konnigito | 20.09.2014 17:06 | Zitat:
Zitat von M-K-D-B
(Beitrag 1362371)
Ja, kannst du machen. | Nein, war nicht sicher. Das booten wird abgebrochen und neugestartet, wieder abgebrochen und neugestartet...
Den Scan habe ich jetzt aus dem abgesicherten Modus heraus gemacht
6cb4f0b1c715c25e plus ein paar unsigned asus treiber Code:
17:54:00.0703 0x0418 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
17:54:04.0546 0x0418 ============================================================
17:54:04.0546 0x0418 Current date / time: 2014/09/20 17:54:04.0546
17:54:04.0546 0x0418 SystemInfo:
17:54:04.0546 0x0418
17:54:04.0546 0x0418 OS Version: 5.1.2600 ServicePack: 3.0
17:54:04.0546 0x0418 Product type: Workstation
17:54:04.0546 0x0418 ComputerName: EEE-PC
17:54:04.0546 0x0418 UserName: Administrator
17:54:04.0546 0x0418 Windows directory: C:\WINDOWS
17:54:04.0546 0x0418 System windows directory: C:\WINDOWS
17:54:04.0546 0x0418 Processor architecture: Intel x86
17:54:04.0546 0x0418 Number of processors: 2
17:54:04.0546 0x0418 Page size: 0x1000
17:54:04.0546 0x0418 Boot type: Safe boot
17:54:04.0546 0x0418 ============================================================
17:54:04.0546 0x0418 BG loaded
17:54:06.0250 0x0418 System UUID: {86D107B0-7E38-3615-BAD1-DDFD9EE692D5}
17:54:10.0546 0x0418 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000044
17:54:10.0546 0x0418 ============================================================
17:54:10.0546 0x0418 \Device\Harddisk0\DR0:
17:54:10.0546 0x0418 MBR partitions:
17:54:10.0546 0x0418 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1
17:54:10.0546 0x0418 ============================================================
17:54:10.0593 0x0418 C: <-> \Device\Harddisk0\DR0\Partition1
17:54:10.0593 0x0418 ============================================================
17:54:10.0593 0x0418 Initialize success
17:54:10.0593 0x0418 ============================================================
17:54:46.0453 0x0438 ============================================================
17:54:46.0453 0x0438 Scan started
17:54:46.0453 0x0438 Mode: Manual; SigCheck; TDLFS;
17:54:46.0453 0x0438 ============================================================
17:54:46.0453 0x0438 KSN ping started
17:54:47.0390 0x0438 KSN ping finished: false
17:54:52.0890 0x0438 ================ Scan system memory ========================
17:54:52.0890 0x0438 System memory - ok
17:54:52.0890 0x0438 ================ Scan services =============================
17:54:52.0953 0x0438 Suspicious service (NoAccess): 6cb4f0b1c715c25e
17:54:53.0484 0x0438 [ 5A553543948F966FF1E5E8D5300F4BFB, 1A5C2E2DEAAE8DDBF051970A27707B12286A425A142F08F071A03DEBE3F54D21 ] 6cb4f0b1c715c25e C:\WINDOWS\System32\Drivers\6cb4f0b1c715c25e.sys
17:54:53.0484 0x0438 Suspicious file ( NoAccess ): C:\WINDOWS\System32\Drivers\6cb4f0b1c715c25e.sys. md5: 5A553543948F966FF1E5E8D5300F4BFB, sha256: 1A5C2E2DEAAE8DDBF051970A27707B12286A425A142F08F071A03DEBE3F54D21
17:54:55.0734 0x0438 6cb4f0b1c715c25e - detected Rootkit.Win32.Necurs.gen ( 0 )
17:54:56.0390 0x0438 6cb4f0b1c715c25e ( Rootkit.Win32.Necurs.gen ) - infected
17:54:56.0390 0x0438 Force sending object to P2P due to detect: 6cb4f0b1c715c25e
17:54:56.0406 0x0438 Object send P2P result: false
17:54:56.0421 0x0438 Abiosdsk - ok
17:54:56.0453 0x0438 abp480n5 - ok
17:54:56.0671 0x0438 [ AC407F1A62C3A300B4F2B5A9F1D55B2C, 31F5FC61B37E22100B3A52A590295A7E827FFC581FA9960C64B9032452AAECED ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:55:02.0500 0x0438 ACPI - ok
17:55:02.0562 0x0438 [ 9E1CA3160DAFB159CA14F83B1E317F75, 13B3E897B0E819BF734449416D9EC6EBCAC89538EC69BF48C068593B82D57004 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
17:55:02.0843 0x0438 ACPIEC - ok
17:55:02.0859 0x0438 adpu160m - ok
17:55:03.0031 0x0438 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
17:55:03.0437 0x0438 aec - ok
17:55:03.0578 0x0438 [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
17:55:03.0796 0x0438 AFD - ok
17:55:03.0812 0x0438 Aha154x - ok
17:55:03.0843 0x0438 aic78u2 - ok
17:55:03.0875 0x0438 aic78xx - ok
17:55:03.0953 0x0438 [ 738D80CC01D7BC7584BE917B7F544394, DCC17AAEF5CDDF52FAAC3CC6904EF421CD595F66318A2370BEE261D5C3A8E340 ] Alerter C:\WINDOWS\system32\alrsvc.dll
17:55:04.0250 0x0438 Alerter - ok
17:55:04.0328 0x0438 [ 190CD73D4984F94D823F9444980513E5, 93A32C2495CCA094F768BA707C74DA5C00B8A88A9236DD1A297439A7C2E6C6FA ] ALG C:\WINDOWS\System32\alg.exe
17:55:04.0484 0x0438 ALG - ok
17:55:04.0500 0x0438 AliIde - ok
17:55:04.0531 0x0438 amsint - ok
17:55:04.0734 0x0438 [ D45960BE52C3C610D361977057F98C54, 9186589B502F46B47672CFB8EBD558D51B0F3CBFE4E0DDBA625A4265236518CE ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
17:55:05.0015 0x0438 AppMgmt - ok
17:55:05.0031 0x0438 asc - ok
17:55:05.0046 0x0438 asc3350p - ok
17:55:05.0078 0x0438 asc3550 - ok
17:55:05.0250 0x0438 aspnet_state - ok
17:55:05.0328 0x0438 [ 12415A4B61DED200FE9932B47A35FA42, EA9D32CCD98990F6F20412F919B0477D63771E631755CC593E2CD9B8D70A8E25 ] AsusACPI C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys
17:55:05.0421 0x0438 AsusACPI - ok
17:55:05.0468 0x0438 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:55:05.0765 0x0438 AsyncMac - ok
17:55:05.0890 0x0438 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
17:55:06.0156 0x0438 atapi - ok
17:55:06.0187 0x0438 Atdisk - ok
17:55:06.0296 0x0438 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:55:06.0593 0x0438 Atmarpc - ok
17:55:06.0687 0x0438 [ 58ED0D5452DF7BE732193E7999C6B9A4, 254E2ECF592DDA2E3E6CA9F6F3E77926E2265586A7937BA95199ED47BCDE69A3 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
17:55:06.0984 0x0438 AudioSrv - ok
17:55:07.0062 0x0438 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
17:55:07.0312 0x0438 audstub - ok
17:55:07.0421 0x0438 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
17:55:07.0703 0x0438 Beep - ok
17:55:08.0015 0x0438 [ D6F603772A789BB3228F310D650B8BD1, A539025C70FD998A9B8703DE05CAE5E99BC721D8852EA561EBC2DD20CB371D2E ] BITS C:\WINDOWS\system32\qmgr.dll
17:55:08.0875 0x0438 BITS - ok
17:55:09.0000 0x0438 [ F934D1B230F84E1D19DD00AC5A7A83ED, 32CD3A7A1F06DCCE2A4D9FA6E2AE7B3E2B57FA2D5F1C74EA79D72E5E0E352E60 ] Bridge C:\WINDOWS\system32\DRIVERS\bridge.sys
17:55:09.0187 0x0438 Bridge - ok
17:55:09.0312 0x0438 [ F934D1B230F84E1D19DD00AC5A7A83ED, 32CD3A7A1F06DCCE2A4D9FA6E2AE7B3E2B57FA2D5F1C74EA79D72E5E0E352E60 ] BridgeMP C:\WINDOWS\system32\DRIVERS\bridge.sys
17:55:09.0437 0x0438 BridgeMP - ok
17:55:09.0578 0x0438 [ B71549F23736ADF83A571061C47777FD, A1D0320736EE777030A543DCA086367EB5A5B6F95088B9C22D8E09326C3A39A9 ] Browser C:\WINDOWS\System32\browser.dll
17:55:09.0859 0x0438 Browser - ok
17:55:10.0296 0x0438 [ B6E16DA77EAFE84A8C5BC44784FEEAEA, 5E891966A09ACFB6DAA5E9468F8FEA9814F921FA1C15CF9F5487D730295BDA5D ] btaudio C:\WINDOWS\system32\drivers\btaudio.sys
17:55:11.0593 0x0438 btaudio - ok
17:55:11.0703 0x0438 [ 58A49BD10E08D3D4333A60DEDCB1CED8, 2110462BDD51BCEB661C089376E60E5ECE5F5908CF80A09035190529C9F306A4 ] BTDriver C:\WINDOWS\system32\DRIVERS\btport.sys
17:55:11.0812 0x0438 BTDriver - ok
17:55:12.0421 0x0438 [ EF5E0DE0A7CA2977A9255F36F4D915AB, ECF2445200CDF6379ABE0BDA0CDDC4D9FF94CC34D652AD536E34C1AEB576B710 ] BTKRNL C:\WINDOWS\system32\DRIVERS\btkrnl.sys
17:55:13.0593 0x0438 BTKRNL - ok
17:55:13.0937 0x0438 [ FAC8968CE8EFBC0E418FC978A1F174D9, EAA53AA5C5CCF4DC0A84CBADE48F7732C8682F2B374A4ADCD97766AC54AF2D14 ] btwdins C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
17:55:14.0187 0x0438 btwdins - ok
17:55:14.0312 0x0438 [ 80F61DE965C116051614AC2F04222FF7, 010201E19B96DA3937C168051205728AF47FA96C89D1553F1F67739227B086E5 ] BTWDNDIS C:\WINDOWS\system32\DRIVERS\btwdndis.sys
17:55:14.0484 0x0438 BTWDNDIS - ok
17:55:14.0562 0x0438 [ E48668B4A6A5CF68B33AECAD18EE8E1E, CC190DCED4B71FDCC113E90B4FCAC4975830C6C86C04F9CDDF2C4E9F2661AA30 ] btwhid C:\WINDOWS\system32\DRIVERS\btwhid.sys
17:55:14.0656 0x0438 btwhid - ok
17:55:14.0750 0x0438 [ 8BCD7BFE9C70A8FF7444263435B18AA1, CD260090E88D75C5F277403075FA43BA71166E9C65B9ECD3E2D767E67D92374D ] btwmodem C:\WINDOWS\system32\DRIVERS\btwmodem.sys
17:55:14.0828 0x0438 btwmodem - ok
17:55:14.0921 0x0438 [ 053DC5BE74621B63BB48C2B86BAFC7B0, 0BF9810CBB7D94DE00A2153DCF0649BC0A27CDBAF76412E61696083C54189778 ] BTWUSB C:\WINDOWS\system32\Drivers\btwusb.sys
17:55:15.0046 0x0438 BTWUSB - ok
17:55:15.0109 0x0438 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
17:55:15.0375 0x0438 cbidf2k - ok
17:55:15.0468 0x0438 [ 0BE5AEF125BE881C4F854C554F2B025C, 1770DD70B3F115A0EF460907DEDC1E4B7241C08615A98F194D61A49C3E2BAA54 ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:55:15.0812 0x0438 CCDECODE - ok
17:55:15.0828 0x0438 cd20xrnt - ok
17:55:15.0906 0x0438 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
17:55:16.0187 0x0438 Cdaudio - ok
17:55:16.0312 0x0438 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
17:55:16.0625 0x0438 Cdfs - ok
17:55:16.0750 0x0438 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:55:17.0031 0x0438 Cdrom - ok
17:55:17.0046 0x0438 Changer - ok
17:55:17.0140 0x0438 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E, ACB458E8A11AA2143734A5A0281973D95158E6402A6453F98F9832D1E19B01F9 ] CiSvc C:\WINDOWS\system32\cisvc.exe
17:55:17.0421 0x0438 CiSvc - ok
17:55:17.0531 0x0438 [ 778A30ED3C134EB7E406AFC407E9997D, 3E6AD115AB2596EB001BC21AEADDBC75F27C42DB90C986B7AD17743CE631234E ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
17:55:17.0859 0x0438 ClipSrv - ok
17:55:17.0953 0x0438 [ 0F6C187D38D98F8DF904589A5F94D411, DB987093446216CEE913AC27503BF7E23E5A62DF169B355730285DAB64F6ED28 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys
17:55:18.0218 0x0438 CmBatt - ok
17:55:18.0234 0x0438 CmdIde - ok
17:55:18.0343 0x0438 [ 6E4C9F21F0FAE8940661144F41B13203, 731202A0DD021FCF9287FEA631212603AAAC23F9E7F76B2882F913B18A971F1C ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys
17:55:18.0625 0x0438 Compbatt - ok
17:55:18.0640 0x0438 COMSysApp - ok
17:55:18.0703 0x0438 Cpqarray - ok
17:55:18.0796 0x0438 [ 611F824E5C703A5A899F84C5F1699E4D, 9EFA5612FE58E9974E4CC13D39D91D7B5DEA3ED66BEFBED3AAE6D2800FD8162A ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
17:55:19.0046 0x0438 CryptSvc - ok
17:55:19.0062 0x0438 dac2w2k - ok
17:55:19.0093 0x0438 dac960nt - ok
17:55:19.0437 0x0438 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B, ECFBACE3CBF2384948EA1C445BDA3955EB4F44A9874286E6537C67DC1283E5B0 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
17:55:19.0734 0x0438 DcomLaunch - ok
17:55:19.0906 0x0438 [ C29A1C9B75BA38FA37F8C44405DEC360, 7476D8BC4380CDE56764B2034AF3741DA4ED00F315E41C9A02B5EAD04374F241 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
17:55:20.0187 0x0438 Dhcp - ok
17:55:20.0265 0x0438 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
17:55:20.0578 0x0438 Disk - ok
17:55:20.0593 0x0438 dmadmin - ok
17:55:21.0218 0x0438 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA, 89B0AEE5BE01B9FE4FF2989FF16DB6121721ACDFCE6D9655C0ACD321D8C308BE ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
17:55:22.0390 0x0438 dmboot - ok
17:55:22.0578 0x0438 [ 53720AB12B48719D00E327DA470A619A, 800264866A6267C9000A85D00095D57908D059D737E5F28C9C4049B884C46228 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
17:55:22.0984 0x0438 dmio - ok
17:55:23.0062 0x0438 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
17:55:23.0343 0x0438 dmload - ok
17:55:23.0421 0x0438 [ 25C83FFBBA13B554EB6D59A9B2E2EE78, 9FBD655ED3E9163AE11EC207F283E387EFBA5A23108EC790BAE4846B35E66F16 ] dmserver C:\WINDOWS\System32\dmserver.dll
17:55:23.0687 0x0438 dmserver - ok
17:55:23.0796 0x0438 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
17:55:24.0109 0x0438 DMusic - ok
17:55:24.0234 0x0438 [ 407F3227AC618FD1CA54B335B083DE07, 96B8E734648FE9A4EBA59C096C8779BD1A11A93A6303AFD438A406C8122D36C6 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
17:55:24.0390 0x0438 Dnscache - ok
17:55:24.0515 0x0438 [ 676E36C4FF5BCEA1900F44182B9723E6, 740CF18BD40E00FEA26CF0E6340C5D18F7D0B4390055FAEEC258B3AA790C4AE9 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
17:55:24.0953 0x0438 Dot3svc - ok
17:55:24.0968 0x0438 dpti2o - ok
17:55:25.0046 0x0438 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
17:55:25.0296 0x0438 drmkaud - ok
17:55:25.0406 0x0438 [ 4E4F2FDDAB0A0736D7671134DCCE91FB, 8E2C57D1A006856C47CBDD5765A9DD317DB205B26DA8BFC70555A506257A1CD9 ] EapHost C:\WINDOWS\System32\eapsvc.dll
17:55:25.0718 0x0438 EapHost - ok
17:55:25.0796 0x0438 [ 877C18558D70587AA7823A1A308AC96B, 6B336A62112988D855513F45153F73F8470C41A448E9B7438B4A8EC1813AABF1 ] ERSvc C:\WINDOWS\System32\ersvc.dll
17:55:26.0109 0x0438 ERSvc - ok
17:55:26.0265 0x0438 [ A3EDBE9053889FB24AB22492472B39DC, 6F2ED6E04BDE2FCA2A8BF9BD2D1D6923DE6EAECB46F582B6C0BD1CF364D65C9E ] Eventlog C:\WINDOWS\system32\services.exe
17:55:26.0328 0x0438 Eventlog - ok
17:55:26.0562 0x0438 [ AF4F6B5739D18CA7972AB53E091CBC74, A399E2CC026730D3A429727AAB48093B9F1E5DD8EB6336519C7F16182FDB3905 ] EventSystem C:\WINDOWS\system32\es.dll
17:55:26.0703 0x0438 EventSystem - ok
17:55:26.0859 0x0438 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
17:55:27.0234 0x0438 Fastfat - ok
17:55:27.0406 0x0438 [ 2DB7D303C36DDD055215052F118E8E75, BE6E7BBE12A7A4EDF1F1C2935350603970C7426BBCA7A1A6644BB8999123AF17 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
17:55:27.0500 0x0438 FastUserSwitchingCompatibility - ok
17:55:27.0578 0x0438 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
17:55:27.0843 0x0438 Fdc - ok
17:55:27.0906 0x0438 [ B0678A548587C5F1967B0D70BACAD6C1, 7E49910212ED87313F926E4800EA8D34809C287A686CA69B82B79C1A6451F88C ] Fips C:\WINDOWS\system32\drivers\Fips.sys
17:55:28.0234 0x0438 Fips - ok
17:55:28.0312 0x0438 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
17:55:28.0578 0x0438 Flpydisk - ok
17:55:28.0750 0x0438 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
17:55:29.0140 0x0438 FltMgr - ok
17:55:29.0250 0x0438 [ 1F943241F4963CD51E5F61C93D3F45C7, 79762E040ABB6D22921150F9987F9FD999EE2CAA7D1BFB2EC6482A1BFE1F907E ] FsVga C:\WINDOWS\system32\DRIVERS\fsvga.sys
17:55:29.0500 0x0438 FsVga - ok
17:55:29.0562 0x0438 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:55:29.0859 0x0438 Fs_Rec - ok
17:55:30.0000 0x0438 [ 8F1955CE42E1484714B542F341647778, 8EB3F99625F409D3032561E8AB44BEFBFBFBA4EC873C2151C92A5CAAF7F2AA55 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:55:30.0343 0x0438 Ftdisk - ok
17:55:30.0453 0x0438 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:55:30.0765 0x0438 Gpc - ok
17:55:30.0953 0x0438 [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
17:55:31.0234 0x0438 HDAudBus - ok
17:55:31.0484 0x0438 [ 9AE4747663A6C62F6FFE0B991A0F531A, 1D92011CDD97AB6DFDB71F72FB79A6332B4F2BFDE92AAC874982E6B33F557CBE ] HDD & SSD access service C:\Programme\Gemeinsame Dateien\BinarySense\disksvc.exe
17:55:31.0640 0x0438 HDD & SSD access service - detected UnsignedFile.Multi.Generic ( 1 )
17:55:31.0640 0x0438 HDD & SSD access service ( UnsignedFile.Multi.Generic ) - warning
17:55:31.0765 0x0438 [ CB66BF85BF599BEFD6C6A57C2E20357F, 55D3A0F9279FF316766F42548FCB61C452942B08A37590C4892DF110BE4E53C6 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
17:55:32.0062 0x0438 helpsvc - ok
17:55:32.0156 0x0438 [ B35DA85E60C0103F2E4104532DA2F12B, E13C9F73DF7713554CB614B36123D75014F5121AA1FC9069733E61758751CBE4 ] HidServ C:\WINDOWS\System32\hidserv.dll
17:55:32.0453 0x0438 HidServ - ok
17:55:32.0531 0x0438 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:55:32.0796 0x0438 HidUsb - ok
17:55:32.0890 0x0438 [ ED29F14101523A6E0E808107405D452C, B8FA987637787BEECC2EB06D36293DAC355523392B49A8C5A9491EEE961917E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
17:55:33.0203 0x0438 hkmsvc - ok
17:55:33.0218 0x0438 hpn - ok
17:55:33.0500 0x0438 [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
17:55:33.0781 0x0438 HTTP - ok
17:55:33.0843 0x0438 [ 9E4ADB854CEBCFB81A4B36718FEECD16, 677AB64460775686F8366D6BF35D420A2486C3F07338A00A7C2788A5142B9F08 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
17:55:34.0140 0x0438 HTTPFilter - ok
17:55:34.0156 0x0438 i2omgmt - ok
17:55:34.0187 0x0438 i2omp - ok
17:55:34.0328 0x0438 [ E283B97CFBEB86C1D86BAED5F7846A92, 7664F791D08C80DF1E52B34BE69F073AA645610C4BD975F498254807602374AB ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:55:34.0593 0x0438 i8042prt - ok
17:55:38.0781 0x0438 [ 0F68E2EC713F132FFB19E45415B09679, B1439A5D157F9FF54E803581D2B86411DB079242D837617021A4A0BC195E67BB ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
17:55:46.0546 0x0438 ialm - ok
17:55:46.0640 0x0438 iked - ok
17:55:46.0687 0x0438 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
17:55:46.0968 0x0438 Imapi - ok
17:55:47.0125 0x0438 [ D4B413AA210C21E46AEDD2BA5B68D38E, 2309622867AA8FC832A729FA78F48742D4BD6CA0DAFBFB9DDB0772D671E1ED75 ] ImapiService C:\WINDOWS\system32\imapi.exe
17:55:47.0484 0x0438 ImapiService - ok
17:55:47.0515 0x0438 ini910u - ok
17:55:50.0734 0x0438 [ 45FFC97A47248550E799DA5EB5DCA6A1, 7AB9D6CBB3C614F23B69031D500483450F3710FBB2C7C6FF62A6F492B7810235 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
17:55:57.0000 0x0438 IntcAzAudAddService - ok
17:55:57.0046 0x0438 IntelIde - ok
17:55:57.0125 0x0438 [ 4C7D2750158ED6E7AD642D97BFFAE351, C05E4799752F090DCB632F07F62ADE38D31534621064D269AD535CA0BDFED448 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:55:57.0421 0x0438 intelppm - ok
17:55:57.0515 0x0438 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
17:55:57.0828 0x0438 Ip6Fw - ok
17:55:57.0906 0x0438 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:55:58.0187 0x0438 IpFilterDriver - ok
17:55:58.0281 0x0438 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:55:58.0546 0x0438 IpInIp - ok
17:55:58.0734 0x0438 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:55:59.0156 0x0438 IpNat - ok
17:55:59.0296 0x0438 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:55:59.0609 0x0438 IPSec - ok
17:55:59.0625 0x0438 ipsecd - ok
17:55:59.0734 0x0438 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
17:55:59.0875 0x0438 IRENUM - ok
17:56:00.0000 0x0438 [ 6DFB88F64135C525433E87648BDA30DE, 8233EEFBEF36AAA152F2C55D23D7118F0DE40C9C22EB5D9793405A4770889540 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:56:00.0296 0x0438 isapnp - ok
17:56:00.0609 0x0438 [ 80A79264302910C7C24BA7E44267EFEF, 6080C233478350C8E07515D20D2D60C3758C4A65432B04E8C8B816248621A3EF ] JavaQuickStarterService C:\Programme\Java\jre7\bin\jqs.exe
17:56:00.0796 0x0438 JavaQuickStarterService - ok
17:56:00.0875 0x0438 [ 1704D8C4C8807B889E43C649B478A452, E854C90CD301F42BE2520CEDAD35E49DF2D43606CF4EEED861B74882118D04D1 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:56:01.0140 0x0438 Kbdclass - ok
17:56:01.0250 0x0438 [ B6D6C117D771C98130497265F26D1882, E79CC4EA5C088F988BA61F80764F9CAD9B78BC56A7E17DD54622C75483BC5DF4 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
17:56:01.0515 0x0438 kbdhid - ok
17:56:01.0671 0x0438 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
17:56:02.0078 0x0438 kmixer - ok
17:56:02.0187 0x0438 [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
17:56:02.0406 0x0438 KSecDD - ok
17:56:02.0515 0x0438 [ 85B6D85C044E3DF77E92B5A7B265008F, 1068FE42D23BA26DAF73EF2BAAD19ED9B3781F7BB89799C28EEE2F13A766807B ] Ktp C:\WINDOWS\system32\DRIVERS\ETD.sys
17:56:02.0625 0x0438 Ktp - ok
17:56:02.0703 0x0438 [ 303627228DD739D98289679901A38C8F, 2E2C249CDD0C1D04EF4EC03DD5EF1984DD74FC66253BBDA553FB30FAA8173F60 ] L1e C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
17:56:02.0796 0x0438 L1e - ok
17:56:02.0921 0x0438 [ 2BBDCB79900990F0716DFCB714E72DE7, 6283789201164A9254632D9A3C8A54FE697717D5F8D5A37804D924DC2B70C8E3 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
17:56:03.0140 0x0438 LanmanServer - ok
17:56:03.0281 0x0438 [ 1869B14B06B44B44AF70548E1EA3303F, 4D63B4DAF580C86F86837C7D1753E2105B4C52E26D4CA0CAAFE83755EFF7AFBE ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
17:56:03.0453 0x0438 lanmanworkstation - ok
17:56:03.0484 0x0438 lbrtfdc - ok
17:56:03.0609 0x0438 [ 636714B7D43C8D0C80449123FD266920, F06F6C7DC49B26EFCAC3570C67BA9BD934F62C6F382DA4DD2AB302C7B970F414 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
17:56:03.0921 0x0438 LmHosts - ok
17:56:04.0015 0x0438 [ B7550A7107281D170CE85524B1488C98, A3854B16A65436BEF6BEDE918B43B3BE8F00D303660DB5831DD376271DC43239 ] Messenger C:\WINDOWS\System32\msgsvc.dll
17:56:04.0312 0x0438 Messenger - ok
17:56:04.0406 0x0438 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
17:56:04.0656 0x0438 mnmdd - ok
17:56:04.0796 0x0438 [ C2F1D365FD96791B037EE504868065D3, 87BD87E08FD00D115524B049F1A3A719AB86557D68968E7090CD0F271F985CAF ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
17:56:05.0093 0x0438 mnmsrvc - ok
17:56:05.0171 0x0438 [ 6FB74EBD4EC57A6F1781DE3852CC3362, 0454509D9A31E0202C08AE17294E2682F227D177A3C73B303E4C8332757AFCA1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
17:56:05.0468 0x0438 Modem - ok
17:56:05.0546 0x0438 [ B24CE8005DEAB254C0251E15CB71D802, 6804A8ABDAD5EC846E7F8077D1EE9BA45D6226ACFF42C70BE3DE7C8980EF9EC4 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:56:05.0828 0x0438 Mouclass - ok
17:56:05.0906 0x0438 [ 66A6F73C74E1791464160A7065CE711A, 3C570FA1E8EF976B83759220FE95BAC9D7D48D607F91B113EDE4790D34ACBD46 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:56:06.0171 0x0438 mouhid - ok
17:56:06.0250 0x0438 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
17:56:06.0531 0x0438 MountMgr - ok
17:56:06.0562 0x0438 mraid35x - ok
17:56:06.0781 0x0438 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:56:07.0187 0x0438 MRxDAV - ok
17:56:07.0562 0x0438 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:56:08.0187 0x0438 MRxSmb - ok
17:56:08.0265 0x0438 [ 35A031AF38C55F92D28AA03EE9F12CC9, 97245D204C886EE8DCCC2DEAC80A0E358A7E0C1982F77389DA50DCF091FC9DDC ] MSDTC C:\WINDOWS\system32\msdtc.exe
17:56:08.0531 0x0438 MSDTC - ok
17:56:08.0640 0x0438 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
17:56:08.0890 0x0438 Msfs - ok
17:56:08.0906 0x0438 MSIServer - ok
17:56:08.0984 0x0438 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:56:09.0234 0x0438 MSKSSRV - ok
17:56:09.0328 0x0438 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:56:09.0578 0x0438 MSPCLOCK - ok
17:56:09.0640 0x0438 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
17:56:09.0937 0x0438 MSPQM - ok
17:56:10.0031 0x0438 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:56:10.0265 0x0438 mssmbios - ok
17:56:10.0359 0x0438 [ E53736A9E30C45FA9E7B5EAC55056D1D, 38602F280BF69EBA3706AD175AFC1AEB561A8302B4B61E3FECB3C27D7A9BDB41 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
17:56:10.0609 0x0438 MSTEE - ok
17:56:10.0781 0x0438 [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
17:56:10.0937 0x0438 Mup - ok
17:56:11.0031 0x0438 [ 5B50F1B2A2ED47D560577B221DA734DB, C16A554B6E1A7F5F98C94DFA88163E0F7426506BF2F51FD351B1A05FC0DB3BC5 ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:56:11.0343 0x0438 NABTSFEC - ok
17:56:11.0640 0x0438 [ 46BB15AE2AC7D025D6D2567B876817BD, 102A101B96D1078C98FA0F871C801A9A8538E20E5686AB0C7680B2F6C92B3165 ] napagent C:\WINDOWS\System32\qagentrt.dll
17:56:12.0109 0x0438 napagent - ok
17:56:12.0281 0x0438 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
17:56:12.0703 0x0438 NDIS - ok
17:56:12.0765 0x0438 [ 7FF1F1FD8609C149AA432F95A8163D97, 18CD1FF5AC1EF8A38D1EC53014F2BADD28D9CDF4ECE2EBC2313D08903776F323 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:56:13.0015 0x0438 NdisIP - ok
17:56:13.0109 0x0438 [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:56:13.0203 0x0438 NdisTapi - ok
17:56:13.0281 0x0438 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:56:13.0562 0x0438 Ndisuio - ok
17:56:13.0671 0x0438 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:56:14.0015 0x0438 NdisWan - ok
17:56:14.0140 0x0438 [ 2F597BB467E05B1FE3830EABD821B8E0, 141497F5A49D47CCE3C9289644F4BD838DCB238F6D8E847FC006652E21FE02AC ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
17:56:14.0234 0x0438 NDProxy - ok
17:56:14.0296 0x0438 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
17:56:14.0609 0x0438 NetBIOS - ok
17:56:14.0765 0x0438 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
17:56:15.0171 0x0438 NetBT - ok
17:56:15.0328 0x0438 [ 8ACE4251BFFD09CE75679FE940E996CC, 81969521B5EAEA09ECA63058BE9697BB69AF2596339CA9DF0CFEDC031DCFDC7E ] NetDDE C:\WINDOWS\system32\netdde.exe
17:56:15.0687 0x0438 NetDDE - ok
17:56:15.0859 0x0438 [ 8ACE4251BFFD09CE75679FE940E996CC, 81969521B5EAEA09ECA63058BE9697BB69AF2596339CA9DF0CFEDC031DCFDC7E ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
17:56:16.0125 0x0438 NetDDEdsdm - ok
17:56:16.0250 0x0438 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] Netlogon C:\WINDOWS\system32\lsass.exe
17:56:16.0531 0x0438 Netlogon - ok
17:56:16.0718 0x0438 [ E6D88F1F6745BF00B57E7855A2AB696C, 12A5EDD853600FF5EBF91E127077745AE1E61E66DBC1D4D4306570F171AF4A39 ] Netman C:\WINDOWS\System32\netman.dll
17:56:17.0171 0x0438 Netman - ok
17:56:17.0421 0x0438 [ F1B67B6B0751AE0E6E964B02821206A3, 3D5A7593ABDEE2047C5738671C85DC8B95A4ECF58D5D7B04EEE13A689839A540 ] Nla C:\WINDOWS\System32\mswsock.dll
17:56:17.0515 0x0438 Nla - ok
17:56:17.0578 0x0438 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
17:56:17.0843 0x0438 Npfs - ok
17:56:18.0281 0x0438 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
17:56:19.0093 0x0438 Ntfs - ok
17:56:19.0171 0x0438 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
17:56:19.0421 0x0438 NtLmSsp - ok
17:56:19.0781 0x0438 [ 56AF4064996FA5BAC9C449B1514B4770, 154602EFEC22728503D4ABA025DF711B0F2CFC983F5E3BF25F2A4BCD1AE250EC ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
17:56:20.0515 0x0438 NtmsSvc - ok
17:56:20.0578 0x0438 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
17:56:20.0859 0x0438 Null - ok
17:56:20.0906 0x0438 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:56:21.0171 0x0438 NwlnkFlt - ok
17:56:21.0265 0x0438 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:56:21.0546 0x0438 NwlnkFwd - ok
17:56:21.0640 0x0438 [ F84785660305B9B903FB3BCA8BA29837, BDBDE61076800415D98759077E9E039C80B55DBE68E31F8BF44A909C6C3D3276 ] Parport C:\WINDOWS\system32\drivers\Parport.sys
17:56:21.0953 0x0438 Parport - ok
17:56:22.0015 0x0438 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
17:56:22.0281 0x0438 PartMgr - ok
17:56:22.0359 0x0438 [ C2BF987829099A3EAA2CA6A0A90ECB4F, 1DF21EA8E43875CFEECD869407429F82FB449707CFB845718499468E699BAAAA ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
17:56:22.0609 0x0438 ParVdm - ok
17:56:22.0734 0x0438 [ 387E8DEDC343AA2D1EFBC30580273ACD, 5F3E642BDB759777E570ED5B22AC7E93CDCD362708F281657AD7BAB44EDEC802 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
17:56:23.0062 0x0438 PCI - ok
17:56:23.0078 0x0438 PCIDump - ok
17:56:23.0109 0x0438 [ 59BA86D9A61CBCF4DF8E598C331F5B82, 822D11C5CE77BFD7B2F25350CCBF92B0B9388EEA6D86ED220B768C720976D839 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
17:56:23.0390 0x0438 PCIIde - ok
17:56:23.0546 0x0438 [ A2A966B77D61847D61A3051DF87C8C97, 6CED7CA26DC62B0AAFC83A2E07336DAD25954491201BB8E06103971F3F0B8B51 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
17:56:23.0937 0x0438 Pcmcia - ok
17:56:23.0953 0x0438 PDCOMP - ok
17:56:23.0984 0x0438 PDFRAME - ok
17:56:24.0015 0x0438 PDRELI - ok
17:56:24.0046 0x0438 PDRFRAME - ok
17:56:24.0078 0x0438 perc2 - ok
17:56:24.0109 0x0438 perc2hib - ok
17:56:24.0312 0x0438 [ F5ED2F15364B1F58C8B392F43167058F, 62B6DD86708AA2A9FC183C3493C93AAC024E58C36837D095E18DD871F0291079 ] pflt C:\WINDOWS\system32\DRIVERS\vfilter.sys
17:56:24.0421 0x0438 pflt - ok
17:56:24.0531 0x0438 [ A3EDBE9053889FB24AB22492472B39DC, 6F2ED6E04BDE2FCA2A8BF9BD2D1D6923DE6EAECB46F582B6C0BD1CF364D65C9E ] PlugPlay C:\WINDOWS\system32\services.exe
17:56:24.0593 0x0438 PlugPlay - ok
17:56:24.0625 0x0438 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
17:56:24.0890 0x0438 PolicyAgent - ok
17:56:24.0968 0x0438 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:56:25.0281 0x0438 PptpMiniport - ok
17:56:25.0343 0x0438 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
17:56:25.0593 0x0438 ProtectedStorage - ok
17:56:25.0703 0x0438 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
17:56:26.0046 0x0438 PSched - ok
17:56:26.0078 0x0438 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:56:26.0390 0x0438 Ptilink - ok
17:56:26.0406 0x0438 ql1080 - ok
17:56:26.0437 0x0438 Ql10wnt - ok
17:56:26.0468 0x0438 ql12160 - ok
17:56:26.0500 0x0438 ql1240 - ok
17:56:26.0531 0x0438 ql1280 - ok
17:56:26.0781 0x0438 [ 720FEA3AAA15FE7E0BEAB10AC2E6D2B0, E1E6A79751B7CAA86F4C7F9DD2A835D5C30FBD433644F916B8E54CD8105D00D2 ] RalinkRegistryWriter C:\Programme\RALINK\Common\RaRegistry.exe
17:56:26.0937 0x0438 RalinkRegistryWriter - ok
17:56:26.0984 0x0438 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:56:27.0265 0x0438 RasAcd - ok
17:56:27.0359 0x0438 [ F5BA6CACCDB66C8F048E867563203246, AFEAD8FC02313F7EBC8F9F39E7ED2868852B480BE3902FA7BD0AFD81492AB243 ] RasAuto C:\WINDOWS\System32\rasauto.dll
17:56:27.0687 0x0438 RasAuto - ok
17:56:27.0781 0x0438 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:56:28.0093 0x0438 Rasl2tp - ok
17:56:28.0312 0x0438 [ F9A7B66EA345726EDB5862A46B1ECCD5, 5D35429D394D36A1692A7E219BA1A85CD8096FEAE0F90BFE036A63118FEDBF57 ] RasMan C:\WINDOWS\System32\rasmans.dll
17:56:28.0687 0x0438 RasMan - ok
17:56:28.0781 0x0438 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:56:29.0078 0x0438 RasPppoe - ok
17:56:29.0109 0x0438 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
17:56:29.0421 0x0438 Raspti - ok
17:56:29.0578 0x0438 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:56:29.0953 0x0438 Rdbss - ok
17:56:30.0015 0x0438 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:56:30.0281 0x0438 RDPCDD - ok
17:56:30.0500 0x0438 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:56:30.0812 0x0438 rdpdr - ok
17:56:31.0000 0x0438 [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
17:56:31.0203 0x0438 RDPWD - ok
17:56:31.0359 0x0438 [ 263AF18AF0F3DB99F574C95F284CCEC9, 2BFA9952E97EFEB386FC56EC2C125080CD12DAC078DBE43C395CB4D9F22165D3 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
17:56:31.0781 0x0438 RDSessMgr - ok
17:56:31.0890 0x0438 [ ED761D453856F795A7FE056E42C36365, EF026585B33415D8FCE94A9F27D7A4396C7C35C88E06A4CF0FEA702401E8597A ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
17:56:32.0156 0x0438 redbook - ok
17:56:32.0296 0x0438 [ 0E97EC96D6942CEEC2D188CC2EB69A01, D4253B4420BEF19451A55AB91E4834482181A31A31134F6E2AFE05C8E20C81A5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
17:56:32.0593 0x0438 RemoteAccess - ok
17:56:32.0718 0x0438 [ E4CD1F3D84E1C2CA0B8CF7501E201593, 649CC0B04F94D407EB6B4C7FDE2C6E4D2B1531307BC67C5775E44D66EF2E4F8A ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
17:56:33.0046 0x0438 RemoteRegistry - ok
17:56:33.0171 0x0438 [ 2A02E21867497DF20B8FC95631395169, D89E2D17ED4E1C727847C0E92D2DF68AEB70BF0B956BD2FE024ED70A961759D2 ] RpcLocator C:\WINDOWS\system32\locator.exe
17:56:33.0515 0x0438 RpcLocator - ok
17:56:33.0843 0x0438 [ 3127AFBF2C1ED0AB14A1BBB7AAECB85B, ECFBACE3CBF2384948EA1C445BDA3955EB4F44A9874286E6537C67DC1283E5B0 ] RpcSs C:\WINDOWS\system32\rpcss.dll
17:56:34.0093 0x0438 RpcSs - ok
17:56:34.0234 0x0438 [ 4BDD71B4B521521499DFD14735C4F398, 7B1498D3C67E56D05B58B7DA319ECB0117C37963AABB0E59B42831C087469DA1 ] RSVP C:\WINDOWS\system32\rsvp.exe
17:56:34.0593 0x0438 RSVP - ok
17:56:35.0562 0x0438 [ 7DCC219C0D5634F87CE4D33EB1F6DADA, 9B58B4B19C3237E927DF24287CCBBA33ED1B7E895B8874964A49CA1F18CB190A ] RT80x86 C:\WINDOWS\system32\DRIVERS\RT2860.sys
17:56:37.0078 0x0438 RT80x86 - ok
17:56:37.0125 0x0438 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] SamSs C:\WINDOWS\system32\lsass.exe
17:56:37.0390 0x0438 SamSs - ok
17:56:37.0546 0x0438 [ DCEC079FAD95D36C8DD5CB6D779DFE32, F8546552D939A225853A0CE4913701A93738DF02C999D16E141E9A828814BBC6 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
17:56:37.0921 0x0438 SCardSvr - ok
17:56:38.0140 0x0438 [ A050194A44D7FA8D7186ED2F4E8367AE, BCDF56D5A2F9E202DC67E7FE4BCC617BCC0BDFF2D221A621020068B17B2855BB ] Schedule C:\WINDOWS\system32\schedsvc.dll
17:56:38.0546 0x0438 Schedule - ok
17:56:38.0656 0x0438 [ F34C06D1C706A6D9433570B087A18B02, 5A1B059458CD71FA9883C8E92F9300B86B79A6E6FBBC87431630DA43D1508319 ] Scutum50 C:\WINDOWS\system32\Drivers\Scutum50.sys
17:56:38.0703 0x0438 Scutum50 - detected UnsignedFile.Multi.Generic ( 1 )
17:56:38.0703 0x0438 Scutum50 ( UnsignedFile.Multi.Generic ) - warning
17:56:38.0750 0x0438 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:56:38.0906 0x0438 Secdrv - ok
17:56:39.0015 0x0438 [ BEE4CFD1D48C23B44CF4B974B0B79B2B, DF3B02D713F8A4602BE75F004074D5DF79AFF2D58FF37110B2A6AC29F680758B ] seclogon C:\WINDOWS\System32\seclogon.dll
17:56:39.0296 0x0438 seclogon - ok
17:56:39.0390 0x0438 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3, 95D83F054A6610328D56E56CD948A6618C590231853E56FC20E7557DB61384A4 ] SENS C:\WINDOWS\system32\sens.dll
17:56:39.0687 0x0438 SENS - ok
17:56:39.0765 0x0438 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
17:56:40.0046 0x0438 serenum - ok
17:56:40.0140 0x0438 [ CF24EB4F0412C82BCD1F4F35A025E31D, B74CB094126F5C23F601C34D53B2DF5BE3E5918230AC9DCFCFFA8E66B3A0FA25 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
17:56:40.0453 0x0438 Serial - ok
17:56:40.0531 0x0438 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
17:56:40.0781 0x0438 Sfloppy - ok
17:56:41.0062 0x0438 [ CAD058D5F8B889A87CA3EB3CF624DCEF, A7CDCF44261D1F4D820927253EA8EBB63714B7BAFF8B08DE073507D9A7EEA5BB ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
17:56:41.0718 0x0438 SharedAccess - ok
17:56:41.0875 0x0438 [ 2DB7D303C36DDD055215052F118E8E75, BE6E7BBE12A7A4EDF1F1C2935350603970C7426BBCA7A1A6644BB8999123AF17 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
17:56:41.0953 0x0438 ShellHWDetection - ok
17:56:41.0968 0x0438 Simbad - ok
17:56:42.0015 0x0438 [ 866D538EBE33709A5C9F5C62B73B7D14, BC94BEB7C17B4FCAC8B5D0D5006A203BC209E0504EECE149651D8691935696CD ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:56:42.0281 0x0438 SLIP - ok
17:56:42.0296 0x0438 Sparrow - ok
17:56:42.0343 0x0438 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
17:56:42.0625 0x0438 splitter - ok
17:56:42.0750 0x0438 [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
17:56:42.0890 0x0438 Spooler - ok
17:56:43.0406 0x0438 [ CDDDEC541BC3C96F91ECB48759673505, B030FFA02832317AC5626BF1BF8A4A95A5992C9A6E81BC1C002D5F4D667C27FB ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
17:56:44.0281 0x0438 sptd - ok
17:56:44.0375 0x0438 [ 50FA898F8C032796D3B1B9951BB5A90F, 1C86273EC19EB96D6DB9CE6670C00683B77C99C42CC2F7E75BC50872B93446B1 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
17:56:44.0578 0x0438 sr - ok
17:56:44.0734 0x0438 [ FE77A85495065F3AD59C5C65B6C54182, EB4BAF992F961B2FD5D24BFCB6BCB2142BC32933139A818835FEAB190E4283BB ] srservice C:\WINDOWS\system32\srsvc.dll
17:56:44.0875 0x0438 srservice - ok
17:56:45.0203 0x0438 [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
17:56:45.0718 0x0438 Srv - ok
17:56:45.0859 0x0438 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500, 2971D7D45D6942D310D47DBD19B9680D2D29527E79B86133C72217FD29259465 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
17:56:46.0093 0x0438 SSDPSRV - ok
17:56:46.0359 0x0438 [ BC2C5985611C5356B24AEB370953DED9, 15CBAB8166827DC098E2B16AB6F49A1441A4CB52AF3588F0AD964CAB596DFE10 ] stisvc C:\WINDOWS\system32\wiaservc.dll
17:56:47.0015 0x0438 stisvc - ok
17:56:47.0093 0x0438 [ 77813007BA6265C4B6098187E6ED79D2, 93939120E803C46FBFD577C8FC2E6C7E71C0460E01D25CB29579490640AB50C7 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:56:47.0375 0x0438 streamip - ok
17:56:47.0421 0x0438 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
17:56:47.0656 0x0438 swenum - ok
17:56:47.0750 0x0438 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
17:56:48.0062 0x0438 swmidi - ok
17:56:48.0078 0x0438 SwPrv - ok
17:56:48.0156 0x0438 symc810 - ok
17:56:48.0187 0x0438 symc8xx - ok
17:56:48.0218 0x0438 sym_hi - ok
17:56:48.0250 0x0438 sym_u3 - ok
17:56:48.0375 0x0438 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
17:56:48.0687 0x0438 sysaudio - ok
17:56:48.0875 0x0438 syshost32 - ok
17:56:49.0000 0x0438 [ 2903FFFA2523926D6219428040DCE6B9, 4F13181931B0499F6C3F08138054DBCD1F84CB9806999A9172B80DE79D446F62 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
17:56:49.0328 0x0438 SysmonLog - ok
17:56:49.0437 0x0438 [ E930A912C441B14E12DD744E726ED4CE, CB2501082EDD19EF07B6EE6D8F00DFD2D42A2286CFC18CEA986E19A40CDF98A5 ] tap0901 C:\WINDOWS\system32\DRIVERS\tap0901.sys
17:56:49.0484 0x0438 tap0901 - detected UnsignedFile.Multi.Generic ( 1 )
17:56:49.0484 0x0438 tap0901 ( UnsignedFile.Multi.Generic ) - warning
17:56:49.0703 0x0438 [ 05903CAC4B98908D55EA5774775B382E, AC3666CBD894D737874A5998DC7F46A0A51A7B23B1835FC735B9AD503A2191CC ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
17:56:50.0437 0x0438 TapiSrv - ok
17:56:50.0828 0x0438 [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:56:51.0531 0x0438 Tcpip - ok
17:56:51.0625 0x0438 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
17:56:51.0984 0x0438 TDPIPE - ok
17:56:52.0062 0x0438 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
17:56:52.0531 0x0438 TDTCP - ok
17:56:52.0640 0x0438 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
17:56:53.0031 0x0438 TermDD - ok
17:56:53.0328 0x0438 [ B7DE02C863D8F5A005A7BF375375A6A4, 6DE05A7B28CA5A78D58536347FC47F15883EEDBEF487CEA0117CC280FC582DCC ] TermService C:\WINDOWS\System32\termsrv.dll
17:56:54.0156 0x0438 TermService - ok
17:56:54.0281 0x0438 [ 2DB7D303C36DDD055215052F118E8E75, BE6E7BBE12A7A4EDF1F1C2935350603970C7426BBCA7A1A6644BB8999123AF17 ] Themes C:\WINDOWS\System32\shsvcs.dll
17:56:54.0375 0x0438 Themes - ok
17:56:54.0531 0x0438 [ 03681A1CE77F51586903869A5AB1DEAB, E2EC0A481412166B654682C2F3D953E96E757466135CBD2D813B967EDB13C721 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
17:56:54.0843 0x0438 TlntSvr - ok
17:56:54.0921 0x0438 TosIde - ok
17:56:55.0109 0x0438 [ 626504572B175867F30F3215C04B3E2F, 47E87CE9BC666D5CB5953C5D497DC00A7CC28F8EC0A064B3E47700279C5C4B91 ] TrkWks C:\WINDOWS\system32\trkwks.dll
17:56:55.0515 0x0438 TrkWks - ok
17:56:55.0671 0x0438 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
17:56:56.0125 0x0438 Udfs - ok
17:56:56.0140 0x0438 ultra - ok
17:56:56.0484 0x0438 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
17:56:57.0000 0x0438 Update - ok
17:56:57.0218 0x0438 [ 1DFD8975D8C89214B98D9387C1125B49, 0B6B268487C8E45E9B86BF4A0A9DB669E0E45D600DE3C82B63F9986CA9E01082 ] upnphost C:\WINDOWS\System32\upnphost.dll
17:56:57.0578 0x0438 upnphost - ok
17:56:57.0625 0x0438 [ 9B11E6118958E63E1FEF129466E2BDA7, 97168BCE3F4A9BB9E6500F05E34851FB957B219C598944FADC28AC0011C0503B ] UPS C:\WINDOWS\System32\ups.exe
17:56:57.0937 0x0438 UPS - ok
17:56:58.0000 0x0438 [ 1B611611C28D2DF25BC057D79C6F13FC, B0D86F63E44B40413BBAE6402CC088046CFAE082D41BBC2ED5A916293356B846 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:56:58.0187 0x0438 usbccgp - ok
17:56:58.0250 0x0438 [ 4BAC8DF07F1D8434FC640E677A62204E, 76C1351AF6752224BF59DEEE0F8665FE699F3DFD679F5BCD01C7D9383E6402A4 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:56:58.0312 0x0438 usbehci - ok
17:56:58.0421 0x0438 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:56:58.0703 0x0438 usbhub - ok
17:56:58.0781 0x0438 [ 84C44D720655A8AA475E57A9E764D675, 2D450199338A217FBD951317812A74223E8B477974C7634667E8896316C3FEA0 ] usbser C:\WINDOWS\system32\DRIVERS\usbser.sys
17:56:59.0015 0x0438 usbser - ok
17:56:59.0093 0x0438 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:56:59.0421 0x0438 usbstor - ok
17:56:59.0515 0x0438 [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:56:59.0796 0x0438 usbuhci - ok
17:56:59.0921 0x0438 [ 813236B1183CFCF289E367BD5DE6E29E, 167FE18A96F330AEEC1A4C419770C15EFEB536D43838285E51E7A62E95DF4674 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys
17:57:00.0093 0x0438 usbvideo - ok
17:57:00.0140 0x0438 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
17:57:00.0406 0x0438 VgaSave - ok
17:57:00.0421 0x0438 ViaIde - ok
17:57:00.0531 0x0438 [ A8087593A397B43BE57F4CD3AA11E81F, 6AF0EBFD9291B24975B7E2BD6C16EA2276D9495C7742243344797BB17683719B ] vnet C:\WINDOWS\system32\DRIVERS\virtualnet.sys
17:57:00.0593 0x0438 vnet - ok
17:57:00.0671 0x0438 [ A5A712F4E880874A477AF790B5186E1D, FE885ED04C3EAFC379787F836738A2769E43D07CF52DD917D90C38E001957A5E ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
17:57:00.0968 0x0438 VolSnap - ok
17:57:01.0015 0x0438 vpnva - ok
17:57:01.0281 0x0438 [ 68F106273BE29E7B7EF8266977268E78, 1488AB7A654EBC94C73E1D494067189ACB95BC233980110CAC4C0297CDC4115A ] VSS C:\WINDOWS\System32\vssvc.exe
17:57:01.0609 0x0438 VSS - ok
17:57:01.0828 0x0438 [ 7B353059E665F8B7AD2BBEAEF597CF45, 84A4311F18A4B8DCB364741DEA7D18E2363F19564B2EF25214965DC729527068 ] W32Time C:\WINDOWS\system32\w32time.dll
17:57:02.0109 0x0438 W32Time - ok
17:57:02.0203 0x0438 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:57:02.0531 0x0438 Wanarp - ok
17:57:02.0671 0x0438 [ DC7F91B2ED24A738C807EA07F298928C, A4DCE890B7CC550B0DD3D7D4CDE01623B64C5688953CE386D9602CD542B261C9 ] wceusbsh C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
17:57:02.0859 0x0438 wceusbsh - ok
17:57:02.0875 0x0438 WDICA - ok
17:57:02.0984 0x0438 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
17:57:03.0937 0x0438 wdmaud - ok
17:57:04.0031 0x0438 [ 81727C9873E3905A2FFC1EBD07265002, 6AC2383A1DCBB7FA3DB90FBB874C8E1819F5B7492717FF41E303EFC7BF72F93E ] WebClient C:\WINDOWS\System32\webclnt.dll
17:57:04.0593 0x0438 WebClient - ok
17:57:05.0015 0x0438 [ 6F3F3973D97714CC5F906A19FE883729, 7817118BE94D0F6FAE0F9CE48AD70FFE0AEF886CCE09C666768FAB61047F992F ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
17:57:05.0296 0x0438 winmgmt - ok
17:57:05.0453 0x0438 [ 6E18978B749F0696A774DE3F2CB142DD, 4BBE31A78F6CF474A4CFDBB7C365DE058247F8BFA21F7E563111E84D8937BC26 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
17:57:05.0734 0x0438 WmdmPmSN - ok
17:57:06.0328 0x0438 [ FFA4D901D46D07A5BAB2D8307FBB51A6, 53C6D04D111EDF774C7F7EEB8D032B372E6244774D56B1B34CF1236027EC9450 ] Wmi C:\WINDOWS\System32\advapi32.dll
17:57:06.0828 0x0438 Wmi - ok
17:57:07.0000 0x0438 [ 93908111BA57A6E60EC2FA2DE202105C, F395F25F18D15C6B9FEDB45FD31E10295FFE5517E2BC86ACAC11904EA0664BE2 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
17:57:07.0359 0x0438 WmiApSrv - ok
17:57:07.0531 0x0438 [ 300B3E84FAF1A5C1F791C159BA28035D, 0194856BDF94C1F274AF70AD558290ACDACDDEA331BD66FEB8E167ABD1E36786 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
17:57:07.0953 0x0438 wscsvc - ok
17:57:08.0031 0x0438 [ C98B39829C2BBD34E454150633C62C78, 71B60EA3AD0E2637917D528C6A9E7ECF2949E3E5E91036AA5BBADA95BD725511 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:57:08.0296 0x0438 WSTCODEC - ok
17:57:08.0375 0x0438 [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085, A1DB8909FA73337DB613D01824945485186654364A4DF129B8CB913CF87D1D2E ] wuauserv C:\WINDOWS\system32\wuauserv.dll
17:57:08.0703 0x0438 wuauserv - ok
17:57:09.0187 0x0438 [ C4F109C005F6725162D2D12CA751E4A7, AC996B44338328BDD4442FE48406F286A64526F0EC77BE00A19FA7FDB0407CFE ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
17:57:10.0062 0x0438 WZCSVC - ok
17:57:10.0234 0x0438 [ 0ADA34871A2E1CD2CAAFED1237A47750, 45BEF8649078BD74C1A347B5F2D3A1958E5A7DCD6C6BA8A2E0CAD277A929C64E ] xmlprov C:\WINDOWS\System32\xmlprov.dll
17:57:10.0625 0x0438 xmlprov - ok
17:57:10.0687 0x0438 ================ Scan global ===============================
17:57:10.0843 0x0438 [ 2C60091CA5F67C3032EAB3B30390C27F, 9E205C8E67F4B61FCFA2A82AA1968D522C3B6410D7075BE813F7F1564D61632E ] C:\WINDOWS\system32\basesrv.dll
17:57:11.0062 0x0438 [ E62178BC21EAC63A3B9A2DBD46C1B505, CAA5480CC4DAA37758F0CF445F865FD6F4630080B044EF2E606C2F62DAA4061A ] C:\WINDOWS\system32\winsrv.dll
17:57:11.0296 0x0438 [ E62178BC21EAC63A3B9A2DBD46C1B505, CAA5480CC4DAA37758F0CF445F865FD6F4630080B044EF2E606C2F62DAA4061A ] C:\WINDOWS\system32\winsrv.dll
17:57:11.0406 0x0438 [ A3EDBE9053889FB24AB22492472B39DC, 6F2ED6E04BDE2FCA2A8BF9BD2D1D6923DE6EAECB46F582B6C0BD1CF364D65C9E ] C:\WINDOWS\system32\services.exe
17:57:11.0421 0x0438 [ Global ] - ok
17:57:11.0421 0x0438 ================ Scan MBR ==================================
17:57:11.0468 0x0438 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0
17:57:12.0031 0x0438 \Device\Harddisk0\DR0 - ok
17:57:12.0031 0x0438 ================ Scan VBR ==================================
17:57:12.0046 0x0438 [ 4245CEA1EB3D659C1B14657ADD2B60D1 ] \Device\Harddisk0\DR0\Partition1
17:57:12.0062 0x0438 \Device\Harddisk0\DR0\Partition1 - ok
17:57:12.0062 0x0438 ================ Scan generic autorun ======================
17:57:23.0546 0x0438 [ 61176ADAE8FD9DF0A8F1BF88D046CB93, 45AA62402B314CEF6481CFB713616127E3F68250E6A86BBA76EE942B8828E5AD ] C:\WINDOWS\RTHDCPL.EXE
17:57:47.0640 0x0438 RTHDCPL - ok
17:57:47.0781 0x0438 [ 0D034E8C4F88C5B2B0C1AF3CF438CC4F, F44F9A6BBA0AE6D350F98CDBF2D5B09D56D9B1CF46F4CB9F50566232B32F8BAE ] C:\WINDOWS\SOUNDMAN.EXE
17:57:47.0953 0x0438 SoundMan - ok
17:57:49.0859 0x0438 [ EC05E964058693D1F71D1B5506B5CF09, B1E126AA040800FEC99CAE2C675A225183D50A6F3D24262051A5FB5D96E61012 ] C:\WINDOWS\ALCWZRD.EXE
17:57:53.0484 0x0438 AlcWzrd - ok
17:57:53.0609 0x0438 [ 5490BD0896299C6FCB1AC0040742B2A7, 12938ACC18B257C9293FA278A59E5DEF56021F29A93D700B38DEEF92EC2D3B68 ] C:\Programme\EeePC\ACPI\AsTray.exe
17:57:53.0734 0x0438 AsusTray - detected UnsignedFile.Multi.Generic ( 1 )
17:57:53.0734 0x0438 AsusTray ( UnsignedFile.Multi.Generic ) - warning
17:57:54.0171 0x0438 [ 25BB2C4C7D4709855BF8BB66E499941B, 003E2496D5C14469650CFA75F84B9394E2B34C2E3DD7E3F7E6B1E8C4079BD91C ] C:\Programme\EeePC\ACPI\AsAcpiSvr.exe
17:57:54.0937 0x0438 AsusACPIServer - detected UnsignedFile.Multi.Generic ( 1 )
17:57:54.0937 0x0438 AsusACPIServer ( UnsignedFile.Multi.Generic ) - warning
17:57:54.0937 0x0438 Force sending object to P2P due to detect: C:\Programme\EeePC\ACPI\AsAcpiSvr.exe
17:57:55.0250 0x0438 Object send P2P result: false
17:57:55.0328 0x0438 [ 2D3A4F1B70420B367763AB14F9E9510F, 6301BC932A12403AC64ADB3C0A45A492499AD3AD12729329891BD4BA3E322518 ] C:\Programme\EeePC\ACPI\AsEPCMon.exe
17:57:55.0421 0x0438 AsusEPCMonitor - detected UnsignedFile.Multi.Generic ( 1 )
17:57:55.0421 0x0438 AsusEPCMonitor ( UnsignedFile.Multi.Generic ) - warning
17:57:55.0734 0x0438 [ DD3F9185387C4392D59A11673B84A67B, C1B85748C8286488887261D2F2523392DDFCE31C4D8788B15473E973B1959987 ] C:\Programme\Elantech\ETDCtrl.exe
17:57:56.0265 0x0438 ETDWare - ok
17:57:56.0500 0x0438 [ 7BBE4CF421AECC7F0226EDD75F12079F, 8E78FC5E0657DB066F9EBAADEA9AFECB1AAA570DD9C08C7ED42116704D2E379D ] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
17:57:56.0906 0x0438 IMJPMIG8.1 - ok
17:57:57.0015 0x0438 [ 1B17E09C1223F6D17336D2DD7A1AF4F4, 06DFAD95007532CCF46D593EEDC2474936614AEDCEA7BF983E36DAD22F850B08 ] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
17:57:57.0343 0x0438 MSPY2002 - ok
17:57:57.0718 0x0438 [ 024DC0F68DF5FD6AE9DD82DFBAF479D6, FDBF0FD05CFB757C704B22703DF23E05207F14877A4EF52E3032012B6FD0C4E0 ] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
17:57:58.0468 0x0438 PHIME2002ASync - ok
17:57:58.0828 0x0438 [ 024DC0F68DF5FD6AE9DD82DFBAF479D6, FDBF0FD05CFB757C704B22703DF23E05207F14877A4EF52E3032012B6FD0C4E0 ] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
17:57:59.0265 0x0438 PHIME2002A - ok
17:57:59.0421 0x0438 [ 4F0BED169FAB31EA094A649B0473B5C6, 492516BEA51D0A793F055EB789DC0A07477A78FAC6321C0AAB9BEF72EE7FCC80 ] C:\WINDOWS\system32\igfxtray.exe
17:57:59.0593 0x0438 IgfxTray - ok
17:57:59.0703 0x0438 [ 8B0DE4B972DB725FB9D591E69CD236FB, DF84C7DAE087772C4AAF8D13B48F9BE1E6BC31869DE6BD9642B598C0DF660F12 ] C:\WINDOWS\system32\hkcmd.exe
17:57:59.0859 0x0438 HotKeysCmds - ok
17:57:59.0968 0x0438 [ CC632EB3A7D106464E933E7D53883550, F1378C5AD859296A73BF23F3AB1765D5BD4EFB856E011A7A8676BE793BBC29B5 ] C:\WINDOWS\system32\igfxpers.exe
17:58:00.0125 0x0438 Persistence - ok
17:58:00.0375 0x0438 [ 5B6E8E09BE6401A7E022F52FDFCB2FF8, 471C556CF9405BBB380A8CEFE945C126B954B7C94F79CC72441B51F80141FC5E ] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
17:58:00.0609 0x0438 SunJavaUpdateSched - ok
17:58:00.0781 0x0438 [ 4DA2F2DA54A92850F56C0DB712058188, 9FB9BD1D9874DD64A627FFBE7B54B753D5496425BB595A112D0E17601A5E86A0 ] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe
17:58:00.0875 0x0438 Malwarebytes Anti-Malware (cleanup) - ok
17:58:00.0875 0x0438 {F79B4AEA-120D-4808-9376-FB23F64217F1} - ok
17:58:00.0937 0x0438 [ 01B4E6E990B6C5EA8856D96C7FD044B2, 2266296FD3C8E0DFA657F21406EE4E494477870DFAF7C65BEBCB6FBA8CADC7C6 ] C:\WINDOWS\system32\CTFMON.EXE
17:58:01.0187 0x0438 CTFMON.EXE - ok
17:58:01.0250 0x0438 [ 01B4E6E990B6C5EA8856D96C7FD044B2, 2266296FD3C8E0DFA657F21406EE4E494477870DFAF7C65BEBCB6FBA8CADC7C6 ] C:\WINDOWS\system32\CTFMON.EXE
17:58:01.0484 0x0438 CTFMON.EXE - ok
17:58:01.0562 0x0438 [ 01B4E6E990B6C5EA8856D96C7FD044B2, 2266296FD3C8E0DFA657F21406EE4E494477870DFAF7C65BEBCB6FBA8CADC7C6 ] C:\WINDOWS\system32\ctfmon.exe
17:58:01.0796 0x0438 CTFMON.EXE - ok
17:58:02.0109 0x0438 [ F34E7705751BB413283434697BF8E55D, BDF8B29A56C51439BEB9B4C3576341BBE3EE80582063AD602AB77D19A0630C35 ] C:\Programme\DAEMON Tools Lite\DTLite.exe
17:58:02.0593 0x0438 DAEMON Tools Lite - ok
17:58:03.0234 0x0438 [ 98EBAF30AE3B607B916F0773456B075A, 7A7FF445E6075999BCEAA6B045435D5318C02E27BF2BEBBFE966E7A5451FAAB8 ] C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe
17:58:04.0218 0x0438 FlashPlayerUpdate - ok
17:58:04.0375 0x0438 ============================================================
17:58:04.0375 0x0438 Scan finished
17:58:04.0375 0x0438 ============================================================
17:58:04.0421 0x0430 Detected object count: 7
17:58:04.0421 0x0430 Actual detected object count: 7
17:59:18.0890 0x0430 6cb4f0b1c715c25e ( Rootkit.Win32.Necurs.gen ) - skipped by user
17:59:18.0890 0x0430 6cb4f0b1c715c25e ( Rootkit.Win32.Necurs.gen ) - User select action: Skip
17:59:18.0890 0x0430 HDD & SSD access service ( UnsignedFile.Multi.Generic ) - skipped by user
17:59:18.0890 0x0430 HDD & SSD access service ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:59:18.0906 0x0430 Scutum50 ( UnsignedFile.Multi.Generic ) - skipped by user
17:59:18.0906 0x0430 Scutum50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:59:18.0921 0x0430 tap0901 ( UnsignedFile.Multi.Generic ) - skipped by user
17:59:18.0921 0x0430 tap0901 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:59:18.0937 0x0430 AsusTray ( UnsignedFile.Multi.Generic ) - skipped by user
17:59:18.0937 0x0430 AsusTray ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:59:18.0937 0x0430 AsusACPIServer ( UnsignedFile.Multi.Generic ) - skipped by user
17:59:18.0937 0x0430 AsusACPIServer ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:59:18.0953 0x0430 AsusEPCMonitor ( UnsignedFile.Multi.Generic ) - skipped by user
17:59:18.0953 0x0430 AsusEPCMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip |