![]() |
Trojaner: Urheberrecht und verwandte Schutzrechte Liste der Anhänge anzeigen (Anzahl: 1) Hallo liebes Forum, über eine ZIP Datei, hat sich mein Mann einen Trojaner gezogen. Nett finde ich, dass das die ZIP Dateien für die Prüfungsvorbereitungen von Kommilitonen bereit gestellt werden. Der Trojaner wurde nur aktiv, wenn IE oder Mozilla gestartet wurde, dann war der PC nicht mehr steuerbar. Ich habe Malwarebytes drüber laufen und versehentlich das Ergebnis gelöscht, aber eine Hardcopy gemacht. M-Bytes hat die Trojaner gelöscht, aber ist der Rechner wirklich sauber? |
:hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Zitat:
Führe bitte die folgenden Schritte aus und dann sehen wir weiter. Schritt 1 Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop (falls noch nicht vorhanden).
Code: activex
Schritt 2 Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Klicke den Re-enable Button nicht ohne Anweisung. Schritt 3 Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit. Schritt 4 Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen. Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
Lieber M-K-D-B, vielen Dank, für Deine sehr detailierte Anleitung. Ich komme vor dem Sonntag nicht dazu, dies alles durchzuführen. Ich hoffe dies ist ok für Dich. Gruß Sabine |
Servus, vielen Dank für die Rückmeldung. Dann bis Sonntag. :) |
Servus Matthias, Schritt 1: OTL OTL Logfile: Code: OTL logfile created on: 14.10.2012 14:45:37 - Run 1 Extras OTL Logfile: Code: OTL Extras logfile created on: 14.10.2012 14:45:37 - Run 1 Schritt 2 kein Ergebnis |
Schritte 3 aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-10-14 15:01:05 ----------------------------- 15:01:05.367 OS Version: Windows x64 6.1.7601 Service Pack 1 15:01:05.367 Number of processors: 8 586 0x2A07 15:01:05.367 ComputerName: CHRISTIAN-HP UserName: Christian 15:01:06.771 Initialize success 15:05:24.424 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 15:05:24.424 Disk 0 Vendor: ST1000LM 2AR1 Size: 953869MB BusType: 3 15:05:24.455 Disk 0 MBR read successfully 15:05:24.455 Disk 0 MBR scan 15:05:24.455 Disk 0 Windows 7 default MBR code 15:05:24.471 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 15:05:24.486 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 927238 MB offset 409600 15:05:24.518 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 22368 MB offset 1899393024 15:05:24.518 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 4062 MB offset 1945202688 15:05:24.580 Disk 0 scanning C:\Windows\system32\drivers 15:05:47.106 Service scanning 15:06:02.660 Modules scanning 15:06:02.660 Disk 0 trace - called modules: 15:06:02.675 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll 15:06:02.691 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80083e8790] 15:06:02.691 3 CLASSPNP.SYS[fffff88001cb243f] -> nt!IofCallDriver -> [0xfffffa80082eeb10] 15:06:02.691 5 hpdskflt.sys[fffff88001899189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800810d050] 15:06:02.691 Scan finished successfully 15:08:32.545 Disk 0 MBR has been saved successfully to "G:\MBR.dat" 15:08:32.701 The log file has been saved successfully to "G:\Schritt3_aswMBR.txt" Schritt 4 15:09:24.0082 4368 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24 15:09:24.0456 4368 ============================================================ 15:09:24.0456 4368 Current date / time: 2012/10/14 15:09:24.0456 15:09:24.0456 4368 SystemInfo: 15:09:24.0456 4368 15:09:24.0456 4368 OS Version: 6.1.7601 ServicePack: 1.0 15:09:24.0456 4368 Product type: Workstation 15:09:24.0456 4368 ComputerName: CHRISTIAN-HP 15:09:24.0456 4368 UserName: Christian 15:09:24.0456 4368 Windows directory: C:\Windows 15:09:24.0456 4368 System windows directory: C:\Windows 15:09:24.0456 4368 Running under WOW64 15:09:24.0456 4368 Processor architecture: Intel x64 15:09:24.0456 4368 Number of processors: 8 15:09:24.0456 4368 Page size: 0x1000 15:09:24.0456 4368 Boot type: Normal boot 15:09:24.0456 4368 ============================================================ 15:09:24.0893 4368 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 15:09:24.0893 4368 Drive \Device\Harddisk1\DR2 - Size: 0x1E2000000 (7.53 Gb), SectorSize: 0x200, Cylinders: 0x3D7, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 15:09:24.0893 4368 ============================================================ 15:09:24.0893 4368 \Device\Harddisk0\DR0: 15:09:24.0893 4368 MBR partitions: 15:09:24.0893 4368 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800 15:09:24.0893 4368 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x71303000 15:09:24.0893 4368 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x71367000, BlocksNum 0x2BB0000 15:09:24.0893 4368 \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x73F17000, BlocksNum 0x7EF000 15:09:24.0893 4368 \Device\Harddisk1\DR2: 15:09:24.0893 4368 MBR partitions: 15:09:24.0893 4368 ============================================================ 15:09:24.0924 4368 C: <-> \Device\Harddisk0\DR0\Partition2 15:09:24.0986 4368 D: <-> \Device\Harddisk0\DR0\Partition3 15:09:24.0986 4368 E: <-> \Device\Harddisk0\DR0\Partition4 15:09:24.0986 4368 ============================================================ 15:09:24.0986 4368 Initialize success 15:09:24.0986 4368 ============================================================ 15:09:30.0431 3700 ============================================================ 15:09:30.0431 3700 Scan started 15:09:30.0431 3700 Mode: Manual; 15:09:30.0431 3700 ============================================================ 15:09:30.0992 3700 ================ Scan system memory ======================== 15:09:30.0992 3700 System memory - ok 15:09:30.0992 3700 ================ Scan services ============================= 15:09:31.0148 3700 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 15:09:31.0148 3700 1394ohci - ok 15:09:31.0180 3700 [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer C:\Windows\system32\DRIVERS\Accelerometer.sys 15:09:31.0180 3700 Accelerometer - ok 15:09:31.0211 3700 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 15:09:31.0226 3700 ACPI - ok 15:09:31.0258 3700 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 15:09:31.0258 3700 AcpiPmi - ok 15:09:31.0351 3700 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 15:09:31.0367 3700 AdobeARMservice - ok 15:09:31.0476 3700 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 15:09:31.0476 3700 AdobeFlashPlayerUpdateSvc - ok 15:09:31.0538 3700 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 15:09:31.0554 3700 adp94xx - ok 15:09:31.0585 3700 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 15:09:31.0585 3700 adpahci - ok 15:09:31.0632 3700 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 15:09:31.0632 3700 adpu320 - ok 15:09:31.0663 3700 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 15:09:31.0663 3700 AeLookupSvc - ok 15:09:31.0726 3700 [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters C:\Program Files\IDT\WDM\AESTSr64.exe 15:09:31.0741 3700 AESTFilters - ok 15:09:31.0788 3700 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 15:09:31.0804 3700 AFD - ok 15:09:31.0835 3700 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 15:09:31.0835 3700 agp440 - ok 15:09:31.0866 3700 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 15:09:31.0866 3700 ALG - ok 15:09:31.0913 3700 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 15:09:31.0913 3700 aliide - ok 15:09:31.0960 3700 [ C53D784D7303C463D004C0D5782917B4 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 15:09:31.0960 3700 AMD External Events Utility - ok 15:09:31.0960 3700 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 15:09:31.0975 3700 amdide - ok 15:09:32.0006 3700 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 15:09:32.0006 3700 AmdK8 - ok 15:09:32.0256 3700 [ 06778049A44C316E8D016039B9D14667 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys 15:09:32.0459 3700 amdkmdag - ok 15:09:32.0506 3700 [ 94B4028F0EEA1F166D78186A254676B5 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 15:09:32.0521 3700 amdkmdap - ok 15:09:32.0521 3700 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 15:09:32.0537 3700 AmdPPM - ok 15:09:32.0568 3700 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 15:09:32.0568 3700 amdsata - ok 15:09:32.0584 3700 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 15:09:32.0584 3700 amdsbs - ok 15:09:32.0615 3700 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 15:09:32.0615 3700 amdxata - ok 15:09:32.0708 3700 [ 3BCAC0D02139BD3B4A04DFF0CCD85452 ] AntiVirMailService C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe 15:09:32.0724 3700 AntiVirMailService - ok 15:09:32.0771 3700 [ 7B0CB3B7AA7638A3057CF5A2E86BD565 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 15:09:32.0771 3700 AntiVirSchedulerService - ok 15:09:32.0802 3700 [ DE7C88712F961E828BEF15FCBB840F9F ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 15:09:32.0802 3700 AntiVirService - ok 15:09:32.0864 3700 [ D77DF1FAEBDC438ED5A50FF69CC1E53B ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE 15:09:32.0864 3700 AntiVirWebService - ok 15:09:32.0927 3700 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 15:09:32.0927 3700 AppID - ok 15:09:32.0974 3700 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 15:09:32.0974 3700 AppIDSvc - ok 15:09:33.0005 3700 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 15:09:33.0005 3700 Appinfo - ok 15:09:33.0020 3700 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 15:09:33.0020 3700 arc - ok 15:09:33.0036 3700 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 15:09:33.0036 3700 arcsas - ok 15:09:33.0052 3700 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 15:09:33.0052 3700 AsyncMac - ok 15:09:33.0067 3700 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 15:09:33.0067 3700 atapi - ok 15:09:33.0114 3700 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 15:09:33.0130 3700 AudioEndpointBuilder - ok 15:09:33.0145 3700 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 15:09:33.0161 3700 AudioSrv - ok 15:09:33.0192 3700 [ 25B63A3C24A5E0223A35DE2F0D9E0FAF ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 15:09:33.0192 3700 avgntflt - ok 15:09:33.0239 3700 [ A83691240C1568E6A3EAA5C86D9F8AE3 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 15:09:33.0239 3700 avipbb - ok 15:09:33.0254 3700 [ CD0E732347BF09717E0BDDC0C66699AB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 15:09:33.0254 3700 avkmgr - ok 15:09:33.0286 3700 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 15:09:33.0301 3700 AxInstSV - ok 15:09:33.0332 3700 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 15:09:33.0332 3700 b06bdrv - ok 15:09:33.0364 3700 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 15:09:33.0379 3700 b57nd60a - ok 15:09:33.0442 3700 [ 9E84A931DBEE0292E38ED672F6293A99 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys 15:09:33.0473 3700 BCM43XX - ok 15:09:33.0488 3700 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 15:09:33.0488 3700 BDESVC - ok 15:09:33.0504 3700 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 15:09:33.0504 3700 Beep - ok 15:09:33.0551 3700 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 15:09:33.0566 3700 BFE - ok 15:09:33.0613 3700 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 15:09:33.0629 3700 BITS - ok 15:09:33.0660 3700 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 15:09:33.0660 3700 blbdrive - ok 15:09:33.0660 3700 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 15:09:33.0660 3700 bowser - ok 15:09:33.0691 3700 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 15:09:33.0691 3700 BrFiltLo - ok 15:09:33.0722 3700 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 15:09:33.0722 3700 BrFiltUp - ok 15:09:33.0754 3700 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 15:09:33.0754 3700 Browser - ok 15:09:33.0785 3700 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 15:09:33.0785 3700 Brserid - ok 15:09:33.0800 3700 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 15:09:33.0800 3700 BrSerWdm - ok 15:09:33.0832 3700 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 15:09:33.0832 3700 BrUsbMdm - ok 15:09:33.0832 3700 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 15:09:33.0832 3700 BrUsbSer - ok 15:09:33.0863 3700 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 15:09:33.0863 3700 BTHMODEM - ok 15:09:33.0910 3700 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 15:09:33.0910 3700 bthserv - ok 15:09:33.0941 3700 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 15:09:33.0941 3700 cdfs - ok 15:09:33.0972 3700 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 15:09:33.0972 3700 cdrom - ok 15:09:34.0019 3700 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 15:09:34.0019 3700 CertPropSvc - ok 15:09:34.0050 3700 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 15:09:34.0050 3700 circlass - ok 15:09:34.0081 3700 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 15:09:34.0081 3700 CLFS - ok 15:09:34.0175 3700 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:09:34.0175 3700 clr_optimization_v2.0.50727_32 - ok 15:09:34.0222 3700 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 15:09:34.0237 3700 clr_optimization_v2.0.50727_64 - ok 15:09:34.0300 3700 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 15:09:34.0300 3700 clr_optimization_v4.0.30319_32 - ok 15:09:34.0331 3700 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 15:09:34.0331 3700 clr_optimization_v4.0.30319_64 - ok 15:09:34.0378 3700 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys 15:09:34.0378 3700 clwvd - ok 15:09:34.0409 3700 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 15:09:34.0409 3700 CmBatt - ok 15:09:34.0424 3700 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 15:09:34.0424 3700 cmdide - ok 15:09:34.0471 3700 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 15:09:34.0487 3700 CNG - ok 15:09:34.0502 3700 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 15:09:34.0502 3700 Compbatt - ok 15:09:34.0518 3700 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 15:09:34.0518 3700 CompositeBus - ok 15:09:34.0549 3700 COMSysApp - ok 15:09:34.0565 3700 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 15:09:34.0565 3700 crcdisk - ok 15:09:34.0612 3700 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 15:09:34.0612 3700 CryptSvc - ok 15:09:34.0674 3700 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 15:09:34.0690 3700 DcomLaunch - ok 15:09:34.0736 3700 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 15:09:34.0736 3700 defragsvc - ok 15:09:34.0752 3700 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 15:09:34.0768 3700 DfsC - ok 15:09:34.0814 3700 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 15:09:34.0814 3700 Dhcp - ok 15:09:34.0830 3700 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 15:09:34.0846 3700 discache - ok 15:09:34.0861 3700 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 15:09:34.0861 3700 Disk - ok 15:09:34.0892 3700 DlinkUDSMBus - ok 15:09:34.0908 3700 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 15:09:34.0908 3700 Dnscache - ok 15:09:34.0924 3700 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 15:09:34.0939 3700 dot3svc - ok 15:09:34.0955 3700 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 15:09:34.0955 3700 DPS - ok 15:09:34.0986 3700 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 15:09:34.0986 3700 drmkaud - ok 15:09:35.0033 3700 [ A4F408AD1065C7AD2ED332C68025B435 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 15:09:35.0048 3700 DXGKrnl - ok 15:09:35.0095 3700 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 15:09:35.0111 3700 EapHost - ok 15:09:35.0204 3700 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 15:09:35.0282 3700 ebdrv - ok 15:09:35.0314 3700 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 15:09:35.0329 3700 EFS - ok 15:09:35.0392 3700 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 15:09:35.0407 3700 ehRecvr - ok 15:09:35.0423 3700 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 15:09:35.0423 3700 ehSched - ok 15:09:35.0470 3700 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 15:09:35.0470 3700 elxstor - ok 15:09:35.0532 3700 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 15:09:35.0532 3700 ErrDev - ok 15:09:35.0594 3700 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 15:09:35.0594 3700 EventSystem - ok 15:09:35.0626 3700 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 15:09:35.0626 3700 exfat - ok 15:09:35.0641 3700 ezSharedSvc - ok 15:09:35.0657 3700 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 15:09:35.0657 3700 fastfat - ok 15:09:35.0688 3700 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 15:09:35.0704 3700 Fax - ok 15:09:35.0750 3700 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 15:09:35.0750 3700 fdc - ok 15:09:35.0766 3700 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 15:09:35.0782 3700 fdPHost - ok 15:09:35.0797 3700 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 15:09:35.0797 3700 FDResPub - ok 15:09:35.0813 3700 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 15:09:35.0813 3700 FileInfo - ok 15:09:35.0828 3700 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 15:09:35.0828 3700 Filetrace - ok 15:09:35.0828 3700 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 15:09:35.0828 3700 flpydisk - ok 15:09:35.0844 3700 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 15:09:35.0844 3700 FltMgr - ok 15:09:35.0875 3700 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 15:09:35.0891 3700 FontCache - ok 15:09:35.0922 3700 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 15:09:35.0922 3700 FontCache3.0.0.0 - ok 15:09:35.0969 3700 [ F80BDC0D9E7B9595E74B434446AD3781 ] FPLService C:\Program Files (x86)\HP SimplePass 2012\TrueSuiteService.exe 15:09:35.0969 3700 FPLService - ok 15:09:35.0984 3700 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 15:09:35.0984 3700 FsDepends - ok 15:09:36.0031 3700 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 15:09:36.0031 3700 Fs_Rec - ok 15:09:36.0062 3700 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 15:09:36.0062 3700 fvevol - ok 15:09:36.0094 3700 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 15:09:36.0094 3700 gagp30kx - ok 15:09:36.0140 3700 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe 15:09:36.0140 3700 GamesAppService - ok 15:09:36.0187 3700 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 15:09:36.0187 3700 gpsvc - ok 15:09:36.0265 3700 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 15:09:36.0265 3700 gupdate - ok 15:09:36.0265 3700 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 15:09:36.0265 3700 gupdatem - ok 15:09:36.0296 3700 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 15:09:36.0296 3700 hcw85cir - ok 15:09:36.0328 3700 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 15:09:36.0328 3700 HdAudAddService - ok 15:09:36.0343 3700 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 15:09:36.0343 3700 HDAudBus - ok 15:09:36.0374 3700 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 15:09:36.0374 3700 HidBatt - ok 15:09:36.0374 3700 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 15:09:36.0374 3700 HidBth - ok 15:09:36.0390 3700 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 15:09:36.0390 3700 HidIr - ok 15:09:36.0421 3700 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 15:09:36.0421 3700 hidserv - ok 15:09:36.0421 3700 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 15:09:36.0421 3700 HidUsb - ok 15:09:36.0468 3700 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 15:09:36.0468 3700 hkmsvc - ok 15:09:36.0499 3700 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 15:09:36.0499 3700 HomeGroupListener - ok 15:09:36.0515 3700 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 15:09:36.0515 3700 HomeGroupProvider - ok 15:09:36.0562 3700 [ 13BB1114451C63BFB41BA7DAA4D70A29 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe 15:09:36.0562 3700 HP Support Assistant Service - ok 15:09:36.0593 3700 [ 6A181452D4E240B8ECC7614B9A19BDE9 ] HPClientSvc C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe 15:09:36.0593 3700 HPClientSvc - ok 15:09:36.0640 3700 [ E6AB9E7FF923928E9F549FDDFCEDB28A ] HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe 15:09:36.0640 3700 HPDrvMntSvc.exe - ok 15:09:36.0671 3700 [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt C:\Windows\system32\DRIVERS\hpdskflt.sys 15:09:36.0671 3700 hpdskflt - ok 15:09:36.0718 3700 [ DBDC0581D4506C13E6BEF48D14B1C55B ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe 15:09:36.0733 3700 hpqwmiex - ok 15:09:36.0764 3700 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 15:09:36.0764 3700 HpSAMD - ok 15:09:36.0796 3700 [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv C:\Windows\system32\Hpservice.exe 15:09:36.0796 3700 hpsrv - ok 15:09:36.0842 3700 [ 491CE9B6321FB74E4B37AF2C47F98434 ] HPWMISVC C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe 15:09:36.0842 3700 HPWMISVC - ok 15:09:36.0889 3700 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 15:09:36.0905 3700 HTTP - ok 15:09:36.0920 3700 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 15:09:36.0920 3700 hwpolicy - ok 15:09:36.0936 3700 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 15:09:36.0952 3700 i8042prt - ok 15:09:36.0983 3700 [ 2FDAEC4B02729C48C0FD1B0B4695995B ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 15:09:36.0983 3700 iaStor - ok 15:09:37.0076 3700 [ D41861E56E7552C13674D7F147A02464 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 15:09:37.0076 3700 IAStorDataMgrSvc - ok 15:09:37.0108 3700 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 15:09:37.0123 3700 iaStorV - ok 15:09:37.0232 3700 [ D72BF0AE484F88399E8343E821C10D6A ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe 15:09:37.0248 3700 IconMan_R - ok 15:09:37.0310 3700 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 15:09:37.0326 3700 idsvc - ok 15:09:37.0357 3700 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 15:09:37.0357 3700 iirsp - ok 15:09:37.0404 3700 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 15:09:37.0420 3700 IKEEXT - ok 15:09:37.0466 3700 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys 15:09:37.0466 3700 IntcDAud - ok 15:09:37.0498 3700 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 15:09:37.0498 3700 intelide - ok 15:09:37.0778 3700 [ 33FAA40B288002C89529DBD14F3AB72C ] intelkmd C:\Windows\system32\DRIVERS\igdpmd64.sys 15:09:37.0981 3700 intelkmd - ok 15:09:38.0012 3700 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 15:09:38.0012 3700 intelppm - ok 15:09:38.0044 3700 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 15:09:38.0059 3700 IPBusEnum - ok 15:09:38.0075 3700 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 15:09:38.0090 3700 IpFilterDriver - ok 15:09:38.0122 3700 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 15:09:38.0137 3700 iphlpsvc - ok 15:09:38.0153 3700 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 15:09:38.0168 3700 IPMIDRV - ok 15:09:38.0168 3700 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 15:09:38.0168 3700 IPNAT - ok 15:09:38.0200 3700 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 15:09:38.0200 3700 IRENUM - ok 15:09:38.0246 3700 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 15:09:38.0246 3700 isapnp - ok 15:09:38.0262 3700 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 15:09:38.0278 3700 iScsiPrt - ok 15:09:38.0324 3700 [ 6C85719A21B3F62C2C76280F4BD36C7B ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe 15:09:38.0324 3700 jhi_service - ok 15:09:38.0340 3700 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 15:09:38.0340 3700 kbdclass - ok 15:09:38.0371 3700 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 15:09:38.0371 3700 kbdhid - ok 15:09:38.0402 3700 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 15:09:38.0402 3700 KeyIso - ok 15:09:38.0449 3700 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 15:09:38.0449 3700 KSecDD - ok 15:09:38.0480 3700 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 15:09:38.0480 3700 KSecPkg - ok 15:09:38.0512 3700 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 15:09:38.0512 3700 ksthunk - ok 15:09:38.0558 3700 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 15:09:38.0558 3700 KtmRm - ok 15:09:38.0605 3700 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 15:09:38.0605 3700 LanmanServer - ok 15:09:38.0636 3700 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 15:09:38.0652 3700 LanmanWorkstation - ok 15:09:38.0683 3700 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 15:09:38.0683 3700 lltdio - ok 15:09:38.0714 3700 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 15:09:38.0714 3700 lltdsvc - ok 15:09:38.0746 3700 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 15:09:38.0746 3700 lmhosts - ok 15:09:38.0792 3700 [ 519D66259DF1672AABCE9D2E0ACC5552 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 15:09:38.0792 3700 LMS - ok 15:09:38.0839 3700 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 15:09:38.0839 3700 LSI_FC - ok 15:09:38.0855 3700 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 15:09:38.0855 3700 LSI_SAS - ok 15:09:38.0855 3700 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 15:09:38.0855 3700 LSI_SAS2 - ok 15:09:38.0870 3700 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 15:09:38.0870 3700 LSI_SCSI - ok 15:09:38.0902 3700 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 15:09:38.0902 3700 luafv - ok 15:09:38.0948 3700 [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 15:09:38.0948 3700 MBAMProtector - ok 15:09:38.0980 3700 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 15:09:38.0980 3700 MBAMScheduler - ok 15:09:39.0011 3700 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 15:09:39.0026 3700 MBAMService - ok 15:09:39.0104 3700 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 15:09:39.0104 3700 Mcx2Svc - ok 15:09:39.0136 3700 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 15:09:39.0136 3700 megasas - ok 15:09:39.0151 3700 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 15:09:39.0167 3700 MegaSR - ok 15:09:39.0198 3700 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 15:09:39.0198 3700 MEIx64 - ok 15:09:39.0245 3700 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 15:09:39.0245 3700 MMCSS - ok 15:09:39.0292 3700 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 15:09:39.0292 3700 Modem - ok 15:09:39.0307 3700 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 15:09:39.0307 3700 monitor - ok 15:09:39.0323 3700 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 15:09:39.0323 3700 mouclass - ok 15:09:39.0338 3700 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 15:09:39.0338 3700 mouhid - ok 15:09:39.0354 3700 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 15:09:39.0354 3700 mountmgr - ok 15:09:39.0401 3700 [ 15D5398EED42C2504BB3D4FC875C15D1 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 15:09:39.0401 3700 MozillaMaintenance - ok 15:09:39.0416 3700 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 15:09:39.0432 3700 mpio - ok 15:09:39.0448 3700 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 15:09:39.0448 3700 mpsdrv - ok 15:09:39.0494 3700 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 15:09:39.0510 3700 MpsSvc - ok 15:09:39.0526 3700 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 15:09:39.0526 3700 MRxDAV - ok 15:09:39.0541 3700 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 15:09:39.0541 3700 mrxsmb - ok 15:09:39.0557 3700 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 15:09:39.0557 3700 mrxsmb10 - ok 15:09:39.0572 3700 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 15:09:39.0572 3700 mrxsmb20 - ok 15:09:39.0588 3700 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 15:09:39.0588 3700 msahci - ok 15:09:39.0588 3700 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 15:09:39.0604 3700 msdsm - ok 15:09:39.0619 3700 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 15:09:39.0619 3700 MSDTC - ok 15:09:39.0635 3700 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 15:09:39.0635 3700 Msfs - ok 15:09:39.0650 3700 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 15:09:39.0650 3700 mshidkmdf - ok 15:09:39.0682 3700 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 15:09:39.0682 3700 msisadrv - ok 15:09:39.0713 3700 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 15:09:39.0713 3700 MSiSCSI - ok 15:09:39.0713 3700 msiserver - ok 15:09:39.0760 3700 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 15:09:39.0760 3700 MSKSSRV - ok 15:09:39.0760 3700 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 15:09:39.0760 3700 MSPCLOCK - ok 15:09:39.0775 3700 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 15:09:39.0775 3700 MSPQM - ok 15:09:39.0791 3700 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 15:09:39.0791 3700 MsRPC - ok 15:09:39.0806 3700 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 15:09:39.0806 3700 mssmbios - ok 15:09:39.0806 3700 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 15:09:39.0806 3700 MSTEE - ok 15:09:39.0822 3700 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 15:09:39.0822 3700 MTConfig - ok 15:09:39.0822 3700 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 15:09:39.0838 3700 Mup - ok 15:09:39.0869 3700 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 15:09:39.0884 3700 napagent - ok 15:09:39.0916 3700 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 15:09:39.0931 3700 NativeWifiP - ok 15:09:39.0994 3700 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 15:09:40.0009 3700 NDIS - ok 15:09:40.0040 3700 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 15:09:40.0040 3700 NdisCap - ok 15:09:40.0072 3700 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 15:09:40.0072 3700 NdisTapi - ok 15:09:40.0087 3700 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 15:09:40.0087 3700 Ndisuio - ok 15:09:40.0103 3700 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 15:09:40.0103 3700 NdisWan - ok 15:09:40.0118 3700 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 15:09:40.0118 3700 NDProxy - ok 15:09:40.0150 3700 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 15:09:40.0150 3700 NetBIOS - ok 15:09:40.0165 3700 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 15:09:40.0165 3700 NetBT - ok 15:09:40.0196 3700 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 15:09:40.0196 3700 Netlogon - ok 15:09:40.0228 3700 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 15:09:40.0243 3700 Netman - ok 15:09:40.0259 3700 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 15:09:40.0259 3700 netprofm - ok 15:09:40.0290 3700 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 15:09:40.0290 3700 NetTcpPortSharing - ok 15:09:40.0321 3700 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 15:09:40.0321 3700 nfrd960 - ok 15:09:40.0368 3700 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 15:09:40.0368 3700 NlaSvc - ok 15:09:40.0399 3700 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 15:09:40.0399 3700 Npfs - ok 15:09:40.0415 3700 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 15:09:40.0415 3700 nsi - ok 15:09:40.0446 3700 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 15:09:40.0446 3700 nsiproxy - ok 15:09:40.0508 3700 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 15:09:40.0555 3700 Ntfs - ok 15:09:40.0571 3700 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 15:09:40.0571 3700 Null - ok 15:09:40.0618 3700 [ 9A33100AC62A0463C49E47EE8E77083A ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys 15:09:40.0618 3700 nusb3hub - ok 15:09:40.0664 3700 [ 87C321F7BEE646B7EC6EEDD6EB725741 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys 15:09:40.0664 3700 nusb3xhc - ok 15:09:40.0711 3700 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys 15:09:40.0727 3700 NVENETFD - ok 15:09:40.0742 3700 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 15:09:40.0742 3700 nvraid - ok 15:09:40.0758 3700 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 15:09:40.0758 3700 nvstor - ok 15:09:40.0774 3700 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 15:09:40.0774 3700 nv_agp - ok 15:09:40.0883 3700 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 15:09:40.0883 3700 odserv - ok 15:09:40.0898 3700 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 15:09:40.0898 3700 ohci1394 - ok 15:09:40.0914 3700 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 15:09:40.0930 3700 ose - ok 15:09:40.0961 3700 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 15:09:40.0976 3700 p2pimsvc - ok 15:09:40.0992 3700 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 15:09:41.0008 3700 p2psvc - ok 15:09:41.0039 3700 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 15:09:41.0039 3700 Parport - ok 15:09:41.0054 3700 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 15:09:41.0070 3700 partmgr - ok 15:09:41.0086 3700 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 15:09:41.0086 3700 PcaSvc - ok 15:09:41.0117 3700 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 15:09:41.0117 3700 pci - ok 15:09:41.0148 3700 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 15:09:41.0148 3700 pciide - ok 15:09:41.0164 3700 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 15:09:41.0164 3700 pcmcia - ok 15:09:41.0164 3700 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 15:09:41.0179 3700 pcw - ok 15:09:41.0195 3700 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 15:09:41.0210 3700 PEAUTH - ok 15:09:41.0288 3700 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 15:09:41.0304 3700 PerfHost - ok 15:09:41.0366 3700 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 15:09:41.0398 3700 pla - ok 15:09:41.0460 3700 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 15:09:41.0476 3700 PlugPlay - ok 15:09:41.0491 3700 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 15:09:41.0491 3700 PNRPAutoReg - ok 15:09:41.0522 3700 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 15:09:41.0538 3700 PNRPsvc - ok 15:09:41.0569 3700 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 15:09:41.0585 3700 PolicyAgent - ok 15:09:41.0616 3700 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 15:09:41.0616 3700 Power - ok 15:09:41.0647 3700 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 15:09:41.0663 3700 PptpMiniport - ok 15:09:41.0678 3700 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 15:09:41.0678 3700 Processor - ok 15:09:41.0710 3700 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 15:09:41.0710 3700 ProfSvc - ok 15:09:41.0725 3700 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 15:09:41.0741 3700 ProtectedStorage - ok 15:09:41.0756 3700 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 15:09:41.0772 3700 Psched - ok 15:09:41.0834 3700 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 15:09:41.0866 3700 ql2300 - ok 15:09:41.0897 3700 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 15:09:41.0897 3700 ql40xx - ok 15:09:41.0928 3700 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 15:09:41.0928 3700 QWAVE - ok 15:09:41.0959 3700 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 15:09:41.0959 3700 QWAVEdrv - ok 15:09:41.0975 3700 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 15:09:41.0975 3700 RasAcd - ok 15:09:42.0022 3700 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 15:09:42.0022 3700 RasAgileVpn - ok 15:09:42.0037 3700 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 15:09:42.0053 3700 RasAuto - ok 15:09:42.0068 3700 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 15:09:42.0068 3700 Rasl2tp - ok 15:09:42.0084 3700 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 15:09:42.0100 3700 RasMan - ok 15:09:42.0100 3700 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 15:09:42.0100 3700 RasPppoe - ok 15:09:42.0115 3700 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 15:09:42.0131 3700 RasSstp - ok 15:09:42.0146 3700 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 15:09:42.0162 3700 rdbss - ok 15:09:42.0178 3700 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 15:09:42.0178 3700 rdpbus - ok 15:09:42.0193 3700 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 15:09:42.0193 3700 RDPCDD - ok 15:09:42.0209 3700 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 15:09:42.0209 3700 RDPENCDD - ok 15:09:42.0224 3700 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 15:09:42.0224 3700 RDPREFMP - ok 15:09:42.0256 3700 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 15:09:42.0271 3700 RDPWD - ok 15:09:42.0271 3700 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 15:09:42.0287 3700 rdyboost - ok 15:09:42.0318 3700 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 15:09:42.0334 3700 RemoteAccess - ok 15:09:42.0349 3700 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 15:09:42.0365 3700 RemoteRegistry - ok 15:09:42.0380 3700 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 15:09:42.0380 3700 RpcEptMapper - ok 15:09:42.0412 3700 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 15:09:42.0412 3700 RpcLocator - ok 15:09:42.0443 3700 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 15:09:42.0443 3700 RpcSs - ok 15:09:42.0505 3700 [ 1F5E7AF59B390261A85F5BEDB1BB88B3 ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys 15:09:42.0505 3700 RSPCIESTOR - ok 15:09:42.0552 3700 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 15:09:42.0568 3700 rspndr - ok 15:09:42.0614 3700 [ ED5873F7DFB2F96D37F13322211B6BDC ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 15:09:42.0614 3700 RTL8167 - ok 15:09:42.0692 3700 [ F33E70E48A54A7A1BFBEEB4F3B273E4A ] RTL8192Ce C:\Windows\system32\DRIVERS\rtl8192Ce.sys 15:09:42.0708 3700 RTL8192Ce - ok 15:09:42.0724 3700 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 15:09:42.0739 3700 SamSs - ok 15:09:42.0770 3700 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 15:09:42.0770 3700 sbp2port - ok 15:09:42.0786 3700 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 15:09:42.0802 3700 SCardSvr - ok 15:09:42.0817 3700 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 15:09:42.0817 3700 scfilter - ok 15:09:42.0864 3700 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 15:09:42.0880 3700 Schedule - ok 15:09:42.0926 3700 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 15:09:42.0926 3700 SCPolicySvc - ok 15:09:42.0942 3700 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 15:09:42.0958 3700 sdbus - ok 15:09:42.0973 3700 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 15:09:42.0989 3700 SDRSVC - ok 15:09:43.0036 3700 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 15:09:43.0036 3700 secdrv - ok 15:09:43.0051 3700 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 15:09:43.0051 3700 seclogon - ok 15:09:43.0067 3700 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 15:09:43.0082 3700 SENS - ok 15:09:43.0098 3700 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 15:09:43.0098 3700 SensrSvc - ok 15:09:43.0129 3700 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 15:09:43.0145 3700 Serenum - ok 15:09:43.0160 3700 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 15:09:43.0176 3700 Serial - ok 15:09:43.0192 3700 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 15:09:43.0192 3700 sermouse - ok 15:09:43.0223 3700 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 15:09:43.0223 3700 SessionEnv - ok 15:09:43.0254 3700 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 15:09:43.0254 3700 sffdisk - ok 15:09:43.0254 3700 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 15:09:43.0254 3700 sffp_mmc - ok 15:09:43.0270 3700 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 15:09:43.0270 3700 sffp_sd - ok 15:09:43.0270 3700 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 15:09:43.0270 3700 sfloppy - ok 15:09:43.0301 3700 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 15:09:43.0316 3700 SharedAccess - ok 15:09:43.0348 3700 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 15:09:43.0348 3700 ShellHWDetection - ok 15:09:43.0379 3700 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 15:09:43.0379 3700 SiSRaid2 - ok 15:09:43.0394 3700 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 15:09:43.0394 3700 SiSRaid4 - ok 15:09:43.0472 3700 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 15:09:43.0472 3700 SkypeUpdate - ok 15:09:43.0488 3700 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 15:09:43.0504 3700 Smb - ok 15:09:43.0535 3700 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 15:09:43.0550 3700 SNMPTRAP - ok 15:09:43.0566 3700 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 15:09:43.0566 3700 spldr - ok 15:09:43.0597 3700 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 15:09:43.0613 3700 Spooler - ok 15:09:43.0722 3700 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 15:09:43.0800 3700 sppsvc - ok 15:09:43.0816 3700 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 15:09:43.0816 3700 sppuinotify - ok 15:09:43.0847 3700 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 15:09:43.0862 3700 srv - ok 15:09:43.0878 3700 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 15:09:43.0878 3700 srv2 - ok 15:09:43.0925 3700 [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS 15:09:43.0925 3700 SrvHsfHDA - ok 15:09:43.0972 3700 [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS 15:09:44.0003 3700 SrvHsfV92 - ok 15:09:44.0034 3700 [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS 15:09:44.0050 3700 SrvHsfWinac - ok 15:09:44.0065 3700 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 15:09:44.0081 3700 srvnet - ok 15:09:44.0112 3700 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys 15:09:44.0112 3700 ssadbus - ok 15:09:44.0143 3700 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys 15:09:44.0143 3700 ssadmdfl - ok 15:09:44.0159 3700 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys 15:09:44.0159 3700 ssadmdm - ok 15:09:44.0206 3700 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 15:09:44.0206 3700 SSDPSRV - ok 15:09:44.0237 3700 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 15:09:44.0237 3700 SstpSvc - ok 15:09:44.0330 3700 [ 20E27AA5BCC01C2149830C05FE22F675 ] STacSV C:\Program Files\IDT\WDM\STacSV64.exe 15:09:44.0346 3700 STacSV - ok 15:09:44.0346 3700 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 15:09:44.0346 3700 stexstor - ok 15:09:44.0393 3700 [ BEB37CE4E7456F5EFA52D783D1E06D8C ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys 15:09:44.0393 3700 STHDA - ok 15:09:44.0440 3700 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 15:09:44.0455 3700 stisvc - ok 15:09:44.0471 3700 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 15:09:44.0486 3700 swenum - ok 15:09:44.0518 3700 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 15:09:44.0533 3700 swprv - ok 15:09:44.0611 3700 [ C447977ED2A4AE9346FE3A0579A34D7C ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 15:09:44.0642 3700 SynTP - ok 15:09:44.0705 3700 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 15:09:44.0736 3700 SysMain - ok 15:09:44.0752 3700 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 15:09:44.0752 3700 TabletInputService - ok 15:09:44.0767 3700 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 15:09:44.0783 3700 TapiSrv - ok 15:09:44.0798 3700 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 15:09:44.0798 3700 TBS - ok 15:09:44.0892 3700 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys 15:09:44.0923 3700 Tcpip - ok 15:09:44.0970 3700 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 15:09:45.0001 3700 TCPIP6 - ok 15:09:45.0032 3700 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 15:09:45.0032 3700 tcpipreg - ok 15:09:45.0048 3700 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 15:09:45.0048 3700 TDPIPE - ok 15:09:45.0079 3700 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 15:09:45.0079 3700 TDTCP - ok 15:09:45.0095 3700 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 15:09:45.0095 3700 tdx - ok 15:09:45.0110 3700 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 15:09:45.0110 3700 TermDD - ok 15:09:45.0142 3700 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 15:09:45.0157 3700 TermService - ok 15:09:45.0173 3700 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 15:09:45.0173 3700 Themes - ok 15:09:45.0220 3700 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 15:09:45.0220 3700 THREADORDER - ok 15:09:45.0235 3700 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 15:09:45.0251 3700 TrkWks - ok 15:09:45.0298 3700 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 15:09:45.0298 3700 TrustedInstaller - ok 15:09:45.0313 3700 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 15:09:45.0313 3700 tssecsrv - ok 15:09:45.0344 3700 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 15:09:45.0344 3700 TsUsbFlt - ok 15:09:45.0360 3700 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 15:09:45.0360 3700 TsUsbGD - ok 15:09:45.0391 3700 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 15:09:45.0391 3700 tunnel - ok 15:09:45.0422 3700 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 15:09:45.0422 3700 uagp35 - ok 15:09:45.0454 3700 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 15:09:45.0454 3700 udfs - ok 15:09:45.0485 3700 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 15:09:45.0485 3700 UI0Detect - ok 15:09:45.0500 3700 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 15:09:45.0500 3700 uliagpkx - ok 15:09:45.0516 3700 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 15:09:45.0516 3700 umbus - ok 15:09:45.0532 3700 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 15:09:45.0532 3700 UmPass - ok 15:09:45.0672 3700 [ 1B71370AEC1115F80D9A4A209317C968 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 15:09:45.0688 3700 UNS - ok 15:09:45.0719 3700 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 15:09:45.0734 3700 upnphost - ok 15:09:45.0750 3700 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 15:09:45.0750 3700 usbccgp - ok 15:09:45.0781 3700 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 15:09:45.0781 3700 usbcir - ok 15:09:45.0781 3700 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 15:09:45.0797 3700 usbehci - ok 15:09:45.0812 3700 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\drivers\usbhub.sys 15:09:45.0828 3700 usbhub - ok 15:09:45.0844 3700 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 15:09:45.0844 3700 usbohci - ok 15:09:45.0844 3700 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys 15:09:45.0844 3700 usbprint - ok 15:09:45.0859 3700 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 15:09:45.0859 3700 USBSTOR - ok 15:09:45.0875 3700 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 15:09:45.0875 3700 usbuhci - ok 15:09:45.0906 3700 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 15:09:45.0906 3700 usbvideo - ok 15:09:45.0922 3700 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 15:09:45.0937 3700 UxSms - ok 15:09:45.0953 3700 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 15:09:45.0968 3700 VaultSvc - ok 15:09:45.0968 3700 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 15:09:45.0968 3700 vdrvroot - ok 15:09:46.0000 3700 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 15:09:46.0015 3700 vds - ok 15:09:46.0046 3700 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 15:09:46.0046 3700 vga - ok 15:09:46.0046 3700 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 15:09:46.0062 3700 VgaSave - ok 15:09:46.0062 3700 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 15:09:46.0062 3700 vhdmp - ok 15:09:46.0093 3700 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 15:09:46.0093 3700 viaide - ok 15:09:46.0124 3700 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 15:09:46.0124 3700 volmgr - ok 15:09:46.0140 3700 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 15:09:46.0140 3700 volmgrx - ok 15:09:46.0156 3700 [ DF8126BD41180351A093A3AD2FC8903B ] volsnap C:\Windows\system32\drivers\volsnap.sys 15:09:46.0171 3700 volsnap - ok 15:09:46.0187 3700 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 15:09:46.0187 3700 vsmraid - ok 15:09:46.0249 3700 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 15:09:46.0280 3700 VSS - ok 15:09:46.0312 3700 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 15:09:46.0312 3700 vwifibus - ok 15:09:46.0343 3700 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 15:09:46.0343 3700 vwififlt - ok 15:09:46.0374 3700 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 15:09:46.0390 3700 W32Time - ok 15:09:46.0405 3700 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 15:09:46.0405 3700 WacomPen - ok 15:09:46.0436 3700 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 15:09:46.0452 3700 WANARP - ok 15:09:46.0452 3700 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 15:09:46.0452 3700 Wanarpv6 - ok 15:09:46.0514 3700 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 15:09:46.0546 3700 wbengine - ok 15:09:46.0577 3700 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 15:09:46.0577 3700 WbioSrvc - ok 15:09:46.0592 3700 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 15:09:46.0608 3700 wcncsvc - ok 15:09:46.0624 3700 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 15:09:46.0639 3700 WcsPlugInService - ok 15:09:46.0655 3700 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 15:09:46.0655 3700 Wd - ok 15:09:46.0686 3700 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 15:09:46.0702 3700 Wdf01000 - ok 15:09:46.0717 3700 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 15:09:46.0733 3700 WdiServiceHost - ok 15:09:46.0733 3700 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 15:09:46.0748 3700 WdiSystemHost - ok 15:09:46.0764 3700 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 15:09:46.0780 3700 WebClient - ok 15:09:46.0795 3700 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 15:09:46.0811 3700 Wecsvc - ok 15:09:46.0842 3700 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 15:09:46.0842 3700 wercplsupport - ok 15:09:46.0858 3700 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 15:09:46.0873 3700 WerSvc - ok 15:09:46.0889 3700 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 15:09:46.0889 3700 WfpLwf - ok 15:09:46.0904 3700 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 15:09:46.0904 3700 WIMMount - ok 15:09:46.0936 3700 WinDefend - ok 15:09:46.0951 3700 WinHttpAutoProxySvc - ok 15:09:47.0014 3700 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 15:09:47.0014 3700 Winmgmt - ok 15:09:47.0107 3700 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 15:09:47.0138 3700 WinRM - ok 15:09:47.0201 3700 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys 15:09:47.0201 3700 WinUsb - ok 15:09:47.0248 3700 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 15:09:47.0279 3700 Wlansvc - ok 15:09:47.0326 3700 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 15:09:47.0326 3700 wlcrasvc - ok 15:09:47.0435 3700 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 15:09:47.0450 3700 wlidsvc - ok 15:09:47.0482 3700 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 15:09:47.0482 3700 WmiAcpi - ok 15:09:47.0528 3700 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 15:09:47.0528 3700 wmiApSrv - ok 15:09:47.0575 3700 WMPNetworkSvc - ok 15:09:47.0606 3700 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 15:09:47.0606 3700 WPCSvc - ok 15:09:47.0638 3700 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 15:09:47.0638 3700 WPDBusEnum - ok 15:09:47.0653 3700 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 15:09:47.0653 3700 ws2ifsl - ok 15:09:47.0669 3700 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 15:09:47.0684 3700 wscsvc - ok 15:09:47.0684 3700 WSearch - ok 15:09:47.0794 3700 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 15:09:47.0840 3700 wuauserv - ok 15:09:47.0856 3700 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 15:09:47.0856 3700 WudfPf - ok 15:09:47.0872 3700 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 15:09:47.0872 3700 WUDFRd - ok 15:09:47.0887 3700 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 15:09:47.0903 3700 wudfsvc - ok 15:09:47.0918 3700 [ CE8CF9DE9CBFDAA318BD04D8BE3FCADA ] WwanSvc C:\Windows\System32\wwansvc.dll 15:09:47.0934 3700 WwanSvc - ok 15:09:47.0950 3700 ================ Scan global =============================== 15:09:47.0965 3700 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 15:09:47.0996 3700 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll 15:09:48.0012 3700 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll 15:09:48.0043 3700 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 15:09:48.0059 3700 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 15:09:48.0074 3700 [Global] - ok 15:09:48.0074 3700 ================ Scan MBR ================================== 15:09:48.0090 3700 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 15:09:48.0262 3700 \Device\Harddisk0\DR0 - ok 15:09:48.0277 3700 [ 2224EFB038DD4AD5AA83C96CCCA800DF ] \Device\Harddisk1\DR2 15:09:51.0896 3700 \Device\Harddisk1\DR2 - ok 15:09:51.0896 3700 ================ Scan VBR ================================== 15:09:51.0912 3700 [ 781F484C2DF434801AFBA090F9DBAB94 ] \Device\Harddisk0\DR0\Partition1 15:09:51.0912 3700 \Device\Harddisk0\DR0\Partition1 - ok 15:09:51.0943 3700 [ CEADE0837393544D0366ADEB321AE874 ] \Device\Harddisk0\DR0\Partition2 15:09:51.0943 3700 \Device\Harddisk0\DR0\Partition2 - ok 15:09:51.0974 3700 [ 231E7E31CEB0491090DE4C727387430A ] \Device\Harddisk0\DR0\Partition3 15:09:51.0974 3700 \Device\Harddisk0\DR0\Partition3 - ok 15:09:51.0990 3700 [ EDCD24EA88EED1474AE06F500B3E1D9C ] \Device\Harddisk0\DR0\Partition4 15:09:51.0990 3700 \Device\Harddisk0\DR0\Partition4 - ok 15:09:51.0990 3700 ============================================================ 15:09:51.0990 3700 Scan finished 15:09:51.0990 3700 ============================================================ 15:09:52.0021 5748 Detected object count: 0 15:09:52.0021 5748 Actual detected object count: 0 |
Servus, bitte genau lesen... wenn ich schreibe, das Tool xy vom Desktop starten, dann mein ich das auch so... Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
|
AVIRA hat den Zugriff auf die Registry gestoppt :-( Ich dachte eigentlich ich hätte alle Dienste bei AVIRA gestoppt. Combofix Logfile: Code: ComboFix 12-10-14.03 - Christian 14.10.2012 16:06:01.1.8 - x64 |
Servus, ComboFix hat Reste der Malware entfernt. :) So geht es weiter: Schritt 1
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck
Bitte poste mit deiner nächsten Antwort
|
Schritt 1: Malwarebytes Anti-Malware (Test) 1.65.0.1400 Malwarebytes : Free anti-malware download Datenbank Version: v2012.10.14.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Christian :: CHRISTIAN-HP [Administrator] Schutz: Deaktiviert 14.10.2012 17:23:44 mbam-log-2012-10-14 (17-23-44).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 358944 Laufzeit: 28 Minute(n), 51 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Schritt2 C:\Documents and Settings\Christian_2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QRHQA47R\0913a[1].pdf JS/Exploit.Pdfka.PTB trojan C:\Users\Christian_2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QRHQA47R\0913a[1].pdf JS/Exploit.Pdfka.PTB trojan Schritt 3 Security Check Results of screen317's Security Check version 0.99.51 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.65.0.1400 JavaFX 2.1.1 Java(TM) 7 Update 5 Java version out of Date! Adobe Flash Player 11.4.402.287 Adobe Reader X (10.1.4) Mozilla Firefox 13.0.1 Firefox out of Date! Google Chrome 21.0.1180.83 Google Chrome 21.0.1180.89 Google Chrome 22.0.1229.79 Google Chrome 22.0.1229.92 Google Chrome 22.0.1229.94 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Servus, tut mir Leid, hab dein Thema übersehen. :wtf: Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1
Code: :Commands
Schritt 2 Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Schritt 3
Prüfe bitte auch (regelmässig) ob folgende Links fehlende Updates bei deinen Plugins zeigen: Schritt 4 Starte DeFogger und klicke auf Re-enable. Gegebenenfalls muss dein Rechner neu gestartet werden. Schritt 5 Ich würde dir empfehlen, 1 mal pro Woche auch mit diesem Scanner dein System zu prüfen. Möchtest Du ESET denoch deinstallieren, Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster. Code: "%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\OnlineScannerUninstaller.exe" Schritt 6 Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren. Windows-Taste + R drücke. Kopiere nun folgende Zeile in die Kommandozeile und klicke OK. Code: Combofix /Uninstall Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch aus dieser die Schädlinge verschwinden. Nun die eben deaktivierten Programme wieder aktivieren. Schritt 7 Starte bitte OTL und klicke auf Bereinigung. Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen. Schritt 8 Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich diesen Thread aus meinen Abos löschen kann. |
Hi Matthias, kein Problem, mache ich am Wochenende, ist ja doch einiges zu tun. Aber was ist mit dem Ergebnis von Schritt 2? Das verwirrt mich noch ein wenig. Schritt2 C:\Documents and Settings\Christian_2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QRHQA47R\0913a[1].pdf JS/Exploit.Pdfka.PTB trojan C:\Users\Christian_2\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QRHQA47R\0913a[1].pdf JS/Exploit.Pdfka.PTB trojan |
Servus, das erledigt OTL, wenn du Schritt 1 meiner letzten Antwort ausführst. ;) Die abschließende Bereinigung und die Updates werden nicht lange dauern. :) Ich bin froh, dass wir helfen konnten :abklatsch: Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Ich danke Dir recht herzlich! :daumenhoc Schritt 1 All processes killed ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Christian ->Temp folder emptied: 768032330 bytes ->Temporary Internet Files folder emptied: 8917494 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 100850580 bytes User: Christian_2 ->Temp folder emptied: 116926 bytes ->Temporary Internet Files folder emptied: 478775280 bytes ->Java cache emptied: 12637250 bytes ->FireFox cache emptied: 65659117 bytes ->Google Chrome cache emptied: 13402882 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1940 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.381,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10192012_180708 [QUOTE=sabine78;940892]Ich danke Dir recht herzlich! :daumenhoc Schritt 1 All processes killed ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Christian ->Temp folder emptied: 768032330 bytes ->Temporary Internet Files folder emptied: 8917494 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 100850580 bytes User: Christian_2 ->Temp folder emptied: 116926 bytes ->Temporary Internet Files folder emptied: 478775280 bytes ->Java cache emptied: 12637250 bytes ->FireFox cache emptied: 65659117 bytes ->Google Chrome cache emptied: 13402882 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1940 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.381,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10192012_180708 Files\Folders moved on Reboot... C:\Users\Christian\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Christian_2\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Alle Zeitangaben in WEZ +1. Es ist jetzt 08:28 Uhr. |
Copyright ©2000-2025, Trojaner-Board