvnet - ok
23:15:40.0518 0x0ea8  [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV        C:\windows\System32\ssdpsrv.dll
23:15:40.0528 0x0ea8  SSDPSRV - ok
23:15:40.0554 0x0ea8  [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc        C:\windows\system32\sstpsvc.dll
23:15:40.0563 0x0ea8  SstpSvc - ok
23:15:40.0595 0x0ea8  [ DB32D325C192B801DF274BFD12A7E72B ] stexstor        C:\windows\system32\DRIVERS\stexstor.sys
23:15:40.0599 0x0ea8  stexstor - ok
23:15:40.0643 0x0ea8  [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc          C:\windows\System32\wiaservc.dll
23:15:40.0699 0x0ea8  StiSvc - ok
23:15:40.0738 0x0ea8  [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum          C:\windows\system32\drivers\swenum.sys
23:15:40.0742 0x0ea8  swenum - ok
23:15:40.0786 0x0ea8  [ A28BD92DF340E57B024BA433165D34D7 ] swprv          C:\windows\System32\swprv.dll
23:15:40.0799 0x0ea8  swprv - ok
23:15:40.0871 0x0ea8  [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain        C:\windows\system32\sysmain.dll
23:15:40.0925 0x0ea8  SysMain - ok
23:15:40.0977 0x0ea8  [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\windows\System32\TabSvc.dll
23:15:40.0988 0x0ea8  TabletInputService - ok
23:15:41.0034 0x0ea8  [ 613BF4820361543956909043A265C6AC ] TapiSrv        C:\windows\System32\tapisrv.dll
23:15:41.0046 0x0ea8  TapiSrv - ok
23:15:41.0090 0x0ea8  [ B799D9FDB26111737F58288D8DC172D9 ] TBS            C:\windows\System32\tbssvc.dll
23:15:41.0100 0x0ea8  TBS - ok
23:15:41.0170 0x0ea8  [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] Tcpip          C:\windows\system32\drivers\tcpip.sys
23:15:41.0234 0x0ea8  Tcpip - ok
23:15:41.0282 0x0ea8  [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] TCPIP6          C:\windows\system32\DRIVERS\tcpip.sys
23:15:41.0297 0x0ea8  TCPIP6 - ok
23:15:41.0342 0x0ea8  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg        C:\windows\system32\drivers\tcpipreg.sys
23:15:41.0346 0x0ea8  tcpipreg - ok
23:15:41.0387 0x0ea8  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE          C:\windows\system32\drivers\tdpipe.sys
23:15:41.0391 0x0ea8  TDPIPE - ok
23:15:41.0435 0x0ea8  [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP          C:\windows\system32\drivers\tdtcp.sys
23:15:41.0439 0x0ea8  TDTCP - ok
23:15:41.0473 0x0ea8  [ B459575348C20E8121D6039DA063C704 ] tdx            C:\windows\system32\DRIVERS\tdx.sys
23:15:41.0478 0x0ea8  tdx - ok
23:15:41.0492 0x0ea8  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD          C:\windows\system32\drivers\termdd.sys
23:15:41.0498 0x0ea8  TermDD - ok
23:15:41.0547 0x0ea8  [ 382C804C92811BE57829D8E550A900E2 ] TermService    C:\windows\System32\termsrv.dll
23:15:41.0579 0x0ea8  TermService - ok
23:15:41.0616 0x0ea8  [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes          C:\windows\system32\themeservice.dll
23:15:41.0626 0x0ea8  Themes - ok
23:15:41.0645 0x0ea8  [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER    C:\windows\system32\mmcss.dll
23:15:41.0650 0x0ea8  THREADORDER - ok
23:15:41.0680 0x0ea8  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks          C:\windows\System32\trkwks.dll
23:15:41.0690 0x0ea8  TrkWks - ok
23:15:41.0759 0x0ea8  [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
23:15:41.0768 0x0ea8  TrustedInstaller - ok
23:15:41.0816 0x0ea8  [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv        C:\windows\system32\DRIVERS\tssecsrv.sys
23:15:41.0821 0x0ea8  tssecsrv - ok
23:15:41.0855 0x0ea8  [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt        C:\windows\system32\drivers\tsusbflt.sys
23:15:41.0859 0x0ea8  TsUsbFlt - ok
23:15:41.0905 0x0ea8  [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel          C:\windows\system32\DRIVERS\tunnel.sys
23:15:41.0910 0x0ea8  tunnel - ok
23:15:41.0943 0x0ea8  [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35          C:\windows\system32\DRIVERS\uagp35.sys
23:15:41.0947 0x0ea8  uagp35 - ok
23:15:41.0996 0x0ea8  [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs            C:\windows\system32\DRIVERS\udfs.sys
23:15:42.0004 0x0ea8  udfs - ok
23:15:42.0059 0x0ea8  [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect      C:\windows\system32\UI0Detect.exe
23:15:42.0069 0x0ea8  UI0Detect - ok
23:15:42.0106 0x0ea8  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx        C:\windows\system32\drivers\uliagpkx.sys
23:15:42.0111 0x0ea8  uliagpkx - ok
23:15:42.0151 0x0ea8  [ D295BED4B898F0FD999FCFA9B32B071B ] umbus          C:\windows\system32\drivers\umbus.sys
23:15:42.0155 0x0ea8  umbus - ok
23:15:42.0186 0x0ea8  [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass          C:\windows\system32\DRIVERS\umpass.sys
23:15:42.0190 0x0ea8  UmPass - ok
23:15:42.0220 0x0ea8  [ 833FBB672460EFCE8011D262175FAD33 ] upnphost        C:\windows\System32\upnphost.dll
23:15:42.0232 0x0ea8  upnphost - ok
23:15:42.0260 0x0ea8  [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp        C:\windows\system32\DRIVERS\usbccgp.sys
23:15:42.0266 0x0ea8  usbccgp - ok
23:15:42.0310 0x0ea8  [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir          C:\windows\system32\drivers\usbcir.sys
23:15:42.0316 0x0ea8  usbcir - ok
23:15:42.0346 0x0ea8  [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci        C:\windows\system32\drivers\usbehci.sys
23:15:42.0351 0x0ea8  usbehci - ok
23:15:42.0378 0x0ea8  [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub          C:\windows\system32\DRIVERS\usbhub.sys
23:15:42.0386 0x0ea8  usbhub - ok
23:15:42.0412 0x0ea8  [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci        C:\windows\system32\drivers\usbohci.sys
23:15:42.0416 0x0ea8  usbohci - ok
23:15:42.0442 0x0ea8  [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint        C:\windows\system32\DRIVERS\usbprint.sys
23:15:42.0447 0x0ea8  usbprint - ok
23:15:42.0472 0x0ea8  [ F991AB9CC6B908DB552166768176896A ] USBSTOR        C:\windows\system32\DRIVERS\USBSTOR.SYS
23:15:42.0477 0x0ea8  USBSTOR - ok
23:15:42.0498 0x0ea8  [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci        C:\windows\system32\drivers\usbuhci.sys
23:15:42.0504 0x0ea8  usbuhci - ok
23:15:42.0551 0x0ea8  [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo        C:\windows\System32\Drivers\usbvideo.sys
23:15:42.0558 0x0ea8  usbvideo - ok
23:15:42.0605 0x0ea8  [ AF77716205C97E902E6C5B78DECE2CCA ] usb_rndisx      C:\windows\system32\drivers\usb8023x.sys
23:15:42.0609 0x0ea8  usb_rndisx - ok
23:15:42.0653 0x0ea8  [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms          C:\windows\System32\uxsms.dll
23:15:42.0662 0x0ea8  UxSms - ok
23:15:42.0688 0x0ea8  [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc        C:\windows\system32\lsass.exe
23:15:42.0693 0x0ea8  VaultSvc - ok
23:15:42.0741 0x0ea8  [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot        C:\windows\system32\drivers\vdrvroot.sys
23:15:42.0747 0x0ea8  vdrvroot - ok
23:15:42.0796 0x0ea8  [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds            C:\windows\System32\vds.exe
23:15:42.0831 0x0ea8  vds - ok
23:15:42.0866 0x0ea8  [ 17C408214EA61696CEC9C66E388B14F3 ] vga            C:\windows\system32\DRIVERS\vgapnp.sys
23:15:42.0870 0x0ea8  vga - ok
23:15:42.0901 0x0ea8  [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave        C:\windows\System32\drivers\vga.sys
23:15:42.0906 0x0ea8  VgaSave - ok
23:15:42.0942 0x0ea8  [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp          C:\windows\system32\drivers\vhdmp.sys
23:15:42.0948 0x0ea8  vhdmp - ok
23:15:42.0988 0x0ea8  [ C829317A37B4BEA8F39735D4B076E923 ] viaagp          C:\windows\system32\drivers\viaagp.sys
23:15:42.0993 0x0ea8  viaagp - ok
23:15:43.0023 0x0ea8  [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7          C:\windows\system32\DRIVERS\viac7.sys
23:15:43.0028 0x0ea8  ViaC7 - ok
23:15:43.0057 0x0ea8  [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide          C:\windows\system32\drivers\viaide.sys
23:15:43.0061 0x0ea8  viaide - ok
23:15:43.0097 0x0ea8  [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr          C:\windows\system32\drivers\volmgr.sys
23:15:43.0102 0x0ea8  volmgr - ok
23:15:43.0124 0x0ea8  [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx        C:\windows\system32\drivers\volmgrx.sys
23:15:43.0130 0x0ea8  volmgrx - ok
23:15:43.0150 0x0ea8  [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap        C:\windows\system32\drivers\volsnap.sys
23:15:43.0157 0x0ea8  volsnap - ok
23:15:43.0192 0x0ea8  [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid        C:\windows\system32\DRIVERS\vsmraid.sys
23:15:43.0198 0x0ea8  vsmraid - ok
23:15:43.0266 0x0ea8  [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS            C:\windows\system32\vssvc.exe
23:15:43.0311 0x0ea8  VSS - ok
23:15:43.0371 0x0ea8  [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus        C:\windows\system32\DRIVERS\vwifibus.sys
23:15:43.0375 0x0ea8  vwifibus - ok
23:15:43.0414 0x0ea8  [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt        C:\windows\system32\DRIVERS\vwififlt.sys
23:15:43.0418 0x0ea8  vwififlt - ok
23:15:43.0442 0x0ea8  [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp        C:\windows\system32\DRIVERS\vwifimp.sys
23:15:43.0446 0x0ea8  vwifimp - ok
23:15:43.0488 0x0ea8  [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time        C:\windows\system32\w32time.dll
23:15:43.0508 0x0ea8  W32Time - ok
23:15:43.0537 0x0ea8  [ DE3721E89C653AA281428C8A69745D90 ] WacomPen        C:\windows\system32\DRIVERS\wacompen.sys
23:15:43.0542 0x0ea8  WacomPen - ok
23:15:43.0570 0x0ea8  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP          C:\windows\system32\DRIVERS\wanarp.sys
23:15:43.0575 0x0ea8  WANARP - ok
23:15:43.0595 0x0ea8  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6        C:\windows\system32\DRIVERS\wanarp.sys
23:15:43.0598 0x0ea8  Wanarpv6 - ok
23:15:43.0652 0x0ea8  [ 691E3285E53DCA558E1A84667F13E15A ] wbengine        C:\windows\system32\wbengine.exe
23:15:43.0697 0x0ea8  wbengine - ok
23:15:43.0744 0x0ea8  [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc        C:\windows\System32\wbiosrvc.dll
23:15:43.0757 0x0ea8  WbioSrvc - ok
23:15:43.0815 0x0ea8  [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc        C:\windows\System32\wcncsvc.dll
23:15:43.0834 0x0ea8  wcncsvc - ok
23:15:43.0862 0x0ea8  [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
23:15:43.0872 0x0ea8  WcsPlugInService - ok
23:15:43.0906 0x0ea8  [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd              C:\windows\system32\DRIVERS\wd.sys
23:15:43.0910 0x0ea8  Wd - ok
23:15:43.0952 0x0ea8  [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000        C:\windows\system32\drivers\Wdf01000.sys
23:15:43.0968 0x0ea8  Wdf01000 - ok
23:15:43.0994 0x0ea8  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost  C:\windows\system32\wdi.dll
23:15:44.0004 0x0ea8  WdiServiceHost - ok
23:15:44.0027 0x0ea8  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost  C:\windows\system32\wdi.dll
23:15:44.0042 0x0ea8  WdiSystemHost - ok
23:15:44.0086 0x0ea8  [ A9D880F97530D5B8FEE278923349929D ] WebClient      C:\windows\System32\webclnt.dll
23:15:44.0098 0x0ea8  WebClient - ok
23:15:44.0137 0x0ea8  [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc          C:\windows\system32\wecsvc.dll
23:15:44.0149 0x0ea8  Wecsvc - ok
23:15:44.0176 0x0ea8  [ AC804569BB2364FB6017370258A4091B ] wercplsupport  C:\windows\System32\wercplsupport.dll
23:15:44.0186 0x0ea8  wercplsupport - ok
23:15:44.0209 0x0ea8  [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc          C:\windows\System32\WerSvc.dll
23:15:44.0219 0x0ea8  WerSvc - ok
23:15:44.0256 0x0ea8  [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf          C:\windows\system32\DRIVERS\wfplwf.sys
23:15:44.0260 0x0ea8  WfpLwf - ok
23:15:44.0292 0x0ea8  [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount        C:\windows\system32\drivers\wimmount.sys
23:15:44.0297 0x0ea8  WIMMount - ok
23:15:44.0385 0x0ea8  [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
23:15:44.0417 0x0ea8  WinDefend - ok
23:15:44.0438 0x0ea8  WinHttpAutoProxySvc - ok
23:15:44.0523 0x0ea8  [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt        C:\windows\system32\wbem\WMIsvc.dll
23:15:44.0530 0x0ea8  Winmgmt - ok
23:15:44.0598 0x0ea8  [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM          C:\windows\system32\WsmSvc.dll
23:15:44.0643 0x0ea8  WinRM - ok
23:15:44.0701 0x0ea8  [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb          C:\windows\system32\DRIVERS\WinUsb.sys
23:15:44.0705 0x0ea8  WinUsb - ok
23:15:44.0762 0x0ea8  [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc        C:\windows\System32\wlansvc.dll
23:15:44.0795 0x0ea8  Wlansvc - ok
23:15:44.0901 0x0ea8  [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
23:15:44.0958 0x0ea8  wlidsvc - ok
23:15:45.0004 0x0ea8  [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi        C:\windows\system32\drivers\wmiacpi.sys
23:15:45.0007 0x0ea8  WmiAcpi - ok
23:15:45.0057 0x0ea8  [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv        C:\windows\system32\wbem\WmiApSrv.exe
23:15:45.0065 0x0ea8  wmiApSrv - ok
23:15:45.0159 0x0ea8  [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
23:15:45.0198 0x0ea8  WMPNetworkSvc - ok
23:15:45.0232 0x0ea8  [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc          C:\windows\System32\wpcsvc.dll
23:15:45.0243 0x0ea8  WPCSvc - ok
23:15:45.0283 0x0ea8  [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum      C:\windows\system32\wpdbusenum.dll
23:15:45.0295 0x0ea8  WPDBusEnum - ok
23:15:45.0348 0x0ea8  [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl        C:\windows\system32\drivers\ws2ifsl.sys
23:15:45.0349 0x0ea8  ws2ifsl - ok
23:15:45.0376 0x0ea8  [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc          C:\windows\system32\wscsvc.dll
23:15:45.0386 0x0ea8  wscsvc - ok
23:15:45.0398 0x0ea8  WSearch - ok
23:15:45.0501 0x0ea8  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\windows\system32\wuaueng.dll
23:15:45.0557 0x0ea8  wuauserv - ok
23:15:45.0597 0x0ea8  [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf          C:\windows\system32\drivers\WudfPf.sys
23:15:45.0602 0x0ea8  WudfPf - ok
23:15:45.0627 0x0ea8  [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd          C:\windows\system32\DRIVERS\WUDFRd.sys
23:15:45.0633 0x0ea8  WUDFRd - ok
23:15:45.0661 0x0ea8  [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc        C:\windows\System32\WUDFSvc.dll
23:15:45.0671 0x0ea8  wudfsvc - ok
23:15:45.0741 0x0ea8  [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc        C:\windows\System32\wwansvc.dll
23:15:45.0775 0x0ea8  WwanSvc - ok
23:15:45.0839 0x0ea8  [ B07C5B7EFDF936FF93D4F540938725BE ] yukonw7        C:\windows\system32\DRIVERS\yk62x86.sys
23:15:45.0847 0x0ea8  yukonw7 - ok
23:15:45.0860 0x0ea8  ZTEusbmdm6k - ok
23:15:45.0878 0x0ea8  ZTEusbnmea - ok
23:15:45.0895 0x0ea8  ZTEusbser6k - ok
23:15:45.0956 0x0ea8  ================ Scan global ===============================
23:15:46.0014 0x0ea8  [ DAB748AE0439955ED2FA22357533DDDB ] C:\windows\system32\basesrv.dll
23:15:46.0046 0x0ea8  [ 1F5F07091D50244F17DD8D5147A628CC ] C:\windows\system32\winsrv.dll
23:15:46.0080 0x0ea8  [ 1F5F07091D50244F17DD8D5147A628CC ] C:\windows\system32\winsrv.dll
23:15:46.0129 0x0ea8  [ 364455805E64882844EE9ACB72522830 ] C:\windows\system32\sxssrv.dll
23:15:46.0173 0x0ea8  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\windows\system32\services.exe
23:15:46.0184 0x0ea8  [Global] - ok
23:15:46.0185 0x0ea8  ================ Scan MBR ==================================
23:15:46.0201 0x0ea8  [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk0\DR0
23:15:47.0189 0x0ea8  \Device\Harddisk0\DR0 - ok
23:15:47.0191 0x0ea8  ================ Scan VBR ==================================
23:15:47.0203 0x0ea8  [ EBE7021849C58A9AEC766C3853048523 ] \Device\Harddisk0\DR0\Partition1
23:15:47.0210 0x0ea8  \Device\Harddisk0\DR0\Partition1 - ok
23:15:47.0229 0x0ea8  [ D7E7F6AF8F42ADA0FE917521BCFEB30E ] \Device\Harddisk0\DR0\Partition2
23:15:47.0235 0x0ea8  \Device\Harddisk0\DR0\Partition2 - ok
23:15:47.0261 0x0ea8  [ 160E334ECD7686A73F8FE08EF04AE405 ] \Device\Harddisk0\DR0\Partition3
23:15:47.0267 0x0ea8  \Device\Harddisk0\DR0\Partition3 - ok
23:15:47.0268 0x0ea8  ============================================================
23:15:47.0268 0x0ea8  Scan finished
23:15:47.0268 0x0ea8  ============================================================
23:15:47.0299 0x1184  Detected object count: 0
23:15:47.0299 0x1184  Actual detected object count: 0



Alle Zeitangaben in WEZ +1. Es ist jetzt 12:25 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131