troianjoerg | 08.08.2016 10:42 | Code:
11:20:17.0915 0x19dc TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12
11:20:17.0915 0x19dc UEFI system
11:20:22.0146 0x19dc ============================================================
11:20:22.0146 0x19dc Current date / time: 2016/08/03 11:20:22.0146
11:20:22.0146 0x19dc SystemInfo:
11:20:22.0148 0x19dc
11:20:22.0148 0x19dc OS Version: 10.0.10586 ServicePack: 0.0
11:20:22.0148 0x19dc Product type: Workstation
11:20:22.0148 0x19dc ComputerName: TECHNIK-WIRTZ
11:20:22.0149 0x19dc UserName: user
11:20:22.0149 0x19dc Windows directory: C:\WINDOWS
11:20:22.0149 0x19dc System windows directory: C:\WINDOWS
11:20:22.0149 0x19dc Running under WOW64
11:20:22.0149 0x19dc Processor architecture: Intel x64
11:20:22.0149 0x19dc Number of processors: 8
11:20:22.0149 0x19dc Page size: 0x1000
11:20:22.0149 0x19dc Boot type: Normal boot
11:20:22.0149 0x19dc ============================================================
11:20:23.0192 0x19dc KLMD registered as C:\WINDOWS\system32\drivers\05155779.sys
11:20:23.0942 0x19dc System UUID: {1F752477-1F0E-A959-BEB2-91AEB1193823}
11:20:24.0546 0x19dc Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:20:24.0562 0x19dc ============================================================
11:20:24.0562 0x19dc \Device\Harddisk0\DR0:
11:20:24.0562 0x19dc GPT partitions:
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {9C08367F-9459-4943-9BEF-1F659CA45045}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0xFA000
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {796BADD3-6BBF-4D9F-B631-466EB71A4965}, UniqueGUID: {94011857-C4C3-4FD8-8967-EA5F56585D03}, Name: Basic data partition, StartLBA 0xFA800, BlocksNum 0x14000
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {867DC625-8248-4606-A3B0-A47AAD700259}, Name: Microsoft reserved partition, StartLBA 0x10E800, BlocksNum 0x40000
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {2EBE5239-57FF-4682-9D29-A289E1A24D3E}, Name: Basic data partition, StartLBA 0x14E800, BlocksNum 0x400000
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {273FCB84-FA86-48DB-A7FB-FD867EF7A396}, Name: Basic data partition, StartLBA 0x54E800, BlocksNum 0x72B52800
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {F9055C9D-FAEE-4A4E-AE82-420B662599A8}, Name: , StartLBA 0x730A1000, BlocksNum 0xE1000
11:20:24.0587 0x19dc \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {EF9F0A4B-9F32-44E6-AB85-351E1AF907AA}, Name: Microsoft recovery partition, StartLBA 0x73182000, BlocksNum 0x15845B0
11:20:24.0587 0x19dc MBR partitions:
11:20:24.0587 0x19dc ============================================================
11:20:24.0589 0x19dc C: <-> \Device\Harddisk0\DR0\Partition5
11:20:24.0589 0x19dc ============================================================
11:20:24.0589 0x19dc Initialize success
11:20:24.0589 0x19dc ============================================================
11:20:40.0099 0x22c4 ============================================================
11:20:40.0099 0x22c4 Scan started
11:20:40.0099 0x22c4 Mode: Manual;
11:20:40.0099 0x22c4 ============================================================
11:20:40.0099 0x22c4 KSN ping started
11:20:42.0406 0x22c4 KSN ping finished: true
11:20:51.0550 0x22c4 ================ Scan system memory ========================
11:20:51.0550 0x22c4 System memory - ok
11:20:51.0551 0x22c4 ================ Scan services =============================
11:20:52.0619 0x22c4 1394ohci - ok
11:20:52.0628 0x22c4 3ware - ok
11:20:52.0649 0x22c4 ACPI - ok
11:20:52.0654 0x22c4 acpiex - ok
11:20:52.0658 0x22c4 acpipagr - ok
11:20:52.0678 0x22c4 AcpiPmi - ok
11:20:52.0682 0x22c4 acpitime - ok
11:20:52.0692 0x22c4 ADP80XX - ok
11:20:52.0712 0x22c4 AFD - ok
11:20:52.0722 0x22c4 agp440 - ok
11:20:52.0730 0x22c4 ahcache - ok
11:20:52.0779 0x22c4 AJRouter - ok
11:20:52.0787 0x22c4 ALG - ok
11:20:52.0792 0x22c4 AmdK8 - ok
11:20:52.0798 0x22c4 AmdPPM - ok
11:20:52.0805 0x22c4 amdsata - ok
11:20:52.0809 0x22c4 amdsbs - ok
11:20:52.0812 0x22c4 amdxata - ok
11:20:52.0850 0x22c4 AppID - ok
11:20:52.0877 0x22c4 AppIDSvc - ok
11:20:52.0879 0x22c4 Appinfo - ok
11:20:52.0882 0x22c4 AppReadiness - ok
11:20:52.0900 0x22c4 AppXSvc - ok
11:20:52.0902 0x22c4 arcsas - ok
11:20:53.0095 0x22c4 aspnet_state - ok
11:20:53.0107 0x22c4 AsyncMac - ok
11:20:53.0114 0x22c4 atapi - ok
11:20:53.0253 0x22c4 [ 35A831D8736ACC3D3BF38F5D4C4D03DF, 7A843A4D9E9DC5D7015BD4EDB41778BD0EAFA2A2A2BE135F080D26CB8C30FFF5 ] athr C:\WINDOWS\System32\drivers\athw10x.sys
11:20:53.0326 0x22c4 athr - ok
11:20:53.0397 0x22c4 AudioEndpointBuilder - ok
11:20:53.0405 0x22c4 Audiosrv - ok
11:20:53.0446 0x22c4 AxInstSV - ok
11:20:53.0449 0x22c4 b06bdrv - ok
11:20:53.0458 0x22c4 BasicDisplay - ok
11:20:53.0460 0x22c4 BasicRender - ok
11:20:53.0464 0x22c4 bcmfn - ok
11:20:53.0466 0x22c4 bcmfn2 - ok
11:20:53.0470 0x22c4 BDESVC - ok
11:20:53.0478 0x22c4 Beep - ok
11:20:53.0489 0x22c4 BFE - ok
11:20:53.0503 0x22c4 BITS - ok
11:20:53.0505 0x22c4 bowser - ok
11:20:53.0532 0x22c4 BrokerInfrastructure - ok
11:20:53.0538 0x22c4 Browser - ok
11:20:53.0560 0x22c4 [ C6978F7EBA6F37D626482AC6B9390630, B4BF939AB9962A61DE9518604C20347DC2A6FCDCEB3D8AEF295AF12E6F2CDCF3 ] BTATH_BUS C:\WINDOWS\System32\drivers\btath_bus.sys
11:20:53.0580 0x22c4 BTATH_BUS - ok
11:20:53.0623 0x22c4 [ 239A81CC18170F3369D389DA65E74342, 5E26976176A6651B149784B1ED86ECCA133B7755EBB8B04361A8DDB705767AA3 ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys
11:20:53.0652 0x22c4 BtFilter - ok
11:20:53.0676 0x22c4 BthAvrcpTg - ok
11:20:53.0682 0x22c4 BthEnum - ok
11:20:53.0687 0x22c4 BthHFEnum - ok
11:20:53.0690 0x22c4 bthhfhid - ok
11:20:53.0705 0x22c4 BthHFSrv - ok
11:20:53.0720 0x22c4 BthLEEnum - ok
11:20:53.0723 0x22c4 BTHMODEM - ok
11:20:53.0726 0x22c4 BthPan - ok
11:20:53.0730 0x22c4 BTHPORT - ok
11:20:53.0733 0x22c4 bthserv - ok
11:20:53.0738 0x22c4 BTHUSB - ok
11:20:53.0741 0x22c4 buttonconverter - ok
11:20:53.0841 0x22c4 c2wts - ok
11:20:53.0848 0x22c4 CapImg - ok
11:20:53.0867 0x22c4 cdfs - ok
11:20:53.0912 0x22c4 CDPSvc - ok
11:20:53.0920 0x22c4 cdrom - ok
11:20:53.0928 0x22c4 CertPropSvc - ok
11:20:53.0935 0x22c4 circlass - ok
11:20:53.0943 0x22c4 CLFS - ok
11:20:53.0963 0x22c4 ClipSVC - ok
11:20:54.0006 0x22c4 [ 3E76A1547F2448BCEE3D2F4AE3931AB5, 31B41723FAA4210A86B1AE02D6C052BD8B738C4B89FB0177C1AE997D24BA5B8C ] CLVirtualDrive C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys
11:20:54.0018 0x22c4 CLVirtualDrive - ok
11:20:54.0023 0x22c4 CmBatt - ok
11:20:54.0031 0x22c4 CNG - ok
11:20:54.0036 0x22c4 cnghwassist - ok
11:20:54.0357 0x22c4 CompositeBus - ok
11:20:54.0365 0x22c4 COMSysApp - ok
11:20:54.0374 0x22c4 condrv - ok
11:20:54.0407 0x22c4 CoreMessagingRegistrar - ok
11:20:54.0423 0x22c4 CryptSvc - ok
11:20:54.0495 0x22c4 dam - ok
11:20:54.0510 0x22c4 DcomLaunch - ok
11:20:54.0559 0x22c4 DcpSvc - ok
11:20:54.0578 0x22c4 [ B56714DED87E29377F1EE930691DADA2, B3C3BC4F546A786A93823C1471D560BF678A9C95237065E3B99B2B80E6C28131 ] DDDriver C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys
11:20:54.0580 0x22c4 DDDriver - ok
11:20:54.0587 0x22c4 defragsvc - ok
11:20:54.0901 0x22c4 [ E554163D138B79CD8C6EDF73187FC635, 0EDC0B76437B145607C39288F3E6B92975E3B406859EA8213BBE635A0C21922D ] DellDataVault C:\Program Files\Dell\DellDataVault\DellDataVault.exe
11:20:54.0981 0x22c4 DellDataVault - ok
11:20:55.0045 0x22c4 [ D8F74B93897C8FDF2EAF4C99E30500A4, 565D69AE486074C3E2D30EC8DCF11D720F1887BF45BF7EE1DF24DB012ED1F4A3 ] DellDataVaultWiz C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
11:20:55.0050 0x22c4 DellDataVaultWiz - ok
11:20:55.0069 0x22c4 [ DC3BD578642252FD9569B9CD75CEF81E, 63F44BC19389C19BA9F9E974BF2E5236AF7F66D9076943B9CF46775264BBE413 ] DellProf C:\WINDOWS\system32\drivers\DellProf.sys
11:20:55.0070 0x22c4 DellProf - ok
11:20:55.0083 0x22c4 DeviceAssociationService - ok
11:20:55.0086 0x22c4 DeviceInstall - ok
11:20:55.0088 0x22c4 DevQueryBroker - ok
11:20:55.0094 0x22c4 Dfsc - ok
11:20:55.0126 0x22c4 [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
11:20:55.0143 0x22c4 dg_ssudbus - ok
11:20:55.0151 0x22c4 Dhcp - ok
11:20:55.0204 0x22c4 diagnosticshub.standardcollector.service - ok
11:20:55.0222 0x22c4 DiagTrack - ok
11:20:55.0237 0x22c4 disk - ok
11:20:55.0262 0x22c4 DmEnrollmentSvc - ok
11:20:55.0282 0x22c4 dmvsc - ok
11:20:55.0291 0x22c4 dmwappushservice - ok
11:20:55.0314 0x22c4 Dnscache - ok
11:20:55.0326 0x22c4 dot3svc - ok
11:20:55.0339 0x22c4 DPS - ok
11:20:55.0354 0x22c4 drmkaud - ok
11:20:55.0365 0x22c4 DsmSvc - ok
11:20:55.0380 0x22c4 DsSvc - ok
11:20:55.0384 0x22c4 DXGKrnl - ok
11:20:55.0388 0x22c4 Eaphost - ok
11:20:55.0392 0x22c4 ebdrv - ok
11:20:55.0413 0x22c4 EFS - ok
11:20:55.0439 0x22c4 EhStorClass - ok
11:20:55.0449 0x22c4 EhStorTcgDrv - ok
11:20:55.0468 0x22c4 embeddedmode - ok
11:20:55.0470 0x22c4 EntAppSvc - ok
11:20:55.0473 0x22c4 ErrDev - ok
11:20:55.0478 0x22c4 EventSystem - ok
11:20:55.0481 0x22c4 exfat - ok
11:20:55.0484 0x22c4 fastfat - ok
11:20:55.0514 0x22c4 Fax - ok
11:20:55.0516 0x22c4 fdc - ok
11:20:55.0533 0x22c4 fdPHost - ok
11:20:55.0544 0x22c4 FDResPub - ok
11:20:55.0555 0x22c4 fhsvc - ok
11:20:55.0557 0x22c4 FileCrypt - ok
11:20:55.0566 0x22c4 FileInfo - ok
11:20:55.0569 0x22c4 Filetrace - ok
11:20:55.0665 0x22c4 [ F76D04F7413B07DAA029F6520B64B4E8, 3EB13C0EFE737880853FB8952381E7A57723F9472E0E4ED7CDA8A0D7DE8DC90D ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
11:20:55.0682 0x22c4 FLEXnet Licensing Service - ok
11:20:55.0685 0x22c4 flpydisk - ok
11:20:55.0688 0x22c4 FltMgr - ok
11:20:55.0690 0x22c4 FontCache - ok
11:20:55.0728 0x22c4 FontCache3.0.0.0 - ok
11:20:55.0739 0x22c4 FsDepends - ok
11:20:55.0742 0x22c4 Fs_Rec - ok
11:20:55.0835 0x22c4 [ 014195B03B378CFEAA029958CBC53695, 0F069F37CF83234929D618A78A58F369D0D033A4ABBC4AD02D37825E9857B731 ] fussvc C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe
11:20:55.0848 0x22c4 fussvc - ok
11:20:55.0856 0x22c4 fvevol - ok
11:20:55.0864 0x22c4 gagp30kx - ok
11:20:55.0935 0x22c4 gencounter - ok
11:20:55.0944 0x22c4 genericusbfn - ok
11:20:56.0101 0x22c4 [ A27A06D8359BC5202F2F8E3240DE205F, C2BB64106D6894E6CF45121FE3ECCDE2A00CAE9268CF5ECA11F436C10DBFC6F0 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
11:20:56.0135 0x22c4 GfExperienceService - ok
11:20:56.0141 0x22c4 GPIOClx0101 - ok
11:20:56.0143 0x22c4 gpsvc - ok
11:20:56.0170 0x22c4 GpuEnergyDrv - ok
11:20:56.0246 0x22c4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:20:56.0260 0x22c4 gupdate - ok
11:20:56.0273 0x22c4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:20:56.0281 0x22c4 gupdatem - ok
11:20:56.0288 0x22c4 HDAudBus - ok
11:20:56.0293 0x22c4 HidBatt - ok
11:20:56.0298 0x22c4 HidBth - ok
11:20:56.0314 0x22c4 hidi2c - ok
11:20:56.0325 0x22c4 hidinterrupt - ok
11:20:56.0333 0x22c4 HidIr - ok
11:20:56.0342 0x22c4 hidserv - ok
11:20:56.0370 0x22c4 HidUsb - ok
11:20:56.0414 0x22c4 HomeGroupListener - ok
11:20:56.0419 0x22c4 HomeGroupProvider - ok
11:20:56.0422 0x22c4 HpSAMD - ok
11:20:56.0433 0x22c4 HTTP - ok
11:20:56.0437 0x22c4 hwpolicy - ok
11:20:56.0439 0x22c4 hyperkbd - ok
11:20:56.0442 0x22c4 i8042prt - ok
11:20:56.0449 0x22c4 iai2c - ok
11:20:56.0462 0x22c4 iaLPSS2i_I2C - ok
11:20:56.0465 0x22c4 iaLPSSi_GPIO - ok
11:20:56.0473 0x22c4 iaLPSSi_I2C - ok
11:20:56.0527 0x22c4 [ 57CD95DEB3529181BCC931DD2DFB2341, 03ACF906E4C3CF954F503900F42C7A60FCD5624772B90A956F032484146E42B7 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
11:20:56.0555 0x22c4 iaStorA - ok
11:20:56.0568 0x22c4 iaStorAV - ok
11:20:56.0706 0x22c4 [ 20E83F4632E15A5E9E716FF2E8AC7FAE, 7CA1A4924F432AD30ED7FA6247C6513DA173EE31132AE115E85C0ED7E5971029 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
11:20:56.0723 0x22c4 IAStorDataMgrSvc - ok
11:20:56.0730 0x22c4 iaStorV - ok
11:20:56.0738 0x22c4 ibbus - ok
11:20:56.0779 0x22c4 icssvc - ok
11:20:56.0783 0x22c4 IEEtwCollectorService - ok
11:20:56.0803 0x22c4 IKEEXT - ok
11:20:56.0939 0x22c4 [ 48AC5F706780BCC34811EA89A0727189, F76EC13A5A0FD24D9B63B7546FF749739022D1785357AD06E3FAA7F608E8C714 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
11:20:57.0023 0x22c4 IntcAzAudAddService - ok
11:20:57.0114 0x22c4 [ 4C17F57E43645E75800E9E84787E34E5, 6A1531D97462BA3B3DBDAD472AF15B717C958AA8C5CE2373DE0B2A41C35BE33E ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
11:20:57.0138 0x22c4 Intel(R) Capability Licensing Service TCP IP Interface - ok
11:20:57.0226 0x22c4 [ 2390C395882F7773AB7D6CC2547B41DE, 220EBA14BC4A686ED9879D27900AD66ACD937899759A4319297E0F15DFAB247C ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
11:20:57.0234 0x22c4 Intel(R) ME Service - ok
11:20:57.0242 0x22c4 intelide - ok
11:20:57.0249 0x22c4 intelpep - ok
11:20:57.0255 0x22c4 intelppm - ok
11:20:57.0259 0x22c4 IoQos - ok
11:20:57.0264 0x22c4 IpFilterDriver - ok
11:20:57.0281 0x22c4 iphlpsvc - ok
11:20:57.0284 0x22c4 IPMIDRV - ok
11:20:57.0288 0x22c4 IPNAT - ok
11:20:57.0303 0x22c4 IRENUM - ok
11:20:57.0313 0x22c4 isapnp - ok
11:20:57.0325 0x22c4 iScsiPrt - ok
11:20:57.0437 0x22c4 [ 16B5B394028D8ED80A569123A38DC4F7, 19839364B7A48584615F0ED56D94AB6E6F8159EAD826605F74C73845CE2C5C12 ] iumsvc C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
11:20:57.0446 0x22c4 iumsvc - ok
11:20:57.0472 0x22c4 [ BDC9C7931DB723CB1AF9F7075EA06645, EEBD5DC9C4656F14F8F0A0A5E84657B6B2BA35283E0E571119DA82F131D5C21B ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
11:20:57.0475 0x22c4 jhi_service - ok
11:20:57.0477 0x22c4 kbdclass - ok
11:20:57.0478 0x22c4 kbdhid - ok
11:20:57.0480 0x22c4 kdnic - ok
11:20:57.0482 0x22c4 KeyIso - ok
11:20:57.0487 0x22c4 KSecDD - ok
11:20:57.0490 0x22c4 KSecPkg - ok
11:20:57.0492 0x22c4 ksthunk - ok
11:20:57.0546 0x22c4 KtmRm - ok
11:20:57.0552 0x22c4 LanmanServer - ok
11:20:57.0555 0x22c4 LanmanWorkstation - ok
11:20:57.0601 0x22c4 [ 808AEDFB82408AF854A32EFBF54F7066, CBD0E6F367BD6DEE1A2C9F6754BC3BE18AFD5715D3D69399D3104406127BB32A ] Lexware_Update_Service C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe
11:20:57.0610 0x22c4 Lexware_Update_Service - ok
11:20:57.0612 0x22c4 lfsvc - ok
11:20:57.0613 0x22c4 LicenseManager - ok
11:20:57.0615 0x22c4 lltdio - ok
11:20:57.0635 0x22c4 lltdsvc - ok
11:20:57.0650 0x22c4 lmhosts - ok
11:20:57.0676 0x22c4 [ A7D2A96187E5C5F4F7650900A15788AA, F131C3E8206A89A9244ECF2507F4FC1A8550E594A58F75338939A54C973078AF ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:20:57.0682 0x22c4 LMS - ok
11:20:57.0685 0x22c4 LSI_SAS - ok
11:20:57.0700 0x22c4 LSI_SAS2i - ok
11:20:57.0702 0x22c4 LSI_SAS3i - ok
11:20:57.0704 0x22c4 LSI_SSS - ok
11:20:57.0708 0x22c4 LSM - ok
11:20:57.0710 0x22c4 luafv - ok
11:20:57.0714 0x22c4 MapsBroker - ok
11:20:57.0766 0x22c4 [ 78BFF5425E044086E74E78650A359FBB, 294738C10F3ED933D4EC40EA0659372FCF19A3C6D45D356917438CA495F2CB45 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
11:20:57.0767 0x22c4 MBAMProtector - ok
11:20:57.0847 0x22c4 [ 9611577752E293259C7DCE19E9026362, 8CB5DFD63FA15603BB6FA6B501E09ED7F4DE0E8F68CB28B78CECAC3711BEFD24 ] MBAMScheduler C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
11:20:57.0888 0x22c4 MBAMScheduler - ok
11:20:57.0960 0x22c4 [ F1A89A34388B5626F1548D393B23ECB1, EA00AC76C4C8C9340753B58A3313C9177A9B98F9F1BDE08F184CD0F53D0C186F ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
11:20:57.0979 0x22c4 MBAMService - ok
11:20:57.0999 0x22c4 [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
11:20:58.0002 0x22c4 MBAMSwissArmy - ok
11:20:58.0019 0x22c4 [ 898415AC0B5F1D2A9A48ABCB68A6DC4B, E1FD9AE5E22E3E5A18288E66A6184E92A4B63A1274DCE147A7728BB09C6A225E ] MBAMWebAccessControl C:\WINDOWS\system32\drivers\mwac.sys
11:20:58.0021 0x22c4 MBAMWebAccessControl - ok
11:20:58.0087 0x22c4 [ ED1D9AB517A038ACC0EC298CD62438CA, 61617915D0804C0D20C6EC0EDB46EA2B6FB37E3574DA9F8832D9743F1092E443 ] McAfee SiteAdvisor Service C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
11:20:58.0096 0x22c4 McAfee SiteAdvisor Service - ok
11:20:58.0221 0x22c4 [ 11F714F85530A2BD134074DC30E99FCA, BDB5FD3B2DF4ADD19B31965B3E789768B59E872B3EA85912B1FFB32B2AF9D5D8 ] MDM C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
11:20:58.0234 0x22c4 MDM - ok
11:20:58.0239 0x22c4 megasas - ok
11:20:58.0242 0x22c4 megasr - ok
11:20:58.0257 0x22c4 [ AFEA4FAABCE6F0C299E9231FF4F466BE, BCF0C50F02C4AC2784139935F3756F5C4D24FCAF07ACD9567B87991A9D1F16DB ] MEIx64 C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
11:20:58.0260 0x22c4 MEIx64 - ok
11:20:58.0275 0x22c4 MessagingService - ok
11:20:58.0379 0x22c4 [ B8487AB1E90E38BF428216D2772F450F, 5416951B35F7A5B63434D371C9FA81DA2656852A82D2613191AC2056FB8F895A ] mfesapsn C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys
11:20:58.0380 0x22c4 mfesapsn - ok
11:20:58.0382 0x22c4 mlx4_bus - ok
11:20:58.0385 0x22c4 MMCSS - ok
11:20:58.0387 0x22c4 Modem - ok
11:20:58.0390 0x22c4 monitor - ok
11:20:58.0392 0x22c4 mouclass - ok
11:20:58.0396 0x22c4 mouhid - ok
11:20:58.0398 0x22c4 mountmgr - ok
11:20:58.0457 0x22c4 [ D6F67A73E6557578B755F7B534E00F47, 769F3D6CB86B2DC4065BDE4CE39139879B7D96F455A3BE80C7ECEAD5494E8B79 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:20:58.0464 0x22c4 MozillaMaintenance - ok
11:20:58.0470 0x22c4 mpsdrv - ok
11:20:58.0487 0x22c4 MpsSvc - ok
11:20:58.0491 0x22c4 MRxDAV - ok
11:20:58.0494 0x22c4 mrxsmb - ok
11:20:58.0498 0x22c4 mrxsmb10 - ok
11:20:58.0503 0x22c4 mrxsmb20 - ok
11:20:58.0509 0x22c4 MsBridge - ok
11:20:58.0531 0x22c4 MSDTC - ok
11:20:58.0535 0x22c4 Msfs - ok
11:20:58.0559 0x22c4 msgpiowin32 - ok
11:20:58.0562 0x22c4 mshidkmdf - ok
11:20:58.0566 0x22c4 mshidumdf - ok
11:20:58.0569 0x22c4 msisadrv - ok
11:20:58.0593 0x22c4 MSiSCSI - ok
11:20:58.0596 0x22c4 msiserver - ok
11:20:58.0598 0x22c4 MSKSSRV - ok
11:20:58.0600 0x22c4 MsLldp - ok
11:20:58.0602 0x22c4 MSPCLOCK - ok
11:20:58.0604 0x22c4 MSPQM - ok
11:20:58.0608 0x22c4 MsRPC - ok
11:20:58.0611 0x22c4 mssmbios - ok
11:20:58.0613 0x22c4 MSTEE - ok
11:20:58.0615 0x22c4 MTConfig - ok
11:20:58.0617 0x22c4 Mup - ok
11:20:58.0621 0x22c4 mvumis - ok
11:20:58.0625 0x22c4 NativeWifiP - ok
11:20:58.0648 0x22c4 NcaSvc - ok
11:20:58.0654 0x22c4 NcbService - ok
11:20:58.0656 0x22c4 NcdAutoSetup - ok
11:20:58.0657 0x22c4 ndfltr - ok
11:20:58.0659 0x22c4 NDIS - ok
11:20:58.0661 0x22c4 NdisCap - ok
11:20:58.0662 0x22c4 NdisImPlatform - ok
11:20:58.0664 0x22c4 NdisTapi - ok
11:20:58.0666 0x22c4 Ndisuio - ok
11:20:58.0669 0x22c4 NdisVirtualBus - ok
11:20:58.0671 0x22c4 NdisWan - ok
11:20:58.0672 0x22c4 ndiswanlegacy - ok
11:20:58.0674 0x22c4 ndproxy - ok
11:20:58.0676 0x22c4 Ndu - ok
11:20:58.0678 0x22c4 NetBIOS - ok
11:20:58.0681 0x22c4 NetBT - ok
11:20:58.0682 0x22c4 Netlogon - ok
11:20:58.0693 0x22c4 Netman - ok
11:20:58.0700 0x22c4 netprofm - ok
11:20:58.0710 0x22c4 NetSetupSvc - ok
11:20:58.0841 0x22c4 NetTcpPortSharing - ok
11:20:58.0849 0x22c4 NgcCtnrSvc - ok
11:20:58.0852 0x22c4 NgcSvc - ok
11:20:58.0872 0x22c4 NlaSvc - ok
11:20:58.0883 0x22c4 Npfs - ok
11:20:58.0902 0x22c4 npsvctrig - ok
11:20:58.0914 0x22c4 nsi - ok
11:20:58.0917 0x22c4 nsiproxy - ok
11:20:58.0925 0x22c4 NTFS - ok
11:20:58.0950 0x22c4 Null - ok
11:20:58.0979 0x22c4 [ 7A0AA6E6967155DF0FDC82EA124B2E34, 3603954E5E33D73274464A3D4D52C5253E8298363D3DC33C43E1A74B1E3CDCF5 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
11:20:59.0000 0x22c4 NVHDA - ok
11:20:59.0746 0x22c4 [ 2AA6C5CBB9AFEFC82A3A4CAF0740B4CD, 19B835B06272BE776338CBE62D273D0583F9331B1FE1C3EB8C15B99368FFBC38 ] nvlddmkm C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
11:20:59.0919 0x22c4 nvlddmkm - ok
11:21:00.0089 0x22c4 [ 507E699BD36530491BA0F95251B22F06, BDE6EB91FADBCB8CE16C31EF43A97DC6CC5D0F4EBAEA7903810556D0D70F54BC ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
11:21:00.0373 0x22c4 NvNetworkService - ok
11:21:00.0427 0x22c4 [ 473EE68E7A5D9A21BE653C10B2665ACF, 3DD9A31B22DD4378D18D87E4EA8CB184CEAD225F0D3774FE9E7B12164FF89AEE ] nvpciflt C:\WINDOWS\system32\DRIVERS\nvpciflt.sys
11:21:00.0489 0x22c4 nvpciflt - ok
11:21:00.0561 0x22c4 nvraid - ok
11:21:00.0564 0x22c4 nvstor - ok
11:21:00.0600 0x22c4 [ 7E4C1879248629A2C9CC9ADF52CBB9B7, 856FF60FD111C3C80B137BC62B7EF92D3B95FBA462A29F97D65457A5A507506E ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
11:21:00.0601 0x22c4 NvStreamKms - ok
11:21:02.0282 0x22c4 [ C3EB27E4BC00283CA166A9FC42B90FC7, FED7F68D1C6EB442292E40DCFAEE7339AE21D5EF726A9DC9BCB6AB5C5873B3E0 ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
11:21:02.0634 0x22c4 NvStreamSvc - ok
11:21:02.0747 0x22c4 [ 25FEA7ECF2CCC69284BA2FE962AA7E30, 04A0F2316B3E08C330510DCD1CEAFD8E1170BB0842C64592722F913FA1B8A57A ] NvStUSB C:\WINDOWS\System32\drivers\nvstusb.sys
11:21:02.0767 0x22c4 NvStUSB - ok
11:21:02.0951 0x22c4 [ 90566025EFD5BA4005A5C9A2773B230B, 9075981E7020250E38D25C046E39C69B252B46888A9F6F749FF50FB442907E37 ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
11:21:02.0970 0x22c4 nvsvc - ok
11:21:03.0003 0x22c4 [ 1AF619620613869C07F9C147BC37520F, 0AD4E100354E201D5E72BA236C1464F5083A7E3B58C4AC6BA712489D258955F5 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
11:21:03.0015 0x22c4 nvvad_WaveExtensible - ok
11:21:03.0017 0x22c4 nv_agp - ok
11:21:03.0029 0x22c4 OneSyncSvc - ok
11:21:03.0064 0x22c4 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:21:03.0067 0x22c4 ose - ok
11:21:03.0551 0x22c4 [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:21:03.0663 0x22c4 osppsvc - ok
11:21:03.0718 0x22c4 p2pimsvc - ok
11:21:03.0725 0x22c4 p2psvc - ok
11:21:03.0745 0x22c4 Parport - ok
11:21:03.0749 0x22c4 partmgr - ok
11:21:03.0753 0x22c4 PcaSvc - ok
11:21:03.0764 0x22c4 pci - ok
11:21:03.0777 0x22c4 pciide - ok
11:21:03.0782 0x22c4 pcmcia - ok
11:21:03.0787 0x22c4 pcw - ok
11:21:03.0804 0x22c4 pdc - ok
11:21:03.0820 0x22c4 PEAUTH - ok
11:21:03.0843 0x22c4 percsas2i - ok
11:21:03.0862 0x22c4 percsas3i - ok
11:21:04.0523 0x22c4 PerfHost - ok
11:21:04.0541 0x22c4 PhoneSvc - ok
11:21:04.0566 0x22c4 PimIndexMaintenanceSvc - ok
11:21:04.0577 0x22c4 pla - ok
11:21:04.0611 0x22c4 PlugPlay - ok
11:21:04.0618 0x22c4 PNRPAutoReg - ok
11:21:04.0623 0x22c4 PNRPsvc - ok
11:21:04.0641 0x22c4 PolicyAgent - ok
11:21:04.0650 0x22c4 Power - ok
11:21:04.0657 0x22c4 PptpMiniport - ok
11:21:05.0311 0x22c4 [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
11:21:05.0353 0x22c4 PrintNotify - ok
11:21:05.0358 0x22c4 Processor - ok
11:21:05.0372 0x22c4 ProfSvc - ok
11:21:05.0374 0x22c4 Psched - ok
11:21:05.0386 0x22c4 QWAVE - ok
11:21:05.0403 0x22c4 QWAVEdrv - ok
11:21:05.0405 0x22c4 RasAcd - ok
11:21:05.0423 0x22c4 RasAgileVpn - ok
11:21:05.0450 0x22c4 RasAuto - ok
11:21:05.0459 0x22c4 Rasl2tp - ok
11:21:05.0509 0x22c4 RasMan - ok
11:21:05.0511 0x22c4 RasPppoe - ok
11:21:05.0521 0x22c4 RasSstp - ok
11:21:05.0523 0x22c4 rdbss - ok
11:21:05.0526 0x22c4 rdpbus - ok
11:21:05.0532 0x22c4 RDPDR - ok
11:21:05.0555 0x22c4 RdpVideoMiniport - ok
11:21:05.0560 0x22c4 rdyboost - ok
11:21:05.0565 0x22c4 ReFSv1 - ok
11:21:05.0587 0x22c4 RemoteAccess - ok
11:21:05.0627 0x22c4 RemoteRegistry - ok
11:21:05.0651 0x22c4 RetailDemo - ok
11:21:05.0664 0x22c4 RFCOMM - ok
11:21:05.0737 0x22c4 [ CBE300DA6064C31F2AC4ED8A0722BEF0, D98D41937E36390426F521713AF2BAA1E49E750BBEAC420D1BD770EB303F1E4F ] RichVideo C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
11:21:05.0756 0x22c4 RichVideo - ok
11:21:05.0768 0x22c4 RpcEptMapper - ok
11:21:05.0780 0x22c4 RpcLocator - ok
11:21:05.0784 0x22c4 RpcSs - ok
11:21:05.0788 0x22c4 rspndr - ok
11:21:05.0827 0x22c4 [ 9CF8593B62102545CB1652A1D8748FDD, 818639795720A7567CCE01EBC24A0119BFDCEA1B7A5ED4A11B5012D763C1B5CC ] RSUSBSTOR C:\WINDOWS\System32\Drivers\RtsUStor.sys
11:21:05.0837 0x22c4 RSUSBSTOR - ok
11:21:05.0911 0x22c4 [ DBE1ADA144291F8E0F29ECC40AE14562, D85E5F698EFC6B2374FB330BE4C6828AA3E1A87D3F08BB855A790A5113D5ED5B ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
11:21:05.0925 0x22c4 RtkAudioService - ok
11:21:06.0062 0x22c4 [ 948D5E71CF9DB59961353A355EA45139, A23D012B07A92CC217C67C904CDFBA2BCCDCC2BD49B24FB694BD230D000F2B7B ] RTL8168 C:\WINDOWS\System32\drivers\Rt630x64.sys
11:21:06.0108 0x22c4 RTL8168 - ok
11:21:06.0155 0x22c4 [ 03E76CF0657BCABA2D7F7EE4384E6562, DCCAA648A34358B3DDBF908E2136C4A3460A297AC9E001B6709C65A9F320EB07 ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
11:21:06.0171 0x22c4 RTSUER - ok
11:21:06.0176 0x22c4 s3cap - ok
11:21:06.0191 0x22c4 SamSs - ok
11:21:06.0202 0x22c4 sbp2port - ok
11:21:06.0211 0x22c4 SCardSvr - ok
11:21:06.0213 0x22c4 ScDeviceEnum - ok
11:21:06.0216 0x22c4 scfilter - ok
11:21:06.0223 0x22c4 Schedule - ok
11:21:06.0232 0x22c4 SCPolicySvc - ok
11:21:06.0240 0x22c4 sdbus - ok
11:21:06.0242 0x22c4 SDRSVC - ok
11:21:06.0244 0x22c4 sdstor - ok
11:21:06.0245 0x22c4 seclogon - ok
11:21:06.0248 0x22c4 SENS - ok
11:21:06.0249 0x22c4 SensorDataService - ok
11:21:06.0257 0x22c4 SensorService - ok
11:21:06.0259 0x22c4 SensorsSimulatorDriver - ok
11:21:06.0261 0x22c4 SensrSvc - ok
11:21:06.0262 0x22c4 SerCx - ok
11:21:06.0264 0x22c4 SerCx2 - ok
11:21:06.0266 0x22c4 Serenum - ok
11:21:06.0268 0x22c4 Serial - ok
11:21:06.0269 0x22c4 sermouse - ok
11:21:06.0275 0x22c4 SessionEnv - ok
11:21:06.0277 0x22c4 sfloppy - ok
11:21:06.0279 0x22c4 SharedAccess - ok
11:21:06.0293 0x22c4 ShellHWDetection - ok
11:21:06.0296 0x22c4 SiSRaid2 - ok
11:21:06.0297 0x22c4 SiSRaid4 - ok
11:21:06.0299 0x22c4 smphost - ok
11:21:06.0302 0x22c4 SmsRouter - ok
11:21:06.0307 0x22c4 SNMPTRAP - ok
11:21:06.0319 0x22c4 spaceport - ok
11:21:06.0321 0x22c4 SpbCx - ok
11:21:06.0324 0x22c4 Spooler - ok
11:21:06.0326 0x22c4 sppsvc - ok
11:21:06.0398 0x22c4 [ 055B0DE7BCDB14FB18279F09DCA07954, 94944F996F2F73233A96F8E766606EA5CCC7142EA2AF4BCEFD2603578F2B4A4A ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
11:21:06.0407 0x22c4 SQLWriter - ok
11:21:06.0411 0x22c4 srv - ok
11:21:06.0415 0x22c4 srv2 - ok
11:21:06.0419 0x22c4 srvnet - ok
11:21:06.0423 0x22c4 SSDPSRV - ok
11:21:06.0427 0x22c4 SstpSvc - ok
11:21:06.0475 0x22c4 [ 5252D7BC56E5E0ED715AEA8FE173A455, 1408B3E98B35A449434718777EE70595F0D306197A428279C6281D2F1953F259 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
11:21:06.0484 0x22c4 ssudmdm - ok
11:21:06.0486 0x22c4 StateRepository - ok
11:21:06.0594 0x22c4 [ 49B1E5AF3AA400752A20BE169CB73DFA, D990BC79B289912EB07F3FD50F1236C593A45C5E9B7BD8162269687258E07CE2 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
11:21:06.0615 0x22c4 Stereo Service - ok
11:21:06.0620 0x22c4 stexstor - ok
11:21:06.0624 0x22c4 stisvc - ok
11:21:06.0628 0x22c4 storahci - ok
11:21:06.0632 0x22c4 storflt - ok
11:21:06.0635 0x22c4 stornvme - ok
11:21:06.0640 0x22c4 storqosflt - ok
11:21:06.0642 0x22c4 StorSvc - ok
11:21:06.0645 0x22c4 storufs - ok
11:21:06.0647 0x22c4 storvsc - ok
11:21:06.0744 0x22c4 [ 1957C598952FBE08193EE43A109FD3DD, A0E77C20B263BD911AE3D7842210E65DD5D0E64191201553154205F64CFA8D70 ] SupportAssistAgent C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
11:21:06.0765 0x22c4 SupportAssistAgent - ok
11:21:06.0788 0x22c4 svsvc - ok
11:21:06.0792 0x22c4 swenum - ok
11:21:06.0967 0x22c4 [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
11:21:06.0988 0x22c4 SwitchBoard - ok
11:21:06.0992 0x22c4 swprv - ok
11:21:07.0017 0x22c4 Synth3dVsc - ok
11:21:07.0024 0x22c4 SysMain - ok
11:21:07.0044 0x22c4 SystemEventsBroker - ok
11:21:07.0054 0x22c4 TabletInputService - ok
11:21:07.0065 0x22c4 TapiSrv - ok
11:21:07.0075 0x22c4 Tcpip - ok
11:21:07.0085 0x22c4 Tcpip6 - ok
11:21:07.0096 0x22c4 tcpipreg - ok
11:21:07.0103 0x22c4 tdx - ok
11:21:07.0185 0x22c4 [ 950AD1AE7498A492126FB9F9B2E27DB5, C4C9A972015F567FC87A4094C86835B2DD3476426AB8B40CD4872A725CA89CFC ] Te.Service C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe
11:21:07.0196 0x22c4 Te.Service - ok
11:21:07.0680 0x22c4 [ CFC9B7B465283378D374D5E380D5D244, 5E66A62C6A6272B65181F116031AA80E8DCEDA3B7E2C1130DD631347DF644D79 ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
11:21:07.0772 0x22c4 TeamViewer - ok
11:21:07.0794 0x22c4 terminpt - ok
11:21:07.0799 0x22c4 TermService - ok
11:21:07.0820 0x22c4 Themes - ok
11:21:07.0832 0x22c4 TieringEngineService - ok
11:21:07.0840 0x22c4 tiledatamodelsvc - ok
11:21:07.0842 0x22c4 TimeBroker - ok
11:21:07.0852 0x22c4 TPM - ok
11:21:07.0858 0x22c4 TrkWks - ok
11:21:07.0888 0x22c4 TrustedInstaller - ok
11:21:07.0891 0x22c4 tsusbflt - ok
11:21:07.0893 0x22c4 TsUsbGD - ok
11:21:07.0906 0x22c4 tunnel - ok
11:21:07.0921 0x22c4 tzautoupdate - ok
11:21:07.0922 0x22c4 uagp35 - ok
11:21:07.0929 0x22c4 UASPStor - ok
11:21:07.0934 0x22c4 UcmCx0101 - ok
11:21:07.0939 0x22c4 UcmUcsi - ok
11:21:07.0944 0x22c4 Ucx01000 - ok
11:21:07.0951 0x22c4 UdeCx - ok
11:21:07.0969 0x22c4 udfs - ok
11:21:07.0972 0x22c4 UEFI - ok
11:21:07.0987 0x22c4 Ufx01000 - ok
11:21:08.0010 0x22c4 UfxChipidea - ok
11:21:08.0031 0x22c4 ufxsynopsys - ok
11:21:08.0050 0x22c4 UI0Detect - ok
11:21:08.0057 0x22c4 uliagpkx - ok
11:21:08.0061 0x22c4 umbus - ok
11:21:08.0069 0x22c4 UmPass - ok
11:21:08.0079 0x22c4 UmRdpService - ok
11:21:08.0082 0x22c4 UnistoreSvc - ok
11:21:08.0087 0x22c4 upnphost - ok
11:21:08.0118 0x22c4 UrsChipidea - ok
11:21:08.0120 0x22c4 UrsCx01000 - ok
11:21:08.0123 0x22c4 UrsSynopsys - ok
11:21:08.0126 0x22c4 usbccgp - ok
11:21:08.0128 0x22c4 usbcir - ok
11:21:08.0131 0x22c4 usbehci - ok
11:21:08.0137 0x22c4 usbhub - ok
11:21:08.0150 0x22c4 USBHUB3 - ok
11:21:08.0163 0x22c4 usbohci - ok
11:21:08.0178 0x22c4 usbprint - ok
11:21:08.0185 0x22c4 usbser - ok
11:21:08.0194 0x22c4 USBSTOR - ok
11:21:08.0205 0x22c4 usbuhci - ok
11:21:08.0213 0x22c4 USBXHCI - ok
11:21:08.0226 0x22c4 UserDataSvc - ok
11:21:08.0246 0x22c4 UserManager - ok
11:21:08.0249 0x22c4 UsoSvc - ok
11:21:08.0252 0x22c4 VaultSvc - ok
11:21:08.0254 0x22c4 vdrvroot - ok
11:21:08.0257 0x22c4 vds - ok
11:21:08.0259 0x22c4 VerifierExt - ok
11:21:08.0262 0x22c4 vhdmp - ok
11:21:08.0265 0x22c4 vhf - ok
11:21:08.0267 0x22c4 vmbus - ok
11:21:08.0270 0x22c4 VMBusHID - ok
11:21:08.0312 0x22c4 vmicguestinterface - ok
11:21:08.0315 0x22c4 vmicheartbeat - ok
11:21:08.0320 0x22c4 vmickvpexchange - ok
11:21:08.0323 0x22c4 vmicrdv - ok
11:21:08.0326 0x22c4 vmicshutdown - ok
11:21:08.0341 0x22c4 vmictimesync - ok
11:21:08.0344 0x22c4 vmicvmsession - ok
11:21:08.0346 0x22c4 vmicvss - ok
11:21:08.0349 0x22c4 volmgr - ok
11:21:08.0352 0x22c4 volmgrx - ok
11:21:08.0353 0x22c4 volsnap - ok
11:21:08.0355 0x22c4 vpci - ok
11:21:08.0376 0x22c4 [ 9B4F6978628D07FAEBF77FF6F8F2960D, FC36FE6BE77445D55E4E92CE3EAF172E253EC8CF8D2EBCA204969CF21FFA5600 ] VsEtwService120 C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe
11:21:08.0377 0x22c4 VsEtwService120 - ok
11:21:08.0380 0x22c4 vsmraid - ok
11:21:08.0381 0x22c4 VSS - ok
11:21:08.0383 0x22c4 VSTXRAID - ok
11:21:08.0385 0x22c4 vwifibus - ok
11:21:08.0387 0x22c4 vwififlt - ok
11:21:08.0388 0x22c4 vwifimp - ok
11:21:08.0402 0x22c4 W32Time - ok
11:21:08.0404 0x22c4 WacomPen - ok
11:21:08.0411 0x22c4 WalletService - ok
11:21:08.0413 0x22c4 wanarp - ok
11:21:08.0414 0x22c4 wanarpv6 - ok
11:21:08.0416 0x22c4 wbengine - ok
11:21:08.0418 0x22c4 WbioSrvc - ok
11:21:08.0420 0x22c4 Wcmsvc - ok
11:21:08.0422 0x22c4 wcncsvc - ok
11:21:08.0424 0x22c4 WcsPlugInService - ok
11:21:08.0426 0x22c4 WdBoot - ok
11:21:08.0428 0x22c4 Wdf01000 - ok
11:21:08.0430 0x22c4 WdFilter - ok
11:21:08.0432 0x22c4 WdiServiceHost - ok
11:21:08.0435 0x22c4 WdiSystemHost - ok
11:21:08.0439 0x22c4 wdiwifi - ok
11:21:08.0446 0x22c4 WdNisDrv - ok
11:21:08.0477 0x22c4 WdNisSvc - ok
11:21:08.0480 0x22c4 WebClient - ok
11:21:08.0566 0x22c4 [ D41BC1D8D635E90DF0D6768E440060CD, B0D7BDB0FD87A6ACB0C96037987B96A3F12A607D45E92798E7B59EF0BB224996 ] weClientDataTransferService C:\Program Files (x86)\Dell\Client\wecdt.exe
11:21:08.0626 0x22c4 weClientDataTransferService - ok
11:21:08.0654 0x22c4 [ 73584ABD1CB73F8C34FA9769BD6261BE, 012D29D8DBB0DC5DE774CE63346C97BDEF3E5D68A607CEBC7F349150CFC1B6BA ] weClientMessengerService C:\Program Files (x86)\Dell\Client\wecmsg.exe
11:21:08.0675 0x22c4 weClientMessengerService - ok
11:21:08.0678 0x22c4 Wecsvc - ok
11:21:08.0680 0x22c4 WEPHOSTSVC - ok
11:21:08.0693 0x22c4 wercplsupport - ok
11:21:08.0695 0x22c4 WerSvc - ok
11:21:08.0703 0x22c4 WFPLWFS - ok
11:21:08.0705 0x22c4 WiaRpc - ok
11:21:08.0707 0x22c4 WIMMount - ok
11:21:08.0708 0x22c4 WinDefend - ok
11:21:08.0712 0x22c4 WindowsTrustedRT - ok
11:21:08.0717 0x22c4 WindowsTrustedRTProxy - ok
11:21:08.0719 0x22c4 WinHttpAutoProxySvc - ok
11:21:08.0721 0x22c4 WinMad - ok
11:21:08.0936 0x22c4 Winmgmt - ok
11:21:08.0946 0x22c4 WinRM - ok
11:21:08.0995 0x22c4 WINUSB - ok
11:21:09.0002 0x22c4 WinVerbs - ok
11:21:09.0011 0x22c4 WlanSvc - ok
11:21:09.0046 0x22c4 wlidsvc - ok
11:21:09.0051 0x22c4 WmiAcpi - ok
11:21:09.0068 0x22c4 wmiApSrv - ok
11:21:09.0115 0x22c4 WMPNetworkSvc - ok
11:21:09.0148 0x22c4 [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys
11:21:09.0163 0x22c4 Wof - ok
11:21:09.0170 0x22c4 workfolderssvc - ok
11:21:09.0175 0x22c4 wpcfltr - ok
11:21:09.0180 0x22c4 WPDBusEnum - ok
11:21:09.0184 0x22c4 WpdUpFltr - ok
11:21:09.0189 0x22c4 WpnService - ok
11:21:09.0192 0x22c4 ws2ifsl - ok
11:21:09.0195 0x22c4 wscsvc - ok
11:21:09.0197 0x22c4 WSDPrintDevice - ok
11:21:09.0199 0x22c4 WSDScan - ok
11:21:09.0201 0x22c4 WSearch - ok
11:21:09.0205 0x22c4 WSService - ok
11:21:09.0208 0x22c4 wuauserv - ok
11:21:09.0210 0x22c4 WudfPf - ok
11:21:09.0212 0x22c4 WUDFRd - ok
11:21:09.0234 0x22c4 wudfsvc - ok
11:21:09.0236 0x22c4 WUDFWpdFs - ok
11:21:09.0238 0x22c4 WwanSvc - ok
11:21:09.0239 0x22c4 XblAuthManager - ok
11:21:09.0246 0x22c4 XblGameSave - ok
11:21:09.0255 0x22c4 xboxgip - ok
11:21:09.0257 0x22c4 XboxNetApiSvc - ok
11:21:09.0334 0x22c4 [ 5193C637BD0E080A1EC881A9204A4310, DDF58E94544267AEDC20DC1BCA1E72A8F8014E46A050A457D9D50E7E978EEBC5 ] XeroxPrintJobEventManagerService C:\Program Files\Xerox\XeroxPrintExperience\CommonFiles\XeroxPrintJobEventManagerService.exe
11:21:09.0354 0x22c4 XeroxPrintJobEventManagerService - ok
11:21:09.0362 0x22c4 xinputhid - ok
11:21:09.0392 0x22c4 [ DCF1C283860C3CAB0BF0A71528A0136C, DFC44E5337A8B37C54CA57D53F74E41BE2C0495AF2A566FE1E9A37C045BF4C84 ] XtuAcpiDriver C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys
11:21:09.0401 0x22c4 XtuAcpiDriver - ok
11:21:09.0401 0x22c4 ================ Scan global ===============================
11:21:09.0439 0x22c4 [ Global ] - ok
11:21:09.0440 0x22c4 ================ Scan MBR ==================================
11:21:09.0469 0x22c4 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
11:21:09.0490 0x22c4 \Device\Harddisk0\DR0 - ok
11:21:09.0491 0x22c4 ================ Scan VBR ==================================
11:21:09.0507 0x22c4 [ E19831703BC66066D86D836E18F7508C ] \Device\Harddisk0\DR0\Partition1
11:21:09.0562 0x22c4 \Device\Harddisk0\DR0\Partition1 - ok
11:21:09.0580 0x22c4 [ 06CC707FECFDA31348C48E2F43B3FA7D ] \Device\Harddisk0\DR0\Partition2
11:21:09.0654 0x22c4 \Device\Harddisk0\DR0\Partition2 - ok
11:21:09.0669 0x22c4 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
11:21:09.0683 0x22c4 \Device\Harddisk0\DR0\Partition3 - ok
11:21:09.0701 0x22c4 [ 6C1963B925DCD6FD2935BC842EDAAB7E ] \Device\Harddisk0\DR0\Partition4
11:21:09.0873 0x22c4 \Device\Harddisk0\DR0\Partition4 - ok
11:21:09.0895 0x22c4 [ 36E2E79A3A15291392D5F9A0E8DE88B0 ] \Device\Harddisk0\DR0\Partition5
11:21:10.0051 0x22c4 \Device\Harddisk0\DR0\Partition5 - ok
11:21:10.0093 0x22c4 [ 501AED2C959CE654E581FFBB74CC1CF4 ] \Device\Harddisk0\DR0\Partition6
11:21:10.0151 0x22c4 \Device\Harddisk0\DR0\Partition6 - ok
11:21:10.0185 0x22c4 [ DA36FEAE3D7336F302E5160B0FD77B59 ] \Device\Harddisk0\DR0\Partition7
11:21:10.0212 0x22c4 \Device\Harddisk0\DR0\Partition7 - ok
11:21:10.0213 0x22c4 ================ Scan generic autorun ======================
11:21:10.0878 0x22c4 [ 641B19018CB32619ADBD0AED4964E1D9, 4F85CD33E69A1EE9C145407E2FE28C0D6EAE0782576D656E583052A69677A910 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
11:21:10.0983 0x22c4 RTHDVCPL - ok
11:21:11.0120 0x22c4 [ BC5A40AEAC1CF7708D07CBC2F577F90B, A70B2C08CE007532739C60B474289459225D0554C8C5DA113DC649955BDC9DF6 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
11:21:11.0159 0x22c4 RtHDVBg - ok
11:21:11.0249 0x22c4 [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
11:21:11.0257 0x22c4 IAStorIcon - ok
11:21:11.0307 0x22c4 [ 5447AF432CDA61159ADDE218C468FFD9, 63BD74521F679F195C24C1818267ECCBD8A7F5C2B4CEF3E60EC46B5AE0AC72A8 ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
11:21:11.0359 0x22c4 AdobeAAMUpdater-1.0 - ok
11:21:11.0664 0x22c4 [ 4F011F572DAC7057DF9D6E9064AA77E8, CC05441572740A9996525C3B9382191022E4F918C45C09EC0DE4C11215F81008 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
11:21:11.0719 0x22c4 NvBackend - ok
11:21:11.0739 0x22c4 ShadowPlay - ok
11:21:11.0795 0x22c4 [ 27CFFB1E41A2BE2A25957A679BD84E10, 521DC8F3439EAA780AE0DA68B0FC6E671963AF76E165590EA83D2F6896B1C941 ] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
11:21:11.0805 0x22c4 AdobeCS5ServiceManager - ok
11:21:11.0827 0x22c4 [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
11:21:11.0837 0x22c4 SwitchBoard - ok
11:21:12.0013 0x22c4 [ AEB3E8A6308604C3490A36D06D6685DC, CAFAE7697261CDA6934E324FC45D893BB452F23A1196FECC6930B72FFA8A2738 ] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
11:21:12.0020 0x22c4 Adobe Acrobat Speed Launcher - ok
11:21:12.0547 0x22c4 OneDriveSetup - ok
11:21:12.0550 0x22c4 OneDriveSetup - ok
11:21:12.0660 0x22c4 [ 45354238785AE4DCB7DFDC5C8440C19D, 2E7941F6BE02C2DF60436B0471876F26F9F02EA2B604666875F17DFFB7EFE277 ] c:\temp\anwesenheitsmail.exe
11:21:12.0661 0x22c4 Anmelde-Mail - ok
11:21:12.0806 0x22c4 [ 50FCC5C822A6B4FC6F377EE9F9F37C7B, 57BD4032367D91EF19931E927127AA1D54DA6118B36C219B0FFD95326A2FFCA0 ] C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe
11:21:12.0819 0x22c4 Google Update - ok
11:21:12.0885 0x22c4 [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrive.exe
11:21:12.0911 0x22c4 OneDrive - ok
11:21:12.0913 0x22c4 OneDriveSetup - ok
11:21:12.0949 0x22c4 WAB Migrate - ok
11:21:12.0950 0x22c4 Waiting for KSN requests completion. In queue: 46
11:21:13.0951 0x22c4 Waiting for KSN requests completion. In queue: 46
11:21:14.0952 0x22c4 Waiting for KSN requests completion. In queue: 46
11:21:16.0119 0x22c4 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x61100 ( enabled : updated )
11:21:16.0146 0x22c4 Win FW state via NFP2: enabled ( trusted )
11:21:18.0500 0x22c4 ============================================================
11:21:18.0500 0x22c4 Scan finished
11:21:18.0500 0x22c4 ============================================================
11:21:18.0507 0x267c Detected object count: 0
11:21:18.0507 0x267c Actual detected object count: 0
11:22:24.0284 0x0604 Deinitialize success Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 03.08.2016
Suchlaufzeit: 09:37
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.08.03.03
Rootkit-Datenbank: v2016.05.27.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: user
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 453706
Abgelaufene Zeit: 27 Min., 45 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockUpdateSvc.exe, 2064, Löschen bei Neustart, [d9d6a2a43169ef47794ea0178f72e41c]
Module: 24
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
Registrierungsschlüssel: 25
PUP.Optional.DNSBlock, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DnsBlockUpdateSvc, In Quarantäne, [d9d6a2a43169ef47794ea0178f72e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}\INPROCSERVER32, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\DPBHO.DownloadProtect.1, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\DPBHO.DownloadProtect, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DPBHO.DownloadProtect, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DPBHO.DownloadProtect, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DPBHO.DownloadProtect.1, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DPBHO.DownloadProtect.1, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKU\S-1-5-21-3427957863-554338918-1319331597-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, HKU\S-1-5-21-3427957863-554338918-1319331597-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DNSBlock, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7b5da7f5-de7d-4e00-b330-a2e08e460095}, In Quarantäne, [7c332d19118912240ebabcfbac5549b7],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\APPID\DPBHO.DLL, In Quarantäne, [8728bd89ebafb1856e1fb0321ee58b75],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\DPBHO.DLL, In Quarantäne, [08a764e2c0dae94d84090bd72cd7d22e],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\DPBHO.DLL, In Quarantäne, [dfd0ba8c61398ea8b0ddae34f90ad42c],
Registrierungswerte: 2
PUP.Optional.DownloadProtectExtension, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{13EFC634-39AC-418D-A8C0-E4E07093C996}, C:\Windows\Installer\{9F1F32F5-A54C-43C6-A82E-2D5D5BBD7D2E}\{13EFC634-39AC-418D-A8C0-E4E07093C996}.xpi, In Quarantäne, [159a15316b2f3cfa3b87970960a3f20e]
PUP.Optional.DownloadProtectExtension, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{D4F156C4-1806-47A2-9E73-864C0703DE74}, C:\WINDOWS\Installer\{65AE91B1-F12C-4B92-91AB-8A27305C721E}\{D4F156C4-1806-47A2-9E73-864C0703DE74}.xpi, In Quarantäne, [98179da93e5cb48200c2059bcb3803fd]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 6
PUP.Optional.DownloadProtect, C:\Windows\Installer\{09233CE3-3433-4474-BCEA-46A619E71056}, In Quarantäne, [dad53610d1c9a09648753f615ba84eb2],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{8F8AA500-CC0A-4A80-BAC5-0866C9047D28}, In Quarantäne, [8e21370fd5c5db5b7a43d5cb20e30ef2],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{B97E776D-F9C8-4DAC-99EA-D5E3F8B7E126}, In Quarantäne, [04aba6a08713e15546773a66c93a7e82],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{C7AC4F4F-9150-4AF8-B1CF-23D1D74C6CD4}, In Quarantäne, [c4eb3c0ab5e5ac8acdf0465a33d018e8],
PUP.Optional.DownloadProtect.ChrPRST, C:\Windows\Installer\{65AE91B1-F12C-4B92-91AB-8A27305C721E}, In Quarantäne, [2b8491b57129d660ec2e44a204ff07f9],
PUP.Optional.DownloadProtect.ChrPRST, C:\Windows\Installer\{9F1F32F5-A54C-43C6-A82E-2D5D5BBD7D2E}, In Quarantäne, [49665cea6f2b0036b76308de1ae9da26],
Dateien: 20
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [eac5c581bfdbc47216b330874db440c0],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [8a2575d1bedc2f079732d6e13dc4ea16],
PUP.Optional.DNSBlock, C:\Windows\System32\DnsBlockUpdateSvc.exe, Löschen bei Neustart, [d9d6a2a43169ef47794ea0178f72e41c],
PUP.Optional.DownloadProtect, C:\Program Files\{84A13FAB-F340-44D2-8D84-FBDD00D3D7EF}\{CD81E72B-6467-4C6A-9D13-C909504E4BF5}.bin, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{128A2B84-C68C-4F5C-9EE4-A8CB0E412E4D}\{4204356E-6D94-4625-A7C1-3EF72E730A67}.bin, In Quarantäne, [9e11c1851f7b39fdd1d9256a46bc9c64],
PUP.Optional.DNSBlock, C:\Program Files (x86)\DnsBlock\uninst.exe, In Quarantäne, [7c332d19118912240ebabcfbac5549b7],
PUP.Optional.DNSBlock, C:\Windows\SysWOW64\DnsBlockA.dll, Löschen bei Neustart, [cee1f84e9ffb69cdb3165463926fce32],
PUP.Optional.DNSBlock, C:\Windows\SysWOW64\DnsBlockB.dll, Löschen bei Neustart, [456aa0a62773d264e9e00ea9d829d927],
Trojan.Agent.WSB, C:\Windows\SysWOW64\msoeacdt.dll, In Quarantäne, [48673016e7b3003612f30be87190bc44],
PUP.Optional.DNSBlocker.BrwsrFlsh, C:\Windows\System32\dns.block, In Quarantäne, [bcf368def6a42313b7acdeb719eaf60a],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{09233CE3-3433-4474-BCEA-46A619E71056}\cclolebfchjjacadbnfjdkgpbecegkhimrx, In Quarantäne, [dad53610d1c9a09648753f615ba84eb2],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{09233CE3-3433-4474-BCEA-46A619E71056}\xclolebfchjjacadbnfjdkgpbecegkhimml, In Quarantäne, [dad53610d1c9a09648753f615ba84eb2],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{8F8AA500-CC0A-4A80-BAC5-0866C9047D28}\cgpicdmgboidfeflapgikfedcihgapecirx, In Quarantäne, [8e21370fd5c5db5b7a43d5cb20e30ef2],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{8F8AA500-CC0A-4A80-BAC5-0866C9047D28}\xgpicdmgboidfeflapgikfedcihgapeciml, In Quarantäne, [8e21370fd5c5db5b7a43d5cb20e30ef2],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{B97E776D-F9C8-4DAC-99EA-D5E3F8B7E126}\cdgmgcljlfcmgfkckegojjodbfholadfdrx, In Quarantäne, [04aba6a08713e15546773a66c93a7e82],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{B97E776D-F9C8-4DAC-99EA-D5E3F8B7E126}\xdgmgcljlfcmgfkckegojjodbfholadfdml, In Quarantäne, [04aba6a08713e15546773a66c93a7e82],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{C7AC4F4F-9150-4AF8-B1CF-23D1D74C6CD4}\ciadlhfnjalachogoigppimkainnmmaedrx, In Quarantäne, [c4eb3c0ab5e5ac8acdf0465a33d018e8],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{C7AC4F4F-9150-4AF8-B1CF-23D1D74C6CD4}\xiadlhfnjalachogoigppimkainnmmaedml, In Quarantäne, [c4eb3c0ab5e5ac8acdf0465a33d018e8],
PUP.Optional.DownloadProtect.ChrPRST, C:\Windows\Installer\{65AE91B1-F12C-4B92-91AB-8A27305C721E}\{D4F156C4-1806-47A2-9E73-864C0703DE74}.xpi, In Quarantäne, [2b8491b57129d660ec2e44a204ff07f9],
PUP.Optional.DownloadProtect.ChrPRST, C:\Windows\Installer\{9F1F32F5-A54C-43C6-A82E-2D5D5BBD7D2E}\{13EFC634-39AC-418D-A8C0-E4E07093C996}.xpi, In Quarantäne, [49665cea6f2b0036b76308de1ae9da26],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)
Den renitenten "DNSBlock Tray" habe ich über durchsuchen der Registry gefunden, da war in einem der Run-Ordner noch ein Verweis auf eine .exe
Habe das aus der Registry entfernt, die Datei manuell gelöscht und bisher auch nicht wieder gesehen. |