Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner "Trojan.Ransomlock.P" in Archiv.zip (Abrechnung Archiv.scr) (https://www.trojaner-board.de/116754-trojaner-trojan-ransomlock-p-archiv-zip-abrechnung-archiv-scr.html)

derhunne 07.06.2012 15:56

Trojaner "Trojan.Ransomlock.P" in Archiv.zip (Abrechnung Archiv.scr)
 
Liste der Anhänge anzeigen (Anzahl: 1)
Hallo,

ich hatte hier schon an anderer Stelle mein Problem mit einer E-Mail inklusive Virus beschrieben.

GMX lies den Trojaner rein und mein System ist jetzt kaputt.
Weiterleiten kann ich die Email nicht mit dem Anhang verschicken.

__________________________________________________

Antwort von GMX in Kurzform.

Liebes GMX Mitglied,

in einer von Ihnen verschickten E-Mail wurde ein Virus gefunden.

Datei: "Abrechnung Archiv.scr"
Virus: "Trojan.Ransomlock.P"

Die E-Mail wurde nicht an den Empfänger weitergeleitet. Verwenden Sie bitte
einen lokalen Virenscanner, um Ihren PC zu überprüfen.

Es folgen Details zu der betroffenen E-Mail:
....
_________________________________________________

Wie bekomme ich mein System wieder Sauber.

Malwarebytes Anti-Malware und Antivir haben schon einiges Bereinigt. Scheinen allerdings aufgrund der bestehenden Probleme nicht alles gefunden zu haben oder systemspezifische Dateien wurden durch den Trojaner beschädigt.

Gibt es eine Möglichkeit außerhalb der, das System neu zu installeren?

MfG

Der Hunne

cosinus 10.06.2012 01:00

Was sollen diese Screenshots?
Malwarebytes erstellt Logdateien, die wollen wir sehen!

derhunne 10.06.2012 20:11

servus

die habe ich leider nicht mehr :headbang: oder ist das die ??

habe auch OTL.txt und Extras.txt ...hoffe das es jetzt richtig ist ..

lg

habs doch gefunden :headbang:hier
Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.06.02

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Ati :: ATI-PC [Administrator]

Schutz: Aktiviert

06.06.2012 11:07:43
mbam-log-2012-06-06 (11-07-43).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 200935
Laufzeit: 3 Minute(n), 13 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|A0768011 (Trojan.WinLock) -> Daten: C:\Users\Ati\AppData\Roaming\Kpckw\207D6F75A07680114C05.exe -> Löschen bei Neustart.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Users\Ati\AppData\Roaming\Kpckw\207D6F75A07680114C05.exe (Trojan.WinLock) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Ati\AppData\Local\Temp\nnrfctydlp.pre (Trojan.WinLock) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Ati\AppData\Local\Temp\qjjqotoddd.pre (Trojan.WinLock) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Ati\AppData\Local\Temp\vaguguuugu.pre (Trojan.WinLock) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

und hier noch die OTL.txt und Extras.txt :
OTL Logfile:
Code:

OTL logfile created on: 10.06.2012 20:40:10 - Run 1
OTL by OldTimer - Version 3.2.48.0    Folder = C:\Users\Ati\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,74 Gb Total Physical Memory | 1,66 Gb Available Physical Memory | 60,47% Memory free
5,48 Gb Paging File | 3,97 Gb Available in Paging File | 72,47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,97 Gb Total Space | 105,16 Gb Free Space | 23,21% Space Free | Partition Type: NTFS
 
Computer Name: ATI-PC | User Name: Ati | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.10 20:20:06 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Ati\Desktop\OTL.exe
PRC - [2012.05.09 08:16:09 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.09 08:16:09 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.09 08:16:09 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.04.11 01:59:14 | 000,542,552 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.04.02 20:46:58 | 000,329,544 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
PRC - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.11.15 20:26:48 | 000,363,336 | ---- | M] (AnchorFree Inc.) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2010.08.11 03:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010.08.11 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010.08.11 03:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010.07.15 16:05:48 | 000,600,688 | ---- | M] (Chicony) -- C:\Program Files (x86)\Video Web Camera\traybar.exe
PRC - [2010.06.29 00:23:24 | 000,263,936 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010.06.29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010.06.10 04:54:04 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010.03.03 14:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.03.03 14:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2009.09.11 12:34:22 | 002,403,840 | ---- | M] (Vodafone) -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
PRC - [2009.09.11 12:33:54 | 000,009,216 | ---- | M] (Vodafone) -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.05.10 18:53:52 | 000,997,888 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\3f9dee1ce0ccb42145293a5bfcbe7205\System.Management.ni.dll
MOD - [2012.05.10 08:15:05 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\49ed832fa09c702258b6ed873c485428\System.ServiceProcess.ni.dll
MOD - [2012.05.10 08:14:47 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0c00b1a8336dd4c1bd1ebce7780f20b4\System.Runtime.Remoting.ni.dll
MOD - [2012.05.10 08:14:45 | 006,618,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\294d439cfe959b5528ca81d37d3d502f\System.Data.ni.dll
MOD - [2012.05.10 08:14:45 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\61fbbd8bc7d76972115b292b132ff2d1\System.Transactions.ni.dll
MOD - [2012.05.10 08:14:17 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90d42781d5b19478870e412f7b7c71eb\System.Windows.Forms.ni.dll
MOD - [2012.05.10 08:14:09 | 001,590,784 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e65dbd1b68789fc21b9fb3c605b699a7\System.Drawing.ni.dll
MOD - [2012.05.10 08:13:51 | 000,680,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\61af058c2bc079f28397a29ed145fbc7\System.Security.ni.dll
MOD - [2012.05.10 08:13:47 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll
MOD - [2012.05.10 08:13:43 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll
MOD - [2012.05.10 08:13:41 | 007,952,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll
MOD - [2012.05.10 08:13:34 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll
MOD - [2010.10.17 11:48:07 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2010.10.17 11:48:03 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.06.29 00:20:54 | 000,465,576 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2010.06.10 04:54:04 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2009.07.14 03:15:45 | 000,364,544 | ---- | M] () -- C:\Windows\SysWOW64\msjetoledb40.dll
MOD - [2009.06.10 23:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009.06.10 23:23:17 | 002,933,248 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009.05.21 00:02:04 | 000,072,200 | ---- | M] () -- C:\Program Files (x86)\Launch Manager\CdDirIo.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.06.10 17:06:49 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.05 08:47:23 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.09 08:16:09 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.05.09 08:16:09 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.04.11 02:06:10 | 000,077,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService)
SRV - [2012.04.11 01:59:14 | 000,542,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012.04.05 11:37:38 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.04.02 20:46:58 | 000,329,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2011.11.25 16:32:36 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @C:\Program Files (x86)
SRV - [2011.11.15 20:26:48 | 000,363,336 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010.10.17 02:19:05 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.08.11 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010.06.29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010.06.11 14:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2010.04.04 01:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.03 14:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.03.03 14:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.15 23:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009.10.09 05:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009.09.11 12:33:54 | 000,009,216 | ---- | M] (Vodafone) [Auto | Running] -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.05.09 08:16:09 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.09 08:16:09 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.04.11 17:40:28 | 000,056,832 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HssDrv.sys -- (HssDrv)
DRV:64bit: - [2012.04.06 20:15:10 | 000,038,632 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.03.01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.09.16 16:08:07 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.03.11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.06.10 22:57:20 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2010.06.08 04:36:18 | 000,406,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2010.05.12 04:11:38 | 002,229,608 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.04.21 21:18:44 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.02.27 02:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.03 16:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2009.09.18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.09.17 12:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.29 18:00:50 | 000,132,608 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
DRV:64bit: - [2009.06.29 18:00:50 | 000,116,096 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbfake.sys -- (hwusbfake)
DRV:64bit: - [2009.06.20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:64bit: - [2009.06.10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.06 01:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009.05.06 01:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2009.04.09 13:38:24 | 000,116,864 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2008.06.16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_257.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.05 08:47:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.04.20 10:54:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ati\AppData\Roaming\mozilla\Extensions
[2012.06.07 10:36:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\89ooj1zc.default\extensions
[2012.06.07 10:36:10 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\89ooj1zc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.06.06 17:20:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.06.06 17:20:48 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com
[2012.04.20 10:53:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\distribution\extensions
[2012.04.20 10:53:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files (x86)\mozilla firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.06.05 08:47:23 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.04.21 20:00:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.04.21 20:00:08 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.04.21 20:00:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.04.21 20:00:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.04.21 20:00:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.04.21 20:00:08 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKCU..\Run: [Clip2Net] C:\Program Files (x86)\Clip2Net\clip2net.exe ()
O4 - HKCU..\Run: [Vidalia] "C:\Program Files (x86)\Vidalia Bundle\Vidalia\vidalia.exe" File not found
O4 - Startup: C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\G-Recorder.lnk = C:\Program Files (x86)\G-Recorder\G-Recorder.exe ()
O4 - Startup: C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk = C:\Program Files (x86)\MultiSkypeLauncher\MultiSkypeLauncher.exe (IM-history)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseDefaultTile = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideShutdownScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Feed Discovery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Feeds present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\ZOOM present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictCpl = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrivesInSendToMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecycleFiles = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: PreventItemCreationInUsersFilesFolder = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoReadingPane = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPreviewPane = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DontSetAutoplayCheckbox = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyDocuments = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesRecycleBin = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCustomizeWebView = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWinKeys = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSecurityTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableThumbnails = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableThumbnailsOnNetworkFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCustomizeThisFolder = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebView = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DontShowSuperHidden = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoOnlinePrintsWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPublishingWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AlwaysShowClassicMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentProgForNewUserInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserFolderInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchComputerLinkInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchProgramsInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchInternetInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchFilesInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchCommInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuNetworkPlaces = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNtSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceMaxRecentDocs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyGames = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTips = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LockTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAVolume = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCANetwork = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAPower = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCABattery = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoNotification = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTaskGrouping = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoThumbnail = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarLockAll = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoResize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoAddRemoveToolbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoDragToolbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoRedock = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictWelcomeCenter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileUrl = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: SpecifyDefaultButtons = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInplaceSharing = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseFoldersInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TurnOffSPIAnimations = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: PromptRunasInstallNetPath = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceCopyAclwithFile = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartRunNoHOMEPATH = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 0? = amicosinglun64.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 1? = igfxtray.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 2? = hkcmd.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 3? = igfxpers.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 4? = ravcpl64.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 5? = syntpenh.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 6? = plfseti.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 7? = epowertray.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 8? = newlock.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 9? = skype.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 10? = clip2net.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 11? = vidalia.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 12? = multiskypelauncher.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 13? = newadmin.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B1532EC-F43C-48F3-BC4C-65FA159ADE9D}: NameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBF73C85-6F70-47B5-AAA3-449A365CB6B7}: DhcpNameServer = 192.168.11.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1a9068fe-8bd5-11e1-90d5-206a8a1e2a09}\Shell - "" = AutoRun
O33 - MountPoints2\{1a9068fe-8bd5-11e1-90d5-206a8a1e2a09}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{1a906991-8bd5-11e1-90d5-206a8a1e2a09}\Shell - "" = AutoRun
O33 - MountPoints2\{1a906991-8bd5-11e1-90d5-206a8a1e2a09}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{f414f707-8f8c-11e1-be84-206a8a1e2a09}\Shell - "" = AutoRun
O33 - MountPoints2\{f414f707-8f8c-11e1-be84-206a8a1e2a09}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.10 20:20:04 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Ati\Desktop\OTL.exe
[2012.06.10 17:08:00 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Macromedia
[2012.06.07 13:53:13 | 000,000,000 | ---D | C] -- C:\Users\Ati\Desktop\virus.etc
[2012.06.07 10:36:11 | 000,000,000 | ---D | C] -- C:\ProgramData\hssff
[2012.06.06 18:05:52 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MultiSkypeLauncher
[2012.06.06 17:21:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Hotspot Shield
[2012.06.06 17:20:56 | 000,000,000 | ---D | C] -- C:\Hotspot Shield
[2012.06.06 17:20:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
[2012.06.06 17:20:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hotspot Shield
[2012.06.06 13:12:02 | 000,000,000 | ---D | C] -- C:\Users\Ati\Documents\G-Recorder Skype Calls
[2012.06.06 12:44:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\G-Recorder
[2012.06.06 12:44:14 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\G-Recorder
[2012.06.06 12:44:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\G-Recorder
[2012.06.06 11:06:44 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Malwarebytes
[2012.06.06 11:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.06 11:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.06 11:06:37 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.06 11:06:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.06 09:38:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\Desktop\was ist das
[2012.06.06 08:30:12 | 000,000,000 | ---D | C] -- C:\Users\Ati\Desktop\kündigung bestätigung
[2012.06.06 08:19:46 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Kpckw
[2012.06.05 08:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.06.05 08:47:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.05.24 22:03:00 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\gtk-2.0
[2012.05.17 20:21:01 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Diagnostics
[2012.05.15 21:31:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\TP
[2012.05.12 23:57:16 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Nero_AG
[2012.05.12 23:56:52 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Nero
[2012.05.12 23:55:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nero
[2012.05.12 23:41:30 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Nero
[2012.05.12 23:40:07 | 000,000,000 | ---D | C] -- C:\Users\Ati\.gimp-2.6
[2012.05.12 23:40:06 | 000,000,000 | ---D | C] -- C:\Users\Ati\Documents\gegl-0.0
[2012.05.12 23:03:16 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\tor
[2012.05.12 18:25:40 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Canneverbe Limited
[2012.05.12 18:25:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2012.05.12 18:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.10 20:20:06 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Ati\Desktop\OTL.exe
[2012.06.10 20:19:28 | 000,000,000 | ---- | M] () -- C:\Users\Ati\defogger_reenable
[2012.06.10 20:15:35 | 000,050,477 | ---- | M] () -- C:\Users\Ati\Desktop\Defogger.exe
[2012.06.10 19:44:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.10 17:26:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.10 17:14:27 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.10 17:14:27 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.10 17:05:35 | 2205,544,448 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.08 17:05:17 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.08 17:05:17 | 000,654,166 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.08 17:05:17 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.08 17:05:17 | 000,130,006 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.08 17:05:17 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.07 13:06:34 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2012.06.06 18:12:12 | 000,029,285 | ---- | M] () -- C:\Users\Ati\Desktop\multil..jpg
[2012.06.06 18:09:52 | 000,001,143 | ---- | M] () -- C:\Users\Ati\Desktop\MultiSkypeLauncher.lnk
[2012.06.06 18:08:23 | 000,001,083 | ---- | M] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\G-Recorder.lnk
[2012.06.06 18:05:52 | 000,001,201 | ---- | M] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
[2012.06.06 11:06:38 | 000,001,125 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.05 23:54:21 | 000,005,021 | ---- | M] () -- C:\Users\Ati\Desktop\sLQUfNOuJEEgfeloJjnDy
[2012.06.03 01:10:17 | 000,000,007 | ---- | M] () -- C:\Users\Ati\Desktop\TpaQTvJgDXleaTlO
[2012.05.12 18:25:32 | 000,001,754 | ---- | M] () -- C:\Users\Ati\Desktop\CDBurnerXP.lnk
 
========== Files Created - No Company Name ==========
 
[2012.06.10 20:19:28 | 000,000,000 | ---- | C] () -- C:\Users\Ati\defogger_reenable
[2012.06.10 20:15:28 | 000,050,477 | ---- | C] () -- C:\Users\Ati\Desktop\Defogger.exe
[2012.06.06 18:12:12 | 000,029,285 | ---- | C] () -- C:\Users\Ati\Desktop\multil..jpg
[2012.06.06 18:05:52 | 000,001,201 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
[2012.06.06 18:05:52 | 000,001,143 | ---- | C] () -- C:\Users\Ati\Desktop\MultiSkypeLauncher.lnk
[2012.06.06 12:44:14 | 000,001,083 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\G-Recorder.lnk
[2012.06.06 11:06:38 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.06 08:29:38 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2012.05.12 18:25:32 | 000,001,754 | ---- | C] () -- C:\Users\Ati\Desktop\CDBurnerXP.lnk
[2012.05.12 18:25:32 | 000,001,704 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2010.10.17 11:40:27 | 000,000,267 | ---- | C] () -- C:\Windows\LaunApp.ini
[2010.10.17 11:38:41 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.10.17 11:38:41 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010.10.17 11:38:41 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010.10.17 11:38:41 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010.10.17 11:38:40 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.10.17 11:38:17 | 000,001,652 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2010.10.17 02:03:28 | 000,206,208 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2010.10.17 02:03:28 | 000,000,302 | ---- | C] () -- C:\Windows\PidList_C.ini
[2010.09.08 05:16:07 | 000,000,325 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2010.09.08 05:16:07 | 000,000,271 | ---- | C] () -- C:\Windows\WisPriority.ini
[2010.09.08 05:16:07 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini
 
========== LOP Check ==========
 
[2012.06.07 21:57:16 | 000,032,568 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---


Extras.txt::OTL Logfile:
Code:

OTL Extras logfile created on: 10.06.2012 20:40:10 - Run 1
OTL by OldTimer - Version 3.2.48.0    Folder = C:\Users\Ati\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,74 Gb Total Physical Memory | 1,66 Gb Available Physical Memory | 60,47% Memory free
5,48 Gb Paging File | 3,97 Gb Available in Paging File | 72,47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452,97 Gb Total Space | 105,16 Gb Free Space | 23,21% Space Free | Partition Type: NTFS
 
Computer Name: ATI-PC | User Name: Ati | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2EB36017-80B6-4853-8219-78DBE940770D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{32248897-9DE3-4846-8BD5-5B69212169A3}" = lport=138 | protocol=17 | dir=in | app=system |
"{38328399-66F1-40CE-B17A-35CDF5161FCB}" = rport=139 | protocol=6 | dir=out | app=system |
"{3912CF38-E28C-4CE3-B787-6B7185957E2F}" = rport=137 | protocol=17 | dir=out | app=system |
"{3F2FA377-A3A0-46B0-9D82-6AC411C307CA}" = rport=445 | protocol=6 | dir=out | app=system |
"{41A351A1-359F-425C-B465-B320A089F517}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{45040460-050B-4989-BA8A-51CF7BE0F1C8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50C4029F-3D71-47FB-8C72-F758DF01CC74}" = lport=137 | protocol=17 | dir=in | app=system |
"{5A9D50D8-0A8F-42E0-AAC9-15A1E86A8874}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5E132222-F179-421F-9A56-A4363AD9498E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{637C9898-5232-43DB-88DC-6646A968CE93}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6BB1AB4C-D6C1-43BD-8892-67745F9213FB}" = lport=139 | protocol=6 | dir=in | app=system |
"{7CE1065E-AF11-4547-95EB-79860EE42F83}" = lport=10243 | protocol=6 | dir=in | app=system |
"{879E37C1-3F87-4FF7-9744-D6C52035855A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{975D1F75-E713-4D4C-904E-D3662EB5DA11}" = rport=138 | protocol=17 | dir=out | app=system |
"{9F45A7C4-0D24-4678-9DF2-7AD81433315E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9F68252C-1969-4A7B-B187-6328DAA4A208}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AE158122-7A00-43C1-B270-3C23740BE927}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B98E25C0-A509-4395-9C72-293AD464E9D3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{BBC77C1E-636D-4F54-A165-4070D96CE464}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C05A1FE9-4B67-457F-B4A7-CED7A65E3CD5}" = lport=445 | protocol=6 | dir=in | app=system |
"{E9B9FC7D-21F1-4194-8010-68EB13619E31}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{ED81152C-38ED-4CEB-992A-A2E200626900}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003220FE-E69D-42E9-A150-C68A9FCF75FC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{05A9E43A-9758-46AC-86BB-5D81525344D7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{05B77E67-7D76-4739-9361-4F8635416DE7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{06ABFD2D-F80B-426E-B171-A0F93097E1CD}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{095B829F-B414-4F8A-970D-35AE55EF7CC6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B3DED8D-811E-436E-8437-C4CF3774C1D3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{117D1520-2CAE-4F90-B675-D86FE604882D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{20DC2628-66FC-4DA4-9EF0-B9163D70BEA1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4E9DCFA9-58A5-4332-B670-FFB2B61BA84A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5CA0C6B9-5F80-432B-A834-C00E06255A59}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{5F30C93A-7689-4FB0-BC26-F9D2E4AE9E31}" = protocol=6 | dir=out | app=system |
"{62FFA435-7850-4355-9078-41577F6CEB0D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{6ECE97AA-0B19-4F42-957A-7BB3A4A82B3A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{783797B3-0884-4474-944C-56A5D2550C6E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{82825E6E-E4FD-481D-82DB-4ECEF4482ACB}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{86FFC6C3-040C-4A78-AAA7-8F03B4B6B882}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{99540CFE-0836-47E4-B877-30FFACC272D4}" = protocol=17 | dir=in | app=c:\users\ati\appdata\local\temp\7zs74f2.tmp\symnrt.exe |
"{A9638747-157E-40E1-8FFD-7A3246803887}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B25B3645-E1B4-453E-B42F-F0C4BDEFFE72}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B7CFA353-ABCE-4117-B2A9-D269CC0F3C19}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{BBE63EDF-3668-4BB6-9B81-FA5EE5C0247D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CE9110D8-BA5E-4801-AD01-7FC4D0C929B6}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{E3B3365A-E745-4C05-BF6D-4930210A233E}" = protocol=6 | dir=in | app=c:\users\ati\appdata\local\temp\7zs74f2.tmp\symnrt.exe |
"{E3B5222C-3079-45DB-8BF4-91615BF82921}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FEEBA12C-8F48-4878-A830-563853428493}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{DE85A005-EEBE-420A-AF6E-9190498AB47F}C:\users\ati\ati alles\programme\teamviewer\version7\teamviewer.exe" = protocol=6 | dir=in | app=c:\users\ati\ati alles\programme\teamviewer\version7\teamviewer.exe |
"UDP Query User{E724382C-BABD-4D90-A912-5DB6AB614ACD}C:\users\ati\ati alles\programme\teamviewer\version7\teamviewer.exe" = protocol=17 | dir=in | app=c:\users\ati\ati alles\programme\teamviewer\version7\teamviewer.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"SynTPDeinstKey" = Synaptics Pointing Device Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{12A1B519-5934-4508-ADBD-335347B0DC87}" = Video Web Camera
"{16337ff7-9fb9-4476-837b-acc962fc4bc5}" = Nero 9 Essentials
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{20F71B17-008C-43B4-8097-58FB62EA7AB8}" = Nero Kwik Media
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Packard Bell Power Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5A212B2D-140D-46F4-B625-2D1CA5A00594}" = Nero 11 Kwik Themes Basic
"{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}" = Vodafone Mobile Connect Lite
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}" = Nero Kwik Media Help (CHM)
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BE814218-3919-4EA3-868A-2F60BC135CB4}" = Nero Kwik Media
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Avira AntiVir Desktop" = Avira Free Antivirus
"Clip2Net_is1" = Clip2Net 0.9.2b
"G-Recorder" = G-Recorder (remove only)
"HotspotShield" = Hotspot Shield 2.53
"Identity Card" = Identity Card
"InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Packard Bell MyBackup
"InstallShield_{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Mozilla Firefox 12.0 (x86 de)" = Mozilla Firefox 12.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MultiSkypeLauncher" = MultiSkypeLauncher (remove only)
"Packard Bell Game Console" = Packard Bell Game Console
"Packard Bell InfoCentre" = Packard Bell InfoCentre
"Packard Bell Registration" = Packard Bell Registration
"Packard Bell Screensaver" = Packard Bell ScreenSaver
"Packard Bell Welcome Center" = Welcome Center
"WildTangent packardbell Master Uninstall" = Packard Bell Games
"WinGimp-2.0_is1" = GIMP 2.6.12
"WinLiveSuite_Wave3" = Windows Live Essentials
"WT088216" = Agatha Christie - Death on the Nile
"WT088226" = Bejeweled 2 Deluxe
"WT088228" = Build-a-lot 2
"WT088235" = Chuzzle Deluxe
"WT088238" = Diner Dash 2 Restaurant Rescue
"WT088260" = Farm Frenzy
"WT088268" = Insaniquarium Deluxe
"WT088269" = Jewel Quest Solitaire 2
"WT088283" = Plants vs. Zombies
"WT088292" = Zuma Deluxe
"WT088416" = FATE
"WT088420" = Final Drive Nitro
"WT088448" = John Deere Drive Green
"WT088452" = Penguins!
"WT088456" = Polar Bowler
"WT088460" = Polar Golfer
"WT088508" = Virtual Villagers 4 - The Tree of Life
"WT088531" = Zuma's Revenge
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 07.06.2012 15:57:54 | Computer Name = Ati-PC | Source = MsiInstaller | ID = 10005
Description =
 
Error - 08.06.2012 01:32:15 | Computer Name = Ati-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
 
Error - 08.06.2012 02:03:52 | Computer Name = Ati-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 08.06.2012 03:42:03 | Computer Name = Ati-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =
 
Error - 08.06.2012 04:32:02 | Computer Name = Ati-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =
 
Error - 08.06.2012 08:50:27 | Computer Name = Ati-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
 
Error - 08.06.2012 08:51:36 | Computer Name = Ati-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 08.06.2012 11:05:47 | Computer Name = Ati-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "H:\Musik von
Ati\programme\windows\SoftonicDownloader_fuer_windows-xp-service-pack.exe". Fehler
 in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
 
Error - 08.06.2012 11:05:47 | Computer Name = Ati-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "H:\Musik von
Ati\programme\windows\SoftonicDownloader_fuer_windows-xp-service-pack(1).exe". Fehler
 in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
 
Error - 09.06.2012 07:16:55 | Computer Name = Ati-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
 
[ System Events ]
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 09:01:42 | Computer Name = Ati-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 08.06.2012 14:37:56 | Computer Name = Ati-PC | Source = bowser | ID = 8003
Description =
 
Error - 08.06.2012 15:12:20 | Computer Name = Ati-PC | Source = bowser | ID = 8003
Description =
 
Error - 09.06.2012 13:27:07 | Computer Name = Ati-PC | Source = DCOM | ID = 10010
Description =
 
 
< End of report >

--- --- ---



will euch wirklich nicht ärgern ...bin einfach nur ein anfänger :(

cosinus 10.06.2012 20:48

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

derhunne 10.06.2012 20:58

ok ...werde alles schritte nach einander machen ...denk ca.1.5h dauert der voll scann ...habe nur den Quick gemacht gehabt weil das irgendwo im theard so stand ...hab ja versucht selber schlau zu machen ...leider weis ich nicht ob ich wiklich alles weg hab oder nicht ....also wenn alles fertig ist poste ich es hier ...dank erstmal

lg

p.s. andere log. ja nur ohne befunde ...die sind alle nach der säuberung

moinmoin ,

so hier die logs von eset online scann und Malwarebytes Anti-Malware
Code:

  ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=9e5c2144e94d6845a4ef659f8d51b66c
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-11 12:47:28
# local_time=2012-06-11 02:47:28 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 4455083 4455083 0 0
# compatibility_mode=5893 16776573 100 94 124979 90995879 0 0
# compatibility_mode=8192 67108863 100 0 202 202 0 0
# scanned=169698
# found=9
# cleaned=9
# scan_time=9618
C:\ProgramData\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll        a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\AppData\Local\Temp\YontooSetup-Silent.exe        Win32/Adware.Yontoo application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\AppData\Local\Temp\ICReinstall\cnet2_G-Recorder-Basic-setup_exe.exe        a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\AppData\Local\Temp\ICReinstall\cnet2_MultiSkypeLauncher_setup_exe(1).exe        a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\AppData\Local\Temp\ICReinstall\cnet2_MultiSkypeLauncher_setup_exe.exe        a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\ati alles\programme\FoxTab Audio Converter\AudioConverter.exe        a variant of Win32/InstallCore.A application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\Downloads\cnet2_G-Recorder-Basic-setup_exe.exe        a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\Downloads\cnet2_MultiSkypeLauncher_setup_exe(1).exe        a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C
C:\Users\Ati\Downloads\cnet2_MultiSkypeLauncher_setup_exe.exe        a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)        00000000000000000000000000000000        C


cosinus 11.06.2012 08:46

Das Log vom Vollscan mit Malwarebytes fehlt leider noch.

derhunne 12.06.2012 07:21

Zitat:

Zitat von cosinus (Beitrag 844006)
Das Log vom Vollscan mit Malwarebytes fehlt leider noch.

uppsss :pfeiff: hier kommt sie ...nur da is eh nix mehr zusehen ....

Code:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.10.08

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Ati :: ATI-PC [Administrator]

Schutz: Aktiviert

10.06.2012 21:59:45
mbam-log-2012-06-10 (21-59-45).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 349558
Laufzeit: 1 Stunde(n), 18 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

p.s für entschlüsselung von txt.und pdf.datein sollte ich bestimmt nen neuen thread auf machen oder ?

lg

cosinus 12.06.2012 13:43

Zitat:

p.s für entschlüsselung von txt.und pdf.datein sollte ich bestimmt nen neuen thread auf machen oder ?
Nein. Einfach mal hier die Hinweise beachten!

Hinweise bzgl. der verschlüsselten Dateien:
Wann genau deine Daten entschlüsselt werden können wird dir niemand genau sagen können außer vllt einer :glaskugel: es kann sein, dass du eine neuere Variante hast, deren Verschlüsselungsalgorithmus noch unbekannt ist. Sowas kann man (noch) nicht entschlüsseln und ohne Schlüssel schon garnicht - ist ja auch logisch, sonst wär es ja keine vernünftige Verschlüsselung
Einfach hier nochmal reinsehen in regelmäßigen Abständen, obige Hinweise beachten. 8 Tools mitsamt hunderten Diskussionsbeiträgen stehen da schon

Eine Notlösung für Vista und Win7-User => http://www.trojaner-board.de/115496-...erstellen.html

Entschlüsselungsversuche der verschlüsselten Dateien sind nur auf zusätzliche Kopien der verschlüsselten Dateien anzuwenden, sonst zerhackt man sich die noch weiter ohne die "original" verschlüsselte Datei mehr zu haben. Das willst du sicher nicht!

Man darf sich aber keine falschen Hoffnungen machen. Mittlerweile sieht es finster aus => Delphi-PRAXiS - Einzelnen Beitrag anzeigen - Verschlüsselungs-Trojaner, Hilfe benötigt


Und in Zukunft willst du sicher mal an ein besseres Backupkonzept denken. Hier ein Denkanstoß => http://www.trojaner-board.de/115678-...r-backups.html


Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

derhunne 12.06.2012 21:42

moinsen ,

Backup :pfeiff: ...werde ich machen ...mit den daten ...mal schauen wie weit ich da komme ...die wichtigsten habe ich gott sei danke aufen anderen rechner noch und auf ner externen..mit dem nach lesen bin ich fleissig denke ich ...nur ich vertiefe mich den in andere themen ...wie kann ich den diese zip datei an euch senden damit ihr selber schauen könnt ...per mail bekomme ich sie nicht raus ...sage schonmal :dankeschoen:

Zitat:

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
zu1 .in pinzip ja ...bin mir nur nicht sicher ob halt alles wieder ok ist
zu2 .ausser der datein nein bis auf das ein programm wenn ich den lappy starte immer ein fehler meldung zeigt obwohl ich es wieder neu insterliert habe

cosinus 12.06.2012 22:38

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


derhunne 13.06.2012 19:22

servus,
hier die logfile....bin gespannt was raus kommt ...

lg der hunne


OTL Logfile:
Code:

OTL logfile created on: 13.06.2012 20:03:15 - Run 1
OTL by OldTimer - Version 3.2.48.0    Folder = C:\Users\Ati\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,74 Gb Total Physical Memory | 1,34 Gb Available Physical Memory | 48,93% Memory free
5,48 Gb Paging File | 3,88 Gb Available in Paging File | 70,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,46 Gb Total Space | 97,92 Gb Free Space | 80,62% Space Free | Partition Type: NTFS
Drive E: | 165,75 Gb Total Space | 165,66 Gb Free Space | 99,94% Space Free | Partition Type: NTFS
Drive F: | 165,75 Gb Total Space | 165,66 Gb Free Space | 99,94% Space Free | Partition Type: NTFS
 
Computer Name: ATI-PC | User Name: Ati | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.13 20:00:42 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Ati\Downloads\OTL.exe
PRC - [2012.06.01 17:37:13 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012.01.17 23:20:24 | 000,660,296 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
PRC - [2012.01.17 23:18:54 | 000,331,608 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
PRC - [2012.01.05 01:02:02 | 000,329,544 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
PRC - [2012.01.05 01:01:58 | 000,363,336 | ---- | M] (AnchorFree Inc.) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2011.06.13 22:40:06 | 002,899,968 | ---- | M] () -- C:\Program Files (x86)\G-Recorder\G-Recorder.exe
PRC - [2010.08.11 03:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010.08.11 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010.08.11 03:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010.07.15 16:05:48 | 000,600,688 | ---- | M] (Chicony) -- C:\Program Files (x86)\Video Web Camera\traybar.exe
PRC - [2010.06.29 00:23:24 | 000,263,936 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010.06.29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010.06.10 04:54:04 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010.03.03 14:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.03.03 14:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2009.10.09 05:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.13 18:26:31 | 008,797,856 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
MOD - [2012.06.01 17:37:31 | 002,042,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.01.17 23:20:52 | 000,009,544 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\lang\gui-ger.dll
MOD - [2012.01.17 23:20:24 | 000,660,296 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
MOD - [2011.06.13 22:40:06 | 002,899,968 | ---- | M] () -- C:\Program Files (x86)\G-Recorder\G-Recorder.exe
MOD - [2010.06.29 00:20:54 | 000,465,576 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2010.06.10 04:54:04 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2009.05.21 00:02:04 | 000,072,200 | ---- | M] () -- C:\Program Files (x86)\Launch Manager\CdDirIo.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.06.13 18:35:15 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.13 13:05:13 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.06.05 15:17:44 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.06.01 17:37:22 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012.01.17 23:22:00 | 000,077,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService)
SRV - [2012.01.17 23:18:54 | 000,331,608 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012.01.05 01:02:02 | 000,329,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2012.01.05 01:01:58 | 000,363,336 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010.08.11 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010.06.29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010.06.11 14:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2010.04.04 01:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.03.03 14:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.03.03 14:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.15 23:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009.10.09 05:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.05.02 15:24:12 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.04.27 10:20:04 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.04.25 00:32:27 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.01.05 01:01:58 | 000,056,832 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HssDrv.sys -- (HssDrv)
DRV:64bit: - [2012.01.05 01:01:54 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:64bit: - [2010.06.10 22:57:20 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2010.06.08 04:36:18 | 000,406,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2010.05.12 04:11:38 | 002,229,608 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.04.21 21:18:44 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.02.27 02:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.03 16:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2009.09.18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.09.17 12:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:64bit: - [2009.06.10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.06 01:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009.05.06 01:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2008.06.16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.hotspotshield.com/g/?c=h
IE - HKCU\..\SearchScopes,DefaultScope = {c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}
IE - HKCU\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.13 14:18:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.06.13 14:19:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ati\AppData\Roaming\mozilla\Extensions
[2012.06.13 16:52:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.06.13 16:52:27 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com
[2012.06.01 17:38:43 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.01 18:33:00 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.01 18:33:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.01 18:33:00 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.01 18:33:00 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.01.05 01:02:04 | 000,001,847 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\privatesearch.xml
[2012.06.01 18:33:00 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.01 18:33:00 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [Clip2Net] C:\Program Files (x86)\Clip2Net\clip2net.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\G-Recorder.lnk = C:\Program Files (x86)\G-Recorder\G-Recorder.exe ()
O4 - Startup: C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk = C:\Program Files (x86)\MultiSkypeLauncher\MultiSkypeLauncher.exe (IM-history)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8D4FB64C-6BB7-4DBC-ADE7-9384F6AFE5DD}: DhcpNameServer = 192.168.11.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.13 22:04:03 | 000,000,000 | ---D | C] -- C:\Windows\de-DE
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\de-DE
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\de
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\0407
[2012.06.13 22:03:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0407
[2012.06.13 22:03:58 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\de-DE
[2012.06.13 22:03:58 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\de
[2012.06.13 22:03:09 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerId.sys.mui
[2012.06.13 22:03:09 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerIb.sys.mui
[2012.06.13 22:03:08 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\SysNative\drivers\de-DE\pscr.sys.mui
[2012.06.13 22:03:07 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrParwdm.sys.mui
[2012.06.13 21:58:28 | 000,000,000 | ---D | C] -- C:\Windows\NAPP_Dism_Log
[2012.06.13 21:54:33 | 002,229,608 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\athrx.sys
[2012.06.13 21:54:31 | 000,349,776 | ---- | C] (Dritek System Inc.) -- C:\Windows\UNINSTLMv4.EXE
[2012.06.13 21:54:28 | 000,396,072 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCOM.dll
[2012.06.13 21:54:28 | 000,292,912 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys
[2012.06.13 21:54:28 | 000,263,464 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCtrl.dll
[2012.06.13 21:54:28 | 000,206,120 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCtrl.dll
[2012.06.13 21:54:28 | 000,205,608 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPAPI.dll
[2012.06.13 21:54:28 | 000,169,256 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCOM.dll
[2012.06.13 21:54:28 | 000,147,752 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPCo4.dll
[2012.06.13 21:54:28 | 000,107,816 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynTPCOM.dll
[2012.06.13 21:53:49 | 000,527,400 | ---- | C] (Wistron Corp.) -- C:\Windows\WGRegx64.exe
[2012.06.13 21:53:48 | 000,000,000 | ---D | C] -- C:\Windows\Lan
[2012.06.13 21:53:35 | 001,422,888 | ---- | C] (Wistron Corp.) -- C:\Windows\PatchFul.exe
[2012.06.13 21:53:35 | 000,484,128 | ---- | C] (Wistron Corp.) -- C:\Windows\WisMvImg.exe
[2012.06.13 21:53:35 | 000,255,264 | ---- | C] (Wistron Corp.) -- C:\Windows\WISI2BAT.EXE
[2012.06.13 21:53:34 | 000,388,384 | ---- | C] (Wistron Corp.) -- C:\Windows\WisGAPasx64.exe
[2012.06.13 21:53:34 | 000,342,560 | ---- | C] (Acer Inc.) -- C:\Windows\ParseModule_X64.exe
[2012.06.13 21:53:34 | 000,326,432 | ---- | C] (Wistron Corp.) -- C:\Windows\WisGAPas.exe
[2012.06.13 21:53:34 | 000,231,968 | ---- | C] (Acer Inc.) -- C:\Windows\ParseModule_X86.exe
[2012.06.13 18:35:08 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012.06.13 18:18:44 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Adobe
[2012.06.13 18:18:37 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2012.06.13 16:57:37 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Nero
[2012.06.13 16:53:20 | 000,000,000 | ---D | C] -- C:\Hotspot Shield
[2012.06.13 16:53:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
[2012.06.13 16:52:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hotspot Shield
[2012.06.13 15:29:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2012.06.13 15:27:57 | 000,000,000 | ---D | C] -- C:\Users\Ati\Documents\gegl-0.0
[2012.06.13 15:27:57 | 000,000,000 | ---D | C] -- C:\Users\Ati\.gimp-2.6
[2012.06.13 15:23:59 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\TeamViewer
[2012.06.13 15:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2012.06.13 15:22:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIMP-2.0
[2012.06.13 15:20:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clip2Net
[2012.06.13 15:20:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Clip2Net
[2012.06.13 15:17:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.06.13 15:17:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2012.06.13 15:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.06.13 15:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2012.06.13 15:16:44 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2012.06.13 15:16:42 | 000,000,000 | ---D | C] -- C:\Program Files\Clip2Net
[2012.06.13 14:59:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Skype
[2012.06.13 14:59:11 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012.06.13 14:59:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.06.13 14:59:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012.06.13 14:37:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\Desktop\ich
[2012.06.13 14:19:07 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Mozilla
[2012.06.13 14:19:07 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Mozilla
[2012.06.13 14:18:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.06.13 14:18:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.06.13 14:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.06.13 14:15:40 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\MultiSkypeLauncher
[2012.06.13 14:14:47 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\G-Recorder
[2012.06.13 14:14:41 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\G-Recorder
[2012.06.13 14:14:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\G-Recorder
[2012.06.13 14:14:26 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MultiSkypeLauncher
[2012.06.13 14:14:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MultiSkypeLauncher
[2012.06.13 13:58:38 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Adobe
[2012.06.13 13:55:33 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Avira
[2012.06.13 13:50:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.06.13 13:50:11 | 000,132,832 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.06.13 13:50:11 | 000,098,848 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012.06.13 13:50:11 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2012.06.13 13:50:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.06.13 13:50:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.06.13 13:48:32 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Malwarebytes
[2012.06.13 13:48:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.13 13:48:26 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.13 13:48:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.13 13:48:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.13 13:40:49 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Ad-Aware Antivirus
[2012.06.13 13:17:52 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Macromedia
[2012.06.13 13:17:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OEM
[2012.06.13 13:17:30 | 000,000,000 | ---D | C] -- C:\Program Files\PB Accessory Store
[2012.06.13 13:17:28 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.06.13 13:17:28 | 000,000,000 | R--D | C] -- C:\Users\Ati\Searches
[2012.06.13 13:17:28 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.06.13 13:17:19 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Identities
[2012.06.13 13:17:14 | 000,000,000 | R--D | C] -- C:\Users\Ati\Contacts
[2012.06.13 13:17:11 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\VirtualStore
[2012.06.13 13:16:48 | 000,000,000 | --SD | C] -- C:\Users\Ati\AppData\Roaming\Microsoft
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Videos
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Saved Games
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Pictures
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Music
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Links
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Favorites
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Downloads
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Documents
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Desktop
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Vorlagen
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\AppData\Local\Verlauf
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\AppData\Local\Temporary Internet Files
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Startmenü
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\SendTo
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Recent
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Netzwerkumgebung
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Lokale Einstellungen
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Documents\Eigene Videos
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Documents\Eigene Musik
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Eigene Dateien
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Documents\Eigene Bilder
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Druckumgebung
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Cookies
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\AppData\Local\Anwendungsdaten
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Anwendungsdaten
[2012.06.13 13:16:48 | 000,000,000 | -H-D | C] -- C:\Users\Ati\AppData
[2012.06.13 13:16:48 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Temp
[2012.06.13 13:16:48 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Microsoft
[2012.06.13 13:16:48 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Media Center Programs
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.06.13 13:05:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2012.06.13 13:04:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2012.06.13 13:04:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2012.06.13 13:02:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012.06.13 12:23:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012.06.13 12:22:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2012.06.13 12:22:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive
[2012.06.13 12:22:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2012.06.13 12:21:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2012.06.13 12:21:45 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012.06.13 12:21:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2012.06.13 12:19:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2012.06.13 12:19:25 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Social Networks
[2012.06.13 12:19:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cyberlink
[2012.06.13 12:19:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Social Networks
[2012.06.13 12:18:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2012.06.13 12:18:36 | 000,214,400 | ---- | C] (Sonix) -- C:\Windows\SysWow64\Snpropwp.dll
[2012.06.13 12:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Web Camera
[2012.06.13 12:18:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Video Web Camera
[2012.06.13 12:18:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Launch Manager
[2012.06.13 12:18:16 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2012.06.13 12:16:04 | 000,064,000 | ---- | C] (LSI Corporation) -- C:\Windows\SysWow64\agrsmdel.exe
[2012.06.13 12:16:04 | 000,027,648 | ---- | C] (LSI Corporation) -- C:\Windows\SysWow64\agrsco64.dll
[2012.06.13 12:16:03 | 000,000,000 | ---D | C] -- C:\Windows\Options
[2012.06.13 12:15:52 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2012.06.13 12:15:47 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.06.13 12:15:43 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012.06.13 12:15:41 | 002,601,816 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2012.06.13 12:15:41 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2012.06.13 12:15:41 | 000,220,496 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFNHK64.dll
[2012.06.13 12:15:41 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2012.06.13 12:15:41 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2012.06.13 12:15:41 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2012.06.13 12:15:41 | 000,081,232 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFCOM64.dll
[2012.06.13 12:15:41 | 000,078,160 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFAPO64.dll
[2012.06.13 12:15:41 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
[2012.06.13 12:15:40 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2012.06.13 12:15:40 | 001,756,160 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek.dll
[2012.06.13 12:15:40 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2012.06.13 12:15:40 | 000,334,848 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
[2012.06.13 12:15:40 | 000,334,680 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2012.06.13 12:15:40 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2012.06.13 12:15:40 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2012.06.13 12:15:40 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2012.06.13 12:15:40 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2012.06.13 12:15:40 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2012.06.13 12:15:40 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2012.06.13 12:15:39 | 001,325,328 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2012.06.13 12:15:39 | 001,178,384 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2012.06.13 12:15:39 | 001,110,800 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
[2012.06.13 12:15:39 | 000,504,592 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2012.06.13 12:15:39 | 000,489,744 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2012.06.13 12:15:39 | 000,474,896 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2012.06.13 12:15:39 | 000,330,656 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2012.06.13 12:15:39 | 000,315,152 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2012.06.13 12:15:39 | 000,268,560 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
[2012.06.13 12:15:39 | 000,265,488 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2012.06.13 12:15:39 | 000,124,128 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
[2012.06.13 12:15:39 | 000,124,128 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
[2012.06.13 12:15:39 | 000,123,104 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
[2012.06.13 12:15:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2012.06.13 12:15:38 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2012.06.13 12:15:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2012.06.13 12:15:27 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2012.06.13 12:14:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2012.06.13 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2012.06.13 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2012.06.13 12:09:35 | 000,000,000 | -HSD | C] -- C:\System Volume Information
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.13 22:07:46 | 000,001,652 | ---- | M] () -- C:\Windows\WPatchProgress.ini
[2012.06.13 22:03:47 | 000,295,922 | ---- | M] () -- C:\Windows\SysNative\perfi007.dat
[2012.06.13 22:03:47 | 000,038,104 | ---- | M] () -- C:\Windows\SysNative\perfd007.dat
[2012.06.13 22:03:09 | 000,011,776 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerId.sys.mui
[2012.06.13 22:03:09 | 000,011,776 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerIb.sys.mui
[2012.06.13 22:03:08 | 000,004,096 | ---- | M] (SCM Microsystems, Inc.) -- C:\Windows\SysNative\drivers\de-DE\pscr.sys.mui
[2012.06.13 22:03:07 | 000,002,560 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrParwdm.sys.mui
[2012.06.13 21:58:28 | 000,011,453 | ---- | M] () -- C:\Windows\ChangeLang_Done.tag
[2012.06.13 21:56:01 | 000,000,926 | ---- | M] () -- C:\Windows\MOD01SET74DE0N0003.XML
[2012.06.13 19:35:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.13 18:17:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.13 17:01:21 | 000,001,831 | ---- | M] () -- C:\Users\Ati\Desktop\NeroStartSmart - Verknüpfung.lnk
[2012.06.13 16:56:09 | 000,001,023 | ---- | M] () -- C:\Users\Ati\Desktop\clip2net - Verknüpfung.lnk
[2012.06.13 16:53:42 | 000,001,150 | ---- | M] () -- C:\Users\Public\Desktop\Hotspot Shield Launch.lnk
[2012.06.13 15:08:18 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.13 15:08:18 | 000,643,866 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.13 15:08:18 | 000,607,190 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.13 15:08:18 | 000,126,394 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.13 15:08:18 | 000,103,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.13 14:14:41 | 000,001,083 | ---- | M] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\G-Recorder.lnk
[2012.06.13 14:14:26 | 000,001,201 | ---- | M] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
[2012.06.13 14:02:35 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.13 14:02:35 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.13 13:50:16 | 000,002,082 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.06.13 13:48:27 | 000,001,125 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.13 13:38:18 | 2205,544,448 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.13 13:18:18 | 000,000,201 | ---- | M] () -- C:\Windows\USER.XML
[2012.06.13 13:17:40 | 000,002,609 | ---- | M] () -- C:\Users\Public\Desktop\eBay.lnk
[2012.06.13 13:17:30 | 000,001,962 | ---- | M] () -- C:\Users\Public\Desktop\PB Zubehör Shop.lnk
[2012.06.13 13:16:55 | 000,000,222 | RHS- | M] () -- C:\Preload.rev
[2012.06.13 13:16:55 | 000,000,168 | ---- | M] () -- C:\Windows\WisLangCode.ini
[2012.06.13 13:16:26 | 000,052,953 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.06.13 13:16:26 | 000,052,953 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.06.13 13:15:00 | 000,271,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.13 13:14:00 | 000,000,213 | ---- | M] () -- C:\Windows\Factory.xml
[2012.06.13 13:05:51 | 000,000,267 | ---- | M] () -- C:\Windows\LaunApp.ini
[2012.06.13 13:05:01 | 000,001,225 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Photoshop Elements 8.0.lnk
[2012.06.13 12:23:03 | 000,000,020 | ---- | M] () -- C:\Windows\lôN
[2012.06.13 12:18:27 | 000,000,184 | ---- | M] () -- C:\Windows\LMv4.UNI
[2012.06.13 12:18:18 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
 
========== Files Created - No Company Name ==========
 
[2012.06.13 22:07:46 | 000,011,453 | ---- | C] () -- C:\Windows\ChangeLang_Done.tag
[2012.06.13 22:04:27 | 000,643,866 | ---- | C] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.13 22:04:27 | 000,295,922 | ---- | C] () -- C:\Windows\SysNative\perfi007.dat
[2012.06.13 22:04:27 | 000,126,394 | ---- | C] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.13 22:04:27 | 000,038,104 | ---- | C] () -- C:\Windows\SysNative\perfd007.dat
[2012.06.13 21:56:08 | 000,000,926 | ---- | C] () -- C:\Windows\MOD01SET74DE0N0003.XML
[2012.06.13 21:55:31 | 000,000,267 | ---- | C] () -- C:\Windows\LaunApp.ini
[2012.06.13 21:55:29 | 000,000,441 | RHS- | C] () -- C:\Patch.rev
[2012.06.13 21:55:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\1025_Acer_Packard Bell_EasyNote LM85.mrk
[2012.06.13 21:55:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\drivers\1025_Acer_Packard Bell_EasyNote LM85.mrk
[2012.06.13 21:53:57 | 001,991,936 | ---- | C] () -- C:\Windows\SysNative\iglhxa64.cpa
[2012.06.13 21:53:57 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2012.06.13 21:53:57 | 000,205,824 | ---- | C] () -- C:\Windows\SysNative\iglhsip64.dll
[2012.06.13 21:53:57 | 000,152,600 | ---- | C] () -- C:\Windows\SysNative\difx64.exe
[2012.06.13 21:53:57 | 000,060,254 | ---- | C] () -- C:\Windows\SysNative\iglhxg64.vp
[2012.06.13 21:53:57 | 000,060,226 | ---- | C] () -- C:\Windows\SysNative\iglhxc64.vp
[2012.06.13 21:53:57 | 000,060,015 | ---- | C] () -- C:\Windows\SysNative\iglhxo64.vp
[2012.06.13 21:53:57 | 000,005,368 | ---- | C] () -- C:\Windows\SysNative\iglhxs64.vp
[2012.06.13 21:53:57 | 000,001,090 | ---- | C] () -- C:\Windows\SysNative\iglhxa64.vp
[2012.06.13 21:53:56 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2012.06.13 21:53:56 | 000,870,560 | ---- | C] () -- C:\Windows\SysNative\igkrng575.bin
[2012.06.13 21:53:56 | 000,189,369 | ---- | C] () -- C:\Windows\SysNative\Gfxres.th-TH.resources
[2012.06.13 21:53:56 | 000,187,392 | ---- | C] () -- C:\Windows\SysNative\iglhcp64.dll
[2012.06.13 21:53:56 | 000,178,235 | ---- | C] () -- C:\Windows\SysNative\Gfxres.el-GR.resources
[2012.06.13 21:53:56 | 000,165,209 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ru-RU.resources
[2012.06.13 21:53:56 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2012.06.13 21:53:56 | 000,139,736 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ar-SA.resources
[2012.06.13 21:53:56 | 000,136,237 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ja-JP.resources
[2012.06.13 21:53:56 | 000,133,575 | ---- | C] () -- C:\Windows\SysNative\Gfxres.he-IL.resources
[2012.06.13 21:53:56 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2012.06.13 21:53:56 | 000,127,868 | ---- | C] () -- C:\Windows\SysNative\igcompkrng575.bin
[2012.06.13 21:53:56 | 000,125,382 | ---- | C] () -- C:\Windows\SysNative\Gfxres.it-IT.resources
[2012.06.13 21:53:56 | 000,123,063 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ko-KR.resources
[2012.06.13 21:53:56 | 000,122,758 | ---- | C] () -- C:\Windows\SysNative\Gfxres.es-ES.resources
[2012.06.13 21:53:56 | 000,122,535 | ---- | C] () -- C:\Windows\SysNative\Gfxres.de-DE.resources
[2012.06.13 21:53:56 | 000,121,000 | ---- | C] () -- C:\Windows\SysNative\Gfxres.tr-TR.resources
[2012.06.13 21:53:56 | 000,120,616 | ---- | C] () -- C:\Windows\SysNative\Gfxres.fr-FR.resources
[2012.06.13 21:53:56 | 000,120,195 | ---- | C] () -- C:\Windows\SysNative\Gfxres.pt-BR.resources
[2012.06.13 21:53:56 | 000,119,433 | ---- | C] () -- C:\Windows\SysNative\Gfxres.hu-HU.resources
[2012.06.13 21:53:56 | 000,119,416 | ---- | C] () -- C:\Windows\SysNative\Gfxres.nl-NL.resources
[2012.06.13 21:53:56 | 000,119,176 | ---- | C] () -- C:\Windows\SysNative\Gfxres.sv-SE.resources
[2012.06.13 21:53:56 | 000,118,893 | ---- | C] () -- C:\Windows\SysNative\Gfxres.pt-PT.resources
[2012.06.13 21:53:56 | 000,118,589 | ---- | C] () -- C:\Windows\SysNative\Gfxres.cs-CZ.resources
[2012.06.13 21:53:56 | 000,118,512 | ---- | C] () -- C:\Windows\SysNative\Gfxres.fi-FI.resources
[2012.06.13 21:53:56 | 000,118,244 | ---- | C] () -- C:\Windows\SysNative\Gfxres.pl-PL.resources
[2012.06.13 21:53:56 | 000,117,884 | ---- | C] () -- C:\Windows\SysNative\Gfxres.sk-SK.resources
[2012.06.13 21:53:56 | 000,114,668 | ---- | C] () -- C:\Windows\SysNative\Gfxres.nb-NO.resources
[2012.06.13 21:53:56 | 000,114,189 | ---- | C] () -- C:\Windows\SysNative\Gfxres.sl-SI.resources
[2012.06.13 21:53:56 | 000,114,077 | ---- | C] () -- C:\Windows\SysNative\Gfxres.da-DK.resources
[2012.06.13 21:53:56 | 000,110,040 | ---- | C] () -- C:\Windows\SysNative\Gfxres.en-US.resources
[2012.06.13 21:53:56 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2012.06.13 21:53:56 | 000,104,636 | ---- | C] () -- C:\Windows\SysNative\igfcg575m.bin
[2012.06.13 21:53:56 | 000,103,868 | ---- | C] () -- C:\Windows\SysNative\Gfxres.zh-TW.resources
[2012.06.13 21:53:56 | 000,102,707 | ---- | C] () -- C:\Windows\SysNative\Gfxres.zh-CN.resources
[2012.06.13 21:53:56 | 000,004,096 | ---- | C] ( ) -- C:\Windows\SysNative\IGFXDEVLib.dll
[2012.06.13 21:53:56 | 000,000,151 | ---- | C] () -- C:\Windows\SysNative\GfxUI.exe.config
[2012.06.13 21:53:48 | 000,000,201 | ---- | C] () -- C:\Windows\USER.XML
[2012.06.13 21:53:33 | 000,001,652 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2012.06.13 18:26:32 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.13 17:01:21 | 000,001,831 | ---- | C] () -- C:\Users\Ati\Desktop\NeroStartSmart - Verknüpfung.lnk
[2012.06.13 16:56:09 | 000,001,023 | ---- | C] () -- C:\Users\Ati\Desktop\clip2net - Verknüpfung.lnk
[2012.06.13 16:53:42 | 000,001,150 | ---- | C] () -- C:\Users\Public\Desktop\Hotspot Shield Launch.lnk
[2012.06.13 15:29:59 | 000,001,190 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.06.13 14:18:24 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.06.13 14:14:41 | 000,001,083 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\G-Recorder.lnk
[2012.06.13 14:14:26 | 000,001,201 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
[2012.06.13 13:50:16 | 000,002,082 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.06.13 13:48:27 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.13 13:17:40 | 000,002,609 | ---- | C] () -- C:\Users\Public\Desktop\eBay.lnk
[2012.06.13 13:17:40 | 000,001,421 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.06.13 13:17:34 | 000,001,455 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.06.13 13:17:30 | 000,001,962 | ---- | C] () -- C:\Users\Public\Desktop\PB Zubehör Shop.lnk
[2012.06.13 13:05:01 | 000,001,237 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 8.0.lnk
[2012.06.13 13:05:01 | 000,001,225 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Photoshop Elements 8.0.lnk
[2012.06.13 13:02:52 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2012.06.13 12:23:02 | 000,000,020 | ---- | C] () -- C:\Windows\lôN
[2012.06.13 12:18:36 | 000,206,208 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2012.06.13 12:18:36 | 000,000,302 | ---- | C] () -- C:\Windows\PidList_C.ini
[2012.06.13 12:18:27 | 000,000,184 | ---- | C] () -- C:\Windows\LMv4.UNI
[2012.06.13 12:18:18 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012.06.13 12:15:42 | 000,247,560 | ---- | C] () -- C:\Windows\SysNative\drivers\RTConvEQ.dat
[2012.06.13 12:15:42 | 000,037,468 | ---- | C] () -- C:\Windows\SysNative\drivers\RtPCEE3.DAT
[2012.06.13 12:15:42 | 000,001,448 | ---- | C] () -- C:\Windows\SysNative\drivers\RtHdatEx.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX3.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX2.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX1.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX0.dat
[2012.06.13 12:15:42 | 000,000,176 | ---- | C] () -- C:\Windows\SysNative\drivers\RTHDAEQ1.dat
[2012.06.13 12:15:42 | 000,000,016 | ---- | C] () -- C:\Windows\SysNative\drivers\rtkhdaud.dat
[2012.06.13 12:09:35 | 2205,544,448 | -HS- | C] () -- C:\hiberfil.sys
[2010.09.08 05:16:07 | 000,000,325 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2010.09.08 05:16:07 | 000,000,271 | ---- | C] () -- C:\Windows\WisPriority.ini
[2010.09.08 05:16:07 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini
 
========== LOP Check ==========
 
[2009.07.14 07:08:49 | 000,005,858 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.06.13 13:45:50 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Ad-Aware Antivirus
[2012.06.13 18:18:47 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Adobe
[2012.06.13 13:55:33 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Avira
[2012.06.13 14:14:47 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\G-Recorder
[2012.06.13 13:17:19 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Identities
[2012.06.13 13:17:52 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Macromedia
[2012.06.13 13:48:32 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Malwarebytes
[2010.09.08 05:25:27 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Media Center Programs
[2012.06.13 16:56:31 | 000,000,000 | --SD | M] -- C:\Users\Ati\AppData\Roaming\Microsoft
[2012.06.13 14:19:13 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Mozilla
[2012.06.13 14:15:41 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\MultiSkypeLauncher
[2012.06.13 16:57:51 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Nero
[2012.06.13 16:50:35 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Skype
[2012.06.13 15:23:59 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\TeamViewer
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2010.03.04 05:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- C:\OEM\Preload\Autorun\DRV\AHCI\F6\f6flpy-x86\iaStor.sys
[2010.03.04 05:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\OEM\Preload\Autorun\DRV\AHCI\F6\f6flpy-x64\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_78ebae21a80aa2b4\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010.09.08 04:41:06 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010.09.08 04:41:06 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2010.09.08 04:41:06 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

cosinus 13.06.2012 21:17

Zitat:

Scan Mode: Current user
Du hast den Haken bei alle Benutzer vergesen

derhunne 15.06.2012 16:37

hallo cosinus,


hoffe jetzt ist richtig .

lg der hunne




OTL Logfile:
Code:

OTL logfile created on: 15.06.2012 16:11:22 - Run 2
OTL by OldTimer - Version 3.2.48.0    Folder = C:\Users\Ati\Downloads
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,74 Gb Total Physical Memory | 1,51 Gb Available Physical Memory | 54,95% Memory free
5,48 Gb Paging File | 4,00 Gb Available in Paging File | 73,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 62,87 Gb Total Space | 33,25 Gb Free Space | 52,90% Space Free | Partition Type: NTFS
Drive D: | 169,49 Gb Total Space | 169,40 Gb Free Space | 99,95% Space Free | Partition Type: NTFS
Drive E: | 162,01 Gb Total Space | 161,92 Gb Free Space | 99,94% Space Free | Partition Type: NTFS
 
Computer Name: ATI-PC | User Name: Ati | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.15 16:02:03 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Ati\Downloads\OTL(1).exe
PRC - [2012.06.06 00:04:53 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.02 00:31:35 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.11 02:04:10 | 001,202,504 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
PRC - [2012.04.11 01:59:14 | 000,542,552 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.04.02 20:46:58 | 000,329,544 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
PRC - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2011.11.15 20:26:48 | 000,363,336 | ---- | M] (AnchorFree Inc.) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2011.09.08 17:38:04 | 001,879,552 | ---- | M] () -- C:\Program Files (x86)\Clip2Net\clip2net.exe
PRC - [2010.08.11 03:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010.08.11 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010.08.11 03:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010.07.15 16:05:48 | 000,600,688 | ---- | M] (Chicony) -- C:\Program Files (x86)\Video Web Camera\traybar.exe
PRC - [2010.06.29 00:23:24 | 000,263,936 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010.06.29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010.06.10 04:54:04 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010.03.03 14:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.03.03 14:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2009.10.09 05:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.13 18:26:31 | 008,797,856 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
MOD - [2012.06.06 00:05:12 | 002,000,352 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012.04.11 02:05:12 | 000,010,056 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\lang\gui-ger.dll
MOD - [2012.04.11 02:04:10 | 001,202,504 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
MOD - [2011.09.08 17:38:04 | 001,879,552 | ---- | M] () -- C:\Program Files (x86)\Clip2Net\clip2net.exe
MOD - [2010.06.29 00:20:54 | 000,465,576 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2010.06.10 04:54:04 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2009.05.21 00:02:04 | 000,072,200 | ---- | M] () -- C:\Program Files (x86)\Launch Manager\CdDirIo.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.06.13 18:35:15 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.13 13:05:13 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.06.06 00:05:03 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.05 15:17:44 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.11 02:06:10 | 000,077,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE -- (HssTrayService)
SRV - [2012.04.11 01:59:14 | 000,542,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.04.02 20:46:58 | 000,329,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2012.03.19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2011.11.15 20:26:48 | 000,363,336 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010.08.11 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010.06.29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010.06.11 14:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2010.04.04 01:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.03.03 14:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.03.03 14:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.15 23:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010.01.08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009.10.09 05:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.05.02 15:24:12 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012.04.27 10:20:04 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.04.25 00:32:27 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.04.11 17:40:28 | 000,056,832 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HssDrv.sys -- (HssDrv)
DRV:64bit: - [2012.04.06 20:15:10 | 000,038,632 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.03.01 08:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2010.06.10 22:57:20 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2010.06.08 04:36:18 | 000,406,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2010.05.12 04:11:38 | 002,229,608 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.04.21 21:18:44 | 010,326,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.02.27 02:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.03 16:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2009.09.18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.09.17 12:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:64bit: - [2009.06.10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.06 01:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009.05.06 01:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2008.06.16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE - HKLM\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1561552
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1561552
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.14 08:17:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012.06.13 14:19:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ati\AppData\Roaming\mozilla\Extensions
[2012.06.14 08:18:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions
[2012.06.13 23:07:37 | 000,000,000 | ---D | M] (Hotspot Shield Community Toolbar) -- C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
[2012.06.14 08:17:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.06.13 23:06:33 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com
[2012.06.14 08:17:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\distribution\extensions
[2012.06.14 08:18:00 | 001,184,804 | ---- | M] () (No name found) -- C:\USERS\ATI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4U5CE4HN.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI
[2012.06.06 00:06:25 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.06.06 00:36:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.06 00:36:57 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.06 00:36:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.06 00:36:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.06 00:36:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.06 00:36:57 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\Toolbar\WebBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000..\Run: [Clip2Net] C:\Program Files (x86)\Clip2Net\clip2net.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk = C:\Program Files (x86)\MultiSkypeLauncher\MultiSkypeLauncher.exe (IM-history)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8D4FB64C-6BB7-4DBC-ADE7-9384F6AFE5DD}: DhcpNameServer = 192.168.11.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.14 18:24:43 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\ElevatedDiagnostics
[2012.06.14 14:39:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012.06.14 13:09:07 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Diagnostics
[2012.06.14 09:11:23 | 000,000,000 | R--D | C] -- C:\Users\Ati\Documents\Notes
[2012.06.13 23:07:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012.06.13 23:07:31 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Conduit
[2012.06.13 23:07:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hotspot_Shield
[2012.06.13 23:07:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Hotspot Shield
[2012.06.13 23:06:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
[2012.06.13 23:06:41 | 000,000,000 | ---D | C] -- C:\Hotspot Shield
[2012.06.13 23:06:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hotspot Shield
[2012.06.13 22:04:03 | 000,000,000 | ---D | C] -- C:\Windows\de-DE
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\de-DE
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\de
[2012.06.13 22:04:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\0407
[2012.06.13 22:03:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\0407
[2012.06.13 22:03:58 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\de-DE
[2012.06.13 22:03:58 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\de
[2012.06.13 22:03:09 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerId.sys.mui
[2012.06.13 22:03:09 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerIb.sys.mui
[2012.06.13 22:03:08 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\SysNative\drivers\de-DE\pscr.sys.mui
[2012.06.13 22:03:07 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrParwdm.sys.mui
[2012.06.13 21:58:28 | 000,000,000 | ---D | C] -- C:\Windows\NAPP_Dism_Log
[2012.06.13 21:54:33 | 002,229,608 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\athrx.sys
[2012.06.13 21:54:31 | 000,349,776 | ---- | C] (Dritek System Inc.) -- C:\Windows\UNINSTLMv4.EXE
[2012.06.13 21:54:28 | 000,396,072 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCOM.dll
[2012.06.13 21:54:28 | 000,292,912 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys
[2012.06.13 21:54:28 | 000,263,464 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCtrl.dll
[2012.06.13 21:54:28 | 000,206,120 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCtrl.dll
[2012.06.13 21:54:28 | 000,205,608 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPAPI.dll
[2012.06.13 21:54:28 | 000,169,256 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCOM.dll
[2012.06.13 21:54:28 | 000,147,752 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPCo4.dll
[2012.06.13 21:54:28 | 000,107,816 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynTPCOM.dll
[2012.06.13 21:53:49 | 000,527,400 | ---- | C] (Wistron Corp.) -- C:\Windows\WGRegx64.exe
[2012.06.13 21:53:48 | 000,000,000 | ---D | C] -- C:\Windows\Lan
[2012.06.13 21:53:35 | 001,422,888 | ---- | C] (Wistron Corp.) -- C:\Windows\PatchFul.exe
[2012.06.13 21:53:35 | 000,484,128 | ---- | C] (Wistron Corp.) -- C:\Windows\WisMvImg.exe
[2012.06.13 21:53:35 | 000,255,264 | ---- | C] (Wistron Corp.) -- C:\Windows\WISI2BAT.EXE
[2012.06.13 21:53:34 | 000,388,384 | ---- | C] (Wistron Corp.) -- C:\Windows\WisGAPasx64.exe
[2012.06.13 21:53:34 | 000,342,560 | ---- | C] (Acer Inc.) -- C:\Windows\ParseModule_X64.exe
[2012.06.13 21:53:34 | 000,326,432 | ---- | C] (Wistron Corp.) -- C:\Windows\WisGAPas.exe
[2012.06.13 21:53:34 | 000,231,968 | ---- | C] (Acer Inc.) -- C:\Windows\ParseModule_X86.exe
[2012.06.13 18:35:08 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012.06.13 18:18:44 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Adobe
[2012.06.13 18:18:37 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2012.06.13 16:57:37 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Nero
[2012.06.13 15:29:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2012.06.13 15:27:57 | 000,000,000 | ---D | C] -- C:\Users\Ati\Documents\gegl-0.0
[2012.06.13 15:27:57 | 000,000,000 | ---D | C] -- C:\Users\Ati\.gimp-2.6
[2012.06.13 15:23:59 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\TeamViewer
[2012.06.13 15:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2012.06.13 15:22:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIMP-2.0
[2012.06.13 15:20:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clip2Net
[2012.06.13 15:20:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Clip2Net
[2012.06.13 15:17:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.06.13 15:17:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2012.06.13 15:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.06.13 15:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2012.06.13 15:16:44 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2012.06.13 15:16:42 | 000,000,000 | ---D | C] -- C:\Program Files\Clip2Net
[2012.06.13 14:59:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Skype
[2012.06.13 14:59:11 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012.06.13 14:59:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.06.13 14:59:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012.06.13 14:37:17 | 000,000,000 | ---D | C] -- C:\Users\Ati\Desktop\ich
[2012.06.13 14:19:07 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Mozilla
[2012.06.13 14:19:07 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Mozilla
[2012.06.13 14:18:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.06.13 14:18:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.06.13 14:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.06.13 14:15:40 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\MultiSkypeLauncher
[2012.06.13 14:14:47 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\G-Recorder
[2012.06.13 14:14:41 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\G-Recorder
[2012.06.13 14:14:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\G-Recorder
[2012.06.13 14:14:26 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MultiSkypeLauncher
[2012.06.13 14:14:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MultiSkypeLauncher
[2012.06.13 13:58:38 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Adobe
[2012.06.13 13:55:33 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Avira
[2012.06.13 13:50:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.06.13 13:50:11 | 000,132,832 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.06.13 13:50:11 | 000,098,848 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012.06.13 13:50:11 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2012.06.13 13:50:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.06.13 13:50:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.06.13 13:48:32 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Malwarebytes
[2012.06.13 13:48:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.06.13 13:48:26 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.06.13 13:48:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.13 13:48:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.06.13 13:40:49 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Ad-Aware Antivirus
[2012.06.13 13:17:52 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Macromedia
[2012.06.13 13:17:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OEM
[2012.06.13 13:17:30 | 000,000,000 | ---D | C] -- C:\Program Files\PB Accessory Store
[2012.06.13 13:17:28 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.06.13 13:17:28 | 000,000,000 | R--D | C] -- C:\Users\Ati\Searches
[2012.06.13 13:17:28 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.06.13 13:17:19 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Identities
[2012.06.13 13:17:14 | 000,000,000 | R--D | C] -- C:\Users\Ati\Contacts
[2012.06.13 13:17:11 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\VirtualStore
[2012.06.13 13:16:48 | 000,000,000 | --SD | C] -- C:\Users\Ati\AppData\Roaming\Microsoft
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Videos
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Saved Games
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Pictures
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Music
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Links
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Favorites
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Downloads
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Documents
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\Desktop
[2012.06.13 13:16:48 | 000,000,000 | R--D | C] -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Vorlagen
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\AppData\Local\Verlauf
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\AppData\Local\Temporary Internet Files
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Startmenü
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\SendTo
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Recent
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Netzwerkumgebung
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Lokale Einstellungen
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Documents\Eigene Videos
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Documents\Eigene Musik
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Eigene Dateien
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Documents\Eigene Bilder
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Druckumgebung
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Cookies
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\AppData\Local\Anwendungsdaten
[2012.06.13 13:16:48 | 000,000,000 | -HSD | C] -- C:\Users\Ati\Anwendungsdaten
[2012.06.13 13:16:48 | 000,000,000 | -H-D | C] -- C:\Users\Ati\AppData
[2012.06.13 13:16:48 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Temp
[2012.06.13 13:16:48 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Microsoft
[2012.06.13 13:16:48 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Roaming\Media Center Programs
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.06.13 13:16:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.06.13 13:05:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2012.06.13 13:04:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2012.06.13 13:04:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2012.06.13 13:02:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012.06.13 12:23:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012.06.13 12:22:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2012.06.13 12:22:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive
[2012.06.13 12:22:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2012.06.13 12:21:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2012.06.13 12:21:45 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012.06.13 12:21:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2012.06.13 12:19:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2012.06.13 12:19:25 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Social Networks
[2012.06.13 12:19:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cyberlink
[2012.06.13 12:19:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Social Networks
[2012.06.13 12:18:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2012.06.13 12:18:36 | 000,214,400 | ---- | C] (Sonix) -- C:\Windows\SysWow64\Snpropwp.dll
[2012.06.13 12:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Web Camera
[2012.06.13 12:18:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Video Web Camera
[2012.06.13 12:18:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Launch Manager
[2012.06.13 12:18:16 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2012.06.13 12:16:04 | 000,064,000 | ---- | C] (LSI Corporation) -- C:\Windows\SysWow64\agrsmdel.exe
[2012.06.13 12:16:04 | 000,027,648 | ---- | C] (LSI Corporation) -- C:\Windows\SysWow64\agrsco64.dll
[2012.06.13 12:16:03 | 000,000,000 | ---D | C] -- C:\Windows\Options
[2012.06.13 12:15:52 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2012.06.13 12:15:47 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.06.13 12:15:43 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012.06.13 12:15:41 | 002,601,816 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2012.06.13 12:15:41 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2012.06.13 12:15:41 | 000,220,496 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFNHK64.dll
[2012.06.13 12:15:41 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2012.06.13 12:15:41 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2012.06.13 12:15:41 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2012.06.13 12:15:41 | 000,081,232 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFCOM64.dll
[2012.06.13 12:15:41 | 000,078,160 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFAPO64.dll
[2012.06.13 12:15:41 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
[2012.06.13 12:15:40 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2012.06.13 12:15:40 | 001,756,160 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek.dll
[2012.06.13 12:15:40 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2012.06.13 12:15:40 | 000,334,848 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
[2012.06.13 12:15:40 | 000,334,680 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2012.06.13 12:15:40 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2012.06.13 12:15:40 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2012.06.13 12:15:40 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2012.06.13 12:15:40 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2012.06.13 12:15:40 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2012.06.13 12:15:40 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2012.06.13 12:15:39 | 001,325,328 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2012.06.13 12:15:39 | 001,178,384 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2012.06.13 12:15:39 | 001,110,800 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
[2012.06.13 12:15:39 | 000,504,592 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2012.06.13 12:15:39 | 000,489,744 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2012.06.13 12:15:39 | 000,474,896 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2012.06.13 12:15:39 | 000,330,656 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2012.06.13 12:15:39 | 000,315,152 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2012.06.13 12:15:39 | 000,268,560 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
[2012.06.13 12:15:39 | 000,265,488 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2012.06.13 12:15:39 | 000,124,128 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
[2012.06.13 12:15:39 | 000,124,128 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
[2012.06.13 12:15:39 | 000,123,104 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
[2012.06.13 12:15:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2012.06.13 12:15:38 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2012.06.13 12:15:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2012.06.13 12:15:27 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2012.06.13 12:14:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2012.06.13 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2012.06.13 12:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2012.06.13 12:09:35 | 000,000,000 | -HSD | C] -- C:\System Volume Information
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.15 15:53:58 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.15 15:53:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.15 08:39:38 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.15 08:39:38 | 000,017,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.15 08:38:19 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.06.15 08:38:19 | 000,643,866 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.15 08:38:19 | 000,607,190 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.06.15 08:38:19 | 000,126,394 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.15 08:38:19 | 000,103,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.06.15 08:31:58 | 2205,544,448 | -HS- | M] () -- C:\hiberfil.sys
[2012.06.14 22:26:53 | 000,310,878 | ---- | M] () -- C:\Users\Ati\Desktop\server 3.jnt
[2012.06.14 16:47:48 | 000,271,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 08:17:29 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.06.13 23:07:28 | 000,001,150 | ---- | M] () -- C:\Users\Public\Desktop\Hotspot Shield Launch.lnk
[2012.06.13 22:07:46 | 000,001,652 | ---- | M] () -- C:\Windows\WPatchProgress.ini
[2012.06.13 22:03:47 | 000,295,922 | ---- | M] () -- C:\Windows\SysNative\perfi007.dat
[2012.06.13 22:03:47 | 000,038,104 | ---- | M] () -- C:\Windows\SysNative\perfd007.dat
[2012.06.13 22:03:09 | 000,011,776 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerId.sys.mui
[2012.06.13 22:03:09 | 000,011,776 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrSerIb.sys.mui
[2012.06.13 22:03:08 | 000,004,096 | ---- | M] (SCM Microsystems, Inc.) -- C:\Windows\SysNative\drivers\de-DE\pscr.sys.mui
[2012.06.13 22:03:07 | 000,002,560 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\de-DE\BrParwdm.sys.mui
[2012.06.13 21:58:28 | 000,011,453 | ---- | M] () -- C:\Windows\ChangeLang_Done.tag
[2012.06.13 21:56:01 | 000,000,926 | ---- | M] () -- C:\Windows\MOD01SET74DE0N0003.XML
[2012.06.13 21:11:21 | 000,083,785 | ---- | M] () -- C:\Users\Ati\Documents\Download.jpg
[2012.06.13 21:09:19 | 000,103,621 | ---- | M] () -- C:\Users\Ati\Documents\so sieht es jetzt aus.jpg
[2012.06.13 20:48:24 | 000,120,760 | ---- | M] () -- C:\Users\Ati\Documents\Partition.jpg
[2012.06.13 20:38:25 | 000,102,742 | ---- | M] () -- C:\Users\Ati\Documents\deswegen.jpg
[2012.06.13 17:01:21 | 000,001,831 | ---- | M] () -- C:\Users\Ati\Desktop\NeroStartSmart - Verknüpfung.lnk
[2012.06.13 16:56:09 | 000,001,023 | ---- | M] () -- C:\Users\Ati\Desktop\clip2net - Verknüpfung.lnk
[2012.06.13 14:14:26 | 000,001,201 | ---- | M] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
[2012.06.13 13:50:16 | 000,002,082 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.06.13 13:48:27 | 000,001,125 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.13 13:18:18 | 000,000,201 | ---- | M] () -- C:\Windows\USER.XML
[2012.06.13 13:17:40 | 000,002,609 | ---- | M] () -- C:\Users\Public\Desktop\eBay.lnk
[2012.06.13 13:17:30 | 000,001,962 | ---- | M] () -- C:\Users\Public\Desktop\PB Zubehör Shop.lnk
[2012.06.13 13:16:55 | 000,000,222 | RHS- | M] () -- C:\Preload.rev
[2012.06.13 13:16:55 | 000,000,168 | ---- | M] () -- C:\Windows\WisLangCode.ini
[2012.06.13 13:16:26 | 000,052,953 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.06.13 13:16:26 | 000,052,953 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.06.13 13:14:00 | 000,000,213 | ---- | M] () -- C:\Windows\Factory.xml
[2012.06.13 13:05:51 | 000,000,267 | ---- | M] () -- C:\Windows\LaunApp.ini
[2012.06.13 13:05:01 | 000,001,225 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Photoshop Elements 8.0.lnk
[2012.06.13 12:23:03 | 000,000,020 | ---- | M] () -- C:\Windows\lôN
[2012.06.13 12:18:27 | 000,000,184 | ---- | M] () -- C:\Windows\LMv4.UNI
[2012.06.13 12:18:18 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
 
========== Files Created - No Company Name ==========
 
[2012.06.14 09:11:19 | 000,310,878 | ---- | C] () -- C:\Users\Ati\Desktop\server 3.jnt
[2012.06.14 08:17:29 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.06.13 23:07:28 | 000,001,150 | ---- | C] () -- C:\Users\Public\Desktop\Hotspot Shield Launch.lnk
[2012.06.13 22:07:46 | 000,011,453 | ---- | C] () -- C:\Windows\ChangeLang_Done.tag
[2012.06.13 22:04:27 | 000,643,866 | ---- | C] () -- C:\Windows\SysNative\perfh007.dat
[2012.06.13 22:04:27 | 000,295,922 | ---- | C] () -- C:\Windows\SysNative\perfi007.dat
[2012.06.13 22:04:27 | 000,126,394 | ---- | C] () -- C:\Windows\SysNative\perfc007.dat
[2012.06.13 22:04:27 | 000,038,104 | ---- | C] () -- C:\Windows\SysNative\perfd007.dat
[2012.06.13 21:56:08 | 000,000,926 | ---- | C] () -- C:\Windows\MOD01SET74DE0N0003.XML
[2012.06.13 21:55:31 | 000,000,267 | ---- | C] () -- C:\Windows\LaunApp.ini
[2012.06.13 21:55:29 | 000,000,441 | RHS- | C] () -- C:\Patch.rev
[2012.06.13 21:55:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\1025_Acer_Packard Bell_EasyNote LM85.mrk
[2012.06.13 21:55:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\drivers\1025_Acer_Packard Bell_EasyNote LM85.mrk
[2012.06.13 21:53:57 | 001,991,936 | ---- | C] () -- C:\Windows\SysNative\iglhxa64.cpa
[2012.06.13 21:53:57 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2012.06.13 21:53:57 | 000,205,824 | ---- | C] () -- C:\Windows\SysNative\iglhsip64.dll
[2012.06.13 21:53:57 | 000,152,600 | ---- | C] () -- C:\Windows\SysNative\difx64.exe
[2012.06.13 21:53:57 | 000,060,254 | ---- | C] () -- C:\Windows\SysNative\iglhxg64.vp
[2012.06.13 21:53:57 | 000,060,226 | ---- | C] () -- C:\Windows\SysNative\iglhxc64.vp
[2012.06.13 21:53:57 | 000,060,015 | ---- | C] () -- C:\Windows\SysNative\iglhxo64.vp
[2012.06.13 21:53:57 | 000,005,368 | ---- | C] () -- C:\Windows\SysNative\iglhxs64.vp
[2012.06.13 21:53:57 | 000,001,090 | ---- | C] () -- C:\Windows\SysNative\iglhxa64.vp
[2012.06.13 21:53:56 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2012.06.13 21:53:56 | 000,870,560 | ---- | C] () -- C:\Windows\SysNative\igkrng575.bin
[2012.06.13 21:53:56 | 000,189,369 | ---- | C] () -- C:\Windows\SysNative\Gfxres.th-TH.resources
[2012.06.13 21:53:56 | 000,187,392 | ---- | C] () -- C:\Windows\SysNative\iglhcp64.dll
[2012.06.13 21:53:56 | 000,178,235 | ---- | C] () -- C:\Windows\SysNative\Gfxres.el-GR.resources
[2012.06.13 21:53:56 | 000,165,209 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ru-RU.resources
[2012.06.13 21:53:56 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2012.06.13 21:53:56 | 000,139,736 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ar-SA.resources
[2012.06.13 21:53:56 | 000,136,237 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ja-JP.resources
[2012.06.13 21:53:56 | 000,133,575 | ---- | C] () -- C:\Windows\SysNative\Gfxres.he-IL.resources
[2012.06.13 21:53:56 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2012.06.13 21:53:56 | 000,127,868 | ---- | C] () -- C:\Windows\SysNative\igcompkrng575.bin
[2012.06.13 21:53:56 | 000,125,382 | ---- | C] () -- C:\Windows\SysNative\Gfxres.it-IT.resources
[2012.06.13 21:53:56 | 000,123,063 | ---- | C] () -- C:\Windows\SysNative\Gfxres.ko-KR.resources
[2012.06.13 21:53:56 | 000,122,758 | ---- | C] () -- C:\Windows\SysNative\Gfxres.es-ES.resources
[2012.06.13 21:53:56 | 000,122,535 | ---- | C] () -- C:\Windows\SysNative\Gfxres.de-DE.resources
[2012.06.13 21:53:56 | 000,121,000 | ---- | C] () -- C:\Windows\SysNative\Gfxres.tr-TR.resources
[2012.06.13 21:53:56 | 000,120,616 | ---- | C] () -- C:\Windows\SysNative\Gfxres.fr-FR.resources
[2012.06.13 21:53:56 | 000,120,195 | ---- | C] () -- C:\Windows\SysNative\Gfxres.pt-BR.resources
[2012.06.13 21:53:56 | 000,119,433 | ---- | C] () -- C:\Windows\SysNative\Gfxres.hu-HU.resources
[2012.06.13 21:53:56 | 000,119,416 | ---- | C] () -- C:\Windows\SysNative\Gfxres.nl-NL.resources
[2012.06.13 21:53:56 | 000,119,176 | ---- | C] () -- C:\Windows\SysNative\Gfxres.sv-SE.resources
[2012.06.13 21:53:56 | 000,118,893 | ---- | C] () -- C:\Windows\SysNative\Gfxres.pt-PT.resources
[2012.06.13 21:53:56 | 000,118,589 | ---- | C] () -- C:\Windows\SysNative\Gfxres.cs-CZ.resources
[2012.06.13 21:53:56 | 000,118,512 | ---- | C] () -- C:\Windows\SysNative\Gfxres.fi-FI.resources
[2012.06.13 21:53:56 | 000,118,244 | ---- | C] () -- C:\Windows\SysNative\Gfxres.pl-PL.resources
[2012.06.13 21:53:56 | 000,117,884 | ---- | C] () -- C:\Windows\SysNative\Gfxres.sk-SK.resources
[2012.06.13 21:53:56 | 000,114,668 | ---- | C] () -- C:\Windows\SysNative\Gfxres.nb-NO.resources
[2012.06.13 21:53:56 | 000,114,189 | ---- | C] () -- C:\Windows\SysNative\Gfxres.sl-SI.resources
[2012.06.13 21:53:56 | 000,114,077 | ---- | C] () -- C:\Windows\SysNative\Gfxres.da-DK.resources
[2012.06.13 21:53:56 | 000,110,040 | ---- | C] () -- C:\Windows\SysNative\Gfxres.en-US.resources
[2012.06.13 21:53:56 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2012.06.13 21:53:56 | 000,104,636 | ---- | C] () -- C:\Windows\SysNative\igfcg575m.bin
[2012.06.13 21:53:56 | 000,103,868 | ---- | C] () -- C:\Windows\SysNative\Gfxres.zh-TW.resources
[2012.06.13 21:53:56 | 000,102,707 | ---- | C] () -- C:\Windows\SysNative\Gfxres.zh-CN.resources
[2012.06.13 21:53:56 | 000,004,096 | ---- | C] ( ) -- C:\Windows\SysNative\IGFXDEVLib.dll
[2012.06.13 21:53:56 | 000,000,151 | ---- | C] () -- C:\Windows\SysNative\GfxUI.exe.config
[2012.06.13 21:53:48 | 000,000,201 | ---- | C] () -- C:\Windows\USER.XML
[2012.06.13 21:53:33 | 000,001,652 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2012.06.13 21:11:17 | 000,083,785 | ---- | C] () -- C:\Users\Ati\Documents\Download.jpg
[2012.06.13 21:09:19 | 000,103,621 | ---- | C] () -- C:\Users\Ati\Documents\so sieht es jetzt aus.jpg
[2012.06.13 20:48:11 | 000,120,760 | ---- | C] () -- C:\Users\Ati\Documents\Partition.jpg
[2012.06.13 20:38:25 | 000,102,742 | ---- | C] () -- C:\Users\Ati\Documents\deswegen.jpg
[2012.06.13 18:26:32 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.13 17:01:21 | 000,001,831 | ---- | C] () -- C:\Users\Ati\Desktop\NeroStartSmart - Verknüpfung.lnk
[2012.06.13 16:56:09 | 000,001,023 | ---- | C] () -- C:\Users\Ati\Desktop\clip2net - Verknüpfung.lnk
[2012.06.13 15:29:59 | 000,001,190 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.06.13 14:18:24 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.06.13 14:14:26 | 000,001,201 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MultiSkypeLauncher.lnk
[2012.06.13 13:50:16 | 000,002,082 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.06.13 13:48:27 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.13 13:17:40 | 000,002,609 | ---- | C] () -- C:\Users\Public\Desktop\eBay.lnk
[2012.06.13 13:17:40 | 000,001,421 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.06.13 13:17:34 | 000,001,455 | ---- | C] () -- C:\Users\Ati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.06.13 13:17:30 | 000,001,962 | ---- | C] () -- C:\Users\Public\Desktop\PB Zubehör Shop.lnk
[2012.06.13 13:05:01 | 000,001,237 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 8.0.lnk
[2012.06.13 13:05:01 | 000,001,225 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Photoshop Elements 8.0.lnk
[2012.06.13 13:02:52 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2012.06.13 12:23:02 | 000,000,020 | ---- | C] () -- C:\Windows\lôN
[2012.06.13 12:18:36 | 000,206,208 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2012.06.13 12:18:36 | 000,000,302 | ---- | C] () -- C:\Windows\PidList_C.ini
[2012.06.13 12:18:27 | 000,000,184 | ---- | C] () -- C:\Windows\LMv4.UNI
[2012.06.13 12:18:18 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012.06.13 12:15:42 | 000,247,560 | ---- | C] () -- C:\Windows\SysNative\drivers\RTConvEQ.dat
[2012.06.13 12:15:42 | 000,037,468 | ---- | C] () -- C:\Windows\SysNative\drivers\RtPCEE3.DAT
[2012.06.13 12:15:42 | 000,001,448 | ---- | C] () -- C:\Windows\SysNative\drivers\RtHdatEx.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX3.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX2.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX1.dat
[2012.06.13 12:15:42 | 000,000,520 | ---- | C] () -- C:\Windows\SysNative\drivers\RTEQEX0.dat
[2012.06.13 12:15:42 | 000,000,176 | ---- | C] () -- C:\Windows\SysNative\drivers\RTHDAEQ1.dat
[2012.06.13 12:15:42 | 000,000,016 | ---- | C] () -- C:\Windows\SysNative\drivers\rtkhdaud.dat
[2012.06.13 12:09:35 | 2205,544,448 | -HS- | C] () -- C:\hiberfil.sys
[2010.09.08 05:16:07 | 000,000,325 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2010.09.08 05:16:07 | 000,000,271 | ---- | C] () -- C:\Windows\WisPriority.ini
[2010.09.08 05:16:07 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini
 
========== LOP Check ==========
 
[2009.07.14 07:08:49 | 000,006,866 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.06.13 13:45:50 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Ad-Aware Antivirus
[2012.06.13 22:35:11 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Adobe
[2012.06.13 13:55:33 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Avira
[2012.06.13 23:01:02 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\G-Recorder
[2012.06.13 13:17:19 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Identities
[2012.06.13 13:17:52 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Macromedia
[2012.06.13 13:48:32 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Malwarebytes
[2010.09.08 05:25:27 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Media Center Programs
[2012.06.13 16:56:31 | 000,000,000 | --SD | M] -- C:\Users\Ati\AppData\Roaming\Microsoft
[2012.06.13 14:19:13 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Mozilla
[2012.06.13 14:15:41 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\MultiSkypeLauncher
[2012.06.13 16:57:51 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Nero
[2012.06.15 15:56:05 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\Skype
[2012.06.13 15:23:59 | 000,000,000 | ---D | M] -- C:\Users\Ati\AppData\Roaming\TeamViewer
 
< %APPDATA%\*.exe /s >
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2010.03.04 05:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- C:\OEM\Preload\Autorun\DRV\AHCI\F6\f6flpy-x86\iaStor.sys
[2010.03.04 05:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\OEM\Preload\Autorun\DRV\AHCI\F6\f6flpy-x64\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_78ebae21a80aa2b4\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SoftwareDistribution\Download\381aab19d0d6e32692591e63c85c2f8b\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\SysNative\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010.09.08 04:41:06 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010.09.08 04:41:06 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2010.09.08 04:41:06 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---
[/code]

cosinus 15.06.2012 17:31

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1561552
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\URLSearchHook: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1561552
IE - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = http://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
[2012.06.13 23:07:37 | 000,000,000 | ---D | M] (Hotspot Shield Community Toolbar) -- C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
[2012.06.13 23:06:33 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Hotspot Shield Toolbar) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\..\Toolbar\WebBrowser: (Hotspot Shield Toolbar) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll (Conduit Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
[2012.06.13 23:07:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012.06.13 23:07:31 | 000,000,000 | ---D | C] -- C:\Users\Ati\AppData\Local\Conduit
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

derhunne 15.06.2012 19:22

Bitte schön





Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{c95a4e8e-816d-4655-8c79-d736da1adb6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\ deleted successfully.
C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
HKU\S-1-5-21-3025037035-3077624742-2941347832-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3025037035-3077624742-2941347832-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{c95a4e8e-816d-4655-8c79-d736da1adb6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\ not found.
File C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll not found.
HKEY_USERS\S-1-5-21-3025037035-3077624742-2941347832-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3025037035-3077624742-2941347832-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-3025037035-3077624742-2941347832-1000\Software\Microsoft\Internet Explorer\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}\ not found.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\searchplugin folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\Plugins folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\modules folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\META-INF folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\defaults folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\chrome folder moved successfully.
C:\Users\Ati\AppData\Roaming\mozilla\Firefox\Profiles\4u5ce4hn.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d} folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\skin folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\locale\en-US folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\locale folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\defaults\preferences folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\defaults folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\components folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\chrome\content folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com\chrome folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\afurladvisor@anchorfree.com folder moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\ deleted successfully.
C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\ not found.
File C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\ deleted successfully.
C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{c95a4e8e-816d-4655-8c79-d736da1adb6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\ not found.
File C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3025037035-3077624742-2941347832-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}\ not found.
File C:\Program Files (x86)\Hotspot_Shield\prxtbHots.dll not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
C:\Program Files (x86)\Conduit\Community Alerts folder moved successfully.
C:\Program Files (x86)\Conduit folder moved successfully.
C:\Users\Ati\AppData\Local\Conduit\CT1561552 folder moved successfully.
C:\Users\Ati\AppData\Local\Conduit folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Ati
->Temp folder emptied: 19191720 bytes
->Temporary Internet Files folder emptied: 65698049 bytes
->FireFox cache emptied: 358281364 bytes
->Flash cache emptied: 2366 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1128465 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 107872849 bytes
 
Total Files Cleaned = 527,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Ati
->Flash cache emptied: 0 bytes
 
User: Default
 
User: Default User
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.48.0 log created on 06152012_201342

Files\Folders moved on Reboot...
C:\Users\Ati\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.

Registry entries deleted on Reboot...


cosinus 15.06.2012 20:28

Danke? :D

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

derhunne 15.06.2012 21:38

hier ..geht nicht anders ...ist zu lang...erstmal teil 1 rest folgt gleich...



Code:

22:12:01.0745 4276        TDSS rootkit removing tool 2.7.40.0 Jun 15 2012 15:13:31
22:12:01.0761 4276        ============================================================
22:12:01.0761 4276        Current date / time: 2012/06/15 22:12:01.0761
22:12:01.0761 4276        SystemInfo:
22:12:01.0761 4276       
22:12:01.0761 4276        OS Version: 6.1.7600 ServicePack: 0.0
22:12:01.0761 4276        Product type: Workstation
22:12:01.0761 4276        ComputerName: ATI-PC
22:12:01.0761 4276        UserName: Ati
22:12:01.0761 4276        Windows directory: C:\Windows
22:12:01.0761 4276        System windows directory: C:\Windows
22:12:01.0761 4276        Running under WOW64
22:12:01.0761 4276        Processor architecture: Intel x64
22:12:01.0761 4276        Number of processors: 2
22:12:01.0761 4276        Page size: 0x1000
22:12:01.0761 4276        Boot type: Normal boot
22:12:01.0761 4276        ============================================================
22:12:02.0291 4276        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:12:02.0291 4276        ============================================================
22:12:02.0291 4276        \Device\Harddisk0\DR0:
22:12:02.0291 4276        MBR partitions:
22:12:02.0307 4276        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1964800, BlocksNum 0x32000
22:12:02.0307 4276        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1996800, BlocksNum 0x7DBB998
22:12:02.0307 4276        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x10C83000, BlocksNum 0x14406000
22:12:02.0338 4276        \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x25089800, BlocksNum 0x152FC000
22:12:02.0338 4276        ============================================================
22:12:02.0369 4276        C: <-> \Device\Harddisk0\DR0\Partition1
22:12:02.0400 4276        E: <-> \Device\Harddisk0\DR0\Partition2
22:12:02.0431 4276        D: <-> \Device\Harddisk0\DR0\Partition3
22:12:02.0431 4276        ============================================================
22:12:02.0431 4276        Initialize success
22:12:02.0431 4276        ============================================================
22:12:57.0453 2860        ============================================================
22:12:57.0453 2860        Scan started
22:12:57.0453 2860        Mode: Manual; SigCheck; TDLFS;
22:12:57.0453 2860        ============================================================
22:12:58.0046 2860        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:12:58.0202 2860        1394ohci - ok
22:12:58.0264 2860        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:12:58.0311 2860        ACPI - ok
22:12:58.0358 2860        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:12:58.0436 2860        AcpiPmi - ok
22:12:58.0592 2860        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:12:58.0623 2860        AdobeActiveFileMonitor8.0 - ok
22:12:58.0779 2860        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:12:58.0810 2860        AdobeFlashPlayerUpdateSvc - ok
22:12:58.0888 2860        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:12:58.0935 2860        adp94xx - ok
22:12:58.0997 2860        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:12:59.0044 2860        adpahci - ok
22:12:59.0075 2860        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:12:59.0106 2860        adpu320 - ok
22:12:59.0153 2860        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:12:59.0309 2860        AeLookupSvc - ok
22:12:59.0372 2860        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:12:59.0450 2860        AFD - ok
22:12:59.0481 2860        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:12:59.0512 2860        agp440 - ok
22:12:59.0559 2860        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:12:59.0621 2860        ALG - ok
22:12:59.0652 2860        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:12:59.0668 2860        aliide - ok
22:12:59.0699 2860        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:12:59.0730 2860        amdide - ok
22:12:59.0762 2860        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:12:59.0824 2860        AmdK8 - ok
22:12:59.0871 2860        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:12:59.0918 2860        AmdPPM - ok
22:12:59.0949 2860        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:12:59.0980 2860        amdsata - ok
22:13:00.0027 2860        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:13:00.0074 2860        amdsbs - ok
22:13:00.0089 2860        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:13:00.0105 2860        amdxata - ok
22:13:00.0167 2860        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:13:00.0198 2860        AmUStor - ok
22:13:00.0292 2860        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:13:00.0308 2860        AntiVirSchedulerService - ok
22:13:00.0339 2860        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:13:00.0354 2860        AntiVirService - ok
22:13:00.0417 2860        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:13:00.0526 2860        AppID - ok
22:13:00.0557 2860        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:13:00.0635 2860        AppIDSvc - ok
22:13:00.0666 2860        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:13:00.0713 2860        Appinfo - ok
22:13:00.0760 2860        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:13:00.0791 2860        arc - ok
22:13:00.0807 2860        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:13:00.0838 2860        arcsas - ok
22:13:00.0885 2860        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:13:00.0963 2860        AsyncMac - ok
22:13:01.0025 2860        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:13:01.0041 2860        atapi - ok
22:13:01.0275 2860        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:13:01.0400 2860        athr - ok
22:13:01.0556 2860        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:13:01.0649 2860        AudioEndpointBuilder - ok
22:13:01.0665 2860        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:13:01.0712 2860        AudioSrv - ok
22:13:01.0758 2860        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:13:01.0883 2860        avgntflt - ok
22:13:01.0914 2860        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:13:01.0992 2860        avipbb - ok
22:13:01.0992 2860        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:13:02.0055 2860        avkmgr - ok
22:13:02.0133 2860        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:13:02.0226 2860        AxInstSV - ok
22:13:02.0320 2860        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:13:02.0382 2860        b06bdrv - ok
22:13:02.0460 2860        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:13:02.0538 2860        b57nd60a - ok
22:13:02.0694 2860        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:13:02.0772 2860        BCM43XX - ok
22:13:02.0835 2860        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:13:02.0897 2860        BDESVC - ok
22:13:02.0960 2860        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:13:03.0053 2860        Beep - ok
22:13:03.0162 2860        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:13:03.0272 2860        BFE - ok
22:13:03.0365 2860        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:13:03.0490 2860        BITS - ok
22:13:03.0568 2860        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:13:03.0615 2860        blbdrive - ok
22:13:03.0677 2860        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:13:03.0740 2860        bowser - ok
22:13:03.0771 2860        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:13:03.0818 2860        BrFiltLo - ok
22:13:03.0833 2860        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:13:03.0864 2860        BrFiltUp - ok
22:13:03.0911 2860        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:13:03.0989 2860        Browser - ok
22:13:04.0020 2860        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:13:04.0067 2860        Brserid - ok
22:13:04.0083 2860        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:13:04.0130 2860        BrSerWdm - ok
22:13:04.0145 2860        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:13:04.0192 2860        BrUsbMdm - ok
22:13:04.0208 2860        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:13:04.0239 2860        BrUsbSer - ok
22:13:04.0239 2860        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:13:04.0286 2860        BTHMODEM - ok
22:13:04.0301 2860        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:13:04.0379 2860        bthserv - ok
22:13:04.0426 2860        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:13:04.0520 2860        cdfs - ok
22:13:04.0566 2860        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:13:04.0613 2860        cdrom - ok
22:13:04.0660 2860        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:13:04.0738 2860        CertPropSvc - ok
22:13:04.0769 2860        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:13:04.0832 2860        circlass - ok
22:13:04.0894 2860        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:13:04.0941 2860        CLFS - ok
22:13:05.0003 2860        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:13:05.0034 2860        clr_optimization_v2.0.50727_32 - ok
22:13:05.0081 2860        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:13:05.0112 2860        clr_optimization_v2.0.50727_64 - ok
22:13:05.0144 2860        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:13:05.0175 2860        CmBatt - ok
22:13:05.0206 2860        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:13:05.0237 2860        cmdide - ok
22:13:05.0315 2860        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:13:05.0393 2860        CNG - ok
22:13:05.0424 2860        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:13:05.0456 2860        Compbatt - ok
22:13:05.0471 2860        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:13:05.0518 2860        CompositeBus - ok
22:13:05.0534 2860        COMSysApp - ok
22:13:05.0549 2860        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:13:05.0580 2860        crcdisk - ok
22:13:05.0643 2860        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:13:05.0705 2860        CryptSvc - ok
22:13:05.0799 2860        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:13:05.0908 2860        DcomLaunch - ok
22:13:05.0970 2860        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:13:06.0080 2860        defragsvc - ok
22:13:06.0126 2860        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:13:06.0189 2860        DfsC - ok
22:13:06.0267 2860        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:13:06.0376 2860        Dhcp - ok
22:13:06.0423 2860        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:13:06.0516 2860        discache - ok
22:13:06.0563 2860        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:13:06.0594 2860        Disk - ok
22:13:06.0641 2860        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:13:06.0688 2860        Dnscache - ok
22:13:06.0750 2860        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:13:06.0844 2860        dot3svc - ok
22:13:06.0875 2860        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:13:06.0969 2860        DPS - ok
22:13:07.0000 2860        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:13:07.0016 2860        drmkaud - ok
22:13:07.0140 2860        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:13:07.0234 2860        DsiWMIService - ok
22:13:07.0343 2860        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:13:07.0406 2860        DXGKrnl - ok
22:13:07.0437 2860        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:13:07.0499 2860        EapHost - ok
22:13:07.0811 2860        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:13:07.0936 2860        ebdrv - ok
22:13:08.0061 2860        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:13:08.0108 2860        EFS - ok
22:13:08.0248 2860        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:13:08.0326 2860        ehRecvr - ok
22:13:08.0357 2860        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:13:08.0404 2860        ehSched - ok
22:13:08.0513 2860        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:13:08.0576 2860        elxstor - ok
22:13:08.0794 2860        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:13:08.0934 2860        ePowerSvc - ok
22:13:09.0090 2860        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:13:09.0122 2860        ErrDev - ok
22:13:09.0200 2860        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:13:09.0309 2860        EventSystem - ok
22:13:09.0387 2860        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:13:09.0496 2860        exfat - ok
22:13:09.0527 2860        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:13:09.0590 2860        fastfat - ok
22:13:09.0683 2860        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:13:09.0761 2860        Fax - ok
22:13:09.0777 2860        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:13:09.0808 2860        fdc - ok
22:13:09.0855 2860        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:13:09.0933 2860        fdPHost - ok
22:13:09.0948 2860        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:13:09.0995 2860        FDResPub - ok
22:13:10.0026 2860        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:13:10.0042 2860        FileInfo - ok
22:13:10.0058 2860        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:13:10.0120 2860        Filetrace - ok
22:13:10.0229 2860        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:13:10.0292 2860        FLEXnet Licensing Service - ok
22:13:10.0307 2860        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:13:10.0323 2860        flpydisk - ok
22:13:10.0370 2860        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:13:10.0401 2860        FltMgr - ok
22:13:10.0526 2860        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:13:10.0635 2860        FontCache - ok
22:13:10.0697 2860        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:13:10.0713 2860        FontCache3.0.0.0 - ok
22:13:10.0760 2860        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:13:10.0791 2860        FsDepends - ok
22:13:10.0838 2860        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:13:10.0853 2860        Fs_Rec - ok
22:13:10.0900 2860        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:13:10.0947 2860        fvevol - ok
22:13:10.0978 2860        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:13:11.0009 2860        gagp30kx - ok
22:13:11.0118 2860        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:13:11.0165 2860        GameConsoleService - ok
22:13:11.0274 2860        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:13:11.0337 2860        gpsvc - ok
22:13:11.0399 2860        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:13:11.0477 2860        GREGService - ok
22:13:11.0508 2860        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:13:11.0571 2860        hcw85cir - ok
22:13:11.0633 2860        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:13:11.0680 2860        HdAudAddService - ok
22:13:11.0711 2860        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:13:11.0774 2860        HDAudBus - ok
22:13:11.0820 2860        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:13:11.0898 2860        HECIx64 - ok
22:13:11.0930 2860        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:13:11.0961 2860        HidBatt - ok
22:13:11.0976 2860        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:13:12.0023 2860        HidBth - ok
22:13:12.0039 2860        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:13:12.0086 2860        HidIr - ok
22:13:12.0132 2860        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:13:12.0210 2860        hidserv - ok
22:13:12.0242 2860        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:13:12.0273 2860        HidUsb - ok
22:13:12.0335 2860        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:13:12.0429 2860        hkmsvc - ok
22:13:12.0460 2860        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:13:12.0538 2860        HomeGroupListener - ok
22:13:12.0569 2860        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:13:12.0600 2860        HomeGroupProvider - ok
22:13:12.0663 2860        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:13:12.0694 2860        HpSAMD - ok
22:13:12.0834 2860        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:13:12.0881 2860        hshld - ok
22:13:12.0912 2860        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:13:12.0990 2860        HssDrv - ok
22:13:13.0053 2860        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:13:13.0084 2860        HssSrv - ok
22:13:13.0131 2860        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:13:13.0146 2860        HssTrayService - ok
22:13:13.0162 2860        HssWd - ok
22:13:13.0256 2860        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:13:13.0334 2860        HTTP - ok
22:13:13.0365 2860        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:13:13.0380 2860        hwpolicy - ok
22:13:13.0412 2860        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:13:13.0427 2860        i8042prt - ok
22:13:13.0505 2860        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:13:13.0614 2860        iaStor - ok
22:13:13.0677 2860        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:13:13.0724 2860        iaStorV - ok
22:13:13.0848 2860        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:13:13.0926 2860        idsvc - ok
22:13:14.0660 2860        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:13:15.0096 2860        igfx - ok
22:13:15.0237 2860        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:13:15.0268 2860        iirsp - ok
22:13:15.0362 2860        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:13:15.0486 2860        IKEEXT - ok
22:13:15.0533 2860        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:13:15.0580 2860        Impcd - ok
22:13:15.0814 2860        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:13:15.0986 2860        IntcAzAudAddService - ok
22:13:16.0173 2860        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:13:16.0235 2860        IntcDAud - ok
22:13:16.0266 2860        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:13:16.0298 2860        intelide - ok
22:13:16.0329 2860        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:13:16.0360 2860        intelppm - ok
22:13:16.0407 2860        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:13:16.0500 2860        IPBusEnum - ok
22:13:16.0547 2860        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:13:16.0625 2860        IpFilterDriver - ok
22:13:16.0672 2860        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:13:16.0766 2860        iphlpsvc - ok
22:13:16.0781 2860        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:13:16.0797 2860        IPMIDRV - ok
22:13:16.0812 2860        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:13:16.0890 2860        IPNAT - ok
22:13:16.0922 2860        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:13:16.0968 2860        IRENUM - ok
22:13:16.0984 2860        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:13:17.0000 2860        isapnp - ok
22:13:17.0046 2860        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:13:17.0093 2860        iScsiPrt - ok
22:13:17.0156 2860        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:13:17.0249 2860        k57nd60a - ok
22:13:17.0280 2860        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:13:17.0312 2860        kbdclass - ok
22:13:17.0327 2860        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:13:17.0374 2860        kbdhid - ok
22:13:17.0390 2860        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:13:17.0421 2860        KeyIso - ok
22:13:17.0436 2860        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:13:17.0452 2860        KSecDD - ok
22:13:17.0483 2860        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:13:17.0514 2860        KSecPkg - ok
22:13:17.0561 2860        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:13:17.0639 2860        ksthunk - ok
22:13:17.0686 2860        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:13:17.0795 2860        KtmRm - ok
22:13:17.0842 2860        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:13:17.0858 2860        L1E - ok
22:13:17.0920 2860        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:13:17.0982 2860        LanmanServer - ok
22:13:18.0029 2860        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:13:18.0123 2860        LanmanWorkstation - ok
22:13:18.0154 2860        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:13:18.0232 2860        lltdio - ok
22:13:18.0279 2860        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:13:18.0372 2860        lltdsvc - ok
22:13:18.0404 2860        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:13:18.0466 2860        lmhosts - ok
22:13:18.0606 2860        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:13:18.0684 2860        LMS - ok
22:13:18.0747 2860        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:13:18.0778 2860        LSI_FC - ok
22:13:18.0794 2860        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:13:18.0809 2860        LSI_SAS - ok
22:13:18.0825 2860        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:13:18.0856 2860        LSI_SAS2 - ok
22:13:18.0872 2860        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:13:18.0903 2860        LSI_SCSI - ok
22:13:18.0934 2860        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:13:19.0028 2860        luafv - ok
22:13:19.0059 2860        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:13:19.0137 2860        MBAMProtector - ok
22:13:19.0215 2860        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:13:19.0277 2860        MBAMService - ok
22:13:19.0308 2860        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:13:19.0355 2860        Mcx2Svc - ok
22:13:19.0386 2860        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:13:19.0402 2860        megasas - ok
22:13:19.0449 2860        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:13:19.0496 2860        MegaSR - ok
22:13:19.0527 2860        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:13:19.0605 2860        MMCSS - ok
22:13:19.0620 2860        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:13:19.0652 2860        Modem - ok
22:13:19.0683 2860        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:13:19.0714 2860        monitor - ok
22:13:19.0745 2860        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:13:19.0776 2860        mouclass - ok
22:13:19.0776 2860        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:13:19.0808 2860        mouhid - ok
22:13:19.0823 2860        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:13:19.0854 2860        mountmgr - ok
22:13:19.0948 2860        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:13:19.0979 2860        MozillaMaintenance - ok
22:13:20.0010 2860        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:13:20.0042 2860        mpio - ok
22:13:20.0073 2860        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:13:20.0151 2860        mpsdrv - ok
22:13:20.0229 2860        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:13:20.0338 2860        MpsSvc - ok
22:13:20.0354 2860        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:13:20.0400 2860        MRxDAV - ok
22:13:20.0432 2860        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:13:20.0478 2860        mrxsmb - ok
22:13:20.0510 2860        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:13:20.0556 2860        mrxsmb10 - ok
22:13:20.0588 2860        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:13:20.0619 2860        mrxsmb20 - ok
22:13:20.0650 2860        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:13:20.0681 2860        msahci - ok
22:13:20.0697 2860        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:13:20.0728 2860        msdsm - ok
22:13:20.0775 2860        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:13:20.0806 2860        MSDTC - ok
22:13:20.0822 2860        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:13:20.0900 2860        Msfs - ok
22:13:20.0915 2860        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:13:20.0978 2860        mshidkmdf - ok
22:13:20.0993 2860        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:13:20.0993 2860        msisadrv - ok
22:13:21.0040 2860        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:13:21.0134 2860        MSiSCSI - ok
22:13:21.0134 2860        msiserver - ok
22:13:21.0165 2860        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:13:21.0196 2860        MSKSSRV - ok
22:13:21.0212 2860        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:13:21.0274 2860        MSPCLOCK - ok
22:13:21.0274 2860        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:13:21.0321 2860        MSPQM - ok
22:13:21.0368 2860        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:13:21.0383 2860        MsRPC - ok
22:13:21.0383 2860        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:13:21.0399 2860        mssmbios - ok
22:13:21.0430 2860        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:13:21.0492 2860        MSTEE - ok
22:13:21.0508 2860        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:13:21.0555 2860        MTConfig - ok
22:13:21.0555 2860        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:13:21.0586 2860        Mup - ok
22:13:21.0664 2860        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:13:21.0758 2860        napagent - ok
22:13:21.0804 2860        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:13:21.0882 2860        NativeWifiP - ok
22:13:22.0023 2860        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:13:22.0101 2860        NDIS - ok
22:13:22.0148 2860        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:13:22.0241 2860        NdisCap - ok
22:13:22.0272 2860        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:13:22.0350 2860        NdisTapi - ok
22:13:22.0382 2860        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:13:22.0491 2860        Ndisuio - ok
22:13:22.0506 2860        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:13:22.0553 2860        NdisWan - ok
22:13:22.0569 2860        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:13:22.0616 2860        NDProxy - ok
22:13:22.0787 2860        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:13:22.0881 2860        Nero BackItUp Scheduler 4.0 - ok
22:13:22.0928 2860        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:13:23.0021 2860        NetBIOS - ok
22:13:23.0052 2860        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:13:23.0115 2860        NetBT - ok
22:13:23.0162 2860        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:13:23.0177 2860        Netlogon - ok
22:13:23.0224 2860        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:13:23.0302 2860        Netman - ok
22:13:23.0349 2860        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:13:23.0411 2860        netprofm - ok
22:13:23.0489 2860        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:13:23.0520 2860        NetTcpPortSharing - ok
22:13:23.0552 2860        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:13:23.0583 2860        nfrd960 - ok
22:13:23.0645 2860        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:13:23.0754 2860        NlaSvc - ok
22:13:23.0801 2860        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:13:23.0895 2860        Npfs - ok
22:13:23.0926 2860        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:13:24.0004 2860        nsi - ok
22:13:24.0004 2860        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:13:24.0066 2860        nsiproxy - ok
22:13:24.0254 2860        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:13:24.0347 2860        Ntfs - ok
22:13:24.0503 2860        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:13:24.0550 2860        NTI IScheduleSvc - ok
22:13:24.0675 2860        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:13:24.0753 2860        NTIDrvr - ok
22:13:24.0784 2860        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:13:24.0862 2860        Null - ok
22:13:24.0909 2860        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:13:24.0956 2860        nvraid - ok
22:13:25.0002 2860        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:13:25.0034 2860        nvstor - ok
22:13:25.0080 2860        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:13:25.0096 2860        nv_agp - ok
22:13:25.0096 2860        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:13:25.0127 2860        ohci1394 - ok
22:13:25.0174 2860        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:13:25.0236 2860        p2pimsvc - ok
22:13:25.0299 2860        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:13:25.0330 2860        p2psvc - ok
22:13:25.0377 2860        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:13:25.0408 2860        Parport - ok
22:13:25.0424 2860        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:13:25.0455 2860        partmgr - ok
22:13:25.0470 2860        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:13:25.0533 2860        PcaSvc - ok
22:13:25.0564 2860        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:13:25.0595 2860        pci - ok
22:13:25.0611 2860        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:13:25.0642 2860        pciide - ok
22:13:25.0673 2860        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:13:25.0720 2860        pcmcia - ok
22:13:25.0736 2860        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:13:25.0751 2860        pcw - ok
22:13:25.0798 2860        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:13:25.0892 2860        PEAUTH - ok
22:13:26.0001 2860        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:13:26.0048 2860        PerfHost - ok
22:13:26.0204 2860        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:13:26.0328 2860        pla - ok
22:13:26.0406 2860        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:13:26.0453 2860        PlugPlay - ok
22:13:26.0484 2860        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:13:26.0531 2860        PNRPAutoReg - ok
22:13:26.0547 2860        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:13:26.0594 2860        PNRPsvc - ok
22:13:26.0656 2860        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:13:26.0765 2860        PolicyAgent - ok
22:13:26.0828 2860        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:13:26.0921 2860        Power - ok
22:13:26.0999 2860        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:13:27.0093 2860        PptpMiniport - ok
22:13:27.0108 2860        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:13:27.0124 2860        Processor - ok
22:13:27.0171 2860        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:13:27.0218 2860        ProfSvc - ok
22:13:27.0249 2860        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:13:27.0264 2860        ProtectedStorage - ok
22:13:27.0327 2860        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:13:27.0389 2860        Psched - ok
22:13:27.0436 2860        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:13:27.0514 2860        PxHlpa64 - ok
22:13:27.0670 2860        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:13:27.0764 2860        ql2300 - ok
22:13:27.0920 2860        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:13:27.0951 2860        ql40xx - ok
22:13:27.0998 2860        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:13:28.0060 2860        QWAVE - ok
22:13:28.0076 2860        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:13:28.0122 2860        QWAVEdrv - ok
22:13:28.0154 2860        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:13:28.0216 2860        RasAcd - ok
22:13:28.0247 2860        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:13:28.0325 2860        RasAgileVpn - ok
22:13:28.0372 2860        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:13:28.0450 2860        RasAuto - ok
22:13:28.0481 2860        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:13:28.0559 2860        Rasl2tp - ok
22:13:28.0606 2860        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:13:28.0715 2860        RasMan - ok
22:13:28.0746 2860        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:13:28.0840 2860        RasPppoe - ok
22:13:28.0840 2860        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:13:28.0918 2860        RasSstp - ok
22:13:28.0934 2860        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:13:28.0980 2860        rdbss - ok
22:13:28.0996 2860        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:13:29.0027 2860        rdpbus - ok
22:13:29.0058 2860        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:13:29.0105 2860        RDPCDD - ok
22:13:29.0105 2860        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:13:29.0168 2860        RDPENCDD - ok
22:13:29.0168 2860        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:13:29.0214 2860        RDPREFMP - ok
22:13:29.0261 2860        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:13:29.0324 2860        RDPWD - ok
22:13:29.0402 2860        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:13:29.0433 2860        rdyboost - ok
22:13:29.0464 2860        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:13:29.0542 2860        RemoteAccess - ok
22:13:29.0589 2860        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:13:29.0698 2860        RemoteRegistry - ok
22:13:29.0729 2860        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:13:29.0792 2860        RpcEptMapper - ok
22:13:29.0823 2860        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:13:29.0838 2860        RpcLocator - ok
22:13:29.0901 2860        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:13:29.0963 2860        RpcSs - ok
22:13:30.0041 2860        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:13:30.0119 2860        rspndr - ok
22:13:30.0150 2860        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:13:30.0166 2860        SamSs - ok
22:13:30.0182 2860        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:13:30.0197 2860        sbp2port - ok
22:13:30.0244 2860        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:13:30.0322 2860        SCardSvr - ok
22:13:30.0322 2860        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:13:30.0384 2860        scfilter - ok
22:13:30.0509 2860        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:13:30.0587 2860        Schedule - ok
22:13:30.0618 2860        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:13:30.0696 2860        SCPolicySvc - ok
22:13:30.0743 2860        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:13:30.0806 2860        SDRSVC - ok
22:13:30.0868 2860        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:13:30.0962 2860        secdrv - ok
22:13:30.0993 2860        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:13:31.0086 2860        seclogon - ok
22:13:31.0102 2860        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:13:31.0149 2860        SENS - ok
22:13:31.0149 2860        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:13:31.0227 2860        SensrSvc - ok
22:13:31.0258 2860        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:13:31.0274 2860        Serenum - ok
22:13:31.0320 2860        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:13:31.0367 2860        Serial - ok
22:13:31.0430 2860        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:13:31.0461 2860        sermouse - ok
22:13:31.0523 2860        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:13:31.0601 2860        SessionEnv - ok
22:13:31.0601 2860        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:13:31.0648 2860        sffdisk - ok
22:13:31.0679 2860        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:13:31.0710 2860        sffp_mmc - ok
22:13:31.0726 2860        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:13:31.0742 2860        sffp_sd - ok
22:13:31.0757 2860        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:13:31.0788 2860        sfloppy - ok
22:13:31.0851 2860        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:13:31.0960 2860        SharedAccess - ok
22:13:32.0022 2860        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:13:32.0085 2860        ShellHWDetection - ok
22:13:32.0116 2860        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:13:32.0132 2860        SiSRaid2 - ok
22:13:32.0163 2860        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:13:32.0178 2860        SiSRaid4 - ok
22:13:32.0256 2860        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:13:32.0272 2860        SkypeUpdate - ok
22:13:32.0319 2860        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:13:32.0381 2860        Smb - ok
22:13:32.0444 2860        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:13:32.0475 2860        SNMPTRAP - ok
22:13:32.0506 2860        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:13:32.0537 2860        spldr - ok
22:13:32.0600 2860        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:13:32.0678 2860        Spooler - ok
22:13:32.0958 2860        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:13:33.0083 2860        sppsvc - ok
22:13:33.0208 2860        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:13:33.0270 2860        sppuinotify - ok
22:13:33.0364 2860        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:13:33.0426 2860        srv - ok
22:13:33.0489 2860        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:13:33.0520 2860        srv2 - ok
22:13:33.0567 2860        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:13:33.0598 2860        srvnet - ok
22:13:33.0660 2860        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:13:33.0754 2860        SSDPSRV - ok
22:13:33.0754 2860        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:13:33.0801 2860        SstpSvc - ok
22:13:33.0832 2860        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:13:33.0848 2860        stexstor - ok
22:13:33.0926 2860        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:13:33.0972 2860        stisvc - ok
22:13:33.0988 2860        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:13:34.0004 2860        swenum - ok
22:13:34.0082 2860        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:13:34.0160 2860        swprv - ok
22:13:34.0222 2860        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:13:34.0316 2860        SynTP - ok
22:13:34.0472 2860        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:13:34.0581 2860        SysMain - ok
22:13:34.0706 2860        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:13:34.0768 2860        TabletInputService - ok
22:13:34.0830 2860        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:13:34.0924 2860        taphss - ok
22:13:34.0971 2860        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:13:35.0080 2860        TapiSrv - ok
22:13:35.0080 2860        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:13:35.0142 2860        TBS - ok
22:13:35.0314 2860        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:13:35.0423 2860        Tcpip - ok
22:13:35.0704 2860        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:13:35.0782 2860        TCPIP6 - ok
22:13:35.0891 2860        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:13:35.0969 2860        tcpipreg - ok
22:13:36.0000 2860        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:13:36.0047 2860        TDPIPE - ok
22:13:36.0094 2860        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:13:36.0125 2860        TDTCP - ok
22:13:36.0156 2860        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:13:36.0250 2860        tdx - ok
22:13:36.0546 2860        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:13:36.0656 2860        TeamViewer7 - ok
22:13:36.0812 2860        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:13:36.0843 2860        TermDD - ok
22:13:36.0936 2860        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:13:37.0030 2860        TermService - ok
22:13:37.0061 2860        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:13:37.0108 2860        Themes - ok
22:13:37.0139 2860        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:13:37.0202 2860        THREADORDER - ok
22:13:37.0233 2860        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:13:37.0311 2860        TrkWks - ok
22:13:37.0373 2860        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:13:37.0420 2860        TrustedInstaller - ok
22:13:37.0451 2860        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:13:37.0498 2860        tssecsrv - ok
22:13:37.0545 2860        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:13:37.0623 2860        tunnel - ok
22:13:37.0638 2860        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:13:37.0654 2860        uagp35 - ok
22:13:37.0685 2860        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:13:37.0763 2860        UBHelper - ok
22:13:37.0810 2860        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:13:37.0904 2860        udfs - ok
22:13:37.0935 2860        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:13:37.0950 2860        UI0Detect - ok
22:13:37.0966 2860        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:13:37.0982 2860        uliagpkx - ok
22:13:38.0044 2860        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:13:38.0091 2860        umbus - ok
22:13:38.0106 2860        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:13:38.0122 2860        UmPass - ok
22:13:38.0434 2860        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:13:38.0606 2860        UNS - ok
22:13:38.0715 2860        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:13:38.0808 2860        Updater Service - ok
22:13:38.0949 2860        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:13:39.0027 2860        upnphost - ok
22:13:39.0074 2860        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:13:39.0120 2860        usbccgp - ok
22:13:39.0152 2860        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:13:39.0198 2860        usbcir - ok
22:13:39.0245 2860        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:13:39.0276 2860        usbehci - ok
22:13:39.0339 2860        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:13:39.0386 2860        usbhub - ok
22:13:39.0417 2860        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:13:39.0432 2860        usbohci - ok
22:13:39.0464 2860        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:13:39.0526 2860        usbprint - ok
22:13:39.0557 2860        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:13:39.0588 2860        USBSTOR - ok
22:13:39.0620 2860        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:13:39.0651 2860        usbuhci - ok
22:13:39.0713 2860        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:13:39.0776 2860        usbvideo - ok
22:13:39.0807 2860        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:13:39.0885 2860        UxSms - ok
22:13:39.0900 2860        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:13:39.0916 2860        VaultSvc - ok
22:13:39.0947 2860        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:13:39.0978 2860        vdrvroot - ok
22:13:40.0056 2860        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:13:40.0103 2860        vds - ok
22:13:40.0119 2860        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:13:40.0150 2860        vga - ok
22:13:40.0166 2860        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:13:40.0244 2860        VgaSave - ok
22:13:40.0275 2860        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:13:40.0306 2860        vhdmp - ok
22:13:40.0337 2860        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:13:40.0353 2860        viaide - ok
22:13:40.0368 2860        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:13:40.0384 2860        volmgr - ok
22:13:40.0431 2860        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:13:40.0462 2860        volmgrx - ok
22:13:40.0509 2860        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:13:40.0524 2860        volsnap - ok
22:13:40.0571 2860        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:13:40.0602 2860        vsmraid - ok
22:13:40.0758 2860        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:13:40.0883 2860        VSS - ok
22:13:41.0024 2860        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:13:41.0055 2860        vwifibus - ok
22:13:41.0055 2860        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:13:41.0117 2860        vwififlt - ok
22:13:41.0164 2860        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:13:41.0195 2860        vwifimp - ok
22:13:41.0273 2860        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:13:41.0351 2860        W32Time - ok
22:13:41.0382 2860        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:13:41.0382 2860        WacomPen - ok
22:13:41.0414 2860        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:13:41.0460 2860        WANARP - ok
22:13:41.0476 2860        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:13:41.0523 2860        Wanarpv6 - ok
22:13:41.0663 2860        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:13:41.0788 2860        wbengine - ok
22:13:41.0928 2860        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:13:41.0991 2860        WbioSrvc - ok
22:13:42.0053 2860        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:13:42.0116 2860        wcncsvc - ok
22:13:42.0131 2860        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:13:42.0178 2860        WcsPlugInService - ok
22:13:42.0240 2860        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:13:42.0272 2860        Wd - ok
22:13:42.0334 2860        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:13:42.0381 2860        Wdf01000 - ok
22:13:42.0396 2860        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:13:42.0443 2860        WdiServiceHost - ok
22:13:42.0459 2860        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:13:42.0474 2860        WdiSystemHost - ok
22:13:42.0537 2860        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:13:42.0599 2860        WebClient - ok
22:13:42.0646 2860        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:13:42.0755 2860        Wecsvc - ok
22:13:42.0771 2860        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:13:42.0833 2860        wercplsupport - ok
22:13:42.0864 2860        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:13:42.0927 2860        WerSvc - ok
22:13:42.0989 2860        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:13:43.0052 2860        WfpLwf - ok
22:13:43.0067 2860        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:13:43.0083 2860        WIMMount - ok
22:13:43.0114 2860        WinDefend - ok
22:13:43.0114 2860        WinHttpAutoProxySvc - ok
22:13:43.0176 2860        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:13:43.0270 2860        Winmgmt - ok
22:13:43.0473 2860        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:13:43.0629 2860        WinRM - ok
22:13:43.0832 2860        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:13:43.0894 2860        Wlansvc - ok
22:13:43.0941 2860        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:13:43.0972 2860        WmiAcpi - ok
22:13:44.0034 2860        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:13:44.0081 2860        wmiApSrv - ok
22:13:44.0128 2860        WMPNetworkSvc - ok
22:13:44.0175 2860        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:13:44.0206 2860        WPCSvc - ok
22:13:44.0237 2860        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:13:44.0284 2860        WPDBusEnum - ok
22:13:44.0315 2860        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:13:44.0378 2860        ws2ifsl - ok
22:13:44.0424 2860        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:13:44.0471 2860        wscsvc - ok
22:13:44.0471 2860        WSearch - ok
22:13:44.0705 2860        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:13:44.0830 2860        wuauserv - ok
22:13:44.0986 2860        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:13:45.0064 2860        WudfPf - ok
22:13:45.0126 2860        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:13:45.0236 2860        WUDFRd - ok
22:13:45.0267 2860        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:13:45.0329 2860        wudfsvc - ok
22:13:45.0345 2860        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:13:45.0376 2860        WwanSvc - ok
22:13:45.0423 2860        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:13:45.0860 2860        \Device\Harddisk0\DR0 - ok
22:13:45.0875 2860        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:13:45.0875 2860        \Device\Harddisk0\DR0\Partition0 - ok
22:13:45.0906 2860        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:13:45.0906 2860        \Device\Harddisk0\DR0\Partition1 - ok
22:13:45.0922 2860        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:13:45.0922 2860        \Device\Harddisk0\DR0\Partition2 - ok
22:13:45.0953 2860        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:13:45.0953 2860        \Device\Harddisk0\DR0\Partition3 - ok
22:13:45.0953 2860        ============================================================
22:13:45.0953 2860        Scan finished
22:13:45.0953 2860        ============================================================
22:13:45.0969 3472        Detected object count: 0
22:13:45.0969 3472        Actual detected object count: 0
22:14:17.0278 2144        ============================================================
22:14:17.0278 2144        Scan started
22:14:17.0278 2144        Mode: Manual;
22:14:17.0278 2144        ============================================================
22:14:18.0635 2144        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:14:18.0635 2144        1394ohci - ok
22:14:18.0698 2144        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:14:18.0698 2144        ACPI - ok
22:14:18.0713 2144        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:14:18.0713 2144        AcpiPmi - ok
22:14:18.0807 2144        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:14:18.0822 2144        AdobeActiveFileMonitor8.0 - ok
22:14:18.0932 2144        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:14:18.0947 2144        AdobeFlashPlayerUpdateSvc - ok
22:14:19.0010 2144        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:14:19.0025 2144        adp94xx - ok
22:14:19.0088 2144        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:14:19.0088 2144        adpahci - ok
22:14:19.0134 2144        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:14:19.0134 2144        adpu320 - ok
22:14:19.0197 2144        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:14:19.0197 2144        AeLookupSvc - ok
22:14:19.0259 2144        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:14:19.0275 2144        AFD - ok
22:14:19.0322 2144        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:14:19.0322 2144        agp440 - ok
22:14:19.0322 2144        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:14:19.0337 2144        ALG - ok
22:14:19.0353 2144        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:14:19.0353 2144        aliide - ok
22:14:19.0368 2144        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:14:19.0368 2144        amdide - ok
22:14:19.0384 2144        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:14:19.0384 2144        AmdK8 - ok
22:14:19.0384 2144        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:14:19.0384 2144        AmdPPM - ok
22:14:19.0415 2144        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:14:19.0415 2144        amdsata - ok
22:14:19.0446 2144        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:14:19.0446 2144        amdsbs - ok
22:14:19.0478 2144        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:14:19.0478 2144        amdxata - ok
22:14:19.0509 2144        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:14:19.0509 2144        AmUStor - ok
22:14:19.0587 2144        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:14:19.0587 2144        AntiVirSchedulerService - ok
22:14:19.0618 2144        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:14:19.0618 2144        AntiVirService - ok
22:14:19.0649 2144        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:14:19.0649 2144        AppID - ok
22:14:19.0680 2144        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:14:19.0680 2144        AppIDSvc - ok
22:14:19.0696 2144        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:14:19.0696 2144        Appinfo - ok
22:14:19.0727 2144        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:14:19.0727 2144        arc - ok
22:14:19.0743 2144        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:14:19.0743 2144        arcsas - ok
22:14:19.0743 2144        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:14:19.0743 2144        AsyncMac - ok
22:14:19.0758 2144        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:14:19.0758 2144        atapi - ok
22:14:19.0977 2144        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:14:19.0992 2144        athr - ok
22:14:20.0164 2144        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:14:20.0180 2144        AudioEndpointBuilder - ok
22:14:20.0195 2144        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:14:20.0195 2144        AudioSrv - ok
22:14:20.0258 2144        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:14:20.0258 2144        avgntflt - ok
22:14:20.0289 2144        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:14:20.0289 2144        avipbb - ok
22:14:20.0304 2144        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:14:20.0304 2144        avkmgr - ok
22:14:20.0336 2144        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:14:20.0336 2144        AxInstSV - ok
22:14:20.0414 2144        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:14:20.0414 2144        b06bdrv - ok
22:14:20.0445 2144        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:14:20.0460 2144        b57nd60a - ok
22:14:20.0585 2144        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:14:20.0601 2144        BCM43XX - ok
22:14:20.0616 2144        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:14:20.0616 2144        BDESVC - ok
22:14:20.0663 2144        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:14:20.0663 2144        Beep - ok
22:14:20.0726 2144        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:14:20.0741 2144        BFE - ok
22:14:20.0866 2144        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:14:20.0882 2144        BITS - ok
22:14:20.0928 2144        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:14:20.0928 2144        blbdrive - ok
22:14:20.0960 2144        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:14:20.0960 2144        bowser - ok
22:14:20.0975 2144        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:14:20.0975 2144        BrFiltLo - ok
22:14:20.0991 2144        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:14:20.0991 2144        BrFiltUp - ok
22:14:21.0022 2144        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:14:21.0038 2144        Browser - ok
22:14:21.0053 2144        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:14:21.0053 2144        Brserid - ok
22:14:21.0069 2144        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:14:21.0069 2144        BrSerWdm - ok
22:14:21.0069 2144        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:14:21.0069 2144        BrUsbMdm - ok
22:14:21.0084 2144        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:14:21.0084 2144        BrUsbSer - ok
22:14:21.0100 2144        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:14:21.0100 2144        BTHMODEM - ok
22:14:21.0116 2144        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:14:21.0116 2144        bthserv - ok
22:14:21.0131 2144        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:14:21.0131 2144        cdfs - ok
22:14:21.0162 2144        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:14:21.0162 2144        cdrom - ok
22:14:21.0194 2144        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:14:21.0194 2144        CertPropSvc - ok
22:14:21.0194 2144        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:14:21.0194 2144        circlass - ok
22:14:21.0240 2144        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:14:21.0240 2144        CLFS - ok
22:14:21.0318 2144        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:14:21.0318 2144        clr_optimization_v2.0.50727_32 - ok
22:14:21.0350 2144        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:14:21.0350 2144        clr_optimization_v2.0.50727_64 - ok
22:14:21.0381 2144        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:14:21.0381 2144        CmBatt - ok
22:14:21.0396 2144        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:14:21.0412 2144        cmdide - ok
22:14:21.0459 2144        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:14:21.0474 2144        CNG - ok
22:14:21.0490 2144        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:14:21.0490 2144        Compbatt - ok
22:14:21.0506 2144        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:14:21.0506 2144        CompositeBus - ok
22:14:21.0506 2144        COMSysApp - ok
22:14:21.0521 2144        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:14:21.0521 2144        crcdisk - ok
22:14:21.0568 2144        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:14:21.0584 2144        CryptSvc - ok
22:14:21.0662 2144        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:14:21.0662 2144        DcomLaunch - ok
22:14:21.0724 2144        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:14:21.0724 2144        defragsvc - ok
22:14:21.0771 2144        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:14:21.0771 2144        DfsC - ok
22:14:21.0818 2144        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:14:21.0818 2144        Dhcp - ok
22:14:21.0849 2144        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:14:21.0849 2144        discache - ok
22:14:21.0880 2144        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:14:21.0880 2144        Disk - ok
22:14:21.0927 2144        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:14:21.0927 2144        Dnscache - ok
22:14:21.0974 2144        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:14:21.0974 2144        dot3svc - ok
22:14:22.0005 2144        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:14:22.0005 2144        DPS - ok
22:14:22.0036 2144        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:14:22.0036 2144        drmkaud - ok
22:14:22.0130 2144        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:14:22.0130 2144        DsiWMIService - ok
22:14:22.0239 2144        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:14:22.0254 2144        DXGKrnl - ok
22:14:22.0301 2144        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:14:22.0301 2144        EapHost - ok
22:14:22.0566 2144        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:14:22.0598 2144        ebdrv - ok
22:14:22.0722 2144        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:14:22.0738 2144        EFS - ok
22:14:22.0847 2144        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:14:22.0863 2144        ehRecvr - ok
22:14:22.0910 2144        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:14:22.0910 2144        ehSched - ok
22:14:23.0003 2144        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:14:23.0019 2144        elxstor - ok
22:14:23.0237 2144        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:14:23.0253 2144        ePowerSvc - ok
22:14:23.0378 2144        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:14:23.0378 2144        ErrDev - ok
22:14:23.0440 2144        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:14:23.0440 2144        EventSystem - ok
22:14:23.0471 2144        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:14:23.0471 2144        exfat - ok
22:14:23.0502 2144        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:14:23.0502 2144        fastfat - ok
22:14:23.0565 2144        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:14:23.0580 2144        Fax - ok
22:14:23.0580 2144        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:14:23.0580 2144        fdc - ok
22:14:23.0596 2144        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:14:23.0596 2144        fdPHost - ok
22:14:23.0612 2144        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:14:23.0612 2144        FDResPub - ok
22:14:23.0643 2144        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:14:23.0643 2144        FileInfo - ok
22:14:23.0643 2144        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:14:23.0658 2144        Filetrace - ok
22:14:23.0783 2144        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:14:23.0783 2144        FLEXnet Licensing Service - ok
22:14:23.0814 2144        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:14:23.0814 2144        flpydisk - ok
22:14:23.0846 2144        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:14:23.0846 2144        FltMgr - ok
22:14:23.0955 2144        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:14:23.0970 2144        FontCache - ok
22:14:24.0048 2144        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:14:24.0048 2144        FontCache3.0.0.0 - ok
22:14:24.0095 2144        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:14:24.0095 2144        FsDepends - ok
22:14:24.0111 2144        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:14:24.0111 2144        Fs_Rec - ok
22:14:24.0158 2144        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:14:24.0173 2144        fvevol - ok
22:14:24.0189 2144        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:14:24.0189 2144        gagp30kx - ok
22:14:24.0298 2144        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:14:24.0298 2144        GameConsoleService - ok
22:14:24.0392 2144        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:14:24.0407 2144        gpsvc - ok
22:14:24.0438 2144        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:14:24.0438 2144        GREGService - ok
22:14:24.0485 2144        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:14:24.0485 2144        hcw85cir - ok
22:14:24.0563 2144        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:14:24.0563 2144        HdAudAddService - ok
22:14:24.0610 2144        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:14:24.0610 2144        HDAudBus - ok
22:14:24.0641 2144        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:14:24.0641 2144        HECIx64 - ok
22:14:24.0672 2144        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:14:24.0672 2144        HidBatt - ok
22:14:24.0688 2144        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:14:24.0688 2144        HidBth - ok
22:14:24.0704 2144        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:14:24.0704 2144        HidIr - ok
22:14:24.0735 2144        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:14:24.0735 2144        hidserv - ok
22:14:24.0750 2144        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:14:24.0750 2144        HidUsb - ok
22:14:24.0766 2144        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:14:24.0782 2144        hkmsvc - ok
22:14:24.0813 2144        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:14:24.0813 2144        HomeGroupListener - ok
22:14:24.0860 2144        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:14:24.0860 2144        HomeGroupProvider - ok
22:14:24.0891 2144        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:14:24.0891 2144        HpSAMD - ok
22:14:25.0000 2144        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:14:25.0000 2144        hshld - ok
22:14:25.0031 2144        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:14:25.0031 2144        HssDrv - ok
22:14:25.0094 2144        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:14:25.0094 2144        HssSrv - ok
22:14:25.0125 2144        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:14:25.0125 2144        HssTrayService - ok
22:14:25.0140 2144        HssWd - ok
22:14:25.0218 2144        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:14:25.0234 2144        HTTP - ok
22:14:25.0265 2144        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:14:25.0265 2144        hwpolicy - ok
22:14:25.0281 2144        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:14:25.0281 2144        i8042prt - ok
22:14:25.0343 2144        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:14:25.0359 2144        iaStor - ok
22:14:25.0406 2144        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:14:25.0421 2144        iaStorV - ok
22:14:25.0530 2144        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:14:25.0546 2144        idsvc - ok
22:14:26.0264 2144        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:14:26.0326 2144        igfx - ok
22:14:26.0466 2144        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:14:26.0466 2144        iirsp - ok
22:14:26.0576 2144        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:14:26.0576 2144        IKEEXT - ok
22:14:26.0622 2144        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:14:26.0622 2144        Impcd - ok
22:14:26.0841 2144        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:14:26.0872 2144        IntcAzAudAddService - ok
22:14:27.0044 2144        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:14:27.0044 2144        IntcDAud - ok
22:14:27.0075 2144        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:14:27.0075 2144        intelide - ok
22:14:27.0090 2144        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:14:27.0090 2144        intelppm - ok
22:14:27.0122 2144        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:14:27.0137 2144        IPBusEnum - ok
22:14:27.0153 2144        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:14:27.0153 2144        IpFilterDriver - ok
22:14:27.0215 2144        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:14:27.0215 2144        iphlpsvc - ok
22:14:27.0231 2144        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:14:27.0231 2144        IPMIDRV - ok
22:14:27.0246 2144        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:14:27.0246 2144        IPNAT - ok
22:14:27.0246 2144        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:14:27.0246 2144        IRENUM - ok
22:14:27.0262 2144        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:14:27.0278 2144        isapnp - ok
22:14:27.0309 2144        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:14:27.0309 2144        iScsiPrt - ok
22:14:27.0371 2144        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:14:27.0371 2144        k57nd60a - ok
22:14:27.0387 2144        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:14:27.0387 2144        kbdclass - ok
22:14:27.0387 2144        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:14:27.0387 2144        kbdhid - ok
22:14:27.0418 2144        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:14:27.0418 2144        KeyIso - ok
22:14:27.0434 2144        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:14:27.0434 2144        KSecDD - ok
22:14:27.0465 2144        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:14:27.0465 2144        KSecPkg - ok
22:14:27.0480 2144        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:14:27.0480 2144        ksthunk - ok
22:14:27.0543 2144        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:14:27.0543 2144        KtmRm - ok
22:14:27.0574 2144        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:14:27.0574 2144        L1E - ok
22:14:27.0621 2144        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:14:27.0636 2144        LanmanServer - ok
22:14:27.0668 2144        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:14:27.0668 2144        LanmanWorkstation - ok
22:14:27.0683 2144        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:14:27.0683 2144        lltdio - ok
22:14:27.0746 2144        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:14:27.0746 2144        lltdsvc - ok
22:14:27.0777 2144        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:14:27.0777 2144        lmhosts - ok
22:14:27.0902 2144        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:14:27.0902 2144        LMS - ok
22:14:27.0948 2144        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:14:27.0948 2144        LSI_FC - ok
22:14:27.0964 2144        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:14:27.0964 2144        LSI_SAS - ok
22:14:27.0995 2144        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:14:27.0995 2144        LSI_SAS2 - ok
22:14:28.0011 2144        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:14:28.0011 2144        LSI_SCSI - ok
22:14:28.0042 2144        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:14:28.0042 2144        luafv - ok
22:14:28.0058 2144        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:14:28.0073 2144        MBAMProtector - ok
22:14:28.0136 2144        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:14:28.0151 2144        MBAMService - ok
22:14:28.0182 2144        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:14:28.0182 2144        Mcx2Svc - ok
22:14:28.0214 2144        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:14:28.0214 2144        megasas - ok
22:14:28.0260 2144        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:14:28.0260 2144        MegaSR - ok
22:14:28.0292 2144        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:14:28.0292 2144        MMCSS - ok
22:14:28.0307 2144        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:14:28.0307 2144        Modem - ok
22:14:28.0323 2144        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:14:28.0323 2144        monitor - ok
22:14:28.0338 2144        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:14:28.0338 2144        mouclass - ok
22:14:28.0338 2144        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:14:28.0354 2144        mouhid - ok
22:14:28.0354 2144        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:14:28.0354 2144        mountmgr - ok
22:14:28.0432 2144        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:14:28.0432 2144        MozillaMaintenance - ok
22:14:28.0463 2144        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:14:28.0463 2144        mpio - ok
22:14:28.0463 2144        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:14:28.0479 2144        mpsdrv - ok
22:14:28.0572 2144        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:14:28.0588 2144        MpsSvc - ok
22:14:28.0604 2144        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:14:28.0619 2144        MRxDAV - ok
22:14:28.0650 2144        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:14:28.0650 2144        mrxsmb - ok
22:14:28.0697 2144        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:14:28.0697 2144        mrxsmb10 - ok
22:14:28.0728 2144        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:14:28.0728 2144        mrxsmb20 - ok
22:14:28.0760 2144        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:14:28.0760 2144        msahci - ok
22:14:28.0791 2144        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:14:28.0791 2144        msdsm - ok
22:14:28.0838 2144        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:14:28.0838 2144        MSDTC - ok
22:14:28.0853 2144        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:14:28.0853 2144        Msfs - ok
22:14:28.0869 2144        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:14:28.0869 2144        mshidkmdf - ok
22:14:28.0884 2144        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:14:28.0884 2144        msisadrv - ok
22:14:28.0916 2144        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:14:28.0916 2144        MSiSCSI - ok
22:14:28.0916 2144        msiserver - ok
22:14:28.0947 2144        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:14:28.0947 2144        MSKSSRV - ok
22:14:28.0947 2144        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:14:28.0947 2144        MSPCLOCK - ok
22:14:28.0962 2144        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:14:28.0962 2144        MSPQM - ok
22:14:28.0994 2144        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:14:28.0994 2144        MsRPC - ok
22:14:29.0009 2144        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:14:29.0009 2144        mssmbios - ok
22:14:29.0025 2144        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:14:29.0025 2144        MSTEE - ok
22:14:29.0025 2144        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:14:29.0025 2144        MTConfig - ok
22:14:29.0040 2144        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:14:29.0040 2144        Mup - ok
22:14:29.0103 2144        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:14:29.0103 2144        napagent - ok
22:14:29.0150 2144        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:14:29.0150 2144        NativeWifiP - ok
22:14:29.0243 2144        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:14:29.0259 2144        NDIS - ok
22:14:29.0274 2144        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:14:29.0274 2144        NdisCap - ok
22:14:29.0290 2144        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:14:29.0290 2144        NdisTapi - ok
22:14:29.0306 2144        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:14:29.0306 2144        Ndisuio - ok
22:14:29.0321 2144        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:14:29.0321 2144        NdisWan - ok
22:14:29.0321 2144        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:14:29.0337 2144        NDProxy - ok
22:14:29.0493 2144        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:14:29.0493 2144        Nero BackItUp Scheduler 4.0 - ok
22:14:29.0508 2144        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:14:29.0508 2144        NetBIOS - ok
22:14:29.0540 2144        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:14:29.0555 2144        NetBT - ok
22:14:29.0571 2144        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:14:29.0571 2144        Netlogon - ok
22:14:29.0633 2144        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:14:29.0633 2144        Netman - ok
22:14:29.0680 2144        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:14:29.0696 2144        netprofm - ok
22:14:29.0758 2144        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:14:29.0758 2144        NetTcpPortSharing - ok
22:14:29.0789 2144        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:14:29.0789 2144        nfrd960 - ok
22:14:29.0852 2144        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:14:29.0852 2144        NlaSvc - ok
22:14:29.0883 2144        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:14:29.0883 2144        Npfs - ok
22:14:29.0898 2144        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:14:29.0898 2144        nsi - ok
22:14:29.0914 2144        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:14:29.0914 2144        nsiproxy - ok
22:14:30.0070 2144        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:14:30.0086 2144        Ntfs - ok
22:14:30.0179 2144        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:14:30.0179 2144        NTI IScheduleSvc - ok
22:14:30.0320 2144        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:14:30.0320 2144        NTIDrvr - ok
22:14:30.0351 2144        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:14:30.0351 2144        Null - ok
22:14:30.0382 2144        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:14:30.0382 2144        nvraid - ok
22:14:30.0413 2144        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:14:30.0413 2144        nvstor - ok
22:14:30.0444 2144        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:14:30.0460 2144        nv_agp - ok
22:14:30.0460 2144        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:14:30.0460 2144        ohci1394 - ok
22:14:30.0522 2144        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:14:30.0522 2144        p2pimsvc - ok
22:14:30.0585 2144        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:14:30.0585 2144        p2psvc - ok
22:14:30.0600 2144        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:14:30.0600 2144        Parport - ok
22:14:30.0632 2144        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:14:30.0632 2144        partmgr - ok
22:14:30.0647 2144        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:14:30.0663 2144        PcaSvc - ok
22:14:30.0694 2144        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:14:30.0694 2144        pci - ok
22:14:30.0725 2144        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:14:30.0725 2144        pciide - ok
22:14:30.0756 2144        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:14:30.0756 2144        pcmcia - ok
22:14:30.0772 2144        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:14:30.0772 2144        pcw - ok
22:14:30.0819 2144        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:14:30.0834 2144        PEAUTH - ok
22:14:30.0928 2144        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:14:30.0928 2144        PerfHost - ok
22:14:31.0084 2144        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:14:31.0100 2144        pla - ok
22:14:31.0162 2144        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:14:31.0162 2144        PlugPlay - ok
22:14:31.0178 2144        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:14:31.0193 2144        PNRPAutoReg - ok
22:14:31.0224 2144        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:14:31.0224 2144        PNRPsvc - ok
22:14:31.0287 2144        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:14:31.0287 2144        PolicyAgent - ok
22:14:31.0334 2144        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:14:31.0349 2144        Power - ok
22:14:31.0412 2144        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:14:31.0412 2144        PptpMiniport - ok
22:14:31.0458 2144        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:14:31.0458 2144        Processor - ok
22:14:31.0505 2144        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:14:31.0505 2144        ProfSvc - ok
22:14:31.0536 2144        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:14:31.0536 2144        ProtectedStorage - ok
22:14:31.0583 2144        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:14:31.0583 2144        Psched - ok
22:14:31.0614 2144        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:14:31.0614 2144        PxHlpa64 - ok
22:14:31.0770 2144        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:14:31.0786 2144        ql2300 - ok
22:14:31.0942 2144        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:14:31.0942 2144        ql40xx - ok
22:14:31.0989 2144        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:14:31.0989 2144        QWAVE - ok
22:14:32.0020 2144        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:14:32.0020 2144        QWAVEdrv - ok
22:14:32.0036 2144        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:14:32.0036 2144        RasAcd - ok
22:14:32.0067 2144        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:14:32.0067 2144        RasAgileVpn - ok
22:14:32.0114 2144        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:14:32.0114 2144        RasAuto - ok
22:14:32.0145 2144        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:14:32.0145 2144        Rasl2tp - ok
22:14:32.0192 2144        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:14:32.0207 2144        RasMan - ok
22:14:32.0223 2144        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:14:32.0223 2144        RasPppoe - ok
22:14:32.0238 2144        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:14:32.0238 2144        RasSstp - ok
22:14:32.0254 2144        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:14:32.0270 2144        rdbss - ok
22:14:32.0285 2144        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:14:32.0285 2144        rdpbus - ok
22:14:32.0301 2144        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:14:32.0301 2144        RDPCDD - ok
22:14:32.0316 2144        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:14:32.0316 2144        RDPENCDD - ok
22:14:32.0316 2144        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:14:32.0316 2144        RDPREFMP - ok
22:14:32.0379 2144        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:14:32.0379 2144        RDPWD - ok
22:14:32.0426 2144        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:14:32.0426 2144        rdyboost - ok
22:14:32.0457 2144        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:14:32.0457 2144        RemoteAccess - ok
22:14:32.0519 2144        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:14:32.0519 2144        RemoteRegistry - ok
22:14:32.0535 2144        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:14:32.0535 2144        RpcEptMapper - ok
22:14:32.0566 2144        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:14:32.0566 2144        RpcLocator - ok
22:14:32.0628 2144        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:14:32.0628 2144        RpcSs - ok
22:14:32.0675 2144        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:14:32.0675 2144        rspndr - ok
22:14:32.0691 2144        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:14:32.0691 2144        SamSs - ok
22:14:32.0722 2144        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:14:32.0722 2144        sbp2port - ok
22:14:32.0784 2144        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:14:32.0784 2144        SCardSvr - ok
22:14:32.0800 2144        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:14:32.0800 2144        scfilter - ok
22:14:32.0925 2144        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:14:32.0940 2144        Schedule - ok
22:14:32.0972 2144        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:14:32.0972 2144        SCPolicySvc - ok
22:14:33.0018 2144        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:14:33.0034 2144        SDRSVC - ok
22:14:33.0096 2144        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:14:33.0096 2144        secdrv - ok
22:14:33.0112 2144        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:14:33.0112 2144        seclogon - ok
22:14:33.0128 2144        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:14:33.0128 2144        SENS - ok
22:14:33.0143 2144        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:14:33.0143 2144        SensrSvc - ok
22:14:33.0159 2144        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:14:33.0159 2144        Serenum - ok
22:14:33.0190 2144        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:14:33.0190 2144        Serial - ok
22:14:33.0206 2144        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:14:33.0206 2144        sermouse - ok
22:14:33.0221 2144        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:14:33.0221 2144        SessionEnv - ok
22:14:33.0237 2144        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:14:33.0237 2144        sffdisk - ok
22:14:33.0237 2144        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:14:33.0237 2144        sffp_mmc - ok
22:14:33.0268 2144        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:14:33.0268 2144        sffp_sd - ok
22:14:33.0268 2144        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:14:33.0268 2144        sfloppy - ok
22:14:33.0330 2144        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:14:33.0346 2144        SharedAccess - ok
22:14:33.0393 2144        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:14:33.0408 2144        ShellHWDetection - ok
22:14:33.0424 2144        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:14:33.0424 2144        SiSRaid2 - ok
22:14:33.0471 2144        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:14:33.0471 2144        SiSRaid4 - ok
22:14:33.0533 2144        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:14:33.0533 2144        SkypeUpdate - ok
22:14:33.0549 2144        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:14:33.0549 2144        Smb - ok
22:14:33.0596 2144        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:14:33.0596 2144        SNMPTRAP - ok
22:14:33.0627 2144        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:14:33.0627 2144        spldr - ok
22:14:33.0689 2144        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:14:33.0705 2144        Spooler - ok
22:14:33.0986 2144        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:14:34.0032 2144        sppsvc - ok
22:14:34.0142 2144        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:14:34.0142 2144        sppuinotify - ok
22:14:34.0235 2144        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:14:34.0251 2144        srv - ok
22:14:34.0298 2144        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:14:34.0298 2144        srv2 - ok
22:14:34.0329 2144        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:14:34.0344 2144        srvnet - ok
22:14:34.0376 2144        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:14:34.0376 2144        SSDPSRV - ok
22:14:34.0391 2144        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:14:34.0391 2144        SstpSvc - ok
22:14:34.0422 2144        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:14:34.0422 2144        stexstor - ok
22:14:34.0500 2144        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:14:34.0516 2144        stisvc - ok
22:14:34.0532 2144        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:14:34.0532 2144        swenum - ok
22:14:34.0610 2144        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:14:34.0625 2144        swprv - ok
22:14:34.0688 2144        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:14:34.0688 2144        SynTP - ok
22:14:34.0875 2144        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:14:34.0890 2144        SysMain - ok
22:14:35.0015 2144        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:14:35.0015 2144        TabletInputService - ok
22:14:35.0078 2144        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:14:35.0078 2144        taphss - ok
22:14:35.0124 2144        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:14:35.0140 2144        TapiSrv - ok
22:14:35.0140 2144        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:14:35.0156 2144        TBS - ok
22:14:35.0327 2144        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:14:35.0343 2144        Tcpip - ok
22:14:35.0624 2144        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:14:35.0639 2144        TCPIP6 - ok
22:14:35.0733 2144        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:14:35.0733 2144        tcpipreg - ok
22:14:35.0748 2144        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:14:35.0764 2144        TDPIPE - ok
22:14:35.0795 2144        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:14:35.0795 2144        TDTCP - ok
22:14:35.0811 2144        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:14:35.0811 2144        tdx - ok
22:14:36.0092 2144        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:14:36.0107 2144        TeamViewer7 - ok
22:14:36.0248 2144        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:14:36.0248 2144        TermDD - ok
22:14:36.0341 2144        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:14:36.0341 2144        TermService - ok
22:14:36.0357 2144        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:14:36.0357 2144        Themes - ok
22:14:36.0404 2144        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:14:36.0404 2144        THREADORDER - ok
22:14:36.0419 2144        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:14:36.0435 2144        TrkWks - ok
22:14:36.0482 2144        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:14:36.0482 2144        TrustedInstaller - ok
22:14:36.0513 2144        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:14:36.0513 2144        tssecsrv - ok
22:14:36.0528 2144        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:14:36.0544 2144        tunnel - ok
22:14:36.0560 2144        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:14:36.0560 2144        uagp35 - ok
22:14:36.0591 2144        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:14:36.0591 2144        UBHelper - ok
22:14:36.0622 2144        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:14:36.0622 2144        udfs - ok
22:14:36.0653 2144        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:14:36.0653 2144        UI0Detect - ok
22:14:36.0669 2144        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:14:36.0669 2144        uliagpkx - ok
22:14:36.0684 2144        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:14:36.0684 2144        umbus - ok
22:14:36.0716 2144        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:14:36.0716 2144        UmPass - ok
22:14:37.0012 2144        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:14:37.0043 2144        UNS - ok
22:14:37.0121 2144        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:14:37.0137 2144        Updater Service - ok
22:14:37.0277 2144        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:14:37.0293 2144        upnphost - ok
22:14:37.0340 2144        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:14:37.0340 2144        usbccgp - ok
22:14:37.0371 2144        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:14:37.0371 2144        usbcir - ok
22:14:37.0371 2144        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:14:37.0386 2144        usbehci - ok
22:14:37.0433 2144        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:14:37.0433 2144        usbhub - ok
22:14:37.0464 2144        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:14:37.0464 2144        usbohci - ok
22:14:37.0480 2144        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:14:37.0480 2144        usbprint - ok
22:14:37.0496 2144        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:14:37.0511 2144        USBSTOR - ok
22:14:37.0527 2144        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:14:37.0527 2144        usbuhci - ok
22:14:37.0589 2144        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:14:37.0589 2144        usbvideo - ok
22:14:37.0620 2144        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:14:37.0636 2144        UxSms - ok
22:14:37.0652 2144        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:14:37.0652 2144        VaultSvc - ok
22:14:37.0683 2144        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:14:37.0683 2144        vdrvroot - ok
22:14:37.0745 2144        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:14:37.0745 2144        vds - ok
22:14:37.0776 2144        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:14:37.0776 2144        vga - ok
22:14:37.0792 2144        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:14:37.0792 2144        VgaSave - ok
22:14:37.0823 2144        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:14:37.0823 2144        vhdmp - ok
22:14:37.0854 2144        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:14:37.0854 2144        viaide - ok
22:14:37.0854 2144        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:14:37.0854 2144        volmgr - ok
22:14:37.0901 2144        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:14:37.0901 2144        volmgrx - ok
22:14:37.0948 2144        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:14:37.0948 2144        volsnap - ok
22:14:37.0979 2144        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:14:37.0979 2144        vsmraid - ok
22:14:38.0135 2144        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:14:38.0151 2144        VSS - ok
22:14:38.0307 2144        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:14:38.0307 2144        vwifibus - ok
22:14:38.0322 2144        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:14:38.0322 2144        vwififlt - ok
22:14:38.0338 2144        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:14:38.0354 2144        vwifimp - ok
22:14:38.0416 2144        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:14:38.0416 2144        W32Time - ok
22:14:38.0432 2144        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:14:38.0432 2144        WacomPen - ok
22:14:38.0447 2144        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:14:38.0447 2144        WANARP - ok
22:14:38.0447 2144        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:14:38.0447 2144        Wanarpv6 - ok
22:14:38.0603 2144        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:14:38.0619 2144        wbengine - ok
22:14:38.0744 2144        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:14:38.0759 2144        WbioSrvc - ok
22:14:38.0822 2144        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:14:38.0822 2144        wcncsvc - ok
22:14:38.0837 2144        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:14:38.0853 2144        WcsPlugInService - ok
22:14:38.0884 2144        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:14:38.0900 2144        Wd - ok
22:14:38.0962 2144        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:14:38.0962 2144        Wdf01000 - ok
22:14:38.0993 2144        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:14:38.0993 2144        WdiServiceHost - ok


derhunne 15.06.2012 21:40

Code:

22:14:38.0993 2144        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:14:39.0009 2144        WdiSystemHost - ok
22:14:39.0056 2144        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:14:39.0056 2144        WebClient - ok
22:14:39.0118 2144        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:14:39.0118 2144        Wecsvc - ok
22:14:39.0134 2144        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:14:39.0134 2144        wercplsupport - ok
22:14:39.0149 2144        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:14:39.0149 2144        WerSvc - ok
22:14:39.0212 2144        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:14:39.0212 2144        WfpLwf - ok
22:14:39.0243 2144        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:14:39.0243 2144        WIMMount - ok
22:14:39.0258 2144        WinDefend - ok
22:14:39.0274 2144        WinHttpAutoProxySvc - ok
22:14:39.0352 2144        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:14:39.0352 2144        Winmgmt - ok
22:14:39.0586 2144        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:14:39.0602 2144        WinRM - ok
22:14:39.0804 2144        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:14:39.0820 2144        Wlansvc - ok
22:14:39.0867 2144        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:14:39.0867 2144        WmiAcpi - ok
22:14:39.0929 2144        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:14:39.0929 2144        wmiApSrv - ok
22:14:39.0976 2144        WMPNetworkSvc - ok
22:14:40.0007 2144        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:14:40.0007 2144        WPCSvc - ok
22:14:40.0038 2144        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:14:40.0038 2144        WPDBusEnum - ok
22:14:40.0070 2144        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:14:40.0070 2144        ws2ifsl - ok
22:14:40.0101 2144        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:14:40.0116 2144        wscsvc - ok
22:14:40.0116 2144        WSearch - ok
22:14:40.0335 2144        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:14:40.0366 2144        wuauserv - ok
22:14:40.0522 2144        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:14:40.0522 2144        WudfPf - ok
22:14:40.0569 2144        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:14:40.0569 2144        WUDFRd - ok
22:14:40.0600 2144        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:14:40.0600 2144        wudfsvc - ok
22:14:40.0616 2144        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:14:40.0631 2144        WwanSvc - ok
22:14:40.0662 2144        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:14:40.0974 2144        \Device\Harddisk0\DR0 - ok
22:14:40.0974 2144        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:14:40.0974 2144        \Device\Harddisk0\DR0\Partition0 - ok
22:14:40.0990 2144        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:14:40.0990 2144        \Device\Harddisk0\DR0\Partition1 - ok
22:14:41.0021 2144        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:14:41.0021 2144        \Device\Harddisk0\DR0\Partition2 - ok
22:14:41.0052 2144        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:14:41.0052 2144        \Device\Harddisk0\DR0\Partition3 - ok
22:14:41.0052 2144        ============================================================
22:14:41.0052 2144        Scan finished
22:14:41.0052 2144        ============================================================
22:14:41.0068 2980        Detected object count: 0
22:14:41.0068 2980        Actual detected object count: 0
22:17:06.0726 5008        ============================================================
22:17:06.0726 5008        Scan started
22:17:06.0726 5008        Mode: Manual; SigCheck; TDLFS;
22:17:06.0726 5008        ============================================================
22:17:08.0364 5008        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:17:08.0426 5008        1394ohci - ok
22:17:08.0457 5008        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:17:08.0504 5008        ACPI - ok
22:17:08.0504 5008        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:17:08.0535 5008        AcpiPmi - ok
22:17:08.0644 5008        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:17:08.0691 5008        AdobeActiveFileMonitor8.0 - ok
22:17:08.0832 5008        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:17:08.0863 5008        AdobeFlashPlayerUpdateSvc - ok
22:17:08.0910 5008        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:17:08.0956 5008        adp94xx - ok
22:17:09.0019 5008        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:17:09.0050 5008        adpahci - ok
22:17:09.0097 5008        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:17:09.0128 5008        adpu320 - ok
22:17:09.0175 5008        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:17:09.0253 5008        AeLookupSvc - ok
22:17:09.0315 5008        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:17:09.0362 5008        AFD - ok
22:17:09.0393 5008        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:17:09.0424 5008        agp440 - ok
22:17:09.0440 5008        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:17:09.0487 5008        ALG - ok
22:17:09.0502 5008        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:17:09.0534 5008        aliide - ok
22:17:09.0549 5008        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:17:09.0580 5008        amdide - ok
22:17:09.0596 5008        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:17:09.0627 5008        AmdK8 - ok
22:17:09.0627 5008        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:17:09.0658 5008        AmdPPM - ok
22:17:09.0690 5008        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:17:09.0721 5008        amdsata - ok
22:17:09.0736 5008        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:17:09.0783 5008        amdsbs - ok
22:17:09.0799 5008        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:17:09.0830 5008        amdxata - ok
22:17:09.0846 5008        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:17:09.0877 5008        AmUStor - ok
22:17:09.0970 5008        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:17:10.0002 5008        AntiVirSchedulerService - ok
22:17:10.0033 5008        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:17:10.0064 5008        AntiVirService - ok
22:17:10.0095 5008        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:17:10.0142 5008        AppID - ok
22:17:10.0173 5008        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:17:10.0251 5008        AppIDSvc - ok
22:17:10.0251 5008        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:17:10.0267 5008        Appinfo - ok
22:17:10.0282 5008        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:17:10.0314 5008        arc - ok
22:17:10.0314 5008        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:17:10.0345 5008        arcsas - ok
22:17:10.0345 5008        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:17:10.0392 5008        AsyncMac - ok
22:17:10.0407 5008        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:17:10.0438 5008        atapi - ok
22:17:10.0641 5008        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:17:10.0750 5008        athr - ok
22:17:10.0922 5008        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:17:11.0031 5008        AudioEndpointBuilder - ok
22:17:11.0047 5008        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:17:11.0109 5008        AudioSrv - ok
22:17:11.0156 5008        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:17:11.0187 5008        avgntflt - ok
22:17:11.0218 5008        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:17:11.0250 5008        avipbb - ok
22:17:11.0265 5008        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:17:11.0281 5008        avkmgr - ok
22:17:11.0312 5008        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:17:11.0359 5008        AxInstSV - ok
22:17:11.0421 5008        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:17:11.0468 5008        b06bdrv - ok
22:17:11.0515 5008        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:17:11.0546 5008        b57nd60a - ok
22:17:11.0686 5008        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:17:11.0764 5008        BCM43XX - ok
22:17:11.0796 5008        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:17:11.0827 5008        BDESVC - ok
22:17:11.0858 5008        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:17:11.0936 5008        Beep - ok
22:17:11.0998 5008        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:17:12.0108 5008        BFE - ok
22:17:12.0217 5008        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:17:12.0310 5008        BITS - ok
22:17:12.0357 5008        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:17:12.0388 5008        blbdrive - ok
22:17:12.0435 5008        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:17:12.0466 5008        bowser - ok
22:17:12.0482 5008        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:17:12.0513 5008        BrFiltLo - ok
22:17:12.0529 5008        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:17:12.0544 5008        BrFiltUp - ok
22:17:12.0591 5008        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:17:12.0669 5008        Browser - ok
22:17:12.0700 5008        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:17:12.0716 5008        Brserid - ok
22:17:12.0732 5008        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:17:12.0747 5008        BrSerWdm - ok
22:17:12.0763 5008        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:17:12.0778 5008        BrUsbMdm - ok
22:17:12.0778 5008        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:17:12.0794 5008        BrUsbSer - ok
22:17:12.0810 5008        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:17:12.0825 5008        BTHMODEM - ok
22:17:12.0841 5008        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:17:12.0888 5008        bthserv - ok
22:17:12.0919 5008        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:17:12.0966 5008        cdfs - ok
22:17:12.0997 5008        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:17:13.0028 5008        cdrom - ok
22:17:13.0044 5008        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:17:13.0122 5008        CertPropSvc - ok
22:17:13.0137 5008        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:17:13.0153 5008        circlass - ok
22:17:13.0200 5008        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:17:13.0231 5008        CLFS - ok
22:17:13.0293 5008        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:17:13.0324 5008        clr_optimization_v2.0.50727_32 - ok
22:17:13.0356 5008        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:17:13.0387 5008        clr_optimization_v2.0.50727_64 - ok
22:17:13.0402 5008        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:17:13.0434 5008        CmBatt - ok
22:17:13.0465 5008        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:17:13.0496 5008        cmdide - ok
22:17:13.0543 5008        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:17:13.0605 5008        CNG - ok
22:17:13.0621 5008        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:17:13.0652 5008        Compbatt - ok
22:17:13.0652 5008        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:17:13.0683 5008        CompositeBus - ok
22:17:13.0699 5008        COMSysApp - ok
22:17:13.0714 5008        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:17:13.0730 5008        crcdisk - ok
22:17:13.0792 5008        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:17:13.0839 5008        CryptSvc - ok
22:17:13.0933 5008        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:17:13.0995 5008        DcomLaunch - ok
22:17:14.0058 5008        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:17:14.0136 5008        defragsvc - ok
22:17:14.0182 5008        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:17:14.0214 5008        DfsC - ok
22:17:14.0260 5008        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:17:14.0292 5008        Dhcp - ok
22:17:14.0338 5008        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:17:14.0385 5008        discache - ok
22:17:14.0401 5008        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:17:14.0416 5008        Disk - ok
22:17:14.0463 5008        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:17:14.0479 5008        Dnscache - ok
22:17:14.0526 5008        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:17:14.0572 5008        dot3svc - ok
22:17:14.0604 5008        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:17:14.0666 5008        DPS - ok
22:17:14.0697 5008        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:17:14.0728 5008        drmkaud - ok
22:17:14.0838 5008        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:17:14.0884 5008        DsiWMIService - ok
22:17:14.0994 5008        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:17:15.0056 5008        DXGKrnl - ok
22:17:15.0118 5008        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:17:15.0196 5008        EapHost - ok
22:17:15.0462 5008        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:17:15.0555 5008        ebdrv - ok
22:17:15.0680 5008        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:17:15.0711 5008        EFS - ok
22:17:15.0820 5008        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:17:15.0883 5008        ehRecvr - ok
22:17:15.0914 5008        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:17:15.0945 5008        ehSched - ok
22:17:16.0039 5008        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:17:16.0101 5008        elxstor - ok
22:17:16.0304 5008        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:17:16.0366 5008        ePowerSvc - ok
22:17:16.0507 5008        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:17:16.0538 5008        ErrDev - ok
22:17:16.0600 5008        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:17:16.0678 5008        EventSystem - ok
22:17:16.0710 5008        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:17:16.0772 5008        exfat - ok
22:17:16.0788 5008        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:17:16.0850 5008        fastfat - ok
22:17:16.0897 5008        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:17:16.0944 5008        Fax - ok
22:17:16.0944 5008        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:17:16.0959 5008        fdc - ok
22:17:16.0975 5008        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:17:17.0037 5008        fdPHost - ok
22:17:17.0053 5008        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:17:17.0100 5008        FDResPub - ok
22:17:17.0115 5008        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:17:17.0131 5008        FileInfo - ok
22:17:17.0146 5008        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:17:17.0193 5008        Filetrace - ok
22:17:17.0334 5008        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:17:17.0396 5008        FLEXnet Licensing Service - ok
22:17:17.0412 5008        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:17:17.0443 5008        flpydisk - ok
22:17:17.0474 5008        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:17:17.0521 5008        FltMgr - ok
22:17:17.0646 5008        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:17:17.0739 5008        FontCache - ok
22:17:17.0802 5008        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:17:17.0833 5008        FontCache3.0.0.0 - ok
22:17:17.0864 5008        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:17:17.0895 5008        FsDepends - ok
22:17:17.0926 5008        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:17:17.0958 5008        Fs_Rec - ok
22:17:18.0004 5008        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:17:18.0067 5008        fvevol - ok
22:17:18.0082 5008        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:17:18.0114 5008        gagp30kx - ok
22:17:18.0223 5008        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:17:18.0270 5008        GameConsoleService - ok
22:17:18.0363 5008        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:17:18.0441 5008        gpsvc - ok
22:17:18.0472 5008        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:17:18.0488 5008        GREGService - ok
22:17:18.0535 5008        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:17:18.0566 5008        hcw85cir - ok
22:17:18.0613 5008        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:17:18.0660 5008        HdAudAddService - ok
22:17:18.0691 5008        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:17:18.0722 5008        HDAudBus - ok
22:17:18.0753 5008        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:17:18.0784 5008        HECIx64 - ok
22:17:18.0800 5008        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:17:18.0831 5008        HidBatt - ok
22:17:18.0847 5008        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:17:18.0878 5008        HidBth - ok
22:17:18.0894 5008        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:17:18.0909 5008        HidIr - ok
22:17:18.0940 5008        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:17:19.0003 5008        hidserv - ok
22:17:19.0003 5008        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:17:19.0018 5008        HidUsb - ok
22:17:19.0034 5008        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:17:19.0096 5008        hkmsvc - ok
22:17:19.0112 5008        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:17:19.0143 5008        HomeGroupListener - ok
22:17:19.0190 5008        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:17:19.0221 5008        HomeGroupProvider - ok
22:17:19.0268 5008        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:17:19.0299 5008        HpSAMD - ok
22:17:19.0424 5008        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:17:19.0486 5008        hshld - ok
22:17:19.0502 5008        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:17:19.0533 5008        HssDrv - ok
22:17:19.0580 5008        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:17:19.0627 5008        HssSrv - ok
22:17:19.0658 5008        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:17:19.0689 5008        HssTrayService - ok
22:17:19.0705 5008        HssWd - ok
22:17:19.0783 5008        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:17:19.0876 5008        HTTP - ok
22:17:19.0908 5008        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:17:19.0923 5008        hwpolicy - ok
22:17:19.0923 5008        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:17:19.0954 5008        i8042prt - ok
22:17:20.0017 5008        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:17:20.0064 5008        iaStor - ok
22:17:20.0110 5008        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:17:20.0157 5008        iaStorV - ok
22:17:20.0282 5008        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:17:20.0360 5008        idsvc - ok
22:17:21.0078 5008        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:17:21.0249 5008        igfx - ok
22:17:21.0390 5008        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:17:21.0421 5008        iirsp - ok
22:17:21.0514 5008        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:17:21.0624 5008        IKEEXT - ok
22:17:21.0670 5008        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:17:21.0686 5008        Impcd - ok
22:17:21.0967 5008        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:17:22.0076 5008        IntcAzAudAddService - ok
22:17:22.0232 5008        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:17:22.0263 5008        IntcDAud - ok
22:17:22.0326 5008        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:17:22.0341 5008        intelide - ok
22:17:22.0372 5008        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:17:22.0404 5008        intelppm - ok
22:17:22.0435 5008        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:17:22.0513 5008        IPBusEnum - ok
22:17:22.0544 5008        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:17:22.0591 5008        IpFilterDriver - ok
22:17:22.0622 5008        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:17:22.0700 5008        iphlpsvc - ok
22:17:22.0716 5008        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:17:22.0731 5008        IPMIDRV - ok
22:17:22.0747 5008        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:17:22.0794 5008        IPNAT - ok
22:17:22.0794 5008        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:17:22.0825 5008        IRENUM - ok
22:17:22.0872 5008        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:17:22.0903 5008        isapnp - ok
22:17:22.0934 5008        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:17:22.0981 5008        iScsiPrt - ok
22:17:23.0028 5008        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:17:23.0074 5008        k57nd60a - ok
22:17:23.0090 5008        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:17:23.0137 5008        kbdclass - ok
22:17:23.0137 5008        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:17:23.0168 5008        kbdhid - ok
22:17:23.0184 5008        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:17:23.0215 5008        KeyIso - ok
22:17:23.0230 5008        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:17:23.0262 5008        KSecDD - ok
22:17:23.0293 5008        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:17:23.0340 5008        KSecPkg - ok
22:17:23.0340 5008        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:17:23.0418 5008        ksthunk - ok
22:17:23.0464 5008        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:17:23.0558 5008        KtmRm - ok
22:17:23.0574 5008        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:17:23.0605 5008        L1E - ok
22:17:23.0652 5008        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:17:23.0698 5008        LanmanServer - ok
22:17:23.0730 5008        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:17:23.0823 5008        LanmanWorkstation - ok
22:17:23.0839 5008        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:17:23.0886 5008        lltdio - ok
22:17:23.0948 5008        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:17:24.0026 5008        lltdsvc - ok
22:17:24.0042 5008        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:17:24.0088 5008        lmhosts - ok
22:17:24.0198 5008        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:17:24.0244 5008        LMS - ok
22:17:24.0276 5008        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:17:24.0322 5008        LSI_FC - ok
22:17:24.0354 5008        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:17:24.0385 5008        LSI_SAS - ok
22:17:24.0400 5008        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:17:24.0432 5008        LSI_SAS2 - ok
22:17:24.0463 5008        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:17:24.0510 5008        LSI_SCSI - ok
22:17:24.0556 5008        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:17:24.0634 5008        luafv - ok
22:17:24.0666 5008        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:17:24.0697 5008        MBAMProtector - ok
22:17:24.0759 5008        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:17:24.0822 5008        MBAMService - ok
22:17:24.0868 5008        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:17:24.0900 5008        Mcx2Svc - ok
22:17:24.0931 5008        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:17:24.0962 5008        megasas - ok
22:17:24.0993 5008        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:17:25.0040 5008        MegaSR - ok
22:17:25.0071 5008        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:17:25.0134 5008        MMCSS - ok
22:17:25.0149 5008        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:17:25.0196 5008        Modem - ok
22:17:25.0212 5008        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:17:25.0227 5008        monitor - ok
22:17:25.0227 5008        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:17:25.0243 5008        mouclass - ok
22:17:25.0258 5008        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:17:25.0274 5008        mouhid - ok
22:17:25.0290 5008        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:17:25.0305 5008        mountmgr - ok
22:17:25.0368 5008        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:17:25.0414 5008        MozillaMaintenance - ok
22:17:25.0430 5008        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:17:25.0477 5008        mpio - ok
22:17:25.0524 5008        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:17:25.0617 5008        mpsdrv - ok
22:17:25.0711 5008        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:17:25.0789 5008        MpsSvc - ok
22:17:25.0820 5008        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:17:25.0851 5008        MRxDAV - ok
22:17:25.0882 5008        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:17:25.0914 5008        mrxsmb - ok
22:17:25.0960 5008        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:17:25.0992 5008        mrxsmb10 - ok
22:17:26.0023 5008        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:17:26.0054 5008        mrxsmb20 - ok
22:17:26.0085 5008        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:17:26.0116 5008        msahci - ok
22:17:26.0148 5008        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:17:26.0179 5008        msdsm - ok
22:17:26.0226 5008        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:17:26.0272 5008        MSDTC - ok
22:17:26.0288 5008        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:17:26.0382 5008        Msfs - ok
22:17:26.0397 5008        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:17:26.0444 5008        mshidkmdf - ok
22:17:26.0444 5008        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:17:26.0460 5008        msisadrv - ok
22:17:26.0506 5008        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:17:26.0584 5008        MSiSCSI - ok
22:17:26.0584 5008        msiserver - ok
22:17:26.0600 5008        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:17:26.0647 5008        MSKSSRV - ok
22:17:26.0647 5008        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:17:26.0694 5008        MSPCLOCK - ok
22:17:26.0694 5008        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:17:26.0740 5008        MSPQM - ok
22:17:26.0772 5008        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:17:26.0803 5008        MsRPC - ok
22:17:26.0803 5008        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:17:26.0818 5008        mssmbios - ok
22:17:26.0834 5008        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:17:26.0881 5008        MSTEE - ok
22:17:26.0881 5008        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:17:26.0912 5008        MTConfig - ok
22:17:26.0912 5008        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:17:26.0928 5008        Mup - ok
22:17:26.0990 5008        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:17:27.0084 5008        napagent - ok
22:17:27.0130 5008        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:17:27.0177 5008        NativeWifiP - ok
22:17:27.0271 5008        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:17:27.0349 5008        NDIS - ok
22:17:27.0364 5008        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:17:27.0427 5008        NdisCap - ok
22:17:27.0442 5008        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:17:27.0489 5008        NdisTapi - ok
22:17:27.0489 5008        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:17:27.0552 5008        Ndisuio - ok
22:17:27.0567 5008        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:17:27.0614 5008        NdisWan - ok
22:17:27.0614 5008        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:17:27.0676 5008        NDProxy - ok
22:17:27.0832 5008        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:17:27.0895 5008        Nero BackItUp Scheduler 4.0 - ok
22:17:27.0910 5008        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:17:27.0988 5008        NetBIOS - ok
22:17:28.0020 5008        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:17:28.0129 5008        NetBT - ok
22:17:28.0160 5008        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:17:28.0176 5008        Netlogon - ok
22:17:28.0254 5008        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:17:28.0332 5008        Netman - ok
22:17:28.0378 5008        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:17:28.0456 5008        netprofm - ok
22:17:28.0534 5008        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:17:28.0566 5008        NetTcpPortSharing - ok
22:17:28.0597 5008        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:17:28.0628 5008        nfrd960 - ok
22:17:28.0690 5008        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:17:28.0768 5008        NlaSvc - ok
22:17:28.0800 5008        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:17:28.0846 5008        Npfs - ok
22:17:28.0846 5008        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:17:28.0893 5008        nsi - ok
22:17:28.0893 5008        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:17:28.0940 5008        nsiproxy - ok
22:17:29.0080 5008        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:17:29.0174 5008        Ntfs - ok
22:17:29.0268 5008        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:17:29.0314 5008        NTI IScheduleSvc - ok
22:17:29.0439 5008        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:17:29.0455 5008        NTIDrvr - ok
22:17:29.0486 5008        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:17:29.0564 5008        Null - ok
22:17:29.0580 5008        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:17:29.0626 5008        nvraid - ok
22:17:29.0658 5008        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:17:29.0689 5008        nvstor - ok
22:17:29.0720 5008        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:17:29.0751 5008        nv_agp - ok
22:17:29.0767 5008        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:17:29.0814 5008        ohci1394 - ok
22:17:29.0876 5008        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:17:29.0907 5008        p2pimsvc - ok
22:17:29.0954 5008        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:17:30.0001 5008        p2psvc - ok
22:17:30.0016 5008        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:17:30.0048 5008        Parport - ok
22:17:30.0063 5008        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:17:30.0094 5008        partmgr - ok
22:17:30.0110 5008        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:17:30.0141 5008        PcaSvc - ok
22:17:30.0188 5008        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:17:30.0204 5008        pci - ok
22:17:30.0219 5008        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:17:30.0235 5008        pciide - ok
22:17:30.0266 5008        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:17:30.0297 5008        pcmcia - ok
22:17:30.0313 5008        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:17:30.0328 5008        pcw - ok
22:17:30.0375 5008        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:17:30.0484 5008        PEAUTH - ok
22:17:30.0578 5008        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:17:30.0625 5008        PerfHost - ok
22:17:30.0734 5008        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:17:30.0812 5008        pla - ok
22:17:30.0874 5008        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:17:30.0921 5008        PlugPlay - ok
22:17:30.0937 5008        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:17:30.0968 5008        PNRPAutoReg - ok
22:17:30.0984 5008        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:17:31.0015 5008        PNRPsvc - ok
22:17:31.0108 5008        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:17:31.0218 5008        PolicyAgent - ok
22:17:31.0264 5008        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:17:31.0342 5008        Power - ok
22:17:31.0405 5008        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:17:31.0483 5008        PptpMiniport - ok
22:17:31.0514 5008        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:17:31.0530 5008        Processor - ok
22:17:31.0576 5008        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:17:31.0608 5008        ProfSvc - ok
22:17:31.0639 5008        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:17:31.0670 5008        ProtectedStorage - ok
22:17:31.0701 5008        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:17:31.0779 5008        Psched - ok
22:17:31.0810 5008        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:17:31.0826 5008        PxHlpa64 - ok
22:17:31.0966 5008        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:17:32.0044 5008        ql2300 - ok
22:17:32.0200 5008        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:17:32.0232 5008        ql40xx - ok
22:17:32.0278 5008        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:17:32.0325 5008        QWAVE - ok
22:17:32.0356 5008        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:17:32.0388 5008        QWAVEdrv - ok
22:17:32.0419 5008        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:17:32.0497 5008        RasAcd - ok
22:17:32.0528 5008        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:17:32.0606 5008        RasAgileVpn - ok
22:17:32.0637 5008        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:17:32.0731 5008        RasAuto - ok
22:17:32.0746 5008        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:17:32.0809 5008        Rasl2tp - ok
22:17:32.0840 5008        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:17:32.0902 5008        RasMan - ok
22:17:32.0934 5008        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:17:32.0980 5008        RasPppoe - ok
22:17:32.0996 5008        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:17:33.0043 5008        RasSstp - ok
22:17:33.0058 5008        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:17:33.0121 5008        rdbss - ok
22:17:33.0136 5008        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:17:33.0168 5008        rdpbus - ok
22:17:33.0183 5008        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:17:33.0230 5008        RDPCDD - ok
22:17:33.0230 5008        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:17:33.0277 5008        RDPENCDD - ok
22:17:33.0292 5008        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:17:33.0339 5008        RDPREFMP - ok
22:17:33.0370 5008        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:17:33.0402 5008        RDPWD - ok
22:17:33.0448 5008        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:17:33.0495 5008        rdyboost - ok
22:17:33.0526 5008        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:17:33.0604 5008        RemoteAccess - ok
22:17:33.0651 5008        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:17:33.0745 5008        RemoteRegistry - ok
22:17:33.0760 5008        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:17:33.0807 5008        RpcEptMapper - ok
22:17:33.0823 5008        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:17:33.0838 5008        RpcLocator - ok
22:17:33.0901 5008        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:17:33.0979 5008        RpcSs - ok
22:17:34.0010 5008        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:17:34.0072 5008        rspndr - ok
22:17:34.0088 5008        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:17:34.0104 5008        SamSs - ok
22:17:34.0135 5008        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:17:34.0166 5008        sbp2port - ok
22:17:34.0197 5008        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:17:34.0260 5008        SCardSvr - ok
22:17:34.0260 5008        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:17:34.0306 5008        scfilter - ok
22:17:34.0431 5008        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:17:34.0494 5008        Schedule - ok
22:17:34.0525 5008        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:17:34.0603 5008        SCPolicySvc - ok
22:17:34.0650 5008        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:17:34.0681 5008        SDRSVC - ok
22:17:34.0743 5008        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:17:34.0837 5008        secdrv - ok
22:17:34.0852 5008        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:17:34.0915 5008        seclogon - ok
22:17:34.0915 5008        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:17:34.0962 5008        SENS - ok
22:17:34.0962 5008        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:17:34.0977 5008        SensrSvc - ok
22:17:34.0993 5008        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:17:35.0008 5008        Serenum - ok
22:17:35.0040 5008        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:17:35.0055 5008        Serial - ok
22:17:35.0071 5008        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:17:35.0086 5008        sermouse - ok
22:17:35.0118 5008        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:17:35.0164 5008        SessionEnv - ok
22:17:35.0164 5008        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:17:35.0180 5008        sffdisk - ok
22:17:35.0180 5008        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:17:35.0196 5008        sffp_mmc - ok
22:17:35.0211 5008        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:17:35.0227 5008        sffp_sd - ok
22:17:35.0227 5008        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:17:35.0242 5008        sfloppy - ok
22:17:35.0320 5008        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:17:35.0398 5008        SharedAccess - ok
22:17:35.0445 5008        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:17:35.0508 5008        ShellHWDetection - ok
22:17:35.0523 5008        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:17:35.0554 5008        SiSRaid2 - ok
22:17:35.0586 5008        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:17:35.0617 5008        SiSRaid4 - ok
22:17:35.0726 5008        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:17:35.0788 5008        SkypeUpdate - ok
22:17:35.0820 5008        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:17:35.0898 5008        Smb - ok
22:17:35.0929 5008        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:17:35.0944 5008        SNMPTRAP - ok
22:17:35.0991 5008        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:17:36.0022 5008        spldr - ok
22:17:36.0085 5008        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:17:36.0132 5008        Spooler - ok
22:17:36.0428 5008        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:17:36.0553 5008        sppsvc - ok
22:17:36.0662 5008        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:17:36.0756 5008        sppuinotify - ok
22:17:36.0849 5008        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:17:36.0896 5008        srv - ok
22:17:36.0943 5008        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:17:36.0990 5008        srv2 - ok
22:17:37.0021 5008        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:17:37.0068 5008        srvnet - ok
22:17:37.0130 5008        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:17:37.0208 5008        SSDPSRV - ok
22:17:37.0224 5008        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:17:37.0270 5008        SstpSvc - ok
22:17:37.0302 5008        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:17:37.0333 5008        stexstor - ok
22:17:37.0411 5008        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:17:37.0458 5008        stisvc - ok
22:17:37.0473 5008        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:17:37.0504 5008        swenum - ok
22:17:37.0582 5008        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:17:37.0676 5008        swprv - ok
22:17:37.0754 5008        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:17:37.0785 5008        SynTP - ok
22:17:37.0941 5008        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:17:38.0019 5008        SysMain - ok
22:17:38.0144 5008        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:17:38.0191 5008        TabletInputService - ok
22:17:38.0238 5008        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:17:38.0269 5008        taphss - ok
22:17:38.0316 5008        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:17:38.0409 5008        TapiSrv - ok
22:17:38.0425 5008        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:17:38.0472 5008        TBS - ok
22:17:38.0659 5008        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:17:38.0752 5008        Tcpip - ok
22:17:39.0018 5008        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:17:39.0080 5008        TCPIP6 - ok
22:17:39.0252 5008        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:17:39.0330 5008        tcpipreg - ok
22:17:39.0345 5008        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:17:39.0361 5008        TDPIPE - ok
22:17:39.0408 5008        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:17:39.0439 5008        TDTCP - ok
22:17:39.0439 5008        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:17:39.0548 5008        tdx - ok
22:17:39.0829 5008        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:17:39.0938 5008        TeamViewer7 - ok
22:17:40.0078 5008        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:17:40.0110 5008        TermDD - ok
22:17:40.0203 5008        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:17:40.0281 5008        TermService - ok
22:17:40.0297 5008        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:17:40.0312 5008        Themes - ok
22:17:40.0344 5008        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:17:40.0390 5008        THREADORDER - ok
22:17:40.0406 5008        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:17:40.0468 5008        TrkWks - ok
22:17:40.0546 5008        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:17:40.0578 5008        TrustedInstaller - ok
22:17:40.0593 5008        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:17:40.0671 5008        tssecsrv - ok
22:17:40.0702 5008        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:17:40.0780 5008        tunnel - ok
22:17:40.0796 5008        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:17:40.0827 5008        uagp35 - ok
22:17:40.0858 5008        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:17:40.0874 5008        UBHelper - ok
22:17:40.0905 5008        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:17:40.0983 5008        udfs - ok
22:17:41.0014 5008        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:17:41.0030 5008        UI0Detect - ok
22:17:41.0046 5008        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:17:41.0061 5008        uliagpkx - ok
22:17:41.0077 5008        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:17:41.0092 5008        umbus - ok
22:17:41.0108 5008        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:17:41.0124 5008        UmPass - ok
22:17:41.0404 5008        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:17:41.0529 5008        UNS - ok
22:17:41.0623 5008        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:17:41.0654 5008        Updater Service - ok
22:17:41.0826 5008        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:17:41.0919 5008        upnphost - ok
22:17:41.0982 5008        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:17:42.0013 5008        usbccgp - ok
22:17:42.0028 5008        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:17:42.0075 5008        usbcir - ok
22:17:42.0091 5008        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:17:42.0122 5008        usbehci - ok
22:17:42.0153 5008        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:17:42.0184 5008        usbhub - ok
22:17:42.0216 5008        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:17:42.0231 5008        usbohci - ok
22:17:42.0247 5008        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:17:42.0278 5008        usbprint - ok
22:17:42.0309 5008        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:17:42.0340 5008        USBSTOR - ok
22:17:42.0356 5008        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:17:42.0387 5008        usbuhci - ok
22:17:42.0434 5008        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:17:42.0465 5008        usbvideo - ok
22:17:42.0496 5008        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:17:42.0590 5008        UxSms - ok
22:17:42.0621 5008        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:17:42.0637 5008        VaultSvc - ok
22:17:42.0668 5008        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:17:42.0684 5008        vdrvroot - ok
22:17:42.0762 5008        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:17:42.0793 5008        vds - ok
22:17:42.0808 5008        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:17:42.0840 5008        vga - ok
22:17:42.0855 5008        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:17:42.0918 5008        VgaSave - ok
22:17:42.0949 5008        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:17:42.0996 5008        vhdmp - ok
22:17:43.0011 5008        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:17:43.0042 5008        viaide - ok
22:17:43.0042 5008        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:17:43.0074 5008        volmgr - ok
22:17:43.0105 5008        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:17:43.0136 5008        volmgrx - ok
22:17:43.0183 5008        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:17:43.0230 5008        volsnap - ok
22:17:43.0261 5008        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:17:43.0292 5008        vsmraid - ok
22:17:43.0432 5008        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:17:43.0510 5008        VSS - ok
22:17:43.0651 5008        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:17:43.0682 5008        vwifibus - ok
22:17:43.0698 5008        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:17:43.0729 5008        vwififlt - ok
22:17:43.0729 5008        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:17:43.0760 5008        vwifimp - ok
22:17:43.0822 5008        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:17:43.0916 5008        W32Time - ok
22:17:43.0916 5008        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:17:43.0932 5008        WacomPen - ok
22:17:43.0947 5008        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:17:43.0994 5008        WANARP - ok
22:17:43.0994 5008        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:17:44.0041 5008        Wanarpv6 - ok
22:17:44.0181 5008        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:17:44.0244 5008        wbengine - ok
22:17:44.0368 5008        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:17:44.0431 5008        WbioSrvc - ok
22:17:44.0493 5008        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:17:44.0540 5008        wcncsvc - ok
22:17:44.0556 5008        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:17:44.0587 5008        WcsPlugInService - ok
22:17:44.0649 5008        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:17:44.0680 5008        Wd - ok
22:17:44.0743 5008        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:17:44.0805 5008        Wdf01000 - ok
22:17:44.0821 5008        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:17:44.0852 5008        WdiServiceHost - ok
22:17:44.0868 5008        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:17:44.0883 5008        WdiSystemHost - ok
22:17:44.0946 5008        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:17:44.0977 5008        WebClient - ok
22:17:45.0039 5008        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:17:45.0133 5008        Wecsvc - ok
22:17:45.0148 5008        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:17:45.0195 5008        wercplsupport - ok
22:17:45.0211 5008        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:17:45.0258 5008        WerSvc - ok
22:17:45.0304 5008        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:17:45.0367 5008        WfpLwf - ok
22:17:45.0398 5008        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:17:45.0414 5008        WIMMount - ok
22:17:45.0429 5008        WinDefend - ok
22:17:45.0429 5008        WinHttpAutoProxySvc - ok
22:17:45.0507 5008        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:17:45.0601 5008        Winmgmt - ok
22:17:45.0788 5008        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:17:45.0897 5008        WinRM - ok
22:17:46.0084 5008        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:17:46.0147 5008        Wlansvc - ok
22:17:46.0178 5008        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:17:46.0194 5008        WmiAcpi - ok
22:17:46.0256 5008        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:17:46.0287 5008        wmiApSrv - ok
22:17:46.0318 5008        WMPNetworkSvc - ok
22:17:46.0350 5008        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:17:46.0381 5008        WPCSvc - ok
22:17:46.0412 5008        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:17:46.0459 5008        WPDBusEnum - ok
22:17:46.0490 5008        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:17:46.0568 5008        ws2ifsl - ok
22:17:46.0599 5008        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:17:46.0646 5008        wscsvc - ok
22:17:46.0646 5008        WSearch - ok
22:17:46.0849 5008        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:17:46.0974 5008        wuauserv - ok
22:17:47.0114 5008        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:17:47.0192 5008        WudfPf - ok
22:17:47.0223 5008        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:17:47.0270 5008        WUDFRd - ok
22:17:47.0301 5008        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:17:47.0348 5008        wudfsvc - ok
22:17:47.0364 5008        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:17:47.0395 5008        WwanSvc - ok
22:17:47.0442 5008        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:17:47.0878 5008        \Device\Harddisk0\DR0 - ok
22:17:47.0894 5008        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:17:47.0894 5008        \Device\Harddisk0\DR0\Partition0 - ok
22:17:47.0925 5008        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:17:47.0925 5008        \Device\Harddisk0\DR0\Partition1 - ok
22:17:47.0941 5008        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:17:47.0941 5008        \Device\Harddisk0\DR0\Partition2 - ok
22:17:47.0972 5008        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:17:47.0972 5008        \Device\Harddisk0\DR0\Partition3 - ok
22:17:47.0972 5008        ============================================================
22:17:47.0972 5008        Scan finished
22:17:47.0972 5008        ============================================================
22:17:47.0988 4000        Detected object count: 0
22:17:47.0988 4000        Actual detected object count: 0
22:20:31.0079 2636        ============================================================
22:20:31.0079 2636        Scan started
22:20:31.0079 2636        Mode: Manual; TDLFS;
22:20:31.0079 2636        ============================================================
22:20:31.0110 2636        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:20:31.0532 2636        \Device\Harddisk0\DR0 - ok
22:20:31.0547 2636        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:20:31.0547 2636        \Device\Harddisk0\DR0\Partition0 - ok
22:20:31.0578 2636        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:20:31.0578 2636        \Device\Harddisk0\DR0\Partition1 - ok
22:20:31.0594 2636        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:20:31.0594 2636        \Device\Harddisk0\DR0\Partition2 - ok
22:20:31.0625 2636        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:20:31.0625 2636        \Device\Harddisk0\DR0\Partition3 - ok
22:20:31.0625 2636        ============================================================
22:20:31.0625 2636        Scan finished
22:20:31.0625 2636        ============================================================
22:20:31.0641 3268        Detected object count: 0
22:20:31.0641 3268        Actual detected object count: 0
22:20:39.0706 4036        ============================================================
22:20:39.0706 4036        Scan started
22:20:39.0706 4036        Mode: Manual; SigCheck; TDLFS;
22:20:39.0706 4036        ============================================================
22:20:39.0706 4036        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:20:41.0048 4036        \Device\Harddisk0\DR0 - ok
22:20:41.0079 4036        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:20:41.0079 4036        \Device\Harddisk0\DR0\Partition0 - ok
22:20:41.0094 4036        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:20:41.0094 4036        \Device\Harddisk0\DR0\Partition1 - ok
22:20:41.0126 4036        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:20:41.0126 4036        \Device\Harddisk0\DR0\Partition2 - ok
22:20:41.0141 4036        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:20:41.0141 4036        \Device\Harddisk0\DR0\Partition3 - ok
22:20:41.0157 4036        ============================================================
22:20:41.0157 4036        Scan finished
22:20:41.0157 4036        ============================================================
22:20:41.0157 4156        Detected object count: 0
22:20:41.0157 4156        Actual detected object count: 0
22:20:48.0957 1072        ============================================================
22:20:48.0957 1072        Scan started
22:20:48.0957 1072        Mode: Manual; SigCheck;
22:20:48.0957 1072        ============================================================
22:20:49.0128 1072        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:20:49.0160 1072        1394ohci - ok
22:20:49.0206 1072        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:20:49.0238 1072        ACPI - ok
22:20:49.0238 1072        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:20:49.0284 1072        AcpiPmi - ok
22:20:49.0394 1072        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:20:49.0409 1072        AdobeActiveFileMonitor8.0 - ok
22:20:49.0534 1072        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:20:49.0565 1072        AdobeFlashPlayerUpdateSvc - ok
22:20:49.0612 1072        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:20:49.0643 1072        adp94xx - ok
22:20:49.0706 1072        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:20:49.0737 1072        adpahci - ok
22:20:49.0768 1072        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:20:49.0784 1072        adpu320 - ok
22:20:49.0815 1072        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:20:49.0877 1072        AeLookupSvc - ok
22:20:49.0940 1072        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:20:49.0971 1072        AFD - ok
22:20:50.0002 1072        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:20:50.0033 1072        agp440 - ok
22:20:50.0033 1072        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:20:50.0064 1072        ALG - ok
22:20:50.0080 1072        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:20:50.0111 1072        aliide - ok
22:20:50.0111 1072        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:20:50.0142 1072        amdide - ok
22:20:50.0158 1072        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:20:50.0174 1072        AmdK8 - ok
22:20:50.0174 1072        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:20:50.0189 1072        AmdPPM - ok
22:20:50.0205 1072        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:20:50.0236 1072        amdsata - ok
22:20:50.0252 1072        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:20:50.0283 1072        amdsbs - ok
22:20:50.0298 1072        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:20:50.0330 1072        amdxata - ok
22:20:50.0361 1072        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:20:50.0376 1072        AmUStor - ok
22:20:50.0439 1072        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:20:50.0470 1072        AntiVirSchedulerService - ok
22:20:50.0486 1072        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:20:50.0517 1072        AntiVirService - ok
22:20:50.0548 1072        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:20:50.0595 1072        AppID - ok
22:20:50.0610 1072        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:20:50.0673 1072        AppIDSvc - ok
22:20:50.0673 1072        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:20:50.0688 1072        Appinfo - ok
22:20:50.0720 1072        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:20:50.0735 1072        arc - ok
22:20:50.0751 1072        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:20:50.0766 1072        arcsas - ok
22:20:50.0766 1072        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:20:50.0813 1072        AsyncMac - ok
22:20:50.0844 1072        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:20:50.0860 1072        atapi - ok
22:20:51.0047 1072        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:20:51.0125 1072        athr - ok
22:20:51.0281 1072        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:20:51.0375 1072        AudioEndpointBuilder - ok
22:20:51.0375 1072        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:20:51.0437 1072        AudioSrv - ok
22:20:51.0500 1072        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:20:51.0515 1072        avgntflt - ok
22:20:51.0546 1072        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:20:51.0578 1072        avipbb - ok
22:20:51.0593 1072        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:20:51.0609 1072        avkmgr - ok
22:20:51.0640 1072        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:20:51.0687 1072        AxInstSV - ok
22:20:51.0749 1072        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:20:51.0796 1072        b06bdrv - ok
22:20:51.0827 1072        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:20:51.0858 1072        b57nd60a - ok
22:20:51.0999 1072        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:20:52.0061 1072        BCM43XX - ok
22:20:52.0092 1072        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:20:52.0124 1072        BDESVC - ok
22:20:52.0186 1072        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:20:52.0264 1072        Beep - ok
22:20:52.0311 1072        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:20:52.0358 1072        BFE - ok
22:20:52.0451 1072        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:20:52.0529 1072        BITS - ok
22:20:52.0592 1072        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:20:52.0607 1072        blbdrive - ok
22:20:52.0654 1072        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:20:52.0685 1072        bowser - ok
22:20:52.0701 1072        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:20:52.0732 1072        BrFiltLo - ok
22:20:52.0732 1072        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:20:52.0763 1072        BrFiltUp - ok
22:20:52.0810 1072        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:20:52.0872 1072        Browser - ok
22:20:52.0904 1072        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:20:52.0935 1072        Brserid - ok
22:20:52.0935 1072        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:20:52.0982 1072        BrSerWdm - ok
22:20:52.0982 1072        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:20:52.0997 1072        BrUsbMdm - ok
22:20:53.0013 1072        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:20:53.0028 1072        BrUsbSer - ok
22:20:53.0028 1072        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:20:53.0060 1072        BTHMODEM - ok
22:20:53.0075 1072        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:20:53.0122 1072        bthserv - ok
22:20:53.0153 1072        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:20:53.0216 1072        cdfs - ok
22:20:53.0247 1072        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:20:53.0278 1072        cdrom - ok
22:20:53.0294 1072        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:20:53.0372 1072        CertPropSvc - ok
22:20:53.0372 1072        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:20:53.0403 1072        circlass - ok
22:20:53.0434 1072        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:20:53.0465 1072        CLFS - ok
22:20:53.0543 1072        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:20:53.0574 1072        clr_optimization_v2.0.50727_32 - ok
22:20:53.0606 1072        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:20:53.0621 1072        clr_optimization_v2.0.50727_64 - ok
22:20:53.0637 1072        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:20:53.0668 1072        CmBatt - ok
22:20:53.0699 1072        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:20:53.0730 1072        cmdide - ok
22:20:53.0793 1072        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:20:53.0840 1072        CNG - ok
22:20:53.0855 1072        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:20:53.0871 1072        Compbatt - ok
22:20:53.0871 1072        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:20:53.0902 1072        CompositeBus - ok
22:20:53.0902 1072        COMSysApp - ok
22:20:53.0918 1072        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:20:53.0933 1072        crcdisk - ok
22:20:53.0980 1072        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:20:54.0011 1072        CryptSvc - ok
22:20:54.0074 1072        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:20:54.0152 1072        DcomLaunch - ok
22:20:54.0198 1072        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:20:54.0276 1072        defragsvc - ok
22:20:54.0323 1072        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:20:54.0339 1072        DfsC - ok
22:20:54.0401 1072        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:20:54.0432 1072        Dhcp - ok
22:20:54.0479 1072        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:20:54.0542 1072        discache - ok
22:20:54.0557 1072        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:20:54.0573 1072        Disk - ok
22:20:54.0620 1072        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:20:54.0651 1072        Dnscache - ok
22:20:54.0698 1072        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:20:54.0760 1072        dot3svc - ok
22:20:54.0791 1072        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:20:54.0838 1072        DPS - ok
22:20:54.0854 1072        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:20:54.0869 1072        drmkaud - ok
22:20:54.0978 1072        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:20:55.0010 1072        DsiWMIService - ok
22:20:55.0103 1072        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:20:55.0150 1072        DXGKrnl - ok
22:20:55.0181 1072        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:20:55.0244 1072        EapHost - ok
22:20:55.0524 1072        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:20:55.0602 1072        ebdrv - ok
22:20:55.0712 1072        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:20:55.0743 1072        EFS - ok
22:20:55.0868 1072        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:20:55.0899 1072        ehRecvr - ok
22:20:55.0930 1072        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:20:55.0961 1072        ehSched - ok
22:20:56.0070 1072        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:20:56.0102 1072        elxstor - ok
22:20:56.0320 1072        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:20:56.0367 1072        ePowerSvc - ok
22:20:56.0492 1072        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:20:56.0523 1072        ErrDev - ok
22:20:56.0585 1072        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:20:56.0663 1072        EventSystem - ok
22:20:56.0694 1072        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:20:56.0757 1072        exfat - ok
22:20:56.0772 1072        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:20:56.0819 1072        fastfat - ok
22:20:56.0882 1072        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:20:56.0928 1072        Fax - ok
22:20:56.0944 1072        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:20:56.0960 1072        fdc - ok
22:20:56.0975 1072        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:20:57.0069 1072        fdPHost - ok
22:20:57.0084 1072        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:20:57.0162 1072        FDResPub - ok
22:20:57.0178 1072        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:20:57.0194 1072        FileInfo - ok
22:20:57.0194 1072        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:20:57.0240 1072        Filetrace - ok
22:20:57.0350 1072        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:20:57.0396 1072        FLEXnet Licensing Service - ok
22:20:57.0428 1072        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:20:57.0443 1072        flpydisk - ok
22:20:57.0459 1072        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:20:57.0490 1072        FltMgr - ok
22:20:57.0599 1072        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:20:57.0693 1072        FontCache - ok
22:20:57.0755 1072        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:20:57.0786 1072        FontCache3.0.0.0 - ok
22:20:57.0818 1072        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:20:57.0849 1072        FsDepends - ok
22:20:57.0864 1072        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:20:57.0896 1072        Fs_Rec - ok
22:20:57.0942 1072        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:20:57.0974 1072        fvevol - ok
22:20:57.0989 1072        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:20:58.0005 1072        gagp30kx - ok
22:20:58.0098 1072        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:20:58.0130 1072        GameConsoleService - ok
22:20:58.0223 1072        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:20:58.0286 1072        gpsvc - ok
22:20:58.0317 1072        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:20:58.0332 1072        GREGService - ok
22:20:58.0364 1072        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:20:58.0379 1072        hcw85cir - ok
22:20:58.0426 1072        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:20:58.0457 1072        HdAudAddService - ok
22:20:58.0488 1072        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:20:58.0520 1072        HDAudBus - ok
22:20:58.0551 1072        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:20:58.0566 1072        HECIx64 - ok
22:20:58.0566 1072        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:20:58.0598 1072        HidBatt - ok
22:20:58.0613 1072        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:20:58.0644 1072        HidBth - ok
22:20:58.0660 1072        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:20:58.0691 1072        HidIr - ok
22:20:58.0722 1072        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:20:58.0769 1072        hidserv - ok
22:20:58.0800 1072        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:20:58.0800 1072        HidUsb - ok
22:20:58.0832 1072        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:20:58.0878 1072        hkmsvc - ok
22:20:58.0910 1072        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:20:58.0925 1072        HomeGroupListener - ok
22:20:58.0956 1072        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:20:58.0988 1072        HomeGroupProvider - ok
22:20:59.0019 1072        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:20:59.0050 1072        HpSAMD - ok
22:20:59.0159 1072        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:20:59.0206 1072        hshld - ok
22:20:59.0222 1072        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:20:59.0237 1072        HssDrv - ok
22:20:59.0268 1072        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:20:59.0300 1072        HssSrv - ok
22:20:59.0331 1072        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:20:59.0346 1072        HssTrayService - ok
22:20:59.0362 1072        HssWd - ok
22:20:59.0440 1072        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:20:59.0534 1072        HTTP - ok
22:20:59.0549 1072        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:20:59.0565 1072        hwpolicy - ok
22:20:59.0580 1072        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:20:59.0596 1072        i8042prt - ok
22:20:59.0674 1072        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:20:59.0705 1072        iaStor - ok
22:20:59.0752 1072        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:20:59.0783 1072        iaStorV - ok
22:20:59.0970 1072        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:21:00.0017 1072        idsvc - ok
22:21:00.0735 1072        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:21:00.0875 1072        igfx - ok
22:21:01.0016 1072        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:21:01.0031 1072        iirsp - ok
22:21:01.0140 1072        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:21:01.0234 1072        IKEEXT - ok
22:21:01.0265 1072        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:21:01.0281 1072        Impcd - ok
22:21:01.0484 1072        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:21:01.0593 1072        IntcAzAudAddService - ok
22:21:01.0733 1072        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:21:01.0764 1072        IntcDAud - ok
22:21:01.0796 1072        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:21:01.0811 1072        intelide - ok
22:21:01.0842 1072        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:21:01.0858 1072        intelppm - ok
22:21:01.0889 1072        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:21:01.0983 1072        IPBusEnum - ok
22:21:02.0014 1072        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:21:02.0076 1072        IpFilterDriver - ok
22:21:02.0123 1072        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:21:02.0217 1072        iphlpsvc - ok
22:21:02.0217 1072        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:21:02.0232 1072        IPMIDRV - ok
22:21:02.0248 1072        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:21:02.0295 1072        IPNAT - ok
22:21:02.0295 1072        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:21:02.0310 1072        IRENUM - ok
22:21:02.0326 1072        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:21:02.0342 1072        isapnp - ok
22:21:02.0373 1072        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:21:02.0388 1072        iScsiPrt - ok
22:21:02.0451 1072        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:21:02.0482 1072        k57nd60a - ok
22:21:02.0482 1072        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:21:02.0513 1072        kbdclass - ok
22:21:02.0513 1072        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:21:02.0544 1072        kbdhid - ok
22:21:02.0560 1072        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:02.0591 1072        KeyIso - ok
22:21:02.0607 1072        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:21:02.0622 1072        KSecDD - ok
22:21:02.0654 1072        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:21:02.0669 1072        KSecPkg - ok
22:21:02.0685 1072        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:21:02.0732 1072        ksthunk - ok
22:21:02.0778 1072        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:21:02.0856 1072        KtmRm - ok
22:21:02.0872 1072        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:21:02.0888 1072        L1E - ok
22:21:02.0950 1072        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:21:02.0981 1072        LanmanServer - ok
22:21:03.0012 1072        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:21:03.0075 1072        LanmanWorkstation - ok
22:21:03.0090 1072        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:21:03.0137 1072        lltdio - ok
22:21:03.0200 1072        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:21:03.0262 1072        lltdsvc - ok
22:21:03.0278 1072        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:21:03.0340 1072        lmhosts - ok
22:21:03.0449 1072        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:21:03.0480 1072        LMS - ok
22:21:03.0527 1072        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:21:03.0558 1072        LSI_FC - ok
22:21:03.0574 1072        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:21:03.0605 1072        LSI_SAS - ok
22:21:03.0621 1072        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:21:03.0652 1072        LSI_SAS2 - ok
22:21:03.0668 1072        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:21:03.0699 1072        LSI_SCSI - ok
22:21:03.0730 1072        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:21:03.0777 1072        luafv - ok
22:21:03.0808 1072        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:21:03.0824 1072        MBAMProtector - ok
22:21:03.0886 1072        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:21:03.0933 1072        MBAMService - ok
22:21:03.0980 1072        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:21:04.0011 1072        Mcx2Svc - ok
22:21:04.0026 1072        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:21:04.0058 1072        megasas - ok
22:21:04.0089 1072        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:21:04.0104 1072        MegaSR - ok
22:21:04.0136 1072        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:21:04.0198 1072        MMCSS - ok
22:21:04.0214 1072        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:21:04.0260 1072        Modem - ok
22:21:04.0276 1072        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:21:04.0292 1072        monitor - ok
22:21:04.0307 1072        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:21:04.0323 1072        mouclass - ok
22:21:04.0323 1072        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:21:04.0338 1072        mouhid - ok
22:21:04.0354 1072        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:21:04.0370 1072        mountmgr - ok
22:21:04.0432 1072        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:21:04.0463 1072        MozillaMaintenance - ok
22:21:04.0494 1072        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:21:04.0526 1072        mpio - ok
22:21:04.0526 1072        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:21:04.0588 1072        mpsdrv - ok
22:21:04.0666 1072        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:21:04.0760 1072        MpsSvc - ok
22:21:04.0775 1072        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:21:04.0806 1072        MRxDAV - ok
22:21:04.0838 1072        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:21:04.0869 1072        mrxsmb - ok
22:21:04.0916 1072        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:21:04.0931 1072        mrxsmb10 - ok
22:21:04.0962 1072        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:21:04.0978 1072        mrxsmb20 - ok
22:21:05.0009 1072        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:21:05.0025 1072        msahci - ok
22:21:05.0056 1072        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:21:05.0072 1072        msdsm - ok
22:21:05.0103 1072        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:21:05.0134 1072        MSDTC - ok
22:21:05.0165 1072        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:21:05.0228 1072        Msfs - ok
22:21:05.0243 1072        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:21:05.0290 1072        mshidkmdf - ok
22:21:05.0290 1072        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:21:05.0306 1072        msisadrv - ok
22:21:05.0337 1072        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:21:05.0384 1072        MSiSCSI - ok
22:21:05.0384 1072        msiserver - ok
22:21:05.0399 1072        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:21:05.0446 1072        MSKSSRV - ok
22:21:05.0446 1072        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:21:05.0493 1072        MSPCLOCK - ok
22:21:05.0508 1072        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:21:05.0540 1072        MSPQM - ok
22:21:05.0571 1072        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:21:05.0586 1072        MsRPC - ok
22:21:05.0602 1072        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:21:05.0618 1072        mssmbios - ok
22:21:05.0633 1072        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:21:05.0664 1072        MSTEE - ok
22:21:05.0680 1072        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:21:05.0696 1072        MTConfig - ok
22:21:05.0711 1072        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:21:05.0711 1072        Mup - ok
22:21:05.0805 1072        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:21:05.0898 1072        napagent - ok
22:21:05.0930 1072        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:21:05.0976 1072        NativeWifiP - ok
22:21:06.0070 1072        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:21:06.0117 1072        NDIS - ok
22:21:06.0148 1072        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:21:06.0195 1072        NdisCap - ok
22:21:06.0210 1072        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:21:06.0242 1072        NdisTapi - ok
22:21:06.0257 1072        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:21:06.0304 1072        Ndisuio - ok
22:21:06.0304 1072        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:21:06.0351 1072        NdisWan - ok
22:21:06.0366 1072        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:21:06.0413 1072        NDProxy - ok
22:21:06.0569 1072        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:21:06.0616 1072        Nero BackItUp Scheduler 4.0 - ok
22:21:06.0616 1072        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:21:06.0678 1072        NetBIOS - ok
22:21:06.0710 1072        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:21:06.0756 1072        NetBT - ok
22:21:06.0788 1072        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:06.0803 1072        Netlogon - ok
22:21:06.0850 1072        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:21:06.0912 1072        Netman - ok
22:21:06.0959 1072        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:21:07.0022 1072        netprofm - ok
22:21:07.0100 1072        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:21:07.0115 1072        NetTcpPortSharing - ok
22:21:07.0146 1072        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:21:07.0178 1072        nfrd960 - ok
22:21:07.0224 1072        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:21:07.0318 1072        NlaSvc - ok
22:21:07.0334 1072        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:21:07.0380 1072        Npfs - ok
22:21:07.0396 1072        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:21:07.0427 1072        nsi - ok
22:21:07.0443 1072        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:21:07.0474 1072        nsiproxy - ok
22:21:07.0630 1072        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:21:07.0677 1072        Ntfs - ok
22:21:07.0786 1072        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:21:07.0802 1072        NTI IScheduleSvc - ok
22:21:07.0958 1072        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:21:07.0973 1072        NTIDrvr - ok
22:21:08.0004 1072        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:21:08.0098 1072        Null - ok
22:21:08.0129 1072        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:21:08.0145 1072        nvraid - ok
22:21:08.0176 1072        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:21:08.0192 1072        nvstor - ok
22:21:08.0207 1072        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:21:08.0238 1072        nv_agp - ok
22:21:08.0238 1072        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:21:08.0254 1072        ohci1394 - ok
22:21:08.0332 1072        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:21:08.0363 1072        p2pimsvc - ok
22:21:08.0410 1072        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:21:08.0441 1072        p2psvc - ok
22:21:08.0457 1072        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:21:08.0472 1072        Parport - ok
22:21:08.0504 1072        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:21:08.0535 1072        partmgr - ok
22:21:08.0550 1072        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:21:08.0597 1072        PcaSvc - ok
22:21:08.0628 1072        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:21:08.0660 1072        pci - ok
22:21:08.0691 1072        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:21:08.0706 1072        pciide - ok
22:21:08.0738 1072        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:21:08.0784 1072        pcmcia - ok
22:21:08.0784 1072        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:21:08.0816 1072        pcw - ok
22:21:08.0862 1072        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:21:08.0940 1072        PEAUTH - ok
22:21:09.0018 1072        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:21:09.0050 1072        PerfHost - ok
22:21:09.0206 1072        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:21:09.0299 1072        pla - ok
22:21:09.0362 1072        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:21:09.0393 1072        PlugPlay - ok
22:21:09.0408 1072        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:21:09.0440 1072        PNRPAutoReg - ok
22:21:09.0486 1072        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:21:09.0533 1072        PNRPsvc - ok
22:21:09.0611 1072        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:21:09.0689 1072        PolicyAgent - ok
22:21:09.0720 1072        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:21:09.0783 1072        Power - ok
22:21:09.0845 1072        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:21:09.0908 1072        PptpMiniport - ok
22:21:09.0954 1072        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:21:09.0970 1072        Processor - ok
22:21:10.0017 1072        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:21:10.0048 1072        ProfSvc - ok
22:21:10.0079 1072        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:10.0110 1072        ProtectedStorage - ok
22:21:10.0142 1072        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:21:10.0235 1072        Psched - ok
22:21:10.0266 1072        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:21:10.0266 1072        PxHlpa64 - ok
22:21:10.0407 1072        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:21:10.0485 1072        ql2300 - ok
22:21:10.0641 1072        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:21:10.0672 1072        ql40xx - ok
22:21:10.0703 1072        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:21:10.0750 1072        QWAVE - ok
22:21:10.0766 1072        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:21:10.0797 1072        QWAVEdrv - ok
22:21:10.0812 1072        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:21:10.0859 1072        RasAcd - ok
22:21:10.0890 1072        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:21:10.0937 1072        RasAgileVpn - ok
22:21:10.0984 1072        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:21:11.0031 1072        RasAuto - ok
22:21:11.0046 1072        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:21:11.0093 1072        Rasl2tp - ok
22:21:11.0140 1072        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:21:11.0187 1072        RasMan - ok
22:21:11.0202 1072        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:21:11.0249 1072        RasPppoe - ok
22:21:11.0265 1072        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:21:11.0296 1072        RasSstp - ok
22:21:11.0327 1072        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:21:11.0374 1072        rdbss - ok
22:21:11.0390 1072        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:21:11.0405 1072        rdpbus - ok
22:21:11.0421 1072        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:21:11.0468 1072        RDPCDD - ok
22:21:11.0468 1072        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:21:11.0514 1072        RDPENCDD - ok
22:21:11.0514 1072        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:21:11.0561 1072        RDPREFMP - ok
22:21:11.0592 1072        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:21:11.0624 1072        RDPWD - ok
22:21:11.0670 1072        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:21:11.0686 1072        rdyboost - ok
22:21:11.0717 1072        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:21:11.0780 1072        RemoteAccess - ok
22:21:11.0826 1072        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:21:11.0904 1072        RemoteRegistry - ok
22:21:11.0920 1072        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:21:11.0982 1072        RpcEptMapper - ok
22:21:11.0998 1072        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:21:12.0029 1072        RpcLocator - ok
22:21:12.0092 1072        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:21:12.0170 1072        RpcSs - ok
22:21:12.0201 1072        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:21:12.0248 1072        rspndr - ok
22:21:12.0263 1072        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:12.0279 1072        SamSs - ok
22:21:12.0310 1072        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:21:12.0326 1072        sbp2port - ok
22:21:12.0357 1072        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:21:12.0404 1072        SCardSvr - ok
22:21:12.0419 1072        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:21:12.0450 1072        scfilter - ok
22:21:12.0575 1072        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:21:12.0622 1072        Schedule - ok
22:21:12.0653 1072        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:21:12.0716 1072        SCPolicySvc - ok
22:21:12.0747 1072        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:21:12.0778 1072        SDRSVC - ok
22:21:12.0840 1072        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:21:12.0903 1072        secdrv - ok
22:21:12.0918 1072        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:21:12.0981 1072        seclogon - ok
22:21:12.0981 1072        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:21:13.0028 1072        SENS - ok
22:21:13.0028 1072        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:21:13.0043 1072        SensrSvc - ok
22:21:13.0074 1072        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:21:13.0074 1072        Serenum - ok
22:21:13.0106 1072        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:21:13.0121 1072        Serial - ok
22:21:13.0121 1072        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:21:13.0137 1072        sermouse - ok
22:21:13.0152 1072        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:21:13.0199 1072        SessionEnv - ok
22:21:13.0215 1072        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:21:13.0215 1072        sffdisk - ok
22:21:13.0230 1072        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:21:13.0230 1072        sffp_mmc - ok
22:21:13.0246 1072        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:21:13.0262 1072        sffp_sd - ok
22:21:13.0262 1072        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:21:13.0277 1072        sfloppy - ok
22:21:13.0324 1072        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:21:13.0418 1072        SharedAccess - ok
22:21:13.0464 1072        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:21:13.0511 1072        ShellHWDetection - ok
22:21:13.0527 1072        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:21:13.0542 1072        SiSRaid2 - ok
22:21:13.0574 1072        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:21:13.0589 1072        SiSRaid4 - ok
22:21:13.0652 1072        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:21:13.0667 1072        SkypeUpdate - ok
22:21:13.0698 1072        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:21:13.0776 1072        Smb - ok
22:21:13.0823 1072        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:21:13.0839 1072        SNMPTRAP - ok
22:21:13.0870 1072        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:21:13.0886 1072        spldr - ok
22:21:13.0964 1072        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:21:13.0995 1072        Spooler - ok
22:21:14.0291 1072        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:21:14.0354 1072        sppsvc - ok
22:21:14.0463 1072        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:21:14.0541 1072        sppuinotify - ok
22:21:14.0619 1072        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:21:14.0650 1072        srv - ok
22:21:14.0697 1072        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:21:14.0744 1072        srv2 - ok
22:21:14.0759 1072        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:21:14.0775 1072        srvnet - ok
22:21:14.0822 1072        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:21:14.0884 1072        SSDPSRV - ok
22:21:14.0884 1072        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:21:14.0946 1072        SstpSvc - ok
22:21:14.0978 1072        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:21:15.0009 1072        stexstor - ok
22:21:15.0087 1072        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:21:15.0134 1072        stisvc - ok
22:21:15.0149 1072        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:21:15.0165 1072        swenum - ok
22:21:15.0227 1072        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:21:15.0321 1072        swprv - ok
22:21:15.0368 1072        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:21:15.0399 1072        SynTP - ok
22:21:15.0539 1072        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:21:15.0602 1072        SysMain - ok
22:21:15.0726 1072        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:21:15.0773 1072        TabletInputService - ok
22:21:15.0820 1072        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:21:15.0836 1072        taphss - ok
22:21:15.0882 1072        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:21:15.0945 1072        TapiSrv - ok
22:21:15.0976 1072        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:21:16.0023 1072        TBS - ok
22:21:16.0194 1072        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:21:16.0257 1072        Tcpip - ok
22:21:16.0538 1072        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:21:16.0616 1072        TCPIP6 - ok
22:21:16.0772 1072        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:21:16.0850 1072        tcpipreg - ok
22:21:16.0865 1072        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:21:16.0881 1072        TDPIPE - ok
22:21:16.0912 1072        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:21:16.0928 1072        TDTCP - ok
22:21:16.0943 1072        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:21:16.0990 1072        tdx - ok
22:21:17.0255 1072        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:21:17.0333 1072        TeamViewer7 - ok
22:21:17.0489 1072        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:21:17.0505 1072        TermDD - ok
22:21:17.0598 1072        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:21:17.0676 1072        TermService - ok
22:21:17.0692 1072        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:21:17.0708 1072        Themes - ok
22:21:17.0739 1072        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:21:17.0801 1072        THREADORDER - ok
22:21:17.0832 1072        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:21:17.0879 1072        TrkWks - ok
22:21:17.0957 1072        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:21:17.0988 1072        TrustedInstaller - ok
22:21:18.0004 1072        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:21:18.0066 1072        tssecsrv - ok
22:21:18.0098 1072        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:21:18.0144 1072        tunnel - ok
22:21:18.0160 1072        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:21:18.0176 1072        uagp35 - ok
22:21:18.0191 1072        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:21:18.0207 1072        UBHelper - ok
22:21:18.0238 1072        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:21:18.0300 1072        udfs - ok
22:21:18.0316 1072        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:21:18.0332 1072        UI0Detect - ok
22:21:18.0332 1072        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:21:18.0347 1072        uliagpkx - ok
22:21:18.0363 1072        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:21:18.0378 1072        umbus - ok
22:21:18.0378 1072        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:21:18.0394 1072        UmPass - ok
22:21:18.0675 1072        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:21:18.0753 1072        UNS - ok
22:21:18.0815 1072        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:21:18.0831 1072        Updater Service - ok
22:21:18.0987 1072        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:21:19.0065 1072        upnphost - ok
22:21:19.0127 1072        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:21:19.0158 1072        usbccgp - ok
22:21:19.0174 1072        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:21:19.0205 1072        usbcir - ok
22:21:19.0221 1072        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:21:19.0252 1072        usbehci - ok
22:21:19.0283 1072        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:21:19.0314 1072        usbhub - ok
22:21:19.0346 1072        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:21:19.0361 1072        usbohci - ok
22:21:19.0377 1072        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:21:19.0408 1072        usbprint - ok
22:21:19.0439 1072        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:21:19.0455 1072        USBSTOR - ok
22:21:19.0470 1072        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:21:19.0486 1072        usbuhci - ok
22:21:19.0533 1072        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:21:19.0548 1072        usbvideo - ok
22:21:19.0595 1072        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:21:19.0658 1072        UxSms - ok
22:21:19.0704 1072        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:19.0736 1072        VaultSvc - ok
22:21:19.0767 1072        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:21:19.0798 1072        vdrvroot - ok
22:21:19.0892 1072        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:21:19.0923 1072        vds - ok
22:21:19.0938 1072        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:21:19.0970 1072        vga - ok
22:21:19.0985 1072        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:21:20.0032 1072        VgaSave - ok
22:21:20.0079 1072        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:21:20.0094 1072        vhdmp - ok
22:21:20.0094 1072        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:21:20.0110 1072        viaide - ok
22:21:20.0126 1072        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:21:20.0141 1072        volmgr - ok
22:21:20.0172 1072        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:21:20.0188 1072        volmgrx - ok
22:21:20.0219 1072        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:21:20.0266 1072        volsnap - ok
22:21:20.0297 1072        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:21:20.0313 1072        vsmraid - ok
22:21:20.0500 1072        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:21:20.0562 1072        VSS - ok
22:21:20.0718 1072        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:21:20.0750 1072        vwifibus - ok
22:21:20.0750 1072        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:21:20.0781 1072        vwififlt - ok
22:21:20.0796 1072        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:21:20.0828 1072        vwifimp - ok
22:21:20.0890 1072        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:21:20.0968 1072        W32Time - ok
22:21:20.0968 1072        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:21:20.0984 1072        WacomPen - ok
22:21:20.0999 1072        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:21:21.0030 1072        WANARP - ok
22:21:21.0046 1072        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:21:21.0077 1072        Wanarpv6 - ok
22:21:21.0218 1072        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:21:21.0264 1072        wbengine - ok
22:21:21.0405 1072        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:21:21.0452 1072        WbioSrvc - ok
22:21:21.0514 1072        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:21:21.0545 1072        wcncsvc - ok
22:21:21.0561 1072        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:21:21.0576 1072        WcsPlugInService - ok
22:21:21.0639 1072        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:21:21.0670 1072        Wd - ok


derhunne 15.06.2012 21:43

so der letzte....



Code:

22:21:21.0732 1072        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:21:21.0764 1072        Wdf01000 - ok
22:21:21.0779 1072        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:21:21.0795 1072        WdiServiceHost - ok
22:21:21.0795 1072        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:21:21.0826 1072        WdiSystemHost - ok
22:21:21.0873 1072        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:21:21.0888 1072        WebClient - ok
22:21:21.0935 1072        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:21:22.0013 1072        Wecsvc - ok
22:21:22.0044 1072        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:21:22.0091 1072        wercplsupport - ok
22:21:22.0107 1072        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:21:22.0154 1072        WerSvc - ok
22:21:22.0216 1072        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:21:22.0294 1072        WfpLwf - ok
22:21:22.0325 1072        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:21:22.0341 1072        WIMMount - ok
22:21:22.0372 1072        WinDefend - ok
22:21:22.0372 1072        WinHttpAutoProxySvc - ok
22:21:22.0466 1072        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:21:22.0544 1072        Winmgmt - ok
22:21:22.0731 1072        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:21:22.0824 1072        WinRM - ok
22:21:23.0027 1072        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:21:23.0090 1072        Wlansvc - ok
22:21:23.0136 1072        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:21:23.0152 1072        WmiAcpi - ok
22:21:23.0230 1072        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:21:23.0261 1072        wmiApSrv - ok
22:21:23.0292 1072        WMPNetworkSvc - ok
22:21:23.0324 1072        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:21:23.0355 1072        WPCSvc - ok
22:21:23.0370 1072        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:21:23.0402 1072        WPDBusEnum - ok
22:21:23.0433 1072        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:21:23.0511 1072        ws2ifsl - ok
22:21:23.0558 1072        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:21:23.0573 1072        wscsvc - ok
22:21:23.0573 1072        WSearch - ok
22:21:23.0792 1072        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:21:23.0870 1072        wuauserv - ok
22:21:24.0041 1072        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:21:24.0104 1072        WudfPf - ok
22:21:24.0135 1072        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:21:24.0182 1072        WUDFRd - ok
22:21:24.0213 1072        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:21:24.0306 1072        wudfsvc - ok
22:21:24.0322 1072        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:21:24.0353 1072        WwanSvc - ok
22:21:24.0369 1072        ============================================================
22:21:24.0369 1072        Scan finished
22:21:24.0369 1072        ============================================================
22:21:24.0369 2724        Detected object count: 0
22:21:24.0369 2724        Actual detected object count: 0
22:21:33.0744 0168        ============================================================
22:21:33.0744 0168        Scan started
22:21:33.0744 0168        Mode: Manual; SigCheck;
22:21:33.0744 0168        ============================================================
22:21:33.0932 0168        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:21:33.0963 0168        1394ohci - ok
22:21:34.0010 0168        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:21:34.0056 0168        ACPI - ok
22:21:34.0056 0168        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:21:34.0088 0168        AcpiPmi - ok
22:21:34.0197 0168        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:21:34.0212 0168        AdobeActiveFileMonitor8.0 - ok
22:21:34.0353 0168        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:21:34.0384 0168        AdobeFlashPlayerUpdateSvc - ok
22:21:34.0431 0168        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:21:34.0478 0168        adp94xx - ok
22:21:34.0524 0168        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:21:34.0571 0168        adpahci - ok
22:21:34.0602 0168        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:21:34.0618 0168        adpu320 - ok
22:21:34.0665 0168        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:21:34.0743 0168        AeLookupSvc - ok
22:21:34.0805 0168        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:21:34.0836 0168        AFD - ok
22:21:34.0868 0168        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:21:34.0899 0168        agp440 - ok
22:21:34.0899 0168        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:21:34.0930 0168        ALG - ok
22:21:34.0946 0168        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:21:34.0961 0168        aliide - ok
22:21:34.0977 0168        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:21:34.0992 0168        amdide - ok
22:21:35.0024 0168        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:21:35.0055 0168        AmdK8 - ok
22:21:35.0086 0168        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:21:35.0117 0168        AmdPPM - ok
22:21:35.0148 0168        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:21:35.0164 0168        amdsata - ok
22:21:35.0195 0168        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:21:35.0226 0168        amdsbs - ok
22:21:35.0242 0168        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:21:35.0258 0168        amdxata - ok
22:21:35.0289 0168        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:21:35.0304 0168        AmUStor - ok
22:21:35.0382 0168        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:21:35.0398 0168        AntiVirSchedulerService - ok
22:21:35.0429 0168        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:21:35.0445 0168        AntiVirService - ok
22:21:35.0476 0168        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:21:35.0507 0168        AppID - ok
22:21:35.0554 0168        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:21:35.0616 0168        AppIDSvc - ok
22:21:35.0632 0168        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:21:35.0648 0168        Appinfo - ok
22:21:35.0663 0168        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:21:35.0679 0168        arc - ok
22:21:35.0694 0168        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:21:35.0710 0168        arcsas - ok
22:21:35.0710 0168        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:21:35.0757 0168        AsyncMac - ok
22:21:35.0788 0168        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:21:35.0788 0168        atapi - ok
22:21:35.0991 0168        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:21:36.0053 0168        athr - ok
22:21:36.0225 0168        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:21:36.0287 0168        AudioEndpointBuilder - ok
22:21:36.0303 0168        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:21:36.0350 0168        AudioSrv - ok
22:21:36.0396 0168        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:21:36.0412 0168        avgntflt - ok
22:21:36.0428 0168        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:21:36.0443 0168        avipbb - ok
22:21:36.0459 0168        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:21:36.0459 0168        avkmgr - ok
22:21:36.0490 0168        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:21:36.0537 0168        AxInstSV - ok
22:21:36.0615 0168        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:21:36.0646 0168        b06bdrv - ok
22:21:36.0677 0168        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:21:36.0708 0168        b57nd60a - ok
22:21:36.0849 0168        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:21:36.0896 0168        BCM43XX - ok
22:21:36.0927 0168        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:21:36.0942 0168        BDESVC - ok
22:21:36.0974 0168        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:21:37.0052 0168        Beep - ok
22:21:37.0098 0168        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:21:37.0176 0168        BFE - ok
22:21:37.0270 0168        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:21:37.0348 0168        BITS - ok
22:21:37.0395 0168        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:21:37.0426 0168        blbdrive - ok
22:21:37.0457 0168        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:21:37.0488 0168        bowser - ok
22:21:37.0504 0168        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:21:37.0520 0168        BrFiltLo - ok
22:21:37.0535 0168        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:21:37.0551 0168        BrFiltUp - ok
22:21:37.0582 0168        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:21:37.0644 0168        Browser - ok
22:21:37.0660 0168        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:21:37.0676 0168        Brserid - ok
22:21:37.0676 0168        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:21:37.0691 0168        BrSerWdm - ok
22:21:37.0707 0168        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:21:37.0722 0168        BrUsbMdm - ok
22:21:37.0722 0168        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:21:37.0738 0168        BrUsbSer - ok
22:21:37.0738 0168        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:21:37.0754 0168        BTHMODEM - ok
22:21:37.0769 0168        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:21:37.0816 0168        bthserv - ok
22:21:37.0832 0168        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:21:37.0878 0168        cdfs - ok
22:21:37.0910 0168        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:21:37.0925 0168        cdrom - ok
22:21:37.0941 0168        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:21:37.0988 0168        CertPropSvc - ok
22:21:37.0988 0168        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:21:38.0003 0168        circlass - ok
22:21:38.0050 0168        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:21:38.0081 0168        CLFS - ok
22:21:38.0144 0168        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:21:38.0159 0168        clr_optimization_v2.0.50727_32 - ok
22:21:38.0190 0168        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:21:38.0222 0168        clr_optimization_v2.0.50727_64 - ok
22:21:38.0237 0168        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:21:38.0268 0168        CmBatt - ok
22:21:38.0300 0168        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:21:38.0331 0168        cmdide - ok
22:21:38.0378 0168        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:21:38.0440 0168        CNG - ok
22:21:38.0456 0168        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:21:38.0471 0168        Compbatt - ok
22:21:38.0487 0168        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:21:38.0518 0168        CompositeBus - ok
22:21:38.0518 0168        COMSysApp - ok
22:21:38.0549 0168        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:21:38.0565 0168        crcdisk - ok
22:21:38.0612 0168        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:21:38.0643 0168        CryptSvc - ok
22:21:38.0705 0168        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:21:38.0768 0168        DcomLaunch - ok
22:21:38.0814 0168        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:21:38.0877 0168        defragsvc - ok
22:21:38.0924 0168        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:21:38.0939 0168        DfsC - ok
22:21:38.0986 0168        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:21:39.0033 0168        Dhcp - ok
22:21:39.0064 0168        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:21:39.0142 0168        discache - ok
22:21:39.0158 0168        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:21:39.0173 0168        Disk - ok
22:21:39.0220 0168        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:21:39.0236 0168        Dnscache - ok
22:21:39.0282 0168        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:21:39.0329 0168        dot3svc - ok
22:21:39.0360 0168        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:21:39.0407 0168        DPS - ok
22:21:39.0423 0168        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:21:39.0454 0168        drmkaud - ok
22:21:39.0563 0168        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:21:39.0579 0168        DsiWMIService - ok
22:21:39.0688 0168        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:21:39.0719 0168        DXGKrnl - ok
22:21:39.0766 0168        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:21:39.0844 0168        EapHost - ok
22:21:40.0140 0168        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:21:40.0203 0168        ebdrv - ok
22:21:40.0328 0168        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:21:40.0343 0168        EFS - ok
22:21:40.0468 0168        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:21:40.0499 0168        ehRecvr - ok
22:21:40.0530 0168        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:21:40.0546 0168        ehSched - ok
22:21:40.0640 0168        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:21:40.0671 0168        elxstor - ok
22:21:40.0905 0168        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:21:40.0936 0168        ePowerSvc - ok
22:21:41.0076 0168        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:21:41.0108 0168        ErrDev - ok
22:21:41.0154 0168        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:21:41.0232 0168        EventSystem - ok
22:21:41.0264 0168        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:21:41.0357 0168        exfat - ok
22:21:41.0373 0168        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:21:41.0435 0168        fastfat - ok
22:21:41.0498 0168        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:21:41.0529 0168        Fax - ok
22:21:41.0544 0168        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:21:41.0560 0168        fdc - ok
22:21:41.0576 0168        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:21:41.0638 0168        fdPHost - ok
22:21:41.0654 0168        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:21:41.0685 0168        FDResPub - ok
22:21:41.0700 0168        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:21:41.0716 0168        FileInfo - ok
22:21:41.0732 0168        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:21:41.0778 0168        Filetrace - ok
22:21:41.0903 0168        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:21:41.0934 0168        FLEXnet Licensing Service - ok
22:21:41.0950 0168        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:21:41.0966 0168        flpydisk - ok
22:21:41.0997 0168        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:21:42.0012 0168        FltMgr - ok
22:21:42.0137 0168        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:21:42.0231 0168        FontCache - ok
22:21:42.0293 0168        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:21:42.0309 0168        FontCache3.0.0.0 - ok
22:21:42.0356 0168        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:21:42.0371 0168        FsDepends - ok
22:21:42.0402 0168        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:21:42.0418 0168        Fs_Rec - ok
22:21:42.0465 0168        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:21:42.0496 0168        fvevol - ok
22:21:42.0527 0168        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:21:42.0543 0168        gagp30kx - ok
22:21:42.0636 0168        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:21:42.0668 0168        GameConsoleService - ok
22:21:42.0746 0168        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:21:42.0792 0168        gpsvc - ok
22:21:42.0824 0168        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:21:42.0839 0168        GREGService - ok
22:21:42.0886 0168        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:21:42.0902 0168        hcw85cir - ok
22:21:42.0948 0168        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:21:42.0995 0168        HdAudAddService - ok
22:21:43.0026 0168        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:21:43.0058 0168        HDAudBus - ok
22:21:43.0089 0168        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:21:43.0104 0168        HECIx64 - ok
22:21:43.0120 0168        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:21:43.0151 0168        HidBatt - ok
22:21:43.0167 0168        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:21:43.0198 0168        HidBth - ok
22:21:43.0198 0168        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:21:43.0245 0168        HidIr - ok
22:21:43.0276 0168        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:21:43.0354 0168        hidserv - ok
22:21:43.0354 0168        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:21:43.0370 0168        HidUsb - ok
22:21:43.0385 0168        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:21:43.0448 0168        hkmsvc - ok
22:21:43.0463 0168        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:21:43.0479 0168        HomeGroupListener - ok
22:21:43.0526 0168        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:21:43.0557 0168        HomeGroupProvider - ok
22:21:43.0604 0168        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:21:43.0619 0168        HpSAMD - ok
22:21:43.0744 0168        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:21:43.0791 0168        hshld - ok
22:21:43.0806 0168        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:21:43.0838 0168        HssDrv - ok
22:21:43.0884 0168        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:21:43.0916 0168        HssSrv - ok
22:21:43.0947 0168        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:21:43.0962 0168        HssTrayService - ok
22:21:43.0978 0168        HssWd - ok
22:21:44.0056 0168        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:21:44.0134 0168        HTTP - ok
22:21:44.0150 0168        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:21:44.0165 0168        hwpolicy - ok
22:21:44.0181 0168        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:21:44.0196 0168        i8042prt - ok
22:21:44.0259 0168        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:21:44.0290 0168        iaStor - ok
22:21:44.0352 0168        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:21:44.0384 0168        iaStorV - ok
22:21:44.0524 0168        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:21:44.0571 0168        idsvc - ok
22:21:45.0335 0168        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:21:45.0476 0168        igfx - ok
22:21:45.0694 0168        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:21:45.0710 0168        iirsp - ok
22:21:45.0803 0168        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:21:45.0897 0168        IKEEXT - ok
22:21:45.0944 0168        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:21:45.0959 0168        Impcd - ok
22:21:46.0178 0168        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:21:46.0271 0168        IntcAzAudAddService - ok
22:21:46.0427 0168        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:21:46.0443 0168        IntcDAud - ok
22:21:46.0474 0168        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:21:46.0505 0168        intelide - ok
22:21:46.0521 0168        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:21:46.0552 0168        intelppm - ok
22:21:46.0583 0168        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:21:46.0661 0168        IPBusEnum - ok
22:21:46.0692 0168        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:21:46.0739 0168        IpFilterDriver - ok
22:21:46.0786 0168        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:21:46.0848 0168        iphlpsvc - ok
22:21:46.0848 0168        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:21:46.0864 0168        IPMIDRV - ok
22:21:46.0880 0168        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:21:46.0926 0168        IPNAT - ok
22:21:46.0926 0168        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:21:46.0942 0168        IRENUM - ok
22:21:46.0958 0168        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:21:46.0973 0168        isapnp - ok
22:21:47.0004 0168        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:21:47.0036 0168        iScsiPrt - ok
22:21:47.0098 0168        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:21:47.0129 0168        k57nd60a - ok
22:21:47.0145 0168        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:21:47.0160 0168        kbdclass - ok
22:21:47.0160 0168        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:21:47.0176 0168        kbdhid - ok
22:21:47.0207 0168        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:47.0223 0168        KeyIso - ok
22:21:47.0238 0168        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:21:47.0254 0168        KSecDD - ok
22:21:47.0270 0168        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:21:47.0285 0168        KSecPkg - ok
22:21:47.0301 0168        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:21:47.0348 0168        ksthunk - ok
22:21:47.0394 0168        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:21:47.0472 0168        KtmRm - ok
22:21:47.0488 0168        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:21:47.0519 0168        L1E - ok
22:21:47.0582 0168        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:21:47.0613 0168        LanmanServer - ok
22:21:47.0644 0168        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:21:47.0738 0168        LanmanWorkstation - ok
22:21:47.0753 0168        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:21:47.0800 0168        lltdio - ok
22:21:47.0862 0168        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:21:47.0925 0168        lltdsvc - ok
22:21:47.0940 0168        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:21:47.0987 0168        lmhosts - ok
22:21:48.0143 0168        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:21:48.0159 0168        LMS - ok
22:21:48.0206 0168        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:21:48.0221 0168        LSI_FC - ok
22:21:48.0252 0168        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:21:48.0268 0168        LSI_SAS - ok
22:21:48.0284 0168        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:21:48.0299 0168        LSI_SAS2 - ok
22:21:48.0330 0168        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:21:48.0346 0168        LSI_SCSI - ok
22:21:48.0377 0168        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:21:48.0455 0168        luafv - ok
22:21:48.0471 0168        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:21:48.0486 0168        MBAMProtector - ok
22:21:48.0549 0168        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:21:48.0596 0168        MBAMService - ok
22:21:48.0627 0168        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:21:48.0658 0168        Mcx2Svc - ok
22:21:48.0689 0168        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:21:48.0705 0168        megasas - ok
22:21:48.0736 0168        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:21:48.0767 0168        MegaSR - ok
22:21:48.0798 0168        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:21:48.0876 0168        MMCSS - ok
22:21:48.0892 0168        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:21:48.0954 0168        Modem - ok
22:21:48.0970 0168        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:21:48.0986 0168        monitor - ok
22:21:48.0986 0168        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:21:49.0001 0168        mouclass - ok
22:21:49.0017 0168        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:21:49.0032 0168        mouhid - ok
22:21:49.0032 0168        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:21:49.0048 0168        mountmgr - ok
22:21:49.0126 0168        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:21:49.0142 0168        MozillaMaintenance - ok
22:21:49.0173 0168        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:21:49.0204 0168        mpio - ok
22:21:49.0220 0168        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:21:49.0266 0168        mpsdrv - ok
22:21:49.0344 0168        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:21:49.0454 0168        MpsSvc - ok
22:21:49.0485 0168        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:21:49.0500 0168        MRxDAV - ok
22:21:49.0547 0168        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:21:49.0563 0168        mrxsmb - ok
22:21:49.0610 0168        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:21:49.0641 0168        mrxsmb10 - ok
22:21:49.0656 0168        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:21:49.0672 0168        mrxsmb20 - ok
22:21:49.0703 0168        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:21:49.0719 0168        msahci - ok
22:21:49.0734 0168        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:21:49.0750 0168        msdsm - ok
22:21:49.0797 0168        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:21:49.0828 0168        MSDTC - ok
22:21:49.0859 0168        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:21:49.0906 0168        Msfs - ok
22:21:49.0922 0168        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:21:49.0968 0168        mshidkmdf - ok
22:21:49.0968 0168        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:21:49.0984 0168        msisadrv - ok
22:21:50.0015 0168        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:21:50.0078 0168        MSiSCSI - ok
22:21:50.0093 0168        msiserver - ok
22:21:50.0109 0168        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:21:50.0156 0168        MSKSSRV - ok
22:21:50.0156 0168        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:21:50.0202 0168        MSPCLOCK - ok
22:21:50.0202 0168        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:21:50.0249 0168        MSPQM - ok
22:21:50.0265 0168        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:21:50.0296 0168        MsRPC - ok
22:21:50.0296 0168        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:21:50.0312 0168        mssmbios - ok
22:21:50.0327 0168        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:21:50.0374 0168        MSTEE - ok
22:21:50.0374 0168        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:21:50.0390 0168        MTConfig - ok
22:21:50.0405 0168        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:21:50.0421 0168        Mup - ok
22:21:50.0483 0168        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:21:50.0561 0168        napagent - ok
22:21:50.0608 0168        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:21:50.0655 0168        NativeWifiP - ok
22:21:50.0748 0168        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:21:50.0795 0168        NDIS - ok
22:21:50.0811 0168        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:21:50.0858 0168        NdisCap - ok
22:21:50.0889 0168        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:21:50.0920 0168        NdisTapi - ok
22:21:50.0936 0168        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:21:50.0982 0168        Ndisuio - ok
22:21:50.0982 0168        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:21:51.0029 0168        NdisWan - ok
22:21:51.0045 0168        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:21:51.0092 0168        NDProxy - ok
22:21:51.0248 0168        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:21:51.0294 0168        Nero BackItUp Scheduler 4.0 - ok
22:21:51.0294 0168        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:21:51.0357 0168        NetBIOS - ok
22:21:51.0388 0168        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:21:51.0435 0168        NetBT - ok
22:21:51.0466 0168        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:51.0482 0168        Netlogon - ok
22:21:51.0544 0168        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:21:51.0638 0168        Netman - ok
22:21:51.0669 0168        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:21:51.0731 0168        netprofm - ok
22:21:51.0809 0168        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:21:51.0825 0168        NetTcpPortSharing - ok
22:21:51.0856 0168        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:21:51.0887 0168        nfrd960 - ok
22:21:51.0934 0168        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:21:52.0012 0168        NlaSvc - ok
22:21:52.0028 0168        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:21:52.0059 0168        Npfs - ok
22:21:52.0074 0168        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:21:52.0121 0168        nsi - ok
22:21:52.0121 0168        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:21:52.0168 0168        nsiproxy - ok
22:21:52.0308 0168        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:21:52.0386 0168        Ntfs - ok
22:21:52.0480 0168        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:21:52.0511 0168        NTI IScheduleSvc - ok
22:21:52.0636 0168        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:21:52.0652 0168        NTIDrvr - ok
22:21:52.0683 0168        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:21:52.0745 0168        Null - ok
22:21:52.0776 0168        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:21:52.0808 0168        nvraid - ok
22:21:52.0839 0168        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:21:52.0870 0168        nvstor - ok
22:21:52.0886 0168        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:21:52.0917 0168        nv_agp - ok
22:21:52.0917 0168        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:21:52.0932 0168        ohci1394 - ok
22:21:52.0995 0168        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:21:53.0026 0168        p2pimsvc - ok
22:21:53.0073 0168        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:21:53.0120 0168        p2psvc - ok
22:21:53.0120 0168        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:21:53.0151 0168        Parport - ok
22:21:53.0182 0168        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:21:53.0213 0168        partmgr - ok
22:21:53.0229 0168        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:21:53.0276 0168        PcaSvc - ok
22:21:53.0291 0168        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:21:53.0322 0168        pci - ok
22:21:53.0338 0168        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:21:53.0354 0168        pciide - ok
22:21:53.0385 0168        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:21:53.0416 0168        pcmcia - ok
22:21:53.0416 0168        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:21:53.0432 0168        pcw - ok
22:21:53.0478 0168        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:21:53.0572 0168        PEAUTH - ok
22:21:53.0650 0168        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:21:53.0681 0168        PerfHost - ok
22:21:53.0837 0168        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:21:53.0946 0168        pla - ok
22:21:54.0009 0168        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:21:54.0040 0168        PlugPlay - ok
22:21:54.0071 0168        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:21:54.0087 0168        PNRPAutoReg - ok
22:21:54.0118 0168        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:21:54.0149 0168        PNRPsvc - ok
22:21:54.0227 0168        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:21:54.0290 0168        PolicyAgent - ok
22:21:54.0352 0168        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:21:54.0414 0168        Power - ok
22:21:54.0492 0168        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:21:54.0555 0168        PptpMiniport - ok
22:21:54.0586 0168        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:21:54.0602 0168        Processor - ok
22:21:54.0648 0168        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:21:54.0680 0168        ProfSvc - ok
22:21:54.0695 0168        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:54.0726 0168        ProtectedStorage - ok
22:21:54.0773 0168        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:21:54.0851 0168        Psched - ok
22:21:54.0882 0168        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:21:54.0898 0168        PxHlpa64 - ok
22:21:55.0038 0168        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:21:55.0085 0168        ql2300 - ok
22:21:55.0241 0168        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:21:55.0272 0168        ql40xx - ok
22:21:55.0319 0168        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:21:55.0350 0168        QWAVE - ok
22:21:55.0366 0168        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:21:55.0397 0168        QWAVEdrv - ok
22:21:55.0413 0168        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:21:55.0460 0168        RasAcd - ok
22:21:55.0506 0168        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:21:55.0538 0168        RasAgileVpn - ok
22:21:55.0569 0168        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:21:55.0647 0168        RasAuto - ok
22:21:55.0662 0168        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:21:55.0709 0168        Rasl2tp - ok
22:21:55.0772 0168        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:21:55.0850 0168        RasMan - ok
22:21:55.0865 0168        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:21:55.0912 0168        RasPppoe - ok
22:21:55.0912 0168        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:21:55.0959 0168        RasSstp - ok
22:21:55.0974 0168        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:21:56.0021 0168        rdbss - ok
22:21:56.0052 0168        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:21:56.0068 0168        rdpbus - ok
22:21:56.0068 0168        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:21:56.0115 0168        RDPCDD - ok
22:21:56.0130 0168        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:21:56.0177 0168        RDPENCDD - ok
22:21:56.0193 0168        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:21:56.0224 0168        RDPREFMP - ok
22:21:56.0271 0168        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:21:56.0302 0168        RDPWD - ok
22:21:56.0349 0168        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:21:56.0380 0168        rdyboost - ok
22:21:56.0427 0168        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:21:56.0489 0168        RemoteAccess - ok
22:21:56.0536 0168        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:21:56.0614 0168        RemoteRegistry - ok
22:21:56.0630 0168        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:21:56.0692 0168        RpcEptMapper - ok
22:21:56.0708 0168        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:21:56.0739 0168        RpcLocator - ok
22:21:56.0801 0168        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:21:56.0879 0168        RpcSs - ok
22:21:56.0895 0168        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:21:56.0942 0168        rspndr - ok
22:21:56.0973 0168        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:21:56.0988 0168        SamSs - ok
22:21:57.0004 0168        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:21:57.0020 0168        sbp2port - ok
22:21:57.0051 0168        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:21:57.0098 0168        SCardSvr - ok
22:21:57.0098 0168        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:21:57.0144 0168        scfilter - ok
22:21:57.0269 0168        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:21:57.0316 0168        Schedule - ok
22:21:57.0363 0168        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:21:57.0425 0168        SCPolicySvc - ok
22:21:57.0472 0168        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:21:57.0503 0168        SDRSVC - ok
22:21:57.0566 0168        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:21:57.0644 0168        secdrv - ok
22:21:57.0659 0168        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:21:57.0722 0168        seclogon - ok
22:21:57.0737 0168        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:21:57.0768 0168        SENS - ok
22:21:57.0784 0168        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:21:57.0800 0168        SensrSvc - ok
22:21:57.0815 0168        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:21:57.0831 0168        Serenum - ok
22:21:57.0846 0168        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:21:57.0862 0168        Serial - ok
22:21:57.0862 0168        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:21:57.0878 0168        sermouse - ok
22:21:57.0909 0168        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:21:57.0956 0168        SessionEnv - ok
22:21:57.0956 0168        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:21:57.0971 0168        sffdisk - ok
22:21:57.0971 0168        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:21:57.0987 0168        sffp_mmc - ok
22:21:58.0002 0168        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:21:58.0018 0168        sffp_sd - ok
22:21:58.0018 0168        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:21:58.0034 0168        sfloppy - ok
22:21:58.0096 0168        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:21:58.0190 0168        SharedAccess - ok
22:21:58.0236 0168        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:21:58.0268 0168        ShellHWDetection - ok
22:21:58.0283 0168        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:21:58.0299 0168        SiSRaid2 - ok
22:21:58.0346 0168        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:21:58.0361 0168        SiSRaid4 - ok
22:21:58.0424 0168        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:21:58.0455 0168        SkypeUpdate - ok
22:21:58.0470 0168        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:21:58.0548 0168        Smb - ok
22:21:58.0595 0168        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:21:58.0611 0168        SNMPTRAP - ok
22:21:58.0642 0168        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:21:58.0658 0168        spldr - ok
22:21:58.0736 0168        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:21:58.0767 0168        Spooler - ok
22:21:59.0063 0168        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:21:59.0126 0168        sppsvc - ok
22:21:59.0235 0168        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:21:59.0313 0168        sppuinotify - ok
22:21:59.0406 0168        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:21:59.0438 0168        srv - ok
22:21:59.0484 0168        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:21:59.0531 0168        srv2 - ok
22:21:59.0547 0168        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:21:59.0578 0168        srvnet - ok
22:21:59.0625 0168        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:21:59.0718 0168        SSDPSRV - ok
22:21:59.0734 0168        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:21:59.0781 0168        SstpSvc - ok
22:21:59.0812 0168        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:21:59.0828 0168        stexstor - ok
22:21:59.0890 0168        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:21:59.0921 0168        stisvc - ok
22:21:59.0937 0168        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:21:59.0952 0168        swenum - ok
22:22:00.0030 0168        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:22:00.0124 0168        swprv - ok
22:22:00.0186 0168        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:22:00.0218 0168        SynTP - ok
22:22:00.0374 0168        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:22:00.0420 0168        SysMain - ok
22:22:00.0530 0168        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:22:00.0576 0168        TabletInputService - ok
22:22:00.0623 0168        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:22:00.0639 0168        taphss - ok
22:22:00.0701 0168        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:22:00.0764 0168        TapiSrv - ok
22:22:00.0779 0168        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:22:00.0826 0168        TBS - ok
22:22:00.0982 0168        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:22:01.0060 0168        Tcpip - ok
22:22:01.0341 0168        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:22:01.0403 0168        TCPIP6 - ok
22:22:01.0512 0168        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:22:01.0575 0168        tcpipreg - ok
22:22:01.0590 0168        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:22:01.0606 0168        TDPIPE - ok
22:22:01.0637 0168        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:22:01.0653 0168        TDTCP - ok
22:22:01.0668 0168        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:22:01.0731 0168        tdx - ok
22:22:02.0012 0168        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:22:02.0074 0168        TeamViewer7 - ok
22:22:02.0230 0168        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:22:02.0246 0168        TermDD - ok
22:22:02.0339 0168        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:22:02.0448 0168        TermService - ok
22:22:02.0464 0168        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:22:02.0511 0168        Themes - ok
22:22:02.0542 0168        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:22:02.0636 0168        THREADORDER - ok
22:22:02.0651 0168        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:22:02.0714 0168        TrkWks - ok
22:22:02.0792 0168        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:22:02.0823 0168        TrustedInstaller - ok
22:22:02.0854 0168        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:22:02.0901 0168        tssecsrv - ok
22:22:02.0932 0168        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:22:02.0994 0168        tunnel - ok
22:22:03.0010 0168        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:22:03.0026 0168        uagp35 - ok
22:22:03.0041 0168        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:22:03.0057 0168        UBHelper - ok
22:22:03.0088 0168        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:22:03.0135 0168        udfs - ok
22:22:03.0166 0168        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:22:03.0182 0168        UI0Detect - ok
22:22:03.0197 0168        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:22:03.0213 0168        uliagpkx - ok
22:22:03.0244 0168        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:22:03.0275 0168        umbus - ok
22:22:03.0275 0168        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:22:03.0306 0168        UmPass - ok
22:22:03.0587 0168        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:22:03.0665 0168        UNS - ok
22:22:03.0743 0168        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:22:03.0774 0168        Updater Service - ok
22:22:03.0930 0168        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:22:04.0024 0168        upnphost - ok
22:22:04.0086 0168        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:22:04.0102 0168        usbccgp - ok
22:22:04.0133 0168        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:22:04.0164 0168        usbcir - ok
22:22:04.0180 0168        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:22:04.0196 0168        usbehci - ok
22:22:04.0242 0168        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:22:04.0274 0168        usbhub - ok
22:22:04.0289 0168        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:22:04.0305 0168        usbohci - ok
22:22:04.0336 0168        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:22:04.0352 0168        usbprint - ok
22:22:04.0383 0168        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:22:04.0398 0168        USBSTOR - ok
22:22:04.0414 0168        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:22:04.0430 0168        usbuhci - ok
22:22:04.0476 0168        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:22:04.0492 0168        usbvideo - ok
22:22:04.0539 0168        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:22:04.0601 0168        UxSms - ok
22:22:04.0617 0168        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:22:04.0632 0168        VaultSvc - ok
22:22:04.0648 0168        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:22:04.0679 0168        vdrvroot - ok
22:22:04.0757 0168        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:22:04.0804 0168        vds - ok
22:22:04.0820 0168        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:22:04.0835 0168        vga - ok
22:22:04.0866 0168        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:22:04.0913 0168        VgaSave - ok
22:22:04.0960 0168        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:22:04.0976 0168        vhdmp - ok
22:22:04.0991 0168        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:22:05.0007 0168        viaide - ok
22:22:05.0007 0168        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:22:05.0038 0168        volmgr - ok
22:22:05.0054 0168        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:22:05.0085 0168        volmgrx - ok
22:22:05.0132 0168        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:22:05.0147 0168        volsnap - ok
22:22:05.0178 0168        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:22:05.0194 0168        vsmraid - ok
22:22:05.0350 0168        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:22:05.0412 0168        VSS - ok
22:22:05.0553 0168        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:22:05.0584 0168        vwifibus - ok
22:22:05.0600 0168        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:22:05.0631 0168        vwififlt - ok
22:22:05.0646 0168        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:22:05.0693 0168        vwifimp - ok
22:22:05.0756 0168        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:22:05.0834 0168        W32Time - ok
22:22:05.0849 0168        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:22:05.0849 0168        WacomPen - ok
22:22:05.0865 0168        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:22:05.0912 0168        WANARP - ok
22:22:05.0912 0168        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:22:05.0958 0168        Wanarpv6 - ok
22:22:06.0099 0168        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:22:06.0146 0168        wbengine - ok
22:22:06.0286 0168        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:22:06.0317 0168        WbioSrvc - ok
22:22:06.0380 0168        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:22:06.0411 0168        wcncsvc - ok
22:22:06.0426 0168        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:22:06.0458 0168        WcsPlugInService - ok
22:22:06.0504 0168        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:22:06.0520 0168        Wd - ok
22:22:06.0582 0168        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:22:06.0629 0168        Wdf01000 - ok
22:22:06.0660 0168        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:22:06.0707 0168        WdiServiceHost - ok
22:22:06.0707 0168        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:22:06.0738 0168        WdiSystemHost - ok
22:22:06.0785 0168        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:22:06.0816 0168        WebClient - ok
22:22:06.0879 0168        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:22:06.0957 0168        Wecsvc - ok
22:22:06.0957 0168        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:22:07.0004 0168        wercplsupport - ok
22:22:07.0019 0168        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:22:07.0066 0168        WerSvc - ok
22:22:07.0144 0168        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:22:07.0222 0168        WfpLwf - ok
22:22:07.0238 0168        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:22:07.0253 0168        WIMMount - ok
22:22:07.0284 0168        WinDefend - ok
22:22:07.0284 0168        WinHttpAutoProxySvc - ok
22:22:07.0347 0168        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:22:07.0425 0168        Winmgmt - ok
22:22:07.0612 0168        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:22:07.0706 0168        WinRM - ok
22:22:07.0893 0168        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:22:07.0955 0168        Wlansvc - ok
22:22:08.0018 0168        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:22:08.0033 0168        WmiAcpi - ok
22:22:08.0111 0168        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:22:08.0142 0168        wmiApSrv - ok
22:22:08.0174 0168        WMPNetworkSvc - ok
22:22:08.0205 0168        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:22:08.0236 0168        WPCSvc - ok
22:22:08.0252 0168        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:22:08.0283 0168        WPDBusEnum - ok
22:22:08.0314 0168        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:22:08.0376 0168        ws2ifsl - ok
22:22:08.0423 0168        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:22:08.0454 0168        wscsvc - ok
22:22:08.0454 0168        WSearch - ok
22:22:08.0673 0168        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:22:08.0766 0168        wuauserv - ok
22:22:08.0907 0168        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:22:08.0985 0168        WudfPf - ok
22:22:09.0000 0168        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:22:09.0063 0168        WUDFRd - ok
22:22:09.0078 0168        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:22:09.0141 0168        wudfsvc - ok
22:22:09.0156 0168        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:22:09.0172 0168        WwanSvc - ok
22:22:09.0203 0168        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:22:09.0546 0168        \Device\Harddisk0\DR0 - ok
22:22:09.0546 0168        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:22:09.0546 0168        \Device\Harddisk0\DR0\Partition0 - ok
22:22:09.0562 0168        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:22:09.0562 0168        \Device\Harddisk0\DR0\Partition1 - ok
22:22:09.0578 0168        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:22:09.0578 0168        \Device\Harddisk0\DR0\Partition2 - ok
22:22:09.0609 0168        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:22:09.0609 0168        \Device\Harddisk0\DR0\Partition3 - ok
22:22:09.0609 0168        ============================================================
22:22:09.0609 0168        Scan finished
22:22:09.0609 0168        ============================================================
22:22:09.0624 3560        Detected object count: 0
22:22:09.0624 3560        Actual detected object count: 0
22:22:19.0109 4768        ============================================================
22:22:19.0109 4768        Scan started
22:22:19.0109 4768        Mode: Manual; SigCheck; TDLFS;
22:22:19.0109 4768        ============================================================
22:22:19.0328 4768        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:22:19.0359 4768        1394ohci - ok
22:22:19.0406 4768        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:22:19.0452 4768        ACPI - ok
22:22:19.0452 4768        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:22:19.0468 4768        AcpiPmi - ok
22:22:19.0624 4768        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:22:19.0640 4768        AdobeActiveFileMonitor8.0 - ok
22:22:19.0780 4768        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:22:19.0796 4768        AdobeFlashPlayerUpdateSvc - ok
22:22:19.0858 4768        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:22:19.0889 4768        adp94xx - ok
22:22:19.0936 4768        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:22:19.0983 4768        adpahci - ok
22:22:20.0014 4768        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:22:20.0030 4768        adpu320 - ok
22:22:20.0076 4768        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:22:20.0154 4768        AeLookupSvc - ok
22:22:20.0217 4768        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:22:20.0248 4768        AFD - ok
22:22:20.0326 4768        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:22:20.0357 4768        agp440 - ok
22:22:20.0388 4768        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:22:20.0420 4768        ALG - ok
22:22:20.0435 4768        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:22:20.0466 4768        aliide - ok
22:22:20.0466 4768        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:22:20.0482 4768        amdide - ok
22:22:20.0513 4768        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:22:20.0529 4768        AmdK8 - ok
22:22:20.0544 4768        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:22:20.0560 4768        AmdPPM - ok
22:22:20.0576 4768        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:22:20.0591 4768        amdsata - ok
22:22:20.0622 4768        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:22:20.0638 4768        amdsbs - ok
22:22:20.0654 4768        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:22:20.0669 4768        amdxata - ok
22:22:20.0700 4768        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:22:20.0700 4768        AmUStor - ok
22:22:20.0778 4768        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:22:20.0810 4768        AntiVirSchedulerService - ok
22:22:20.0841 4768        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:22:20.0856 4768        AntiVirService - ok
22:22:20.0888 4768        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:22:20.0934 4768        AppID - ok
22:22:20.0966 4768        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:22:21.0044 4768        AppIDSvc - ok
22:22:21.0044 4768        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:22:21.0059 4768        Appinfo - ok
22:22:21.0090 4768        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:22:21.0090 4768        arc - ok
22:22:21.0106 4768        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:22:21.0122 4768        arcsas - ok
22:22:21.0122 4768        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:22:21.0168 4768        AsyncMac - ok
22:22:21.0184 4768        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:22:21.0200 4768        atapi - ok
22:22:21.0402 4768        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:22:21.0465 4768        athr - ok
22:22:21.0636 4768        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:22:21.0714 4768        AudioEndpointBuilder - ok
22:22:21.0714 4768        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:22:21.0777 4768        AudioSrv - ok
22:22:21.0824 4768        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:22:21.0839 4768        avgntflt - ok
22:22:21.0855 4768        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:22:21.0870 4768        avipbb - ok
22:22:21.0886 4768        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:22:21.0902 4768        avkmgr - ok
22:22:21.0933 4768        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:22:21.0948 4768        AxInstSV - ok
22:22:22.0026 4768        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:22:22.0058 4768        b06bdrv - ok
22:22:22.0089 4768        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:22:22.0104 4768        b57nd60a - ok
22:22:22.0229 4768        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:22:22.0292 4768        BCM43XX - ok
22:22:22.0307 4768        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:22:22.0323 4768        BDESVC - ok
22:22:22.0354 4768        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:22:22.0401 4768        Beep - ok
22:22:22.0463 4768        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:22:22.0541 4768        BFE - ok
22:22:22.0635 4768        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:22:22.0713 4768        BITS - ok
22:22:22.0744 4768        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:22:22.0775 4768        blbdrive - ok
22:22:22.0822 4768        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:22:22.0838 4768        bowser - ok
22:22:22.0869 4768        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:22:22.0885 4768        BrFiltLo - ok
22:22:22.0885 4768        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:22:22.0916 4768        BrFiltUp - ok
22:22:22.0963 4768        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:22:23.0025 4768        Browser - ok
22:22:23.0041 4768        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:22:23.0056 4768        Brserid - ok
22:22:23.0056 4768        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:22:23.0087 4768        BrSerWdm - ok
22:22:23.0087 4768        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:22:23.0103 4768        BrUsbMdm - ok
22:22:23.0103 4768        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:22:23.0119 4768        BrUsbSer - ok
22:22:23.0134 4768        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:22:23.0150 4768        BTHMODEM - ok
22:22:23.0150 4768        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:22:23.0197 4768        bthserv - ok
22:22:23.0228 4768        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:22:23.0275 4768        cdfs - ok
22:22:23.0290 4768        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:22:23.0306 4768        cdrom - ok
22:22:23.0321 4768        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:22:23.0368 4768        CertPropSvc - ok
22:22:23.0384 4768        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:22:23.0399 4768        circlass - ok
22:22:23.0446 4768        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:22:23.0477 4768        CLFS - ok
22:22:23.0540 4768        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:22:23.0571 4768        clr_optimization_v2.0.50727_32 - ok
22:22:23.0602 4768        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:22:23.0618 4768        clr_optimization_v2.0.50727_64 - ok
22:22:23.0633 4768        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:22:23.0665 4768        CmBatt - ok
22:22:23.0696 4768        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:22:23.0727 4768        cmdide - ok
22:22:23.0789 4768        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:22:23.0836 4768        CNG - ok
22:22:23.0852 4768        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:22:23.0867 4768        Compbatt - ok
22:22:23.0867 4768        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:22:23.0899 4768        CompositeBus - ok
22:22:23.0899 4768        COMSysApp - ok
22:22:23.0914 4768        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:22:23.0914 4768        crcdisk - ok
22:22:23.0977 4768        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:22:23.0992 4768        CryptSvc - ok
22:22:24.0070 4768        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:22:24.0148 4768        DcomLaunch - ok
22:22:24.0195 4768        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:22:24.0257 4768        defragsvc - ok
22:22:24.0289 4768        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:22:24.0304 4768        DfsC - ok
22:22:24.0351 4768        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:22:24.0382 4768        Dhcp - ok
22:22:24.0413 4768        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:22:24.0476 4768        discache - ok
22:22:24.0491 4768        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:22:24.0507 4768        Disk - ok
22:22:24.0554 4768        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:22:24.0569 4768        Dnscache - ok
22:22:24.0616 4768        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:22:24.0710 4768        dot3svc - ok
22:22:24.0725 4768        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:22:24.0803 4768        DPS - ok
22:22:24.0835 4768        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:22:24.0850 4768        drmkaud - ok
22:22:24.0959 4768        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:22:24.0991 4768        DsiWMIService - ok
22:22:25.0100 4768        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:22:25.0162 4768        DXGKrnl - ok
22:22:25.0209 4768        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:22:25.0287 4768        EapHost - ok
22:22:25.0537 4768        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:22:25.0599 4768        ebdrv - ok
22:22:25.0724 4768        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:22:25.0755 4768        EFS - ok
22:22:25.0864 4768        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:22:25.0911 4768        ehRecvr - ok
22:22:25.0942 4768        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:22:25.0958 4768        ehSched - ok
22:22:26.0067 4768        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:22:26.0098 4768        elxstor - ok
22:22:26.0317 4768        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:22:26.0363 4768        ePowerSvc - ok
22:22:26.0504 4768        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:22:26.0519 4768        ErrDev - ok
22:22:26.0582 4768        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:22:26.0644 4768        EventSystem - ok
22:22:26.0660 4768        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:22:26.0707 4768        exfat - ok
22:22:26.0738 4768        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:22:26.0785 4768        fastfat - ok
22:22:26.0847 4768        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:22:26.0878 4768        Fax - ok
22:22:26.0878 4768        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:22:26.0909 4768        fdc - ok
22:22:26.0909 4768        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:22:26.0972 4768        fdPHost - ok
22:22:26.0972 4768        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:22:27.0019 4768        FDResPub - ok
22:22:27.0034 4768        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:22:27.0050 4768        FileInfo - ok
22:22:27.0050 4768        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:22:27.0097 4768        Filetrace - ok
22:22:27.0206 4768        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:22:27.0237 4768        FLEXnet Licensing Service - ok
22:22:27.0268 4768        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:22:27.0284 4768        flpydisk - ok
22:22:27.0299 4768        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:22:27.0315 4768        FltMgr - ok
22:22:27.0440 4768        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:22:27.0518 4768        FontCache - ok
22:22:27.0580 4768        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:22:27.0596 4768        FontCache3.0.0.0 - ok
22:22:27.0643 4768        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:22:27.0658 4768        FsDepends - ok
22:22:27.0689 4768        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:22:27.0705 4768        Fs_Rec - ok
22:22:27.0752 4768        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:22:27.0799 4768        fvevol - ok
22:22:27.0814 4768        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:22:27.0830 4768        gagp30kx - ok
22:22:27.0939 4768        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:22:27.0955 4768        GameConsoleService - ok
22:22:28.0064 4768        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:22:28.0111 4768        gpsvc - ok
22:22:28.0142 4768        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:22:28.0204 4768        GREGService - ok
22:22:28.0235 4768        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:22:28.0251 4768        hcw85cir - ok
22:22:28.0298 4768        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:22:28.0345 4768        HdAudAddService - ok
22:22:28.0360 4768        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:22:28.0391 4768        HDAudBus - ok
22:22:28.0423 4768        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:22:28.0423 4768        HECIx64 - ok
22:22:28.0454 4768        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:22:28.0485 4768        HidBatt - ok
22:22:28.0501 4768        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:22:28.0532 4768        HidBth - ok
22:22:28.0532 4768        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:22:28.0563 4768        HidIr - ok
22:22:28.0594 4768        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:22:28.0641 4768        hidserv - ok
22:22:28.0657 4768        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:22:28.0672 4768        HidUsb - ok
22:22:28.0688 4768        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:22:28.0735 4768        hkmsvc - ok
22:22:28.0766 4768        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:22:28.0781 4768        HomeGroupListener - ok
22:22:28.0828 4768        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:22:28.0859 4768        HomeGroupProvider - ok
22:22:28.0891 4768        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:22:28.0922 4768        HpSAMD - ok
22:22:29.0031 4768        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:22:29.0078 4768        hshld - ok
22:22:29.0093 4768        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:22:29.0109 4768        HssDrv - ok
22:22:29.0156 4768        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:22:29.0187 4768        HssSrv - ok
22:22:29.0218 4768        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:22:29.0234 4768        HssTrayService - ok
22:22:29.0234 4768        HssWd - ok
22:22:29.0312 4768        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:22:29.0390 4768        HTTP - ok
22:22:29.0421 4768        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:22:29.0437 4768        hwpolicy - ok
22:22:29.0452 4768        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:22:29.0468 4768        i8042prt - ok
22:22:29.0530 4768        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:22:29.0577 4768        iaStor - ok
22:22:29.0608 4768        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:22:29.0655 4768        iaStorV - ok
22:22:29.0795 4768        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:22:29.0842 4768        idsvc - ok
22:22:30.0560 4768        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:22:30.0700 4768        igfx - ok
22:22:30.0841 4768        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:22:30.0872 4768        iirsp - ok
22:22:30.0965 4768        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:22:31.0043 4768        IKEEXT - ok
22:22:31.0075 4768        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:22:31.0090 4768        Impcd - ok
22:22:31.0293 4768        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:22:31.0355 4768        IntcAzAudAddService - ok
22:22:31.0511 4768        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:22:31.0543 4768        IntcDAud - ok
22:22:31.0589 4768        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:22:31.0621 4768        intelide - ok
22:22:31.0636 4768        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:22:31.0652 4768        intelppm - ok
22:22:31.0683 4768        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:22:31.0761 4768        IPBusEnum - ok
22:22:31.0792 4768        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:22:31.0855 4768        IpFilterDriver - ok
22:22:31.0901 4768        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:22:31.0964 4768        iphlpsvc - ok
22:22:31.0964 4768        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:22:31.0979 4768        IPMIDRV - ok
22:22:31.0995 4768        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:22:32.0026 4768        IPNAT - ok
22:22:32.0042 4768        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:22:32.0057 4768        IRENUM - ok
22:22:32.0073 4768        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:22:32.0089 4768        isapnp - ok
22:22:32.0120 4768        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:22:32.0135 4768        iScsiPrt - ok
22:22:32.0182 4768        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:22:32.0213 4768        k57nd60a - ok
22:22:32.0229 4768        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:22:32.0245 4768        kbdclass - ok
22:22:32.0260 4768        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:22:32.0291 4768        kbdhid - ok
22:22:32.0307 4768        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:22:32.0338 4768        KeyIso - ok
22:22:32.0369 4768        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:22:32.0385 4768        KSecDD - ok
22:22:32.0416 4768        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:22:32.0447 4768        KSecPkg - ok
22:22:32.0447 4768        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:22:32.0541 4768        ksthunk - ok
22:22:32.0588 4768        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:22:32.0650 4768        KtmRm - ok
22:22:32.0666 4768        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:22:32.0681 4768        L1E - ok
22:22:32.0728 4768        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:22:32.0759 4768        LanmanServer - ok
22:22:32.0806 4768        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:22:32.0884 4768        LanmanWorkstation - ok
22:22:32.0900 4768        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:22:32.0962 4768        lltdio - ok
22:22:33.0009 4768        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:22:33.0071 4768        lltdsvc - ok
22:22:33.0103 4768        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:22:33.0134 4768        lmhosts - ok
22:22:33.0259 4768        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:22:33.0290 4768        LMS - ok
22:22:33.0337 4768        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:22:33.0352 4768        LSI_FC - ok
22:22:33.0383 4768        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:22:33.0415 4768        LSI_SAS - ok
22:22:33.0430 4768        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:22:33.0461 4768        LSI_SAS2 - ok
22:22:33.0477 4768        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:22:33.0508 4768        LSI_SCSI - ok
22:22:33.0539 4768        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:22:33.0602 4768        luafv - ok
22:22:33.0633 4768        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:22:33.0633 4768        MBAMProtector - ok
22:22:33.0711 4768        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:22:33.0758 4768        MBAMService - ok
22:22:33.0805 4768        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:22:33.0820 4768        Mcx2Svc - ok
22:22:33.0851 4768        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:22:33.0867 4768        megasas - ok
22:22:33.0914 4768        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:22:33.0945 4768        MegaSR - ok
22:22:33.0976 4768        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:22:34.0023 4768        MMCSS - ok
22:22:34.0039 4768        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:22:34.0085 4768        Modem - ok
22:22:34.0101 4768        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:22:34.0117 4768        monitor - ok
22:22:34.0117 4768        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:22:34.0132 4768        mouclass - ok
22:22:34.0148 4768        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:22:34.0148 4768        mouhid - ok
22:22:34.0163 4768        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:22:34.0179 4768        mountmgr - ok
22:22:34.0257 4768        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:22:34.0273 4768        MozillaMaintenance - ok
22:22:34.0304 4768        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:22:34.0335 4768        mpio - ok
22:22:34.0351 4768        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:22:34.0413 4768        mpsdrv - ok
22:22:34.0491 4768        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:22:34.0569 4768        MpsSvc - ok
22:22:34.0585 4768        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:22:34.0616 4768        MRxDAV - ok
22:22:34.0647 4768        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:22:34.0678 4768        mrxsmb - ok
22:22:34.0709 4768        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:22:34.0741 4768        mrxsmb10 - ok
22:22:34.0772 4768        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:22:34.0787 4768        mrxsmb20 - ok
22:22:34.0819 4768        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:22:34.0834 4768        msahci - ok
22:22:34.0865 4768        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:22:34.0897 4768        msdsm - ok
22:22:34.0943 4768        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:22:34.0975 4768        MSDTC - ok
22:22:34.0990 4768        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:22:35.0068 4768        Msfs - ok
22:22:35.0084 4768        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:22:35.0115 4768        mshidkmdf - ok
22:22:35.0131 4768        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:22:35.0131 4768        msisadrv - ok
22:22:35.0162 4768        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:22:35.0240 4768        MSiSCSI - ok
22:22:35.0240 4768        msiserver - ok
22:22:35.0255 4768        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:22:35.0302 4768        MSKSSRV - ok
22:22:35.0302 4768        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:22:35.0349 4768        MSPCLOCK - ok
22:22:35.0349 4768        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:22:35.0396 4768        MSPQM - ok
22:22:35.0427 4768        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:22:35.0443 4768        MsRPC - ok
22:22:35.0443 4768        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:22:35.0458 4768        mssmbios - ok
22:22:35.0474 4768        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:22:35.0505 4768        MSTEE - ok
22:22:35.0521 4768        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:22:35.0536 4768        MTConfig - ok
22:22:35.0552 4768        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:22:35.0552 4768        Mup - ok
22:22:35.0630 4768        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:22:35.0692 4768        napagent - ok
22:22:35.0723 4768        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:22:35.0755 4768        NativeWifiP - ok
22:22:35.0833 4768        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:22:35.0879 4768        NDIS - ok
22:22:35.0895 4768        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:22:35.0942 4768        NdisCap - ok
22:22:35.0957 4768        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:22:36.0004 4768        NdisTapi - ok
22:22:36.0004 4768        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:22:36.0051 4768        Ndisuio - ok
22:22:36.0067 4768        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:22:36.0113 4768        NdisWan - ok
22:22:36.0113 4768        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:22:36.0160 4768        NDProxy - ok
22:22:36.0332 4768        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:22:36.0394 4768        Nero BackItUp Scheduler 4.0 - ok
22:22:36.0425 4768        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:22:36.0503 4768        NetBIOS - ok
22:22:36.0550 4768        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:22:36.0597 4768        NetBT - ok
22:22:36.0628 4768        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:22:36.0628 4768        Netlogon - ok
22:22:36.0691 4768        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:22:36.0769 4768        Netman - ok
22:22:36.0815 4768        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:22:36.0878 4768        netprofm - ok
22:22:36.0940 4768        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:22:36.0971 4768        NetTcpPortSharing - ok
22:22:37.0003 4768        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:22:37.0018 4768        nfrd960 - ok
22:22:37.0081 4768        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:22:37.0143 4768        NlaSvc - ok
22:22:37.0159 4768        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:22:37.0205 4768        Npfs - ok
22:22:37.0221 4768        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:22:37.0268 4768        nsi - ok
22:22:37.0268 4768        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:22:37.0315 4768        nsiproxy - ok
22:22:37.0455 4768        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:22:37.0517 4768        Ntfs - ok
22:22:37.0627 4768        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:22:37.0642 4768        NTI IScheduleSvc - ok
22:22:37.0767 4768        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:22:37.0783 4768        NTIDrvr - ok
22:22:37.0814 4768        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:22:37.0892 4768        Null - ok
22:22:37.0923 4768        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:22:37.0939 4768        nvraid - ok
22:22:37.0970 4768        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:22:37.0985 4768        nvstor - ok
22:22:38.0017 4768        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:22:38.0032 4768        nv_agp - ok
22:22:38.0032 4768        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:22:38.0063 4768        ohci1394 - ok
22:22:38.0110 4768        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:22:38.0141 4768        p2pimsvc - ok
22:22:38.0188 4768        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:22:38.0219 4768        p2psvc - ok
22:22:38.0219 4768        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:22:38.0251 4768        Parport - ok
22:22:38.0266 4768        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:22:38.0297 4768        partmgr - ok
22:22:38.0313 4768        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:22:38.0329 4768        PcaSvc - ok
22:22:38.0360 4768        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:22:38.0375 4768        pci - ok
22:22:38.0407 4768        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:22:38.0422 4768        pciide - ok
22:22:38.0453 4768        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:22:38.0469 4768        pcmcia - ok
22:22:38.0485 4768        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:22:38.0500 4768        pcw - ok
22:22:38.0531 4768        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:22:38.0594 4768        PEAUTH - ok
22:22:38.0687 4768        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:22:38.0719 4768        PerfHost - ok
22:22:38.0859 4768        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:22:38.0953 4768        pla - ok
22:22:38.0999 4768        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:22:39.0031 4768        PlugPlay - ok
22:22:39.0046 4768        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:22:39.0062 4768        PNRPAutoReg - ok
22:22:39.0093 4768        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:22:39.0109 4768        PNRPsvc - ok
22:22:39.0187 4768        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:22:39.0265 4768        PolicyAgent - ok
22:22:39.0296 4768        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:22:39.0343 4768        Power - ok
22:22:39.0405 4768        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:22:39.0499 4768        PptpMiniport - ok
22:22:39.0530 4768        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:22:39.0545 4768        Processor - ok
22:22:39.0592 4768        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:22:39.0608 4768        ProfSvc - ok
22:22:39.0639 4768        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:22:39.0670 4768        ProtectedStorage - ok
22:22:39.0717 4768        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:22:39.0779 4768        Psched - ok
22:22:39.0795 4768        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:22:39.0811 4768        PxHlpa64 - ok
22:22:39.0935 4768        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:22:39.0998 4768        ql2300 - ok
22:22:40.0154 4768        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:22:40.0185 4768        ql40xx - ok
22:22:40.0232 4768        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:22:40.0263 4768        QWAVE - ok
22:22:40.0294 4768        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:22:40.0325 4768        QWAVEdrv - ok
22:22:40.0341 4768        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:22:40.0388 4768        RasAcd - ok
22:22:40.0419 4768        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:22:40.0466 4768        RasAgileVpn - ok
22:22:40.0497 4768        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:22:40.0544 4768        RasAuto - ok
22:22:40.0559 4768        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:22:40.0606 4768        Rasl2tp - ok
22:22:40.0637 4768        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:22:40.0684 4768        RasMan - ok
22:22:40.0700 4768        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:22:40.0747 4768        RasPppoe - ok
22:22:40.0747 4768        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:22:40.0793 4768        RasSstp - ok
22:22:40.0825 4768        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:22:40.0871 4768        rdbss - ok
22:22:40.0887 4768        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:22:40.0903 4768        rdpbus - ok
22:22:40.0918 4768        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:22:40.0965 4768        RDPCDD - ok
22:22:40.0965 4768        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:22:41.0012 4768        RDPENCDD - ok
22:22:41.0012 4768        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:22:41.0059 4768        RDPREFMP - ok
22:22:41.0105 4768        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:22:41.0121 4768        RDPWD - ok
22:22:41.0168 4768        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:22:41.0199 4768        rdyboost - ok
22:22:41.0230 4768        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:22:41.0308 4768        RemoteAccess - ok
22:22:41.0355 4768        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:22:41.0433 4768        RemoteRegistry - ok
22:22:41.0449 4768        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:22:41.0495 4768        RpcEptMapper - ok
22:22:41.0527 4768        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:22:41.0542 4768        RpcLocator - ok
22:22:41.0589 4768        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:22:41.0651 4768        RpcSs - ok
22:22:41.0683 4768        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:22:41.0745 4768        rspndr - ok
22:22:41.0776 4768        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:22:41.0807 4768        SamSs - ok
22:22:41.0839 4768        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:22:41.0854 4768        sbp2port - ok
22:22:41.0901 4768        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:22:41.0963 4768        SCardSvr - ok
22:22:41.0979 4768        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:22:42.0010 4768        scfilter - ok
22:22:42.0135 4768        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:22:42.0182 4768        Schedule - ok
22:22:42.0213 4768        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:22:42.0275 4768        SCPolicySvc - ok
22:22:42.0322 4768        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:22:42.0353 4768        SDRSVC - ok
22:22:42.0416 4768        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:22:42.0494 4768        secdrv - ok
22:22:42.0509 4768        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:22:42.0556 4768        seclogon - ok
22:22:42.0572 4768        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:22:42.0619 4768        SENS - ok
22:22:42.0619 4768        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:22:42.0634 4768        SensrSvc - ok
22:22:42.0650 4768        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:22:42.0650 4768        Serenum - ok
22:22:42.0681 4768        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:22:42.0697 4768        Serial - ok
22:22:42.0697 4768        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:22:42.0712 4768        sermouse - ok
22:22:42.0728 4768        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:22:42.0775 4768        SessionEnv - ok
22:22:42.0775 4768        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:22:42.0790 4768        sffdisk - ok
22:22:42.0790 4768        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:22:42.0806 4768        sffp_mmc - ok
22:22:42.0821 4768        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:22:42.0837 4768        sffp_sd - ok
22:22:42.0837 4768        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:22:42.0853 4768        sfloppy - ok
22:22:42.0915 4768        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:22:42.0993 4768        SharedAccess - ok
22:22:43.0040 4768        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:22:43.0102 4768        ShellHWDetection - ok
22:22:43.0102 4768        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:22:43.0118 4768        SiSRaid2 - ok
22:22:43.0149 4768        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:22:43.0165 4768        SiSRaid4 - ok
22:22:43.0227 4768        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:22:43.0243 4768        SkypeUpdate - ok
22:22:43.0274 4768        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:22:43.0336 4768        Smb - ok
22:22:43.0352 4768        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:22:43.0367 4768        SNMPTRAP - ok
22:22:43.0399 4768        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:22:43.0414 4768        spldr - ok
22:22:43.0477 4768        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:22:43.0523 4768        Spooler - ok
22:22:43.0789 4768        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:22:43.0867 4768        sppsvc - ok
22:22:43.0991 4768        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:22:44.0054 4768        sppuinotify - ok
22:22:44.0147 4768        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:22:44.0179 4768        srv - ok
22:22:44.0225 4768        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:22:44.0241 4768        srv2 - ok
22:22:44.0272 4768        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:22:44.0288 4768        srvnet - ok
22:22:44.0335 4768        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:22:44.0413 4768        SSDPSRV - ok
22:22:44.0428 4768        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:22:44.0475 4768        SstpSvc - ok
22:22:44.0506 4768        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:22:44.0522 4768        stexstor - ok
22:22:44.0600 4768        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:22:44.0647 4768        stisvc - ok
22:22:44.0662 4768        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:22:44.0678 4768        swenum - ok
22:22:44.0740 4768        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:22:44.0803 4768        swprv - ok
22:22:44.0865 4768        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:22:44.0896 4768        SynTP - ok
22:22:45.0083 4768        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:22:45.0146 4768        SysMain - ok
22:22:45.0271 4768        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:22:45.0302 4768        TabletInputService - ok
22:22:45.0364 4768        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:22:45.0380 4768        taphss - ok
22:22:45.0427 4768        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:22:45.0489 4768        TapiSrv - ok
22:22:45.0505 4768        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:22:45.0551 4768        TBS - ok
22:22:45.0707 4768        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:22:45.0770 4768        Tcpip - ok
22:22:46.0066 4768        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:22:46.0129 4768        TCPIP6 - ok
22:22:46.0238 4768        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:22:46.0300 4768        tcpipreg - ok
22:22:46.0316 4768        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:22:46.0331 4768        TDPIPE - ok
22:22:46.0363 4768        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:22:46.0394 4768        TDTCP - ok
22:22:46.0394 4768        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:22:46.0456 4768        tdx - ok
22:22:46.0721 4768        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:22:46.0799 4768        TeamViewer7 - ok
22:22:46.0955 4768        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:22:46.0987 4768        TermDD - ok
22:22:47.0080 4768        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:22:47.0158 4768        TermService - ok
22:22:47.0174 4768        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:22:47.0189 4768        Themes - ok
22:22:47.0221 4768        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:22:47.0267 4768        THREADORDER - ok
22:22:47.0299 4768        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:22:47.0345 4768        TrkWks - ok
22:22:47.0408 4768        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:22:47.0439 4768        TrustedInstaller - ok
22:22:47.0470 4768        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:22:47.0517 4768        tssecsrv - ok
22:22:47.0548 4768        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:22:47.0595 4768        tunnel - ok
22:22:47.0626 4768        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:22:47.0626 4768        uagp35 - ok
22:22:47.0657 4768        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:22:47.0673 4768        UBHelper - ok
22:22:47.0689 4768        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:22:47.0751 4768        udfs - ok
22:22:47.0782 4768        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:22:47.0798 4768        UI0Detect - ok
22:22:47.0798 4768        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:22:47.0813 4768        uliagpkx - ok
22:22:47.0845 4768        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:22:47.0860 4768        umbus - ok
22:22:47.0860 4768        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:22:47.0876 4768        UmPass - ok
22:22:48.0172 4768        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:22:48.0235 4768        UNS - ok
22:22:48.0328 4768        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:22:48.0344 4768        Updater Service - ok
22:22:48.0484 4768        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:22:48.0562 4768        upnphost - ok
22:22:48.0609 4768        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:22:48.0625 4768        usbccgp - ok
22:22:48.0640 4768        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:22:48.0656 4768        usbcir - ok
22:22:48.0671 4768        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:22:48.0687 4768        usbehci - ok
22:22:48.0734 4768        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:22:48.0765 4768        usbhub - ok
22:22:48.0781 4768        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:22:48.0796 4768        usbohci - ok
22:22:48.0827 4768        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:22:48.0843 4768        usbprint - ok
22:22:48.0859 4768        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:22:48.0874 4768        USBSTOR - ok
22:22:48.0905 4768        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:22:48.0921 4768        usbuhci - ok
22:22:48.0968 4768        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:22:48.0983 4768        usbvideo - ok
22:22:49.0015 4768        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:22:49.0077 4768        UxSms - ok
22:22:49.0108 4768        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:22:49.0124 4768        VaultSvc - ok
22:22:49.0139 4768        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:22:49.0155 4768        vdrvroot - ok
22:22:49.0217 4768        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:22:49.0249 4768        vds - ok
22:22:49.0264 4768        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:22:49.0280 4768        vga - ok
22:22:49.0295 4768        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:22:49.0358 4768        VgaSave - ok
22:22:49.0389 4768        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:22:49.0405 4768        vhdmp - ok
22:22:49.0420 4768        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:22:49.0436 4768        viaide - ok
22:22:49.0436 4768        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:22:49.0451 4768        volmgr - ok
22:22:49.0483 4768        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:22:49.0498 4768        volmgrx - ok
22:22:49.0529 4768        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:22:49.0545 4768        volsnap - ok
22:22:49.0592 4768        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:22:49.0607 4768        vsmraid - ok
22:22:49.0748 4768        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:22:49.0810 4768        VSS - ok
22:22:49.0951 4768        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:22:49.0982 4768        vwifibus - ok
22:22:49.0997 4768        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:22:50.0013 4768        vwififlt - ok
22:22:50.0044 4768        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:22:50.0060 4768        vwifimp - ok
22:22:50.0122 4768        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:22:50.0200 4768        W32Time - ok
22:22:50.0200 4768        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:22:50.0216 4768        WacomPen - ok
22:22:50.0231 4768        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:22:50.0278 4768        WANARP - ok
22:22:50.0278 4768        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:22:50.0325 4768        Wanarpv6 - ok
22:22:50.0450 4768        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:22:50.0497 4768        wbengine - ok
22:22:50.0621 4768        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:22:50.0668 4768        WbioSrvc - ok
22:22:50.0731 4768        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:22:50.0762 4768        wcncsvc - ok
22:22:50.0777 4768        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:22:50.0793 4768        WcsPlugInService - ok
22:22:50.0840 4768        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:22:50.0871 4768        Wd - ok
22:22:50.0933 4768        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:22:50.0965 4768        Wdf01000 - ok
22:22:50.0996 4768        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:22:51.0027 4768        WdiServiceHost - ok
22:22:51.0027 4768        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:22:51.0058 4768        WdiSystemHost - ok
22:22:51.0105 4768        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:22:51.0136 4768        WebClient - ok
22:22:51.0183 4768        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:22:51.0245 4768        Wecsvc - ok
22:22:51.0261 4768        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:22:51.0308 4768        wercplsupport - ok
22:22:51.0323 4768        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:22:51.0370 4768        WerSvc - ok
22:22:51.0417 4768        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:22:51.0495 4768        WfpLwf - ok
22:22:51.0511 4768        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:22:51.0526 4768        WIMMount - ok
22:22:51.0542 4768        WinDefend - ok
22:22:51.0542 4768        WinHttpAutoProxySvc - ok
22:22:51.0620 4768        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:22:51.0698 4768        Winmgmt - ok
22:22:51.0869 4768        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:22:51.0963 4768        WinRM - ok
22:22:52.0181 4768        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:22:52.0228 4768        Wlansvc - ok
22:22:52.0259 4768        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:22:52.0275 4768        WmiAcpi - ok
22:22:52.0337 4768        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:22:52.0369 4768        wmiApSrv - ok
22:22:52.0384 4768        WMPNetworkSvc - ok
22:22:52.0431 4768        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:22:52.0447 4768        WPCSvc - ok
22:22:52.0509 4768        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:22:52.0540 4768        WPDBusEnum - ok
22:22:52.0571 4768        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:22:52.0634 4768        ws2ifsl - ok
22:22:52.0665 4768        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:22:52.0681 4768        wscsvc - ok
22:22:52.0681 4768        WSearch - ok
22:22:52.0930 4768        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:22:53.0008 4768        wuauserv - ok
22:22:53.0164 4768        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:22:53.0227 4768        WudfPf - ok
22:22:53.0273 4768        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:22:53.0336 4768        WUDFRd - ok
22:22:53.0367 4768        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:22:53.0429 4768        wudfsvc - ok
22:22:53.0445 4768        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:22:53.0461 4768        WwanSvc - ok
22:22:53.0492 4768        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:22:53.0913 4768        \Device\Harddisk0\DR0 - ok
22:22:53.0913 4768        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:22:53.0913 4768        \Device\Harddisk0\DR0\Partition0 - ok
22:22:53.0944 4768        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:22:53.0944 4768        \Device\Harddisk0\DR0\Partition1 - ok
22:22:53.0975 4768        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:22:53.0975 4768        \Device\Harddisk0\DR0\Partition2 - ok
22:22:53.0991 4768        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:22:54.0007 4768        \Device\Harddisk0\DR0\Partition3 - ok
22:22:54.0007 4768        ============================================================
22:22:54.0007 4768        Scan finished
22:22:54.0007 4768        ============================================================
22:22:54.0007 2772        Detected object count: 0
22:22:54.0007 2772        Actual detected object count: 0
22:22:59.0045 3920        Deinitialize success


derhunne 15.06.2012 21:49

sorry war nicht absicht ...hier der richtige ...:headbang:

Code:

22:45:19.0276 0328        TDSS rootkit removing tool 2.7.40.0 Jun 15 2012 15:13:31
22:45:19.0487 0328        ============================================================
22:45:19.0487 0328        Current date / time: 2012/06/15 22:45:19.0487
22:45:19.0487 0328        SystemInfo:
22:45:19.0487 0328       
22:45:19.0488 0328        OS Version: 6.1.7600 ServicePack: 0.0
22:45:19.0488 0328        Product type: Workstation
22:45:19.0488 0328        ComputerName: ATI-PC
22:45:19.0488 0328        UserName: Ati
22:45:19.0488 0328        Windows directory: C:\Windows
22:45:19.0488 0328        System windows directory: C:\Windows
22:45:19.0488 0328        Running under WOW64
22:45:19.0488 0328        Processor architecture: Intel x64
22:45:19.0488 0328        Number of processors: 2
22:45:19.0488 0328        Page size: 0x1000
22:45:19.0488 0328        Boot type: Normal boot
22:45:19.0488 0328        ============================================================
22:45:20.0240 0328        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:45:20.0248 0328        ============================================================
22:45:20.0248 0328        \Device\Harddisk0\DR0:
22:45:20.0249 0328        MBR partitions:
22:45:20.0249 0328        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1964800, BlocksNum 0x32000
22:45:20.0249 0328        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1996800, BlocksNum 0x7DBB998
22:45:20.0264 0328        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x10C83000, BlocksNum 0x14406000
22:45:20.0287 0328        \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x25089800, BlocksNum 0x152FC000
22:45:20.0287 0328        ============================================================
22:45:20.0332 0328        C: <-> \Device\Harddisk0\DR0\Partition1
22:45:20.0361 0328        E: <-> \Device\Harddisk0\DR0\Partition2
22:45:20.0396 0328        D: <-> \Device\Harddisk0\DR0\Partition3
22:45:20.0397 0328        ============================================================
22:45:20.0397 0328        Initialize success
22:45:20.0397 0328        ============================================================
22:45:26.0510 4084        ============================================================
22:45:26.0510 4084        Scan started
22:45:26.0510 4084        Mode: Manual; SigCheck; TDLFS;
22:45:26.0510 4084        ============================================================
22:45:26.0925 4084        1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:45:27.0036 4084        1394ohci - ok
22:45:27.0095 4084        ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:45:27.0134 4084        ACPI - ok
22:45:27.0147 4084        AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:45:27.0167 4084        AcpiPmi - ok
22:45:27.0302 4084        AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
22:45:27.0329 4084        AdobeActiveFileMonitor8.0 - ok
22:45:27.0503 4084        AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:45:27.0531 4084        AdobeFlashPlayerUpdateSvc - ok
22:45:27.0628 4084        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:45:27.0671 4084        adp94xx - ok
22:45:27.0746 4084        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:45:27.0784 4084        adpahci - ok
22:45:27.0836 4084        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:45:27.0868 4084        adpu320 - ok
22:45:27.0909 4084        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:45:27.0989 4084        AeLookupSvc - ok
22:45:28.0058 4084        AFD            (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
22:45:28.0097 4084        AFD - ok
22:45:28.0150 4084        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:45:28.0176 4084        agp440 - ok
22:45:28.0211 4084        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:45:28.0242 4084        ALG - ok
22:45:28.0286 4084        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:45:28.0311 4084        aliide - ok
22:45:28.0355 4084        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:45:28.0379 4084        amdide - ok
22:45:28.0409 4084        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:45:28.0436 4084        AmdK8 - ok
22:45:28.0445 4084        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:45:28.0471 4084        AmdPPM - ok
22:45:28.0515 4084        amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:45:28.0546 4084        amdsata - ok
22:45:28.0597 4084        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:45:28.0629 4084        amdsbs - ok
22:45:28.0650 4084        amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:45:28.0667 4084        amdxata - ok
22:45:28.0725 4084        AmUStor        (391887990cdaa83de5c56c3fde966da1) C:\Windows\system32\drivers\AmUStor.SYS
22:45:28.0748 4084        AmUStor - ok
22:45:28.0847 4084        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:45:28.0870 4084        AntiVirSchedulerService - ok
22:45:28.0906 4084        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:45:28.0928 4084        AntiVirService - ok
22:45:28.0985 4084        AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:45:29.0026 4084        AppID - ok
22:45:29.0062 4084        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:45:29.0116 4084        AppIDSvc - ok
22:45:29.0135 4084        Appinfo        (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:45:29.0150 4084        Appinfo - ok
22:45:29.0178 4084        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:45:29.0192 4084        arc - ok
22:45:29.0217 4084        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:45:29.0231 4084        arcsas - ok
22:45:29.0254 4084        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:45:29.0305 4084        AsyncMac - ok
22:45:29.0330 4084        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:45:29.0345 4084        atapi - ok
22:45:29.0559 4084        athr            (e642491f64e58cd5bc8fb8b347dcf65f) C:\Windows\system32\DRIVERS\athrx.sys
22:45:29.0661 4084        athr - ok
22:45:29.0821 4084        AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:45:29.0905 4084        AudioEndpointBuilder - ok
22:45:29.0913 4084        AudioSrv        (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:45:29.0968 4084        AudioSrv - ok
22:45:30.0011 4084        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:45:30.0112 4084        avgntflt - ok
22:45:30.0143 4084        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:45:30.0165 4084        avipbb - ok
22:45:30.0179 4084        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:45:30.0197 4084        avkmgr - ok
22:45:30.0246 4084        AxInstSV        (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:45:30.0282 4084        AxInstSV - ok
22:45:30.0367 4084        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:45:30.0403 4084        b06bdrv - ok
22:45:30.0437 4084        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:45:30.0469 4084        b57nd60a - ok
22:45:30.0614 4084        BCM43XX        (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
22:45:30.0668 4084        BCM43XX - ok
22:45:30.0699 4084        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:45:30.0724 4084        BDESVC - ok
22:45:30.0837 4084        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:45:30.0921 4084        Beep - ok
22:45:31.0028 4084        BFE            (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:45:31.0136 4084        BFE - ok
22:45:31.0246 4084        BITS            (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:45:31.0325 4084        BITS - ok
22:45:31.0391 4084        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:45:31.0417 4084        blbdrive - ok
22:45:31.0465 4084        bowser          (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:45:31.0492 4084        bowser - ok
22:45:31.0511 4084        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:45:31.0544 4084        BrFiltLo - ok
22:45:31.0548 4084        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:45:31.0571 4084        BrFiltUp - ok
22:45:31.0629 4084        Browser        (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:45:31.0701 4084        Browser - ok
22:45:31.0725 4084        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:45:31.0747 4084        Brserid - ok
22:45:31.0754 4084        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:45:31.0777 4084        BrSerWdm - ok
22:45:31.0783 4084        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:45:31.0806 4084        BrUsbMdm - ok
22:45:31.0810 4084        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:45:31.0827 4084        BrUsbSer - ok
22:45:31.0837 4084        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:45:31.0860 4084        BTHMODEM - ok
22:45:31.0876 4084        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:45:31.0935 4084        bthserv - ok
22:45:31.0953 4084        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:45:31.0998 4084        cdfs - ok
22:45:32.0034 4084        cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:45:32.0064 4084        cdrom - ok
22:45:32.0109 4084        CertPropSvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:45:32.0172 4084        CertPropSvc - ok
22:45:32.0222 4084        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:45:32.0256 4084        circlass - ok
22:45:32.0304 4084        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:45:32.0342 4084        CLFS - ok
22:45:32.0416 4084        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:45:32.0438 4084        clr_optimization_v2.0.50727_32 - ok
22:45:32.0478 4084        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:45:32.0501 4084        clr_optimization_v2.0.50727_64 - ok
22:45:32.0545 4084        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:45:32.0572 4084        CmBatt - ok
22:45:32.0604 4084        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:45:32.0628 4084        cmdide - ok
22:45:32.0711 4084        CNG            (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
22:45:32.0756 4084        CNG - ok
22:45:32.0781 4084        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:45:32.0796 4084        Compbatt - ok
22:45:32.0816 4084        CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:45:32.0837 4084        CompositeBus - ok
22:45:32.0845 4084        COMSysApp - ok
22:45:32.0870 4084        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:45:32.0886 4084        crcdisk - ok
22:45:32.0930 4084        CryptSvc        (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
22:45:32.0961 4084        CryptSvc - ok
22:45:33.0035 4084        DcomLaunch      (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:45:33.0120 4084        DcomLaunch - ok
22:45:33.0171 4084        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:45:33.0240 4084        defragsvc - ok
22:45:33.0276 4084        DfsC            (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
22:45:33.0297 4084        DfsC - ok
22:45:33.0355 4084        Dhcp            (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:45:33.0401 4084        Dhcp - ok
22:45:33.0440 4084        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:45:33.0510 4084        discache - ok
22:45:33.0551 4084        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:45:33.0577 4084        Disk - ok
22:45:33.0632 4084        Dnscache        (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:45:33.0661 4084        Dnscache - ok
22:45:33.0706 4084        dot3svc        (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:45:33.0775 4084        dot3svc - ok
22:45:33.0804 4084        DPS            (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:45:33.0855 4084        DPS - ok
22:45:33.0889 4084        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:45:33.0909 4084        drmkaud - ok
22:45:34.0033 4084        DsiWMIService  (9cf46fdf163e06b83d03ff929ef2296c) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
22:45:34.0063 4084        DsiWMIService - ok
22:45:34.0180 4084        DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
22:45:34.0236 4084        DXGKrnl - ok
22:45:34.0277 4084        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:45:34.0356 4084        EapHost - ok
22:45:34.0628 4084        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:45:34.0706 4084        ebdrv - ok
22:45:34.0829 4084        EFS            (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
22:45:34.0854 4084        EFS - ok
22:45:34.0964 4084        ehRecvr        (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:45:35.0006 4084        ehRecvr - ok
22:45:35.0038 4084        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:45:35.0067 4084        ehSched - ok
22:45:35.0177 4084        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:45:35.0214 4084        elxstor - ok
22:45:35.0447 4084        ePowerSvc      (3ea2c4f68a782839d97b3c83595575b6) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
22:45:35.0497 4084        ePowerSvc - ok
22:45:35.0646 4084        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:45:35.0671 4084        ErrDev - ok
22:45:35.0738 4084        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:45:35.0825 4084        EventSystem - ok
22:45:35.0861 4084        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:45:35.0923 4084        exfat - ok
22:45:35.0940 4084        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:45:35.0987 4084        fastfat - ok
22:45:36.0059 4084        Fax            (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:45:36.0101 4084        Fax - ok
22:45:36.0125 4084        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:45:36.0152 4084        fdc - ok
22:45:36.0178 4084        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:45:36.0250 4084        fdPHost - ok
22:45:36.0262 4084        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:45:36.0307 4084        FDResPub - ok
22:45:36.0331 4084        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:45:36.0344 4084        FileInfo - ok
22:45:36.0358 4084        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:45:36.0402 4084        Filetrace - ok
22:45:36.0525 4084        FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:45:36.0574 4084        FLEXnet Licensing Service - ok
22:45:36.0603 4084        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:45:36.0629 4084        flpydisk - ok
22:45:36.0673 4084        FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:45:36.0708 4084        FltMgr - ok
22:45:36.0825 4084        FontCache      (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:45:36.0932 4084        FontCache - ok
22:45:36.0999 4084        FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:45:37.0019 4084        FontCache3.0.0.0 - ok
22:45:37.0067 4084        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:45:37.0093 4084        FsDepends - ok
22:45:37.0149 4084        Fs_Rec          (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
22:45:37.0174 4084        Fs_Rec - ok
22:45:37.0231 4084        fvevol          (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:45:37.0268 4084        fvevol - ok
22:45:37.0304 4084        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:45:37.0331 4084        gagp30kx - ok
22:45:37.0453 4084        GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe
22:45:37.0478 4084        GameConsoleService - ok
22:45:37.0611 4084        gpsvc          (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:45:37.0658 4084        gpsvc - ok
22:45:37.0723 4084        GREGService    (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
22:45:37.0740 4084        GREGService - ok
22:45:37.0773 4084        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:45:37.0799 4084        hcw85cir - ok
22:45:37.0856 4084        HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:45:37.0893 4084        HdAudAddService - ok
22:45:37.0935 4084        HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:45:37.0970 4084        HDAudBus - ok
22:45:38.0010 4084        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
22:45:38.0029 4084        HECIx64 - ok
22:45:38.0063 4084        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:45:38.0089 4084        HidBatt - ok
22:45:38.0101 4084        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:45:38.0137 4084        HidBth - ok
22:45:38.0155 4084        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:45:38.0189 4084        HidIr - ok
22:45:38.0221 4084        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:45:38.0293 4084        hidserv - ok
22:45:38.0318 4084        HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:45:38.0343 4084        HidUsb - ok
22:45:38.0385 4084        hkmsvc          (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:45:38.0463 4084        hkmsvc - ok
22:45:38.0494 4084        HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:45:38.0512 4084        HomeGroupListener - ok
22:45:38.0541 4084        HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:45:38.0560 4084        HomeGroupProvider - ok
22:45:38.0602 4084        HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:45:38.0629 4084        HpSAMD - ok
22:45:38.0767 4084        hshld          (b7cfe93627e7796624004687125a729f) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
22:45:38.0805 4084        hshld - ok
22:45:38.0905 4084        HssDrv          (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
22:45:38.0924 4084        HssDrv - ok
22:45:38.0967 4084        HssSrv          (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
22:45:38.0998 4084        HssSrv - ok
22:45:39.0042 4084        HssTrayService  (b3c6eeeff5c5ea3235b7d84317c1fb3f) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
22:45:39.0061 4084        HssTrayService - ok
22:45:39.0082 4084        HssWd - ok
22:45:39.0169 4084        HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:45:39.0244 4084        HTTP - ok
22:45:39.0270 4084        hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:45:39.0285 4084        hwpolicy - ok
22:45:39.0303 4084        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:45:39.0320 4084        i8042prt - ok
22:45:39.0407 4084        iaStor          (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
22:45:39.0440 4084        iaStor - ok
22:45:39.0532 4084        iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:45:39.0564 4084        iaStorV - ok
22:45:39.0704 4084        idsvc          (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:45:39.0747 4084        idsvc - ok
22:45:40.0468 4084        igfx            (2a22ab054f4630d2ef4bab2853f6d5f6) C:\Windows\system32\DRIVERS\igdkmd64.sys
22:45:40.0616 4084        igfx - ok
22:45:40.0771 4084        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:45:40.0797 4084        iirsp - ok
22:45:40.0904 4084        IKEEXT          (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:45:40.0975 4084        IKEEXT - ok
22:45:41.0008 4084        Impcd          (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\DRIVERS\Impcd.sys
22:45:41.0020 4084        Impcd - ok
22:45:41.0237 4084        IntcAzAudAddService (e8017f1662d9142f45ceab694d013c00) C:\Windows\system32\drivers\RTKVHD64.sys
22:45:41.0315 4084        IntcAzAudAddService - ok
22:45:41.0486 4084        IntcDAud        (58cf58dee26c909bd6f977b61d246295) C:\Windows\system32\DRIVERS\IntcDAud.sys
22:45:41.0511 4084        IntcDAud - ok
22:45:41.0550 4084        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:45:41.0575 4084        intelide - ok
22:45:41.0616 4084        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:45:41.0642 4084        intelppm - ok
22:45:41.0684 4084        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:45:41.0763 4084        IPBusEnum - ok
22:45:41.0802 4084        IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:45:41.0876 4084        IpFilterDriver - ok
22:45:41.0920 4084        iphlpsvc        (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:45:41.0979 4084        iphlpsvc - ok
22:45:41.0986 4084        IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:45:42.0000 4084        IPMIDRV - ok
22:45:42.0018 4084        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:45:42.0064 4084        IPNAT - ok
22:45:42.0090 4084        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:45:42.0109 4084        IRENUM - ok
22:45:42.0125 4084        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:45:42.0138 4084        isapnp - ok
22:45:42.0179 4084        iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:45:42.0196 4084        iScsiPrt - ok
22:45:42.0269 4084        k57nd60a        (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys
22:45:42.0301 4084        k57nd60a - ok
22:45:42.0339 4084        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:45:42.0364 4084        kbdclass - ok
22:45:42.0372 4084        kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:45:42.0389 4084        kbdhid - ok
22:45:42.0406 4084        KeyIso          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:45:42.0423 4084        KeyIso - ok
22:45:42.0447 4084        KSecDD          (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
22:45:42.0464 4084        KSecDD - ok
22:45:42.0490 4084        KSecPkg        (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
22:45:42.0510 4084        KSecPkg - ok
22:45:42.0560 4084        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:45:42.0627 4084        ksthunk - ok
22:45:42.0670 4084        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:45:42.0754 4084        KtmRm - ok
22:45:42.0789 4084        L1E            (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys
22:45:42.0813 4084        L1E - ok
22:45:42.0869 4084        LanmanServer    (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:45:42.0901 4084        LanmanServer - ok
22:45:42.0940 4084        LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:45:43.0021 4084        LanmanWorkstation - ok
22:45:43.0052 4084        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:45:43.0107 4084        lltdio - ok
22:45:43.0177 4084        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:45:43.0261 4084        lltdsvc - ok
22:45:43.0281 4084        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:45:43.0335 4084        lmhosts - ok
22:45:43.0487 4084        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:45:43.0514 4084        LMS - ok
22:45:43.0570 4084        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:45:43.0598 4084        LSI_FC - ok
22:45:43.0622 4084        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:45:43.0640 4084        LSI_SAS - ok
22:45:43.0660 4084        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:45:43.0677 4084        LSI_SAS2 - ok
22:45:43.0694 4084        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:45:43.0711 4084        LSI_SCSI - ok
22:45:43.0741 4084        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:45:43.0809 4084        luafv - ok
22:45:43.0842 4084        MBAMProtector  (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
22:45:43.0865 4084        MBAMProtector - ok
22:45:43.0938 4084        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:45:43.0980 4084        MBAMService - ok
22:45:44.0025 4084        Mcx2Svc        (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:45:44.0054 4084        Mcx2Svc - ok
22:45:44.0078 4084        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:45:44.0103 4084        megasas - ok
22:45:44.0147 4084        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:45:44.0179 4084        MegaSR - ok
22:45:44.0210 4084        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:45:44.0270 4084        MMCSS - ok
22:45:44.0288 4084        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:45:44.0336 4084        Modem - ok
22:45:44.0361 4084        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:45:44.0379 4084        monitor - ok
22:45:44.0394 4084        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:45:44.0407 4084        mouclass - ok
22:45:44.0420 4084        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:45:44.0435 4084        mouhid - ok
22:45:44.0454 4084        mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:45:44.0468 4084        mountmgr - ok
22:45:44.0560 4084        MozillaMaintenance (28ac11b4bc84923a75b4447de137dc99) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:45:44.0584 4084        MozillaMaintenance - ok
22:45:44.0614 4084        mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:45:44.0644 4084        mpio - ok
22:45:44.0670 4084        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:45:44.0741 4084        mpsdrv - ok
22:45:44.0819 4084        MpsSvc          (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:45:44.0907 4084        MpsSvc - ok
22:45:44.0931 4084        MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:45:44.0958 4084        MRxDAV - ok
22:45:44.0988 4084        mrxsmb          (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:45:45.0008 4084        mrxsmb - ok
22:45:45.0043 4084        mrxsmb10        (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:45:45.0073 4084        mrxsmb10 - ok
22:45:45.0093 4084        mrxsmb20        (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:45:45.0117 4084        mrxsmb20 - ok
22:45:45.0155 4084        msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:45:45.0177 4084        msahci - ok
22:45:45.0207 4084        msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:45:45.0233 4084        msdsm - ok
22:45:45.0278 4084        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:45:45.0310 4084        MSDTC - ok
22:45:45.0335 4084        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:45:45.0403 4084        Msfs - ok
22:45:45.0415 4084        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:45:45.0467 4084        mshidkmdf - ok
22:45:45.0471 4084        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:45:45.0483 4084        msisadrv - ok
22:45:45.0519 4084        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:45:45.0569 4084        MSiSCSI - ok
22:45:45.0572 4084        msiserver - ok
22:45:45.0598 4084        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:45:45.0643 4084        MSKSSRV - ok
22:45:45.0647 4084        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:45:45.0692 4084        MSPCLOCK - ok
22:45:45.0695 4084        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:45:45.0740 4084        MSPQM - ok
22:45:45.0765 4084        MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:45:45.0785 4084        MsRPC - ok
22:45:45.0792 4084        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:45:45.0806 4084        mssmbios - ok
22:45:45.0818 4084        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:45:45.0865 4084        MSTEE - ok
22:45:45.0874 4084        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:45:45.0889 4084        MTConfig - ok
22:45:45.0896 4084        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:45:45.0910 4084        Mup - ok
22:45:45.0989 4084        napagent        (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:45:46.0075 4084        napagent - ok
22:45:46.0123 4084        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:45:46.0152 4084        NativeWifiP - ok
22:45:46.0257 4084        NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:45:46.0317 4084        NDIS - ok
22:45:46.0333 4084        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:45:46.0423 4084        NdisCap - ok
22:45:46.0451 4084        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:45:46.0511 4084        NdisTapi - ok
22:45:46.0532 4084        Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:45:46.0588 4084        Ndisuio - ok
22:45:46.0600 4084        NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:45:46.0647 4084        NdisWan - ok
22:45:46.0657 4084        NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:45:46.0702 4084        NDProxy - ok
22:45:46.0874 4084        Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
22:45:46.0927 4084        Nero BackItUp Scheduler 4.0 - ok
22:45:46.0980 4084        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:45:47.0051 4084        NetBIOS - ok
22:45:47.0078 4084        NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:45:47.0131 4084        NetBT - ok
22:45:47.0162 4084        Netlogon        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:45:47.0176 4084        Netlogon - ok
22:45:47.0233 4084        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:45:47.0316 4084        Netman - ok
22:45:47.0353 4084        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:45:47.0433 4084        netprofm - ok
22:45:47.0506 4084        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:45:47.0529 4084        NetTcpPortSharing - ok
22:45:47.0571 4084        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:45:47.0597 4084        nfrd960 - ok
22:45:47.0662 4084        NlaSvc          (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:45:47.0741 4084        NlaSvc - ok
22:45:47.0770 4084        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:45:47.0839 4084        Npfs - ok
22:45:47.0859 4084        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:45:47.0912 4084        nsi - ok
22:45:47.0917 4084        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:45:47.0962 4084        nsiproxy - ok
22:45:48.0101 4084        Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:45:48.0166 4084        Ntfs - ok
22:45:48.0291 4084        NTI IScheduleSvc (9a308fcdcca98a15b6f62d36a272160e) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
22:45:48.0315 4084        NTI IScheduleSvc - ok
22:45:48.0419 4084        NTIDrvr        (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys
22:45:48.0436 4084        NTIDrvr - ok
22:45:48.0462 4084        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:45:48.0531 4084        Null - ok
22:45:48.0571 4084        nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:45:48.0591 4084        nvraid - ok
22:45:48.0617 4084        nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:45:48.0638 4084        nvstor - ok
22:45:48.0662 4084        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:45:48.0684 4084        nv_agp - ok
22:45:48.0692 4084        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:45:48.0713 4084        ohci1394 - ok
22:45:48.0767 4084        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:45:48.0800 4084        p2pimsvc - ok
22:45:48.0848 4084        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:45:48.0885 4084        p2psvc - ok
22:45:48.0897 4084        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:45:48.0925 4084        Parport - ok
22:45:48.0956 4084        partmgr        (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
22:45:48.0983 4084        partmgr - ok
22:45:49.0001 4084        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:45:49.0040 4084        PcaSvc - ok
22:45:49.0066 4084        pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:45:49.0086 4084        pci - ok
22:45:49.0120 4084        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:45:49.0143 4084        pciide - ok
22:45:49.0180 4084        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:45:49.0212 4084        pcmcia - ok
22:45:49.0219 4084        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:45:49.0234 4084        pcw - ok
22:45:49.0286 4084        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:45:49.0376 4084        PEAUTH - ok
22:45:49.0480 4084        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:45:49.0509 4084        PerfHost - ok
22:45:49.0677 4084        pla            (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:45:49.0759 4084        pla - ok
22:45:49.0838 4084        PlugPlay        (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
22:45:49.0874 4084        PlugPlay - ok
22:45:49.0895 4084        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:45:49.0915 4084        PNRPAutoReg - ok
22:45:49.0941 4084        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:45:49.0965 4084        PNRPsvc - ok
22:45:50.0036 4084        PolicyAgent    (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:45:50.0117 4084        PolicyAgent - ok
22:45:50.0169 4084        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:45:50.0250 4084        Power - ok
22:45:50.0336 4084        PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:45:50.0416 4084        PptpMiniport - ok
22:45:50.0440 4084        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:45:50.0454 4084        Processor - ok
22:45:50.0504 4084        ProfSvc        (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
22:45:50.0534 4084        ProfSvc - ok
22:45:50.0562 4084        ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:45:50.0585 4084        ProtectedStorage - ok
22:45:50.0616 4084        Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:45:50.0680 4084        Psched - ok
22:45:50.0741 4084        PxHlpa64        (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
22:45:50.0761 4084        PxHlpa64 - ok
22:45:50.0913 4084        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:45:50.0990 4084        ql2300 - ok
22:45:51.0151 4084        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:45:51.0180 4084        ql40xx - ok
22:45:51.0230 4084        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:45:51.0274 4084        QWAVE - ok
22:45:51.0292 4084        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:45:51.0315 4084        QWAVEdrv - ok
22:45:51.0333 4084        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:45:51.0387 4084        RasAcd - ok
22:45:51.0425 4084        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:45:51.0480 4084        RasAgileVpn - ok
22:45:51.0525 4084        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:45:51.0598 4084        RasAuto - ok
22:45:51.0620 4084        Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:45:51.0668 4084        Rasl2tp - ok
22:45:51.0700 4084        RasMan          (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:45:51.0754 4084        RasMan - ok
22:45:51.0774 4084        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:45:51.0821 4084        RasPppoe - ok
22:45:51.0829 4084        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:45:51.0873 4084        RasSstp - ok
22:45:51.0898 4084        rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:45:51.0948 4084        rdbss - ok
22:45:51.0962 4084        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:45:51.0980 4084        rdpbus - ok
22:45:52.0001 4084        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:45:52.0046 4084        RDPCDD - ok
22:45:52.0052 4084        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:45:52.0096 4084        RDPENCDD - ok
22:45:52.0101 4084        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:45:52.0145 4084        RDPREFMP - ok
22:45:52.0179 4084        RDPWD          (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
22:45:52.0204 4084        RDPWD - ok
22:45:52.0269 4084        rdyboost        (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
22:45:52.0301 4084        rdyboost - ok
22:45:52.0337 4084        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:45:52.0403 4084        RemoteAccess - ok
22:45:52.0466 4084        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:45:52.0541 4084        RemoteRegistry - ok
22:45:52.0561 4084        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:45:52.0606 4084        RpcEptMapper - ok
22:45:52.0637 4084        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:45:52.0651 4084        RpcLocator - ok
22:45:52.0707 4084        RpcSs          (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:45:52.0776 4084        RpcSs - ok
22:45:52.0826 4084        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:45:52.0900 4084        rspndr - ok
22:45:52.0917 4084        SamSs          (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:45:52.0934 4084        SamSs - ok
22:45:52.0981 4084        sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:45:52.0999 4084        sbp2port - ok
22:45:53.0048 4084        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:45:53.0112 4084        SCardSvr - ok
22:45:53.0124 4084        scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:45:53.0169 4084        scfilter - ok
22:45:53.0287 4084        Schedule        (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:45:53.0335 4084        Schedule - ok
22:45:53.0376 4084        SCPolicySvc    (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:45:53.0432 4084        SCPolicySvc - ok
22:45:53.0479 4084        SDRSVC          (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:45:53.0509 4084        SDRSVC - ok
22:45:53.0582 4084        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:45:53.0652 4084        secdrv - ok
22:45:53.0670 4084        seclogon        (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:45:53.0716 4084        seclogon - ok
22:45:53.0737 4084        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:45:53.0785 4084        SENS - ok
22:45:53.0791 4084        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:45:53.0805 4084        SensrSvc - ok
22:45:53.0827 4084        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:45:53.0842 4084        Serenum - ok
22:45:53.0878 4084        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:45:53.0894 4084        Serial - ok
22:45:53.0926 4084        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:45:53.0955 4084        sermouse - ok
22:45:54.0006 4084        SessionEnv      (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:45:54.0072 4084        SessionEnv - ok
22:45:54.0076 4084        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:45:54.0091 4084        sffdisk - ok
22:45:54.0097 4084        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:45:54.0112 4084        sffp_mmc - ok
22:45:54.0121 4084        sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:45:54.0136 4084        sffp_sd - ok
22:45:54.0150 4084        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:45:54.0166 4084        sfloppy - ok
22:45:54.0248 4084        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:45:54.0333 4084        SharedAccess - ok
22:45:54.0388 4084        ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:45:54.0437 4084        ShellHWDetection - ok
22:45:54.0462 4084        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:45:54.0490 4084        SiSRaid2 - ok
22:45:54.0529 4084        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:45:54.0549 4084        SiSRaid4 - ok
22:45:54.0629 4084        SkypeUpdate    (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:45:54.0652 4084        SkypeUpdate - ok
22:45:54.0698 4084        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:45:54.0766 4084        Smb - ok
22:45:54.0831 4084        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:45:54.0858 4084        SNMPTRAP - ok
22:45:54.0884 4084        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:45:54.0902 4084        spldr - ok
22:45:55.0025 4084        Spooler        (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:45:55.0064 4084        Spooler - ok
22:45:55.0355 4084        sppsvc          (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:45:55.0428 4084        sppsvc - ok
22:45:55.0545 4084        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:45:55.0624 4084        sppuinotify - ok
22:45:55.0706 4084        srv            (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
22:45:55.0742 4084        srv - ok
22:45:55.0796 4084        srv2            (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
22:45:55.0830 4084        srv2 - ok
22:45:55.0858 4084        srvnet          (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
22:45:55.0884 4084        srvnet - ok
22:45:55.0933 4084        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:45:56.0020 4084        SSDPSRV - ok
22:45:56.0030 4084        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:45:56.0080 4084        SstpSvc - ok
22:45:56.0106 4084        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:45:56.0120 4084        stexstor - ok
22:45:56.0195 4084        stisvc          (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:45:56.0248 4084        stisvc - ok
22:45:56.0268 4084        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:45:56.0293 4084        swenum - ok
22:45:56.0357 4084        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:45:56.0441 4084        swprv - ok
22:45:56.0511 4084        SynTP          (ed6d1424e5b0c21a57b28dd8508d6843) C:\Windows\system32\DRIVERS\SynTP.sys
22:45:56.0539 4084        SynTP - ok
22:45:56.0696 4084        SysMain        (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:45:56.0755 4084        SysMain - ok
22:45:56.0872 4084        TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:45:56.0913 4084        TabletInputService - ok
22:45:56.0976 4084        taphss          (b70df208e97536ca9f29289e609f5b16) C:\Windows\system32\DRIVERS\taphss.sys
22:45:56.0995 4084        taphss - ok
22:45:57.0062 4084        TapiSrv        (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:45:57.0138 4084        TapiSrv - ok
22:45:57.0145 4084        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:45:57.0190 4084        TBS - ok
22:45:57.0355 4084        Tcpip          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
22:45:57.0417 4084        Tcpip - ok
22:45:57.0699 4084        TCPIP6          (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
22:45:57.0769 4084        TCPIP6 - ok
22:45:57.0882 4084        tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:45:57.0960 4084        tcpipreg - ok
22:45:57.0978 4084        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:45:57.0994 4084        TDPIPE - ok
22:45:58.0038 4084        TDTCP          (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
22:45:58.0062 4084        TDTCP - ok
22:45:58.0074 4084        tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:45:58.0141 4084        tdx - ok
22:45:58.0429 4084        TeamViewer7    (a4d2ce94b028ef1e437cf4ac3d8ff26c) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
22:45:58.0510 4084        TeamViewer7 - ok
22:45:58.0653 4084        TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:45:58.0676 4084        TermDD - ok
22:45:58.0770 4084        TermService    (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:45:58.0859 4084        TermService - ok
22:45:58.0871 4084        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:45:58.0893 4084        Themes - ok
22:45:58.0921 4084        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:45:58.0975 4084        THREADORDER - ok
22:45:58.0999 4084        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:45:59.0046 4084        TrkWks - ok
22:45:59.0117 4084        TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:45:59.0148 4084        TrustedInstaller - ok
22:45:59.0174 4084        tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:45:59.0220 4084        tssecsrv - ok
22:45:59.0255 4084        tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:45:59.0300 4084        tunnel - ok
22:45:59.0314 4084        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:45:59.0327 4084        uagp35 - ok
22:45:59.0364 4084        UBHelper        (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys
22:45:59.0373 4084        UBHelper - ok
22:45:59.0399 4084        udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:45:59.0449 4084        udfs - ok
22:45:59.0475 4084        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:45:59.0491 4084        UI0Detect - ok
22:45:59.0498 4084        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:45:59.0512 4084        uliagpkx - ok
22:45:59.0554 4084        umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:45:59.0569 4084        umbus - ok
22:45:59.0579 4084        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:45:59.0594 4084        UmPass - ok
22:45:59.0903 4084        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:45:59.0970 4084        UNS - ok
22:46:00.0059 4084        Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
22:46:00.0084 4084        Updater Service - ok
22:46:00.0238 4084        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:46:00.0315 4084        upnphost - ok
22:46:00.0387 4084        usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:46:00.0414 4084        usbccgp - ok
22:46:00.0445 4084        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:46:00.0477 4084        usbcir - ok
22:46:00.0486 4084        usbehci        (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
22:46:00.0509 4084        usbehci - ok
22:46:00.0578 4084        usbhub          (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
22:46:00.0610 4084        usbhub - ok
22:46:00.0632 4084        usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:46:00.0654 4084        usbohci - ok
22:46:00.0670 4084        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:46:00.0700 4084        usbprint - ok
22:46:00.0724 4084        USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:46:00.0742 4084        USBSTOR - ok
22:46:00.0772 4084        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:46:00.0788 4084        usbuhci - ok
22:46:00.0848 4084        usbvideo        (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
22:46:00.0876 4084        usbvideo - ok
22:46:00.0905 4084        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:46:00.0976 4084        UxSms - ok
22:46:00.0995 4084        VaultSvc        (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
22:46:01.0008 4084        VaultSvc - ok
22:46:01.0049 4084        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:46:01.0071 4084        vdrvroot - ok
22:46:01.0154 4084        vds            (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:46:01.0192 4084        vds - ok
22:46:01.0213 4084        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:46:01.0235 4084        vga - ok
22:46:01.0253 4084        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:46:01.0309 4084        VgaSave - ok
22:46:01.0342 4084        vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:46:01.0358 4084        vhdmp - ok
22:46:01.0382 4084        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:46:01.0396 4084        viaide - ok
22:46:01.0403 4084        volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:46:01.0417 4084        volmgr - ok
22:46:01.0447 4084        volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:46:01.0469 4084        volmgrx - ok
22:46:01.0507 4084        volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:46:01.0529 4084        volsnap - ok
22:46:01.0571 4084        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:46:01.0599 4084        vsmraid - ok
22:46:01.0769 4084        VSS            (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:46:01.0825 4084        VSS - ok
22:46:01.0959 4084        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:46:01.0993 4084        vwifibus - ok
22:46:02.0001 4084        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:46:02.0040 4084        vwififlt - ok
22:46:02.0089 4084        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:46:02.0126 4084        vwifimp - ok
22:46:02.0191 4084        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:46:02.0270 4084        W32Time - ok
22:46:02.0293 4084        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:46:02.0310 4084        WacomPen - ok
22:46:02.0344 4084        WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:46:02.0399 4084        WANARP - ok
22:46:02.0402 4084        Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:46:02.0448 4084        Wanarpv6 - ok
22:46:02.0598 4084        wbengine        (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:46:02.0662 4084        wbengine - ok
22:46:02.0804 4084        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:46:02.0848 4084        WbioSrvc - ok
22:46:02.0915 4084        wcncsvc        (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:46:02.0950 4084        wcncsvc - ok
22:46:02.0965 4084        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:46:02.0982 4084        WcsPlugInService - ok
22:46:03.0047 4084        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:46:03.0071 4084        Wd - ok
22:46:03.0135 4084        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:46:03.0175 4084        Wdf01000 - ok
22:46:03.0221 4084        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:46:03.0264 4084        WdiServiceHost - ok
22:46:03.0271 4084        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:46:03.0314 4084        WdiSystemHost - ok
22:46:03.0362 4084        WebClient      (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:46:03.0394 4084        WebClient - ok
22:46:03.0445 4084        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:46:03.0522 4084        Wecsvc - ok
22:46:03.0545 4084        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:46:03.0594 4084        wercplsupport - ok
22:46:03.0619 4084        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:46:03.0666 4084        WerSvc - ok
22:46:03.0736 4084        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:46:03.0814 4084        WfpLwf - ok
22:46:03.0825 4084        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:46:03.0837 4084        WIMMount - ok
22:46:03.0860 4084        WinDefend - ok
22:46:03.0866 4084        WinHttpAutoProxySvc - ok
22:46:03.0946 4084        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:46:04.0014 4084        Winmgmt - ok
22:46:04.0195 4084        WinRM          (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:46:04.0288 4084        WinRM - ok
22:46:04.0491 4084        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:46:04.0537 4084        Wlansvc - ok
22:46:04.0570 4084        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:46:04.0593 4084        WmiAcpi - ok
22:46:04.0663 4084        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:46:04.0698 4084        wmiApSrv - ok
22:46:04.0775 4084        WMPNetworkSvc - ok
22:46:04.0818 4084        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:46:04.0844 4084        WPCSvc - ok
22:46:04.0866 4084        WPDBusEnum      (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:46:04.0898 4084        WPDBusEnum - ok
22:46:04.0927 4084        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:46:04.0995 4084        ws2ifsl - ok
22:46:05.0039 4084        wscsvc          (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:46:05.0056 4084        wscsvc - ok
22:46:05.0059 4084        WSearch - ok
22:46:05.0267 4084        wuauserv        (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
22:46:05.0367 4084        wuauserv - ok
22:46:05.0513 4084        WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:46:05.0588 4084        WudfPf - ok
22:46:05.0652 4084        WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:46:05.0732 4084        WUDFRd - ok
22:46:05.0763 4084        wudfsvc        (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:46:05.0819 4084        wudfsvc - ok
22:46:05.0836 4084        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:46:05.0863 4084        WwanSvc - ok
22:46:05.0916 4084        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
22:46:06.0351 4084        \Device\Harddisk0\DR0 - ok
22:46:06.0361 4084        Boot (0x1200)  (4590c359c1397ff476d25a7e40681509) \Device\Harddisk0\DR0\Partition0
22:46:06.0363 4084        \Device\Harddisk0\DR0\Partition0 - ok
22:46:06.0394 4084        Boot (0x1200)  (ac8d5b56739406991345b6c8c7d4ec40) \Device\Harddisk0\DR0\Partition1
22:46:06.0396 4084        \Device\Harddisk0\DR0\Partition1 - ok
22:46:06.0420 4084        Boot (0x1200)  (b3a236284051ca3b63697f6e10d96550) \Device\Harddisk0\DR0\Partition2
22:46:06.0422 4084        \Device\Harddisk0\DR0\Partition2 - ok
22:46:06.0447 4084        Boot (0x1200)  (fdf6e4bb24595e02ea93b69c8ea2ea09) \Device\Harddisk0\DR0\Partition3
22:46:06.0449 4084        \Device\Harddisk0\DR0\Partition3 - ok
22:46:06.0450 4084        ============================================================
22:46:06.0450 4084        Scan finished
22:46:06.0450 4084        ============================================================
22:46:06.0463 4216        Detected object count: 0
22:46:06.0463 4216        Actual detected object count: 0


cosinus 15.06.2012 23:17

:D

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:24 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19