FRST.txt-Teil 2 Code:
C:\WINDOWS\system32\qedit.dll
2016-03-05 13:34 - 2016-01-05 02:45 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-03-05 13:34 - 2016-01-05 02:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2016-03-05 13:34 - 2016-01-05 02:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-03-05 13:34 - 2016-01-05 02:43 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-03-05 13:34 - 2016-01-05 02:41 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-03-05 13:34 - 2016-01-05 02:41 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-03-05 13:34 - 2016-01-05 02:40 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-03-05 13:34 - 2016-01-05 02:40 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2016-03-05 13:34 - 2016-01-05 02:39 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-03-05 13:34 - 2016-01-05 02:39 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-03-05 13:34 - 2016-01-05 02:39 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-03-05 13:34 - 2016-01-05 02:38 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-03-05 13:34 - 2016-01-05 02:36 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-03-05 13:34 - 2016-01-05 02:36 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-03-05 13:34 - 2015-12-07 05:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-03-05 13:34 - 2015-12-07 05:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-03-05 13:34 - 2015-12-07 05:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-03-05 13:34 - 2015-12-07 05:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2016-03-05 13:34 - 2015-12-07 05:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2016-03-05 13:34 - 2015-12-07 05:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2016-03-05 13:34 - 2015-12-07 05:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-03-05 13:34 - 2015-12-07 05:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-03-05 13:34 - 2015-12-07 05:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-03-05 13:34 - 2015-12-07 05:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-03-05 13:34 - 2015-12-07 05:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-03-05 13:34 - 2015-12-07 05:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-03-05 13:34 - 2015-12-07 05:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-03-05 13:34 - 2015-12-07 05:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-03-05 13:34 - 2015-12-07 05:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-03-05 13:34 - 2015-12-07 05:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-03-05 13:34 - 2015-12-07 05:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-03-05 13:34 - 2015-12-07 05:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-03-05 13:34 - 2015-12-07 05:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-03-05 13:34 - 2015-12-07 05:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-03-05 13:34 - 2015-12-07 05:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2016-03-05 13:34 - 2015-12-07 04:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-03-05 13:34 - 2015-12-07 04:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-03-05 13:34 - 2015-12-07 04:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-03-05 13:34 - 2015-12-07 04:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-03-05 13:34 - 2015-12-07 04:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-03-05 13:34 - 2015-12-07 04:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-03-05 13:34 - 2015-12-07 04:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-03-05 13:34 - 2015-12-07 04:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-03-05 13:34 - 2015-12-07 04:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-03-05 13:34 - 2015-12-07 04:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-03-05 13:34 - 2015-12-07 04:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-03-05 13:34 - 2015-12-07 04:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2016-03-05 13:34 - 2015-12-07 04:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2016-03-05 13:34 - 2015-11-24 11:26 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-03-05 13:34 - 2015-11-24 10:37 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2016-03-05 13:34 - 2015-11-24 10:26 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-03-05 13:34 - 2015-11-24 10:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-03-05 13:34 - 2015-11-24 10:12 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2016-03-05 13:34 - 2015-11-24 09:52 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-03-05 13:34 - 2015-11-24 09:14 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2016-03-05 13:34 - 2015-11-24 08:59 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-03-05 13:34 - 2015-11-24 08:04 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-03-05 13:34 - 2015-11-22 11:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-03-05 13:34 - 2015-11-22 11:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2016-03-05 13:34 - 2015-11-22 11:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2016-03-05 13:34 - 2015-11-22 11:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-03-05 13:34 - 2015-11-22 11:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-03-05 13:34 - 2015-11-22 11:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-03-05 13:34 - 2015-11-22 11:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2016-03-05 13:34 - 2015-11-22 10:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-03-05 13:34 - 2015-11-22 10:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-03-05 13:34 - 2015-11-22 10:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2016-03-05 13:34 - 2015-11-22 10:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2016-03-05 13:34 - 2015-11-22 10:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-03-05 13:34 - 2015-11-22 10:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2016-03-05 13:34 - 2015-11-22 10:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2016-03-05 13:34 - 2015-11-22 10:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-03-05 13:34 - 2015-11-22 10:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-03-05 13:34 - 2015-11-22 10:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2016-03-05 13:34 - 2015-11-22 10:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-03-05 13:34 - 2015-11-22 10:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-03-05 13:34 - 2015-11-22 10:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-03-05 13:34 - 2015-11-22 10:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-03-05 13:34 - 2015-11-22 10:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2016-03-05 13:34 - 2015-11-22 10:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-03-05 13:34 - 2015-11-22 10:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-03-05 13:34 - 2015-11-22 10:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-03-05 13:34 - 2015-11-22 10:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-03-05 13:34 - 2015-11-22 10:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2016-03-05 13:34 - 2015-11-22 10:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-03-05 13:34 - 2015-11-22 10:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-03-05 13:34 - 2015-11-22 10:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-03-05 13:34 - 2015-11-22 10:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-03-05 13:34 - 2015-11-21 06:44 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-03-05 13:34 - 2015-11-13 07:55 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2016-03-05 13:34 - 2015-11-13 07:51 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2016-03-05 13:34 - 2015-11-13 07:51 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2016-03-05 13:34 - 2015-11-13 07:51 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-03-05 13:34 - 2015-11-13 07:43 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2016-03-05 13:34 - 2015-11-13 07:43 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-03-05 13:34 - 2015-11-13 07:42 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-03-05 13:34 - 2015-11-13 07:42 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-03-05 13:34 - 2015-11-13 07:33 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2016-03-05 13:34 - 2015-11-13 07:33 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2016-03-05 13:34 - 2015-11-13 07:33 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-03-05 13:34 - 2015-11-13 07:32 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-03-05 13:34 - 2015-11-13 07:21 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-03-05 13:34 - 2015-11-13 07:21 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2016-03-05 13:34 - 2015-11-13 07:21 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2016-03-05 13:34 - 2015-11-13 07:21 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-03-05 13:34 - 2015-11-13 07:09 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2016-03-05 13:34 - 2015-11-13 06:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2016-03-05 13:34 - 2015-11-13 06:57 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-03-05 13:34 - 2015-11-05 13:05 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2016-03-05 13:34 - 2015-11-05 11:25 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-03-05 13:34 - 2015-11-05 10:10 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-03-05 13:34 - 2015-11-05 09:15 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-03-05 13:33 - 2016-02-23 10:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-05 13:33 - 2016-02-23 10:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-05 13:33 - 2016-02-23 10:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-03-05 13:33 - 2016-02-23 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-03-05 13:33 - 2016-02-23 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-03-05 13:33 - 2016-02-23 09:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2016-03-05 13:33 - 2016-02-23 09:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2016-03-05 13:33 - 2016-02-23 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-03-05 13:33 - 2016-02-23 09:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-05 13:33 - 2016-02-23 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-03-05 13:33 - 2016-02-23 09:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-03-05 13:33 - 2016-02-23 09:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-03-05 13:33 - 2016-02-23 09:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-03-05 13:33 - 2016-02-23 08:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-05 13:33 - 2016-02-23 08:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2016-03-05 13:33 - 2016-02-23 08:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-05 13:33 - 2016-02-23 08:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-03-05 13:33 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-03-05 13:33 - 2016-01-27 05:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-03-05 13:33 - 2016-01-16 06:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-03-05 13:33 - 2016-01-16 06:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-03-05 13:33 - 2016-01-16 06:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-03-05 13:33 - 2016-01-16 06:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-03-05 13:33 - 2016-01-16 06:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-03-05 13:33 - 2016-01-16 06:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-03-05 13:33 - 2016-01-16 06:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-03-05 13:33 - 2016-01-16 06:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-03-05 13:33 - 2016-01-16 06:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-03-05 13:33 - 2016-01-16 06:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-03-05 13:33 - 2016-01-05 02:52 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-03-05 13:33 - 2016-01-05 02:51 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-03-05 13:33 - 2016-01-05 02:51 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-03-05 13:33 - 2016-01-05 02:49 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-03-05 13:33 - 2016-01-05 02:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-03-05 13:33 - 2015-12-07 05:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-03-05 13:33 - 2015-12-07 05:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-03-05 13:33 - 2015-12-07 05:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-03-05 13:33 - 2015-12-07 05:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-03-05 13:33 - 2015-12-07 05:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
2016-03-05 13:33 - 2015-11-24 11:01 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-03-05 13:33 - 2015-11-24 10:54 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2016-03-05 13:33 - 2015-11-24 10:53 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-03-05 13:33 - 2015-11-24 10:45 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2016-03-05 13:33 - 2015-11-24 09:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-03-05 13:33 - 2015-11-22 11:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-03-05 13:33 - 2015-11-22 11:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-03-05 13:33 - 2015-11-22 10:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-03-05 13:33 - 2015-11-22 10:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-03-05 13:33 - 2015-11-22 10:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-03-05 13:33 - 2015-11-22 10:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-03-05 13:33 - 2015-11-22 10:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-03-05 13:33 - 2015-11-22 10:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-03-05 13:33 - 2015-11-22 10:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2016-03-05 13:33 - 2015-11-22 10:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2016-03-05 13:33 - 2015-11-22 10:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-03-05 13:33 - 2015-11-22 10:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-03-05 13:33 - 2015-11-22 10:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-03-05 13:33 - 2015-11-22 10:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-03-05 13:33 - 2015-11-22 10:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2016-03-05 13:33 - 2015-11-22 10:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-03-05 13:33 - 2015-11-22 10:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-03-05 13:33 - 2015-11-22 10:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-03-05 13:33 - 2015-11-22 10:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-03-05 13:33 - 2015-11-22 10:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2016-03-05 13:33 - 2015-11-22 10:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-03-05 13:33 - 2015-11-22 10:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2016-03-05 13:33 - 2015-11-22 10:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-03-05 13:33 - 2015-11-22 10:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-03-05 13:33 - 2015-11-22 10:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-03-05 13:33 - 2015-11-22 10:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2016-03-05 13:33 - 2015-11-22 10:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2016-03-05 13:33 - 2015-11-22 10:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-03-05 13:33 - 2015-11-22 10:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-03-05 13:33 - 2015-11-22 10:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-03-05 13:33 - 2015-11-22 10:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2016-03-05 13:33 - 2015-11-22 10:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-03-05 13:33 - 2015-11-22 10:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-03-05 13:33 - 2015-11-22 10:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-03-05 13:33 - 2015-11-22 10:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2016-03-05 13:33 - 2015-11-22 10:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2016-03-05 13:33 - 2015-11-22 10:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-03-05 13:33 - 2015-11-22 10:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-03-05 13:33 - 2015-11-22 10:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-03-05 13:33 - 2015-11-22 10:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-03-05 13:33 - 2015-11-22 10:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-03-05 13:33 - 2015-11-22 10:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2016-03-05 13:33 - 2015-11-13 07:07 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-03-05 13:33 - 2015-11-13 07:06 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-03-05 13:33 - 2015-11-13 07:05 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-03-05 13:33 - 2015-11-13 07:05 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-03-05 13:33 - 2015-11-13 07:05 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-03-05 13:33 - 2015-11-13 07:05 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2016-03-05 13:33 - 2015-11-13 07:04 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-03-05 13:33 - 2015-11-13 07:04 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-03-05 13:33 - 2015-11-13 07:03 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2016-03-05 13:33 - 2015-11-13 07:00 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-03-05 13:33 - 2015-11-13 06:56 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-03-05 13:33 - 2015-11-13 06:40 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2016-03-05 13:33 - 2015-11-13 06:34 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2016-03-05 13:33 - 2015-11-13 06:30 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-03-05 13:33 - 2015-11-05 11:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2016-03-05 13:33 - 2015-11-05 11:08 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2016-03-05 13:33 - 2015-11-05 10:03 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2016-03-05 13:33 - 2015-11-05 10:02 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 32420536 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 31495336 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumdim32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 29092864 _____ (Intel Corporation) C:\WINDOWS\system32\common_clang64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 27346568 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd11dxva32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 26071248 _____ (Intel Corporation) C:\WINDOWS\system32\igd11dxva64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 19852800 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\common_clang32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 15335848 _____ (Intel Corporation) C:\WINDOWS\system32\igc64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 14419416 _____ (Intel Corporation) C:\WINDOWS\system32\igd10iumd64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 13467648 _____ (Intel Corporation) C:\WINDOWS\system32\ig8icd64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 13326392 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igc32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 11731000 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10iumd32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 10210816 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig8icd32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 07876072 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2016-03-04 23:48 - 2016-03-04 23:48 - 06536480 _____ (Intel Corporation) C:\WINDOWS\system32\igdusc64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 05799386 _____ C:\WINDOWS\system32\igdclbif.bin
2016-03-04 23:48 - 2016-03-04 23:48 - 05677056 _____ (Intel Corporation) C:\WINDOWS\system32\igdmcl64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 05254144 _____ (Intel Corporation) C:\WINDOWS\system32\GfxResources.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 05003944 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdusc32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 04634112 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 04163072 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 04146264 _____ (Intel Corporation) C:\WINDOWS\system32\igd12umd64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 04018456 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd12umd32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 03961344 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmcl32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 02813952 _____ C:\WINDOWS\system32\iglhxa64.cpa
2016-03-04 23:48 - 2016-03-04 23:48 - 02133168 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 02062336 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 01792376 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 01789752 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 01654712 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 01568256 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 01159168 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 01018344 _____ C:\WINDOWS\system32\igfxSDK.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00955368 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00951784 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00826090 _____ C:\WINDOWS\system32\DisplayAudiox64.cab
2016-03-04 23:48 - 2016-03-04 23:48 - 00742400 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00641530 _____ C:\WINDOWS\system32\FilmModeDetection.wmv
2016-03-04 23:48 - 2016-03-04 23:48 - 00624128 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00614376 _____ (Intel Corporation) C:\WINDOWS\system32\IntelCpHDCPSvc.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00527848 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00511260 _____ C:\WINDOWS\system32\cp_resources.bin
2016-03-04 23:48 - 2016-03-04 23:48 - 00458216 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00430592 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00422552 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00421464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00407552 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00403671 _____ C:\WINDOWS\system32\ImageStabilization.wmv
2016-03-04 23:48 - 2016-03-04 23:48 - 00394216 _____ C:\WINDOWS\system32\igfxTray.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00381440 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00379904 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00378368 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00375173 _____ C:\WINDOWS\system32\ColorImageEnhancement.wmv
2016-03-04 23:48 - 2016-03-04 23:48 - 00369944 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00367832 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00365032 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00346088 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00341488 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCComp64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00309752 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00301392 _____ (Intel Corporation) C:\WINDOWS\system32\igd10idpp64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00292840 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00285856 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10idpp32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00264704 _____ C:\WINDOWS\system32\igfxCPL.cpl
2016-03-04 23:48 - 2016-03-04 23:48 - 00260584 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00257536 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00246776 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00231312 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00228328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00223720 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00223208 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00216576 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00212072 _____ (Intel Corporation) C:\WINDOWS\system32\igdde64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00198144 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4364.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00194872 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00184320 _____ (Intel Corporation) C:\WINDOWS\system32\igdail64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00171024 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdde32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00166376 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-03-04 23:48 - 2016-03-04 23:48 - 00164352 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdail32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00102912 _____ ( ) C:\WINDOWS\system32\igfxSDKLibv2_0.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00095232 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00094720 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00092160 _____ ( ) C:\WINDOWS\system32\igfxSDKLib.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00091128 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00086528 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00075776 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00045952 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00044024 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00041296 _____ C:\WINDOWS\system32\iglhxc64_dev.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00040931 _____ C:\WINDOWS\system32\iglhxo64_dev.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00040343 _____ C:\WINDOWS\system32\iglhxo64.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00040316 _____ C:\WINDOWS\system32\iglhxc64.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00039798 _____ C:\WINDOWS\system32\iglhxg64_dev.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00039658 _____ C:\WINDOWS\system32\iglhxg64.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00020480 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00020480 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00018944 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00018936 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00013824 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00013824 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00004826 _____ C:\WINDOWS\system32\iglhxs64.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00001125 _____ C:\WINDOWS\system32\iglhxa64.vp
2016-03-04 23:48 - 2016-03-04 23:48 - 00000935 _____ C:\WINDOWS\system32\Gfxv4_0.exe.config
2016-03-04 23:48 - 2016-03-04 23:48 - 00000935 _____ C:\WINDOWS\system32\DPTopologyApp.exe.config
2016-03-04 23:48 - 2016-03-04 23:48 - 00000895 _____ C:\WINDOWS\system32\Gfxv2_0.exe.config
2016-03-04 23:48 - 2016-03-04 23:48 - 00000895 _____ C:\WINDOWS\system32\DPTopologyAppv2_0.exe.config
2016-03-04 20:36 - 2016-03-04 20:36 - 00122160 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudbus.sys
2016-03-04 20:36 - 2016-03-04 20:36 - 00057648 _____ (QUALCOMM Incorporated) C:\WINDOWS\system32\Drivers\ssudqcfilter.sys
2016-03-04 20:03 - 2016-03-04 20:03 - 05062384 _____ (Realtek semiconductor) C:\WINDOWS\RTFTrack.exe
2016-03-04 20:03 - 2016-03-04 20:03 - 03069680 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\rtsuvc.sys
2016-03-04 20:03 - 2016-03-04 20:03 - 02637552 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtCamU64.exe
2016-03-04 20:03 - 2016-03-04 20:03 - 01982192 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsDecode.dll
2016-03-04 20:03 - 2016-03-04 20:03 - 01157563 _____ C:\WINDOWS\FTDataP.xml
2016-03-04 20:03 - 2016-03-04 20:03 - 00946032 _____ C:\WINDOWS\FTData.xml
2016-03-04 20:03 - 2016-03-04 20:03 - 00817241 _____ C:\WINDOWS\FTDataR1.xml
2016-03-04 20:03 - 2016-03-04 20:03 - 00817191 _____ C:\WINDOWS\FTDataR0.xml
2016-03-04 20:03 - 2016-03-04 20:03 - 00557824 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCamX64.dll
2016-03-04 20:03 - 2016-03-04 20:03 - 00497392 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RtCamX.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 72123392 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2016-03-04 18:39 - 2016-03-04 18:39 - 07172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 07096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 06264640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
2016-03-04 18:39 - 2016-03-04 18:39 - 04589312 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2016-03-04 18:39 - 2016-03-04 18:39 - 03686140 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2016-03-04 18:39 - 2016-03-04 18:39 - 03271912 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 03233472 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 02999024 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 02988288 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 02711296 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2016-03-04 18:39 - 2016-03-04 18:39 - 02493672 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 02051704 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01967336 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01961128 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01782144 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01761024 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01592584 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 01347808 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00953728 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00745488 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00728960 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00708320 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00679712 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00679192 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00645464 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00576280 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00533904 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00447728 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00446928 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00442792 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00388840 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00363576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00358272 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00332088 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00328984 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00323240 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00311952 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00274240 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00255424 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00254400 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00253872 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00223496 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00216352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00211064 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00196712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00167728 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00153312 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00134208 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00122328 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00112512 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00086136 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00085152 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2016-03-04 18:39 - 2016-03-04 18:39 - 00025224 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2016-03-04 18:38 - 2016-03-04 18:38 - 00042328 _____ (Lenovo Corporation) C:\WINDOWS\system32\Drivers\AcpiVpc.sys
2016-03-04 18:37 - 2016-03-04 18:37 - 00376592 _____ (Intel Corporation) C:\WINDOWS\system32\ibtproppage.dll
2016-03-04 18:37 - 2016-03-04 18:37 - 00299280 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\ibtusb.sys
2016-03-04 18:37 - 2016-03-04 18:37 - 00174352 _____ (Intel Corporation) C:\WINDOWS\system32\ibtsiva.exe
2016-03-04 18:36 - 2016-03-04 18:36 - 09898752 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsCRIcon.dll
2016-03-04 18:36 - 2016-03-04 18:36 - 00525512 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\Drivers\ETD.sys
2016-03-04 18:36 - 2016-03-04 18:36 - 00310528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RtsP2Stor.sys
2016-03-04 18:36 - 2016-03-04 18:36 - 00091904 _____ (Realtek Semiconductor.) C:\WINDOWS\system32\RtCRX64.dll
2016-03-04 18:36 - 2016-03-04 18:36 - 00056008 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\ETDCoInstaller01000.dll
2016-03-04 18:32 - 2016-03-04 18:32 - 00194320 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2016-03-04 17:33 - 2016-03-04 17:33 - 00887552 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2016-03-04 17:33 - 2016-03-04 17:33 - 00084064 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-03-04 23:48 - 2015-10-30 08:18 - 00095232 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2016-03-11 01:50 - 2016-03-11 01:50 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-03-11 01:45
==================== Ende von FRST.txt ============================ Die Addtion.txt Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
durchgeführt von Vanessa (2016-03-14 21:33:53)
Gestartet von C:\Users\Vanessa\Desktop
Windows 10 Pro Version 1511 (X64) (2016-03-10 16:00:15)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-1189241312-1818108196-3406372783-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1189241312-1818108196-3406372783-503 - Limited - Disabled)
Gast (S-1-5-21-1189241312-1818108196-3406372783-501 - Limited - Disabled)
Vanessa (S-1-5-21-1189241312-1818108196-3406372783-1001 - Administrator - Enabled) => C:\Users\Vanessa
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.182 - Adobe Systems Incorporated)
ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f0aecb48-77c7-45fa-b264-ea1945fdee59}) (Version: 18.33.0 - Intel Corporation)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11105 - Realtek Semiconductor Corp.)
Mozilla Firefox 45.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 45.0 (x86 de)) (Version: 45.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0 - Mozilla)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7592 - Realtek Semiconductor Corp.)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-1189241312-1818108196-3406372783-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Vanessa\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0802E269-EDBE-4A60-9BCC-053E0292E753} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2016-03-10] (Microsoft Corporation)
Task: {EC3CABF3-5086-4ADB-88BA-2EB64855FC14} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-10] (Adobe Systems Incorporated)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-03-05 13:35 - 2016-02-23 12:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-05 13:35 - 2016-02-23 12:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-03-11 00:36 - 2016-03-11 00:37 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-03-05 13:33 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-05 13:34 - 2016-02-23 09:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-03-04 23:48 - 2016-03-04 23:48 - 00394216 _____ () C:\WINDOWS\system32\igfxTray.exe
2016-03-05 13:35 - 2016-01-05 02:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-03-05 13:34 - 2016-01-05 02:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-03-05 13:35 - 2016-01-16 06:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-03-05 13:35 - 2016-01-16 06:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-03-11 00:39 - 2016-03-11 00:39 - 10244608 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.29.13.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2016-03-11 00:36 - 2016-03-11 00:37 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-03-11 00:36 - 2016-03-11 00:38 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2016-03-10 16:32 - 2016-03-10 16:29 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-1189241312-1818108196-3406372783-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Vanessa\Downloads\landscape_nrm_1420498727-sagittarus.jpg
DNS Servers: 192.168.42.129
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{CE8AD957-6922-4BF4-A210-77B0E98118F8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{32303F9E-BC76-451C-96A5-E738D55ADCD2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{37F6BB29-3AF4-4539-ACC9-9FECB60F4E5C}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
==================== Wiederherstellungspunkte =========================
10-03-2016 16:57:40 Windows Modules Installer
11-03-2016 17:07:14 Windows Modules Installer
14-03-2016 17:40:28 Intel® PROSet/Wireless Software
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (03/14/2016 05:40:46 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (03/14/2016 05:28:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.10586.122, Zeitstempel: 0x56cbf9dd
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000ee6dc
ID des fehlerhaften Prozesses: 0x4d4
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5
Error: (03/14/2016 05:24:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.10586.122, Zeitstempel: 0x56cbf9dd
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000ee6dc
ID des fehlerhaften Prozesses: 0xb0
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5
Error: (03/14/2016 04:32:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.10586.122, Zeitstempel: 0x56cbf9dd
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000ee6dc
ID des fehlerhaften Prozesses: 0xe30
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5
Error: (03/11/2016 05:07:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (03/11/2016 02:21:58 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
Error: (03/11/2016 12:39:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-1TA3T6T)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (03/10/2016 05:56:50 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-1TA3T6T)
Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (03/10/2016 05:53:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d193
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000edfac
ID des fehlerhaften Prozesses: 0x172c
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5
Error: (03/10/2016 05:52:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NetworkUXBroker.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7f4
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d193
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000edfac
ID des fehlerhaften Prozesses: 0x1b48
Startzeit der fehlerhaften Anwendung: 0xNetworkUXBroker.exe0
Pfad der fehlerhaften Anwendung: NetworkUXBroker.exe1
Pfad des fehlerhaften Moduls: NetworkUXBroker.exe2
Berichtskennung: NetworkUXBroker.exe3
Vollständiger Name des fehlerhaften Pakets: NetworkUXBroker.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: NetworkUXBroker.exe5
Systemfehler:
=============
Error: (03/14/2016 08:42:20 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "SAMSUNG Mobile USB Remote NDIS Network Device, {9CB4147F-A930-4A43-AE28-3CE5AA9E2F52}" ist das Ereignis "74" aufgetreten.
Error: (03/14/2016 05:54:10 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (03/14/2016 05:26:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_22e785" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/14/2016 05:26:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _22e785" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/14/2016 05:26:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_22e785" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/14/2016 05:26:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_22e785" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/14/2016 05:26:03 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (03/14/2016 11:37:50 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT-AUTORITÄT)
Description: Für den Miniport "SAMSUNG Mobile USB Remote NDIS Network Device, {9CB4147F-A930-4A43-AE28-3CE5AA9E2F52}" ist das Ereignis "74" aufgetreten.
Error: (03/14/2016 12:50:33 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (03/13/2016 01:18:36 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
CodeIntegrity:
===================================
Date: 2016-03-12 03:01:14.659
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-11 12:22:34.972
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-10 19:07:11.730
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-10 18:23:05.407
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-10 16:59:07.103
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-11 01:49:18.798
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz
Prozentuale Nutzung des RAM: 45%
Installierter physikalischer RAM: 4009.84 MB
Verfügbarer physikalischer RAM: 2192.04 MB
Summe virtueller Speicher: 4713.84 MB
Verfügbarer virtueller Speicher: 2879.26 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:465.21 GB) (Free:410.27 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: D9FA2484)
Partition: GPT.
==================== Ende von Addition.txt ============================ Und die TDSS-Logdatei: Code:
21:37:32.0592 0x0e80 TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12
21:37:32.0592 0x0e80 UEFI system
21:37:37.0600 0x0e80 ============================================================
21:37:37.0600 0x0e80 Current date / time: 2016/03/14 21:37:37.0600
21:37:37.0600 0x0e80 SystemInfo:
21:37:37.0694 0x0e80
21:37:37.0694 0x0e80 OS Version: 10.0.10586 ServicePack: 0.0
21:37:37.0694 0x0e80 Product type: Workstation
21:37:37.0694 0x0e80 ComputerName: DESKTOP-1TA3T6T
21:37:37.0694 0x0e80 UserName: Vanessa
21:37:37.0694 0x0e80 Windows directory: C:\WINDOWS
21:37:37.0694 0x0e80 System windows directory: C:\WINDOWS
21:37:37.0694 0x0e80 Running under WOW64
21:37:37.0694 0x0e80 Processor architecture: Intel x64
21:37:37.0694 0x0e80 Number of processors: 4
21:37:37.0694 0x0e80 Page size: 0x1000
21:37:37.0694 0x0e80 Boot type: Normal boot
21:37:37.0694 0x0e80 ============================================================
21:37:38.0366 0x0e80 KLMD registered as C:\WINDOWS\system32\drivers\22119148.sys
21:37:39.0132 0x0e80 System UUID: {4B152735-A7DF-7255-C00A-9A62523D028D}
21:37:40.0069 0x0e80 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:37:40.0085 0x0e80 ============================================================
21:37:40.0085 0x0e80 \Device\Harddisk0\DR0:
21:37:40.0085 0x0e80 GPT partitions:
21:37:40.0085 0x0e80 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {7F1C7379-DDD8-48B8-948F-CBEB50B3A5F0}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xE1000
21:37:40.0085 0x0e80 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {99BDABCC-BCCA-407E-8C93-20FD19C233DC}, Name: EFI system partition, StartLBA 0xE1800, BlocksNum 0x32000
21:37:40.0085 0x0e80 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {048BDEA5-05DD-4BA0-8593-CCAC080996AF}, Name: Microsoft reserved partition, StartLBA 0x113800, BlocksNum 0x8000
21:37:40.0085 0x0e80 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {2327364B-11A3-4F23-9D48-F9CC9C37E440}, Name: Basic data partition, StartLBA 0x11B800, BlocksNum 0x3A26A000
21:37:40.0085 0x0e80 MBR partitions:
21:37:40.0085 0x0e80 ============================================================
21:37:40.0116 0x0e80 C: <-> \Device\Harddisk0\DR0\Partition4
21:37:40.0116 0x0e80 ============================================================
21:37:40.0116 0x0e80 Initialize success
21:37:40.0116 0x0e80 ============================================================
21:37:50.0458 0x0078 ============================================================
21:37:50.0458 0x0078 Scan started
21:37:50.0458 0x0078 Mode: Manual; SigCheck; TDLFS;
21:37:50.0458 0x0078 ============================================================
21:37:50.0458 0x0078 KSN ping started
21:37:52.0898 0x0078 KSN ping finished: true
21:37:54.0630 0x0078 ================ Scan system memory ========================
21:37:54.0630 0x0078 System memory - ok
21:37:54.0630 0x0078 ================ Scan services =============================
21:37:54.0789 0x0078 1394ohci - ok
21:37:54.0805 0x0078 3ware - ok
21:37:54.0836 0x0078 ACPI - ok
21:37:54.0867 0x0078 acpiex - ok
21:37:54.0883 0x0078 acpipagr - ok
21:37:54.0930 0x0078 AcpiPmi - ok
21:37:54.0946 0x0078 acpitime - ok
21:37:54.0992 0x0078 [ E13DE7CD2B62254DD4FF658B7798A37D, 9FCCC90DEF6BE83F8C41D4552D235A7BB5534954D2E7CB7B1C336A31FCCAB3AD ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
21:37:55.0039 0x0078 ACPIVPC - ok
21:37:55.0166 0x0078 [ 99B993BD0F4C033D832B50D5E83BEBEC, A091635B2B428A51400468353F52D3FF35095460D3FA8CB29E2C4A804D87B845 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:37:55.0181 0x0078 AdobeFlashPlayerUpdateSvc - ok
21:37:55.0244 0x0078 ADP80XX - ok
21:37:55.0275 0x0078 AFD - ok
21:37:55.0306 0x0078 agp440 - ok
21:37:55.0322 0x0078 ahcache - ok
21:37:55.0353 0x0078 AJRouter - ok
21:37:55.0369 0x0078 ALG - ok
21:37:55.0384 0x0078 AmdK8 - ok
21:37:55.0400 0x0078 AmdPPM - ok
21:37:55.0431 0x0078 amdsata - ok
21:37:55.0447 0x0078 amdsbs - ok
21:37:55.0463 0x0078 amdxata - ok
21:37:55.0478 0x0078 AppID - ok
21:37:55.0525 0x0078 AppIDSvc - ok
21:37:55.0541 0x0078 Appinfo - ok
21:37:55.0541 0x0078 AppMgmt - ok
21:37:55.0572 0x0078 AppReadiness - ok
21:37:55.0603 0x0078 AppXSvc - ok
21:37:55.0619 0x0078 arcsas - ok
21:37:55.0650 0x0078 AsyncMac - ok
21:37:55.0697 0x0078 atapi - ok
21:37:55.0759 0x0078 AudioEndpointBuilder - ok
21:37:55.0791 0x0078 Audiosrv - ok
21:37:55.0822 0x0078 AxInstSV - ok
21:37:55.0884 0x0078 b06bdrv - ok
21:37:55.0900 0x0078 BasicDisplay - ok
21:37:55.0916 0x0078 BasicRender - ok
21:37:55.0963 0x0078 bcmfn - ok
21:37:55.0978 0x0078 bcmfn2 - ok
21:37:56.0009 0x0078 BDESVC - ok
21:37:56.0041 0x0078 Beep - ok
21:37:56.0072 0x0078 BFE - ok
21:37:56.0119 0x0078 BITS - ok
21:37:56.0150 0x0078 bowser - ok
21:37:56.0197 0x0078 BrokerInfrastructure - ok
21:37:56.0244 0x0078 Browser - ok
21:37:56.0306 0x0078 BthAvrcpTg - ok
21:37:56.0353 0x0078 BthEnum - ok
21:37:56.0369 0x0078 BthHFEnum - ok
21:37:56.0400 0x0078 bthhfhid - ok
21:37:56.0431 0x0078 BthHFSrv - ok
21:37:56.0494 0x0078 BthLEEnum - ok
21:37:56.0666 0x0078 BTHMODEM - ok
21:37:56.0681 0x0078 BthPan - ok
21:37:56.0728 0x0078 BTHPORT - ok
21:37:56.0775 0x0078 bthserv - ok
21:37:56.0791 0x0078 BTHUSB - ok
21:37:56.0822 0x0078 buttonconverter - ok
21:37:56.0838 0x0078 CapImg - ok
21:37:56.0869 0x0078 cdfs - ok
21:37:56.0884 0x0078 CDPSvc - ok
21:37:56.0916 0x0078 cdrom - ok
21:37:56.0931 0x0078 CertPropSvc - ok
21:37:56.0978 0x0078 circlass - ok
21:37:56.0994 0x0078 CLFS - ok
21:37:57.0022 0x0078 ClipSVC - ok
21:37:57.0078 0x0078 CmBatt - ok
21:37:57.0094 0x0078 CNG - ok
21:37:57.0125 0x0078 cnghwassist - ok
21:37:57.0188 0x0078 CompositeBus - ok
21:37:57.0203 0x0078 COMSysApp - ok
21:37:57.0219 0x0078 condrv - ok
21:37:57.0250 0x0078 CoreMessagingRegistrar - ok
21:37:57.0345 0x0078 [ DEB6A1567D038EB73E22C076FAABE1E5, FB3503F07B4AF0FA0C4C6D78041C5AE6D86D1A94361E6B02B4ACEEC770453023 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
21:37:57.0360 0x0078 cphs - ok
21:37:57.0407 0x0078 CryptSvc - ok
21:37:57.0407 0x0078 CSC - ok
21:37:57.0423 0x0078 CscService - ok
21:37:57.0438 0x0078 dam - ok
21:37:57.0454 0x0078 DcomLaunch - ok
21:37:57.0470 0x0078 DcpSvc - ok
21:37:57.0470 0x0078 defragsvc - ok
21:37:57.0485 0x0078 DeviceAssociationService - ok
21:37:57.0501 0x0078 DeviceInstall - ok
21:37:57.0517 0x0078 DevQueryBroker - ok
21:37:57.0532 0x0078 Dfsc - ok
21:37:57.0563 0x0078 [ 85137571AEC8AC757D497B9DD30D544D, 6E15C9FB4010B26A8E5AFD4E85F7362B2616EB8503ACCE28EC31AC1E7D18566F ] dg_ssudbus C:\WINDOWS\System32\drivers\ssudbus.sys
21:37:57.0563 0x0078 dg_ssudbus - ok
21:37:57.0610 0x0078 Dhcp - ok
21:37:57.0673 0x0078 diagnosticshub.standardcollector.service - ok
21:37:57.0720 0x0078 DiagTrack - ok
21:37:57.0751 0x0078 disk - ok
21:37:57.0798 0x0078 DmEnrollmentSvc - ok
21:37:57.0845 0x0078 dmvsc - ok
21:37:57.0892 0x0078 dmwappushservice - ok
21:37:57.0954 0x0078 Dnscache - ok
21:37:57.0954 0x0078 dot3svc - ok
21:37:57.0970 0x0078 DPS - ok
21:37:58.0001 0x0078 drmkaud - ok
21:37:58.0048 0x0078 DsmSvc - ok
21:37:58.0095 0x0078 DsSvc - ok
21:37:58.0110 0x0078 DXGKrnl - ok
21:37:58.0157 0x0078 Eaphost - ok
21:37:58.0204 0x0078 ebdrv - ok
21:37:58.0238 0x0078 EFS - ok
21:37:58.0285 0x0078 EhStorClass - ok
21:37:58.0332 0x0078 EhStorTcgDrv - ok
21:37:58.0379 0x0078 embeddedmode - ok
21:37:58.0395 0x0078 EntAppSvc - ok
21:37:58.0441 0x0078 ErrDev - ok
21:37:58.0504 0x0078 [ 6BD85B39B7B23F03B24CF641ED29147B, 850F21750BB39E5239B1584E1117844CAAAF6A5C58E79366552309F917675CE5 ] ETD C:\WINDOWS\System32\drivers\ETD.sys
21:37:58.0535 0x0078 ETD - ok
21:37:58.0583 0x0078 [ 8916EACF1256E1C5A3AF81FD39C747E7, FF28FB95E9F9287C1005CF0D9EB84F7CA3D137689862860C9848398504E1EFFF ] ETDService C:\Program Files\Elantech\ETDService.exe
21:37:58.0583 0x0078 ETDService - ok
21:37:58.0614 0x0078 EventSystem - ok
21:37:58.0754 0x0078 [ 88B51CBB28513AF2E982DCE02C02A805, 9CB5EE508D753F9338E13405F7AE7D9E99BD1F2116436A0940E9626356265527 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
21:37:58.0770 0x0078 EvtEng - ok
21:37:58.0786 0x0078 exfat - ok
21:37:58.0801 0x0078 fastfat - ok
21:37:58.0823 0x0078 Fax - ok
21:37:58.0855 0x0078 fcvsc - ok
21:37:58.0870 0x0078 fdc - ok
21:37:58.0886 0x0078 fdPHost - ok
21:37:58.0901 0x0078 FDResPub - ok
21:37:58.0901 0x0078 fhsvc - ok
21:37:58.0917 0x0078 FileCrypt - ok
21:37:58.0933 0x0078 FileInfo - ok
21:37:58.0995 0x0078 Filetrace - ok
21:37:59.0027 0x0078 flpydisk - ok
21:37:59.0027 0x0078 FltMgr - ok
21:37:59.0073 0x0078 FontCache - ok
21:37:59.0167 0x0078 FontCache3.0.0.0 - ok
21:37:59.0198 0x0078 FsDepends - ok
21:37:59.0214 0x0078 Fs_Rec - ok
21:37:59.0214 0x0078 fvevol - ok
21:37:59.0261 0x0078 gagp30kx - ok
21:37:59.0293 0x0078 gencounter - ok
21:37:59.0340 0x0078 genericusbfn - ok
21:37:59.0340 0x0078 GPIOClx0101 - ok
21:37:59.0371 0x0078 gpsvc - ok
21:37:59.0386 0x0078 GpuEnergyDrv - ok
21:37:59.0402 0x0078 HDAudBus - ok
21:37:59.0433 0x0078 HidBatt - ok
21:37:59.0465 0x0078 HidBth - ok
21:37:59.0480 0x0078 hidi2c - ok
21:37:59.0512 0x0078 hidinterrupt - ok
21:37:59.0527 0x0078 HidIr - ok
21:37:59.0543 0x0078 hidserv - ok
21:37:59.0574 0x0078 HidUsb - ok
21:37:59.0636 0x0078 HomeGroupListener - ok
21:37:59.0652 0x0078 HomeGroupProvider - ok
21:37:59.0668 0x0078 HpSAMD - ok
21:37:59.0683 0x0078 HTTP - ok
21:37:59.0715 0x0078 hwpolicy - ok
21:37:59.0746 0x0078 hyperkbd - ok
21:37:59.0761 0x0078 i8042prt - ok
21:37:59.0777 0x0078 iai2c - ok
21:37:59.0824 0x0078 iaLPSS2i_I2C - ok
21:37:59.0840 0x0078 iaLPSSi_GPIO - ok
21:37:59.0840 0x0078 iaLPSSi_I2C - ok
21:37:59.0871 0x0078 iaStorAV - ok
21:37:59.0889 0x0078 iaStorV - ok
21:37:59.0920 0x0078 ibbus - ok
21:37:59.0920 0x0078 ibtsiva - ok
21:37:59.0967 0x0078 [ AA173D4202F9BFDD1C50B37550560780, B519D66406EC6CD03CAAF22F316D94541CDEBC06FF8D91D0B27BD9328C3920BA ] ibtusb C:\WINDOWS\system32\DRIVERS\ibtusb.sys
21:37:59.0998 0x0078 ibtusb - ok
21:38:00.0046 0x0078 icssvc - ok
21:38:00.0062 0x0078 IEEtwCollectorService - ok
21:38:00.0313 0x0078 [ F8AA37364D1EE0DB8ADD0F83CF7ABC7F, CAD3B65D61D12DDF071DACC25B1E0F246923851668CCF0A95F1C083CF6081A93 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
21:38:00.0469 0x0078 igfx - ok
21:38:00.0500 0x0078 [ 51837568B60B16880B943503AA443809, DB12D605A09CA61E0B95BE35D506BD93276B372458DBEAFAEB03F7F4EC94E981 ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
21:38:00.0516 0x0078 igfxCUIService2.0.0.0 - ok
21:38:00.0547 0x0078 IKEEXT - ok
21:38:00.0660 0x0078 [ 3499042E89001AE39F8FCEDE15028743, 8E4BDBEBD26E09896333A95A40302929F8747F209440593CBD94E69FF9265128 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
21:38:00.0753 0x0078 IntcAzAudAddService - ok
21:38:00.0863 0x0078 [ A38C7B403BBFD5B30F27C2D6B11AAF25, 25F0E31A9987B49224C8884F30AF85DE3B1181E20BC8C0401C0F85BAA481A7D1 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
21:38:00.0894 0x0078 IntcDAud - ok
21:38:00.0957 0x0078 intelide - ok
21:38:00.0988 0x0078 intelpep - ok
21:38:01.0003 0x0078 intelppm - ok
21:38:01.0019 0x0078 IoQos - ok
21:38:01.0050 0x0078 IpFilterDriver - ok
21:38:01.0082 0x0078 iphlpsvc - ok
21:38:01.0128 0x0078 IPMIDRV - ok
21:38:01.0160 0x0078 IPNAT - ok
21:38:01.0175 0x0078 IRENUM - ok
21:38:01.0207 0x0078 isapnp - ok
21:38:01.0222 0x0078 iScsiPrt - ok
21:38:01.0269 0x0078 kbdclass - ok
21:38:01.0285 0x0078 kbdhid - ok
21:38:01.0300 0x0078 kdnic - ok
21:38:01.0316 0x0078 KeyIso - ok
21:38:01.0332 0x0078 KSecDD - ok
21:38:01.0363 0x0078 KSecPkg - ok
21:38:01.0363 0x0078 ksthunk - ok
21:38:01.0410 0x0078 KtmRm - ok
21:38:01.0441 0x0078 LanmanServer - ok
21:38:01.0488 0x0078 LanmanWorkstation - ok
21:38:01.0535 0x0078 lfsvc - ok
21:38:01.0569 0x0078 LicenseManager - ok
21:38:01.0600 0x0078 lltdio - ok
21:38:01.0600 0x0078 lltdsvc - ok
21:38:01.0616 0x0078 lmhosts - ok
21:38:01.0663 0x0078 LSI_SAS - ok
21:38:01.0710 0x0078 LSI_SAS2i - ok
21:38:01.0819 0x0078 LSI_SAS3i - ok
21:38:01.0835 0x0078 LSI_SSS - ok
21:38:01.0866 0x0078 LSM - ok
21:38:01.0866 0x0078 luafv - ok
21:38:01.0898 0x0078 MapsBroker - ok
21:38:01.0913 0x0078 megasas - ok
21:38:01.0960 0x0078 megasr - ok
21:38:02.0007 0x0078 [ 9732602297242FFFBA9D9ED0290442F0, 27848E3497AEC52CCC36684E7CC3B8FDFF66EC4947DABF64F57ED5D4E988D9B7 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
21:38:02.0038 0x0078 MEIx64 - ok
21:38:02.0070 0x0078 MessagingService - ok
21:38:02.0148 0x0078 mlx4_bus - ok
21:38:02.0163 0x0078 MMCSS - ok
21:38:02.0179 0x0078 Modem - ok
21:38:02.0195 0x0078 monitor - ok
21:38:02.0210 0x0078 mouclass - ok
21:38:02.0226 0x0078 mouhid - ok
21:38:02.0242 0x0078 mountmgr - ok
21:38:02.0320 0x0078 [ 9EA771C01B8F99360F5BE1F732C59C3F, 69868A00F29379E822DC5A77EB4372CCAD690D2BDF10FEABB79C987527730FD5 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:38:02.0335 0x0078 MozillaMaintenance - ok
21:38:02.0351 0x0078 mpsdrv - ok
21:38:02.0382 0x0078 MpsSvc - ok
21:38:02.0398 0x0078 MRxDAV - ok
21:38:02.0414 0x0078 mrxsmb - ok
21:38:02.0429 0x0078 mrxsmb10 - ok
21:38:02.0460 0x0078 mrxsmb20 - ok
21:38:02.0460 0x0078 MsBridge - ok
21:38:02.0507 0x0078 MSDTC - ok
21:38:02.0507 0x0078 Msfs - ok
21:38:02.0570 0x0078 msgpiowin32 - ok
21:38:02.0601 0x0078 mshidkmdf - ok
21:38:02.0617 0x0078 mshidumdf - ok
21:38:02.0648 0x0078 msisadrv - ok
21:38:02.0679 0x0078 MSiSCSI - ok
21:38:02.0679 0x0078 msiserver - ok
21:38:02.0710 0x0078 MSKSSRV - ok
21:38:02.0710 0x0078 MsLldp - ok
21:38:02.0726 0x0078 MSPCLOCK - ok
21:38:02.0742 0x0078 MSPQM - ok
21:38:02.0757 0x0078 MsRPC - ok
21:38:02.0789 0x0078 mssmbios - ok
21:38:02.0789 0x0078 MSTEE - ok
21:38:02.0804 0x0078 MTConfig - ok
21:38:02.0820 0x0078 Mup - ok
21:38:02.0820 0x0078 mvumis - ok
21:38:02.0867 0x0078 [ D4700C711D03F5FF6CB38C7D55DE6222, BF553F1FCCA34431FEED3DFB101ABCDA78377570C60FFB81031B16CC745B181B ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
21:38:02.0898 0x0078 MyWiFiDHCPDNS - ok
21:38:02.0914 0x0078 NativeWifiP - ok
21:38:02.0945 0x0078 NcaSvc - ok
21:38:02.0976 0x0078 NcbService - ok
21:38:02.0976 0x0078 NcdAutoSetup - ok
21:38:03.0023 0x0078 ndfltr - ok
21:38:03.0023 0x0078 NDIS - ok
21:38:03.0023 0x0078 NdisCap - ok
21:38:03.0039 0x0078 NdisImPlatform - ok
21:38:03.0039 0x0078 NdisTapi - ok
21:38:03.0054 0x0078 Ndisuio - ok
21:38:03.0070 0x0078 NdisVirtualBus - ok
21:38:03.0085 0x0078 NdisWan - ok
21:38:03.0085 0x0078 ndiswanlegacy - ok
21:38:03.0085 0x0078 ndproxy - ok
21:38:03.0101 0x0078 Ndu - ok
21:38:03.0101 0x0078 NetBIOS - ok
21:38:03.0117 0x0078 NetBT - ok
21:38:03.0117 0x0078 Netlogon - ok
21:38:03.0164 0x0078 Netman - ok
21:38:03.0210 0x0078 netprofm - ok
21:38:03.0226 0x0078 NetSetupSvc - ok
21:38:03.0289 0x0078 NetTcpPortSharing - ok
21:38:03.0445 0x0078 [ ECCD9EACFE0FD5FF3CE509A73B8BCE52, C43A8CC5B8887D45AE66C5AB0AB46FA7F6F3D8C6C613CF3022D806EA7B74C664 ] NETwNb64 C:\WINDOWS\System32\drivers\Netwbw02.sys
21:38:03.0523 0x0078 NETwNb64 - ok
21:38:03.0585 0x0078 NgcCtnrSvc - ok
21:38:03.0601 0x0078 NgcSvc - ok
21:38:03.0664 0x0078 NlaSvc - ok
21:38:03.0679 0x0078 Npfs - ok
21:38:03.0710 0x0078 npsvctrig - ok
21:38:03.0726 0x0078 nsi - ok
21:38:03.0726 0x0078 nsiproxy - ok
21:38:03.0742 0x0078 NTFS - ok
21:38:03.0742 0x0078 Null - ok
21:38:03.0789 0x0078 nvraid - ok
21:38:03.0789 0x0078 nvstor - ok
21:38:03.0820 0x0078 nv_agp - ok
21:38:03.0867 0x0078 OneSyncSvc - ok
21:38:03.0898 0x0078 p2pimsvc - ok
21:38:03.0945 0x0078 p2psvc - ok
21:38:03.0961 0x0078 Parport - ok
21:38:03.0976 0x0078 partmgr - ok
21:38:03.0992 0x0078 PcaSvc - ok
21:38:04.0007 0x0078 pci - ok
21:38:04.0039 0x0078 pciide - ok
21:38:04.0070 0x0078 pcmcia - ok
21:38:04.0070 0x0078 pcw - ok
21:38:04.0086 0x0078 pdc - ok
21:38:04.0101 0x0078 PEAUTH - ok
21:38:04.0134 0x0078 PeerDistSvc - ok
21:38:04.0181 0x0078 percsas2i - ok
21:38:04.0181 0x0078 percsas3i - ok
21:38:04.0243 0x0078 PerfHost - ok
21:38:04.0290 0x0078 PhoneSvc - ok
21:38:04.0321 0x0078 PimIndexMaintenanceSvc - ok
21:38:04.0353 0x0078 pla - ok
21:38:04.0368 0x0078 PlugPlay - ok
21:38:04.0384 0x0078 PNRPAutoReg - ok
21:38:04.0384 0x0078 PNRPsvc - ok
21:38:04.0415 0x0078 PolicyAgent - ok
21:38:04.0415 0x0078 Power - ok
21:38:04.0431 0x0078 PptpMiniport - ok
21:38:04.0649 0x0078 [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
21:38:04.0821 0x0078 PrintNotify - ok
21:38:04.0853 0x0078 Processor - ok
21:38:04.0884 0x0078 ProfSvc - ok
21:38:04.0884 0x0078 Psched - ok
21:38:04.0899 0x0078 QWAVE - ok
21:38:04.0937 0x0078 QWAVEdrv - ok
21:38:04.0953 0x0078 RasAcd - ok
21:38:04.0968 0x0078 RasAgileVpn - ok
21:38:05.0000 0x0078 RasAuto - ok
21:38:05.0015 0x0078 Rasl2tp - ok
21:38:05.0062 0x0078 RasMan - ok
21:38:05.0062 0x0078 RasPppoe - ok
21:38:05.0078 0x0078 RasSstp - ok
21:38:05.0093 0x0078 rdbss - ok
21:38:05.0140 0x0078 rdpbus - ok
21:38:05.0140 0x0078 RDPDR - ok
21:38:05.0171 0x0078 RdpVideoMiniport - ok
21:38:05.0187 0x0078 rdyboost - ok
21:38:05.0187 0x0078 ReFSv1 - ok
21:38:05.0265 0x0078 [ 8AA2314A213BDD905A14AE9F691CA5E2, C5215CB44BF6555535ED34703445903B0C363100E3699FAFB773A4366347F710 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
21:38:05.0296 0x0078 RegSrvc - ok
21:38:05.0328 0x0078 RemoteAccess - ok
21:38:05.0343 0x0078 RemoteRegistry - ok
21:38:05.0359 0x0078 RetailDemo - ok
21:38:05.0406 0x0078 RFCOMM - ok
21:38:05.0421 0x0078 RpcEptMapper - ok
21:38:05.0437 0x0078 RpcLocator - ok
21:38:05.0453 0x0078 RpcSs - ok
21:38:05.0468 0x0078 [ 5BEBB8AFA0203EE5283C1049647F7B3C, 6B98A3965951E3BF7A098E033C7AF9F66563E71B6747BC6319519B691A471072 ] RSP2STOR C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys
21:38:05.0484 0x0078 RSP2STOR - ok
21:38:05.0515 0x0078 rspndr - ok
21:38:05.0562 0x0078 [ 923EDCF774AD0207BAFA3DC58C5DA866, 7EA642D78B530EF00809B25986EDEED2EEBECFE40F2EC04661731C4A407FF754 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
21:38:05.0578 0x0078 rt640x64 - ok
21:38:05.0687 0x0078 [ 0A7A972AADEF62F2187A6E601FF0328D, D80F5CC4F226CBB473F49834BFE510D71955EEE575005820F266A5FDB88D9C58 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
21:38:05.0750 0x0078 rtsuvc - ok
21:38:05.0781 0x0078 s3cap - ok
21:38:05.0796 0x0078 SamSs - ok
21:38:05.0843 0x0078 sbp2port - ok
21:38:05.0875 0x0078 SCardSvr - ok
21:38:05.0906 0x0078 ScDeviceEnum - ok
21:38:05.0937 0x0078 scfilter - ok
21:38:05.0953 0x0078 Schedule - ok
21:38:06.0000 0x0078 SCPolicySvc - ok
21:38:06.0015 0x0078 sdbus - ok
21:38:06.0046 0x0078 SDRSVC - ok
21:38:06.0062 0x0078 sdstor - ok
21:38:06.0093 0x0078 seclogon - ok
21:38:06.0109 0x0078 SENS - ok
21:38:06.0125 0x0078 SensorDataService - ok
21:38:06.0140 0x0078 SensorService - ok
21:38:06.0140 0x0078 SensrSvc - ok
21:38:06.0156 0x0078 SerCx - ok
21:38:06.0171 0x0078 SerCx2 - ok
21:38:06.0203 0x0078 Serenum - ok
21:38:06.0218 0x0078 Serial - ok
21:38:06.0250 0x0078 sermouse - ok
21:38:06.0281 0x0078 SessionEnv - ok
21:38:06.0312 0x0078 sfloppy - ok
21:38:06.0343 0x0078 SharedAccess - ok
21:38:06.0375 0x0078 ShellHWDetection - ok
21:38:06.0406 0x0078 SiSRaid2 - ok
21:38:06.0421 0x0078 SiSRaid4 - ok
21:38:06.0453 0x0078 smphost - ok
21:38:06.0468 0x0078 SmsRouter - ok
21:38:06.0500 0x0078 SNMPTRAP - ok
21:38:06.0546 0x0078 spaceport - ok
21:38:06.0578 0x0078 SpbCx - ok
21:38:06.0609 0x0078 Spooler - ok
21:38:06.0625 0x0078 sppsvc - ok
21:38:06.0640 0x0078 srv - ok
21:38:06.0640 0x0078 srv2 - ok
21:38:06.0656 0x0078 srvnet - ok
21:38:06.0671 0x0078 SSDPSRV - ok
21:38:06.0718 0x0078 SstpSvc - ok
21:38:06.0750 0x0078 [ 3267933B06415A5801FE888B203C2046, 8AB522EBF47294760D7F5F49034175A29E16D61481B414B6E193DB144FCA9A62 ] ssudqcfilter C:\WINDOWS\System32\drivers\ssudqcfilter.sys
21:38:06.0750 0x0078 ssudqcfilter - ok
21:38:06.0781 0x0078 StateRepository - ok
21:38:06.0828 0x0078 stexstor - ok
21:38:06.0937 0x0078 stisvc - ok
21:38:06.0968 0x0078 storahci - ok
21:38:06.0984 0x0078 storflt - ok
21:38:07.0016 0x0078 stornvme - ok
21:38:07.0016 0x0078 storqosflt - ok
21:38:07.0062 0x0078 StorSvc - ok
21:38:07.0078 0x0078 storufs - ok
21:38:07.0094 0x0078 storvsc - ok
21:38:07.0125 0x0078 svsvc - ok
21:38:07.0141 0x0078 swenum - ok
21:38:07.0156 0x0078 swprv - ok
21:38:07.0187 0x0078 Synth3dVsc - ok
21:38:07.0203 0x0078 SysMain - ok
21:38:07.0234 0x0078 SystemEventsBroker - ok
21:38:07.0234 0x0078 TabletInputService - ok
21:38:07.0234 0x0078 TapiSrv - ok
21:38:07.0297 0x0078 Tcpip - ok
21:38:07.0312 0x0078 Tcpip6 - ok
21:38:07.0312 0x0078 tcpipreg - ok
21:38:07.0359 0x0078 tdx - ok
21:38:07.0391 0x0078 terminpt - ok
21:38:07.0406 0x0078 TermService - ok
21:38:07.0437 0x0078 Themes - ok
21:38:07.0469 0x0078 TieringEngineService - ok
21:38:07.0469 0x0078 tiledatamodelsvc - ok
21:38:07.0500 0x0078 TimeBroker - ok
21:38:07.0547 0x0078 TPM - ok
21:38:07.0562 0x0078 TrkWks - ok
21:38:07.0609 0x0078 TrustedInstaller - ok
21:38:07.0625 0x0078 TsUsbFlt - ok
21:38:07.0656 0x0078 TsUsbGD - ok
21:38:07.0703 0x0078 tunnel - ok
21:38:07.0719 0x0078 tzautoupdate - ok
21:38:07.0750 0x0078 uagp35 - ok
21:38:07.0781 0x0078 UASPStor - ok
21:38:07.0797 0x0078 UcmCx0101 - ok
21:38:07.0828 0x0078 UcmUcsi - ok
21:38:07.0844 0x0078 Ucx01000 - ok
21:38:07.0859 0x0078 UdeCx - ok
21:38:07.0859 0x0078 udfs - ok
21:38:07.0875 0x0078 UEFI - ok
21:38:07.0890 0x0078 Ufx01000 - ok
21:38:07.0922 0x0078 UfxChipidea - ok
21:38:07.0937 0x0078 ufxsynopsys - ok
21:38:07.0969 0x0078 UI0Detect - ok
21:38:08.0000 0x0078 uliagpkx - ok
21:38:08.0016 0x0078 umbus - ok
21:38:08.0047 0x0078 UmPass - ok
21:38:08.0078 0x0078 UmRdpService - ok
21:38:08.0125 0x0078 UnistoreSvc - ok
21:38:08.0141 0x0078 upnphost - ok
21:38:08.0187 0x0078 UrsChipidea - ok
21:38:08.0234 0x0078 UrsCx01000 - ok
21:38:08.0250 0x0078 UrsSynopsys - ok
21:38:08.0297 0x0078 usbccgp - ok
21:38:08.0328 0x0078 usbcir - ok
21:38:08.0328 0x0078 usbehci - ok
21:38:08.0344 0x0078 usbhub - ok
21:38:08.0359 0x0078 USBHUB3 - ok
21:38:08.0375 0x0078 usbohci - ok
21:38:08.0406 0x0078 usbprint - ok
21:38:08.0422 0x0078 usbrndis6 - ok
21:38:08.0422 0x0078 usbser - ok
21:38:08.0453 0x0078 USBSTOR - ok
21:38:08.0484 0x0078 usbuhci - ok
21:38:08.0500 0x0078 USBXHCI - ok
21:38:08.0515 0x0078 UserDataSvc - ok
21:38:08.0547 0x0078 UserManager - ok
21:38:08.0578 0x0078 UsoSvc - ok
21:38:08.0594 0x0078 VaultSvc - ok
21:38:08.0609 0x0078 vdrvroot - ok
21:38:08.0625 0x0078 vds - ok
21:38:08.0656 0x0078 VerifierExt - ok
21:38:08.0687 0x0078 vhdmp - ok
21:38:08.0687 0x0078 vhf - ok
21:38:08.0719 0x0078 vmbus - ok
21:38:08.0734 0x0078 VMBusHID - ok
21:38:08.0766 0x0078 vmicguestinterface - ok
21:38:08.0766 0x0078 vmicheartbeat - ok
21:38:08.0766 0x0078 vmickvpexchange - ok
21:38:08.0781 0x0078 vmicrdv - ok
21:38:08.0781 0x0078 vmicshutdown - ok
21:38:08.0781 0x0078 vmictimesync - ok
21:38:08.0797 0x0078 vmicvmsession - ok
21:38:08.0797 0x0078 vmicvss - ok
21:38:08.0812 0x0078 volmgr - ok
21:38:08.0828 0x0078 volmgrx - ok
21:38:08.0828 0x0078 volsnap - ok
21:38:08.0859 0x0078 vpci - ok
21:38:08.0875 0x0078 vsmraid - ok
21:38:08.0891 0x0078 VSS - ok
21:38:08.0906 0x0078 VSTXRAID - ok
21:38:08.0922 0x0078 vwifibus - ok
21:38:08.0922 0x0078 vwififlt - ok
21:38:08.0922 0x0078 vwifimp - ok
21:38:08.0938 0x0078 W32Time - ok
21:38:08.0969 0x0078 WacomPen - ok
21:38:09.0016 0x0078 WalletService - ok
21:38:09.0032 0x0078 wanarp - ok
21:38:09.0032 0x0078 wanarpv6 - ok
21:38:09.0079 0x0078 wbengine - ok
21:38:09.0094 0x0078 WbioSrvc - ok
21:38:09.0110 0x0078 Wcmsvc - ok
21:38:09.0110 0x0078 wcncsvc - ok
21:38:09.0141 0x0078 WcsPlugInService - ok
21:38:09.0157 0x0078 WdBoot - ok
21:38:09.0172 0x0078 Wdf01000 - ok
21:38:09.0188 0x0078 WdFilter - ok
21:38:09.0188 0x0078 WdiServiceHost - ok
21:38:09.0204 0x0078 WdiSystemHost - ok
21:38:09.0204 0x0078 wdiwifi - ok
21:38:09.0204 0x0078 WdNisDrv - ok
21:38:09.0251 0x0078 WdNisSvc - ok
21:38:09.0251 0x0078 WebClient - ok
21:38:09.0251 0x0078 Wecsvc - ok
21:38:09.0298 0x0078 WEPHOSTSVC - ok
21:38:09.0313 0x0078 wercplsupport - ok
21:38:09.0329 0x0078 WerSvc - ok
21:38:09.0344 0x0078 WFPLWFS - ok
21:38:09.0344 0x0078 WiaRpc - ok
21:38:09.0376 0x0078 WIMMount - ok
21:38:09.0376 0x0078 WinDefend - ok
21:38:09.0407 0x0078 WindowsTrustedRT - ok
21:38:09.0454 0x0078 WindowsTrustedRTProxy - ok
21:38:09.0469 0x0078 WinHttpAutoProxySvc - ok
21:38:09.0516 0x0078 WinMad - ok
21:38:09.0579 0x0078 Winmgmt - ok
21:38:09.0610 0x0078 WinRM - ok
21:38:09.0673 0x0078 WINUSB - ok
21:38:09.0704 0x0078 WinVerbs - ok
21:38:09.0751 0x0078 WlanSvc - ok
21:38:09.0766 0x0078 wlidsvc - ok
21:38:09.0782 0x0078 WmiAcpi - ok
21:38:09.0813 0x0078 wmiApSrv - ok
21:38:09.0829 0x0078 WMPNetworkSvc - ok
21:38:09.0844 0x0078 [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys
21:38:09.0876 0x0078 Wof - ok
21:38:09.0923 0x0078 workfolderssvc - ok
21:38:09.0954 0x0078 wpcfltr - ok
21:38:09.0985 0x0078 WPDBusEnum - ok
21:38:10.0016 0x0078 WpdUpFltr - ok
21:38:10.0016 0x0078 WpnService - ok
21:38:10.0063 0x0078 ws2ifsl - ok
21:38:10.0095 0x0078 wscsvc - ok
21:38:10.0110 0x0078 WSearch - ok
21:38:10.0157 0x0078 WSService - ok
21:38:10.0157 0x0078 wuauserv - ok
21:38:10.0173 0x0078 WudfPf - ok
21:38:10.0173 0x0078 WUDFRd - ok
21:38:10.0204 0x0078 wudfsvc - ok
21:38:10.0220 0x0078 WUDFWpdFs - ok
21:38:10.0220 0x0078 WUDFWpdMtp - ok
21:38:10.0235 0x0078 WwanSvc - ok
21:38:10.0251 0x0078 XblAuthManager - ok
21:38:10.0266 0x0078 XblGameSave - ok
21:38:10.0282 0x0078 xboxgip - ok
21:38:10.0282 0x0078 XboxNetApiSvc - ok
21:38:10.0313 0x0078 xinputhid - ok
21:38:10.0532 0x0078 [ 27B1453C72A71DB1E32C043EFBF7DE73, 6BE61174D4074764F3061635AB633A4DDBC93CE8A6EF3B3E997D7B8A99C1E7EF ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
21:38:10.0594 0x0078 ZeroConfigService - ok
21:38:10.0610 0x0078 ================ Scan global ===============================
21:38:10.0766 0x0078 [ Global ] - ok
21:38:10.0766 0x0078 ================ Scan MBR ==================================
21:38:10.0782 0x0078 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
21:38:10.0926 0x0078 \Device\Harddisk0\DR0 - ok
21:38:10.0926 0x0078 ================ Scan VBR ==================================
21:38:10.0957 0x0078 [ F491CCB48B89CAA98713D2A2522D1868 ] \Device\Harddisk0\DR0\Partition1
21:38:10.0972 0x0078 \Device\Harddisk0\DR0\Partition1 - ok
21:38:10.0972 0x0078 [ E4002E8D31414780B003B1C1AA5C6EF3 ] \Device\Harddisk0\DR0\Partition2
21:38:10.0988 0x0078 \Device\Harddisk0\DR0\Partition2 - ok
21:38:11.0019 0x0078 [ A4020249126334F22F2D0FF7968D974F ] \Device\Harddisk0\DR0\Partition3
21:38:11.0019 0x0078 \Device\Harddisk0\DR0\Partition3 - ok
21:38:11.0019 0x0078 [ 56B5B579C6278A2E7B0CEBA368896E13 ] \Device\Harddisk0\DR0\Partition4
21:38:11.0035 0x0078 \Device\Harddisk0\DR0\Partition4 - ok
21:38:11.0035 0x0078 ================ Scan generic autorun ======================
21:38:11.0035 0x0078 ETDCtrl - ok
21:38:11.0489 0x1bb4 Object required for P2P: [ AA173D4202F9BFDD1C50B37550560780 ] ibtusb
21:38:11.0520 0x0078 [ D3BD123CF28F0B42E7126F06322CB447, EE956599EF414BBA69E55D58BCC3127F384ACD8335B9F830F7EA5927DFF38E5D ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
21:38:12.0055 0x0078 RtHDVCpl - ok
21:38:12.0117 0x0078 [ 4D87916E4A24532C1314EC89DC554DDE, 487C45494012DBED5782511029F348020C8F18BFF1263E9C28DE01D4F7364661 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
21:38:12.0164 0x0078 RtHDVBg_Dolby - ok
21:38:12.0212 0x0078 [ 4D87916E4A24532C1314EC89DC554DDE, 487C45494012DBED5782511029F348020C8F18BFF1263E9C28DE01D4F7364661 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
21:38:12.0243 0x0078 RtHDVBg_LENOVO_DOLBYDRAGON - ok
21:38:12.0305 0x0078 [ 4D87916E4A24532C1314EC89DC554DDE, 487C45494012DBED5782511029F348020C8F18BFF1263E9C28DE01D4F7364661 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
21:38:12.0337 0x0078 RtHDVBg_LENOVO_MICPKEY - ok
21:38:12.0477 0x0078 [ 11E2687D7AD9B4E8051F3FF68063E332, 7AF318768561272B094D86087FF8F502F095D0018A3315E626C7D71BD82E3172 ] C:\WINDOWS\RTFTrack.exe
21:38:12.0665 0x0078 RtsFT - ok
21:38:12.0743 0x0078 OneDriveSetup - ok
21:38:12.0743 0x0078 OneDriveSetup - ok
21:38:12.0868 0x0078 [ 61F488AC3053DEB2AADB6A34DEBC8876, B5C5E0325F0FB4A37E80F08273B7483630F676C6342519564798CE7D1F121CB7 ] C:\Users\Vanessa\AppData\Local\Microsoft\OneDrive\OneDrive.exe
21:38:12.0899 0x0078 OneDrive - ok
21:38:12.0915 0x0078 Uninstall C:\Users\Vanessa\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64 - ok
21:38:12.0930 0x0078 Waiting for KSN requests completion. In queue: 23
21:38:13.0932 0x0078 Waiting for KSN requests completion. In queue: 23
21:38:14.0182 0x1bb4 Object send P2P result: true
21:38:14.0182 0x1bb4 Object required for P2P: [ 9EA771C01B8F99360F5BE1F732C59C3F ] MozillaMaintenance
21:38:14.0947 0x0078 Waiting for KSN requests completion. In queue: 17
21:38:15.0963 0x0078 Waiting for KSN requests completion. In queue: 9
21:38:16.0682 0x1bb4 Object send P2P result: true
21:38:17.0072 0x0078 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x61100 ( enabled : updated )
21:38:17.0103 0x0078 Win FW state via NFP2: enabled ( trusted )
21:38:19.0542 0x0078 ============================================================
21:38:19.0542 0x0078 Scan finished
21:38:19.0542 0x0078 ============================================================
21:38:19.0558 0x169c Detected object count: 0
21:38:19.0558 0x169c Actual detected object count: 0
21:39:12.0403 0x0fbc Deinitialize success Vielen Dank nochmal für die Hilfe! |