muffelpuffel | 14.07.2016 21:22 | Addition.txt Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 13-07-2016 02
durchgeführt von Marco (2016-07-14 22:14:44)
Gestartet von C:\Users\Marco\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-19 15:15:56)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-284644802-3611648286-2238396948-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-284644802-3611648286-2238396948-503 - Limited - Disabled)
Gast (S-1-5-21-284644802-3611648286-2238396948-501 - Limited - Disabled)
Marco (S-1-5-21-284644802-3611648286-2238396948-1001 - Administrator - Enabled) => C:\Users\Marco
Silvia (S-1-5-21-284644802-3611648286-2238396948-1003 - Administrator - Enabled) => C:\Users\Silvia
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
7-Zip 15.09 beta (x64) (HKLM\...\7-Zip) (Version: 15.09 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{AAFD93A0-6522-9FF4-69CF-15B98681681A}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AVG (Version: 16.81.7640 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4627 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.81.7640 - AVG Technologies)
BUFFALO LinkStation(LS-XL Series) Setup Guide (HKLM-x32\...\UN110525) (Version: - )
BUFFALO NAS Navigator2 (HKLM-x32\...\UN060501) (Version: - )
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: 4.5.0 - Canon Inc.)
Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.15 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.6.5844 - CDBurnerXP)
Classic Shell (HKLM\...\{D4B3454F-7529-4F5F-851D-2C36933F7D64}) (Version: 4.2.5 - IvoSoft)
DoNotSpy10 (HKLM-x32\...\{32D066BD-F94C-4948-8FA8-84653EE9617E}_is1) (Version: 1.1.0.0 - pXc-coding.com)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
FMW 1 (Version: 1.102.4 - AVG Technologies) Hidden
FontManagementSystem (HKLM-x32\...\{3F2E8044-BA23-4604-AB00-BB164410964C}) (Version: 4.3.0 - Summitsoft Corp)
Free YouTube Download (HKLM-x32\...\Free YouTube Download_is1) (Version: 4.1.0.1224 - DVDVideoSoft Ltd.)
Free YouTube To MP3 Converter (HKLM-x32\...\Free YouTube To MP3 Converter_is1) (Version: 4.1.24.627 - Digital Wave Ltd)
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software)
Iperius Backup Version 4.4.3.0 (HKLM-x32\...\Iperius Backup_is1) (Version: 4.4.3.0 - Enter Srl)
IrfanView 64 (remove only) (HKLM\...\IrfanView) (Version: 4.40 - Irfan Skiljan)
Kits Configuration Installer (x32 Version: 8.100.25984 - Microsoft) Hidden
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 47.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 de)) (Version: 47.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1.6018 - Mozilla)
Nero WaveEditor (HKLM-x32\...\{8EBCCD6B-CDE8-4070-80BC-8A3109C6944B}) (Version: 14.0.00300 - Nero AG)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PhoneRescue 2.1.1 (HKLM-x32\...\{2FAFFE02-4D6B-4C0A-906B-1B33DAF0DD14}}_is1) (Version: 2.1.1 - iMobie Inc.)
Prerequisite installer (x32 Version: 12.0.0010 - Nero AG) Hidden
ReOrganize! (HKLM-x32\...\ReOrganize_is1) (Version: 2.3.1 - Oliver Frietsch)
Toolkit Documentation (x32 Version: 8.100.26866 - Microsoft) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Wand-FotoWalender 2016 (HKLM-x32\...\{2bf219a5-110f-4ef7-a686-049716ca8b86}_is1) (Version: - )
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Assessment and Deployment Kit for Windows 8.1 (HKLM-x32\...\{e9e06304-a604-434b-b35f-d9beb94dc06d}) (Version: 8.100.26866 - Microsoft Corporation)
Windows Tweaker (HKLM-x32\...\{F6881752-3DD7-44C9-9AC6-D827A1E641CC}) (Version: 5.3 - Windows Tweaker)
WPT Redistributables (x32 Version: 8.100.26866 - Microsoft) Hidden
WPTx64 (x32 Version: 8.100.26837 - Microsoft) Hidden
xp-AntiSpy 3.98-2 (HKLM-x32\...\xp-AntiSpy) (Version: - Christian Taubenheim)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {317D8221-FAE8-4C83-B5B9-68FBA859523D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {4355F8A0-9EB5-45F9-8629-67CDCD27728C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {4F1FB8EE-0E39-431F-98AA-456FB29AD5F9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {52F4769E-B0A7-4271-B991-F2B264D4480C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {69BB015A-EE85-4C71-A02D-D7A3AC71E941} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {75F8DDF5-39E4-4F48-A09A-B08FDA312F86} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {85CAC42D-8762-46C8-BD7D-0838E836C8AB} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-07-13] (Microsoft Corporation)
Task: {9C39AE91-E085-4F64-8D50-A82F20CF1D59} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-02-12] (Piriform Ltd)
Task: {A08F6015-11C5-4743-AB6D-2C5C9D05C39D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {B209556A-E819-457D-A38D-2FDD25E87EBD} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {B8275BC9-A138-46FB-9255-481C62D7B9BD} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2016-01-13] ()
Task: {BA8F881B-F28F-465C-A31F-EF7055904906} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {C6DC8487-3B7E-424C-BBCE-E80961EF6397} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {CE4B194B-CDAE-4062-8090-0C25271E4FE8} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated)
Task: {DCAE994E-188D-43D3-B9CD-BF35180A56FA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {DCBE8554-95A4-478E-892C-92510A6FCC4D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {E0CAA5F8-5D84-4C27-B0D5-7370693D7905} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-13 11:00 - 2016-07-01 06:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-02-12 23:13 - 2016-02-12 23:13 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2016-06-28 09:48 - 2016-06-28 09:48 - 03790336 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\Calculator.exe
2015-12-20 11:04 - 2015-12-20 11:04 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2016-06-03 16:26 - 2016-06-03 16:37 - 00173056 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_3.10.6302.0_x64__8wekyb3d8bbwe\CellNativeClientUniversal.dll
2016-07-01 09:34 - 2016-07-01 09:34 - 04108184 _____ () C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.0.1606.0_x64__8wekyb3d8bbwe\Microsoft.Advertising.dll
2016-03-15 10:46 - 2016-03-15 10:46 - 03128832 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_3.10.6302.0_x64__8wekyb3d8bbwe\Avatars.dll
2016-04-19 07:36 - 2016-04-19 07:36 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-10-30 09:18 - 2015-10-30 09:18 - 00218456 _____ () c:\windows\system32\WerEtw.dll
2016-07-13 11:00 - 2016-07-01 06:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-19 12:40 - 2015-12-19 12:40 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-13 11:03 - 2016-07-01 05:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-07-13 11:01 - 2016-07-01 05:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-07-13 11:00 - 2016-07-01 05:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-07-13 11:01 - 2016-07-01 05:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-07-13 11:01 - 2016-07-01 05:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-12-29 14:27 - 2016-06-27 14:52 - 00112552 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
2015-12-29 14:27 - 2016-06-27 14:52 - 00105896 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
2015-12-29 14:27 - 2016-06-27 14:52 - 00021928 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
2015-12-29 14:27 - 2016-06-27 14:52 - 00045992 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
2015-11-02 21:14 - 2015-08-26 19:44 - 00622880 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2015-11-02 20:45 - 2016-04-07 18:50 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2016-04-19 07:36 - 2016-04-19 07:36 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 07:36 - 2016-04-19 07:36 - 02941440 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\MessagingNativeCore.dll
2016-04-19 07:36 - 2016-04-19 07:36 - 00583168 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\MessagingEntityExtractionProxy.dll
2016-04-19 07:36 - 2016-04-19 07:36 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-04-19 07:36 - 2016-04-19 07:36 - 01300992 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\MessagingNativeBase.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-284644802-3611648286-2238396948-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-284644802-3611648286-2238396948-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Silvia\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 208.67.222.222 - 208.67.220.220
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKU\S-1-5-21-284644802-3611648286-2238396948-1001\...\StartupApproved\Run: => "OneDrive"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{90E0BD90-0792-4CEB-8979-735999702CDF}E:\programme\muli\avafmule.exe] => (Allow) E:\programme\muli\avafmule.exe
FirewallRules: [TCP Query User{E6D6514B-1034-4FCB-AE86-074F9604BB32}E:\programme\muli\avafmule.exe] => (Allow) E:\programme\muli\avafmule.exe
FirewallRules: [{18C73F6B-2550-4715-8234-1611D3F64282}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{228C5116-D4C9-4F6B-B4EE-516C3E66D5A9}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{CDB49A72-EF64-4E18-A5C3-D93084A3E1BC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1013A1FC-2F30-4A80-A963-328928A80716}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3B06CA0E-5CF3-482B-AD45-AFC084B894A5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{D1F7059A-FF42-4D41-8C3F-4BE127967F9D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{9EC60F7E-6D70-458E-B4CE-E1ED7573E1BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6B85FE29-69ED-4104-A60B-E2D8B387C876}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FEAB6140-A09B-493F-B996-6E7BF98BCA0D}] => (Allow) C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe
FirewallRules: [{43399507-2D93-4646-B6CE-7CCF27C3E414}] => (Allow) C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe
FirewallRules: [{348A76C6-7AD3-43FF-B8FA-5CD96C412065}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{CEDAD37C-27DF-406B-BD59-81705B5F03AE}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{B74C5B00-A998-4C77-8A12-484ADB15CC78}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{6F362578-BD7E-4D29-A6C9-D51A4AEB8A34}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{AABDCAB7-3B33-45AA-872C-297A3FD5051F}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{EED467A7-150B-49C6-A144-956A51240D9F}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
==================== Wiederherstellungspunkte =========================
28-06-2016 14:03:36 Geplanter Prüfpunkt
07-07-2016 12:54:14 Geplanter Prüfpunkt
13-07-2016 11:11:34 Windows Update
13-07-2016 11:12:41 Windows Update
14-07-2016 18:20:00 JRT Pre-Junkware Removal
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (07/14/2016 09:41:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe, Version: 3.1.0.9, Zeitstempel: 0x566b28d2
Name des fehlerhaften Moduls: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe, Version: 3.1.0.9, Zeitstempel: 0x566b28d2
Ausnahmecode: 0x40000015
Fehleroffset: 0x0014321c
ID des fehlerhaften Prozesses: 0x2148
Startzeit der fehlerhaften Anwendung: 0x{8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe0
Pfad der fehlerhaften Anwendung: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe1
Pfad des fehlerhaften Moduls: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe2
Berichtskennung: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe3
Vollständiger Name des fehlerhaften Pakets: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: {8B2D7A1C-89BB-4ECE-A90B-EFE1A2E91899}.exe5
Error: (07/14/2016 09:40:36 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_ea85e725b9ba5a4b.manifest.
Error: (07/14/2016 07:08:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Maschine1)
Description: Das Paket „Microsoft.MicrosoftSolitaireCollection_3.10.6302.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (07/14/2016 06:52:59 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_ea85e725b9ba5a4b.manifest.
Error: (07/14/2016 06:49:18 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_ea85e725b9ba5a4b.manifest.
Error: (07/14/2016 06:49:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_ea85e725b9ba5a4b.manifest.
Error: (07/14/2016 06:20:09 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (07/13/2016 11:12:51 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (07/13/2016 11:11:59 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (07/13/2016 10:47:57 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Maschine1)
Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Systemfehler:
=============
Error: (07/14/2016 09:04:41 PM) (Source: DCOM) (EventID: 10016) (User: Maschine1)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Maschine1MarcoS-1-5-21-284644802-3611648286-2238396948-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (07/14/2016 08:54:14 PM) (Source: DCOM) (EventID: 10016) (User: Maschine1)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Maschine1MarcoS-1-5-21-284644802-3611648286-2238396948-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (07/14/2016 08:51:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_10ac0e" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (07/14/2016 08:51:43 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (07/14/2016 08:30:36 PM) (Source: DCOM) (EventID: 10016) (User: Maschine1)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Maschine1MarcoS-1-5-21-284644802-3611648286-2238396948-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (07/14/2016 08:26:44 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {F3B4E234-7A68-4E43-B813-E4BA55A065F6}
Error: (07/14/2016 08:25:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1275 = Der Treiber konnte nicht geladen werden.
Error: (07/14/2016 08:25:47 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\Marco\AppData\Local\Temp\ehdrv.sys
Error: (07/14/2016 08:25:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1275 = Der Treiber konnte nicht geladen werden.
Error: (07/14/2016 08:25:46 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\Marco\AppData\Local\Temp\ehdrv.sys
CodeIntegrity:
===================================
Date: 2016-07-14 17:38:04.219
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-07-13 16:24:25.401
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-17 19:31:45.280
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-15 20:15:39.956
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-05-16 12:19:24.911
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-05-15 11:32:40.113
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-05-12 11:48:46.398
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-05-11 20:54:02.958
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-04-23 19:51:20.195
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-04-23 19:07:20.291
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM)2 Quad CPU Q6700 @ 2.66GHz
Prozentuale Nutzung des RAM: 60%
Installierter physikalischer RAM: 4095.11 MB
Verfügbarer physikalischer RAM: 1623.22 MB
Summe virtueller Speicher: 4799.11 MB
Verfügbarer virtueller Speicher: 2196.82 MB
==================== Laufwerke ================================
Drive c: (Windows) (Fixed) (Total:232.35 GB) (Free:204.31 GB) NTFS
Drive e: (Download) (Fixed) (Total:74.53 GB) (Free:65.66 GB) NTFS
Drive g: (Platte2) (Fixed) (Total:232.88 GB) (Free:198.04 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: F7A2F7A2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 6F1EE4FF)
Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: D1B8A18C)
Partition 1: (Not Active) - (Size=74.5 GB) - (Type=42)
==================== Ende von Addition.txt ============================ Code:
22:17:39.0856 0x0098 TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12
22:17:42.0638 0x0098 ============================================================
22:17:42.0638 0x0098 Current date / time: 2016/07/14 22:17:42.0638
22:17:42.0638 0x0098 SystemInfo:
22:17:42.0638 0x0098
22:17:42.0638 0x0098 OS Version: 10.0.10586 ServicePack: 0.0
22:17:42.0638 0x0098 Product type: Workstation
22:17:42.0638 0x0098 ComputerName: MASCHINE1
22:17:42.0638 0x0098 UserName: Marco
22:17:42.0638 0x0098 Windows directory: C:\WINDOWS
22:17:42.0638 0x0098 System windows directory: C:\WINDOWS
22:17:42.0638 0x0098 Running under WOW64
22:17:42.0638 0x0098 Processor architecture: Intel x64
22:17:42.0638 0x0098 Number of processors: 4
22:17:42.0638 0x0098 Page size: 0x1000
22:17:42.0638 0x0098 Boot type: Normal boot
22:17:42.0638 0x0098 ============================================================
22:17:43.0091 0x0098 System UUID: {14E18F31-20D4-7A9F-F3C2-EE4A3C01902B}
22:17:43.0716 0x0098 Drive \Device\Harddisk2\DR2 - Size: 0x12A1F16000 ( 74.53 Gb ), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:17:43.0731 0x0098 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x1C042, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000040
22:17:43.0731 0x0098 Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:17:43.0731 0x0098 ============================================================
22:17:43.0731 0x0098 \Device\Harddisk2\DR2:
22:17:43.0731 0x0098 MBR partitions:
22:17:43.0731 0x0098 \Device\Harddisk0\DR0:
22:17:43.0731 0x0098 MBR partitions:
22:17:43.0731 0x0098 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:17:43.0731 0x0098 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1D0B1800
22:17:43.0731 0x0098 \Device\Harddisk1\DR1:
22:17:43.0731 0x0098 MBR partitions:
22:17:43.0731 0x0098 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D1C4800
22:17:43.0731 0x0098 ============================================================
22:17:43.0747 0x0098 C: <-> \Device\Harddisk0\DR0\Partition2
22:17:43.0778 0x0098 G: <-> \Device\Harddisk1\DR1\Partition1
22:17:43.0778 0x0098 ============================================================
22:17:43.0778 0x0098 Initialize success
22:17:43.0778 0x0098 ============================================================
22:17:50.0950 0x1c0c ============================================================
22:17:50.0950 0x1c0c Scan started
22:17:50.0950 0x1c0c Mode: Manual; SigCheck; TDLFS;
22:17:50.0950 0x1c0c ============================================================
22:17:50.0950 0x1c0c KSN ping started
22:17:51.0091 0x1c0c KSN ping finished: true
22:17:52.0200 0x1c0c ================ Scan system memory ========================
22:17:52.0200 0x1c0c System memory - ok
22:17:52.0200 0x1c0c ================ Scan services =============================
22:17:52.0325 0x1c0c 1394ohci - ok
22:17:52.0325 0x1c0c 3ware - ok
22:17:52.0341 0x1c0c ACPI - ok
22:17:52.0356 0x1c0c acpiex - ok
22:17:52.0356 0x1c0c acpipagr - ok
22:17:52.0388 0x1c0c AcpiPmi - ok
22:17:52.0388 0x1c0c acpitime - ok
22:17:52.0466 0x1c0c [ 68E7DEA59FDEF410BAF29FDB5B7A6EEF, B808FCF0C30B465A1330E47947B84FC722A3B4C46260E261C54B1EED725A288F ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:17:52.0513 0x1c0c AdobeARMservice - ok
22:17:52.0669 0x1c0c [ 32B31B696CB8E8F380831DFEB80A67E4, 8C8F6E16F2FB3E8F10569261B7712BBC931A2924B6C27D561E7F828041C4F3E6 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:17:52.0685 0x1c0c AdobeFlashPlayerUpdateSvc - ok
22:17:52.0731 0x1c0c ADP80XX - ok
22:17:52.0763 0x1c0c AFD - ok
22:17:52.0778 0x1c0c agp440 - ok
22:17:52.0810 0x1c0c ahcache - ok
22:17:52.0856 0x1c0c AJRouter - ok
22:17:52.0919 0x1c0c ALG - ok
22:17:52.0950 0x1c0c [ BBADD85854BFB5D43C60B7AC8EEA3DBA, 968C043ABEA46F5C79525863B3FE2681AC0FA4202036C9EFD20B408DECF407E2 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
22:17:52.0997 0x1c0c AMD External Events Utility - ok
22:17:52.0997 0x1c0c AmdK8 - ok
22:17:53.0044 0x1c0c [ F2FF8C1B41B3784EDBD5C6D5397F403C, 104873700D2BDF4812DC48200B4609F46A63E7A50594A0599100EF1438863708 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys
22:17:53.0091 0x1c0c amdkmafd - ok
22:17:53.0122 0x1c0c amdkmdag - ok
22:17:53.0200 0x1c0c [ 17BA5C907E14947574CBB788F4CEB85F, EAA3DBF436637C58666A91905E388287FC54334EBB2589A00727EB09AC4870E3 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
22:17:53.0263 0x1c0c amdkmdap - ok
22:17:53.0278 0x1c0c AmdPPM - ok
22:17:53.0294 0x1c0c amdsata - ok
22:17:53.0294 0x1c0c amdsbs - ok
22:17:53.0310 0x1c0c amdxata - ok
22:17:53.0341 0x1c0c AppID - ok
22:17:53.0372 0x1c0c AppIDSvc - ok
22:17:53.0372 0x1c0c Appinfo - ok
22:17:53.0388 0x1c0c AppMgmt - ok
22:17:53.0435 0x1c0c AppReadiness - ok
22:17:53.0435 0x1c0c AppXSvc - ok
22:17:53.0450 0x1c0c arcsas - ok
22:17:53.0450 0x1c0c AsyncMac - ok
22:17:53.0466 0x1c0c atapi - ok
22:17:53.0497 0x1c0c [ AF6DD5993D46AF2492C19E1FF6D9A04C, 720F27791FF5D486AD07A447A4BC44D137AA245B91CE1D624E40B1DA78B6CACF ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWB6.sys
22:17:53.0544 0x1c0c AtiHDAudioService - ok
22:17:53.0591 0x1c0c AudioEndpointBuilder - ok
22:17:53.0606 0x1c0c Audiosrv - ok
22:17:53.0669 0x1c0c [ ACA2E23062A46CC432667DD5260AB037, A3CD584C65EB3990CD3F6B3128019DD71521F87E4E5BABD04E1CC68CF8903B45 ] AvgAMPS C:\Program Files (x86)\AVG\Av\avgamps.exe
22:17:53.0700 0x1c0c AvgAMPS - ok
22:17:53.0731 0x1c0c [ 344B89E8D91B1F25239310DCC7337ED0, CF57BD6AAA2A1527957DA4BA4FFC8072D4BE071C95A8741690CA051727B4E30C ] Avgboota C:\WINDOWS\system32\DRIVERS\avgboota.sys
22:17:53.0747 0x1c0c Avgboota - ok
22:17:53.0778 0x1c0c [ 3BF8CE64524E6249469F4EE69EBD10F9, B01CE4290235AA487126483B1CA233868605A3765FA47932278558BDE227E62C ] Avgdiska C:\WINDOWS\system32\DRIVERS\avgdiska.sys
22:17:53.0794 0x1c0c Avgdiska - ok
22:17:53.0935 0x1c0c [ DA1D211B4EA5B7B3CE1D6611494C006C, 9925EF1D140319A3A80DB05C4EC2C511F050CC2D5E0198311BEB904DBB779413 ] AVGIDSAgent C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
22:17:54.0106 0x1c0c AVGIDSAgent - ok
22:17:54.0153 0x1c0c [ 40A057A0EE883F700968B658356E1A6F, 882060AB4B8498CEE061D55A08DD82EB54F7934810D931AA02FDE3C6B0EF40D7 ] AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdrivera.sys
22:17:54.0169 0x1c0c AVGIDSDriver - ok
22:17:54.0200 0x1c0c [ D54A730B8DA065C33901737446D7C006, 5054DE9BD322D8D794AC69A8F2FA91C6FA0D82CB67047796114DB958AB7A9771 ] AVGIDSHA C:\WINDOWS\system32\DRIVERS\avgidsha.sys
22:17:54.0216 0x1c0c AVGIDSHA - ok
22:17:54.0231 0x1c0c [ EF29083E562CF4283503A550DA31EA80, F7B257E0962F5CBE3A3C54A1F7159D0DA6D7DF6E7DFFBD873BDE44713569C96A ] Avgldx64 C:\WINDOWS\system32\DRIVERS\avgldx64.sys
22:17:54.0247 0x1c0c Avgldx64 - ok
22:17:54.0278 0x1c0c [ 301E95F388C93D3C73EE35E3693C6A97, 512BA2905EDCC900B12037701A120EE527A14894BF562610F3CF57A65D20FCD5 ] Avgloga C:\WINDOWS\system32\DRIVERS\avgloga.sys
22:17:54.0294 0x1c0c Avgloga - ok
22:17:54.0325 0x1c0c [ 0E1CAF2EF339C9C3C3AFD574541A661F, 85AAA367134826A41EB84F549AE27AE9A3B0AA5BA1EA23C07B352B2B84E20E81 ] Avgmfx64 C:\WINDOWS\system32\DRIVERS\avgmfx64.sys
22:17:54.0341 0x1c0c Avgmfx64 - ok
22:17:54.0356 0x1c0c [ 6F5CD5907DA028D61E7D2F39557370E4, 6B2046F30219DF0F8F7B9250DECFA1D4DAFFEEBC899E3C38228D5809A2A1107E ] Avgrkx64 C:\WINDOWS\system32\DRIVERS\avgrkx64.sys
22:17:54.0372 0x1c0c Avgrkx64 - ok
22:17:54.0435 0x1c0c [ A994548B7F442CE9653D1569BB91CD17, 06444973AD436E341A89BD122E1FC7DE2FFCAC4D8553889204772B1880D87D3C ] avgsvc C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
22:17:54.0481 0x1c0c avgsvc - ok
22:17:54.0513 0x1c0c [ 66B4C2719D60DF8164D226756F3113BB, 94E6DEA8A931B17F9344AA96F53BF8F6D274DB31200D0DEEA02BC162B9A241B7 ] Avguniva C:\WINDOWS\system32\DRIVERS\avguniva.sys
22:17:54.0513 0x1c0c Avguniva - ok
22:17:54.0544 0x1c0c [ 7FEEDE7935E6867E8FE1378AF19908F9, F091FA416B5C958826DE433DB61993A0F34BC1CAACF968E10C385A6A3901E0CE ] avgwd C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
22:17:54.0575 0x1c0c avgwd - ok
22:17:54.0606 0x1c0c [ E1280D6DE33584FF88B128C9A6773719, 0161DD5736BCB0D4DBCEA8FF576E25CB860C5432B330DCD8412CF3BEC64A3C5E ] Avgwfpa C:\WINDOWS\system32\DRIVERS\avgwfpa.sys
22:17:54.0622 0x1c0c Avgwfpa - ok
22:17:54.0638 0x1c0c AxInstSV - ok
22:17:54.0653 0x1c0c b06bdrv - ok
22:17:54.0653 0x1c0c BasicDisplay - ok
22:17:54.0669 0x1c0c BasicRender - ok
22:17:54.0669 0x1c0c bcmfn - ok
22:17:54.0685 0x1c0c bcmfn2 - ok
22:17:54.0700 0x1c0c BDESVC - ok
22:17:54.0716 0x1c0c Beep - ok
22:17:54.0731 0x1c0c BFE - ok
22:17:54.0747 0x1c0c BITS - ok
22:17:54.0747 0x1c0c bowser - ok
22:17:54.0763 0x1c0c BrokerInfrastructure - ok
22:17:54.0763 0x1c0c Browser - ok
22:17:54.0794 0x1c0c BthAvrcpTg - ok
22:17:54.0794 0x1c0c BthHFEnum - ok
22:17:54.0810 0x1c0c bthhfhid - ok
22:17:54.0825 0x1c0c BthHFSrv - ok
22:17:54.0825 0x1c0c BTHMODEM - ok
22:17:54.0841 0x1c0c bthserv - ok
22:17:54.0856 0x1c0c buttonconverter - ok
22:17:54.0872 0x1c0c CapImg - ok
22:17:54.0888 0x1c0c cdfs - ok
22:17:54.0903 0x1c0c CDPSvc - ok
22:17:54.0903 0x1c0c cdrom - ok
22:17:54.0919 0x1c0c CertPropSvc - ok
22:17:54.0935 0x1c0c circlass - ok
22:17:54.0950 0x1c0c CLFS - ok
22:17:54.0966 0x1c0c ClipSVC - ok
22:17:54.0981 0x1c0c CmBatt - ok
22:17:54.0997 0x1c0c CNG - ok
22:17:54.0997 0x1c0c cnghwassist - ok
22:17:55.0028 0x1c0c CompositeBus - ok
22:17:55.0044 0x1c0c COMSysApp - ok
22:17:55.0044 0x1c0c condrv - ok
22:17:55.0075 0x1c0c CoreMessagingRegistrar - ok
22:17:55.0091 0x1c0c CryptSvc - ok
22:17:55.0091 0x1c0c CSC - ok
22:17:55.0106 0x1c0c CscService - ok
22:17:55.0138 0x1c0c dam - ok
22:17:55.0153 0x1c0c DcomLaunch - ok
22:17:55.0153 0x1c0c DcpSvc - ok
22:17:55.0169 0x1c0c defragsvc - ok
22:17:55.0185 0x1c0c DeviceAssociationService - ok
22:17:55.0185 0x1c0c DeviceInstall - ok
22:17:55.0185 0x1c0c DevQueryBroker - ok
22:17:55.0200 0x1c0c Dfsc - ok
22:17:55.0216 0x1c0c Dhcp - ok
22:17:55.0294 0x1c0c diagnosticshub.standardcollector.service - ok
22:17:55.0310 0x1c0c DiagTrack - ok
22:17:55.0419 0x1c0c [ 8749F477493BF9DBA365E7C7B423BBCC, 2A6F890BD14B09A04EEA6C46CE57E24B75567B8FC0AC5DB44DE541A13B2AE6F7 ] DigitalWave.Update.Service C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
22:17:55.0435 0x1c0c DigitalWave.Update.Service - detected UnsignedFile.Multi.Generic ( 1 )
22:17:55.0528 0x1c0c Detect skipped due to KSN trusted
22:17:55.0528 0x1c0c DigitalWave.Update.Service - ok
22:17:55.0544 0x1c0c disk - ok
22:17:55.0560 0x1c0c DmEnrollmentSvc - ok
22:17:55.0575 0x1c0c dmvsc - ok
22:17:55.0591 0x1c0c dmwappushservice - ok
22:17:55.0606 0x1c0c Dnscache - ok
22:17:55.0606 0x1c0c dot3svc - ok
22:17:55.0622 0x1c0c DPS - ok
22:17:55.0653 0x1c0c drmkaud - ok
22:17:55.0653 0x1c0c DsmSvc - ok
22:17:55.0685 0x1c0c DsSvc - ok
22:17:55.0700 0x1c0c DXGKrnl - ok
22:17:55.0716 0x1c0c Eaphost - ok
22:17:55.0716 0x1c0c ebdrv - ok
22:17:55.0731 0x1c0c EFS - ok
22:17:55.0731 0x1c0c EhStorClass - ok
22:17:55.0747 0x1c0c EhStorTcgDrv - ok
22:17:55.0747 0x1c0c embeddedmode - ok
22:17:55.0763 0x1c0c EntAppSvc - ok
22:17:55.0778 0x1c0c ErrDev - ok
22:17:55.0794 0x1c0c EventSystem - ok
22:17:55.0810 0x1c0c exfat - ok
22:17:55.0825 0x1c0c fastfat - ok
22:17:55.0825 0x1c0c fdc - ok
22:17:55.0841 0x1c0c fdPHost - ok
22:17:55.0841 0x1c0c FDResPub - ok
22:17:55.0856 0x1c0c fhsvc - ok
22:17:55.0856 0x1c0c FileCrypt - ok
22:17:55.0872 0x1c0c FileInfo - ok
22:17:55.0872 0x1c0c Filetrace - ok
22:17:55.0872 0x1c0c flpydisk - ok
22:17:55.0888 0x1c0c FltMgr - ok
22:17:55.0903 0x1c0c FontCache - ok
22:17:56.0013 0x1c0c FontCache3.0.0.0 - ok
22:17:56.0028 0x1c0c FsDepends - ok
22:17:56.0044 0x1c0c Fs_Rec - ok
22:17:56.0060 0x1c0c fvevol - ok
22:17:56.0060 0x1c0c gagp30kx - ok
22:17:56.0091 0x1c0c gencounter - ok
22:17:56.0122 0x1c0c genericusbfn - ok
22:17:56.0122 0x1c0c GPIOClx0101 - ok
22:17:56.0138 0x1c0c gpsvc - ok
22:17:56.0138 0x1c0c GpuEnergyDrv - ok
22:17:56.0153 0x1c0c HdAudAddService - ok
22:17:56.0153 0x1c0c HDAudBus - ok
22:17:56.0169 0x1c0c HidBatt - ok
22:17:56.0169 0x1c0c HidBth - ok
22:17:56.0169 0x1c0c hidi2c - ok
22:17:56.0185 0x1c0c hidinterrupt - ok
22:17:56.0185 0x1c0c HidIr - ok
22:17:56.0200 0x1c0c hidserv - ok
22:17:56.0216 0x1c0c HidUsb - ok
22:17:56.0231 0x1c0c HomeGroupListener - ok
22:17:56.0247 0x1c0c HomeGroupProvider - ok
22:17:56.0263 0x1c0c HpSAMD - ok
22:17:56.0278 0x1c0c HTTP - ok
22:17:56.0294 0x1c0c hwpolicy - ok
22:17:56.0294 0x1c0c hyperkbd - ok
22:17:56.0310 0x1c0c i8042prt - ok
22:17:56.0310 0x1c0c iai2c - ok
22:17:56.0341 0x1c0c iaLPSS2i_I2C - ok
22:17:56.0341 0x1c0c iaLPSSi_GPIO - ok
22:17:56.0341 0x1c0c iaLPSSi_I2C - ok
22:17:56.0356 0x1c0c iaStorAV - ok
22:17:56.0356 0x1c0c iaStorV - ok
22:17:56.0372 0x1c0c ibbus - ok
22:17:56.0388 0x1c0c icssvc - ok
22:17:56.0388 0x1c0c IEEtwCollectorService - ok
22:17:56.0403 0x1c0c IKEEXT - ok
22:17:56.0403 0x1c0c intelide - ok
22:17:56.0419 0x1c0c intelpep - ok
22:17:56.0419 0x1c0c intelppm - ok
22:17:56.0419 0x1c0c IoQos - ok
22:17:56.0435 0x1c0c IpFilterDriver - ok
22:17:56.0435 0x1c0c iphlpsvc - ok
22:17:56.0450 0x1c0c IPMIDRV - ok
22:17:56.0450 0x1c0c IPNAT - ok
22:17:56.0450 0x1c0c IRENUM - ok
22:17:56.0466 0x1c0c isapnp - ok
22:17:56.0466 0x1c0c iScsiPrt - ok
22:17:56.0481 0x1c0c kbdclass - ok
22:17:56.0481 0x1c0c kbdhid - ok
22:17:56.0497 0x1c0c kdnic - ok
22:17:56.0497 0x1c0c KeyIso - ok
22:17:56.0497 0x1c0c KSecDD - ok
22:17:56.0528 0x1c0c KSecPkg - ok
22:17:56.0528 0x1c0c ksthunk - ok
22:17:56.0544 0x1c0c KtmRm - ok
22:17:56.0560 0x1c0c LanmanServer - ok
22:17:56.0560 0x1c0c LanmanWorkstation - ok
22:17:56.0575 0x1c0c lfsvc - ok
22:17:56.0575 0x1c0c LicenseManager - ok
22:17:56.0669 0x1c0c [ 69145D913B745AFF7D5F5B0349F8593E, 7D7B750DC9BA8DA795DDD1A34996BEE9F63ECE5EFA50B3A88BA13DCB0DA416D1 ] LiveUpdateSvc C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
22:17:56.0763 0x1c0c LiveUpdateSvc - ok
22:17:56.0778 0x1c0c lltdio - ok
22:17:56.0778 0x1c0c lltdsvc - ok
22:17:56.0794 0x1c0c lmhosts - ok
22:17:56.0810 0x1c0c LSI_SAS - ok
22:17:56.0810 0x1c0c LSI_SAS2i - ok
22:17:56.0810 0x1c0c LSI_SAS3i - ok
22:17:56.0825 0x1c0c LSI_SSS - ok
22:17:56.0825 0x1c0c LSM - ok
22:17:56.0841 0x1c0c luafv - ok
22:17:56.0872 0x1c0c MapsBroker - ok
22:17:56.0872 0x1c0c megasas - ok
22:17:56.0872 0x1c0c megasr - ok
22:17:56.0888 0x1c0c MessagingService - ok
22:17:56.0935 0x1c0c mlx4_bus - ok
22:17:56.0950 0x1c0c MMCSS - ok
22:17:56.0950 0x1c0c Modem - ok
22:17:56.0966 0x1c0c monitor - ok
22:17:56.0966 0x1c0c mouclass - ok
22:17:56.0966 0x1c0c mouhid - ok
22:17:56.0981 0x1c0c mountmgr - ok
22:17:57.0013 0x1c0c [ 69E23C730974BAC8C11DF2B7C4C9D37B, 8DC4448EC9C9647381952D7822B39C89E0997B4B964A785AE274144FADEE3C02 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:17:57.0028 0x1c0c MozillaMaintenance - ok
22:17:57.0028 0x1c0c mpsdrv - ok
22:17:57.0044 0x1c0c MpsSvc - ok
22:17:57.0044 0x1c0c MRxDAV - ok
22:17:57.0060 0x1c0c mrxsmb - ok
22:17:57.0060 0x1c0c mrxsmb10 - ok
22:17:57.0075 0x1c0c mrxsmb20 - ok
22:17:57.0075 0x1c0c MsBridge - ok
22:17:57.0106 0x1c0c MSDTC - ok
22:17:57.0106 0x1c0c Msfs - ok
22:17:57.0122 0x1c0c msgpiowin32 - ok
22:17:57.0122 0x1c0c mshidkmdf - ok
22:17:57.0138 0x1c0c mshidumdf - ok
22:17:57.0138 0x1c0c msisadrv - ok
22:17:57.0169 0x1c0c MSiSCSI - ok
22:17:57.0169 0x1c0c msiserver - ok
22:17:57.0169 0x1c0c MSKSSRV - ok
22:17:57.0169 0x1c0c MsLldp - ok
22:17:57.0185 0x1c0c MSPCLOCK - ok
22:17:57.0185 0x1c0c MSPQM - ok
22:17:57.0200 0x1c0c MsRPC - ok
22:17:57.0200 0x1c0c mssmbios - ok
22:17:57.0200 0x1c0c MSTEE - ok
22:17:57.0216 0x1c0c MTConfig - ok
22:17:57.0263 0x1c0c [ 640617B6E682A150C36BE39D78547F6C, 784F712E9DC3EEE81F07946BBA08AA2BEAC7B3961E430B75043645EF7ECA715C ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:17:57.0263 0x1c0c MTsensor - ok
22:17:57.0263 0x1c0c Mup - ok
22:17:57.0278 0x1c0c mvumis - ok
22:17:57.0310 0x1c0c NasPmService - ok
22:17:57.0325 0x1c0c NativeWifiP - ok
22:17:57.0372 0x1c0c [ 4DF6F43F761A600208F90A55D05F9B7E, AC93B4497FB428F7EC42DCF5956A2A61B951394E555BF6C89E55943E0B681586 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
22:17:57.0388 0x1c0c NAUpdate - ok
22:17:57.0403 0x1c0c NcaSvc - ok
22:17:57.0435 0x1c0c NcbService - ok
22:17:57.0435 0x1c0c NcdAutoSetup - ok
22:17:57.0450 0x1c0c ndfltr - ok
22:17:57.0450 0x1c0c NDIS - ok
22:17:57.0481 0x1c0c NdisCap - ok
22:17:57.0481 0x1c0c NdisImPlatform - ok
22:17:57.0481 0x1c0c NdisTapi - ok
22:17:57.0497 0x1c0c Ndisuio - ok
22:17:57.0497 0x1c0c NdisVirtualBus - ok
22:17:57.0497 0x1c0c NdisWan - ok
22:17:57.0513 0x1c0c ndiswanlegacy - ok
22:17:57.0513 0x1c0c ndproxy - ok
22:17:57.0528 0x1c0c Ndu - ok
22:17:57.0544 0x1c0c NetBIOS - ok
22:17:57.0544 0x1c0c NetBT - ok
22:17:57.0544 0x1c0c Netlogon - ok
22:17:57.0575 0x1c0c Netman - ok
22:17:57.0575 0x1c0c netprofm - ok
22:17:57.0591 0x1c0c NetSetupSvc - ok
22:17:57.0622 0x1c0c NetTcpPortSharing - ok
22:17:57.0653 0x1c0c NgcCtnrSvc - ok
22:17:57.0653 0x1c0c NgcSvc - ok
22:17:57.0669 0x1c0c NlaSvc - ok
22:17:57.0669 0x1c0c Npfs - ok
22:17:57.0700 0x1c0c npsvctrig - ok
22:17:57.0700 0x1c0c nsi - ok
22:17:57.0700 0x1c0c nsiproxy - ok
22:17:57.0731 0x1c0c NTFS - ok
22:17:57.0731 0x1c0c Null - ok
22:17:57.0731 0x1c0c nvraid - ok
22:17:57.0731 0x1c0c nvstor - ok
22:17:57.0747 0x1c0c nv_agp - ok
22:17:57.0763 0x1c0c OneSyncSvc - ok
22:17:57.0856 0x1c0c [ B9C125314A025127FE562C116D614AA3, 79C46C0BACEBBB5B8E1C162766B21587365A100BBAD01171C77B995C514BC7D6 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:17:57.0872 0x1c0c ose64 - ok
22:17:57.0888 0x1c0c p2pimsvc - ok
22:17:57.0888 0x1c0c p2psvc - ok
22:17:57.0935 0x1c0c Parport - ok
22:17:57.0935 0x1c0c partmgr - ok
22:17:57.0935 0x1c0c PcaSvc - ok
22:17:57.0950 0x1c0c pci - ok
22:17:57.0950 0x1c0c pciide - ok
22:17:57.0966 0x1c0c pcmcia - ok
22:17:57.0966 0x1c0c pcw - ok
22:17:57.0981 0x1c0c pdc - ok
22:17:57.0997 0x1c0c PEAUTH - ok
22:17:58.0013 0x1c0c PeerDistSvc - ok
22:17:58.0028 0x1c0c percsas2i - ok
22:17:58.0028 0x1c0c percsas3i - ok
22:17:58.0091 0x1c0c PerfHost - ok
22:17:58.0138 0x1c0c PhoneSvc - ok
22:17:58.0169 0x1c0c PimIndexMaintenanceSvc - ok
22:17:58.0185 0x1c0c pla - ok
22:17:58.0200 0x1c0c PlugPlay - ok
22:17:58.0200 0x1c0c PNRPAutoReg - ok
22:17:58.0216 0x1c0c PNRPsvc - ok
22:17:58.0231 0x1c0c PolicyAgent - ok
22:17:58.0231 0x1c0c Power - ok
22:17:58.0247 0x1c0c PptpMiniport - ok
22:17:58.0388 0x1c0c [ C9908063F90F5541098BF19EA63E1327, AA6B5E4D01CD8061D5953FDE3025FE4AF01B265C182B8818107A035E4FFAD0DF ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
22:17:58.0513 0x1c0c PrintNotify - ok
22:17:58.0544 0x1c0c Processor - ok
22:17:58.0560 0x1c0c ProfSvc - ok
22:17:58.0560 0x1c0c Psched - ok
22:17:58.0575 0x1c0c QWAVE - ok
22:17:58.0606 0x1c0c QWAVEdrv - ok
22:17:58.0622 0x1c0c RasAcd - ok
22:17:58.0653 0x1c0c RasAgileVpn - ok
22:17:58.0653 0x1c0c RasAuto - ok
22:17:58.0669 0x1c0c Rasl2tp - ok
22:17:58.0685 0x1c0c RasMan - ok
22:17:58.0685 0x1c0c RasPppoe - ok
22:17:58.0700 0x1c0c RasSstp - ok
22:17:58.0700 0x1c0c rdbss - ok
22:17:58.0716 0x1c0c rdpbus - ok
22:17:58.0731 0x1c0c RDPDR - ok
22:17:58.0763 0x1c0c RdpVideoMiniport - ok
22:17:58.0763 0x1c0c rdyboost - ok
22:17:58.0778 0x1c0c ReFSv1 - ok
22:17:58.0794 0x1c0c RemoteAccess - ok
22:17:58.0810 0x1c0c RemoteRegistry - ok
22:17:58.0825 0x1c0c RetailDemo - ok
22:17:58.0841 0x1c0c RpcEptMapper - ok
22:17:58.0872 0x1c0c RpcLocator - ok
22:17:58.0872 0x1c0c RpcSs - ok
22:17:58.0872 0x1c0c rspndr - ok
22:17:58.0888 0x1c0c rt640x64 - ok
22:17:58.0888 0x1c0c s3cap - ok
22:17:58.0888 0x1c0c SamSs - ok
22:17:58.0903 0x1c0c sbp2port - ok
22:17:58.0935 0x1c0c SCardSvr - ok
22:17:58.0935 0x1c0c ScDeviceEnum - ok
22:17:58.0935 0x1c0c scfilter - ok
22:17:58.0950 0x1c0c Schedule - ok
22:17:58.0966 0x1c0c SCPolicySvc - ok
22:17:58.0981 0x1c0c sdbus - ok
22:17:58.0997 0x1c0c SDRSVC - ok
22:17:59.0013 0x1c0c sdstor - ok
22:17:59.0028 0x1c0c seclogon - ok
22:17:59.0028 0x1c0c SENS - ok
22:17:59.0060 0x1c0c SensorDataService - ok
22:17:59.0075 0x1c0c SensorService - ok
22:17:59.0091 0x1c0c SensrSvc - ok
22:17:59.0106 0x1c0c SerCx - ok
22:17:59.0106 0x1c0c SerCx2 - ok
22:17:59.0122 0x1c0c Serenum - ok
22:17:59.0138 0x1c0c Serial - ok
22:17:59.0138 0x1c0c sermouse - ok
22:17:59.0153 0x1c0c SessionEnv - ok
22:17:59.0153 0x1c0c sfloppy - ok
22:17:59.0169 0x1c0c SharedAccess - ok
22:17:59.0169 0x1c0c ShellHWDetection - ok
22:17:59.0169 0x1c0c SiSRaid2 - ok
22:17:59.0185 0x1c0c SiSRaid4 - ok
22:17:59.0200 0x1c0c smphost - ok
22:17:59.0216 0x1c0c SmsRouter - ok
22:17:59.0247 0x1c0c SNMPTRAP - ok
22:17:59.0263 0x1c0c spaceport - ok
22:17:59.0278 0x1c0c SpbCx - ok
22:17:59.0278 0x1c0c Spooler - ok
22:17:59.0294 0x1c0c sppsvc - ok
22:17:59.0325 0x1c0c srv - ok
22:17:59.0325 0x1c0c srv2 - ok
22:17:59.0325 0x1c0c srvnet - ok
22:17:59.0341 0x1c0c SSDPSRV - ok
22:17:59.0341 0x1c0c SstpSvc - ok
22:17:59.0372 0x1c0c StateRepository - ok
22:17:59.0372 0x1c0c stexstor - ok
22:17:59.0388 0x1c0c stisvc - ok
22:17:59.0388 0x1c0c storahci - ok
22:17:59.0388 0x1c0c storflt - ok
22:17:59.0388 0x1c0c stornvme - ok
22:17:59.0403 0x1c0c storqosflt - ok
22:17:59.0419 0x1c0c StorSvc - ok
22:17:59.0419 0x1c0c storufs - ok
22:17:59.0419 0x1c0c storvsc - ok
22:17:59.0435 0x1c0c svsvc - ok
22:17:59.0435 0x1c0c swenum - ok
22:17:59.0435 0x1c0c swprv - ok
22:17:59.0466 0x1c0c Synth3dVsc - ok
22:17:59.0481 0x1c0c SysMain - ok
22:17:59.0497 0x1c0c SystemEventsBroker - ok
22:17:59.0513 0x1c0c TabletInputService - ok
22:17:59.0528 0x1c0c TapiSrv - ok
22:17:59.0544 0x1c0c Tcpip - ok
22:17:59.0544 0x1c0c Tcpip6 - ok
22:17:59.0544 0x1c0c tcpipreg - ok
22:17:59.0575 0x1c0c tdx - ok
22:17:59.0575 0x1c0c terminpt - ok
22:17:59.0575 0x1c0c TermService - ok
22:17:59.0575 0x1c0c Themes - ok
22:17:59.0591 0x1c0c TieringEngineService - ok
22:17:59.0622 0x1c0c tiledatamodelsvc - ok
22:17:59.0622 0x1c0c TimeBroker - ok
22:17:59.0638 0x1c0c TPM - ok
22:17:59.0638 0x1c0c TrkWks - ok
22:17:59.0669 0x1c0c TrustedInstaller - ok
22:17:59.0700 0x1c0c tsusbflt - ok
22:17:59.0700 0x1c0c TsUsbGD - ok
22:17:59.0716 0x1c0c tunnel - ok
22:17:59.0731 0x1c0c tzautoupdate - ok
22:17:59.0747 0x1c0c uagp35 - ok
22:17:59.0763 0x1c0c UASPStor - ok
22:17:59.0778 0x1c0c UcmCx0101 - ok
22:17:59.0794 0x1c0c UcmUcsi - ok
22:17:59.0794 0x1c0c Ucx01000 - ok
22:17:59.0794 0x1c0c UdeCx - ok
22:17:59.0810 0x1c0c udfs - ok
22:17:59.0810 0x1c0c UEFI - ok
22:17:59.0841 0x1c0c Ufx01000 - ok
22:17:59.0872 0x1c0c UfxChipidea - ok
22:17:59.0872 0x1c0c ufxsynopsys - ok
22:17:59.0888 0x1c0c UI0Detect - ok
22:17:59.0903 0x1c0c uliagpkx - ok
22:17:59.0903 0x1c0c umbus - ok
22:17:59.0903 0x1c0c UmPass - ok
22:17:59.0935 0x1c0c UmRdpService - ok
22:17:59.0935 0x1c0c UnistoreSvc - ok
22:17:59.0981 0x1c0c upnphost - ok
22:17:59.0997 0x1c0c UrsChipidea - ok
22:17:59.0997 0x1c0c UrsCx01000 - ok
22:18:00.0013 0x1c0c UrsSynopsys - ok
22:18:00.0028 0x1c0c [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
22:18:00.0044 0x1c0c USBAAPL64 - detected UnsignedFile.Multi.Generic ( 1 )
22:18:00.0138 0x1c0c Detect skipped due to KSN trusted
22:18:00.0138 0x1c0c USBAAPL64 - ok
22:18:00.0138 0x1c0c usbccgp - ok
22:18:00.0153 0x1c0c usbcir - ok
22:18:00.0153 0x1c0c usbehci - ok
22:18:00.0153 0x1c0c usbhub - ok
22:18:00.0169 0x1c0c USBHUB3 - ok
22:18:00.0185 0x1c0c usbohci - ok
22:18:00.0185 0x1c0c usbprint - ok
22:18:00.0231 0x1c0c [ D67B6A4A6FB99D29444C2DBA2B636799, 62BC778D60593B2AB0DA13C4DB3EA5971895AE09DA06E8AB2D03973C940C890C ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:18:00.0247 0x1c0c usbscan - ok
22:18:00.0247 0x1c0c usbser - ok
22:18:00.0263 0x1c0c USBSTOR - ok
22:18:00.0263 0x1c0c usbuhci - ok
22:18:00.0263 0x1c0c USBXHCI - ok
22:18:00.0278 0x1c0c UserDataSvc - ok
22:18:00.0325 0x1c0c UserManager - ok
22:18:00.0341 0x1c0c UsoSvc - ok
22:18:00.0341 0x1c0c VaultSvc - ok
22:18:00.0372 0x1c0c vdrvroot - ok
22:18:00.0388 0x1c0c vds - ok
22:18:00.0388 0x1c0c VerifierExt - ok
22:18:00.0388 0x1c0c vhdmp - ok
22:18:00.0403 0x1c0c vhf - ok
22:18:00.0403 0x1c0c vmbus - ok
22:18:00.0403 0x1c0c VMBusHID - ok
22:18:00.0419 0x1c0c vmicguestinterface - ok
22:18:00.0419 0x1c0c vmicheartbeat - ok
22:18:00.0419 0x1c0c vmickvpexchange - ok
22:18:00.0435 0x1c0c vmicrdv - ok
22:18:00.0435 0x1c0c vmicshutdown - ok
22:18:00.0435 0x1c0c vmictimesync - ok
22:18:00.0450 0x1c0c vmicvmsession - ok
22:18:00.0450 0x1c0c vmicvss - ok
22:18:00.0450 0x1c0c volmgr - ok
22:18:00.0466 0x1c0c volmgrx - ok
22:18:00.0466 0x1c0c volsnap - ok
22:18:00.0481 0x1c0c vpci - ok
22:18:00.0497 0x1c0c vsmraid - ok
22:18:00.0497 0x1c0c VSS - ok
22:18:00.0497 0x1c0c VSTXRAID - ok
22:18:00.0513 0x1c0c vwifibus - ok
22:18:00.0513 0x1c0c vwififlt - ok
22:18:00.0528 0x1c0c W32Time - ok
22:18:00.0544 0x1c0c WacomPen - ok
22:18:00.0544 0x1c0c WalletService - ok
22:18:00.0544 0x1c0c wanarp - ok
22:18:00.0560 0x1c0c wanarpv6 - ok
22:18:00.0560 0x1c0c wbengine - ok
22:18:00.0575 0x1c0c WbioSrvc - ok
22:18:00.0591 0x1c0c Wcmsvc - ok
22:18:00.0591 0x1c0c wcncsvc - ok
22:18:00.0591 0x1c0c WcsPlugInService - ok
22:18:00.0591 0x1c0c WdBoot - ok
22:18:00.0606 0x1c0c Wdf01000 - ok
22:18:00.0606 0x1c0c WdFilter - ok
22:18:00.0622 0x1c0c WdiServiceHost - ok
22:18:00.0622 0x1c0c WdiSystemHost - ok
22:18:00.0638 0x1c0c wdiwifi - ok
22:18:00.0638 0x1c0c WdNisDrv - ok
22:18:00.0669 0x1c0c WdNisSvc - ok
22:18:00.0669 0x1c0c WebClient - ok
22:18:00.0685 0x1c0c Wecsvc - ok
22:18:00.0685 0x1c0c WEPHOSTSVC - ok
22:18:00.0716 0x1c0c wercplsupport - ok
22:18:00.0716 0x1c0c WerSvc - ok
22:18:00.0763 0x1c0c WFPLWFS - ok
22:18:00.0763 0x1c0c WiaRpc - ok
22:18:00.0778 0x1c0c WIMMount - ok
22:18:00.0778 0x1c0c WinDefend - ok
22:18:00.0794 0x1c0c WindowsTrustedRT - ok
22:18:00.0825 0x1c0c WindowsTrustedRTProxy - ok
22:18:00.0841 0x1c0c WinHttpAutoProxySvc - ok
22:18:00.0856 0x1c0c WinMad - ok
22:18:00.0888 0x1c0c Winmgmt - ok
22:18:00.0903 0x1c0c WinRM - ok
22:18:00.0919 0x1c0c WINUSB - ok
22:18:00.0935 0x1c0c WinVerbs - ok
22:18:00.0950 0x1c0c WlanSvc - ok
22:18:00.0966 0x1c0c wlidsvc - ok
22:18:00.0981 0x1c0c WmiAcpi - ok
22:18:00.0997 0x1c0c wmiApSrv - ok
22:18:01.0013 0x1c0c WMPNetworkSvc - ok
22:18:01.0028 0x1c0c [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys
22:18:01.0044 0x1c0c Wof - ok
22:18:01.0060 0x1c0c workfolderssvc - ok
22:18:01.0091 0x1c0c wpcfltr - ok
22:18:01.0106 0x1c0c WPDBusEnum - ok
22:18:01.0122 0x1c0c WpdUpFltr - ok
22:18:01.0122 0x1c0c WpnService - ok
22:18:01.0138 0x1c0c ws2ifsl - ok
22:18:01.0216 0x1c0c [ 69671F82C17650612B68519ADA192F65, 282A0B8E5455DEEAE8AFED270A438F67463324C1B2A11369A7D3B0D47987EE53 ] WsAppService C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe
22:18:01.0231 0x1c0c WsAppService - detected UnsignedFile.Multi.Generic ( 1 )
22:18:01.0325 0x1c0c Detect skipped due to KSN trusted
22:18:01.0325 0x1c0c WsAppService - ok
22:18:01.0341 0x1c0c wscsvc - ok
22:18:01.0341 0x1c0c WSDPrintDevice - ok
22:18:01.0341 0x1c0c WSDScan - ok
22:18:01.0341 0x1c0c WSearch - ok
22:18:01.0372 0x1c0c WSService - ok
22:18:01.0372 0x1c0c wuauserv - ok
22:18:01.0388 0x1c0c WudfPf - ok
22:18:01.0403 0x1c0c WUDFRd - ok
22:18:01.0435 0x1c0c wudfsvc - ok
22:18:01.0435 0x1c0c WUDFWpdFs - ok
22:18:01.0435 0x1c0c WUDFWpdMtp - ok
22:18:01.0450 0x1c0c WwanSvc - ok
22:18:01.0466 0x1c0c XblAuthManager - ok
22:18:01.0481 0x1c0c XblGameSave - ok
22:18:01.0481 0x1c0c xboxgip - ok
22:18:01.0513 0x1c0c XboxNetApiSvc - ok
22:18:01.0528 0x1c0c xinputhid - ok
22:18:01.0544 0x1c0c ================ Scan global ===============================
22:18:01.0591 0x1c0c [ Global ] - ok
22:18:01.0591 0x1c0c ================ Scan MBR ==================================
22:18:01.0622 0x1c0c [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk2\DR2
22:18:01.0810 0x1c0c \Device\Harddisk2\DR2 - ok
22:18:01.0810 0x1c0c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:18:02.0044 0x1c0c \Device\Harddisk0\DR0 - ok
22:18:02.0044 0x1c0c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
22:18:02.0091 0x1c0c \Device\Harddisk1\DR1 - ok
22:18:02.0091 0x1c0c ================ Scan VBR ==================================
22:18:02.0091 0x1c0c [ 003FF50A9F8EE4D9D37AD55788CD2A84 ] \Device\Harddisk0\DR0\Partition1
22:18:02.0091 0x1c0c \Device\Harddisk0\DR0\Partition1 - ok
22:18:02.0106 0x1c0c [ 9FF97B6F187739B0249BD2347C2FBF6E ] \Device\Harddisk0\DR0\Partition2
22:18:02.0122 0x1c0c \Device\Harddisk0\DR0\Partition2 - ok
22:18:02.0138 0x1c0c [ 8EAAF72ACC8D1B5FF1869753BE80DDD7 ] \Device\Harddisk1\DR1\Partition1
22:18:02.0138 0x1c0c \Device\Harddisk1\DR1\Partition1 - ok
22:18:02.0138 0x1c0c ================ Scan generic autorun ======================
22:18:02.0138 0x1c0c Logitech Download Assistant - ok
22:18:02.0185 0x1c0c [ 889E56C58F5AC4242E395E3AD5F7780C, 35AA891112BE86C28C6AF8DF44BFEE342BAB7BDA877917C9B6466204091B9ADE ] C:\Program Files\Classic Shell\ClassicStartMenu.exe
22:18:02.0200 0x1c0c Classic Start Menu - ok
22:18:02.0294 0x1c0c [ 4C6AAABB264526A9C845A39AEBB79B69, B27F869E8B44CC5F1F9ADCA53AA848C16D706587ED9C7F995AE59BF9B0426523 ] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe
22:18:02.0310 0x1c0c StartCCC - ok
22:18:02.0372 0x1c0c [ 269E4E0E2A3E0F891AE1C492299E4519, 510A2A9FD807F225B16F4DE8F8BC9E58E395230A40B4F377466DE655D95B86D3 ] C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe
22:18:02.0388 0x1c0c AvgUi - ok
22:18:02.0419 0x1c0c [ F177B21BD5F99269B11F83BFA2937868, D9D7C4214B8AC334A8F954BFDFB3B5C5484388A5E3BF6994B5B913BA668B7217 ] C:\Program Files (x86)\AVG\Av\avuirunnerx.exe
22:18:02.0419 0x1c0c AVG_UI - ok
22:18:02.0481 0x1c0c OneDriveSetup - ok
22:18:02.0481 0x1c0c OneDriveSetup - ok
22:18:02.0528 0x1c0c Iperius Backup - ok
22:18:02.0747 0x1c0c [ E93D62A6DB736AA82A3EEDDFDFE73311, 96EC57F66EE1A36580536518A814299DE6D5DACC0026F5A659B41918434ED8FA ] C:\Program Files\CCleaner\CCleaner64.exe
22:18:02.0919 0x1c0c CCleaner Monitoring - ok
22:18:03.0044 0x1c0c [ 2010CA459E5EC8F9D5FC8B000D130294, 058FF215A3AAD04F2A4CF23B2CC62A5EA28F5A705EFA689DCE9126720CF33229 ] C:\Users\Silvia\AppData\Local\Microsoft\OneDrive\OneDrive.exe
22:18:03.0075 0x1c0c OneDrive - ok
22:18:03.0075 0x1c0c Waiting for KSN requests completion. In queue: 34
22:18:04.0106 0x1c0c AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.494 ), 0x62100 ( disabled : updated )
22:18:04.0106 0x1c0c AV detected via SS2: AVG AntiVirus Free Edition, C:\Program Files (x86)\AVG\Av\avgwsc.exe ( 16.81.0.7640 ), 0x41000 ( enabled : updated )
22:18:04.0106 0x1c0c Win FW state via NFP2: enabled ( trusted )
22:18:04.0372 0x1c0c ============================================================
22:18:04.0372 0x1c0c Scan finished
22:18:04.0372 0x1c0c ============================================================
22:18:04.0372 0x1ea8 Detected object count: 0
22:18:04.0372 0x1ea8 Actual detected object count: 0
22:18:30.0778 0x0824 Deinitialize success |