![]() |
Trojan.Agent in syshost.exe Hallo! Ich habe blöderweise auf eine nette Phishingmail (noch vorhanden, falls gewünscht) geklickt und mir einen Trojan.Agent eingefangen. Avira Echtzeitscanner und Updates waren seither deaktiviert. Eine nicht beendbare syshost.exe war im Taskmanager zu sehen. - Möglicherweise ist/war noch etwas anderes Schädliches unterwegs, denn Windows meckerte schon seit 2 oder 3 Tagen, daß die Firewall deaktiviert sei. Hatte dann jeweils die Windows Firewall aktiviert, damit war die Sache vorerst erledigt. - Habe Avira, Hijackthis, Adware und Malwarebytes drüberlaufen lassen. Avira hat nur ca. 260 Warnungen harausgegeben, daß bestimmte Dateien nicht zu öffnen sind, aber nichts gefunden. (Die Warnungen waren beim nächsten Lauf verschwunden.) Hijackthis zeigte auch die syshost.exe an (fixen war nicht möglich). Adware hat nichts gefunden, Mbam hat den Trojan.Agent gefunden, ist jetzt in Quarantäne. Mbam-Log und Hijackthis-Log konnte ich speichern. (Welche soll ich posten?) Avira habe ich deinstalliert und versucht neu zu installieren, funktioniert natürlich auch nicht. Bricht ohne Meldung ab. Erbitte Hilfe, ich habe vermutlich nicht alles erwischt. Vielen Dank. |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Danke für die ultraschnelle Antwort. Ich habe persönliche Namen aus den Logfiles ausgesternt. Was mir noch einfiel, ich hatte vorher spybot auch noch drüberlaufen lassen, ohne Fund. Was mir merkwürdig erscheint, daß avira als installiertes Programm gelistet wird, aber ich hab es heute deinstalliert?! EDIT: War zu voreilig und habe Programm vom Stick gestartet. Das nächste Mal mach ichs dann richtig vom Desktop. Entschuldigung. FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01 --- --- --- --- --- --- --- --- --- Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 26-11-2014 01 |
hi, Downloade dir bitte ![]()
|
Hallo, hier das Log. Lssrvc.exe hab ich von Nero und kann weg. Daß er bei Teatimer anschlägt, könnte normal sein, oder? Danke. Code: 10:58:52.0421 0x012c TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34 |
hier gehts weiter: Code: 10:59:40.0046 0x047c D:\WINDOWS\system32\setupapi.dll - ok |
Zitat:
Starte TDSSkiller.exe mit Doppelklick. Vista und Win7 User mit Rechtsklick "als Administrator starten"
Als Beispiel: C:\TDSSKiller.<version_date_time>log.txt Poste den Inhalt bitte hier in deinen Thread. Scan mit Combofix
|
Hallo, hier die Logs. TDSS erster Teil [CODE 19:00:03.0875 0x0218 TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34 19:00:05.0781 0x0218 ============================================================ 19:00:05.0781 0x0218 Current date / time: 2014/11/30 19:00:05.0781 19:00:05.0781 0x0218 SystemInfo: 19:00:05.0781 0x0218 19:00:05.0781 0x0218 OS Version: 5.1.2600 ServicePack: 3.0 19:00:05.0781 0x0218 Product type: Workstation 19:00:05.0781 0x0218 ComputerName: INTRNET 19:00:05.0781 0x0218 UserName: Arbeit 19:00:05.0781 0x0218 Windows directory: D:\WINDOWS 19:00:05.0781 0x0218 System windows directory: D:\WINDOWS 19:00:05.0781 0x0218 Processor architecture: Intel x86 19:00:05.0781 0x0218 Number of processors: 2 19:00:05.0781 0x0218 Page size: 0x1000 19:00:05.0781 0x0218 Boot type: Normal boot 19:00:05.0781 0x0218 ============================================================ 19:00:05.0781 0x0218 BG loaded 19:00:05.0953 0x0218 System UUID: {78DF7FD0-1D0E-3939-D90F-C6BA596866FA} 19:00:06.0437 0x0218 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000044 19:00:06.0437 0x0218 Drive \Device\Harddisk1\DR3 - Size: 0x7A800000 ( 1.91 Gb ), SectorSize: 0x200, Cylinders: 0xF9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 19:00:06.0453 0x0218 ============================================================ 19:00:06.0453 0x0218 \Device\Harddisk0\DR0: 19:00:06.0453 0x0218 MBR partitions: 19:00:06.0453 0x0218 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x9C25FE 19:00:06.0453 0x0218 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x9C267C, BlocksNum 0x1C7FE044 19:00:06.0453 0x0218 \Device\Harddisk1\DR3: 19:00:06.0453 0x0218 MBR partitions: 19:00:06.0453 0x0218 \Device\Harddisk1\DR3\Partition1: MBR, Type 0x6, StartLBA 0x5F0, BlocksNum 0x3D3A10 19:00:06.0453 0x0218 ============================================================ 19:00:06.0468 0x0218 C: <-> \Device\Harddisk0\DR0\Partition1 19:00:06.0500 0x0218 D: <-> \Device\Harddisk0\DR0\Partition2 19:00:06.0500 0x0218 ============================================================ 19:00:06.0500 0x0218 Initialize success 19:00:06.0500 0x0218 ============================================================ 19:00:25.0265 0x05c8 ============================================================ 19:00:25.0265 0x05c8 Scan started 19:00:25.0265 0x05c8 Mode: Manual; SigCheck; TDLFS; 19:00:25.0265 0x05c8 ============================================================ 19:00:25.0265 0x05c8 KSN ping started 19:00:25.0312 0x05c8 KSN ping finished: false 19:00:25.0718 0x05c8 ================ Scan system memory ======================== 19:00:25.0718 0x05c8 System memory - ok 19:00:25.0718 0x05c8 ================ Scan services ============================= 19:00:25.0718 0x05c8 Suspicious service (NoAccess): 41d78ef79c384a09 19:00:25.0812 0x05c8 [ B2234CF29BF7D128FA69510E0F2D11E2, 11C378B58C37C42365897250DE874E51E612137AC83B181E206571FD173AF4DA ] 41d78ef79c384a09 D:\WINDOWS\System32\Drivers\41d78ef79c384a09.sys 19:00:25.0812 0x05c8 Suspicious file ( NoAccess ): D:\WINDOWS\System32\Drivers\41d78ef79c384a09.sys. md5: B2234CF29BF7D128FA69510E0F2D11E2, sha256: 11C378B58C37C42365897250DE874E51E612137AC83B181E206571FD173AF4DA 19:00:26.0406 0x05c8 41d78ef79c384a09 - detected Rootkit.Win32.Necurs.gen ( 0 ) 19:00:26.0562 0x05c8 41d78ef79c384a09 ( Rootkit.Win32.Necurs.gen ) - infected 19:00:26.0562 0x05c8 Force sending object to P2P due to detect: 41d78ef79c384a09 19:00:26.0562 0x05c8 Object send P2P result: false 19:00:26.0562 0x05c8 Abiosdsk - ok 19:00:26.0562 0x05c8 abp480n5 - ok 19:00:26.0656 0x05c8 ACDaemon - ok 19:00:26.0687 0x05c8 [ AC407F1A62C3A300B4F2B5A9F1D55B2C, 31F5FC61B37E22100B3A52A590295A7E827FFC581FA9960C64B9032452AAECED ] ACPI D:\WINDOWS\system32\DRIVERS\ACPI.sys 19:00:27.0531 0x05c8 ACPI - ok 19:00:27.0578 0x05c8 [ 9E1CA3160DAFB159CA14F83B1E317F75, 13B3E897B0E819BF734449416D9EC6EBCAC89538EC69BF48C068593B82D57004 ] ACPIEC D:\WINDOWS\system32\drivers\ACPIEC.sys 19:00:27.0671 0x05c8 ACPIEC - ok 19:00:27.0671 0x05c8 adpu160m - ok 19:00:27.0703 0x05c8 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec D:\WINDOWS\system32\drivers\aec.sys 19:00:27.0796 0x05c8 aec - ok 19:00:27.0843 0x05c8 [ FE3EA6E9AFC1A78E6EDCA121E006AFB7, B596ABBAC058D93C505C9DBF8685049C88E4364195A4092DB580D2D44FA8C23C ] Afc D:\WINDOWS\system32\drivers\Afc.sys 19:00:27.0890 0x05c8 Afc - ok 19:00:27.0968 0x05c8 [ 322D0E36693D6E24A2398BEE62A268CD, FB0BFF5846E50DBCC2826639318A6A1DE79EE7DEA2719ED74A5F6F44454E13D0 ] AFD D:\WINDOWS\System32\drivers\afd.sys 19:00:28.0062 0x05c8 AFD - ok 19:00:28.0062 0x05c8 Aha154x - ok 19:00:28.0062 0x05c8 aic78u2 - ok 19:00:28.0062 0x05c8 aic78xx - ok 19:00:28.0125 0x05c8 [ 738D80CC01D7BC7584BE917B7F544394, DCC17AAEF5CDDF52FAAC3CC6904EF421CD595F66318A2370BEE261D5C3A8E340 ] Alerter D:\WINDOWS\system32\alrsvc.dll 19:00:28.0234 0x05c8 Alerter - ok 19:00:28.0250 0x05c8 [ 190CD73D4984F94D823F9444980513E5, 93A32C2495CCA094F768BA707C74DA5C00B8A88A9236DD1A297439A7C2E6C6FA ] ALG D:\WINDOWS\System32\alg.exe 19:00:28.0328 0x05c8 ALG - ok 19:00:28.0328 0x05c8 AliIde - ok 19:00:28.0421 0x05c8 [ F6AF59D6EEE5E1C304F7F73706AD11D8, F5D39EF40CDB5102A84C8594CFC54DDBD5060E193E6D07421A9003D2ABC63E30 ] Ambfilt D:\WINDOWS\system32\drivers\Ambfilt.sys 19:00:28.0531 0x05c8 Ambfilt - ok 19:00:28.0562 0x05c8 [ 033448D435E65C4BD72E70521FD05C76, A5462C22D5461F1BA06E81CD7E1ECE5409092DE53A8E4D3E78D089B65CB474D4 ] AmdPPM D:\WINDOWS\system32\DRIVERS\AmdPPM.sys 19:00:28.0609 0x05c8 AmdPPM - ok 19:00:28.0609 0x05c8 amsint - ok 19:00:28.0640 0x05c8 [ D45960BE52C3C610D361977057F98C54, 9186589B502F46B47672CFB8EBD558D51B0F3CBFE4E0DDBA625A4265236518CE ] AppMgmt D:\WINDOWS\System32\appmgmts.dll 19:00:28.0734 0x05c8 AppMgmt - ok 19:00:28.0734 0x05c8 asc - ok 19:00:28.0750 0x05c8 asc3350p - ok 19:00:28.0750 0x05c8 asc3550 - ok 19:00:28.0796 0x05c8 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac D:\WINDOWS\system32\DRIVERS\asyncmac.sys 19:00:28.0875 0x05c8 AsyncMac - ok 19:00:28.0906 0x05c8 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi D:\WINDOWS\system32\DRIVERS\atapi.sys 19:00:28.0984 0x05c8 atapi - ok 19:00:29.0000 0x05c8 Atdisk - ok 19:00:29.0062 0x05c8 [ ECA673779ECD27D674953D692FE070F6, 6FBCAF6C347E06032C63B72261785109D0929BE1B23CA5465995803951954616 ] Ati HotKey Poller D:\WINDOWS\system32\Ati2evxx.exe 19:00:29.0125 0x05c8 Ati HotKey Poller - ok 19:00:29.0234 0x05c8 [ 15B2FE76E2ECEB98C49ED52311A6F26F, E917AEBD221BF2DB217C111F256033FDA2B28FE55C7E87DAD4A16B84E3FD9398 ] ati2mtag D:\WINDOWS\system32\DRIVERS\ati2mtag.sys 19:00:29.0390 0x05c8 ati2mtag - ok 19:00:29.0453 0x05c8 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc D:\WINDOWS\system32\DRIVERS\atmarpc.sys 19:00:29.0546 0x05c8 Atmarpc - ok 19:00:29.0578 0x05c8 [ 58ED0D5452DF7BE732193E7999C6B9A4, 254E2ECF592DDA2E3E6CA9F6F3E77926E2265586A7937BA95199ED47BCDE69A3 ] AudioSrv D:\WINDOWS\System32\audiosrv.dll 19:00:29.0656 0x05c8 AudioSrv - ok 19:00:29.0703 0x05c8 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub D:\WINDOWS\system32\DRIVERS\audstub.sys 19:00:29.0781 0x05c8 audstub - ok 19:00:29.0828 0x05c8 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep D:\WINDOWS\system32\drivers\Beep.sys 19:00:29.0906 0x05c8 Beep - ok 19:00:29.0953 0x05c8 [ D6F603772A789BB3228F310D650B8BD1, A539025C70FD998A9B8703DE05CAE5E99BC721D8852EA561EBC2DD20CB371D2E ] BITS D:\WINDOWS\system32\qmgr.dll 19:00:30.0062 0x05c8 BITS - ok 19:00:30.0093 0x05c8 [ 852A1BD08E7DFEB9E30B5440881C0501, 92D3F82A29D4466706DA0A30921B4AE5D67F08C2C4EF362EDB1A2D254A5AF068 ] BlueletAudio D:\WINDOWS\system32\DRIVERS\blueletaudio.sys 19:00:30.0109 0x05c8 BlueletAudio - ok 19:00:30.0125 0x05c8 [ 8FC27B12A02B43947787F0EF1885DF9B, 1C0A44406FCD78BB6410140512B2165F974CD1837400A818529E4054A358E7BF ] BlueletSCOAudio D:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys 19:00:30.0140 0x05c8 BlueletSCOAudio - ok 19:00:30.0171 0x05c8 [ B42057F06BBB98B31876C0B3F2B54E33, 779AF28378E8D37E784BEDBEE23DCFFC6C9C9068180F2A9058C91047E33ED078 ] Browser D:\WINDOWS\System32\browser.dll 19:00:30.0250 0x05c8 Browser - ok 19:00:30.0265 0x05c8 [ C5CCE2B26F73F8CF7F3C82159E79AA08, 09FDCB702ADB4A58F061D314BD7FD4A2BD487EA877F89A5F31B86BE0BBC24360 ] BT D:\WINDOWS\system32\DRIVERS\btnetdrv.sys 19:00:30.0265 0x05c8 BT - ok 19:00:30.0281 0x05c8 [ DA473D279420234170DA795F1CAD4479, A6958C700496695D9B24D570FDCCB47C114217426AACB3FABBBA1941C722008D ] Btcsrusb D:\WINDOWS\system32\Drivers\btcusb.sys 19:00:30.0281 0x05c8 Btcsrusb - ok 19:00:30.0328 0x05c8 [ B279426E3C0C344893ED78A613A73BDE, 30B29ED5DCFF0C180B806A5FBC705E1CAF6B0F525298CDA79A77FC2AF6E5AAA7 ] BthEnum D:\WINDOWS\system32\DRIVERS\BthEnum.sys 19:00:30.0421 0x05c8 BthEnum - ok 19:00:30.0437 0x05c8 [ CE643D0918123D76A5CAAB008FCA9663, 045FA050D273C56AF13DC24A3E4AB14B236AC2CB4DD48D5B3180696096D3A931 ] BTHidEnum D:\WINDOWS\system32\Drivers\vbtenum.sys 19:00:30.0437 0x05c8 BTHidEnum - ok 19:00:30.0437 0x05c8 [ DFCA4FE4C8AEC786B4D0F432EB730F48, 3D9731A50127E86280B93466A3CAA90607027341E04EA3A8AE89B373DFC0A5B8 ] BTHidMgr D:\WINDOWS\system32\Drivers\BTHidMgr.sys 19:00:30.0453 0x05c8 BTHidMgr - ok 19:00:30.0453 0x05c8 [ FCA6F069597B62D42495191ACE3FC6C1, 23A4EAA542547AC48BCB19DEC9C8E1C1D7D83F199F045DA4682C33292F011CE9 ] BTHMODEM D:\WINDOWS\system32\DRIVERS\bthmodem.sys 19:00:30.0531 0x05c8 BTHMODEM - ok 19:00:30.0546 0x05c8 [ 80602B8746D3738F5886CE3D67EF06B6, 15ABAA8106C42A4453763EEB92B291844580168C934088DB1E22B2065DC238E9 ] BthPan D:\WINDOWS\system32\DRIVERS\bthpan.sys 19:00:30.0640 0x05c8 BthPan - ok 19:00:30.0671 0x05c8 [ 27D6108CFEBA7EF5AA976FC66EC77BBD, B0C3C61B3AF6358D9BE12DF56F741FE3CC5714950C74014EBED6804034D9D5DE ] BTHPORT D:\WINDOWS\system32\Drivers\BTHport.sys 19:00:30.0750 0x05c8 BTHPORT - ok 19:00:30.0796 0x05c8 [ 26C601EF7525E31379744ABFC6F35A1B, 842626D3A00DDA959A4AB730C0D551244DCDA15AC291FD70CC7324571A6088EC ] BthServ D:\WINDOWS\System32\bthserv.dll 19:00:30.0875 0x05c8 BthServ - ok 19:00:30.0890 0x05c8 [ 61364CD71EF63B0F038B7E9DF00F1EFA, FB44D02B4379A8AF7DD8B0B22B53888B758903700142BFE45A412709294CE88A ] BTHUSB D:\WINDOWS\system32\Drivers\BTHUSB.sys 19:00:30.0968 0x05c8 BTHUSB - ok 19:00:31.0031 0x05c8 [ 4F26303BECBB7CC5CA8FF39593124CF2, 2953C2F0F81230B97ABD517F68367A3B787A2F02E780062386EFFF2F22E159BF ] BTNetFilter D:\Programme\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys 19:00:31.0046 0x05c8 BTNetFilter - ok 19:00:31.0062 0x05c8 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k D:\WINDOWS\system32\drivers\cbidf2k.sys 19:00:31.0140 0x05c8 cbidf2k - ok 19:00:31.0140 0x05c8 cd20xrnt - ok 19:00:31.0171 0x05c8 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio D:\WINDOWS\system32\drivers\Cdaudio.sys 19:00:31.0250 0x05c8 Cdaudio - ok 19:00:31.0296 0x05c8 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs D:\WINDOWS\system32\drivers\Cdfs.sys 19:00:31.0375 0x05c8 Cdfs - ok 19:00:31.0375 0x05c8 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom D:\WINDOWS\system32\DRIVERS\cdrom.sys 19:00:31.0468 0x05c8 Cdrom - ok 19:00:31.0468 0x05c8 Changer - ok 19:00:31.0500 0x05c8 [ 28E3040D1F1CA2008CD6B29DFEBC9A5E, ACB458E8A11AA2143734A5A0281973D95158E6402A6453F98F9832D1E19B01F9 ] CiSvc D:\WINDOWS\system32\cisvc.exe 19:00:31.0578 0x05c8 CiSvc - ok 19:00:31.0593 0x05c8 [ 778A30ED3C134EB7E406AFC407E9997D, 3E6AD115AB2596EB001BC21AEADDBC75F27C42DB90C986B7AD17743CE631234E ] ClipSrv D:\WINDOWS\system32\clipsrv.exe 19:00:31.0656 0x05c8 ClipSrv - ok 19:00:31.0656 0x05c8 CmdIde - ok 19:00:31.0671 0x05c8 COMSysApp - ok 19:00:31.0671 0x05c8 Cpqarray - ok 19:00:31.0687 0x05c8 [ 611F824E5C703A5A899F84C5F1699E4D, 9EFA5612FE58E9974E4CC13D39D91D7B5DEA3ED66BEFBED3AAE6D2800FD8162A ] CryptSvc D:\WINDOWS\System32\cryptsvc.dll 19:00:31.0765 0x05c8 CryptSvc - ok 19:00:31.0765 0x05c8 dac2w2k - ok 19:00:31.0765 0x05c8 dac960nt - ok 19:00:31.0828 0x05c8 [ E970C2296916BF4A2F958680016FE312, ED7FA2854D12D82A0E58536702C7DCD89E274677B113B6974AED4B276FAA4DF4 ] DcomLaunch D:\WINDOWS\system32\rpcss.dll 19:00:31.0921 0x05c8 DcomLaunch - ok 19:00:31.0984 0x05c8 [ C29A1C9B75BA38FA37F8C44405DEC360, 7476D8BC4380CDE56764B2034AF3741DA4ED00F315E41C9A02B5EAD04374F241 ] Dhcp D:\WINDOWS\System32\dhcpcsvc.dll 19:00:32.0062 0x05c8 Dhcp - ok 19:00:32.0093 0x05c8 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk D:\WINDOWS\system32\DRIVERS\disk.sys 19:00:32.0171 0x05c8 Disk - ok 19:00:32.0187 0x05c8 dmadmin - ok 19:00:32.0234 0x05c8 [ 0DCFC8395A99FECBB1EF771CEC7FE4EA, 89B0AEE5BE01B9FE4FF2989FF16DB6121721ACDFCE6D9655C0ACD321D8C308BE ] dmboot D:\WINDOWS\system32\drivers\dmboot.sys 19:00:32.0343 0x05c8 dmboot - ok 19:00:32.0359 0x05c8 [ 53720AB12B48719D00E327DA470A619A, 800264866A6267C9000A85D00095D57908D059D737E5F28C9C4049B884C46228 ] dmio D:\WINDOWS\system32\drivers\dmio.sys 19:00:32.0437 0x05c8 dmio - ok 19:00:32.0468 0x05c8 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload D:\WINDOWS\system32\drivers\dmload.sys 19:00:32.0546 0x05c8 dmload - ok 19:00:32.0578 0x05c8 [ 25C83FFBBA13B554EB6D59A9B2E2EE78, 9FBD655ED3E9163AE11EC207F283E387EFBA5A23108EC790BAE4846B35E66F16 ] dmserver D:\WINDOWS\System32\dmserver.dll 19:00:32.0656 0x05c8 dmserver - ok 19:00:32.0687 0x05c8 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic D:\WINDOWS\system32\drivers\DMusic.sys 19:00:32.0765 0x05c8 DMusic - ok 19:00:32.0781 0x05c8 [ 8C9ED3B2834AAE63081AB2DA831C6FE9, 87D2931A5CD3658A28072BEC3F28384B91CC3B19D072CE9C69F119B80671C163 ] Dnscache D:\WINDOWS\System32\dnsrslvr.dll 19:00:32.0859 0x05c8 Dnscache - ok 19:00:32.0906 0x05c8 [ 676E36C4FF5BCEA1900F44182B9723E6, 740CF18BD40E00FEA26CF0E6340C5D18F7D0B4390055FAEEC258B3AA790C4AE9 ] Dot3svc D:\WINDOWS\System32\dot3svc.dll 19:00:32.0984 0x05c8 Dot3svc - ok 19:00:33.0000 0x05c8 dpti2o - ok 19:00:33.0015 0x05c8 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud D:\WINDOWS\system32\drivers\drmkaud.sys 19:00:33.0093 0x05c8 drmkaud - ok 19:00:33.0140 0x05c8 [ 4E4F2FDDAB0A0736D7671134DCCE91FB, 8E2C57D1A006856C47CBDD5765A9DD317DB205B26DA8BFC70555A506257A1CD9 ] EapHost D:\WINDOWS\System32\eapsvc.dll 19:00:33.0718 0x05c8 EapHost - ok 19:00:33.0765 0x05c8 [ 877C18558D70587AA7823A1A308AC96B, 6B336A62112988D855513F45153F73F8470C41A448E9B7438B4A8EC1813AABF1 ] ERSvc D:\WINDOWS\System32\ersvc.dll 19:00:33.0843 0x05c8 ERSvc - ok 19:00:33.0875 0x05c8 [ 4BB6A83640F1D1792AD21CE767B621C6, 7B88A06D5220DE5C378B8C017354E9C8C89D625251A6EB607059A663E2BACD0A ] Eventlog D:\WINDOWS\system32\services.exe 19:00:33.0953 0x05c8 Eventlog - ok 19:00:33.0984 0x05c8 [ 0F3EDAEE1EF97CF3DB2BE23A7289B78C, 8FB19E57429EA5C35C43DADC9C37088A9AD6D039067DA7920DD6A3C9287D0FED ] EventSystem D:\WINDOWS\system32\es.dll 19:00:34.0062 0x05c8 EventSystem - ok 19:00:34.0109 0x05c8 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat D:\WINDOWS\system32\drivers\Fastfat.sys 19:00:34.0187 0x05c8 Fastfat - ok 19:00:34.0234 0x05c8 [ 40602EBFBE06AA075C8E4560743F6883, 808AF03F31CA4168888D0E3802AE4A0DE7F7324F4CD2F8FE491211895C9C6901 ] FastUserSwitchingCompatibility D:\WINDOWS\System32\shsvcs.dll 19:00:34.0312 0x05c8 FastUserSwitchingCompatibility - ok 19:00:34.0328 0x05c8 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc D:\WINDOWS\system32\drivers\Fdc.sys 19:00:34.0390 0x05c8 Fdc - ok 19:00:34.0390 0x05c8 [ B0678A548587C5F1967B0D70BACAD6C1, 7E49910212ED87313F926E4800EA8D34809C287A686CA69B82B79C1A6451F88C ] Fips D:\WINDOWS\system32\drivers\Fips.sys 19:00:34.0468 0x05c8 Fips - ok 19:00:34.0468 0x05c8 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk D:\WINDOWS\system32\drivers\Flpydisk.sys 19:00:34.0546 0x05c8 Flpydisk - ok 19:00:34.0593 0x05c8 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr D:\WINDOWS\system32\drivers\fltmgr.sys 19:00:34.0656 0x05c8 FltMgr - ok 19:00:34.0671 0x05c8 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec D:\WINDOWS\system32\drivers\Fs_Rec.sys 19:00:34.0750 0x05c8 Fs_Rec - ok 19:00:34.0765 0x05c8 [ 8F1955CE42E1484714B542F341647778, 8EB3F99625F409D3032561E8AB44BEFBFBFBA4EC873C2151C92A5CAAF7F2AA55 ] Ftdisk D:\WINDOWS\system32\DRIVERS\ftdisk.sys 19:00:34.0843 0x05c8 Ftdisk - ok 19:00:34.0843 0x05c8 gdrv - ok 19:00:34.0890 0x05c8 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc D:\WINDOWS\system32\DRIVERS\msgpc.sys 19:00:34.0953 0x05c8 Gpc - ok 19:00:34.0984 0x05c8 [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] HDAudBus D:\WINDOWS\system32\DRIVERS\HDAudBus.sys 19:00:35.0062 0x05c8 HDAudBus - ok 19:00:35.0156 0x05c8 [ CB66BF85BF599BEFD6C6A57C2E20357F, 55D3A0F9279FF316766F42548FCB61C452942B08A37590C4892DF110BE4E53C6 ] helpsvc D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 19:00:35.0218 0x05c8 helpsvc - ok 19:00:35.0250 0x05c8 [ B35DA85E60C0103F2E4104532DA2F12B, E13C9F73DF7713554CB614B36123D75014F5121AA1FC9069733E61758751CBE4 ] HidServ D:\WINDOWS\System32\hidserv.dll 19:00:35.0312 0x05c8 HidServ - ok 19:00:35.0343 0x05c8 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] hidusb D:\WINDOWS\system32\DRIVERS\hidusb.sys 19:00:35.0421 0x05c8 hidusb - ok 19:00:35.0468 0x05c8 [ ED29F14101523A6E0E808107405D452C, B8FA987637787BEECC2EB06D36293DAC355523392B49A8C5A9491EEE961917E9 ] hkmsvc D:\WINDOWS\System32\kmsvc.dll 19:00:35.0546 0x05c8 hkmsvc - ok 19:00:35.0546 0x05c8 hpn - ok 19:00:35.0593 0x05c8 [ F6AACF5BCE2893E0C1754AFEB672E5C9, 62A7A70515B5570A649DC30A3A122B1302F6839A63927C8B29EBE04ABA654892 ] HTTP D:\WINDOWS\system32\Drivers\HTTP.sys 19:00:35.0671 0x05c8 HTTP - ok 19:00:35.0703 0x05c8 [ 9E4ADB854CEBCFB81A4B36718FEECD16, 677AB64460775686F8366D6BF35D420A2486C3F07338A00A7C2788A5142B9F08 ] HTTPFilter D:\WINDOWS\System32\w3ssl.dll 19:00:35.0781 0x05c8 HTTPFilter - ok 19:00:35.0781 0x05c8 i2omgmt - ok 19:00:35.0781 0x05c8 i2omp - ok 19:00:35.0828 0x05c8 [ E283B97CFBEB86C1D86BAED5F7846A92, 7664F791D08C80DF1E52B34BE69F073AA645610C4BD975F498254807602374AB ] i8042prt D:\WINDOWS\system32\DRIVERS\i8042prt.sys 19:00:35.0906 0x05c8 i8042prt - ok 19:00:35.0921 0x05c8 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi D:\WINDOWS\system32\DRIVERS\imapi.sys 19:00:36.0000 0x05c8 Imapi - ok 19:00:36.0031 0x05c8 [ D4B413AA210C21E46AEDD2BA5B68D38E, 2309622867AA8FC832A729FA78F48742D4BD6CA0DAFBFB9DDB0772D671E1ED75 ] ImapiService D:\WINDOWS\system32\imapi.exe 19:00:36.0109 0x05c8 ImapiService - ok 19:00:36.0125 0x05c8 ini910u - ok 19:00:36.0312 0x05c8 [ 0C5A04F0FFAEBC25AC815EE14441A8CB, 1A140EFBAC42370180830543F765780508176CAD342541843F54F2B2BCFBD102 ] IntcAzAudAddService D:\WINDOWS\system32\drivers\RtkHDAud.sys 19:00:36.0531 0x05c8 IntcAzAudAddService - ok 19:00:36.0546 0x05c8 IntelIde - ok 19:00:36.0593 0x05c8 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw D:\WINDOWS\system32\drivers\ip6fw.sys 19:00:36.0671 0x05c8 Ip6Fw - ok 19:00:36.0718 0x05c8 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver D:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 19:00:36.0812 0x05c8 IpFilterDriver - ok 19:00:36.0859 0x05c8 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp D:\WINDOWS\system32\DRIVERS\ipinip.sys 19:00:36.0921 0x05c8 IpInIp - ok 19:00:36.0953 0x05c8 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat D:\WINDOWS\system32\DRIVERS\ipnat.sys 19:00:37.0046 0x05c8 IpNat - ok 19:00:37.0062 0x05c8 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec D:\WINDOWS\system32\DRIVERS\ipsec.sys 19:00:37.0140 0x05c8 IPSec - ok 19:00:37.0140 0x05c8 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM D:\WINDOWS\system32\DRIVERS\irenum.sys 19:00:37.0218 0x05c8 IRENUM - ok 19:00:37.0234 0x05c8 [ 6DFB88F64135C525433E87648BDA30DE, 8233EEFBEF36AAA152F2C55D23D7118F0DE40C9C22EB5D9793405A4770889540 ] isapnp D:\WINDOWS\system32\DRIVERS\isapnp.sys 19:00:37.0296 0x05c8 isapnp - ok 19:00:37.0312 0x05c8 [ 1704D8C4C8807B889E43C649B478A452, E854C90CD301F42BE2520CEDAD35E49DF2D43606CF4EEED861B74882118D04D1 ] Kbdclass D:\WINDOWS\system32\DRIVERS\kbdclass.sys 19:00:37.0406 0x05c8 Kbdclass - ok 19:00:37.0421 0x05c8 [ B6D6C117D771C98130497265F26D1882, E79CC4EA5C088F988BA61F80764F9CAD9B78BC56A7E17DD54622C75483BC5DF4 ] kbdhid D:\WINDOWS\system32\DRIVERS\kbdhid.sys 19:00:37.0500 0x05c8 kbdhid - ok 19:00:37.0531 0x05c8 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer D:\WINDOWS\system32\drivers\kmixer.sys 19:00:37.0609 0x05c8 kmixer - ok 19:00:37.0656 0x05c8 [ 1705745D900DABF2D89F90EBADDC7517, FE90589415BDB3BA482D3EBE1A87A7BF1429791E8F18BCB66BF8874631CC8B2C ] KSecDD D:\WINDOWS\system32\drivers\KSecDD.sys 19:00:37.0750 0x05c8 KSecDD - ok 19:00:37.0781 0x05c8 [ D6EB4916B203CBE525F8EFF5FD5AB16C, 93C0F25E7D018B85FE8725EF39F25AED80698D39356FA8FC9CA534F68C430EE8 ] lanmanserver D:\WINDOWS\System32\srvsvc.dll 19:00:37.0859 0x05c8 lanmanserver - ok 19:00:37.0906 0x05c8 [ C0DB1E9367681ECD7ECCA9615C1D0F9B, 0CB18C35032E39163645C1761A9488639D2EF0643D856FDAA013BFF8A69DC744 ] lanmanworkstation D:\WINDOWS\System32\wkssvc.dll 19:00:37.0984 0x05c8 lanmanworkstation - ok 19:00:37.0984 0x05c8 lbrtfdc - ok 19:00:38.0062 0x05c8 [ 9696786759C4B43FA5C894747E893EA2, 4E68CD3A109EF892F09E2A2E7805A53969B512E7F427A09880E2C2082513929F ] LightScribeService D:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe 19:00:38.0062 0x05c8 LightScribeService - detected UnsignedFile.Multi.Generic ( 1 ) 19:00:38.0078 0x05c8 LightScribeService ( UnsignedFile.Multi.Generic ) - warning 19:00:38.0109 0x05c8 [ 636714B7D43C8D0C80449123FD266920, F06F6C7DC49B26EFCAC3570C67BA9BD934F62C6F382DA4DD2AB302C7B970F414 ] LmHosts D:\WINDOWS\System32\lmhsvc.dll 19:00:38.0187 0x05c8 LmHosts - ok 19:00:38.0234 0x05c8 [ D2DED3C333A5D9CB3F4C244B0F0DD877, 5C1D6C2520C24B12AC99B4B1AB8A0C41052B78CEC2E8B52807057B09A03AD81F ] MBAMProtector D:\WINDOWS\system32\drivers\mbam.sys 19:00:38.0234 0x05c8 MBAMProtector - ok 19:00:38.0343 0x05c8 [ 6D8A2EE4244630B290A837E79C0F37A1, 6783BBC0BDC93E4D6D43531A1AD0DF5CD26C3BBFA6384927C5CF65AD97FB04AD ] MBAMScheduler D:\Programme\Malwarebam\mbamscheduler.exe 19:00:38.0390 0x05c8 MBAMScheduler - ok 19:00:38.0484 0x05c8 [ 09D4503CBB6ADB3A54E7C7A75090B728, 6139EA3338FD64205481EDEC813A44F8D395FDA7B67AA431DA61F3631C3EDAE6 ] MBAMService D:\Programme\Malwarebam\mbamservice.exe 19:00:38.0546 0x05c8 MBAMService - ok 19:00:38.0593 0x05c8 [ 8E2E9CCD873ABF180F48BCAEEEBE347D, 35DBBB8E63B480151EA5701D9DB7C90642FA2391D044DB400D3644F3E21BB0C1 ] MBAMSwissArmy D:\WINDOWS\system32\drivers\49F22E28.sys 19:00:38.0609 0x05c8 MBAMSwissArmy - ok 19:00:38.0640 0x05c8 [ B7550A7107281D170CE85524B1488C98, A3854B16A65436BEF6BEDE918B43B3BE8F00D303660DB5831DD376271DC43239 ] Messenger D:\WINDOWS\System32\msgsvc.dll 19:00:38.0703 0x05c8 Messenger - ok 19:00:38.0750 0x05c8 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd D:\WINDOWS\system32\drivers\mnmdd.sys 19:00:38.0828 0x05c8 mnmdd - ok 19:00:38.0875 0x05c8 [ C2F1D365FD96791B037EE504868065D3, 87BD87E08FD00D115524B049F1A3A719AB86557D68968E7090CD0F271F985CAF ] mnmsrvc D:\WINDOWS\system32\mnmsrvc.exe 19:00:38.0953 0x05c8 mnmsrvc - ok 19:00:38.0968 0x05c8 [ 6FB74EBD4EC57A6F1781DE3852CC3362, 0454509D9A31E0202C08AE17294E2682F227D177A3C73B303E4C8332757AFCA1 ] Modem D:\WINDOWS\system32\drivers\Modem.sys 19:00:39.0062 0x05c8 Modem - ok 19:00:39.0140 0x05c8 [ 9FA7207D1B1ADEAD88AE8EED9CDBBAA5, 2AC3875B2E7D9B0692253A9867B940CF214DE03574808B42C3702843BC1D5696 ] Monfilt D:\WINDOWS\system32\drivers\Monfilt.sys 19:00:39.0218 0x05c8 Monfilt - ok 19:00:39.0250 0x05c8 [ B24CE8005DEAB254C0251E15CB71D802, 6804A8ABDAD5EC846E7F8077D1EE9BA45D6226ACFF42C70BE3DE7C8980EF9EC4 ] Mouclass D:\WINDOWS\system32\DRIVERS\mouclass.sys 19:00:39.0328 0x05c8 Mouclass - ok 19:00:39.0343 0x05c8 [ 66A6F73C74E1791464160A7065CE711A, 3C570FA1E8EF976B83759220FE95BAC9D7D48D607F91B113EDE4790D34ACBD46 ] mouhid D:\WINDOWS\system32\DRIVERS\mouhid.sys 19:00:39.0437 0x05c8 mouhid - ok 19:00:39.0437 0x05c8 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr D:\WINDOWS\system32\drivers\MountMgr.sys 19:00:39.0515 0x05c8 MountMgr - ok 19:00:39.0531 0x05c8 MozillaMaintenance - ok 19:00:39.0531 0x05c8 mraid35x - ok 19:00:39.0546 0x05c8 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV D:\WINDOWS\system32\DRIVERS\mrxdav.sys 19:00:39.0609 0x05c8 MRxDAV - ok 19:00:39.0640 0x05c8 [ 68755F0FF16070178B54674FE5B847B0, 2FFBCE3A67FA7E30E373624521C602E5510C5565F04381C6C9F961253DA928A6 ] MRxSmb D:\WINDOWS\system32\DRIVERS\mrxsmb.sys 19:00:39.0718 0x05c8 MRxSmb - ok 19:00:39.0765 0x05c8 [ 35A031AF38C55F92D28AA03EE9F12CC9, 97245D204C886EE8DCCC2DEAC80A0E358A7E0C1982F77389DA50DCF091FC9DDC ] MSDTC D:\WINDOWS\system32\msdtc.exe 19:00:39.0828 0x05c8 MSDTC - ok 19:00:39.0843 0x05c8 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs D:\WINDOWS\system32\drivers\Msfs.sys 19:00:39.0906 0x05c8 Msfs - ok 19:00:39.0906 0x05c8 MSIServer - ok 19:00:39.0937 0x05c8 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV D:\WINDOWS\system32\drivers\MSKSSRV.sys 19:00:40.0015 0x05c8 MSKSSRV - ok 19:00:40.0031 0x05c8 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK D:\WINDOWS\system32\drivers\MSPCLOCK.sys 19:00:40.0093 0x05c8 MSPCLOCK - ok 19:00:40.0109 0x05c8 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM D:\WINDOWS\system32\drivers\MSPQM.sys 19:00:40.0187 0x05c8 MSPQM - ok 19:00:40.0187 0x05c8 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios D:\WINDOWS\system32\DRIVERS\mssmbios.sys 19:00:40.0265 0x05c8 mssmbios - ok 19:00:40.0281 0x05c8 [ 2F625D11385B1A94360BFC70AAEFDEE1, 23E4974120233CF1A7BEE48977706A0A55418699379D1450502ABEB24191AC80 ] Mup D:\WINDOWS\system32\drivers\Mup.sys 19:00:40.0343 0x05c8 Mup - ok 19:00:40.0390 0x05c8 [ 46BB15AE2AC7D025D6D2567B876817BD, 102A101B96D1078C98FA0F871C801A9A8538E20E5686AB0C7680B2F6C92B3165 ] napagent D:\WINDOWS\System32\qagentrt.dll 19:00:40.0484 0x05c8 napagent - ok 19:00:40.0546 0x05c8 NAVENG - ok 19:00:40.0546 0x05c8 NAVEX15 - ok 19:00:40.0578 0x05c8 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS D:\WINDOWS\system32\drivers\NDIS.sys 19:00:40.0656 0x05c8 NDIS - ok 19:00:40.0671 0x05c8 [ 1AB3D00C991AB086E69DB84B6C0ED78F, 1F881FCCF5557C44C078D99CA2DD38D635413D6212DBEDC06A428EDAC7F8B04E ] NdisTapi D:\WINDOWS\system32\DRIVERS\ndistapi.sys 19:00:40.0750 0x05c8 NdisTapi - ok 19:00:40.0765 0x05c8 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio D:\WINDOWS\system32\DRIVERS\ndisuio.sys 19:00:40.0828 0x05c8 Ndisuio - ok 19:00:40.0828 0x05c8 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan D:\WINDOWS\system32\DRIVERS\ndiswan.sys 19:00:40.0937 0x05c8 NdisWan - ok 19:00:40.0953 0x05c8 [ 6215023940CFD3702B46ABC304E1D45A, C767F3A349B365F6E7566C0738E2F62D8FFF8CB4457347E3614BD403BC6CADCB ] NDProxy D:\WINDOWS\system32\drivers\NDProxy.sys 19:00:41.0031 0x05c8 NDProxy - ok 19:00:41.0046 0x05c8 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS D:\WINDOWS\system32\DRIVERS\netbios.sys 19:00:41.0125 0x05c8 NetBIOS - ok 19:00:41.0140 0x05c8 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT D:\WINDOWS\system32\DRIVERS\netbt.sys 19:00:41.0234 0x05c8 NetBT - ok 19:00:41.0265 0x05c8 [ 8ACE4251BFFD09CE75679FE940E996CC, 81969521B5EAEA09ECA63058BE9697BB69AF2596339CA9DF0CFEDC031DCFDC7E ] NetDDE D:\WINDOWS\system32\netdde.exe 19:00:41.0343 0x05c8 NetDDE - ok 19:00:41.0343 0x05c8 [ 8ACE4251BFFD09CE75679FE940E996CC, 81969521B5EAEA09ECA63058BE9697BB69AF2596339CA9DF0CFEDC031DCFDC7E ] NetDDEdsdm D:\WINDOWS\system32\netdde.exe 19:00:41.0421 0x05c8 NetDDEdsdm - ok 19:00:41.0468 0x05c8 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] Netlogon D:\WINDOWS\system32\lsass.exe 19:00:41.0546 0x05c8 Netlogon - ok 19:00:41.0562 0x05c8 [ E6D88F1F6745BF00B57E7855A2AB696C, 12A5EDD853600FF5EBF91E127077745AE1E61E66DBC1D4D4306570F171AF4A39 ] Netman D:\WINDOWS\System32\netman.dll 19:00:41.0640 0x05c8 Netman - ok 19:00:41.0671 0x05c8 [ F12B9D9A069331877D006CC81B4735F9, 28EEE4A21412174BE0CAF7B041DAAB8299AA59EA5F6E41B8AFDD1A4DA770C793 ] Nla D:\WINDOWS\System32\mswsock.dll 19:00:41.0750 0x05c8 Nla - ok 19:00:41.0750 0x05c8 Norton Internet Security - ok 19:00:41.0796 0x05c8 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs D:\WINDOWS\system32\drivers\Npfs.sys 19:00:41.0859 0x05c8 Npfs - ok 19:00:41.0906 0x05c8 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs D:\WINDOWS\system32\drivers\Ntfs.sys 19:00:42.0015 0x05c8 Ntfs - ok 19:00:42.0046 0x05c8 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] NtLmSsp D:\WINDOWS\system32\lsass.exe 19:00:42.0109 0x05c8 NtLmSsp - ok 19:00:42.0171 0x05c8 [ 56AF4064996FA5BAC9C449B1514B4770, 154602EFEC22728503D4ABA025DF711B0F2CFC983F5E3BF25F2A4BCD1AE250EC ] NtmsSvc D:\WINDOWS\system32\ntmssvc.dll 19:00:42.0265 0x05c8 NtmsSvc - ok 19:00:42.0296 0x05c8 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null D:\WINDOWS\system32\drivers\Null.sys 19:00:42.0359 0x05c8 Null - ok 19:00:42.0406 0x05c8 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt D:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 19:00:42.0484 0x05c8 NwlnkFlt - ok 19:00:42.0500 0x05c8 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd D:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 19:00:42.0578 0x05c8 NwlnkFwd - ok 19:00:42.0656 0x05c8 [ 7A56CF3E3F12E8AF599963B16F50FB6A, 882C82BAE96D263138D4C0D6C425458B770B7B9C8E9C1D28AC918BF6BE94A5C2 ] ose D:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE 19:00:42.0656 0x05c8 ose - ok 19:00:42.0703 0x05c8 [ F84785660305B9B903FB3BCA8BA29837, BDBDE61076800415D98759077E9E039C80B55DBE68E31F8BF44A909C6C3D3276 ] Parport D:\WINDOWS\system32\DRIVERS\parport.sys 19:00:42.0781 0x05c8 Parport - ok 19:00:42.0796 0x05c8 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr D:\WINDOWS\system32\drivers\PartMgr.sys 19:00:42.0875 0x05c8 PartMgr - ok 19:00:42.0921 0x05c8 [ C2BF987829099A3EAA2CA6A0A90ECB4F, 1DF21EA8E43875CFEECD869407429F82FB449707CFB845718499468E699BAAAA ] ParVdm D:\WINDOWS\system32\drivers\ParVdm.sys 19:00:43.0000 0x05c8 ParVdm - ok 19:00:43.0000 0x05c8 [ 387E8DEDC343AA2D1EFBC30580273ACD, 5F3E642BDB759777E570ED5B22AC7E93CDCD362708F281657AD7BAB44EDEC802 ] PCI D:\WINDOWS\system32\DRIVERS\pci.sys 19:00:43.0078 0x05c8 PCI - ok 19:00:43.0078 0x05c8 PCIDump - ok 19:00:43.0078 0x05c8 [ 59BA86D9A61CBCF4DF8E598C331F5B82, 822D11C5CE77BFD7B2F25350CCBF92B0B9388EEA6D86ED220B768C720976D839 ] PCIIde D:\WINDOWS\system32\DRIVERS\pciide.sys 19:00:43.0187 0x05c8 PCIIde - ok 19:00:43.0203 0x05c8 [ A2A966B77D61847D61A3051DF87C8C97, 6CED7CA26DC62B0AAFC83A2E07336DAD25954491201BB8E06103971F3F0B8B51 ] Pcmcia D:\WINDOWS\system32\drivers\Pcmcia.sys 19:00:43.0281 0x05c8 Pcmcia - ok 19:00:43.0296 0x05c8 PDCOMP - ok 19:00:43.0296 0x05c8 PDFRAME - ok 19:00:43.0296 0x05c8 PDRELI - ok 19:00:43.0296 0x05c8 PDRFRAME - ok 19:00:43.0312 0x05c8 perc2 - ok 19:00:43.0312 0x05c8 perc2hib - ok 19:00:43.0328 0x05c8 [ 4BB6A83640F1D1792AD21CE767B621C6, 7B88A06D5220DE5C378B8C017354E9C8C89D625251A6EB607059A663E2BACD0A ] PlugPlay D:\WINDOWS\system32\services.exe 19:00:43.0406 0x05c8 PlugPlay - ok 19:00:43.0406 0x05c8 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] PolicyAgent D:\WINDOWS\system32\lsass.exe 19:00:43.0468 0x05c8 PolicyAgent - ok 19:00:43.0515 0x05c8 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport D:\WINDOWS\system32\DRIVERS\raspptp.sys 19:00:43.0593 0x05c8 PptpMiniport - ok 19:00:43.0609 0x05c8 [ 2CB55427C58679F49AD600FCCBA76360, 2B5242E9637FCB6A7C16F720C9D8D440AA88B61FB5F108B295A208886C01C4D1 ] Processor D:\WINDOWS\system32\DRIVERS\processr.sys 19:00:43.0671 0x05c8 Processor - ok 19:00:43.0687 0x05c8 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] ProtectedStorage D:\WINDOWS\system32\lsass.exe 19:00:43.0750 0x05c8 ProtectedStorage - ok 19:00:43.0750 0x05c8 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched D:\WINDOWS\system32\DRIVERS\psched.sys 19:00:43.0828 0x05c8 PSched - ok 19:00:43.0843 0x05c8 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink D:\WINDOWS\system32\DRIVERS\ptilink.sys 19:00:43.0937 0x05c8 Ptilink - ok 19:00:43.0937 0x05c8 ql1080 - ok 19:00:43.0937 0x05c8 Ql10wnt - ok 19:00:43.0937 0x05c8 ql12160 - ok 19:00:43.0953 0x05c8 ql1240 - ok 19:00:43.0953 0x05c8 ql1280 - ok 19:00:43.0968 0x05c8 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd D:\WINDOWS\system32\DRIVERS\rasacd.sys 19:00:44.0046 0x05c8 RasAcd - ok 19:00:44.0093 0x05c8 [ F5BA6CACCDB66C8F048E867563203246, AFEAD8FC02313F7EBC8F9F39E7ED2868852B480BE3902FA7BD0AFD81492AB243 ] RasAuto D:\WINDOWS\System32\rasauto.dll 19:00:44.0171 0x05c8 RasAuto - ok 19:00:44.0218 0x05c8 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp D:\WINDOWS\system32\DRIVERS\rasl2tp.sys 19:00:44.0296 0x05c8 Rasl2tp - ok 19:00:44.0343 0x05c8 [ F9A7B66EA345726EDB5862A46B1ECCD5, 5D35429D394D36A1692A7E219BA1A85CD8096FEAE0F90BFE036A63118FEDBF57 ] RasMan D:\WINDOWS\System32\rasmans.dll 19:00:44.0406 0x05c8 RasMan - ok 19:00:44.0406 0x05c8 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe D:\WINDOWS\system32\DRIVERS\raspppoe.sys 19:00:44.0500 0x05c8 RasPppoe - ok 19:00:44.0500 0x05c8 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti D:\WINDOWS\system32\DRIVERS\raspti.sys 19:00:44.0578 0x05c8 Raspti - ok 19:00:44.0593 0x05c8 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss D:\WINDOWS\system32\DRIVERS\rdbss.sys 19:00:44.0671 0x05c8 Rdbss - ok 19:00:44.0687 0x05c8 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD D:\WINDOWS\system32\DRIVERS\RDPCDD.sys 19:00:44.0781 0x05c8 RDPCDD - ok 19:00:44.0781 0x05c8 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr D:\WINDOWS\system32\DRIVERS\rdpdr.sys 19:00:44.0875 0x05c8 rdpdr - ok 19:00:44.0906 0x05c8 [ 6728E45B66F93C08F11DE2E316FC70DD, EA63ECD4F84CAE08BD2BF843C48AF505B1B9D7B61349A63536C9C6FEBEF23452 ] RDPWD D:\WINDOWS\system32\drivers\RDPWD.sys 19:00:44.0984 0x05c8 RDPWD - ok 19:00:45.0015 0x05c8 [ 263AF18AF0F3DB99F574C95F284CCEC9, 2BFA9952E97EFEB386FC56EC2C125080CD12DAC078DBE43C395CB4D9F22165D3 ] RDSessMgr D:\WINDOWS\system32\sessmgr.exe 19:00:45.0109 0x05c8 RDSessMgr - ok 19:00:45.0156 0x05c8 [ ED761D453856F795A7FE056E42C36365, EF026585B33415D8FCE94A9F27D7A4396C7C35C88E06A4CF0FEA702401E8597A ] redbook D:\WINDOWS\system32\DRIVERS\redbook.sys 19:00:45.0218 0x05c8 redbook - ok 19:00:45.0250 0x05c8 [ 0E97EC96D6942CEEC2D188CC2EB69A01, D4253B4420BEF19451A55AB91E4834482181A31A31134F6E2AFE05C8E20C81A5 ] RemoteAccess D:\WINDOWS\System32\mprdim.dll 19:00:45.0343 0x05c8 RemoteAccess - ok 19:00:45.0390 0x05c8 [ E4CD1F3D84E1C2CA0B8CF7501E201593, 649CC0B04F94D407EB6B4C7FDE2C6E4D2B1531307BC67C5775E44D66EF2E4F8A ] RemoteRegistry D:\WINDOWS\system32\regsvc.dll 19:00:45.0468 0x05c8 RemoteRegistry - ok 19:00:45.0515 0x05c8 [ 851C30DF2807FCFA21E4C681A7D6440E, C2269B8ED4E831664B83F8F3BE33E5A340206A9E07F89CDF6707EAD8F280FBE9 ] RFCOMM D:\WINDOWS\system32\DRIVERS\rfcomm.sys 19:00:45.0578 0x05c8 RFCOMM - ok 19:00:45.0625 0x05c8 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7, CDF10D3D8ADA7ADB1CC1567BFA986557C6D69F4099B70FDFABD4C3D09E3CA778 ] ROOTMODEM D:\WINDOWS\system32\Drivers\RootMdm.sys 19:00:45.0687 0x05c8 ROOTMODEM - ok 19:00:45.0703 0x05c8 [ 2A02E21867497DF20B8FC95631395169, D89E2D17ED4E1C727847C0E92D2DF68AEB70BF0B956BD2FE024ED70A961759D2 ] RpcLocator D:\WINDOWS\system32\locator.exe 19:00:45.0781 0x05c8 RpcLocator - ok 19:00:45.0796 0x05c8 [ E970C2296916BF4A2F958680016FE312, ED7FA2854D12D82A0E58536702C7DCD89E274677B113B6974AED4B276FAA4DF4 ] RpcSs D:\WINDOWS\system32\rpcss.dll 19:00:45.0890 0x05c8 RpcSs - ok 19:00:45.0906 0x05c8 [ 4BDD71B4B521521499DFD14735C4F398, 7B1498D3C67E56D05B58B7DA319ECB0117C37963AABB0E59B42831C087469DA1 ] RSVP D:\WINDOWS\system32\rsvp.exe 19:00:46.0000 0x05c8 RSVP - ok 19:00:46.0156 0x05c8 [ 1674A34F0084BFFDEC2DCDB1625A87F0, 139F0F18779009EBDD72AEFCC8395B0F818A197E7B1D624896D88D7399026281 ] RTHDMIAzAudService D:\WINDOWS\system32\drivers\RtKHDMI.sys 19:00:46.0296 0x05c8 RTHDMIAzAudService - ok 19:00:46.0328 0x05c8 [ 00FD6811350E175585ABCF7D4A61DD90, 00B54CB6547E47E6A2B8AE4BB220E68BBFECF2188CB7DFE651B50F7FE6AC7E9D ] RTLE8023xp D:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 19:00:46.0359 0x05c8 RTLE8023xp - ok 19:00:46.0390 0x05c8 [ AFB8261B56CBA0D86AEB6DF682AF9785, 104D96F1F19DD4CE492064ACC9634406A019EAE20B42D03198E400E661897127 ] SamSs D:\WINDOWS\system32\lsass.exe 19:00:46.0453 0x05c8 SamSs - ok 19:00:46.0484 0x05c8 [ DCEC079FAD95D36C8DD5CB6D779DFE32, F8546552D939A225853A0CE4913701A93738DF02C999D16E141E9A828814BBC6 ] SCardSvr D:\WINDOWS\System32\SCardSvr.exe 19:00:46.0562 0x05c8 SCardSvr - ok 19:00:46.0625 0x05c8 [ A050194A44D7FA8D7186ED2F4E8367AE, BCDF56D5A2F9E202DC67E7FE4BCC617BCC0BDFF2D221A621020068B17B2855BB ] Schedule D:\WINDOWS\system32\schedsvc.dll 19:00:46.0703 0x05c8 Schedule - ok 19:00:46.0734 0x05c8 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv D:\WINDOWS\system32\DRIVERS\secdrv.sys 19:00:46.0796 0x05c8 Secdrv - ok 19:00:46.0828 0x05c8 [ BEE4CFD1D48C23B44CF4B974B0B79B2B, DF3B02D713F8A4602BE75F004074D5DF79AFF2D58FF37110B2A6AC29F680758B ] seclogon D:\WINDOWS\System32\seclogon.dll 19:00:46.0921 0x05c8 seclogon - ok 19:00:46.0921 0x05c8 [ 2AAC9B6ED9EDDFFB721D6452E34D67E3, 95D83F054A6610328D56E56CD948A6618C590231853E56FC20E7557DB61384A4 ] SENS D:\WINDOWS\system32\sens.dll 19:00:46.0984 0x05c8 SENS - ok 19:00:47.0015 0x05c8 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum D:\WINDOWS\system32\DRIVERS\serenum.sys 19:00:47.0078 0x05c8 serenum - ok 19:00:47.0078 0x05c8 [ CF24EB4F0412C82BCD1F4F35A025E31D, B74CB094126F5C23F601C34D53B2DF5BE3E5918230AC9DCFCFFA8E66B3A0FA25 ] Serial D:\WINDOWS\system32\DRIVERS\serial.sys 19:00:47.0156 0x05c8 Serial - ok 19:00:47.0171 0x05c8 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy D:\WINDOWS\system32\drivers\Sfloppy.sys 19:00:47.0250 0x05c8 Sfloppy - ok 19:00:47.0296 0x05c8 [ CAD058D5F8B889A87CA3EB3CF624DCEF, A7CDCF44261D1F4D820927253EA8EBB63714B7BAFF8B08DE073507D9A7EEA5BB ] SharedAccess D:\WINDOWS\System32\ipnathlp.dll 19:00:47.0375 0x05c8 SharedAccess - ok 19:00:47.0406 0x05c8 [ 40602EBFBE06AA075C8E4560743F6883, 808AF03F31CA4168888D0E3802AE4A0DE7F7324F4CD2F8FE491211895C9C6901 ] ShellHWDetection D:\WINDOWS\System32\shsvcs.dll 19:00:47.0468 0x05c8 ShellHWDetection - ok 19:00:47.0468 0x05c8 Simbad - ok 19:00:47.0468 0x05c8 Sparrow - ok 19:00:47.0515 0x05c8 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter D:\WINDOWS\system32\drivers\splitter.sys 19:00:47.0593 0x05c8 splitter - ok 19:00:47.0640 0x05c8 [ 39356A9CDB6753A6D13A4072A9F5A4BB, 7E41478460B0FFE7606F245B74AD60244816F4523FD4355C26BADF724BCE6575 ] Spooler D:\WINDOWS\system32\spoolsv.exe 19:00:47.0718 0x05c8 Spooler - ok 19:00:47.0734 0x05c8 [ 50FA898F8C032796D3B1B9951BB5A90F, 1C86273EC19EB96D6DB9CE6670C00683B77C99C42CC2F7E75BC50872B93446B1 ] sr D:\WINDOWS\system32\DRIVERS\sr.sys 19:00:47.0796 0x05c8 sr - ok 19:00:47.0828 0x05c8 [ FE77A85495065F3AD59C5C65B6C54182, EB4BAF992F961B2FD5D24BFCB6BCB2142BC32933139A818835FEAB190E4283BB ] srservice D:\WINDOWS\system32\srsvc.dll 19:00:47.0906 0x05c8 srservice - ok 19:00:47.0906 0x05c8 SRTSP - ok 19:00:47.0921 0x05c8 SRTSPX - ok 19:00:47.0953 0x05c8 [ 5252605079810904E31C332E241CD59B, 039DD965DE2137219168F95CA3BF1CA7353957026BDD0481F7964E2578DF2128 ] Srv D:\WINDOWS\system32\DRIVERS\srv.sys 19:00:48.0031 0x05c8 Srv - ok 19:00:48.0062 0x05c8 [ 4DF5B05DFAEC29E13E1ED6F6EE12C500, 2971D7D45D6942D310D47DBD19B9680D2D29527E79B86133C72217FD29259465 ] SSDPSRV D:\WINDOWS\System32\ssdpsrv.dll 19:00:48.0125 0x05c8 SSDPSRV - ok 19:00:48.0171 0x05c8 [ BC2C5985611C5356B24AEB370953DED9, 15CBAB8166827DC098E2B16AB6F49A1441A4CB52AF3588F0AD964CAB596DFE10 ] stisvc D:\WINDOWS\system32\wiaservc.dll 19:00:48.0265 0x05c8 stisvc - ok 19:00:48.0296 0x05c8 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum D:\WINDOWS\system32\DRIVERS\swenum.sys 19:00:48.0375 0x05c8 swenum - ok 19:00:48.0390 0x05c8 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi D:\WINDOWS\system32\drivers\swmidi.sys 19:00:48.0468 0x05c8 swmidi - ok 19:00:48.0468 0x05c8 SwPrv - ok 19:00:48.0468 0x05c8 symc810 - ok 19:00:48.0468 0x05c8 symc8xx - ok 19:00:48.0484 0x05c8 sym_hi - ok 19:00:48.0484 0x05c8 sym_u3 - ok 19:00:48.0500 0x05c8 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio D:\WINDOWS\system32\drivers\sysaudio.sys 19:00:48.0578 0x05c8 sysaudio - ok 19:00:48.0625 0x05c8 [ 2903FFFA2523926D6219428040DCE6B9, 4F13181931B0499F6C3F08138054DBCD1F84CB9806999A9172B80DE79D446F62 ] SysmonLog D:\WINDOWS\system32\smlogsvc.exe 19:00:48.0703 0x05c8 SysmonLog - ok 19:00:48.0718 0x05c8 [ 05903CAC4B98908D55EA5774775B382E, AC3666CBD894D737874A5998DC7F46A0A51A7B23B1835FC735B9AD503A2191CC ] TapiSrv D:\WINDOWS\System32\tapisrv.dll 19:00:48.0796 0x05c8 TapiSrv - ok 19:00:48.0843 0x05c8 [ 93EA8D04EC73A85DB02EB8805988F733, 013008E23F5F14E0C836C28524D1181759BAF84530C6331163882A772217F398 ] Tcpip D:\WINDOWS\system32\DRIVERS\tcpip.sys 19:00:48.0921 0x05c8 Tcpip - ok 19:00:48.0953 0x05c8 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE D:\WINDOWS\system32\drivers\TDPIPE.sys 19:00:49.0031 0x05c8 TDPIPE - ok 19:00:49.0031 0x05c8 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP D:\WINDOWS\system32\drivers\TDTCP.sys 19:00:49.0093 0x05c8 TDTCP - ok 19:00:49.0109 0x05c8 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD D:\WINDOWS\system32\DRIVERS\termdd.sys 19:00:49.0187 0x05c8 TermDD - ok 19:00:49.0234 0x05c8 [ B7DE02C863D8F5A005A7BF375375A6A4, 6DE05A7B28CA5A78D58536347FC47F15883EEDBEF487CEA0117CC280FC582DCC ] TermService D:\WINDOWS\System32\termsrv.dll 19:00:49.0312 0x05c8 TermService - ok 19:00:49.0343 0x05c8 [ 40602EBFBE06AA075C8E4560743F6883, 808AF03F31CA4168888D0E3802AE4A0DE7F7324F4CD2F8FE491211895C9C6901 ] Themes D:\WINDOWS\System32\shsvcs.dll 19:00:49.0406 0x05c8 Themes - ok 19:00:49.0437 0x05c8 [ 03681A1CE77F51586903869A5AB1DEAB, E2EC0A481412166B654682C2F3D953E96E757466135CBD2D813B967EDB13C721 ] TlntSvr D:\WINDOWS\system32\tlntsvr.exe 19:00:49.0500 0x05c8 TlntSvr - ok 19:00:49.0515 0x05c8 TosIde - ok 19:00:49.0531 0x05c8 [ 626504572B175867F30F3215C04B3E2F, 47E87CE9BC666D5CB5953C5D497DC00A7CC28F8EC0A064B3E47700279C5C4B91 ] TrkWks D:\WINDOWS\system32\trkwks.dll 19:00:49.0625 0x05c8 TrkWks - ok 19:00:49.0656 0x05c8 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs D:\WINDOWS\system32\drivers\Udfs.sys 19:00:49.0734 0x05c8 Udfs - ok 19:00:49.0734 0x05c8 ultra - ok 19:00:49.0796 0x05c8 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update D:\WINDOWS\system32\DRIVERS\update.sys 19:00:49.0875 0x05c8 Update - ok 19:00:49.0906 0x05c8 [ 1DFD8975D8C89214B98D9387C1125B49, 0B6B268487C8E45E9B86BF4A0A9DB669E0E45D600DE3C82B63F9986CA9E01082 ] upnphost D:\WINDOWS\System32\upnphost.dll 19:00:50.0000 0x05c8 upnphost - ok 19:00:50.0015 0x05c8 [ 9B11E6118958E63E1FEF129466E2BDA7, 97168BCE3F4A9BB9E6500F05E34851FB957B219C598944FADC28AC0011C0503B ] UPS D:\WINDOWS\System32\ups.exe 19:00:50.0093 0x05c8 UPS - ok 19:00:50.0140 0x05c8 [ 173F317CE0DB8E21322E71B7E60A27E8, 7042441BA63AE38AE9D7BE0BC5CA7404FC9EE5BB3F084604A68F01E82769652A ] usbccgp D:\WINDOWS\system32\DRIVERS\usbccgp.sys 19:00:50.0218 0x05c8 usbccgp - ok 19:00:50.0265 0x05c8 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci D:\WINDOWS\system32\DRIVERS\usbehci.sys 19:00:50.0328 0x05c8 usbehci - ok 19:00:50.0343 0x05c8 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub D:\WINDOWS\system32\DRIVERS\usbhub.sys 19:00:50.0421 0x05c8 usbhub - ok 19:00:50.0437 0x05c8 [ 0DAECCE65366EA32B162F85F07C6753B, 3C33AC2FC95E876933F2016CF0CDA2745491679728684DA8DF95A515CE4804BD ] usbohci D:\WINDOWS\system32\DRIVERS\usbohci.sys 19:00:50.0500 0x05c8 usbohci - ok 19:00:50.0546 0x05c8 [ A0B8CF9DEB1184FBDD20784A58FA75D4, D8AFD45BD9CF7B02F2554AA6085194DE82893AF794EDF479BC9B9E9C1758DC75 ] usbscan D:\WINDOWS\system32\DRIVERS\usbscan.sys 19:00:50.0625 0x05c8 usbscan - ok 19:00:50.0671 0x05c8 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] usbstor D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 19:00:50.0734 0x05c8 usbstor - ok 19:00:50.0781 0x05c8 [ 51750B0539986186C6931FC40D171521, 8288954D1393D8D3EEECDF79A73FB82E19B03B67022AFE9C20E99134E6E4C8BF ] VComm D:\WINDOWS\system32\DRIVERS\VComm.sys 19:00:50.0781 0x05c8 VComm - ok 19:00:50.0796 0x05c8 [ 6D9C891C0A761AFED1F3609C2E56F2B9, 53A528AB64CE5567C05194D006F066E8ABA572DCF305A42A5915EFE66A127BDA ] VcommMgr D:\WINDOWS\system32\Drivers\VcommMgr.sys 19:00:50.0796 0x05c8 VcommMgr - ok 19:00:50.0843 0x05c8 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave D:\WINDOWS\System32\drivers\vga.sys 19:00:50.0921 0x05c8 VgaSave - ok 19:00:50.0921 0x05c8 ViaIde - ok 19:00:50.0953 0x05c8 [ A5A712F4E880874A477AF790B5186E1D, FE885ED04C3EAFC379787F836738A2769E43D07CF52DD917D90C38E001957A5E ] VolSnap D:\WINDOWS\system32\drivers\VolSnap.sys 19:00:51.0031 0x05c8 VolSnap - ok 19:00:51.0078 0x05c8 [ 68F106273BE29E7B7EF8266977268E78, 1488AB7A654EBC94C73E1D494067189ACB95BC233980110CAC4C0297CDC4115A ] VSS D:\WINDOWS\System32\vssvc.exe 19:00:51.0171 0x05c8 VSS - ok 19:00:51.0187 0x05c8 [ 7B353059E665F8B7AD2BBEAEF597CF45, 84A4311F18A4B8DCB364741DEA7D18E2363F19564B2EF25214965DC729527068 ] W32Time D:\WINDOWS\system32\w32time.dll 19:00:51.0265 0x05c8 W32Time - ok 19:00:51.0296 0x05c8 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp D:\WINDOWS\system32\DRIVERS\wanarp.sys 19:00:51.0375 0x05c8 Wanarp - ok 19:00:51.0375 0x05c8 WDICA - ok 19:00:51.0390 0x05c8 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud D:\WINDOWS\system32\drivers\wdmaud.sys 19:00:51.0453 0x05c8 wdmaud - ok 19:00:51.0500 0x05c8 [ 81727C9873E3905A2FFC1EBD07265002, 6AC2383A1DCBB7FA3DB90FBB874C8E1819F5B7492717FF41E303EFC7BF72F93E ] WebClient D:\WINDOWS\System32\webclnt.dll 19:00:51.0578 0x05c8 WebClient - ok 19:00:51.0671 0x05c8 [ 6F3F3973D97714CC5F906A19FE883729, 7817118BE94D0F6FAE0F9CE48AD70FFE0AEF886CCE09C666768FAB61047F992F ] winmgmt D:\WINDOWS\system32\wbem\WMIsvc.dll 19:00:51.0750 0x05c8 winmgmt - ok 19:00:51.0796 0x05c8 [ 6E18978B749F0696A774DE3F2CB142DD, 4BBE31A78F6CF474A4CFDBB7C365DE058247F8BFA21F7E563111E84D8937BC26 ] WmdmPmSN D:\WINDOWS\system32\mspmsnsv.dll 19:00:51.0875 0x05c8 WmdmPmSN - ok 19:00:51.0921 0x05c8 [ 53E1CCF332A2F40B5E08476921CD8B44, BBD472701811695EB8BD06CB3DFAF07D2632E1D271B387395455FE9B274CB470 ] Wmi D:\WINDOWS\System32\advapi32.dll 19:00:52.0046 0x05c8 Wmi - ok 19:00:52.0078 0x05c8 [ 93908111BA57A6E60EC2FA2DE202105C, F395F25F18D15C6B9FEDB45FD31E10295FFE5517E2BC86ACAC11904EA0664BE2 ] WmiApSrv D:\WINDOWS\system32\wbem\wmiapsrv.exe 19:00:52.0156 0x05c8 WmiApSrv - ok 19:00:52.0203 0x05c8 [ 6ABE6E225ADB5A751622A9CC3BC19CE8, 4061C5D0F051DFF1730E2A3BFC1CCA97B29602FC50F10F6B44D93B0D28F42024 ] WS2IFSL D:\WINDOWS\System32\drivers\ws2ifsl.sys 19:00:52.0265 0x05c8 WS2IFSL - ok 19:00:52.0312 0x05c8 [ 300B3E84FAF1A5C1F791C159BA28035D, 0194856BDF94C1F274AF70AD558290ACDACDDEA331BD66FEB8E167ABD1E36786 ] wscsvc D:\WINDOWS\system32\wscsvc.dll 19:00:52.0390 0x05c8 wscsvc - ok 19:00:52.0421 0x05c8 [ 7B4FE05202AA6BF9F4DFD0E6A0D8A085, A1DB8909FA73337DB613D01824945485186654364A4DF129B8CB913CF87D1D2E ] wuauserv D:\WINDOWS\system32\wuauserv.dll 19:00:52.0515 0x05c8 wuauserv - ok 19:00:52.0562 0x05c8 [ C4F109C005F6725162D2D12CA751E4A7, AC996B44338328BDD4442FE48406F286A64526F0EC77BE00A19FA7FDB0407CFE ] WZCSVC D:\WINDOWS\System32\wzcsvc.dll 19:00:52.0656 0x05c8 WZCSVC - ok 19:00:52.0718 0x05c8 [ 0ADA34871A2E1CD2CAAFED1237A47750, 45BEF8649078BD74C1A347B5F2D3A1958E5A7DCD6C6BA8A2E0CAD277A929C64E ] xmlprov D:\WINDOWS\System32\xmlprov.dll 19:00:52.0828 0x05c8 xmlprov - ok 19:00:52.0828 0x05c8 ================ Scan global =============================== 19:00:52.0875 0x05c8 [ 2C60091CA5F67C3032EAB3B30390C27F, 9E205C8E67F4B61FCFA2A82AA1968D522C3B6410D7075BE813F7F1564D61632E ] D:\WINDOWS\system32\basesrv.dll 19:00:52.0906 0x05c8 [ 4CD408F799D4A72B0DE1F1116A77A48E, 7EF6B36B63DD010C30AC7B4825E6980C70B18DA4327AB6BC69FBA977E1952992 ] D:\WINDOWS\system32\winsrv.dll 19:00:52.0921 0x05c8 [ 4CD408F799D4A72B0DE1F1116A77A48E, 7EF6B36B63DD010C30AC7B4825E6980C70B18DA4327AB6BC69FBA977E1952992 ] D:\WINDOWS\system32\winsrv.dll 19:00:52.0937 0x05c8 [ 4BB6A83640F1D1792AD21CE767B621C6, 7B88A06D5220DE5C378B8C017354E9C8C89D625251A6EB607059A663E2BACD0A ] D:\WINDOWS\system32\services.exe 19:00:52.0953 0x05c8 [ Global ] - ok 19:00:52.0953 0x05c8 ================ Scan MBR ================================== 19:00:52.0968 0x05c8 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 19:00:53.0140 0x05c8 \Device\Harddisk0\DR0 - ok 19:00:53.0156 0x05c8 [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk1\DR3 19:00:53.0312 0x05c8 \Device\Harddisk1\DR3 - ok 19:00:53.0312 0x05c8 ================ Scan VBR ================================== 19:00:53.0312 0x05c8 [ EEA1061F0EF31F4EDA64FCBE1BD45D45 ] \Device\Harddisk0\DR0\Partition1 19:00:53.0312 0x05c8 \Device\Harddisk0\DR0\Partition1 - ok 19:00:53.0328 0x05c8 [ B4F7B80D6A8D52769E63625C7E1C6299 ] \Device\Harddisk0\DR0\Partition2 19:00:53.0328 0x05c8 \Device\Harddisk0\DR0\Partition2 - ok 19:00:53.0328 0x05c8 [ 6A7D02BEED42A7C411D6FF9B31958F5E ] \Device\Harddisk1\DR3\Partition1 19:00:53.0328 0x05c8 \Device\Harddisk1\DR3\Partition1 - ok 19:00:53.0328 0x05c8 ================ Scan active images ======================== 19:00:53.0328 0x05c8 [ 033448D435E65C4BD72E70521FD05C76, A5462C22D5461F1BA06E81CD7E1ECE5409092DE53A8E4D3E78D089B65CB474D4 ] D:\WINDOWS\system32\drivers\AmdPPM.sys 19:00:53.0328 0x05c8 D:\WINDOWS\system32\drivers\AmdPPM.sys - ok 19:00:53.0328 0x05c8 [ E28726B72C46821A28830E077D39A55B, 66BE8A1055544C8CEBB7125726C1C306A026F3A1764589FCDDF3792076AF891F ] D:\WINDOWS\system32\drivers\videoprt.sys 19:00:53.0328 0x05c8 D:\WINDOWS\system32\drivers\videoprt.sys - ok 19:00:53.0343 0x05c8 [ 15B2FE76E2ECEB98C49ED52311A6F26F, E917AEBD221BF2DB217C111F256033FDA2B28FE55C7E87DAD4A16B84E3FD9398 ] D:\WINDOWS\system32\drivers\ati2mtag.sys 19:00:53.0343 0x05c8 D:\WINDOWS\system32\drivers\ati2mtag.sys - ok 19:00:53.0343 0x05c8 [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] D:\WINDOWS\system32\drivers\hdaudbus.sys 19:00:53.0343 0x05c8 D:\WINDOWS\system32\drivers\hdaudbus.sys - ok 19:00:53.0343 0x05c8 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] D:\WINDOWS\system32\drivers\imapi.sys 19:00:53.0343 0x05c8 D:\WINDOWS\system32\drivers\imapi.sys - ok 19:00:53.0343 0x05c8 [ FE3EA6E9AFC1A78E6EDCA121E006AFB7, B596ABBAC058D93C505C9DBF8685049C88E4364195A4092DB580D2D44FA8C23C ] D:\WINDOWS\system32\drivers\afc.sys 19:00:53.0343 0x05c8 D:\WINDOWS\system32\drivers\afc.sys - ok 19:00:53.0343 0x05c8 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] D:\WINDOWS\system32\drivers\cdrom.sys 19:00:53.0343 0x05c8 D:\WINDOWS\system32\drivers\cdrom.sys - ok 19:00:53.0359 0x05c8 [ 0753515F78DF7F271A5E61C20BCD36A1, A8D600CD0C592DFB875DE2D4F1AEDB207B80A43CF724051B6552BB6E539E9AFC ] D:\WINDOWS\system32\drivers\ks.sys 19:00:53.0359 0x05c8 D:\WINDOWS\system32\drivers\ks.sys - ok 19:00:53.0359 0x05c8 [ ED761D453856F795A7FE056E42C36365, EF026585B33415D8FCE94A9F27D7A4396C7C35C88E06A4CF0FEA702401E8597A ] D:\WINDOWS\system32\drivers\redbook.sys 19:00:53.0359 0x05c8 D:\WINDOWS\system32\drivers\redbook.sys - ok 19:00:53.0359 0x05c8 [ 0DAECCE65366EA32B162F85F07C6753B, 3C33AC2FC95E876933F2016CF0CDA2745491679728684DA8DF95A515CE4804BD ] D:\WINDOWS\system32\drivers\usbohci.sys 19:00:53.0359 0x05c8 D:\WINDOWS\system32\drivers\usbohci.sys - ok 19:00:53.0359 0x05c8 [ 791912E524CC2CC6F50B5F2B52D1EB71, 2B269372E5B39B03089F781CC69AE519D1C840A80ADBE15EA3787FBCDE97F1A8 ] D:\WINDOWS\system32\drivers\usbport.sys 19:00:53.0359 0x05c8 D:\WINDOWS\system32\drivers\usbport.sys - ok 19:00:53.0359 0x05c8 [ F84785660305B9B903FB3BCA8BA29837, BDBDE61076800415D98759077E9E039C80B55DBE68E31F8BF44A909C6C3D3276 ] D:\WINDOWS\system32\drivers\parport.sys 19:00:53.0359 0x05c8 D:\WINDOWS\system32\drivers\parport.sys - ok 19:00:53.0375 0x05c8 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] D:\WINDOWS\system32\drivers\serenum.sys 19:00:53.0375 0x05c8 D:\WINDOWS\system32\drivers\serenum.sys - ok 19:00:53.0375 0x05c8 [ CF24EB4F0412C82BCD1F4F35A025E31D, B74CB094126F5C23F601C34D53B2DF5BE3E5918230AC9DCFCFFA8E66B3A0FA25 ] D:\WINDOWS\system32\drivers\serial.sys 19:00:53.0375 0x05c8 D:\WINDOWS\system32\drivers\serial.sys - ok 19:00:53.0375 0x05c8 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] D:\WINDOWS\system32\drivers\usbehci.sys 19:00:53.0375 0x05c8 D:\WINDOWS\system32\drivers\usbehci.sys - ok 19:00:53.0375 0x05c8 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] D:\WINDOWS\system32\drivers\audstub.sys 19:00:53.0375 0x05c8 D:\WINDOWS\system32\drivers\audstub.sys - ok 19:00:53.0390 0x05c8 [ 852A1BD08E7DFEB9E30B5440881C0501, 92D3F82A29D4466706DA0A30921B4AE5D67F08C2C4EF362EDB1A2D254A5AF068 ] D:\WINDOWS\system32\drivers\blueletaudio.sys 19:00:53.0390 0x05c8 D:\WINDOWS\system32\drivers\blueletaudio.sys - ok 19:00:53.0390 0x05c8 [ 8FC27B12A02B43947787F0EF1885DF9B, 1C0A44406FCD78BB6410140512B2165F974CD1837400A818529E4054A358E7BF ] D:\WINDOWS\system32\drivers\BlueletSCOAudio.sys 19:00:53.0390 0x05c8 D:\WINDOWS\system32\drivers\BlueletSCOAudio.sys - ok 19:00:53.0390 0x05c8 [ 6CB08593487F5701D2D2254E693EAFCE, 0518A1FC540C036E6864DA8C01CADE043D4F897D7FCF8C61352865131DEB7414 ] D:\WINDOWS\system32\drivers\drmk.sys 19:00:53.0390 0x05c8 D:\WINDOWS\system32\drivers\drmk.sys - ok 19:00:53.0390 0x05c8 [ E82A496C3961EFC6828B508C310CE98F, E142A0809525B34A376B3063B07B8822930056BBCB886B7CF1D7585BCEC371A0 ] D:\WINDOWS\system32\drivers\portcls.sys 19:00:53.0390 0x05c8 D:\WINDOWS\system32\drivers\portcls.sys - ok 19:00:53.0390 0x05c8 [ 6D9C891C0A761AFED1F3609C2E56F2B9, 53A528AB64CE5567C05194D006F066E8ABA572DCF305A42A5915EFE66A127BDA ] D:\WINDOWS\system32\drivers\VcommMgr.sys 19:00:53.0390 0x05c8 D:\WINDOWS\system32\drivers\VcommMgr.sys - ok 19:00:53.0406 0x05c8 [ 6FB74EBD4EC57A6F1781DE3852CC3362, 0454509D9A31E0202C08AE17294E2682F227D177A3C73B303E4C8332757AFCA1 ] D:\WINDOWS\system32\drivers\modem.sys 19:00:53.0406 0x05c8 D:\WINDOWS\system32\drivers\modem.sys - ok 19:00:53.0406 0x05c8 [ 1AB3D00C991AB086E69DB84B6C0ED78F, 1F881FCCF5557C44C078D99CA2DD38D635413D6212DBEDC06A428EDAC7F8B04E ] D:\WINDOWS\system32\drivers\ndistapi.sys 19:00:53.0406 0x05c8 D:\WINDOWS\system32\drivers\ndistapi.sys - ok 19:00:53.0406 0x05c8 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] D:\WINDOWS\system32\drivers\ndiswan.sys 19:00:53.0406 0x05c8 D:\WINDOWS\system32\drivers\ndiswan.sys - ok 19:00:53.0406 0x05c8 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] D:\WINDOWS\system32\drivers\rasl2tp.sys 19:00:53.0406 0x05c8 D:\WINDOWS\system32\drivers\rasl2tp.sys - ok 19:00:53.0406 0x05c8 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] D:\WINDOWS\system32\drivers\raspppoe.sys 19:00:53.0406 0x05c8 D:\WINDOWS\system32\drivers\raspppoe.sys - ok 19:00:53.0421 0x05c8 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7, CDF10D3D8ADA7ADB1CC1567BFA986557C6D69F4099B70FDFABD4C3D09E3CA778 ] D:\WINDOWS\system32\drivers\rootmdm.sys 19:00:53.0421 0x05c8 D:\WINDOWS\system32\drivers\rootmdm.sys - ok 19:00:53.0421 0x05c8 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] D:\WINDOWS\system32\drivers\msgpc.sys 19:00:53.0421 0x05c8 D:\WINDOWS\system32\drivers\msgpc.sys - ok 19:00:53.0421 0x05c8 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] D:\WINDOWS\system32\drivers\psched.sys 19:00:53.0421 0x05c8 D:\WINDOWS\system32\drivers\psched.sys - ok 19:00:53.0421 0x05c8 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] D:\WINDOWS\system32\drivers\raspptp.sys 19:00:53.0421 0x05c8 D:\WINDOWS\system32\drivers\raspptp.sys - ok 19:00:53.0437 0x05c8 [ 0539D5E53587F82D1B4FD74C5BE205CF, 9C578FC46AC3B8260258B83C89A33C3D7990B365D7708AEF2296CD235C7D301A ] D:\WINDOWS\system32\drivers\tdi.sys 19:00:53.0437 0x05c8 D:\WINDOWS\system32\drivers\tdi.sys - ok 19:00:53.0437 0x05c8 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] D:\WINDOWS\system32\drivers\ptilink.sys 19:00:53.0437 0x05c8 D:\WINDOWS\system32\drivers\ptilink.sys - ok 19:00:53.0437 0x05c8 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] D:\WINDOWS\system32\drivers\raspti.sys 19:00:53.0437 0x05c8 D:\WINDOWS\system32\drivers\raspti.sys - ok 19:00:53.0437 0x05c8 [ 51750B0539986186C6931FC40D171521, 8288954D1393D8D3EEECDF79A73FB82E19B03B67022AFE9C20E99134E6E4C8BF ] D:\WINDOWS\system32\drivers\VComm.sys 19:00:53.0437 0x05c8 D:\WINDOWS\system32\drivers\VComm.sys - ok 19:00:53.0437 0x05c8 [ 1704D8C4C8807B889E43C649B478A452, E854C90CD301F42BE2520CEDAD35E49DF2D43606CF4EEED861B74882118D04D1 ] D:\WINDOWS\system32\drivers\kbdclass.sys 19:00:53.0437 0x05c8 D:\WINDOWS\system32\drivers\kbdclass.sys - ok 19:00:53.0453 0x05c8 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] D:\WINDOWS\system32\drivers\rdpdr.sys 19:00:53.0453 0x05c8 D:\WINDOWS\system32\drivers\rdpdr.sys - ok 19:00:53.0453 0x05c8 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] D:\WINDOWS\system32\drivers\termdd.sys 19:00:53.0453 0x05c8 D:\WINDOWS\system32\drivers\termdd.sys - ok 19:00:53.0453 0x05c8 [ B24CE8005DEAB254C0251E15CB71D802, 6804A8ABDAD5EC846E7F8077D1EE9BA45D6226ACFF42C70BE3DE7C8980EF9EC4 ] D:\WINDOWS\system32\drivers\mouclass.sys 19:00:53.0453 0x05c8 D:\WINDOWS\system32\drivers\mouclass.sys - ok 19:00:53.0453 0x05c8 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] D:\WINDOWS\system32\drivers\swenum.sys 19:00:53.0453 0x05c8 D:\WINDOWS\system32\drivers\swenum.sys - ok 19:00:53.0453 0x05c8 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] D:\WINDOWS\system32\drivers\update.sys 19:00:53.0453 0x05c8 D:\WINDOWS\system32\drivers\update.sys - ok 19:00:53.0468 0x05c8 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] D:\WINDOWS\system32\drivers\mssmbios.sys 19:00:53.0468 0x05c8 D:\WINDOWS\system32\drivers\mssmbios.sys - ok 19:00:53.0468 0x05c8 [ 6215023940CFD3702B46ABC304E1D45A, C767F3A349B365F6E7566C0738E2F62D8FFF8CB4457347E3614BD403BC6CADCB ] D:\WINDOWS\system32\drivers\ndproxy.sys 19:00:53.0468 0x05c8 D:\WINDOWS\system32\drivers\ndproxy.sys - ok 19:00:53.0468 0x05c8 [ 1674A34F0084BFFDEC2DCDB1625A87F0, 139F0F18779009EBDD72AEFCC8395B0F818A197E7B1D624896D88D7399026281 ] D:\WINDOWS\system32\drivers\RtKHDMI.sys 19:00:53.0468 0x05c8 D:\WINDOWS\system32\drivers\RtKHDMI.sys - ok 19:00:53.0468 0x05c8 [ 596EB39B50D6EBD9B734DC4AE0544693, EFCA2CFFFB8467BAC63F5174F125FEEFFA1F29491285C5BF99B3A2B2A6A25934 ] D:\WINDOWS\system32\drivers\usbd.sys 19:00:53.0468 0x05c8 D:\WINDOWS\system32\drivers\usbd.sys - ok 19:00:53.0484 0x05c8 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] D:\WINDOWS\system32\drivers\usbhub.sys 19:00:53.0484 0x05c8 D:\WINDOWS\system32\drivers\usbhub.sys - ok 19:00:53.0484 0x05c8 [ 0C5A04F0FFAEBC25AC815EE14441A8CB, 1A140EFBAC42370180830543F765780508176CAD342541843F54F2B2BCFBD102 ] D:\WINDOWS\system32\drivers\RtkHDAud.sys 19:00:53.0484 0x05c8 D:\WINDOWS\system32\drivers\RtkHDAud.sys - ok 19:00:53.0484 0x05c8 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] D:\WINDOWS\system32\drivers\fdc.sys 19:00:53.0484 0x05c8 D:\WINDOWS\system32\drivers\fdc.sys - ok 19:00:53.0484 0x05c8 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] D:\WINDOWS\system32\drivers\cdaudio.sys 19:00:53.0484 0x05c8 D:\WINDOWS\system32\drivers\cdaudio.sys - ok 19:00:53.0484 0x05c8 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] D:\WINDOWS\system32\drivers\flpydisk.sys 19:00:53.0484 0x05c8 D:\WINDOWS\system32\drivers\flpydisk.sys - ok 19:00:53.0500 0x05c8 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] D:\WINDOWS\system32\drivers\sfloppy.sys 19:00:53.0500 0x05c8 D:\WINDOWS\system32\drivers\sfloppy.sys - ok 19:00:53.0500 0x05c8 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] D:\WINDOWS\system32\drivers\beep.sys 19:00:53.0500 0x05c8 D:\WINDOWS\system32\drivers\beep.sys - ok 19:00:53.0500 0x05c8 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] D:\WINDOWS\system32\drivers\fs_rec.sys 19:00:53.0500 0x05c8 D:\WINDOWS\system32\drivers\fs_rec.sys - ok 19:00:53.0500 0x05c8 [ 96ECCF28FDBF1B2CC12725818A63628D, 0F25069EE8A44B6F4B18F82F384D404CC1776A2AFC5032D9ED19CE36FF2A61DC ] D:\WINDOWS\system32\drivers\hidparse.sys 19:00:53.0500 0x05c8 D:\WINDOWS\system32\drivers\hidparse.sys - ok 19:00:53.0500 0x05c8 [ E283B97CFBEB86C1D86BAED5F7846A92, 7664F791D08C80DF1E52B34BE69F073AA645610C4BD975F498254807602374AB ] D:\WINDOWS\system32\drivers\i8042prt.sys 19:00:53.0500 0x05c8 D:\WINDOWS\system32\drivers\i8042prt.sys - ok 19:00:53.0515 0x05c8 [ B6D6C117D771C98130497265F26D1882, E79CC4EA5C088F988BA61F80764F9CAD9B78BC56A7E17DD54622C75483BC5DF4 ] D:\WINDOWS\system32\drivers\kbdhid.sys 19:00:53.0515 0x05c8 D:\WINDOWS\system32\drivers\kbdhid.sys - ok 19:00:53.0515 0x05c8 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] D:\WINDOWS\system32\drivers\null.sys 19:00:53.0515 0x05c8 D:\WINDOWS\system32\drivers\null.sys - ok 19:00:53.0515 0x05c8 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] D:\WINDOWS\system32\drivers\vga.sys 19:00:53.0515 0x05c8 D:\WINDOWS\system32\drivers\vga.sys - ok 19:00:53.0515 0x05c8 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] D:\WINDOWS\system32\drivers\mnmdd.sys 19:00:53.0515 0x05c8 D:\WINDOWS\system32\drivers\mnmdd.sys - ok 19:00:53.0515 0x05c8 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] D:\WINDOWS\system32\drivers\msfs.sys 19:00:53.0515 0x05c8 D:\WINDOWS\system32\drivers\msfs.sys - ok 19:00:53.0531 0x05c8 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] D:\WINDOWS\system32\drivers\rdpcdd.sys 19:00:53.0531 0x05c8 D:\WINDOWS\system32\drivers\rdpcdd.sys - ok 19:00:53.0531 0x05c8 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] D:\WINDOWS\system32\drivers\ipsec.sys 19:00:53.0531 0x05c8 D:\WINDOWS\system32\drivers\ipsec.sys - ok 19:00:53.0531 0x05c8 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] D:\WINDOWS\system32\drivers\npfs.sys 19:00:53.0531 0x05c8 D:\WINDOWS\system32\drivers\npfs.sys - ok 19:00:53.0531 0x05c8 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] D:\WINDOWS\system32\drivers\rasacd.sys 19:00:53.0531 0x05c8 D:\WINDOWS\system32\drivers\rasacd.sys - ok 19:00:53.0546 0x05c8 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] D:\WINDOWS\system32\drivers\netbt.sys 19:00:53.0546 0x05c8 D:\WINDOWS\system32\drivers\netbt.sys - ok 19:00:53.0546 0x05c8 [ 93EA8D04EC73A85DB02EB8805988F733, 013008E23F5F14E0C836C28524D1181759BAF84530C6331163882A772217F398 ] D:\WINDOWS\system32\drivers\tcpip.sys 19:00:53.0546 0x05c8 D:\WINDOWS\system32\drivers\tcpip.sys - ok 19:00:53.0546 0x05c8 [ 322D0E36693D6E24A2398BEE62A268CD, FB0BFF5846E50DBCC2826639318A6A1DE79EE7DEA2719ED74A5F6F44454E13D0 ] D:\WINDOWS\system32\drivers\afd.sys 19:00:53.0546 0x05c8 D:\WINDOWS\system32\drivers\afd.sys - ok 19:00:53.0546 0x05c8 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] D:\WINDOWS\system32\drivers\ipnat.sys 19:00:53.0546 0x05c8 D:\WINDOWS\system32\drivers\ipnat.sys - ok 19:00:53.0546 0x05c8 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] D:\WINDOWS\system32\drivers\wanarp.sys 19:00:53.0546 0x05c8 D:\WINDOWS\system32\drivers\wanarp.sys - ok 19:00:53.0562 0x05c8 [ 6ABE6E225ADB5A751622A9CC3BC19CE8, 4061C5D0F051DFF1730E2A3BFC1CCA97B29602FC50F10F6B44D93B0D28F42024 ] D:\WINDOWS\system32\drivers\ws2ifsl.sys 19:00:53.0562 0x05c8 D:\WINDOWS\system32\drivers\ws2ifsl.sys - ok 19:00:53.0562 0x05c8 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] D:\WINDOWS\system32\drivers\netbios.sys 19:00:53.0562 0x05c8 D:\WINDOWS\system32\drivers\netbios.sys - ok 19:00:53.0562 0x05c8 [ 2CB55427C58679F49AD600FCCBA76360, 2B5242E9637FCB6A7C16F720C9D8D440AA88B61FB5F108B295A208886C01C4D1 ] D:\WINDOWS\system32\drivers\processr.sys 19:00:53.0562 0x05c8 D:\WINDOWS\system32\drivers\processr.sys - ok 19:00:53.0562 0x05c8 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] D:\WINDOWS\system32\drivers\rdbss.sys 19:00:53.0562 0x05c8 D:\WINDOWS\system32\drivers\rdbss.sys - ok 19:00:53.0562 0x05c8 [ 68755F0FF16070178B54674FE5B847B0, 2FFBCE3A67FA7E30E373624521C602E5510C5565F04381C6C9F961253DA928A6 ] D:\WINDOWS\system32\drivers\mrxsmb.sys 19:00:53.0562 0x05c8 D:\WINDOWS\system32\drivers\mrxsmb.sys - ok 19:00:53.0578 0x05c8 [ B0678A548587C5F1967B0D70BACAD6C1, 7E49910212ED87313F926E4800EA8D34809C287A686CA69B82B79C1A6451F88C ] D:\WINDOWS\system32\drivers\fips.sys 19:00:53.0578 0x05c8 D:\WINDOWS\system32\drivers\fips.sys - ok 19:00:53.0578 0x05c8 [ 95092EFBE367A108ECDD5D6E439754C3, 82B3041AFC520243B0D1E6DB5FF908771BB0DE86B8FCB1514B2C1E25ADCA95B1 ] D:\WINDOWS\system32\ntdll.dll 19:00:53.0578 0x05c8 D:\WINDOWS\system32\ntdll.dll - ok 19:00:53.0578 0x05c8 [ B3EFDE4B2CC3AC949BCDE7A89712AFCF, EE1A3E5F7324E0169F42683E698B74AA72459BE817E5512BD7319F488E39D3B8 ] D:\WINDOWS\system32\smss.exe 19:00:53.0578 0x05c8 D:\WINDOWS\system32\smss.exe - ok 19:00:53.0578 0x05c8 [ 813DB4805C6EF1D8A86EAF530597EAB7, 445E6ECBA0DB169B52B68CC05ACD3E5F2D69CE6F06FD31667247FC17D24C1EDF ] D:\WINDOWS\system32\autochk.exe 19:00:53.0578 0x05c8 D:\WINDOWS\system32\autochk.exe - ok 19:00:53.0593 0x05c8 [ 5251425B86EA4A3532B8BB8D14044E61, 3A5F57DA2C2B4C1BA5B5B356379D0B12C358EA76642856DD607422B656EF4985 ] D:\WINDOWS\system32\sfcfiles.dll 19:00:53.0593 0x05c8 D:\WINDOWS\system32\sfcfiles.dll - ok 19:00:53.0593 0x05c8 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] D:\WINDOWS\system32\drivers\cdfs.sys 19:00:53.0593 0x05c8 D:\WINDOWS\system32\drivers\cdfs.sys - ok 19:00:53.0593 0x05c8 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] D:\WINDOWS\system32\drivers\usbstor.sys 19:00:53.0593 0x05c8 D:\WINDOWS\system32\drivers\usbstor.sys - ok 19:00:53.0593 0x05c8 [ 1AF592532532A402ED7C060F6954004F, 84A55432A7FBBD1B84FF8DD1BD84266747E4A88297BDAA84AAD12F13B848BFF2 ] D:\WINDOWS\system32\drivers\hidclass.sys 19:00:53.0593 0x05c8 D:\WINDOWS\system32\drivers\hidclass.sys - ok 19:00:53.0593 0x05c8 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] D:\WINDOWS\system32\drivers\hidusb.sys 19:00:53.0593 0x05c8 D:\WINDOWS\system32\drivers\hidusb.sys - ok 19:00:53.0609 0x05c8 [ 173F317CE0DB8E21322E71B7E60A27E8, 7042441BA63AE38AE9D7BE0BC5CA7404FC9EE5BB3F084604A68F01E82769652A ] D:\WINDOWS\system32\drivers\usbccgp.sys 19:00:53.0609 0x05c8 D:\WINDOWS\system32\drivers\usbccgp.sys - ok 19:00:53.0609 0x05c8 [ 66A6F73C74E1791464160A7065CE711A, 3C570FA1E8EF976B83759220FE95BAC9D7D48D607F91B113EDE4790D34ACBD46 ] D:\WINDOWS\system32\drivers\mouhid.sys 19:00:53.0609 0x05c8 D:\WINDOWS\system32\drivers\mouhid.sys - ok 19:00:53.0609 0x05c8 [ FE97D0343ACFDEBDD578FC67CC91FA87, FE26FBA13079189EF96A1C994036EA472A4BF34FA14C163C693AD481BF31E676 ] D:\WINDOWS\system32\drivers\dxapi.sys 19:00:53.0609 0x05c8 D:\WINDOWS\system32\drivers\dxapi.sys - ok 19:00:53.0609 0x05c8 [ 9A10AACBFDC4922715375FB4065EC930, E407953587C04F75DDB163420A5121FF520D31F74753D452E316042C42D360CF ] D:\WINDOWS\system32\watchdog.sys 19:00:53.0609 0x05c8 D:\WINDOWS\system32\watchdog.sys - ok 19:00:53.0625 0x05c8 [ 261BC0644BEFEF7D3DB5E45D244866FA, 8A55EB0C9D849B41A7902BEF94BAD759654AE70ABD5D1A7CFF68AA9A831823B1 ] D:\WINDOWS\system32\win32k.sys 19:00:53.0625 0x05c8 D:\WINDOWS\system32\win32k.sys - ok 19:00:53.0625 0x05c8 [ 2C60091CA5F67C3032EAB3B30390C27F, 9E205C8E67F4B61FCFA2A82AA1968D522C3B6410D7075BE813F7F1564D61632E ] D:\WINDOWS\system32\basesrv.dll 19:00:53.0625 0x05c8 D:\WINDOWS\system32\basesrv.dll - ok 19:00:53.0625 0x05c8 [ D192E1ECA15213F90601FF4DF5683C15, 6AED1CFE6190A12171A97E1BC333E99ECEC891F0E86DE74C32A640025359AA8B ] D:\WINDOWS\system32\csrsrv.dll 19:00:53.0625 0x05c8 D:\WINDOWS\system32\csrsrv.dll - ok 19:00:53.0625 0x05c8 [ 9B22AAE3566AEFEE33CE498DBE0D2FD2, C2AD4DA8DB58BE4DB12FE93451F24D3070C591BB4E8D56FA1505A7CD3BAD6E4D ] D:\WINDOWS\system32\csrss.exe 19:00:53.0625 0x05c8 D:\WINDOWS\system32\csrss.exe - ok 19:00:53.0625 0x05c8 [ 4CD408F799D4A72B0DE1F1116A77A48E, 7EF6B36B63DD010C30AC7B4825E6980C70B18DA4327AB6BC69FBA977E1952992 ] D:\WINDOWS\system32\winsrv.dll 19:00:53.0625 0x05c8 D:\WINDOWS\system32\winsrv.dll - ok 19:00:53.0640 0x05c8 [ ADDA37626598A6F5ED786195EAC26A4F, 5484A37A3E5265DCE0D2AB4C6A3F0D6E7A3F8BD482BCF9E473DA414483AC7861 ] D:\WINDOWS\system32\gdi32.dll 19:00:53.0640 0x05c8 D:\WINDOWS\system32\gdi32.dll - ok 19:00:53.0640 0x05c8 [ 4C897C69754D88F496339B1A666907C1, 39C9F8330E87D81EC3955E8D41218CC0EB1799915A13F3ADCED5A0E4DA596949 ] D:\WINDOWS\system32\kernel32.dll 19:00:53.0640 0x05c8 D:\WINDOWS\system32\kernel32.dll - ok 19:00:53.0640 0x05c8 [ B0050CC5340E3A0760DD8B417FF7AEBD, 340C042C78E55824F2D84D83E03E6C5CA0F44B329245AC2F4C034F2CB4306F53 ] D:\WINDOWS\system32\user32.dll 19:00:53.0640 0x05c8 D:\WINDOWS\system32\user32.dll - ok 19:00:53.0640 0x05c8 [ AC7280566A7BB85CB3291F04DDC1198E, 7640BC4C28B5D5167A10C4B0DA0FC8C7A255334D4BA11FD3E28A697A5B58583C ] D:\WINDOWS\system32\drivers\dxg.sys 19:00:53.0640 0x05c8 D:\WINDOWS\system32\drivers\dxg.sys - ok 19:00:53.0656 0x05c8 [ A73F5D6705B1D820C19B18782E176EFD, C36486504C3A596FDCA487143F6D3B43C0BEE01321F6F1F3071976556533C419 ] D:\WINDOWS\system32\drivers\dxgthk.sys 19:00:53.0656 0x05c8 D:\WINDOWS\system32\drivers\dxgthk.sys - ok 19:00:53.0656 0x05c8 [ A06014D0934F17FA5A567FAEB42118D9, 5F25A45975301B8E8012C8A665814A1D95BD4516E2AEBC8E6588B7264C702B35 ] D:\WINDOWS\system32\ati2dvag.dll 19:00:53.0656 0x05c8 D:\WINDOWS\system32\ati2dvag.dll - ok 19:00:53.0656 0x05c8 [ BEF558BEDEC2B5F2728D0AAE8EDBDC20, 9F14F75A3A0FA608E5CD0CBB98D86627E8287CC55E1F74BA9D0C0C5F9D7BC752 ] D:\WINDOWS\system32\ati2cqag.dll 19:00:53.0656 0x05c8 D:\WINDOWS\system32\ati2cqag.dll - ok 19:00:53.0656 0x05c8 [ 44F99CA575CEEBA6819578C4F170FCAC, 49B1223095F9DF3374C8A80C57D59D2C57F9877AD721259C058DE9233C00A7D0 ] D:\WINDOWS\system32\atikvmag.dll 19:00:53.0656 0x05c8 D:\WINDOWS\system32\atikvmag.dll - ok 19:00:53.0656 0x05c8 [ 95C6B8206B8A55D89CD517675583AA4B, 1ACD1B84C93DE18921AC6B5765FAA9B3577420FCA9047A7BEC6017D4208C3415 ] D:\WINDOWS\system32\vga.dll 19:00:53.0656 0x05c8 D:\WINDOWS\system32\vga.dll - ok 19:00:53.0671 0x05c8 [ E129E32C09F5B2F3A1C61C264691500E, 1B83CDB3243A5BEA468C7A680511EFF6F0D53CDC71151C202C456C002A4EAA58 ] D:\WINDOWS\system32\atiok3x2.dll 19:00:53.0671 0x05c8 D:\WINDOWS\system32\atiok3x2.dll - ok 19:00:53.0671 0x05c8 [ 167395C27BE91BCD950CED197FE7A5E4, D9CB7DE0AC5E4430F270AA3EABCD4BC76EFD521723534F1A19CD252A84C492B9 ] D:\WINDOWS\system32\ati3duag.dll 19:00:53.0671 0x05c8 D:\WINDOWS\system32\ati3duag.dll - ok 19:00:53.0671 0x05c8 [ BC3BBAEC284D360CD37E1E035929C6D8, A3E653103EAC08980A64116561D8A36D53953E69AF5359FFA30499F7C7D0C6E3 ] D:\WINDOWS\system32\ativvaxx.dll 19:00:53.0671 0x05c8 D:\WINDOWS\system32\ativvaxx.dll - ok 19:00:53.0671 0x05c8 [ F09A527B422E25C478E38CAA0E44417A, 8E4D860C5C753B657A1BCB42579556E582CBDAABF07EAE59F81519AC6997ACCB ] D:\WINDOWS\system32\winlogon.exe 19:00:53.0671 0x05c8 D:\WINDOWS\system32\winlogon.exe - ok 19:00:53.0671 0x05c8 [ 53E1CCF332A2F40B5E08476921CD8B44, BBD472701811695EB8BD06CB3DFAF07D2632E1D271B387395455FE9B274CB470 ] D:\WINDOWS\system32\advapi32.dll 19:00:53.0671 0x05c8 D:\WINDOWS\system32\advapi32.dll - ok 19:00:53.0687 0x05c8 [ 8B171E51F5486FC0ACE108BE3E76B1E0, 5FF8172ACB26707FA6689CE6BDFAAA6DF0CEAE9818931496CF39DDE04FBA61FE ] D:\WINDOWS\system32\authz.dll 19:00:53.0687 0x05c8 D:\WINDOWS\system32\authz.dll - ok 19:00:53.0687 0x05c8 [ E7E67C2EE5A306B2AF30D4B446248E34, 7A7818135AC2B4E3512A1488E7808DDCD8426C32024C7C2FBF0C6F0FE305AFF2 ] D:\WINDOWS\system32\rpcrt4.dll 19:00:53.0687 0x05c8 D:\WINDOWS\system32\rpcrt4.dll - ok 19:00:53.0687 0x05c8 [ 7CB4DF6D66F99E6C5E09ADFBE29E0275, 1FBE28BD0A6431DC294EE5EE373205CF858A8991A9FE43C9FB5A6B540EE1ECD7 ] D:\WINDOWS\system32\secur32.dll 19:00:53.0687 0x05c8 D:\WINDOWS\system32\secur32.dll - ok 19:00:53.0687 0x05c8 [ 7727D9C5FFB84E103484D52F978D5DC6, B9E1A1C458B50738F5BEC4C2EEFFCB6E9F0085EA67584936303DCAA9B20C0938 ] D:\WINDOWS\system32\crypt32.dll 19:00:53.0687 0x05c8 D:\WINDOWS\system32\crypt32.dll - ok 19:00:53.0687 0x05c8 [ C6A6E53A0C34EC87883137A6CB87AE5E, AC2BA6B65390258D88B08252037AC77CE7CD0FD7E9CFCC6BB412FF07517A6F63 ] D:\WINDOWS\system32\msvcrt.dll 19:00:53.0687 0x05c8 D:\WINDOWS\system32\msvcrt.dll - ok 19:00:53.0703 0x05c8 [ AE8ACAD9F6931ECC0BD9A3751A0AB0C4, 19E5920E1D98004C957759EE5E3E7E63D01F3696A48F7E6A27BA09E71EBF04E0 ] D:\WINDOWS\system32\msasn1.dll 19:00:53.0703 0x05c8 D:\WINDOWS\system32\msasn1.dll - ok 19:00:53.0703 0x05c8 [ E500CB5F6FE4C1AF388608A54B32E7F7, FF142DEDD4879F41437AC2999AB52F0274682EA3E60B1010D50087ED80E4A0BA ] D:\WINDOWS\system32\nddeapi.dll 19:00:53.0703 0x05c8 D:\WINDOWS\system32\nddeapi.dll - ok 19:00:53.0703 0x05c8 [ 7B40A9A5029111D94AB6B97AF0C9FA5E, C2C20AE04A32657F95AFB47D8F6475B0E471ED9E2172CBBF42D77A13DDAE995F ] D:\WINDOWS\system32\netapi32.dll 19:00:53.0703 0x05c8 D:\WINDOWS\system32\netapi32.dll - ok 19:00:53.0703 0x05c8 [ B50FBE927DA41AB4A151663F59664B82, CED5ECDDAC5A3CAE51543421F85E853DEAA1C519850F2BD5A1BA9C3A3AF849A8 ] D:\WINDOWS\system32\profmap.dll 19:00:53.0703 0x05c8 D:\WINDOWS\system32\profmap.dll - ok 19:00:53.0718 0x05c8 [ 8CB206B85C69B8FB0E7AD1E949BF3194, 8E0F48856A1E59CCFA2A520B8311EBA12299CE4E748F28E81DC2C0462785F2A3 ] D:\WINDOWS\system32\userenv.dll 19:00:53.0718 0x05c8 D:\WINDOWS\system32\userenv.dll - ok 19:00:53.0718 0x05c8 [ D0112D84372AB2C47DC9755696354CE6, 12A66C2C1C96DFD871579E19A318FD371191F4D65A1F3C61339CB9BC4C52656C ] D:\WINDOWS\system32\psapi.dll 19:00:53.0718 0x05c8 D:\WINDOWS\system32\psapi.dll - ok 19:00:53.0718 0x05c8 [ 06C0391672FB97E017B431076F455857, 6E09ABAD4442E294185D9CE215BAAFFA05174C4F5CC364D981C239EAEA9FA2CB ] D:\WINDOWS\system32\regapi.dll 19:00:53.0718 0x05c8 D:\WINDOWS\system32\regapi.dll - ok 19:00:53.0718 0x05c8 [ 5B04BC7C5AF0E2A0A8EC402B2FCBD9E5, 6F0654C8E490149005CCC910909D26167B49A3DBD2F7F551FBF2A94911CCFEA9 ] D:\WINDOWS\system32\setupapi.dll 19:00:53.0718 0x05c8 D:\WINDOWS\system32\setupapi.dll - ok 19:00:53.0718 0x05c8 [ 24EEC6968BF76464609B2C96523976B8, 283E845CF4088C468F12088579277E93C6B35D2DD588A7C16EC1E19142D40FF9 ] D:\WINDOWS\system32\imagehlp.dll 19:00:53.0718 0x05c8 D:\WINDOWS\system32\imagehlp.dll - ok 19:00:53.0734 0x05c8 [ F86000634319F71535BCE6B06995EE99, E88CAA85659500DEE3234571267FFEB557A8FB5155EE7FDE8E0D4D84F62E6CCA ] D:\WINDOWS\system32\version.dll 19:00:53.0734 0x05c8 D:\WINDOWS\system32\version.dll - ok 19:00:53.0734 0x05c8 [ 455AEC2D466FB582D1CB0EF49CE8EDEC, A38530673546363DA970952DE80482DF739BC8EEFFA99D1EA61345C9A59D21DD ] D:\WINDOWS\system32\winsta.dll 19:00:53.0734 0x05c8 D:\WINDOWS\system32\winsta.dll - ok 19:00:53.0734 0x05c8 [ 493A290C0D641E22578129BE23F2CA82, 77C87A214C1F05DE856569A06AE977CC1AEF9647048E8CE185E49644C7E02622 ] D:\WINDOWS\system32\wintrust.dll 19:00:53.0734 0x05c8 D:\WINDOWS\system32\wintrust.dll - ok 19:00:53.0734 0x05c8 [ 3C1708C5C05910FE495D832C6536ED78, 81E86FB3590E786D129EE6F653B32D5114F432AD3321CE7FA60A89D979B89A7D ] D:\WINDOWS\system32\kbdgr.dll 19:00:53.0734 0x05c8 D:\WINDOWS\system32\kbdgr.dll - ok 19:00:53.0734 0x05c8 [ C7D8A0517CBF16B84F657DE87EBE9D4B, B69AAEE7E28375F16C0F2746AFD28C58C7968068C140A2C83838A74A4907F084 ] D:\WINDOWS\system32\ws2help.dll 19:00:53.0734 0x05c8 D:\WINDOWS\system32\ws2help.dll - ok 19:00:53.0750 0x05c8 [ 6A35E2D6F5F052C84EC2CEB296389439, 0349BA3243BC91149D6394F5CB3B114934DA5FBB953A8A59AFA90156029D1163 ] D:\WINDOWS\system32\ws2_32.dll 19:00:53.0750 0x05c8 D:\WINDOWS\system32\ws2_32.dll - ok 19:00:53.0750 0x05c8 [ 56C5B179FE3308B655EB6208C3256FEC, C70BCE54E5DF47D37C835804EAAEC7C06C1A226EFA2003226BE290D1D552126F ] D:\WINDOWS\system32\kbdus.dll 19:00:53.0750 0x05c8 D:\WINDOWS\system32\kbdus.dll - ok 19:00:53.0750 0x05c8 [ BEEB23CAA0A08CBECB13D55C1922C86E, 30F8A3F4785757272E1B8598F0361C27BBE4572932B5DB0D931354C04400B907 ] D:\WINDOWS\system32\msgina.dll 19:00:53.0750 0x05c8 D:\WINDOWS\system32\msgina.dll - ok 19:00:53.0750 0x05c8 [ AD28671D1B83A386B070DC451A113C13, D906178EC646A26AA9B7E82371E6D7347866713A7071EBFEC18B3E04BF7DD570 ] D:\WINDOWS\system32\comctl32.dll 19:00:53.0750 0x05c8 D:\WINDOWS\system32\comctl32.dll - ok 19:00:53.0765 0x05c8 [ 220A7166831EE2B71F07010E70AFA34A, 30D15911013394AE769E645C89CDC5D38BF4C4ABDF88208DFDA96A66A9831C0D ] D:\WINDOWS\system32\odbc32.dll 19:00:53.0765 0x05c8 D:\WINDOWS\system32\odbc32.dll - ok 19:00:53.0765 0x05c8 [ 96E31F7B305D0CD510950B945E2ED829, EC0896B347BD376CB00C52A2403B8227C7259E257E89548663EA8A0C48AA4635 ] D:\WINDOWS\system32\comdlg32.dll 19:00:53.0765 0x05c8 D:\WINDOWS\system32\comdlg32.dll - ok 19:00:53.0765 0x05c8 [ 0721590C8C1E99FB4286F1EEA65731C2, 7B48BE620AA2BB9049C2EBEB06B123F5ED5ECED4E7B3AC84D780B17FDD68114F ] D:\WINDOWS\system32\shell32.dll 19:00:53.0765 0x05c8 D:\WINDOWS\system32\shell32.dll - ok 19:00:53.0765 0x05c8 [ 21F5F91A49CADC4AB873417F54D17D25, DFCC0AEB47DE305ECFCED6349624393ED9C0CA343AD25F3A7E37FA47B75B4F57 ] D:\WINDOWS\system32\shlwapi.dll 19:00:53.0765 0x05c8 D:\WINDOWS\system32\shlwapi.dll - ok 19:00:53.0765 0x05c8 [ 353FC7A3091E25F831439E94082C9B35, 2B40A7EC4BFB6DA4775C70192DD3113B9A87C22054BE3C1BDB2B394F01BE0310 ] D:\WINDOWS\system32\sxs.dll 19:00:53.0765 0x05c8 D:\WINDOWS\system32\sxs.dll - ok 19:00:53.0781 0x05c8 [ 3C93CE6C6985C55952B7BE6673E9FD15, 1F0D2D8F9739063FF5EAFEFB50D20C235E50CCBB924F6B473E8EBAA5C6BA7619 ] D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll 19:00:53.0781 0x05c8 D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll - ok 19:00:53.0781 0x05c8 [ 4E7F74CFC0DBB2DB988A8A460A603407, 30B439F2FDAFD3FC8F5AA3A987F4C2430486F674BFC0FECCA7DC3B6AE342A4E3 ] D:\WINDOWS\system32\odbcint.dll 19:00:53.0781 0x05c8 D:\WINDOWS\system32\odbcint.dll - ok 19:00:53.0781 0x05c8 [ 44161A59DC33AC2EA9C95438ADFFFB7F, 4287C019D707FB601D33779AFA360289EF7775B8E47D438AA3B7ECF68A0D127B ] D:\WINDOWS\system32\sfc.dll 19:00:53.0781 0x05c8 D:\WINDOWS\system32\sfc.dll - ok 19:00:53.0781 0x05c8 [ D110369E8D883029325B77D7E1B7B2AD, 81856C906386D11DAC8044477914FF3E4B79EC8CF5EF85DA4B41E230EF7A3749 ] D:\WINDOWS\system32\sfc_os.dll 19:00:53.0781 0x05c8 D:\WINDOWS\system32\sfc_os.dll - ok 19:00:53.0781 0x05c8 [ 40602EBFBE06AA075C8E4560743F6883, 808AF03F31CA4168888D0E3802AE4A0DE7F7324F4CD2F8FE491211895C9C6901 ] D:\WINDOWS\system32\shsvcs.dll 19:00:53.0781 0x05c8 D:\WINDOWS\system32\shsvcs.dll - ok 19:00:53.0796 0x05c8 [ E08D638BA3D3DD6DF6E31216AB66AE0B, 4CD060A85D194173FA296A56D98D0EFF1C1873C0CE087EA724521D8D97C77BEE ] D:\WINDOWS\system32\ole32.dll [/CODE] |
TDSS zweiter Teil Code: 19:00:53.0796 0x05c8 D:\WINDOWS\system32\ole32.dll - ok Code: 19:07:23.0562 0x0634 TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34 Combofix Logfile: [CODE]ComboFix 14-11-25.01 - Arbeit 30.11.2014 19:39:17.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.1918.1443 [GMT 1:00] ausgeführt von:: d:\dokumente und einstellungen\Arbeit\Desktop\ComboFix.exe . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . d:\dokumente und einstellungen\Internet volker\WINDOWS d:\dokumente und einstellungen\internet\WINDOWS d:\dokumente und einstellungen\ve\WINDOWS d:\windows\IsUn0407.exe d:\windows\system32\DC120fc7_32.dll d:\windows\unin0407.exe . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_SYSHOST32 -------\Service_SYSHOST32 . . ((((((((((((((((((((((( Dateien erstellt von 2014-10-28 bis 2014-11-30 )))))))))))))))))))))))))))))) . . 2014-11-30 18:01 . 2014-11-30 18:01 -------- d-----w- D:\TDSSKiller_Quarantine 2014-11-30 10:31 . 2014-11-30 10:31 114904 ----a-w- d:\windows\system32\drivers\6EDC00ED.sys 2014-11-29 21:18 . 2014-11-29 21:19 -------- d-----w- D:\FRST 2014-11-29 19:29 . 2014-11-29 19:29 114904 ----a-w- d:\windows\system32\drivers\06AF4E76.sys 2014-11-29 18:50 . 2014-11-29 18:50 -------- d-----w- d:\windows\system32\CatRoot_bak 2014-11-29 17:31 . 2014-11-29 17:31 114904 ----a-w- d:\windows\system32\drivers\29F57440.sys 2014-11-29 13:14 . 2014-11-29 13:14 114904 ----a-w- d:\windows\system32\drivers\20342FBD.sys 2014-11-29 13:12 . 2014-11-29 13:12 114904 ----a-w- d:\windows\system32\drivers\49F22E28.sys 2014-11-29 13:12 . 2014-11-29 13:12 -------- d-----w- d:\programme\Malwarebam 2014-11-29 13:12 . 2014-10-01 10:11 54360 ----a-w- d:\windows\system32\drivers\mbamchameleon.sys 2014-11-29 13:12 . 2014-10-01 10:11 23256 ----a-w- d:\windows\system32\drivers\mbam.sys 2014-11-29 10:41 . 2014-11-29 10:41 114904 ----a-w- d:\windows\system32\drivers\113D3A7C.sys 2014-11-29 10:39 . 2014-11-29 10:39 114904 ----a-w- d:\windows\system32\drivers\2CAF392C.sys 2014-11-29 09:52 . 2014-11-29 10:04 114904 ----a-w- d:\windows\system32\drivers\241A155A.sys 2014-11-29 09:49 . 2014-11-29 17:29 -------- d-----w- d:\dokumente und einstellungen\All Users\Anwendungsdaten\Package Cache 2014-11-27 19:19 . 2014-11-27 19:19 110296 ----a-w- d:\windows\system32\drivers\48230029.sys 2014-11-26 18:54 . 2014-11-26 18:54 -------- d-----w- d:\dokumente und einstellungen\Arbeit\Lokale Einstellungen\Anwendungsdaten\WMTools Downloaded Files 2014-11-26 18:34 . 2014-11-26 18:35 -------- d-----w- D:\AdwCleaner 2014-11-13 20:06 . 2014-11-26 18:28 -------- d-----w- D:\Bewerbung 2014-11-13 19:53 . 2014-11-13 19:53 -------- d-----w- d:\dokumente und einstellungen\internet\Lokale Einstellungen\Anwendungsdaten\PDF24 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-09-13 04:49 . 2014-09-13 04:49 1409 ----a-w- d:\windows\system32\tmpE80A8.FOT 2014-09-13 04:49 . 2014-09-13 04:49 1409 ----a-w- d:\windows\system32\tmp120A8.FOT 2007-03-12 17:59 . 2007-03-12 17:59 299008 ----a-w- d:\programme\navigram_register.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-14 06:52 15360 ----a-w- d:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2001-07-09 09:50 155648 ----a-w- d:\windows\system32\NeroCheck.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint] 2014-05-14 08:34 191016 ----a-w- d:\programme\PDF24\pdf24.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SHIWebOnDiskManager] 2014-05-15 14:46 245760 ------r- d:\programme\SHIWebOnDiskManager\SHIWebOnDiskManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "MSIServer"=3 (0x3) "MozillaMaintenance"=3 (0x3) "mnmsrvc"=3 (0x3) "CiSvc"=3 (0x3) "ACDaemon"=3 (0x3) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "d:\\Programme\\Windows Media Player\\wmplayer.exe"= "d:\\Programme\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "d:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"= "d:\\WINDOWS\\system32\\sessmgr.exe"= "d:\\Programme\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 . R0 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\49F22E28.sys [29.11.2014 14:12 114904] R2 MBAMScheduler;MBAMScheduler;d:\programme\Malwarebam\mbamscheduler.exe [29.11.2014 14:12 1871160] R3 MBAMProtector;MBAMProtector;d:\windows\system32\drivers\mbam.sys [29.11.2014 14:12 23256] S2 MBAMService;MBAMService;d:\programme\Malwarebam\mbamservice.exe [29.11.2014 14:12 968504] S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [29.12.2009 21:54 1684736] S4 Norton Internet Security;Norton Internet Security;"d:\programme\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "d:\programme\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1 --> d:\programme\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [?] . . ------- Zusätzlicher Suchlauf ------- . FF - ProfilePath - d:\dokumente und einstellungen\Arbeit\Anwendungsdaten\Mozilla\Firefox\Profiles\2t452zou.default\ FF - prefs.js: browser.startup.homepage - www.google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . SafeBoot-53460251.sys SafeBoot-70922823.sys SafeBoot-72734582.sys AddRemove-ArCon - d:\windows\unin0407.exe AddRemove-Frhed - d:\programme\Frhed\uninst.exe AddRemove-Loewe2 - d:\windows\IsUn0407.exe AddRemove-Loewe4 - d:\windows\IsUn0407.exe AddRemove-MozillaMaintenanceService - d:\programme\Mozilla Maintenance Service\uninstall.exe AddRemove-QuickTime 3.0 - d:\windows\unin0407.exe AddRemove-S3 - d:\windows\IsUn0407.exe AddRemove-Secret Of Six Seas - d:\progra~1\SECRET~1\UNWISE.EXE . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-11-30 20:00 Windows 5.1.2600 Service Pack 3 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security] "ImagePath"="\"d:\programme\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"d:\programme\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1" . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'winlogon.exe'(580) d:\windows\system32\Ati2evxx.dll . - - - - - - - > 'explorer.exe'(2040) d:\windows\system32\msi.dll . ------------------------ Weitere laufende Prozesse ------------------------ . d:\windows\system32\Ati2evxx.exe d:\windows\system32\Ati2evxx.exe d:\programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe d:\windows\system32\wscntfy.exe d:\windows\system32\rundll32.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-11-30 20:01:39 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-11-30 19:01 . Vor Suchlauf: 32 Verzeichnis(se), 140.248.481.792 Bytes frei Nach Suchlauf: 35 Verzeichnis(se), 140.675.706.880 Bytes frei . - - End Of File - - 659632314552B1CFE387B372BED0F767 72B8CE41AF0DE751C946802B3ED844B4 /CODE] Kann ich die Lssrvc.exe beim nächsten Lauf TDSS abschießen lassen oder ist es besser, diese irgendwie zu deinstallieren? Was mache ich falsch mit dem Code-Tag? Mal klappts, mal nicht... Danke. |
Zitat:
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Hauptsächlich, weil ich die Lssrvc gar nicht brauche (hab jetzt erst mal nachgeschaut, was das eigentlich ist). Die läuft dauernd im Taskmanager. Also weg damit. Logs folgen. Mbam und adwcleaner habe ich schon, soll ich das alte mbam Log von letzter Woche auch mal posten? (adwcleaner hatte nichts gefunden). Aber ich lade mir alles noch mal neu und frisch runter und mache die Läufe gleich. Hey, diesmal hab ich nur eine Stunde gebraucht ;) mbam (frisch) Code: Malwarebytes Anti-Malware Code: # AdwCleaner v4.103 - Bericht erstellt am 01/12/2014 um 22:09:48 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ [CODE] FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01 --- --- --- --- --- --- |
Dann deinstalliert man erstmal die Software bevor man einfach nen Dienst killt :) ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Zitat:
Deinstallieren ist zuviel gesagt, ich hab den Task manuell beendet, die Lssrvc.exe (mehr war nicht da) jetzt erst mal in den Papierkorb geschoben (nachdem alle Scans durch waren). Sie kam wohl mit Nero mit, aber ich bezweifle stark, daß mein alter Brenner überhaupt Lightscribe-fähig ist. Nun zu den Logs: Code: ESETSmartInstaller@High as downloader log: Code: Results of screen317's Security Check version 0.99.91 FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01 --- --- --- --- --- --- Zitat:
|
Flash und Firefox updaten. Und unbedingt über ein anderes WIndows nachdenken. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Moin moin, hier das Fixlog. Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-11-2014 01 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:23 Uhr. |
Copyright ©2000-2025, Trojaner-Board